Exium keeps the SASE/XDR client on every managed device at the latest, fully-patched version — automatically, off-hours, and without user or MSP effort. This guide covers three things MSPs need to know: how upgrades happen, what to do when another security tool blocks Exium, and how Exium's tamper-proofing keeps devices protected.
Zero-touch by design. In most environments, everything below happens on its own. You only need to act when another security product actively blocks Exium — covered in Handling Software Blockages.
Exium continuously ensures the version running on each device is the latest release, with all security and functional patches applied. There is no separate patch cycle for the MSP to manage.
For MSPs who prefer explicit control, upgrades can also be triggered on demand from the Admin Console with a single click (see Centralized Management).
Because the Exium client installs a network driver and a WireGuard-based tunnel, other endpoint security products — anti-virus, EDR, or a competing VPN — can occasionally block the install or an upgrade. When this happens, Exium detects the blockage and emails the MSP automatically, with the exact whitelisting steps for the product involved. No guesswork, no manual troubleshooting.
Exium's files are listed in Exium's Modular SASE and XDR Client Software. Rather than allow-listing files one at a time, use one of these two exclusions:
Preferred — exclude by signer/certificate. Create an exclusion for the code-signing identity ==NETGEAR INC==. This covers every current and future Exium binary automatically, so upgrades never re-trigger the block.
Alternative — exclude by folder. Some partners find it simpler to exclude the folder that holds all Exium files:
C:\Program Files\Speerity.
Each product falls into one of three categories, shown in the last column of the table:
| Security Software | Action required | Instructions | Co-exist? | |
|---|---|---|---|---|
| 1 | ThreatLocker | Allow the Exium app | Permitting Software from the Approval Center | ✅ Yes |
| 2 | Webroot SecureAnywhere | Allow the Exium app | Block/Allow Files settings | ✅ Yes |
| 3 | SentinelOne | Add Exium to the exclusion list | SentinelOne (Windows & Mac) Exclusions | ✅ Yes |
| 4 | McAfee | Exclude Exium files from scans | Exclude files from virus scans (Windows & macOS) | ✅ Yes |
| 5 | Cisco Secure Endpoint | Add Exium to the exclusion list | Configure and Identify Secure Endpoint Exclusions | ✅ Yes |
| 6 | Cisco AnyConnect | Disconnect and retry install; if it still fails, uninstall AnyConnect | Remove AnyConnect Modules (Windows) · Manual uninstall (macOS) | ⚠️ Maybe |
| 7 | FortiClient | Disconnect and retry install; if it still fails, uninstall FortiClient | Uninstalling FortiClient | ⚠️ Maybe |
| 8 | Perimeter81 | Uninstall Perimeter81 | Uninstalling the agent | ❌ No |
| 9 | Cato Networks | Uninstall the Cato Networks client | Uninstall the Windows Client Using MsiExec.exe | ❌ No |
| 10 | Another WireGuard VPN | Uninstall the other WireGuard VPN | Exium uses WireGuard; two WireGuard clients will conflict | ❌ No |
A device is only secure while the SASE client is running, so Exium actively protects the client against removal.
If Exium is uninstalled — by an admin or an end user — Exium automatically re-pushes and reinstalls the client to bring the device back to a fully secured state.
This means the client cannot simply be uninstalled from the device to remove protection. To permanently remove Exium from a device, the MSP must remove the user or device from the Admin Console. That is the only supported way to stop reinstallation.
As long as a user or device remains in the Exium system, Exium will keep the SASE client installed and running — guaranteeing the device stays protected.
The Admin Console gives MSPs a single place to monitor and manage the SASE client across all clients and devices. From it you can:
To explore SASE, XDR, IAM, and GRC solutions tailored to your organization, contact Exium at partners@exium.net for a consultation or demo. Ready to go? See our testing and onboarding process.