BriefingInformationCybersecurityIT

Do not count iOS open-network timeline entries as every Wi-Fi reconnection

Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureBriefing · 2 min read
Executive summary

What you need to know

Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?

Potentially affected

Defender for Endpoint on iOS using the open-network event experience introduced with the May 2025 app update, excluding GCC's retained alert behavior.

DSE recommendation

Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins.

Source facts

With the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. Microsoft Learn.

Applicability

Establish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device’s experience proves which behavior applies to the device under investigation.

DSE recommendation

Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.

Verification

On a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.

Official references

Microsoft Learn: Defender for Endpoint iOS features. Source reviewed September 9, 2026.

Primary reference

Review the official source

Configure Microsoft Defender for Endpoint on iOS features - Microsoft Defender for Endpoint | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE