Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1057719

MDE Mobile: Open Wi-Fi and Certificate Detections will be logged as Events

Plan for Change

Message ID

MC1057719
View in Admin Center

Services

Microsoft Defender XDR

Summary

The update to Microsoft Defender for Mobile will log open Wi-Fi and suspicious certificate detections as events instead of alerts starting late May 2025. This change aims to reduce alert fatigue and improve triage efficiency. No action is required from admins, and current security settings remain unchanged. GCC organizations can disregard this message.

Details

Updated May 14, 2025: After further review, we will not be rolling this out to GCC during the timeline outlined below. We will communicate via Message center when we are ready to proceed. Organizations in GCC can safely disregard this message. Thank you for your patience.

As part of our ongoing efforts to enhance the Microsoft Defender for Mobile security portal experience, we are updating the ‘Open Wi-Fi’ and ‘Cert Detection for Android’ features within the Network Protection suite. Effective May 19, 2025, when a user connects to an open Wi-Fi network on a mobile device, an alert will no longer be generated on the security portal. Instead, this activity will be recorded as an event and viewable under the device timeline. Similarly, detecting a suspicious certificate during download and installation will also be recorded as an event rather than generating an alert. This change ensures administrators still have visibility without generating alerts there by reducing fatigue.

When this will happen:

This change will take effect in a phased rollout starting late May 2025 (previously May 19).

How this affects your organization:

This update addresses customer feedback about alert fatigue, especially in environments with high mobile device usage. By logging events like open Wi-Fi connections and suspicious certificate detections in the device timeline rather than triggering alerts, we help reduce noise and streamline operations. This change benefits SOC analysts and administrators by preserving visibility into potential risky events while allowing them to focus on high-priority incidents, improving overall triage efficiency.

How the experience looks after the change:

Current security and privacy settings will remain unchanged. The current security settings will apply to the new behavior, so no action is required by the admin.

By default, showing open Wi-Fi and suspicious cert detection information on the device timeline is enabled. Admins can disable it or set it to audit mode without any change in current behavior.

There will be no change in user experience; all current behaviors will stay the same with this change.

What you can do to prepare

No immediate action is required, but it is recommended that admins review their current Intune policies related to open Wi-Fi networks and cert detection to ensure both are enabled to see events on the device timeline.


Timeline

📅
Published
Apr 18, 2025
Message published to Message Center
✏️
Updated
May 14, 2025
Message content updated
🏁
End Date
Jun 29, 2025
Message timeline ends

Tags

#Updated message#Feature update#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1052160●

Microsoft Defender XDR services: Changes to the IdentityInfo table in Advanced Hunting

Apr 10, 2025
MC1073068

Microsoft Defender for Identity: We will disable collection of local administrators' group members (using SAM-R)

May 13, 2025
MC1042926

Microsoft Defender for Office 365: Platform migration for enhanced data storage and performance

Mar 28, 2025
MC1036568

Updates to App Governance Pre-Defined Policies in Defender for Cloud Apps

Mar 19, 2025
MC1023484

Microsoft Defender for Identity: New recommendations for Microsoft Secure Score

Mar 5, 2025