You said
"Run As SmartScreen" is intended for the H_C default-deny setup to run:
EXE or MSI installers which are located in unsafe (not whitelisted) locations.
Are the same unsafe locations that you specified it for "Run by Smartscreen' ?
'Run as SmartScreen' is it like you force to run it with UAC prompt, it it more or less secure than 'Run by Smartscreen' ? So depending on the HC setup, either 'Default Deny' or either Allow, we choose 'Run as Smartscreen' or 'Run by Smartscreen', right ?