You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|Smart facility devices | Doors, fire alarms, elevators, turnstiles, HVAC systems |
76
-
-->
77
59
*Unclassified* devices are devices that don't have an out-of-the-box category defined.
78
60
79
61
## Unauthorized devices
@@ -104,7 +86,7 @@ The following table lists the columns available in the Defender for IoT device i
104
86
105
87
|Name |Description
106
88
|---------|---------|
107
-
|**Authorization**/ **Is Authorized*** |Editable. Determines whether or not the device is marked as *authorized*. This value may need to change as the device security changes. |
89
+
|**Authorization** * |Editable. Determines whether or not the device is marked as *authorized*. This value may need to change as the device security changes. |
108
90
|**Business Function**| Editable. Describes the device's business function. |
109
91
|**Class**| Editable. The device's class. <br>Default: `IoT`|
110
92
|**Data source**| The source of the data, such as a micro agent, OT sensor, or Microsoft Defender for Endpoint. <br>Default: `MicroAgent`|
@@ -113,106 +95,43 @@ The following table lists the columns available in the Defender for IoT device i
113
95
|**Firmware model**| The device's firmware model.|
114
96
|**Firmware vendor**| Editable. The vendor of the device's firmware. |
115
97
|**Firmware version** * |Editable. The device's firmware version. |
116
-
|**First seen** / **Discovered** * | The date and time the device was first seen. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format.|
117
-
|**Hardware Vendor**|<!--missing from columns--> Editable. The device's hardware vendor. |
98
+
|**First seen** * | The date and time the device was first seen. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. On the OT sensor, shown as **Discovered**.|
118
99
|**Importance**| Editable. The device's important level: `Low`, `Medium`, or `High`. |
119
100
|**IPv4 Address**| The device's IPv4 address. |
120
101
|**IPv6 Address**| The device's IPv6 address.|
121
102
|**Last activity** * | The date and time the device last sent an event through to Azure or to the OT sensor, depending on where you're viewing the device inventory. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. |
122
103
|**Location**| Editable. The device's physical location. |
123
104
|**MAC Address** * | The device's MAC address. |
124
-
|**Model**/ **Hardware model** *| Editable The device's hardware model. |
105
+
|**Model** *| Editable The device's hardware model. |
125
106
|**Name** * | Mandatory, and editable. The device's name as the sensor discovered it, or as entered by the user. |
126
107
|**OS architecture**| Editable. The device's operating system architecture. |
127
108
|**OS distribution**| Editable. The device's operating system distribution, such as Android, Linux, and Haiku. |
128
-
|**OS platform**/ **Operating System** * | Editable. The device's operating system, if detected. |
109
+
|**OS platform*** | Editable. The device's operating system, if detected. On the OT sensor, shown as **Operating System**.|
129
110
|**OS version**| Editable. The device's operating system version, such as Windows 10 or Ubuntu 20.04.1. |
130
-
|**PLC mode** *| The device's PLC operating mode, including both the *Key* state (physical / logical) and the *Run* state (logical). If both states are the same, then only one state is listed.<br><br>- Possible *Key* states include: `Run`, `Program`, `Remote`, `Stop`, `Invalid`, and `Programming Disabled`. <br><br>- Possible *Run* states are `Run`, `Program`, `Stop`, `Paused`, `Exception`, `Halted`, `Trapped`, `Idle`, or `Offline`. |
131
-
|**Programming device**/ **Is Programming device** * | Editable. Defines whether the device is defined as a *Programming Device*, performing programming activities for PLCs, RTUs, and controllers, which are relevant to engineering stations. |
111
+
|**PLC mode** *| The device's PLC operating mode, including both the *Key* state (physical / logical) and the *Run* state (logical). If both states are the same, then only one state is listed.<br><br>- Possible *Key* states include: `Run`, `Program`, `Remote`, `Stop`, `Invalid`, and `Programming Disabled`. <br><br>- Possible *Run* states are `Run`, `Program`, `Stop`, `Paused`, `Exception`, `Halted`, `Trapped`, `Idle`, or `Offline`. |
112
+
|**Programming device** * | Editable. Defines whether the device is defined as a *Programming Device*, performing programming activities for PLCs, RTUs, and controllers, which are relevant to engineering stations. |
132
113
|**Protocols** *| The protocols that the device uses. |
133
114
|**Purdue level**| Editable. The Purdue level in which the device exists.|
134
-
|**Scanner device**/ **Is Known as Scanner** * | Editable. Defines whether the device performs scanning-like activities in the network. |
135
-
|**Sensor** / **Appliance**| The sensor the device is connected to. |
136
-
|**Serial number**/ **Serial***| The device's serial number. |
115
+
|**Scanner device** * | Editable. Defines whether the device performs scanning-like activities in the network. |
116
+
|**Sensor**| The sensor the device is connected to. |
117
+
|**Serial number** *| The device's serial number. |
137
118
|**Site**| The device's site. <br><br>All Enterprise IoT sensors are automatically added to the **Enterprise network** site. |
138
-
|**Slots**/ **Slot** *| The number of slots the device has. <!--unclear for slot on sensor/cm-->|
119
+
|**Slots**| The number of slots the device has. |
139
120
|**Subtype**| Editable. The device's subtype, such as *Speaker* or *Smart TV*. <br>**Default**: `Managed Device`|
140
121
