Forum Discussion
bjork6
Aug 24, 2021Copper Contributor
problems with MS Defender for Endpoint on iOS device
Hi. We recently deployed MS Defender for Endpoint on all our iOS devices through Intune. However, since then, people are complaining their internet browsing experience is not good. It's slow, some si...
MarkTheITGuy
Oct 26, 2021Copper Contributor
Thanks for the reply rickside - It makes sense what you're saying. The downside is that if we remove the policy, and leave the outbound traffic un-inspected, would that then mean that malicious links clicked from emails, that redirect to a malicious site, would then be allowed to load as normal?
We've had a few incidents recently, where unaware users, clicked links in email, and also a couple from website popups, that were blocked by ATP so the user was protected.
Just thinking if we turn it off, would these users (and there will be more) fall pray to these links?
Thanks again, mate.
We've had a few incidents recently, where unaware users, clicked links in email, and also a couple from website popups, that were blocked by ATP so the user was protected.
Just thinking if we turn it off, would these users (and there will be more) fall pray to these links?
Thanks again, mate.
rickside
Oct 26, 2021Copper Contributor
From what I understand, ATP will still do its job (meaning it will block malicious websites that it already knows) but you are correct, it will not analyze outbound traffic on the fly. Unless Microsoft provides a better way to do this, I am afraid you'll just have to live with it or search for another product/solution. I am not a big fan of the way the traffic inspection works on iOS (i.e. VPN-THAT-POINTS-TO-LOCAL-LOOPBACK) but it seems that's the way they decided to go.
- sunayanasinghOct 27, 2021
Microsoft
rickside MarkTheITGuy , Currently there is a known issue with the content profile (script that you deploy from Intune) which is causing internet connectivity problems. We are looking into this issue. Meanwhile, you can un-deploy this profile to help resolve the internet connectivity problems. Please find more details here.
Also, even without the profile, Defender for Endpoint will still protect you from phishing in real-time leveraging the VPN capabilities. Hope this helps. Please revert back for further questions.
- MarkTheITGuyOct 27, 2021Copper Contributorsunayanasingh Thanks for the update. Out of curiosity, any ETA currently for the updated profile to be released?
- MarkTheITGuyOct 27, 2021Copper Contributor
@sunayansingh Awesome. Thank You.