Skip to content

Commit bc25dd4

Browse files
authored
Update mtd.md
1 parent aae78b8 commit bc25dd4

File tree

1 file changed

+17
-17
lines changed

1 file changed

+17
-17
lines changed

defender-endpoint/mtd.md

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -62,34 +62,34 @@ The following table summarizes how to deploy Microsoft Defender for Endpoint on
6262
- [Overview of Microsoft Defender for Endpoint on Android](microsoft-defender-endpoint-android.md), and
6363
- [Overview of Microsoft Defender for Endpoint on iOS](microsoft-defender-endpoint-ios.md)
6464

65-
**Android Enrollment Scenarios**
65+
## Supported Android enrollment Scenarios
6666

67-
|Scenarios|Company portal app required on the device?|Protection Profile/Prerequisites|Steps|
67+
|Scenarios|Company portal app required on the device?|Protection Profile/Prerequisites|How to deploy|
6868
| -------- | -------- | -------- | -------- |
69-
|Android Enterprise personally owned devices using a work profile|Yes| Protects only the work profile section. [Learn more about work profiles](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles)|[Deployment steps](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
70-
|Android Enterprise personally owned devices using a personal profile|Yes| Protects the personal profile. When a customer has a scenario with work profile as well then it protects the entire device. Note the following **prerequisites:** **A**. The company portal app must be enabled on personal profile. **B**. Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profile.|[Deployment Steps](/defender-endpoint/android-intune)|
71-
|Android Enterprise corporate owned work profile (COPE)|Yes|Protects only the work profile section. The Company Portal app and Microsoft Intune app both are automatically installed. | [Deployment Steps](/defender-endpoint/android-intune) |
72-
|Android Enterprise corporate owned fully managed - no work profile (COBO)|Yes|Protects the entire device. The Company Portal app and Microsoft Intune app both are automatically installed.|[Deployment Steps](/defender-endpoint/android-intune)|
73-
|MAM|Yes, (need to just install, setup is not required) | Protects only enrolled apps. MAM supports with/without Device enrollment or enrolled with third party Enterprise Mobility Management.|[Deployment Steps](/defender-endpoint/android-configure-mam)|
74-
|Device Administrator|Yes|Intune is ending support for android device administrator management on devices with access to Google Mobile Services (GMS) on December 31, 2024.|-|
69+
|Android Enterprise personally owned devices using a work profile|Yes| Protects only the work profile section. [Learn more about work the profile](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles)|[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices) |
70+
|Android Enterprise personally owned devices using a personal profile|Yes| Protects the personal profile. When a customer has a scenario with work profile as well then it protects the entire device. Note the following: The company portal app must be enabled on personal profile and the Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profile.|[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#set-up-microsoft-defender-in-personal-profile-on-android-enterprise-in-byod-mode)|
71+
|Android Enterprise corporate owned work profile (COPE)|Yes|Protects only the work profile section. The Company Portal app and Microsoft Intune app both are automatically installed. | [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices) |
72+
|Android Enterprise corporate owned fully managed - no work profile (COBO)|Yes|Protects the entire device. The Company Portal app and Microsoft Intune app both are automatically installed.|[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune#deploy-on-android-enterprise-enrolled-devices)|
73+
|MAM|Yes, (need to just install, setup is not required) | Protects only enrolled apps. MAM supports with/without Device enrollment or enrolled with third party Enterprise Mobility Management.|[Configure Microsoft Defender for Endpoint on Android risk signals using App Protection Policies (MAM)](/defender-endpoint/android-configure-mam)|
74+
|Device Administrator|Yes|Intune is ending support for android device administrator management on devices with access to Google Mobile Services (GMS) on December 31, 2024.|[-](https://learn.microsoft.com/en-us/defender-endpoint/android-intune#deploy-on-device-administrator-enrolled-devices)|
7575

7676

77-
### Unsupported scenarios
77+
### Unsupported Android enrollment scenarios
7878
These scenarios are not currently supported:
7979
- **Android Enterprise corporate-owned Personal profile**
8080
- **Android Enterprise corporate owned dedicated devices (COSU) (Kiosk/Shared)**
8181
- **Android Open-Source Project (AOSP)**
8282

83-
**iOS Enrollment Scenarios**
83+
## Supported iOS enrollment Scenarios
8484

85+
|Scenarios|Is company portal app required on device?|Protection Profile/Prerequisites|Steps|
86+
| -------- | -------- | -------- | -------- |
87+
|Supervised Devices (ADE and Apple Configurator Enrollment|Yes|Protects the entire device. For ADE if users use Just in Time (JIT) registration - company portal app not required because app itself will enroll the device by connecting to Intune server| [Deployment Steps](/defender-endpoint/ios-install) |
88+
|Unsupervised Devices (Device Enrollment)|Yes|1)Protects the entire device. (In case of web-based device enrollment company portal app is not required because through this after managed app sign in it leads to download configuration policy and not the company portal app)|[Deployment Steps](/defender-endpoint/ios-install)|
89+
|Unsupervised Devices (User Enrollment)|Yes|1) Protects work data only. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install)|
90+
|MAM|No|Protects only enrolled apps. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install-unmanaged)|
8591

86-
|Scenarios|Is MDE supported?|Is company portal app required on device?|Protection Profile/Prerequisites|Steps|
87-
| -------- | -------- | -------- | -------- | -------- |
88-
|Supervised Devices (ADE and Apple Configurator Enrollment|Yes|Yes|1) It protects the entire device. In terms of ADE if they use Just in Time (JIT) registration - company portal app not required because app itself will enroll the device through connecting to Intune server| [Deployment Steps](/defender-endpoint/ios-install) |
89-
|Unsupervised Devices (Device Enrollment)|Yes|Yes|1) It protects the entire device. (In case of web-based device enrollment company portal app is not required because through this after managed app sign in it leads to download configuration policy and not the company portal app)|[Deployment Steps](/defender-endpoint/ios-install)|
90-
|Unsupervised Devices (User Enrollment)|Yes|Yes|1) It protects work data only. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install)|
91-
|MAM|Yes|No|1) It protects only enrolled apps. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install-unmanaged)|
92-
|Dedicated/Shared/Kiosk Devices|No|-|-|- |
92+
iOS Dedicated/shared/kiosk device enrollment is not supported.
9393

9494
**Android low touch onboarding supported scenarios**
9595

0 commit comments

Comments
 (0)