09-Mar-2020 15:22

You could have quite a few Antimalware policies, but I’ll be working with the default policy in my screenshots today.

At this point, those who are familiar with these settings may be ready to skip ahead. You’ve got a few options here, so let’s discuss what they actually do.

Multiple UNC paths can be specified, as seen below.

The error references the UNC: \SERVER.domainname\Kiosk-SCEP\x86 - this hyperlinked UNC is clickable from the event log - clicking it opens it, so it doesn't seem to be a permissions issue (the service account is stored in credential manager.) Looking at the policy that the SCEP client references, the UNC Path is set to: \SERVER.domainname\Kiosk-SCEP - it hasn't been set to the x86 folder.When the SCEP client definitions become too far out of date, or if the end user clicks Update in the UI, the SCEP client looks for a Fall Back Order registry key in HKLM\Software\Policies\Microsoft\Microsoft Antimalware\Signature Updates .The SCEP client will check each update source in order until it locates a source that has available definitions.Believe it or not, SCEP cannot use CM as an update source location for definitions, which is why this setting does not modify the Fall Back Order registry key.

If we select this option, we must also define the UNC paths in the definition updates section of the antimalware policy. This option modifies both the Fallback Order key and the Definition Update File Share Sources key.

Hi everyone, my name is Nicholas Jones, Premier Field Engineer with Microsoft, specializing in System Center Configuration Manager.