Configure Microsoft Defender for Endpoint on Android
In brief
The guide was retitled and restructured. It now covers protection, privacy, file scanning, device tagging, vulnerability assessment, sign-out controls, custom indicators, and web protection through Microsoft Intune, with updated licensing and platform-limit details.
What Defender admins need to know
Review the revised guidance when configuring Android devices, particularly the Intune subscription requirement and custom indicator limitations. No immediate administrator action is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure Microsoft Defender for Endpoint features on Android
Security administrators can use Microsoft Intune to configure risk-based Conditional Access, custom indicators, web and network protection, privacy controls, vulnerability assessment, file scanning, sign-out controls, and device tags for Microsoft Defender for Endpoint on Android. Before you configure these features, deploy and onboard Defender for Endpoint on the Android featuresdevices you manage.
Microsoft Intune is a separate product that isn't included with every Defender for Endpoint subscription. You need a subscription that includes Intune, or you can buy Intune as a standalone subscription or add-on. For more information, see Microsoft Intune licensing.
Conditional Access with Defender for Endpoint on Android
Microsoft Defender for Endpoint on Android, alongAndroid works with Microsoft Intune and Microsoft Entra ID, enables enforcing DeviceID to enforce device compliance and Conditional Access policies based on device risk levels. Defender for Endpoint is a Mobile Threat Defensemobile threat defense (MTD) solution that you can deploy through Intune.
For more information about how to set up Defender for Endpoint on Android and Conditional Access, see Defender for Endpoint and Intune.
Configure custom indicators
Defender for Endpoint on Android supports custom indicators with some platform-specific limitations.
For information about configuring custom indicators, see Overview of indicators.
Configure web protection
Defender for Endpoint on Android allows IT Administrators the ability toadministrators can configure the web protection feature. This capability is available withinin the Microsoft Intune admin center.
Web protection helps For the complete procedure to create a Managed devices app configuration policy in Intune, see Create an app configuration policy (opens in a new tab in the Intune documentation). When creating the policy, always start with these settings: Network protection Network protection includes Network protection in Trusted CA certificate list for Network Protection: If your organization uses private root certification authorities (CAs), establish explicit trust between Intune, the mobile device management (MDM) solution, and user devices. Establishing trust helps prevent Defender from flagging the root CAs as rogue certificates.
Value type: Keep the default value String to enter the certificate thumbprints directly.
Configuration value: Add a comma-separated list of Secure Hash Algorithm 1 (SHA-1) certificate thumbprints in one of the following formats:
For example, Enable Network Protection Privacy: Enables or disables privacy in network protection.
Enable Users to Trust Networks and Certificates: Allows or prevents users from trusting or removing trust from unsecured networks and malicious certificates in the app.
Automatic Remediation of Network Protection Alerts: Enables or disables remediation alerts when users take remediation actions. For example, a user switches to a safer Wi-Fi access point or deletes a suspicious certificate detected by Defender. This setting applies only to alerts and doesn't affect device timeline events. It doesn't apply to the detection of open Wi-Fi networks or self-signed certificates.
Manage Network Protection detection for Open Networks: Enables or disables open network detection.
Manage Network protection Detection for Certificates: In audit mode, events are sent to security operations center (SOC) administrators, but users don't receive notifications when Defender detects a malicious certificate. Set the value to Any other separation characters are invalid.
For other configurations related to Network protection, add the following keys and appropriate corresponding value.
Add the required groups to which the policy has to be applied. Review and create the policy.
Privacy controls Prerequisite Use the Managed devices app configuration policy procedure, and Hide URLs in report: Hide app details in report: When a security administrator enables the corresponding privacy setting, users can configure the following controls: For more management modes that Defender for Endpoint By default, In addition to scanning Android application packages (APK files), Defender for Endpoint on Android can scan non-APK files, such as documents, compressed archives, and scripts, that users download, receive, or store on the device. This capability extends malware protection to more file types. Non-APK file scanning is supported on enrolled devices in the following management scenarios: To enable non-APK file scanning, use the Managed devices app configuration policy procedure, and add the following configuration key: To confirm the policy is applied, verify that EnableNonAPKFileScan is present and set to When Defender for Endpoint detects malware in a non-APK file, the user receives a notification that the device To turn on privacy for targeted users in the work To turn on privacy for targeted users in the work Using this privacy control Defender for Endpoint supports deployment without the sign out button in the Defender for Endpoint on Android to secure devices against web threats and protect users from phishing attacks. Anti-phishing and custom indicators (URL and IP addresses) are supported as part of web protection. Web content filteringfiltering, which is a separate web protection capability, is currently not supported on mobile platforms.
Configure network protection
provides protection againstdetects threats from rogue Wi-Fi related threatsnetworks and rogue certificates, which are the primary attack vector for Wi-Fi networks. Adminscertificates. Security administrators can list thetrusted root Certificate Authoritycertification authority (CA) and private root CAself-signed certificates in the Microsoft Intune admin center andto establish trust with endpoints. It provides the user a guided experienceNetwork protection guides users to connect to secure networks and also notifies them ifwhen it detects a related threat is detected.threat.
several admin controls to offer flexibility, such as the ability to configurefor configuring the feature from withinand adding trusted certificates in the Microsoft Intune admin center and add trusted certificates. Adminscenter. Security administrators can enable privacy controlsprivacy controls to configure the data sent to Defender for Endpoint from Android devices.
Microsoft Defender for endpointEndpoint is enabled by default. Admins can useUse the Managed devices app configuration policy procedure, and add the following steps to configure Network protection in Android devices.configuration keys:
In the Microsoft Intune admin center, navigate to Apps > App configuration policies. Create a new App configuration policy.
Provide a name and description to uniquely identify the policy. Select 'Android Enterprise' as the platform and 'Personally-owned work profile only' as the profile type and 'Microsoft Defender' as the Targeted app.In Settings page, select 'Use configuration designer' and add 'Enable Network Protection in Microsoft Defender': When you add this key, its default Configuration value asis 0, which disables network protection. To enable network protection, change the key and value as '0'to disable Network Protection. (Network protection is enabled by default)1.
50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31503006091d97d4f5ae39f7cbe7927d7d652d343150 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31, 503006091d97d4f5ae39f7cbe7927d7d652d3431. Any other separation characters in the certificate thumbprint (for example, :) are invalid.
1: Enable (default)0: Disable
1: Enable0: Disable (default)
1: Enable (default)0: Disable
2: Enable (default)1: Audit mode0: Disable2 to enable full functionality. When the value is 2, users receive notifications, and events are sent to SOC administrators when Defender detects a malicious certificate.
