How to exclude specific software updates from Software Updater in WithSecure Elements Endpoint Protection? - WithSecure Community
<main>
<article class="userContent">
<h3 data-version="14" data-article="000006571" data-id="issue">Issue:</h3>
<p>How to create an exclusion for a certain software update with the WithSecure Software Updater feature in the Elements Endpoint Protection Portal for EPP for Computers or EPP for Servers devices? I do not want to have Software Updater installing updates automatically or have the user manually installing the update.</p>
<h3 data-id="resolution">Resolution:</h3>
<p></p><p><b>Prerequisite</b>: You need to have a non-default profile before you can configure your software updater settings.</p>
<p>You can exclude specific software updates from automatic installation by following these steps:</p>
<ol><li>Log in to the Elements Endpoint Protection Portal</li><li>Go to the <b>Profiles</b> page</li><li>Select the profile you want to modify</li><li>Go to <b>Software updater </b>settings tab</li><li>Under <b>Exclude software from automatic installation</b>, click <b>Add rule </b></li><li>Select from the<b> Rule </b>drop-down menu one of the following:
<ul><li>Update name contains</li><li>Software name contains</li><li>Vendor name contains </li><li>Severity equals to</li><li>Bulletin ID equals to</li></ul></li><li>Then depending on the rule you've chosen, enter the value to the remaining field. Examples:
<ul><li>Update name contains: <b>Google Chrome 89.0.4389.82 </b>(Note: for Microsoft updates, do not include the version number. Use for example only the KB number)</li><li>Software name contains: <b>Google Chrome</b></li><li>Vendor name contains: <b>Google Inc.</b></li><li>Severity equals to: Critical Security / <b>Important Security </b></li><li>Bulletin ID equals to: <b>FSPM-41-64283-4 </b>(Note: Same update can have several different Bulletin IDs due to for example Operating system version)</li></ul></li></ol>
You can view the update details from the <b>Software Updater </b>page in the Endpoint Protection Portal.<br><br><b>Note:</b>
<ul><li>Only one software per exclusion is supported. If you need to add multiple software, click <b>Add rule </b>again.</li><li>You can add several conditions in one rule, if you want to combine for example <b>Software name contains </b>and <b>Severity equals to </b>conditions, click <b>Add condition </b>in the <b>rule </b>column.</li></ul><p><br>After the profile has been saved and published, the exclusion will be taken into use on the devices that have this profile assigned. <br><br>If you would like to hide the update completely from being detected as missing by Software Updater, you need to exclude it via the following setting in the Endpoint Protection Portal profile editor:</p>
<ol><li>Log in to the Endpoint Protection Portal</li><li>Go to the <b>Profiles</b> page</li><li>Select the profile you want to modify</li><li>Go to <b>Software updater </b>settings tab</li><li>Scroll down to the <b>Exclude updates from scan results </b>section</li><li>Click <b>Add rule</b></li></ol>
When the update is hidden with this rule, the update will not be listed at all in the <b>Software Updates Missing updates </b>tab in the Endpoint Protection portal. It will also not be visible locally on the device for the user.
<p>Article no: 000006571</p>
</article>
</main>