Jump to content

Windows 10 plus Deep Freeze: Good Enough?


Recommended Posts

Posted
The brunt of our student computers are Optiplex 780s with Core2/4GB RAM/mechanical HDD/Windows 7. The problem with them is they are unbearably slow when loaded with Symantec 12.1 End Point Protection; when Symantec is uninstalled they run great. The systems also have Deep Freeze from Faronics and are scheduled to boot up via WOL at night and thaw for updates. This got me thinking: Windows 10 has Defender built in; which is just rebranded Security Essentials, so do you guys think this is good enough in terms of AV? Security Essential's updates are delivered via Windows Update and Deep Freeze works great with it. In testing Windows 10 runs very well on these systems without Symantec being installed. So, good enough? I should also note that staff and students only have limited user rights on these computers. Thanks...
Posted

To answer the question: yes, it's absolutely good enough. In my opinion, you honestly don't need antivirus at all so long as three things are true:

--You are using DeepFreeze AND

--You have the machines scheduled to turn off every night AND

--You have a note on the machines encouraging students to restart the machines before using them.

 

If the machines don't have admin rights, that makes the decision even easier.

 

However, we don't do this for one very simple reason: we have to follow State of North Carolina security policies, which state that all machines must have antivirus installed. It makes no mention of DeepFreeze as a mitigating agent, unfortunately. Otherwise, we'd use nothing on DeepFreeze machines, since important administrative work shouldn't be done on public machines, anyway.

  • Thanks 1
Posted
To answer the question: yes, it's absolutely good enough. In my opinion, you honestly don't need antivirus at all so long as three things are true:

--You are using DeepFreeze AND

--You have the machines scheduled to turn off every night AND

--You have a note on the machines encouraging students to restart the machines before using them.

 

If the machines don't have admin rights, that makes the decision even easier.

 

However, we don't do this for one very simple reason: we have to follow State of North Carolina security policies, which state that all machines must have antivirus installed. It makes no mention of DeepFreeze as a mitigating agent, unfortunately. Otherwise, we'd use nothing on DeepFreeze machines, since important administrative work shouldn't be done on public machines, anyway.

 

I wonder if Windows Defender would meet your State's requirement of AV. If so, this might be a route you could take too.

 

The machines are scheduled by Deep Freeze to shutdown every night and will wake back up in the early morning. I can't count on users at all (staff or students) to follow any kind of procedure with equipment. Most I can hope to do is limit their options and force them down the direction I want.

 

We already go this route on our wireless carts seeing as how we can't remotely wake the machines up for updates, the AV client brings them to their knees, and the definition updates are huge to the point it would cripple the wireless network. What worried me about the desktops is that 2 hour window in the middle of the night where they are thawed for updates. I've had to chase worms through a district before - not fun. I guess what I need to figure out is if Defender is enough to combat stuff like that; I'm not so much worried about malware since the users are limited and the machines are frozen when in use.

 

Thanks for your input.

Posted

Excuse my ignorance, i'm just looking for an explanation as to how Deep Freeze mitigates the effects of a worm on systems/data that are not protected by deep freeze.

 

E.g. CryptoLocker getting onto your shared drives and encrypting all data on the server. Surely not having AV on clients allows any malware/virus/trojan to roam free for the window between reboots, doesn't that mean things that carry keyloggers, ransomware etc... can all have adverse affects on your data integrity/security?

Posted
Excuse my ignorance, i'm just looking for an explanation as to how Deep Freeze mitigates the effects of a worm on systems/data that are not protected by deep freeze.

 

None at all sadfully. It's really only designed to get a pc back to a usable state ("generally" for things that aren't network based e.g. library computer that's on the internet that resets itself daily), if your server gets infected your "clean" clients are useless :p

 

Steve

Posted
None at all sadfully. It's really only designed to get a pc back to a usable state ("generally" for things that aren't network based e.g. library computer that's on the internet that resets itself daily), if your server gets infected your "clean" clients are useless :p

 

Steve

 

I was wondering this... in which case, using Deep Freeze isn't in any way an effective replacement for AV/Malware protection, which others in this thread appear to be potentially planning to do?

Posted
I was wondering this... in which case, using Deep Freeze isn't in any way an effective replacement for AV/Malware protection, which others in this thread appear to be potentially planning to do?

 

The OP was talking about using security essentials which is effectively the AV, but yes you're right about the other suggestions (my opinion anyway)

 

Steve

Posted
The OP was talking about using security essentials which is effectively the AV, but yes you're right about the other suggestions (my opinion anyway)

 

Steve

 

Ah yes, fair enough... not sure how security essentials fairs against some of the big names in AV, but something is better than nothing...

Posted
Ah yes, fair enough... not sure how security essentials fairs against some of the big names in AV, but something is better than nothing...

 

To be honest I'm liking it, a lot of schools using it since it's free with SCCM etc (Endpoint being the same as that in Win8/10 just different name).

 

Often get things flagged up, specifically with USB drives/dodgy websites so nice to know it's doing its stuff :) But as ever a lot depends on your lockdowns in relation to Crypto etc

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...