Encryption in XProtect Update Manager
To install XProtect Update Manager, you must use certificates for encryption.
Important
To install updates on your hosts, you must disable the Turn Off Automatic Root Certificates Update setting before installing the update server and agents. See Enable automatic root certificate updates in Windows.
During the installation of the update server, you select the type of certificate to use:
System-generated certificates are self-signed certificates created by the installation wizard. Every system-generated certificate comes with a secure connection key. To establish a secure connection with the update server, you add the secure connection key to every update agent computer.
Your own certificate. To see your certificate listed in the installation wizard, you must import a .pfx certificate to the Personal store on the computer.