<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MSFAQ.SE &#187; admin</title>
	<atom:link href="http://www.msfaq.se/author/admin/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.msfaq.se</link>
	<description>System Management by Stefan Schörling</description>
	<lastBuildDate>Mon, 31 Oct 2011 20:26:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Best of MMS &#8211; Sweden</title>
		<link>http://www.msfaq.se/2011/10/best-of-mms-sweden-2/</link>
		<comments>http://www.msfaq.se/2011/10/best-of-mms-sweden-2/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 20:26:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[ConfigMgr 2012]]></category>
		<category><![CDATA[MBAM]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/2011/10/best-of-mms-sweden-2/</guid>
		<description><![CDATA[&#160; Thanks to everyone that attended mine and Jörgens&#160; session last week. As promised we will post some MBAM (Microsoft Bitlocker and Administration) Blog posts the coming weeks. &#160; To start with here are the links that we had in our presentation. We will post more thing related to MBAM along the way so please [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.msfaq.se/wp-content/uploads/2011/10/MBAM.jpg"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="" border="0" alt="" src="http://www.msfaq.se/wp-content/uploads/2011/10/MBAM_thumb.jpg" width="234" height="166" /></a></p>
<p>&#160;</p>
<p>Thanks to everyone that attended mine and <a href="http://ccmexec.com" target="_blank">Jörgens</a>&#160; session last week. As promised we will post some MBAM (Microsoft Bitlocker and Administration) Blog posts the coming weeks.</p>
<p>&#160;</p>
<p>To start with here are the links that we had in our presentation. We will post more thing related to MBAM along the way so please stay tuned here for more MBAM information.</p>
<p><strong>General</strong></p>
<p>MBAM MP for Operations Manager   <br /><a href="http://www.microsoft.com/download/en/details.aspx?id=26796">http://www.microsoft.com/download/en/details.aspx?id=26796</a>    <br />Bitlocker FAQ    <br /><a href="http://technet.microsoft.com/en-us/library/ee449438(WS.10).aspx">http://technet.microsoft.com/en-us/library/ee449438(WS.10).aspx</a>    <br />MBAM in WinPE    <br /><a href="http://myitforum.com/cs2/blogs/nbrady/archive/2011/09/06/how-can-i-retrieve-my-bitlocker-recovery-key-from-mbam-in-windows-pe.aspx">http://myitforum.com/cs2/blogs/nbrady/archive/2011/09/06/how-can-i-retrieve-my-bitlocker-recovery-key-from-mbam-in-windows-pe.aspx</a>    <br />KBs    <br /><a href="http://support.microsoft.com/kb/2612822">http://support.microsoft.com/kb/2612822</a></p>
<p><strong>Handling of TPM</strong> </p>
<p>HP    <br /><a href="http://itbloggen.se/cs/blogs/micke/archive/2010/10/18/enable-tpm-via-task-sequence-on-hp-boxes.aspx">http://itbloggen.se/cs/blogs/micke/archive/2010/10/18/enable-tpm-via-task-sequence-on-hp-boxes.aspx</a>    <br />Dell    <br /><a href="Http://www.nullsession.com/2010/12/02/enable-tpm-in-task-sequence-with-sccm-and-cctk/">Http://www.nullsession.com/2010/12/02/enable-tpm-in-task-sequence-with-sccm-and-cctk/</a>    <br />Lenovo    <br /><a href="http://blog.coretech.dk/mip/enable-lenovo-tpm-security-chip-and-other-stuff-from-a-ts/">http://blog.coretech.dk/mip/enable-lenovo-tpm-security-chip-and-other-stuff-from-a-ts/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/10/best-of-mms-sweden-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FEP 2010 Update Rollup 1</title>
		<link>http://www.msfaq.se/2011/06/fep-2010-update-rollup-1/</link>
		<comments>http://www.msfaq.se/2011/06/fep-2010-update-rollup-1/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 20:10:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[FEP]]></category>
		<category><![CDATA[KB]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/?p=362</guid>
		<description><![CDATA[Update Rollup for FEP 2010 has been released so go read about it as it will enhance your FEP expericne with Config Mgr for update management. It also has some new OS uspport TechNet Whats New ! &#8211; http://technet.microsoft.com/en-us/library/hh211541.aspx Download &#8211; http://www.microsoft.com/download/en/details.aspx?id=26583]]></description>
			<content:encoded><![CDATA[<p>Update Rollup for FEP 2010 has been released so go read about it as it will enhance your FEP expericne with Config Mgr for update management. It also has some new OS uspport</p>
