Skip to content

Commit 73490aa

Browse files
committed
device notifications and transient devices
1 parent 2319f7d commit 73490aa

File tree

3 files changed

+33
-5
lines changed

3 files changed

+33
-5
lines changed

articles/defender-for-iot/organizations/device-inventory.md

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ For more information, see:
4444
> - [Defender for Endpoint device discovery](/microsoft-365/security/defender-endpoint/device-discovery)
4545
>
4646
47-
## Supported device classes
47+
## Supported devices
4848

4949
Defender for IoT's device inventory supports the following device classes:
5050

@@ -56,7 +56,19 @@ Defender for IoT's device inventory supports the following device classes:
5656
|**Network devices** | Switches, routers, controllers, or access points |
5757
|**OT devices** | Industrial and operational devices, such as PLCs, historian devices, HMIs, scales, pneumatic devices, or packaging systems |
5858

59-
A *transient* device type indicates a device that was connected to the network for a very short time before disconnecting. We recommend investigating these devices carefully to understand their impact on your network.
59+
60+
|Devices |For example ... |
61+
|---------|---------|
62+
|**Manufacturing**| Industrial and operational devices, such as pneumatic devices, packaging systems, industrial packaging systems, industrial robots |
63+
|**Building** | Access panels, surveillance devices, HVAC systems, elevators , smart lighting systems |
64+
|**Health care** | Glucose meters, monitors |
65+
|**Transportation / Utilities** | Turnstiles, people counters, motion sensors, fire and safety systems, intercoms |
66+
|**Energy and resources** | DCS controllers, PLCs, historian devices, HMIs |
67+
|**Endpoint devices** | Workstations, servers, or mobile devices |
68+
| **Enterprise** | Smart devices, printers, communication devices, or audio/video devices |
69+
| **Retail** | Barcode scanners, humidity sensor, punch clocks |
70+
71+
A *transient* device type indicates a device that was detected for only a short time. We recommend investigating these devices carefully to understand their impact on your network.
6072

6173
*Unclassified* devices are devices that don't otherwise have an out-of-the-box category defined.
6274

articles/defender-for-iot/organizations/how-to-manage-individual-sensors.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -429,6 +429,20 @@ Maximum size for uploaded files is 2 GB.
429429
> [!TIP]
430430
> Select **Clear All** to clear the sensor of all PCAP files loaded.
431431
432+
## Modify notification auto-resolve thresholds
433+
434+
By default, selected device notifications are automatically resolved if they aren't dismissed or otherwise handled within 14 days. Admin users can change this threshold to more or fewer days in the OT sensor's system settings.
435+
436+
**To modify auto-resolve thresholds**:
437+
438+
1. Sign into your OT sensor as an **Admin** user.
439+
1. Select **System settings** > **Advanced configurations** > **Conflicts**.
440+
1. Locate the `notifications_resolve_threshold_days=14` line and change `14` to another integer.
441+
1. Select **Save** > **Close** to save your changes.
442+
443+
For more information, see [Manage device notifications](how-to-work-with-the-sensor-device-map.md#manage-device-notifications).
444+
445+
432446
## Adjust system properties
433447

434448
System properties control various operations and settings in the sensor. Editing or modifying them might damage the operation of the sensor console.

articles/defender-for-iot/organizations/how-to-work-with-the-sensor-device-map.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -177,7 +177,9 @@ For example, you might receive a notification about an inactive device that need
177177
- Select **Select All** to show which notifications can be [handled together](#handling-multiple-notifications-together). Clear selections for specific notifications, and then select **Accept All** or **Dismiss All** to handle any remaining selected notifications together.
178178

179179
> [!NOTE]
180-
> Selected notifications are automatically resolved if they aren't dismissed or otherwise handled within 14 days. For more information, see the action indicated in the **Auto-resolve** column in the table [below](#device-notification-responses).
180+
> By default, selected notifications are automatically resolved if they aren't dismissed or otherwise handled within 14 days. Admin users can change this threshold in the OT sensor's system setting.
181+
>
182+
> For more information, see the action indicated in the **Auto-resolve** column in the table [below](#device-notification-responses) and <xref>.
181183
>
182184
183185
### Handling multiple notifications together
@@ -190,15 +192,15 @@ You may have situations where you'd want to handle multiple notifications togeth
190192

191193
When you handle multiple notifications together, you may still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected.
192194

195+
193196
### Device notification responses
194197

195198
The following table lists available responses for each notification, and when we recommend using each one:
196199

197200
| Type | Description | Available responses | Auto-resolve|
198201
|--|--|--|--|
199202
| **New IP detected** | A new IP address is associated with the device. This may occur in the following scenarios: <br><br>- A new or additional IP address was associated with a device already detected, with an existing MAC address.<br><br> - A new IP address was detected for a device that's using a NetBIOS name. <br /><br /> - An IP address was detected as the management interface for a device associated with a MAC address. <br /><br /> - A new IP address was detected for a device that's using a virtual IP address. | - **Set Additional IP to Device**: Merge the devices <br />- **Replace Existing IP**: Replaces any existing IP address with the new address <br /> - **Dismiss**: Remove the notification. |**Dismiss** |
200-
| **Inactive devices** | Traffic wasn't detected on a device for more than 60 days. | - **Delete**: Delete any devices that aren't part of your network anymore.<br />- **Dismiss**: Remove the notification if the device is still part of your network. You may want to reconnect the device if it's been disconnected by accident.|**Delete** |
201-
| **New OT devices** | A subnet includes an OT device that's not defined in an ICS subnet. <br><br>This may occur when a device is detected that can be defined as an ICS subnet. We recommend defining such devices as ICS subnets to differentiate between OT and IT devices on the map. | - **Set as ICS Subnet**: Define the device as an ICS subnet. <br>- **Dismiss**: Remove the notification if the device isn't part of the subnet. |No automatic handling|
203+
| <!--check w meir and remove this-->**New OT devices** | A subnet includes an OT device that's not defined in an ICS subnet. <br><br>This may occur when a device is detected that can be defined as an ICS subnet. We recommend defining such devices as ICS subnets to differentiate between OT and IT devices on the map. | - **Set as ICS Subnet**: Define the device as an ICS subnet. <br>- **Dismiss**: Remove the notification if the device isn't part of the subnet. |No automatic handling|
202204
| **No subnets configured** | No subnets are currently configured in your network. <br /><br /> We recommend configuring subnets for the ability to differentiate between OT and IT devices on the map. | - **Open Subnets Configuration** and [configure subnets](how-to-control-what-traffic-is-monitored.md#configure-subnets). <br />- **Dismiss**: Remove the notification. |**Dismiss** |
203205
| **Operating system changes** | One or more new operating systems have been associated with the device. | - Select the name of the new OS that you want to associate with the device.<br /> - **Dismiss**: Remove the notification. |No automatic handling<!--Set with new operating system only if not already configured manually. <br><br>If the operating system has already been configured: **Dismiss**.-->|
204206
| **New subnets** | New subnets were discovered. |- **Learn**: Automatically add the subnet.<br />- **Open Subnet Configuration**: Add all missing subnet information.<br />- **Dismiss**<br />Remove the notification. |**Dismiss** |

0 commit comments

Comments
 (0)