Blog Post

Microsoft Defender for Endpoint Blog
3 MIN READ

Microsoft Defender ATP for Mac is moving to system extensions

Helen_Allas's avatar
Helen_Allas
Icon for Microsoft rankMicrosoft
Aug 31, 2020

As part of our commitment to provide the best in market endpoint protection to our customers, we strive to ensure that Microsoft Defender ATP for Mac evolves in lock step with the macOS platform. We are also committed to minimizing security agent related friction as organizations migrate to the next major macOS version. Apple is shifting away from kernel extensions, starting with macOS 11 Big Sur. In alignment with Apple’s strategy, public preview is now open for Microsoft Defender ATP for Mac implementation that leverages the new system extensions instead of kernel extensions.

 

 

 

How will the system extensions-based update be delivered?

 

The system extensions-based version of Microsoft Defender ATP for Mac will be delivered to all macOS devices via the existing Microsoft AutoUpdate (MAU) channel.

 

Refer to our system extensions-based update documentation for additional update related details and how to determine if a device is running the new version based on system extensions.

 

After successfully deploying and activating the update, the on-device experience will remain unchanged.

 

What devices are eligible for the system extensions-based update?

 

To experience the new system extensions-based implementation during public preview, you’ll need to have preview features turned on in the Microsoft Defender Security Center. If you have not yet opted into previews, we encourage you to turn on preview features in the Microsoft Defender Security Center today.

 

Prior to the general availability of macOS 11 Big Sur, the new system extensions-based code path can be activated on devices running macOS Catalina version 10.15.4 or later and registered for the InsiderFast MAU update channel.

Once macOS 11 Big Sur is generally available, the new system extensions-based implementation will be activated on all devices running macOS 11.

 

How to prepare for activation of the system extensions-based update

 

To ensure that the Microsoft Defender ATP for Mac system extensions-based update is delivered and applied seamlessly from an end-user experience perspective, a new remote configuration must be deployed to all eligible macOS devices before the new code path is activated. If the configuration is not deployed prior to the activation of the new Microsoft Defender ATP for Mac agent implementation, end-users will be presented with a series of system dialogs asking to grant the agent all necessary permissions associated with the new system extensions. Refer to our system extensions-based update documentation to learn in detail what to expect without applying the new remote configuration.

 

Benefits of taking action ahead of broader update applicability

 

The new Microsoft Defender ATP for Mac system extension-based implementation is currently only applicable to devices running macOS version 10.15.4 or later and in InsiderFast MAU ring. However, deploying configuration proactively across the entire macOS fleet ensures that all Mac devices are prepared for macOS 11 Big Sur on its release day. It also ensures that Microsoft Defender ATP for Mac continues protecting all macOS devices immediately post-upgrade to Big Sur. The new remote configuration is supplemental to any prior Microsoft Defender ATP for Mac configuration and will have no adverse effect on devices that still run the kernel extension-based version.

 

 

We invite you to monitor the What's new in Microsoft Defender ATP for Mac page for upcoming announcements (including general availability of the system extensions-based update). 

 

We welcome your feedback and look forward to hearing from you!

You can submit feedback by opening Microsoft Defender ATP for Mac on your device and navigating to Help > Send feedback. Another option is to submit feedback via the Microsoft Defender Security Center.

 

If you’re not yet taking advantage of Microsoft’s industry leading optics and detection capabilities, sign up for free trial of Microsoft Defender ATP today. 

 

 

Helen Allas

Microsoft Defender ATP team

Updated Nov 06, 2020
Version 9.0
  • MarcVChicago's avatar
    MarcVChicago
    Copper Contributor

    Hi!

    Tomer_Hevlin , Just to confirm what do you mean M1 is not supported for now? If our organization currently has M1 Macs can they not run MDATP until M1 native support is available? 

    Thanks!

    Marc V

  • Yes, We are currently work on M1 native support. it will be ready soon. For now, M1 is not supported.

    We will update with a blog post here once it will be supported.

  • jsesslerscr's avatar
    jsesslerscr
    Copper Contributor

    Will you be releasing a Apple M1 native version of ATP, and if so when?  Are there any words of caution for installing the current Intel version on an M1, or does it install at all?

     

  • Syswpit's avatar
    Syswpit
    Brass Contributor

    Hello,

     

    Is there any update on M1 support?

    The WDAV-KEXT profile we normally use for MacOS/Big Sur is giving an error (-2016336102 (No error code)), so I assume it's still not supported?

    Thanks.

  • textral's avatar
    textral
    Copper Contributor

    Also looking for an update on M1 - We've got a large Mac fleet looking to move from Sophos to Microsoft ATP; this is a showstopper for us.

  • Paul Mitchell's avatar
    Paul Mitchell
    Brass Contributor

    Same question here, we don't have a large Mac fleet, just a small subset including our CEO!!

  • francklf's avatar
    francklf
    Copper Contributor

    Hi everybody,

    Tomer_Hevlin do you have any information when MDATP will support M1 ?

    We have to prepare our new deployment and M1 have been ordered :cool:

    Thanks you 

  • jgramke's avatar
    jgramke
    Copper Contributor

    Looking to move from Symantec to MDE/MSATP, only to find it doesn't' work on the new macs we have for this summer.    Big black eye.  New updates seem few and far between.

     

  • MichelLisman's avatar
    MichelLisman
    Copper Contributor

    Is there any news on an ETA? Looking to move our Macs into the Defender ecosystem, but we cannot as long as M1 hardware / system extensions are not there.

    You can run MDATP through Rosetta, but there are already malware toolkits targeting M1 specifically so it's too big of a risk for us to leave it at that.

     

    Otherwise we would be looking to continue current anti-malware solutions and re-evaluate at a later time.