Huntress also examined a policy setting that hides exclusions from local administrators querying them through PowerShell.
Despite its name, the same setting prevented queries made under SYSTEM, a privileged Windows account. That can create a misleading impression that no exclusions exist when the configuration has simply been concealed.
Registry monitoring provides a broader view because exclusion changes ultimately reach the registry regardless of the administration method used.