Book Image

Microsoft System Center 2012 Endpoint Protection Cookbook

By : Andrew J Plue
Book Image

Microsoft System Center 2012 Endpoint Protection Cookbook

By: Andrew J Plue

Overview of this book

Microsoft System Center 2012 Endpoint Protection (previously known as Forefront Endpoint Protection 2012) protects client and server operating systems against threats with leading malware detection technologies. Built on Configuration Manager, it provides a unified infrastructure for client security and compliance management and "Microsoft System Center 2012 Endpoint Protection Cookbook" will help you get to grips with vital tasks for implementing this security tool. With the release of System Center 2012 Endpoint Protection, Microsoft is continuing its commitment to offering a cutting edge, enterprise- ready Anti-Virus solution. With its practical and easy to follow recipes, "Microsoft System Center 2012 Endpoint Protection Cookbook" fully prepares you for a simple, headache-free migration. This hands-on, practical cookbook will have you equipped with the knowledge to install and manage System Center 2012 Endpoint Protection like a pro in no time by following step by step recipes. You'll gain insight into a wide range of management tasks, such as building your SCEP infrastructure, deploying SCEP clients and building the perfect AV policies for your workstation and servers. You'll also benefit from a complete SCEP walk-through in a bonus appendix chapter. With "Microsoft System Center 2012 Endpoint Protection Cookbook" in hand, you will have the confidence to tackle essential tasks like deployment, policy and much more for SCEP.
Table of Contents (17 chapters)
Microsoft System Center 2012 Endpoint Protection Cookbook
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Integrating SCEP with SCOM 2012


In order to install the System Center Security Monitoring Pack for Endpoint Protection, you will need to use an account with administrator access to SCOM. You will also need to download the management pack, which is available at the following URL:

http://www.microsoft.com/en-us/download/details.aspx?id=9754

Now, follow these steps:

  1. 1. Begin by logging into your SCOM management server and unpacking the MSI, which you downloaded from Microsoft's website. To do so, double-click on fep2010 security mp.msi and agree to EULA. Do not worry that the management pack we just downloaded has FEP in the title; this MP works for SCEP as well. Refer to the following screenshot:

  2. 2. Next, select a destination path for the files to unpack to. Whether you stick with the default or choose your own location is up to you. Either way make sure to copy the path, as you will need it in a later step. Refer to the following screenshot:

  3. 3. Now just click on the Install button and wait for the task to complete, as shown in the following screenshot:

  4. 4. Now you will need to open the SCOM management console, and select the Administration tab. Locate the Management Packs object and then right-click on it. Select the option for Import Management Packs, as shown in the following screenshot:

  5. 5. The Import Management Packs wizard should appear. Next, click on the Add button, as shown in the following screenshot:

  6. 6. You'll be prompted with an Online Catalog Connection dialog box, as we've already downloaded the management pack. Now, click on No to proceed, as shown in the following screenshot:

  7. 7. You'll then be presented with a window that allows you to browse to the location for which we unpacked the files to in step 2. The first file you'll need to pick is Microsoft.FEPS.Libary.mp. Then, click on the Open button to proceed, as shown in the following screenshot:

  8. 8. You will be brought back to the Import Management Packs wizard. If you've selected the correct file, then you'll see a green check next to the filename. You'll need to click on the Add button again and repeat the process for the other two files in the folder, Microsoft.FEPS.Application.mp and Microsoft.FEPS.Reports.mp. Once you've added all three .mp files, you can then click on the Install button, as shown in the following screenshot:

  9. 9. The import process will likely take a few minutes, but once it's complete, you should see the following screenshot:

  10. 10. Click on the Close button to complete the import procedure.

The procedure in this recipe will only import the management pack into your SCOM 2012 environment, in order. For clients, to start sending SCEP related data to SCOM, they will also need to have the SCOM client deployed to them. In other words, the SCOM Management Pack collects data directly from the Endpoint clients themselves, rather than pulling data out of your SCCM 2012 server.

As such, there is a lot of overlap between SCCM 2012 with SCEP enabled and a SCOM server with the Endpoint Protection Management pack installed. Therefore, it's recommended that you only use the Management Pack if you have a good reason for doing so.