Skip to content

Commit 5b00a5e

Browse files
committed
liran's comments
1 parent c57625b commit 5b00a5e

File tree

1 file changed

+19
-20
lines changed

1 file changed

+19
-20
lines changed

articles/defender-for-iot/organizations/integrate-overview.md

Lines changed: 19 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -14,100 +14,99 @@ Integrate Microsoft Defender for Iot with partner services to view partner data
1414

1515
|Name |Description |Support scope |Supported by |Learn more |
1616
|---------|---------|---------|---------|---------|
17-
|**Aruba ClearPass** | Share Defender for IoT data with ClearPass Security Exchange and update the ClearPass Policy Manager Endpoint Database with Defender for IoT data. | - OT networks only<br>- Locally managed sensors only | ClearPass | [Integrate ClearPass with Microsoft Defender for IoT](tutorial-clearpass.md) |
17+
|**Aruba ClearPass** | Share Defender for IoT data with ClearPass Security Exchange and update the ClearPass Policy Manager Endpoint Database with Defender for IoT data. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate ClearPass with Microsoft Defender for IoT](tutorial-clearpass.md) |
1818

1919
## Axonius
2020

2121

2222
|Name |Description |Support scope |Supported by |Learn more |
2323
|---------|---------|---------|---------|---------|
24-
|**Axonius Cybersecurity Asset Management** | Import and manage device inventory discovered by Defender for IoT in your Axonius instance. | - OT networks only<br>- Locally managed sensors only | Axonius | [Axonius documentation](https://docs.axonius.com/docs/azure-defender-for-iot) |
24+
|**Axonius Cybersecurity Asset Management** | Import and manage device inventory discovered by Defender for IoT in your Axonius instance. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Axonius | [Axonius documentation](https://docs.axonius.com/docs/azure-defender-for-iot) |
2525

2626
## CyberArk PSM
2727

2828
|Name |Description |Support scope |Supported by |Learn more |
2929
|---------|---------|---------|---------|---------|
30-
|**CyberArk Privileged Session Manager (PSM)** | Send CyberArk PSM syslog data on remote sessions and verification failures to Defender for IoT for data correlation. | - OT networks only<br>- Locally managed sensors only | CyberArk | [Integrate CyberArk with Microsoft Defender for IoT](tutorial-cyberark.md) |
30+
|**CyberArk Privileged Session Manager (PSM)** | Send CyberArk PSM syslog data on remote sessions and verification failures to Defender for IoT for data correlation. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate CyberArk with Microsoft Defender for IoT](tutorial-cyberark.md) |
3131

3232
## Forescout
3333

3434
|Name |Description |Support scope |Supported by |Learn more |
3535
|---------|---------|---------|---------|---------|
36-
|**Forescout** | Automate actions in Forescout based on activity detected by Defender for IoT, and correlate Defender for IoT data with other *Forescout eyeExtended* modules that oversee monitoring, incident management, and device control. | - OT networks only<br>- Locally managed sensors only | Forescout | [Integrate Forescout with Microsoft Defender for IoT](tutorial-forescout.md) |
36+
|**Forescout** | Automate actions in Forescout based on activity detected by Defender for IoT, and correlate Defender for IoT data with other *Forescout eyeExtended* modules that oversee monitoring, incident management, and device control. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate Forescout with Microsoft Defender for IoT](tutorial-forescout.md) |
3737

3838
## Fortinet
3939

4040
|Name |Description |Support scope |Supported by |Learn more |
4141
|---------|---------|---------|---------|---------|
42-
|**Fortinet FortiSIEM and FortiGate** | Send Defender for IoT data to Fortinet services for: <br><br>- Enhanced network visibility in FortiSIEM<br>- Extra abilities in FortiGate to stop anomalous behavior | - OT networks only<br>- Locally managed sensors only | Fortinet | [Integrate Fortinet with Microsoft Defender for IoT](tutorial-fortinet.md) |
42+
|**Fortinet FortiSIEM and FortiGate** | Send Defender for IoT data to Fortinet services for: <br><br>- Enhanced network visibility in FortiSIEM<br>- Extra abilities in FortiGate to stop anomalous behavior | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate Fortinet with Microsoft Defender for IoT](tutorial-fortinet.md) |
4343

4444
## IBM QRadar
4545

4646
|Name |Description |Support scope |Supported by |Learn more |
4747
|---------|---------|---------|---------|---------|
48-
| **IBM QRadar** | Send Defender for IoT alerts to IBM QRadar | - OT networks only <br>- Cloud connected sensors only | Microsoft | [Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242) |
49-
|**IBM QRadar** | Forward Defender for IoT alerts to IBM QRadar. | - OT networks only<br>- Locally managed sensors only | Qradar | [Integrate Qradar with Microsoft Defender for IoT](tutorial-qradar.md) |
48+
| **IBM QRadar** | Send Defender for IoT alerts to IBM QRadar | - OT networks <br>- Cloud connected sensors | Microsoft | [Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242) |
49+
|**IBM QRadar** | Forward Defender for IoT alerts to IBM QRadar. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate Qradar with Microsoft Defender for IoT](tutorial-qradar.md) |
5050

5151
## LogRhythm
5252

5353
|Name |Description |Support scope |Supported by |Learn more |
5454
|---------|---------|---------|---------|---------|
55-
|**LogRhythm** | Forward Defender for IoT alerts to LogRhythm. | - OT networks only<br>- Locally managed sensors only | Microsoft | [Integrate LogRhythm with Microsoft Defender for IoT](integrations/logrhythm.md) |
55+
|**LogRhythm** | Forward Defender for IoT alerts to LogRhythm. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate LogRhythm with Microsoft Defender for IoT](integrations/logrhythm.md) |
5656

5757
## Micro Focus ArcSight
5858

5959
|Name |Description |Support scope |Supported by |Learn more |
6060
|---------|---------|---------|---------|---------|
61-
|**Micro Focus ArcSight** | Forward Defender for IoT alerts to ArcSight. | - OT networks only<br>- Locally managed sensors only | Microsoft | [Integrate ArcSight with Microsoft Defender for IoT](integrations/arcsight.md) |
61+
|**Micro Focus ArcSight** | Forward Defender for IoT alerts to ArcSight. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate ArcSight with Microsoft Defender for IoT](integrations/arcsight.md) |
6262

6363
## Microsoft Defender for Endpoint
6464

6565
|Name |Description |Support scope |Supported by |Learn more |
6666
|---------|---------|---------|---------|---------|
67-
|**Microsoft Defender for Endpoint** | Integrates Defender for IoT data in Defender for Endpoint's device inventory, alerts, recommendations, and vulnerabilities. Displays device data about Defender for Endpoint endpoints in the Defender for IoT **Device inventory** page on the Azure portal. | - Enterprise IoT networks and sensors only | Microsoft | [Onboard with Microsoft Defender for IoT](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration) |
67+
|**Microsoft Defender for Endpoint** | Integrates Defender for IoT data in Defender for Endpoint's device inventory, alerts, recommendations, and vulnerabilities. Displays device data about Defender for Endpoint endpoints in the Defender for IoT **Device inventory** page on the Azure portal. | - Enterprise IoT networks and sensors | Microsoft | [Onboard with Microsoft Defender for IoT](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration) |
6868

6969
## Microsoft Sentinel
7070

7171
|Name |Description |Support scope |Supported by |Learn more |
7272
|---------|---------|---------|---------|---------|
73-
|**Defender for IoT data connector** | Displays Defender for IoT data in Microsoft Sentinel, supporting end-to-end SOC investigations for Defender for IoT alerts. | - OT networks only <br>- Cloud-connected sensors only | Microsoft | [Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended) |
74-
|**IoT/OT Threat Monitoring with Defender for IoT** | Provides additional security content for Defender for IoT data in Microsoft Sentinel | - OT networks only <br>- Cloud-connected sensors only | Microsoft | [Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended) |
73+
|**Defender for IoT data connector** | Displays Defender for IoT data in Microsoft Sentinel, supporting end-to-end SOC investigations for Defender for IoT alerts. | - OT and Enterprise IoT networks <br>- Cloud-connected sensors | Microsoft | [Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended) |
7574

7675

7776
## Palo Alto
7877

7978
|Name |Description |Support scope |Supported by |Learn more |
8079
|---------|---------|---------|---------|---------|
81-
|**Palo Alto** | Use Defender for IoT data to block critical threats with Palo Alto firewalls, either with automatic blocking or with blocking recommendations. | - OT networks only<br>- Locally managed sensors only | Palo Alto | [Integrate Palo-Alto with Microsoft Defender for IoT](tutorial-palo-alto.md) |
80+
|**Palo Alto** | Use Defender for IoT data to block critical threats with Palo Alto firewalls, either with automatic blocking or with blocking recommendations. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate Palo-Alto with Microsoft Defender for IoT](tutorial-palo-alto.md) |
8281

