Microsoft Defender for Endpoint
Endpoint protection

Ios Configure Features

In brief

The article clarifies local VPN behavior, open-network alert changes, privacy controls, jailbreak compliance, sign-out settings, and device tagging. It also separates instructions for enrolled and unenrolled devices and improves section headings and links.

What Defender admins need to know

Administrators get clearer guidance for iOS, BYOD, VPN, compliance, sign-out, and device-tag configurations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Defender for Endpoint on iOS uses a VPN in order to provide web protection. The VPN is local, and unlike traditional VPN, network traffic isn't sent outside the device.

While the Defender for Endpoint local VPN is enabled by default, there might be some cases that require you to disable VPN.it. For example, if you wantneed to run some apps that don't work when a VPN is configured. In such cases,configured, you can choose to disable VPN from the appDefender for Endpoint VPN on the device by following these steps:

  1. On your iOS device, open the Settings app, select General and then VPN.

Disable web protection

Web protection is one of the key features of Defender for Endpoint and it requires a VPN to provide web protection. The VPN used is a local/loopback VPN and not a traditional VPN, however there are several reasons for which customers might not prefer the VPN. If you don't want to set up a VPN, you can disable web protection and deploy Defender for Endpoint without that feature.web protection. Other Defender for Endpoint features continues to work.

The web protection configuration is available for both enrolled (MDM) devices and unenrolled (MAM) devices. For customers with MDM, admins can configure web protection through managed devices in the App Config. For customers without enrollment, using MAM, admins can configure the web protection through managed apps in the App Config.

  1. Review and create the configuration policy.

Understand coexistence of multiple VPN profiles on iOS

Apple iOS doesn't support multiple device-wide VPNs to be active simultaneously. While multiple VPN profiles can exist on the device, only one VPN can be active at a time.

Configure end-user privacy controls in the Microsoft Defender app

The end-user privacy controls in the Microsoft Defender app help the end user configure the information shared to their organization.

For supervised devices, end-user controls aren't visible. Your admin decides and controls the settings. However, for unsupervised devices, the control is displayed under the Settings > Privacy.

Optional permissions

Microsoft Defender for Endpoint on iOS enables optional permissions in the onboarding flow. Currently the permissions required by Defender for Endpoint are mandatory in the onboarding flow. With optional VPN permissions, admins can deploy Defender for Endpoint on BYOD devices without enforcing the mandatory VPN permission during onboarding. End users can onboard the app without the mandatory permissions and can later review these permissions. This feature is currently present only for enrolled devices (MDM).

Configure optional permissions using MDM

Jailbreak detection

Microsoft Defender for Endpoint has the capability of detecting unmanaged and managed devices that are jailbroken. These jailbreak checks are done periodically. If a device is detected as jailbroken, the following actions occur:

  • A high-risk alert is reported to the Microsoft Defender portal. If device Compliance and Conditional Access are set up based on device risk score, then the device is blocked from accessing corporate data.
  • User data on app is cleared. When user opens the app after jailbreaking, the VPN profile (only Defender for Endpoint loopback VPN Profile) also is deleted, and no web protection is offered. VPN profiles delivered by Intune aren't removed.

To create a compliance policy against jailbroken devices, follow these steps:

  1. In the Microsoft Intune admin center, go to Devices > Compliance policies > Create Policy. Select "iOS/iPadOS" as platform and select Create.

Configure disable sign out using MDM

Use the following steps to disable sign out for enrolled devices.

For enrolled devices (MDM)

  1. In the Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

Configure disable sign out using MAM

Use the following steps to disable sign out for unenrolled devices.

For unenrolled devices (MAM)

  1. In the Microsoft Intune admin center, navigate to Apps > App configuration policies > Add > Managed apps.

  2. Select Next, and then assign this policy to targeted devices/users.

Device taggingConfigure device tags on iOS

Defender for Endpoint on iOS enables bulk tagging the mobile devices during onboarding by allowing the admins to set up tags via Intune. Admin can configure the device tags through Intune via configuration policies and push them to user's devices. Once the User installs and activates Defender, the client app passes the device tags to the Microsoft Defender portal. The Device tags appear against the devices in the Device Inventory.

Configure device tags using MDM

Use the following steps to configure device tags for enrolled devices.

For enrolled devices (MDM)

  1. In the Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

Configure device tags using MAM

Use the following steps to configure device tags for unenrolled devices.

For unenrolled devices (MAM)

  1. In the Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed apps.

Suppress OS update notifications

A configuration is available for customers to suppress OS update notification in Defender for Endpoint on iOS. Once the config key is set in the Intune App configuration policies, Defender for Endpoint won't send any notifications on the device for OS updates. However, when you open the Microsoft Defender app, the Device Health card is visible and show the state of your OS.

The OS update notification suppression configuration is available for both enrolled (MDM) devices and unenrolled (MAM) devices. Admins can use the following steps to suppress OS update notifications.

Configure OS update notifications using MDM

For enrolled devices (MDM)

  1. In the Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

Configure OS update notifications using MAM

For unenrolled devices (MAM)

  1. In the Microsoft Intune admin center, navigate to Apps > App configuration policies > Add > Managed apps.

Phishing websites impersonate trustworthy websites by obtaining your personal or financial information. Visit the Provide feedback about network protection

A configuration is available for customers to suppress OS update notification in Defender for Endpoint on iOS. Once the config key is set in the Intune App configuration policies, Defender for Endpoint won't send any notifications on the device for OS updates. However, when you open the Microsoft Defender app, the Device Health card is visible and show the state of your OS.

The OS update notification suppression configuration is available for both enrolled (MDM) devices and unenrolled (MAM) devices. Admins can use the following steps to suppress OS update notifications.

Configure OS update notifications using MDM

Use the following steps to suppress OS update notifications for enrolled devices.

For enrolled devices (MDM)

  1. In the Microsoft Intune admin center, go to Apps > App configuration policies > Add > Managed devices.

Configure OS update notifications using MAM

Use the following steps to suppress OS update notifications for unenrolled devices.

For unenrolled devices (MAM)

  1. In the Microsoft Intune admin center, navigate to Apps > App configuration policies > Add > Managed apps.

Phishing websites impersonate trustworthy websites by obtaining your personal or financial information. Visit the Provide feedback about network protection page to report a website that could be a phishing site.

Related content