ios MDE Microsoft Defender for Endpoint Security

Zero Touch Onboarding & Activation of Microsoft Defender for Endpoint

Overview You can now configure your iOS devices to be silently onboarded and activated on Microsoft Defender for Endpoint without requiring interaction from the end user. In this flow, you will create a few configuration profiles, and the user will be notified of the installation. Defender for Endpoint is automatically

6 min read
Zero Touch Onboarding & Activation of Microsoft Defender for Endpoint

Overview

You can now configure your iOS devices to be silently onboarded and activated on Microsoft Defender for Endpoint without requiring interaction from the end user. In this flow, you will create a few configuration profiles, and the user will be notified of the installation. Defender for Endpoint is automatically installed and activated without the user needing to open the app. Follow the steps below to set up zero-touch or silent deployment and activation of Defender for Endpoint on enrolled iOS devices:


Pre-requisites


Deploy the App

You have two options for deploying MDE app to your user’s devices:

  1. App Store App
  2. VPP App

Deploy Defender as App Store App

Select the app as public store app
app info

Deploy Defender as VPP App (Recommended way)

Add app in ABM

Availability of app licenses depends on the amount purchased. If you purchased:

  • 5000 licenses or fewer, they are immediately processed
  • 5001 to 19,999 licenses, they are processed daily after 1:00 p.m., Pacific time
  • 20,000 licenses or more, they are processed daily after 4:00 p.m., Pacific time

Configure Supervised Mode via Intune

For configuring the supervised mode for Defender for Endpoint app, we would need an app configuration policy and device configuration profile. Follow the below steps to configure them:

App Configuration Policy

App configuration policy
add the app

Device Configuration Profile

This profile is for enabling enhanced Anti-phishing capabilities. Follow the steps below:


Zero-touch Onboarding & Activation

The configurations for the custom vpn profile are case sensitive. Any slight mistake will disable auto-activation of MDE.


End User Experience

The VPN configuration profile is pushed to the device as soon as the device is enrolled. Until Microsoft Defender is installed and activated on the device, the connection is just a self-loop.

You will see the blue dot on the MDE app icon within a few minutes and a notification in the device’s notification center that the device has been successfully onboarded to MDE.

Device silently onboarded

Tap the Defender for Endpoint app icon (MSDefender), and you will notice that the app is activated with web protection auto-enabled.


Wrapping-Up

When looking from the end-user perspective, the experience is super cool. No interaction is required, as the onboarding and activation are 100% silent.

At the same time, from the administrator’s perspective, these features give you complete visibility of the device’s security, and the ease of onboarding devices is also what we have been looking forward from many years. I hope that Android Enterprise will also have the same experience soon.

Ref:

App-based deployment for Microsoft Defender for Endpoint on iOS | Microsoft Learn


Share This Post

Check out these related posts

iOS Alternative App Stores? Not on My Supervised Devices!

Uncover the Secrets of AppleSeed: Part III - Mastering the Tools

Uncover the Secrets of AppleSeed: Part II - Exploring the Tools