ACR Index Get a draft ACR

Microsoft Defender for Endpoint

Accessibility Conformance Report published by Microsoft

Conformance by level

Reported by the vendor. WCAG Level AA is the benchmark referenced by ADA Title II, Section 508 and the European Accessibility Act; Level AAA is optional and often left unevaluated.

Source: Download the original report from Microsoft (Word document). Or browse all of Microsoft's reports on Microsoft's own site.

These figures are extracted from that document. They are the vendor's own statements, not an independent assessment, and automated extraction can misread a table.

All reported criteria (87)

Conformance as stated by Microsoft in its published report.
CriterionNameLevel ConformanceRemarks from vendor
1.1.1 Non-text Content A Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the screen reader does not announce the “opens in a new tab” icon in the info icon control of the Configuration Settings step.
1.2.1 Audio-only and Video-only (Prerecorded) A Not Applicable
1.2.2 Captions (Prerecorded) A Not Applicable
1.2.3 Audio Description or Media Alternative (Prerecorded) A Not Applicable
1.3.1 Info and Relationships A Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies – Create a New Policy, the visually appearing heading “Additional settings” is not programmatically defined as a heading on the dialog.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, an incorrect label is announced as selected within a row, causing confusion between selected and non-selected rows.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the screen reader announces an incorrect list count and cannot navigate all toggle buttons in the Compliance Status chart legend.
1.3.2 Meaningful Sequence A Supports
1.3.3 Sensory Characteristics A Supports
1.4.1 Use of Color A Supports
1.4.2 Audio Control A Not Applicable
2.1.1 Keyboard A Partially Supports - In Microsoft Defender MDE Search (Files) – File Content and Deep Analysis, the tooltip under the “Details” column is not keyboard accessible.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, info tooltips are not scrollable by keyboard at 400% zoom in reflow mode.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the “Learn more” link in the info icon tooltip is not accessible by keyboard in the Create a New Policy dialog.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, table headers in the Review + step wizard cannot be dragged using the keyboard.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, elements with scrollable content are not accessible by keyboard.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, table headers in the Add Configuration Settings step cannot be resized using the keyboard.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the Info button in the Customized Name column is not keyboard accessible.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the tooltip of the +More control in the Compliance Level column is not keyboard accessible.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, table headers on the Settings page cannot be dragged using the keyboard.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the tooltip in the Compliance Level column is not keyboard accessible.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment – Profile, the Device Compliance chart in the Devices table is not keyboard accessible.
2.1.2 No Keyboard Trap A Supports
2.1.4 Character Key Shortcuts A Supports
2.2.1 Timing Adjustable A Supports
2.2.2 Pause, Stop, Hide A Supports
2.3.1 Three Flashes or Below Threshold A Supports
2.4.1 Bypass Blocks A Supports
2.4.2 Page Titled A Supports
2.4.3 Focus Order A Partially Supports - In Microsoft Defender MDE Indicators – Certificates, activating the “Save” button on the table flyout causes keyboard focus to be lost, and subsequent tabbing moves focus outside the UI.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, activating the “Learn more” link in the info icon control incorrectly shifts keyboard focus to the top of the browser.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, saving the Customize Configuration dialog causes keyboard focus to be lost.
2.4.4 Link Purpose (In Context) A Supports
2.5.1 Pointer Gestures A Supports
2.5.2 Pointer Cancellation A Supports
2.5.3 Label in Name A Supports
2.5.4 Motion Actuation A Supports
3.1.1 Language of Page A Supports
3.2.1 On Focus A Supports
3.2.2 On Input A Supports
3.2.6 Consistent Help A Supports
3.3.1 Error Identification A Supports
3.3.2 Labels or Instructions A Supports
3.3.7 Redundant Entry A Supports
4.1.1 Parsing A Not Applicable
4.1.2 Name, Role, Value A Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the info button next to “Auto Resolve” in the Configuration Settings step does not have discernible text.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies – Manage Reusable Settings, the “Match type” combobox does not have an accessible name for its ARIA input field.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the combobox below “Threat Severity Default Action” in the Create a New Policy dialog does not have an accessible name.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies – Create a New Policy, the Close button in the Select Reusable Settings dialog does not have discernible text.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies – Create a New Policy, ARIA buttons, links, and menu items do not have accessible names.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the PrinterConnectionId and PrimaryId comboboxes are not associated with visual labels.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, ARIA input fields for comboboxes are missing accessible names.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the Type of Tag edit field does not have an accessible name for its ARIA input field.- In Microsoft Defender MDE Configuration Management – Create a New Policy, the screen reader does not announce the name of the region after selecting Next.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the info buttons in the Configure Printer instance flyout do not have defined names.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the Exception Duration combobox does not have an accessible name for its ARIA input field.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, all checkboxes in the table lack accessible names for their ARIA toggle fields.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the Expand/Collapse button in the Configurations table header does not have a defined name.- In Microsoft Defender MDE Vulnerability Management – Device page and panel page, the bulleted icons are incorrectly assigned the “Alert” role and an unnecessary tooltip.
