You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/mac-install-manually.md
+6-30Lines changed: 6 additions & 30 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -42,6 +42,11 @@ This article describes how to deploy Microsoft Defender for Endpoint on macOS ma
42
42
43
43
Before you get started, see [the main Microsoft Defender for Endpoint on macOS page](microsoft-defender-endpoint-mac.md) for a description of prerequisites and system requirements for the current software version.
44
44
45
+
> [!IMPORTANT]
46
+
> Manual installation of Microsoft Defender for Endpoint on macOS requires changes to the Privacy & Security Settings on macOS. Please consult Apple's documentation for details.
47
+
> [Change Privacy & Security settings on MacOS Sonoma 14](https://support.apple.com/guide/mac-help/change-privacy-security-settings-on-mac-mchl211c911f/14.0/mac/14.0)
48
+
> [Change Privacy & Security settings on MacOS Sequoia 15](https://support.apple.com/guide/mac-help/change-privacy-security-settings-on-mac-mchl211c911f/15.0/mac/15.0)
49
+
>
45
50
## Download installation and onboarding packages
46
51
47
52
Download the installation and onboarding packages from Microsoft Defender portal.
@@ -55,12 +60,10 @@ Download the installation and onboarding packages from Microsoft Defender portal
55
60
3. In Section 2 of the page, select **Download installation package**. Save it as wdav.pkg to a local directory.
56
61
57
62
4. In Section 2 of the page, select **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
58
-
:::image type="content" source="media/onboarding-package-step4.png" alt-text="Screenshot that shows the options to download the installation and onboarding packages.":::
59
63
60
64
5. From a command prompt, verify that you have the two files.
61
65
- Type *cd Downloads* and press **Enter**.
62
66
- Type *ls* and press **Enter**.
63
-
:::image type="content" source="media/Terminal-image-step5.png" alt-text="Screenshot that displays the two download files.":::
64
67
65
68
6. Copy the *wdav.pkg* and *MicrosoftDefenderATPOnboardingMacOs.sh* to the device where you want to deploy the Microsoft Defender for Endpoint on macOS.
66
69
@@ -79,55 +82,37 @@ To complete this process, you must have admin privileges on the device.
:::image type="content" source="media/monterey-install-1.png" alt-text="Screenshot that shows the installation process for the application.":::
84
85
85
86
2. Select **Continue**.
86
87
87
88
3. Read through the **Software License Agreement** and select **Continue** to agree with the terms.
88
89
89
-
:::image type="content" source="media/software-license-agreement.png" alt-text="Screenshot that shows the Software License Agreement.":::
90
-
91
90
4. Read through the *End-User License Agreement (EULA)* and select **Agree**.
92
91
93
-
:::image type="content" source="media/agree-license.png" alt-text="Screenshot that shows the acceptance of the agreement.":::
94
-
95
92
5. From **Destination Select**, select the disk where you want to install the Microsoft Defender Software, for example, *Macintosh HD* and select **Continue**.
96
93
97
-
:::image type="content" source="media/destination-select.png" alt-text="Screenshot that shows the selection of destination for installation.":::
98
-
99
94
> [!NOTE]
100
95
> The amount of disk space required for installation is around 777 MB.
101
96
102
97
6. To change the installation destination, select **Change Install Location...**.
103
98
104
-
:::image type="content" source="media/installation-type.png" alt-text="Screenshot that shows the final installation step.":::
105
-
106
99
7. Select **Install**.
107
100
108
101
8. Enter the password, when prompted.
109
102
110
-
:::image type="content" source="media/password-2g.png" alt-text="Screenshot that shows the password dialog box.":::
111
-
112
-
9. Select **Install Software**.
103
+
1. Select **Install Software**.
113
104
114
105
10. At the end of the installation process, for macOS Ventura (13.0) or latest version, you're prompted to approve the system extensions used by the product. Select **Open Security Preferences**.
115
106
116
-
:::image type="content" source="media/monterey-install-2.png" alt-text="Screenshot that shows the system extension approval":::
117
-
118
107
11. To enable system extension, select **Details**.
119
108
120
-
:::image type="content" source="media/system-extention-image.png" alt-text="Screenshot that shows the system extension.":::
121
109
122
110
12. From the **Security & Privacy** window, select the checkboxes next to **Microsoft Defender** and select **OK**.
123
111
124
-
:::image type="content" source="media/security-privacy-window-updated.png" alt-text="Screenshot that shows the security and privacy window.":::
125
-
126
112
13. Repeat steps 11 and 12 for all system extensions distributed with Microsoft Defender for Endpoint on macOS.
127
113
128
114
14. As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on macOS inspects socket traffic and reports this information to the Microsoft Defender portal. When prompted to grant Microsoft Defender for Endpoint permissions to filter network traffic, select **Allow**.
129
115
130
-
:::image type="content" source="media/monterey-install-4.png" alt-text="Screenshot that shows the system extension security preferences2":::
131
116
132
117
To troubleshoot System Extension issues, refer [Troubleshoot System Extension](mac-support-sys-ext.md).