2: Enable1: Audit mode0: Disable (default)To establish trust for the root CAs, use 'Trusted CA certificate list for Network Protection' as the key. In the value, add the 'comma separated list of certificate thumbprints (SHA 1)'.Example of Thumbprint format to add: 50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31, 503006091d97d4f5ae39f7cbe7927d7d652d3431
Configuration Key
Description
Trusted CA certificate list for Network Protection
Security admins manage this setting to establish trust for root CA and self-signed certificates.
Enable Network protection in Microsoft Defender
1: Enable (default)
0: Disable
This setting is used by the IT admin to enable or disable the network protection capabilities in the Defender app.
Enable Network Protection Privacy
1: Enable (default)
0: Disable
Security admins manage this setting to enable or disable privacy in network protection.
Enable Users to Trust Networks and Certificates
1: Enable
0: Disable (default)
This setting is used by IT admins to enable or disable the end user in-app experience to trust and untrust the unsecure networks and malicious certificates.
Automatic Remediation of Network Protection Alerts
1: Enable (default)
0: Disable
This setting is used by IT admins to enable or disable the remediation alerts that are sent when a user does remediation activities. For example, the user switches to a safer Wi-Fi access point or deletes suspicious certificates that were detected by Defender. This setting only applies to alerts and does not affect device timeline events. As such, it does not apply to the detection of open Wi-Fi networks or self-signed certificates
Manage Network Protection detection for Open Networks
2: Enable (default)
1: Audit Mode
0: Disable
Security admins manage this setting to enable or disable open network detection.
Manage Network protection Detection for Certificates
2: Enable
1: Audit mode
0: Disable (default)
In audit mode, events are sent to SOC admins, but no end user notifications are shown when Defender detects a bad certificate. Admins can enable full feature functionality by setting the value 2. When the value is 2, end user notifications are sent to users and events are sent to SOC admins when Defender detects a bad certificate.
Configure privacyPrivacy controls overvieware settings that let adminssecurity administrators limit which threat details Defender for Endpoint sends in alert reports from Android devices. The following privacy controls are available:devices:
For configuration instructions, see Configure privacy alert reports.
Threat ReportDetailsreportAdmins can set up privacy control for malware report. Ifreports: When privacy is enabled, then Defender for Endpoint wondoesn't send the malwaremalicious app name andor other app details as part of thein malware alert report.Phish reportAdmins can set up privacy control for phishing reports. IfFor configuration instructions, see Configure privacy for malware threat reports.then Defender for Endpoint wondoesn't send the domain name and details of theor unsafe website as part of thedetails in phishing alert report.reports. For configuration instructions, see Configure privacy for phishing alert reports. : By default only information aboutdefault, Defender for Endpoint sends the list of apps installed in the work profile is sent for vulnerability assessment. AdminsSecurity administrators can disableenable privacy to include personal appsprevent this app inventory from being sent. For configuration instructions, see Configure app inventory privacy for an Android Enterprise work profile. ProtectionAdmins can enable or disableprotection: When privacy in network protection. Ifis enabled, then Defender wonfor Endpoint doesn't send network details.
(June 2025) or later.
portal must be installed, andPortal version must be >=5.0.6621.0Configure privacy alert report
AdminsSecurity administrators can now enable privacy controlcontrols for the phishing report,and malware report, and network reportreports sent by Microsoft Defender for Endpoint on Android. This configuration ensures thatWhen Defender detects a corresponding threat, these controls prevent domain or app details from being sent in the domain name, app details,alert.network details, respectively, aren't sent as partadd one or both of the alert whenever a corresponding threat is detected.Admin Privacy Controls (MDM) Use the following steps to enable privacy.In Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.Give the policy a name, Platform > Android enterprise, select the profile type.Select Microsoft Defender for Endpoint as the target app.On the Settings page, select Use configuration designer and then select Add.Select the required privacy settingkeys:
1: Hide URLsdomain and website details in report for personal profilephishing alert reports.0: Include domain and website details in phishing alert reports (default).1: Hide app detailsnames and package information in report for personal profilemalware alert reports.Enable Network Protection Privacy0: Include app names and package information in malware alert reports (default).To enable privacy, enter integer value as 1 and assign this policy to users. By default, this value is set to 0 for MDE in work profile and 1 for MDE on personal profile.Review and assign this profile to targeted devices/users.End End-user privacy controlsThe end-End-user privacy controls helplet users choose which threat details Defender for Endpoint shares with their organization. Availability depends on the end Android Enterprise profile:to configureprivacy controls aren't available. Security administrators control the information shared to their organization.For Android Enterprisefrom the work profile, end user controls won't be visible. Admins control these settings.profile.For Android Enterprise personalPersonal profile, the control is displayed: End-user privacy controls appear under Settings> Privacy in the Defender app. For information about supported work and personal profile configurations, see Supported Android enrollment scenarios.UsersMalicious applications: Controls whether Defender sends app names and package information in malware alert reports. For the administrator setting, see a toggle for Unsafe Site Info, malicious application,Configure privacy for malware threat reports.network protection.The Unsafe Site Info, malicious application, andcertificate details in network protection toggles are only visible if enabled byreports. For the admin. Users can decide if they want to send the information to their organization or not.administrator setting, see Configure network protection.Enabling/disabling the aboveChanging these privacy controls wondoesn't affect the device compliance checkchecks or conditional access.Conditional Access.Configure app vulnerability assessment
of apps for BYODpersonally owned devicesFromStarting with Defender for Endpoint on Android version 1.0.3425.0303 of(October 2021), Microsoft Defender for Endpoint on Android, you're able to run vulnerability assessments ofVulnerability Management can assess the OSoperating system (OS) and apps installed on the onboarded mobile devices.
Notes about privacy related toThe apps from personal devices (BYOD):included in vulnerability assessment depend on how the personally owned device is managed:
For Android Enterprise personally owned devices with a work profile,profile: Defender for Endpoint assesses only apps installed onin the work profile are supported.profile. It can't access apps in the personal profile.For other BYOD modes, by default, vulnerabilityDevice administrator mode: Vulnerability assessment of apps will not be enabled. However, whenisn't enabled by default. Security administrators can enable the device is on administrator mode, admins can explicitly enable this feature through Microsoft Intune to getcollect the list of apps installed on the device.information, see details below.Configure privacy forinformation about the Android Enterprise work profilesupports vulnerability assessment of apps in the work profile. However, in case you want to turn off this feature for targeted users, you can use the following steps:supports, see Supported Android enrollment scenarios.
In Microsoft Intune admin center, go to Apps > App configuration policies \> Add > Managed devices.Give the policy a name; Platform > Android Enterprise; select the profile type.Select Microsoft Defender for Endpoint as the target app.In Settings page, select Use configuration designer and add Enable TVM Privacy as the key and value type as IntegerTo disable vulnerability of apps in the work profile, enter value as 1 and assign this policy to users. this value is set to 0.For users with key set as 0, Defender for Endpoint sends the list of apps fromin the work profile to Microsoft Defender Vulnerability Management for assessment. To prevent this app inventory from being sent for targeted users, use the backend serviceManaged devices app configuration policy procedure with Personally-Owned Work Profile Only as the profile type. Add the following configuration key:0: Send the work profile app inventory for vulnerability assessment (default).1: Don't send the work profile app inventory for vulnerability assessment.Select Next and assign this profile to targeted devices/users.Turning the aboveThis privacy controls on or off wonsetting doesn't affect device compliance checks or Conditional Access.Configure non-APK file scanning
1: Enable non-APK file scanning.0: Disable non-APK file scanning (default).1 on the target device.compliance check or conditional access.is at risk, and an alert appears in the Microsoft Defender portal. Security teams investigate and remediate the threat by using the same malware alert experience as other Defender for Endpoint detections.
Configure privacy for phishing alert report
PrivacyThe privacy control for phish reportphishing reports can be used to disable the collection of domain name ornames and website information in the phishphishing threat report. Thisreports. Use this setting gives organizations the flexibility to choose whether they want to collectDefender for Endpoint collects the domain name when it detects and blocks a malicious or phish website is detected and blocked by Defender for Endpoint.phishing website.
Configure privacy for phishing alert report on Android Enterprise work profileprofile:In Microsoft Intune admin center and go to Apps > App configuration policies > Add > Managed devices.Giveprofile, use the policy a name, Platform > Android EnterpriseManaged devices app configuration policy procedure, select the profile type.Select Microsoft Defender for Endpoint as the target app.In Settings page, select Use configuration designer and add the following configuration key: as the key and value: as : Integer.Enter 1 to enable privacy. The default value is 0.1: Enable privacy.0: Disable privacy (default).Select Next and assignTurning this profile to targeted devices/users.Turning the above privacy controlscontrol on or off wondoesn't affect the device compliance check or conditional access.Conditional Access.
Configure privacy for malware threat report
PrivacyThe privacy control for malware threat reportreports can be used to disable the collection of app details (namedetails, including name and package information)information, from the malware threat report. Thisreports. Use this setting gives organizations the flexibility to choose whether they want to collectDefender for Endpoint collects the app name when it detects a malicious app is detected.app.
Configure privacy for malware alert report on Android Enterprise work profileprofile:In Microsoft Intune admin center and go to Apps > App configuration policies > Add > Managed devices.Giveprofile, use the policy a name, Platform > Android EnterpriseManaged devices app configuration policy procedure, select the profile type.Select Microsoft Defender for Endpoint as the target app.In Settings page, select Use configuration designer and add the following configuration key: as the key and value: as : IntegerEnter 1 to enable privacy. The default value is 0.Select NextConfiguration values and assign this profile to targeted devices/users.:1: Enable privacy.0: Disable privacy (default).wondoesn't affect the device compliance check or conditional access.Conditional Access. For example, devices with a malicious app will always have a risk level of "Medium".
Disable sign out
app to prevent users from signing out ofapp. Hiding the Defender app. This is important tobutton helps prevent users from tampering with the device. Use the following steps to configure Disable out sign:In Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.Give the policy a name, select Platform > Android EnterpriseManaged devices app configuration policy procedure, and selectadd the profile type.following configuration key:
Select Microsoft Defender for Endpoint as the target app.In the Settings page, select Use configuration designer and add Disable Sign Out as:1: Hide the key and Integer assign out button. This value is the value type.By default, Disable Sign Out = 1default for Android Enterprise personally owned work profiles, fully managed, company managed devices, and corporate-owned personally enabled profiles.devices with a work profile.Admins need to make Disable Sign Out = 0: Show the sign out to enablebutton in the app. Users are able to see the sign out button once the policy is pushed.button.Select Next and assign this profile to targeted devices and users.Configure device tagging
enablessupports bulk tagging theof mobile devices during onboarding by allowing the admins to set up tags via Intune. Admin canonboarding. Security administrators configure the device tags through Intune viaapp configuration policies and pushdeploy them to userusers's devices. Once the User installsAfter users install and activatesactivate Defender, the client app passessends the device tags to the Security Portal.Microsoft Defender portal. The Device tags appear againstwith the devices in the Device Inventory. device inventory.
