Microsoft Defender for Endpoint
Endpoint protection

Network Protection Macos

In brief

The network protection for macOS page now links to the updated Microsoft Defender SmartScreen documentation URL.

What Defender admins need to know

Administrators can use the updated link when reviewing SmartScreen behavior; no configuration change is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • exploits
  • other malicious content on the Internet

Network protection expands the scope of Microsoft Defender SmartScreenSmartScreen to block all outbound HTTP/HTTPS traffic that attempts to connect to low-reputation sources across all major browsers. Blocks on outbound HTTP/HTTPS traffic are based on the domain or hostname.

In non-Microsoft Edge processes, Network Protection determines the fully qualified domain name for each HTTPS connection by examining the content of the TLS handshake that occurs after a TCP/IP handshake. This requires that the HTTPS connection use TCP/IP (not UDP/QUIC) and that the ClientHello message not be encrypted. To disable QUIC and Encrypted Client Hello in Google Chrome, see QuicAllowed and EncryptedClientHelloEnabled. For Mozilla Firefox, see Disable EncryptedClientHello and network.http.http3.enable.