If a program is configured as an updater, it can install new software and update existing software. With the Script as Updater (SAU) feature, you can give updater rights to scripts (such as .bat, .vbs, and .py) .
Script as Updater (SAU) and Memory-protection (MP) features are enabled by default. But when you perform a clean installation and enable Application Control, you can permanently disable these features.
Important
These features can be permanently disabled only when installing Application Control in a managed ePO - On-prem environment. In standalone mode, the SAU feature is available by default after the endpoint is restarted.
Disabling SAU and MP features in the Initial Feature configuration is permanent. You can’t enable them again after installation. Any change of MP or SAU status through a policy is ignored by the endpoint.