UseTo configure device tags, use the Managed devices app configuration policy procedure, and add the following steps to configure the Device tags:In Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.Give the policy a name, select Platform > Android Enterprise, and select the profile type.Select Microsoft Defender for Endpoint as the target app.In Settings page, select Use configuration designer and add DefenderDeviceTag as the key and value type as String.key:
Admin canDefenderDeviceTag:tag by adding the key DefenderDeviceTag and settingtag, enter a value for the device tag.Admin canTo edit an existing tag by modifyingtag, change the value of the key DefenderDeviceTag.value.Admin canTo delete an existing tag by removingtag, remove the configuration key DefenderDeviceTag.from the policy.Select Next and assign this policy to targeted devices and users.Related content
@@ -1,6 +1,6 @@ ----title: Configure Microsoft Defender for Endpoint on Android risk and protection settings-description: Learn how to configure web protection, network protection, privacy controls, custom indicators, and device tagging for Microsoft Defender for Endpoint on Android using Microsoft Intune.+title: Configure Microsoft Defender for Endpoint on Android+description: Learn how to configure protection, privacy, file scanning, and device tagging for Microsoft Defender for Endpoint on Android by using Microsoft Intune. ms.service: defender-endpoint ms.author: painbar author: paulinbar@@ -12,261 +12,305 @@ ms.collection: - mde-android ms.topic: how-to ms.subservice: android-ms.date: 06/19/2026+ms.date: 08/26/2026 appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016++#customer intent: As a security administrator, I want to configure Defender for Endpoint features on Android devices so that I can protect devices and control the security data they report. --- -# Configure Defender for Endpoint on Android features+# Configure Microsoft Defender for Endpoint features on Android++Security administrators can use Microsoft Intune to configure risk-based Conditional Access, custom indicators, web and network protection, privacy controls, vulnerability assessment, file scanning, sign-out controls, and device tags for Microsoft Defender for Endpoint on Android. Before you configure these features, deploy and onboard Defender for Endpoint on the Android devices you manage. +Microsoft Intune is a separate product that isn't included with every Defender for Endpoint subscription. You need a subscription that includes Intune, or you can buy Intune as a standalone subscription or add-on. For more information, see [Microsoft Intune licensing](/intune/intune-service/fundamentals/licenses). ## Conditional Access with Defender for Endpoint on Android -Microsoft Defender for Endpoint on Android, along with Microsoft Intune and Microsoft Entra ID, enables enforcing Device compliance and Conditional Access policies based on device risk levels. Defender for Endpoint is a Mobile Threat Defense (MTD) solution that you can deploy through Intune.+Microsoft Defender for Endpoint on Android works with Microsoft Intune and Microsoft Entra ID to enforce device compliance and Conditional Access policies based on device risk levels. Defender for Endpoint is a mobile threat defense (MTD) solution that you can deploy through Intune. For more information about how to set up Defender for Endpoint on Android and Conditional Access, see [Defender for Endpoint and Intune](/intune/intune-service/protect/advanced-threat-protection). ## Configure custom indicators +Defender for Endpoint on Android supports custom indicators with some platform-specific limitations.+ > [!NOTE] > Defender for Endpoint on Android supports creating custom indicators only for URLs and domains. IP-based custom indicators aren't supported on Android.-> -> IP `245.245.0.1` is an internal Defender IP and should not be included in custom indicators by customers to avoid any functionality issues.-> Also, alerts for custom indicators are currently not supported for Defender for Endpoint on Android.+>+> IP address `245.245.0.1` is an internal Defender IP address. Don't include it in custom indicators because doing so can cause functionality issues.+>+> Alerts for custom indicators are currently not supported for Defender for Endpoint on Android. -Defender for Endpoint on Android enables admins to configure custom indicators to support Android devices as well. For more information on how to configure custom indicators, see [Overview of indicators](indicators-overview.md).+For information about configuring custom indicators, see [Overview of indicators](indicators-overview.md). ## Configure web protection -Defender for Endpoint on Android allows IT Administrators the ability to configure the web protection feature. This capability is available within the Microsoft Intune admin center.--[Web protection](web-protection-overview.md) helps to secure devices against web threats and protect users from phishing attacks. Anti-phishing and custom indicators (URL and IP addresses) are supported as part of web protection. Web content filtering is currently not supported on mobile platforms.- > [!NOTE]-> Defender for Endpoint on Android would use a VPN in order to provide the Web Protection feature. This VPN isn't a regular VPN. Instead, it's a local/self-looping VPN that doesn't take traffic outside the device.+> Defender for Endpoint on Android uses a local loopback virtual private network (VPN) to provide web protection. The VPN doesn't route traffic outside the device. > > For more information, see [Configure web protection on devices that run Android](/intune/intune-service/protect/advanced-threat-protection-manage-android). -<a name="network-protection"></a>-## Configure network protection+IT administrators can configure web protection in the Microsoft Intune admin center. -Network protection provides protection against rogue Wi-Fi related threats and rogue certificates, which are the primary attack vector for Wi-Fi networks. Admins can list the root Certificate Authority (CA) and private root CA certificates in Microsoft Intune admin center and establish trust with endpoints. It provides the user a guided experience to connect to secure networks and also notifies them if a related threat is detected.+[Web protection](web-protection-overview.md) helps secure devices against web threats and protect users from phishing attacks. Web content filtering, which is a separate web protection capability, is currently not supported on mobile platforms. -Network protection includes several admin controls to offer flexibility, such as the ability to configure the feature from within the Microsoft Intune admin center and add trusted certificates. Admins can enable [privacy controls](android-configure.md#privacy-controls) to configure the data sent to Defender for Endpoint from Android devices.+## Create a Managed devices app configuration policy -Network protection in Microsoft Defender for endpoint is enabled by default. Admins can use the following steps to **configure Network protection in Android devices.**+The Defender settings in the following sections use an Android Enterprise **Managed devices** app configuration policy in Intune. You can add multiple Defender configuration keys to one policy when the keys apply to the same profile type and assignments. Create separate policies when you need to target different profiles, users, or devices. -In the Microsoft Intune admin center, navigate to Apps > App configuration policies. Create a new App configuration policy.+Before you create the policy, add and approve **Defender: Antivirus** from Managed Google Play, and then sync it to Intune. After the sync, the app appears in Intune as **Microsoft Defender: Antivirus**. For deployment instructions, see [Deploy Microsoft Defender for Endpoint on Android with Microsoft Intune](/intune/device-security/microsoft-defender/deploy-android). -1. Provide a name and description to uniquely identify the policy. Select **'Android Enterprise'** as the platform and **'Personally-owned work profile only'** as the profile type and **'Microsoft Defender'** as the Targeted app.