We did this successfully with SUS by creating an app class for SUS updates with the executable @system\wuauclt.exe allowed to download and execute all files with the .exe extension from the directory *:\Program Files\WindowsUpdates\**.
We added it as an exception to the Trojan Detection rule and to the App class.
There may be a bit more but I'd have to check.