Jump to content

Recommended Posts

Posted

Does anyone here use the built in Endpoint Protection feature of SCCM 2012 R2 as an AV solution?

 

We currently use Sophos but a)it's a complete PITA to manage and b)we want to save money we were looking at using an alternative and SCCM came to mind as I'm really looking at implementing it properly over the summer and then it would be one more SCCM managed thing rather than something separate.

Posted
Yes we do, it's simple, inoffensive and just works. A combination of that and careful settings (helped with locked down mandatory profiles) means we've had absolutely no outbreaks in the 2 years we've been running with it. It probably picks up about a dozen infections per month and they're usually all the same drivebys (Axpergle is the usual culprit) and users' autorun.inf, all dealt with automatically.
Posted
We use it, and it does what it says on the tin. I also use software restriction policies and we have had no outbreaks so far (touching wood)!
Posted

Used it here for a couple of years and found it pretty easy to rollout and manage. As above haven't had any outbreaks and it seems to nip most things in the bud with minimal fuss.

 

Definition updates go out via WSUS with the GPO option to install updates immediately set.

Posted

We use Endpoint protection without any central server (never quite got why you need that) and it works fine.

 

Haven't had a virus in years.

Posted

Used it in a couple of schools now and had no issues with it once SCCM has been configured. I've used Sophos and McAfee in the past and it's been the easiest to administer.

 

Security experts will tell you that it's more vulnerable than some of the other big AV solutions though, which could just be the usual sales doublespeak from competitors.

Posted
Been using it for four years. Looks after itself, has never let an outbreak kick off, is light on system resources, can be set to update automatically quite easily, tells us everything that's going on via email, and saves me about £2k pa on what I was paying for Symantec before. It has also never broken itself with a silly update as so many others seem to have. No complaints at all :)
Posted

Thanks for all your responses. Sure I can get it by the powers that be when the mention of 'reduced running costs in the IT department' is mentioned! :)

 

I'll probably give it a whirl on a small cluster of test PCs and see how I get on, it goes hand in hand with sorting WSUS / software updates out too which haven't been working all year due to various issues (Mainly : a lack of time!!!)

Posted
We used Kaspersky and Symantec in the past as Local Authority offerings and have used SCCM Forefront for around the last 8 - 12 months. I can't really sure it's done any worse or better than the previous solutions but we haven't had any major issues and once setup it's just worked for us.
Posted
I can't really sure it's done any worse or better than the previous solutions but we haven't had any major issues and once setup it's just worked for us.

We had the following trojan downloader attached to an e-mail today. Endpoint Protection caught it (as would have Kaspersky and Symantec), but Avast, Avira, BitDefender and Malwarebytes wouldn't.

 

www.virustotal.com/en/file/37c4799099a075ccb5715012140e248ca0ee2cf4f2cb2762b89284fd2fae531f/analysis/

 

SCEP seems to be working quite well so far.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...