Microsoft Defender for Endpoint
Endpoint protection

Configure Microsoft Defender for Endpoint on Android risk signals using App Protection Policies (MAM)

In brief

The documentation now describes scanning documents, archives, and scripts in addition to APKs, with Intune Managed apps configuration steps. It also clarifies support for enrolled and unenrolled devices.

What Defender admins need to know

Administrators can enable broader file scanning through an app configuration policy; scanning respects Android work and personal profile boundaries.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Microsoft Defender for Endpoint on Android risk signals using App Protection Policies (MAM)

Microsoft Defender for Endpoint on Android, which already protects enterprise users on Mobile Device Management (MDM) scenarios, now extends support to Mobile App Management (MAM), for devices that aren't enrolled using Intune mobile device management (MDM). It also extends thisMAM support to customers who use other enterprise mobility management solutions, while still using Intune for mobile application management (MAM). Microsoft Defender for Endpoint support for MAM allows you to manage and protect your organization's data within an application.

Microsoft Defender for Endpoint on Android threat information is applied by Intune App Protection Policies to protect these apps. App protection policies (APP) are rules that ensure an organization's data remains safe or contained in a managed app. A managed application has app protection policies applied to it and can be managed by Intune.

Microsoft Defender for Endpoint on Android supports both the configurations of MAM.MAM configurations: Intune MDM + MAM and MAM without device enrollment.

  • Intune MDM + MAM: IT administrators can only manage apps using App Protection Policies on devices that are enrolled with Intune mobile device management (MDM).
  • MAM without device enrollment: MAM without device enrollment, or MAM-WE, allows IT administrators to manage apps using App Protection Policies on devices not enrolled with Intune MDM. MAM without device enrollment means that apps can be managed by Intune on devices enrolled with third-party EMM providers. End users also need to take steps to install Microsoft Defender for Endpoint on their device and activate the onboarding flow.

Administrator prerequisites

Before you begin, complete the following configuration steps to connect Microsoft Defender for Endpoint with Intune and create app protection policies.

  1. Go to security.microsoft.com.

  2. Select Settings > Endpoints > Advanced Features > Microsoft Intune Connection is turned on.

  3. If the connection isn't turned on, select the toggle to turn it on and then select Save Preferences.

    Use this option to specify whether this policy applies to unmanaged devices. In Android, you can specify the policy applies to Android Enterprise, Device Admin, or Unmanaged devices. You can also choose to target your policy to apps on devices of any management state.

    Because mobile app managementMAM without device enrollment doesn't require device management, youorganizations can protect company data on both managed and unmanaged devices. The management is centered on the user identity, which removes the requirement for device management. Companies can use app protection policies with or without MDM at the same time. For example, consider an employee that uses both a phone issued by the company, and their own personal tablet. The company phone is enrolled in MDM and protected by app protection policies while the personal device is protected by app protection policies only.

    1. Select Apps.
  • Users have the required licenses for the managed app and have the app installed.

End-user onboarding

  1. Install the Microsoft Defender: Antivirus (Mobile) app and go back to the managed app onboarding screen.

    a. :::image type="content" source="media/mam-flow.png" alt-text="Shows the procedure of downloading Microsoft Defender: Antivirus (Mobile) app." lightbox="media/mam-flow.png":::

  2. Click Continue > Launch. The Microsoft Defender for Endpoint app onboarding/activation flow is initiated. Follow the steps to complete onboarding. You'll automatically be redirected back to Managed app onboarding screen, which now indicates that the device is healthy.

  3. Select Continue to log into the managed application.

    • antiphishing
    • vpn

    To disable web protection, enter 0 for the antiphishing and VPN values.

    To disable only the use of VPN by web protection, enter these values:

    • 0 for vpn
    • 1 for antiphishing

    Add the DefenderMAMConfigs key and set the value as 1. By default, this key is not set; in this case, the system applies the default values for all capability configurations.

  4. Assign this policy to users.

  5. Review and create the policy.

  6. Include or exclude the groups you want the policy to apply to. Proceed to review and submit the policy.

  1. Assign this policy to users. By default, this value is set to false.
  2. Review and create the policy.

Configure non-APK file scanning

Beyond scanning Android application packages (APK files), Defender for Endpoint on Android can scan non-APK files, such as documents, compressed archives, and scripts. Defender for Endpoint respects Android profile boundaries and can't access files in the user's personal profile.

To enable non-APK file scanning, create a Managed apps app configuration policy. For the full procedure, see Add an app configuration policy for managed apps (opens in a new tab in the Intune documentation). When you create the policy, use these settings:

  • Basics tab: Configure the following settings
    • Target policy to: Verify Selected apps is selected.
    • Public apps: Select Select public apps, find and select Microsoft Defender Endpoint Android, and then select Select.
  • Settings tab: Configure the following settings in the General configuration settings section:
    • Name: Enter EnableNonAPKFileScan. Value: Enter 1.
    • Name: Enter DefenderMAMConfigs. Value: Enter 1.

Optional permissions

Microsoft Defender for Endpoint on Android enables Optional Permissions in the onboarding flow. Currently the permissions required by MDE are mandatory in the onboarding flow. With this feature, admin can deploy MDE on Android devices with MAM policies without enforcing the mandatory VPN and Accessibility Permissions during onboarding. End Users can onboard the app without the mandatory permissions and can later review these permissions.

  1. Select Next and assign this profile to targeted devices/users.

User flow for optional permissions during onboarding

Users can install and open the app to start the onboarding process.

Disable sign out

Defender for Endpoint allows you to deploy the app and disabling the sign out button. By hiding the sign out button, users are prevented from signing out of the Defender app. Hiding the sign-out button helps prevent tampering with the device when Defender for Endpoint isn't running.

Use the following steps to configure the Disable sign out:

  1. Provide the policy a name.
  2. Under Select Public Apps, choose Microsoft Defender for Endpoint as the target app.
  3. In the Settings page, under the General Configuration Settings, add DisableSignOut as the key and set the value as 1.
    • By default, Disable Sign Out = 0.
    • Admin needs to make Disable Sign Out = 1 to disable the sign-out button in the app. Users will not see the sign out button once the policy is pushed to the device.
  4. Select Next and assign this profile to targeted devices and users.

Configure device tagging

Defender for Endpoint on Android enables bulk tagging the mobile devices during onboarding by allowing the admins to set up tags via Intune. Admin can configure the device tags through Intune via configuration policies and push them to user's devices. Once the User installs and activates Defender, the client app passes the device tags to the Security Portal. The Device tags appear against the devices in the Device Inventory.

Disable end-user onboarding

Defender for Endpoint on Android is enabled by default in MAM mode. To prevent end users from downloading and setting up Defender on unenrolled devices, the DefenderMAMConfigs key can be set to 0 to block onboarding. Use the following steps to disable onboarding:

  1. Click Next and assign this policy to targeted devices and users.

Related content