Skip to content

Commit 6b60818

Browse files
Merge pull request #279441 from tarTech23/data
New storage policy
2 parents b42d645 + 6cd9113 commit 6b60818

File tree

2 files changed

+56
-29
lines changed

2 files changed

+56
-29
lines changed

articles/defender-for-iot/organizations/back-up-restore-sensor.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ OT sensors are automatically backed up daily at 3:00 AM, including configuration
2020

2121
We recommend that you configure your system to automatically transfer backup files to your own internal network.
2222

23-
For more information, see [On-premises backup file capacity](references-data-retention.md#on-premises-backup-file-capacity).
23+
For more information, see [On-premises backup file capacity](references-data-retention.md#backup-file-capacity).
2424

2525
> [!NOTE]
2626
> Backup files can be used to restore an OT sensor only if the OT sensor's current software version is the same as the version in the backup file.

articles/defender-for-iot/organizations/references-data-retention.md

Lines changed: 55 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,46 @@
11
---
22
title: Data retention and sharing across Microsoft Defender for IoT
3-
description: Learn about the data retention periods and capacities for Microsoft Defender for IoT data stored in Azure, the OT sensor, and on-premises management console.
3+
description: Learn about the data retention periods and capacities for Microsoft Defender for IoT data stored in Microsoft Azure, the OT sensor, and on-premises management console.
44
ms.topic: conceptual
5-
ms.date: 01/22/2023
5+
ms.date: 06/30/2024
66
---
77

8-
# Data retention and sharing across Microsoft Defender for IoT
8+
# Data retention, privacy, and sharing across Microsoft Defender for IoT
99

10-
Microsoft Defender for IoT sensors learn a baseline of your network traffic during the initial learning period after deployment. This learned baseline is stored indefinitely on your sensors.
10+
Microsoft Defender for IoT stores data in the Microsoft Azure portal, in OT network sensors, and in on-premises management consoles.
1111

12-
Defender for IoT also stores other data in the Azure portal, on OT network sensors, and on-premises management consoles.
12+
Each storage type has varying storage capacity options and retention times. This article describes the data retention policy for the amount of data and length of time the data is stored in each storage type before being deleted or overwritten.
1313

14-
Each storage location affords a certain storage capacity and retention times. This article describes how much and how long each type of data is stored in each location before it's either deleted or overridden.
14+
## What are we collecting?
15+
16+
Defender for IoT collects information from your configured devices and stores it in a service specific, customer-dedicated and segregated tenant. The stored data is for administration, tracking, and reporting purposes.
17+
18+
Information collected includes network connection data (IPs and ports), and device details (device identifiers, names, operating system versions, firmware versions). Defender for IoT stores this data securely in accordance with Microsoft privacy practices and [Microsoft Trust Center policies](https://azure.microsoft.com/explore/trusted-cloud/).
19+
20+
This data enables Defender for IoT to:
21+
22+
- Proactively identify indicators of attack (IOAs) in your organization.
23+
- Generate alerts if a possible attack is detected.
24+
- Provide your security team a view into devices and addresses related to threat signals from your network, enabling you to investigate and explore possible network security threats.
25+
26+
Microsoft doesn't use your data for advertising.
27+
28+
## Data location
29+
30+
Defender for IoT uses the Microsoft Azure data centers in the European Union and the United States. Customer data collected by the service might be stored in one of two geo-locations:
31+
32+
- The geolocation of the tenant as identified during provisioning.
33+
- The geolocation as defined by the data storage rules of an online service, that's used by Defender for IoT to process its data.
34+
35+
## Data retention
36+
37+
Data from Defender for IoT is retained for as long as a customer is active or for 90 days after the end of your contract. During this period the data is visible across your other services on the portal.
38+
39+
Your data is kept and is available while your license is under a grace period or in suspended mode. 90 days after the end of this period, your data is erased from Microsoft's systems making it unrecoverable.
1540

1641
## Device data retention periods
1742

18-
The following table lists how long device data is stored in each Defender for IoT location.
43+
The following table lists how long device data is stored in each Defender for IoT storage type.
1944

2045
| Storage type | Details |
2146
|---------|---------|
@@ -25,7 +50,7 @@ The following table lists how long device data is stored in each Defender for Io
2550

2651
## Alert data retention
2752

28-
The following table lists how long alert data is stored in each Defender for IoT location. Alert data is stored as listed, regardless of the alert's status, or whether it's been learned or muted.
53+
The following table lists how long alert data is stored in each Defender for IoT storage type. Alert data is stored as listed, regardless of the alert's status, or whether it's been learned or muted.
2954

3055
| Storage type | Details |
3156
|---------|---------|
@@ -35,12 +60,12 @@ The following table lists how long alert data is stored in each Defender for IoT
3560

3661
### OT alert PCAP data retention
3762

38-
The following table lists how long PCAP data is stored in each Defender for IoT location.
63+
The following table lists how long PCAP data is stored in each Defender for IoT storage type.
3964

