Microsoft Defender for Endpoint
Endpoint protection

Configure and validate exclusions for Microsoft Defender for Endpoint on macOS

In brief

Updated Microsoft Defender documentation in defender-endpoint/mac-exclusions.md.

What Defender admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure and validate exclusions for Microsoft Defender for Endpoint on macOS

[!INCLUDE side-by-side-scenarios]

Choose the right mitigation

Use the narrowest mitigation that addresses the identified component.

FindingNext step
wdavdaemon_unprivileged is affected, and real-time protection statistics identify a file, folder, or processConsider an antivirus exclusion after reviewing the security impact.
wdavdaemon or wdavdaemon_enterprise is affectedCollect hot event sources and Client Analyzer performance data. Antivirus exclusions might not address this event-processing load.
Another endpoint security product is installedConfirm the intended active or passive mode and the coexistence settings for both products before adding workload exclusions.
The affected workload isn't identifiedDon't add a broad exclusion. Reproduce the issue and collect performance diagnostics first.

After applying an exclusion, repeat the same workload and compare CPU usage, memory usage, scan counts, and elapsed time. Remove the exclusion if it doesn't provide a measurable improvement.

Supported exclusion types

The following table shows the exclusion types supported by Defender for Endpoint on macOS.

mdatp threat allowed add --name "EICAR-Test-File (not a virus)"