Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Use Microsoft Intune to deploy Microsoft Defender for Endpoint to managed macOS devices. Create the required configuration profiles, deploy the app and onboarding package, and verify the deployment. Before you begin, review the prerequisites and system requirements.
Microsoft Intune is the recommended tool for configuring and distributing Defender for Endpoint features to devices. However, Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. To use Intune, you need a subscription that includes it, or you can buy it separately as a standalone subscription or add-on. If you don't have Intune, you can use any of the other methods in this article. For more information, see Microsoft Intune licensing.
Prerequisites and system requirements
For an overview of the product's capabilities and features, see Microsoft Defender for Endpoint on macOS. Before you start the deployment, review the Microsoft Defender for Endpoint on macOS prerequisites.
Important
If you want to run multiple security solutions side by side, see Considerations for performance, configuration, and support.
You might have already configured mutual security exclusions for devices onboarded to Microsoft Defender for Endpoint. If you still need to set mutual exclusions to avoid conflicts, see Add Microsoft Defender for Endpoint to the exclusion list for your existing solution.
Deployment overview
The following table summarizes the profiles and packages used to deploy Defender for Endpoint on macOS with Intune.
| Step | Sample file name | Bundle identifier |
|---|---|---|
| Approve system extensions | Not applicable | com.microsoft.wdav.epsext and com.microsoft.wdav.netext |
| Network extension policy | netfilter.mobileconfig |
com.microsoft.wdav.netext |
| Full Disk Access | fulldisk.mobileconfig |
com.microsoft.wdav, com.microsoft.wdav.epsext, and com.microsoft.dlp.daemon |
| Defender for Endpoint preferences If you plan to run a non-Microsoft antivirus product on macOS, configure passive mode in the preferences profile. |
com.microsoft.wdav.xml |
com.microsoft.wdav |
| Background services | background_services.mobileconfig |
Not applicable |
| Notifications | notif.mobileconfig |
com.microsoft.wdav.tray and com.microsoft.autoupdate2 |
| Accessibility settings | accessibility.mobileconfig |
com.microsoft.dlp.daemon |
| Bluetooth permissions | bluetooth.mobileconfig |
com.microsoft.dlp.agent |
| Microsoft AutoUpdate | com.microsoft.autoupdate2.mobileconfig |
com.microsoft.autoupdate2 |
| Onboarding package | WindowsDefenderATPOnboarding.xml |
com.microsoft.wdav.atp |
| Defender for Endpoint app | Not applicable | Not applicable |
Create system configuration profiles
Create the system configuration profiles that Microsoft Defender for Endpoint needs.
Most steps in this section use a custom macOS configuration profile. For detailed instructions, see Add custom settings to Apple devices in Microsoft Intune (link opens in a new tab).
When a step tells you to create a custom configuration profile, use these common settings:
- Policy type: Go to Manage devices > Configuration on the Devices | Overview page at https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/configuration.
- Platform: Select macOS.
- Profile type: Select Templates.
- Template name: Select Custom.
Assign each profile to the user or device groups that should receive it. You can also add scope tags and exclude groups from the assignment.
Step 1: Approve system extensions
Use the Intune settings catalog to approve the required system extensions. For detailed instructions, see Approve Microsoft Defender for Endpoint macOS extensions using the Intune settings catalog.
When you create the policy, use these specific settings:
- Policy type: Go to Manage devices > Configuration on the Devices | Overview page at https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/configuration.
- Platform: Select macOS.
- Profile type: Select Settings catalog.
When you create or modify the policy, add Allowed System Extensions and Allowed System Extension Types from System Configuration > System Extensions on the Configuration settings tab. Configure these entries:
- Allowed System Extensions:
- Allowed System Extensions: Add
com.microsoft.wdav.epsextandcom.microsoft.wdav.netext. - Team identifier: Enter
UBF8T346G9.
- Allowed System Extensions: Add
- Allowed System Extension Types:
- Allowed System Extension Types: Add
NetworkandEndpointSecurity. - Team identifier: Enter
UBF8T346G9.
- Allowed System Extension Types: Add
Step 2: Network filter
Defender for Endpoint uses the network extension for network content inspection. The network filter profile allows the extension to inspect socket traffic.
Download netfilter.mobileconfig from the Defender for Endpoint macOS configuration profile repository.
Important
macOS supports only one network filter .mobileconfig file. Adding multiple network filters can cause network connectivity issues. This limitation isn't specific to Defender for Endpoint.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS network filter. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the netfilter.mobileconfig file that you downloaded.
Step 3: Full Disk Access
Note
macOS Catalina 10.15 and later use Transparency, Consent, and Control (TCC) to protect access to sensitive user data. Deploying the Full Disk Access profile through mobile device management (MDM) prevents local users from revoking the permissions that Defender for Endpoint needs.
