Edit

Deploy Microsoft Defender for Endpoint on macOS with Microsoft Intune

Use Microsoft Intune to deploy Microsoft Defender for Endpoint to managed macOS devices. Create the required configuration profiles, deploy the app and onboarding package, and verify the deployment. Before you begin, review the prerequisites and system requirements.

Microsoft Intune is the recommended tool for configuring and distributing Defender for Endpoint features to devices. However, Intune is a separate product that isn't part of Defender for Endpoint, and it isn't included in all subscriptions. To use Intune, you need a subscription that includes it, or you can buy it separately as a standalone subscription or add-on. If you don't have Intune, you can use any of the other methods in this article. For more information, see Microsoft Intune licensing.

Prerequisites and system requirements

For an overview of the product's capabilities and features, see Microsoft Defender for Endpoint on macOS. Before you start the deployment, review the Microsoft Defender for Endpoint on macOS prerequisites.

Important

If you want to run multiple security solutions side by side, see Considerations for performance, configuration, and support.

You might have already configured mutual security exclusions for devices onboarded to Microsoft Defender for Endpoint. If you still need to set mutual exclusions to avoid conflicts, see Add Microsoft Defender for Endpoint to the exclusion list for your existing solution.

Deployment overview

The following table summarizes the profiles and packages used to deploy Defender for Endpoint on macOS with Intune.

Step Sample file name Bundle identifier
Approve system extensions Not applicable com.microsoft.wdav.epsext and com.microsoft.wdav.netext
Network extension policy netfilter.mobileconfig com.microsoft.wdav.netext
Full Disk Access fulldisk.mobileconfig com.microsoft.wdav, com.microsoft.wdav.epsext, and com.microsoft.dlp.daemon
Defender for Endpoint preferences

If you plan to run a non-Microsoft antivirus product on macOS, configure passive mode in the preferences profile.
com.microsoft.wdav.xml com.microsoft.wdav
Background services background_services.mobileconfig Not applicable
Notifications notif.mobileconfig com.microsoft.wdav.tray and com.microsoft.autoupdate2
Accessibility settings accessibility.mobileconfig com.microsoft.dlp.daemon
Bluetooth permissions bluetooth.mobileconfig com.microsoft.dlp.agent
Microsoft AutoUpdate com.microsoft.autoupdate2.mobileconfig com.microsoft.autoupdate2
Onboarding package WindowsDefenderATPOnboarding.xml com.microsoft.wdav.atp
Defender for Endpoint app Not applicable Not applicable

Create system configuration profiles

Create the system configuration profiles that Microsoft Defender for Endpoint needs.

Most steps in this section use a custom macOS configuration profile. For detailed instructions, see Add custom settings to Apple devices in Microsoft Intune (link opens in a new tab).

When a step tells you to create a custom configuration profile, use these common settings:

Assign each profile to the user or device groups that should receive it. You can also add scope tags and exclude groups from the assignment.

Step 1: Approve system extensions

Use the Intune settings catalog to approve the required system extensions. For detailed instructions, see Approve Microsoft Defender for Endpoint macOS extensions using the Intune settings catalog.

When you create the policy, use these specific settings:

When you create or modify the policy, add Allowed System Extensions and Allowed System Extension Types from System Configuration > System Extensions on the Configuration settings tab. Configure these entries:

  • Allowed System Extensions:
    • Allowed System Extensions: Add com.microsoft.wdav.epsext and com.microsoft.wdav.netext.
    • Team identifier: Enter UBF8T346G9.
  • Allowed System Extension Types:
    • Allowed System Extension Types: Add Network and EndpointSecurity.
    • Team identifier: Enter UBF8T346G9.

Step 2: Network filter

Defender for Endpoint uses the network extension for network content inspection. The network filter profile allows the extension to inspect socket traffic.

Download netfilter.mobileconfig from the Defender for Endpoint macOS configuration profile repository.

Important

macOS supports only one network filter .mobileconfig file. Adding multiple network filters can cause network connectivity issues. This limitation isn't specific to Defender for Endpoint.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS network filter.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the netfilter.mobileconfig file that you downloaded.

Step 3: Full Disk Access

Note

macOS Catalina 10.15 and later use Transparency, Consent, and Control (TCC) to protect access to sensitive user data. Deploying the Full Disk Access profile through mobile device management (MDM) prevents local users from revoking the permissions that Defender for Endpoint needs.

This profile grants Full Disk Access to Defender for Endpoint. If you configured Defender for Endpoint through Intune without this profile, update the deployment to include it.

Download fulldisk.mobileconfig from the Defender for Endpoint macOS configuration profile repository.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS full disk access.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the fulldisk.mobileconfig file that you downloaded.

Note

Full Disk Access granted through an Apple MDM configuration profile isn't shown in System Settings > Privacy & Security > Full Disk Access.

Step 4: Background services

Caution

Starting in macOS 13 (Ventura), apps need explicit permission to run in the background. Defender for Endpoint must run background processes. This profile grants the required background service permissions. If you configured Defender for Endpoint through Intune without this profile, update the deployment to include it.

Download background_services.mobileconfig from the Defender for Endpoint macOS configuration profile repository.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS background services.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the background_services.mobileconfig file that you downloaded.

Step 5: Notifications

This profile allows Defender for Endpoint and Microsoft AutoUpdate to display notifications.

Download notif.mobileconfig from the Defender for Endpoint macOS configuration profile repository.

To hide notifications from users, change ShowInNotificationCenter from true to false for the applicable app in notif.mobileconfig.

Screenshot of notif.mobileconfig with ShowInNotificationCenter set to true.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS notifications consent.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the notif.mobileconfig file that you downloaded.

Step 6: Accessibility settings

This profile grants Accessibility permission to the com.microsoft.dlp.daemon component.

Download accessibility.mobileconfig from the Defender for Endpoint macOS configuration profile repository.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS accessibility settings.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the accessibility.mobileconfig file that you downloaded.

Step 7: Bluetooth permissions (optional)

Caution

Starting in macOS 14 (Sonoma), apps need explicit permission to access Bluetooth. Deploy this profile if you configure Bluetooth policies for Device Control.

Download bluetooth.mobileconfig from the GitHub repository.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS Bluetooth consent.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the bluetooth.mobileconfig file that you downloaded.

Note

Bluetooth access granted through an Apple MDM configuration profile isn't shown in System Settings > Privacy & Security > Bluetooth.

Step 8: Microsoft AutoUpdate

This profile configures Microsoft AutoUpdate to update Defender for Endpoint. Select one of the following update channels:

  • Beta
  • Preview
  • Current

For more information, see Deploy updates for Microsoft Defender for Endpoint on macOS.

Download com.microsoft.autoupdate2.mobileconfig from the Microsoft AutoUpdate settings repository.

Note

The sample com.microsoft.autoupdate2.mobileconfig file is configured for Current Channel (Production).

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS Microsoft AutoUpdate.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the com.microsoft.autoupdate2.mobileconfig file that you downloaded.

Step 9: Microsoft Defender for Endpoint configuration settings

Configure antimalware and EDR policies by using either the Microsoft Defender portal in step 9a or the Microsoft Intune admin center in step 9b.

Note

Complete only one of the following steps: 9a or 9b.

9a. Set policies in the Microsoft Defender portal

If your organization manages endpoint security policies in the Microsoft Defender portal, you can configure antivirus and endpoint detection and response (EDR) settings with the same endpoint security policies that Intune uses.

For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open in new tabs).

Before you create the policies, configure the connection between Microsoft Defender for Endpoint and Intune.

When you create the endpoint security Antivirus policy on the macOS policies tab of the Endpoint security policies page in the Defender portal at https://security.microsoft.com/policy-inventory?osPlatform=Mac, use these specific settings:

  • Select platform: Select macOS.
  • Select template: Select Microsoft Defender Antivirus.

Configure the antivirus settings required by your organization. Then, create another policy with the following settings:

  • Select platform: Select macOS.
  • Select template: Select Endpoint detection and response.

9b. Set policies in Microsoft Intune

To create this profile, copy the code for the Intune recommended profile (recommended) or the Intune full profile (for advanced scenarios), and save the file as com.microsoft.wdav.xml.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as macOS Microsoft Defender preferences.
  • Configuration profile name: Enter com.microsoft.wdav.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the com.microsoft.wdav.xml file that you created.

Caution

Enter com.microsoft.wdav as the Configuration profile name. Defender for Endpoint doesn't recognize the preferences if you use another value.

For more information, see Set preferences for Microsoft Defender for Endpoint on macOS.

For more information about managing security settings, see:

Step 10: Network protection for Microsoft Defender for Endpoint on macOS (optional)

Configure network protection in the Microsoft Defender Antivirus policy or the Defender for Endpoint preferences profile that you created in step 9.

For requirements, configuration options, and verification steps, see Network protection for macOS.

Step 11: Device Control for Microsoft Defender for Endpoint on macOS (optional)

Device Control requires Full Disk Access for com.microsoft.dlp.daemon and separate Device Control settings and policies. The fulldisk.mobileconfig profile in step 3 includes the required Full Disk Access permission.

For requirements and configuration instructions, see Device Control for macOS.

Important

Deploy the required configuration profiles before you deploy the Defender for Endpoint app and onboarding package.

