Skip to content

Commit c204007

Browse files
authored
Merge pull request #1523 from denishdonga27/docs-editor/mtd-1728304149
Update mtd.md
2 parents 7d008cb + 28b4140 commit c204007

File tree

1 file changed

+83
-13
lines changed

1 file changed

+83
-13
lines changed

defender-endpoint/mtd.md

Lines changed: 83 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.subservice: onboard
77
ms.author: deniseb
88
author: denisebmsft
99
ms.localizationpriority: medium
10-
ms.date: 09/05/2024
10+
ms.date: 10/08/2024
1111
manager: deniseb
1212
audience: ITPro
1313
ms.collection:
@@ -62,21 +62,91 @@ The following table summarizes how to deploy Microsoft Defender for Endpoint on
6262
- [Overview of Microsoft Defender for Endpoint on Android](microsoft-defender-endpoint-android.md), and
6363
- [Overview of Microsoft Defender for Endpoint on iOS](microsoft-defender-endpoint-ios.md)
6464

65-
**Android**
65+
**Android Enrollment Scenarios**
6666

67-
|Enrollment type |Details |
68-
|--------------------|-------------|
69-
|Android Enterprise with Intune |[Deploy on Android Enterprise enrolled devices](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
70-
|Device Administrator with Intune |[Deploy on Device Administrator enrolled devices](android-intune.md#deploy-on-device-administrator-enrolled-devices)|
71-
|Unmanaged BYOD OR devices managed by other enterprise mobility management / Set up app protection policy (MAM)|[Configure Defender risk signals in app protection policy (MAM)](android-configure-mam.md)|
67+
|Scenarios|Defender for Endpoint Supported?|Is the company portal app required on the device?|Protection Profile/Prerequisites|Steps|
68+
| -------- | -------- | -------- | -------- | -------- |
69+
|Android Enterprise personally owned devices using a work profile|Yes|Yes|1) It protects only the work profile section 2) To Know more about work profile [click here](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles)|[Deployment steps](android-intune.md#deploy-on-android-enterprise-enrolled-devices)|
70+
|Android Enterprise personally owned devices using a personal profile|Yes|Yes|1) It protects the personal profile. When a customer has a scenario with work profile as well then it protects the entire device. 2) **Prerequisites:** **A**. The company portal app needs to be enabled on personal profile. **B**. Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profile.|[Deployment Steps](/defender-endpoint/android-intune)|
71+
|Android Enterprise corporate owned work profile (COPE)|Yes|Yes|1) It protects only the work profile section. 2) Company Portal app and Microsoft Intune app both are auto installed| [Deployment Steps](/defender-endpoint/android-intune) |
72+
|Android Enterprise corporate owned personal profile|No|-|-|-|
73+
|Android Enterprise corporate owned fully managed - no work profile (COBO)|Yes|Yes|1) It protects the entire device. <BR> 2) Company Portal app and Microsoft Intune app both are auto installed.|[Deployment Steps](/defender-endpoint/android-intune)|
74+
|Android Enterprise corporate owned dedicated devices (COSU)(Kiosk/Shared)|No|-|-|-|
75+
|MAM|Yes|Yes, (Need to just install, setup is not required)|1) It protects only enrolled apps. 2) MAM supports with/without Device enrollment or enrolled with third party Enterprise Mobility Management.|[Deployment Steps](/defender-endpoint/android-configure-mam)|
76+
|Device Administrator|Yes|Yes|1) Intune is ending support for android device administrator management on devices with access to Google Mobile Services (GMS) on December 31, 2024.|-|
77+
|Android Open-Source Project (AOSP)|No|-|-|-|
7278

73-
**iOS**
79+
## Option 1: Supported Defender for Endpoint on Android enrollment scenarios
80+
The following sections describe the different scenarios for how to onboard Android devices to Defender for Endpoint.
7481

