ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Webroot SecureAnywhere Business Replacement?

    IT Discussion
    webroot antivirus intune defender ninite pdq depoy secureanywhere
    9
    45
    4.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender @Kelly
      last edited by

      @kelly said in Webroot SecureAnywhere Business Replacement?:

      @dashrender said in Webroot SecureAnywhere Business Replacement?:

      @kelly said in Webroot SecureAnywhere Business Replacement?:

      @dashrender said in Webroot SecureAnywhere Business Replacement?:

      @wrx7m said in Webroot SecureAnywhere Business Replacement?:

      I will definitely need centralized management.

      So for Intune, it boils down to - does the cost make sense when you add in the other features you gain along with AV? I'm not sure I can get there. Damn it's way more expensive than O365 Business, 20% more... for RMM and AV...

      Shit MS is basically giving O365 away, it's the add-ons that kill ya!

      Intune is actually a good price compared to Apple focued MDM solutions.

      Sure, if MDM is what you're looking for. In my case, I'm mainly looking for an AV alternative, a sprinkle of MDM would be nice, but not something I was really looking for.

      At least wrx7m seems like he wants both, so likely the cost will be justifiable to his management.

      Lots of options for Defender now: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.

      Without digging into all those articles, does anything offer centralized logging other than SCCM and Intune?

      Perhaps the rest do, but only if you're pulling logs from the clients into something like Graylog server, or if all of your devices are set to send their logs to a centralized Windows server (then you get to deal with Windows Event Viewer - ewww!

      KellyK 1 Reply Last reply Reply Quote 0
      • KellyK
        Kelly @Dashrender
        last edited by

        @dashrender said in Webroot SecureAnywhere Business Replacement?:

        @kelly said in Webroot SecureAnywhere Business Replacement?:

        @dashrender said in Webroot SecureAnywhere Business Replacement?:

        @kelly said in Webroot SecureAnywhere Business Replacement?:

        @dashrender said in Webroot SecureAnywhere Business Replacement?:

        @wrx7m said in Webroot SecureAnywhere Business Replacement?:

        I will definitely need centralized management.

        So for Intune, it boils down to - does the cost make sense when you add in the other features you gain along with AV? I'm not sure I can get there. Damn it's way more expensive than O365 Business, 20% more... for RMM and AV...

        Shit MS is basically giving O365 away, it's the add-ons that kill ya!

        Intune is actually a good price compared to Apple focued MDM solutions.

        Sure, if MDM is what you're looking for. In my case, I'm mainly looking for an AV alternative, a sprinkle of MDM would be nice, but not something I was really looking for.

        At least wrx7m seems like he wants both, so likely the cost will be justifiable to his management.

        Lots of options for Defender now: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.

        Without digging into all those articles, does anything offer centralized logging other than SCCM and Intune?

        Perhaps the rest do, but only if you're pulling logs from the clients into something like Graylog server, or if all of your devices are set to send their logs to a centralized Windows server (then you get to deal with Windows Event Viewer - ewww!

        I don't think there is a way to do it without third party tools.

        DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @DustinB3403
          last edited by

          @dustinb3403 said in Webroot SecureAnywhere Business Replacement?:

          Webroot was opening applications?!

          I' page @Nic but he doesn't work there any longer.

          not for years, now.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @Kelly
            last edited by

            @kelly said in Webroot SecureAnywhere Business Replacement?:

            @dashrender said in Webroot SecureAnywhere Business Replacement?:

            @kelly said in Webroot SecureAnywhere Business Replacement?:

            @dashrender said in Webroot SecureAnywhere Business Replacement?:

            @kelly said in Webroot SecureAnywhere Business Replacement?:

            @dashrender said in Webroot SecureAnywhere Business Replacement?:

            @wrx7m said in Webroot SecureAnywhere Business Replacement?:

            I will definitely need centralized management.

            So for Intune, it boils down to - does the cost make sense when you add in the other features you gain along with AV? I'm not sure I can get there. Damn it's way more expensive than O365 Business, 20% more... for RMM and AV...

