Skip to content

Commit 38c41c1

Browse files
authored
Merge branch 'main' into godonnell-update-gtd-portal-instructions-2
2 parents 5f45f90 + 210be63 commit 38c41c1

File tree

14 files changed

+103
-23
lines changed

14 files changed

+103
-23
lines changed

articles/active-directory/develop/v2-protocols-oidc.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Sign in Azure AD users by using the Microsoft identity platform's i
44
author: OwenRichards1
55
manager: CelesteDG
66
ms.custom: aaddev, identityplatformtop40
7-
ms.date: 05/30/2023
7+
ms.date: 09/13/2023
88
ms.author: owenrichards
99
ms.reviewer: ludwignick
1010
ms.service: active-directory
@@ -34,6 +34,9 @@ ID tokens aren't issued by default for an application registered with the Micros
3434

3535
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
3636
1. Browse to **Identity** > **Applications** > **App registrations** > *\<your application\>* > **Authentication**.
37+
1. Under **Platform configurations**, select **Add a platform**.
38+
1. In the pane that opens, select the appropriate platform for your application. For example, select **Web** for a web application.
39+
1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.
3740
1. Under **Implicit grant and hybrid flows**, select the **ID tokens (used for implicit and hybrid flows)** checkbox.
3841

3942
Or:

articles/defender-for-iot/organizations/concept-supported-protocols.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Protocols supported by Microsoft Defender for IoT
33
description: Learn about protocols that Microsoft Defender for IoT supports.
4-
ms.date: 01/30/2023
4+
ms.date: 08/31/2023
55
ms.topic: concept-article
66
ms.custom: enterprise-iot
77
---
@@ -23,25 +23,27 @@ OT network sensors can detect the following protocols when identifying assets an
2323
|**DNP. org** | DNP3 |
2424
|**Emerson** | DeltaV<br> DeltaV - Discovery<br> Emerson OpenBSI/BSAP<br> Ovation DCS ADMD<br>Ovation DCS DPUSTAT<br> Ovation DCS SSRPC |
2525
|**Emerson Fischer** | ROC |
26-
|**GE** | Bentley Nevada (System 1 / BN3500)<br>ClassicSDI (MarkVle) <br> EGD<br> GSM (GE MarkVI and MarkVIe)<br> InterSite<br> SDI (MarkVle) <br> SRTP (GE)<br> GE_CMP |
26+
|**GE** | ADL (MarkVIe) <br>Bentley Nevada (System 1 / BN3500)<br>ClassicSDI (MarkVle) <br> EGD<br> GSM (GE MarkVI and MarkVIe)<br> InterSite<br> SDI (MarkVle) <br> SRTP (GE)<br> GE_CMP |
2727
|**Generic Applications** | Active Directory<br> RDP<br> Teamviewer<br> VNC<br> |
2828
|**Honeywell** | ENAP<br> Experion DCS CDA<br> Experion DCS FDA<br> Honeywell EUCN <br> Honeywell Discovery |
2929
|**IEC** | Codesys V3<br>IEC 60870-5-7 (IEC 62351-3 + IEC 62351-5)<br> IEC 60870-5-104<br> IEC 60870-5-104 ASDU_APCI<br> IEC 60870 ICCP TASE.2<br> IEC 61850 GOOSE<br> IEC 61850 MMS<br> IEC 61850 SMV (SAMPLED-VALUES)<br> LonTalk (LonWorks) |
3030
|**IEEE** | LLC<br> STP<br> VLAN |
3131
|**IETF** | ARP<br> DHCP<br> DCE RPC<br> DNS<br> FTP (FTP_ADAT<br> FTP_DATA)<br> GSSAPI (RFC2743)<br> HTTP<br> ICMP<br> IPv4<br> IPv6<br> LLDP<br> MDNS<br> NBNS<br> NTLM (NTLMSSP Auth Protocol)<br> RPC<br> SMB / Browse / NBDGM<br> SMB / CIFS<br> SNMP<br> SPNEGO (RFC4178)<br> SSH<br> Syslog<br> TCP<br> Telnet<br> TFTP<br> TPKT<br> UDP |
3232
|**ISO** | CLNP (ISO 8473)<br> COTP (ISO 8073)<br> ISO Industrial Protocol<br> MQTT (IEC 20922) |
33+
| **Jenesys** |FOX <br>Niagara |
3334
|**Medical** |ASTM<br> HL7 |
3435
|**Microsoft** | Horizon community dissectors<br> Horizon proprietary dissectors (developed by customers) |
3536
|**Mitsubishi** | Melsoft / Melsec (Mitsubishi Electric) |
36-
|**Omron** | FINS |
37-
|**OPC** | UA |
37+
|**Omron** | FINS <br>HTTP |
38+
|**OPC** | AE <br>Common <br> DA <br>HDA <br> UA |
3839
|**Oracle** | TDS<br> TNS |
3940
|**Rockwell Automation** | CSP2<br> ENIP<br> EtherNet/IP CIP (including Rockwell extension)<br> EtherNet/IP CIP FW version 27 and above |
4041
|**Samsung** | Samsung TV |
4142
|**Schneider Electric** | Modbus/TCP<br> Modbus TCP–Schneider Unity Extensions<br> OASYS (Schneider Electric Telvant)<br> Schneider TSAA |
4243
|**Schneider Electric / Invensys** | Foxboro Evo<br> Foxboro I/A<br> Trident<br> TriGP<br> TriStation |
4344
|**Schneider Electric / Modicon** | Modbus RTU |
4445
|**Schneider Electric / Wonderware** | Wonderware Suitelink |
46+
| **SEL** | FTP <br> Telnet |
4547
|**Siemens** | CAMP<br> PCS7<br> PCS7 WinCC – Historian<br> Profinet DCP<br> Profinet I/O<br> Profinet Realtime<br> Siemens PHD<br> Siemens S7<br> Siemens S7 - Firmware and model extraction<br> Siemens S7 – key state<br> Siemens S7-Plus<br> Siemens SICAM<br> Siemens WinCC |
4648
|**Toshiba** |Toshiba Computer Link |
4749
|**Yokogawa** | Centum ODEQ (Centum / ProSafe DCS)<br> HIS Equalize<br> FA-M3<br> Vnet/IP |