133
118
@@ -144,12 +129,8 @@ To grant full disk access:
144
129
145
130
2. Grant **Full Disk Access** permission to **Microsoft Defender** and **Microsoft Defenders Endpoint Security Extension**.
146
131
147
-
:::image type="content" source="media/full-disk-access-security-privacy.png" alt-text="The screenshot shows the full disk access's security and privacy.":::
148
-
149
132
3. Select **General** \> **Restart** for the new system extensions to take effect.
150
133
151
-
:::image type="content" source="media/restart-fulldisk.png" alt-text="Screenshot that allows you to restart the system for new system extensions to be enabled.":::
152
-
153
134
4. Enable *Potentially Unwanted Application* (PUA) in block mode.
154
135
155
136
To enable PUA, refer [configure PUA protection](mac-pua.md).
@@ -173,11 +154,9 @@ To grant full disk access:
173
154
Starting with macOS 13, a user must explicitly allow an application to run in background.
174
155
macOS will pop a prompt up, telling the user that Microsoft Defender can run in background.
175
156
176
-
:::image type="content" source="media/background-items-notification.png" alt-text="Screenshot that shows background items notification":::
177
157
178
158
You can view applications permitted to run in background in System Settings => sign in Items => Allow in the Background at any time:
179
159
180
-
:::image type="content" source="media/background-items.png" alt-text="Screenshot that shows background items":::
181
160
182
161
Make sure all Microsoft Defender and Microsoft Corporation items are enabled. If they're disabled, then macOS won't start Microsoft Defender after a machine restart.
183
162
@@ -187,12 +166,9 @@ Starting with macOS 14, a user must explicitly allow an application to access Bl
187
166
macOS will pop a prompt up, telling the user that Microsoft Defender can access Bluetooth (applies only if you use Bluetooth based policies for Device Control).
188
167
Select Allow to grant Microsoft Defender to access Bluetooth.
189
168
190
-
:::image type="content" source="media/macos-defender-bluetooth.png" alt-text="Screenshot that shows Bluetooth access request":::
191
169
192
170
You can confirm that permissions are granted in System Settings => Privacy Settings => Bluetooth.
193
171
194
-
:::image type="content" source="media/macos-defender-bluetooth-review.png" alt-text="Screenshot that shows Review Bluetooth access":::
195
-
196
172
## Onboarding Package
197
173
198
174
Once you install the MDE on macOS client, you must now onboard the package, which registers to your Microsoft Defender for Endpoint tenant and licenses it.
Copy file name to clipboardExpand all lines: defender-endpoint/mac-whatsnew.md
+9-4Lines changed: 9 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,10 +32,11 @@ ms.reviewer: mavel
32
32
33
33
For more information on Microsoft Defender for Endpoint on other operating systems:
34
34
35
+
-[What's new in Microsoft Defender for Endpoint](whats-new-in-microsoft-defender-endpoint.md)
35
36
-[What's new in Microsoft Defender for Endpoint on Linux](linux-whatsnew.md)
36
37
-[What's new in Microsoft Defender for Endpoint on iOS](ios-whatsnew.md)
37
-
-[What's new in Microsoft Defender for Endpoint](whats-new-in-microsoft-defender-endpoint.md)
38
-
-[What's new in Microsoft Defender for Endpoint on macOS](mac-whatsnew.md)
38
+
-[What's new in Microsoft Defender for Endpoint on Android](android-whatsnew.md)
39
+
39
40
40
41
> [!TIP]
41
42
> If you have any feedback that you would like to share, submit it by opening Microsoft Defender for Endpoint on macOS devices and navigating to **Help**\>**Send feedback**.
@@ -58,13 +59,17 @@ To get the latest features, including preview capabilities (such as endpoint det
58
59
59
60
If an end user encounters a prompt for Defender for Endpoint on macOS processes such as `wdavdaemon_enterprise` or `Microsoft Defender Helper`, the end user can safely choose the **Deny** option. This selection doesn't affect Defender for Endpoint's functionality. Enterprises can also add *Microsoft Defender* to allow [incoming connections](https://support.apple.com/en-ca/guide/deployment/dep8d306275f/web). This issue is fixed in macOS Sequoia 15.2.
60
61
62
+
## Tahoe support
63
+
64
+
- Microsoft Defender for Endpoint supports version 26.0 or newer.
65
+
61
66
## Sequoia support
62
67
63
68
- Microsoft Defender for Endpoint supports version 15.0.1 or newer.
64
69
65
70
## macOS Deprecation
66
71
67
-
- Microsoft Defender for Endpoint no longer supports macOS 11 (Big Sur) and 12 (Monterey).
72
+
- Microsoft Defender for Endpoint no longer supports macOS 11 (Big Sur), 12 (Monterey) and 13 (Ventura)
68
73
69
74
## Releases for Defender for Endpoint on macOS
70
75
@@ -81,7 +86,7 @@ Behavior monitoring monitors process behavior to detect and analyze potential th
0 commit comments