Centralized AV for Server 2012


Recommended Posts

Hello folks,

I'm just wondering if there is a AV product out yet that is designed for Server 2012 environments. I'd like to be able to deploy AV clients to Windows 7, Vista, and XP machines on my LAN via my Server 2012 box. Based on the small amount of reading I've done, FEP doesn't yet support Server 2012. Are there other alternatives?

Link to comment
https://www.neowin.net/forum/topic/1135814-centralized-av-for-server-2012/
Share on other sites

FEP is now System Center 2012 Endpoint Protection and does have support in System Center 2012 SP1 for both Win8 and Server 2012.

I haven't installed System Center yet, so I can't say how well it works or licensing for System Center itself. We have an EES Agreement for MS, so it's not bad for us.

I can't speak for alternatives. We just got Server 2012 installed around the first of the year and haven't got too in-depth yet.

Hello,

I would think that just about any anti-malware vendor that has a Microsoft Windows 8 compatible product out has a Windows Server 2012 compatible product out, or at least one that is going through the certification process right now.

Regards,

Aryeh Goretsky

Kaspersky Endpoint Security 10 for Windows (for file servers) supports Server 2012

http://support.kaspersky.com/kes10fs#requirements

Just go with Kaspersky.

Symantec Endpoint Protection 12.1.2 is also compatible (also a lot cheaper than Kaspersky)

http://www.symantec.com/business/support/index?page=content&id=TECH195325

http://www.symantec.com/connect/articles/latest-symantec-endpoint-protection-releases-symantec-endpoint-protection-121-ru2

ESET has solutions for server core, server, client, gateway etc supports the latest windows editions with remote administration and update mirroring.

please go with a better program than system center. I am testing out system center and I see it as a very unintuitive pain in the rear package. ease of use as well as ability to protect your systems should be your goal, and from what I am reading it can't protect your systems and it isn't very easy to use (initially).

please go with a better program than system center. I am testing out system center and I see it as a very unintuitive pain in the rear package. ease of use as well as ability to protect your systems should be your goal, and from what I am reading it can't protect your systems and it isn't very easy to use (initially).

Huh? How exactly is SCEP or FEP more complicated than any other antimalware package that has centralized control and reporting over multiple platforms? I've been using it since before it was integrated with SCCM 2007 R3, and SCEP/FEP itself is pretty damn easy to manage. You don't even require SCCM if you don't want centralized reporting, you can use a GPO instead (mind, I haven't bothered doing a GPO for it since SCCM 2012 was released).

I currently have SCEP deployed to over 500 systems running Mac OS 10.8, Mac OS 10.7, Windows 8 & 2012, Windows 7 & 2008 R2, and Red Hat Enterprise Linux. I'm extremely happy with it now that it supports every platform I also support. Any entity supports many platforms should definitely give SCEP consideration.

I won't deny that Configuration Manager as an entire entity is a beast, but I'd say the Antimalware components of it are pretty damn easy, and very powerful from an Administrative viewpoint.

FEP is now System Center 2012 Endpoint Protection and does have support in System Center 2012 SP1 for both Win8 and Server 2012.

I haven't installed System Center yet, so I can't say how well it works or licensing for System Center itself. We have an EES Agreement for MS, so it's not bad for us.

I have the EES Enterprise Agreement. If you are on this tier of the EES already, SCEP is extremely cheap to implement for desktops. You?ll probably just need one System Center Suite Standard or Datacenter license, and you can then use all aspects of System Center against your desktops. Costs may go up a fair bit however if you plan to support servers with it, as it?s highly unlikely your existing agreement covers server management CAL's unless some aspect of your infrastructure is already supported by System Center.

It?s been a very long time since I was on the EES Standard Agreement, but if you are on that agreement, you may find you only have partial desktop management coverage. It may cover part of System Center, but is unlikely to cover all of it. Either way, talk to your vendor to discover the limits of your existing agreement.

it is the sccm as a whole. it really is a pain...

Lets go into deploying a client...where is the verification in the admin console that it has been pushed successfully, it has been installed successfully, or if it failed for that matter. Lets go into managing a client that may or may not have the client pushed, how do you tell it was pushed, how do you tell it wasn't, how do you tell if it is in the process of. Lets go into attempting to view anything...connection fails because of a firewall issue..all the ports are open, hell the firewall is disabled...how can it be a firewall issue???

