Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Windows Defender: Bypassing Group Policy software update settings

Reply
Thread Tools Display Modes

Windows Defender: Bypassing Group Policy software update settings

 
 
desil
Guest
Posts: n/a

 
      02-16-2006
[ Microsoft this week released the replacement for Microsoft AntiSpyware
(beta 1), called Windows Defender (beta 2):
http://www.microsoft.com/antispyware ]

Two new features in Defender, when combined, are giving trouble. They are:

1) Configuration settings now controlled via Group Policy, and
2) Malicious and unwanted software signatures are downloaded via Windows
Update.

Our office network currently uses Software Update Services (SUS) because the
server set aside for this task isn't powerful enough to run Windows Server
Update Services (WSUS). A Group Policy Object (GPO) configures all
workstations to get all Windows updates from the local SUS server. We're
running AD2003, with the clients a mix of Windows 2000 (SP4) and XP (RTM,
SP1, SP2).

This is where the problem is. I'm testing Defender on a couple of
workstations and it turns out that it is unable to retrieve updates for
itself. Having run 'netstat' from the Command Prompt, I can see that Defender
is trying to connect to our SUS server (which doesn't have any Defender
definitions).

Can someone tell me how to either use Group Policy to instruct Defender to
get its updates directly from the Internet, or update SUS so that Defender
definitions are included? (Keep in mind that updating to WSUS is not an
option right now.)

Thanks,
desil.
 
Reply With Quote
 
 
 
 
PA Bear
Guest
Posts: n/a

 
      02-17-2006
Microsoft has established separate newsgroups Windows Defender Beta2 support
and comments. See
http://www.microsoft.com/athome/secu...s/default.mspx.

--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE, Shell/User, Security), Aumha.org VSOP, DTS-L.org

desil wrote:
> [ Microsoft this week released the replacement for Microsoft AntiSpyware
> (beta 1), called Windows Defender (beta 2):
> http://www.microsoft.com/antispyware ]
>
> Two new features in Defender, when combined, are giving trouble. They are:
>
> 1) Configuration settings now controlled via Group Policy, and
> 2) Malicious and unwanted software signatures are downloaded via Windows
> Update.
>
> Our office network currently uses Software Update Services (SUS) because
> the server set aside for this task isn't powerful enough to run Windows
> Server Update Services (WSUS). A Group Policy Object (GPO) configures all
> workstations to get all Windows updates from the local SUS server. We're
> running AD2003, with the clients a mix of Windows 2000 (SP4) and XP (RTM,
> SP1, SP2).
>
> This is where the problem is. I'm testing Defender on a couple of
> workstations and it turns out that it is unable to retrieve updates for
> itself. Having run 'netstat' from the Command Prompt, I can see that
> Defender is trying to connect to our SUS server (which doesn't have any
> Defender definitions).
>
> Can someone tell me how to either use Group Policy to instruct Defender to
> get its updates directly from the Internet, or update SUS so that Defender
> definitions are included? (Keep in mind that updating to WSUS is not an
> option right now.)
>
> Thanks,
> desil.


 
Reply With Quote
 
desil
Guest
Posts: n/a

 
      02-17-2006
Hmmm... I didn't see that. But they're top-secret private newsgroups! I'll
repost my message there. Will post back here if I get anything useful.

"PA Bear" wrote:

> Microsoft has established separate newsgroups Windows Defender Beta2 support
> and comments. See
> http://www.microsoft.com/athome/secu...s/default.mspx.
>
> --
> ~Robear Dyer (PA Bear)
> MS MVP-Windows (IE/OE, Shell/User, Security), Aumha.org VSOP, DTS-L.org
>
> desil wrote:
> > [ Microsoft this week released the replacement for Microsoft AntiSpyware
> > (beta 1), called Windows Defender (beta 2):
> > http://www.microsoft.com/antispyware ]
> >
> > Two new features in Defender, when combined, are giving trouble. They are:
> >
> > 1) Configuration settings now controlled via Group Policy, and
> > 2) Malicious and unwanted software signatures are downloaded via Windows
> > Update.
> >
> > Our office network currently uses Software Update Services (SUS) because
> > the server set aside for this task isn't powerful enough to run Windows
> > Server Update Services (WSUS). A Group Policy Object (GPO) configures all
> > workstations to get all Windows updates from the local SUS server. We're
> > running AD2003, with the clients a mix of Windows 2000 (SP4) and XP (RTM,
> > SP1, SP2).
> >
> > This is where the problem is. I'm testing Defender on a couple of
> > workstations and it turns out that it is unable to retrieve updates for
> > itself. Having run 'netstat' from the Command Prompt, I can see that
> > Defender is trying to connect to our SUS server (which doesn't have any
> > Defender definitions).
> >
> > Can someone tell me how to either use Group Policy to instruct Defender to
> > get its updates directly from the Internet, or update SUS so that Defender
> > definitions are included? (Keep in mind that updating to WSUS is not an
> > option right now.)
> >
> > Thanks,
> > desil.

