Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Microsoft Defender for Endpoint on macOS helps your organization prevent, detect, investigate, and respond to threats on Mac devices. It uses Apple's system extension architecture and integrates with the Microsoft Defender portal for centralized security operations. Review the capabilities, requirements, and deployment methods before you install and onboard devices.
Defender for Endpoint on macOS includes the following core security capabilities:
- Next-generation protection: Provides real-time prevention against malware and emerging threats by using cloud-based machine learning, behavior monitoring, and heuristics.
- Real-time protection: Uses next-generation antivirus protection, local and cloud-based machine learning, behavior monitoring, and heuristics.
- Cloud-delivered protection: Detects and blocks new and emerging threats, including infostealers and supply chain attacks.
- Security settings configuration: Configure antivirus, cloud protection, and scan options, detect and block potentially unwanted applications, and define custom indicators of compromise for IP addresses and URLs.
- Network protection and web protection: Help protect Mac devices from web-based threats by controlling connections to malicious or unwanted sites.
- Tamper protection: Protects security settings from unauthorized changes.
- Device control: Monitors and restricts access to removable media, including USB storage, Bluetooth, and other peripherals. Deploy granular policies through Intune or Jamf Pro.
- Endpoint detection and response (EDR): Provides visibility into endpoint activity for investigating and responding to advanced attacks.
- AI-driven detection: Uses AI and advanced analytics to detect and respond to threats in close to real time.
- Centralized management: Use the Microsoft Defender portal at https://security.microsoft.com to view detections and manage devices.
- Advanced hunting: Query raw event data to proactively hunt for threats on Mac devices.
- Response actions: Run antivirus scans, isolate devices, collect investigation packages, and collect files for analysis.
- Live response: Use a remote shell connection for investigation and response on macOS devices.
- Posture management: Provides risk-based vulnerability management, remediation, and tracking.
- Vulnerability management: Prioritize, remediate, and track vulnerabilities on Mac devices.
- Exposure score: View your organization's risk exposure for managed Mac devices.
- Security recommendations: Review recommended actions to reduce endpoint risk.
- Remediation tracking: Track remediation activities and exposure reduction.
- Software inventory: View software installed on managed Mac devices.
- Streamlined management and operations: Supports deployment, configuration, and management through MDM tools and the Microsoft Defender portal.
- MDM integration: Use Microsoft Intune, Jamf Pro, or another MDM solution to deploy and manage Defender for Endpoint.
- Security settings configuration: Configure security settings centrally. Security settings management also lets you manage supported security policies from the Microsoft Defender portal without full Intune enrollment.
- Software updates: Use Microsoft AutoUpdate (MAU) to keep Defender for Endpoint current.
- Management APIs: Use APIs to integrate device management, vulnerability management, and threat intelligence with other systems.
- Integration and extensibility: Connects Defender for Endpoint with APIs, security information and event management (SIEM) solutions, and other Microsoft Defender products.
- System extensions: Use Apple's system extension architecture on supported Intel and Apple silicon processors.
- API integration: Integrate Defender for Endpoint data and actions with other systems.
- SIEM connectors: Connect security data to SIEM solutions for centralized monitoring and automated response.
- Power BI support: Create Power BI reports that use Defender for Endpoint data and role-based access control (RBAC).
What's new in the latest release
For general updates, see What's new in Microsoft Defender for Endpoint. For macOS product builds and changes, see What's new in Microsoft Defender for Endpoint on Mac.
To send product feedback, open Microsoft Defender on the Mac device, and then select Help > Send feedback. To evaluate preview capabilities, configure the device to use the Beta update channel, formerly named InsiderFast.
Deploy Defender for Endpoint on macOS
Choose a deployment method based on how your organization manages Mac devices. Each method installs the Microsoft Defender app, provides the required macOS permissions and configuration, onboards the device, and verifies connectivity to the Defender for Endpoint service.
Before you begin, review the Defender for Endpoint on macOS prerequisites, including licensing, supported operating systems, permissions, and network connectivity.
Important
If you want to run multiple security solutions side by side, see Considerations for performance, configuration, and support.
You might have already configured mutual security exclusions for devices onboarded to Microsoft Defender for Endpoint. If you still need to set mutual exclusions to avoid conflicts, see Add Microsoft Defender for Endpoint to the exclusion list for your existing solution.
| Deployment method | Use this method when | Considerations |
|---|---|---|
| Microsoft Intune | Your organization manages Mac devices with Intune. | Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. You need a subscription that includes Intune, or you can buy it separately. For more information, see Microsoft Intune licensing. |
| Jamf Pro | Your organization manages Apple devices with Jamf Pro. | Jamf Pro is a separate third-party product that requires its own subscription. The Jamf deployment uses separate articles for groups, profiles and policies, packages, and device enrollment. |
| Another mobile device management solution | Your organization uses an MDM solution other than Intune or Jamf Pro. | The MDM solution must support package deployment and device-level Apple configuration profiles. Microsoft support doesn't cover third-party product behavior. |
| Manual deployment | You need to install Defender for Endpoint on an individual evaluation or test device without using MDM. | A local administrator must install the app and approve the required macOS permissions on the device. Use an MDM solution for centrally managed production deployments. |
The exact steps depend on the selected deployment method, but every deployment has the following stages:
- Prepare the network and confirm that the device meets the system requirements.
- Approve or preapprove the required system extensions and macOS permissions.
- Install the Microsoft Defender application package.
- Apply the onboarding package to associate the device with your organization.
- Verify onboarding, connectivity, antivirus protection, and endpoint detection and response (EDR).
Verify the deployment
After installation and onboarding, confirm that the device reports an organization identifier and can connect to the Defender for Endpoint service:
Check the organization identifier:
mdatp health --field org_idTest service connectivity:
mdatp connectivity test
Run an antivirus detection test and an EDR detection test to confirm that the device reports detections and alerts to the Microsoft Defender portal.