On the ePO - On-prem console, you can configure updaters by editing the list of generic launcher processes and restricted certificate names.
You can configure these settings:
Generic launcher processes — Certain processes on the Windows operating system, such as explorer.exe and iexplore.exe, start other processes and can be used to start any software. Such processes are referred to as generic launcher processes and must never be configured as updaters. A predefined list of such processes is available on the Application Control configuration interface. You can review and edit the list of generic launcher processes. No updater rules are generated for generic launcher processes at the endpoints.
Restricted certificate names — Certificates from certain vendors such as Microsoft are associated with multiple commonly used applications. They should not be used to define rules based on the certificate. A predefined list of such certificates is available on the Application Control configuration interface. You can review and edit the list of restricted certificate names. If the file in a request is signed by one of these certificates, you can't create rules based on the certificate associated with the file.
On the ePO - On-prem console, select Menu → Configuration → Server Settings → Solidcore.
Review and edit the list of generic launcher processes.
Review the processes listed in the Generic launcher processes field.
Click Edit to update the list.
Add the process name to the end of this list (separated by a comma), then click Save.
Review and edit the list of restricted certificates.
Review the names listed in the Restricted certificate names field.
Click Edit to update the list.
Add the vendor name to the end of this list (separated by a comma), then click Save.
For example, to prevent creation of rules based on the Microsoft certificate, add
Microsoftto the list. Use the value listed in the ISSUED TO field of the certificate.