|**Tags**| Editable. The device's tags. |
141
122
|**Type** * | Editable. The device type, such as *Communication* or *Industrial*. <br>**Default**: `Miscellaneous`|
142
123
|**Vendor** *| The name of the device's vendor, as defined in the MAC address. |
143
-
|**VLAN**/ **VLAN Ids** * | The device's VLAN. |
124
+
|**VLAN** * | The device's VLAN. |
144
125
|**Zone**| The device's zone. |
145
126
146
-
<!--
147
-
148
-
The following additional columns are available on OT sensors only:
149
-
150
-
|**DHCP Address** | The device's DHCP address. |
151
-
|**FQDN** | The device's FQDN value |
152
-
|**FQDN Last Lookup Time** | The device's FQDN lookup time |
153
-
| **Groups** | The device groups that include the device, as [defined on the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#create-a-custom-device-group-from-an-ot-sensor-device-map). |- | ✔ | ✔ |
154
-
| **IP Address** | The device's IP address. |- | ✔ | ✔ |
155
-
| Module address | - | ✔ |✔ |
156
-
| **Rack** | The number of device racks. | - | ✔ | ✔|
157
-
| **Unacknowledged Alerts** | The number of unacknowledged alerts associated with the device. |- | ✔ | ✔ |
|**Authorization** / **Is Authorized** |Editable. Determines whether or not the device is marked as *authorized*. This value may need to change as the device security changes. |✔ | ✔ | ✔ |
164
-
|**Business Function** | Editable. Describes the device's business function. |✔ | - | - |
165
-
| **Business Unit** | The device's business unit, as [defined on the on-premises management console](how-to-activate-and-set-up-your-on-premises-management-console.md#create-enterprise-zones). |- | - | ✔ |
| **Data source** | The source of the data, such as a micro agent, OT sensor, or Microsoft Defender for Endpoint. <br>Default: `MicroAgent`|✔ | - | - |
| **First seen** / **Discovered** | The date and time the device was first seen. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. | ✔ | ✔ | ✔ |
176
-
| **FQDN** | The device's FQDN value |- | ✔ | - |
177
-
| **FQDN Last Lookup Time** | The device's FQDN lookup time |- | ✔ | - |
178
-
| **Groups** | The device groups that include the device, as [defined on the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#create-a-custom-device-group-from-an-ot-sensor-device-map). |- | ✔ | ✔ |
| **Last activity** | The date and time the device last sent an event through to Azure or to the OT sensor, depending on where you're viewing the device inventory. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. | ✔ | ✔ | ✔ |
| **Name** | Mandatory, and editable. The device's name as the sensor discovered it, or as entered by the user. |✔ | ✔ | ✔ |
190
-
| **OS architecture** | Editable. The device's operating system architecture. |✔ | - | - |
191
-
| **OS distribution** | Editable. The device's operating system distribution, such as Android, Linux, and Haiku. |✔ | - | - |
192
-
| **OS platform** / **Operating System** | Editable. The device's operating system, if detected. |✔ | ✔ | ✔ |
193
-
| **OS version** | Editable. The device's operating system version, such as Windows 10 or Ubuntu 20.04.1. |✔ | - | - |
194
-
| **PLC mode** | The device's PLC operating mode, including both the *Key* state (physical / logical) and the *Run* state (logical). Possible *Key* states include: `Run`, `Program`, `Remote`, `Stop`, `Invalid`, and `Programming Disabled`. Possible *Run* states are `Run`, `Program`, `Stop`, `Paused`, `Exception`, `Halted`, `Trapped`, `Idle`, or `Offline`. If both states are the same, then only one state is listed. |✔ | ✔ | ✔ |
195
-
|**Programming device** / **Is Programming device** | Editable. Defines whether the device is defined as a *Programming Device*, performing programming activities for PLCs, RTUs, and controllers, which are relevant to engineering stations. |✔ | ✔ | ✔ |
196
-
| **Protocols** | The protocols that the device uses. |✔ | ✔ | ✔ |
197
-
| **Purdue level** | Editable. The Purdue level in which the device exists. |✔ | - | - |
198
-
| **Rack** | The number of device racks. | - | ✔ | ✔|
199
-
|**Region**| The device's region, as [defined on the on-premises management console](how-to-activate-and-set-up-your-on-premises-management-console.md#set-up-a-site) | - | - | ✔ |
200
-
| **Scanner device** / **Is Known as Scanner** | Editable. Defines whether the device performs scanning-like activities in the network. |✔ | ✔ | ✔ |
201
-
| **Sensor** / **Appliance** | The sensor the device is connected to. |✔ | - | ✔ |
202
-
| **Serial number** / **Serial**| The device's serial number. | ✔ | ✔|✔ |
203
-
| **Site** | The device's site. <br><br>All Enterprise IoT sensors are automatically added to the **Enterprise network** site.|✔ | - | ✔ |
204
-
| **Slots** / **Slot** | The number of slots the device has. |✔ |✔|✔ |
205
-
| **Subtype** | Editable. The device's subtype, such as *Speaker* or *Smart TV*. <br>**Default**: `Managed Device` |✔ | - | - |
The following columns are available on OT sensors only:
215
128
129
+
- The device's **DHCP Address**
130
+
- The device's **FQDN** address and **FQDN Last Lookup Time**
131
+
- The device **Groups** that include the device, as [defined on the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#create-a-custom-device-group-from-an-ot-sensor-device-map)
132
+
- The device's **Module address**
133
+
- The device's **Rack** and **Slot**
134
+
- The number of **Unacknowledged Alerts** alerts associated with the device
216
135
217
136
> [!NOTE]
218
137
> The additional **Agent type** and **Agent version** columns are used for by device builders. For more information, see [Microsoft Defender for IoT for device builders documentation](/azure/defender-for-iot/device-builders/).
