Skip to content

Commit c070375

Browse files
Merge pull request #206223 from yoninalmsft/FAQ-new
FAQ EIoT
2 parents 246b02b + 433f6d7 commit c070375

File tree

6 files changed

+172
-32
lines changed

6 files changed

+172
-32
lines changed

.openpublishing.redirection.defender-for-iot.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,10 @@
11
{
22
"redirections": [
3+
{
4+
"source_path_from_root": "/articles/defender-for-iot/organizations/resources-frequently-asked-questions.md",
5+
"redirect_url": "/azure/defender-for-iot/organizations/faqs-general",
6+
"redirect_document_id": false
7+
},
38
{
49
"source_path_from_root": "/articles/defender-for-iot/organizations/appliance-catalog/appliance-catalog-overview.md",
510
"redirect_url": "/azure/defender-for-iot/organizations/appliance-catalog/index",

articles/defender-for-iot/organizations/TOC.yml

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -265,9 +265,14 @@
265265
href: references-work-with-defender-for-iot-apis.md
266266
- name: Defender for IoT CLI commands
267267
href: references-work-with-defender-for-iot-cli-commands.md
268-
- name: Frequently asked questions - service
269-
displayName: FAQ, regulation, internet, connection, hardware, appliances, ports, logs
270-
href: resources-frequently-asked-questions.md
268+
- name: Frequently asked questions
269+
items:
270+
- name: General FAQ
271+
href: faqs-general.md
272+
- name: OT networks FAQ
273+
href: faqs-ot.md
274+
- name: Enterprise IoT networks FAQ
275+
href: faqs-eiot.md
271276
- name: Defender for IoT glossary
272277
href: references-defender-for-iot-glossary.md
273278
- name: Resources
Lines changed: 106 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,106 @@
1+
---
2+
title: FAQs for Enterprise IoT networks - Microsoft Defender for IoT
3+
description: Find answers to the most frequently asked questions about Microsoft Defender for IoT Enterprise IoT networks.
4+
ms.topic: conceptual
5+
ms.date: 07/07/2022
6+
---
7+
8+
# Enterprise IoT networks frequently asked questions
9+
10+
This article provides a list of frequently asked questions and answers about Enterprise IoT networks in Defender for IoT.
11+
12+
## What is the difference between OT and Enterprise IoT?
13+
14+
### OT
15+
16+
OT network sensors use agentless, patented technology to discover, learn, and continuously monitor network devices for a deep visibility into Operational Technology (OT) / Industrial Control System (ICS) risks. Sensors carry out data collection, analysis, and alerting on-site, making them ideal for locations with low bandwidth or high latency.
17+
18+
### Enterprise IoT
19+
20+
Enterprise IoT provides visibility and security for IoT devices in the corporate environment.
21+
22+
Enterprise IoT network protection extends agentless features beyond operational environments, providing coverage for all IoT devices in your environment. For example, an enterprise IoT environment may include printers, cameras, and purpose-built, proprietary, devices.
23+
24+
## What additional security value can Enterprise IoT provide Microsoft Defender for Endpoint customers?
25+
26+
Enterprise IoT is designed to help customers secure unmanaged devices throughout the organization and extend IT security to also cover IoT devices. The solution leverages multiple means in order to ensure optimal coverage.
27+
28+
- **In the Microsoft Defender for Endpoint portal**: This is the GA offering for Enterprise IoT. Microsoft 365 P2 customers already have visibility for discovered IoT devices in the **Device inventory** page in Defender for Endpoint. Customers can onboard an Enterprise IoT plan in the same portal and gain security value by viewing alerts, recommendations and vulnerabilities for their discovered IoT devices.
29+
30+
- **In the Azure portal**: Defender for IoT customers can view their discovered IoT devices in the **Device inventory** page in Defender for IoT in the Azure portal. To view Enterprise IoT devices in the Azure portal, you'll need to set up a network sensor (currently in Public Preview). or more information, see [Tutorial: Get started with Enterprise IoT monitoring](tutorial-getting-started-eiot-sensor.md).
31+
32+
## How can I start using Enterprise IoT?
33+
34+
To get started, Microsoft 365 P2 customers need to [add a Defender for IoT plan with Enterprise IoT](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#onboard-a-defender-for-iot-plan) to an Azure subscription from the Microsoft Defender for Endpoint portal.
35+
36+
**Public Preview**: Defender for Endpoint customers can also install a network sensor to gain more visibility into additional IoT segments of the corporate network that weren't previously covered by Defender for Endpoint. Deploying a network sensor is not a prerequisite for onboarding Enterprise IoT.
37+
For more information, see [Tutorial: Get started with Enterprise IoT monitoring](tutorial-getting-started-eiot-sensor.md)
38+
39+
If you’re a Defender for Endpoint customer, when adding your Defender for IoT plan, take care to exclude any devices already managed by Defender for Endpoint from your count of committed devices.
40+
41+
## How can I use the Enterprise IoT network sensor?
42+
43+
The Enterprise IoT network sensor is currently in Public Preview and can be used by all customers without additional charge. Onboard a Defender for IoT plan with Enterprise IoT, and then set up your Enterprise IoT network sensor.
44+
45+
For more information, see [Tutorial: Get started with Enterprise IoT](tutorial-getting-started-eiot-sensor.md).
46+
47+
## What permissions do I need to add a Defender for IoT plan? Can I use any Azure subscription?
48+
49+
For information on required permissions, see [Prerequisites](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
50+
51+
## Which devices are billable?
52+
53+
For more information about billable devices, see [Defender for IoT committed devices](how-to-manage-subscriptions.md#defender-for-iot-committed-devices).
54+
55+
## How should I estimate the number of committed devices?
56+
57+
In the **Device inventory** in Defender for Endpoint:
58+
59+
Add the total number of discovered network devices with the total number of discovered IoT devices. Round that up to a multiple of 100, and that is the number of committed devices to use.
60+
61+
For more information, see [Defender for IoT committed devices](how-to-manage-subscriptions.md#defender-for-iot-committed-devices).
62+
63+
## How does the integration between Microsoft Defender for Endpoint and Microsoft Defender for IoT work?
64+
65+
Once you've [added a Defender for IoT plan with Enterprise IoT to an Azure subscription in Defender for Endpoint](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#onboard-a-defender-for-iot-plan), integration between the two products takes place seamlessly.
66+
67+
Discovered IoT devices can be viewed in both Defender for IoT and Defender for Endpoint. For more information, see [Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
68+
69+
## Can I change the subscription I’m using for Defender for IoT?
70+
71+
To change the subscription you're using for your Defender for IoT plan, you'll need to cancel your plan on the existing subscription, and then onboard a new plan to a new subscription. Your existing data won't be migrated to the new subscription. For more information, see [Move existing sensors to a different subscription](how-to-manage-subscriptions.md#move-existing-sensors-to-a-different-subscription).
72+
73+
## How can I edit my plan in Defender for Endpoint?
74+
75+
To make any changes to an existing plan, you'll need to cancel your existing plan and onboard a new plan with the new details. Changes might include moving billing charges from one subscription to another, changing the number of committed devices, or changing the plan commitment from a trial to a monthly commitment.
76+
77+
## How can I cancel Enterprise IoT?
78+
79+
To remove only Enterprise IoT from your plan, cancel your plan from Microsoft Defender for Endpoint. For more information, see [Cancel your Defender for IoT plan](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#cancel-your-defender-for-iot-plan).
80+
81+
To cancel the plan and remove all Defender for IoT services from the associated subscription, cancel the plan in Defender for IoT in the Azure portal. For more information, see [Cancel a Defender for IoT plan from a subscription](how-to-manage-subscriptions.md#cancel-a-defender-for-iot-plan-from-a-subscription).
82+
83+
## What happens when the 30-day trial ends?
84+
85+
If you haven't changed your plan from a trial to a monthly commitment by the time your trial ends, your plan is automatically canceled, and you’ll lose access to Defender for IoT security features.
86+
87+
