Anti-Virus Exclusions and You!
So there is some amount of confusion on what exclusions are needed for various Microsoft products. This blog is not necessarily meant to be a definitive list, but is a compilation, a list, of KB articles that point to the various products and their individual guidance on AV exclusions.
A special shout-out to Aaron Ellison for compiling this list internally! Go team PFE!
(social wiki has a dynamic list that may be more updated here:
https://social.technet.microsoft.com/wiki/contents/articles/953.aspx)
Enterprise Configuration Recommendations:
https://support.microsoft.com/kb/822158
Forefront Configuration:
https://support.microsoft.com/kb/943556
Forefront:
https://support.microsoft.com/kb/943620
https://technet.microsoft.com/en-us/library/cc707727.aspx
Windows / Active Directory:
https://support.microsoft.com/kb/822158
https://support.microsoft.com/kb/837932
FRS:
https://support.microsoft.com/kb/815263
SQL:
https://support.microsoft.com/kb/309422
IIS:
https://support.microsoft.com/kb/821749
https://support.microsoft.com/kb/817442
DHCP:
https://support.microsoft.com/kb/927059
SCOM / MOM:
https://support.microsoft.com/kb/975931
Hyper-V:
https://support.microsoft.com/default.aspx/kb/961804
https://support.microsoft.com/kb/2628135
Exchange:
https://support.microsoft.com/kb/328841
https://support.microsoft.com/kb/823166
https://support.microsoft.com/kb/245822
https://technet.microsoft.com/en-us/library/bb332342(EXCHG.80).aspx
https://technet.microsoft.com/en-us/library/bb332342.aspx
Cluster:
https://support.microsoft.com/kb/250355
SharePoint:
https://support.microsoft.com/kb/320111
https://support.microsoft.com/kb/322941
SMS:
https://support.microsoft.com/kb/327453
ISA:
https://support.microsoft.com/kb/887311
WSUS:
https://support.microsoft.com/kb/900638
SBS:
https://support.microsoft.com/kb/885685
DPM:
technet.microsoft.com/.../bb808691.aspx
Dynamics CRM:
Hope this helps with your configurations!
Cheers,
Jeff
Comments
Anonymous
January 01, 2003
@Brian - Treat this like a DC in terms of exclusions I am told, as the Certificate Service is another ESE engine. Specifically you might want to exclude the transaction logs located at "C:windowssystem32certlog" by default. Shout out to Sean Ivey for this tidbit by the way!Anonymous
August 06, 2010
You can add DPM in as well : technet.microsoft.com/.../bb808691.aspxAnonymous
October 18, 2010
Are there any antivirus exclusions for Microsoft Certificate Services, specifically on an Enterprise CA?Anonymous
December 01, 2010
Anyone have any recommendations for Windows Storage Server 2008?Anonymous
March 02, 2011
The comment has been removedAnonymous
June 07, 2011
Great stuff Jeff!Anonymous
October 28, 2011
Another one for Hyper-V / SCVMM: support.microsoft.com/.../2628135 Includes one entry not included in the existing Hyper-V article