Jump to content

Recommended Posts

Posted

Hi,

 

Just beginning to move staff over to Windows 10 and I am wondering if anyone has scrapped their current anti virus in favour of Windows Defender?

 

Is it good enough? Would be a great plus point for moving people to Windows 10 if we could get rid of another annual payment!

 

Cheers,

  • 2 months later...
Posted
It would seem Defender isn't that great at protecting your clients.

Defender/SCEP has improved a lot in recent months. e.g.

 

  • Protection against 0-day malware attacks = 100% for the last three months running (December to February 2017)
     
     
  • Detection of widespread and prevalent malware discovered in the last 4 weeks = 99.6% (which is better than the industry average of 99%)

I found defender not to offer a lot of features to prevent malware and mitigate ransomware.

Which features are you thinking of? Some of them are in the operating system now, rather than the AV.

 

www.zdnet.com/article/windows-10-security-so-good-it-can-block-zero-days-without-being-patched

  • Thanks 1
Posted
Have a read of this: https://www.av-test.org/en/antivirus/business-windows-client/windows-10/

 

It would seem Defender isn't that great at protecting your clients. As a result it's made me to continue with Symantec Endpoint Protection for all my clients, including Mac OS. I found defender not to offer a lot of features to prevent malware and mitigate ransomware.

 

ESET isn't even on the list, costs about £2K for 3 years so as primary schools we will be looking at Defender.

Posted

We have Forefront Endpoint Protection which uses basically the same engine as Defender/Windows Security Essentials.

 

Thought it was OK until last week when one of our PCs picked up the Spora ransomware from a compromised website and FEP did absolutely nothing about it. First we knew of it was one of the network drives being half encrypted!

 

So for me FEP/Defender is useless and is going asap.

Posted
on its own in a school defender is useless as it has no reporting facilities as part of microsofts i cant remember the name enterprise "defender" its not terrible but im not sure id trust it as much as a dedicated offering
Posted (edited)
I can't remember the name enterprise "defender"

System Center Endpoint Protection and/or Windows Defender Advanced Threat Protection?

 

Thought it was OK until last week when one of our PCs picked up the Spora ransomware from a compromised website and FEP did absolutely nothing about it. First we knew of it was one of the network drives being half encrypted!

Was that because its browser or Flash Player plug-in wasn't up-to-date?

Edited by Arthur
Posted
Hi,

 

Just beginning to move staff over to Windows 10 and I am wondering if anyone has scrapped their current anti virus in favour of Windows Defender?

 

Is it good enough? Would be a great plus point for moving people to Windows 10 if we could get rid of another annual payment!

 

Cheers,

 

Yes :)

Posted (edited)
Windows 10 they made SCEP/Defender the same thing. so if you are using SCEP for windows 10 it is still called defender. then to just really confuse things they have the additional Advance Threat Protection under the Defender branding. which is not just about reporting anti virus and malware but monitoring user behavior to protect against remote attackers so compromised accounts can be detected faster. Edited by gaz350b
  • 2 weeks later...
Posted
We have Forefront Endpoint Protection which uses basically the same engine as Defender/Windows Security Essentials.

 

Thought it was OK until last week when one of our PCs picked up the Spora ransomware from a compromised website and FEP did absolutely nothing about it. First we knew of it was one of the network drives being half encrypted!

 

So for me FEP/Defender is useless and is going asap.

 

I'm not going to defend "defender"...nor for that matter any other antivirus/malware product.....but...

 

Keep in mind that no protection software is going to give you 100% protection. I few years ago I remember Norton or some such product being tested and was found to be effective against 60% (yes...only 60%) of current malware at the time. ...and that was one of the better products tested. And while some products claim to offer some protection against zero day attack there is no guarantee its going to protect you against the attack you might experience. Simply paying money for a separate commercial product may give you a sense of peace of mind - but to be honest it would be largely an illusion - although its one I have been happy to invest in - if only to be able to say to SLT - that yes we pay for a product to protect us. But if you are really thinking "FEP/Defender is useless and is going asap" don't imagine for a monent that other products are going to be better. Hopefully - you have analysed carefully how the attack managed to compromise your network....I'm thinking it must have been a user with elevated or administrator priviledges - or perhaps you have no restrictions on what executables your users can run. "Drive by" infections are an increasing menace...and malicious email attachment attacks increasingly sophisticated as attackers now seem to to harvest first/last name and company names etc which make such emails seem genuine.

  • 3 weeks later...
Posted (edited)

Due to us receiving some emails with dodgy Word attachments, I've added this GP that stops Marcos from running on docs downloaded from the internet.

 

http://www.edugeek.net/forums/security/176254-office-2013-can-now-block-macros-documents-originating-internet.html#post1510169

 

But I was wondering what interval does everyone have for Defender to checking for updates? I have mine set at 8 hours but going to change it to 4 as am worried that might mean it goes a day without updating.

 

Thanks.

Edited by mullet_man
Posted
am worried that might mean it goes a day without updating.

Not necessarily...

 

Allow real-time definition updates based on reports to Microsoft MAPS

 

This policy setting allows you to enable real-time definition updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest definition update has definitions for a threat involving that file, the service will receive all of the latest definitions for that threat immediately. You must have configured your computer to join Microsoft MAPS for this functionality to work.

 

If you enable or do not configure this setting, real-time definition updates will be enabled.

Posted (edited)
I had 142 malware

What sort of malware was it? With a number that high it sounds more like adware or potentially unwanted programs (PUPs). Windows Defender can scan for the latter, but it's not enabled by default.

 

Programs like Malwarebytes and AdwCleaner typically do a better job at removing adware compared to antivirus software.

Edited by Arthur
Posted

Loving Windows Defender here. We originally had McAfee 3 or so years ago but ditched it when we bought SCCM licenses... back then it was mainly financial reasons rather than technical but honestly I haven't looked back.

 

I probably wouldn't use it on it's own, but with SCCM the reporting is there and SCCM pushes silent definition updates out to clients every 2 hours (if there's a new one available). As soon as anyone in school gets something bad on their machine and it pops up in SCCM it e-mails IT about it so we can be a little quicker on the mark :)

  • Thanks 1
Posted
Am on the latest version of SCCM.

I have a slightly older version of SCCM. One of my jobs for the summer hols is to upgrade it. :)

Posted
Loving Windows Defender here. We originally had McAfee 3 or so years ago but ditched it when we bought SCCM licenses... back then it was mainly financial reasons rather than technical but honestly I haven't looked back.

 

I probably wouldn't use it on it's own, but with SCCM the reporting is there and SCCM pushes silent definition updates out to clients every 2 hours (if there's a new one available). As soon as anyone in school gets something bad on their machine and it pops up in SCCM it e-mails IT about it so we can be a little quicker on the mark :)

 

I quite like it as agree with what you say wouldn't use it on its own, we don't use SCCM but have some Management tools from a company called Burconix and they have built in central management for this which is really good, remote scan, alerts on console, email alerts, gives description of issue and link to Microsoft website to describe issue.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...