Whitelisting non-MSI installation packages can introduce several potential issues when you attempt to install and later run executable files. The Package Contents Whitelist Policy type will scan files for only MSI packages. Non-MSI packages will be scanned for only the installation application itself.
The first issue happens when you try to execute an .exe installer; if an exception blacklist policy is present, then the intermediary applications that get launched by an installer will be caught by the blacklist, thus preventing the installation.
The second issue occurs after an application has been installed. Applications that have been installed by an .exe rather than .msi will not automatically be whitelisted by the Package Contents Whitelist Policy, which means those applications will be prevented from running with the blacklist.
Ensure child processes and installed files of whitelisted installers are whitelisted by doing one of the following solutions.
Repackage .exe installers into .msi files, which will allow the Package Contents Whitelist Policy to add the applications in the package to a whitelist.