caffrey Posted October 4, 2018 Posted October 4, 2018 I don't even bother with central management, just have defender running and block everything that can execute code that's in a folder users can write to with SRP You can do attack surface reduction rules too https://github.com/MicrosoftDocs/windows-itpro-docs/blob/master/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction.md 1
Davida1992 Posted October 4, 2018 Posted October 4, 2018 We currently use Sophos, but we use a lot of the features such as application control etc. We don't have any plans to stop using Sophos in the near future, I don't think we would want to atm
synaesthesia Posted October 4, 2018 Posted October 4, 2018 We've been using Defender/SCEP since 2012 and have had zero outbreaks. One attempted big problem was stopped in it's tracks by it, and I have no hesitation in recommending it as long as it's managed by SCCM. 650 devices, 1200 users.
Jawloms Posted October 4, 2018 Posted October 4, 2018 If I wanted to set this up from scratch to look after WSUS and Defender on a newly built 2016 server, which of the seemingly 4 million options of "System Center " in MVLS do I download? I can find heaps of info on what it does and how, and tutorials to get it installed and working, I just need the right media!
Arthur Posted October 4, 2018 Posted October 4, 2018 which of the seemingly 4 million options of "System Center " in MVLS do I download? 1
Steven_Cleaver Posted October 4, 2018 Posted October 4, 2018 Same here used Defender whilst I was in education for a good few years never had any issues and we are looking at it in the company i work for now which supports about 50 small and large companies private sector.
ozydave Posted October 5, 2018 Posted October 5, 2018 I was using defender for two years controlled by SCCM. Then had a virus scare that spread a bit and made a part of my anatomy twitch. Defender didn't raise an eyebrow! But the legacy sophos that was still on some machines picked it up. That's what alerted me. Now gone back to sophos. Cheap ahen brought through the local authority.
free780 Posted October 5, 2018 Posted October 5, 2018 I think with Windows 10 is makes sense as a lot of the issues with updates can be due to 3rd party AV. It does look like Microsoft are focusing on Windows Defender ATP with leverages telemetry, but is only avaliable on Microsoft 365 E5. Though you can mange it without SCCM, you could forward events to a server and then powershell an email alert. You can add the definitions to WSUS. You need to get group policy right otherwise the clients will go straight to Microsoft. Though these days I don't know how anyone can survive without SCCM. 1
Duke5A Posted October 5, 2018 Posted October 5, 2018 I was using defender for two years controlled by SCCM. Then had a virus scare that spread a bit and made a part of my anatomy twitch. Proof that we're all living inside a computer simulation. 1
Mujja Posted October 10, 2018 Posted October 10, 2018 As we're migrating to Windows 10 we're not bothering with Sophos and using only Defender. Not managing the clients yet, will get around to that eventually through SCCM.
Steven_Cleaver Posted October 11, 2018 Posted October 11, 2018 I did nearly look at going back to Sophos as when we initially moved to Defender as wasn't easy way of sort of central console and we didn't have SCCM but we used a third party management tools and I think quite a few of their customers moved to Defender so they built in sort of central console, email alerts, remote scanning and displayed information about the threat linked back to Microsoft recommendations into their tools so worked well for us. Out of education now working for MSP and we use Sophos and is good but someone else manages this mostly and he does say he seems to have a lot of issues with this and we are looking at Defender again for clients.
CyBeRkId2002 Posted December 12, 2018 Posted December 12, 2018 Sorry to drag up this old thread but we have started supporting a couple of primaries who use disparate AV's so am thinking of standardising to the Microsoft solution (we use SCEP here). Few of these primaries have the capacity or funds for a full SCCM solution so am aiming to just manage with GPO's for now. My big questions is: Is the Windows 8 (and possibly 7???) version of Windows Defender as effective as that of the built-in Windows 10, or am I better off rolling out the SCEP installer to these older OS'? I only ask as I am aware the installer for W10 only takes management of the builtin defender in 10, so am guessing there is some difference functionality-wise.
CHiLL Posted December 12, 2018 Posted December 12, 2018 Sorry to drag up this old thread but we have started supporting a couple of primaries who use disparate AV's so am thinking of standardising to the Microsoft solution (we use SCEP here). Few of these primaries have the capacity or funds for a full SCCM solution so am aiming to just manage with GPO's for now. My big questions is: Is the Windows 8 (and possibly 7???) version of Windows Defender as effective as that of the built-in Windows 10, or am I better off rolling out the SCEP installer to these older OS'? I only ask as I am aware the installer for W10 only takes management of the builtin defender in 10, so am guessing there is some difference functionality-wise. I'd recommend installing the SCEP client onto those primary computers. Taken from: https://docs.microsoft.com/en-us/sccm/protect/deploy-use/endpoint-protection Beginning with Windows 10 and Windows Server 2016 computers, Windows Defender is already installed. For these operating systems, a management client for Windows Defender is installed when the Configuration Manager client installs. On Windows 8.1 and earlier computers, the Endpoint Protection client is installed with the Configuration Manager client. Windows Defender and the Endpoint Protection client have the following capabilities: Malware and spyware detection and remediation Rootkit detection and remediation Critical vulnerability assessment and automatic definition and engine updates Network vulnerability detection through Network Inspection System Integration with Cloud Protection Service to report malware to Microsoft. When you join this service, the Endpoint Protection client or Windows Defender downloads the latest definitions from the Malware Protection Center when unidentified malware is detected on a computer.
synaesthesia Posted December 12, 2018 Posted December 12, 2018 Not really, but only because the newer version in windows 10 takes into account advanced threat protection, malware etc rather than just AV. Saying that, we ran for 5 years on win7 and SCEP with zero outbreaks or problems; obviously just make sure everything else is tight as well. I don't think I'd be quite so happy if there's laptops with local admin users, people with ability to run executables from their areas etc.
LeMarchand Posted December 12, 2018 Posted December 12, 2018 Sorry to drag up this old thread but we have started supporting a couple of primaries who use disparate AV's so am thinking of standardising to the Microsoft solution (we use SCEP here). Few of these primaries have the capacity or funds for a full SCCM solution so am aiming to just manage with GPO's for now. My big questions is: Is the Windows 8 (and possibly 7???) version of Windows Defender as effective as that of the built-in Windows 10, or am I better off rolling out the SCEP installer to these older OS'? I only ask as I am aware the installer for W10 only takes management of the builtin defender in 10, so am guessing there is some difference functionality-wise. From what I've seen recently W8.1 seems fine but W7 needs Security Essentials installed unless you go down the SCEP route.
free780 Posted December 12, 2018 Posted December 12, 2018 Yep just over a year to go for support. You won't get any alerting without SCCM.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now