Simulation
Before you really start blocking programs, make sure to use one of the two simulation modes (whitelist (simulate) or blacklist (simulate)) to test the effects of your rules in advance. During a simulation, DriveLock generates event messages for started or blocked applications based on configured rules, but execution itself is neither allowed nor prevented.
Use the simulation modes to identify applications that users are running before you enforce any blocking rules. Use the Windows Event Viewer for analysis or examine the data in the DriveLock Operations Center (DOC) to quickly find corresponding events.
Similar to applications, the simulation mode is also available for blocking (or allowing) device classes.