Can registry exceptions be made within Forefront Client Security?

Greetings -

I use Group Policy Preferences extensively in my environment and Forefront Client Security is noticing when I write values to the "Run" keys in the registry and logging entries for these changes in the System Event Log.  This is flooding the logs given that Group Policy is updating every 60 minutes in my environment.

Is anyone aware of a way to authorize certain registry values to be written and ignored?  I can't find any way to do this in policy.  I can exclude files and folders but not registry keys.

Who is Participating?
ForrorConnect With a Mentor Commented:
Do not log events for files marked "Unknown"

 On (1)

Off (0)
 R, S, C
Might help if the log events are being marked Unknown, not sure what errors or log message you were getting.
*.reg  does not work?  Just curious myself, or possibly filter by REG_SZ or REG_DWORD to exclude those?

Just throwing suggestions.
amendalaAuthor Commented:
This is the solution I implemented, though I found that there's a check box in the policy for this as well.  Thanks!  It works.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.