Share via

AppLocker publisher rules failing to recognize valid digital signatures on enterprise application update packages

Harry Taylor 0 Reputation points
2026-06-10T15:49:19.93+00:00

Hi guys, we use AppLocker publisher rules to allow trusted software updates to execute automatically based on the vendor certificate. A recent vendor update package for our core accounting suite was blocked by AppLocker on all client nodes, despite the file properties showing a fully valid digital signature from the vendor.

Windows for business | Windows 365 Enterprise
0 comments No comments

1 answer

Sort by: Most helpful
  1. Harry Phan 21,825 Reputation points Independent Advisor
    2026-06-10T16:09:40.17+00:00

    Hi Harry,

    What happened is the vendor’s update was signed a little differently than before, so your existing AppLocker rule no longer recognizes it. Even though the signature looks valid, AppLocker checks more than just the certificate, things like product name or version can break the match if they change. The fix is simple: create a new publisher rule directly from the updated file so AppLocker learns the new signature details. Also make sure the certificate chain is trusted on the client machines under Trusted Publishers. Once the rule is refreshed, future updates from that vendor should run without being blocked.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.