What you need to know
Why can repeated open-Wi-Fi connections produce few Defender timeline events and no new alerts?
Potentially affected
Defender for Endpoint on iOS using the open-network event experience introduced with the May 2025 app update, excluding GCC's retained alert behavior.
DSE recommendation
Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins.
Source facts
With the documented May 2025 iOS app update, Defender open-wireless-network activity moves from alerts to device-timeline events. Repeated connections within a 24-hour period produce only one connection event and one disconnection event. User-trusted open networks are included. The change requires the corresponding app update and does not apply to GCC customers, who retain the previous alert experience. Microsoft Learn.
Applicability
Establish the tenant cloud and installed application version before explaining a quiet alert queue or a small event count. Do not assume that a different device’s experience proves which behavior applies to the device under investigation.
DSE recommendation
Interpret the mobile timeline as the documented summarized event signal, not a complete count of network joins. Ask the security operations owner to update searches and help-desk explanations that still expect a new alert for every connection. If the investigation needs connection frequency, identify an authorized evidence source appropriate to that requirement rather than calculating it from these summarized entries. Keep trusted-network status separate from whether an event can appear.
Verification
On a permitted test device, record the app version and cloud, then compare the observed timeline and alert behavior with the applicable documented path. Preserve the time range and device identity when examining repeated activity. State the observation narrowly: an event establishes the reported activity, but the documented one-per-type limit does not support a total reconnection count. Investigate missing expected evidence without inventing unobserved joins.
Official references
Microsoft Learn: Defender for Endpoint iOS features. Source reviewed September 9, 2026.
Review the official source
Configure Microsoft Defender for Endpoint on iOS features - Microsoft Defender for Endpoint | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE