When you use Endpoint Protection with Configuration Manager, you benefit from the following:



Similar documents
How To Deploy Software Updates Using SCCM 2012 R2

Implementing Endpoint Protection in System Center 2012 R2 Configuration Manager

K7 Business Lite User Manual

SCCM How to guide deploying SCCM Client, setting up SUP and SCEP. Hans Chr. Andersen

Microsoft Forefront Endpoint Protection 2010 Evaluation Guide

How to install and use the File Sharing Outlook Plugin

Managing Software Updates with System Center 2012 R2 Configuration Manager

Idera SQL Diagnostic Manager Management Pack Guide for System Center Operations Manager. Install Guide. Idera Inc., Published: April 2013

Managing your Datacenter

SOLARWINDS ORION. Patch Manager Evaluation Guide for ConfigMgr 2012

SysAid Remote Discovery Tool

How to deploy fonts using Configuration Manager 2012 R2

Deploying Endpoint Protection Updates Offline Using SCCM 2012 R2

Deep Freeze and Microsoft System Center Configuration Manager 2012 Integration

Configuration Manager 2012 R2 Client Installation

How To Deploy Office 2016 With Office 2016 Deployment Tool

How To Backup SCCM 2012 R2 Server

Deep Freeze and Microsoft System Center Configuration Manager 2012 Integration

Forefront Endpoint Protection. Jack Cobben

Exam Questions

Stellar Phoenix Exchange Server Backup

Deploying Windows 7 Using SCCM 2012 R2

Creating and Issuing the Workstation Authentication Certificate Template on the Certification Authority

Sophos Computer Security Scan startup guide

Integrating Trend Micro OfficeScan 10 EventTracker v7.x

Installing Windows Server Update Services (WSUS) on Windows Server 2012 R2 Essentials

avast! Small Office Administration Console Small Office Administration Console User Guide

Product Guide. McAfee Endpoint Protection for Mac 2.1.0

How To Install & Use Metascan With Policy Patrol

System Center Configuration Manager

Microsoft SharePoint 2010 End User Quick Reference Card

BITDEFENDER SECURITY FOR AMAZON WEB SERVICES

Sophos Enterprise Console Help. Product version: 5.1 Document date: June 2012

Microsoft IT Increases Security and Streamlines Antimalware Management by Using Microsoft Forefront Endpoint. Protection 2010.

HP Client Catalog for Microsoft System Center Products

Deploying Applications To Users Using SCCM 2012 R2

Windows Server Update Services 3.0 SP2 Step By Step Guide

EML-09 Keeping Operating Systems and Applications up to date with Patch Management 7.1

Kaspersky Lab Mobile Device Management Deployment Guide

Microsoft Access 2007 Advanced Queries

Sophos Enterprise Console Help

Total Protection Service

Group Management Server User Guide

BitDefender Security for Exchange

GRAVITYZONE UNIFIED SECURITY MANAGEMENT. Use Cases for Beta Testers

User Management Tool 1.6

Managed Antivirus Quick Start Guide

Symantec Endpoint Protection Getting Started Guide

What is Windows Intune? The Windows Intune Administrator Console. System Overview

Total Protection Service

Sage HRMS 2014 Sage Employee Self Service Tech Installation Guide for Windows 2003, 2008, and October 2013

Create, Link, or Edit a GPO with Active Directory Users and Computers

BUILDING A SECURITY OPERATION CENTER (SOC) ACI-BIT Vancouver, BC. Los Angeles World Airports

Colligo Manager 6.2. Offline Mode - User Guide

System Center 2012 R2 SP1 Configuration Manager & Microsoft Intune

How to Configure Sophos Anti-Virus for Home Systems

Best Practice Configurations for OfficeScan 10.0

SCCM 2012 SP1. Administrator Guide. Rev. 3 May 16, 2013 UNIVERSITY OF LOUISVILLE

1. PART ONE: PREPARE OFFICE 365 PACKAGE 1.1. DOWNLOAD OFFICE 365

To install antivirus software on the Selenia Dimensions product. This document provides instructions for the following products.

