This message was deleted.
# citrix-vad
s
This message was deleted.
n
Hold on, let me find the old thread about this. I never got around to writing up a guide, unfortunately.
Start with this: https://www.linen.dev/s/worldofeuc/t/7982641/anyone-found-a-good-way-to-tell-what-is-consuming-pvs-cache-#624bcb6a-ab98-46db-9310-dff2372ef7d7 Those few posts show my GPO settings for Defender, along with my sealing script for the master/golden image, as those particular settings must be baked into the image. They can be reinforced via GPO, but they must be baked in to work properly.
I did not onboard the master image, and would never recommend it. Instead, I used the GPO startup script method, where you download the onboarding scripts from your Defender portal and use Onboard-NonPersistentMachine.ps1 in a startup script.
💯 1
I created a scheduled task to download Defender updates, and ran it on one of my management servers, using an account that had full control over the share that was used for them: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/deployment-vdi-microsoft-defender-antivirus?view=o365-worldwide
If you have any questions, fire away and I'll answer what I can recall. We don't use Defender at the new place, so I can probably only be so helpful.
Also, this is the PS script I used for the scheduled task: https://github.com/JesseEsquivel/MDATP/blob/master/Scripts/VDI/MDATP-Sec-Intel-Packages.ps1 I did modify it so that if it failed it e-mailed myself and another person. If you want a copy of that, let me know and I'll attach it here.
And yes, I feel guilty about not blogging this. Somewhere, Kasper is shaking his head at me.
😆 1
d
Awesome! I will look at these links in little and let you know what questions I have. Thank you!!!
@Nick Panaccio dumb question time...what should go in the scrip parameters portion if anything?
also i put this powershell ona network drive, not on the gold image bc i dont want the gold being onboarded
n
No parameters required. I actually used the folder that the GPOs files are stored in on Sysvol for the script, so either way works.
d
it doesnt apear to be running. I thought that maybe the execution policy needs to be set. I even tried to put the files in the grouppolicy/machine/startup folder but no dice. is there a way to see events for this in the log?
n
I want to say that there may be an event in one of the Defender event logs, but I couldn't tell you which one anymore.
d
so strange
ok i got it working. im just dumb...thought i didn't need the .CMD file that is part of the vdi onboarding. Thought its either the Powershell file or the CMD. lol
n
Crap, you know what? I think I might have said you only need the PS earlier.
I totally forgot that it has to live with the PS1 file since it calls the cmd.
Because why the hell would MS not just do everything in one script.
💯 1
And bam, there's your logging from the cmd file: eventcreate /l Application /so WDATPOnboarding /t Information /id 20 /d "%successOutput%" >NUL 2>&1
d
yea see i wasn't getting any logging from that. I looked online and saw that entry for WDATP but nothing in my logs which then got me thinking to look at the PS1 files contents where i saw it call for the CMD
I saw a cool post on reddit with someone who made their own script logic to avoid onboarding the gold image https://pastebin.com/Y9u2mY7f 1. if ($env:computerName.contains("GOLD")) { 2. Write-Host "This is a Citrix Gold Server, onboarding will be skipped" 3. Exit 4. } 5. else { 6. Write-Host "Onboarding has started" 7. & "C:\WINDOWS\System32\GroupPolicy\Machine\Scripts\Startup\Onboard-NonPersistentMachine.ps1" 8. 9. }
Thanks for your help @Nick Panaccio I still have to look at other parts you linked. the VDI won't update defender itself from microsoft? It needs all those other steps?
n
You can configure Defender to use Windows Update for the defs, but I think best practice is to have the defs downloaded to a share every 4-6 hours and letting the VDAs hit that share at set intervals to grab the latest defs.
I don't know anyone who leaves Windows Update on in Citrix, so that option is basically DOA.
d
ah i see, i thought defender would grab them outside windows update
m
Do you use BIS-F? I drop the content of the onboarding zip into bisf. never had any problems, works extremly well.
I stopped providing the Signature share, way too much work, I just set everything in GPO to MMPC updates, and monitore the signature age, didn't have any problems since then.
d
Nope, don't quite understand BIS-F at all unfortunately. I looked at it a bit before but was overwhelmed and moved on. @Nick Panaccio so im looking at the creation of the share. I made the folder as they requested. then it says to run the SignatureDownloadCustomTask via powerhsell to create the task but later on you write you had another scheduled task running.
im thinking of a using the same server to download and host the share. I could just set up the files to download directly to the share right?
m
You could drop the idea of the share and the script and just set it like this, never look back, that share was just to error prone
n
I only have experience with using a share, which worked fine for us. As for the task, I used the one from that Git page I linked.
d
oh? interesting. So in the defender GPO under security intelligence updates change that to what you wrote and defender will get the updates?
@Marco Hofmann does it require rebooting the vda or "baking" in the gpo?
n
You still need to bake that in if you want to be 100% sure.
m
I use Windows Server 2019 via MCS everywhere. Golde Images build by MDT. I do the onboarding with the two Scripts from the ZIP file, which are linked to the BIS-F Framework. And then I just set that setting via GPO and I also monitor the signature age to be sure that it really works. Never had any issues. Yes, I do apply my Defender GPO at the Master, bevore the MCS process AND at the OU with the MCS clones.
d
Awesome I'm using the same server. Will test now! Thank both of you guys! It's nice to see two different methods but I'm a sucker for the easier one lol
m
I had the signature shares+script everywhere, but it triggered me hard, that my whole security stack was bound to one single script that has to work extremely reliable. I ditched that after two years of constant fear.
n
It may not matter, but it's worth noting that definition updates via MMPC are larger, so it'll take longer to download, etc.
Compared to using the shares.
m
Yes, that's true, and the reason I started with the share. But that single point a failure was something I couldn't live with.
n
That's why I built in some reporting on failures for the PS script that the scheduled task ran. Never actually failed, but if it did, I'd have received an e-mail.
👍🏻 1