Edit

Manually deploy Microsoft Defender for Endpoint on macOS

Want to experience Defender for Endpoint? Sign up for a free trial.

You can use manual deployment to install and onboard Microsoft Defender for Endpoint on an individual evaluation or test Mac without using mobile device management (MDM). For centrally managed production devices, choose an MDM method in Deploy Defender for Endpoint on macOS.

Complete the following tasks:

Prerequisites

Before you start, review the Defender for Endpoint on macOS prerequisites. You need local administrator privileges and a supported Mac that meets the licensing, system, permission, and network requirements.

Important

Manual installation requires changes to macOS privacy and security settings. For Apple's instructions, see Change Privacy & Security settings on Mac.

Download installation and onboarding packages

Download the installation and onboarding packages from the Microsoft Defender portal:

Warning

Repackaging the Defender for Endpoint installation package is not a supported scenario. Doing so can negatively impact the integrity of the product and lead to adverse results, including but not limited to triggering tampering alerts and updates failing to apply.

  1. On the Onboarding page in the Microsoft Defender portal in the Microsoft Defender portal at https://security.microsoft.com/securitysettings/endpoints/onboarding, select the following options:

    • Step 1: Select an operating system to start deployment: Select macOS.
    • Connectivity type: Select Streamlined.
    • Deployment method: Verify Local script (for up to 10 devices) is selected.
  2. Select Download installation package, to download and save the wdav.pkg file.

  3. Select Download onboarding package to download and save the WindowsDefenderATPOnboardingPackage.zip in the same folder.

  4. Extract WindowsDefenderATPOnboardingPackage.zip to get the WindowsDefenderATPOnboarding.mobileconfig file.

  5. Confirm that wdav.pkg and WindowsDefenderATPOnboarding.mobileconfig exist on the Mac where you want to deploy Defender for Endpoint.

Install the application

Install wdav.pkg by using Finder or Terminal.

Install by using Finder

To use the graphical installer:

  1. In Finder, locate and open wdav.pkg.

  2. Select Continue.

  3. Review the Software License Agreement, and then select Continue.

  4. Select Agree to accept the license agreement.

  5. On the Destination Select page, select the installation disk, and then select Continue.

  6. To use a different disk, select Change Install Location....

  7. Select Install.

  8. Enter the local administrator password when prompted.

  9. Select Install Software.

Install by using Terminal

If wdav.pkg is in /Users/admin/Downloads, run the following command to install the application:

sudo installer -pkg /Users/admin/Downloads/wdav.pkg -target /

Approve system extensions and macOS permissions

After installation, approve the system extensions and grant the applicable macOS permissions. The procedure covers Full Disk Access, Accessibility, and notifications. When prompted to allow Microsoft Defender to filter network content, select Allow.

When macOS notifies you that Microsoft Defender added background items, keep the Microsoft Defender and Microsoft Corporation items enabled. If you use Bluetooth-based Device Control policies, select Allow when macOS prompts you to grant Microsoft Defender Bluetooth access.

For the required extension identifiers and permissions, see System extensions and macOS permissions. To resolve extension approval problems, see Troubleshoot system extension issues.

Onboard the device

Install the onboarding configuration profile:

  1. In Finder, open WindowsDefenderATPOnboarding.mobileconfig.

  2. On the Mac, open the Apple menu, select System Settings, select General in the sidebar, and then select Device Management.

  3. In the Downloaded section, double-click the onboarding profile.

  4. Review the profile, and then select Continue or Install. Enter the local administrator password if prompted.

For more information about manually installing a configuration profile, see Use configuration profiles to standardize settings on Mac computers.

After onboarding, the Microsoft Defender icon appears in the macOS menu bar.

Screenshot of the Microsoft Defender icon in the macOS menu bar.

Use the shared deployment verification procedure to confirm the organization identifier and service connectivity. Then run an antivirus detection test and an endpoint detection and response (EDR) detection test.

If onboarding doesn't assign a license or connect the device to the service, see Troubleshoot license issues and Troubleshoot cloud connectivity issues.

Troubleshoot installation

The installer writes detailed errors to the installation log. Use the following resources to troubleshoot manual deployment:

Uninstall Defender for Endpoint

Follow the Defender for Endpoint uninstallation procedure to offboard the device and remove the application.

Tip

To share product feedback, open Microsoft Defender on the Mac, and then select Help > Send feedback.