Book Image

Microsoft System Center 2012 Endpoint Protection Cookbook

By : Andrew J Plue
Book Image

Microsoft System Center 2012 Endpoint Protection Cookbook

By: Andrew J Plue

Overview of this book

Microsoft System Center 2012 Endpoint Protection (previously known as Forefront Endpoint Protection 2012) protects client and server operating systems against threats with leading malware detection technologies. Built on Configuration Manager, it provides a unified infrastructure for client security and compliance management and "Microsoft System Center 2012 Endpoint Protection Cookbook" will help you get to grips with vital tasks for implementing this security tool. With the release of System Center 2012 Endpoint Protection, Microsoft is continuing its commitment to offering a cutting edge, enterprise- ready Anti-Virus solution. With its practical and easy to follow recipes, "Microsoft System Center 2012 Endpoint Protection Cookbook" fully prepares you for a simple, headache-free migration. This hands-on, practical cookbook will have you equipped with the knowledge to install and manage System Center 2012 Endpoint Protection like a pro in no time by following step by step recipes. You'll gain insight into a wide range of management tasks, such as building your SCEP infrastructure, deploying SCEP clients and building the perfect AV policies for your workstation and servers. You'll also benefit from a complete SCEP walk-through in a bonus appendix chapter. With "Microsoft System Center 2012 Endpoint Protection Cookbook" in hand, you will have the confidence to tackle essential tasks like deployment, policy and much more for SCEP.
Table of Contents (17 chapters)
Microsoft System Center 2012 Endpoint Protection Cookbook
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Responding to SCEP alerts


So it's 2 A.M. on a Tuesday, you're the SCEP administrator on call, and you've just been woken up for an alert for a malware outbreak. What do you do? This recipe will show you where to go in the SCCM console to review the alert, as well as provide some guidance on what actions to take.

For the example outlined in this recipe, we will be responding to a situation where malware has been detected on a few PCs in the All Systems collection, which has an alert for malware detection assigned to it, and the number of PCs with the malware in question was great enough to trigger the malware outbreak alert as well.

Getting ready

For this recipe, you will need to utilize an account that has at least the SCEP administrator role assignment attached to it.

How to do it...

Follow these steps:

  1. 1. Log into your SCCM CAS server and launch your SCCM 2012 management console.

  2. 2. Navigate to Monitoring | Overview | Alerts.

  3. 3. Any alerts that have been recently triggered will be marked with...