If you have viruses or malware that hasn’t been detected by Forefront Endpoint Protection, you can use this link below to submit samples for analysis.
https://www.microsoft.com/security/portal/Submission/Submit.aspx
The answer is it depends, this information is from a icrosoft presentation and the information may change without further notice.
Microsoft reset the definition updates through a process they call ‘re-base’ – currently once a month as part of the engine release
Today there are 4 types of packages which can be used to update FEP clients
- Full (~55MB)
The full signature set (called the base) + any signatures since the last engine release (delta)Most recent engine
- Delta (ranges from ~200KB to ~5MB)
Contains the incremental signatures added since the last engine release (rebase).
- Binary Delta Engine (BDE) (ranges from ~2MB to ~15MB)
Binary diff of the previous base and engine with current base and engine plus the current incremental delta of signatures
- Binary Delta Delta (BDD) (ranges from ~100KB to ~1MB)
BDD package is different than Delta package since it will offer differential content from the previous release. Hence only new content is offered to the user.
All three package types are available on MU
Only Full packages are available on the Download Center
Internal detection logic allows each client to download the smallest package size available
The more up-to-date the client, the smaller package that client needs to download.
- First install or really out-dated (>2 engine releases behind) => Full package
- Older signatures, old engine => BDE package
- signature > 36h, current engine => delta package
- signature < 36h, current engine => bdd package
If you want to track definitions and se how your client behaves have alook in this folder (Win7)
ProgramDataMicrosoftMicrosoft AntimalwareDefinition UpdatesBackup
Below is a list of good links when you start deploying Forefront Endpoint Protection
The question came up today how can I see what policy that is applied to a local client on the local client itself ?
There are atleast 2 ways of doing this
1. GUI Option
Open the FEP Client
Press the little arrow to the right of Help and choose About Forefront Endpoint Protection
The About Screen will show up and at the bottom you see the applied policy.

2. Registry Option
The second way is to look into the registry on this or the following registy key and String
HKEY_LOCAL_MACHINESOFTWAREMicrosoftMicrosoft Security Client
“LastSuccessfullyAppliedPolicy”=”Default Desktop Policy”
You may also lookinto the log file on the client to troubleshoot eventuel errors for applying the policy and the log files is listed below:
C:WindowstempFEP-ApplyPolicy-MACHINENAME.LOG
Replace MACHINENAME with the local computername
I have seen some question on the forums and heard from customers , is it possible to change the retention period on the databas how long data is saved for Forefront Endpoint Protection Managed by ConfigMgr, so I tried to find the information and I found it so Id though id share the information with you.
You need to open the SQL Management Studio and execute the following command on your FEP DW Database
XXX Corresponds to your ConfigMgr SiteCode and value is the retention period a value between 3 and 12 (months)
EXEC FEPDW_XXX.dbo.spAN_Common_Report_UpdateMaintenanceConfiguration value
So for a site with sitecode P01 and I want to keep tha data for 3 months its this command to execute.
EXEC FEPDW_P01.dbo.spAN_Common_Report_UpdateMaintenanceConfiguration 3
The following features are new to Configuration Manager 2007 R3.
-
-
Power Management: Provides a set of tools that enable the site administrator to configure standard Windows power settings across computers and monitor power consumption and computer activity.
-
Operating System Deployment Improvements: Provides pre-staging of boot images and Windows Imaging Format (.wim) files on new computers that enables the administrator to apply a task sequence to the device that can use the pre-staged media.
-
Dynamic Collection Evaluation: Enables you to rapidly evaluate a collection membership by adding only newly discovered resources.
-
Active Directory Delta Discovery: Performs an intermediate discovery cycle that adds only new resources to the Configuration Manager 2007 database.
-
Simplified Resource Management: Enables you to search for and add resources to a specified collection.
-
Desired Configuration Management: Enables you to create a collection of compliant or noncompliant computers in desired configuration management.
-
Higher Number of Supported Clients Per Hierarchy: Configuration Manager 2007 R3 supports up to 300,000 clients per hierarchy when it uses the default settings for all Configuration Manager 2007 features. This increase in supported clients is the result of improvements to the Active Directory synchronization and Collection Evaluation processes
Installation
1. Read the Readme file
2. Launch the splash.hta
3. Install Confiuration Manager 2007 R3

4. If you havent deployed the hotfix KB977384 you need to do that first before continuing otherwise you will get the message below.

5. Press Next

6. Read and accept EULA

7. Press Next

8. Setup Complete Press Finish to complete

9. To verify ,open the console and right click on your site and choose properties to verify that the installation is done.


If you havent seen it yet now you have seen it Configuration Manager R3 is now finally RTM !
Se further details here.
http://blogs.technet.com/b/systemcenter/archive/2010/10/14/configuration-manager-2007-r3-is-here.aspx
System Center User Group Sweden is inviting our members for a new opportunity to meet, ask your questions and listen to Wally Mead (Microsoft , PM Configuration Manager). For our Swedish attendes please sign up for a membership in SCUG.SE on www.scug.se and then for the event according to this post http://www.scug.se/?p=67
Regards
Stefan Schörling