75-
|Enrollment type |Details |
76-
|--------------------|-------------|
77-
|Supervised devices with Intune |1. [Deploy as iOS store app](ios-install.md)<br/>2. [Setup Web Protection without VPN for supervised iOS devices](ios-install.md#complete-deployment-for-supervised-devices)|
78-
|Unsupervised (BYOD) devices enrolled with Intune |[Deploy as iOS store app](ios-install.md)|
79-
|Unmanaged BYOD OR devices managed by other enterprise mobility management / Set up app protection policy (MAM)|[Configure Defender risk signals in app protection policy (MAM)](ios-install-unmanaged.md)|
82+
### Android Enterprise personally owned devices using a work profile
83+
#### Prerequisites
84+
- Company portal app required on the device
85+
86+
#### Protection mode
87+
- This mode only protects the work profile section Learn more: [Mobile Application Management (MAM) and Android Enterprise personally-owned work profiles in Microsoft Intune](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles#android-enterprise-personally-owned-work-profiles)
88+
89+
#### How to deploy
90+
- [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices)
91+
92+
### Android Enterprise personally owned devices using a personal profile
93+
#### Prerequisites
94+
- The Company portal needs to be enabled on personal profile.
95+
- Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profiles.
96+
97+
#### Protection mode
98+
- This mode protects the Android personal profile. When a customer has a scenario with work profile as well this mode protects the entire device.
99+
100+
#### How to deploy
101+
- [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#set-up-microsoft-defender-in-personal-profile-on-android-enterprise-in-byod-mode)
102+
103+
### Android Enterprise corporate-owned work profile (COPE)
104+
#### Prerequisites
105+
- The Company portal app and Microsoft Intune app both are automatically installed
106+
107+
#### Protection mode
108+
- This mode protects only the work profile section.
109+
110+
#### How to deploy
111+
- [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices)
112+
113+
## Table Option 2
114+
| Scenario | Prerequisites | Protection mode | How to deploy|
115+
|---|---|---|---|
116+
|Android Enterprise personally owned devices using a work profile | Company portal app required on the device | This mode only protects the work profile section Learn more: [Mobile Application Management (MAM) and Android Enterprise personally-owned work profiles in Microsoft Intune](/mem/intune/apps/android-deployment-scenarios-app-protection-work-profiles#android-enterprise-personally-owned-work-profiles) | [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices) |
117+
|Android Enterprise personally owned devices using a personal profile | The Company portal needs to be enabled on personal profile and Microsoft Defender must be already installed and active in work profile to enable Microsoft Defender in personal profiles. | This mode protects the Android personal profile. When a customer has a scenario with work profile as well this mode protects the entire device. | [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#set-up-microsoft-defender-in-personal-profile-on-android-enterprise-in-byod-mode) |
118+
|Android Enterprise corporate-owned work profile (COPE) | The Company portal app and Microsoft Intune app both are automatically installed | This mode protects only the work profile section. | [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](android-intune.md#deploy-on-android-enterprise-enrolled-devices) |
119+
120+
### Unsupported scenarios
121+
These scenarios are not currently supported:
122+
- **Android Enterprise corporate-owned Personal profile (COPE)**
123+
- **Android Enterprise corporate owned dedicated devices (COSU) (Kiosk/Shared)**
124+
125+
126+
**iOS Enrollment Scenarios**
127+
128+
129+
|Scenarios|Is MDE supported?|Is company portal app required on device?|Protection Profile/Prerequisites|Steps|
130+
| -------- | -------- | -------- | -------- | -------- |
131+
|Supervised Devices (ADE and Apple Configurator Enrollment|Yes|Yes|1) It protects the entire device. In terms of ADE if they use Just in Time (JIT) registration - company portal app not required because app itself will enroll the device through connecting to Intune server| [Deployment Steps](/defender-endpoint/ios-install) |
132+
|Unsupervised Devices (Device Enrollment)|Yes|Yes|1) It protects the entire device. (In case of web-based device enrollment company portal app is not required because through this after managed app sign in it leads to download configuration policy and not the company portal app)|[Deployment Steps](/defender-endpoint/ios-install)|
133+
|Unsupervised Devices (User Enrollment)|Yes|Yes|1) It protects work data only. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install)|
134+
|MAM|Yes|No|1) It protects only enrolled apps. (VPN has access to entire device so can scan all app traffic)|[Deployment Steps](/defender-endpoint/ios-install-unmanaged)|
135+
|Dedicated/Shared/Kiosk Devices|No|-|-|- |
136+
137+
**Android low touch onboarding supported scenarios**
138+
139+
1. Android Enterprise personally owned devices using a work profile
140+
141+
1. Android Enterprise corporate owned work profile (COPE)
142+
143+
1. Android Enterprise corporate owned fully managed - No work profile (COBO)
144+
145+
**iOS zero touch onboarding supported scenarios**
146+
147+
1. Supervised Devices (ADE and Apple Configurator Enrollment)
148+
149+
1. Unsupervised Devices (Device Enrollment)
80150

81151
### End-user onboarding
82152

0 commit comments

Comments
 (0)