Jump to content

Windows Defender - Anyone brave enough to drop their Endpoint Security?


Recommended Posts

Posted

Hi All,

 

I'm approaching the end of my contract with my current antivirus / end point security provider and with budgets getting ever tighter here in West Sussex, the thought has crossed my mind about the possibility of switching to Windows Defender only on my servers (2013 / 2016) and desktops/laptops (Windows 10 1803)...

 

Has anyone been brave or perhaps crazy enough to try this themselves or are we under the opinion that Microsoft cannot protect us exclusively and we still need additional security even after all these years since Windows Defender was implemented?

Posted

we've been using Defender (or Endpoint protection) via SCCM since is included in our OVS-EES agreement anyway. The cost for the SCCM server licence was a fraction of renewing with another of the AV providers, and gives us application deployment as well.

 

Touch wood not had any issues, and it's been a lower impact on stations compared to our previous Sophos installation.

Posted

Yeah we just use the build in stuff now, managed by SCCM and Intune.

 

No issues so far - we also block all executable files inside C:\Users\%username%\AppData from running too.

Posted
I'm approaching the end of my contract with my current antivirus / end point security provider and with budgets getting ever tighter here in West Sussex, the thought has crossed my mind about the possibility of switching to Windows Defender only on my servers (2013 / 2016) and desktops/laptops (Windows 10 1803)...

 

Now that Avast want money (how inconsiderate ;)), I'm also giving this serious thought.

Posted
I'm considering ditching sophos for Defender, but haven't tried it with SCCM, just local clients so I'm not sure how well it will work. I think it definitely the next step for us though.
Posted
I take it having an OVS-EES agreement doesn't include Defender licensing? Never really looked into it until very recently, a few local primaries are also considering it.
Posted

Free! Blimey I really should have looked into this earlier!

 

I've used defender at home for a while and its been fine - hence the reason I'm looking into it.

Posted
I ditched Sophos for Endpoint Protection via SCCM two years ago. The cost saving is massive if you have a EVS agreement ( you do have to pay to manage servers with SCCM) and as others have commented SCEP/Defender is perfectly OK in conjunction with other standard precautions. It was a motivation for getting SCCM working, which I had been wanting to do for some time, and although the learning curve was quite steep the investment in time has been worth it. We now use SCCM for security, OS deployment, updates and now software deployment, so although there is a significant investment in time you save on the bottom line and develop a lot of useful skills and knowledge setting it up.
Posted
Has anyone been brave or perhaps crazy enough to try this themselves or are we under the opinion that Microsoft cannot protect us exclusively and we still need additional security even after all these years since Windows Defender was implemented?

Defender is one of the best Windows A/Vs available, although you will need SCCM to monitor it properly.

 

 

tOBwCY.png

 

It's recommended to enable the Block At First Sight and potentially unwanted applications features for the best protection.

 

Windows 10 itself has some additional attack surface reduction rules you may want to enable too (in addition to AppLocker). See the Cryptolocker thread for further details. :)

Posted
Yeah I'm looking to use SCCM to manage defender, I was still stuck in the Windows 7 mentality where it was a paid for option (Security Essentials IIRC?)
Posted
Yeah I'm looking to use SCCM to manage defender, I was still stuck in the Windows 7 mentality where it was a paid for option (Security Essentials IIRC?)

 

Nope, also free in Windows 7

Posted

So if a school has an EES agreement already, what additional costs are there (either per server, or per cal or whatever) to run defender and control it with SCCM? I'm not after the value necessarily as this can vary depending on all sorts, just what additional licencing is required?

 

Stuart

Posted
Nope, also free in Windows 7

 

https://support.microsoft.com/en-gb/help/14210/security-essentials-download

Note: Windows Defender is also available in Windows 7. However, in Windows 7, Defender only provides protection against spyware. In the Windows 8, Windows RT, Windows 8.1, Windows RT 8.1, and Windows 10, Windows Defender provides full malware protection for your PC. Malware consists of viruses, spyware, and other potentially unwanted software.

 

For proper protection in Win 7 you need Security Essentials as well and pay for it as well

 

https://support.microsoft.com/en-us/help/13752/windows-security-essentials-eula

1. INSTALLATION AND USE RIGHTS.

 

Home Use. If you are a home user, then you may install and use any number of copies of the software on your personal devices for use by people who reside in your household.

Small Business. If you operate a small business, then you may install and use the software on up to ten (10) devices in your business.

Restrictions. The software may not be used on devices owned by government or academic institutions.

Separation of Components. The components of the software are licensed as a single unit. You may not separate the components and install them on different devices.

Included Microsoft Programs. The software may contain other Microsoft programs. The license terms with those programs apply to your use of them.

Posted

Just had a 1803 install and the sccm deployment was as simple as making a policy as the win 10 1803 has the included files as standard which then just need a policy to manage them.

 

Currently I’m going through best practices and have just moved wsus to sccm today as well with help from my it provider. This means all reporting and updates are now central in sccm.

 

We pay £1280 ish for server data centre (x2 rack servers) and sccm pack included ( basically unlimited servers and full sccm )

Posted
I don't even bother with central management, just have defender running and block everything that can execute code that's in a folder users can write to with SRP
Posted
Scep and wse are the same product (sort of), but scep is the Enterprise version which is free, but requires sccm for management.

 

Again, if you want to manage it through sccm you need to make sure that you have the scep cals and they are not free.

Posted (edited)
Again, if you want to manage it through sccm you need to make sure that you have the scep cals and they are not free.
I'd say most schools use ovs-es, so in that sense yes they aren't free, but included with the core cals Edited by ITGuyWestMidlands

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...