Skip to content

Commit be6486b

Browse files
committed
validated draft
1 parent 8820bf3 commit be6486b

File tree

3 files changed

+26
-32
lines changed

3 files changed

+26
-32
lines changed

articles/defender-for-iot/organizations/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -235,7 +235,7 @@
235235
displayName: Enterprise IoT sensor
236236
- name: Manage sensors from the Azure portal
237237
href: how-to-manage-sensors-on-the-cloud.md
238-
- name: Define OT sensor settings from the Azure portal
238+
- name: Configure OT sensor settings from the Azure portal
239239
href: configure-sensor-settings-portal.md
240240
- name: Create and manage users
241241
items:

articles/defender-for-iot/organizations/configure-sensor-settings-portal.md

Lines changed: 25 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,27 +1,27 @@
11
---
2-
title: Configure OT sensors from the Azure portal - Microsoft Defender for IoT
2+
title: Configure OT sensor settings from the Azure portal - Microsoft Defender for IoT
33
description: Learn how to configure settings for OT network sensors from Microsoft Defender for IoT on the Azure portal.
44
ms.date: 12/27/2022
55
ms.topic: how-to
66
---
77

8-
# Define and view OT sensor settings from the Azure portal (Public preview)
8+
# Configure OT sensor settings from the Azure portal (Public preview)
99

10-
After onboarding a new OT network sensor to Microsoft Defender for IoT, define several settings directly on the sensor console, such as [adding users](manage-users-sensor.md), [connecting to an on-premises management console](how-to-manage-individual-sensors.md#connect-a-sensor-to-the-management-console), and more.
10+
After [onboarding](onboard-sensors.md) a new OT network sensor to Microsoft Defender for IoT, you may want to define several settings directly on the OT sensor console, such as [adding local users](manage-users-sensor.md) or [connecting to an on-premises management console](how-to-manage-individual-sensors.md#connect-a-sensor-to-the-management-console).
1111

12-
Selected sensor settings, listed below, are also available directly from the Azure portal, and can be applied in bulk across multiple cloud-connected sensors at a time, or across specific sites or zones. This article describes how to define and view OT network sensor settings from the Azure portal.
12+
Selected OT sensor settings, listed below, are also available directly from the Azure portal, and can be applied in bulk across multiple cloud-connected OT sensors at a time, or across all OT sensors in a specific site or zone. This article describes how to view and configure view OT network sensor settings from the Azure portal.
1313

1414
> [!NOTE]
1515
> The **Settings** page in Defender for IoT is in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include other legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
1616
>
1717
1818
## Prerequisites
1919

20-
To define sensor settings, make sure that you have the following:
20+
To define OT sensor settings, make sure that you have the following:
2121

2222
- **An Azure subscription onboarded to Defender for IoT**. If you need to, [sign up for a free account](https://azure.microsoft.com/free/) and then use the [Quickstart: Get started with Defender for IoT](getting-started.md) to onboard.
2323

24-
- **Permissions**: <!--yair to check with idan. is this the sensor owner operator role?-->
24+
- **Permissions**:
2525

2626
- To view settings that others have defined, sign in with a [Security Reader](../../role-based-access-control/built-in-roles.md#security-reader), [Security admin](/azure/role-based-access-control/built-in-roles#security-admin), [Contributor](/azure/role-based-access-control/built-in-roles#contributor), or [Owner](/azure/role-based-access-control/built-in-roles#owner) role for the subscription.
2727

@@ -33,38 +33,30 @@ To define sensor settings, make sure that you have the following:
3333

3434
## Define a new sensor setting
3535

36-
Define a new setting whenever you want to define a specific configuration for one or more OT network sensors. For example, you might want to define bandwidth caps for all sensors in a specific site or zone, or for a single sensor at a specific location in your network.
36+
Define a new setting whenever you want to define a specific configuration for one or more OT network sensors. For example, you might want to define bandwidth caps for all OT sensors in a specific site or zone, or for a single OT sensor at a specific location in your network.
3737

3838
**To define a new setting**:
3939

40-
1. In Defender for IoT on the Azure portal, access the **Sensor settings (Preview)** page using one of the following paths:
41-
42-
- From the menu on the left, select **Settings (Preview)** > **Sensor settings (Preview)** <!--this still to change-->
43-
- On the **Sites and sensors** page, select **Sensor settings (Preview)**
40+
1. In Defender for IoT on the Azure portal, select **Sites and sensors** > **Sensor settings (Preview)**.
4441

4542
1. On the **Sensor settings (Preview)** page, select **+ Add**, and then use the wizard to define the following values for your setting. Select **Next** when you're done with each tab in the wizard to move to the next step.
4643

4744
|Tab name |Description |
4845
|---------|---------|
4946
|**Basics** | Select the subscription where you want to apply your setting, and your [setting type](#sensor-setting-reference). <br><br>Enter a meaningful name and an optional description for your setting. |
5047
|**Setting** | Define the values for your selected setting type.<br>For details about the options available for each setting type, find your selected setting type in the [Sensor setting reference](#sensor-setting-reference) below. |
51-
|**Apply** | Use the **Select sites**, **Select zones**, and **Select sensors** dropdown menus to define where you want to apply your setting. <br><br>**Important**: Selecting a site or zone applies the setting to all connected sensors, including any sensors added to the site or zone later on. <br>If you select to apply your settings to an entire site, you don't also need to select its zones or sensors. |
48+
|**Apply** | Use the **Select sites**, **Select zones**, and **Select sensors** dropdown menus to define where you want to apply your setting. <br><br>**Important**: Selecting a site or zone applies the setting to all connected OT sensors, including any OT sensors added to the site or zone later on. <br>If you select to apply your settings to an entire site, you don't also need to select its zones or sensors. |
5249
|**Review and create** | Check the selections you've made for your setting. <br><br>If your new setting replaces an existing setting, a :::image type="icon" source="media/how-to-manage-individual-sensors/warning-icon.png" border="false"::: warning is shown to indicate the existing setting.<br><br>When you're satisfied with the setting's configuration, select **Create**. |
5350

54-
Your new setting is now listed on the **Sensor settings (Preview)** page under it's setting type, and on the sensor details page for any related sensor. For example:
55-
56-
<!--screenshot tbd it's read only from here-->
57-
51+
Your new setting is now listed on the **Sensor settings (Preview)** page under it's setting type, and on the sensor details page for any related OT sensor. Sensor settings are shown as read-only on the sensor details page. For example:
5852

53+
:::image type="content" source="media/configure-sensor-settings-portal/sensor-details-setting.png" alt-text="Screenshot of a sensor details page showing a setting applied.":::
5954

60-
## View and edit current sensor settings
55+
## View and edit current OT sensor settings
6156

6257
**To view the current settings already defined for your subscription**:
6358

64-
1. In Defender for IoT on the Azure portal, access the **Sensor settings (Preview)** page using one of the following paths:
65-
66-
- From the menu on the left, select **Settings (Preview)** > **Sensor settings (Preview)** <!--this still to change-->
67-
- On the **Sites and sensors** page, select **Sensor settings (Preview)**
59+
1. In Defender for IoT on the Azure portal, select **Sites and sensors** > **Sensor settings (Preview)**
6860

6961
The **Sensor settings (Preview)** page shows any settings already defined for your subscriptions, listed by setting type. Expand or collapse each type to view detailed configurations. For example:
7062

@@ -74,9 +66,9 @@ Your new setting is now listed on the **Sensor settings (Preview)** page under i
7466

7567
1. To edit the setting's configuration, select **Edit** and then use the same wizard you used to create the setting to make the updates you need. When you're done, select **Apply** to save your changes.
7668

77-
### Delete an existing sensor setting
69+
### Delete an existing OT sensor setting
7870

79-
To delete a sensor setting altogether:
71+
To delete a OT sensor setting altogether:
8072

8173
1. On the **Sensor settings (Preview)** page, locate the setting you want to delete.
8274
1. Select the **...** options menu at the top-right corner of the setting's card and then select **Delete**.
@@ -85,19 +77,21 @@ For example:
8577

8678
:::image type="content" source="media/configure-sensor-settings-portal/delete-setting.png" alt-text="Screenshot of the Delete setting option.":::
8779

88-
## Edit settings for disconnected sensors
80+
## Edit settings for disconnected OT sensors
81+
82+
This procedure describes how to edit OT sensor settings if your OT sensor is currently disconnected from Azure, such as during an ongoing security incident.
8983

90-
This procedure describes how to edit sensor settings if your sensor is currently disconnected from Azure, such as during an ongoing security incident.
84+
By default, if you've configured any settings from the Azure portal, all settings that are configurable from both the Azure portal and the OT sensor are set to read-only on the OT sensor itself. For example, if you've configured a VLAN from the Azure portal, then bandwidth cap, subnet, and VLAN settings are *all* set to read-only, and blocked from modifications on the OT sensor.
9185

92-
By default, if you've configured any sensor settings from the Azure portal, all settings that are configurable from both the Azure portal and the sensor are set to read-only on the sensor itself. For example, if you've configured a VLAN from the Azure portal, then bandwidth cap, subnet, and VLAN settings are *all* set to read-only, and blocked from modifications on the sensor.
86+
If you're in a situation where the OT sensor is disconnected from Azure, and you need to modify one of these settings, you'll first need to gain write access to those settings.
9387

94-
If you're in a situation where the sensor is disconnected from Azure, and you need to modify one of these settings, you'll first need to gain write access to those settings.
88+
**To gain write access to blocked OT sensor settings**:
9589

96-
**To gain write access to blocked sensor settings**:
90+
1. On the Azure portal, in the **Sensor settings (Preview)** page, locate the setting you want to edit and open it for editing. For more information, see [View and edit current OT sensor settings](#view-and-edit-current-ot-sensor-settings) above.
9791

98-
1. On the Azure portal, in the **Sensor settings (Preview)** page, locate the setting you want to edit and open it for editing. For more information, see [View and edit current sensor settings](#view-and-edit-current-sensor-settings) above.
92+
Edit the scope of the setting so that it no longer includes the OT sensor, and any changes you make while the OT sensor is disconnected aren't overwritten when you connect it back to Azure.
9993

100-
<!--rewrite this. you do this so that any changes you make won't get overwrriten when you connect it back to azure.-->Edit the scope of the setting so that it no longer includes the affected sensor. Settings defined on the Azure portal always overwrite settings defined on the sensor, so you'll want to make sure that your sensor changes won't be lost when it's reconnected to Azure.
94+
Settings defined on the Azure portal always override settings defined on the OT sensor.
10195

10296
1. Sign into the affected OT sensor console, and select **Settings > Advanced configurations** > **Azure Remote Config**.
10397

@@ -109,7 +103,7 @@ Continue by updating the relevant setting directly on the OT network sensor. For
109103

110104
## Sensor setting reference
111105

112-
Use the following sections to learn more about individual OT sensor settings:
106+
Use the following sections to learn more about the individual OT sensor settings available from the Azure portal:
113107

114108
### Bandwidth cap
115109

116 KB
Loading

0 commit comments

Comments
 (0)