In the registry filter, the following two items are defined in advance.
No.
1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RegFilter
Key
\Parameters\MonitoredKeys\_MachineAccount
ClassKey(REG_SZ)
FileNameForSaving(REG_SZ)
Value
RelativeKeyName(REG_SZ)
2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RegFilter
Key
\Parameters\MonitoredKeys\_MSLicensing
ClassKey(REG_SZ)
FileNameForSaving(REG_SZ)
Value
RelativeKeyName(REG_SZ)
No.1: It is prepared for devices participating in the domain. To participate in a domain, you need
to update the system's secret information every 30 days, and that data is written to the
registry. If the system volume is protected by EWF or FBWF, this change is not discarded.
No. 2: It is prepared for devices that use TSCAL. When connecting to the application server
using Remote Desktop Client, TSCAL will be issued the first time you connect. If the
system volume is protected by EWF or FBWF, this license information stored in the
registry is not lost.
Table 4-7 Defined Registry Filter Setting List
Registry filter setting
4-13
4. PRECAUTIONS REGARDING THE OS
:HKLM
:_MachineAccount.RGF
:SECURITY\Policy\Secrets\$MACHINE.ACC
:HKLM
:_MSLicensing.RGF
:Software\Microsoft\MSLicensing