<p>TechNet Whats New ! &#8211; <a href="http://technet.microsoft.com/en-us/library/hh211541.aspx" target="_blank">http://technet.microsoft.com/en-us/library/hh211541.aspx</a></p>
<p>Download &#8211; <a href="http://www.microsoft.com/download/en/details.aspx?id=26583" target="_blank">http://www.microsoft.com/download/en/details.aspx?id=26583</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/06/fep-2010-update-rollup-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>(Swedish) Informator Seminarie</title>
		<link>http://www.msfaq.se/2011/04/swedish-informator-seminarie/</link>
		<comments>http://www.msfaq.se/2011/04/swedish-informator-seminarie/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 05:43:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2012]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/?p=355</guid>
		<description><![CDATA[Hej som utlovat kommer presentationen från dagens seminare på följande länk. Om ni har frågor eller andra tankar är ni välkomna att skicka e-post på adressen som står i presentationen. Config Mgr 2012 &#8211; Overview]]></description>
			<content:encoded><![CDATA[<p>Hej som utlovat kommer presentationen från dagens seminare på följande länk. Om ni har frågor eller andra tankar är ni välkomna att skicka e-post på adressen som står i presentationen.</p>
<p><a href="http://www.msfaq.se/wp-content/uploads/2011/04/Config-Mgr-2012-Overview-Ed_1b.pdf">Config Mgr 2012 &#8211; Overview</a></p>
<p><a href="http://www.informator.se/" target="_blank"><img class="alignnone size-full wp-image-358" title="informatorlogo" src="http://www.msfaq.se/wp-content/uploads/2011/04/informatorlogo.gif" alt="" width="148" height="93" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/04/swedish-informator-seminarie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Handling users uninstalling FEP</title>
		<link>http://www.msfaq.se/2011/04/handling-users-uninstalling-fep/</link>
		<comments>http://www.msfaq.se/2011/04/handling-users-uninstalling-fep/#comments</comments>
		<pubDate>Thu, 07 Apr 2011 19:29:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[FEP]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/2011/04/handling-users-uninstalling-fep/</guid>
		<description><![CDATA[If you have local administrators they might uninstall Forefront Endpoint Protection 2010 from their system, to keep track of this and automatically remediating this. Then you have the option to advertise a FEP installation to the built-in collection for FEP called “Locally Removed”.&#160; So if a user uninstalls the client they will get it automatically [...]]]></description>
			<content:encoded><![CDATA[<p>If you have local administrators they might uninstall Forefront Endpoint Protection 2010 from their system, to keep track of this and automatically remediating this. Then you have the option to advertise a FEP installation to the built-in collection for FEP called “Locally Removed”.&#160; So if a user uninstalls the client they will get it automatically again. </p>
<p>&#160;</p>
<p><a href="http://msfaq.se/wp-content/uploads/2011/04/fep-locally-removed.png"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px; padding-top: 0px" title="fep-locally-removed" border="0" alt="fep-locally-removed" src="http://msfaq.se/wp-content/uploads/2011/04/fep-locally-removed_thumb.png" width="244" height="189" /></a></p>
<p>Don’t forget to set the advertisement to always rerun. Its also a good idea to keep track of the advertisement to make sure you don’t have clients that end up in a loop.</p>
<p><strong>Note:</strong> I have seen some cases where there is an issue with clients ending up in this collection without having the client uninstalled. Usually triggering a Hardware Inventory resolves this.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/04/handling-users-uninstalling-fep/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remediating FEP clients with protection disabled</title>
		<link>http://www.msfaq.se/2011/04/remediating-fep-clients-with-protection-disabled/</link>
		<comments>http://www.msfaq.se/2011/04/remediating-fep-clients-with-protection-disabled/#comments</comments>
		<pubDate>Thu, 07 Apr 2011 19:20:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[FEP]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/2011/04/remediating-fep-clients-with-protection-disabled/</guid>
