Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender for Endpoint on Android

In brief

The guide was retitled and restructured. It now covers protection, privacy, file scanning, device tagging, vulnerability assessment, sign-out controls, custom indicators, and web protection through Microsoft Intune, with updated licensing and platform-limit details.

What Defender admins need to know

Review the revised guidance when configuring Android devices, particularly the Intune subscription requirement and custom indicator limitations. No immediate administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Microsoft Defender for Endpoint features on Android

Security administrators can use Microsoft Intune to configure risk-based Conditional Access, custom indicators, web and network protection, privacy controls, vulnerability assessment, file scanning, sign-out controls, and device tags for Microsoft Defender for Endpoint on Android. Before you configure these features, deploy and onboard Defender for Endpoint on the Android featuresdevices you manage.

Microsoft Intune is a separate product that isn't included with every Defender for Endpoint subscription. You need a subscription that includes Intune, or you can buy Intune as a standalone subscription or add-on. For more information, see Microsoft Intune licensing.

Conditional Access with Defender for Endpoint on Android

Microsoft Defender for Endpoint on Android, alongAndroid works with Microsoft Intune and Microsoft Entra ID, enables enforcing DeviceID to enforce device compliance and Conditional Access policies based on device risk levels. Defender for Endpoint is a Mobile Threat Defensemobile threat defense (MTD) solution that you can deploy through Intune.

For more information about how to set up Defender for Endpoint on Android and Conditional Access, see Defender for Endpoint and Intune.

Configure custom indicators

Defender for Endpoint on Android supports custom indicators with some platform-specific limitations.

For information about configuring custom indicators, see Overview of indicators.

Configure web protection

Defender for Endpoint on Android allows IT Administrators the ability toadministrators can configure the web protection feature. This capability is available withinin the Microsoft Intune admin center.

Web protection helps to secure devices against web threats and protect users from phishing attacks. Anti-phishing and custom indicators (URL and IP addresses) are supported as part of web protection. Web content filteringfiltering, which is a separate web protection capability, is currently not supported on mobile platforms.

For the complete procedure to create a Managed devices app configuration policy in Intune, see Create an app configuration policy (opens in a new tab in the Intune documentation). When creating the policy, always start with these settings:

  • Basics tab: Configure the following settings:
    • Platform: Select Android Enterprise.
    • Profile type: Select one of the following values:
      • All Profile Types: Applies the policy to all supported enrollment types. You can't associate an Intune certificate profile with the app configuration policy.
      • Fully Managed, Dedicated, and Corporate-Owned Work Profile Only: Applies the policy to corporate-owned, personally enabled (COPE) and corporate-owned, business-only (COBO) devices.
      • Personally-Owned Work Profile Only: Applies the policy to bring-your-own-device (BYOD) work profiles.
    • Targeted app: Select Select app, select Microsoft Defender: Antivirus, and then select OK.
  • Settings tab: Select Use configuration designer for Configuration settings format, and then select Add.
    • In the flyout that opens, select the configuration keys specified in the applicable sections of this article, and then select OK.
    • Configure the value for each key, and then complete the assignments and create the policy as described in the Intune procedure.

Configure network protection

Network protection provides protection againstdetects threats from rogue Wi-Fi related threatsnetworks and rogue certificates, which are the primary attack vector for Wi-Fi networks. Adminscertificates. Security administrators can list thetrusted root Certificate Authoritycertification authority (CA) and private root CAself-signed certificates in the Microsoft Intune admin center andto establish trust with endpoints. It provides the user a guided experienceNetwork protection guides users to connect to secure networks and also notifies them ifwhen it detects a related threat is detected.threat.

Network protection includes several admin controls to offer flexibility, such as the ability to configurefor configuring the feature from withinand adding trusted certificates in the Microsoft Intune admin center and add trusted certificates. Adminscenter. Security administrators can enable privacy controlsprivacy controls to configure the data sent to Defender for Endpoint from Android devices.

Network protection in Microsoft Defender for endpointEndpoint is enabled by default. Admins can useUse the Managed devices app configuration policy procedure, and add the following steps to configure Network protection in Android devices.configuration keys:

In the Microsoft Intune admin center, navigate to Apps > App configuration policies. Create a new App configuration policy.

    • Provide a name and description to uniquely identify the policy. Select 'Android Enterprise' as the platform and 'Personally-owned work profile only' as the profile type and 'Microsoft Defender' as the Targeted app.

