Checklist
Onboarding macOS to Defender for Endpoint with Intune: profiles, app and onboarding package
Based on the article: Onboarding macOS to Defender for Endpoint with Intune: profiles, app and onboarding package · 5 min read
Onboarding a Mac to Defender for Endpoint is less about installing an app and more about getting macOS to trust it: system extensions, Full Disk Access, a network filter and background execution all need pre-approval, or users see prompts and the sensor runs half-blind. In this post I'll walk through the Intune deployment in the order Microsoft documents it, how to prove each piece landed, and what to do when it doesn't.
Before you start
- Licensing: Defender for Endpoint Plan 1 or Plan 2, or Defender for Business, plus Intune. Set up the Intune connection to Defender (Tenant administration › Connectors and tokens › Microsoft Defender for Endpoint in Intune, and the Microsoft Intune connection toggle under Settings › Endpoints › General › Advanced features in the Defender portal) if you want macOS compliance signals and the Defender portal policy option.
- macOS versions: Microsoft supports the three most recent major releases. At the time of writing the prerequisites page lists macOS 27, 26 (Tahoe) and 15 (Sequoia); betas aren't supported, and new major versions are supported from release day. Re-check the list before a rollout, because it rolls forward every autumn.
- Hardware: Intel 64-bit or Apple silicon, 1 GB of free disk space, and System Integrity Protection left on.
- Network: direct, PAC, WPAD or static-proxy access to the Defender service URLs. Authenticated proxies and TLS inspection aren't supported.
- Enrollment: Macs enrolled in Intune through Company Portal or Automated Device Enrollment, because every profile below deploys on the device channel.
Checklist
Deploy the configuration profiles first, then the app, then the onboarding package. Microsoft calls out this order explicitly; reversing it is how you end up with permission prompts and unlicensed sensors.
- 1
Approve the system extensions (settings catalog)
In the Microsoft Intune admin center, go to Devices › Configuration › Create › New policy, platform macOS, profile type Settings catalog. Under System configuration › System extensions add:
- Allowed System Extensions:
com.microsoft.wdav.epsextandcom.microsoft.wdav.netext, team identifierUBF8T346G9. - Allowed System Extension Types: Network and EndpointSecurity, same team identifier.
- Allowed System Extensions:
- 2
Deploy the permission profiles (custom templates)
Each of the following is a macOS Templates › Custom profile with Deployment channel set to Device channel, uploading a .mobileconfig file from Microsoft's Defender for Endpoint macOS configuration profile repository on GitHub:
Profile Sample file What it does Network filter netfilter.mobileconfigLets the network extension inspect traffic for EDR, network protection and web content filtering. Deploy exactly one network filter profile; several cause connectivity problems. Full Disk Access fulldisk.mobileconfigGrants Full Disk Access to Defender, the Endpoint Security extension and the DLP daemon, and stops users revoking it. Background services background_services.mobileconfigRequired from macOS 13 so Defender's processes may run in the background. Notifications notif.mobileconfigAllows Defender and Microsoft AutoUpdate to notify; set ShowInNotificationCenterto false to hide them.Microsoft AutoUpdate com.microsoft.autoupdate2.mobileconfigPins the update channel (Current, Preview or Beta). The sample is set to Current. Accessibility, Bluetooth accessibility.mobileconfig,bluetooth.mobileconfigOptional: needed for Endpoint DLP and for Bluetooth-based device control. - 3
Configure Defender's own settings
Choose one of two routes. Either create endpoint security policies for macOS using the Microsoft Defender Antivirus and Endpoint detection and response templates (from the Endpoint security policies page in the Defender portal, or from Endpoint security in Intune), or deploy a custom profile containing Microsoft's recommended
com.microsoft.wdav.xml. - 4
Publish the app
Go to Apps › All apps › Create and, under Microsoft Defender for Endpoint, select macOS. This built-in app type installs Microsoft Defender together with Microsoft AutoUpdate, which then keeps it current on the channel you pinned.
- 5
Deploy the onboarding package
In the Defender portal, open Settings › Endpoints › Device management › Onboarding, select macOS, keep Streamlined connectivity, choose Mobile Device Management / Microsoft Intune and download the package. Unzip it, take
intune/WindowsDefenderATPOnboarding.xmland deploy it as another custom profile on the device channel.
Verify
- Intune: each profile's Device and user check-in status report shows Succeeded, and the app shows Installed.
- On the Mac: System Settings › General › Device Management lists the profiles including the onboarding profile, and the Defender shield appears in the menu bar. Full Disk Access granted by MDM is not shown under Privacy & Security, so don't look for it there.
- Terminal:
mdatp health --field healthy
mdatp health --field licensed
mdatp health --field org_id
mdatp health --field real_time_protection_enabled
mdatp connectivity test
systemextensionsctl listYou want healthy and licensed true, your organisation ID populated, real-time protection enabled, every connectivity test passing, and both Microsoft extensions listed as activated and enabled.
Tips & gotchas
- "No license found" or an empty org_id: the onboarding profile hasn't applied. Check its assignment and that you uploaded the Intune XML, not the Jamf plist from the same package.
- Extensions not approved: the user sees a system extension prompt, or
systemextensionsctl listshows them waiting for approval. Verify the settings catalog profile includes both bundle IDs and the team identifier, and that it reached the device before the app did. - Full Disk Access missing: real-time protection reports problems and scans skip files. Make sure the FDA profile is on the device channel and assigned to the device group, not only to users.
- Network trouble after deployment: look for a second network filter profile from another product.
- Logs:
/Library/Logs/Microsoft/mdatp/install.logfor install failures;sudo mdatp diagnostic createbundles diagnostics for support;mdatp health --details tamper_protectionshows the effective tamper protection mode and its source.
+1 more tips in the full article.