You need to ensure that a notification appears only when an application tries to make changes to the computer
You need to minimize the amount of Trusted Platform Module (TPM) authorization information that is stored in the registry