Administrator Guide
More Information: http://go.microsoft.com/fwlink/?linkid=37020&name=Virus:DOS/EICAR_Test_File&threatid=2147519003
Malware Severity: Severe
How to update antimalware denitions manually
By default, Endpoint Protection checks for updated antimalware denitions every eight hours. You should not need to update antimalware
denitions manually; this is optional.
Antimalware updates are applied automatically by Windows Server Update Services (WSUS). Part of the initial installation and setup of
Endpoint Protection included conguring WSUS to approve antivirus and antimalware updates automatically.
To update denitions manually, in the Operations console, do the following. We recommend that if you want to update antimalware
denitions manually, you do this outside of peak usage hours:
1 In the Monitoring workspace, expand Forefront Endpoint Protection. Select either Dashboard or Endpoints with FEP.
2 Multi-select the computers on which you want to update antimalware denitions.
3 In the Tasks pane, under Protected Endpoint Tasks, click Update Antimalware Denitions.
4 In the Update Antimalware Denitions dialog box, verify the list of target computers, and then click Run.
How to verify that updates are working
To verify that WSUS is applying current antivirus and antimalware denitions, review the logs in the Operations console:
1 In the Monitoring workspace, expand Forefront Endpoint Protection, and then click Security Events.
2 Look for Event ID (Event Number) 2000.
The following is a sample of a security event that shows the antimalware version number, with the current and previous signature version.
Figure 56. Verify updates are working
Managing certicates
It is recommended that you use a public key infrastructure (PKI) management tool to track the expiration and renewal of required
certicates. By default, this is not installed as part of Dell Hybrid Cloud System for Microsoft.
The following are common management tasks for certicates. You will need to perform most of these tasks at regular intervals.
126
Security