You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/architecture.md
+17-15Lines changed: 17 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.date: 12/25/2022
9
9
10
10
The Microsoft Defender for IoT system is built to provide broad coverage and visibility from diverse data sources.
11
11
12
-
The following image shows how data can stream into Defender for IoT from network sensors and partner sources to provide a unified view of IoT/OT security. Defender for IoT in the Azure portal provides asset inventories, vulnerability assessments, and continuous threat monitoring.
12
+
The following image shows how data can stream into Defender for IoT from network sensors and third-party sources to provide a unified view of IoT/OT security. Defender for IoT in the Azure portal provides asset inventories, vulnerability assessments, and continuous threat monitoring.
13
13
14
14
:::image type="content" source="media/architecture/system-architecture.png" alt-text="Diagram of the Defender for IoT OT system architecture." border="false":::
15
15
@@ -18,7 +18,7 @@ Defender for IoT connects to both cloud and on-premises components, and is built
18
18
Defender for IoT includes the following OT security monitoring components:
19
19
20
20
-**The Azure portal**, for cloud management and integration to other Microsoft services, such as Microsoft Sentinel.
21
-
-**OT network sensors**, to detect OT devices across your network. OT network sensors are deployed on either a virtual machine or a physical appliance, and configured as cloud-connected sensors, or fully on-premises sensors.
21
+
-**OT network sensors**, to detect OT devices across your network. OT network sensors are deployed on either a virtual machine or a physical appliance, and configured as cloud-connected sensors, or fully on-premises, locally-managed sensors.
22
22
-**An on-premises management console** for centralized OT site management in local, air-gapped environments.
23
23
24
24
## What is a Defender for IoT committed device?
@@ -29,7 +29,7 @@ Defender for IoT includes the following OT security monitoring components:
29
29
30
30
OT network sensors discover and continuously monitor network traffic across your OT devices.
31
31
32
-
- Network sensors are purpose-built for OT networks. They connect to a SPAN port or network TAP and can provide visibility into risks within minutes of connecting to the network.
32
+
- Network sensors are purpose-built for OT networks and connect to a SPAN port or network TAP. OT network sensors can provide visibility into risks within minutes of connecting to the network.
33
33
34
34
- Network sensors use OT-aware analytics engines and Layer-6 Deep Packet Inspection (DPI) to detect threats, such as fileless malware, based on anomalous or unauthorized activity.
35
35
@@ -51,55 +51,57 @@ When you have a cloud connected OT network sensor:
51
51
52
52
In contrast, when working with locally managed sensors:
53
53
54
-
- View any data for a specific sensor from the sensor console. For a unified view of all information detected by several sensors, use an on-premises management console. For more information, see [Manage sensors from the management console](how-to-manage-sensors-from-the-on-premises-management-console.md).
54
+
- View any data for a specific sensor from the sensor console. For a unified view of all information detected by several sensors, use an on-premises management console.
55
55
56
56
- You must manually upload any threat intelligence packages to locally managed sensors.
57
57
58
58
- Sensor names can be updated in the sensor console.
59
59
60
+
For more information, see [Manage OT sensors from the sensor console](how-to-manage-individual-sensors.md) and [Manage OT sensors from the management console](how-to-manage-sensors-from-the-on-premises-management-console.md).
60
61
61
62
### Analytics engines on OT network sensors
62
63
63
64
OT network sensors analyze ingested data using built-in analytics engines, and trigger alerts based on both real-time and pre-recorded traffic.
64
65
65
66
Analytics engines provide machine learning and profile analytics, risk analysis, a device database and set of insights, threat intelligence, and behavioral analytics.
66
67
67
-
For example, the **policy violation detection** engine models industry control system (ICS) networks and alerts users of any deviation from baseline behavior. For example, deviations might include unauthorized use of specific function codes, access to specific objects, or changes to device configuration.
68
+
For example, the **policy violation detection** engine models industry control system (ICS) networks and alerts users of any deviation from baseline behavior. Deviations might include unauthorized use of specific function codes, access to specific objects, or changes to device configuration.
68
69
69
-
Since many detection algorithms were built for IT, rather than OT, networks, the extra baseline for ICS networks helps to shorten the systems learning curve for new detections.
