Introduction

In Microsoft Defender for Endpoint there are two types of antivirus policies for macOS endpoints where one of them is legacy and the other one is newer as it allows us to configure features such as cloud protection, scheduled scanning, archive bomb, and potentially unwanted applications.

Whenever I tried to create the modern antivirus policy for macOS endpoints the “Next” button was grayed out and wouldn’t let me proceed with creating the antivirus policy. In this article I’ll go through solving the issue where the “Next” button is grayed out in macOS and provide security configuration.

Solution

In this section I’ll go through implementing modern Microsoft Defender Antivirus policy for macOS endpoints.

  1. Go to Microsoft Intune

  2. Click on Endpoint Security Antivirus.

  3. Click on Create then select macOS Microsoft Defender Antivirus.

  4. Enter the Name and Description.

  5. After configuring the Antivirus Engine section the “Next” button is disabled.

  6. The “Next” button will be disabled until the “Allow Threats” is configured with a single entry.

So basically the “Next” button will be disabled until someone configures the “Allow Threats” with a minimum of a single entry otherwise it will not allow us to create the Microsoft Defender Antivirus Policy for macOS. Unfortunately, I don’t know the reasoning why Microsoft demands minimum a single entry…

Recommendations

I would recommend configuring Microsoft Defender Antivirus Policy for macOS endpoints with the following configurations to secure them.

SectionSettingValue
Cloud delivered protection
Cloud delivered protectionEnabled
Automatic sample submissionEnabled
Diagnostic collection levelrequired
Automatic security intelligence updatesEnabled
Automatic sample submission consentall
Security intelligence update due (days)1
Tamper protection
Enforcement levelblock
Features
Behavior monitoringenabled
Scheduled scanenabled
Offline SI updates signature verificationenabled
Performance profilesenabled
Scheduled scan
Check for definitions updateEnabled
↳ Time of day12
Daily/hourly quick scan configuration
↳ Start time0
Low priority scheduled scanEnabled
Ignore exclusionsEnabled
Network protection
Enforcement levelblock
Antivirus engine
Real-time protection (deprecated)Enabled
Passive mode (deprecated)Enabled
Exclusions mergeadmin_only
Threat type settings mergeadmin_only
Allowed threatsNULL
File hash computationFalse
Run scan after definitions updateEnabled
Scan inside archive filesTrue
Enforcement levelpassive
Offline security intelligence updatesdisabled
Fallback to Microsoft cloud updatesEnabled
Threat Type
Potentially Unwanted ApplicationBlock
Archive BombBlock

Once the configurations are applied successfully to macOS endpoints without any issues I would enable randomized scheduled scanning as it will help with detecting threats that are more complex.

Conclusion

The modern version of Microsoft Defender Antivirus policy comes with more configurations which allows us to secure our macOS endpoints. However, to create the configuration the “Allow Threats” feature must have at minimum have a single entry otherwise the “Next” button will be grayed out and it won’t let us create the policy.