Allow a file by certificate

Prev Next

You can define rules to allow an application, executable file, or ActiveX control to run on all endpoints in the enterprise based on the certificate associated with the file.

  1. On the ePO - On-prem console, select MenuApplication ControlPolicy Discovery to open the Policy Discovery page.

  2. Select the request where you want to define rules.

  3. Click ActionsAllow by Certificate Globally.

  4. The Allow by Certificate Globally dialog box provides details and prompts you to confirm the action. Based on the file associated with a selected request, the certificate is assigned or not assigned updater privileges. If the certificate has updater privileges, allowing based on certificate allows all applications signed by the certificate to make changes to existing executable files or start new applications on the endpoints.

  5. Click OK.

    Note

    The Allow by Certificate Globally action is unavailable if the main executable associated with the request is signed by a certificate included in the Restricted certificate names list.