You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/faqs-eiot.md
+23-28Lines changed: 23 additions & 28 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,12 +9,10 @@ ms.date: 07/07/2022
9
9
10
10
This article provides a list of frequently asked questions and answers about Enterprise IoT networks in Defender for IoT.
11
11
12
-
## What is the difference between OT and Enterprise IoT? What additional security value can Enterprise IoT provide Microsoft Defender for Endpoint customers?
12
+
## What is the difference between OT and Enterprise IoT?
13
13
14
14
### OT
15
15
16
-
Microsoft Defender for IoT provides agentless network detection and response (NDR) designed to secure ICS/OT devices and protocols across all industries. It seamlessly integrates with IT security tools, providing the ideal platform for those pursuing IT/OT convergence.
17
-
18
16
OT network sensors use agentless, patented technology to discover, learn, and continuously monitor network devices for a deep visibility into Operational Technology (OT) / Industrial Control System (ICS) risks. Sensors carry out data collection, analysis, and alerting on-site, making them ideal for locations with low bandwidth or high latency.
19
17
20
18
### Enterprise IoT
@@ -23,61 +21,58 @@ Enterprise IoT provides visibility and security for IoT devices in the corporate
23
21
24
22
Enterprise IoT network protection extends agentless features beyond operational environments, providing coverage for all IoT devices in your environment. For example, an enterprise IoT environment may include printers, cameras, and purpose-built, proprietary, devices.
25
23
26
-
-**In the Defender for Endpoint portal**: This is the GA offering for Enterprise IoT. P2 customers already have visibility for discovered IoT devices in the **Device inventory** page in Defender for Endpoint. Customers can onboard an Enterprise IoT plan in the same portal and gain security value by viewing alerts, recommendations and vulnerabilities for their discovered IoT devices.
24
+
## What additional security value can Enterprise IoT provide Microsoft Defender for Endpoint customers?
27
25
28
-
-**In the Azure portal**: Defender for IoT customers can view their discovered IoT devices in the **Device inventory** page in Defender for IoT in the Azure portal. To view Enterprise IoT devices in the Azure portal, you'll need to set up a network sensor (currently in Public Preview).
26
+
Enterprise IoT is designed to help customers secure unmanaged devices throughout the organization and extend IT security to also cover IoT devices. The solution leverages multiple means in order to ensure optimal coverage.
29
27
30
-
## How can I start using Enterprise IoT?
28
+
-**In the Defender for Endpoint portal**: This is the GA offering for Enterprise IoT. Microsoft 365 P2 customers already have visibility for discovered IoT devices in the **Device inventory** page in Defender for Endpoint. Customers can onboard an Enterprise IoT plan in the same portal and gain security value by viewing alerts, recommendations and vulnerabilities for their discovered IoT devices.
31
29
32
-
To get started, you'll need to add a Defender for IoT plan with Enterprise IoT to your Azure subscription from [Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#onboard-a-defender-for-iot-plan).
30
+
-**In the Azure portal**: Defender for IoT customers can view their discovered IoT devices in the **Device inventory** page in Defender for IoT in the Azure portal. To view Enterprise IoT devices in the Azure portal, you'll need to set up a network sensor (currently in Public Preview). or more information, see [Tutorial: Get started with Enterprise IoT monitoring](tutorial-getting-started-eiot-sensor.md).
33
31
34
-
- Microsoft 365 P2 customers can onboard the Enterprise IoT GA offering through the Microsoft Defender for Endpoint portal.
32
+
## How can I start using Enterprise IoT?
33
+
34
+
To get started, Microsoft 365 P2 customers need to [add a Defender for IoT plan with Enterprise IoT](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#onboard-a-defender-for-iot-plan) to an Azure subscription from the Microsoft Defender for Endpoint portal.
35
35
36
-
- Now in Public Preview - Defender for Endpoint customers can also install a network sensor to gain more visibility into additional IoT segments of the corporate network that were not previously covered by Defender for Endpoint. Deploying a network sensor is not a prerequisite for onboarding Enterprise IoT. For more information, see [Tutorial: Get started with Enterprise IoT monitoring](tutorial-getting-started-eiot-sensor.md)
36
+
**Public Preview**: Defender for Endpoint customers can also install a network sensor to gain more visibility into additional IoT segments of the corporate network that weren't previously covered by Defender for Endpoint. Deploying a network sensor is not a prerequisite for onboarding Enterprise IoT.
37
+
For more information, see [Tutorial: Get started with Enterprise IoT monitoring](tutorial-getting-started-eiot-sensor.md)
37
38
38
39
If you’re a Defender for Endpoint customer, when adding your Defender for IoT plan, take care to exclude any devices already managed by Defender for Endpoint from your count of committed devices.
39
40
40
-
For more information, see:
41
-
-[Tutorial: Get started with Enterprise IoT](tutorial-getting-started-eiot-sensor.md)
42
-
-[Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration)
43
-
44
41
## How can I use the Enterprise IoT network sensor?
45
42
46
-
The Enterprise IoT network sensor is currently in Public Preview and can be used by all customers without additional charge. Add a Defender for IoT plan with Enterprise IoT, and then set up your Enterprise IoT network sensor.