To change your plan from a trial to a monthly commitment before the end of the trial, you'll need to cancel your trial plan and onboard a new plan in Defender for Endpoint. For more information, see [Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
88+
89+
## How is the Defender for IoT pricing affected now that support for Enterprise IoT networks is in General Availability?
90+
91+
For more information, see the [Microsoft Defender for IoT pricing](https://azure.microsoft.com/pricing/details/iot-defender/) page.
92+
93+
> [!NOTE]
94+
> The Enterprise IoT network sensor is currently in Public Preview.
95+
96+
## How can I resolve billing issues associated with my Defender for IoT plan?
97+
98+
For any billing or technical issues, create a support request in the Azure portal.
99+
100+
## Next steps
101+
102+
For more information on getting started with Enterprise IoT, see:
103+
104+
- [Tutorial: Get started with Enterprise IoT monitoring](tutorial-getting-started-eiot-sensor.md)
105+
- [Manage Defender for IoT plans](how-to-manage-subscriptions.md)
106+
- [Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration)
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
---
2+
title: General FAQs - Microsoft Defender for IoT
3+
description: Find answers to the most frequently asked questions about Microsoft Defender for IoT features and service.
4+
ms.topic: conceptual
5+
ms.date: 07/07/2022
6+
---
7+
8+
# Microsoft Defender for IoT frequently asked questions
9+
10+
This article provides a list of frequently asked questions and answers about Defender for IoT.
11+
12+
## What is Azure's unique value proposition for IoT security?
13+
14+
Defender for IoT enables enterprises to extend their existing cyber security view to their entire IoT solution. Azure provides an end to end view of your business solution, enabling you to take business-related actions and decisions based on your enterprise security posture and collected data. Combined security using Azure IoT, Azure IoT Edge, and Microsoft Defender for Cloud enable you to create the solution you want with the security you need.
15+
16+
## How does Defender for IoT compare to the competition?
17+
18+
Microsoft Defender for IoT delivers comprehensive security across all your IoT/OT devices. For **end-user organizations**, Microsoft Defender for IoT offers agentless, network-layer security that is rapidly deployed, works with diverse proprietary OT equipment and legacy Windows systems, and interoperates with Microsoft Sentinel and other SOC tools. It can be deployed on-premises or in Azure-connected environments. For **IoT device builders**, Microsoft Defender for IoT offers lightweight agents to embed device-layer security into new IoT/OT initiatives.
19+
20+
## Do I have to be an Azure customer?
21+
22+
No, for the agentless version of Microsoft Defender for IoT, you do not need to be an Azure customer. However, if you want to send alerts to Microsoft Sentinel; provision network sensors and monitor their health from the cloud; and benefit from automatic software and threat intelligence updates, you will need to connect the sensor to Azure and Defender for IoT. For more information, see [Sensor connection methods](architecture-connections.md).
23+
24+
For the agent-based version of Microsoft Defender for IoT, you must be an Azure customer.
25+
26+
## What happens when the internet connection stops working?
27+
28+
The sensors and agents continue to run and store data as long as the device is running. Data is stored in the security message cache according to size configuration. When the device regains connectivity, security messages resume sending.
29+
30+
## Next steps
31+
32+
To learn more about how to get started with Defender for IoT, see the following articles:
33+
34+
- Read the Defender for IoT [overview](overview.md)
35+
- [Get started with Defender for IoT](getting-started.md)
36+
- [OT Networks frequently asked questions](faqs-ot.md)
37+
- [Enterprise IoT networks frequently asked questions](faqs-eiot.md)
Lines changed: 7 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,13 @@
11
---
2-
title: Defender for IoT frequently asked questions
3-
description: Find answers to the most frequently asked questions about Microsoft Defender for IoT features and service.
2+
title: FAQs for OT networks - Microsoft Defender for IoT
3+
description: Find answers to the most frequently asked questions about Microsoft Defender for IoT OT networks.
44
ms.topic: conceptual
5-
ms.date: 11/09/2021
5+
ms.date: 07/07/2022
66
---
77