            Shit MS is basically giving O365 away, it's the add-ons that kill ya!

            Intune is actually a good price compared to Apple focued MDM solutions.

            Sure, if MDM is what you're looking for. In my case, I'm mainly looking for an AV alternative, a sprinkle of MDM would be nice, but not something I was really looking for.

            At least wrx7m seems like he wants both, so likely the cost will be justifiable to his management.

            Lots of options for Defender now: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.

            Without digging into all those articles, does anything offer centralized logging other than SCCM and Intune?

            Perhaps the rest do, but only if you're pulling logs from the clients into something like Graylog server, or if all of your devices are set to send their logs to a centralized Windows server (then you get to deal with Windows Event Viewer - ewww!

            I don't think there is a way to do it without third party tools.

            I'd say that's a killer for Defender itself, assuming you need that logging info.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @wrx7m
              last edited by

              @wrx7m said in Webroot SecureAnywhere Business Replacement?:

              @dashrender said in Webroot SecureAnywhere Business Replacement?:

              @wrx7m said in Webroot SecureAnywhere Business Replacement?:

              mouse would go into slow motion and would be extremely delayed to the point it would take at least a full 2 minutes to close

              What about looking at Intune?

              Thanks. I hadn't considered it for this, but was thinking about it for MDM/EMM. I will take a look.

              There is the first replacement suggestion. What are others using?

              What all features do you need?

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Kelly
                last edited by

                @kelly said in Webroot SecureAnywhere Business Replacement?:

                @dashrender said in Webroot SecureAnywhere Business Replacement?:

                @kelly said in Webroot SecureAnywhere Business Replacement?:

                @dashrender said in Webroot SecureAnywhere Business Replacement?:

                @kelly said in Webroot SecureAnywhere Business Replacement?:

                @dashrender said in Webroot SecureAnywhere Business Replacement?:

                @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                I will definitely need centralized management.

                So for Intune, it boils down to - does the cost make sense when you add in the other features you gain along with AV? I'm not sure I can get there. Damn it's way more expensive than O365 Business, 20% more... for RMM and AV...

                Shit MS is basically giving O365 away, it's the add-ons that kill ya!

                Intune is actually a good price compared to Apple focued MDM solutions.

                Sure, if MDM is what you're looking for. In my case, I'm mainly looking for an AV alternative, a sprinkle of MDM would be nice, but not something I was really looking for.

                At least wrx7m seems like he wants both, so likely the cost will be justifiable to his management.

                Lots of options for Defender now: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.

                Without digging into all those articles, does anything offer centralized logging other than SCCM and Intune?

                Perhaps the rest do, but only if you're pulling logs from the clients into something like Graylog server, or if all of your devices are set to send their logs to a centralized Windows server (then you get to deal with Windows Event Viewer - ewww!

                I don't think there is a way to do it without third party tools.

                https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus

                KellyK DashrenderD 2 Replies Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @wrx7m
                  last edited by

                  @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                  I will definitely need centralized management.

                  What's the piece of that that you need? AV isn't something requiring much management typically. You want it updated and running, maybe centrally reporting. What do you want to manage?

                  KellyK wrx7mW DashrenderD 3 Replies Last reply Reply Quote 0
                  • KellyK
                    Kelly @scottalanmiller
                    last edited by

                    This post is deleted!
                    1 Reply Last reply Reply Quote 0
                    • KellyK
                      Kelly @scottalanmiller
                      last edited by

                      @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                      @kelly said in Webroot SecureAnywhere Business Replacement?:

                      @dashrender said in Webroot SecureAnywhere Business Replacement?:

                      @kelly said in Webroot SecureAnywhere Business Replacement?:

                      @dashrender said in Webroot SecureAnywhere Business Replacement?:

                      @kelly said in Webroot SecureAnywhere Business Replacement?:

                      @dashrender said in Webroot SecureAnywhere Business Replacement?:

                      @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                      I will definitely need centralized management.

