Guys, running a windows estate of ~ 1000 servers. On-Access scan is disabled and I want it enabled for security. That said, wondering what experienced people are doing around:
Microsoft publish this list of recommendations and a baseline one for Windows Servers here. Is there any guide on how to set them up specif to VSE or ENS though? MS mention exclusions but not sure if that means (in the VSE/ENS content) to use low risk processes that do not scan on read/write or exclude for all processes and ODS etc.
Anyone with experience managing VSE/ENS on a large server estate would be much appreciated. Particularly how you justify risk of exclusions etc.
Solved! Go to Solution.
Hi @shocko
For ENS:
How to improve performance with Endpoint Security 10.x
https://kb.mcafee.com/agent/index?page=content&id=KB88205
Consolidated list of Endpoint Security and VirusScan Enterprise exclusion articles
https://kb.mcafee.com/agent/index?page=content&id=KB66909
Here are the important take away’s from these KBs:
The above is only relevant for ENS OAS. For ODS you may need to add specific exclusions but typically the whole point of running the ODS task is to scan those locations that you've excluded from OAS scanning.
VSE is less intelligent than ENS. You should use low/ high risk profiles as with ENS so you can properly define a process exclusion. The main important thing to remember is that is you exclude i.e. test.exe within the default exclusions, this is a file exclusion only - the process will still be scanned. To exclude the process from being scanned, you need to define it as a low risk process and potentially disable scanning for low risk processes. For VSE systems you will need to add the recommended MS exclusions. However I would encourage a migration of those systems to ENS to benefit from the new features and scan architecture.
Hi @shocko
For ENS:
How to improve performance with Endpoint Security 10.x
https://kb.mcafee.com/agent/index?page=content&id=KB88205
Consolidated list of Endpoint Security and VirusScan Enterprise exclusion articles
https://kb.mcafee.com/agent/index?page=content&id=KB66909
Here are the important take away’s from these KBs:
The above is only relevant for ENS OAS. For ODS you may need to add specific exclusions but typically the whole point of running the ODS task is to scan those locations that you've excluded from OAS scanning.
VSE is less intelligent than ENS. You should use low/ high risk profiles as with ENS so you can properly define a process exclusion. The main important thing to remember is that is you exclude i.e. test.exe within the default exclusions, this is a file exclusion only - the process will still be scanned. To exclude the process from being scanned, you need to define it as a low risk process and potentially disable scanning for low risk processes. For VSE systems you will need to add the recommended MS exclusions. However I would encourage a migration of those systems to ENS to benefit from the new features and scan architecture.
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: