Corrata and Microsoft Defender for Endpoint: How they compare on mobile

If your organisation runs Microsoft 365 E3 or E5, you already own a mobile threat defence product. Microsoft Defender for Endpoint on Android and iOS is Microsoft’s MTD solution, and it is available with both Plan 1, which comes with E3, and Plan 2, which comes with E5. It deploys through Intune and reports into the same portal your SOC already uses. What differs between the plans is what sits behind the mobile agent, since vulnerability management, advanced hunting and EDR are Plan 2 capabilities.
So the fair question is not whether Microsoft has something for mobile, but what that agent covers, where it stops, and whether the gaps matter for your risk profile. We spend a lot of time in Microsoft-first environments, so we put this together for security and IT teams working through exactly that question.
What we compared, and what we did not
This comparison covers Defender for Endpoint on iOS and Android, against Microsoft’s own published capability list.
Microsoft has other products that touch mobile, and it would be unfair to ignore them. Intune app protection policies control data movement inside managed apps. Entra conditional access decides who gets to connect. Purview handles classification and DLP. Where one of those changes the picture, we say so. Comparing Corrata against the entire Microsoft estate is a different exercise, and a much longer one.
One thing worth flagging before we start. Microsoft’s mobile capabilities are spread across several places: Defender web protection, custom URL indicators, and Intune app configuration policies for Edge. Coverage also varies by platform, since malware scanning and certificate detection each work differently on iOS and Android, and custom IP indicators are supported on Android but not on iOS. So if you are not certain exactly what your current licence covers on mobile, that is understandable, and it is worth checking before you assume either way.
The short version
|
Capability |
Corrata |
Defender for Endpoint on mobile |
|---|---|---|
|
Anti-phishing across SMS, messaging apps, QR codes |
Inspects traffic on the device in real time across messaging apps, browsers and QR codes, and Zero Day Protection blocks destinations with no reputation history |
Anti-phishing and blocking of unsafe network connections, with custom indicators limited to URLs and domains. Detection works from the destination rather than the traffic |
|
Malware and malicious app detection |
App inventory and hashes on both platforms, plus traffic-level detection that cuts off command-and-control activity |
Cloud-backed app and file scanning, Android only |
|
Device vulnerability and configuration checks |
Tracks OS versions, configuration, jailbreak and root, with a score per device |
Defender Vulnerability Management reports OS and app exposure, with Plan 2 rather than Plan 1 |
|
Category-based web filtering |
Enforces acceptable use by category across all traffic, not just one browser |
Not supported on mobile. Nearest routes are custom URL indicators or Edge allow and block lists via Intune, which govern one browser |
|
AI chatbot and SaaS policy control |
Allows sanctioned AI services and blocks the rest at the network layer, including embedded LLM SDKs |
Purview endpoint DLP covers Windows and macOS. On mobile the control point is Intune app protection, which acts at the app boundary |
|
Monitoring of SaaS use across the mobile fleet |
Discovers which SaaS services the fleet is using, on or off the corporate network |
Endpoint-based discovery covers Windows and macOS. Firewall log ingestion sees mobile traffic only while the device is on your network |
|
On-device forensics |
Collects diagnostic files and packet captures from the handset itself |
Mobile alerts and network events reach the portal, but there is no on-device diagnostic or packet capture collection |
|
Device quarantine |
Isolates an at-risk device from corporate resources automatically |
Isolation is documented for Windows, macOS and Linux. On mobile, risk signals drive conditional access blocking instead |
|
Encryption quality assessment |
Inspects the TLS handshake and reports weak encryption, with blocking as an admin policy choice |
Not assessed. Network protection covers rogue networks and certificates rather than cipher strength |
|
Rogue Wi-Fi and certificate detection |
Detects both, on both platforms, from connection and certificate metadata |
Network protection detects rogue Wi-Fi, with certificate detection on Android only |
|
Employee privacy footprint |
Domain-level metadata only. No full URLs, page content, search terms, message content, files or location |
Android app requests storage access for scanning and prompts for optional location access for Wi-Fi threat detection |
Corrata’s DLP, AI governance, device quarantine and forensic capture sit in the Business and Enterprise tiers rather than in Essentials, so the comparison above is against the full platform.
Read down that table and the pattern matters more than the individual rows.
