<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Forefront Endpoint Protection Blog - All Comments</title><link>http://blogs.technet.com/b/clientsecurity/</link><description>All the latest news and information on Forefront Client Security, Forefront Endpoint Protection and System Center Endpoint Protection 2012</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: The System Center Security Monitoring Pack for Endpoint Protection now supports System Center 2012 Operations Manager SP1</title><link>http://blogs.technet.com/b/clientsecurity/archive/2013/02/13/the-system-center-security-monitoring-pack-for-endpoint-protection-now-supports-system-center-2012-operations-manager-sp1.aspx#3559633</link><pubDate>Tue, 19 Mar 2013 17:27:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3559633</guid><dc:creator>J.C. Hornbeck [MSFT]</dc:creator><description>&lt;p&gt;Hi Steve, to the best of my knowledge there&amp;#39;s no work around like you describe but I&amp;#39;ll definitely pass this along to the dev team.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3559633" width="1" height="1"&gt;</description></item><item><title>re: The System Center Security Monitoring Pack for Endpoint Protection now supports System Center 2012 Operations Manager SP1</title><link>http://blogs.technet.com/b/clientsecurity/archive/2013/02/13/the-system-center-security-monitoring-pack-for-endpoint-protection-now-supports-system-center-2012-operations-manager-sp1.aspx#3559576</link><pubDate>Tue, 19 Mar 2013 14:22:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3559576</guid><dc:creator>Steve Burkett</dc:creator><description>&lt;p&gt;Hi J.C.,&lt;/p&gt;
&lt;p&gt;The docs for the MP say that to monitor clients, they all need Ops Manager agents on them (Pricey!).&lt;/p&gt;
&lt;p&gt;Is that the only option to monitor SCEP clients using Ops Manager? &amp;nbsp;We&amp;#39;d just want to flag up an alert when we get an infection somewhere.&lt;/p&gt;
&lt;p&gt;Is it possible for Ops Manager to monitor just the SCCM 2012 server which is pulling in all the SCEP status reports anyway?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3559576" width="1" height="1"&gt;</description></item><item><title>re: Monitoring Forefront Endpoint Protection 2010 – the FEP Dashboard</title><link>http://blogs.technet.com/b/clientsecurity/archive/2010/11/09/monitoring-forefront-endpoint-protection-2010-the-fep-dashboard.aspx#3547878</link><pubDate>Wed, 23 Jan 2013 18:34:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3547878</guid><dc:creator>J.C. Hornbeck [MSFT]</dc:creator><description>&lt;p&gt;The dashboard data is a result of WSQL queries that run every hour. These queries essentially sort the machines into the different FEP Collections based on the FEP data uploaded by the ConfigMgr client.&lt;/p&gt;
&lt;p&gt;There is no setting to determine a timeframe because there isn’t a timeframe. It’s real-time in the sense that every hour the database is queried and machines are moved based on their relative data.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3547878" width="1" height="1"&gt;</description></item><item><title>re: Monitoring Forefront Endpoint Protection 2010 – the FEP Dashboard</title><link>http://blogs.technet.com/b/clientsecurity/archive/2010/11/09/monitoring-forefront-endpoint-protection-2010-the-fep-dashboard.aspx#3547847</link><pubDate>Wed, 23 Jan 2013 16:39:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3547847</guid><dc:creator>Jon</dc:creator><description>&lt;p&gt;Hello -&lt;/p&gt;
&lt;p&gt;Can anyone tell me how current is the dashboard data, is it real-time or span of over a few days, etc.? &amp;nbsp;Second question is (depending on the answer to the first question), where is the &amp;nbsp;setting to set the timeframe data on the dashboard?&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3547847" width="1" height="1"&gt;</description></item><item><title>re: How to move the FEP Databases and the CM Site Database</title><link>http://blogs.technet.com/b/clientsecurity/archive/2011/07/14/how-to-move-the-fep-databases-and-the-cm-site-database.aspx#3546588</link><pubDate>Fri, 18 Jan 2013 02:15:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3546588</guid><dc:creator>Kriss Milne</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;I recently ran into this issue when migrating the FEP database and it wasn&amp;#39;t acceptable to loose the historical data.&lt;/p&gt;
&lt;p&gt;I isolated and identified the root cause of the problem and have managed to successfully migrate the FEP database and all of my FEP reports are successfully working.&lt;/p&gt;
&lt;p&gt;I wanted to share here the solution for others that run into this issue:&lt;/p&gt;
&lt;p&gt;The problem is that some of the views in the FEPDW database reference the local SQL server by a linkedserver instead of the actual servername, this is by design to provide the felxibility of changing servers etc...&lt;/p&gt;
&lt;p&gt;The problem is that when running the ServerSetup.exe and using an existing database (the migrated one) it doesn&amp;#39;t create the linkedserver references and as such the views in the FEPDW database do not work.&lt;/p&gt;
&lt;p&gt;You can use the following SQL query to view the linkedserver entries:&lt;/p&gt;
&lt;p&gt;select *&lt;/p&gt;
&lt;p&gt;from sys.servers&lt;/p&gt;
&lt;p&gt;The two entries that are required by the FEP database are:&lt;/p&gt;
&lt;p&gt;SelfLinkedServer&lt;/p&gt;
&lt;p&gt;FEPDW_ORG_FEPDW_ORG_OLAPProvider_FEP&lt;/p&gt;
