# Keep Android non-APK scanning expectations inside the managed profile

> Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:08+00:00
- Modified: 2026-09-10T01:20:46+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?

## Potentially affected

Enrolled Android BYOD work-profile, corporate-owned work-profile and fully managed devices evaluating Defender non-APK scanning preview.

## DSE recommendation

Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users.

## Article

## Source facts

Defender for Endpoint’s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/android-configure).

## Applicability

The Android guidance requires Defender to be deployed and onboarded before configuring these features. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/android-configure). Confirm the actual enrollment model and obtain the organization’s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.

## DSE recommendation

Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.

## Verification

Check a representative device’s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization’s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.

## Official references

[Microsoft Learn: Configure Defender on Android](https://learn.microsoft.com/en-us/defender-endpoint/android-configure). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure Microsoft Defender for Endpoint on Android - Microsoft Defender for Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-endpoint/android-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep Android non-APK scanning expectations inside the managed profile,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-228-keep-android-non-apk-scanning-expectations-inside-the-managed-profile/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
