Microsoft Defender for Endpoint
Troubleshooting

Overview for how to troubleshoot performance issues for Microsoft Defender for Endpoint on macOS

In brief

Updated Microsoft Defender documentation in defender-endpoint/mac-support-perf-overview.md.

What Defender admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Overview for how to troubleshoot performance issues for Microsoft Defender for Endpoint on macOS

When troubleshooting performance issues for Microsoft Defender for Endpoint on macOS, review Activity Monitor or run top to identify which Defender process has high CPU or memory usage. Collect the data while the performance issue is occurring.

Daemon name Component First troubleshooting step
wdavdaemon Core (privileged) Collect Client Analyzer performance data and hot event sources.
wdavdaemon_unprivileged Antivirus and endpoint protection platform (EPP) Use real-time protection statistics to identify files and processes that trigger scans.
wdavdaemon_enterprise Endpoint detection and response (EDR) Collect Client Analyzer performance data and hot event sources.

For all three processes, record the process name, CPU and memory use, duration, device model and processor, Defender version, macOS version, enforcement mode, workload, and other security products. Gather Microsoft Defender for Endpoint Client Analyzer.wdavdaemon_unprivilegedAnti-malware (AV, EPP)Review Troubleshoot performance issues for Microsoft Defender for Endpoint on macOS.wdavdaemon_enterpriseEndpoint Detection and Response (EDR)Open a Microsoft support case.

Additionally, gather Defender for Endpoint Client Analyzer files while the issue occurs. This is used by the support team to investigate the issue.