KoolTech Posted January 10, 2017 Posted January 10, 2017 Hi, Just beginning to move staff over to Windows 10 and I am wondering if anyone has scrapped their current anti virus in favour of Windows Defender? Is it good enough? Would be a great plus point for moving people to Windows 10 if we could get rid of another annual payment! Cheers,
Chuckster Posted January 10, 2017 Posted January 10, 2017 Have a read of this: https://www.av-test.org/en/antivirus/business-windows-client/windows-10/ It would seem Defender isn't that great at protecting your clients. As a result it's made me to continue with Symantec Endpoint Protection for all my clients, including Mac OS. I found defender not to offer a lot of features to prevent malware and mitigate ransomware. 1
Arthur Posted April 2, 2017 Posted April 2, 2017 It would seem Defender isn't that great at protecting your clients. Defender/SCEP has improved a lot in recent months. e.g. Protection against 0-day malware attacks = 100% for the last three months running (December to February 2017) Detection of widespread and prevalent malware discovered in the last 4 weeks = 99.6% (which is better than the industry average of 99%) I found defender not to offer a lot of features to prevent malware and mitigate ransomware. Which features are you thinking of? Some of them are in the operating system now, rather than the AV. www.zdnet.com/article/windows-10-security-so-good-it-can-block-zero-days-without-being-patched 1
JATSO Posted April 3, 2017 Posted April 3, 2017 Have a read of this: https://www.av-test.org/en/antivirus/business-windows-client/windows-10/ It would seem Defender isn't that great at protecting your clients. As a result it's made me to continue with Symantec Endpoint Protection for all my clients, including Mac OS. I found defender not to offer a lot of features to prevent malware and mitigate ransomware. ESET isn't even on the list, costs about £2K for 3 years so as primary schools we will be looking at Defender.
crc-ict Posted April 4, 2017 Posted April 4, 2017 We have Forefront Endpoint Protection which uses basically the same engine as Defender/Windows Security Essentials. Thought it was OK until last week when one of our PCs picked up the Spora ransomware from a compromised website and FEP did absolutely nothing about it. First we knew of it was one of the network drives being half encrypted! So for me FEP/Defender is useless and is going asap.
sted Posted April 4, 2017 Posted April 4, 2017 on its own in a school defender is useless as it has no reporting facilities as part of microsofts i cant remember the name enterprise "defender" its not terrible but im not sure id trust it as much as a dedicated offering
Arthur Posted April 4, 2017 Posted April 4, 2017 (edited) I can't remember the name enterprise "defender" System Center Endpoint Protection and/or Windows Defender Advanced Threat Protection? Thought it was OK until last week when one of our PCs picked up the Spora ransomware from a compromised website and FEP did absolutely nothing about it. First we knew of it was one of the network drives being half encrypted! Was that because its browser or Flash Player plug-in wasn't up-to-date? Edited April 4, 2017 by Arthur
Michael Posted April 4, 2017 Posted April 4, 2017 Hi, Just beginning to move staff over to Windows 10 and I am wondering if anyone has scrapped their current anti virus in favour of Windows Defender? Is it good enough? Would be a great plus point for moving people to Windows 10 if we could get rid of another annual payment! Cheers, Yes
gaz350b Posted April 4, 2017 Posted April 4, 2017 (edited) Windows 10 they made SCEP/Defender the same thing. so if you are using SCEP for windows 10 it is still called defender. then to just really confuse things they have the additional Advance Threat Protection under the Defender branding. which is not just about reporting anti virus and malware but monitoring user behavior to protect against remote attackers so compromised accounts can be detected faster. Edited April 4, 2017 by gaz350b
sparkeh Posted April 4, 2017 Posted April 4, 2017 Yes we ditched our AV for SCEP. As shown above, it's very good at the moment.
mullet_man Posted April 4, 2017 Posted April 4, 2017 No major issues here, been using t for about 2 and half years.
AlanD Posted April 17, 2017 Posted April 17, 2017 We have Forefront Endpoint Protection which uses basically the same engine as Defender/Windows Security Essentials. Thought it was OK until last week when one of our PCs picked up the Spora ransomware from a compromised website and FEP did absolutely nothing about it. First we knew of it was one of the network drives being half encrypted! So for me FEP/Defender is useless and is going asap. I'm not going to defend "defender"...nor for that matter any other antivirus/malware product.....but... Keep in mind that no protection software is going to give you 100% protection. I few years ago I remember Norton or some such product being tested and was found to be effective against 60% (yes...only 60%) of current malware at the time. ...and that was one of the better products tested. And while some products claim to offer some protection against zero day attack there is no guarantee its going to protect you against the attack you might experience. Simply paying money for a separate commercial product may give you a sense of peace of mind - but to be honest it would be largely an illusion - although its one I have been happy to invest in - if only to be able to say to SLT - that yes we pay for a product to protect us. But if you are really thinking "FEP/Defender is useless and is going asap" don't imagine for a monent that other products are going to be better. Hopefully - you have analysed carefully how the attack managed to compromise your network....I'm thinking it must have been a user with elevated or administrator priviledges - or perhaps you have no restrictions on what executables your users can run. "Drive by" infections are an increasing menace...and malicious email attachment attacks increasingly sophisticated as attackers now seem to to harvest first/last name and company names etc which make such emails seem genuine.