This profile grants Full Disk Access to Defender for Endpoint. If you configured Defender for Endpoint through Intune without this profile, update the deployment to include it.
Download fulldisk.mobileconfig from the Defender for Endpoint macOS configuration profile repository.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS full disk access. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the fulldisk.mobileconfig file that you downloaded.
Note
Full Disk Access granted through an Apple MDM configuration profile isn't shown in System Settings > Privacy & Security > Full Disk Access.
Step 4: Background services
Caution
Starting in macOS 13 (Ventura), apps need explicit permission to run in the background. Defender for Endpoint must run background processes. This profile grants the required background service permissions. If you configured Defender for Endpoint through Intune without this profile, update the deployment to include it.
Download background_services.mobileconfig from the Defender for Endpoint macOS configuration profile repository.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS background services. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the background_services.mobileconfig file that you downloaded.
Step 5: Notifications
This profile allows Defender for Endpoint and Microsoft AutoUpdate to display notifications.
Download notif.mobileconfig from the Defender for Endpoint macOS configuration profile repository.
To hide notifications from users, change ShowInNotificationCenter from true to false for the applicable app in notif.mobileconfig.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS notifications consent. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the notif.mobileconfig file that you downloaded.
Step 6: Accessibility settings
This profile grants Accessibility permission to the com.microsoft.dlp.daemon component.
Download accessibility.mobileconfig from the Defender for Endpoint macOS configuration profile repository.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS accessibility settings. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the accessibility.mobileconfig file that you downloaded.
Step 7: Bluetooth permissions (optional)
Caution
Starting in macOS 14 (Sonoma), apps need explicit permission to access Bluetooth. Deploy this profile if you configure Bluetooth policies for Device Control.
Download bluetooth.mobileconfig from the GitHub repository.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS Bluetooth consent. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the bluetooth.mobileconfig file that you downloaded.
Note
Bluetooth access granted through an Apple MDM configuration profile isn't shown in System Settings > Privacy & Security > Bluetooth.
Step 8: Microsoft AutoUpdate
This profile configures Microsoft AutoUpdate to update Defender for Endpoint. Select one of the following update channels:
BetaPreviewCurrent
For more information, see Deploy updates for Microsoft Defender for Endpoint on macOS.
Download com.microsoft.autoupdate2.mobileconfig from the Microsoft AutoUpdate settings repository.
Note
The sample com.microsoft.autoupdate2.mobileconfig file is configured for Current Channel (Production).
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS Microsoft AutoUpdate. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the com.microsoft.autoupdate2.mobileconfig file that you downloaded.
Step 9: Microsoft Defender for Endpoint configuration settings
Configure antimalware and EDR policies by using either the Microsoft Defender portal in step 9a or the Microsoft Intune admin center in step 9b.
Note
Complete only one of the following steps: 9a or 9b.
9a. Set policies in the Microsoft Defender portal
If your organization manages endpoint security policies in the Microsoft Defender portal, you can configure antivirus and endpoint detection and response (EDR) settings with the same endpoint security policies that Intune uses.
For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open in new tabs).
Before you create the policies, configure the connection between Microsoft Defender for Endpoint and Intune.
When you create the endpoint security Antivirus policy on the macOS policies tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Mac, use these specific settings:
- Select platform: Select macOS.
- Select template: Select Microsoft Defender Antivirus.
Configure the antivirus settings required by your organization. Then, create another policy with the following settings:
- Select platform: Select macOS.
- Select template: Select Endpoint detection and response.
9b. Set policies in Microsoft Intune
To create this profile, copy the code for the Intune recommended profile (recommended) or the Intune full profile (for advanced scenarios), and save the file as com.microsoft.wdav.xml.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
macOS Microsoft Defender preferences. - Configuration profile name: Enter
com.microsoft.wdav. - Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the
com.microsoft.wdav.xmlfile that you created.
Caution
Enter com.microsoft.wdav as the Configuration profile name. Defender for Endpoint doesn't recognize the preferences if you use another value.
For more information, see Set preferences for Microsoft Defender for Endpoint on macOS.
For more information about managing security settings, see:
- Manage Microsoft Defender for Endpoint on devices with Microsoft Intune
- Manage security settings for Windows, macOS, and Linux natively in Defender for Endpoint
Step 10: Network protection for Microsoft Defender for Endpoint on macOS (optional)
Configure network protection in the Microsoft Defender Antivirus policy or the Defender for Endpoint preferences profile that you created in step 9.
For requirements, configuration options, and verification steps, see Network protection for macOS.
Step 11: Device Control for Microsoft Defender for Endpoint on macOS (optional)
Device Control requires Full Disk Access for com.microsoft.dlp.daemon and separate Device Control settings and policies. The fulldisk.mobileconfig profile in step 3 includes the required Full Disk Access permission.
For requirements and configuration instructions, see Device Control for macOS.
