In some cases, enterprises might use Airlock or similar solutions to block unsigned installers from running.
In those cases, the hash of the installer will always have to be whitelisted manually each time there is a new update for that software.
with Intune, a code signing certificate can be specified in PMPC to sign detection scripts.
Would it be possible to also offer the choice of signing unsigned installers with the same certificate?
A manual whitelist of the unsigned installer won't be necessary anymore.