Skip to content

Commit b5f7e56

Browse files
committed
merge conflicts
2 parents fd2ebeb + 9c2f5b0 commit b5f7e56

File tree

3 files changed

+139
-60
lines changed

3 files changed

+139
-60
lines changed

articles/defender-for-iot/organizations/how-to-investigate-sensor-detections-in-a-device-inventory.md

Lines changed: 60 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Manage your OT device inventory from a sensor console
33
description: Learn how to view and manage OT devices (assets) from the Device inventory page on a sensor console.
4-
ms.date: 07/12/2022
4+
ms.date: 07/21/2022
55
ms.topic: how-to
66
---
77

@@ -72,32 +72,76 @@ To export device inventory data, on the **Device inventory** page, select **Expo
7272

7373
The device inventory is exported with any filters currently applied, and you can save the file locally.
7474

75-
## Delete a device
75+
## Merge devices
7676

77-
If you have devices no longer in use, delete them from the device inventory so that they're no longer connected to Defender for IoT.
77+
You may need to merge duplicate devices if the sensor has discovered separate network entities that are associated with a single, unique device.
7878

79-
Devices might be inactive because of misconfigured SPAN ports, changes in network coverage, or because the device was unplugged from the network.
79+
Examples of this scenario might include a PLC with four network cards, a laptop with both WiFi and a physical network card, or a single workstation with multiple network cards.
8080

81-
Delete inactive devices to maintain a correct representation of current network activity, better understand your committed devices when managing your Defender for IoT plans, and to reduce clutter on your screen.
81+
> [!NOTE]
82+
> - You can only merge authorized devices.
83+
> - Device merges are irreversible. If you merge devices incorrectly, you'll have to delete the merged device and wait for the sensor to rediscover both devices.
84+
> - Alternately, merge devices from the [Device map](how-to-work-with-the-sensor-device-map.md) page.
85+
When merging, you instruct the sensor to combine the device properties of two devices into one. When you do this, the Device Properties window and sensor reports will be updated with the new device property details.
8286

83-
Devices you delete from the Inventory are removed from the map and won't be calculated when generating Defender for IoT reports, for example Data Mining, Risk Assessment, and Attack Vector reports.
87+
For example, if you merge two devices, each with an IP address, both IP addresses will appear as separate interfaces in the Device Properties window.
8488

85-
> [!NOTE]
86-
> Devices must be inactive for 7 days or more in order for you to be able to delete them.
87-
>
89+
**To merge devices from the device inventory:**
90+
91+
1. Use the SHIFT key to select two devices from the inventory, and then right-click one of them.
92+
93+
1. Select **Merge** to merge the devices. This can take up to 2 minutes to complete.
94+
95+
1. When the **Set merge device attributes** dialog appears, enter a meaningful name for your merged device, and then select **Save**.
8896

89-
**To delete inactive devices**:
97+
## View inactive devices
9098

91-
1. On the **Device inventory** page, filter the grid by the **Last Activity** field. In the **Filter** field, select one of the following time periods:
99+
You may want to view devices in your network that have been inactive and delete them.
100+
101+
For example, devices may become inactive because of misconfigured SPAN ports, changes in network coverage, or by unplugging them from the network
102+
103+
**To view inactive devices**, filter the device inventory to display devices that have been inactive.
104+
105+
On the **Device inventory** page:
106+
107+
1. Select **Add filter**.
108+
1. Select **Last Activity** in the column field.
109+
1. Choose the time period in the **Filter** field. Filtering options include seven days or more, 14 days or more, 30 days or more, or 90 days or more.
110+
111+
> [!TIP]
112+
> We recommend that you [delete](#delete-devices) inactive devices to display a more accurate representation of current network activity, better evaluate [committed devices](architecture.md#what-is-a-defender-for-iot-committed-device), and reduce clutter on your screen.
92113
93-
- for seven days or more
94-
- for 14 days or more
95-
- 30 days or more
96-
- 90 days or more
114+
## Delete devices
97115

