查看: 4624|回复: 5
收起左侧

[新手上路] How to Deploy Potentially Unwanted Application Protection Policy for Endpoint...

[复制链接]
ELOHIM
发表于 2015-11-16 21:00:20 | 显示全部楼层 |阅读模式
本帖最后由 ELOHIM 于 2015-11-17 20:55 编辑

[url=]原文链接:https://technet.microsoft.com/en ... 770.aspx#BKMK_Step1   懒得翻译了。。

[/url]
Potential Unwanted Application (PUA) is a threat classification based on reputation and research-driven identification. Most commonly, these PUA applications are unwanted application bundlers or their bundled applications .
You can protect your users from PUA by deploying an antimalware policy in your Microsoft System Center 2012 Endpoint Protection Configuration Manager. The protection policy setting is disabled by default. If enabled, this feature will block PUA at download and install time. However, you can exclude specific files or folders to meet the specific needs of your environment.
[url=]To create a configuration item to enable PUA protection[/url]
  •         In the Configuration Manager console, click Assets and Compliance.

  • In the Assets and Compliance workspace, open the Compliance Settings folder, right-click on Configuration Items, and then click Create Configuration Item.

  • In the Configuration Item wizard, select a name and the Windows Desktops and Server (custom) Configuration Item type before clicking Next. Select the targeted operating systems, and go to the next page. Click New to create a new setting.

  • In the Create Setting dialog box, select a name for the setting, and specify the following additional information:
    • Data type – Select the Integer type to set the value type to used
    • Hive - Select HKEY_LOCAL_MACHINE as the hive root
    • Key – Select the key according to your product version:
      Product name
      Key
      System Center Endpoint Protection
      Software\Policies\Microsoft\Microsoft Antimalware\MpEngine\
      Forefront Endpoint Protection
      Software\Policies\Microsoft\Microsoft Antimalware\MpEngine\
      Microsoft Security Essentials
      Software\Policies\Microsoft\Microsoft Antimalware\MpEngine\
      Windows Defender
      Software\Policies\Microsoft\Windows Defender\MpEngine\
    • ValueEnter MpEnablePus as the registry value name to be configured
    • Select This registry value is associated with a 64-bit application

    Click the Compliant Rules tab

  •         In the Compliant Rules tab, click the New button to create a rule.

  • In the Create Rule dialog box, specify the following information:
    • Enter a Name for the rule
    • Select a Rule type of Value
    • Select the Equals operator for the comparison
    • Select a value according to the PUA setting you would like to deploy:
      Value
      Description
      0 (default)
      Potentially Unwanted Application protection is disabled
      1
      Potentially Unwanted Application protection is enabled. The applications with unwanted behaviour will be blocked at download and install-time.
    •         Select Remediate noncompliant rules when supported
    • Select Report noncompliance if this setting instance is not found

    Click OK to finish creating the rule.

  • In the Create Setting dialog box, click Apply. Click Next until you reach the summary dialog box. Validate the configuration preferences before clicking Next and Close. You have now created the Configuration Item.


Your Configuration Item can be added to a Configuration Baseline and deployed. See How to Create Configuration Baselines for Compliance Settings in Configuration Manager and How to Deploy Configuration Baselines in Configuration Manager for more information.





[url=]To exclude specific files or folders[/url]
Note
Be careful when you add exclusions because it might reduce the security of the affected machines.

If you believe that an application was incorrectly identified as PUA, submit the file to the Malware Protection Center for evaluation. Include PUA and the detection name in the comments field.

龙神果然哎钻研爱读书,读好书。赞他一个。






htc360
发表于 2015-11-16 23:07:43 | 显示全部楼层
代译-----潜在不需要应用程序 (PUA) 是基于声誉和研究驱动识别威胁分类。最常见的这些 PUA 应用程序是不需要的应用捆扎机或其捆绑的应用程序。
通过部署反恶意软件政策你微软系统中心 2012年端点保护配置管理器中的,可以将您的用户防止 PUA。默认情况下禁用保护策略设置。如果启用,此功能会阻止 PUA 在下载和安装时间。但是,您可以排除特定的文件或文件夹,以满足您的环境的特定需要。
要创建一个配置项来启用 PUA 保护 [/ 网址]
        在配置管理器控制台中,单击资产和法规遵从性。

在资产和法规遵从性工作区中,打开合规性设置文件夹,对配置项,右键单击,然后单击创建配置项。

在配置项目向导中,单击下一步之前选择名称和 Windows 桌面计算机和服务器的 (自定义) 配置项类型。选择有针对性的操作系统,并转到下一页面。单击新建创建一个新的设置。

在创建设置对话框中,选择设置的名称并指定以下附加信息:
数据类型 – 选择要设置要使用的值类型的整数类型蜂巢

评分

参与人数 1人气 +1 收起 理由
ELOHIM + 1 感谢解答: )

查看全部评分

HEMM
发表于 2015-11-16 21:04:44 | 显示全部楼层
天!好歹弄个机翻啊......
这岂是我等小白看得懂的?
PS:龙阁阁很介意其中一个词汇,你应该编辑掉。
ELOHIM
 楼主| 发表于 2015-11-16 21:15:07 | 显示全部楼层
本帖最后由 ELOHIM 于 2015-11-16 21:23 编辑
HEMM 发表于 2015-11-16 21:04
天!好歹弄个机翻啊......
这岂是我等小白看得懂的?
PS:龙阁阁很介意其中一个词汇,你应该编辑掉。


尊称。。
@驭龙 小龙。。
技术大拿,这个称呼不错吧。

不过我发现,key 值可能有出入。
因为Software\Policies\Microsoft\Microsoft Antimalware\MpEngine\ 这个值不对。
应该是SOFTWARE\Microsoft\Microsoft Antimalware\MpEngine。(XP下的路径)
莫非还要创建项啊?
原文我也没有仔细看…………
村里人看不懂E文。
1518589226
发表于 2015-11-16 23:01:59 | 显示全部楼层
应该在设置里面设置以个打开控件哪怕设置成高级设置里面也好啊。。。我这种看长文就晕的。。。
ELOHIM
 楼主| 发表于 2015-11-16 23:03:53 | 显示全部楼层
1518589226 发表于 2015-11-16 23:01
应该在设置里面设置以个打开控件哪怕设置成高级设置里面也好啊。。。我这种看长文就晕的。。。


我也不懂,我就是转发一下。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-20 23:22 , Processed in 0.117090 second(s), 19 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表