Forefront doesn't come with any .adm file to manage it through group policies.
You can use Forefront Client Security Console to setup parameters (scan schedule, user's rights...).
When deployed using a GPO, you'll find parameters under Extra Registry Settings which is not very handy.
On the Aaron Tiensivu's Blog you will find an adm file (forefront.adm) that you can copy to your C:\Windows\inf folder of your server running Group Policy Management to have a more readable view.
Very cool.