Windows 10, SCCM and SCEP
If, like me, you have a pathological avoidance of reading instructions (Except when playing board games, where, strangely, the instructions must be read, in full, and explained to everyone, in detail, before we can begin. Thinking about it I haven't been invited to Games Evening is a while...) and prefer to 'have a go' you can find SCCM a bewildering place to be. Thus is was when I tried to deploy SCEP to Windows 10 and found it didn't work as expected.
So, in an effort to save other people the hassle of searching for this info here are a couple of things I learnt and my notes on how I deployed SCEP in the first place. Of course this is for my environment but can be easily adapted for yours. This is best way I could come up to structure everything in SCCM. Feel free correct any idiocies contained within.
Stuff I learnt:
- Pre-Win10 machines use the full FEP client installed as a separate application, with post-Win 10 machines a layer is added to Windows Defender to control settings, def updates and AV policy
- Hence from 1. its not a good idea to have Defender disabled by GPO
- People having a Games Evening don't like to be lectured on the finer points of why can't play *that* particular card that that point in the game and don't respond to huffs, tuts and arm crossing
How I deployed SCEP
The elements of my AV setup in SCCM are:
1) Client Groups
2) Definition updates
3) AV policy
4) Client settings
Client groups (\Assets and Compliance\Device Collections\Endpoint protection groups)
My clients are organised into following groups based on product installed and location:
- FEP - onsite devices
- FEP - laptops
- Defender - onsite devices
- Defender - laptops
- Servers
Groups were then created to apply def updates and AV policies:
- Def updates
- All FEP clients
- All Defender clients
- AV Policy
- Groups for each type of machine that need a different policy (e.g. laptops are allowed to update defs from the Internet, different server types have different exclusions)
- Client settings
- A group containing all the AV clients to apply the global settings to
Def updates (\Software Library\Overview\Software Updates)
- Two Auto Deployment rules:
- ADR: FEP definition updates
- ADR: Windows Defender definition updates
- ADRs run every night after WSUS sync and add updates to appropriate Software Update Group and Deployment Package
- Software Deployment Groups are targeted at appropriate def update client group above
AV Policy (\Assets and Compliance\Overview\Endpoint Protection\Antimalware Policies)
- AV policies have been created for different types of machine
- Policies are targeted at appropriate AV Policy client group above
Client Settings (\Administration\Overview\Client Settings)
- Endpoint Protection management settings contain the settings the apply to the AV Client - this package is deployed to the Client Settings client group above (and hence to all machines with FEP to WD AV protection)

0 Comments
Recommended Comments
There are no comments to display.
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now