none
policy not applying to computers ot on my network when manually applied.

    Вопрос

  • I have several users who are not on our network and are not normally. When I get onto their machines to install Forefront I apply the policy at the same time, but it never takes. I end up having to go into it and adding in all of the exceptions myself. I usually do the install through the command line so I can do the policy at the same time I us this line:

    fepinstall.exe /policy c:\forefront\policies\policyname

    When that doesn't work I can still navigate to the security client and try the 'ConfigSecurityPolicy' command and it still doesn't apply the policy.

    Is there another way to force them to accept the policy?


    Mike in IT

    20 июня 2012 г. 16:24

Ответы

  • As a temporary workaround, you could export the FEP exclusion settings from the registry on a known good machine and import the reg files on the problem machines. This would save you from manual entry. They will be located in one of the following areas:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Microsoft Antimalware\Exclusions

    • Помечено в качестве ответа Mike in IT 25 июня 2012 г. 19:39
    20 июня 2012 г. 17:59
  • When you export from regedit, it creates a .reg file. To import it on another machine, you just have to copy the .reg file to the local system and double-click it. So yeah, the scenario you describe should work fine.

    • Помечено в качестве ответа Mike in IT 25 июня 2012 г. 19:38
    20 июня 2012 г. 18:23
  • Hi Mike,

    Thank you for the post.

    Please ensure you copy fepinstall.exe to the computer local disk and run FEP install command with elevated permission.
    http://technet.microsoft.com/en-us/library/gg412485.aspx

    To use ConfigSecurityPolicy.exe update the policy, it need to wait for three minutes to update policy in user interface.
    http://technet.microsoft.com/en-us/library/gg417152.aspx

    If there are more inquiries on this issue, please feel free to let us know.
     
    Regards


    Rick Tan

    TechNet Community Support

    • Помечено в качестве ответа Mike in IT 25 июня 2012 г. 19:38
    22 июня 2012 г. 1:29
    Модератор

Все ответы