Corrata’s coverage is broad because it comes from one place: category-based web filtering, DLP over data heading to unsanctioned services including AI assistants, visibility of SaaS use across the fleet, encryption quality assessment, forensic capture from a suspect device, and quarantine while it is investigated. All of it needs an agent that can see the device’s own traffic in detail and act on it locally, which is what on-device deep packet inspection provides.
Defender’s mobile agent works from the destination and the device’s configuration instead. It provides anti-phishing and blocks unsafe network connections, scans apps and files on Android, assesses vulnerabilities, detects jailbreak and root, and feeds risk into conditional access. That architecture is why it has no category filtering, no mobile DLP, no view of AI or SaaS use, no encryption assessment and no on-device forensics.
Let’s break it down across six areas of concern.
Phishing that arrives outside the browser
Most mobile phishing does not arrive by email any more. It arrives by SMS, WhatsApp, iMessage, a QR code on a poster, or a poisoned search result. Defender’s web protection inspects connections and provides anti-phishing and blocks unsafe network connections, with custom indicators limited to URLs and domains. It works from the destination, which means the delivery channel matters less than whether the destination is already flagged.
That is where the difference shows up. In Corrata’s own weekly testing across mobile messaging channels, Defender for iOS detected fewer than one in five of the phishing attacks we sent through.
Our detection inspects traffic on the device in real time, and Zero Day Protection blocks destinations with no reputation history rather than waiting for one to build. Phishing infrastructure that only lives for a few hours is where reputation-based checking struggles most.
Acceptable use and category-based web filtering
If you need to stop staff reaching gambling, adult or other categories on a work phone, Defender will not do it. Microsoft’s documentation states that web content filtering is not supported on mobile platforms, on either Android or iOS. You can block named sites with custom URL and domain indicators, so a specific block list is achievable, but there is no category engine behind it.
There is a second route, and it is worth understanding before anyone suggests it. Intune app configuration policies let you set an allow list or a block list on Edge for iOS and Android. On iOS, Microsoft’s Edge data security guidance notes that the two lists are mutually exclusive, so you get one or the other. The lists apply at navigation level, so a blocked URL embedded inside a page still loads, and Edge blocks sites only when they are reached directly rather than through an intermediate service such as a translation proxy. And it only covers Edge, so it does nothing unless you also block every other browser through conditional access. Maintaining a hand-built domain list per category, across two platforms, in a single browser, is not what most acceptable use policies assume.
Corrata filters by category across all traffic rather than one browser, which supports acceptable use enforcement and wider compliance efforts.
Data leaving the device, including AI chatbots
This is the gap that has grown fastest. Staff paste customer data into whichever AI assistant is open, and on mobile most security teams have no visibility at all.
Microsoft’s endpoint DLP covers Windows and macOS devices, with no mobile equivalent. Shadow IT discovery has more than one route: you can ingest firewall and proxy logs, which will pick up mobile traffic while the phone is on your network, and you can use the Defender for Endpoint integration, which is what extends discovery beyond the corporate network and lists Windows and macOS as prerequisites. So a phone on cellular or home Wi-Fi is not covered either way.
Intune app protection policies do help here, and any fair assessment should say so. They stop data moving from a managed app into an unmanaged one. They work at the app boundary, though, so they cannot tell you which AI services your staff are using, and they will not stop someone opening an unsanctioned chatbot in a browser and typing into it.
Corrata works at the network layer on the device, which means you can allow the AI tools you have sanctioned, block the ones you have not, restrict unauthorised file shares and email services, and see which SaaS services your mobile fleet is actually using, on or off your network.
Spyware, forensics and containment
Mercenary spyware is a niche concern for most organisations and an existential one for a few: legal, journalism, public sector, anyone with exposure to nation-state interest.
Investigating it needs three things. Continuous visibility of device traffic. The ability to pull diagnostic files and packet captures off a suspect handset. A way to contain the device quickly. Microsoft’s mobile capability list does not include behavioural monitoring of device traffic, and device isolation is documented for Windows, macOS and Linux rather than mobile. Mobile alerts and network events do surface in the portal and, with Plan 2, in advanced hunting. What you cannot do is pull diagnostic files or a packet capture off the handset itself, which is what a spyware investigation turns on.
There is a containment route on mobile, which is risk-based conditional access. It blocks the device from reaching corporate resources, which is useful and worth configuring. It does not take the device off the network, so anything already resident on it keeps running and keeps talking to its operator.
