Skip to content

Commit ab195ea

Browse files
Merge pull request #232128 from batamig/air-gapped-ent-tutorials
Deployment guide release: air-gapped, enterprise, and tutorials
2 parents 54b6bb5 + 2a55b60 commit ab195ea

16 files changed

+462
-105
lines changed

articles/defender-for-iot/organizations/TOC.yml

Lines changed: 29 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,20 +23,46 @@
2323
- name: Enable Enterprise IoT security
2424
href: eiot-defender-for-endpoint.md
2525
displayName: onboard
26+
- name: Deploy
27+
items:
28+
- name: Deploy air-gapped OT sensor management
29+
items:
30+
- name: Air-gapped management deployment path
31+
href: ot-deploy/air-gapped-deploy.md
32+
- name: Install an on-premises management console
33+
href: ot-deploy/install-software-on-premises-management-console.md
34+
- name: Activate and set up an on-premises management console
35+
href: ot-deploy/activate-deploy-management.md
36+
- name: Connect OT sensors to an on-premises management console
37+
href: ot-deploy/connect-sensors-to-management.md
38+
- name: Configure on-premises sites and zones
39+
href: ot-deploy/sites-and-zones-on-premises.md
40+
displayName: site, zone, Zero Trust
41+
- name: Deploy Enterprise IoT monitoring
42+
items:
43+
- name: Enable Enterprise IoT security
44+
href: eiot-defender-for-endpoint.md
45+
displayName: onboard
46+
- name: Discover Enterprise IoT devices
47+
href: eiot-sensor.md
48+
displayName: Enterprise IoT sensor
49+
- name: Extra deployment steps and samples
50+
href: extra-deploy-enterprise-iot.md
51+
displayName: Enterprise IoT sensor
2652
- name: Tutorials
2753
expanded: false
2854
items:
2955
- name: Onboard and activate a virtual OT sensor
3056
href: tutorial-onboarding.md
57+
- name: Investigate an OT network alert
58+
href: respond-ot-alert.md
3159
- name: Integrate with Microsoft Sentinel
3260
items:
3361
- name: Connect Defender for IoT cloud data to Microsoft Sentinel
3462
href: iot-solution.md
3563
- name: Investigate Defender for IoT incidents with Microsoft Sentinel
3664
href: iot-advanced-threat-monitoring.md
37-
- name: Investigate an OT network alert
38-
href: respond-ot-alert.md
39-
- name: Monitor with Zero Trust
65+
- name: Monitor with Zero Trust principles
4066
href: monitor-zero-trust.md
4167
- name: Concepts
4268
items:

articles/defender-for-iot/organizations/eiot-defender-for-endpoint.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -69,13 +69,11 @@ This procedure describes how to view related alerts, recommendations, and vulner
6969

7070
- On the **Discovered vulnerabilities** tab, check for any known CVEs associated with the device. Known CVEs can help decide whether to patch, remove, or contain the device and mitigate risk to your network.
7171

72-
73-
7472
## Next steps
7573

7674
Learn how to set up an Enterprise IoT network sensor (Public preview) and gain more visibility into more IoT segments of your corporate network that aren't otherwise covered by Defender for Endpoint.
7775

7876
Customers that have set up an Enterprise IoT network sensor will be able to see all discovered devices in the **Device inventory** in either Microsoft 365 Defender, or Defender for IoT in the Azure portal.
7977

8078
> [!div class="nextstepaction"]
81-
> [Enhance device discovery with an Enterprise IoT network sensor](eiot-sensor.md)
79+
> [Enhance device discovery with an Enterprise IoT network sensor](eiot-sensor.md)

articles/defender-for-iot/organizations/eiot-sensor.md

Lines changed: 24 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -25,27 +25,38 @@ For more information, see [Securing IoT devices in the enterprise](concept-enter
2525
2626
## Prerequisites
2727

28-
Before you start registering an Enterprise IoT sensor:
28+
This section describes the prerequisites required before deploying an Enterprise IoT network sensor.
2929

30-
- To view Defender for IoT data in Microsoft 365 Defender, including devices, alerts, recommendations, and vulnerabilities, you must have an Enterprise IoT plan, [onboarded from Microsoft 365 Defender](eiot-defender-for-endpoint.md).
30+
### Azure requirements
31+
32+
- To view Defender for IoT data in Microsoft 365 Defender, including devices, alerts, recommendations, and vulnerabilities, you must have an Enterprise IoT plan, [onboarded from Microsoft 365 Defender](eiot-defender-for-endpoint.md).
3133

3234
If you only want to view data in the Azure portal, an Enterprise IoT plan isn't required. You can also onboard your Enterprise IoT plan from Microsoft 365 Defender after registering your network sensor to bring [extra device visibility and security value](concept-enterprise.md#security-value-in-microsoft-365-defender) to your organization.
3335

3436
- Make sure you can access the Azure portal as a [Security admin](../../role-based-access-control/built-in-roles.md#security-admin), [Contributor](../../role-based-access-control/built-in-roles.md#contributor), or [Owner](../../role-based-access-control/built-in-roles.md#owner) user. If you don't already have an Azure account, you can [create your free Azure account today](https://azure.microsoft.com/free/).
3537

38+
### Network requirements
39+
40+
- Identify the devices and subnets you want to monitor so that you understand where to place an Enterprise IoT sensor in your network. You may want to deploy multiple Enterprise IoT sensors.
41+
42+
- Configure traffic mirroring in your network so that the traffic you want to monitor is mirrored to your Enterprise IoT sensor. Supported traffic mirroring methods are the same as for OT monitoring. For more information, see [Choose a traffic mirroring method for traffic monitoring](best-practices/traffic-mirroring-methods.md).
3643