                      So for Intune, it boils down to - does the cost make sense when you add in the other features you gain along with AV? I'm not sure I can get there. Damn it's way more expensive than O365 Business, 20% more... for RMM and AV...

                      Shit MS is basically giving O365 away, it's the add-ons that kill ya!

                      Intune is actually a good price compared to Apple focued MDM solutions.

                      Sure, if MDM is what you're looking for. In my case, I'm mainly looking for an AV alternative, a sprinkle of MDM would be nice, but not something I was really looking for.

                      At least wrx7m seems like he wants both, so likely the cost will be justifiable to his management.

                      Lots of options for Defender now: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.

                      Without digging into all those articles, does anything offer centralized logging other than SCCM and Intune?

                      Perhaps the rest do, but only if you're pulling logs from the clients into something like Graylog server, or if all of your devices are set to send their logs to a centralized Windows server (then you get to deal with Windows Event Viewer - ewww!

                      I don't think there is a way to do it without third party tools.

                      https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus

                      From your link:

                      "You can use System Center Configuration Manager, the Update Compliance add-in for Microsoft Operations Management Suite, a third-party SIEM product (by consuming Windows event logs), or Microsoft Intune to monitor protection status and create reports about endpoint protection"

                      1 Reply Last reply Reply Quote 0
                      • wrx7mW
                        wrx7m @scottalanmiller
                        last edited by

                        @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                        @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                        I will definitely need centralized management.

                        What's the piece of that that you need? AV isn't something requiring much management typically. You want it updated and running, maybe centrally reporting. What do you want to manage?

                        Deployment, configuration and reporting.

                        scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender @scottalanmiller
                          last edited by

                          @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                          @kelly said in Webroot SecureAnywhere Business Replacement?:

                          @dashrender said in Webroot SecureAnywhere Business Replacement?:

                          @kelly said in Webroot SecureAnywhere Business Replacement?:

                          @dashrender said in Webroot SecureAnywhere Business Replacement?:

                          @kelly said in Webroot SecureAnywhere Business Replacement?:

                          @dashrender said in Webroot SecureAnywhere Business Replacement?:

                          @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                          I will definitely need centralized management.

                          So for Intune, it boils down to - does the cost make sense when you add in the other features you gain along with AV? I'm not sure I can get there. Damn it's way more expensive than O365 Business, 20% more... for RMM and AV...

                          Shit MS is basically giving O365 away, it's the add-ons that kill ya!

                          Intune is actually a good price compared to Apple focued MDM solutions.

                          Sure, if MDM is what you're looking for. In my case, I'm mainly looking for an AV alternative, a sprinkle of MDM would be nice, but not something I was really looking for.

                          At least wrx7m seems like he wants both, so likely the cost will be justifiable to his management.

                          Lots of options for Defender now: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/configuration-management-reference-windows-defender-antivirus.

                          Without digging into all those articles, does anything offer centralized logging other than SCCM and Intune?

                          Perhaps the rest do, but only if you're pulling logs from the clients into something like Graylog server, or if all of your devices are set to send their logs to a centralized Windows server (then you get to deal with Windows Event Viewer - ewww!

                          I don't think there is a way to do it without third party tools.

                          https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/deploy-manage-report-windows-defender-antivirus

                          https://i.imgur.com/X9Rkw2e.png

                          So straight GPO doesn't give you reporting, but you can use Powershell to collect information, I'm not really sure how the WMI part works - I'm guessing one could write a web applet that could poll this data from MSFT_MpPreference class and MSFT_MpSignature class?

                          1 Reply Last reply Reply Quote 1
                          • DashrenderD
                            Dashrender @scottalanmiller
                            last edited by

                            @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                            @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                            I will definitely need centralized management.

                            What's the piece of that that you need? AV isn't something requiring much management typically. You want it updated and running, maybe centrally reporting. What do you want to manage?

                            White listing something would be the main thing I could think of for management.

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @wrx7m
                              last edited by

                              @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                              @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                              @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                              I will definitely need centralized management.

                              What's the piece of that that you need? AV isn't something requiring much management typically. You want it updated and running, maybe centrally reporting. What do you want to manage?

