Endpoint Protection

 View Only
  • 1.  Symantec EndPoint Protection and SysPrep

    Posted Mar 21, 2010 10:38 PM
    I'd like to suggest a change for the Symantec EndPoint client.  In short, I'd like to suggest that you support Microsoft's SysPrep Provider feature (http://technet.microsoft.com/en-us/library/ee676646%28WS.10%29.aspx). 

    Supporting this feature would allow SysPrep to correctly remove the keys and files that Symantec suggests here (http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110510364248) in an automated and orderly fashion.  It would also allow Symantec to match the cleanup requirements to the currently installed client, since the provider can be updated as the cleanup requirements of the other client components change.  This provides a much better solution for administrators going forward than googling symantec.com and hoping you have found the most current instructions.

    If I were to spec this out, I would envision that Symantec's Sysprep provider would:

    Cleanup phase:
    Remove all log files
    Remove all events
    Empty the quarantine bin
    Remove any old versions of virus definitions
    (Optionally) remove current virus definitions

    Generalize phase:
    Remove all hardware id keys (registry and xml)

    Specialize phase:
    Create the new hardware id
    Trigger an immediate LiveUpdate call to get both the latest program updates and definitions.

    I'm tempted to write this myself as the basics of creating such a DLL are remarkably simple.  However, doing this outside Symantec is impractical.  In order to remove some of these keys/files, the related services must be shut down.  I (like many administrators) have toggled the switch from "Allow tampering" to "Disable Tampering."  As a result, shutting down those services is all but impossible.  Presumably a Symantec-provided solution could resolve that problem.

    Also (presumably) a Symantec solution would be more complete, since you would know where all the bodies (files, registry keys, etc) are buried.


  • 2.  RE: Symantec EndPoint Protection and SysPrep

    Posted Mar 21, 2010 11:25 PM
    Just wanted to let you know that you should post this in our ideas section of the forums. That way users can vote on it, and you can track the process as it is implemented. Ideas can be created here https://www-secure.symantec.com/connect/security/ideas . I think this is a good one, so if you don't end up posting it there I think I will come back and cut and paste your idea for you.

    Thanks
    Grant


  • 3.  RE: Symantec EndPoint Protection and SysPrep

    Posted Mar 21, 2010 11:56 PM
    I was not familiar with that section.  Thanks for pointing it out.

    Per your suggestion, I have copied this idea to https://www-secure.symantec.com/connect/idea/symantec-endpoint-protection-and-sysprep

    Anyone who uses SysPrep, or who is considering using it for Win7 deployments is encouraged to visit that link and click the "Agree" button.

    In a related question, is there a place for 3rd party add-ins for SEP?  If Symantec elects not to do this, or if there is likely to be a lengthy delay, I might be interested in creating this myself (as best I can).  But there's little point if I am the only person who would benefit from it.