37-
- Allocate a physical appliance or a virtual machine (VM) to use as your network sensor. Make sure that your machine has the following specifications:
44+
### Physical or virtual machine requirements
3845

39-
| Tier | Requirements |
40-
|--|--|
41-
| **Minimum** | To support up to 1 Gbps of data: <br><br>- 4 CPUs, each with 2.4 GHz or more<br>- 16-GB RAM of DDR4 or better<br>- 250 GB HDD |
42-
| **Recommended** | To support up to 15 Gbps of data: <br><br>- 8 CPUs, each with 2.4 GHz or more<br>- 32-GB RAM of DDR4 or better<br>- 500 GB HDD |
46+
Allocate a physical appliance or a virtual machine (VM) to use as your network sensor. Make sure that your machine has the following specifications:
4347

44-
Your machine must also have:
48+
| Tier | Requirements |
49+
|--|--|
50+
| **Minimum** | To support up to 1 Gbps of data: <br><br>- 4 CPUs, each with 2.4 GHz or more<br>- 16-GB RAM of DDR4 or better<br>- 250 GB HDD |
51+
| **Recommended** | To support up to 15 Gbps of data: <br><br>- 8 CPUs, each with 2.4 GHz or more<br>- 32-GB RAM of DDR4 or better<br>- 500 GB HDD |
4552

46-
- The [Ubuntu 18.04 Server](https://releases.ubuntu.com/18.04/) operating system. If you don't yet have Ubuntu installed, download the installation files to an external storage, such as a DVD or disk-on-key, and then install it on your appliance or VM. For more information, see the Ubuntu [Image Burning Guide](https://help.ubuntu.com/community/BurningIsoHowto).
53+
Your machine must also have:
4754

48-
- Network adapters, at least one for your switch monitoring (SPAN) port, and one for your management port to access the sensor's user interface
55+
- The [Ubuntu 18.04 Server](https://releases.ubuntu.com/18.04/) operating system. If you don't yet have Ubuntu installed, download the installation files to an external storage, such as a DVD or disk-on-key, and then install it on your appliance or VM. For more information, see the Ubuntu [Image Burning Guide](https://help.ubuntu.com/community/BurningIsoHowto).
56+
57+
- Network adapters, at least one for your switch monitoring (SPAN) port, and one for your management port to access the sensor's user interface
58+
59+
Your Enterprise IoT sensor must have access to the Azure cloud using a [direct connection](architecture-connections.md#direct-connections). Direct connections are configured for Enterprise IoT sensors using the same procedure as for OT sensors.
4960

5061
## Prepare a physical appliance or VM
5162

@@ -84,7 +95,6 @@ This procedure describes how to prepare your physical appliance or VM to install
8495
| HTTPS | TCP | In/Out | 443 | Cloud connection |
8596
| DNS | TCP/UDP | In/Out | 53 | Address resolution |
8697

87-
8898
1. Make sure that your physical appliance or VM can access the cloud using HTTPS on port 443 to the following Microsoft endpoints:
8999

90100
- **EventHub**: `*.servicebus.windows.net`
@@ -202,7 +212,7 @@ Delete a sensor if it's no longer in use with Defender for IoT.
202212

203213
1. From the **Sites and sensors** page on the Azure portal, locate your sensor in the grid.
204214

205-
1. In the row for your sensor, select the **...** options menu on the right > **Delete sensor**.
215+
1. In the row for your sensor, select the **...** options menu > **Delete sensor**.
206216

207217
For more information, see [Manage sensors with Defender for IoT in the Azure portal](how-to-manage-sensors-on-the-cloud.md).
208218

@@ -234,7 +244,7 @@ Billing changes will take effect one hour after cancellation of the previous sub
234244

235245
1. Delete the legacy sensor from the previous subscription. In Defender for IoT, go to the **Sites and sensors** page and locate the legacy sensor on the previous subscription.
236246

237-
1. In the row for your sensor, from the options (**...**) menu on the right, select **Delete** to delete the sensor from the previous subscription.
247+
1. In the row for your sensor, from the options (**...**) menu, select **Delete** to delete the sensor from the previous subscription.
238248

239249
1. If relevant, cancel the Defender for IoT plan from the previous subscription. For more information, see [Cancel your Enterprise IoT plan](manage-subscriptions-enterprise.md#cancel-your-enterprise-iot-plan).
240250

@@ -246,4 +256,4 @@ Billing changes will take effect one hour after cancellation of the previous sub
246256

247257
- [View and manage alerts from the Azure portal](how-to-manage-cloud-alerts.md). For more information, see [Malware engine alerts](alert-engine-messages.md#malware-engine-alerts).
248258

249-
- [Enhance security posture with security recommendations](recommendations.md)
259+
- [Enhance security posture with security recommendations](recommendations.md)
33.2 KB
Loading
34 KB
Loading
35.1 KB
Loading
38.9 KB
Loading
37.1 KB
Loading
37.4 KB
Loading

articles/defender-for-iot/organizations/monitor-zero-trust.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -237,4 +237,4 @@ For more information, see:
237237
- [Manage sensors with Defender for IoT in the Azure portal](how-to-manage-sensors-on-the-cloud.md)
238238
- [Manage on-premises sites and zones](ot-deploy/sites-and-zones-on-premises.md#manage-sites-and-zones)
239239
- [Manage site-based access control (Public preview)](manage-users-portal.md#manage-site-based-access-control-public-preview)
240-
- [Visualize Microsoft Defender for IoT data with Azure Monitor workbooks](workbooks.md)
240+
- [Visualize Microsoft Defender for IoT data with Azure Monitor workbooks](workbooks.md)

0 commit comments

Comments
 (0)