Not what you're asking for, but just as a data point wanted you to know that we push all 3rd party updates while users are logged in on the 'agent default' schedule. I've never had an issue (I patch Chrome, Reader, Acrobat, Flash, 7zip, iTunes, Wireshark, Google Earth, maybe a few more I'm forgetting). If we patched on startup, we'd constantly be chasing the few users who rarely reboot.
The only 3rd party app I update via software delivery because I don't want it installing when a user is logged in is Java. I haven't tested it installing while user is logged in for a few years, but when I was first testing, if a user had IE opened, the install would sometimes get corrupted. I wrote up my Java procedure here: https://www.symantec.com/connect/articles/updating-java-8-through-managed-software-delivery-policy
Lucky for me, Java doesn't update monthly & we minimize where it gets installed wherever possible.
Also, if you'd like to submit this as a feature request, go to create content at the top of connect and select 'idea' and then link it here for others to vote up if they agree.