<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Forefront Client Security Team Blog : Client Security Agent</title><link>http://blogs.technet.com/clientsecurity/archive/tags/Client+Security+Agent/default.aspx</link><description>Tags: Client Security Agent</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Client Security slow logon issue</title><link>http://blogs.technet.com/clientsecurity/archive/2009/08/13/client-security-slow-logon-issue.aspx</link><pubDate>Thu, 13 Aug 2009 19:43:31 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273181</guid><dc:creator>craigw</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/clientsecurity/comments/3273181.aspx</comments><wfw:commentRss>http://blogs.technet.com/clientsecurity/commentrss.aspx?PostID=3273181</wfw:commentRss><description>&lt;p&gt;After installing the most recent antimalware update (&lt;a href="http://support.microsoft.com/?id=971026"&gt;KB971026&lt;/a&gt;), some Client Security customers have reported that their managed Windows XP SP2 and SP3 clients take longer to logon after a reboot. Our support and sustained engineering teams have researched this issue and wanted to provide additional information and workarounds.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;During the initialization of the antimalware service, FCS does the following:&lt;/p&gt;  &lt;p&gt;1. Loads the kernel-mode mini-filter(mpfilter.sys) and starts filtering&lt;/p&gt;  &lt;p&gt;2. Sets up communication port&lt;/p&gt;  &lt;p&gt;3. Creates Engine configuration &lt;i&gt;&lt;font color="#ff0000"&gt;&amp;lt;--&lt;/font&gt;&lt;/i&gt;&lt;i&gt;&lt;font color="#ff0000"&gt; delay occurs here&lt;/font&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;4. Creates On-Access worker threads&lt;/p&gt;  &lt;p&gt;The problem arises when there is a delay in Step#3. In this situation the mini-filter begins filtering file I/O requests but there are no On-Access worker threads available yet to service the scanning requests. We have found that these delays typically come from network-based file exclusions being set via the Advanced Policy tab in the Client Security management console.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/blogfiles/clientsecurity/WindowsLiveWriter/ClientSecurityslowlogonissue_B2F2/clip_image002_2.jpg"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="policy_Exclusions" border="0" alt="policy_Exclusions" src="http://blogs.technet.com/blogfiles/clientsecurity/WindowsLiveWriter/ClientSecurityslowlogonissue_B2F2/clip_image002_thumb.jpg" width="421" height="215" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The delays occurs when the client receives the UNC paths (e.g. \\server\share) and they are converted to a &lt;a href="http://support.microsoft.com/kb/235128"&gt;device name&lt;/a&gt; that the mini-filter uses. During this conversion the FCS client accesses the path in the exclusion. Slow or ACCESS_DENIED responses to these network requests increases the time in Step#3 above and causes delays before the mini-filter requests can be handled (Step#4).&lt;/p&gt;  &lt;p&gt;The result is that the file I/O in other processes, including those responsible for logon like Winlogon.exe, is queued until all the network requests for exclusions complete or for the duration of the mini-filter timeout. This issue became more visible in the most recent antimalware update (&lt;a href="http://support.microsoft.com/?id=971026"&gt;KB971026&lt;/a&gt;) because the mini-filter timeout was increased.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Workarounds&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;While Microsoft determines the long term solution to this problem, there is a recommended workaround: eliminate network-based file exclusions.&lt;/p&gt;  &lt;p&gt;In most causes these exclusions were created to address the issue described in &lt;a href="http://support.microsoft.com/?id=939361"&gt;KB939361&lt;/a&gt;. This issue can now be corrected by using the DisableScanningNetworkFiles policy setting described in &lt;a href="http://support.microsoft.com/?id=971026"&gt;KB971026&lt;/a&gt;. Therefore, if you implement the DisableScanningNetworkFiles, you should be able to remove any network-based file exclusions from your Client Security policy settings (screenshot above). This should eliminate the device conversion delay and allow logons to complete in a more timely manner.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;We will update this blog when more information about this issue is available.&lt;/p&gt;  &lt;p&gt;Thanks,   &lt;br /&gt;Craig Wiand    &lt;br /&gt;Forefront Escalation Engineer&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273181" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/clientsecurity/archive/tags/Client+Security+Agent/default.aspx">Client Security Agent</category></item><item><title>Changes to FCS Client WSUS Installation package</title><link>http://blogs.technet.com/clientsecurity/archive/2007/10/05/changes-to-fcs-client-wsus-installation-package.aspx</link><pubDate>Sat, 06 Oct 2007 01:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2117432</guid><dc:creator>craigw</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/clientsecurity/comments/2117432.aspx</comments><wfw:commentRss>http://blogs.technet.com/clientsecurity/commentrss.aspx?PostID=2117432</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Using WSUS is likely the easiest and most popular way to deploy the FCS client to computers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As described in the &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb404255.