articles/defender-for-iot/organizations/how-to-manage-device-inventory-for-organizations.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Manage your device inventory from the Azure portal
33
description: Learn how to view and manage OT and IoT devices (assets) from the Device inventory page in the Azure portal.
4-
ms.date: 05/17/2023
4+
ms.date: 08/27/2023
55
ms.topic: how-to
66
ms.custom: enterprise-iot
77
---
@@ -23,7 +23,7 @@ Use any of the following options to modify or filter the devices shown:
2323
|Option |Steps |
2424
|---------|---------|
2525
| **Sort devices** | Select a column header to sort the devices by that column. Select it again to change the sort direction. |
26-
|**Filter devices shown** | Either use the **Search** box to search for specific device details, or select **Add filter** to filter the devices shown. <br><br> In the **Add filter** box, define your filter by column name, operator, and value. Select **Apply** to apply your filter.<br><br> You can apply multiple filters at the same time. Search results and filters aren't saved when you refresh the **Device inventory** page. <br><br> The **Network location (Preview)** filter is on by default. |
26+
|**Filter devices shown** | Either use the **Search** box to search for specific device details, or select **Add filter** to filter the devices shown. <br><br> In the **Add filter** box, define your filter by column name, operator, and value. Select **Apply** to apply your filter.<br><br> You can apply multiple filters at the same time. Search results and filters aren't saved when you refresh the **Device inventory** page. <br><br> The **Last active time** and **Network location (Preview)** filters are on by default. |
2727
|**Modify columns shown** | Select **Edit columns** :::image type="icon" source="media/how-to-manage-device-inventory-on-the-cloud/edit-columns-icon.png" border="false":::. In the **Edit columns** pane:<br><br> - Select the **+ Add Column** button to add new columns to the grid.<br> - Drag and drop fields to change the columns order.<br>- To remove a column, select the **Delete** :::image type="icon" source="media/how-to-manage-device-inventory-on-the-cloud/trashcan-icon.png" border="false"::: icon to the right.<br>- To reset the columns to their default settings, select **Reset** :::image type="icon" source="media/how-to-manage-device-inventory-on-the-cloud/reset-icon.png" border="false":::. <br><br>Select **Save** to save any changes made. |
2828
| **Group devices** | From the **Group by** above the gird, select a category, such as **Class**, **Data source**, **Location**, **Purdue level**, **Site**, **Type**, **Vendor**, or **Zone**, to group the devices shown. Inside each group, devices retain the same column sorting. To remove the grouping, select **No grouping**. |
2929

articles/defender-for-iot/organizations/how-to-troubleshoot-sensor.md

Lines changed: 33 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
2-
title: Troubleshoot the sensor
3-
description: Troubleshoot your sensor to eliminate any problems you might be having.
4-
ms.date: 03/14/2023
2+
title: Troubleshoot the sensor | Microsoft Defender for IoT
3+
description: Learn how to troubleshoot your Microsoft Defender for IoT OT sensor.
4+
ms.date: 09/07/2023
55
ms.topic: troubleshooting
6+
#CustomerIntent: As a Defender for IoT sensor admin, I want to know how to troubleshoot sensor issues so that I can get it back online quickly.
67
---
78
# Troubleshoot the sensor
89

@@ -20,6 +21,35 @@ To perform the procedures in this article, make sure that you have:
2021

2122
- Access to the OT network sensor as a **Support** user. For more information, see [Default privileged on-premises users](roles-on-premises.md#default-privileged-on-premises-users).
2223

24+
## Check sensor - cloud connectivity issues
25+
26+
OT sensors automatically run connectivity checks to ensure that your sensor has access to all required endpoints. If a sensor isn't connected, an error is indicated in the Azure portal, on the **Sites and sensors** page, and on the sensor's **Overview** page. For example:
27+
28+
:::image type="content" source="media/release-notes/connectivity-error.png" alt-text="Screenshot of a connectivity error on the Overview page." lightbox="media/release-notes/connectivity-error.png":::```
29+
30+
Use the **Cloud connectivity troubleshooting** page in your OT sensor to learn more about the error that occurred and recommended mitigation actions you can take.
31+
32+
**To troubleshoot connectivity errors**, sign into your OT sensor and do one of the following:
33+
34+
- From the sensor's **Overview** page, select the **Troubleshoot*** link in the error at the top of the page
35+
- Select **System settings > Sensor management > Health and troubleshooting > Cloud connectivity troubleshooting**
36+
37+
The **Cloud connectivity troubleshooting** pane opens on the right. If the sensor is connected to the Azure portal, the pane indicates that **The sensor is connected to cloud successfully**. If the sensor isn't connected, a description of the issue and any mitigation instructions are listed instead. For example: <!--need new image-->
38+
39+
:::image type="content" source="media/how-to-troubleshoot-the-sensor-and-on-premises-management-console/connectivity-troubleshooting.png" alt-text="Screenshot of the Connectivity troubleshooting pane.":::
40+
41+
The **Cloud connectivity troubleshooting** pane covers the following types of issues:
42+
43+
|Issue |Description |
44+
|---------|---------|
45+
|**Errors establishing secure connections** | Occurs for SSL errors, which typically means that the sensor doesn't trust the certificate found. <br><br>This might occur due to an incorrect sensor time configuration, or using an SSL inspection service. SSL inspection services are often found in proxies and can lead to potential certificate errors. <br><br>For more information, see [Manage SSL/TLS certificates](how-to-manage-individual-sensors.md#manage-ssltls-certificates) and [Synchronize time zones on an OT sensor](how-to-manage-individual-sensors.md#synchronize-time-zones-on-an-ot-sensor).|
46+
|**General connection errors** | Occurs when the sensor can't connect with one or more required endpoints. <br><br>In such cases, ensure that all required endpoints are accessible from your sensor, and consider configuring more endpoints in your firewall. For more information, see [Provision sensors for cloud management](ot-deploy/provision-cloud-management.md). |
47+
|**Unreachable DNS server errors** | Occurs when the sensor can't perform name resolution due to an unreachable DNS server. In such cases, verify that your sensor can access the DNS server. For more information, see [Update the OT sensor network configuration](how-to-manage-individual-sensors.md#update-the-ot-sensor-network-configuration) |
48+
|**Proxy authentication issues** | Occurs when a proxy demands authentication, but no credentials, or incorrect credentials, are provided. <br><br>In such cases, make sure that you've configured the proxy credentials correctly. For more information, see [Update the OT sensor network configuration](how-to-manage-individual-sensors.md#update-the-ot-sensor-network-configuration). |
49+
|**Name resolution failures** | Occurs when the sensor can't perform name resolution for a specific endpoint. <br><br>In such cases, if your DNS server is reachable, make sure that the DNS server is configured on your sensor correctly. If the configuration is correct, we recommend reaching out to your DNS administrator. <br><br>For more information, see [Update the OT sensor network configuration](how-to-manage-individual-sensors.md#update-the-ot-sensor-network-configuration). |
50+
|**Unreachable proxy server errors** | Occurs when the sensor can't establish a connection with the proxy server. In such cases, confirm the reachability of your proxy server with your network team. <br><br>For more information, see [Update the OT sensor network configuration](how-to-manage-individual-sensors.md#update-the-ot-sensor-network-configuration). |
51+
52+
2353
## Check system health
2454

