{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
        "slug": "dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/"
        },
        "title": "Keep Android non-APK scanning expectations inside the managed profile",
        "summary": "Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:08+00:00",
        "modified_at": "2026-09-10T01:20:46+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 236,
        "potentially_affected": "Enrolled Android BYOD work-profile, corporate-owned work-profile and fully managed devices evaluating Defender non-APK scanning preview.",
        "dse_recommendation": "Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users.",
        "primary_source": {
            "name": "Configure Microsoft Defender for Endpoint on Android - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/android-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender for Endpoint&#8217;s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/android-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>The Android guidance requires Defender to be deployed and onboarded before configuring these features. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/android-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>. Confirm the actual enrollment model and obtain the organization&#8217;s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.</p>\n<h2>DSE recommendation</h2>\n<p>Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.</p>\n<h2>Verification</h2>\n<p>Check a representative device&#8217;s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization&#8217;s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/android-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Defender on Android</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender for Endpoint’s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. Microsoft Learn.\nApplicability\nThe Android guidance requires Defender to be deployed and onboarded before configuring these features. Microsoft Learn. Confirm the actual enrollment model and obtain the organization’s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.\nDSE recommendation\nDescribe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.\nVerification\nCheck a representative device’s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization’s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.\nOfficial references\nMicrosoft Learn: Configure Defender on Android. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender for Endpoint’s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/android-configure).\n\n## Applicability\n\nThe Android guidance requires Defender to be deployed and onboarded before configuring these features. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/android-configure). Confirm the actual enrollment model and obtain the organization’s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.\n\n## DSE recommendation\n\nDescribe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.\n\n## Verification\n\nCheck a representative device’s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization’s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.\n\n## Official references\n\n[Microsoft Learn: Configure Defender on Android](https://learn.microsoft.com/en-us/defender-endpoint/android-configure). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep Android non-APK scanning expectations inside the managed profile",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/",
                "headline": "Keep Android non-APK scanning expectations inside the managed profile",
                "description": "Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?",
                "abstract": "Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?",
                "articleBody": "Source facts\nDefender for Endpoint’s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. Microsoft Learn.\nApplicability\nThe Android guidance requires Defender to be deployed and onboarded before configuring these features. Microsoft Learn. Confirm the actual enrollment model and obtain the organization’s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.\nDSE recommendation\nDescribe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.\nVerification\nCheck a representative device’s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization’s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.\nOfficial references\nMicrosoft Learn: Configure Defender on Android. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:28:08+00:00",
                "dateModified": "2026-09-10T01:20:46+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep Android non-APK scanning expectations inside the managed profile"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 236,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Microsoft Defender for Endpoint on Android - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/android-configure"
                }
            }
        ]
    }
}