Video Screencast Help

Scheduled report question about PCs on network without SEP

Created: 27 Jan 2012 | 6 comments

We have about 600 PCs on the network that should have SEP installed on them however some PCs get deployed without it. To find them, we have to perform a "Find unmanaged computers" operation and provided the IP ranges for SEP to scan. This is time consuming and the results cannot be exported to another file. Is it possible to schedule this as a weekly or monthly job? 

Basically, I want to create a task that finds unmanaged computers on the network and email me a report. Is this possible?

Comments 6 CommentsJump to latest comment

Mithun Sanghavi's picture

Hello,

There is a feature of "Unmanaged Detector", check these Articles:

What does it mean to set a client as an Unmanaged Detector?

http://www.symantec.com/docs/TECH105722

Best Practices: When to use the "Find Unmanaged Computers" or "Unmanaged Detector" features in Symantec Endpoint Protection 11.0

http://www.symantec.com/docs/TECH104340

Find Unmanaged Clients on a remote network location using the Unmanaged Detector

http://www.symantec.com/docs/TECH96234

Setting notifications when using the "Unmanaged Detector" feature in the SEPM

http://www.symantec.com/docs/TECH104897

 

Hope that would help you !!!

Mithun Sanghavi
Senior Consultant
MIM | MCSA | MCTS | STS | SSE | SSE+ | ITIL v3

Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

Silverfuel's picture

Thanks. How exactly does the unamanged detector work? Does it scan IP ranges at random times of unmanaged PCs? Can I schedule those times?

Srikanth_Subra's picture

Iam also expecting..can u explain little bit?

Thanks & Regards,

 Srikanth.S

"Defeat the Defeat before the Defeat Defeats you"
(Swami Vivekananda)

Simpson Homer's picture

the unmanaged detector works on a local network and looks at ARP traffic on that subnet to determine whether or not a client is running SEP. If its not running SEP, we report it back to the SEPM and it will appear in the security report (you can also configure notifications for this). Two things to bear in mind:

1. This works on a per subnet basis - you need a detector in each subnet your company has to guarantee coverage
2. This won't detect clients that have SEP installed but are not managed by your SEPM (either "unmanaged" SEP clients or other companies SEP clients because we look to see if SEP is *installed* There are things we can potentially do in the future, depending on how the feature evolves and what customers request.

 

 

https://www-secure.symantec.com/connect/forums/what-unmanaged-detector

https://www-secure.symantec.com/connect/forums/unmanaged-detector-usage

https://www-secure.symantec.com/connect/forums/unmanaged-detector-why-isnt-working

http://www.anti-malware.ru/pda/index.php?act=attach&type=post&id=3530

Srikanth_Subra's picture

Thanks for your info...

Thanks & Regards,

 Srikanth.S

"Defeat the Defeat before the Defeat Defeats you"
(Swami Vivekananda)