Hi,
Q. Is there a way to set up notifications without also having the system administrators box checked?
--> Yes, it's possible, but don't test with EICAR or modify settings.
The damper setting for the notification may be preventing a series of EICAR detections from generating individual notifications, i.e. multiple EICAR detections within the damper period of a "single risk event" notification will generate only one notification for that period. Note also that if you do not see any "single risk event" notifications to acknowledge in the SEPM (under "View Notifications") this is by design. "Single risk" notifications are the only ones that cannot be configured to write a notification to the database -- they will, however, send email or run a custom batch file.
Database maintenance may be deleting EICAR events before the notification task can process them.
To prevent this: In older versions of the SEPM, go to Admin > Servers > Local Site > Properties > Database tab, and uncheck "Delete EICAR events". In newer versions, go to Admin > Servers > localhost > Edit Database Properties > Log Settings, and uncheck "Delete EICAR events" in the Risk Log Settings section