43
+
The Enterprise IoT network sensor is currently in Public Preview and can be used by all customers without additional charge. Onboard a Defender for IoT plan with Enterprise IoT, and then set up your Enterprise IoT network sensor.
47
44
48
45
For more information, see [Tutorial: Get started with Enterprise IoT](tutorial-getting-started-eiot-sensor.md).
49
46
50
47
## What permissions do I need to add a Defender for IoT plan? Can I use any Azure subscription?
51
48
52
-
Azure users with the **Security admin**, **Subscription owner** or **Subscription contributor** roles can add, edit, and cancel Defender for IoT plans. For more information, see [Permissions](getting-started.md#permissions).
53
-
54
-
Defender for Endpoint users with the **Global admin** role can add or cancel plans.
49
+
For information on required permissions, see [Prerequisites](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
55
50
56
51
## Which devices are billable?
57
52
58
-
Devices are listed in the Defender for IoT device inventory based on a unique IP and MAC address coupling. Charges are based on the number of committed devices you provide when adding a Defender for IoT plan.
59
-
60
-
If you're a Defender for Endpoint customer, devices (seats) that are managed by Defender for Endpoint aren't included in the number of devices counted as committed devices.
61
-
62
-
For more information, see [Defender for IoT committed devices](how-to-manage-subscriptions.md#defender-for-iot-committed-devices).
53
+
For more information about billable devices, see [Defender for IoT committed devices](how-to-manage-subscriptions.md#defender-for-iot-committed-devices).
63
54
64
55
## How should I estimate the number of committed devices?
65
56
66
-
We suggest using existing resources in your environment, for example Meraki, CMDB and other sources to get that estimation, as well as the device inventories in Defender for Endpoint and Defender for IoT. Once you have onboarded Defender for IoT, discovered devices will begin to populate in the device inventory and then you can update the number of your committed devices accordingly. A device would be a set combination of IP address and a MAC address. For more information, see [Defender for IoT committed devices](how-to-manage-subscriptions.md#defender-for-iot-committed-devices).
57
+
In the **Device inventory** in MDE:
67
58
68
-
## Can I edit information in Defender for IoT about a discovered device?
59
+
Add the total number of discovered network devices with the total number of discovered IoT devices. Round that up to a multiple of 100, and that is the number of committed devices to use.
69
60
70
-
You can edit several properties for devices, and even delete devices from the Defender for IoT **Device inventory** page. For more information, see [Edit device details](how-to-manage-device-inventory-for-organizations.md#edit-device-details).
61
+
For more information, see [Defender for IoT committed devices](how-to-manage-subscriptions.md#defender-for-iot-committed-devices).
71
62
72
63
## How does the integration between Microsoft Defender for Endpoint and Microsoft Defender for IoT work?
73
64
74
-
Integration between the two products takes place seamlessly, once you have [added a Defender for IoT plan with Enterprise IoT to an Azure subscription in Defender for Endpoint](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#onboard-a-defender-for-iot-plan).
65
+
Once you've [added a Defender for IoT plan with Enterprise IoT to an Azure subscription in Defender for Endpoint](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration#onboard-a-defender-for-iot-plan),integration between the two products takes place seamlessly.
75
66
76
67
Discovered IoT devices can be viewed in both Defender for IoT and Defender for Endpoint. For more information, see [Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
77
68
78
69
## Can I change the subscription I’m using for Defender for IoT?
79
70
80
-
To change the subscription you're using for your Defender for IoT plan, you'll need to cancel your plan on the existing subscription, and then add a new plan to a new subscription. Your existing data won't be migrated to the new subscription. For more information, see [Move existing sensors to a different subscription](how-to-manage-subscriptions.md#move-existing-sensors-to-a-different-subscription).
71
+
To change the subscription you're using for your Defender for IoT plan, you'll need to cancel your plan on the existing subscription, and then onboard a new plan to a new subscription. Your existing data won't be migrated to the new subscription. For more information, see [Move existing sensors to a different subscription](how-to-manage-subscriptions.md#move-existing-sensors-to-a-different-subscription).
72
+
73
+
## How can I edit my plan in Defender for Endpoint?
74
+
75
+
To make any changes to an existing plan, you'll need to cancel your existing plan and onboard a new plan with the new details. Changes might include moving billing charges from one subscription to another, changing the number of committed devices, or changing the plan commitment from a trial to a monthly commitment.
81
76
82
77
## How can I cancel Enterprise IoT?
83
78
@@ -89,7 +84,7 @@ To cancel the plan and remove all Defender for IoT services from the associated
89
84
90
85
If you haven't changed your plan from a trial to a monthly commitment by the time your trial ends, your plan is automatically canceled, and you’ll lose access to Defender for IoT security features.
91
86
92
-
To change your plan from a trial to a monthly or annual commitment, you'll need to cancel your trial plan and onboard a new plan in Defender for Endpoint. For more information, see [Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
87
+
To change your plan from a trial to a monthly commitment before the end of the trial, you'll need to cancel your trial plan and onboard a new plan in Defender for Endpoint. For more information, see [Defender for IoT integration](/microsoft-365/security/defender-endpoint/enable-microsoft-defender-for-iot-integration).
93
88
94
89
## How is the Defender for IoT pricing affected now that support for Enterprise IoT networks is in General Availability?
0 commit comments