Microsoft System Center Endpoint Protection Cookbook - Second Edition
()
About this ebook
Related to Microsoft System Center Endpoint Protection Cookbook - Second Edition
Related ebooks
MCA Modern Desktop Administrator Study Guide: Exam MD-101 Rating: 0 out of 5 stars0 ratingsInstant Citrix XenApp Rating: 5 out of 5 stars5/5MCSA Windows Server 2016 Study Guide: Exam 70-741 Rating: 0 out of 5 stars0 ratingsMCSA Windows Server 2016 Practice Tests: Exam 70-740, Exam 70-741, Exam 70-742, and Exam 70-743 Rating: 0 out of 5 stars0 ratingsConfigMgr - An Administrator's Guide to Deploying Applications using PowerShell Rating: 5 out of 5 stars5/5Instant Migration from Windows Server 2008 and 2008 R2 to 2012 How-to Rating: 0 out of 5 stars0 ratingsMCSA Windows 10 Study Guide: Exam 70-698 Rating: 0 out of 5 stars0 ratingsVMware For New Admins - Upgrade: VMware Admin Series, #3 Rating: 0 out of 5 stars0 ratingsMastering Citrix® XenDesktop® Rating: 0 out of 5 stars0 ratingsMCSA: Windows 10 Complete Study Guide: Exam 70-698 and Exam 70-697 Rating: 0 out of 5 stars0 ratingsMastering VMware vSphere 6.7 Rating: 0 out of 5 stars0 ratingsGetting Started with Windows Server Security Rating: 0 out of 5 stars0 ratingsMCA Modern Desktop Administrator Study Guide: Exam MD-100 Rating: 0 out of 5 stars0 ratingsWindows Server 2012 Automation with PowerShell Cookbook Rating: 0 out of 5 stars0 ratingsMCA Modern Desktop Administrator Practice Tests: Exam MD-100 and MD-101 Rating: 0 out of 5 stars0 ratingsMicrosoft Windows Server Administration Essentials Rating: 0 out of 5 stars0 ratingsWindows Server 2012 R2 Administrator Cookbook Rating: 5 out of 5 stars5/5MCA Windows Server Hybrid Administrator Complete Study Guide with 400 Practice Test Questions: Exam AZ-800 and Exam AZ-801 Rating: 0 out of 5 stars0 ratingsMDM: Fundamentals, Security, and the Modern Desktop: Using Intune, Autopilot, and Azure to Manage, Deploy, and Secure Windows 10 Rating: 0 out of 5 stars0 ratingsGroup Policy: Fundamentals, Security, and the Managed Desktop Rating: 5 out of 5 stars5/5Microsoft Intune Cookbook: Over 75 recipes for configuring, managing, and automating your identities, apps, and endpoint devices Rating: 0 out of 5 stars0 ratingsHyper-V 2016 Best Practices Rating: 0 out of 5 stars0 ratingsMicrosoft DirectAccess Best Practices and Troubleshooting Rating: 5 out of 5 stars5/5Mastering System Center 2012 R2 Configuration Manager Rating: 0 out of 5 stars0 ratingsMicrosoft System Center PowerShell Essentials Rating: 0 out of 5 stars0 ratingsMastering Hyper-V 2012 R2 with System Center and Windows Azure Rating: 0 out of 5 stars0 ratingsIT Career JumpStart: An Introduction to PC Hardware, Software, and Networking Rating: 0 out of 5 stars0 ratingsMicrosoft PowerShell, VBScript and JScript Bible Rating: 0 out of 5 stars0 ratingsMicrosoft Windows Security Essentials Rating: 5 out of 5 stars5/5Mastering Microsoft Azure Infrastructure Services Rating: 0 out of 5 stars0 ratings
System Administration For You
