Forefront Client Security - Security State Assessment ForumDiscussions around the security state asessment, including feedback on existing checks and requests for new checks© 2009 Microsoft Corporation. All rights reserved.Fri, 20 Nov 2009 12:30:39 Ze3d11ddb-4da1-4def-a6c1-49ae5f8e5a29http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/2ae687a9-a3be-4b39-b8b6-903fc5791f24http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/2ae687a9-a3be-4b39-b8b6-903fc5791f24Jono2phttp://social.technet.microsoft.com/Profile/en-US/?user=Jono2pI need to exclude some checks reported by the Security State Assessment check.I work in an organisation with approx 5000+ clients. We are in the process of migrating to Microsoft Forefront from McAfee. When I run the 'Security State Assessment Summary', there are a few checks which I would like to disregard. For example, each client machine has a built in Admin/special account logins which are set to never expire. These are bing flagged by the vulnerability report. Also, certain generic 'autologon' machines are being flagged that we have setup.<br/><br/>Is there a way to exclude these and other checks from the SSA scan?Thu, 12 Nov 2009 11:34:36 Z2009-11-20T12:30:39Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9caec6ee-8c7e-4e04-9a7f-8125d3433ed1http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9caec6ee-8c7e-4e04-9a7f-8125d3433ed1District1http://social.technet.microsoft.com/Profile/en-US/?user=District1Unnecessary Local Administrator CheckSeveral of the workstations in my network are reporting back as &quot;medium&quot; because they are failing the &quot;number of uncessary Local Administrators&quot; check, with a value of &quot;2&quot;.<br/><br/>In each case, the default Administrator account is disabled. We've created a default user account to be a local admin account on each workstation (so that we can script the password change every 3 months) and those two are the only accounts (other than the standard Domain Admins account). <br/><br/>The clients are all Vista x64 boxes, with the latest service patch. FCS has been patched up fully, and works fine.<br/><br/>Do I need to re-enable the local admin accounts and get rid of the default user account? I'm not sure why that's any tighter, security-wise, especially since the local administrator account can't be locked out. <br/><br/>Thoughts? Thu, 09 Jul 2009 22:35:18 Z2009-11-19T08:33:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/3e0cb979-eb39-4f17-9ec0-c595e6866c52http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/3e0cb979-eb39-4f17-9ec0-c595e6866c52thenninghttp://social.technet.microsoft.com/Profile/en-US/?user=thenningAutologon is not configured, but a plaintext password might be exposed on this computer.I have a lot of computers showing up under the Autologon Vulnerability report, none of them actually have autologon enabled.  But they show this error - Autologon is not configured, but a plaintext password might be exposed on this computer.<br/> <br/> I clicked the more link on the report and it pointed me to an article on turning off the autologon.  But says nothing about how to resolve this issue.<br/> <br/> Any ideas?  It's making my numbers for vulnerabilities higher than it needs to be.<br/> <br/> thanksFri, 07 Aug 2009 22:39:57 Z2009-11-10T14:33:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/1e029e8b-32f2-40aa-bd47-532f8294f1bchttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/1e029e8b-32f2-40aa-bd47-532f8294f1bcMeMe12http://social.technet.microsoft.com/Profile/en-US/?user=MeMe12Microsoft Forefront Client Security Antimalware Service not installedAfter install FF I cannot find Microsoft Forefront Client Security Antimalware Service! <div>Every time system boot will show error : application failed initialize...</div> <div>Uninstall it and install again. The service still not installed?</div> <div>Why?