2555
Check your system health from the sensor.
-6.75 KB
Loading
-6.76 KB
Loading
Loading
311 KB
Loading

articles/defender-for-iot/organizations/release-notes.md

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: OT monitoring software versions - Microsoft Defender for IoT
33
description: This article lists Microsoft Defender for IoT on-premises OT monitoring software versions, including release and support dates and highlights for new features.
44
ms.topic: release-notes
5-
ms.date: 08/09/2023
5+
ms.date: 09/14/2023
66
---
77

88
# OT monitoring software versions
@@ -38,6 +38,7 @@ Cloud features may be dependent on a specific sensor version. Such features are
3838
| Version / Patch | Release date | Scope | Supported until |
3939
| ------- | ------------ | ----------- | ------------------- |
4040
| **23.1** | | | |
41+
| 23.1.3 | 09/2023 | Patch | 08/2024 |
4142
| 23.1.2 | 07/2023 | Major | 06/2024 |
4243
| **22.3** | | | |
4344
|22.3.10|07/2023|Patch|06/2024|
@@ -100,6 +101,17 @@ To understand whether a feature is supported in your sensor version, check the r
100101

101102
## Versions 23.1.x
102103

104+
### Version 23.1.3
105+
106+
**Release date**: 09/2023
107+
108+
**Supported until**: 08/2024
109+
110+
This version includes the following updates and enhancements:
111+
112+
- [Connectivity troubleshooting enhancements from the OT sensor](how-to-troubleshoot-sensor.md#check-sensor---cloud-connectivity-issues)
113+
- [Read Only users can access the Event Timeline](roles-on-premises.md)
114+
103115
### Version 23.1.2
104116

105117
**Release date**: 07/2023

articles/defender-for-iot/organizations/roles-on-premises.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: On-premises users and roles for Defender for IoT - Microsoft Defender for IoT
33
description: Learn about the on-premises user roles available for OT monitoring with Microsoft Defender for IoT network sensors and on-premises management consoles.
4-
ms.date: 09/19/2022
4+
ms.date: 08/27/2023
55
ms.topic: concept-article
66
---
77

@@ -44,7 +44,7 @@ Permissions applied to each role differ between the sensor and the on-premises m
4444
| **Control map zoom views** | - | - ||
4545
| **View alerts** ||||
4646
| **Manage alerts**: acknowledge, learn, and mute |- |||
47-
| **View events in a timeline** | - |||
47+
| **View events in a timeline** | |||
4848
| **Authorize devices**, known scanning devices, programming devices | - |||
4949
| **Merge and delete devices** |- |- ||
5050
| **View investigation data** ||||

0 commit comments

Comments
 (0)