CompTIA A+ Complete Review Guide: Core 1 Exam 220-1101 and Core 2 Exam 220-1102 Rating: 5 out of 5 stars5/5PowerShell: A Beginner's Guide to Windows PowerShell Rating: 4 out of 5 stars4/5Cybersecurity: The Beginner's Guide: A comprehensive guide to getting started in cybersecurity Rating: 5 out of 5 stars5/5Linux: Learn in 24 Hours Rating: 5 out of 5 stars5/5Learn PowerShell in a Month of Lunches, Fourth Edition: Covers Windows, Linux, and macOS Rating: 5 out of 5 stars5/5Instant Ubuntu Rating: 4 out of 5 stars4/5Linux Commands By Example Rating: 5 out of 5 stars5/5Mastering Linux Network Administration Rating: 4 out of 5 stars4/5Ethical Hacking Rating: 4 out of 5 stars4/5Linux Bible Rating: 0 out of 5 stars0 ratingsPractical Data Analysis Rating: 4 out of 5 stars4/5Git Essentials Rating: 4 out of 5 stars4/5The Kubernetes Book 2025 Edition Rating: 0 out of 5 stars0 ratingsBash Command Line Pro Tips Rating: 5 out of 5 stars5/5Wordpress 2023 A Beginners Guide : Design Your Own Website With WordPress 2023 Rating: 0 out of 5 stars0 ratingsMastering Windows 365: Deploy and Manage Cloud PCs and Windows 365 Link devices, Copilot with Intune, and Intune Suite Rating: 0 out of 5 stars0 ratingsCompTIA A+ Complete Practice Tests: Core 1 Exam 220-1101 and Core 2 Exam 220-1102 Rating: 0 out of 5 stars0 ratingsThe Ultimate Guide To Microsoft Excel Vba For Beginners And Seniors Rating: 0 out of 5 stars0 ratingsData Communication and Networking: For Under-graduate Students Rating: 0 out of 5 stars0 ratingsTLS Mastery: Beastie Edition: IT Mastery, #16 Rating: 0 out of 5 stars0 ratingsLinux for Beginners: Linux Command Line, Linux Programming and Linux Operating System Rating: 4 out of 5 stars4/5Design and Build Modern Datacentres, A to Z practical guide Rating: 3 out of 5 stars3/5Mastering Linux Administration: A Comprehensive Guide: The IT Collection Rating: 5 out of 5 stars5/5
Reviews for Microsoft System Center Endpoint Protection Cookbook - Second Edition
0 ratings0 reviews
Book preview
Microsoft System Center Endpoint Protection Cookbook - Second Edition - Nicolai Henriksen
Table of Contents
Microsoft System Center Endpoint Protection Cookbook Second Edition
Credits
About the Author
Acknowledgment
About the Reviewer
www.PacktPub.com
eBooks, discount offers, and more
Why subscribe?
Instant updates on new Packt books
Preface
What this book covers
What you need for this book
Who this book is for
Sections
Getting ready
How to do it…
How it works…
There's more…
See also
Conventions
Reader feedback
Customer support
Downloading the color images of this book
Errata
Piracy
Questions
1. Planning and Getting Started with System Center Endpoint Protection
Introduction
How does Endpoint Protection in Configuration Manager work
How to do it…
What made Endpoint Protection that good
Planning for the Endpoint Protection
How to do it…
Prerequisites of the infrastructure
Getting ready
How to do it…
How it works…
Best practices for Endpoint Protection in Configuration Manager
How to do it...
Administrating workflow for Endpoint Protection in Configuration Manager
Getting ready
How to do it…
2. Configuring Endpoint Protection in Configuration Manager
Introduction
Configuring Endpoint Protection in Configuration Manager
Getting ready
How to do it…
How it works…
Configuring alerts for Endpoint Protection in Configuration Manager
Getting ready
How to do it…
How it works…
Configuring definition updates for Endpoint Protection in Configuration Manager
Getting ready
How to do it...