</div>Tue, 27 Oct 2009 02:37:14 Z2009-10-28T07:28:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6eca1aa1-4a9c-43ef-afb7-6bc361d3ec06http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6eca1aa1-4a9c-43ef-afb7-6bc361d3ec06uamstekhttp://social.technet.microsoft.com/Profile/en-US/?user=uamstekAgent Helper.exeIs this Resource Kit utility supposed to be able to run on the version of MOM that comes with Forefront?Fri, 23 Oct 2009 14:00:17 Z2009-10-30T02:57:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/8ebb350c-09dc-4475-95db-e4f769ecbb7bhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/8ebb350c-09dc-4475-95db-e4f769ecbb7bhowardmphttp://social.technet.microsoft.com/Profile/en-US/?user=howardmpShares Check - no reports ? Hello All,<br>I'm looking through my Security State Assessment reports, but can't see the Shares Checks for any of my machines. any ideas what I should do to make them visible?<br><br>I'm running FCS SP1<br><br>thanks<br>Howard Wed, 18 Feb 2009 13:19:26 Z2009-10-23T12:49:16Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/d3ecd627-bab2-4d57-81cd-7ebff772725fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/d3ecd627-bab2-4d57-81cd-7ebff772725fcalitech1http://social.technet.microsoft.com/Profile/en-US/?user=calitech1How do I get MSAT. I can't find I valid link to download from MicrosoftI want to download the MSAT to test it out, but I can't find a good link to get the download. Can someone give me a correct link. <br />Thanks. <br /><br />If I am in the wrong group tell me what groups I should post in. <br /><br />Link1: <a href="https://partner.microsoft.com/40081388?msp_id=msat">https://partner.microsoft.com/40081388?msp_id=msat</a><br /><br />Link2: <a href="http://technet.microsoft.com/en-us/security/cc185712.aspx">http://technet.microsoft.com/en-us/security/cc185712.aspx</a><br />Mon, 12 Oct 2009 22:50:40 Z2009-10-26T01:58:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/e937718a-6352-4212-acac-5c147c234c6ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/e937718a-6352-4212-acac-5c147c234c6eTRC ENGhttp://social.technet.microsoft.com/Profile/en-US/?user=TRC%20ENGMSATThe link for MSAT does not work. Where can I get the app?Tue, 13 Oct 2009 17:47:04 Z2009-10-14T03:51:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/35c48de8-7a52-4c22-91ae-b5d9f210c744http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/35c48de8-7a52-4c22-91ae-b5d9f210c744LA1976http://social.technet.microsoft.com/Profile/en-US/?user=LA1976Update forefront vulnerability engine<p>Forefront <a style="color:#3264c8;cursor:pointer" tabindex=7>Vulnerabilities Engine Deployment Status</a> shows that my machines have old engines. After installing Definition Update for Microsoft Forefront Client Security (Security State Assessment 1.0.1710.103 Full) I still have the engines with an old version. <br/><br/>I read some articles how to manually update the engine but this have not worked. Can this be done automatically some how?<br/><br/>Now I have copied the manifest file from the C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\Updates\Patch-1.0.1710.103 folder <br/><br/>I also copied the dlls to the C:\Program Files\Microsoft Forefront\Client Security\Client\SSA folder.<br/><br/>Then I restarted the server and editted the registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Forefront\Client Security\1.0\SSA and changed the WorkingManifestVersion to  1.0.1710.103<br/><br/>This however is not something I want to do on 200 machines.... <br/></p>Wed, 30 Sep 2009 12:46:38 Z2009-10-09T11:35:43Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/af267269-7681-4d56-85f3-5adb5a347b89http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/af267269-7681-4d56-85f3-5adb5a347b89nnassifhttp://social.technet.microsoft.com/Profile/en-US/?user=nnassifCan not install Security state assessment version 1.0.1710.103 on VistaHi,<br/>i've tried many times to install this update but still got the error code 80070003. With the help I followed the instruction by deleting all the update log. But still after it won't install. Please help me out with this situation. ThanksFri, 28 Aug 2009 00:45:51 Z2009-10-31T20:08:32Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/5c7be921-9f4a-4413-a2fc-4994a69861d7http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/5c7be921-9f4a-4413-a2fc-4994a69861d7sejonghttp://social.technet.microsoft.com/Profile/en-US/?user=sejongSecurity State Assessment Service policy applied with errorsI intsalled Forefront Client Security on Windows Server 2008 R2 RTM using the /NOMOM switch because this is a standalone intallation.  