Behaviour Monitoring in Microsoft Defender for Endpoint is now available for macOS!
This powerful feature continuously tracks the behaviour of applications, daemons, and files across your devices. By analysing how these processes interact with the system, it can detect suspicious activities that might indicate the presence of malware or other malicious threats. Unlike traditional signature-based detection, behaviour monitoring is dynamic and does not rely on known threat patterns. Instead, it identifies unusual behaviours in real-time, allowing it to adapt and respond to new, evolving threats, including zero-day attacks and sophisticated malware variants.
Behaviour monitoring can be deployed via Intune, Jamf, or third-party MDM.
A few prerequisites for enabling behaviour monitoring on macOS:
Device must be onboarded to Microsoft Defender for Endpoint.
Preview features must be enabled in the Microsoft XDR portal (Microsoft Security).
Device must be on the Beta channel (formerly known as InsiderFast).
Minimal Defender version: Beta (Insiders-Fast) 101.24042.0002 or newer (app_version).
Real-Time Protection (RTP) must be enabled.
Cloud-delivered protection must be enabled.
Device must be explicitly enrolled into the preview.
Ready to level up your macOS security?
Check out this article for deployment steps:
BY:
José Lázaro Pinos,
Global Head of Consulting - VP,
Performanta
תגובות