Solved

Can registry exceptions be made within Forefront Client Security?

Posted on 2010-09-01
3
630 Views
Last Modified: 2013-11-22
Greetings -

I use Group Policy Preferences extensively in my environment and Forefront Client Security is noticing when I write values to the "Run" keys in the registry and logging entries for these changes in the System Event Log.  This is flooding the logs given that Group Policy is updating every 60 minutes in my environment.

Is anyone aware of a way to authorize certain registry values to be written and ignored?  I can't find any way to do this in policy.  I can exclude files and folders but not registry keys.

Ideas?
0
Comment
Question by:amendala
  • 2
3 Comments
 
LVL 7

Expert Comment

by:Forror
ID: 33581239
*.reg  does not work?  Just curious myself, or possibly filter by REG_SZ or REG_DWORD to exclude those?

Just throwing suggestions.
0
 
LVL 7

Accepted Solution

by:
Forror earned 500 total points
ID: 33581336
Do not log events for files marked "Unknown"
 AM\Reporting\

DisableLoggingForUnknown
 On (1)

Off (0)
 R, S, C
 
Might help if the log events are being marked Unknown, not sure what errors or log message you were getting.
0
 

Author Closing Comment

by:amendala
ID: 33628644
This is the solution I implemented, though I found that there's a check box in the policy for this as well.  Thanks!  It works.
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the biggest threats facing all high-value targets are APT's.  These threats include sophisticated tactics that "often starts with mapping human organization and collecting intelligence on employees, who are nowadays a weaker link than network…
One of the biggest threats in the cyber realm pertains to advanced persistent threats (APTs). This paper is a compare and contrast of Russian and Chinese APT's.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question