You can define rules to allow an application or executable file to run on all endpoints in the enterprise based on the certificate associated with the file.
On the ePO - SaaS console, select Menu → Application Control → Policy Discovery to open the Policy Discovery page.
Select the request where you want to define rules.
Click Actions → Allow by Certificate Globally.
The Allow by Certificate Globally dialog box provides details and prompts you to confirm the action. Based on the file associated with a selected request, the certificate is assigned or not assigned updater privileges. If the certificate has updater privileges, allowing based on certificate allows all applications signed by the certificate to make changes to existing executable files or start new applications on the endpoints.
Click OK.
Note
The Allow by Certificate Globally action is unavailable if the main executable associated with the request is signed by a certificate included in the Restricted certificate names list.