		<description><![CDATA[As some of you might have noticed there is no Tamper protection with Forefront Endpoint Protection 2010. So how would you handle this in your environment ? Usually the issue comes if you have your users as local administrators on their PCs they have full control over their PC. So there are different ways to [...]]]></description>
			<content:encoded><![CDATA[<p>As some of you might have noticed there is no Tamper protection with Forefront Endpoint Protection 2010. So how would you handle this in your environment ?</p>
<p>Usually the issue comes if you have your users as local administrators on their PCs they have full control over their PC.</p>
<p>So there are different ways to go around this. My first way to handle this is to configure a GPO that controls the Microsoft Antimalware Service. And set the Service to automatically start and only your real administrators to have the Start and Stop Rights.</p>
<p>My option 2 is to have a advertisement with a reoccurring script or startup script to set the service to start automatically and start the service it if its stopped. The target is the Built-in Collection</p>
<p>&#160;</p>
<p><a href="http://msfaq.se/wp-content/uploads/2011/04/protection-service-off.png"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: block; float: none; margin-left: auto; border-top: 0px; margin-right: auto; border-right: 0px; padding-top: 0px" title="protection-service-off" border="0" alt="protection-service-off" src="http://msfaq.se/wp-content/uploads/2011/04/protection-service-off_thumb.png" width="244" height="150" /></a></p>
<p>&#160;</p>
<blockquote><p>strComputer = &quot;.&quot;     <br />Set objWMIService = GetObject(&quot;winmgmts:\&quot; &amp; strComputer &amp; &quot;rootcimv2&quot;)</p>
<p>Set colServiceList = objWMIService.ExecQuery _     <br />(&quot;Select * from Win32_Service where Name = &#8216;MsMpSvc&#8217;&quot;)      <br />For Each objService in colServiceList      <br />objService.ChangeStartMode(&quot;Automatic&quot;)      <br />Wscript.Sleep 5000      <br />errReturnCode = objService.StartService()      <br />Next       </p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/04/remediating-fep-clients-with-protection-disabled/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where do I find information about the latest Forefront definitions ?</title>
		<link>http://www.msfaq.se/2011/04/where-do-i-find-information-about-the-latest-forefront-definitions/</link>
		<comments>http://www.msfaq.se/2011/04/where-do-i-find-information-about-the-latest-forefront-definitions/#comments</comments>
		<pubDate>Thu, 07 Apr 2011 18:51:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[FEP]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/2011/04/where-do-i-find-information-about-the-latest-forefront-definitions/</guid>
		<description><![CDATA[Quite frequently the question where do I see what the latest release definition updates are from Microsoft. Sometime you want to compare and check so you have the latest definitions in your environent. At the url posted below you will find the latest information about definitions and the ability to download them manually. http://www.microsoft.com/security/portal/Definitions/ADL.aspx]]></description>
			<content:encoded><![CDATA[<p>Quite frequently the question where do I see what the latest release definition updates are from Microsoft. Sometime you want to compare and check so you have the latest definitions in your environent.</p>
<p>At the url posted below you will find the latest information about definitions and the ability to download them manually.</p>
<p><a title="http://www.microsoft.com/security/portal/Definitions/ADL.aspx" href="http://www.microsoft.com/security/portal/Definitions/ADL.aspx">http://www.microsoft.com/security/portal/Definitions/ADL.aspx</a></p>
<p align="center"><a href="http://msfaq.se/wp-content/uploads/2011/04/malware-protection-center1.png"><img style="background-image: none; border-bottom: 0px; border-left: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px" title="malware-protection-center" border="0" alt="malware-protection-center" src="http://msfaq.se/wp-content/uploads/2011/04/malware-protection-center_thumb.png" width="447" height="255" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/04/where-do-i-find-information-about-the-latest-forefront-definitions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TechDays 2011 Managing FEP with Config Mgr</title>
		<link>http://www.msfaq.se/2011/03/techdays-2011-managing-fep-with-config-mgr/</link>
		<comments>http://www.msfaq.se/2011/03/techdays-2011-managing-fep-with-config-mgr/#comments</comments>
