- export Certificate without private key. (ex. mykey.cer)
- Open “Group Policy Manager”
- Under Computer Configuration – Windows Settings – Security Settings – Software Restriction Policies
- Right click and create a new Software Restriction policy if you haven’t got one already
- Under Additional rules right click and create new “Certificate rule”
- Click browse and select the exported certificate that is being used to sign the updates (.cer file)
- Change the “Security Level” to Unrestricted otherwise you will stop the computers running any programs!