Microsoft Defender for Endpoint
Endpoint protection

Mac Support Perf Overview

In brief

The performance overview now directly links to real-time protection statistics guidance for identifying files and processes that trigger scans.

What Defender admins need to know

Administrators investigating scan-related performance can access the troubleshooting guidance directly.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Daemon name Component First troubleshooting step
wdavdaemon Core (privileged) Collect Client Analyzer performance data and hot event sources.
wdavdaemon_unprivileged Antivirus and endpoint protection platform (EPP) Use real-time protection statisticsreal-time protection statistics to identify files and processes that trigger scans.
wdavdaemon_enterprise Endpoint detection and response (EDR) Collect Client Analyzer performance data and hot event sources.

For all three processes, record the process name, CPU and memory use, duration, device model and processor, Defender version, macOS version, enforcement mode, workload, and other security products. Gather Microsoft Defender for Endpoint Client Analyzer files while the issue occurs.