Last time I wrote a blogpost about System Center 2012 Endpoint Protection (SCEP) functionality. I mentioned the installation/configuration and deploying SCEP agents (Part 1), and deploying antimalware policies & definition updates (Part 2). This time the SCEP series continues with monitoring, dashboard views and reports. When antimalware policies and definition updates are in place, it's time to have a look at monitoring the SCEP agents. There are multiple functionalities for that.
Let's start with the SCEP dashboard first.
Beneath Monitoring, the "System Center 2012 Endpoint Protection Status" can be found. This is THE dashboard for viewing Security State (Client status, Malware remediation status, Top 5 malware by number of computers) and Operational State (Operational status of clients, Definition status on computers). It can be viewed for all collections where an anti-malware policy is deployed too. Because I deploy it to ALL servers and clients (most of time), I've selected the "All Desktop and Server Clients" collection here.
Nice thing is, it's completely dynamic. You can click on all Links and graphical stuff to go to the relevant system(s). After clicking a Link or graphical item, a specific SCEP collection is showed with systems and ALL (Deployment state, Policy name, Policy application state, Definition last version, Remediation status) Endpoint Protection information. From default collections there are buttons for SCEP available too. Both Endpoint Protection status and Malware details can be watched here. SCEP is integrated on multiple places in the console.
When looking at Reports, there are six SCEP reports available. Most usable ones are "Antimalware activity report" and Dashboard. Both have a nice graphical layout by default. When rightclick on a report it's possible to select "Create Subscription", which generates a report on a scheduled time. Reports can be delivered by Windows File Share and E-mail this way. You can define the Render format also, which can be: XML, CSV, TIFF, PDF, (M)HTML, RPL, Excel and Word files.
My personal conclusion:
Microsoft did a great job with SCEP integration in ConfigMgr 2012, with: automatic SCEP client deployment, multiple policies which can be merged, a very nice dynamic dashboard, automatic deployment rules for definition updates & beautiful reports which can be delivered multiple ways and saved in multiple formats! Therefore I recommend customers for using SCEP all the time. SCEP integration in ConfigMgr 2012 is the best antivirus solution there is!
Showing posts with label System Center 2012 Endpoint Protection. Show all posts
Showing posts with label System Center 2012 Endpoint Protection. Show all posts
Thursday, November 1, 2012
Monday, October 29, 2012
System Center 2012 Endpoint Protection (part 2)
Last time I wrote a blogpost about System Center 2012 Endpoint Protection (SCEP) functionality. I mentioned the installation/configuration and deploying SCEP agents. This time the SCEP series continues with deploying antimalware policies and definition updates. With a SCEP agent installed it's time to manage them with antimalware policies, and make sure definition updates will be installed every 8 hours (if available).
Beneath "Assets and Compliance" there's a folder for creating and managing Antimalware and Windows Firewall policies. Looking at antimalware policies there is a Default Client Antimalware Policy. Just leave it at default settings and create a new policy. Just rightclick and choose "Create Antimalware Policy" or "Import". In my case I'm using Import, and choose default policies for all type of servers being used. That way most values and exclusions are set by default, which can save you a lot of configuration time.
Nice thing is you can merge multiple policies to one single policy now. That functionality wasn't available in the earlier Forefront Endpoint Protection (FEP) 2010 release. When importing (for example) both Domain Controller, DNS Server and DHCP Server policies, you can merge them to one single policy when needed. You can select a Base policy and New policy name also. That way it's a lot easier to create new antimalware policies. Just have a look at the screenshot how it looks like.
Another important step is to configure automatic definition updates. In ConfigMgr 2007 with FEP 2010 it was needed to use the "Definition Update Automation Tool" in combination with a Task Scheduler. More about that in the following blogposts HERE and HERE. In ConfigMgr 2012 you can use "Automatic Deployment Rules" for that. Just create a new rule, select Search criteria based on FEP 2010 and deploy it. In my case I deployed it on the "All Desktop and Server Clients" collection. That way all clients with a SCEP agent will automatically receive new updates.
Both antimalware policies and definition updates are in place now!
My next blogpost will be about deploying monitoring, dashboard views and reports. Stay tuned for more!
Beneath "Assets and Compliance" there's a folder for creating and managing Antimalware and Windows Firewall policies. Looking at antimalware policies there is a Default Client Antimalware Policy. Just leave it at default settings and create a new policy. Just rightclick and choose "Create Antimalware Policy" or "Import". In my case I'm using Import, and choose default policies for all type of servers being used. That way most values and exclusions are set by default, which can save you a lot of configuration time.
Nice thing is you can merge multiple policies to one single policy now. That functionality wasn't available in the earlier Forefront Endpoint Protection (FEP) 2010 release. When importing (for example) both Domain Controller, DNS Server and DHCP Server policies, you can merge them to one single policy when needed. You can select a Base policy and New policy name also. That way it's a lot easier to create new antimalware policies. Just have a look at the screenshot how it looks like.
Another important step is to configure automatic definition updates. In ConfigMgr 2007 with FEP 2010 it was needed to use the "Definition Update Automation Tool" in combination with a Task Scheduler. More about that in the following blogposts HERE and HERE. In ConfigMgr 2012 you can use "Automatic Deployment Rules" for that. Just create a new rule, select Search criteria based on FEP 2010 and deploy it. In my case I deployed it on the "All Desktop and Server Clients" collection. That way all clients with a SCEP agent will automatically receive new updates.
Both antimalware policies and definition updates are in place now!
My next blogpost will be about deploying monitoring, dashboard views and reports. Stay tuned for more!
Monday, October 22, 2012
System Center 2012 Endpoint Protection (part 1)
Last week I installed System Center 2012 Endpoint Protection (SCEP) at my office. SCEP is built on Configuration Manager (ConfigMgr) 2012, creating a single infrastructure for deploying and managing endpoint protection. SCEP uses the same industry-leading antimalware engine as Microsoft Security Essentials and Windows Defender (Windows 8), to protect systems against the latest malware and rootkits. SCEP is previously known as Forefront Endpoint Protection (FEP) 2010.
In this series of blogposts I will mention the installation/configuration and deploying SCEP agents (1), deploying antimalware policies and definition updates (2), monitoring, dashboard views and reports (3).
Let's mention the installation/configuration first.
In ConfigMgr 2007 it was needed to install and integrate FEP 2010 within the ConfigMgr console. More about that HERE. In ConfigMgr 2012 it will be a lot easier than that! Just install the Endpoint Protection point role on your ConfigMgr Site server. That way it will be activated in your environment. No need to create a software package or something like that. This will be created by default also.
Beneath "Assets and Compliance" there will be a folder for creating and managing policies. Beneath "Monitoring" there will be a Dashboard for SCEP 2012 status. In Reports there will be six reports to run. During ConfigMgr 2012 agent install, the CCMSETUP folder will be used for ConfigMgr and SCEP installation. The file SCEPInstall.exe will be download by default also. This file is used for SCEP agent installation.
Normally, SCEP installation is disabled within the ConfigMgr agent policy. Beneath "Administration" there is a Client Settings policy. Just leave it at default settings and create a new Client Settings policy. Within this new policy, enable Endpoint Protection and deploy it on a collection which must have Endpoint Protection. In my case I deployed it on the "All Desktop and Server Clients" collection. That way ALL clients with a ConfigMgr agent will also have SCEP installed automatically.
Both installation/configuration and deploy SCEP agents are done now!
My next blogpost will be about deploying antimalware policies and definition updates. Stay tuned for more!
In this series of blogposts I will mention the installation/configuration and deploying SCEP agents (1), deploying antimalware policies and definition updates (2), monitoring, dashboard views and reports (3).
Let's mention the installation/configuration first.
In ConfigMgr 2007 it was needed to install and integrate FEP 2010 within the ConfigMgr console. More about that HERE. In ConfigMgr 2012 it will be a lot easier than that! Just install the Endpoint Protection point role on your ConfigMgr Site server. That way it will be activated in your environment. No need to create a software package or something like that. This will be created by default also.
Beneath "Assets and Compliance" there will be a folder for creating and managing policies. Beneath "Monitoring" there will be a Dashboard for SCEP 2012 status. In Reports there will be six reports to run. During ConfigMgr 2012 agent install, the CCMSETUP folder will be used for ConfigMgr and SCEP installation. The file SCEPInstall.exe will be download by default also. This file is used for SCEP agent installation.
Normally, SCEP installation is disabled within the ConfigMgr agent policy. Beneath "Administration" there is a Client Settings policy. Just leave it at default settings and create a new Client Settings policy. Within this new policy, enable Endpoint Protection and deploy it on a collection which must have Endpoint Protection. In my case I deployed it on the "All Desktop and Server Clients" collection. That way ALL clients with a ConfigMgr agent will also have SCEP installed automatically.
Both installation/configuration and deploy SCEP agents are done now!
My next blogpost will be about deploying antimalware policies and definition updates. Stay tuned for more!
Subscribe to:
Posts (Atom)