+For the complete procedure to create a **Managed devices** app configuration policy in Intune, see <a href="/intune/app-management/configuration/configure-managed-android#create-an-app-configuration-policy" target="_blank">Create an app configuration policy</a> (opens in a new tab in the Intune documentation). When creating the policy, always start with these settings: -1. In Settings page, select **'Use configuration designer'** and add **'Enable Network Protection in Microsoft Defender'** as the key and value as **'0'** to disable Network Protection. (Network protection is enabled by default)+- **Basics** tab: Configure the following settings:+ - **Platform**: Select **Android Enterprise**.+ - **Profile type**: Select one of the following values:+ - **All Profile Types**: Applies the policy to all supported enrollment types. You can't associate an Intune certificate profile with the app configuration policy.+ - **Fully Managed, Dedicated, and Corporate-Owned Work Profile Only**: Applies the policy to corporate-owned, personally enabled (COPE) and corporate-owned, business-only (COBO) devices.+ - **Personally-Owned Work Profile Only**: Applies the policy to bring-your-own-device (BYOD) work profiles.+ - **Targeted app**: Select **Select app**, select **Microsoft Defender: Antivirus**, and then select **OK**.+- **Settings** tab: Select **Use configuration designer** for **Configuration settings format**, and then select **Add**.+ - In the flyout that opens, select the configuration keys specified in the applicable sections of this article, and then select **OK**.+ - Configure the value for each key, and then complete the assignments and create the policy as described in the Intune procedure. -1. If your organization uses root CAs that are private, you must establish explicit trust between Intune (MDM solution) and user devices. Establishing trust helps prevent Defender from flagging root CAs as rogue certificates.+<a name="network-protection"></a> - To establish trust for the root CAs, use **'Trusted CA certificate list for Network Protection'** as the key. In the value, add the **'comma separated list of certificate thumbprints (SHA 1)'**.+## Configure network protection - **Example of Thumbprint format to add**: `50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31, 503006091d97d4f5ae39f7cbe7927d7d652d3431`+Network protection detects threats from rogue Wi-Fi networks and certificates. Security administrators can list trusted root certification authority (CA) and self-signed certificates in the Microsoft Intune admin center to establish trust with endpoints. Network protection guides users to connect to secure networks and notifies them when it detects a related threat. - > [!IMPORTANT]- > Certificate SHA-1 Thumbprint characters should be with either white space separated, or non separated.- >- > This format is invalid: `50:30:06:09:1d:97:d4:f5:ae:39:f7:cb:e7:92:7d:7d:65:2d:34:31`+Network protection includes controls for configuring the feature and adding trusted certificates in the Microsoft Intune admin center. Security administrators can enable [privacy controls](#privacy-controls-overview) to configure the data sent to Defender for Endpoint from Android devices. - Any other separation characters are invalid.+Network protection in Defender for Endpoint is enabled by default. Use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add the following configuration keys: -1. For other configurations related to Network protection, add the following keys and appropriate corresponding value.+- **Enable Network Protection in Microsoft Defender**: When you add this key, its default **Configuration value** is `0`, which disables network protection. To enable network protection, change the value to `1`. - | Configuration Key | Description|- |---|---|- |Trusted CA certificate list for Network Protection|Security admins manage this setting to establish trust for root CA and self-signed certificates.|- |Enable Network protection in Microsoft Defender|1: Enable (default)<br/> 0: Disable<br/><br/> This setting is used by the IT admin to enable or disable the network protection capabilities in the Defender app.|- |Enable Network Protection Privacy|1: Enable (default) <br/> 0: Disable <br/><br/> Security admins manage this setting to enable or disable privacy in network protection.|- |Enable Users to Trust Networks and Certificates|1: Enable <br/>0: Disable (default) <br/><br/> This setting is used by IT admins to enable or disable the end user in-app experience to trust and untrust the unsecure networks and malicious certificates.|- |Automatic Remediation of Network Protection Alerts|1: Enable (default) <br/> 0: Disable <br/><br/> This setting is used by IT admins to enable or disable the remediation alerts that are sent when a user does remediation activities. For example, the user switches to a safer Wi-Fi access point or deletes suspicious certificates that were detected by Defender. This setting only applies to alerts and does not affect device timeline events. As such, it does not apply to the detection of open Wi-Fi networks or self-signed certificates |- |Manage Network Protection detection for Open Networks| 2: Enable (default)<br/> 1: Audit Mode <br/> 0: Disable <br/><br/>Security admins manage this setting to enable or disable open network detection. |- |Manage Network protection Detection for Certificates|2: Enable <br/> 1: Audit mode<br/> 0: Disable (default)<br/><br/>In audit mode, events are sent to SOC admins, but no end user notifications are shown when Defender detects a bad certificate. Admins can enable full feature functionality by setting the value 2. When the value is 2, end user notifications are sent to users and events are sent to SOC admins when Defender detects a bad certificate.|+ > [!IMPORTANT]+ > The remaining network protection configuration keys in this section take effect only when **Enable Network Protection in Microsoft Defender** is added to the policy and set to `1`. -1. Add the required groups to which the policy has to be applied. Review and create the policy.+- **Trusted CA certificate list for Network Protection**: If your organization uses private root certification authorities (CAs), establish explicit trust between Intune, the mobile device management (MDM) solution, and user devices. Establishing trust helps prevent Defender from flagging the root CAs as rogue certificates.+ - **Value type**: Keep the default value **String** to enter the certificate thumbprints directly.+ - **Configuration value**: Add a comma-separated list of Secure Hash Algorithm 1 (SHA-1) certificate thumbprints in one of the following formats:+ - `50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31`+ - `503006091d97d4f5ae39f7cbe7927d7d652d3431` -> [!NOTE]-> - The other config keys of Network Protection will only work if the parent key '**Enable Network Protection in Microsoft Defender'** is enabled.-> - To ensure comprehensive protection against Wi-Fi threats, users should enable location permission and select the "Allow All the Time" option. This permission is optional but highly recommended, even when the app is not actively in use. If location permission is denied, Defender for Endpoint will only offer limited protection against network threats and will only safeguard users from rogue certificates.+ For example, `50 30 06 09 1d 97 d4 f5 ae 39 f7 cb e7 92 7d 7d 65 2d 34 31, 503006091d97d4f5ae39f7cbe7927d7d652d3431`. Any other separation characters in the certificate thumbprint (for example, `:`) are invalid. -> [!IMPORTANT]-> Starting May 19, 2025, alerts are no longer generated in the Microsoft Defender portal for mobile devices connecting or disconnecting to an open wireless network and for downloading/installing/deleting self-signed certificates. Instead, these activities are now generated as events and are viewable in the device timeline.-> Here are key changes about this new experience:-- For these changes to take effect, end-users must update to the latest version of Defender for Endpoint on Android available on mid-May 2025. Otherwise, the previous experience of generating alerts will still be in place. If auto-remediation key is enabled by the admin, old alerts are resolved automatically after the changes take effect.-- When an end-user connects or disconnects to an open wireless network multiple times within the same 24-hour period, only one event each for the connection and disconnection is generated in that 24-hour period and sent to the device timeline.-- Enable Users to Trust Networks: After the update, connection and disconnection events to open wireless networks, including trusted networks, are sent to the device timeline as events.