Step 12: Publish the Microsoft Defender application

Important

The Microsoft Defender app for macOS supports both Defender for Endpoint and Microsoft Purview Endpoint Data Loss Prevention. If you also plan to onboard the macOS devices to Microsoft Purview in step 18, enable device monitoring as part of the Purview onboarding process. In the Microsoft Purview portal at https://purview.microsoft.com, go to Settings > Device onboarding > Devices, and select Enable device monitoring.

Publish the Microsoft Defender app to devices enrolled in Intune. For detailed instructions, see Add Microsoft Defender for Endpoint to macOS devices using Microsoft Intune (link opens in a new tab).

When you add the app, use these specific settings:

  • App type: Select Microsoft Defender for Endpoint > macOS.
  • App information: Keep the default values.
  • Assignments: Assign the app to the user or device groups that should receive it.

Step 13: Download the Microsoft Defender for Endpoint onboarding package

To download the onboarding package from the Microsoft Defender portal:

  1. On the Onboarding page in the Microsoft Defender portal at https://security.microsoft.com/securitysettings/endpoints/onboarding, configure the following settings:

    1. Select operating system to start onboarding process: Select macOS.

    2. Connectivity type: Verify Streamlined is selected.

    3. Deployment method: Select Mobile Device Management / Microsoft Intune.

      Screenshot of the Onboarding page with macOS, Streamlined, and Mobile Device Management or Microsoft Intune selected.

  2. Select Download onboarding package, and save GatewayWindowsDefenderATPOnboardingPackage.zip.

  3. Extract the contents of the ZIP file so that you can deploy WindowsDefenderATPOnboarding.xml through Intune:

    unzip GatewayWindowsDefenderATPOnboardingPackage.zip
    
    Archive:  GatewayWindowsDefenderATPOnboardingPackage.zip
    warning:  GatewayWindowsDefenderATPOnboardingPackage.zip appears to use backslashes as path separators
     inflating: intune/kext.xml
     inflating: intune/WindowsDefenderATPOnboarding.xml
     inflating: jamf/WindowsDefenderATPOnboarding.plist
    

Step 14: Deploy the Microsoft Defender for Endpoint onboarding package for macOS

This profile contains license information for Microsoft Defender for Endpoint.

Create a custom configuration profile by using the common settings described in Create system configuration profiles. Use these profile-specific settings:

  • Name: Enter a descriptive name, such as Microsoft Defender for Endpoint onboarding for macOS.
  • Configuration profile name: Enter a descriptive name for the profile.
  • Deployment channel: Select the appropriate channel for the profile.
  • Configuration profile file: Select the WindowsDefenderATPOnboarding.xml file that you extracted from the onboarding package.

Step 15: Check device and configuration status

Step 15a. View status

Use the policy report in the Intune admin center to view device and user check-in status:

  1. On the Devices | Configuration page in the Intune admin center at https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/configuration, select a policy.

  2. On Device and user check-in status, select View report.

Step 15b. Enroll a client device

Use Company Portal to enroll the macOS device:

  1. Follow the steps in Enroll your Mac with Intune Company Portal.

  2. After enrollment is complete, verify that the device is listed on the All devices page in the Intune admin center at https://intune.microsoft.com/#view/Microsoft_Intune_Devices/DevicesMenu/~/allDevices.

Step 15c. Verify client device state

Verify the profiles and app on the managed device:

  1. After the configuration profiles are deployed, open System Settings > General > Device Management on the macOS device.

  2. Verify that the configuration profiles for your deployment are present and installed:

    • accessibility.mobileconfig, if deployed.
    • background_services.mobileconfig
    • bluetooth.mobileconfig, if deployed.
    • com.microsoft.autoupdate2.mobileconfig
    • fulldisk.mobileconfig
    • Management Profile, which is the Intune system profile.
    • WindowsDefenderATPOnboarding.xml, which is the Defender for Endpoint onboarding package.
    • netfilter.mobileconfig
    • notif.mobileconfig
  3. Verify that the Microsoft Defender icon appears in the menu bar.

    Screenshot of the Microsoft Defender icon in the macOS menu bar.

Step 16: Verify antimalware detection

Run an antivirus detection test to verify that the device is onboarded and reporting correctly.

Step 17: Verify EDR detection

Run an EDR detection test to verify that endpoint detection and response is working and reporting correctly.

To onboard the device to Microsoft Purview and configure Endpoint Data Loss Prevention (DLP), see Get started with Endpoint DLP.

Troubleshooting

  • Issue: Defender for Endpoint reports that no license was found.
  • Cause: Device onboarding isn't complete.
  • Resolution: Download the onboarding package as described in step 13, and deploy it as described in step 14.

Logging installation issues

See Logging installation issues to find the log that the installer automatically creates when an error occurs.

For information on troubleshooting procedures, see:

Uninstall Defender for Endpoint

See Uninstall Defender for Endpoint on macOS for instructions.