Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING Configmanager client security configuration advisory

  • Thread starter Thread starter 33akhil
  • Start date Start date
  • Replies Replies 0
  • Views Views 225

33akhil

New Member
Messages
4
Reaction score
0
Points
1
My question is specific to Configmanager Client Logs folder. This location is C:\windows\CCM\Logs by default.



Configmanager client installation creates write permissions for this folder to all users. This creates a situation, where everyone has write rights to a folder which has been excluded from antivirus too. In high secure environment this can be seen as a security risk. This folder can be used to store malicious software by anyone.



1. Is recommendation for antivirus exclusion to this folder still valid?
2. What is your recommended best practice for mitigating this security risk?

Recommended antivirus exclusions for Configuration Manager - Configuration Manager

Lists the recommended antivirus exclusions for Configuration Manager site servers, site systems, and clients.
 
Back
Top