Skip to content

Commit 42064e8

Browse files
committed
removing hidden text, handling open issues
1 parent a037afe commit 42064e8

File tree

4 files changed

+29
-106
lines changed

4 files changed

+29
-106
lines changed

articles/defender-for-iot/organizations/device-inventory.md

Lines changed: 18 additions & 99 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,6 @@ For more information, see:
4848

4949
Defender for IoT's device inventory supports the following device classes:
5050

51-
<!--danielle-->
5251
|Class |Device type examples |
5352
|---------|---------|
5453
|**Endpoint devices** | Workstations, servers, or mobile devices |
@@ -57,23 +56,6 @@ Defender for IoT's device inventory supports the following device classes:
5756
|**Network devices** | Switches, routers, controllers, or access points |
5857
|**OT devices** | Industrial and operational devices, such as PLCs, historian devices, HMIs, scales, pneumatic devices, or packaging systems |
5958

60-
<!--from excel sheet
61-
|Name |Examples |
62-
|---------|---------|
63-
|**Network devices** | |
64-
|**Endpoint devices** | Workstations, servers, or mobile devices |
65-
|**OT/IoT devices** | |
66-
|Audio and video devices | Smart TVs, speakers, digital signage, or headsets |
67-
|Communication devices | VoIP phones, intercoms, analog telephone adapters |
68-
|Industrial devices | PLCs, historian devices, HMIs, robot controllers, slots, programmable boards |
69-
|Media and surveillance devices | DVRs, cameras, or video encoders / decoders |
70-
|Medical devices| |
71-
|Miscellaneous devices | Smart watches, ebook readers, Arduino devices, oscilloscopes |
72-
|Operational equipment | Industrial printers, scales, pneumatic devices, packaging systems |
73-
|Printing devices | Scanners, all-in-one printers, or printer servers |
74-
|Smart appliance devices | Smart lights, smart switches, clocks, barcode scanners |
75-
|Smart facility devices | Doors, fire alarms, elevators, turnstiles, HVAC systems |
76-
-->
7759
*Unclassified* devices are devices that don't have an out-of-the-box category defined.
7860

7961
## Unauthorized devices
@@ -104,7 +86,7 @@ The following table lists the columns available in the Defender for IoT device i
10486

