I am crosschecking this. I will update this thread as soon I have an update.
Application Control does not change any firewall settings. Still, I would like to see the installation logs in <systemvolume:>\Windows\solidcore_installer.log.
Also, it would be much helpful if you could run ProcMon, capture its logs and share,
For workaround i have used command sadmin write-protect-reg -i HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile\Al lowLocalPolicyMerge. Workaround worked successfully.
Later, on checking Solidcore.log file after adding above command we got a entry saying “U.1276.1480: Jun 25 2014:14:57:46.748: ERROR: evt.c : 1240: McAfee Solidifier prevented an attempt to modify Registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile' with value 'AllowLocalPolicyMerge' by process C:\Windows\System32\svchost.exe (Process Id: 452, User: NT AUTHORITY\SYSTEM).”
On checking the services which are running under process svchost.exe (Process Id: 452) 'Group Policy Client' is one of the service running.
To clarify that Group Policy Client is the service which resets registry key when solidcore is enabled, we have disabled Group Policy Client and solidified the machine, registry setting was not reset to “0”. Hence confirmed its Group Policy Client which reset registry value with solidcore installation.
I need to know why application control triggered Group policy client to reset registry key.
Will try to attach log files as requested.