Each time the <span style="font-size:x-small">Security State Assessment Service (FcsSas) starts, it records event 10006 (<span lang=EN>Forefront Client Security State Assessment Service policy applied with errors. Reverted to the following settings: Schedule Type: Interval Time: 12 Parameter: ).<br/><br/>There is no option in the FSC console to run a Security State Assessment scan.<br/><br/>Is this behavior expected?  Are Security State Assessment scans available only in a managed environment?<br/><br/>Thanks.</span></span>Fri, 21 Aug 2009 13:56:42 Z2009-10-31T20:08:26Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6615e91a-c8ee-4097-a769-9741bbd57cffhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6615e91a-c8ee-4097-a769-9741bbd57cffsue10http://social.technet.microsoft.com/Profile/en-US/?user=sue1032 bit or 64 bit<p>How can I find out if my computer will work with 32 or 64 bit? can anyone inform pse? I downloded 64 bit but I'm not sure. Tks.</p>Sun, 14 Jun 2009 11:29:02 Z2009-10-31T20:08:29Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6a486ad1-517e-43c5-833d-c314ed518631http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6a486ad1-517e-43c5-833d-c314ed518631Pablo Lopezhttp://social.technet.microsoft.com/Profile/en-US/?user=Pablo%20LopezForefront Client Security State Assessment ServiceHi!<br><br>I have this error when I try to install the FCSSA in a Windows 2000 Server:<br><br> <p>MSI (s) (94:1C) [10:08:55:135]: Executing op: ComponentUnregister(ComponentId={B7296B3B-7EED-4BED-A7A0-B15277D85ECD},ProductKey={E8B56B38-A826-11DB-8C83-0011430C73A4},BinaryType=0,)<br>MSI (s) (94:1C) [10:08:55:151]: Executing op: ComponentUnregister(ComponentId={2DDC2983-09EF-4C0E-BA73-D6BA29B923CE},ProductKey={E8B56B38-A826-11DB-8C83-0011430C73A4},BinaryType=0,)<br>MSI (s) (94:1C) [10:08:55:151]: Executing op: End(Checksum=0,ProgressTotalHDWord=0,ProgressTotalLDWord=0)<br>MSI (s) (94:1C) [10:08:55:151]: Error in rollback skipped. Return: 5<br>MSI (s) (94:1C) [10:08:55:151]: Unlocking Server<br>MSI (s) (94:1C) [10:08:55:151]: PROPERTY CHANGE: Deleting UpdateStarted property. Its current value is '1'.<br>MSI (s) (94:1C) [10:08:55:167]: Note: 1: 1708 <br>MSI (s) (94:1C) [10:08:55:167]: Producto: Microsoft Forefront Client Security State Assessment Service -- Error en la operación de instalación.</p> <p>MSI (s) (94:1C) [10:08:55:167]: Cleaning up uninstalled install packages, if any exist<br>MSI (s) (94:1C) [10:08:55:167]: MainEngineThread is returning 1603<br>MSI (s) (94:64) [10:08:55:167]: Destroying RemoteAPI object.<br>MSI (s) (94:B0) [10:08:55:167]: Custom Action Manager thread ending.<br>MSI (c) (AC:FC) [10:08:55:182]: Decrementing counter to disable shutdown. If counter &gt;= 0, shutdown will be denied.  Counter after decrement: -1<br>MSI (c) (AC:FC) [10:08:55:182]: MainEngineThread is returning 1603<br>=== Verbose logging stopped: 27/03/2009  10:08:55 ===<br><br>Can anybody help me with this, please!!??</p> <p>Thanks a lot!!</p>Fri, 27 Mar 2009 16:36:54 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/e84d079a-d3cc-4ec8-a406-12f25c115554http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/e84d079a-d3cc-4ec8-a406-12f25c115554dburkleyhttp://social.technet.microsoft.com/Profile/en-US/?user=dburkleyPrevent Security State Assessment "Succesful scan" events while still reporting the results of the scan<p>Is there a way to prevent Security State Assessment &quot;Succesful scan&quot; events while still reporting the results of the scan.</p>Wed, 24 Jun 2009 20:11:57 Z2009-10-31T20:08:32Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/63d4bc39-a304-438f-80ce-98ba00823100http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/63d4bc39-a304-438f-80ce-98ba00823100moritZeeri3http://social.technet.microsoft.com/Profile/en-US/?user=moritZeeri3question regarding windows password schemeHi guys, <br/> <br/> Im interested in learning security stuff, Im just wondering, how windows saves our password in the system?<br/> in some other websites, it says that windows doesnt use salt to the password scheme? and I cant find the answer as well. hope you guys can tell me this stuff.<br/> I know that windows uses the NThash for the password. but then the idea of salt is also good to enhance the security. why why why windows doesnt use it???<br/> <br/> Thanks guysSat, 16 May 2009 02:11:03 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/d24b10ef-9ce4-4c3a-af08-da0e82676cbbhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/d24b10ef-9ce4-4c3a-af08-da0e82676cbbtuantuan6688http://social.technet.microsoft.com/Profile/en-US/?user=tuantuan6688chi emAnh Tuan<font style="font-size:10px"></font><font style="font-size:12px"></font>Fri, 27 Mar 2009 19:41:51 Z2009-04-02T21:19:26Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/4bd94f05-b7e2-4da1-898b-ccc9719b4c15http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/4bd94f05-b7e2-4da1-898b-ccc9719b4c15Superpapihttp://social.technet.microsoft.com/Profile/en-US/?user=SuperpapiCannot start FirewallHello<br>I cannot restart the firewall. The message says the Firewall doesn't use the recommended parameters. When I click update th parameters now then I get the message the parameters cannot be displayed because the associated servcice is not running. Would you like to restarty the Firewall.<br>When I click yes I get again the message the firewall cannot be started.<br><br>I am running Vista pro on my Netbook.<br><br>Thanks for your help<br><br>Superpapi<br>Fri, 06 Mar 2009 17:17:36 Z2009-10-31T20:08:31Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/7fb3ebe2-7bfd-4d17-8d5c-949abebc1a0fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/7fb3ebe2-7bfd-4d17-8d5c-949abebc1a0fMaria Chavezhttp://social.technet.microsoft.com/Profile/en-US/?user=Maria%20ChavezI am lost... what does it mean "No threads found for user?" I am lost... what does it mean &quot;No threads found for user?&quot;Thu, 11 Dec 2008 19:39:17 Z2009-10-31T20:08:31Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/5be2e94c-f05a-47d3-a663-3be74978fb8dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/5be2e94c-f05a-47d3-a663-3be74978fb8dKumar Ashwinihttp://social.technet.microsoft.com/Profile/en-US/?user=Kumar%20AshwiniWant to allow only Aim Messanger for in ISA serverHi Everyone !!<br><br>I have ISA server 2006, In my Network every sites are restricted as per the policy. Now I have the requirement to Enable AIM Chat for all the users. <br><br>Please suggest the procedure ..........<br><br>Regards,<br>Ashwini<br><hr size="1" align="left" width="25%">Know more about Messaging :-)Tue, 30 Sep 2008 19:59:57 Z2009-10-31T20:08:29Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9edf9d27-94bf-45f4-8c0d-04fd1b4363f4http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9edf9d27-94bf-45f4-8c0d-04fd1b4363f4Brian H_http://social.technet.microsoft.com/Profile/en-US/?user=Brian%20H_SSA causing File Server to hangAfter working with Microsoft Premier support on an issue of a File server hanging every day around the same time for a few minutes we have discovered the problem appears to be SSA. As soon as I disabled it we have no longer had  the hangs. We were having them every day around the same time in the morning and occassionally 12 hours later which was the interval SSA was being performed at. Tue, 21 Oct 2008 12:33:31 Z2009-10-31T20:08:27Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/e4ef8e86-10ac-4c0a-8941-fb2fc6dafe97http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/e4ef8e86-10ac-4c0a-8941-fb2fc6dafe97Interactive Networkshttp://social.technet.microsoft.com/Profile/en-US/?user=Interactive%20NetworksFalse Virus Alarm <b>Hello,<br><br>This is Cristina from Customer Service Department of Interactive Networks. Our company develops instant messaging software and we have recently received a report from one of our customers about a false virus detected by Forefront Client Security software in one of our files.