    • In Settings page, select 'Use configuration designer' and add 'Enable Network Protection in Microsoft Defender': When you add this key, its default Configuration value asis 0, which disables network protection. To enable network protection, change the key and value as '0'to disable Network Protection. (Network protection is enabled by default)1.

    • Trusted CA certificate list for Network Protection: If your organization uses private root certification authorities (CAs), establish explicit trust between Intune, the mobile device management (MDM) solution, and user devices. Establishing trust helps prevent Defender from flagging the root CAs as rogue certificates.

      • Value type: Keep the default value String to enter the certificate thumbprints directly.

      • Configuration value: Add a comma-separated list of Secure Hash Algorithm 1 (SHA-1) certificate thumbprints in one of the following formats:

        • 50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31
        • 503006091d97d4f5ae39f7cbe7927d7d652d3431

        For example, 50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31, 503006091d97d4f5ae39f7cbe7927d7d652d3431. Any other separation characters in the certificate thumbprint (for example, :) are invalid.

    • Enable Network Protection Privacy: Enables or disables privacy in network protection.

      • Value type: Integer
      • Configuration values:
        • 1: Enable (default)
        • 0: Disable
    • Enable Users to Trust Networks and Certificates: Allows or prevents users from trusting or removing trust from unsecured networks and malicious certificates in the app.

      • Value type: Integer
      • Configuration values:
        • 1: Enable
        • 0: Disable (default)
    • Automatic Remediation of Network Protection Alerts: Enables or disables remediation alerts when users take remediation actions. For example, a user switches to a safer Wi-Fi access point or deletes a suspicious certificate detected by Defender. This setting applies only to alerts and doesn't affect device timeline events. It doesn't apply to the detection of open Wi-Fi networks or self-signed certificates.

      • Value type: Integer
      • Configuration values:
        • 1: Enable (default)
        • 0: Disable
    • Manage Network Protection detection for Open Networks: Enables or disables open network detection.

      • Value type: Integer
      • Configuration values:
        • 2: Enable (default)
        • 1: Audit mode
        • 0: Disable
    • Manage Network protection Detection for Certificates: In audit mode, events are sent to security operations center (SOC) administrators, but users don't receive notifications when Defender detects a malicious certificate. Set the value to 2 to enable full functionality. When the value is 2, users receive notifications, and events are sent to SOC administrators when Defender detects a malicious certificate.

      • Value type: Integer
      • Configuration values:
        • 2: Enable
        • 1: Audit mode
        • 0: Disable (default)

    To establish trust for the root CAs, use 'Trusted CA certificate list for Network Protection' as the key. In the value, add the 'comma separated list of certificate thumbprints (SHA 1)'.

    Example of Thumbprint format to add: 50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31, 503006091d97d4f5ae39f7cbe7927d7d652d3431

Any other separation characters are invalid.

  1. For other configurations related to Network protection, add the following keys and appropriate corresponding value.

    Configuration Key Description
    Trusted CA certificate list for Network Protection Security admins manage this setting to establish trust for root CA and self-signed certificates.
    Enable Network protection in Microsoft Defender 1: Enable (default)
    0: Disable

    This setting is used by the IT admin to enable or disable the network protection capabilities in the Defender app.
    Enable Network Protection Privacy 1: Enable (default)
    0: Disable

    Security admins manage this setting to enable or disable privacy in network protection.
    Enable Users to Trust Networks and Certificates 1: Enable
    0: Disable (default)

    This setting is used by IT admins to enable or disable the end user in-app experience to trust and untrust the unsecure networks and malicious certificates.
    Automatic Remediation of Network Protection Alerts 1: Enable (default)
    0: Disable

    This setting is used by IT admins to enable or disable the remediation alerts that are sent when a user does remediation activities. For example, the user switches to a safer Wi-Fi access point or deletes suspicious certificates that were detected by Defender. This setting only applies to alerts and does not affect device timeline events. As such, it does not apply to the detection of open Wi-Fi networks or self-signed certificates
    Manage Network Protection detection for Open Networks 2: Enable (default)
    1: Audit Mode
    0: Disable

    Security admins manage this setting to enable or disable open network detection.
    Manage Network protection Detection for Certificates 2: Enable
    1: Audit mode
    0: Disable (default)

    In audit mode, events are sent to SOC admins, but no end user notifications are shown when Defender detects a bad certificate. Admins can enable full feature functionality by setting the value 2. When the value is 2, end user notifications are sent to users and events are sent to SOC admins when Defender detects a bad certificate.
  2. Add the required groups to which the policy has to be applied. Review and create the policy.

