Endpoint Protection

 View Only
  • 1.  Policy settings

    Posted Feb 19, 2014 11:21 AM

    My SEPM Server is a Windows Server 2008 SP2, 64bit - SEPM is 12.1.2015.2015. I am having issues with some of the policy that are setup correctly on the SEPM by is not correct ion the registry on the client....

    Example:

    Check Content:

    Server check:  From the Symantec Endpoint Protection Management Server, Symantec Endpoint Protection Management Console:  Select Policies -> Double-click the applied policy -> Under Windows Settings, Scheduled Scans -> Select Administrator-Defined Scans -> Double-click the Weekly Scan -> under the Notifications tab, Notifications -> Ensure "Display a notification message on the infected computer" is selected.

    Criteria:  If "Display a notification message on the infected computer" is not selected, this is a finding.

    On the client machine, use the Windows Registry Editor to navigate to the following key:

    32 bit:

    HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\AV\Scheduler\{SID}\Custom Tasks\{scan ID}

    64 bit:

    HKLM\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\AV\Scheduler\{SID}\Custom Tasks\{scan ID}

    Criteria:  If the value MessageBox is not 1, this is a finding.

    Fix Text:

    From the Symantec Endpoint Protection Management Server, Symantec Endpoint Protection Management Console:  Select Policies -> Double-click the applied policy -> Under Windows Settings, Scheduled Scans -> Select Administrator-Defined Scans -> Double-click the Weekly Scan -> Under the Notifications tab, Notifications -> Select "Display a notification message on the infected computer".

     

    Setting on SEPM is selected, but client shows MessageBox as 0

     

    I have about 23 settings like this... any insight ?



  • 2.  RE: Policy settings

    Posted Feb 19, 2014 11:27 AM

    An obvious question but I assume you did confirm the policy showing in the clients matches that in the SEPM? I'm sure you did but let's get that out of the way first .

    Another thing to do would be run sylink debugging so it picks up the policy change, need to ensure it's properly coming down.

    Just testing and I made the same changes and the "MessageBox" key did not change for me either. You sure this the correct key to look at?



  • 3.  RE: Policy settings

    Posted Feb 19, 2014 12:09 PM

    Regedit on the SEPM and Client show the same. will run the sylink to see what come back..



  • 4.  RE: Policy settings

    Posted Feb 19, 2014 12:12 PM

    Just wondering if that is the right reg key. I tested the same thing but it never changed.