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb404255.aspx"&gt;&lt;FONT face=Calibri color=#800080 size=3&gt;deployment guide&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri size=3&gt;, after deploying FCS policy and approving the package &lt;/FONT&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; LINE-HEIGHT: 115%; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Client Update for Microsoft Forefront Client Security (1.0.1703.0)&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; LINE-HEIGHT: 115%; FONT-FAMILY: 'Tahoma','sans-serif'"&gt; &lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;on your WSUS 2.0 or 3.0 server, the FCS client is downloaded and installed on the machine according to your company’s Windows Update policy.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The FCS package has the ability to detect the language of the machine contacting the WSUS server and install the same FCS language;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;for example if you have a French Vista machine you will receive French FCS, or a Japanese Windows Server 2003 server you will receive Japanese FCS.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This works great for the languages that FCS was localized to, but what about the other Windows languages?&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The FCS team received great feedback from its customers using non-FCS localized Windows languages who also wanted to take advantage of the easy deployment through WSUS.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In response to that feedback, the FCS team has made changes to the FCS client WSUS installation package to support installing English FCS on those machines running a non-FCS localized Windows language (for example Swedish, Russian, or Finnish).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The exceptions to this are Arabic and Hebrew; the package will not be offered to those because of known issues with the FCS client on those bi-directional languages.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Support for WSUS FCS client deployment for these additional languages should be a great benefit for customers in many parts of the world.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Additional technical documentation on the update will be provided in future TechNet documentation or a knowledge base article, and will include:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;WSUS deployment still requires that FCS policy is already deployed&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;For non-FCS localized Windows languages, the new installation package does not automatically install the required KB914882 update on x86 Windows XP SP2.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Therefore, prior to WSUS deployment you must deploy the correct OS language version of update (found in the \client directory of the FCS CD media) to XP machines.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;No additional work is required for other operating systems.&lt;/FONT&gt;&lt;/P&gt;
&lt;H3 style="MARGIN: 10pt 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Cambria color=#4f81bd size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/H3&gt;
&lt;H3 style="MARGIN: 10pt 0in 0pt"&gt;&lt;FONT face=Cambria color=#4f81bd size=3&gt;Re-approval Required&lt;/FONT&gt;&lt;/H3&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The original client installation package was changed to include detection for these additional languages.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;During this process, a new update package was released and the old package was expired.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For this reason, you may notice on your WSUS server that the previous update package is either no longer shown or shows as expired (depending on your view).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;You may also see the current package is shown as “Not Approved”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is because the Forefront Client Security distribution server role creates an auto-approval rule for the &lt;I style="mso-bidi-font-style: normal"&gt;Definition Updates &lt;/I&gt;WSUS classification; however the client installation package has a classification of &lt;I style="mso-bidi-font-style: normal"&gt;Updates&lt;/I&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;U&gt;Therefore, when the new package is downloaded it will not be automatically approved unless your WSUS administrator has created an auto-approval rule for Updates as well.&lt;/U&gt;&lt;/I&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This should not affect FCS definition updates and can be easily returned to its previous state by manually approving the new package &lt;/FONT&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; LINE-HEIGHT: 115%; FONT-FAMILY: 'Tahoma','sans-serif'"&gt;Client Update for Microsoft Forefront Client Security (1.0.1703.0)&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-SIZE: 8pt; COLOR: black; LINE-HEIGHT: 115%; FONT-FAMILY: 'Tahoma','sans-serif'"&gt; &lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;on your WSUS 2.0 or 3.0 server (dated &lt;/FONT&gt;&lt;SPAN style="FONT-SIZE: 9pt; COLOR: black; LINE-HEIGHT: 115%; FONT-FAMILY: 'Tahoma','sans-serif'; mso-bidi-font-size: 8.0pt"&gt;Wednesday, October 03, 2007&lt;/SPAN&gt;&lt;FONT face=Calibri size=3&gt;).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Best of luck and happy deployments.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Craig Wiand&lt;BR&gt;Microsoft Forefront Client Security Support&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2117432" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/clientsecurity/archive/tags/Client+Security+Agent/default.aspx">Client Security Agent</category><category domain="http://blogs.technet.com/clientsecurity/archive/tags/WSUS/default.aspx">WSUS</category></item></channel></rss>