Overview In an enterprise environment using Microsoft Forefront Client Security (FCS), it is important to be able to quickly and easily deploy antimalware (antivirus and antispyware) definition updates throughout the organization. FCS accomplishes this by leveraging Windows Server Update Services (WSUS), which is also leveraged by Microsoft System Center Configuration Manager 2007. While FCS makes use of the WSUS engine in order to deploy definition updates to all of the clients FCS manages, System Center Configuration Manager uses WSUS to provide metadata to the scanning engine on Configuration Manager clients that facilitate software updates.When customers already have a Configuration Manager infrastructure in place, FCS must use that same WSUS infrastructure, as the local Windows Update Agent can only be assigned to a single WSUS server. This means that the WSUS infrastructure will be a shared resource for both FCS and Configuration Manager. This document provides guidance on how to configure FCS definition updates to use an existing Configuration Manager WSUS infrastructure while ensuring that both Configuration Manager and FCS function properly and work together in harmony. Please note this guide does not include instructions on how to configure Configuration Manager in an existing FCS WSUS infrastructure.Note: Customers using Configuration Manager must leverage their existing WSUS infrastructure hierarchy to manage FCS definition updates, as the Windows Update Agent can only be assigned to a single WSUS server. FCS definition updates The goal of this document is to provide guidance for automatically deploying your FCS definition updates using the WSUS infrastructure shared with Configuration Manager for software updates. The guide details how to configure the shared WSUS server to download, approve, and distribute FCS definition updates. The end result of following this guide will be all FCS clients retrieving their definition updates through an existing Configuration Manager WSUS or software update point server.This document assumes that you have a functional Configuration Manager software update infrastructure. For information about deploying Configuration Manager, see Planning and Deploying the Server Infrastructure for Configuration Manager 2007 (http://technet.microsoft.com/en-us/l.../bb680397.aspx). This document also assumes that all FCS management roles and clients, except for the Distribution Server role, are deployed within the organization. For information about deploying FCS, see Deployment (http://technet.microsoft.com/en-us/l.../bb404259.aspx).Note: There is no specific role played by Configuration Manager in the definition update process; all definition updates are managed via WSUS. Internet-facing clients will only be able to get antivirus definitions from the WSUS infrastructure when they are connected to the intranet. Microsoft supported configurationsRefer to Supported configurations for using WSUS to distribute Forefront Client Security Definition updates within SCCM 2007 (http://support.microsoft.com/default.aspx/kb/958491) for supported FCS and Configuration Manager shared configurations. At the time of publication, the following scenarios are officially supported by Microsoft:
*Configuration Manager 2007 R2 should be supported on its release.PrerequisitesThe following list represents the general configuration requirements to support this integration:
ConfigurationThe configuration process consists of five basic steps. For environments with multiple Configuration Manager software update points, please note the following steps must be repeated, depending on applicability:
To configure FCS definition updates to use an existing Configuration Manager WSUS infrastructure