There is now an end user created Forefront Client Security v1 Group Policy Object (GPO) available for use for setting Forefront Client settings without a back-end management server involved. Most commonly called a '/nomom' installation because the client is installed without a management server specified on the command line. This is also ideal for non-domain joined computers and you want to lock down settings locally.
Originally spotted
here talking about a Technet message forum post
here. You can download the .ADM file
here.