How it works…
See also
Provisioning the Endpoint Protection client in a disk image in Configuration Manager
Getting ready
How to do it…
3. Operations and Maintenance for Endpoint Protection in Configuration Manager
Introduction
Creating and deploying antimalware policies for Endpoint Protection in Configuration Manager
How to do it…
Order and combination of policies to be merged
Exclusions
Creating and deploying Windows Firewall policies for Endpoint Protection in Configuration Manager
How to do it…
Monitoring Endpoint Protection in Configuration Manager
How to do it…
4. Updates
Introduction
Understanding Endpoint Protection updates
How to do it…
Working with updates from WSUS
Getting ready
How to do it…
Working with updates from SCCM
How to do it…
What you need to consider and optimize when working with low bandwidth locations
How to do it…
Why and how to use offline updates
How to do it…
5. Security and Privacy for Endpoint Protection in Configuration Manager
Introduction
Security and privacy for Endpoint Protection in Configuration Manager
How to do it…
The Microsoft Security Center
How to do it…
Keeping third-party applications up-to-date
How to do it…
Configuring automatic sample submission
How to do it…
6. Configuring and Troubleshooting Performance and Advanced Protection
Introduction
What you need to consider when running antimalware on your computer
How to do it…
Configuring Endpoint Protection or Defender for Windows 10
How to do it…
Integrating Endpoint Protection with OS Deployment
How to do it…
What you need to consider regarding BitLocker and Endpoint Protection
How to do it…
7. Troubleshooting and Fixing Issues
Introduction
Dealing with Endpoint Protection issues
Getting ready
How to do it…
Solving Endpoint Protection Policy issues
Getting ready
How to do it…
Registry.pol files
Understanding update issues
How to do it…
8. Malware Handling
Introduction
How to handle malware
How to do it…
See also
Responding to infections that often occur
Getting ready
How to do it...
See also
Monitoring infectious outbreaks
How to do it…
Protecting the Windows File Server from known Cryptolocker malware
Index
Microsoft System Center Endpoint Protection Cookbook Second Edition
Microsoft System Center Endpoint Protection Cookbook Second Edition
Copyright © 2016 Packt Publishing
All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews.
Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the Nicolai Henriksen nor Packt Publishing, and its dealers and distributors will be held liable for any damages caused or alleged to be caused directly or indirectly by this book.
Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information.
First published: October 2012
Second edition: December 2016
Production reference: 1151216
Published by Packt Publishing Ltd.
Livery Place
35 Livery Street
Birmingham B3 2PB, UK.
ISBN 978-1-78646-428-6
www.packtpub.com
Credits
Author
Nicolai Henriksen
Reviewer
Ronni Pedersen
Commissioning Editor
Kartikey Pandey
Acquisition Editor
Prachi Bisht
Content Development Editor
Abhishek Jadhav
Technical Editor
Aditya Khadye
Copy Editors
Safis Editing
Dipti Mankame
Project Coordinator
Judie Jose
Proofreader
Safis Editing
Indexer
Pratik Shirodkar
Graphics
Kirk D'Penha
Production Coordinator
Shantanu N. Zagade
Cover Work
Shantanu N. Zagade
About the Author
Nicolai Henriksen works as a chief technical architect consultant presently and lives in Bergen, Norway, with his wife and three children.
He has worked in the information technology consulting business for almost two decades, working and implementing systems in all kinds of various businesses from small to enterprises, mostly with products within the Microsoft family. But he has gained great experience and knowledge about many vendors and products.
Nicolai's educational background started with electronic engineering, and he worked for a while as a technician. That has also been his great interest, besides computers.
He started exploring computers in 1980 as a teenager and somehow then understood the meaning and future perspective that computer science had for the world.
For the past 12 years, he has been dedicatedly working with System Center Configuration Manager in customer projects. Since 2012, Endpoint Protection got integrated into this great product and Nicolai says that by then the amount of companies using this product has increased enormously.
Since 1990, when malware and computer viruses started to evolve, he started helping business to protect their computers with all kinds of antimalware products.
This is the first book Nicolai has written, yet he has done several reviews on System Center books in the past couple of years, and has thought of writing a book for quite some time. It's not unlikely that we will see more books from Nicolai in the future.
Nicolai also speaks in public conferences while he loves to teach and share his knowledge with others. The fact that people are willing to listen and you have burning desire to share without demanding anything back gives a great feeling according to him. He spends some time blogging, Twittering, and answering questions on Technet forums.
