Skip to content

Commit 584522b

Browse files
authored
Merge pull request #4332 from raeanne-marks/docs-editor/behavior-monitor-macos-1750860192
Update behavior-monitor-macos.md
2 parents b968a84 + e6718b9 commit 584522b

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

defender-endpoint/behavior-monitor-macos.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,21 +32,22 @@ f1.keywords: NOCSH
3232
- Microsoft Defender Antivirus
3333
- Supported [versions of macOS](/defender-endpoint/microsoft-defender-endpoint-mac)
3434

35-
> [!IMPORTANT]
36-
> Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
37-
3835
## Overview of behavior monitoring
3936

4037
Behavior monitoring monitors process behavior to detect and analyze potential threats based on the behavior of the applications, daemons, and files within the system. As behavior monitoring observes how the software behaves in real-time, it can adapt quickly to new and evolving threats and block them.
4138

4239
## Prerequisites
4340

4441
- The device must be onboarded to Microsoft Defender for Endpoint.
42+
- For the best experience, Microsoft Defender should be up-to-date with the latest version.
4543
- The minimum Microsoft Defender for Endpoint version number must be [101.25032.0006](/defender-endpoint/mac-whatsnew#apr-2025-build-101250320006---release-version-2012503260) or newer. The version number refers to the `app_version` (also known as **Platform update**).
4644
- Real-time protection (RTP) must be enabled.
4745
- [Cloud-delivered protection](/defender-endpoint/mac-preferences) must be enabled.
46+
4847
## Deployment instructions for behavior monitoring
4948

49+
Behavior Monitoring will soon be on by default. You can confirm your device’s enrollment status by checking the output of ***mdatp health --details features*** in your terminal. If not already enabled, you must configure it.
50+
5051
To deploy behavior monitoring in Microsoft Defender for Endpoint on macOS, you must change the behavior monitoring policy using one of the following methods:
5152

5253
- [Intune](#intune-deployment)
@@ -239,7 +240,7 @@ Once done, disable behavior monitoring statistics:
239240
sudo mdatp config behavior-monitoring-statistics --value disabled
240241
```
241242

242-
If the issue persists, download the [XMDE Client Analyzer](https://aka.ms/XMDEClientAnalyzer), and then contact Microsoft support.
243+
If the issue persists, especially after a reboot, download the [XMDE Client Analyzer](https://aka.ms/XMDEClientAnalyzer), and then contact Microsoft support.
243244

244245
## Network real-time inspection for macOS
245246

0 commit comments

Comments
 (0)