<br>The name of the file is &quot;bircd.exe&quot; and it is part of the IRC component integrated in one of our chat modules. <br>I have been trying to reach Forefront Client Security support people but it was not possible, I have just received automatic replies.<br>Our customers need a quick solution since they are no longer able to use our product because of this false alarm.<br>Who should I contact to help me out with this? <br><br>Thank you.<br><br>Cristina<br>Interactive Networks Inc.<br></b><a href="mailto:crodriguez@interactiveni.com"><b>crodriguez@interactiveni.com</b></a><b> </b>Thu, 21 Aug 2008 14:22:02 Z2009-10-31T20:08:31Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/cba10c6f-1b00-43b0-950a-fbe52417a8eehttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/cba10c6f-1b00-43b0-950a-fbe52417a8eeD Marrahttp://social.technet.microsoft.com/Profile/en-US/?user=D%20MarraScheduling of SSA scansIs there a way to change the schedule of when the SSA scan occurs on an unmanaged client?<br>We are working on the management server, but everything is not in place for it yet. I have several users who report slow downs and each time I've looked it is during an SSA scan. I'd like to be able to change what time it runs to the wee hours of the morning so as to not disturb my users. <br><br>Thanks.Mon, 08 Sep 2008 17:57:10 Z2009-10-31T20:08:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/2f3a1f3c-7756-4b7a-8fe6-88e069fe47d0http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/2f3a1f3c-7756-4b7a-8fe6-88e069fe47d0andy astleyhttp://social.technet.microsoft.com/Profile/en-US/?user=andy%20astleyFCS Install; Reports database is removed by upgrading SQL 2005 with SP2 - On 2008 Server. Hi I am testing FCS on WIN 2008 in a test environment prior to deploying;<br><br>I am unable to install <span class=RadEWrongWord id="RadESpellError_1">FCS</span> after upgrading <span class=RadEWrongWord id="RadESpellError_2">SQL</span> 2005 with <span class=RadEWrongWord id="RadESpellError_3">SP2</span> (The reports Database disappears) and <span class=RadEWrongWord id="RadESpellError_4">FCS</span> fails when it tries to authenticate to the Reports Database &amp; will not let me proceed<br><br>Can anyone help?<br><br>Thanks<br><br>Andy Tue, 16 Sep 2008 18:14:21 Z2009-10-31T20:08:29Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9f33514d-4c04-41aa-ae2d-42997885d3cchttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9f33514d-4c04-41aa-ae2d-42997885d3ccbeythttp://social.technet.microsoft.com/Profile/en-US/?user=beytISA 2004 Error Code 403 forbidden <span style="font-size:10pt;font-family:'Arial','sans-serif'">Hi! I’m Hobert from the Philippines and I am new in handling ISA Server 2004. I am seeking for an advice for the error that all the clients are receiving. When they click for a browser, more often it gives the ERROR CODE 403 FORBIDDEN. THE ISA SERVER DENIED THE SPECIFIED UNIFORM LOCATOR (URL) (12202). By the way, our ISA server is a member of the domain, and is configured as Edge Firewall.</span>Wed, 25 Jun 2008 23:59:10 Z2008-07-14T16:47:18Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/3fe90f61-abc1-40f9-8d67-8880af61c80dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/3fe90f61-abc1-40f9-8d67-8880af61c80dLudwinhttp://social.technet.microsoft.com/Profile/en-US/?user=LudwinError with Deploy Policy on Microsoft ForeFront Client Security<p align=left><font face=Arial size=2>Hi, I have this error when I try to deploy policy on Microsoft ForeFront Client Security:</font></p> <p align=left> </p> <p align=left>Microsoft Forefront Client Security:</p> <p align=left>=========================</p> <p align=left> </p> <p align=left>The policy cannont be deployed.</p> <p align=left>Futher details:<br>Unable to create new group policy object.<br>The specified domain either does not exist or could not be contacted. (Exeption from HRESULT: 0x8007054B)</p> <p> </p> <p align=left>Could you help me?