With the previous version of SCEP (Forefront Endpoint Protection 2010), many organizations opted to install the FEP 2010 Security Management Pack for SCOM, because it added the ability to have real-time reporting. As SCEP has the real-time reporting capabilities natively, this is not as necessary with the current version.
However, there could be other motivating factors that would cause an organization to still choose to install the newly updated System Center Security Monitoring Pack for Endpoint Protection, such as the way monitoring responsibilities have been allocated in your organization, or you may be using an SEM appliance, which connects to SCOM and want to have virus alerts filter up into the SEM.
In order to install the System Center Security Monitoring Pack for Endpoint Protection, you will need to use an account with administrator access to SCOM. You will also need to download the management pack, which is available at the following URL:
http://www.microsoft.com/en-us/download/details.aspx?id=9754
Now, follow these steps:
fep2010 security mp.msi
and agree to EULA. Do not worry that the management pack we just downloaded has FEP in the title; this MP works for SCEP as well. Refer to the following screenshot:Microsoft.FEPS.Libary.mp
. Then, click on the Open button to proceed, as shown in the following screenshot:Microsoft.FEPS.Application.mp
and Microsoft.FEPS.Reports.mp
. Once you've added all three .mp
files, you can then click on the Install button, as shown in the following screenshot:The procedure in this recipe will only import the management pack into your SCOM 2012 environment, in order. For clients, to start sending SCEP related data to SCOM, they will also need to have the SCOM client deployed to them. In other words, the SCOM Management Pack collects data directly from the Endpoint clients themselves, rather than pulling data out of your SCCM 2012 server.
As such, there is a lot of overlap between SCCM 2012 with SCEP enabled and a SCOM server with the Endpoint Protection Management pack installed. Therefore, it's recommended that you only use the Management Pack if you have a good reason for doing so.