how to allowlist vpn client updates in endpoint security software
How to allowlist VPN client updates in endpoint security software: identify the updater processes and signers, then build the allow rules. Use when EDR or antivirus blocks VPN client upgrades. Not for disabling endpoint protection.
TL;DR
Endpoint security tools often quarantine or block VPN client updaters because they install drivers and services. The fix is to allowlist the updater by signer certificate and path, not to disable protection. Identify the exact blocked process from the EDR console first.
The query
how to allowlist vpn client updates in endpoint security softwareUse this when
- VPN client updates fail on machines with EDR installed
- updater executable quarantined after download
- pilot upgrades blocked but manual installs work
Not for
- disabling antivirus to make updates work (do not do this)
- VPN connection failures unrelated to updates
- unmanaged devices outside your EDR
Steps
- In the EDR or antivirus console, find the blocked or quarantined event for the VPN updater. Expected output: the exact process path and hash identified
- Verify the file is signed by the VPN vendor's certificate. Expected output: signer confirmed legitimate
- Create an allowlist rule by signer certificate plus install path, scoped to the updater. Expected output: a narrowly scoped allow rule
- Restore any quarantined updater files. Expected output: files restored
- Push the policy to a pilot group and run the VPN update. Expected output: update succeeds on pilots
- Roll the policy out broadly and monitor for new blocks on the next client version. Expected output: no repeat blocks
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_1o1MAw6QyppcVu9XA3GG-g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.