In 2012, Nicolai was awarded the Microsoft Most Valuable Professional (MVP), which only a few people in the world have achieved. He then specialized in the popular and great management product called System Center Configuration Manager.
Nicolai has been balancing a life as a family man with intense creativity and passion within computer science for many years.
Acknowledgment
I would like to thank my wife, Kristina, for putting up with my many late night working, and our children, Tuva, Malin, and Olav for being patient and kind to their dad. The love and care from these important persons in my life have been essential for my work and career. And I want to thank Packt Publishing for giving me the opportunity to write this book. I would also like to thank the Microsoft MVP Program and MVP members for all the support and inspiration, and MVP Ronni Pedersen for doing a good job reviewing this book. Finally, I want to thank my mom and dad, Ella and Eigil, for always being there for me.
About the Reviewer
Ronni Pedersen works as a Cloud solution architect, Microsoft Enterprise Mobility MVP, Certified Trainer, event speaker, and author. Today, he works for EG A/S, where he also contributes to the community by writing articles and sharing tips and tricks on http://www.ronnipedersen.com/. In recent years, he has been invited as a speaker at various international conferences and User Groups meetings, such as TechEd, Microsoft Management Summit, Midwest Management Summit, Microsoft Ignite, TechTalks, and the global Microsoft Cloud Roadshow. In 2008, he was one of the cofounders of the Danish System Center User Group.
www.PacktPub.com
eBooks, discount offers, and more
Did you know that Packt offers eBook versions of every book published, with PDF and ePub files available? You can upgrade to the eBook version at www.PacktPub.com and as a print book customer, you are entitled to a discount on the eBook copy. Get in touch with us at
At www.PacktPub.com, you can also read a collection of free technical articles, sign up for a range of free newsletters and receive exclusive discounts and offers on Packt books and eBooks.
eBooks, discount offers, and morehttps://www.packtpub.com/mapt
Get the most in-demand software skills with Mapt. Mapt gives you full access to all Packt books and video courses, as well as industry-leading tools to help you plan your personal development and advance your career.
Why subscribe?
Fully searchable across every book published by Packt
Copy and paste, print, and bookmark content
On demand and accessible via a web browser
Instant updates on new Packt books
Get notified! Find out when new books are published by following @PacktEnterprise on Twitter or the Packt Enterprise Facebook page.
Preface
System Center Endpoint Protection, or Windows Defender, is a great security product when using System Center Configuration Manager or Microsoft Intune.
Its ability to protect computers in business increases every day, and it continually improves its features to meet today's security risks and attacks.
Because over 75% of all business around the world are now using the popular and great management tool System Center Configuration Manager, Endpoint Protection has also become widespread over that past few years.
In this book, we will explore the main motivation of using the well-known and established System Center Endpoint Protection and Windows Defender. You will gain knowledge about how to set up and configure the products for your organization based on real-life experience and best practices from a field expert and Microsoft Most Valuable Professional. Throughout the book, you will see several best practice tips and recipes for you to use in your daily life as a security administrator.
This book is suitable for everyone who works with computers, but especially useful for IT administrators who work with System Center Configuration Manager, Endpoint Protection, and Intune.
The book will be useful for most kinds of businesses, from small to large, with making decisions, whether they are already using the product or just considering it. And there will be some recipes of value to you even if you are not using Endpoint Protection or Windows Defender.
Either way, reading this book will give you value that you can take with you in the future. Windows Defender comes built in with Windows 10 as well as Windows Server 2016 and you need to decide whether you choose to use it or disable it.
You will also gain deeper knowledge as a System Center Configuration Manager admin of how to handle and administrate the Endpoint Protection role to suite your antimalware admin needs, and also perhaps give you some good tips regarding Configuration Manager.
What this book covers
Chapter 1, Planning and Getting Started with System Center Endpoint Protection, walks you through an easy approach to what you need to consider when planning and designing an System Center Configuration Manner hierarchy with the Endpoint Protection in mind. You will gain knowledge of real-life best practices when setting up SCCM.
Chapter 2, Configuring