    Allow Modification of Access Protection Policy

      I am wondering if there is a way to set a default policy for a group of computers. In my specific scenario, I want to block mass mailing worms and remote creation of autorun files. However, i need it to allow exceptions so if one server needs the ability to remotely create autorun files(per a file copy process for DVD's we build) that I can just open up virus scan console on the server, unchecked the "block" check box and have it stay that way.

      Right now, it continues to recheck it. Is there any way to blanket this policy across everything in the group but allow it to be permanently modified?

      I dont want to get into creating individual policies for each server which needs a specific exception.

      Is this possible??

      Thank you