Category: ConfigMgr 2007

Where do I submit Malware or Virus Samples to Microsoft?

If you have viruses or malware that hasn’t been detected by Forefront Endpoint Protection, you can use this link below to submit samples for analysis.

 https://www.microsoft.com/security/portal/Submission/Submit.aspx

 

 

How large are Forefront Endpoint Protection 2010 Client Definitions

The answer is it depends, this information is from a icrosoft presentation and the information may change without further notice.

Microsoft reset the definition updates through a process they call ‘re-base’ – currently once a month as part of the engine release
Today there are 4 types of packages which can be used to update FEP clients

  • Full (~55MB)
    The full signature set (called the base) + any signatures since the last engine release (delta)Most recent engine
  • Delta (ranges from ~200KB to ~5MB)
    Contains the incremental signatures added since the last engine release (rebase).
  • Binary Delta Engine (BDE) (ranges from ~2MB to ~15MB)
    Binary diff of the previous base and engine with current base and engine plus the current incremental delta of signatures
  • Binary Delta Delta (BDD) (ranges from ~100KB to ~1MB)
    BDD package is different than Delta package since it will offer differential content from the previous release. Hence only new content is offered to the user.
    All three package types are available on MU
    Only Full packages are available on the Download Center
    Internal detection logic allows each client to download the smallest package size available
    The more up-to-date the client, the smaller package that client needs to download.
  • First install or really out-dated (>2 engine releases behind) => Full package
  • Older signatures, old engine => BDE package
  • signature > 36h, current engine => delta package
  • signature < 36h, current engine => bdd package

 If you want to track definitions and se how your client behaves have alook in this folder (Win7)

ProgramDataMicrosoftMicrosoft AntimalwareDefinition UpdatesBackup

Forefront Endpoint Protection – Resources

Below is a list of good links when you start deploying Forefront Endpoint Protection

View FEP Policy Assigned on Client

The question came up today how can I see what policy that is applied to a local client on the local client itself ?

There are atleast 2 ways of doing this

1. GUI Option

Open the FEP Client

Press the little arrow to the right of Help and choose About Forefront Endpoint Protection

The About Screen will show up and at the bottom you see the applied policy.

2. Registry Option 

The second way is to look into the registry on this or the following registy key and String

 HKEY_LOCAL_MACHINESOFTWAREMicrosoftMicrosoft Security Client

“LastSuccessfullyAppliedPolicy”=”Default Desktop Policy”

You may also lookinto the log file on the client to troubleshoot eventuel errors for applying the policy and the log files is  listed below:

C:WindowstempFEP-ApplyPolicy-MACHINENAME.LOG

 Replace MACHINENAME with the local computername

FEP – Changing Retention Period

I have seen some question on the forums and heard from customers , is it possible to change the retention period on the databas how long data is saved for Forefront Endpoint Protection Managed by ConfigMgr, so I tried to find the information and I found it so Id though id share the information with you.

You need to open the SQL Management Studio and execute the following command on your FEP DW Database

XXX Corresponds to your ConfigMgr SiteCode and value is the retention period a value between 3 and 12 (months)

EXEC FEPDW_XXX.dbo.spAN_Common_Report_UpdateMaintenanceConfiguration value

So for a site with sitecode P01 and I want to keep tha data for 3 months its this command to execute.

EXEC FEPDW_P01.dbo.spAN_Common_Report_UpdateMaintenanceConfiguration 3

Installing Configuration Manager 2007 R3

 

The following features are new to Configuration Manager 2007 R3.

  •  
    • Power Management: Provides a set of tools that enable the site administrator to configure standard Windows power settings across computers and monitor power consumption and computer activity.
    • Operating System Deployment Improvements: Provides pre-staging of boot images and Windows Imaging Format (.wim) files on new computers that enables the administrator to apply a task sequence to the device that can use the pre-staged media.
    • Dynamic Collection Evaluation: Enables you to rapidly evaluate a collection membership by adding only newly discovered resources.
    • Active Directory Delta Discovery: Performs an intermediate discovery cycle that adds only new resources to the Configuration Manager 2007 database.
    • Simplified Resource Management: Enables you to search for and add resources to a specified collection.
    • Desired Configuration Management: Enables you to create a collection of compliant or noncompliant computers in desired configuration management.
    • Higher Number of Supported Clients Per Hierarchy: Configuration Manager 2007 R3 supports up to 300,000 clients per hierarchy when it uses the default settings for all Configuration Manager 2007 features. This increase in supported clients is the result of improvements to the Active Directory synchronization and Collection Evaluation processes

Installation

1. Read the Readme file

2. Launch the splash.hta

3. Install Confiuration Manager 2007 R3

1

4. If you havent deployed the hotfix KB977384 you need to do that first before continuing otherwise you will get the message below.

2

5. Press Next

3

6. Read and accept EULA

4

7. Press Next

5

8. Setup Complete Press Finish to complete

6

9. To verify ,open the console and right click on your site and choose properties to verify that the installation is done.

image

7

Config Mgr R3 RTM

If you havent seen it yet now you have seen it Configuration Manager R3 is now finally RTM !

Se further details here.

http://blogs.technet.com/b/systemcenter/archive/2010/10/14/configuration-manager-2007-r3-is-here.aspx

SCUG Meeting Copenhagen

System Center User Group Sweden is inviting our members for a new opportunity to meet, ask your questions and listen to  Wally Mead (Microsoft , PM Configuration Manager). For our Swedish attendes please sign up for a membership in SCUG.SE on www.scug.se and  then for the event according to this post http://www.scug.se/?p=67

Regards

Stefan Schörling

WordPress Themes