locked
Updates for Client security still downloading after client is uninstalled RRS feed

  • Question

  • I have uninstalled Forefront Client security and installed Forefront Endpoint protection. Windows update is now downloading updates for both clients. The Client security updates always fails, of course, and so it keeps downloading them over and over.

    What does Windows Update look at to decide what updates to download? There is no trace of Client security in the installed programs list.


    Cheers, Mark.
    • Edited by MarkEmery Wednesday, November 23, 2011 11:16 PM
    Wednesday, November 23, 2011 10:47 PM

Answers

  • Pretty crazy suggestion to trash the entire domain to fix one client.

     

    It did give me the idea to delete the client record from WSUS instead and then run Windows Update again on the client. That seems to have fixed the problem.


    Cheers, Mark.
    • Marked as answer by MarkEmery Thursday, November 24, 2011 3:20 AM
    Thursday, November 24, 2011 3:20 AM

All replies

  • Hi Mark,

    Thank you for your post.

    Please perform two steps:
    1. Unapproved all of the FCS client installation packagess, clear update Product: Forefront Client Security
    2. Remove FCS domain group policy and remove local policy via command "fcslocalpolicytool.exe /d"

    Migrating from Forefront Client Security to Forefront Endpoint Protection
    Removing an existing installation of Client Security

    If there are more inquiries on this issue, please feel free to let us know.

    Regards,
    Rick Tan


    • Edited by Rick Tan Thursday, November 24, 2011 3:11 AM
    Thursday, November 24, 2011 3:10 AM
  • Pretty crazy suggestion to trash the entire domain to fix one client.

     

    It did give me the idea to delete the client record from WSUS instead and then run Windows Update again on the client. That seems to have fixed the problem.


    Cheers, Mark.
    • Marked as answer by MarkEmery Thursday, November 24, 2011 3:20 AM
    Thursday, November 24, 2011 3:20 AM
  • Hi,

    I would like to bump this topic, as I have similar problem.

    Mark:

    That is a pretty good suggestion however, will not work for me as I have it mixed in my domain: some PCs use FCS client, other ones FEP.

    Rick:

    Can you advise anything regarding my situation? Unaproving FCS updates, or removing program record from WSUS products list is not an option, as we still use both products: FCS and FEP.

    I do "fcslocalpolicytool.exe /d" before installing FEP (it automatically removes FCS) but it is not helping. Removing it from global policy is not an option of course.



    • Edited by Shemek Thursday, January 5, 2012 3:07 PM
    Thursday, January 5, 2012 3:02 PM
  • Hi Shemek,

    You could create two computer groups (like FCS and FEP) via WSUS console--Computers--All Computers, move the WSUS computer clients to the relevant groups.
    Then change the FEP/FCS updates automatic approvals from All computers to FCS/FEP groups via WSUS console--Options--Automatic Approvals.


    Rick Tan

    TechNet Community Support

    Monday, January 9, 2012 3:24 AM