Supported Microsoft Defender for Endpoint capabilities by platform

Applies to:

Want to experience Defender for Endpoint? Sign up for a free trial.

Learn how to Onboard devices and configure Microsoft Defender for Endpoint capabilities.

The following table gives information about the supported Microsoft Defender for Endpoint capabilities by platform.

Operating System Windows 10 & 11 Windows Server macOS Linux
Prevention
Attack Surface Reduction Yes. Yes. No No
Device Control Yes. No Yes. No
Firewall Yes. Yes. No No
Network Protection Yes. Yes. Yes. Yes.
(preview)
Next-generation protection Yes. Yes. Yes. Yes.
Tamper Protection Yes. Yes. Yes. No
Web Protection Yes. Yes. Yes. Yes.
(preview)
Detection
Advanced Hunting Yes. Yes. Yes. Yes.
Custom file indicators Yes. Yes. Yes. Yes.
Custom network indicators Yes. Yes. Yes. Yes.
(preview)
EDR Block Yes. Yes. No No
Passive Mode Yes. Yes. Yes. Yes.
Sense detection sensor Yes. Yes. Yes. Yes.
Endpoint & network device discovery Yes. Yes.
(See note below)
No No
Vulnerability management Yes. Yes. Yes. Yes.
(preview)
Response
Automated Investigation & Response (AIR) Yes. Yes. No No
Device response capabilities: collect investigation package Yes. Yes. Yes.
(preview)
Yes.
(preview)
Device response capabilities: run antivirus scan Yes. Yes. Yes. Yes.
Device isolation Yes. Yes. Yes. Yes.
File response capabilities: collect file, deep analysis, block file, stop, and quarantine processes Yes. Yes. Yes.
(preview)
Yes.
(preview)
Live Response Yes. Yes. Yes. Yes.

Note

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.