Skip to content

Commit a502bd3

Browse files
Merge pull request #237255 from yoninalmsft/ics-subnet-device-type
Manually define ICS subnet
2 parents 0a83e66 + ddd49c2 commit a502bd3

File tree

1 file changed

+20
-1
lines changed

1 file changed

+20
-1
lines changed

articles/defender-for-iot/organizations/how-to-control-what-traffic-is-monitored.md

Lines changed: 20 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,11 +59,30 @@ While the OT network sensor automatically learns the subnets in your network, we
5959
|**Clear all** | Clear all currently defined subnets. |
6060
|**Auto subnet learning** | Selected by default. Clear this option to define your subnets manually instead of having them automatically detected by your OT sensor as new devices are detected. |
6161
|**Resolve all Internet traffic as internal/private** | Select to consider all public IP addresses as private, local addresses. If selected, public IP addresses are treated as local addresses, and alerts aren't sent about unauthorized internet activity. <br><br>This option reduces notifications and alerts received about external addresses. |
62-
|**ICS subnet** | Read-only. ICS/OT subnets are marked automatically when the system recognizes OT activity or protocols. |
62+
|**ICS subnet** | Read-only. ICS/OT subnets are marked automatically when the system recognizes OT activity or protocols. If there is an OT subnet not being recognized, you can [manually define a subnet as ICS](#manually-define-a-subnet-as-ics). |
6363
|**Segregated** | Select to show this subnet separately when displaying the device map according to Purdue level. |
6464

6565
1. When you're done, select **Save** to save your updates.
6666

67+
### Manually define a subnet as ICS
68+
69+
If you have an OT subnet that is not being marked automatically as an ICS subnet by the sensor, edit the device type for any of the devices in the relevant subnet to an ICS or IoT device type. The subnet will then be automatically marked by the sensor as an ICS subnet.
70+
71+
> [!NOTE]
72+
> To manually change the subnet to be marked as ICS, the device type must be changed in device inventory in the OT sensor, and not from the Azure portal.
73+
74+
**To change the device type to manually update the subnet**:
75+
76+
1. Sign in to your OT sensor console and go to **Device inventory**.
77+
78+
1. In the device inventory grid, select a device from the relevant subnet, and then select **Edit** in the toolbar at the top of the page.
79+
80+
1. In the **Type** field, select a device type from the dropdown list that is listed under **ICS** or **IoT**.
81+
82+
The subnet will now be marked as an ICS subnet in the sensor.
83+
84+
For more information, see [Edit device details](how-to-investigate-sensor-detections-in-a-device-inventory.md#edit-device-details).
85+
6786
## Customize port and VLAN names
6887

6988
Use the following procedures to enrich the device data shown in Defender for IoT by customizing port and VLAN names on your OT network sensors.

0 commit comments

Comments
 (0)