Manually Add Programs to Your Firewall or Anti-Virus Programs Trusted List. ZoneAlarm

Third Party System Management Integration Solution

Getting started with OneDrive

Symantec Patch Management Solution for Windows 7.5 SP1 powered by Altiris User Guide

Vulnerability Scanning and Patch Management

Distribution List Manager User s Manual

Getting Started. Document Overview. What is Faronics Power Save? Installation Process

Sonicwall Reporting Server

Rx Medical. SMD Utility. Task Scheduler Configuration

If the Domain Controller is running Windows Server 2003, it is strongly advised that the Group Policy Management tool is installed.

Boot Images and Distribution Point Configuration For OSD In SCCM 2012 R2

Quick Start Guide v4.0 Client Outlook Connection

Colligo Manager 6.0. Offline Mode - User Guide

User Guide. Version R91. English

Secunia CSI integrated with WSUS (SCCM)

Patch Management Reference

Yale Software Library

How To - Implement Clientless Single Sign On Authentication in Single Active Directory Domain Controller Environment

Patch Management Reference

Anti-Spyware Enterprise Module software

for Small and Medium Business Quick Start Guide

To install anti virus software on the Selenia 5.x product. This document applies to all Selenia 5.x products with version 5.2 software and above.

Best Practice Configurations for OfficeScan (OSCE) 10.6

Providing Patch Management With N-central. Version 7.2

LANDesk Management Suite 9.0. Getting started with Patch Manager

How To - Implement Single Sign On Authentication with Active Directory

10 Integration with System Center Operations Manager 2012 SP1

5nine Security for Hyper-V Datacenter Edition. Version 3.0 Plugin for Microsoft System Center 2012 Virtual Machine Manager

NETWRIX CHANGE NOTIFIER

DEPLOYING EMC DOCUMENTUM BUSINESS ACTIVITY MONITOR SERVER ON IBM WEBSPHERE APPLICATION SERVER CLUSTER

User Management Tool 1.5

CLOUD SECURITY FOR ENDPOINTS POWERED BY GRAVITYZONE

Novell Filr. Windows Client

IBM Endpoint Manager Version 9.2. Patch Management for SUSE Linux Enterprise User's Guide

Version 8.0 Upgrade Installation Guide OfficeCalendar for Microsoft Outlook

ProperSync 1.3 User Manual. Rev 1.2

Installing GFI Network Server Monitor

Sophos for Microsoft SharePoint startup guide

How to Integrate SmartDeploy Enterprise with System Center Configuration Manager

Transcription:

Introduction to Endpoint Protection in Configuration Manager http://technet.microsoft.com/en us/library/hh508781.aspx When you use Endpoint Protection with Configuration Manager, you benefit from the following: You can configure antimalware policies and Windows Firewall settings to selected groups of computers, by using custom antimalware policies and client settings. You can use Configuration Manager software updates to download the latest antimalware definition files to keep client computers up-to-date. You can send email notifications, use in-console monitoring, and view reports to keep administrative users informed when malware is detected on client computers. Endpoint Protection installs its own client, which is in addition to the Configuration Manager client. The Endpoint Protection client has the following capabilities: Malware and Spyware detection and remediation. Rootkit detection and remediation. Critical vulnerability assessment and automatic definition and engine updates. Integrated Windows Firewall management. Network vulnerability detection via Network Inspection System. In the console, click on Administration, expand Overview and expand Site Configuration, select Servers and Site System Roles and click on Home in the Ribbon

and click on Add Site System Roles. Click next and then choose endpoint protection point

