Fix Microsoft Defender for macOS Full Disk Access Configuration Unavailable
Question details
The user needs to resolve an issue where Microsoft Defender for Endpoint on macOS displays a Configuration not available status for Full Disk Access.

- Product
- Microsoft Defender for Endpoint
- Device & OS
- macOS
- Scenario
- Deploying and managing Microsoft Defender security configurations via Microsoft Intune.
- Observed behavior
- The Defender configuration status in the management portal shows Configuration not available instead of confirming that Full Disk Access is successfully granted.
Ensure you have administrator access to the Microsoft Intune admin center and that the target macOS device is powered on and connected to the internet.
Verify Intune Connection and Device Onboarding
Use this solution to ensure that the foundational connection between Microsoft Intune and Defender for Endpoint is active and the Mac is properly enrolled.
If the integration between Intune and Defender is broken or the device hasn't fully onboarded, configuration policies will fail to apply and show as unavailable.
Sign in to the Microsoft Intune admin center, navigate to Endpoint security, and select Microsoft Defender for Endpoint. Verify that the connection status shows as active.
Go to the Devices section in Intune and locate the affected macOS device to confirm it is successfully enrolled.
Check the Microsoft Defender security center to ensure the macOS device appears in the device inventory, indicating a successful onboarding process.

Configure macOS System Extensions and Full Disk Access Profiles
Use this method to correctly configure the required macOS configuration profiles in Intune.
Sync Device and Review Deployment Errors
Force a device sync and check for policy conflicts to resolve delayed or stuck deployments.
Need a Lightweight Office Suite for Your Mac? Try WPS Office
While troubleshooting complex Microsoft Defender and Intune policies on your Mac, you might be looking for a fast, secure, and hassle-free productivity suite. WPS Office is a free, lightweight alternative that offers seamless compatibility with major document formats.
- 1. Download the Installer: Visit the official WPS Office website and download the macOS version.
- 2. Install on Your Mac: Open the downloaded file and follow the on-screen instructions to install the suite.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files without formatting loss.

Frequently Asked Questions
Why does Intune show configuration unavailable for Defender on macOS?
This error typically occurs due to an incomplete onboarding process, delays in device synchronization, or missing configuration profiles granting System Extensions and Full Disk Access in Intune.
How long does it take for Intune policies to apply on macOS?
After initiating a manual sync, policies usually apply within a few minutes. However, depending on network connectivity and Microsoft Intune service loads, it can sometimes take up to 8 hours to fully reflect in the portal.
Can I manually grant Full Disk Access to Defender on a Mac?
Yes, for local troubleshooting you can navigate to System Settings > Privacy & Security > Full Disk Access on the Mac and manually toggle Microsoft Defender. However, for enterprise environments, this should be managed and deployed via Intune profiles.




