Greetings!
I'm having a problem where my SCEP definitions are updating...but they're always at least one day old.
As far as I can tell, I have everything set to run at least daily, and the clients do eventually get updated...just not the current definition.
For example, my client currently has 1.153.222.0 and per the Microsoft malware portal the latest is 1.153.258.0. Also, when I look in the SCEP client it shows the correct policy, but says, "Policy Applied: 6/19/2013 at 9:40pm" which is last night.
Here are some of the pertinent settings:
EP Policy, Definition updates: Check for EP definitions at specific interval: 6 hrs, Check for EP definitions daily at: 6am, Sources: SCCM, WSUS, MS Update, MS Malware Center (in that order...)
ADR: General: Add to existing is selected, Software Updates: Product: ForeFront EP 2010, Superceded: No, Update Class: Definition Updates, Eval Schedule: Every 6 hrs starting @7:15am, Deployment Schedule: Specific time 1 hr (8:15am), Installation deadline: ASAP, User Exp: Deadline behavior Software Install is checked, Download Settings: Download from DP and install (both cases)
Deployment Package: Last refresh time: 6/20/2013 @7:16am, Show Members: There are 10, latest is 1.153.222.0
SUP syncs every 6hrs starting @3:15am
The ADR is configured to re-use the same deployment, and I see the "Date Created" on the DP is current.
I have GPO's, the only WSUS setting I'm pushing is: Configure Automatic Updates: Disabled
(I've read numerous posts and books that have conflicting information on GPO's and WSUS, this was the nearest I could figure to keep the clients from hitting the Internet and not interfering with the SCCM client's local policies...correct me if I'm wrong on this setting.)
Checking the server, under All software updates and search for "endpoint protection" I see the current definition (1.153.258.0). Which leads me to another thing I can't figure out. Per numerous "how-to" posts, and multiple books, such as Agerlund's "SCCM Mastering the Fundamentals" if I perform the query as explained on page 226, "Date Released or Revised: Last 1 Month, Product: Forefront EP 2010, Update Classification: Definition Updates", I get nothing listed...but if I dump the "Date Released" criteria and add "Superceded: No"...the latest def shows up. Also, if I change the date released criteria to "is greater than or equal to" and "Last 1 day"...the last four defs show up...this makes no sense to me.
As you have probably figured out, I'm new to this. I have searched many forums for answers but haven't figured this out, so if I've missed something obvious or posted this in the wrong forum, I apologize in advance...
Thank you in advance for your help, if you need any logs or anything that would help, please let me know.
Thanks,
-Rob