Blog Post

Microsoft Defender for Endpoint Blog
2 MIN READ

Experience zero-touch onboarding with Microsoft Defender for Endpoint on iOS

sunayanasingh's avatar
sunayanasingh
Icon for Microsoft rankMicrosoft
Jan 05, 2022

Today we are excited to announce the general availability of Zero-touch onboarding of Microsoft Defender for Endpoint on iOS.

 

Microsoft Defender for Endpoint delivers a rich set of capabilities, including anti-phishing, blocking unsafe connections, custom Indicators, jailbreak detection, and vulnerability assessment of iOS. In addition, it offers a unified security experience through the Microsoft 365 Defender portal, where security teams can get a centralized view of alerts, incidents, and gain additional context to remediate threats across all endpoints.

 

With this new capability, enterprises can now deploy Microsoft Defender for Endpoint on iOS devices that are enrolled with Microsoft Endpoint Manager automatically, without needing end-users to interact with the app. This eases the deployment frictions and significantly reduces the time needed to deploy the app across all devices as Microsoft Defender for Endpoint gets silently activated on targeted devices and starts protecting your iOS estate.

 

As part of this feature, we support :

1. Zero touch (silent) onboarding for supervised devices via Zero touch Control Filter profile.

2. Zero touch (silent) onboarding for BYOD Intune managed devices.

For setup and configuration details, please visit our documentation.

 

Notes: 

1.   Setup can take upto 5 mins to complete in the background. 

2.  Prerequisite for onboarding is that the end users need to have company portal app installed, signed in and enrolment completed.

3.  Zero touch onboarding does not currently work with Just In Time (Setup Assistant with modern authentication) enrolments.

 

We’re excited to hear your feedback as you explore this new capability, and we will continue to update the documentation throughout the preview.

Additional resources

Microsoft Defender for Endpoint - Mobile Threat Defense | Microsoft Docs 

 

Updated Dec 08, 2023
Version 4.0

10 Comments

  • ATroester's avatar
    ATroester
    Copper Contributor

    Zero-Touch for Supervised devices works at the moment only if you use Company-Portal as initial Setup. If you use JustInTime (with modern outh) it won't work. This was the result from a case we have opened. Microsoft will work on the documentation to make it more clear.

  • This feature is generally available. 

    ATroester : Yes its possible now to have zero touch deployment on supervised devcies with zero touch control filter profile as mentioned in the document. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/ios-install?view=o365-worldwide#device-configuration-profile-control-filter

     

     

    1. Zero touch (Silent) Control Filter - This profile enables silent onboarding for users. Download the config profile from ControlFilterZeroTouch

  • ATroester's avatar
    ATroester
    Copper Contributor

    This documentation contradictory statements https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/ios-install?view=o365-worldwide#device-configuration-profile-control-filter

    Is it possible to have ZeroTouch-Deployment with Control Filter Profile on supervised devices or not?

  • SigurdL : For supervised devices, the VPN profile can be assigned if you want to setup zero-touch onboarding. (Otherwise the VPN profile is not needed on supervised devices). Currently, the VPN profile can be assigned through Intune. (Steps here). However, we are also working to enable zero-touch onboarding without the need for the VPN profile. This is on the roadmap, so stay tuned for further updates.

  • SigurdL's avatar
    SigurdL
    Copper Contributor
    sunayanasingh For supervised device Zero Touch Defender onboarding: Is there an elegant way to assign the VPN profile during onboarding and then remove it from onboarded devices? Like assign to all devises and excludeon boarded devices? Or do we have to manage that manually?
  • Krishanthad's avatar
    Krishanthad
    Copper Contributor

    are we able to have the same device name in MDE. currently it is given a totally deferent name in MDE when device get onboarded. are able to have same name that we have in MEM?

  • cheekynandos456's avatar
    cheekynandos456
    Copper Contributor

    Any signs of MDE being usable without its own VPN? For those who use a VPN already