-- Users allow-listed certificates: After the update, downloading/installing/deleting self-signed certificates events, including user-trusted certificates, are sent to the device timeline as events.-- The previous experience of generating alerts for these activities still continue to apply to GCC tenants.+- **Enable Network Protection Privacy**: Enables or disables privacy in network protection.+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Enable (default)+ - `0`: Disable +- **Enable Users to Trust Networks and Certificates**: Allows or prevents users from trusting or removing trust from unsecured networks and malicious certificates in the app.+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Enable+ - `0`: Disable (default) -<a name="privacy-controls"></a>-## Configure privacy controls+- **Automatic Remediation of Network Protection Alerts**: Enables or disables remediation alerts when users take remediation actions. For example, a user switches to a safer Wi-Fi access point or deletes a suspicious certificate detected by Defender. This setting applies only to alerts and doesn't affect device timeline events. It doesn't apply to the detection of open Wi-Fi networks or self-signed certificates.+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Enable (default)+ - `0`: Disable -Privacy controls are settings that let admins limit which threat details Defender for Endpoint sends in alert reports from Android devices. The following privacy controls are available:+- **Manage Network Protection detection for Open Networks**: Enables or disables open network detection.+ - **Value type**: Integer+ - **Configuration values**:+ - `2`: Enable (default)+ - `1`: Audit mode+ - `0`: Disable -|Threat Report |Details |-|--------------------|-------------|-|Malware report |Admins can set up privacy control for malware report. If privacy is enabled, then Defender for Endpoint won't send the malware app name and other app details as part of the malware alert report. |-|Phish report |Admins can set up privacy control for phishing reports. If privacy is enabled, then Defender for Endpoint won't send the domain name and details of the unsafe website as part of the phishing alert report. |-|Vulnerability assessment of apps |By default only information about apps installed in the work profile is sent for vulnerability assessment. Admins can disable privacy to include personal apps|-|Network Protection | Admins can enable or disable privacy in network protection. If enabled, then Defender won't send network details.|+- **Manage Network protection Detection for Certificates**: In audit mode, events are sent to security operations center (SOC) administrators, but users don't receive notifications when Defender detects a malicious certificate. Set the value to `2` to enable full functionality. When the value is `2`, users receive notifications, and events are sent to SOC administrators when Defender detects a malicious certificate.+ - **Value type**: Integer+ - **Configuration values**:+ - `2`: Enable+ - `1`: Audit mode+ - `0`: Disable (default) -**Prerequisite**+> [!NOTE]+>+> - For comprehensive protection against Wi-Fi threats, users should grant location permission and select **Allow all the time** during onboarding. If users select **While using the app** or deny permission, Defender for Endpoint protects against rogue certificates but can't detect threats on open or suspicious Wi-Fi networks. For more information, see [Complete device onboarding](/intune/device-security/microsoft-defender/deploy-android#complete-device-onboarding).+>+> - Starting in May 2025, the Microsoft Defender portal no longer generates alerts when mobile devices connect to or disconnect from an open wireless network, or when users download, install, or delete self-signed certificates. Instead, these activities generate events that are available in the device timeline. The updated experience includes the following changes:+> - For these changes to take effect, users must update to the version of Defender for Endpoint on Android released in mid-May 2025 or later. Otherwise, the previous alert experience remains in place. If an administrator enables the automatic remediation key, old alerts are resolved automatically after the changes take effect.+> - When a user connects to or disconnects from an open wireless network multiple times in the same 24-hour period, only one connection event and one disconnection event are generated during that period and sent to the device timeline.+> - **Enable Users to Trust Networks**: After the update, connection and disconnection events for open wireless networks, including trusted networks, are sent to the device timeline.+> - **User allowlisted certificates**: After the update, events for downloading, installing, or deleting self-signed certificates, including user-trusted certificates, are sent to the device timeline.+> - The previous alert experience for these activities continues to apply to GCC tenants.++<a name="privacy-controls"></a> -- Company portal must be installed, and version must be >=5.0.6621.0+<a name="configure-privacy-controls"></a> -### Configure privacy alert report+## Privacy controls overview -Admins can now enable privacy control for the phishing report, malware report, and network report sent by Microsoft Defender for Endpoint on Android. This configuration ensures that the domain name, app details, and network details, respectively, aren't sent as part of the alert whenever a corresponding threat is detected.+Privacy controls let security administrators limit which threat details Defender for Endpoint sends from Android devices: -Admin Privacy Controls (MDM) Use the following steps to enable privacy.+- **Malware reports**: When privacy is enabled, Defender for Endpoint doesn't send the malicious app name or other app details in malware alert reports. For configuration instructions, see [Configure privacy for malware threat reports](#configure-privacy-for-malware-threat-report).+- **Phishing reports**: When privacy is enabled, Defender for Endpoint doesn't send the domain name or unsafe website details in phishing alert reports. For configuration instructions, see [Configure privacy for phishing alert reports](#configure-privacy-for-phishing-alert-report).+- **Vulnerability assessment of apps**: By default, Defender for Endpoint sends the list of apps installed in the work profile for vulnerability assessment. Security administrators can enable privacy to prevent this app inventory from being sent. For configuration instructions, see [Configure app inventory privacy for an Android Enterprise work profile](#configure-app-inventory-privacy-for-an-android-enterprise-work-profile).+- **Network protection**: When privacy is enabled, Defender for Endpoint doesn't send network details. For configuration instructions, see [Configure privacy alert reports](#configure-privacy-alert-report). -1. In Microsoft Intune admin center, go to **Apps > App configuration policies > Add > Managed devices**.+**Prerequisite**: Install Company Portal version 5.0.6621.0 (June 2025) or later. -1. Give the policy a **name, Platform > Android enterprise, select the profile type**.+### Configure privacy alert report++Security administrators can enable privacy controls for phishing and malware reports sent by Defender for Endpoint on Android. When Defender detects a corresponding threat, these controls prevent domain or app details from being sent in the alert. -1. Select **Microsoft Defender for Endpoint** as the target app.+Use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add one or both of the following configuration keys: -1. On the Settings page, select **Use configuration designer** and then select **Add**.+- **Hide URLs in report**:+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Hide domain and website details in phishing alert reports.+ - `0`: Include domain and website details in phishing alert reports (default). -1. Select the required privacy setting- - Hide URLs in report- - Hide URLs in report for personal profile- - Hide app details in report- - Hide app details in report for personal profile- - Enable Network Protection Privacy+- **Hide app details in report**:+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Hide app names and package information in malware alert reports.+ - `0`: Include app names and package information in malware alert reports (default). -1. To enable privacy, enter integer value as 1 and assign this policy to users. By default, this value is set to 0 for MDE in work profile and 1 for MDE on personal profile.