&lt;p&gt;on the new SQL Server that you are migrating to you must create these linkedserver entries, the following queries can be used to do this:&lt;/p&gt;
&lt;p&gt;for SelfLinkedServer:&lt;/p&gt;
&lt;p&gt;Exec sp_addlinkedserver&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @server = &amp;#39;SelfLinkedServer&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @srvproduct = &amp;#39;&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @provider = &amp;#39;SQLNCLI&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @datasrc = &amp;#39;SQLSERVERNAME\INSTANCE&amp;#39;&lt;/p&gt;
&lt;p&gt;NOTE: - SQLSERVERNAME\INSTANCE is the servername and instancename of your sql server&lt;/p&gt;
&lt;p&gt;for FEPDW_ORG_FEPDW_ORG_OLAPProvider_FEP:&lt;/p&gt;
&lt;p&gt;Exec sp_addlinkedserver&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @server = &amp;#39;FEPDW_ORG_FEPDW_ORG_OLAPProvider_FEP&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @srvproduct = &amp;#39;&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @provider = &amp;#39;MSOLAP&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @datasrc = &amp;#39;SQLSERVERNAME\INSTANCE&amp;#39;,&lt;/p&gt;
&lt;p&gt; &amp;nbsp; &amp;nbsp; @catalog = &amp;#39;FEPDW_SITECODE&amp;#39;&lt;/p&gt;
&lt;p&gt;NOTE: - FEPDW_SITECODE is the name of your FEPDW database&lt;/p&gt;
&lt;p&gt;After performing these actions you should be able to successfully migrate the FEP database using the FEP ServerSetup.exe&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3546588" width="1" height="1"&gt;</description></item><item><title>re: More information on Microsoft antimalware protection on Windows 8 and Windows Server 2012</title><link>http://blogs.technet.com/b/clientsecurity/archive/2012/11/05/more-information-on-microsoft-antimalware-protection-on-windows-8-and-windows-server-2012.aspx#3542763</link><pubDate>Thu, 27 Dec 2012 13:45:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3542763</guid><dc:creator>kinokijuf</dc:creator><description>&lt;p&gt;What free antivirus do you provide for Server 2012 when used as workstation? On previous version you could use MSE.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3542763" width="1" height="1"&gt;</description></item><item><title>re: Wildcards in path exclusions: FCS</title><link>http://blogs.technet.com/b/clientsecurity/archive/2010/03/08/wildcards-in-path-exclusions.aspx#3536150</link><pubDate>Mon, 03 Dec 2012 19:23:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3536150</guid><dc:creator>rwalke2</dc:creator><description>&lt;p&gt;Does this blog post apply to SCEP 2012 and FEP 2010, or just FEP 2010?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3536150" width="1" height="1"&gt;</description></item><item><title>re: More information on Microsoft antimalware protection on Windows 8 and Windows Server 2012</title><link>http://blogs.technet.com/b/clientsecurity/archive/2012/11/05/more-information-on-microsoft-antimalware-protection-on-windows-8-and-windows-server-2012.aspx#3531370</link><pubDate>Thu, 08 Nov 2012 17:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3531370</guid><dc:creator>J.C. Hornbeck [MSFT]</dc:creator><description>&lt;p&gt;Hi Kevin, that means it should be set to &amp;quot;Enabled.&amp;quot; Just as an FYI there are some steps on how to do this here: &lt;a rel="nofollow" target="_new" href="http://www.ehow.com/how_6834770_disable-windows-defender-group-policy.html#ixzz2BeXJLt2v"&gt;www.ehow.com/how_6834770_disable-windows-defender-group-policy.html&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3531370" width="1" height="1"&gt;</description></item><item><title>re: More information on Microsoft antimalware protection on Windows 8 and Windows Server 2012</title><link>http://blogs.technet.com/b/clientsecurity/archive/2012/11/05/more-information-on-microsoft-antimalware-protection-on-windows-8-and-windows-server-2012.aspx#3531361</link><pubDate>Thu, 08 Nov 2012 17:01:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3531361</guid><dc:creator>KevinMJohnston</dc:creator><description>&lt;p&gt;I&amp;#39;d like clarification on this statement:&lt;/p&gt;
&lt;p&gt;&amp;quot;Please remove any Group Policies containing “Turn off Windows Defender”=Disabled&amp;quot;&lt;/p&gt;
&lt;p&gt;Does this mean that the &amp;quot;turn off Windows Defender&amp;quot; policy should be set to Enabled or Not Configured?&lt;/p&gt;
&lt;p&gt;On my first read of the note, I took it to mean that any policies which disable Windows Defender should be removed. This would makes sense because Defender on Windows 8 is the same service/process (MsMpEng.exe) as FEP/SCEP.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3531361" width="1" height="1"&gt;</description></item><item><title>re: TechNet Wiki went live on Wednesday</title><link>http://blogs.technet.com/b/clientsecurity/archive/2010/04/16/technet-wiki-went-live-on-wednesday.aspx#3497496</link><pubDate>Fri, 11 May 2012 15:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3497496</guid><dc:creator>Kimborly A. Ditto-Ehlert</dc:creator><description>&lt;p&gt;Hi there Lorin!&lt;/p&gt;
&lt;p&gt;Can you head over to &lt;a rel="nofollow" target="_new" href="https://lab.msdn.microsoft.com/mailform/contactus.aspx?refurl=http://technet.microsoft.com/wiki/"&gt;lab.msdn.microsoft.com/.../contactus.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;And submit more details on this issue? That way we can get a repro - we cannot seem to repro the issue you describe.&lt;/p&gt;
&lt;p&gt;Thanks!!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3497496" width="1" height="1"&gt;</description></item></channel></rss>