Contextuels exclusions MDAV on MacOs

meryeme el faik 5 Reputation points
2024-04-12T07:59:50.85+00:00

Hello everyone,

I'm currently exploring exclusion settings in Microsoft Defender on macOS. I'm particularly interested in whether it's possible to implement what's known as "contextual exclusions" on this OS. By contextual exclusions, I mean the ability to set scan exclusions based on specific criteria, like the scan type or the initiating process. To my knowledge, there isn't any official documentation on this topic for macOS. Has anyone here had experience with this, or could point me toward any resources or techniques for achieving this?

Thank you in advance for your assistance and guidance!

Community Center | Not monitored
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 17,360 Reputation points Microsoft External Staff
    2024-04-12T08:48:37.5233333+00:00

    @meryeme el faik, Thanks for posting in Q&A.

    From your description, I know you want to do Contextual exclusions MDAV on MacOS.

    Based on my research, Microsoft Defender for Endpoint on macOS doesn’t seem to support the contextual exclusion.

    However, you can exclude certain files, folders, processes, and process-opened files from Defender for Endpoint on Mac scans.

    Here are the supported exclusion types:

    • File extension.
    • File.
    • Folder.
    • Process.

    Please note that defining exclusions lowers the protection offered by Defender for Endpoint on Mac. You should always evaluate the risks that are associated with implementing exclusions, and you should only exclude files that you are confident are not malicious. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-exclusions?view=o365-worldwide

    Hope it will help.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.