<?xml version="1.0"?>
<rss version="2.0"><channel><title>Endpoint Protection Latest Questions</title><link>https://www.windows-noob.com/forums/forum/97-endpoint-protection/</link><description>Endpoint Protection Latest Questions</description><language>en</language><item><title>SCEP Clients not updating as required</title><link>https://www.windows-noob.com/forums/topic/22866-scep-clients-not-updating-as-required/</link><description><![CDATA[<p>
	Hi all,
</p>

<p>
	My endpoint protection clients aren't updating. I noticed it happening this last month.
</p>

<p>
	Most clients are 2 to 7 days outdated.
</p>

<p>
	They are receiving the correct policy.
</p>

<p>
	I'm on SCCM 2203 as of today.
</p>

<p>
	Attached 2 images of log files from different clients.
</p>

<p><a href="https://www.windows-noob.com/forums/uploads/monthly_2022_06/scep.png.604d696074028a93b15bafec6c3f9c2d.png" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="23172" src="https://www.windows-noob.com/forums/uploads/monthly_2022_06/scep.thumb.png.2975d2ccb6ccd9a087ee743cae5a5e1a.png" data-ratio="51.8" width="1000" class="ipsImage ipsImage_thumbnailed" alt="scep.png"></a></p>
<p><a href="https://www.windows-noob.com/forums/uploads/monthly_2022_06/scep2.png.b48f8daf42e1e26ebbcb8296b6404a83.png" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="23173" src="https://www.windows-noob.com/forums/uploads/monthly_2022_06/scep2.thumb.png.c976eed8b9bd68fb2f5cb609e249dad2.png" data-ratio="44" width="1000" class="ipsImage ipsImage_thumbnailed" alt="scep2.png"></a></p>]]></description><guid isPermaLink="false">22866</guid><pubDate>Mon, 06 Jun 2022 15:47:45 +0000</pubDate></item><item><title>Log for Endpoint Protection within Configuration Manager and Standalone</title><link>https://www.windows-noob.com/forums/topic/23199-log-for-endpoint-protection-within-configuration-manager-and-standalone/</link><description><![CDATA[<p>
	Thanks a lot Niall it works perfectly the Client are receiving the Definition Updates. 
</p>

<p>
	I have some question for the troubleshooting: how does the Client reports its Definition Updates to the Console/CM -  Database?
</p>

<p>
	I noticed several clients having been updated to 1.383.698.0 but still reports only 1.379.517.0 on the CM - Console. What is the workflow for this path between the client and the console? which logs are used?<br />
	Thanks,
</p>

<p>
	Dom
</p>
]]></description><guid isPermaLink="false">23199</guid><pubDate>Mon, 27 Feb 2023 23:41:31 +0000</pubDate></item><item><title>Endpoint protection manager fails after installation</title><link>https://www.windows-noob.com/forums/topic/22857-endpoint-protection-manager-fails-after-installation/</link><description><![CDATA[<p>
	Hello,<br />
	we have a test environment and a productive environment.<br />
	In the test environment we could install and configure an end point protection manager.
</p>

<p>
	In the production environment we get errors as these:<br /><em><strong>Cannot find path for destination inbox Notification Manager on server REGISTRY. The current component is possibly not installed.<br />
	Cannot connect to the inbox source, sleep 30 seconds and try again.  <br />
	[Software Inventory Processor (Site Trusted)] cannot update environment so skiping outbox processing.<br />
	Cannot find path for destination inbox Distribution Manager (incoming) on server registry.<br />
	~~ same goes for: Software Metering Processor Usage (Site), Success Policy Requests / Discovery Data Manager, etc.<br />
	[Notification Manager] cannot update environment so skiping outbox processing.<br />
	[Distribution Manager (Incoming)] halting execution.  <br />
	Remote site is in pull-mode.<br />
	Coult not read registy key HKEY_LOCAL_MACHINE\Software\Microsoft\SMS\MPFDM\INboxes\ on the server. The operating system reported error 2: cannot find the file</strong></em>
</p>