Corrata monitors device traffic continuously, collects diagnostics and packet captures for investigation, and can quarantine a device when something is found.
How well is the traffic actually encrypted?
Defender’s network protection detects rogue Wi-Fi and rogue certificates, which covers the classic interception scenarios and is a real capability. Worth knowing that coverage is uneven across platforms, since Microsoft’s mobile configuration reference notes that certificate detection is available on Android only. Microsoft also tightened this in June 2026, so users can no longer choose to trust a network flagged as suspicious.
What it does not do is assess connection quality. Weak cipher suites, outdated TLS versions and applications sending sensitive data over encryption that should not be trusted all sit outside what the mobile agent looks at.
Corrata inspects the TLS handshake on the device and reports weak encryption when it finds it, and blocking is available as an administrator policy choice rather than something that happens by default.
Employee privacy and permissions
Privacy deserves care here, because Microsoft’s position is clearer than it is often given credit for. Its privacy documentation states that an organisation cannot see browsing history beyond blocked malicious sites, location history, message content, contacts or stored files, and admins have controls over what appears in threat reports.
The practical difference is permission footprint, and it matters because permission prompts are what employees actually react to during rollout. On Android, the app requests storage access so it can scan for malicious files, and prompts for location access so network protection can assess Wi-Fi threats.
Location is optional, and Microsoft notes that declining it leaves rogue certificate protection working while Wi-Fi threat detection is reduced. On iOS the prompt is a VPN profile, which web protection requires. It is a local loopback VPN that keeps traffic on the device, and admins can make the permission optional, though skipping it leaves web protection inactive.
There is one more distinction worth knowing if you run supervised iOS devices. Microsoft’s iOS configuration documentation states that on supervised devices with the configuration profile, Defender can access the entire URL, while on unsupervised devices it has access only to the domain name.
Corrata does not access location, read message content, scan files or record browsing history. What it observes is connection metadata: domain and server names, IP addresses, port numbers, SSL certificate details, app hashes and permissions. Domain-level metadata rather than full URLs, page content or search terms is a meaningful distinction, and it is the one worth making explicit when a works council asks.
Where compliance comes into it
Neither NIS2 nor DORA names mobile threat defence, and no product makes you compliant. Both expect you to show the measures you have in place and evidence how you detect and report incidents. Mobile is usually the part of the estate with nothing to show, and DORA’s clocks are short: initial notification of a major incident within four hours of classification and 24 hours of becoming aware.
Defender covers part of this. Devices appear in the portal, alerts land with everything else, and posture feeds conditional access. What it cannot give you is category-level acceptable use enforcement, a record of what data left a device, or on-device collection to reconstruct an incident on a handset.
Corrata covers that ground. Acceptable use by category, visibility and policy control over data going to unsanctioned services including AI assistants, diagnostics and packet capture from a suspect device, and quarantine while it is investigated, all reporting into your SIEM. For regulated organisations, that supports compliance efforts in the one area that is usually dark.
Which one do you need?
Defender for Endpoint is a strong product, and this comparison should not leave you thinking otherwise. Across Windows, macOS and Linux it gives you EDR, device isolation, vulnerability management and forensic investigation, feeding an XDR picture that spans identity, email and cloud. If your risk is concentrated on laptops and servers, that is a good place to be.
Mobile sits differently inside that mix. The mobile agent brings a subset of what Defender does elsewhere: connection checks against known-bad destinations, app scanning on Android, vulnerability and jailbreak reporting, and risk signals for conditional access. The deeper capabilities stay on the desktop side, which is why category filtering, DLP, on-device forensics and isolation are absent on phones.
That matters more than it used to. Phishing arrives by message rather than email, data leaves through AI assistants nobody sanctioned, and commercial spyware increasingly targets handsets alongside laptops. Phones carry the same data as laptops with a fraction of the visibility, which is why a purpose-built mobile threat defence layer has become a distinct requirement rather than a nice-to-have.
Corrata is that layer. On-device deep packet inspection gives you phishing protection across messaging apps, browsers and QR codes, policy control over AI and SaaS use, category-level acceptable use enforcement, encryption quality assessment, and forensic capture and quarantine when something goes wrong, without asking employees for permissions that read their files or track their location.
Book a demo to explore what Corrata sees on a handful of test devices.