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-work-with-the-sensor-device-map.md
+11-7Lines changed: 11 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -45,15 +45,15 @@ To view devices across multiple sensors in a zone, you'll also need an on-premis
45
45
- The number of devices grouped in a subnet in an IT network, if relevant. This number of devices is shown in a black circle.
46
46
- Whether the device is newly detected or unauthorized.
47
47
48
-
1. Right-click a specific device and select **View properties** to drill down further to a [device details page](how-to-investigate-sensor-detections-in-a-device-inventory.md#view-the-device-inventory). <!--validate this step-->
48
+
1. Right-click a specific device and select **View properties** to drill down further to the **Map View** tab on the device's [device details page](how-to-investigate-sensor-detections-in-a-device-inventory.md#view-the-device-inventory).
49
49
50
50
### Modify the OT sensor map display
51
51
52
52
Use any of the following map tools to modify the data shown and how it's displayed:
53
53
54
54
|Name |Description |
55
55
|---------|---------|
56
-
|**Refresh map**| Select to refresh the map with updated data. <!--how often does this refresh automatically?-->|
56
+
|**Refresh map**| Select to refresh the map with updated data. |
57
57
|**Notifications**| Select to view [device notifications](#manage-device-notifications). |
58
58
|**Search by IP / MAC**| Filter the map to display only devices connected to a specific IP or MAC address. |
59
59
|**Multicast/broadcast**| Select to edit the filter that shows or hides multicast and broadcast devices. By default, multicast and broadcast traffic is hidden. |
@@ -75,15 +75,19 @@ To see device details, select a device and expand the device details pane on the
75
75
76
76
77
77
### View IT subnets from an OT sensor device map
78
-
<!--cant' validate this procedure-->
79
78
80
79
By default, IT devices are automatically aggregated by [subnet](how-to-control-what-traffic-is-monitored.md#configure-subnets), so that the map focuses on OT and ICS networks.
81
80
82
81
**To expand an IT subnet**:
83
82
84
83
1. Sign into your OT sensor and select **Device map**.
85
-
1. Right-click the icon on the map that represents a specific IT network and select **Expand Network**.
86
-
1. In the confirmation box that appears, select **OK**.
84
+
1. Locate your subnet on the map. You might need to zoom in on the map to view a subnet icon, which looks like several machines inside a box. For example:
85
+
86
+
:::image type="content" source="media/how-to-work-with-maps/expand-collapse-subnets.png" alt-text="Screenshot of a subnet device on the device map.":::
87
+
88
+
1. Right-click the subnet device on the map and **Expand Network**.
89
+
90
+
1. In the confirmation message that appears above the map, select **OK**.
87
91
88
92
**To collapse an IT subnet:**
89
93
@@ -108,7 +112,7 @@ In addition to OT sensor's [built-in device groups](#built-in-device-map-groups)
108
112
Use one of the following options to import and export device data:
109
113
110
114
-**Import Devices**. Select to import devices from a pre-configured .CSV file.
111
-
-**Export Devices**. Select to export all currently displayed devices, with full details, to a .CSV file.<!--is this correct?-->
115
+
-**Export Devices**. Select to export all currently displayed devices, with full details, to a .CSV file.
112
116
-**Export Device Summary**. Select to export a high level summary of all currently displayed devices to a .CSV file.
113
117
114
118
@@ -203,7 +207,7 @@ On the on-premises management console, zone maps show all network elements relat
203
207
204
208
**To view a zone map**:
205
209
206
-
1. Sign into an on-premises management console and select **Site Management** > **View Zone Map** for the zone you want to view. For example:<!--fix image-->
210
+
1. Sign into an on-premises management console and select **Site Management** > **View Zone Map** for the zone you want to view. For example:
207
211
208
212
:::image type="content" source="media/how-to-work-with-asset-inventory-information/default-region-to-default-business-unit-v2.png" alt-text="Default region to default business unit." lightbox="media/how-to-work-with-asset-inventory-information/default-region-to-default-business-unit-v2.png":::
0 commit comments