4065
| Storage type | Details |
4166
|---------|---------|
4267
| **Azure portal** | PCAP files are available for download from the Azure portal for as long as the OT network sensor stores them. <br><br> Once downloaded, the files are cached on the Azure portal for 48 hours. <br><br> For more information, see [Access alert PCAP data](how-to-manage-cloud-alerts.md#access-alert-pcap-data). |
43-
| **OT network sensor** | Dependent on the sensor's storage capacity allocated for PCAP files, which is determined by its [hardware profile](ot-appliance-sizing.md): <br><br>- **C5600**: 130 GB <br>- **E1800**: 130 GB <br>- **E1000** : 78 GB<br>- **E500**: 78 GB <br>- **L500**: 7 GB <br>- **L100**: 2.5 GB<br><br> If a sensor exceeds its maximum storage capacity, the oldest PCAP file is deleted to accommodate the new one. <br><br> For more information, see [Access alert PCAP data](how-to-view-alerts.md#access-alert-pcap-data) and [Pre-configured physical appliances for OT monitoring](ot-pre-configured-appliances.md). |
68+
| **OT network sensor** | Dependent on the sensor's storage capacity allocated for PCAP files, which determines its [hardware profile](ot-appliance-sizing.md): <br><br>- **C5600**: 130 GB <br>- **E1800**: 130 GB <br>- **E1000** : 78 GB<br>- **E500**: 78 GB <br>- **L500**: 7 GB <br>- **L100**: 2.5 GB<br><br> If a sensor exceeds its maximum storage capacity, the oldest PCAP file is deleted to accommodate the new one. <br><br> For more information, see [Access alert PCAP data](how-to-view-alerts.md#access-alert-pcap-data) and [Pre-configured physical appliances for OT monitoring](ot-pre-configured-appliances.md). |
4469
| **On-premises management console** | PCAP files aren't stored on the on-premises management console and are only accessed from the on-premises management console via a direct link to the OT sensor. |
4570

4671
The usage of available PCAP storage space depends on factors such as the number of alerts, the type of the alert, and the network bandwidth, all of which affect the size of the PCAP file.
@@ -58,7 +83,7 @@ For more information, see [Enhance security posture with security recommendation
5883

5984
OT event timeline data is stored on OT network sensors only, and the storage capacity differs depending on the sensor's [hardware profile](ot-appliance-sizing.md).
6085

61-
The retention of event timeline data isn't limited by time. However, assuming a frequency of 500 events per day, all hardware profiles will be able to retain the events for at least **90 day**s.
86+
The retention of event timeline data isn't limited by time. However, assuming a frequency of 500 events per day, all hardware profiles are able to retain the events for at least **90 day**s.
6287

6388
If a sensor exceeds its maximum storage size, the oldest event timeline data file is deleted to accommodate the new one.
6489

@@ -86,47 +111,49 @@ For more information, see:
86111
- [Troubleshoot the sensor](how-to-troubleshoot-sensor.md)
87112
- [Troubleshoot the on-premises management console](legacy-central-management/how-to-troubleshoot-on-premises-management-console.md)
88113

89-
## Data sharing
90-
91-
Defender for IoT shares data, including customer data, among the following Microsoft products also licensed by the customer:
92-
93-
- Microsoft Security Exposure Management
94-
95-
## On-premises backup file capacity
114+
## Backup file capacity
96115

97-
Both the OT network sensor and the on-premises management console have automated backups running daily.
98-
99-
On both the OT sensor and the on-premises management console, older backup files are overridden when the configured storage capacity has reached its maximum.
116+
Both the OT network sensor and the on-premises management console have automated backups running daily, and older backup files are overwritten when the configured storage capacity reaches its limit.
100117

101118
For more information, see:
102119

103120
- [Set up backup and restore files on an OT sensor](back-up-restore-sensor.md#set-up-backup-and-restore-files)
104121
- [Configure OT sensor backup settings on an on premises management console](legacy-central-management/back-up-sensors-from-management.md#configure-ot-sensor-backup-settings)
105-
- [Configure OT sensor backup settings for an on-premises management console](legacy-central-management/back-up-sensors-from-management.md#configure-ot-sensor-backup-settings)
106122

107123
### Backups on the OT network sensor
108124

109125
The retention of backup files depends on the sensor's architecture, as each hardware profile has a set amount of hard disk space allocated for backup history:
110126

111127
| Hardware profile | Allocated hard disk space |
112128
|---------|---------|
113-
| **L100** | Backups are not supported |
114-
| **L500** | 20 GB |
129+
| **L100** | Backups aren't supported |
130+
| **L500** | 20 GB |
115131
| **E1000** | 60 GB |
116-
| **E1800** | 100 GB |
117-
| **C5600** | 100 GB |
132+
| **E1800** | 100 GB |
133+
| **C5600** | 100 GB |
118134

119-
If the device doesn't have allocated hard disk space, then only the last backup will be saved on the on-premises management console.
135+
If the device can't allocate enough hard disk space, then only the last backup is saved on the on-premises management console.
120136

121137
### Backups on the on-premises management console
122138

123139
Allocated hard disk space for on-premises management console backup files is limited to 10 GB and to only 20 backups.
124140

125141
If you're using an on-premises management console, each connected OT sensor also has its own, extra backup directory on the on-premises management console:
126142

127-
- A single sensor backup file is limited to a maximum of 40 GB. A file exceeding that size won't be sent to the on-premises management console.
143+
- A single sensor backup file is limited to a maximum of 40 GB. A file exceeding that size isn't sent to the on-premises management console.
128144
- Total hard disk space allocated to sensor backup from all sensors on the on-premises management console is 100 GB.
129145

146+
## Data sharing for Microsoft Defender for IoT
147+
148+
Microsoft Defender for IoT shares data, including customer data, among the following Microsoft products, also licensed by the customer.
149+
150+
- Microsoft Defender XDR
151+
- Microsoft Sentinel
152+
- Microsoft Threat Intelligence Center
153+
- Microsoft Defender for Cloud
154+
- Microsoft Defender for Endpoint
155+
- Microsoft Security Exposure Management
156+
130157
## Next steps
131158

132159
For more information, see:

0 commit comments

Comments
 (0)