diff --git a/windows/security/threat-protection/microsoft-defender-atp/android-privacy.md b/windows/security/threat-protection/microsoft-defender-atp/android-privacy.md new file mode 100644 index 0000000000..c3556182fd --- /dev/null +++ b/windows/security/threat-protection/microsoft-defender-atp/android-privacy.md @@ -0,0 +1,125 @@ +--- +title: Microsoft Defender ATP for Android - Privacy information +description: Privacy controls, how to configure policy settings that impact privacy and information about the diagnostic data collected in Microsoft Defender ATP for Android. +keywords: microsoft, defender, atp, android, privacy, diagnostic +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: dansimp +author: dansimp +ms.localizationpriority: medium +manager: dansimp +audience: ITPro +ms.collection: M365-security-compliance +ms.topic: conceptual +--- + +# Microsoft Defender ATP for Android - Privacy information + +**Applies to:** + +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for Android](microsoft-defender-atp-android.md) + + +icrosoft Defender ATP for Android collects and stores information from your +configured Android devices in the same customer dedicated and segregated tenant +specific to your Microsoft Defender ATP service for administration, tracking, +and reporting purposes. + +Information collected includes the below (but not limited to), to help keep +Microsoft Defender ATP for Android secure, up-to-date and perform as expected on +the device it’s installed and configured on. + +**\#\# Required Data** + +Data in the required category consists of data that is necessary to make +Microsoft Defender ATP for Android work as expected by the customer. This data +is tied to a user, device, network, or application and is essential to the +nature of management. All identifiable data is anonymized before collecting. +Identifiable data can include data related to end user, pseudonymized data with +a unique identifier generated by the system, used to deliver the enterprise +service to users, support data and account data. + +- App information + +> APKs on the device including (but not limited to) data about the APK such as + +- Install source + +- Storage location (file path) of the APK + +- Time of install, size of APK and permissions. + +- Web page / Network information + + - Full URL (on supported browsers), when clicked. + + - IP Address, Domain, sub-domain when background connections occur. + + - Protocol type (such as HTTP, HTTPS, etc.) + + - DNS record name + +- Device and account information + + - Device information such as date & time, Android version, OEM model, CPU + info, Device identifier + + - Device identifier is a anonymized value of one of the below (in order) + + - WiFi adapter Mac address + + - [Android + ID](https://developer.android.com/reference/android/provider/Settings.Secure#ANDROID_ID) + (as generated by Android at the time of first boot of the device) + + - Randomly generated global unique identifier + + - Tenant, Device and User information + + - Azure AD Device ID, Azure tenant ID, Azure User ID + + - Microsoft Defender ATP org ID + + - User Principal Name + +- Product and service usage data + +- App package info like name, version, app upgrade status + + - Actions performed in the app + + - Threat detection information such as threat name, category, etc. + + - Crash report logs generated by Android + +**\#\# Optional Data** + +Data in the optional category is not essential to the product or service +experience. Customers can control the collection of optional data. + +> **Diagnostic data** is used to keep Microsoft Defender ATP secure and +> up-to-date, detect, diagnose and fix problems, and also make product +> improvements. Below diagnostic data is collected only with the consent of +> the user as part of the feedback submission feature. + +- Device information such as Build Information, date & time, Android version, + OEM model, CPU info, Device identifier + +- App usage, CPU and network usage + +- State of the device from the app perspective like scan status, scan timings, + app permissions granted, Upgrade status + +- Features configured by the admin. + +- Basic information about the browsers on device + +> **Feedback Data** is collected thru in-app feedback provided user + +- User email address is optional to provide. + +- Feedback type (smile, frown, idea), Feedback comments submitted by user