Just about every other management console based software has a way to monitor deployments from start to finish and have a way to be able to tell exactly what is stopping them for the admin to fix the issue. I have used many, kaseya, altiris, level platforms, and labtech and all of them you can tell what is going on at any given point during just about whatever you are doing and you get things like logs and error codes. If ms would just steal one of these management suites it would be beneficial to the rest of us.

If you care to prove differently I have a nice test environment that shows otherwise and would be more than happy to give you a brief tour of what I am complaining about.

  • 3 weeks later...

it is the sccm as a whole. it really is a pain...

Lets go into deploying a client...where is the verification in the admin console that it has been pushed successfully, it has been installed successfully, or if it failed for that matter. Lets go into managing a client that may or may not have the client pushed, how do you tell it was pushed, how do you tell it wasn't, how do you tell if it is in the process of. Lets go into attempting to view anything...connection fails because of a firewall issue..all the ports are open, hell the firewall is disabled...how can it be a firewall issue???

Just about every other management console based software has a way to monitor deployments from start to finish and have a way to be able to tell exactly what is stopping them for the admin to fix the issue. I have used many, kaseya, altiris, level platforms, and labtech and all of them you can tell what is going on at any given point during just about whatever you are doing and you get things like logs and error codes. If ms would just steal one of these management suites it would be beneficial to the rest of us.

If you care to prove differently I have a nice test environment that shows otherwise and would be more than happy to give you a brief tour of what I am complaining about.

Windows already has a gigantic servicing engine that logs just about anything, and an SCCM task sequence can monitor this - in addition, a task sequence that uses MDT integration offers even more (logging and TS customization). As someone who's used most of the deployment products out there at this point, SCCM is in fact at least as powerful and configurable, and the fact it's a lifecycle management product (versus just an OSD product) makes it (and SCEP) worth the price when coupled with the other products in the suite. If you need a management console to troubleshoot for you, you're already behind the 8 ball as you're trusting information from someone or something that may or may not be the OS making judgement calls on failures. Any SCCM OSD should have pre-flight checks so that if failures are going to occur, you catch (and log) them before you start touching the client machine to be (re)installed.

I'd put SCCM and SCEP (+DCM, NAP, and DA) up against any lifecycle management product any day of the week - heck, you get licensing to SCOM and Orchestrator as well with your System Center purchase, which also means endpoint monitoring, reporting, and automation as desired based on things like performance data, event logs, and DCM / NAP configuration.

Honestly, most environments that fail to get the most out of the System Center suite (especially with the 2012 version) comes down to the admins not knowing how to set it up and manage it properly, rather than the software.

We mainly use sccm for the remote control feature, a simple feature that any of these products support. Sccm fails at connecting almost 40 percent of the time. Some random error about firewall or network connectivity. I can connect with any other software pushing clients to the computer even connecting with rdp, but sccm ha an issue. This is random, sometimes it connects and sometimes it doesn't. If it can't do something this simple we cannot trust it to do anything else.

Firewall is not an issue, we completely disabled it as a test, Dns isn't an issue we can connect to the computer many different ways, network connectivity isn't an issue see previous comment. It doesn't give an error to properly troubleshoot this. We cannot trust a product like this but my predecessor decided this was a good product to go with and we are stuck with something that works half assed.

For craps and giggles, I created a 2012 sccm server in a test environment, that same issue may or may not be there but after I push there is no status on the console to tell you what/where the install is or if it failed or succeeded. He'll I can push to a pc that has been retired, no error no status, nothing. And you probably will see this as no problem....while this is a small environmental test of around 50 live, the production is several thousand some are turned off in the it closet that won't be deployed. The push from sccm is very poorly designed. I would even say the the remote tools also fall in that category. I wouldn't trust this for a proper inventory or to push packages out.

I deal with environments of 100,000 PCs or more, and setting up reporting (real time and otherwise) isn't that hard. Push works fine, and reporting does too. If you're seeing retired machines still in SCCM, or having issues pushing packages, that would be an issue to be investigated. Perhaps it's easier for me because I do it for a living and know how to use SQL reporting and SQL in general.

It is very easy for me to recommend other utilities because I too do it for a living and have been exposed to many tools not just given one package and told to deal with it. I see it from the user side, the admin side, and the tech side. I can't say with 100% certainty that this package is good or worth the money. I have seen many packages from initial testing to production roll out and have trained many. I can tell you in this environment this system doesn't work properly. it is my first go at sccm which was preinstalled to me coming in and dealing with it. From what I see this is a very cumbersome, unfriendly, and near hostile piece of software. For a tool that is supposed to help you it does a lot of fighting against you and makes you job counter productive.

I can honestly say the Sophos, still, by far was the easiest to setup and configure. I have been busy testing AV suites over the past few days and I still vote for Sophos for large networks.

Sophos might be easy to set up, but it's performance impact compared to just about any other A/V product is pretty horrible. There's more to an A/V product than how easy it is to manage.

For what it's worth, other than FEP/SCEP, the very latest Symantec A/V release (12.1.2) actually has a very light performance impact for a good A/V product.

Sophos might be easy to set up, but it's performance impact compared to just about any other A/V product is pretty horrible. There's more to an A/V product than how easy it is to manage.

For what it's worth, other than FEP/SCEP, the very latest Symantec A/V release (12.1.2) actually has a very light performance impact for a good A/V product.

That was the opposite for my setup. Mine was very low resource usage.

  • 2 weeks later...

Hello folks,

I'm just wondering if there is a AV product out yet that is designed for Server 2012 environments. I'd like to be able to deploy AV clients to Windows 7, Vista, and XP machines on my LAN via my Server 2012 box. Based on the small amount of reading I've done, FEP doesn't yet support Server 2012. Are there other alternatives?

That's because FEP was pretty much replaced by System Center Endpoint Protection (it's the same product, actually) - it's why I'm having to get my feet wet with SCCM for my virtualization test lab. The test lab will have a mixed bag of Windows and Linux clients (I'm adding a Sabayon 11 client right now as I type this). I'm hoping to not need to do a kitchen-sink; preferably, I'll only need CM/EP and VMM along with their prereqs. I have SQL Server 2012 Express SP1 installed with the defaults (it will only be used by System Center). Now I'm trying to figure out the proper settings for SCVMM to link to the SQL Server Express DE - for some reason, I get no warnings, yet the install always bombs connecting to the DE.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • While LibreOffice is not pleased to see a new competitor, they are absolutely correct in stating that Euro-Office using a MS file standard as a default is not being truly "European." Using a MS standard just means Euro-Office is just a "bastardized MS Office Suite." (Wasn't a major purpose of Euro-Office was to get away from being captive and enslaved to MS's Office Suite??)
    • Microsoft continues its long-term policy of spying on their users--despite vehement denials. That feature will be disabled (or removed) either "elegantly" with MS providing a true way to disable it, or "quick and dirty" via a third-party who WILL come up with a way to disable it. Your choice MS...
    • Helium Browser 0.13.3.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.3.1 changelog: f53b28d update: helium 0.13.3.1 (#292) b3cbb2ba revision: bump to 3 (#1925) bcacb8c7 chromium: update to 149.0.7827.114 (#1924) Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft Weekly: Xbox exclusives are back, big Windows app updates, and more by Taras Buria This week's news recap is here. Microsoft is returning to XBOX exclusives, Windows 11 gets new preview builds, the Low-latency Profile is here, big updates for inbox Windows apps, Patch Tuesday updates, and more. Quick links: Windows 10 and 11 Windows Insider Program Updates are available Reviews are in Gaming news Great deals to check Windows 11 and Windows 10 Here, we talk about everything happening around Microsoft's latest operating system in the Stable channel and preview builds: new features, removed features, controversies, bugs, interesting findings, and more. And, of course, you may find a word or two about older versions. The June 2026 Patch Tuesday updates are now publicly available. Windows 11 users can download KB5094126, which introduces plenty of new features and security updates, including the Low-latency Profile for better performance, shared Bluetooth audio support, and more. Windows 10 users with PCs enrolled in the Extended Security Update program can download KB5094127. In addition, Microsoft released new Defender updates for its operating systems. Speaking of Defender, Microsoft will now deliver EDR updates via Microsoft Update for faster security improvements independent of Patch Tuesday updates. Following the release of this month's Patch Tuesday updates, Microsoft also published new Windows 11 images available in the Media Creation Tool app. Now, you can create bootable USB media for clean Windows 11 installations with the latest releases. Some unfortunate stuff is going on with certain PCs from Dell and HP. Dell acknowledged that the SupportAssist bug causes black screens of death, while HP systems are suffering from Secure Boot update issues and boot loops. Both companies issued official advisories. Windows Insider Program Here is what Microsoft released for Windows Insiders this week: Builds Canary Channel Builds 29610.1000 and 28120.2302 This week's "Canary" builds only contain performance improvements and fixes, including the Low-latency mode, which is now available in the Stable channel for all Windows 11 24H2 and 25H2 users. Dev Channel Build 26300.8687 Microsoft brought some useful File Explorer changes with this build. You can now open folders in a new tab by middle-clicking them in the address bar. Beta Channel Build 26220.8680 and 28020.2298 Screen Tint, improved Windows Widgets, and other enhancements are included in this week's Beta releases. Release Preview Channel Builds 26200.8728 and 26100.8728 These builds also feature better widgets, new Windows Update controls, point-in-time restore, File Explorer improvements, and more. In addition to new Windows 11 preview builds, Microsoft announced that inbox Windows 11 apps now have their dedicated release notes in the official documentation. Also, Microsoft dropped massive feature updates for six apps, including Paint, Clock, Calculator, Camera, Media Player, Photos, and more. Updates are available This section covers software, firmware, and other notable updates (released and coming soon) delivering new features, security fixes, improvements, patches, and more from Microsoft and third parties. Google has some bad news for those still using MV2-based extensions in Chromium-based browsers, particularly Chrome. The company is now removing flags responsible for Manifest V2-based extensions (uBlock Origin is one of the most popular). However, some browsers resist this change, and Opera issued a statement that it will allow users to continue using MV2 extensions for as long as possible. While Microsoft is still not ready to share new details about MV2 extensions in Microsoft Edge, the company shared important details about the way it will be updating the browser going forward. Now, Microsoft wants to update Edge every two weeks across all platforms instead of the current four-week schedule (only the Extended Stable is exempt from this change). This week, Microsoft confirmed a useful new Teams feature that is coming to the messenger soon. It also detailed all the improvements that made the platform better for users in 2026. However, not all changes are great, as the company is moving ahead with the check-in feature, which many believe will lead to employee monitoring. PowerToys received a feature update this week. Version 0.100 arrived with a big rework for the Shortcut Guide, a new extension gallery for Command Palette, new Dock features, and plenty of other changes. Here are other updates and releases you may find interesting: Microsoft is bringing big performance improvements to OneDrive on Mac Popular Windows 11 file manager Files gets improved tags, layouts, and a new OneDrive icon New Outlook for Windows and Web is getting a simple but very useful email feature Microsoft had to shut down 70+ GitHub repos after getting hacked, bringing back some Microsoft AI boss no longer believes that AI will replace human workers Microsoft wants to end printer driver headaches with Windows Ready Print SQL Server Management Studio 22.7 brings "What's New" page, T-SQL formatting, and lots more Microsoft releases Visual Studio Code 1.124 with smarter autonomous AI agents Windows Server gets DNS over HTTPS (DoH) support Here are the latest drivers and firmware updates released this week: NVIDIA 610.52 Hotfix with multiple fixes for black screens of death, sleep issues, G-SYNC, and more. Reviews are in Here is the hardware and software we reviewed this week Steven Parker reviewed a rather unorthodox device here on Neowin this week. He took for a spin the DWARF mini, the world's smallest smart telescope for night and day sky captures. It tracks objects in the sky, has a sun filter, and has a low learning curve. There is also nice build quality and a quite affordable price. Pulasthi Ariyasinghe reviewed 007 First Light. The game turned out to be a satisfying spy adventure in the James Bond universe with great gunplay and combat, impressive crowds, over-the-top action sequences, and more. There are a few quirks here and there, but overall, the game scored high on our scale. On the gaming side Learn about upcoming game releases, Xbox rumors, new hardware, software updates, freebies, deals, discounts, and more. Microsoft held the latest XBOX Games Showcase this week. There, the company announced plenty of cool stuff, including a remake of Halo: Combat Evolved, a special 25th anniversary XBOX Series X with a classic translucent green design (coming in November 2026), details about Gears of War: E-Day, Spyro: A Realm Beyond after nearly 20 years since the last release, a new Hellblade game from Ninja Theory, a new expansion for DOOM: The Dark Ages, fresh details about State of Decay 3, and even a new entry in the Crazy Taxi series. More improtantly for XBOX fans, Microsoft announced the return of XBOX exclusives, with Gears of War: E-Day and Clockwork Revolution kicking it off. Microsoft also has some good news for Nintendo Switch 2 owners. Minecraft is coming natively to the second-gen Switch, offering better performance and new features, including the visual overhaul called "Vibrant Visuals." Playground Games revealed a 30-minute gameplay video of the upcoming Fable, showcasing combat, action, NPC simulation, relationships, and player choices. Additionally, the studio confirmed a bug with Forza Horizon 6 wiping saves for some gamers. It also had to shut down one of the game's online modes after users discovered an infinite money glitch. NVIDIA announced new games for the GeForce NOW streaming service and a big Summer sale that lets you get 12 months of GeForce NOW for $35 or $70 less, depending on the tier. Speaking of discounts, check out this week's Weekend PC Game Deals article, full of discounts and the latest freebies from the Epic Games Store. Great deals to check Every week, we cover many deals on different hardware and software. The following discounts are still available, so check them out. You might find something you want or need. GIGABYTE Radeon RX 9070 XT Gaming OC ICE 16G - $649.99 | 13% off 1TB Samsung T7 Portable SSD - $189.98 | 31% off AirPods Pro 3 - $179 | $50 off Edifier R1280Ts Powered Bookshelf Speakers - $129.99 | 24% off This link will take you to other issues of the Microsoft Weekly series. You can also support Neowin by registering for a free member account or subscribing for extra member benefits, along with an ad-free tier option.
    • Microsoft Flight Simulator's City Update 15 enhances Midwest cities by Pulasthi Ariyasinghe The third major city update of the year has landed for the original Microsoft Flight Simulator and the 2024 release. The latest drop is upgrading the visuals and regional accuracy of three metropolitan regions in the American states of Illinois, Minnesota, and Wisconsin. The 15th city update is adding eight new areas of interest that have been enhanced with high-fidelity TIN (triangulated irregular network) surface texturing in the mentioned regions. The free update highlights Chicago, Elgin, Cicero, and Arlington Heights in Illinois, as well as Minneapolis, St. Paul, Bloomington, Duluth, Brooklyn Park, Woodbury, Lakeville, Plymouth, and Blaine in Minnesota. In Wisconsin, the development has also upgraded the lands and buildings of Milwaukee, Madison, and Racine. The update lands just as one of the world's largest enthusiast flight simulation conventions, FlightSimExpo, kicks off in downtown St. Paul, Minnesota, on June 14. The Flight Sim development team's 40-minute keynote at the event can be watched here. At the same time, Microsoft is bringing the 6-seat, single-engine, multi-use light civil airplane Piper M600 into the game as a part of its Expert Series 2 program. This premium plane can be purchased from the in-game marketplace for $24.99. City Update 15: The United States Midwest is now available in Microsoft Flight Simulator, as well as the newer Microsoft Flight Simulator 2024, as an optional download. It can be accessed across Steam and the Microsoft Store for PC, Xbox Series X|S, and PlayStation 5, as well as Xbox and PC Game Pass subscriptions. Xbox One, mobile, and PC players can also jump into the new content using Xbox Cloud Gaming if they have a Game Pass Ultimate membership. The game must be updated to the latest version to download this free update from the in-game marketplace.
  • Recent Achievements

    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Year In
      Markus94287 earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      179
    3. 3
      PsYcHoKiLLa
      140
    4. 4
      ATLien_0
      91
    5. 5
      Steven P.
      78
  • Tell a friend

    Love Neowin? Tell a friend!