Skip to content

Commit 8dabdd8

Browse files
committed
changes
1 parent f27b0e4 commit 8dabdd8

File tree

3 files changed

+3
-4
lines changed

3 files changed

+3
-4
lines changed

articles/defender-for-iot/organizations/how-to-manage-individual-sensors.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -222,7 +222,7 @@ A Microsoft Defender for IoT OT network sensor starts monitoring your network au
222222

223223
Initially, this activity happens in *learning* mode, which instructs your OT sensor to learn your network's usual activity, including the devices and protocols in your network, and the regular file transfers that occur between specific devices. Any regularly detected activity becomes your network's [baseline traffic](ot-deploy/create-learned-baseline.md).
224224

225-
This procedure describes how to turn off learning mode manually if you feel that the current alerts accurately reflect your network activity.
225+
This procedure describes how to turn off learning mode manually when the current alerts accurately reflect your network activity.
226226

227227
**To turn off learning mode**:
228228

articles/defender-for-iot/organizations/ot-deploy/create-learned-baseline.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,6 @@ An OT network sensor starts monitoring your network automatically after it's con
1717

1818
Initially, this activity happens in *learning* mode, which instructs your OT sensor to learn your network's usual activity, including the devices and protocols in your network, and the regular file transfers that occur between specific devices. Any regularly detected activity becomes your network's baseline traffic.
1919

20-
2120
> [!TIP]
2221
> Use your time in learning mode to triage your alerts and *Learn* those that you want to mark as authorized, expected activity. Learned traffic doesn't generate new alerts the next time the same traffic is detected.
2322
>
@@ -27,7 +26,7 @@ For more information, see [Microsoft Defender for IoT alerts](../alerts.md).
2726

2827
### Learn mode timeline
2928

30-
Creating your baseline of OT alerts can take anywhere from a few days to several weeks, depending on your network size and complexity. Learning mode automatically turns off when the sensor detects a decrease in newly detected traffic, which is typically between 2-6 weeks after deployment.
29+
Creating your baseline of OT alerts can take anywhere from a few days to several weeks, depending on your network size and complexity. We recommend that after 2-6 weeks, depending on your network size, you manually change the Learning mode to Dynamic mode when the sensor detects a decrease in newly detected traffic.
3130

3231
[Turn off learning mode manually before then](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) if you feel that the current alerts accurately reflect your network activity.
3332

articles/defender-for-iot/organizations/ot-deploy/ot-deploy-path.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -182,7 +182,7 @@ Your OT sensors will remain in *Learning mode* for as long as new traffic is det
182182
When baseline learning ends, the OT monitoring deployment process is complete, and you'll continue on in operational mode for ongoing monitoring. In operational mode, any activity that differs from your baseline data will trigger an alert.
183183

184184
> [!TIP]
185-
> [Turn off learning mode manually](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) if you feel that the current alerts in Defender for IoT reflect your network traffic accurately, and learning mode hasn't already ended automatically.
185+
> [Turn off learning mode manually](../how-to-manage-individual-sensors.md#turn-off-learning-mode-manually) when the current alerts in Defender for IoT reflect your network traffic accurately.
186186
>
187187
188188
## Connect Defender for IoT data to your SIEM

0 commit comments

Comments
 (0)