I want the folders exempted from real-time scanning during business hours, but I want to be able to do a comprehensive scan at night that includes the entire server, even those folders excluded from real-time scanning.
Well, it's not exactly possible because you cannot schedule real-time scanning (Auto-Protect). You can only turn it on or off. However, it's possible to generally exclude a folder from Auto-Protect scans while scheduled scans are still working on it. To do this, exclude the folder scans only for Auto-Protect in your exception policy:
"Security Risk" means conventional antivirus scanning in this context.
And in your Virus and Spyware Protection policy, you need to create an appropriate scheduled scan. It should not be touched by the setting above and will scan the C:\MyFolder folder.
P.S.: I am aware of the fact that you are not in direct touch with the SEPM GUI, but the snapshot may help to understand what I mean