# Do not count iOS open-network timeline entries as every Wi-Fi reconnection

> Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:55+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?

## Potentially affected

Defender for Endpoint on iOS using the open-network event experience introduced with the May 2025 app update, excluding GCC's retained alert behavior.

## DSE recommendation

Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins.

## Article

## Source facts

With the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features).

## Applicability

Establish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device’s experience proves which behavior applies to the device under investigation.

## DSE recommendation

Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.

## Verification

On a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.

## Official references

[Microsoft Learn: Defender for Endpoint iOS features](https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure Microsoft Defender for Endpoint on iOS features - Microsoft Defender for Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-endpoint/ios-configure-features
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not count iOS open-network timeline entries as every Wi-Fi reconnection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-301-do-not-count-ios-open-network-timeline-entries-as-every-wi-fi-reconnection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
