FIM and Windows Updates Best Practices

Hi all,

When using the File Integrity Module integration, is there a way to tune out expected behavior from Windows updates? Been having a lot of alerts following regular updates.

EDIT: I thought about adding an exception to the alert for TrustedInstaller but pretty sure with enough effort, attackers can act as TrustedInstaller