10587
|Name |Description
10688
|---------|---------|
107-
|**Authorization** / **Is Authorized** * |Editable. Determines whether or not the device is marked as *authorized*. This value may need to change as the device security changes. |
89+
|**Authorization** * |Editable. Determines whether or not the device is marked as *authorized*. This value may need to change as the device security changes. |
10890
|**Business Function** | Editable. Describes the device's business function. |
10991
| **Class** | Editable. The device's class. <br>Default: `IoT` |
11092
|**Data source** | The source of the data, such as a micro agent, OT sensor, or Microsoft Defender for Endpoint. <br>Default: `MicroAgent`|
@@ -113,106 +95,43 @@ The following table lists the columns available in the Defender for IoT device i
11395
| **Firmware model** | The device's firmware model.|
11496
| **Firmware vendor** | Editable. The vendor of the device's firmware. |
11597
| **Firmware version** * |Editable. The device's firmware version. |
116-
|**First seen** / **Discovered** * | The date and time the device was first seen. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format.|
117-
|**Hardware Vendor** | <!--missing from columns--> Editable. The device's hardware vendor. |
98+
|**First seen** * | The date and time the device was first seen. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. On the OT sensor, shown as **Discovered**.|
11899
|**Importance** | Editable. The device's important level: `Low`, `Medium`, or `High`. |
119100
| **IPv4 Address** | The device's IPv4 address. |
120101
|**IPv6 Address** | The device's IPv6 address.|
121102
|**Last activity** * | The date and time the device last sent an event through to Azure or to the OT sensor, depending on where you're viewing the device inventory. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. |
122103
|**Location** | Editable. The device's physical location. |
123104
| **MAC Address** * | The device's MAC address. |
124-
|**Model** / **Hardware model** *| Editable The device's hardware model. |
105+
|**Model** *| Editable The device's hardware model. |
125106
|**Name** * | Mandatory, and editable. The device's name as the sensor discovered it, or as entered by the user. |
126107
|**OS architecture** | Editable. The device's operating system architecture. |
127108
|**OS distribution** | Editable. The device's operating system distribution, such as Android, Linux, and Haiku. |
128-
|**OS platform** / **Operating System** * | Editable. The device's operating system, if detected. |
109+
|**OS platform** * | Editable. The device's operating system, if detected. On the OT sensor, shown as **Operating System**. |
129110
|**OS version** | Editable. The device's operating system version, such as Windows 10 or Ubuntu 20.04.1. |
130-
|**PLC mode** *| The device's PLC operating mode, including both the *Key* state (physical / logical) and the *Run* state (logical). If both states are the same, then only one state is listed.<br><br>- Possible *Key* states include: `Run`, `Program`, `Remote`, `Stop`, `Invalid`, and `Programming Disabled`. <br><br>- Possible *Run* states are `Run`, `Program`, `Stop`, `Paused`, `Exception`, `Halted`, `Trapped`, `Idle`, or `Offline`. |
131-
|**Programming device** / **Is Programming device** * | Editable. Defines whether the device is defined as a *Programming Device*, performing programming activities for PLCs, RTUs, and controllers, which are relevant to engineering stations. |
111+
|**PLC mode** * | The device's PLC operating mode, including both the *Key* state (physical / logical) and the *Run* state (logical). If both states are the same, then only one state is listed.<br><br>- Possible *Key* states include: `Run`, `Program`, `Remote`, `Stop`, `Invalid`, and `Programming Disabled`. <br><br>- Possible *Run* states are `Run`, `Program`, `Stop`, `Paused`, `Exception`, `Halted`, `Trapped`, `Idle`, or `Offline`. |
112+
|**Programming device** * | Editable. Defines whether the device is defined as a *Programming Device*, performing programming activities for PLCs, RTUs, and controllers, which are relevant to engineering stations. |
132113
|**Protocols** *| The protocols that the device uses. |
133114
| **Purdue level** | Editable. The Purdue level in which the device exists.|
134-
|**Scanner device** / **Is Known as Scanner** * | Editable. Defines whether the device performs scanning-like activities in the network. |
135-
|**Sensor** / **Appliance** | The sensor the device is connected to. |
136-
|**Serial number** / **Serial** *| The device's serial number. |
115+
|**Scanner device** * | Editable. Defines whether the device performs scanning-like activities in the network. |
116+
|**Sensor**| The sensor the device is connected to. |
117+
|**Serial number** *| The device's serial number. |
137118
| **Site** | The device's site. <br><br>All Enterprise IoT sensors are automatically added to the **Enterprise network** site. |
138-
| **Slots** / **Slot** *| The number of slots the device has. <!--unclear for slot on sensor/cm--> |
119+
| **Slots** | The number of slots the device has. |
139120
| **Subtype** | Editable. The device's subtype, such as *Speaker* or *Smart TV*. <br>**Default**: `Managed Device` |
140121
| **Tags** | Editable. The device's tags. |
141122
|**Type** * | Editable. The device type, such as *Communication* or *Industrial*. <br>**Default**: `Miscellaneous` |
142123
|**Vendor** *| The name of the device's vendor, as defined in the MAC address. |
143-
| **VLAN** / **VLAN Ids** * | The device's VLAN. |
124+
| **VLAN** * | The device's VLAN. |
144125
|**Zone** | The device's zone. |
145126

146-
<!--
147-
148-
The following additional columns are available on OT sensors only:
149-
150-
|**DHCP Address** | The device's DHCP address. |
151-
|**FQDN** | The device's FQDN value |
152-
|**FQDN Last Lookup Time** | The device's FQDN lookup time |
153-
| **Groups** | The device groups that include the device, as [defined on the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#create-a-custom-device-group-from-an-ot-sensor-device-map). |- | ✔ | ✔ |
154-
| **IP Address** | The device's IP address. |- | ✔ | ✔ |
155-
| Module address | - | ✔ |✔ |
156-
| **Rack** | The number of device racks. | - | ✔ | ✔|
157-
| **Unacknowledged Alerts** | The number of unacknowledged alerts associated with the device. |- | ✔ | ✔ |
158-
159-
160-
161-
|Name |Description |Azure portal | OT sensor | On-premises management console|
162-
|---------|---------|---------|---------|---------|
163-
|**Authorization** / **Is Authorized** |Editable. Determines whether or not the device is marked as *authorized*. This value may need to change as the device security changes. |✔ | ✔ | ✔ |
164-
|**Business Function** | Editable. Describes the device's business function. |✔ | - | - |
165-
| **Business Unit** | The device's business unit, as [defined on the on-premises management console](how-to-activate-and-set-up-your-on-premises-management-console.md#create-enterprise-zones). |- | - | ✔ |
166-
| **Class** | Editable. The device's class. <br>Default: `IoT`|✔ | - | - |
167-
| **Data source** | The source of the data, such as a micro agent, OT sensor, or Microsoft Defender for Endpoint. <br>Default: `MicroAgent`|✔ | - | - |
168-
| **DHCP Address** | The device's DHCP address. | - | ✔ | - |
169-
| **Description** | Editable. The device's description. |✔ | ✔ | - |
170-
| **Device Id** | The device's Azure-assigned ID number | ✔ | -| -|
171-
| **Firmware** | The device's firmware description. | - | - | ✔ |
172-
| **Firmware model** | The device's firmware model. |✔ | - | - |
173-
| **Firmware vendor** | Editable. The vendor of the device's firmware. |✔ | - | - |
174-
| **Firmware version** |Editable. The device's firmware version. |✔ | ✔ | ✔ |
175-
| **First seen** / **Discovered** | The date and time the device was first seen. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. | ✔ | ✔ | ✔ |
176-
| **FQDN** | The device's FQDN value |- | ✔ | - |
177-
| **FQDN Last Lookup Time** | The device's FQDN lookup time |- | ✔ | - |
178-
| **Groups** | The device groups that include the device, as [defined on the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#create-a-custom-device-group-from-an-ot-sensor-device-map). |- | ✔ | ✔ |
179-
|**Hardware Vendor** | Editable. The device's hardware vendor. |✔ | - | - |
180-
| **Importance** | Editable. The device's important level: `Low`, `Medium`, or `High`. |✔ | - | - |
181-
| **IP Address** | The device's IP address. |- | ✔ | ✔ |
182-
| **IPv4 Address** | The device's IPv4 address. |✔ | - | - |
183-
| **IPv6 Address** | The device's IPv6 address. |✔ | - | - |
184-
| **Last activity** | The date and time the device last sent an event through to Azure or to the OT sensor, depending on where you're viewing the device inventory. Shown in `MM/DD/YYYY HH:MM:SS AM/PM` format. | ✔ | ✔ | ✔ |
185-
| **Location** | Editable. The device's physical location. |✔ | - | - |
186-
| **MAC Address** | The device's MAC address. |✔ | ✔ | ✔ |
187-
| **Model** / **Hardware model**| Editable The device's hardware model. |✔ | ✔ | ✔ |
188-
| Module address | - | ✔ |✔ |
189-
| **Name** | Mandatory, and editable. The device's name as the sensor discovered it, or as entered by the user. |✔ | ✔ | ✔ |
190-
| **OS architecture** | Editable. The device's operating system architecture. |✔ | - | - |
191-
| **OS distribution** | Editable. The device's operating system distribution, such as Android, Linux, and Haiku. |✔ | - | - |
192-
| **OS platform** / **Operating System** | Editable. The device's operating system, if detected. |✔ | ✔ | ✔ |
193-
| **OS version** | Editable. The device's operating system version, such as Windows 10 or Ubuntu 20.04.1. |✔ | - | - |
194-
| **PLC mode** | The device's PLC operating mode, including both the *Key* state (physical / logical) and the *Run* state (logical). Possible *Key* states include: `Run`, `Program`, `Remote`, `Stop`, `Invalid`, and `Programming Disabled`. Possible *Run* states are `Run`, `Program`, `Stop`, `Paused`, `Exception`, `Halted`, `Trapped`, `Idle`, or `Offline`. If both states are the same, then only one state is listed. |✔ | ✔ | ✔ |
195-
|**Programming device** / **Is Programming device** | Editable. Defines whether the device is defined as a *Programming Device*, performing programming activities for PLCs, RTUs, and controllers, which are relevant to engineering stations. |✔ | ✔ | ✔ |
196-
| **Protocols** | The protocols that the device uses. |✔ | ✔ | ✔ |
197-
| **Purdue level** | Editable. The Purdue level in which the device exists. |✔ | - | - |
198-
| **Rack** | The number of device racks. | - | ✔ | ✔|
199-
|**Region**| The device's region, as [defined on the on-premises management console](how-to-activate-and-set-up-your-on-premises-management-console.md#set-up-a-site) | - | - | ✔ |
200-
| **Scanner device** / **Is Known as Scanner** | Editable. Defines whether the device performs scanning-like activities in the network. |✔ | ✔ | ✔ |
201-
| **Sensor** / **Appliance** | The sensor the device is connected to. |✔ | - | ✔ |
202-
| **Serial number** / **Serial**| The device's serial number. | ✔ | ✔|✔ |
203-
| **Site** | The device's site. <br><br>All Enterprise IoT sensors are automatically added to the **Enterprise network** site.|✔ | - | ✔ |
204-
| **Slots** / **Slot** | The number of slots the device has. |✔ |✔|✔ |
205-
| **Subtype** | Editable. The device's subtype, such as *Speaker* or *Smart TV*. <br>**Default**: `Managed Device` |✔ | - | - |
206-
| **Tags** | Editable. The device's tags. |✔ | - | - |
207-
| **Type** | Editable. The device type, such as *Communication* or *Industrial*. <br>**Default**: `Miscellaneous` |✔ | ✔ | ✔ |
208-
| **Unacknowledged Alerts** | The number of unacknowledged alerts associated with the device. |- | ✔ | ✔ |
209-
| **Vendor** | The name of the device's vendor, as defined in the MAC address. |✔ | ✔ | ✔ |
210-
| **VLAN** / **VLAN Ids** | The device's VLAN. |✔ | ✔ | ✔ |
211-
| **Zone** | The device's zone. |✔ | - | ✔ |
212-
213-
-->
214-
127+
The following columns are available on OT sensors only:
215128

129+
- The device's **DHCP Address**
130+
- The device's **FQDN** address and **FQDN Last Lookup Time**
131+
- The device **Groups** that include the device, as [defined on the OT sensor's device map](how-to-work-with-the-sensor-device-map.md#create-a-custom-device-group-from-an-ot-sensor-device-map)
132+
- The device's **Module address**
133+
- The device's **Rack** and **Slot**
134+
- The number of **Unacknowledged Alerts** alerts associated with the device
216135

217136
> [!NOTE]
218137
> The additional **Agent type** and **Agent version** columns are used for by device builders. For more information, see [Microsoft Defender for IoT for device builders documentation](/azure/defender-for-iot/device-builders/).

articles/defender-for-iot/organizations/how-to-work-with-the-sensor-device-map.md

Lines changed: 11 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -45,15 +45,15 @@ To view devices across multiple sensors in a zone, you'll also need an on-premis
4545
- The number of devices grouped in a subnet in an IT network, if relevant. This number of devices is shown in a black circle.
4646
- Whether the device is newly detected or unauthorized.
4747

48-
1. Right-click a specific device and select **View properties** to drill down further to a [device details page](how-to-investigate-sensor-detections-in-a-device-inventory.md#view-the-device-inventory). <!--validate this step-->
48+
1. Right-click a specific device and select **View properties** to drill down further to the **Map View** tab on the device's [device details page](how-to-investigate-sensor-detections-in-a-device-inventory.md#view-the-device-inventory).
4949

5050
### Modify the OT sensor map display
5151

5252
Use any of the following map tools to modify the data shown and how it's displayed:
5353

5454
|Name |Description |
5555
|---------|---------|
56-
|**Refresh map** | Select to refresh the map with updated data. <!--how often does this refresh automatically?--> |
56+
|**Refresh map** | Select to refresh the map with updated data. |
5757
| **Notifications** | Select to view [device notifications](#manage-device-notifications). |
5858
|**Search by IP / MAC** | Filter the map to display only devices connected to a specific IP or MAC address. |
5959
|**Multicast/broadcast** | Select to edit the filter that shows or hides multicast and broadcast devices. By default, multicast and broadcast traffic is hidden. |
@@ -75,15 +75,19 @@ To see device details, select a device and expand the device details pane on the
7575

7676

7777
### View IT subnets from an OT sensor device map
78-
<!--cant' validate this procedure-->
7978

8079
By default, IT devices are automatically aggregated by [subnet](how-to-control-what-traffic-is-monitored.md#configure-subnets), so that the map focuses on OT and ICS networks.
8180

8281
**To expand an IT subnet**:
8382

8483
1. Sign into your OT sensor and select **Device map**.
85-
1. Right-click the icon on the map that represents a specific IT network and select **Expand Network**.
86-
1. In the confirmation box that appears, select **OK**.
84+
1. Locate your subnet on the map. You might need to zoom in on the map to view a subnet icon, which looks like several machines inside a box. For example:
85+
86+
:::image type="content" source="media/how-to-work-with-maps/expand-collapse-subnets.png" alt-text="Screenshot of a subnet device on the device map.":::
87+
88+
1. Right-click the subnet device on the map and **Expand Network**.
89+
90+
1. In the confirmation message that appears above the map, select **OK**.
8791

8892
**To collapse an IT subnet:**
8993

@@ -108,7 +112,7 @@ In addition to OT sensor's [built-in device groups](#built-in-device-map-groups)
108112
Use one of the following options to import and export device data:
109113

110114
- **Import Devices**. Select to import devices from a pre-configured .CSV file.
111-
- **Export Devices**. Select to export all currently displayed devices, with full details, to a .CSV file.<!--is this correct?-->
115+
- **Export Devices**. Select to export all currently displayed devices, with full details, to a .CSV file.
112116
- **Export Device Summary**. Select to export a high level summary of all currently displayed devices to a .CSV file.
113117

114118

@@ -203,7 +207,7 @@ On the on-premises management console, zone maps show all network elements relat
203207

204208
**To view a zone map**:
205209

206-
1. Sign into an on-premises management console and select **Site Management** > **View Zone Map** for the zone you want to view. For example: <!--fix image-->
210+
1. Sign into an on-premises management console and select **Site Management** > **View Zone Map** for the zone you want to view. For example:
207211

208212
:::image type="content" source="media/how-to-work-with-asset-inventory-information/default-region-to-default-business-unit-v2.png" alt-text="Default region to default business unit." lightbox="media/how-to-work-with-asset-inventory-information/default-region-to-default-business-unit-v2.png":::
209213

Loading
437 KB
Loading

0 commit comments

Comments
 (0)