Set Processes that are Skipped for System Configuration File Monitoring
Use this group policy to specify programs that modify configuration files which you do not want to be monitored when Set monitoring of system configuration files is enabled.
When you enable this policy, you can specify a list of trusted programs that can modify any system configuration files or directories without causing an audit trail event.
If this policy is Not configured, /usr/sbin/daspool is skipped by default, along with all adclient and dad processes and subprocesses.