<p>
	We have no clue how to resolve this. We opened a case with MS, but so far nothing.<br />
	It seems during the installation stuff from the new epp-server should be pushed onto the siteserver (and stuff should also be written in the registry of the site server,) but this fails.
</p>

<p>
	The SiteServer is admin on the new Site System (we tried to install using the site servers computer account as well as the install service account - both failed).<br />
	The service RemoteRegistry runs on both systems.
</p>

<p>
	Thank you for ideas.<br />
	Sincerely<br />
	Andreas
</p>
]]></description><guid isPermaLink="false">22857</guid><pubDate>Mon, 30 May 2022 13:20:26 +0000</pubDate></item><item><title>Windows defender causing 100% CPU load</title><link>https://www.windows-noob.com/forums/topic/20905-windows-defender-causing-100-cpu-load/</link><description><![CDATA[
<p>
	Hi everyone,
</p>

<p>
	I hope that someone may be able to shed some light on this topic. We've been getting reports from users who have a specific model that see spikes in CPU activity on 100% when the quick scan from Windows Defender starts. The notebook gets practically unusable in the next 10-20 minutes because of a huge lag in responsiveness. I've noticed that even though Defender will report the scan as finished, the sluggishness continues for several more minutes and finally ends after some time. The odd thing is that this is widely reported only on a specific model from Lenovo (ThinkPad P1 Gen2)
</p>

<ul><li>
		We are using SCCM 1806 and Windows 10 1809
	</li>
	<li>
		The CPU usage for the antimalware scan is limited to 30% by SCCM and the usage stays around this number, but the scan causes other processes to spike
	</li>
	<li>
		We've noticed the scan to cause other processes to spike: Skype for Business, Windows interrupts (this struck me as quite odd), Chrome, IntelliJ and others
	</li>
	<li>
		We've tried excluding the whole drive from the scans - still happens 
	</li>
	<li>
		We've tried excluding some processes used daily by some users (browser, development IDE, etc...) - still happens
	</li>
	<li>
		Updated everything from the Lenovo System Update tool 2-3 weeks ago with one user - still happens
	</li>
	<li>
		Windows event log shows nothing of value
	</li>
	<li>
		I was not able to find anything in EndpointProtectionAgent.log that would indicate an issue
	</li>
</ul><p>
	What is really confusing to me:
</p>

<ul><li>
		Out of all devices, only some users with P1 Gen2 models are reporting this issue
	</li>
	<li>
		Some users experience this on a daily basis, while others have seen it only a handful of times in the past several months
	</li>
	<li>
		The spike of CPU load for System interrupts in some cases leads me towards a possible driver issue, but I cannot pinpoint what exactly
	</li>
</ul><p>
	I was not able to find any relevant information in the event viewer. The log files at C:\ProgramData\Microsoft\Windows Defender\Support do not seem much of use as well. I was not able to find information on the path of the scanned items or a way to produce a log with increased verbosity that is in readable format.
</p>

<p>
	 
</p>

<p>
	Is there any way we can troubleshoot this further with more details and pinpoint the exact cause of this problem?
</p>
]]></description><guid isPermaLink="false">20905</guid><pubDate>Tue, 02 Jun 2020 14:12:25 +0000</pubDate></item><item><title>Windows Defender / Endpoint Protection</title><link>https://www.windows-noob.com/forums/topic/17149-windows-defender-endpoint-protection/</link><description><![CDATA[
<p>
	We are getting ready to get rid of our AV solution and are looking to use SCCM Endpoint Protection instead.  
</p>

<ol><li>
		Is this enough?  Are we still going to be protected as we were with a full blown AV?  We are fully Windows 10 going forward.
	</li>
	<li>
		Is there a document that will walk me through setting this all up?
	</li>
	<li>
		Is there a way to setup email alerts when a virus / malware / other security alert is found?
	</li>
	<li>
		Anything else we need to know before starting?
	</li>
</ol><p>
	 
</p>
]]></description><guid isPermaLink="false">17149</guid><pubDate>Tue, 25 Jun 2019 15:07:32 +0000</pubDate></item><item><title>Antimalware Policy not applying</title><link>https://www.windows-noob.com/forums/topic/16337-antimalware-policy-not-applying/</link><description><![CDATA[
<p>
	Hi, I've recently had an issue were my Windows 10 1803 clients don't get signature updates although the definition updates seem to apply ok. Looking through the logs nothing really stuck out except that the machine didn't have a antimalware policy. I check SCCM and the policy is deployed and apperently installed ok (going from the console). Any ideas would really be great!
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://www.windows-noob.com/forums/uploads/monthly_2018_08/20180821_163638.jpg.0944200013fb84050ae69ecd016ae700.jpg" data-fileid="20241" rel=""><img alt="20180821_163638.jpg" class="ipsImage ipsImage_thumbnailed" data-fileid="20241" src="https://www.windows-noob.com/forums/uploads/monthly_2018_08/20180821_163638.thumb.jpg.6e0765152e23eb1a92ba88b6486a4c3b.jpg" /></a>
</p>
]]></description><guid isPermaLink="false">16337</guid><pubDate>Wed, 22 Aug 2018 16:01:16 +0000</pubDate></item><item><title>Uninstall Forefront</title><link>https://www.windows-noob.com/forums/topic/16156-uninstall-forefront/</link><description><![CDATA[
<p>
	My company has decided to go with Avast and remove Forefront. Has anybody done a roll out to disable or uninstall SCEP via SCCM and then roll out new AV?
</p>

<p>
	What steps/procedure did you follow?
</p>

<p>
	I am thinking of these steps:
</p>

<ol><li>
		Creating a Package with a batch file and deploying this to uninstall (@echo off C:Windowsccmsetupscepinstall.exe /u /s)
	</li>
	<li>
		Then to disable Endpoint Protection via client settings on SCCM.
	</li>
	<li>
		Deploy Avast via a new Package or Application.
	</li>
</ol>]]></description><guid isPermaLink="false">16156</guid><pubDate>Tue, 24 Apr 2018 08:54:29 +0000</pubDate></item><item><title>Endpoint Protection status - At Risk</title><link>https://www.windows-noob.com/forums/topic/15484-endpoint-protection-status-at-risk/</link><description><![CDATA[<p>
	How do I find out why clients say they are "At Risk" in System Center Endpoint Protection status?
</p>]]></description><guid isPermaLink="false">15484</guid><pubDate>Tue, 20 Jun 2017 12:28:39 +0000</pubDate></item><item><title>System Center Endpoint / Data Transfer Service 0X80072EFE Error</title><link>https://www.windows-noob.com/forums/topic/15140-system-center-endpoint-data-transfer-service-0x80072efe-error/</link><description><![CDATA[
<p>I currently have a few systems that are remote from the main facility, they are on the network and have their own Distribution Point at the location.<span>  </span>Some systems are working with no issue at all, updating both Microsoft and 3rd party updates along with the EP definitions that are pushed out automatically to all client systems.<span>  </span>I can go into the application and it will download the updates, and successfully install them.<span>  </span>I verified that it is loading the EPAMPolicy.xml file successfully.</p>
<p> </p>
<p>The systems that are having the issue are reporting a 0X80072EFE error in the Data Transfer Service log.<span>  </span>One of the systems when I used “bitsadmin” to see what was queued to the system had 116 pending files that were just sitting there.<span>  </span>Using this link to assist <a href="https://social.technet.microsoft.com/Forums/office/en-US/ba0725b2-c9cc-41e8-81d6-fa5ec83a4be4/windows-update-error-0x80072efe?forum=winservergen" rel="external nofollow"> https://social.technet.microsoft.com/Forums/office/en-US/ba0725b2-c9cc-41e8-81d6-fa5ec83a4be4/windows-update-error-0x80072efe?forum=winservergen</a> I am able to determine that it is not the firewall, nor the AV that is the issues.<span>  </span>I also renamed the softwaredistribution folder on off chance that there was a corrupted file inside one of the folders.<span>  </span>That did not resolve the issue.<span>  </span>I downloaded and ran Checksur.exe and no issues were noted or reported.<span>  </span>I rerun Software Updates Deployment Eval Cycle and Updates Scan Cycle and still receive the same error.<span>  </span>On one of the systems, I performed a SCCM repair and that did not resolve.<span>  </span>Part of the above link is to also run System File Checker (SFC) on the system, which does not find any issues. At each point of this process I run “bitsadmin” and there are usually 6 files queued up and not showing any sign that they are downloading. Attempting to reset them fails and so my only resort is to go in and stop BITS service, rename the 2 files located in programdata\microsoft\network\downloader and this does not resolve the issue.</p>
<p> </p>
<p>I may be looking up the wrong tree, but believe the 0X80072EFE error if resolved would then allow this and the other systems to automatically update themselves.<span>  </span>Being that this a remote location, reimaging the systems is an option, but an option of last resort, but can be done.<span>  </span>I would like to be able to resolve the above issue and move on.<span>  </span>I have a similar setup on another location, and the systems there do not have this issue.<span> </span></p>
<p> </p>
<p><span>I have added the 3 logs and if there are any additional logs that you would like to see, please let me know so I can post them. </span></p>
<p> </p>
<p><span>Tks</span></p>
<p> </p>
<p><span>Mark Reny</span></p>
<p> </p>
<p><a href="https://www.windows-noob.com/forums/applications/core/interface/file/attachment.php?id=18116" data-fileid="18116" rel="">DataTransferServiceLog.txt</a></p>
<p><a href="https://www.windows-noob.com/forums/applications/core/interface/file/attachment.php?id=18117" data-fileid="18117" rel="">EndpointProtectionAgentLog.txt</a></p>
<p><a href="https://www.windows-noob.com/forums/applications/core/interface/file/attachment.php?id=18118" data-fileid="18118" rel="">WUAHandlerLog.txt</a></p>
]]></description><guid isPermaLink="false">15140</guid><pubDate>Tue, 07 Mar 2017 18:22:37 +0000</pubDate></item><item><title>SCEP 1606 not showhing Endpoint Protection on Clients</title><link>https://www.windows-noob.com/forums/topic/14869-scep-1606-not-showhing-endpoint-protection-on-clients/</link><description><![CDATA[
<p>Hello i have a working lab with System Center Manager 1606. I installed the role Endpoint Protection Manager 1606.  I also have 3 Clients with Windows 10 1607.  I created a custom client setting to install Endpoint Protection 1606 to the clients. On the System Center Manager is see the header</p>
<p><a class="ipsAttachLink ipsAttachLink_image" href="https://www.windows-noob.com/forums/uploads/monthly_12_2016/post-34842-0-05745400-1481209793.png" data-fileid="17928" rel=""><img src="https://www.windows-noob.com/forums/uploads/monthly_12_2016/post-34842-0-05745400-1481209793.png" data-fileid="17928" class="ipsImage ipsImage_thumbnailed" alt="post-34842-0-05745400-1481209793.png"></a>.</p>
