GuideInformationCybersecurityIT

Keep Android non-APK scanning expectations inside the managed profile

Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?

Potentially affected

Enrolled Android BYOD work-profile, corporate-owned work-profile and fully managed devices evaluating Defender non-APK scanning preview.

DSE recommendation

Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users.

Source facts

Defender for Endpoint’s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. Microsoft Learn.

Applicability

The Android guidance requires Defender to be deployed and onboarded before configuring these features. Microsoft Learn. Confirm the actual enrollment model and obtain the organization’s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.

DSE recommendation

Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.

Verification

Check a representative device’s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization’s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.

Official references

Microsoft Learn: Configure Defender on Android. Source reviewed September 9, 2026.

Primary reference

Review the official source

Configure Microsoft Defender for Endpoint on Android - Microsoft Defender for Endpoint | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE