Blog Post

Microsoft Defender Vulnerability Management Blog
2 MIN READ

Announcing general availability of vulnerability management support for Android and iOS

rachelpark's avatar
rachelpark
Brass Contributor
Jan 25, 2022

Update: 12/15/2022 -  Vulnerability assessment of apps on iOS devices is now generally available. To configure the feature, read the https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender-endpoint%2Fios-configure-features%3Fview%3Do365-21vianet%23configure-vulnerability-assessment-of-apps&data=05%7C01%7Cv-trusher%40microsoft.com%7C92785e832bf44d36033208da9ccd28c0%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637994702232635948%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=bAigvVXwhm%2BJoZXSLE79Bl0OtFU3C13ZJihgbLDPNgI%3D&reserved=0.

 

Today, we are excited to announce the general availability of threat and vulnerability management support for Android and iOS in Microsoft Defender for Endpoint Plan 2. With this new cross-platform coverage, threat and vulnerability management capabilities now support all major device platforms across the organization - spanning workstations, servers, and mobile devices. 

 

https://www.microsoft.com/security/business/threat-protection/threat-vulnerability-management in Microsoft Defender for Endpoint continuously monitors and identifies impacted devices, assesses associated risks in the environment, and provides intelligent prioritization and integrated workflows to seamlessly remediate vulnerabilities. Microsoft iterates on these features based on the latest information from the threat landscape. 

 

Vulnerability management support for Android and iOS is part of Microsoft Defender for Endpoint’s https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mtd?view=o365-worldwide, which enables customers to maintain a seamless and consistent experience across their device platforms.

 

Organizations now have access to the below vulnerability assessment capabilities:

Android:

  • Vulnerability assessment of Android OS versions of onboarded Android devices.
  • Vulnerability assessment of apps that are installed on onboarded Android devices.
  • Note about privacy related to apps from personal devices (BYOD):
    • For Android Enterprise with a work profile, apps installed only on the work profile will be supported.
    • For other BYOD modes, by default vulnerability assessment of apps will not be available. However, in device administrator mode, admins can explicitly enable this feature through Microsoft Endpoint Manager to get the list of apps installed on the device. Visit our https://aka.ms/mtdtvmdocs to learn more.

iOS:

  • Vulnerability assessment of iOS versions on onboarded iOS/iPadOS devices.
  • Vulnerability assessment of apps installed on iOS devices.
  • Note that Defender for Endpoint on iOS supports vulnerability assessments of apps only for enrolled (MDM) devices.
  • To enable this feature, admins can follow these steps ,
    • In https://go.microsoft.com/fwlink/?linkid=2109431, go to Endpoint Security > Microsoft Defender for Endpoint > Enable App sync for iOS/iPadOS devices.
  • Additional steps needed for unsupervised devices,
    • To get the list of all the Apps, admin needs to Enable the toggle for “Send full application inventory data” in  https://go.microsoft.com/fwlink/?linkid=2109431
    • Admin needs to disable privacy and collect the list of apps installed. By default, privacy is enabled.
    • End Users will have to accept the privacy approval screen on their devices.
  • To configure the feature, read the https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender-endpoint%2Fios-configure-features%3Fview%3Do365-21vianet%23configure-vulnerability-assessment-of-apps&data=05%7C01%7Cmuktaagarwal%40microsoft.com%7C7e2d6b5fe82f431df76508daddfcd531%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638066375304944955%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ejegYGJdjIHJkwuEiwbnAhrKqCEmQS248%2B5%2FmAjScsU%3D&reserved=0.

 

Get started onboarding mobile devices to Microsoft Defender for Endpoint https://aka.ms/mtd.

 

Figure 1 Device Inventory - admins can check exposure level of onboarded mobile devices

 

Figure 2 Vulnerability management dashboard - access insights across devices

Updated Dec 14, 2022
Version 5.0

5 Comments