You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|**Aruba ClearPass**| Share Defender for IoT data with ClearPass Security Exchange and update the ClearPass Policy Manager Endpoint Database with Defender for IoT data. | - OT networks only<br>- Locally managed sensors only |ClearPass|[Integrate ClearPass with Microsoft Defender for IoT](tutorial-clearpass.md)|
17
+
|**Aruba ClearPass**| Share Defender for IoT data with ClearPass Security Exchange and update the ClearPass Policy Manager Endpoint Database with Defender for IoT data. | - OT networks<br>- Locally managed sensors and on-premises management consoles|Microsoft|[Integrate ClearPass with Microsoft Defender for IoT](tutorial-clearpass.md)|
18
18
19
19
## Axonius
20
20
21
21
22
22
|Name |Description |Support scope |Supported by |Learn more |
|**Axonius Cybersecurity Asset Management**| Import and manage device inventory discovered by Defender for IoT in your Axonius instance. | - OT networks only<br>- Locally managed sensors only| Axonius |[Axonius documentation](https://docs.axonius.com/docs/azure-defender-for-iot)|
24
+
|**Axonius Cybersecurity Asset Management**| Import and manage device inventory discovered by Defender for IoT in your Axonius instance. | - OT networks<br>- Locally managed sensors and on-premises management consoles| Axonius |[Axonius documentation](https://docs.axonius.com/docs/azure-defender-for-iot)|
25
25
26
26
## CyberArk PSM
27
27
28
28
|Name |Description |Support scope |Supported by |Learn more |
|**CyberArk Privileged Session Manager (PSM)**| Send CyberArk PSM syslog data on remote sessions and verification failures to Defender for IoT for data correlation. | - OT networks only<br>- Locally managed sensors only |CyberArk|[Integrate CyberArk with Microsoft Defender for IoT](tutorial-cyberark.md)|
30
+
|**CyberArk Privileged Session Manager (PSM)**| Send CyberArk PSM syslog data on remote sessions and verification failures to Defender for IoT for data correlation. | - OT networks<br>- Locally managed sensors and on-premises management consoles|Microsoft|[Integrate CyberArk with Microsoft Defender for IoT](tutorial-cyberark.md)|
31
31
32
32
## Forescout
33
33
34
34
|Name |Description |Support scope |Supported by |Learn more |
|**Forescout**| Automate actions in Forescout based on activity detected by Defender for IoT, and correlate Defender for IoT data with other *Forescout eyeExtended* modules that oversee monitoring, incident management, and device control. | - OT networks only<br>- Locally managed sensors only |Forescout|[Integrate Forescout with Microsoft Defender for IoT](tutorial-forescout.md)|
36
+
|**Forescout**| Automate actions in Forescout based on activity detected by Defender for IoT, and correlate Defender for IoT data with other *Forescout eyeExtended* modules that oversee monitoring, incident management, and device control. | - OT networks<br>- Locally managed sensors and on-premises management consoles|Microsoft|[Integrate Forescout with Microsoft Defender for IoT](tutorial-forescout.md)|
37
37
38
38
## Fortinet
39
39
40
40
|Name |Description |Support scope |Supported by |Learn more |
|**Fortinet FortiSIEM and FortiGate**| Send Defender for IoT data to Fortinet services for: <br><br>- Enhanced network visibility in FortiSIEM<br>- Extra abilities in FortiGate to stop anomalous behavior | - OT networks only<br>- Locally managed sensors only |Fortinet|[Integrate Fortinet with Microsoft Defender for IoT](tutorial-fortinet.md)|
42
+
|**Fortinet FortiSIEM and FortiGate**| Send Defender for IoT data to Fortinet services for: <br><br>- Enhanced network visibility in FortiSIEM<br>- Extra abilities in FortiGate to stop anomalous behavior | - OT networks<br>- Locally managed sensors and on-premises management consoles|Microsoft|[Integrate Fortinet with Microsoft Defender for IoT](tutorial-fortinet.md)|
43
43
44
44
## IBM QRadar
45
45
46
46
|Name |Description |Support scope |Supported by |Learn more |
|**IBM QRadar**| Send Defender for IoT alerts to IBM QRadar | - OT networks only <br>- Cloud connected sensors only| Microsoft |[Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242)|
49
-
|**IBM QRadar**| Forward Defender for IoT alerts to IBM QRadar. | - OT networks only<br>- Locally managed sensors only |Qradar|[Integrate Qradar with Microsoft Defender for IoT](tutorial-qradar.md)|
48
+
|**IBM QRadar**| Send Defender for IoT alerts to IBM QRadar | - OT networks <br>- Cloud connected sensors | Microsoft |[Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242)|
49
+
|**IBM QRadar**| Forward Defender for IoT alerts to IBM QRadar. | - OT networks<br>- Locally managed sensors and on-premises management consoles|Microsoft|[Integrate Qradar with Microsoft Defender for IoT](tutorial-qradar.md)|
50
50
51
51
## LogRhythm
52
52
53
53
|Name |Description |Support scope |Supported by |Learn more |
|**LogRhythm**| Forward Defender for IoT alerts to LogRhythm. | - OT networks only<br>- Locally managed sensors only| Microsoft |[Integrate LogRhythm with Microsoft Defender for IoT](integrations/logrhythm.md)|
55
+
|**LogRhythm**| Forward Defender for IoT alerts to LogRhythm. | - OT networks<br>- Locally managed sensors and on-premises management consoles| Microsoft |[Integrate LogRhythm with Microsoft Defender for IoT](integrations/logrhythm.md)|
56
56
57
57
## Micro Focus ArcSight
58
58
59
59
|Name |Description |Support scope |Supported by |Learn more |
|**Micro Focus ArcSight**| Forward Defender for IoT alerts to ArcSight. | - OT networks only<br>- Locally managed sensors only| Microsoft |[Integrate ArcSight with Microsoft Defender for IoT](integrations/arcsight.md)|
61
+
|**Micro Focus ArcSight**| Forward Defender for IoT alerts to ArcSight. | - OT networks<br>- Locally managed sensors and on-premises management consoles| Microsoft |[Integrate ArcSight with Microsoft Defender for IoT](integrations/arcsight.md)|
62
62
63
63
## Microsoft Defender for Endpoint
64
64
65
65
|Name |Description |Support scope |Supported by |Learn more |
|**Microsoft Defender for Endpoint**| Integrates Defender for IoT data in Defender for Endpoint's device inventory, alerts, recommendations, and vulnerabilities. Displays device data about Defender for Endpoint endpoints in the Defender for IoT **Device inventory** page on the Azure portal. | - Enterprise IoT networks and sensors only | Microsoft |[Onboard with Microsoft Defender for IoT](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration)|
67
+
|**Microsoft Defender for Endpoint**| Integrates Defender for IoT data in Defender for Endpoint's device inventory, alerts, recommendations, and vulnerabilities. Displays device data about Defender for Endpoint endpoints in the Defender for IoT **Device inventory** page on the Azure portal. | - Enterprise IoT networks and sensors | Microsoft |[Onboard with Microsoft Defender for IoT](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration)|
68
68
69
69
## Microsoft Sentinel
70
70
71
71
|Name |Description |Support scope |Supported by |Learn more |
|**Defender for IoT data connector**| Displays Defender for IoT data in Microsoft Sentinel, supporting end-to-end SOC investigations for Defender for IoT alerts. | - OT networks only <br>- Cloud-connected sensors only | Microsoft |[Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended)|
74
-
|**IoT/OT Threat Monitoring with Defender for IoT**| Provides additional security content for Defender for IoT data in Microsoft Sentinel | - OT networks only <br>- Cloud-connected sensors only | Microsoft |[Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended)|
73
+
|**Defender for IoT data connector**| Displays Defender for IoT data in Microsoft Sentinel, supporting end-to-end SOC investigations for Defender for IoT alerts. | - OT and Enterprise IoT networks <br>- Cloud-connected sensors | Microsoft |[Integrate Microsoft Sentinel and Microsoft Defender for IoT](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended)|
75
74
76
75
77
76
## Palo Alto
78
77
79
78
|Name |Description |Support scope |Supported by |Learn more |
|**Palo Alto**| Use Defender for IoT data to block critical threats with Palo Alto firewalls, either with automatic blocking or with blocking recommendations. | - OT networks only<br>- Locally managed sensors only | Palo Alto|[Integrate Palo-Alto with Microsoft Defender for IoT](tutorial-palo-alto.md)|
80
+
|**Palo Alto**| Use Defender for IoT data to block critical threats with Palo Alto firewalls, either with automatic blocking or with blocking recommendations. | - OT networks<br>- Locally managed sensors and on-premises management consoles| Microsoft|[Integrate Palo-Alto with Microsoft Defender for IoT](tutorial-palo-alto.md)|
82
81
83
82
84
83
## RSA NetWitness
85
84
86
85
|Name |Description |Support scope |Supported by |Learn more |
|**RSA NetWitness**| Forward Defender for IoT alerts to RSA NetWitness | - OT networks only<br>- Locally managed sensors only | Microsoft |[Integrate RSA NetWitness with Microsoft Defender for IoT](integrations/netwitness.md) <br><br>[CyberX Platform - RSA NetWitness CEF Parser Implementation Guide](https://community.netwitness.com//t5/netwitness-platform-integrations/cyberx-platform-rsa-netwitness-cef-parser-implementation-guide/ta-p/554364)|
87
+
|**RSA NetWitness**| Forward Defender for IoT alerts to RSA NetWitness | - OT networks<br>- Locally managed sensors and on-premises management consoles| Microsoft |[Integrate RSA NetWitness with Microsoft Defender for IoT](integrations/netwitness.md) <br><br>[Defender for IoT - RSA NetWitness CEF Parser Implementation Guide](https://community.netwitness.com//t5/netwitness-platform-integrations/cyberx-platform-rsa-netwitness-cef-parser-implementation-guide/ta-p/554364)|
89
88
90
89
## ServiceNow
91
90
92
91
|Name |Description |Support scope |Supported by |Learn more |
|**Vulnerability Response Integration with Microsoft Azure Defender for IoT**| View Defender for IoT device detections, attributes, and connections in ServiceNow. | - OT networks only<br>- Locally managed sensors only| ServiceNow |[ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/463a7907c3313010985a1b2d3640dd7e/1.0.1?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)|
95
-
|**Service Graph Connector Integration with Microsoft Azure Defender for IoT**| View Defender for IoT device detections, attributes, and connections in ServiceNow. | - OT networks only<br>- Locally managed sensors only| ServiceNow |[ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/ddd4bf1b53f130104b5cddeeff7b1229/1.0.0?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)|
96
-
|**Microsoft Defender for IoT** (Legacy) | View Defender for IoT device detections, attributes, and connections in ServiceNow. | - OT networks only<br>- Locally managed sensors only |ServiceNow|[ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/6dca6137dbba13406f7deeb5ca961906/3.1.5?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)<br><br>[Integrate ServiceNow with Microsoft Defender for IoT](tutorial-servicenow.md)|
93
+
|**Vulnerability Response Integration with Microsoft Azure Defender for IoT**| View Defender for IoT device vulnerabilities in ServiceNow. | - OT networks<br>- Locally managed sensors and on-premises management consoles| ServiceNow |[ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/463a7907c3313010985a1b2d3640dd7e/1.0.1?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)|
94
+
|**Service Graph Connector Integration with Microsoft Azure Defender for IoT**| View Defender for IoT device detections, sensors, and network connections in ServiceNow. | - OT networks<br>- Locally managed sensors and on-premises management consoles| ServiceNow |[ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/ddd4bf1b53f130104b5cddeeff7b1229/1.0.0?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)|
95
+
|**Microsoft Defender for IoT** (Legacy) | View Defender for IoT device detectionsand alerts in ServiceNow. | - OT networks<br>- Locally managed sensors and on-premises management consoles|Microsoft|[ServiceNow store](https://store.servicenow.com/sn_appstore_store.do#!/store/application/6dca6137dbba13406f7deeb5ca961906/3.1.5?referer=%2Fstore%2Fsearch%3Flistingtype%3Dallintegrations%25253Bancillary_app%25253Bcertified_apps%25253Bcontent%25253Bindustry_solution%25253Boem%25253Butility%25253Btemplate%26q%3Ddefender%2520for%2520iot&sl=sh)<br><br>[Integrate ServiceNow with Microsoft Defender for IoT](tutorial-servicenow.md)|
97
96
98
97
## Skybox
99
98
100
99
|Name |Description |Support scope |Supported by |Learn more |
|**Skybox**| Import vulnerability occurrence data discovered by Defender for IoT in your Skybox platform. | - OT networks only<br>- Locally managed sensors only | Skybox |[Skybox documentation](https://docs.skyboxsecurity.com) <br><br> [Skybox integration page](https://www.skyboxsecurity.com/products/integrations)|
101
+
|**Skybox**| Import vulnerability occurrence data discovered by Defender for IoT in your Skybox platform. | - OT networks<br>- Locally managed sensors and on-premises management consoles| Skybox |[Skybox documentation](https://docs.skyboxsecurity.com) <br><br> [Skybox integration page](https://www.skyboxsecurity.com/products/integrations)|
103
102
104
103
105
104
## Splunk
106
105
107
106
|Name |Description |Support scope |Supported by |Learn more |
|**Splunk**| Send Defender for IoT alerts to Splunk | - OT networks only <br>- Cloud connected sensors only| Microsoft |[Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242)|
110
-
|**Splunk**| Send Defender for IoT alerts to Splunk | - OT networks only<br>- Locally managed sensors only| Microsoft |[Integrate Splunk with Microsoft Defender for IoT](tutorial-splunk.md)|
108
+
|**Splunk**| Send Defender for IoT alerts to Splunk | - OT networks <br>- Cloud connected sensors | Microsoft |[Stream Microsoft Defender for IoT alerts to a 3rd party SIEM](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot-blog/stream-microsoft-defender-for-iot-alerts-to-a-3rd-party-siem/ba-p/3581242)|
109
+
|**Splunk**| Send Defender for IoT alerts to Splunk | - OT networks<br>- Locally managed sensors and on-premises management consoles| Microsoft |[Integrate Splunk with Microsoft Defender for IoT](tutorial-splunk.md)|
0 commit comments