+### End-user privacy controls -1. Review and assign this profile to targeted devices/users.+End-user privacy controls let users choose which threat details Defender for Endpoint shares with their organization. Availability depends on the Android Enterprise profile: -### End user privacy controls+- **Work profile**: End-user privacy controls aren't available. Security administrators control the information shared from the work profile.+- **Personal profile**: End-user privacy controls appear under **Settings** \> **Privacy** in the Defender app. For information about supported work and personal profile configurations, see [Supported Android enrollment scenarios](mtd.md#supported-android-enrollment-scenarios). -The end-user privacy controls help the end user to configure the information shared to their organization.+When a security administrator enables the corresponding privacy setting, users can configure the following controls: -1. For **Android Enterprise work profile**, end user controls won't be visible. Admins control these settings.-1. For **Android Enterprise personal profile**, the control is displayed under **Settings> Privacy**.-1. Users see a toggle for Unsafe Site Info, malicious application, and network protection.+- **Unsafe site information**: Controls whether Defender sends domain and website details in phishing alert reports. For the administrator setting, see [Configure privacy for phishing alert reports](#configure-privacy-for-phishing-alert-report).+- **Malicious applications**: Controls whether Defender sends app names and package information in malware alert reports. For the administrator setting, see [Configure privacy for malware threat reports](#configure-privacy-for-malware-threat-report).+- **Network protection**: Controls whether Defender sends network and certificate details in network protection reports. For the administrator setting, see [Configure network protection](#configure-network-protection). -The Unsafe Site Info, malicious application, and network protection toggles are only visible if enabled by the admin. Users can decide if they want to send the information to their organization or not.+Changing these privacy controls doesn't affect device compliance checks or [Conditional Access](#conditional-access-with-defender-for-endpoint-on-android). -Enabling/disabling the above privacy controls won't affect the device compliance check or conditional access.+<a name="configure-vulnerability-assessment-of-apps-for-byod-devices"></a> -## Configure vulnerability assessment of apps for BYOD devices+## Configure app vulnerability assessment for personally owned devices -From version 1.0.3425.0303 of Microsoft Defender for Endpoint on Android, you're able to run vulnerability assessments of the OS and apps installed on the onboarded mobile devices.+Starting with Defender for Endpoint on Android version 1.0.3425.0303 (October 2021), Microsoft Defender Vulnerability Management can assess the operating system (OS) and apps installed on onboarded mobile devices. > [!NOTE] > Vulnerability assessment is part of [Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management) in Microsoft Defender for Endpoint. -**Notes about privacy related to apps from personal devices (BYOD):**+The apps included in vulnerability assessment depend on how the personally owned device is managed: -- For Android Enterprise with a work profile, only apps installed on the work profile are supported.-- For other BYOD modes, by default, vulnerability assessment of apps will **not** be enabled. However, when the device is on administrator mode, admins can explicitly enable this feature through Microsoft Intune to get the list of apps installed on the device. For more information, see details below.+- **Android Enterprise personally owned devices with a work profile**: Defender for Endpoint assesses only apps installed in the work profile. It can't access apps in the personal profile.+- **Device administrator mode**: Vulnerability assessment of apps isn't enabled by default. Security administrators can enable the feature through Microsoft Intune to collect the list of apps installed on the device. -### Configure privacy for Android Enterprise work profile+For more information about the Android Enterprise management modes that Defender for Endpoint supports, see [Supported Android enrollment scenarios](mtd.md#supported-android-enrollment-scenarios). -Defender for Endpoint supports vulnerability assessment of apps in the work profile. However, in case you want to turn off this feature for targeted users, you can use the following steps:+<a name="configure-privacy-for-android-enterprise-work-profile"></a> -1. In [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Apps** \> **App configuration policies** \\> **Add** > **Managed devices**.-1. Give the policy a name; **Platform \> Android Enterprise**; select the profile type.-1. Select **Microsoft Defender for Endpoint** as the target app.-1. In Settings page, select **Use configuration designer** and add **Enable TVM Privacy** as the key and value type as **Integer**+<a name="configure-app-inventory-privacy-for-an-android-enterprise-work-profile"></a> -- To disable vulnerability of apps in the work profile, enter value as `1` and assign this policy to users. By default, this value is set to `0`.- - For users with key set as `0`, Defender for Endpoint sends the list of apps from the work profile to the backend service for vulnerability assessment.+By default, Defender for Endpoint sends the list of apps in the work profile to Microsoft Defender Vulnerability Management for assessment. To prevent this app inventory from being sent for targeted users, use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy) with **Personally-Owned Work Profile Only** as the profile type. Add the following configuration key: -1. Select **Next** and assign this profile to targeted devices/users.+- **Enable TVM Privacy**:+ - **Value type**: Integer+ - **Configuration values**:+ - `0`: Send the work profile app inventory for vulnerability assessment (default).+ - `1`: Don't send the work profile app inventory for vulnerability assessment. -Turning the above privacy controls on or off won't affect the device compliance check or conditional access.+This privacy setting doesn't affect device compliance checks or Conditional Access. -## Configure privacy for phishing alert report+## Configure non-APK file scanning -Privacy control for phish report can be used to disable the collection of domain name or website information in the phish threat report. This setting gives organizations the flexibility to choose whether they want to collect the domain name when a malicious or phish website is detected and blocked by Defender for Endpoint.+In addition to scanning Android application packages (APK files), Defender for Endpoint on Android can scan non-APK files, such as documents, compressed archives, and scripts, that users download, receive, or store on the device. This capability extends malware protection to more file types. -### Configure privacy for phishing alert report on Android Enterprise work profile+Non-APK file scanning is supported on enrolled devices in the following management scenarios: -Use the following steps to turn on privacy for targeted users in the work profile:+- Personally owned devices with a work profile (BYOD)+- Corporate-owned devices with a work profile (COPE)+- Corporate-owned, fully managed devices (COBO) -1. In [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431) and go to **Apps** > **App configuration policies** > **Add** > **Managed devices**.-1. Give the policy a name, **Platform > Android Enterprise**, select the profile type.-1. Select **Microsoft Defender for Endpoint** as the target app.-1. In Settings page, select **Use configuration designer** and add **DefenderExcludeURLInReport** as the key and value type as **Integer**.+> [!NOTE]+> Defender for Endpoint respects Android profile boundaries. On a device with a work profile, Defender scans only files in the work profile. It can't access or scan files in the user's personal profile. - Enter **1 to enable privacy**. The default value is 0.+To enable non-APK file scanning, use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add the following configuration key: -1. Select **Next** and assign this profile to targeted devices/users.