Important
Deploy the required configuration profiles before you deploy the Defender for Endpoint app and onboarding package.
Step 12: Publish the Microsoft Defender application
Important
The Microsoft Defender app for macOS supports both Defender for Endpoint and Microsoft Purview Endpoint Data Loss Prevention. If you also plan to onboard the macOS devices to Microsoft Purview in step 18, enable device monitoring as part of the Purview onboarding process. In the Microsoft Purview portal at https://purview.microsoft.com, go to Settings > Device onboarding > Devices, and select Enable device monitoring.
Publish the Microsoft Defender app to devices enrolled in Intune. For detailed instructions, see Add Microsoft Defender for Endpoint to macOS devices using Microsoft Intune (link opens in a new tab).
When you add the app, use these specific settings:
- App type: Select Microsoft Defender for Endpoint > macOS.
- App information: Keep the default values.
- Assignments: Assign the app to the user or device groups that should receive it.
Step 13: Download the Microsoft Defender for Endpoint onboarding package
To download the onboarding package from the Microsoft Defender portal:
On the Onboarding page in the Microsoft Defender portal at https://security.microsoft.com/securitysettings/endpoints/onboarding, configure the following settings:
Select Download onboarding package, and save
GatewayWindowsDefenderATPOnboardingPackage.zip.Extract the contents of the ZIP file so that you can deploy
WindowsDefenderATPOnboarding.xmlthrough Intune:unzip GatewayWindowsDefenderATPOnboardingPackage.zipArchive: GatewayWindowsDefenderATPOnboardingPackage.zip warning: GatewayWindowsDefenderATPOnboardingPackage.zip appears to use backslashes as path separators inflating: intune/kext.xml inflating: intune/WindowsDefenderATPOnboarding.xml inflating: jamf/WindowsDefenderATPOnboarding.plist
Step 14: Deploy the Microsoft Defender for Endpoint onboarding package for macOS
This profile contains license information for Microsoft Defender for Endpoint.
Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:
- Name: Enter a descriptive name, such as
Microsoft Defender for Endpoint onboarding for macOS. - Configuration profile name: Enter a descriptive name for the profile.
- Deployment channel: Select the appropriate channel for the profile.
- Configuration profile file: Select the
WindowsDefenderATPOnboarding.xmlfile that you extracted from the onboarding package.
Step 15: Check device and configuration status
Step 15a. View status
Use the policy report in the Intune admin center to view device and user check-in status:
On the Devices | Configuration page in the Intune admin center at https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/configuration, select a policy.
On Device and user check-in status, select View report.
Step 15b. Enroll a client device
Use Company Portal to enroll the macOS device:
Follow the steps in Enroll your Mac with Intune Company Portal.
After enrollment is complete, verify that the device is listed on the All devices page in the Intune admin center at https://intune.microsoft.com/#view/Microsoft_Intune_Devices/DevicesMenu/~/allDevices.
Step 15c. Verify client device state
Verify the profiles and app on the managed device:
After the configuration profiles are deployed, open System Settings > General > Device Management on the macOS device.
Verify that the configuration profiles for your deployment are present and installed:
accessibility.mobileconfig, if deployed.background_services.mobileconfigbluetooth.mobileconfig, if deployed.com.microsoft.autoupdate2.mobileconfigfulldisk.mobileconfig- Management Profile, which is the Intune system profile.
WindowsDefenderATPOnboarding.xml, which is the Defender for Endpoint onboarding package.netfilter.mobileconfignotif.mobileconfig
Verify that the Microsoft Defender icon appears in the menu bar.
Step 16: Verify antimalware detection
Run an antivirus detection test to verify that the device is onboarded and reporting correctly.
Step 17: Verify EDR detection
Run an EDR detection test to verify that endpoint detection and response is working and reporting correctly.
Step 18: Microsoft Purview Endpoint Data Loss Prevention for macOS (strongly recommended)
To onboard the device to Microsoft Purview and configure Endpoint Data Loss Prevention (DLP), see Get started with Endpoint DLP.
Troubleshooting
- Issue: Defender for Endpoint reports that no license was found.
- Cause: Device onboarding isn't complete.
- Resolution: Download the onboarding package as described in step 13, and deploy it as described in step 14.
Logging installation issues
See Logging installation issues to find the log that the installer automatically creates when an error occurs.
For information on troubleshooting procedures, see:
- Troubleshoot system extension issues in Microsoft Defender for Endpoint on macOS
- Troubleshoot installation issues for Microsoft Defender for Endpoint on macOS
- Troubleshoot license issues for Microsoft Defender for Endpoint on macOS
- Troubleshoot cloud connectivity issues for Microsoft Defender for Endpoint on macOS
- Troubleshoot performance issues for Microsoft Defender for Endpoint on macOS
Uninstall Defender for Endpoint
See Uninstall Defender for Endpoint on macOS for instructions.