1.2.4 Captions (Live) AA Not Applicable
1.2.5 Audio Description (Prerecorded) AA Not Applicable
1.3.4 Orientation AA Supports
1.3.5 Identify Input Purpose AA Supports
1.4.3 Contrast (Minimum) AA Partially Supports - In Microsoft Defender Settings – Endpoints – Onboarding, the link text “these instructions” has a luminosity ratio below the required 3:1 compared to the surrounding text.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the graph tooltip text count in dark mode (14px bold text) has a contrast ratio below the required 3:1.
1.4.4 Resize text AA Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the status bar text is truncated at 200% zoom.
1.4.5 Images of Text AA Supports
1.4.10 Reflow AA Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the “Delete” and “Edit” controls are not actionable at 400% zoom in reflow mode.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, all content and controls in the “Additional settings” dialog are truncated at 400% zoom in reflow mode.- In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the placeholder text in the Search Settings by Setting Name field is truncated at 400% zoom in reflow mode.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the Filter by Device Groups menu items are truncated at 400% zoom.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, a horizontal scrollbar appears for the Review and Finish step at 400% zoom.- In Microsoft Defender MDE Vulnerability Management, software tab of Inventories page, at 400% zoom, the dates and the content present under graphs are truncated.
1.4.11 Non-text Contrast AA Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the keyboard focus indicator on the “Edit instance” button in a table row has a 1.435:1 contrast ratio in High Contrast Desert mode, which is below the required level.
1.4.12 Text Spacing AA Supports
1.4.13 Content on Hover or Focus AA Supports
2.4.5 Multiple Ways AA Supports
2.4.6 Headings and Labels AA Supports
2.4.7 Focus Visible AA Supports
2.4.11 Focus Not Obscured (Minimum) AA Supports
2.5.7 Dragging Movements AA Partially Supports - In Microsoft Defender MDE Configuration Management – Endpoint Security Policies, the table in the Assignment wizard does not provide a single‑pointer alternative.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, table column header resizing does not have a single‑pointer alternative.- In Microsoft Defender MDE Vulnerability Management – Premium Baselines Assessment, the table headers in the Settings table do not have a single‑pointer alternative.
2.5.8 Target Size (Minimum) AA Supports
3.1.2 Language of Parts AA Supports
3.2.3 Consistent Navigation AA Supports
3.2.4 Consistent Identification AA Supports
3.3.3 Error Suggestion AA Supports
3.3.4 Error Prevention (Legal, Financial, Data) AA Not Applicable
3.3.8 Accessible Authentication (Minimum) AA Supports
4.1.3 Status Messages AA Partially Supports - In the Overview tab of the Device page and panel in Microsoft Defender, VoiceOver and NVDA do not announce the status message displayed after submitting the “Run Antivirus scan” dialog.
1.2.6 Sign Language (Prerecorded) AAA Not Evaluated
1.2.7 Extended Audio Description (Prerecorded) AAA Not Evaluated
1.2.8 Media Alternative (Prerecorded) AAA Not Evaluated
1.2.9 Audio-only (Live) AAA Not Evaluated
1.3.6 Identify Purpose AAA Not Evaluated
1.4.6 Contrast (Enhanced) AAA Not Evaluated
1.4.7 Low or No Background Audio AAA Not Evaluated
1.4.8 Visual Presentation AAA Not Evaluated
1.4.9 Images of Text (No Exception) AAA Not Evaluated
2.1.3 Keyboard (No Exception) AAA Not Evaluated
2.2.3 No Timing AAA Not Evaluated
2.2.4 Interruptions AAA Not Evaluated
2.2.5 Re-authenticating AAA Not Evaluated
2.2.6 Timeouts AAA Not Evaluated
2.3.2 Three Flashes AAA Not Evaluated
2.3.3 Animation from Interactions AAA Not Evaluated
2.4.8 Location AAA Not Evaluated
2.4.9 Link Purpose (Link Only) AAA Not Evaluated
2.4.10 Section Headings AAA Not Evaluated
2.4.12 Focus Not Obscured (Enhanced) AAA Not Evaluated
2.4.13 Focus Appearance AAA Not Evaluated
2.5.5 Target Size AAA Not Evaluated
2.5.6 Concurrent Input Mechanisms AAA Not Evaluated
3.1.3 Unusual Words AAA Not Evaluated
3.1.4 Abbreviations AAA Not Evaluated
3.1.5 Reading Level AAA Not Evaluated
3.1.6 Pronunciation AAA Not Evaluated
3.2.5 Change on Request AAA Not Evaluated
3.3.5 Help AAA Not Evaluated
3.3.6 Error Prevention (All) AAA Not Evaluated
3.3.9 Accessible Authentication (Enhanced) AAA Not Evaluated

Is this your product? If this report is out of date or misrepresented, we will correct or remove it. Contact us to claim this listing.

Get told when this changes

This report is dated January 13, 2026. An ACR can be quietly replaced at any time, and the published date is the only signal a buyer gets. We will email you when this one is updated.

Double opt-in — we email you once to confirm, and send nothing until you do. One-click unsubscribe on every message. We store your address and what you are watching, nothing else. Privacy.