## TL;DR
Endpoint security tools often quarantine or block VPN client updaters because they install drivers and services. The fix is to allowlist the updater by signer certificate and path, not to disable protection. Identify the exact blocked process from the EDR console first.

## The query
```text
how to allowlist vpn client updates in endpoint security software
```

## Use this when
- VPN client updates fail on machines with EDR installed
- updater executable quarantined after download
- pilot upgrades blocked but manual installs work

## Not for
- disabling antivirus to make updates work (do not do this)
- VPN connection failures unrelated to updates
- unmanaged devices outside your EDR

## Steps
1. In the EDR or antivirus console, find the blocked or quarantined event for the VPN updater. Expected output: the exact process path and hash identified
2. Verify the file is signed by the VPN vendor's certificate. Expected output: signer confirmed legitimate
3. Create an allowlist rule by signer certificate plus install path, scoped to the updater. Expected output: a narrowly scoped allow rule
4. Restore any quarantined updater files. Expected output: files restored
5. Push the policy to a pilot group and run the VPN update. Expected output: update succeeds on pilots
6. Roll the policy out broadly and monitor for new blocks on the next client version. Expected output: no repeat blocks

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_1o1MAw6QyppcVu9XA3GG-g