		<pubDate>Wed, 30 Mar 2011 15:17:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[FEP]]></category>
		<category><![CDATA[Ops Mgr 2007]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/2011/03/techdays-2011-managing-fep-with-config-mgr/</guid>
		<description><![CDATA[After the  session I got some questions regarding the MOM Agent for the FCS Client when upgrading. Apparently my tongue slipped and I misstated the behavior of the MOM  Agent uninstallation. My apologies for that. The intended action is that the MOM Agent should get uninstalled although there has been some minor issues detected with [...]]]></description>
			<content:encoded><![CDATA[<p>After the  session I got some questions regarding the MOM Agent for the FCS Client when upgrading. Apparently my tongue slipped and I misstated the behavior of the MOM  Agent uninstallation. My apologies for that.</p>
<p>The intended action is that the MOM Agent should get uninstalled although there has been some minor issues detected with this. But the normal behavior should be that the MOM Agent <strong>should get uninstalled</strong>! Although if the MOM agent is multihomed uninstallation will prompt  for this. If you encounter the behavior where the client is not uninstalled please contact Microsoft Support.</p>
<p><a href="http://technet.microsoft.com/en-us/library/gg477033.aspx" target="_blank">http://technet.microsoft.com/en-us/library/gg477033.aspx</a></p>
<p>Below you will find a link with the presentation as promised. At the end you will find the links discussed in the presentation. For those of you who have other question feel free to contact me.</p>
<p>I forgot to mention our Swedish based System Center User Group that is  found @ <a href="http://www.scug.se" target="_blank">www.scug.se</a></p>
<p>Best Regards<br />
Stefan Schörling<br />
<a href="mailto:stefan@msfaq.se">stefan@msfaq.se</a></p>
<p>ALL CODE IS PROVIDED AS IS WITH NO WARRANTIES</p>
<p><strong>Presentation: </strong><a href="http://msfaq.se/wp-content/uploads/2011/03/Managing-Forefront-Endpoint-Protection-with-System-Center-Configurationv2.pdf" target="_blank">Managing Forefront Endpoint Protection with System Center Configuration Manager</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/03/techdays-2011-managing-fep-with-config-mgr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What URLs are needed for FEP Deifnition Updates ?</title>
		<link>http://www.msfaq.se/2011/03/what-urls-are-needed-for-fep-deifnition-updates/</link>
		<comments>http://www.msfaq.se/2011/03/what-urls-are-needed-for-fep-deifnition-updates/#comments</comments>
		<pubDate>Thu, 03 Mar 2011 21:41:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ConfigMgr 2007]]></category>
		<category><![CDATA[FEP]]></category>

		<guid isPermaLink="false">http://www.msfaq.se/?p=267</guid>
		<description><![CDATA[Forefont can use Microsoft Update to get definitions and sometime you need to open proxy servers and firewalls for this. It is not a must to use this source but if you are using this method , I have posted a list below of known urls for Microsoft Update that you can exclude or allow in [...]]]></description>
			<content:encoded><![CDATA[<p>Forefont can use Microsoft Update to get definitions and sometime you need to open proxy servers and firewalls for this. It is not a must to use this source but if you are using this method , I have posted a list below of known urls for Microsoft Update that you can exclude or allow in your proxy or firewall.</p>
<p><a href="http://download.windowsupdate.com">http://download.windowsupdate.com</a><br />
<a href="https://*.windowsupdate.microsoft.com">https://*.windowsupdate.microsoft.com</a><br />
<a href="http://*.windowsupdate.microsoft.com">http://*.windowsupdate.microsoft.com</a><br />
<a href="http://update.microsoft.com">http://update.microsoft.com</a><br />
<a href="http://*.windowsupdate.com">http://*.windowsupdate.com</a><br />
<a href="http://download.microsoft.com">http://download.microsoft.com</a><br />
<a href="http://windowsupdate.microsoft.com">http://windowsupdate.microsoft.com</a><br />
<a href="http://ntservicepack.microsoft.com">http://ntservicepack.microsoft.com</a><br />
<a href="http://wustat.windows.com">http://wustat.windows.com</a><br />
<a href="https://update.microsoft.com">https://update.microsoft.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msfaq.se/2011/03/what-urls-are-needed-for-fep-deifnition-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

