Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 21, 2006 12:00 AM

Microsoft Security Comes to the Forefront

Windows IT Pro
InstantDoc ID #94348
Rating: (1)

A few weeks back, I talked about Microsoft's progress with its client-side security applications. But the biggest news in this space is the pending arrival of Forefront Client Security, Microsoft's managed client security solution. Aimed at large and midsized businesses, Forefront Client Security is a much-needed and eagerly awaited solution for client security. And you can grab a public beta today and evaluate whether it's right for your business.

I spoke with members of Microsoft's Security, Access, and Solutions Division recently at a briefing in the Boston area to discuss Forefront Client Security, a product I had first heard rumors of years ago. Forefront Client Security is a centralized, managed solution that integrates with your existing Active Directory (AD) and Group Policy infrastructure to protect client PCs (including desktop PCs and portable computers) and servers from viruses, spyware, and other malware. As you might expect, Forefront Client Security includes a management dashboard, the Forefront Client Security Management Console, as well as a single client-based agent that you need to deploy to all protected systems.

From a technological perspective, Microsoft is handling its security wares intelligently: Forefront Client Security uses the same backend as its other anti-malware solutions, such as Windows Live OneCare, Windows Defender, and Forefront Security for Exchange (formerly Sybari Antigen), which will ship next month for Microsoft Exchange Server 2007). This brings with it certain efficiencies, of course, but the use of a single back-end server means that Forefront Client Security protection will have been used in the real world by millions of people by the time the product ships.

In use, Forefront Client Security is everything you'd expect from a Microsoft enterprise product: The console is feature-rich and easy to use, and deploying the Forefront Client Security agent through Group Policy to, say, an AD organizational unit (OU) is straightforward. By default, users will typically never even be aware that Forefront Client Security is working in the background, and indeed, you can configure it so that they'll never have to deal with a single dialog box. Users who are permitted to do so can run the client-side code manually and will see an application window modeled after that of Windows Defender.

Forefront Client Security uses Windows Server Update Services (WSUS) to provide definition updates for the product's anti-malware functionality, and can fail over to Microsoft Update if WSUS isn't available. Administrators can simply choose to auto-approve all such updates, which is recommended, or you can manually approve them as you go. The client application checks for updated definitions on a scheduled basis, as you'd expect. And each morning, it's possible to scan a security summary report through the Forefront Client Security Management Console to get a capsule view of how the past day went. There's also trend information, which goes back 30 days by default.

Currently, a public beta of Forefront Client Security is available from the Microsoft Web site (see the URL below), and the company intends to ship the final version by the second quarter of 2007. Although Microsoft hasn't yet announced pricing, Forefront Client Security will be made available via a subscription model whereby customers pay a per-year, per-device licensing fee. As part of that licensing fee, you receive constant definition updates and rights to any new versions of Forefront Client Security that ship in that timeframe.

Forefront Client Security looks great, and I recommend that you check it out. The only question is its suitability for small businesses, which is a market that is currently unserved by Microsoft's security solutions. On the very low-end, home-based and other very small businesses could be well served by a solution such as OneCare, and of course Forefront Client Security targets large and midsized businesses. But Microsoft Small Business Server (SBS) customers might be out of luck, though Microsoft is looking at a more pervasive security solution for that platform, perhaps one that combines the functionality of Forefront Client Security with that of Forefront Security for Exchange, for the future. Stay tuned.

Forefront Client Security Beta
http://www.microsoft.com/technet/prodtechnol/beta/forefront/default.mspx

Related Content:

ARTICLE TOOLS

Comments
  • Kristofer
    4 years ago
    Feb 12, 2008

    Missing from the article are the requirements for a rather robust server architecture, with six different server roles requiring at least two servers (and possibly more), one of which must have dual processors. It is unclear from the documentation whether dual core will work, or if it has to be dual processor. Moreover, you did not mention that Live OneCare and Forefront Client Security use the same scanning engine, and Live OneCare is one of the most poorly rated A/V products on the market. What makes Forefront Client Security any better?

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.