Explore Our Microsoft Cloud Security Training →
Known issue
The performance problem is related to the Defender macOS build 101.26012.0015 in the Production ring. Updating to build 101.26012.0017 hotfix or moving to Insider Fast 101.26022.0015 can help resolve this issue.
Full Disk Access and Network Extension
Ensure that Defender extensions have Full Disk Access granted in System Settings > Privacy & Security on macOS. Also, address any network extension crashes on macOS Sequoia 15.0 by upgrading to 15.1 or newer.
Conflicts with native firewall
Common conflicts with the macOS native firewall can lead to performance issues. Address these conflicts for optimal performance.
Update channels and rollback procedures
Understand update channels and rollback procedures in case you need to revert to a previous version of MDE on macOS.
Avoiding known limitations
Avoid using macOS Sonoma 14.3.1 if Bluetooth device control is required due to a known Apple-side limitation.
Generating diagnostic bundles and top contributing processes
mdatp diagnostic create
Use this command to generate a diagnostic bundle for troubleshooting. To capture the top contributing processes, use:
mdatp performance
Conclusion
Troubleshooting Microsoft Defender for Endpoint performance issues on macOS can be a challenging task. However, with the right knowledge and tools, you can address common conflicts and ensure optimal performance. For more in-depth training on Microsoft Cloud Security, including Microsoft Defender for Endpoint, visit our Microsoft Cloud Security Training.
Explore Our Microsoft Cloud Security Training →
Written by Mohammed Akhter
Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →
