Loading...

MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events

MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events

Starting May 19, 2025, Microsoft Defender for Mobile will log open Wi-Fi connections and suspicious certificate detections as events instead of generating alerts. This change aims to reduce alert fatigue while maintaining visibility. No action is required from admins, but reviewing Intune policies is recommended. As part of our ongoing efforts to enhance the Microsoft Defender for Mobile security portal experience, we are updating the ‘Open Wi-Fi’ and ‘Cert Detection for Android’ features within the Network Protection suite. Effective May 19, 2025, when a user connects to an open Wi-Fi network on a mobile device, an alert will no longer be generated on the security portal. Instead, this activity will be recorded as an event and viewable under the device timeline. Similarly, detecting a suspicious certificate during download and installation will also be recorded as an event rather than generating an alert. This change ensures administrators still have visibility without generating alerts there by reducing fatigue. When this will happen: This change will take effect in a phased rollout starting May 19, 2025. How this affects your organization: This update addresses customer feedback about alert fatigue, especially in environments with high mobile device usage. By logging events like open Wi-Fi connections and suspicious certificate detections in the device timeline rather than triggering alerts, we help reduce noise and streamline operations. This change benefits SOC analysts and administrators by preserving visibility into potential risky events while allowing them to focus on high-priority incidents, improving overall triage efficiency. How the experience looks after the change: Current security and privacy settings will remain unchanged. The current security settings will apply to the new behavior, so no action is required by the admin. By default, showing open Wi-Fi and suspicious cert detection information on the device timeline is enabled. Admins can disable it or set it to audit mode without any change in current behavior. There will be no change in user experience; all current behaviors will stay the same with this change. What you can do to prepare No immediate action is required, but it is recommended that admins review their current Intune […]

The post MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Purview: Auto-labeling scalability, policy management, and reporting enhancements

Microsoft Purview is improving auto-labeling capabilities to help organizations manage and validate labeling policies at enterprise scale. The...

20 hours ago

Updates available for Microsoft 365 Apps for all channels

We’ve released updates to the following update channels for Microsoft 365 Apps: Current Channel Monthly Enterprise Channel Semi-Annual E...

20 hours ago

Microsoft Purview | Data Lifecycle Management – Graph API Support for archive mailboxes

Microsoft is retiring Exchange Web Services (EWS) in Exchange Online by April 2027 and expanding Microsoft Graph API support for archive mailb...

20 hours ago

[Whiteboard] Legacy Whiteboard migration to OneDrive

Microsoft Whiteboard is migrating from legacy Azure-based storage to OneDrive-backed storage. Migration must be completed by September 25, 202...

20 hours ago

Microsoft Publisher: Reminder that support ends in October 2026

Microsoft Publisher support ends October 1, 2026; it will no longer be available in Microsoft 365 subscriptions. Users should convert or migra...

20 hours ago

[Whiteboard] Standalone app deprecation (Windows, Mobile)

Microsoft will retire standalone Whiteboard apps for Windows, iOS, and Android on October 16, 2026. Users must switch to accessing Whiteboard ...

20 hours ago

Microsoft Entra: Optimized passkey registration campaign experience

Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoptio...

20 hours ago

The September 2026 Scan Cab is available

IMPORTANT: This notice only affects environments where Scan Cab is used to check for update compliance. What and why: The September 2026 Scan ...

20 hours ago

Teams admin center device state rules and health alerts retire; use Teams Rooms Pro Management portal

Teams admin center’s device state rules and health alerts will retire by late September 2026. Device health monitoring moves to the Team...

20 hours ago

Build apps in Microsoft Copilot Studio and Copilot Cowork

Microsoft announces a preview of app-building in Copilot Cowork starting September 8, 2026, with Copilot Studio following soon. Users with lic...

20 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.