  • For these changes to take effect, end-users must update to the latest version of Defender for Endpoint on Android available on mid-May 2025. Otherwise, the previous experience of generating alerts will still be in place. If auto-remediation key is enabled by the admin, old alerts are resolved automatically after the changes take effect.
  • When an end-user connects or disconnects to an open wireless network multiple times within the same 24-hour period, only one event each for the connection and disconnection is generated in that 24-hour period and sent to the device timeline.
  • Enable Users to Trust Networks: After the update, connection and disconnection events to open wireless networks, including trusted networks, are sent to the device timeline as events.
  • Users allow-listed certificates: After the update, downloading/installing/deleting self-signed certificates events, including user-trusted certificates, are sent to the device timeline as events.
  • The previous experience of generating alerts for these activities still continue to apply to GCC tenants.

Configure privacyPrivacy controls overview

Privacy controls are settings that let adminssecurity administrators limit which threat details Defender for Endpoint sends in alert reports from Android devices. The following privacy controls are available:devices:

Threat ReportDetails
  • Malware report
Admins can set up privacy control for malware report. Ifreports: When privacy is enabled, then Defender for Endpoint wondoesn't send the malwaremalicious app name andor other app details as part of thein malware alert report.
Phish reportAdmins can set up privacy control for phishing reports. IfFor configuration instructions, see Configure privacy for malware threat reports.
  • Phishing reports: When privacy is enabled, then Defender for Endpoint wondoesn't send the domain name and details of theor unsafe website as part of thedetails in phishing alert report.
  • reports. For configuration instructions, see Configure privacy for phishing alert reports.
  • Vulnerability assessment of apps
  • : By default only information aboutdefault, Defender for Endpoint sends the list of apps installed in the work profile is sent for vulnerability assessment. AdminsSecurity administrators can disableenable privacy to include personal apps
    prevent this app inventory from being sent. For configuration instructions, see Configure app inventory privacy for an Android Enterprise work profile.
  • Network Protection
  • Admins can enable or disableprotection: When privacy in network protection. Ifis enabled, then Defender wonfor Endpoint doesn't send network details.
    For configuration instructions, see Configure privacy alert reports.

    Prerequisite

    • : Install Company portal must be installed, andPortal version must be >=5.0.6621.0
    (June 2025) or later.

    Configure privacy alert report

    AdminsSecurity administrators can now enable privacy controlcontrols for the phishing report,and malware report, and network reportreports sent by Microsoft Defender for Endpoint on Android. This configuration ensures thatWhen Defender detects a corresponding threat, these controls prevent domain or app details from being sent in the domain name, app details,alert.

    Use the Managed devices app configuration policy procedure, and network details, respectively, aren't sent as partadd one or both of the alert whenever a corresponding threat is detected.

    Admin Privacy Controls (MDM) Use the following steps to enable privacy.

    1. In Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

    2. Give the policy a name, Platform > Android enterprise, select the profile type.

    3. Select Microsoft Defender for Endpoint as the target app.

    4. On the Settings page, select Use configuration designer and then select Add.

    5. Select the required privacy settingkeys:

      • Hide URLs in report:

        • Value type: Integer
        • Configuration values:
          • 1: Hide URLsdomain and website details in report for personal profilephishing alert reports.
          • 0: Include domain and website details in phishing alert reports (default).
      • Hide app details in report:

        • Value type: Integer
        • Configuration values:
          • 1: Hide app detailsnames and package information in report for personal profilemalware alert reports.
          • Enable Network Protection Privacy0: Include app names and package information in malware alert reports (default).
        • To enable privacy, enter integer value as 1 and assign this policy to users. By default, this value is set to 0 for MDE in work profile and 1 for MDE on personal profile.

      • Review and assign this profile to targeted devices/users.

    End End-user privacy controls

    The end-End-user privacy controls helplet users choose which threat details Defender for Endpoint shares with their organization. Availability depends on the end Android Enterprise profile:

    • Work profile: End-user to configureprivacy controls aren't available. Security administrators control the information shared to their organization.
      1. For Android Enterprisefrom the work profile, end user controls won't be visible. Admins control these settings.profile.
      2. For Android Enterprise personalPersonal profile, the control is displayed: End-user privacy controls appear under Settings> Privacy in the Defender app. For information about supported work and personal profile configurations, see Supported Android enrollment scenarios.

    When a security administrator enables the corresponding privacy setting, users can configure the following controls:

    • Unsafe site information: Controls whether Defender sends domain and website details in phishing alert reports. For the administrator setting, see Configure privacy for phishing alert reports.
    • UsersMalicious applications: Controls whether Defender sends app names and package information in malware alert reports. For the administrator setting, see a toggle for Unsafe Site Info, malicious application,Configure privacy for malware threat reports.
    • Network protection: Controls whether Defender sends network and network protection.
    • The Unsafe Site Info, malicious application, andcertificate details in network protection toggles are only visible if enabled byreports. For the admin. Users can decide if they want to send the information to their organization or not.administrator setting, see Configure network protection.

    Enabling/disabling the aboveChanging these privacy controls wondoesn't affect the device compliance checkchecks or conditional access.Conditional Access.

    Configure app vulnerability assessment of apps for BYODpersonally owned devices

    FromStarting with Defender for Endpoint on Android version 1.0.3425.0303 of(October 2021), Microsoft Defender for Endpoint on Android, you're able to run vulnerability assessments ofVulnerability Management can assess the OSoperating system (OS) and apps installed on the onboarded mobile devices.

    Notes about privacy related toThe apps from personal devices (BYOD):included in vulnerability assessment depend on how the personally owned device is managed:

    • For Android Enterprise personally owned devices with a work profile,profile: Defender for Endpoint assesses only apps installed onin the work profile are supported.profile. It can't access apps in the personal profile.
    • For other BYOD modes, by default, vulnerabilityDevice administrator mode: Vulnerability assessment of apps will not be enabled. However, whenisn't enabled by default. Security administrators can enable the device is on administrator mode, admins can explicitly enable this feature through Microsoft Intune to getcollect the list of apps installed on the device.

    For more information, see details below.

    Configure privacy forinformation about the Android Enterprise work profile

    management modes that Defender for Endpoint supports vulnerability assessment of apps in the work profile. However, in case you want to turn off this feature for targeted users, you can use the following steps:supports, see Supported Android enrollment scenarios.

    1. In Microsoft Intune admin center, go to Apps > App configuration policies \> Add > Managed devices.
    2. Give the policy a name; Platform > Android Enterprise; select the profile type.
    3. Select Microsoft Defender for Endpoint as the target app.
    4. In Settings page, select Use configuration designer and add Enable TVM Privacy as the key and value type as Integer
    • To disable vulnerability of apps in the work profile, enter value as 1 and assign this policy to users.

      By default, this value is set to 0.

      • For users with key set as 0, Defender for Endpoint sends the list of apps fromin the work profile to Microsoft Defender Vulnerability Management for assessment. To prevent this app inventory from being sent for targeted users, use the backend serviceManaged devices app configuration policy procedure with Personally-Owned Work Profile Only as the profile type. Add the following configuration key:
        • Enable TVM Privacy:
          • Value type: Integer
          • Configuration values:
            • 0: Send the work profile app inventory for vulnerability assessment (default).
            • 1: Don't send the work profile app inventory for vulnerability assessment.
          1. Select Next and assign this profile to targeted devices/users.

        Turning the aboveThis privacy controls on or off wonsetting doesn't affect device compliance checks or Conditional Access.

        Configure non-APK file scanning

        In addition to scanning Android application packages (APK files), Defender for Endpoint on Android can scan non-APK files, such as documents, compressed archives, and scripts, that users download, receive, or store on the device. This capability extends malware protection to more file types.

        Non-APK file scanning is supported on enrolled devices in the following management scenarios:

        • Personally owned devices with a work profile (BYOD)
        • Corporate-owned devices with a work profile (COPE)
        • Corporate-owned, fully managed devices (COBO)

        To enable non-APK file scanning, use the Managed devices app configuration policy procedure, and add the following configuration key:

        • [Preview] Enable non-APK file scan in Microsoft Defender:
          • Value type: Integer
          • Configuration values:
            • 1: Enable non-APK file scanning.
            • 0: Disable non-APK file scanning (default).

        To confirm the policy is applied, verify that EnableNonAPKFileScan is present and set to 1 on the target device.

        When Defender for Endpoint detects malware in a non-APK file, the user receives a notification that the device compliance check or conditional access.is at risk, and an alert appears in the Microsoft Defender portal. Security teams investigate and remediate the threat by using the same malware alert experience as other Defender for Endpoint detections.

        Configure privacy for phishing alert report

        PrivacyThe privacy control for phish reportphishing reports can be used to disable the collection of domain name ornames and website information in the phishphishing threat report. Thisreports. Use this setting gives organizations the flexibility to choose whether they want to collectDefender for Endpoint collects the domain name when it detects and blocks a malicious or phish website is detected and blocked by Defender for Endpoint.phishing website.

        Configure privacy for phishing alert report on Android Enterprise work profile

        Use the following steps to

        To turn on privacy for targeted users in the work profile:

        1. In Microsoft Intune admin center and go to Apps > App configuration policies > Add > Managed devices.

        2. Giveprofile, use the policy a name, Platform > Android EnterpriseManaged devices app configuration policy procedure, select the profile type.

        3. Select Microsoft Defender for Endpoint as the target app.

        4. In Settings page, select Use configuration designer and add the following configuration key:

          • DefenderExcludeURLInReport as the key and value:
            • Value type as : Integer.

              Enter 1 to enable privacy. The default value is 0.

            • Configuration values:
              • 1: Enable privacy.
              • 0: Disable privacy (default).

          Select Next and assignTurning this profile to targeted devices/users.

        Turning the above privacy controlscontrol on or off wondoesn't affect the device compliance check or conditional access.Conditional Access.

        Configure privacy for malware threat report

        PrivacyThe privacy control for malware threat reportreports can be used to disable the collection of app details (namedetails, including name and package information)information, from the malware threat report. Thisreports. Use this setting gives organizations the flexibility to choose whether they want to collectDefender for Endpoint collects the app name when it detects a malicious app is detected.app.

        Configure privacy for malware alert report on Android Enterprise work profile

        Use the following steps to

        To turn on privacy for targeted users in the work profile:

        1. In Microsoft Intune admin center and go to Apps > App configuration policies > Add > Managed devices.

        2. Giveprofile, use the policy a name, Platform > Android EnterpriseManaged devices app configuration policy procedure, select the profile type.

        3. Select Microsoft Defender for Endpoint as the target app.

        4. In Settings page, select Use configuration designer and add the following configuration key:

          • DefenderExcludeAppInReport as the key and value:
            • Value type as : Integer

              Enter 1 to enable privacy. The default value is 0.

            • Select NextConfiguration values and assign this profile to targeted devices/users.:

              • 1: Enable privacy.
      • 0: Disable privacy (default).

    Using this privacy control wondoesn't affect the device compliance check or conditional access.Conditional Access. For example, devices with a malicious app will always have a risk level of "Medium".

    Disable sign out

    Defender for Endpoint supports deployment without the sign out button in the app to prevent users from signing out ofapp. Hiding the Defender app. This is important tobutton helps prevent users from tampering with the device. Use the following steps to configure Disable out sign:

    1. In Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

    2. Give the policy a name, select Platform > Android EnterpriseManaged devices app configuration policy procedure, and selectadd the profile type.following configuration key:

      • Select Microsoft Defender for Endpoint as the target app.

      • In the Settings page, select Use configuration designer and add Disable Sign Out as:

        • Value type: Integer
        • Configuration values:
          • 1: Hide the key and Integer assign out button. This value is the value type.
            • By default, Disable Sign Out = 1default for Android Enterprise personally owned work profiles, fully managed, company managed devices, and corporate-owned personally enabled profiles.devices with a work profile.

            • Admins need to make Disable Sign Out = 0 to enable: Show the sign out button in the app. Users are able to see the sign out button once the policy is pushed.button.

          • Select Next and assign this profile to targeted devices and users.

    Configure device tagging

    Defender for Endpoint on Android enablessupports bulk tagging theof mobile devices during onboarding by allowing the admins to set up tags via Intune. Admin canonboarding. Security administrators configure the device tags through Intune viaapp configuration policies and pushdeploy them to userusers's devices. Once the User installsAfter users install and activatesactivate Defender, the client app passessends the device tags to the Security Portal.Microsoft Defender portal. The Device tags appear againstwith the devices in the Device Inventory. device inventory.

    UseTo configure device tags, use the Managed devices app configuration policy procedure, and add the following steps to configure the Device tags:

    1. In Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

    2. Give the policy a name, select Platform > Android Enterprise, and select the profile type.

    3. Select Microsoft Defender for Endpoint as the target app.

    4. In Settings page, select Use configuration designer and add DefenderDeviceTag as the key and value type as String.key:

      • Admin canDefenderDeviceTag:
        • Value type: String
        • Configuration value:
          • To assign a new tag by adding the key DefenderDeviceTag and settingtag, enter a value for the device tag.
          • Admin canTo edit an existing tag by modifyingtag, change the value of the key DefenderDeviceTag.value.
          • Admin canTo delete an existing tag by removingtag, remove the configuration key DefenderDeviceTag.from the policy.
        • Select Next and assign this policy to targeted devices and users.

    Related content