What you need to know
Does enabling Defender's non-APK scanning preview cover files in an Android personal profile?
Potentially affected
Enrolled Android BYOD work-profile, corporate-owned work-profile and fully managed devices evaluating Defender non-APK scanning preview.
DSE recommendation
Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users.
Source facts
Defender for Endpoint’s Android non-APK scanning preview covers file types such as documents, archives and scripts. The documented enrolled scenarios are personally owned work-profile, corporate-owned work-profile and fully managed devices. On a work-profile device, scanning remains inside that profile and cannot access personal-profile files. The preview setting is off by default; EnableNonAPKFileScan set to 1 is the documented configuration check. Microsoft Learn.
Applicability
The Android guidance requires Defender to be deployed and onboarded before configuring these features. Microsoft Learn. Confirm the actual enrollment model and obtain the organization’s required preview approval. Do not promise personal-file scanning merely because the device reports to the service.
DSE recommendation
Describe the protected profile explicitly before enabling the non-APK scanning preview or communicating coverage to users. Have the mobile administrator and security owner identify where relevant business files are expected to reside. Keep help-desk guidance clear about the difference between a work-profile protection setting and whole-device coverage. Treat unsupported or personal-profile requirements as separate design questions, not an invitation to bypass the profile boundary.
Verification
Check a representative device’s enrollment state, onboarding and effective EnableNonAPKFileScan value. Use the organization’s approved validation method with benign test material in the intended managed location. Record exactly which profile and configuration were examined, and preserve any observed alert or scan evidence without exposing personal content. Leave untested locations outside the coverage statement.
Official references
Microsoft Learn: Configure Defender on Android. Source reviewed September 9, 2026.
Review the official source
Configure Microsoft Defender for Endpoint on Android - Microsoft Defender for Endpoint | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE