Skip to content

Commit 5a9477d

Browse files
Merge pull request #291219 from tarTech23/learman
manual update to learn setting change
2 parents 9810258 + a0c59a5 commit 5a9477d

File tree

3 files changed

+6
-5
lines changed

3 files changed

+6
-5
lines changed

articles/defender-for-iot/organizations/how-to-manage-individual-sensors.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -222,7 +222,7 @@ A Microsoft Defender for IoT OT network sensor starts monitoring your network au
222222

223223
Initially, this activity happens in *learning* mode, which instructs your OT sensor to learn your network's usual activity, including the devices and protocols in your network, and the regular file transfers that occur between specific devices. Any regularly detected activity becomes your network's [baseline traffic](ot-deploy/create-learned-baseline.md).
224224

225-
This procedure describes how to turn off learning mode manually if you feel that the current alerts accurately reflect your network activity.
225+
This procedure describes how to turn off learning mode manually when the current alerts accurately reflect your network activity.
226226

227227
**To turn off learning mode**:
228228

articles/defender-for-iot/organizations/ot-deploy/create-learned-baseline.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,6 @@ An OT network sensor starts monitoring your network automatically after it's con
1717

1818
Initially, this activity happens in *learning* mode, which instructs your OT sensor to learn your network's usual activity, including the devices and protocols in your network, and the regular file transfers that occur between specific devices. Any regularly detected activity becomes your network's baseline traffic.
1919

20-
2120
> [!TIP]
2221
> Use your time in learning mode to triage your alerts and *Learn* those that you want to mark as authorized, expected activity. Learned traffic doesn't generate new alerts the next time the same traffic is detected.
2322
>
@@ -27,9 +26,11 @@ For more information, see [Microsoft Defender for IoT alerts](../alerts.md).
2726

2827
### Learn mode timeline
2928

30-
Creating your baseline of OT alerts can take anywhere from a few days to several weeks, depending on your network size and complexity. Learning mode automatically turns off when the sensor detects a decrease in newly detected traffic, which is typically between 2-6 weeks after deployment.
29+
Creating your baseline of OT alerts can take anywhere from a few days to several weeks, depending on your network size and complexity. We recommend that after 2-6 weeks, you manually change the Learning mode to Dynamic mode when the daily number of alerts decreases to a manageable level. In dynamic mode Defender for IoT continues to monitor the network for suspicious traffic, trigger alerts, and also automatically moves an alert category to operational mode if that alert isn't triggered for a specific length of time.
30+
31+
In operational mode all alerts produced are listed in the inventory and must be remediated by following the actions listed in the alert details pane. If the alert was triggered by safe network traffic you'll need to use the **Learn** button to add this traffic to the baseline list so that the sensor doesn't produce an alert for this in the future.
3132

32-
[Turn off learning mode manually before then](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) if you feel that the current alerts accurately reflect your network activity.
33+
[Turn off learning mode manually](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) when the level of alerts accurately reflect your network activity.
3334

3435
## Prerequisites
3536

articles/defender-for-iot/organizations/ot-deploy/ot-deploy-path.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -179,7 +179,7 @@ Your OT sensors will remain in *Learning mode* for as long as new traffic is det
179179
When baseline learning ends, the OT monitoring deployment process is complete, and you'll continue on in operational mode for ongoing monitoring. In operational mode, any activity that differs from your baseline data will trigger an alert.
180180

181181
> [!TIP]
182-
> [Turn off learning mode manually](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) if you feel that the current alerts in Defender for IoT reflect your network traffic accurately, and learning mode hasn't already ended automatically.
182+
> [Turn off learning mode manually](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) when the current alerts in Defender for IoT reflect your network traffic accurately.
183183
>
184184
185185
## Connect Defender for IoT data to your SIEM

0 commit comments

Comments
 (0)