70
+
Since many detection algorithms were built for IT, rather than OT networks, the extra baseline for ICS networks helps to shorten the system's learning curve for new detections.
70
71
71
72
OT network sensors include the following analytics engines:
72
73
73
74
|Name |Description |
74
75
|---------|---------|
75
76
|**Protocol violation detection engine**| Identifies the use of packet structures and field values that violate ICS protocol specifications. <br><br>For example, Modbus exceptions or the initiation of an obsolete function code alerts. |
76
77
|**Industrial malware detection engine**| Identifies behaviors that indicate the presence of known malware, such as Conficker, Black Energy, Havex, WannaCry, NotPetya, and Triton. |
77
-
|**Anomaly detection engine**| Detects unusual machine-to-machine (M2M) communications and behaviors. <br><br>This engine models ICS networks and therefore requires a shorter learning period than analytics developed for IT, and detects anomalies faster, with minimal false positives. <br><br>For example, Excessive SMB sign-in attempts, and PLC Scan Detected alerts. |
78
+
|**Anomaly detection engine**| Detects unusual machine-to-machine (M2M) communications and behaviors. <br><br>This engine models ICS networks and therefore requires a shorter learning period than analytics developed for IT. Anomalies are detected faster, with minimal false positives. <br><br>For example, Excessive SMB sign-in attempts, and PLC Scan Detected alerts. |
78
79
|**Operational incident detection**| Detects operational issues such as intermittent connectivity that can indicate early signs of equipment failure. <br><br> For example, the device might be disconnected (unresponsive), or the Siemens S7 stop PLC command was sent alerts. |
79
80
80
81
81
82
## Management options
82
83
83
84
Defender for IoT provides hybrid network support using the following management options:
84
85
85
-
-**The Azure portal**. Use the Azure portal as a single pane of glass to view all data ingested from your devices via cloud-connected network sensors. The Azure portal provides extra value, such as [workbooks](workbooks.md), [connections to Microsoft Sentinel](../../sentinel/iot-solution.md?bc=%2fazure%2fdefender-for-iot%2fbreadcrumb%2ftoc.json&tabs=use-out-of-the-box-analytics-rules-recommended&toc=%2fazure%2fdefender-for-iot%2forganizations%2ftoc.json), and more.
86
+
-**The Azure portal**. Use the Azure portal as a single pane of glass to view all data ingested from your devices via cloud-connected network sensors. The Azure portal provides extra value, such as [workbooks](workbooks.md), [connections to Microsoft Sentinel](iot-solution.md), [security recommendations](recommendations.md), and more.
86
87
87
88
Also use the Azure portal to obtain new appliances and software updates, onboard and maintain your sensors in Defender for IoT, and update threat intelligence packages. For example:
88
89
89
90
:::image type="content" source="media/architecture/portal.png" alt-text="Screenshot of the Defender for I O T default view on the Azure portal."lightbox="media/architecture/portal.png":::
90
91
91
-
-**The sensor console**. You can also view detections for devices connected to a specific sensor from the sensor's console. Use the sensor console to view a network map for devices detected by that sensor, forward sensor information to partner systems, and more. For example:
92
+
-**The OT sensor console**. View detections for devices connected to a specific OT sensor from the sensor's console. Use the sensor console to view a network map for devices detected by that sensor, a timeline of all events that occur on the sensor, forward sensor information to partner systems, and more. For example:
92
93
93
94
:::image type="content" source="media/release-notes/new-interface.png" alt-text="Screenshot that shows the updated interface." lightbox="media/release-notes/new-interface.png":::
94
95
95
-
-**The on-premises management console**. In air-gapped environments, you can get a central view of data from all of your sensors from an on-premises management console. The on-premises management console also provides extra maintenance tools and reporting features.
96
+
-**The on-premises management console**. In air-gapped environments, you can get a central view of data from all of your sensors from an on-premises management console. The on-premises management console also lets you organize your network into separate sites and zones to support a [Zero Trust](/security/zero-trust/) mindset, and provides extra maintenance tools and reporting features.