Click next and accept the endpoint protection license terms Choose the basic Membership as this is less intrusive, click next until all setting have successfully completed. Check SCCM server to see if endpoint 2012 has installed. How to Configure Alerts for Endpoint Protection in Configuration Manager http://technet.microsoft.com/en-us/library/hh508782.aspx Configure Endpoint Protection alerts in System Center 2012 Configuration Manager to notify administrative users when specific security events occur in your hierarchy. Notifications display in the Endpoint Protection dashboard in the Configuration Manager console, in reports, and you can configure them to be emailed to specified recipients. Use the following steps and the supplemental procedures in this topic to configure alerts for Endpoint Protection in Configuration Manager. To configure Alerts for a Collection, we need to create a collection called, Endpoint Protection Collections Click on Assets and Compliance in the console, device collections and then click on Create Device Collection in the ribbon.

Name the collection, and then browse to All Systems Next choose Query Rule, edit query statement/criteria/show query language and replace the code with; select * from SMS_R_System where SMS_R_System.OperatingSystemNameandVersion like "%Workstation 6.1%"

Click next to finalise

Now we are going to choose the properties of the device collection, and add computers to this collection In Assets and Compliance select Devices and choose Device Collections, select the Endpoint Protection Collections and click on properties Click on the Alerts tab and place a checkmark in View this collection in the Endpoint Protection Dashboard, and then check all the selected items and apply. Configure SUP to deliver Definition Updates In the Configuration Manager console, click Software Library, expand Software Updates and click on Automatic Deployment Rules

click on Create Automatic Deployment Rule and the wizard appears, give the rule a suitable name like Automatic Deployment Rule for Endpoint Protection and point it to our previously created Endpoint Protection Collections, select to create a new software update group

On the Deployment Settings page of the wizard select Minimal from the Detail level dropdown list and then click Next this reduces State Messages returned and thus reduces Server load Select date Released or Revised and specify the value to search for, Last 1 day

Click next and edit your schedule to suit your needs Select Time based on UTC, this will install the latest definition at the same time, and the select hour to allow the deployment to reach all distribution points, then select As soon as possible

I have chosen to hide updates in the Software Center Tick to allow alerts Next we are going to set up a distribution point, so make sure that that you have a package source, Example \\server\folder\updates.

Click Download software updates from distribution point and install Create a new package deployment pack, and add the package source the same as the previously created folder. Add your distribution Point

Click next until the wizard completes.

Configure the SUP Products to Sync and Perform a Sync Click on Administration, expand Overview and expand Site Configuration, select Sites and click on Settings in the ribbon and click on Configure Site Components and select Software Update Point. Click on the products tab and check Endpoint Protection 2010/12 and change your Sync schedule to 1 day

Next click on Click on Software Library, then Software Updates, right click on All Software Updates choose Synchronize Software Updates, and click yes to the configuration manager

Configure Custom Client Settings for Endpoint Protection http://technet.microsoft.com/en us/library/gg682067.aspx All client settings in System Center 2012 Configuration Manager are managed in the Configuration Manager console from the Client Settings node in the Administration workspace. A set of default settings is supplied with Configuration Manager. When you modify the default client settings, these settings are applied to all clients in the hierarchy. You can also configure custom client settings, which override the default client settings when you assign these to collections. Many of the client settings are self-explanatory. Use the following sections for more information about the client settings that might require some information before you configure them. Click on the Configuration Manager console, click Administration, click Client Settings and on the Home tab in the Create group, click Create Custom Client Device Settings.

Select Endpoint Protection and call name it, and then click Ok. Now click on your Endpoint protection to specify the settings for devices;

You can now right click on your custom settings and deploy Configure Custom Antimalware Policies Now we are going to create an Antimalware Policy, click Assets and Compliance, click Endpoint Protection, and select Antimalware Policies. In the ribbon select Create Antimalware Policy.

Give a name and discription Set your Scheduled scans as required

Now as we want SCCM to send out Definition updates, Click on Set Source make sure only the Updates distributed from Configuration Manager is selected. Right click our Antimalware Policy and select Deploy, choose your collection and all should be good.