Microsoft Defender for Endpoint
Troubleshooting

Troubleshoot performance issues for Microsoft Defender for Endpoint on macOS

In brief

Updated Microsoft Defender documentation in defender-endpoint/mac-support-perf.md.

What Defender admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Troubleshoot performance issues for Microsoft Defender for Endpoint on macOS

| Device isn't managed by organization | Terminal: In Terminal, run the following command: mdatp config real-time-protection --value disabled | | Device is managed by organization | See Set preferences for Microsoft Defender for Endpoint on macOS. |

If the performance problem persists while real-time protection is off, the origin of the problem could be the endpoint detection and response component. In this case, contact customer support for further instructions and mitigation.issue isn't limited to antivirus scanning. Continue with Troubleshoot core or endpoint detection and response performance issues.

  1. Open Finder and navigate to Applications > Utilities. Open Activity Monitor and analyze which applications are using the resources on your system. Typical examples include software updaters and compilers.

See the guide on our support page for Behavior Monitoring.

Troubleshoot core or endpoint detection and response performance issues using

Use this workflow when wdavdaemon or wdavdaemon_enterprise has high resource use, or when the issue continues while real-time protection is disabled.

  1. Reproduce the issue and confirm the affected Defender process in Activity Monitor or by running top.

  2. Record the following information:

    • Workload.
    • Start and end times.
    • CPU and memory use.
    • Device model and processor.
    • macOS and Defender versions.
    • Enforcement mode.
    • Other security or monitoring products.
  3. Collect hot event sources during the affected period:

    sudo mdatp diagnostic hot-event-sources --time=360
    

    The command creates a report that identifies applications and processes producing the most Endpoint Security events. Run the collection only while the issue is occurring.

  4. Collect performance data by following the instructions in Run the client analyzer on macOS and Linux.

  5. If another endpoint security product is installed, confirm that the products are configured for the intended coexistence mode. See Microsoft Defender for Endpoint and other security solutions.

  6. Contact Microsoft Defender for Endpoint Client Analyzer

    The Microsoft Defender for EndpointSupport and provide the process measurements, hot event source report, Client Analyzer (MDECA) can collect traces, logs,output, and diagnostic information in order to troubleshoot performance issues on onboarded devicesexact time window when you reproduced the issue.

Troubleshoot performance issues using Microsoft Defender for Endpoint Client Analyzer

The Microsoft Defender for Endpoint Client Analyzer (MDECA) can collect traces, logs, and diagnostic information in order to troubleshoot performance issues on onboarded devices on macOS.