Skip to content

Commit f1bffa0

Browse files
committed
Learn Editor: Update behavior-monitor-macos.md
1 parent 46ba318 commit f1bffa0

File tree

1 file changed

+5
-9
lines changed

1 file changed

+5
-9
lines changed

defender-endpoint/behavior-monitor-macos.md

Lines changed: 5 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -32,25 +32,21 @@ f1.keywords: NOCSH
3232
- Microsoft Defender Antivirus
3333
- Supported [versions of macOS](/defender-endpoint/microsoft-defender-endpoint-mac)
3434

35-
> [!IMPORTANT]
36-
> Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
37-
3835
## Overview of behavior monitoring
3936

4037
Behavior monitoring monitors process behavior to detect and analyze potential threats based on the behavior of the applications, daemons, and files within the system. As behavior monitoring observes how the software behaves in real-time, it can adapt quickly to new and evolving threats and block them.
4138

4239
## Prerequisites
4340

4441
- The device must be onboarded to Microsoft Defender for Endpoint.
45-
- [Preview features](/defender-endpoint/preview) must be enabled in the [Microsoft Defender portal](https://security.microsoft.com).
46-
- The device must be in the [Beta channel](/defender-endpoint/mac-updates) (formerly `InsiderFast`).
47-
- The minimum Microsoft Defender for Endpoint version number must be Beta (Insiders-Fast): [101.24042.0002](/defender-endpoint/mac-whatsnew#may-2024-build-101240420008---release-version-2012404280) or newer. The version number refers to the `app_version` (also known as **Platform update**).
42+
- For the best experience, Microsoft Defender should be up-to-date with the latest version.
43+
4844
- Real-time protection (RTP) must be enabled.
4945
- [Cloud-delivered protection](/defender-endpoint/mac-preferences) must be enabled.
50-
- The device must be explicitly enrolled in the preview program.
51-
5246
## Deployment instructions for behavior monitoring
5347

48+
Behavior Monitoring will soon be on by default. You can confirm your device’s enrollment status by checking the output of ***mdatp health --details features*** in your terminal. If not already enabled, you must configure it.
49+
5450
To deploy behavior monitoring in Microsoft Defender for Endpoint on macOS, you must change the behavior monitoring policy using one of the following methods:
5551

5652
- [Intune](#intune-deployment)
@@ -243,7 +239,7 @@ Once done, disable behavior monitoring statistics:
243239
sudo mdatp config behavior-monitoring-statistics --value disabled
244240
```
245241

246-
If the issue persists, download the [XMDE Client Analyzer](https://aka.ms/XMDEClientAnalyzer), and then contact Microsoft support.
242+
If the issue persists, especially after a reboot, download the [XMDE Client Analyzer](https://aka.ms/XMDEClientAnalyzer), and then contact Microsoft support.
247243

248244
## Network real-time inspection for macOS
249245

0 commit comments

Comments
 (0)