You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/mac-device-control-jamf.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: conceptual
16
16
ms.subservice: macos
17
17
search.appverid: met150
18
-
ms.date: 02/25/2025
18
+
ms.date: 04/16/2025
19
19
---
20
20
21
21
# Deploy and manage Device Control using JAMF
@@ -46,7 +46,7 @@ Before you begin, confirm your subscription. To access and use device control, y
46
46
47
47
### Step 1: Creating a JSON policy
48
48
49
-
Device Control on Mac is defined through a JSON policy. This policy should have the appropriate groups, rules, and settings defined to tailor specific customer conditions. For example, some enterprise organizations might need to block all removable media devices entirely, while others might have specific exceptions for a vendor or serial number. Microsoft has a [local GitHub repository](https://github.com/microsoft/mdatp-devicecontrol/tree/main/macOS/policy/samples"https://github.com/microsoft/mdatp-devicecontrol/tree/main/macos/policy/samples") that you can use to build your policies.
49
+
Device Control on macOS is defined through a JSON policy. This policy should have the appropriate groups, rules, and settings defined to tailor specific customer conditions. For example, some enterprise organizations might need to block all removable media devices entirely, while others might have specific exceptions for a vendor or serial number. Microsoft has a [local GitHub repository](https://github.com/microsoft/mdatp-devicecontrol/tree/main/macOS/policy/samples"https://github.com/microsoft/mdatp-devicecontrol/tree/main/macos/policy/samples") that you can use to build your policies.
50
50
51
51
For more information about settings, rules, and groups, see [Device Control for macOS](mac-device-control-overview.md).
Copy file name to clipboardExpand all lines: defender-endpoint/mac-exclusions.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Configure and validate exclusions for Microsoft Defender for Endpoint on Mac
3
-
description: Provide and validate exclusions for Microsoft Defender for Endpoint on Mac. Exclusions can be set for files, folders, and processes.
2
+
title: Configure and validate exclusions for Microsoft Defender for Endpoint on macOS
3
+
description: Provide and validate exclusions for Microsoft Defender for Endpoint on macOS. Exclusions can be set for files, folders, and processes.
4
4
ms.service: defender-endpoint
5
5
author: emmwalshh
6
6
ms.author: ewalsh
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: conceptual
16
16
ms.subservice: macos
17
17
search.appverid: met150
18
-
ms.date: 06/14/2024
18
+
ms.date: 04/16/2025
19
19
---
20
20
21
21
# Configure and validate exclusions for Microsoft Defender for Endpoint on macOS
@@ -32,20 +32,20 @@ ms.date: 06/14/2024
32
32
This article provides information on how to define exclusions that apply to on-demand scans, and real-time protection and monitoring.
33
33
34
34
> [!IMPORTANT]
35
-
> The exclusions described in this article don't apply to other Defender for Endpoint on Mac capabilities, including endpoint detection and response (EDR). Files that you exclude using the methods described in this article can still trigger EDR alerts and other detections.
35
+
> The exclusions described in this article don't apply to other Defender for Endpoint on macOS capabilities, including endpoint detection and response (EDR). Files that you exclude using the methods described in this article can still trigger EDR alerts and other detections.
36
36
37
-
You can exclude certain files, folders, processes, and process-opened files from Defender for Endpoint on Mac scans.
37
+
You can exclude certain files, folders, processes, and process-opened files from Defender for Endpoint on macOS scans.
38
38
39
-
Exclusions can be useful to avoid incorrect detections on files or software that are unique or customized to your organization. They can also be useful for mitigating performance issues caused by Defender for Endpoint on Mac.
39
+
Exclusions can be useful to avoid incorrect detections on files or software that are unique or customized to your organization. They can also be useful for mitigating performance issues caused by Defender for Endpoint on macOS.
40
40
41
41
To narrow down which process and/or path and/or extension you need to exclude, use [real-time-protection-statistics](mac-support-perf.md).
42
42
43
43
> [!WARNING]
44
-
> Defining exclusions lowers the protection offered by Defender for Endpoint on Mac. You should always evaluate the risks that are associated with implementing exclusions, and you should only exclude files that you're confident aren't malicious.
44
+
> Defining exclusions lowers the protection offered by Defender for Endpoint on macOS. You should always evaluate the risks that are associated with implementing exclusions, and you should only exclude files that you're confident aren't malicious.
45
45
46
46
## Supported exclusion types
47
47
48
-
The following table shows the exclusion types supported by Defender for Endpoint on Mac.
48
+
The following table shows the exclusion types supported by Defender for Endpoint on macOS.
49
49
50
50
Exclusion|Definition|Examples
51
51
---|---|---
@@ -66,7 +66,7 @@ File, folder, and process exclusions support the following wildcards:
66
66
>
67
67
> The product attempts to resolve firm links when evaluating exclusions. Firm link resolution doesn't work when the exclusion contains wildcards or the target file (on the `Data` volume) doesn't exist.
