You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/mtd.md
+83-13Lines changed: 83 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ ms.subservice: onboard
7
7
ms.author: deniseb
8
8
author: denisebmsft
9
9
ms.localizationpriority: medium
10
-
ms.date: 09/05/2024
10
+
ms.date: 10/08/2024
11
11
manager: deniseb
12
12
audience: ITPro
13
13
ms.collection:
@@ -62,21 +62,91 @@ The following table summarizes how to deploy Microsoft Defender for Endpoint on
62
62
-[Overview of Microsoft Defender for Endpoint on Android](microsoft-defender-endpoint-android.md), and
63
63
-[Overview of Microsoft Defender for Endpoint on iOS](microsoft-defender-endpoint-ios.md)
64
64
65
-
**Android**
65
+
**Android Enrollment Scenarios**
66
66
67
-
|Enrollment type |Details |
68
-
|--------------------|-------------|
69
-
|Android Enterprise with Intune |[Deploy on Android Enterprise enrolled devices](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
70
-
|Device Administrator with Intune |[Deploy on Device Administrator enrolled devices](android-intune.md#deploy-on-device-administrator-enrolled-devices)|
71
-
|Unmanaged BYOD OR devices managed by other enterprise mobility management / Set up app protection policy (MAM)|[Configure Defender risk signals in app protection policy (MAM)](android-configure-mam.md)|
67
+
|Scenarios|Defender for Endpoint Supported?|Is the company portal app required on the device?|Protection Profile/Prerequisites|Steps|
|Android Enterprise personally owned devices using a work profile|Yes|Yes|1) It protects only the work profile section 2) To Know more about work profile [click here](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles)|[Deployment steps](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
70
+
|Android Enterprise personally owned devices using a personal profile|Yes|Yes|1) It protects the personal profile. When a customer has a scenario with work profile as well then it protects the entire device. 2) **Prerequisites:****A**. The company portal app needs to be enabled on personal profile. **B**. Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profile.|[Deployment Steps](/defender-endpoint/android-intune)|
71
+
|Android Enterprise corporate owned work profile (COPE)|Yes|Yes|1) It protects only the work profile section. 2) Company Portal app and Microsoft Intune app both are auto installed|[Deployment Steps](/defender-endpoint/android-intune)|
72
+
|Android Enterprise corporate owned personal profile|No|-|-|-|
73
+
|Android Enterprise corporate owned fully managed - no work profile (COBO)|Yes|Yes|1) It protects the entire device. <BR> 2) Company Portal app and Microsoft Intune app both are auto installed.|[Deployment Steps](/defender-endpoint/android-intune)|
|MAM|Yes|Yes, (Need to just install, setup is not required)|1) It protects only enrolled apps. 2) MAM supports with/without Device enrollment or enrolled with third party Enterprise Mobility Management.|[Deployment Steps](/defender-endpoint/android-configure-mam)|
76
+
|Device Administrator|Yes|Yes|1) Intune is ending support for android device administrator management on devices with access to Google Mobile Services (GMS) on December 31, 2024.|-|
77
+
|Android Open-Source Project (AOSP)|No|-|-|-|
72
78
73
-
**iOS**
79
+
## Option 1: Supported Defender for Endpoint on Android enrollment scenarios
80
+
The following sections describe the different scenarios for how to onboard Android devices to Defender for Endpoint.
74
81
75
-
|Enrollment type |Details |
76
-
|--------------------|-------------|
77
-
|Supervised devices with Intune |1. [Deploy as iOS store app](ios-install.md)<br/>2. [Setup Web Protection without VPN for supervised iOS devices](ios-install.md#complete-deployment-for-supervised-devices)|
78
-
|Unsupervised (BYOD) devices enrolled with Intune |[Deploy as iOS store app](ios-install.md)|
79
-
|Unmanaged BYOD OR devices managed by other enterprise mobility management / Set up app protection policy (MAM)|[Configure Defender risk signals in app protection policy (MAM)](ios-install-unmanaged.md)|
82
+
### Android Enterprise personally owned devices using a work profile
83
+
#### Prerequisites
84
+
- Company portal app required on the device
85
+
86
+
#### Protection mode
87
+
- This mode only protects the work profile section Learn more: [Mobile Application Management (MAM) and Android Enterprise personally-owned work profiles in Microsoft Intune](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles#android-enterprise-personally-owned-work-profiles)
88
+
89
+
#### How to deploy
90
+
-[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices)
91
+
92
+
### Android Enterprise personally owned devices using a personal profile
93
+
#### Prerequisites
94
+
- The Company portal needs to be enabled on personal profile.
95
+
- Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profiles.
96
+
97
+
#### Protection mode
98
+
- This mode protects the Android personal profile. When a customer has a scenario with work profile as well this mode protects the entire device.
99
+
100
+
#### How to deploy
101
+
-[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#set-up-microsoft-defender-in-personal-profile-on-android-enterprise-in-byod-mode)
102
+
103
+
### Android Enterprise corporate-owned work profile (COPE)
104
+
#### Prerequisites
105
+
- The Company portal app and Microsoft Intune app both are automatically installed
106
+
107
+
#### Protection mode
108
+
- This mode protects only the work profile section.
109
+
110
+
#### How to deploy
111
+
-[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices)
112
+
113
+
## Table Option 2
114
+
| Scenario | Prerequisites | Protection mode | How to deploy|
115
+
|---|---|---|---|
116
+
|Android Enterprise personally owned devices using a work profile | Company portal app required on the device | This mode only protects the work profile section Learn more: [Mobile Application Management (MAM) and Android Enterprise personally-owned work profiles in Microsoft Intune](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles#android-enterprise-personally-owned-work-profiles)|[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
117
+
|Android Enterprise personally owned devices using a personal profile | The Company portal needs to be enabled on personal profile and Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profiles. | This mode protects the Android personal profile. When a customer has a scenario with work profile as well this mode protects the entire device. |[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#set-up-microsoft-defender-in-personal-profile-on-android-enterprise-in-byod-mode)|
118
+
|Android Enterprise corporate-owned work profile (COPE) | The Company portal app and Microsoft Intune app both are automatically installed | This mode protects only the work profile section. |[Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
119
+
120
+
### Unsupported scenarios
121
+
These scenarios are not currently supported:
122
+
-**Android Enterprise corporate-owned Personal profile (COPE)**
|Supervised Devices (ADE and Apple Configurator Enrollment|Yes|Yes|1) It protects the entire device. In terms of ADE if they use Just in Time (JIT) registration - company portal app not required because app itself will enroll the device through connecting to Intune server|[Deployment Steps](/defender-endpoint/ios-install)|
132
+
|Unsupervised Devices (Device Enrollment)|Yes|Yes|1) It protects the entire device. (In case of web-based device enrollment company portal app is not required because through this after managed app sign in it leads to download configuration policy and not the company portal app)|[Deployment Steps](/defender-endpoint/ios-install)|
133
+
|Unsupervised Devices (User Enrollment)|Yes|Yes|1) It protects work data only. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install)|
134
+
|MAM|Yes|No|1) It protects only enrolled apps. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install-unmanaged)|
0 commit comments