8382

8483
## RSA NetWitness
8584

8685
|Name |Description |Support scope |Supported by |Learn more |
8786
|---------|---------|---------|---------|---------|
88-
|**RSA NetWitness** | Forward Defender for IoT alerts to RSA NetWitness | - OT networks only<br>- Locally managed sensors only | Microsoft | [Integrate RSA NetWitness with Microsoft Defender for IoT](integrations/netwitness.md) <br><br>[CyberX Platform - RSA NetWitness CEF Parser Implementation Guide](https://community.netwitness.com//t5/netwitness-platform-integrations/cyberx-platform-rsa-netwitness-cef-parser-implementation-guide/ta-p/554364) |
87+
|**RSA NetWitness** | Forward Defender for IoT alerts to RSA NetWitness | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate RSA NetWitness with Microsoft Defender for IoT](integrations/netwitness.md) <br><br>[Defender for IoT - RSA NetWitness CEF Parser Implementation Guide](https://community.netwitness.com//t5/netwitness-platform-integrations/cyberx-platform-rsa-netwitness-cef-parser-implementation-guide/ta-p/554364) |
8988

9089
## ServiceNow
9190

9291
|Name |Description |Support scope |Supported by |Learn more |
9392
|---------|---------|---------|---------|---------|
94-
| **Vulnerability Response Integration with Microsoft Azure Defender for IoT** | View Defender for IoT device detections, attributes, and connections in ServiceNow. | - OT networks only<br>- Locally managed sensors only | ServiceNow | [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/463a7907c3313010985a1b2d3640dd7e/1.0.1?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh) |
95-
| **Service Graph Connector Integration with Microsoft Azure Defender for IoT** | View Defender for IoT device detections, attributes, and connections in ServiceNow. | - OT networks only<br>- Locally managed sensors only | ServiceNow | [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/ddd4bf1b53f130104b5cddeeff7b1229/1.0.0?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh) |
96-
| **Microsoft Defender for IoT** (Legacy) | View Defender for IoT device detections, attributes, and connections in ServiceNow. | - OT networks only<br>- Locally managed sensors only | ServiceNow | [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/6dca6137dbba13406f7deeb5ca961906/3.1.5?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)<br><br>[Integrate ServiceNow with Microsoft Defender for IoT](tutorial-servicenow.md) |
93+
| **Vulnerability Response Integration with Microsoft Azure Defender for IoT** | View Defender for IoT device vulnerabilities in ServiceNow. | - OT networks<br>- Locally managed sensors and on-premises management consoles | ServiceNow | [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/463a7907c3313010985a1b2d3640dd7e/1.0.1?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh) |
94+
| **Service Graph Connector Integration with Microsoft Azure Defender for IoT** | View Defender for IoT device detections, sensors, and network connections in ServiceNow. | - OT networks<br>- Locally managed sensors and on-premises management consoles | ServiceNow | [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/ddd4bf1b53f130104b5cddeeff7b1229/1.0.0?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh) |
95+
| **Microsoft Defender for IoT** (Legacy) | View Defender for IoT device detections and alerts in ServiceNow. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/6dca6137dbba13406f7deeb5ca961906/3.1.5?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)<br><br>[Integrate ServiceNow with Microsoft Defender for IoT](tutorial-servicenow.md) |
9796

9897
## Skybox
9998

10099
|Name |Description |Support scope |Supported by |Learn more |
101100
|---------|---------|---------|---------|---------|
102-
|**Skybox** | Import vulnerability occurrence data discovered by Defender for IoT in your Skybox platform. | - OT networks only<br>- Locally managed sensors only | Skybox | [Skybox documentation](https://docs.skyboxsecurity.com) <br><br> [Skybox integration page](https://www.skyboxsecurity.com/products/integrations) |
101+
|**Skybox** | Import vulnerability occurrence data discovered by Defender for IoT in your Skybox platform. | - OT networks<br>- Locally managed sensors and on-premises management consoles | Skybox | [Skybox documentation](https://docs.skyboxsecurity.com) <br><br> [Skybox integration page](https://www.skyboxsecurity.com/products/integrations) |
103102

104103

105104
## Splunk
106105

107106
|Name |Description |Support scope |Supported by |Learn more |
108107
|---------|---------|---------|---------|---------|
109-
| **Splunk** | Send Defender for IoT alerts to Splunk | - OT networks only <br>- Cloud connected sensors only | Microsoft | [Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242) |
110-
|**Splunk** | Send Defender for IoT alerts to Splunk | - OT networks only<br>- Locally managed sensors only | Microsoft | [Integrate Splunk with Microsoft Defender for IoT](tutorial-splunk.md) |
108+
| **Splunk** | Send Defender for IoT alerts to Splunk | - OT networks <br>- Cloud connected sensors | Microsoft | [Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242) |
109+
|**Splunk** | Send Defender for IoT alerts to Splunk | - OT networks<br>- Locally managed sensors and on-premises management consoles | Microsoft | [Integrate Splunk with Microsoft Defender for IoT](tutorial-splunk.md) |
111110

112111

113112
## Next steps

0 commit comments

Comments
 (0)