68
68
69
-
## Best practices for adding antimalware exclusions for Microsoft Defender for Endpoint on macOS.
69
+
## Best practices for adding antimalware exclusions for Microsoft Defender for Endpoint on macOS
70
70
71
71
1. Write down why an exclusion was added to a central location where only SecOps and/or Security Administrator have access. For example, list the submitter, date, app name, reason, and exclusion information.
72
72
@@ -141,7 +141,7 @@ In the following Bash snippet, replace `test.txt` with a file that conforms to y
If Defender for Endpoint on Mac reports malware, then the rule isn't working. If there's no report of malware, and the downloaded file exists, then the exclusion is working. You can open the file to confirm that the contents are the same as what is described on the [EICAR test file website](https://www.eicar.org/download-anti-malware-testfile/).
144
+
If Defender for Endpoint on macOS reports malware, then the rule isn't working. If there's no report of malware, and the downloaded file exists, then the exclusion is working. You can open the file to confirm that the contents are the same as what is described on the [EICAR test file website](https://www.eicar.org/download-anti-malware-testfile/).
145
145
146
146
If you don't have Internet access, you can create your own EICAR test file. Write the EICAR string to a new text file with the following Bash command:
Copy file name to clipboardExpand all lines: defender-endpoint/mac-install-manually.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -123,9 +123,9 @@ To complete this process, you must have admin privileges on the device.
123
123
124
124
:::image type="content" source="media/security-privacy-window-updated.png" alt-text="Screenshot that shows the security and privacy window.":::
125
125
126
-
13. Repeat steps 11 and 12 for all system extensions distributed with Microsoft Defender for Endpoint on Mac.
126
+
13. Repeat steps 11 and 12 for all system extensions distributed with Microsoft Defender for Endpoint on macOS.
127
127
128
-
14. As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on Mac inspects socket traffic and reports this information to the Microsoft Defender portal. When prompted to grant Microsoft Defender for Endpoint permissions to filter network traffic, select **Allow**.
128
+
14. As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on macOS inspects socket traffic and reports this information to the Microsoft Defender portal. When prompted to grant Microsoft Defender for Endpoint permissions to filter network traffic, select **Allow**.
129
129
130
130
:::image type="content" source="media/monterey-install-4.png" alt-text="Screenshot that shows the system extension security preferences2":::
131
131
@@ -261,15 +261,15 @@ See [Uninstalling](mac-resources.md#uninstalling) for details on how to remove M
261
261
> [!TIP]
262
262
>
263
263
> - Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: [Microsoft Defender for Endpoint Tech Community](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/bd-p/MicrosoftDefenderATP).
264
-
> - If you have any feedback that you'll like to share, submit it by opening Microsoft Defender Endpoint on Mac on your device and navigate to **Help**\>**Send feedback**.
264
+
> - If you have any feedback that you'll like to share, submit it by opening Microsoft Defender Endpoint on macOS on your device and navigate to **Help**\>**Send feedback**.
265
265
266
266
## Recommended content
267
267
268
-
-[Learn how to install, configure, update, and use Microsoft Defender for Endpoint on Mac](microsoft-defender-endpoint-mac.md).
268
+
-[Learn how to install, configure, update, and use Microsoft Defender for Endpoint on macOS](microsoft-defender-endpoint-mac.md).
269
269
-[Learn how to set up the Microsoft Defender for Endpoint on macOS policies in Jamf](mac-jamfpro-policies.md).
270
270
-[Learn how to deploy Microsoft Defender for Endpoint on macOS with Jamf Pro](mac-install-with-jamf.md).
271
271
-[Learn how to troubleshoot license issues in Microsoft Defender for Endpoint on Mac](mac-support-license.md).
272
-
-[Learn how to use resources for Microsoft Defender for Endpoint on Mac, including how to uninstall it, how to collect diagnostic logs, CLI commands, and known issues with the product](mac-resources.md).
273
-
-[Learn how to configure Microsoft Defender for Endpoint on Mac in enterprise organizations](mac-preferences.md).
274
-
-[Learn how to install Microsoft Defender for Endpoint on Mac on other management solutions](mac-install-with-other-mdm.md).
272
+
-[Learn how to use resources for Microsoft Defender for Endpoint on macOS, including how to uninstall it, how to collect diagnostic logs, CLI commands, and known issues with the product](mac-resources.md).
273
+
-[Learn how to configure Microsoft Defender for Endpoint on macOS in enterprise organizations](mac-preferences.md).
274
+
-[Learn how to install Microsoft Defender for Endpoint on macOS on other management solutions](mac-install-with-other-mdm.md).
275
275
-[Learn how to detect and block Potentially Unwanted Applications (PUA) using Microsoft Defender for Endpoint on macOS](mac-pua.md).
