Edit

Microsoft Defender for Endpoint on macOS

Microsoft Defender for Endpoint on macOS helps your organization prevent, detect, investigate, and respond to threats on Mac devices. It uses Apple's system extension architecture and integrates with the Microsoft Defender portal for centralized security operations. Review the capabilities, requirements, and deployment methods before you install and onboard devices.

Defender for Endpoint on macOS includes the following core security capabilities:

  • Next-generation protection: Provides real-time prevention against malware and emerging threats by using cloud-based machine learning, behavior monitoring, and heuristics.
  • Endpoint detection and response (EDR): Provides visibility into endpoint activity for investigating and responding to advanced attacks.
    • AI-driven detection: Uses AI and advanced analytics to detect and respond to threats in close to real time.
    • Centralized management: Use the Microsoft Defender portal at https://security.microsoft.com to view detections and manage devices.
    • Advanced hunting: Query raw event data to proactively hunt for threats on Mac devices.
    • Response actions: Run antivirus scans, isolate devices, collect investigation packages, and collect files for analysis.
    • Live response: Use a remote shell connection for investigation and response on macOS devices.
  • Posture management: Provides risk-based vulnerability management, remediation, and tracking.
  • Streamlined management and operations: Supports deployment, configuration, and management through MDM tools and the Microsoft Defender portal.
  • Integration and extensibility: Connects Defender for Endpoint with APIs, security information and event management (SIEM) solutions, and other Microsoft Defender products.
    • System extensions: Use Apple's system extension architecture on supported Intel and Apple silicon processors.
    • API integration: Integrate Defender for Endpoint data and actions with other systems.
    • SIEM connectors: Connect security data to SIEM solutions for centralized monitoring and automated response.
    • Power BI support: Create Power BI reports that use Defender for Endpoint data and role-based access control (RBAC).

What's new in the latest release

For general updates, see What's new in Microsoft Defender for Endpoint. For macOS product builds and changes, see What's new in Microsoft Defender for Endpoint on Mac.

To send product feedback, open Microsoft Defender on the Mac device, and then select Help > Send feedback. To evaluate preview capabilities, configure the device to use the Beta update channel, formerly named InsiderFast.

Deploy Defender for Endpoint on macOS

Choose a deployment method based on how your organization manages Mac devices. Each method installs the Microsoft Defender app, provides the required macOS permissions and configuration, onboards the device, and verifies connectivity to the Defender for Endpoint service.

Before you begin, review the Defender for Endpoint on macOS prerequisites, including licensing, supported operating systems, permissions, and network connectivity.

Important

If you want to run multiple security solutions side by side, see Considerations for performance, configuration, and support.

You might have already configured mutual security exclusions for devices onboarded to Microsoft Defender for Endpoint. If you still need to set mutual exclusions to avoid conflicts, see Add Microsoft Defender for Endpoint to the exclusion list for your existing solution.

Deployment method Use this method when Considerations
Microsoft Intune Your organization manages Mac devices with Intune. Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. You need a subscription that includes Intune, or you can buy it separately. For more information, see Microsoft Intune licensing.
Jamf Pro Your organization manages Apple devices with Jamf Pro. Jamf Pro is a separate third-party product that requires its own subscription. The Jamf deployment uses separate articles for groups, profiles and policies, packages, and device enrollment.
Another mobile device management solution Your organization uses an MDM solution other than Intune or Jamf Pro. The MDM solution must support package deployment and device-level Apple configuration profiles. Microsoft support doesn't cover third-party product behavior.
Manual deployment You need to install Defender for Endpoint on an individual evaluation or test device without using MDM. A local administrator must install the app and approve the required macOS permissions on the device. Use an MDM solution for centrally managed production deployments.

The exact steps depend on the selected deployment method, but every deployment has the following stages:

  1. Prepare the network and confirm that the device meets the system requirements.
  2. Approve or preapprove the required system extensions and macOS permissions.
  3. Install the Microsoft Defender application package.
  4. Apply the onboarding package to associate the device with your organization.
  5. Verify onboarding, connectivity, antivirus protection, and endpoint detection and response (EDR).

Verify the deployment

After installation and onboarding, confirm that the device reports an organization identifier and can connect to the Defender for Endpoint service:

  • Check the organization identifier:

    mdatp health --field org_id
    
  • Test service connectivity:

    mdatp connectivity test
    

Run an antivirus detection test and an EDR detection test to confirm that the device reports detections and alerts to the Microsoft Defender portal.