---
title: Hands-On Offboarding for MDE (macOS)
description: Comprehensive guide to macOS Local MDE offboarding
---

[Skip to content](https://knowledge.sittadel.com/manual-macos-local-script-mde-offboarding#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en)
3. [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)

# Hands-On Offboarding for MDE (macOS)

## Comprehensive guide to macOS Local MDE offboarding: executing the necessary commands to stop Agent functionality and validate that the Agent processes are no longer present on the machine.

### **Offboarding macOS Device from MDE Monitoring**

1. On the desired **macOS Device** that you wish to **Offboard**, access the **Spotlight Search** functionality, provide **Terminal** within the **search field**. Locate and select the **utility** to begin.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-06-26-17-8106-PM.png?width=670&height=427&name=image-png-Aug-29-2024-06-26-17-8106-PM.png)
2. Once the **CLI session** is initiated, we will **execute the command below** to disable the **tamper protection** security control that was enforced during the onboarding process, **if this step is not completed prior to launching the next command it will fail during execution. We will need to execute this command with administrative privileges, you will need to fulfill the authentication prompt that is generated in the session.**
   
   | **Command** |
   | --- |
   | **sudo mdatp config tamper-protection enforcement-level --value disable** |
   
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-06-27-17-1423-PM.png?width=659&height=65&name=image-png-Aug-29-2024-06-27-17-1423-PM.png)
3. After the **disablement of the security control**, we will **execute the command below** to initiate the decommissioning of the **MDE agent** on the machine and severe the connection between **the device** and **Microsoft Defender services**. **We will need to execute this command with administrative privileges, you will need to fulfill the authentication prompt that is generated in the session.**
   
   | **Command** |
   | --- |
   | **sudo '/Library/Application Support/Microsoft/Defender/uninstall/uninstall'** |
   
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-06-29-09-7752-PM.png?width=658&height=35&name=image-png-Aug-29-2024-06-29-09-7752-PM.png)
4. After the **execution of the command above,** we will proceed with supplying the following **command to evaluate if the MDE agent still has proper security functionality enabled for communication to your Organizations Microsoft Defender portal.**
   
   | **Command** |
   | --- |
   | **mdapt connectivity test** |
5. Upon **execution of the script**, you will see values returned in the window below.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-29-2024-06-30-12-0687-PM.png?width=659&height=55&name=image-png-Aug-29-2024-06-30-12-0687-PM.png)
6. Depending on the results there will be **two different paths forward:** 
     1. **If the command returns that the mdatp package is not found on the machine, the agent is no longer on the machine and the MDE offboarding process was successful.** Next steps will be to access the defender portal and exclude the device manually from the system once the offboarding verification process has been executed successfully, this procedure can be [found here](https://knowledge.sittadel.com/mde-device-exclusion?hsLang=en). 
     2. **If the command returns a URL \[OK\] values related to the agent being able to connect to Microsoft Services tied to your organization, that means that the MDE agent has not been successfully removed and the machine is still currently being monitored by the MDE agent. This could be due to the steps outlined above not being conducted correctly, or the offboarding package gathered from the Defender portal having reached its expiration period.** Next steps will require that an investigation of process breakdown be conducted prior to attempting a re-execution of the procedure.

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>