You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/configure-sensor-settings-portal.md
+25-31Lines changed: 25 additions & 31 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,27 +1,27 @@
1
1
---
2
-
title: Configure OT sensors from the Azure portal - Microsoft Defender for IoT
2
+
title: Configure OT sensor settings from the Azure portal - Microsoft Defender for IoT
3
3
description: Learn how to configure settings for OT network sensors from Microsoft Defender for IoT on the Azure portal.
4
4
ms.date: 12/27/2022
5
5
ms.topic: how-to
6
6
---
7
7
8
-
# Define and view OT sensor settings from the Azure portal (Public preview)
8
+
# Configure OT sensor settings from the Azure portal (Public preview)
9
9
10
-
After onboarding a new OT network sensor to Microsoft Defender for IoT, define several settings directly on the sensor console, such as [adding users](manage-users-sensor.md), [connecting to an on-premises management console](how-to-manage-individual-sensors.md#connect-a-sensor-to-the-management-console), and more.
10
+
After [onboarding](onboard-sensors.md) a new OT network sensor to Microsoft Defender for IoT, you may want to define several settings directly on the OT sensor console, such as [adding local users](manage-users-sensor.md) or [connecting to an on-premises management console](how-to-manage-individual-sensors.md#connect-a-sensor-to-the-management-console).
11
11
12
-
Selected sensor settings, listed below, are also available directly from the Azure portal, and can be applied in bulk across multiple cloud-connected sensors at a time, or across specific sites or zones. This article describes how to define and view OT network sensor settings from the Azure portal.
12
+
Selected OT sensor settings, listed below, are also available directly from the Azure portal, and can be applied in bulk across multiple cloud-connected OT sensors at a time, or across all OT sensors in a specific site or zone. This article describes how to view and configure view OT network sensor settings from the Azure portal.
13
13
14
14
> [!NOTE]
15
15
> The **Settings** page in Defender for IoT is in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include other legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
16
16
>
17
17
18
18
## Prerequisites
19
19
20
-
To define sensor settings, make sure that you have the following:
20
+
To define OT sensor settings, make sure that you have the following:
21
21
22
22
-**An Azure subscription onboarded to Defender for IoT**. If you need to, [sign up for a free account](https://azure.microsoft.com/free/) and then use the [Quickstart: Get started with Defender for IoT](getting-started.md) to onboard.
23
23
24
-
-**Permissions**:<!--yair to check with idan. is this the sensor owner operator role?-->
24
+
-**Permissions**:
25
25
26
26
- To view settings that others have defined, sign in with a [Security Reader](../../role-based-access-control/built-in-roles.md#security-reader), [Security admin](/azure/role-based-access-control/built-in-roles#security-admin), [Contributor](/azure/role-based-access-control/built-in-roles#contributor), or [Owner](/azure/role-based-access-control/built-in-roles#owner) role for the subscription.
27
27
@@ -33,38 +33,30 @@ To define sensor settings, make sure that you have the following:
33
33
34
34
## Define a new sensor setting
35
35
36
-
Define a new setting whenever you want to define a specific configuration for one or more OT network sensors. For example, you might want to define bandwidth caps for all sensors in a specific site or zone, or for a single sensor at a specific location in your network.
36
+
Define a new setting whenever you want to define a specific configuration for one or more OT network sensors. For example, you might want to define bandwidth caps for all OT sensors in a specific site or zone, or for a single OT sensor at a specific location in your network.
37
37
38
38
**To define a new setting**:
39
39
40
-
1. In Defender for IoT on the Azure portal, access the **Sensor settings (Preview)** page using one of the following paths:
41
-
42
-
- From the menu on the left, select **Settings (Preview)** > **Sensor settings (Preview)**<!--this still to change-->
43
-
- On the **Sites and sensors** page, select **Sensor settings (Preview)**
40
+
1. In Defender for IoT on the Azure portal, select **Sites and sensors** > **Sensor settings (Preview)**.
44
41
45
42
1. On the **Sensor settings (Preview)** page, select **+ Add**, and then use the wizard to define the following values for your setting. Select **Next** when you're done with each tab in the wizard to move to the next step.
46
43
47
44
|Tab name |Description |
48
45
|---------|---------|
49
46
|**Basics**| Select the subscription where you want to apply your setting, and your [setting type](#sensor-setting-reference). <br><br>Enter a meaningful name and an optional description for your setting. |
50
47
|**Setting**| Define the values for your selected setting type.<br>For details about the options available for each setting type, find your selected setting type in the [Sensor setting reference](#sensor-setting-reference) below. |
51
-
|**Apply**| Use the **Select sites**, **Select zones**, and **Select sensors** dropdown menus to define where you want to apply your setting. <br><br>**Important**: Selecting a site or zone applies the setting to all connected sensors, including any sensors added to the site or zone later on. <br>If you select to apply your settings to an entire site, you don't also need to select its zones or sensors. |
48
+
|**Apply**| Use the **Select sites**, **Select zones**, and **Select sensors** dropdown menus to define where you want to apply your setting. <br><br>**Important**: Selecting a site or zone applies the setting to all connected OT sensors, including any OT sensors added to the site or zone later on. <br>If you select to apply your settings to an entire site, you don't also need to select its zones or sensors. |
52
49
|**Review and create**| Check the selections you've made for your setting. <br><br>If your new setting replaces an existing setting, a :::image type="icon" source="media/how-to-manage-individual-sensors/warning-icon.png" border="false"::: warning is shown to indicate the existing setting.<br><br>When you're satisfied with the setting's configuration, select **Create**. |
53
50
54
-
Your new setting is now listed on the **Sensor settings (Preview)** page under it's setting type, and on the sensor details page for any related sensor. For example:
55
-
56
-
<!--screenshot tbd it's read only from here-->
57
-
51
+
Your new setting is now listed on the **Sensor settings (Preview)** page under it's setting type, and on the sensor details page for any related OT sensor. Sensor settings are shown as read-only on the sensor details page. For example:
58
52
53
+
:::image type="content" source="media/configure-sensor-settings-portal/sensor-details-setting.png" alt-text="Screenshot of a sensor details page showing a setting applied.":::
59
54
60
-
## View and edit current sensor settings
55
+
## View and edit current OT sensor settings
61
56
62
57
**To view the current settings already defined for your subscription**:
63
58
64
-
1. In Defender for IoT on the Azure portal, access the **Sensor settings (Preview)** page using one of the following paths:
65
-
66
-
- From the menu on the left, select **Settings (Preview)** > **Sensor settings (Preview)**<!--this still to change-->
67
-
- On the **Sites and sensors** page, select **Sensor settings (Preview)**
59
+
1. In Defender for IoT on the Azure portal, select **Sites and sensors** > **Sensor settings (Preview)**
68
60
69
61
The **Sensor settings (Preview)** page shows any settings already defined for your subscriptions, listed by setting type. Expand or collapse each type to view detailed configurations. For example:
70
62
@@ -74,9 +66,9 @@ Your new setting is now listed on the **Sensor settings (Preview)** page under i
74
66
75
67
1. To edit the setting's configuration, select **Edit** and then use the same wizard you used to create the setting to make the updates you need. When you're done, select **Apply** to save your changes.
76
68
77
-
### Delete an existing sensor setting
69
+
### Delete an existing OT sensor setting
78
70
79
-
To delete a sensor setting altogether:
71
+
To delete a OT sensor setting altogether:
80
72
81
73
1. On the **Sensor settings (Preview)** page, locate the setting you want to delete.
82
74
1. Select the **...** options menu at the top-right corner of the setting's card and then select **Delete**.
@@ -85,19 +77,21 @@ For example:
85
77
86
78
:::image type="content" source="media/configure-sensor-settings-portal/delete-setting.png" alt-text="Screenshot of the Delete setting option.":::
87
79
88
-
## Edit settings for disconnected sensors
80
+
## Edit settings for disconnected OT sensors
81
+
82
+
This procedure describes how to edit OT sensor settings if your OT sensor is currently disconnected from Azure, such as during an ongoing security incident.
89
83
90
-
This procedure describes how to edit sensor settings if your sensor is currently disconnected from Azure, such as during an ongoing security incident.
84
+
By default, if you've configured any settings from the Azure portal, all settings that are configurable from both the Azure portal and the OT sensor are set to read-only on the OT sensor itself. For example, if you've configured a VLAN from the Azure portal, then bandwidth cap, subnet, and VLAN settings are *all* set to read-only, and blocked from modifications on the OT sensor.
91
85
92
-
By default, if you've configured any sensor settings from the Azure portal, all settings that are configurable from both the Azure portal and the sensor are set to read-only on the sensor itself. For example, if you've configured a VLAN from the Azure portal, then bandwidth cap, subnet, and VLAN settings are *all* set to read-only, and blocked from modifications on the sensor.
86
+
If you're in a situation where the OT sensor is disconnected from Azure, and you need to modify one of these settings, you'll first need to gain write access to those settings.
93
87
94
-
If you're in a situation where the sensor is disconnected from Azure, and you need to modify one of these settings, you'll first need to gain write access to those settings.
88
+
**To gain write access to blocked OT sensor settings**:
95
89
96
-
**To gain write access to blocked sensor settings**:
90
+
1. On the Azure portal, in the **Sensor settings (Preview)** page, locate the setting you want to edit and open it for editing. For more information, see [View and edit current OT sensor settings](#view-and-edit-current-ot-sensor-settings) above.
97
91
98
-
1. On the Azure portal, in the **Sensor settings (Preview)** page, locate the setting you want to edit and open it for editing. For more information, see [View and edit current sensor settings](#view-and-edit-current-sensor-settings) above.
92
+
Edit the scope of the setting so that it no longer includes the OT sensor, and any changes you make while the OT sensor is disconnected aren't overwritten when you connect it back to Azure.
99
93
100
-
<!--rewrite this. you do this so that any changes you make won't get overwrriten when you connect it back to azure.-->Edit the scope of the setting so that it no longer includes the affected sensor. Settings defined on the Azure portal always overwrite settings defined on the sensor, so you'll want to make sure that your sensor changes won't be lost when it's reconnected to Azure.
94
+
Settings defined on the Azure portal always override settings defined on the OT sensor.
101
95
102
96
1. Sign into the affected OT sensor console, and select **Settings > Advanced configurations** > **Azure Remote Config**.
103
97
@@ -109,7 +103,7 @@ Continue by updating the relevant setting directly on the OT network sensor. For
109
103
110
104
## Sensor setting reference
111
105
112
-
Use the following sections to learn more about individual OT sensor settings:
106
+
Use the following sections to learn more about the individual OT sensor settings available from the Azure portal:
0 commit comments