Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×
  • entries
    27
  • comments
    29
  • views
    491

Windows 10, SCCM and SCEP


If, like me, you have a pathological avoidance of reading instructions (Except when playing board games, where, strangely, the instructions must be read, in full, and explained to everyone, in detail, before we can begin. Thinking about it I haven't been invited to Games Evening is a while...) and prefer to 'have a go' you can find SCCM a bewildering place to be. Thus is was when I tried to deploy SCEP to Windows 10 and found it didn't work as expected.

 

So, in an effort to save other people the hassle of searching for this info here are a couple of things I learnt and my notes on how I deployed SCEP in the first place. Of course this is for my environment but can be easily adapted for yours. This is best way I could come up to structure everything in SCCM. Feel free correct any idiocies contained within.

 

Stuff I learnt:

  1. Pre-Win10 machines use the full FEP client installed as a separate application, with post-Win 10 machines a layer is added to Windows Defender to control settings, def updates and AV policy
  2. Hence from 1. its not a good idea to have Defender disabled by GPO
  3. People having a Games Evening don't like to be lectured on the finer points of why can't play *that* particular card that that point in the game and don't respond to huffs, tuts and arm crossing

 

How I deployed SCEP

The elements of my AV setup in SCCM are:

 

 

1) Client Groups

2) Definition updates

3) AV policy

4) Client settings

 

 

Client groups (\Assets and Compliance\Device Collections\Endpoint protection groups)

My clients are organised into following groups based on product installed and location:

 

- FEP - onsite devices

- FEP - laptops

- Defender - onsite devices

- Defender - laptops

- Servers

 

 

Groups were then created to apply def updates and AV policies:

 

 

- Def updates

- All FEP clients

- All Defender clients

- AV Policy

- Groups for each type of machine that need a different policy (e.g. laptops are allowed to update defs from the Internet, different server types have different exclusions)

- Client settings

- A group containing all the AV clients to apply the global settings to

 

 

Def updates (\Software Library\Overview\Software Updates)

 

 

- Two Auto Deployment rules:

- ADR: FEP definition updates

- ADR: Windows Defender definition updates

- ADRs run every night after WSUS sync and add updates to appropriate Software Update Group and Deployment Package

- Software Deployment Groups are targeted at appropriate def update client group above

 

 

AV Policy (\Assets and Compliance\Overview\Endpoint Protection\Antimalware Policies)

 

 

- AV policies have been created for different types of machine

- Policies are targeted at appropriate AV Policy client group above

 

 

Client Settings (\Administration\Overview\Client Settings)

 

 

- Endpoint Protection management settings contain the settings the apply to the AV Client - this package is deployed to the Client Settings client group above (and hence to all machines with FEP to WD AV protection)

0 Comments


Recommended Comments

There are no comments to display.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...