+- **\[Preview\] Enable non-APK file scan in Microsoft Defender**:+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Enable non-APK file scanning.+ - `0`: Disable non-APK file scanning (default). -Turning the above privacy controls on or off won't affect the device compliance check or conditional access.+To confirm the policy is applied, verify that **EnableNonAPKFileScan** is present and set to `1` on the target device. -## Configure privacy for malware threat report+When Defender for Endpoint detects malware in a non-APK file, the user receives a notification that the device is at risk, and an alert appears in the [Microsoft Defender portal](https://security.microsoft.com). Security teams investigate and remediate the threat by using the same malware alert experience as other Defender for Endpoint detections. -Privacy control for malware threat report can be used to disable the collection of app details (name and package information) from the malware threat report. This setting gives organizations the flexibility to choose whether they want to collect the app name when a malicious app is detected.+## Configure privacy for phishing alert report -### Configure privacy for malware alert report on Android Enterprise work profile+The privacy control for phishing reports can disable the collection of domain names and website information in phishing threat reports. Use this setting to choose whether Defender for Endpoint collects the domain name when it detects and blocks a malicious or phishing website. -Use the following steps to turn on privacy for targeted users in the work profile:+<a name="configure-privacy-for-phishing-alert-report-on-android-enterprise-work-profile"></a> -1. In [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431) and go to **Apps** > **App configuration policies** > **Add** > **Managed devices**.-1. Give the policy a name, **Platform > Android Enterprise**, select the profile type.-1. Select **Microsoft Defender for Endpoint** as the target app.-1. In Settings page, select **Use configuration designer** and add **DefenderExcludeAppInReport** as the key and value type as **Integer**+To turn on privacy for targeted users in the work profile, use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add the following configuration key: - Enter **1 to enable privacy**. The default value is 0.+- **DefenderExcludeURLInReport**:+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Enable privacy.+ - `0`: Disable privacy (default). -1. Select **Next** and assign this profile to targeted devices/users.+Turning this privacy control on or off doesn't affect the device compliance check or Conditional Access. -Using this privacy control won't affect the device compliance check or conditional access. For example, devices with a malicious app will always have a risk level of "Medium".+## Configure privacy for malware threat report -## Disable sign out+The privacy control for malware threat reports can disable the collection of app details, including name and package information, from malware threat reports. Use this setting to choose whether Defender for Endpoint collects the app name when it detects a malicious app. -Defender for Endpoint supports deployment without the sign out button in the app to prevent users from signing out of the Defender app. This is important to prevent users from tampering with the device.-Use the following steps to configure Disable out sign:+<a name="configure-privacy-for-malware-alert-report-on-android-enterprise-work-profile"></a> -1. In [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Apps** > **App configuration policies** > **Add** > **Managed devices**.-1. Give the policy a name, select **Platform > Android Enterprise**, and select the profile type.-1. Select **Microsoft Defender for Endpoint** as the target app.-1. In the Settings page, select **Use configuration designer** and add **Disable Sign Out** as the key and **Integer** as the value type.+To turn on privacy for targeted users in the work profile, use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add the following configuration key: - - By default, Disable Sign Out = 1 for Android Enterprise personally owned work profiles, fully managed, company owned personally enabled profiles.- - - Admins need to make Disable Sign Out = 0 to enable the sign out button in the app. Users are able to see the sign out button once the policy is pushed.+- **DefenderExcludeAppInReport**:+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Enable privacy.+ - `0`: Disable privacy (default). -1. Select **Next** and assign this profile to targeted devices and users.+Using this privacy control doesn't affect the device compliance check or Conditional Access. For example, devices with a malicious app always have a risk level of **Medium**. -<a name="device-tagging"></a>-## Configure device tagging+## Disable sign out++Defender for Endpoint supports deployment without the sign out button in the app. Hiding the button helps prevent users from tampering with the device. Use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add the following configuration key: -Defender for Endpoint on Android enables bulk tagging the mobile devices during onboarding by allowing the admins to set up tags via Intune. Admin can configure the device tags through Intune via configuration policies and push them to user's devices. Once the User installs and activates Defender, the client app passes the device tags to the Security Portal. The Device tags appear against the devices in the Device Inventory. +- **Disable Sign Out**:+ - **Value type**: Integer+ - **Configuration values**:+ - `1`: Hide the sign out button. This value is the default for Android Enterprise personally owned work profiles, fully managed devices, and corporate-owned devices with a work profile.+ - `0`: Show the sign out button. -Use the following steps to configure the Device tags:+<a name="device-tagging"></a>++## Configure device tagging -1. In [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Apps** > **App configuration policies** > **Add** > **Managed devices**.-1. Give the policy a name, select **Platform > Android Enterprise**, and select the profile type.-1. Select **Microsoft Defender for Endpoint** as the target app.-1. In Settings page, select Use configuration designer and add **DefenderDeviceTag** as the key and value type as **String**.+Defender for Endpoint on Android supports bulk tagging of mobile devices during onboarding. Security administrators configure device tags through Intune app configuration policies and deploy them to users' devices. After users install and activate Defender, the client app sends the device tags to the Microsoft Defender portal. The tags appear with the devices in the device inventory. - - Admin can assign a new tag by adding the key **DefenderDeviceTag** and setting a value for device tag.- - Admin can edit an existing tag by modifying the value of the key **DefenderDeviceTag**.- - Admin can delete an existing tag by removing the key **DefenderDeviceTag**.+To configure device tags, use the [Managed devices app configuration policy procedure](#create-a-managed-devices-app-configuration-policy), and add the following configuration key: -1. Select Next and assign this policy to targeted devices and users.+- **DefenderDeviceTag**:+ - **Value type**: String+ - **Configuration value**:+ - To assign a new tag, enter a value for the device tag.+ - To edit an existing tag, change the value.+ - To delete an existing tag, remove the configuration key from the policy. > [!NOTE]-> The Defender app needs to be opened for tags to be synced with Intune and passed to Security Portal. It might take up to 18 hours for tags to reflect in the portal.+> Users must open the Defender app before tags can sync with Intune and pass to the Microsoft Defender portal. Tags might take up to 18 hours to appear in the portal. <a name="related-articles"></a>+ ## Related content - [Overview of Microsoft Defender for Endpoint on Android](microsoft-defender-endpoint-android.md)-+- [Configure Dynamic Preview Rings for Microsoft Defender on mobile](mobile-dynamic-preview-rings-configure.md)+- [Android Mobile Threat Defense (MTD) Role for Microsoft Defender for Endpoint](android-mobile-threat-defense-role.md) - <a href="/intune/intune-service/protect/microsoft-defender-deploy-android" target="_blank" rel="noopener noreferrer">Microsoft Intune: Deploy and configure Microsoft Defender for Endpoint on Android</a>-- 