96
97
97
98
## Next steps
98
99
99
-
For OT environments, understand the supported methods for connecting network sensors to Defender for IoT.
100
+
> [!div class="nextstepaction"]
101
+
> [Understand OT sensor connection methods](architecture-connections.md)
100
102
101
-
For more information, see:
103
+
> [!div class="nextstepaction"]
104
+
> [Connect OT sensors to Microsoft Defender for IoT](connect-sensors.md)
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/getting-started.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,26 +37,26 @@ This procedure describes how to add a trial Defender for IoT plan for OT network
37
37
38
38
**To add your plan**:
39
39
40
-
1. In the Azure portal, go to **Defender for IoT**> **Plans and pricing**and select**Add plan**.
40
+
1. In the Azure portal, go to **Defender for IoT**and select **Plans and pricing**>**Add plan**.
41
41
42
42
1. In the **Plan settings** pane, define the following settings:
43
43
44
-
-**Subscription**: Select the Azure subscription where you want to add a plan. You'll need a [Security admin](/azure/role-based-access-control/built-in-roles#security-admin), [Contributor](/azure/role-based-access-control/built-in-roles#contributor), or [Owner](/azure/role-based-access-control/built-in-roles#owner) role for the subscription.
44
+
-**Subscription**: Select the Azure subscription where you want to add a plan. You'll need a [Security admin](/azure/role-based-access-control/built-in-roles#security-admin), [Contributor](/azure/role-based-access-control/built-in-roles#contributor), or [Owner](/azure/role-based-access-control/built-in-roles#owner) role for the selected subscription.
45
45
46
46
> [!TIP]
47
-
> If your subscription isn't listed, check your account details and confirm your permissions with the subscription owner.
47
+
> If your subscription isn't listed, check your account details and confirm your permissions with the subscription owner. Also make sure that you have the right subscriptions selected in your Azure settings > **Directories + subscriptions** page.
48
48
49
49
-**Price plan**: For the sake of this quickstart, select **Trial - 30 days - 1000 assets limit**.
50
50
51
51
For example:
52
52
53
53
:::image type="content" source="media/getting-started/ot-trial.png" alt-text="Screenshot of adding a plan for OT networks to your subscription.":::
54
54
55
-
1. Select **Next** to review your selections.
55
+
1. Select **Next** to review your selections on the **Review and purchase** tab.
56
56
57
-
1.Select the **I accept the terms and conditions** option, and then select**Purchase**.
57
+
1.On the **Review and purchase** tab, select the **I accept the terms and conditions** option >**Purchase**.
58
58
59
-
Your new plan is listed under the relevant subscription in the **Plans**grid. For more information, see [Manage your subscriptions](how-to-manage-subscriptions.md).
59
+
Your new plan is listed under the relevant subscription in the on the **Plans and pricing**> **Plans** page. For more information, see [Manage your subscriptions](how-to-manage-subscriptions.md).
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-manage-individual-sensors.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Manage individual sensors
3
-
description: Learn how to manage individual sensors, including managing activation files, certificates, performing backups, and updating a standalone sensor.
2
+
title: Manage OT sensors from the sensor console - Microsoft Defender for IoT
3
+
description: Learn how to manage individual Microsoft Defender for IoT OT network sensors directly from the sensor's console.
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-manage-sensors-from-the-on-premises-management-console.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,11 @@
1
1
---
2
-
title: Manage sensors from the on-premises management console
3
-
description: Learn how to manage sensors from the management console, including updating sensor versions, pushing system settings to sensors, managing certificates, and enabling and disabling engines on sensors.
2
+
title: Manage OT sensors from the on-premises management console
3
+
description: Learn how to manage OT sensors from the on-premises management console, including updating sensor versions, pushing system settings to sensors, managing certificates, and enabling and disabling engines on sensors.
4
4
ms.date: 06/02/2022
5
5
ms.topic: how-to
6
6
---
7
7
8
-
# Manage sensors from the management console
8
+
# Manage sensors from the on-premises management console
9
9
10
10
This article describes how to manage OT sensors from an on-premises management console, such as pushing system settings to individual sensors, or enabling or disabling specific engines on your sensors.
0 commit comments