mullet_man Posted May 2, 2017 Posted May 2, 2017 (edited) Due to us receiving some emails with dodgy Word attachments, I've added this GP that stops Marcos from running on docs downloaded from the internet. http://www.edugeek.net/forums/security/176254-office-2013-can-now-block-macros-documents-originating-internet.html#post1510169 But I was wondering what interval does everyone have for Defender to checking for updates? I have mine set at 8 hours but going to change it to 4 as am worried that might mean it goes a day without updating. Thanks. Edited May 2, 2017 by mullet_man
Passat1983ICTech Posted May 3, 2017 Posted May 3, 2017 hi there what ever you do get some AV software as defender dose not pick up on malware and if you do you don't have to ware about anything if it dose come though
sparkeh Posted May 3, 2017 Posted May 3, 2017 defender dose not pick up on malware What do you mean? Because, well, it does.
Passat1983ICTech Posted May 3, 2017 Posted May 3, 2017 ive got know AV on windows 10 at home and a t work i had 142 malware on my home and at work pc and i nearly died when i seen i this
Arthur Posted May 4, 2017 Posted May 4, 2017 am worried that might mean it goes a day without updating. Not necessarily... Allow real-time definition updates based on reports to Microsoft MAPS This policy setting allows you to enable real-time definition updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest definition update has definitions for a threat involving that file, the service will receive all of the latest definitions for that threat immediately. You must have configured your computer to join Microsoft MAPS for this functionality to work. If you enable or do not configure this setting, real-time definition updates will be enabled.
Arthur Posted May 4, 2017 Posted May 4, 2017 (edited) I had 142 malware What sort of malware was it? With a number that high it sounds more like adware or potentially unwanted programs (PUPs). Windows Defender can scan for the latter, but it's not enabled by default. Programs like Malwarebytes and AdwCleaner typically do a better job at removing adware compared to antivirus software. Edited May 4, 2017 by Arthur
mullet_man Posted May 4, 2017 Posted May 4, 2017 Not necessarily... Allow real-time definition updates based on reports to Microsoft MAPS My Endpoint Protection Policy is set at Basic membership, wondering then if Advanced is the way to go? Which one are you on Arthur?
Arthur Posted May 4, 2017 Posted May 4, 2017 wondering then if Advanced is the way to go? Which one are you on Arthur? Advanced.
mullet_man Posted May 4, 2017 Posted May 4, 2017 Thanks Arthur, will get mine changed to advanced too.
Blue_Cookeh Posted May 5, 2017 Posted May 5, 2017 Loving Windows Defender here. We originally had McAfee 3 or so years ago but ditched it when we bought SCCM licenses... back then it was mainly financial reasons rather than technical but honestly I haven't looked back. I probably wouldn't use it on it's own, but with SCCM the reporting is there and SCCM pushes silent definition updates out to clients every 2 hours (if there's a new one available). As soon as anyone in school gets something bad on their machine and it pops up in SCCM it e-mails IT about it so we can be a little quicker on the mark 1
mullet_man Posted May 5, 2017 Posted May 5, 2017 My policy looks different to your's Arthur? Has extra options by the looks of it? Am on the latest version of SCCM.
Arthur Posted May 5, 2017 Posted May 5, 2017 Am on the latest version of SCCM. I have a slightly older version of SCCM. One of my jobs for the summer hols is to upgrade it.
Steven_Cleaver Posted May 6, 2017 Posted May 6, 2017 Loving Windows Defender here. We originally had McAfee 3 or so years ago but ditched it when we bought SCCM licenses... back then it was mainly financial reasons rather than technical but honestly I haven't looked back. I probably wouldn't use it on it's own, but with SCCM the reporting is there and SCCM pushes silent definition updates out to clients every 2 hours (if there's a new one available). As soon as anyone in school gets something bad on their machine and it pops up in SCCM it e-mails IT about it so we can be a little quicker on the mark I quite like it as agree with what you say wouldn't use it on its own, we don't use SCCM but have some Management tools from a company called Burconix and they have built in central management for this which is really good, remote scan, alerts on console, email alerts, gives description of issue and link to Microsoft website to describe issue.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now