I just started deploying SEP 11 and received alerts that four PCs had tracking cookies and one user with the box that pops up. I have found many articles on how to get rid of the box but nothing about how to configure the actions when a tracking cookie is found. The SEP log shows the action taken was leave alone and that is the primary and secondary action. But in the policies, I don't have anything set to log only for both actions. For security risks, I have actions set to quarantine and then log.
If you make a centralized exception to get rid of the box, then will you not be able to delete the tracking cookies? In other words, do you live with the box and delete or get rid of the box and log only?