<p> </p>
<p>I also created a custom antimalware policy and deployed it to the windows 10 clients. But they show only windows defender in the header</p>
<p><a class="ipsAttachLink ipsAttachLink_image" href="https://www.windows-noob.com/forums/uploads/monthly_12_2016/post-34842-0-46525600-1481209899.png" data-fileid="17929" rel=""><img src="https://www.windows-noob.com/forums/uploads/monthly_12_2016/post-34842-0-46525600-1481209899.png" data-fileid="17929" class="ipsImage ipsImage_thumbnailed" alt="post-34842-0-46525600-1481209899.png"></a>. So how can i proof if all is working fine?</p>
<p> </p>
<p> </p>
<p>Another Problem. All Guides say we should use SUS for Endpoint Protection Updates but how do i conifgure SUS for Endpoint Protection 1606?</p>
<p> </p>
<p>What Product shoul we use:</p>
<p><a class="ipsAttachLink ipsAttachLink_image" href="https://www.windows-noob.com/forums/uploads/monthly_12_2016/post-34842-0-96035200-1481210021.png" data-fileid="17930" rel=""><img src="https://www.windows-noob.com/forums/uploads/monthly_12_2016/post-34842-0-96035200-1481210021.png" data-fileid="17930" class="ipsImage ipsImage_thumbnailed" alt="post-34842-0-96035200-1481210021.png"></a></p>
<p> </p>
<p> </p>
<p>It is very confusing for me!</p>
<p> </p>
<p>How can check that everything is working well and only the visual thing is confusing.</p>
<p> </p>
<p>Can please anybody clear the things??</p>
]]></description><guid isPermaLink="false">14869</guid><pubDate>Thu, 08 Dec 2016 15:18:22 +0000</pubDate></item><item><title>Deploying FEP</title><link>https://www.windows-noob.com/forums/topic/14782-deploying-fep/</link><description><![CDATA[
<p>Long time lurker here, finally posting something!</p>
<p> </p>
<p>We've been testing deploying FEP on a collection and all went well and no issues on the clients. My manager gave me the go-ahead to deploy to all desktops. However when I deploy for the collection for all desktops, nothing happens and the reporting states "Active clients protection with Endpoint Protection: 0" although the total devices comes up correctly.</p>
<p> </p>
<p>I left this for 24 hours and still nothing. I then re-deployed and still nothing. I then decided to drop a handful of these desktops into our test collection and within half an hour they all had the FEP status as managed.</p>
<p> </p>
<p>Why is this working for one collection but not another? Logs doesn't seem to be providing any information.</p>
]]></description><guid isPermaLink="false">14782</guid><pubDate>Tue, 08 Nov 2016 11:13:30 +0000</pubDate></item><item><title>SCEP Alerts when threshold reached</title><link>https://www.windows-noob.com/forums/topic/14196-scep-alerts-when-threshold-reached/</link><description><![CDATA[
<p>Is there a way to generate a custom alert when the System Center Endpoint Protection Status -&gt; Operational status of clients reaches a given number of systems?</p>
<p> </p>
<p>for example when the number of clients that has the definitions up to 3 days old reaches reaches the number of 1000 clients. </p>
<p> </p>
<p>Would it be possible to check the threshold with every summarization on the report?</p>
<p> </p>
<p>Regards</p>
<p>Pawel</p>
]]></description><guid isPermaLink="false">14196</guid><pubDate>Fri, 03 Jun 2016 08:14:56 +0000</pubDate></item><item><title>Create Custom Alerts?</title><link>https://www.windows-noob.com/forums/topic/13560-create-custom-alerts/</link><description><![CDATA[<p>I am using SCEP and already have alerting setup. Most of the alerts that I receive require no further action since SCEP deleted it. On rare occasion, there will be something detected that SCEP fails to handle automatically. Is there a way to create a custom alert that will only be triggered when this condition occurs? </p>]]></description><guid isPermaLink="false">13560</guid><pubDate>Thu, 14 Jan 2016 20:46:40 +0000</pubDate></item><item><title>MS Security Endpoint Activity Reporting</title><link>https://www.windows-noob.com/forums/topic/12561-ms-security-endpoint-activity-reporting/</link><description><![CDATA[
<p>PCI requires the capability to report 90 days virus/malware activity reporting.</p>
<p> </p>
<p>By default SCCM/MS Security Endpoint appear to provide no more than 30 days when viewed in console.  If I view a report and specify a 90 day window, still only 30 days incidents are reported.</p>
<p> </p>
<p>Is anyone aware of methods to change logging to greater than 30 days?</p>
<p> </p>
<p>Thank you in advance.</p>
<p> </p>
<p>Dan Mahler</p>
<p>Grand Rapids, Michigan</p>
<p> </p>
]]></description><guid isPermaLink="false">12561</guid><pubDate>Thu, 18 Jun 2015 17:16:42 +0000</pubDate></item><item><title>Temporarily disable Endpoint Protection</title><link>https://www.windows-noob.com/forums/topic/7593-temporarily-disable-endpoint-protection/</link><description><![CDATA[<p>As an administrator, how can I temporarily disable Endpoint Protection on a single client? I would like to not allow users the ability, but to do it instantaneously from the server on a single client.</p>]]></description><guid isPermaLink="false">7593</guid><pubDate>Sun, 24 Feb 2013 22:08:19 +0000</pubDate></item></channel></rss>
