Forefront Security for Exchange Server Services
Applies to: Forefront Security for Exchange Server
The Forefront Security for Exchange Server services are the components that run on the Exchange server and control all back-end functionality of FSE. The services process requests from the Microsoft Forefront Server Security Administrator, control the scanning processes, generate e-mail notifications, and store virus incident data (which can be viewed using the Forefront Server Security Administrator). An Administrator-only installation does not install the Forefront Security for Exchange Server services.
The following sections describe the services used by Forefront Security for Exchange server.
FSCController acts as the server component that Forefront Server Security Administrator connects to for configuration and monitoring. FSCController coordinates all Realtime, Manual, and Transport scanning activities. The FSCController startup type defaults to manual.
If you change the startup type to anything other than Manual, FSE may not scan properly.
After being installed, the FSCController becomes a dependency on the FSEIMC service. Due to other dependencies, whenever the Microsoft Exchange Information Store service is started or stopped, the same occurs with the FSCController. The Task Scheduler service must be operating properly for the FSCController to initialize.
The FSCMonitor must run under the Local System account on Exchange 2007. If it is changed to run under a different account, Forefront Security for Exchange Server may not start.
FSCMonitor monitors the Exchange Information Store, Transport stack, and Forefront Security processes to ensure that Forefront Security for Exchange Server provides continuous protection of your messaging environment.
For a mailbox-only role, if FSCController or FSCMonitor is disabled, mail continues to flow, but is not scanned for viruses. For all other roles, you must also stop the Exchange Information Store and Transport services (by selecting Yes when the Stop Other Services prompt appears).
AdoNavSvc is used for browsing the active directory for mailbox names. It will always be in a stopped state unless you are using the Forefront Server Security Administrator to browse mailboxes or public folders in Active Directory or if there is a manual scan or quick scan in progress.
FSEIMC registers the FSE Agent to ensure that messages are scanned by the FSCTransportScanner process. FSEIMC becomes a dependency on the Microsoft Exchange Transport service on Exchange Server 2007. This service normally only runs for a brief time (less than a minute) when Forefront Security for Exchange Server initializes. It then shuts down and does not need to be running for Transport scanning to take place.
FSEMailPickup delivers messages generated by Forefront Server Security, such as notifications, to Exchange for mail pickup. It also handles the delivery of messages from quarantine. If this service is disabled, no notifications are generated and items cannot be delivered from quarantine.
FSCRealtimeScanner provides immediate scanning of e-mail messages that are sent or received by the mailboxes and public folders resident on the Exchange server.
FSCTransportScanner ensures that all messages that pass through the Transport stack are scanned prior to delivery.
The FSCStatisticsService logs scanning statistics for all Forefront Security scan jobs. This information is then available for retrieval by the Microsoft Forefront Security Enterprise Manager.
Disabling the Forefront Security for Exchange Server services
The Forefront Security for Exchange Services can be disabled using the Enable Forefront Security for Exchange Scan option in the General Options work pane.
To disable the Forefront Security for Exchange Server services
Open the Forefront Server Security Administrator.
In the SETTINGS section of the Shuttle Navigator, click General Options. The General Options work pane opens.
In the Enable Forefront Security for Exchange Scan field in the Scanning section, select Disable all.
Recycle Forefront Security services for the change to take effect. (For more information, see Recycling the Forefront Security for Exchange Server services.)
The Forefront Security for Exchange Server services can be enabled by following the same procedure and selecting one of the enabling choices. You can enable all the services, or choose between enabling Store scanning and Transport scanning. The choices in the Enable Forefront Security for Exchange Scan field are:
Enable Store Scanning (Realtime, Manual)
Enable Transport Scanning
Note Forefront Security services must be recycled for the change to take effect.
Recycling the Forefront Security for Exchange Server services
The Service Control Manager is used to recycle the Forefront Security for Exchange Server services.
To recycle the services
Stop all Forefront Security for Exchange Server services. (For details, see Disabling the Forefront Security for Exchange Server services.)
Wait for all services to complete shutting down.
Use Task Manager to make sure that no Forefront Security for Exchange Server processes are still running.
Start all Forefront Security for Exchange Server services.
While the Forefront Security for Exchange Server services are unavailable, mail will continue to flow but will not be scanned for viruses.
Securing the service from unauthorized use
The Forefront Security for Exchange Service utilizes Distributed COM (DCOM) to launch and authenticate Forefront Server Security Administrator connections. You can build an access list of authorized users who can connect to the FSCController utilizing the Forefront Server Security Administrator.
To build an access list of authorized users
Open a Command Prompt window.
Type DCOMCNFG and press ENTER. The Component Services dialog box appears.
In the Console Root section, expand Component Services.
Expand My Computer.
Expand DCOM Config.
Right-click FSCController from the Applications list. The FSCController property dialog appears.
Click the Identity tab and configure your user accounts.
Click the Security tab and use the permissions lists to control which user accounts have rights to launch and activate the FSCController, access the FSCController, or change the DCOM configuration.
Click OK to close the Properties dialog.