Defender for Endpoint intune

Configure Network Protection for Defender for Endpoint for Android and iOS Devices

Overview As part of its Defender for Endpoint (MDE) enterprise endpoint security platform, Microsoft recently announced that the Mobile Network Protection functionality is generally available to assist organizations in identifying network vulnerabilities affecting Android and iOS devices. As soon as the device is onboarded to MDE and network protection is

5 min read
Configure Network Protection for Defender for Endpoint for Android and iOS Devices

Overview

As part of its Defender for Endpoint (MDE) enterprise endpoint security platform, Microsoft recently announced that the Mobile Network Protection functionality is generally available to assist organizations in identifying network vulnerabilities affecting Android and iOS devices.

As soon as the device is onboarded to MDE and network protection is enabled, MDE will provide protection and alerts for all network-related suspicious events and activities. Let’s configure these features and see how the network protection works.


Network Safety

The way companies operate has seen a significant transformation in recent years as a result of people working from home or using a hybrid work style. Users are now more dependent on network connections for personal and professional obligations, which expose users & their devices to new security dangers—as such, protecting the data becomes the utmost priority for organizations.

With the addition of network safety capabilities to MDE for mobile devices, you can now protect your enrolled and unenrolled devices from all network attacks. These features include:


Configure MDE Network Protection Features for iOS Supervised Devices

Network protection in Microsoft Defender for Endpoint is disabled by default. You must follow these steps to configure Network protection in iOS devices. (Authenticator device registration is required for MAM configuration) in iOS devices. Network Protection initialization will require the end user to open the app once.

Img: Create policy for managed apps
Create a policy for managed app
.
Select Defender as a public app
Configuration keys for network protection
Configuration policy

Configure MDE Network Protection Features for Android Enterprise Device

Create a policy for managed devices
Configure device platform
Configuration keys for network protection

If you push your enterprise CA certificate to your devices then make sure that you use ‘Trusted CA certificate list for Network Protection’ as the key and in value add the ‘comma separated list of certificate thumbprints (SHA 1)’ to establish trust for the root CA(s).

Configuration profile

MDE App Permissions On The Device

iOS

Android


Network Protection in Action

By this point, all of the policies have been set up, and users have also logged into the MDE app. The device will be onboarded in Microsoft Defender for Endpoint and visible in the Defender admin console a few minutes after launching the app.

Now, to simulate a network attack, I have not trusted the enterprise root certificate for Android devices. This means that as soon as the MDE policy sync is completed, an alert for a suspicious certificate should be generated, and the device should be reported.

And voila! It’s immediate and works!

Device in defender admin center
Alert classification

Wrapping Up

As the world continues to make sense of digital transformation, the mobile network protection feature in Defender for Endpoint will help us to identify, assess, and remediate endpoint weaknesses with the help of robust threat intelligence.

And with this new cross-platform coverage, threat and vulnerability management capabilities now support all major device platforms.

It is recommended that you should configure alerts in Defender for this network protection.

I’d love to know what you think, so do leave your comments below, and if you liked it, then do share it.

Cheers/

Somesh

Ref:

Announcing the public preview of Mobile Network Protection for Microsoft Defender on Android and iOS

Configure Microsoft Defender for Endpoint on iOS features | Microsoft Learn

Share This Post

Check out these related posts

Defender for Endpoint: Some Essential Queries That You Must Use Right Now!