116+
You may want to delete devices from your device inventory, such as if they've been [merged incorrectly](#merge-devices), or are [inactive](#view-inactive-devices).
117+
118+
Deleted devices are removed from the **Device map** and the device inventories on the Azure portal and on-premises management console, and aren't calculated when generating reports, such as Data Mining, Risk Assessment, or Attack Vector reports.
119+
120+
**To delete a single device**:
121+
122+
You can delete a single device when they’ve been inactive for more than 10 minutes.
123+
124+
1. In the **Device inventory** page, select the device you want to delete, and then select **Delete** :::image type="icon" source="media/how-to-manage-device-inventory-on-the-cloud/delete-device.png" border="false"::: in the toolbar at the top of the page.
125+
1. At the prompt, select **Yes** to confirm that you want to delete the device from Defender for IoT.
126+
127+
**To delete all inactive devices**
128+
129+
This procedure is supported for the *cyberx* and admin users only.
130+
131+
1. Select the **Last Seen** filter icon in the Inventory.
132+
1. Select a filter option.
133+
1. Select **Apply**.
98134
1. Select **Delete Inactive Devices**. In the prompt displayed, enter the reason you're deleting the devices, and then select **Delete**.
99135

100-
All devices detected within the range of the selected filter are deleted. If there are a large number of devices to delete, the process may take a few minutes.
136+
All devices detected within the range of the filter will be deleted. If you delete a large number of devices, the delete process may take a few minutes.
137+
138+
## Export device inventory information
139+
140+
You can export device inventory information to a .csv file.
141+
142+
**To export:**
143+
144+
- Select **Export file** from the Device Inventory page. The report is generated and downloaded.
101145

102146
## Device inventory column reference
103147

articles/defender-for-iot/organizations/release-notes.md

Lines changed: 19 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: What's new in Microsoft Defender for IoT
33
description: This article lets you know what's new in the latest release of Defender for IoT.
44
ms.topic: overview
5-
ms.date: 07/18/2022
5+
ms.date: 07/21/2022
66
---
77

88
# What's new in Microsoft Defender for IoT?
@@ -63,7 +63,7 @@ For more information, see the [Microsoft Security Development Lifecycle practice
6363
|Service area |Updates |
6464
|---------|---------|
6565
|**Enterprise IoT networks** | - [Enterprise IoT purchase experience and Defender for Endpoint integration in GA](#enterprise-iot-purchase-experience-and-defender-for-endpoint-integration-in-ga) |
66-
|**OT networks** |**Sensor software version 22.2.4**: <br>- [**Last seen** on devices replaced by **Last activity**](#last-seen-on-devices-replaced-by-last-activity)<br>- [Enhancements for the ServiceNow integration API](#enhancements-for-the-servicenow-integration-api)<br><br>**Sensor software version 22.2.3**:<br>- [OT appliance hardware profile updates](#ot-appliance-hardware-profile-updates)<br>- [PCAP access from the Azure portal](#pcap-access-from-the-azure-portal-public-preview)<br>- [Bi-directional alert synch between sensors and the Azure portal](#bi-directional-alert-synch-between-sensors-and-the-azure-portal-public-preview)<br>- [Support diagnostic log enhancements](#support-diagnostic-log-enhancements-public-preview)<br>- [Improved security for uploading protocol plugins](#improved-security-for-uploading-protocol-plugins)<br>- [Sensor names shown in browser tabs](#sensor-names-shown-in-browser-tabs)<br><br>To update to version 22.2.3:<br>- From version 22.1.x, update directly to version 22.2.3<br>- From version 10.x, first update to version 21.1.6, and then update again to 22.2.3<br><br>For more information, see [Update Defender for IoT OT monitoring software](update-ot-software.md). |
66+
|**OT networks** |**Sensor software version 22.2.4**: <br>- [Device inventory enhancements](#device-inventory-enhancements)<br>- [Enhancements for the ServiceNow integration API](#enhancements-for-the-servicenow-integration-api)<br><br>**Sensor software version 22.2.3**:<br>- [OT appliance hardware profile updates](#ot-appliance-hardware-profile-updates)<br>- [PCAP access from the Azure portal](#pcap-access-from-the-azure-portal-public-preview)<br>- [Bi-directional alert synch between sensors and the Azure portal](#bi-directional-alert-synch-between-sensors-and-the-azure-portal-public-preview)<br>- [Support diagnostic log enhancements](#support-diagnostic-log-enhancements-public-preview)<br>- [Improved security for uploading protocol plugins](#improved-security-for-uploading-protocol-plugins)<br>- [Sensor names shown in browser tabs](#sensor-names-shown-in-browser-tabs)<br><br>To update to version 22.2.3:<br>- From version 22.1.x, update directly to version 22.2.3<br>- From version 10.x, first update to version 21.1.6, and then update again to 22.2.3<br><br>For more information, see [Update Defender for IoT OT monitoring software](update-ot-software.md). |
6767
|**Cloud-only features** | - [Microsoft Sentinel incident synch with Defender for IoT alerts](#microsoft-sentinel-incident-synch-with-defender-for-iot-alerts) |
6868

