Prerequisites for Installing Forefront Endpoint Protection on a Server

Applies To: Forefront Endpoint Protection

The Forefront Endpoint Protection Setup wizard includes a prerequisites verification that checks that the prerequisites are already installed before you continue with the installation. If the prerequisites verification check identifies missing prerequisites, the check points you to locations where you can download and install the required components.

Forefront Endpoint Protection Server Prerequisites

The following table is the list of minimum requirements for installing the Forefront Endpoint Protection server.

Prerequisite Minimum requirements Notes

Memory

2 GB of RAM

Available disk space

  • Forefront Endpoint Protection server: 600 MB

  • Forefront Endpoint Protection database: 1.25 GB

  • Forefront Endpoint Protection reporting database: 1.25 GB

In database recovery situations in a large scale deployment (more than 10,000 client computers), the computer running Microsoft SQL ServerĀ® where the Forefront Endpoint Protection reporting database resides may require that the tempdb database be configured with a 500 GB Logical Unit Number (LUN) for its data file. For more information about configuring the tempdb data file, see Optimizing tempdb Performance (https://go.microsoft.com/fwlink/?LinkId=206862).

Operating system

  • Windows ServerĀ® 2003 Standard, Enterprise, or Datacenter Edition Service Pack 2 (x86 or x64), or

  • Windows Server 2008 Standard, Enterprise, or Datacenter Service Pack 1 (x86 or x64), or

  • Windows Server 2008 R2 Standard, Enterprise, or Datacenter (x64)

Database servers

  • Microsoft SQL Server 2005 Standard or Enterprise Edition Service Pack 3 (x86 or x64), or

  • Microsoft SQL Server 2008 Standard or Enterprise (x86 or x64), or

  • Microsoft SQL Server 2008 R2 Standard or Enterprise (x86 or x64)

  • When using an RTM release of SQL Server 2008, make sure that the default instance is defined. If the default instance is not defined, reporting and alerting does not function, because data cannot flow up to the Configuration Manager site server.

  • Verify that all computers that are running SQL Server are joined to the domain, that the user account running Setup is a member of sysadmin SQL Server role, and that all SQL Server services are running. Additionally, in nonclustered SQL Server environments, the SQL Server services should be configured to start automatically.

  • The user account running Setup will be set as the owner of the following SQL Server databases:

    • FEPDB_XXX

    • FEPDW_XXX

Additional requirements for installing Forefront Endpoint Protection reporting database

  • SQL Server Analysis Services

  • SQL Server Integration Services

  • SQL Server Reporting Services

  • SQL Server Agent

  • For SQL Server Analysis Services, the user account running Setup, or a domain group of which it is a member, must belong to the server administrator role on your specified SQL Server Analysis Server. For more information, see Analysis Server Properties Dialog Box (https://go.microsoft.com/fwlink/?LinkID=204204).

  • The Forefront Endpoint Protection reporting database and server running SQL Server Analysis Services must be installed on the same SQL Server instance.

  • On the computer that is running SQL Server Analysis Services, the following ports must be open for incoming traffic:

    • SQL Server (TCP 1433)

    • SQL Server Analysis Services (TCP 2383)

    For more information, see Configuring the Windows Firewall to Allow SQL Server Access (https://go.microsoft.com/fwlink/?LinkId=128365).

  • For Forefront Endpoint Protection reporting to function, you must make sure that the Forefront Endpoint Protection client that is installed as part of Forefront Endpoint Protection has access to definition updates via the Configuration Manager client agent, Windows Server Update Services, or Microsoft Update.

Additional requirements for installing Forefront Endpoint Protection reporting database on a SQL Server cluster

  • The name you entered in the SQL Network Name box for your SQL Server cluster must be registered in the domain.

  • SQL Server Integration Services must be installed on all nodes and must be part of the cluster group.

Configuration Manager

  • Microsoft System Center Configuration Manager 2007 Service Pack 2 installed with default roles, and either:

    • Microsoft System Center Configuration Manager 2007 R2 installed and configured to use SQL Server Reporting Services, or

    • Microsoft System Center Configuration Manager 2007 R3 installed and configured to use SQL Server Reporting Services

  • The following client agents are installed and configured:

    • Hardware Inventory

    • Software Distribution

    • Desired Configuration Management

Additional requirements

  • No other version of Forefront Endpoint Protection is installed

  • Microsoft Windows Installer version 3.1

  • Microsoft .Net Framework 3.5 Service Pack 1

  • Configuration Manager Hotfix KB2271736 (https://go.microsoft.com/fwlink/?LinkId=203936)

  • SQL Server Analysis Management Objects

  • The computer where Setup is run is not pending a restart from a previous install or update

  • The user account running Setup is a domain account for the domain of which the Forefront Endpoint Protection server is a member, has local administrative credentials, and has Configuration Manager administrative credentials

  • You must install SQL Server Analysis Management Objects on the computer where Setup is run when the Forefront Endpoint Protection reporting database is being installed on a remote computer.

  • You can download the SQL Server Analysis Management Objects for your version of SQL Server from the following locations:

    • For SQL Server 2008 R2, visit Microsoft SQL Server 2008 R2 Feature Pack (https://go.microsoft.com/fwlink/?LinkId=206861), go to the Microsoft SQL Server 2008 R2 Analysis Management Objects section, and download the appropriate file based on your system architecture.

    • For SQL Server 2008, visit Microsoft SQL Server 2008 Feature Pack (https://go.microsoft.com/fwlink/?LinkId=206625), go to the Microsoft Analysis Management Objects section, and download the appropriate file based on your system architecture.

    • For SQL Server 2005, visit Feature Pack for Microsoft SQL Server 2005 (https://go.microsoft.com/fwlink/?LinkId=206624), go to the Microsoft SQL Server 2005 Management Objects Collection section, and download the appropriate file based on your system architecture.

Forefront Endpoint Protection Console Prerequisites

The following table is the list of minimum requirements for installing the Forefront Endpoint Protection console.

Prerequisite Minimum requirements

Configuration Manager

  • Microsoft System Center Configuration Manager 2007 Service Pack 2 Console, or

  • Microsoft System Center Configuration Manager 2007 R2, or

  • Microsoft System Center Configuration Manager 2007 R3

Additional requirements

  • Microsoft .Net Framework 3.5 Service Pack 1

  • Configuration Manager Hotfix KB2271736 (https://go.microsoft.com/fwlink/?LinkId=203936)

  • The computer running Setup is not pending a restart from a previous install or update

  • The user account running Setup is a domain account for the domain of which the Forefront Endpoint Protection server is a member, has local administrative credentials, and has Configuration Manager administrative credentials