VictorySabre
Technical User
To Fellow ePO/VirusScan Admins:
I've been the ePO Admin for our company's head office for about 4 years now managing about 1200 PCs. We've been getting a lot of complaints from our end users about our various agents/scanning activities and how it is impacting their ability to work. Complaints are steadily growing and is making our IT department look bad in the end users' eyes.
I'm interested in getting some feedback from fellow ePO/VirusScan administrators who manage +1000 PCs to determine:
* Are other companies experiencing the same issues and is no different than our situation?
* What have you done in your environment / infrastructure / policies to correct the problem?
* Are we too lax / just right / too restrictive with our VirusScan configuration given the way we are set up?
* Any recommendations that I can take back to management to help steer us in the right direction?
Here are some details about what I have to deal with. Our company develops software for other companies, military, government, etc. The IT department supports our core set of standardized software on all our PCs, but the individual projects may require/install specialty applications that is requested/required by the customer. A large number of our software developers (70% of all employees in this office) have a separate local admin accounts on their systems to allow them to install/upgrade/remove software on their assigned PC. All users have access to the Internet.
VirusScan Config:
For our desktop PCs:
* We have Read/Write On-Access Scanning enabled
* On-Delivery E-mail Scan Enabled.
* On-Demand Scanning enabled to run once a week on Sunday's at 1:00 AM. PCs that are powered off are set to run missed tasks. On-Demand Scans are limited to run no more than 8 hours and are set to 30% CPU utilization.
For our laptop PCs:
* We have Write On-Access Scanning enabled only. Read scanning disabled recently because of complaints.
* On-Delivery E-mail Scanning disabled over a year ago because of complaints that the scanning was affecting Outlook operation while on the road.
* On-Demand Scanning enabled to run once a week on Wednesday's at 2:00 PM. PCs that are powered off are set to run missed tasks. On-Demand Scans are limited to run no more than 8 hours and are set to 30% CPU utilization.
Our software developers are constantly building/compiling software code. Data is stored on the hard drives on their PCs. As hard drives are getting cheaper and in larger capacity, users are storing more and more data on their PCs.
In an ideal situation, only work-related programs and work-related web surfing is performed by the end users, but I know that is not the case. Some people do go to web sites that they shouldn't be going, which brings down adware/malware/trojans, some people are installing software that are not work-related, etc. Because of this, I've configured our settings to be fairly aggressive to try and keep our system as well protected as possible.
Again, I'm interested in getting feedback from other companies to see how they are managing their systems and whether or not you are encountering the same problems we are. If you have a similar environment as ours, what have you done to improve the end users' experience?
Many thanks in advance!
I've been the ePO Admin for our company's head office for about 4 years now managing about 1200 PCs. We've been getting a lot of complaints from our end users about our various agents/scanning activities and how it is impacting their ability to work. Complaints are steadily growing and is making our IT department look bad in the end users' eyes.
I'm interested in getting some feedback from fellow ePO/VirusScan administrators who manage +1000 PCs to determine:
* Are other companies experiencing the same issues and is no different than our situation?
* What have you done in your environment / infrastructure / policies to correct the problem?
* Are we too lax / just right / too restrictive with our VirusScan configuration given the way we are set up?
* Any recommendations that I can take back to management to help steer us in the right direction?
Here are some details about what I have to deal with. Our company develops software for other companies, military, government, etc. The IT department supports our core set of standardized software on all our PCs, but the individual projects may require/install specialty applications that is requested/required by the customer. A large number of our software developers (70% of all employees in this office) have a separate local admin accounts on their systems to allow them to install/upgrade/remove software on their assigned PC. All users have access to the Internet.
VirusScan Config:
For our desktop PCs:
* We have Read/Write On-Access Scanning enabled
* On-Delivery E-mail Scan Enabled.
* On-Demand Scanning enabled to run once a week on Sunday's at 1:00 AM. PCs that are powered off are set to run missed tasks. On-Demand Scans are limited to run no more than 8 hours and are set to 30% CPU utilization.
For our laptop PCs:
* We have Write On-Access Scanning enabled only. Read scanning disabled recently because of complaints.
* On-Delivery E-mail Scanning disabled over a year ago because of complaints that the scanning was affecting Outlook operation while on the road.
* On-Demand Scanning enabled to run once a week on Wednesday's at 2:00 PM. PCs that are powered off are set to run missed tasks. On-Demand Scans are limited to run no more than 8 hours and are set to 30% CPU utilization.
Our software developers are constantly building/compiling software code. Data is stored on the hard drives on their PCs. As hard drives are getting cheaper and in larger capacity, users are storing more and more data on their PCs.
In an ideal situation, only work-related programs and work-related web surfing is performed by the end users, but I know that is not the case. Some people do go to web sites that they shouldn't be going, which brings down adware/malware/trojans, some people are installing software that are not work-related, etc. Because of this, I've configured our settings to be fairly aggressive to try and keep our system as well protected as possible.
Again, I'm interested in getting feedback from other companies to see how they are managing their systems and whether or not you are encountering the same problems we are. If you have a similar environment as ours, what have you done to improve the end users' experience?
Many thanks in advance!