>
>

 
Reply With Quote
 
PA Bear
Guest
Posts: n/a

 
      02-17-2006
It's the "public" private beta newsgroup, not the "private" private beta
newsgroup. <w>
--
~PA Bear

desil wrote:
> Hmmm... I didn't see that. But they're top-secret private newsgroups! I'll
> repost my message there. Will post back here if I get anything useful.
>
> "PA Bear" wrote:
>
> > Microsoft has established separate newsgroups Windows Defender Beta2
> > support and comments. See
> > http://www.microsoft.com/athome/secu...s/default.mspx.
> >
> > --
> > ~Robear Dyer (PA Bear)
> > MS MVP-Windows (IE/OE, Shell/User, Security), Aumha.org VSOP, DTS-L.org
> >
> > desil wrote:
> > > [ Microsoft this week released the replacement for Microsoft
> > > AntiSpyware (beta 1), called Windows Defender (beta 2):
> > > http://www.microsoft.com/antispyware ]
> > >
> > > Two new features in Defender, when combined, are giving trouble. They
> > > are:
> > >
> > > 1) Configuration settings now controlled via Group Policy, and
> > > 2) Malicious and unwanted software signatures are downloaded via
> > > Windows Update.
> > >
> > > Our office network currently uses Software Update Services (SUS)
> > > because the server set aside for this task isn't powerful enough to
> > > run Windows Server Update Services (WSUS). A Group Policy Object
> > > (GPO) configures all workstations to get all Windows updates from the
> > > local SUS server. We're running AD2003, with the clients a mix of
> > > Windows 2000 (SP4) and XP (RTM, SP1, SP2).
> > >
> > > This is where the problem is. I'm testing Defender on a couple of
> > > workstations and it turns out that it is unable to retrieve updates
> > > for itself. Having run 'netstat' from the Command Prompt, I can see
> > > that Defender is trying to connect to our SUS server (which doesn't
> > > have any Defender definitions).
> > >
> > > Can someone tell me how to either use Group Policy to instruct
> > > Defender to get its updates directly from the Internet, or update SUS
> > > so that Defender definitions are included? (Keep in mind that
> > > updating to WSUS is not an option right now.)
> > >
> > > Thanks,
> > > desil.


 
Reply With Quote
 
Bill Sanderson
Guest
Posts: n/a

 
      03-31-2006
I don't believe we have any useful answer except to update to WSUS, which
desil has already said is not possible. I hope desil is in touch with the
end of life statements at the SUS pages.

--

"PA Bear" <> wrote in message
news:%23Ad53j$...
> It's the "public" private beta newsgroup, not the "private" private beta
> newsgroup. <w>
> --
> ~PA Bear
>
> desil wrote:
>> Hmmm... I didn't see that. But they're top-secret private newsgroups!
>> I'll
>> repost my message there. Will post back here if I get anything useful.
>>
>> "PA Bear" wrote:
>>
>> > Microsoft has established separate newsgroups Windows Defender Beta2
>> > support and comments. See
>> > http://www.microsoft.com/athome/secu...s/default.mspx.
>> >
>> > --
>> > ~Robear Dyer (PA Bear)
>> > MS MVP-Windows (IE/OE, Shell/User, Security), Aumha.org VSOP, DTS-L.org
>> >
>> > desil wrote:
>> > > [ Microsoft this week released the replacement for Microsoft
>> > > AntiSpyware (beta 1), called Windows Defender (beta 2):
>> > > http://www.microsoft.com/antispyware ]
>> > >
>> > > Two new features in Defender, when combined, are giving trouble. They
>> > > are:
>> > >
>> > > 1) Configuration settings now controlled via Group Policy, and
>> > > 2) Malicious and unwanted software signatures are downloaded via
>> > > Windows Update.
>> > >
>> > > Our office network currently uses Software Update Services (SUS)
>> > > because the server set aside for this task isn't powerful enough to
>> > > run Windows Server Update Services (WSUS). A Group Policy Object
>> > > (GPO) configures all workstations to get all Windows updates from the
>> > > local SUS server. We're running AD2003, with the clients a mix of
>> > > Windows 2000 (SP4) and XP (RTM, SP1, SP2).
>> > >
>> > > This is where the problem is. I'm testing Defender on a couple of
>> > > workstations and it turns out that it is unable to retrieve updates
>> > > for itself. Having run 'netstat' from the Command Prompt, I can see
>> > > that Defender is trying to connect to our SUS server (which doesn't
>> > > have any Defender definitions).
>> > >
>> > > Can someone tell me how to either use Group Policy to instruct
>> > > Defender to get its updates directly from the Internet, or update SUS
>> > > so that Defender definitions are included? (Keep in mind that
>> > > updating to WSUS is not an option right now.)
>> > >
>> > > Thanks,
>> > > desil.

>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Defender config disabled due to group policy on Home Premi kira13 Windows Vista Security 2 10-03-2007 04:24 PM
Group Policy Settings are ignored Alex Fischer Windows Vista Installation 1 12-10-2006 08:56 PM
WUAU.ADM Policy Template, Group Policy Editor, Windows Update Automatic Updates dherbage@hotmail.com Windows Update 0 12-15-2005 08:59 PM
Overriding Group Policy settings to run Windows Update Windows Update 0 01-04-2005 01:56 PM
To install items from Windows Update, you must be logged on as an administrator or a member of the Administrators group. If your computer is connected to a network, network policy settings may also prevent you from completing this procedure. CaptainJack Windows Update 2 04-15-2004 01:11 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59