                              Deployment, configuration and reporting.

                              Is that really needed? We use Defender most places. Nothing to deploy, that's automatic. Nothing to configure, also automatic (normally.) And reporting, can be done lots of ways but is rarely needed. that's the one piece that could be improved a lot, but what kind of reporting do you really want?

                              DashrenderD 1 Reply Last reply Reply Quote 1
                              • DashrenderD
                                Dashrender @wrx7m
                                last edited by

                                @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                                @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                                @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                                I will definitely need centralized management.

                                What's the piece of that that you need? AV isn't something requiring much management typically. You want it updated and running, maybe centrally reporting. What do you want to manage?

                                Deployment, configuration and reporting.

                                Deployment is built into Windows 10, so nothing to worry about there. Config - what other than whitelisting something is there to configure?
                                Reporting is the bugaboo. As listed Intune and SCCM with MOM can it, Powershell and WMI can do it, GPO alone can't.

                                1 Reply Last reply Reply Quote 1
                                • DashrenderD
                                  Dashrender @scottalanmiller
                                  last edited by Dashrender

                                  @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                                  , but what kind of reporting do you really want?

                                  To know what the current status of the endpoint is - i.e. version of software, engine and dat files.
                                  Also want to know about any infection/attempted infections.

                                  This last bit I'd like in realtime so we can see if there is something weird going on.

                                  KellyK 1 Reply Last reply Reply Quote 1
                                  • KellyK
                                    Kelly @Dashrender
                                    last edited by

                                    @dashrender said in Webroot SecureAnywhere Business Replacement?:

                                    @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                                    , but what kind of reporting do you really want?

                                    To know what the current status of the endpoint is - i.e. version of software, engine and dat files.
                                    Also want to know about any infection/attempted infections.

                                    This last bit I'd like in realtime so we can see if there is something weird going on.

                                    https://docs.microsoft.com/en-us/powershell/module/defender/index?view=win10-ps

                                    Realtime is the hard part.

                                    DashrenderD 1 Reply Last reply Reply Quote 2
                                    • wrx7mW
                                      wrx7m
                                      last edited by

                                      I still have mostly Windows 7, but am migrating to Windows 10. Also, currently on Server 2012 R2 for all but one Server 2008 r2.

                                      I want reporting for immediate alerts for any infections. Almost no one will notify me of issues until it really impedes their work.

                                      DashrenderD 1 Reply Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @Kelly
                                        last edited by

                                        @kelly said in Webroot SecureAnywhere Business Replacement?:

                                        @dashrender said in Webroot SecureAnywhere Business Replacement?:

                                        @scottalanmiller said in Webroot SecureAnywhere Business Replacement?:

                                        , but what kind of reporting do you really want?

                                        To know what the current status of the endpoint is - i.e. version of software, engine and dat files.
                                        Also want to know about any infection/attempted infections.

                                        This last bit I'd like in realtime so we can see if there is something weird going on.

                                        https://docs.microsoft.com/en-us/powershell/module/defender/index?view=win10-ps

                                        Realtime is the hard part.

                                        Agreed - but the WMI thing I would guess could get you pretty damned close. I'd say 5 mins is good enough in most cases.

                                        1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender @wrx7m
                                          last edited by

                                          @wrx7m said in Webroot SecureAnywhere Business Replacement?:

                                          I still have mostly Windows 7, but am migrating to Windows 10. Also, currently on Server 2012 R2 for all but one Server 2008 r2.

                                          I want reporting for immediate alerts for any infections. Almost no one will notify me of issues until it really impedes their work.

                                          Defender can be baked into your deployment image, so that's not much different that Win 10. And I'm pretty sure you can put defender on Windows Server 2008 or newer.

                                          1 Reply Last reply Reply Quote 2
                                          • travisdh1T
                                            travisdh1
                                            last edited by

                                            At my new place, we use ESET. That's purely for the central management console when we're supporting 250+ small businesses.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 2 / 3
                                            • First post
                                              Last post