Microsoft Defender for Endpoint
Troubleshooting

Mac Troubleshoot Mode

In brief

The page received updated metadata and date information, and its troubleshooting-mode operation headings were rewritten for clarity.

What Defender admins need to know

Administrators can use the clearer headings when consulting the troubleshooting-mode guide; no action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • mde-macos ms.topic: troubleshooting-general ms.subservice: macos search.appverid: met150 ms.date: 12/15/202507/28/2026 appliesto:
    • Microsoft Defender for Endpoint Plan 1
    • Microsoft Defender for Endpoint Plan 2

What do you need to know before you begin

During the troubleshooting mode, you can:can perform the following operations:

  • Use Microsoft Defender for Endpoint on macOS functional troubleshooting /application compatibility (false positives).
  • Local admins, with appropriate permissions, can change the following policy locked configurations on individual endpoints: |groupIds|mdatp edr group-ids --group-id [group]|| |Endpoint DLP|mdatp config data_loss_prevention --value enabled|mdatp config data_loss_prevention --value disabled|

During troubleshooting mode, you can't:t perform the following operations:

  • Disable tamper protection for Microsoft Defender for Endpoint on macOS.
  • Uninstall the Microsoft Defender for Endpoint on macOS.