Copy file name to clipboardExpand all lines: defender-endpoint/mac-install-with-intune.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Intune-based deployment for Microsoft Defender for Endpoint on Mac
3
-
description: Install Microsoft Defender for Endpoint on Mac, using Microsoft Intune.
2
+
title: Intune-based deployment for Microsoft Defender for Endpoint on macOS
3
+
description: Install Microsoft Defender for Endpoint on macOS, using Microsoft Intune.
4
4
ms.service: defender-endpoint
5
5
author: emmwalshh
6
6
ms.author: ewalsh
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: conceptual
16
16
ms.subservice: macos
17
17
search.appverid: met150
18
-
ms.date: 12/02/2024
18
+
ms.date: 04/16/2025
19
19
---
20
20
21
21
# Deploy Microsoft Defender for Endpoint on macOS with Microsoft Intune
@@ -35,14 +35,14 @@ Before you get started, see [the main Microsoft Defender for Endpoint on macOS p
35
35
36
36
## Overview
37
37
38
-
The following table summarizes the steps to deploy and manage Microsoft Defender for Endpoint on Macs via Microsoft Intune. See the following table for more detailed steps:
38
+
The following table summarizes the steps to deploy and manage Microsoft Defender for Endpoint on macOS via Microsoft Intune. See the following table for more detailed steps:
39
39
40
40
|Step |Sample file name |Bundle identifier |
41
41
|---------|---------|---------|
42
42
|Approve system extension|`sysext.mobileconfig`|N/A|
|Full Disk Access|`fulldisk.mobileconfig`|`com.microsoft.wdav.epsext`|
45
-
|Microsoft Defender for Endpoint configuration settings <br/><br/>If you're planning to run non-Microsoft antivirus on Mac, set `passiveMode` to `true`.|`MDE_MDAV_and_exclusion_settings_Preferences.xml`|`com.microsoft.wdav`|
45
+
|Microsoft Defender for Endpoint configuration settings <br/><br/>If you're planning to run non-Microsoft antivirus on macOS, set `passiveMode` to `true`.|`MDE_MDAV_and_exclusion_settings_Preferences.xml`|`com.microsoft.wdav`|
@@ -104,7 +104,7 @@ As part of the Endpoint Detection and Response capabilities, Microsoft Defender
104
104
Download [netfilter.mobileconfig](https://raw.githubusercontent.com/microsoft/mdatp-xplat/master/macos/mobileconfig/profiles/netfilter.mobileconfig) from [GitHub repository](https://github.com/microsoft/mdatp-xplat/tree/master/macos/mobileconfig/profiles).
105
105
106
106
> [!IMPORTANT]
107
-
> Only one `.mobileconfig` (plist) for Network Filter is supported. Adding multiple Network Filters leads to network connectivity issues on Mac. This issue isn't specific to Defender for Endpoint on macOS.
107
+
> Only one `.mobileconfig` (plist) for Network Filter is supported. Adding multiple Network Filters leads to network connectivity issues on macOS. This issue isn't specific to Defender for Endpoint on macOS.
108
108
109
109
To configure your network filter:
110
110
@@ -387,7 +387,7 @@ Once the Intune changes are propagated to the enrolled devices, you can see them
387
387
388
388
#### Client device setup
389
389
390
-
A standard [Company Portal installation](/mem/intune/user-help/enroll-your-device-in-intune-macos-cp) is sufficient for a mac device.
390
+
A standard [Company Portal installation](/mem/intune/user-help/enroll-your-device-in-intune-macos-cp) is sufficient for a Mac device.
Copy file name to clipboardExpand all lines: defender-endpoint/mac-jamfpro-policies.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: conceptual
16
16
ms.subservice: macos
17
17
search.appverid: met150
18
-
ms.date: 12/02/2024
18
+
ms.date: 04/16/2025
19
19
---
20
20
21
21
# Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro
@@ -28,7 +28,7 @@ ms.date: 12/02/2024
28
28
-[Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
29
29
-[Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
30
30
31
-
Use this article to set up policies for Defender for Endpoint on Mac using Jamf Pro.
31
+
Use this article to set up policies for Defender for Endpoint on macOS using Jamf Pro.
32
32
33
33
## Step 1: Get the Microsoft Defender for Endpoint onboarding package
34
34
@@ -385,7 +385,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
385
385
## Step 4: Configure notifications settings
386
386
387
387
> [!NOTE]
388
-
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
388
+
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on macOS requires macOS 11 or later.
389
389
390
390
1. In the Jamf Pro dashboard, select **Computers**, then **Configuration Profiles**.
391
391
@@ -659,7 +659,7 @@ Alternatively, you can download [fulldisk.mobileconfig](https://github.com/micro
659
659
As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on macOS inspects socket traffic and reports this information to the Microsoft Defender portal.
660
660
661
661
> [!NOTE]
662
-
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
662
+
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on macOS requires macOS 11 or later.
663
663
664
664
1. In the Jamf Pro dashboard, select **Computers**, then **Configuration Profiles**.
0 commit comments