</p>Wed, 28 May 2008 14:20:16 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/a7b493c9-0211-4423-9b97-48f754e2ab0chttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/a7b493c9-0211-4423-9b97-48f754e2ab0cAndrew Brennerhttp://social.technet.microsoft.com/Profile/en-US/?user=Andrew%20BrennerThis forum is moving the week of 5/27<p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3>Microsoft has created a new forums platform (</font><a title="http://forums.msdn.microsoft.com/en-US/forums/" href="http://forums.msdn.microsoft.com/en-US/forums/"><font face=Calibri color="#800080" size=3>MSDN</font></a><font face=Calibri size=3> | </font><a title="http://forums.technet.microsoft.com/en-us/Forums/" href="http://forums.technet.microsoft.com/en-us/Forums/"><font face=Calibri color="#800080" size=3>TechNet</font></a><font face=Calibri size=3> | </font><a title="http://forums.expression.microsoft.com/en-US/forums/" href="http://forums.expression.microsoft.com/en-US/forums/"><font face=Calibri color="#800080" size=3>Expression</font></a><font face=Calibri size=3> | </font><a title="http://forums.community.microsoft.com/en-US/forums/" href="http://forums.community.microsoft.com/en-US/forums/"><font face=Calibri color="#800080" size=3>Microsoft</font></a><font face=Calibri size=3>) with increased performance, stability, and an improved user experience. During the week of <b>5/27</b> this forum will be moving to the new platform. To make sure this is a smooth transition, we want everyone using this forum to have a chance to try out the new forums in advance, and give feedback. We’ve created a </font><a title="http://forums.technet.microsoft.com/en-US/tnsandbox/threads/" href="http://forums.technet.microsoft.com/en-US/tnsandbox/threads/"><font face=Calibri color="#800080" size=3>Sandbox forum</font></a><font face=Calibri size=3>, where you can create threads and try out functionality, and a </font><a title="http://forums.technet.microsoft.com/en-US/suggest/threads/" href="http://forums.technet.microsoft.com/en-US/suggest/threads/"><font face=Calibri color="#800080" size=3>suggestions forum</font></a><font face=Calibri size=3> where you can give us your feedback. Please take some time to go to the new forums today and let us know what you think. </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3>On the day the forum moves to the new platform, a post will be made letting you know the process has been started, and the forum will be locked to new posts. Once the process is complete, a final post to the forum will be made letting you know the forum has moved.</font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3> </font></p> <p class=MsoListParagraph style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in"><span style=""><span style=""><font face=Calibri size=3>1.</font><span style="font:7pt 'Times New Roman'">       </span></span></span><font face=Calibri size=3>All posts in the forum will be preserved</font></p> <p class=MsoListParagraph style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in"><span style=""><span style=""><font face=Calibri size=3>2.</font><span style="font:7pt 'Times New Roman'">       </span></span></span><font face=Calibri size=3>Any points you’ve received for replies will move with you (on a per forum basis)</font></p> <p class=MsoListParagraph style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in"><span style=""><span style=""><font face=Calibri size=3>3.</font><span style="font:7pt 'Times New Roman'">       </span></span></span><font face=Calibri size=3>Any bookmarks to this forum or threads within this forum will redirect to their new location</font></p> <p class=MsoListParagraph style="margin:0in 0in 0pt 0.5in;text-indent:-0.25in"><span style=""><span style=""><font face=Calibri size=3>4.</font><span style="font:7pt 'Times New Roman'">       </span></span></span><font face=Calibri size=3>Your “My Threads” will be preserved on the new platform</font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3>The only thing you’ll need to do after migration is set Windows Live Alerts for any threads you were tracking.