Hi. Yes, I have DHCP failover configured between the two DHCP servers. It's configured as a 50/50 load balance failover.
I see now that the PTR record is being updated by the dhcp account... and the account is showing up in the ACL of the record... but only if I delete the existing PTR record that has the machine account in it. This doesn't work for the Forward record though.
EDIT: the PTR record is not consistently updating. Sometimes it is updated (and owned) by the dhcp account, other times by the machine account. Perhaps it depends on what DC is handling it (2012 or the new 2019).
The key does not need to be added manually UNLESS you want to change the default value. After the update, no key is the same as having the key with a value of 1. If you want the value to be 0 or 2, then the key and value needs to be added manually. The KB describes the difference between the values.
The April '22 update will remove the setting of 0 IF you previously set it 0. It will have the same effect as 1... or no key at all. If you previously set the key to 2, that setting will remain.
The July '22 update will remove the key and setting altogether.
The KB does not state how to stop the new events we're seeing in the event logs. Perhaps they will stop once the July '22 updates are applied (which transitions the DCs to enforcement mode.