8-
# Microsoft Defender for IoT frequently asked questions
8+
# OT networks frequently asked questions
99

10-
This article provides a list of frequently asked questions and answers about Defender for IoT.
11-
12-
## What is Azure's unique value proposition for IoT security?
13-
14-
Defender for IoT enables enterprises to extend their existing cyber security view to their entire IoT solution. Azure provides an end to end view of your business solution, enabling you to take business-related actions and decisions based on your enterprise security posture and collected data. Combined security using Azure IoT, Azure IoT Edge, and Microsoft Defender for Cloud enable you to create the solution you want with the security you need.
10+
This article provides a list of frequently asked questions and answers about OT networks in Defender for IoT.
1511

1612
## Our organization uses proprietary non-standard industrial protocols. Are they supported?
1713

@@ -27,7 +23,6 @@ Microsoft Defender for IoT sensor runs on specific hardware specs as described i
2723

2824
Certified hardware has been tested in our labs for driver stability, packet drops and network sizing.
2925

30-
3126
## Regulation doesn't allow us to connect our system to the Internet. Can we still utilize Defender for IoT?
3227

3328
Yes you can! The Microsoft Defender for IoT platform on-premises solution is deployed as a physical or virtual sensor appliance that passively ingests network traffic (via SPAN, RSPAN, or TAP) to analyze, discover, and continuously monitor IT, OT, and IoT networks. For larger enterprises, multiple sensors can aggregate their data to an on-premises management console.
@@ -40,20 +35,6 @@ For example:
4035
- A single appliance (virtual of physical) can be in the Shop Floor DMZ layer, having all Shop Floor cell traffic routed to this layer.
4136
- Alternatively, locate small mini-sensors in each Shop Floor cell with either cloud or local management that will reside in the Shop Floor DMZ layer. Another appliance (virtual or physical) can monitor the traffic in the Shop Floor DMZ layer (for SCADA, Historian, or MES).
4237

43-
## How does Defender for IoT compare to the competition?
44-
45-
Microsoft Defender for IoT delivers comprehensive security across all your IoT/OT devices. For **end-user organizations**, Microsoft Defender for IoT offers agentless, network-layer security that is rapidly deployed, works with diverse proprietary OT equipment and legacy Windows systems, and interoperates with Microsoft Sentinel and other SOC tools. It can be deployed on-premises or in Azure-connected environments. For **IoT device builders**, Microsoft Defender for IoT offers lightweight agents to embed device-layer security into new IoT/OT initiatives.
46-
47-
## Do I have to be an Azure customer?
48-
49-
No, for the agentless version of Microsoft Defender for IoT, you do not need to be an Azure customer. However, if you want to send alerts to Microsoft Sentinel; provision network sensors and monitor their health from the cloud; and benefit from automatic software and threat intelligence updates, you will need to connect the sensor to Azure and Defender for IoT. For more information, see [Sensor connection methods](architecture-connections.md).
50-
51-
For the agent-based version of Microsoft Defender for IoT, you must be an Azure customer.
52-
53-
## What happens when the internet connection stops working?
54-
55-
The sensors and agents continue to run and store data as long as the device is running. Data is stored in the security message cache according to size configuration. When the device regains connectivity, security messages resume sending.
56-
5738
## How can I change a user's passwords
5839

5940
Learn how to [Change a user's password](how-to-create-and-manage-users.md#change-a-users-password) for either the sensor or the on-premises management console.
@@ -82,9 +63,6 @@ You can also use our [UI and CLI tools](how-to-troubleshoot-the-sensor-and-on-pr
8263

8364
For more information, see [Troubleshoot the sensor and on-premises management console](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md).
8465

85-
## Next steps
86-
87-
To learn more about how to get started with Defender for IoT, see the following articles:
66+
## Next Steps
8867

89-
- Read the Defender for IoT [overview](overview.md)
90-
- [Get started with Defender for IoT](getting-started.md)
68+
- [Tutorial: Get started with Microsoft Defender for IoT for OT security](tutorial-onboarding.md)

articles/defender-for-iot/organizations/tutorial-getting-started-eiot-sensor.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -217,6 +217,15 @@ For more information, see [Sensor management options from the Azure portal](how-
217217
218218
Continue viewing device data in both the Azure portal and Defender for Endpoint, depending on your organization's needs.
219219

220+
221+
- [Manage sensors with Defender for IoT in the Azure portal](how-to-manage-sensors-on-the-cloud.md)
222+
- [Threat intelligence research and packages](how-to-work-with-threat-intelligence-packages.md)
223+
- [Manage your IoT devices with the device inventory for organizations](how-to-manage-device-inventory-for-organizations.md)
224+
- [View and manage alerts on the Defender for IoT portal](how-to-manage-cloud-alerts.md)
225+
- [Use Azure Monitor workbooks in Microsoft Defender for IoT (Public preview)](workbooks.md)
226+
- [OT threat monitoring in enterprise SOCs](concept-sentinel-integration.md)
227+
- [Enterprise IoT networks frequently asked questions](faqs-eiot.md)
228+
220229
In Defender for Endpoint, also view alerts data, recommendations and vulnerabilities related to your network traffic.
221230

222231
For more information in Defender for Endpoint documentation, see:

0 commit comments

Comments
 (0)