You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-troubleshoot-sensor.md
+11-7Lines changed: 11 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -247,7 +247,7 @@ When signing into a pre-configured sensor for the first time, you'll need to per
247
247
1. Select **Next**, and your user, and a system-generated password for your OT sensor will then appear.
248
248
249
249
> [!NOTE]
250
-
> When you sign in to a sensor for the first time, it's linked to your Azure subscription, which you'll need if you need to recover the password for the *admin* user. For more information, see [Recover privileged access to a sensor](manage-users-sensor.md#recover-privileged-access-to-a-sensor).
250
+
> When you sign in to a sensor for the first time, it's linked to your Azure subscription, which you need if you need to recover the password for the *admin* user. For more information, see [Recover privileged access to a sensor](manage-users-sensor.md#recover-privileged-access-to-a-sensor).
251
251
252
252
## Investigate a lack of traffic
253
253
@@ -257,7 +257,7 @@ An indicator appears at the top of the console when the sensor recognizes that t
257
257
258
258
When a new sensor is deployed or a sensor is working slowly or not showing any alerts, you can check system performance.
259
259
260
-
1. Sign in to the sensor and select **Overview**. Make sure that **PPS** is greater than 0, and that **Devices** are being discovered.
260
+
1. Sign in to the sensor and select **Overview**. Make sure that **PPS** is greater than 0, and that **Devices** are being discovered.
261
261
1. In the **Data Mining** page, generate a report.
262
262
1. In the **Trends & Statistics** page, create a dashboard.
263
263
1. In the **Alerts** page, check that the alert was created.
@@ -289,7 +289,7 @@ For more information, see:
289
289
290
290
## Connect the sensor to NTP
291
291
292
-
You can configure a standalone sensor and a OT sensor console, with the sensors related to it, to connect to NTP.
292
+
You can configure a standalone sensor and an OT sensor console, with the sensors related to it, to connect to NTP.
293
293
294
294
> [!TIP]
295
295
> When you're ready to start managing your OT sensor settings at scale, define NTP settings from the Azure portal. Once you apply settings from the Azure portal, settings on the sensor console are read-only. For more information, see [Configure OT sensor settings from the Azure portal (Public preview)](configure-sensor-settings-portal.md).
@@ -319,7 +319,7 @@ For more information on how to clear system data, see [Clear OT sensor data](how
319
319
320
320
## Export logs from the sensor console for troubleshooting
321
321
322
-
For further troubleshooting, you may want to export logs to send to the support team, such as database or operating system logs.
322
+
For further troubleshooting, you might want to export logs to send to the support team, such as database or operating system logs.
323
323
324
324
**To export log data**:
325
325
@@ -348,15 +348,19 @@ For further troubleshooting, you may want to export logs to send to the support
348
348
> [!NOTE]
349
349
> Support ticket diagnostics can be downloaded from the sensor console and then uploaded directly to the support team in the Azure portal. For more information on downloading diagnostic logs, see [Download a diagnostics log for support](how-to-troubleshoot-sensor.md#download-a-diagnostics-log-for-support).
350
350
351
-
## configure a backup server after false positive alert
351
+
## Configure a backup server after false positive alert
352
352
<!-- what should the title be?-->
353
353
354
-
If a false positive alert is produced the backup server might be misconfiigured. In order to correct this:
354
+
When a false positive alert is produced the backup server might be misconfigured. In confirm the correct settings:
355
355
356
356
1. In the sensor console, go to **System settings** > **Sensor management** > **Advanced configurations**.
357
+
357
358
1. Select the **Global** category. Ensure that **is_reduce_backup_malware_enabled=1** (Note: **true** is also an acceptable parameter).
358
-
1. Select the **Vulnerability assessment** category. Ensure **backup_servers** contains the back up server device's IP address.
359
+
360
+
1. Select the **Vulnerability assessment** category. Ensure **backup_servers** contains the backup server device's IP address.
361
+
359
362
1. Select the **Ports** category. Ensure that **backup_known_ports** contains the list of port(s) used for the backup server.
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/whats-new.md
+11-3Lines changed: 11 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: What's new in Microsoft Defender for IoT
3
3
description: This article describes new features available in Microsoft Defender for IoT, including both OT and Enterprise IoT networks, and both on-premises and in the Azure portal.
4
4
ms.topic: whats-new
5
-
ms.date: 10/14/2024
5
+
ms.date: 04/08/2025
6
6
ms.custom: enterprise-iot
7
7
---
8
8
@@ -22,6 +22,16 @@ Features released earlier than nine months ago are described in the [What's new
22
22
23
23
The legacy on-premises management console won't be available for download after **January 1st, 2025**. We recommend transitioning to the new architecture using the full spectrum of on-premises and cloud APIs before this date. For more information, see [on-premises management console retirement](ot-deploy/on-premises-management-console-retirement.md).
24
24
25
+
## April 2025
26
+
27
+
|Service area |Updates |
28
+
|---------|---------|
29
+
|**OT networks**| - [Configure a backup server after false positive alert](#configure-a-backup-server-after-false-positive-alert)<br> |
30
+
31
+
### Configure a backup server after false positive alert
32
+
33
+
When a false positive alert is produced, the backup server might need to be reconfigured. For more information, see [configure a backup server after false positive alert](how-to-troubleshoot-sensor.md#configure-a-backup-server-after-false-positive-alert).
34
+
25
35
## March 2025
26
36
27
37
|Service area |Updates |
@@ -32,8 +42,6 @@ The legacy on-premises management console won't be available for download after
32
42
33
43
The "Unauthorized Internet Connectivity Detected" alert details now includes the URL from which the suspicious connection initiated, helping SOC analysts assess and respond to incidents more effectively.
34
44
35
-
:::image type="content" source="media/whats-new/url-parameters.png" alt-text="Screenshot of URL information in alert details." lightbox="media/whats-new/url-parameters.png":::
36
-
37
45
### Improved RDP brute force detection
38
46
39
47
The “Excessive Number of Sessions” alert now includes support by default to a remote desktop protocol (RDP) port, enhancing visibility into potential brute-force attacks and unauthorized access attempts.
0 commit comments