</font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3>If you have feedback, let us know in the </font><a title="http://forums.technet.microsoft.com/en-US/suggest/threads/" href="http://forums.technet.microsoft.com/en-US/suggest/threads/"><font face=Calibri color="#800080" size=3>suggestions forum</font></a><font face=Calibri size=3> or contact me directly at Andrew.Brenner at Microsoft.com</font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3> </font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3>Thanks,</font></p> <p class=MsoNormal style="margin:0in 0in 0pt"><font face=Calibri size=3>-Andrew</font></p>Tue, 13 May 2008 14:21:35 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/23d2d1a1-10b2-4af3-9a76-52a1c30b7a8ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/23d2d1a1-10b2-4af3-9a76-52a1c30b7a8aSQL 2k5 Newbiehttp://social.technet.microsoft.com/Profile/en-US/?user=SQL%202k5%20NewbieVariable Password Expiration Time<p align=left><font face=Arial size=2>Is there a way to make the time it takes for a password to expire variable in SQL Server?</font></p> <p align=left> </p> <p align=left>I'm working on a project that has different requirements for password expiration depending on the type of user.  For example, a normal end user logging in can follow standard system policy for expiration (30 days).  However, a system user (aka service account or application user) only needs to change once a year.  </p> <p align=left> </p> <p align=left>And since changing the password that application uses to login requires updating the connections managed in the application server, changing it is a pain.  So I don't want to force the app users to follow the more strict policy.  Is there a way to make the expiration variable by user?</p>Fri, 25 Apr 2008 13:19:37 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6c793d32-023b-4765-a1d2-2615a9e442afhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/6c793d32-023b-4765-a1d2-2615a9e442afKasshttp://social.technet.microsoft.com/Profile/en-US/?user=Kasschange ssa reporting<p align=left><font face=Arial size=2></font> </p> <p>Hi</p> <p align=left> </p> <p align=left>Is it possible to change what the SSA checks &amp; reports on? I want it to ignore certain checks but cannot find where i can do that from.</p> <p align=left> </p> <p align=left>Thanks</p> <p align=left> </p> <p align=left>Kass</p>Thu, 15 Nov 2007 09:25:57 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/de7082b4-6a69-41dd-81b9-f8dec7d350dbhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/de7082b4-6a69-41dd-81b9-f8dec7d350dbChuck richardshttp://social.technet.microsoft.com/Profile/en-US/?user=Chuck%20richardspassword expiration control<p align=left><font face=Arial size=2></font> </p>for those systems that us a name change for the admin account I'm receiving alerts for password expiration.  it would be great if thier was a way to exclude certain accounts from the check by adding to the pool of system service accounts.Sat, 13 Oct 2007 02:14:08 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/7c869928-28a3-430c-9d6a-8b4fb83015a6http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/7c869928-28a3-430c-9d6a-8b4fb83015a6rahul kumar1http://social.technet.microsoft.com/Profile/en-US/?user=rahul%20kumar1mean of forefront client security<p>this is pesonal data  security with the help of that...</p> <p>knowing that get that with intract with client offering</p>Sat, 10 Mar 2007 10:21:58 Z2008-06-19T00:15:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9f99908f-97b1-49e6-8278-8dda30419493http://social.technet.microsoft.com/Forums/en-US/ForefrontclientSSA/thread/9f99908f-97b1-49e6-8278-8dda30419493Johan Blom, Forefront MVPhttp://social.technet.microsoft.com/Profile/en-US/?user=Johan%20Blom%2c%20Forefront%20MVPSSA scan behavior<p>Hi!</p> <p>I just tried to edit the Vulnerability manifest to destroy the file signature. I wanted to find out the behavior of SSA if the manifest was tampered with in any way</p> <p>I ran a Quick scan of the computer and the SSA simply does not run.  I would have liked the SSA to overwrite the corrupt manifest file with a valid one. (reapply the definition update from WSUS?). </p> <p>This way i can &quot;turn off&quot; the SSA scanning just by corrupting a file. right?</p> <p>/johan</p> <p> </p>Mon, 05 Mar 2007 23:35:35 Z2008-06-19T00:15:52Z