6969
### Enterprise IoT purchase experience and Defender for Endpoint integration in GA
@@ -79,9 +79,25 @@ Defender for IoT’s new purchase experience and the Enterprise IoT integration
7979
> [!NOTE]
8080
> The Enterprise IoT network sensor and all detections remain in Public Preview.
8181
82+
### Device inventory enhancements
83+
84+
Starting in OT sensor versions 22.2.4, you can now take the following actions from the sensor console's **Device inventory** page:
85+
86+
- **Merge duplicate devices**. You may need to merge devices if the sensor has discovered separate network entities that are associated with a single, unique device. Examples of this scenario might include a PLC with four network cards, a laptop with both WiFi and a physical network card, or a single workstation with multiple network cards.
87+
88+
- **Delete single devices**. Now, you can delete a single device that hasn't communicated for at least 10 minutes.
89+
90+
- **Delete inactive devices by admin users**. Now, all admin users, in addition to the **cyberx** user, can delete inactive devices.
91+
92+
Also starting in version 22.2.4, in the sensor console's **Device inventory** page, the **Last seen** value in the device details pane is replaced by **Last activity**. For example:
93+
94+
:::image type="content" source="media/release-notes/last-activity-new.png" alt-text="Screenshot of the new Last activity field showing in the sensor console's device details pane on the Device inventory page.":::
95+
96+
For more information, see [Manage your OT device inventory from a sensor console](how-to-investigate-sensor-detections-in-a-device-inventory.md).
97+
8298
### Enhancements for the ServiceNow integration API
8399

84-
This version of the sensor provides enhancements for the `devicecves` API, which gets details about the CVEs found for a given device.
100+
OT sensor version 22.2.4 provides enhancements for the `devicecves` API, which gets details about the CVEs found for a given device.
85101

86102
Now you can add any of the following parameters to your query to fine tune your results:
87103

@@ -91,14 +107,6 @@ Now you can add any of the following parameters to your query to fine tune your
91107

92108
For more information, see [ServiceNow Integration API - “/external/v3/integration/ (Preview)](references-work-with-defender-for-iot-apis.md#servicenow-integration-api---externalv3integration-preview).
93109

94-
### Last seen on devices replaced by Last activity
95-
96-
In the sensor console's **Device inventory** page, the **Last seen** value in the device details pane is replaced by **Last activity**. For example:
97-
98-
:::image type="content" source="media/release-notes/last-activity-new.png" alt-text="Screenshot of the new Last activity field showing in the sensor console's device details pane on the Device inventory page.":::
99-
100-
For more information, see [Manage your OT device inventory from a sensor console](how-to-investigate-sensor-detections-in-a-device-inventory.md).
101-
102110
### OT appliance hardware profile updates
103111

104112
We've refreshed the naming conventions for our OT appliance hardware profiles for greater transparency and clarity.

0 commit comments

Comments
 (0)