Ideas
What features would you like to see?
All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Configuration Manager, though we can’t promise to reply to all posts.
If you require assisted support, please see https://aka.ms/cmcbsupport for more details.
-
Would like to replace the Windows defender icon with the SCEP icon when managed by Endpoint Protection
In windows 10 when managed by SCCM+Endpoint Protection, we get Windows Defender as the Endpoint Protection client, which is fine as they use the same engine.
However the icon is for Windows Defender which doesn't make sense.
Can we change it to the SCEP icon instead which would make more sense and go along with the installed software SCEP in control panel which does have the correct icon (in Programs and Features).
Having the SCEP icon would be a nice visual clue (aside from looking at applied policies) that SCEP was managing Antivirus rather than Windows itself
195 votes -
SCEP Malware Alerts - Customized
SCEP Malware Alerts - Customized
The ability to customize the text and have the ability to select which fields you wish to include within the Malware email alert.84 votes -
Fix the Update button in SCEP
Currently, the Update button in SCEP does not perform any function when you want to use the SUP as a definition source. Per: https://support.microsoft.com/en-us/kb/2831244 - When you click Update in the SCEP UI, the client looks for a FallbackOrder registry key in HKLM\Software\Policies\Microsoft\Microsoft Antimalware\Signature Updates. The client will check each update source in the FallbackOrder registry key in the order that they are listed until it locates a source that has available definitions. If it goes through all sources without detecting available definitions, it returns an error and the update attempt is unsuccessful. Configuration Manager is never listed in the…
81 votes -
blocking usb
Add the option to allow/block USB devices on the endpoint protection.
78 votes -
Enable Tamper Protection via SCCM
It would be nice to have ability to enable Tamper Protection in defender via SCCM antimalware policy
76 votesThanks for your feedback, updating status to Noted.
See https://docs.microsoft.com/en-us/mem/configmgr/core/understand/find-help#send-a-suggestion for an explanation of each value.
-
SCEP Antimalware detection history view does not show accurate remediation detail
The vAMNormalizedDetectionHistory view in the SCCM database does not accurately reflect the RemediationType for detected threats. It almost always shows NoAction, even though the threat was quarantined or removed.
We are using this view to report status to our SIEM system, and our security team would prefer that it actually show how the threat was remediated.
72 votes -
MBAM fully integrated in 1910 does not have enforcement option
Great to see MBAM fully integrated in CM 1910, but the policy does not have any option to enforce the encryption. User can always postpone it.
For more info, see this: https://www.youtube.com/watch?v=kRkyx_-l9QU
57 votes -
Windows Firewall With and Advance Security integration
So this portion is currently listed under EP in the SCCM console so im posting here. i would like to see an enterprise solution to deploying the windows firewall similar to the way DCM relationships are. Not the existing feature in SCCM where you can simply enable or disable the firewall policy. i would like to see Individual Firewall rules are created as Configuration items and then grouped into Baselines to be applied at a granular level to computers. that way we can remove the GPO dependency on where a computer is placed or at which level its place. SCCM…
47 votes -
Support MBAM / Bitlocker Management IIS roles on CMG
Seeing how the Recovery Service endpoint only requires IIS and a Management Point role, would it be feasible to have the endpoint run on CMG?
Internet-based clients in a co-management environment cannot reach the internal MP URL. Unless they use a VPN connection. We could leverage the BitLocker CSP policies available in Intune but that doesn't offer integration with recovery keys stored in the SQL DB, or the Helpdesk and Self-Service portals.
Supporting the MBAM role through CMG could be a quick win.
46 votes -
Include all ASR Rules in Windows Defender Exploit Guard
Some Attack Surface Reduction Rules are missing in the Windows Defender Exploit Guard settings.
Please include the following Rules:
Block Office communication application from creating child processes
Block Adobe Reader from creating child processes
Block persistence through WMI event subscription44 votes -
More granular settings for Endpoint Protection alerts for malware detection and alerting.
Currently SCCM lets you enable/disable some settings like the newer feature of PUA. It does not allow for alerts of malware and Endpoint Protection to be configured independently. Just because I want it detected, may not mean I wanted it reported on. We like PUA's being detected, but we do not want to be alerted on PUA, because we get too many each week, most of which are valid installers we use. We do not want to exclude them, because a new version of the .exe may have something we are not aware of. I would like to see alerts…
40 votes -
Adding a file hash to Windows defender detection alerts
Adding a file hash of detected or suspected malware son that further research can be done using VirusTotal and simular resources.
As it is now the threat informatinen provided by microsoft have very little detail and restoring files from quarantine to analyze them isn't ideal either38 votes -
Windows Defender Application Control - enchace it with more rule types
In 1906, WDAC rules can be modified only on Folder and Files level and that is not enough. Like in Applocker, we need Publisher rules and file signing support. It is great that ex-Device Guard starts to be more or less accassable to control with GUI, but current features are not enough to utilize it to production yet. Please make it to be as controllable as Applocker.
36 votes -
Maintenance Window for EP Definition Updates/Security Updates
Please add the possibility in a MW to "apply this schedule to"
- EP Defintion Updates (you may want to allow daily defintion updates, but you don't want to install anything else at that time)
- Security Updates (not all Software Updates, as it is now, but only Security Updates)In this case make it multiselect too.
35 votes -
Right Click on a Computer no matter where I am looking at in SCCM and do a Virus Scan.
Right Click on a Computer no matter where I am looking at in SCCM and do a Virus Scan.
34 votes -
Include always latest SCEP client in the SCCM client directory/package
Please include always latest SCEP client in the SCCM client directory/package.
e.g. in SCCM1610 still the SCEP client 4.7.214.0 is included.
Current version is 4.10.209.0.So additional effort can be reduced as the SCEP client will be updated with SCCM client auto-upgrade function.
34 votes -
Policy resultant for SCEP Policy like Clients Settings Resultant
A overview about the SCEP Policy as we have in Client Settings Resultant Box on every Client, that would be nice to show which Policy is finally running on a client. if you have more than 1 Policy you get the really end result of excludes or settings...
33 votes -
password protect client uninstall
Would like to see the option to password protect/prevent client uninstall when the client is used for endpoint protection. This goes with another suggestion of having the client block removable media read and/or write.
33 votes -
Improved alerting for SCEP
Configuration Manager allows the creation of subscriptions to alerts for the following Endpoint Protection events:
- Malware outbreak - the same malware detected on multiple computers
- Multiple malware detected on one computer
- Same malware repeatedly detected on one computer
The ability to subscribe to alerts for these events is useful, but this feature could be improved.
For example, I don't need to be alerted when malicious JavaScript on a website is repeatedly detected and blocked on a user's computer, but there is no way to filter notifications for a specific class of threats. On the other hand, I do want to…
32 votesNoted ·Admindjam (Product Director, or Executive, Microsoft Endpoint Configuration Manager) responded
Can you give more examples? Definitely want to innovate in these areas.
-
SCEP integration with SCSM
SCEP integration to SCSM, so that alerts would create an incidents. It should be possible to configure, so that SCSM wouldn't be flooded with the same alert over and over again for a particular computer, or if there is a major outbreak.
31 votes
- Don't see your idea?