Updaters are authorized components that are allowed to make changes to the system.
If a program is configured as an updater, it can install new software and update existing software. By default, if you provide updater rights to a component, the child component automatically inherits the same rights.
Updaters work at a global-level and aren't application-specific or license-specific. When a program is defined as an updater, it can change any protected file.
An updater isn't authorized automatically. To be authorized, an updater must be in the allow list or given explicit authorization.
Caution
We advise caution when assigning updater rights to executable files. If you set an executable as an updater and invoke any executable from it, it can perform any change on the protected endpoints.
You can also add scripts as updaters. This feature is called Script as Updaters (SAU) and it gives updater rights to scripts (such as .bat, .vbs, and .py). When enabling Application Control, the SAU feature is available by default after the endpoint is restarted.
Application Control also includes predefined default updater rights for commonly used applications that might need to update the systems frequently. These applications are known as default updaters.