You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/device-inventory.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,6 +58,8 @@ Defender for IoT's device inventory supports the following device classes:
58
58
59
59
*Unclassified* devices are devices that don't have an out-of-the-box category defined.
60
60
61
+
<!--how to add in about transient devices?-->
62
+
61
63
## Unauthorized devices
62
64
63
65
When you're first working with Defender for IoT, during the learning period just after deploying a sensor, all devices detected are identified as *authorized* devices.
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-work-with-the-sensor-device-map.md
+23-17Lines changed: 23 additions & 17 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -157,7 +157,7 @@ It can take up to two minutes complete the merge. Merge events are listed in the
157
157
158
158
## Manage device notifications
159
159
160
-
As opposed to alerts, which provide details about changes in your traffic that might present a threat to your network, device notifications on an OT sensor device map provide details about network activity that might require your attention, but aren't threats.
160
+
As opposed to alerts, which provide details about changes in your traffic that might present a threat to your network, device notifications on an OT sensor device map provide details about network activity that might require your attention, but aren't threats.
161
161
162
162
For example, you might receive a notification about an inactive device that needs to be reconnected, or removed if it's no longer part of the network.
163
163
@@ -174,29 +174,35 @@ For example, you might receive a notification about an inactive device that need
174
174
1. Each notification may have different mitigation options. Do one of the following:
175
175
176
176
- Handle one notification at a time, selecting a specific mitigation action, or selecting **Dismiss** to close the notification with no activity.
177
-
- Select **Select All** to show which notifications can be handled together. Clear selections for specific notifications, and then select **Accept All** or **Dismiss All** to handle any remaining selected notifications together.
178
-
179
-
When you handle multiple notifications together, you may still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected.
177
+
- Select **Select All** to show which notifications can be [handled together](#handling-multiple-notifications-together). Clear selections for specific notifications, and then select **Accept All** or **Dismiss All** to handle any remaining selected notifications together.
180
178
181
179
> [!NOTE]
182
-
> For example, you may want to handle multiple notifications together if:
183
-
>
184
-
> - IT upgraded the OS across multiple network servers and you want to learn all of the new server versions.
185
-
> - A group of devices is no longer active, and you want to instruct the OT sensor to remove the devices from the OT sensor.
180
+
> Selected notifications are automatically resolved if they aren't dismissed or otherwise handled within 14 days. For more information, see the action indicated in the **Auto-resolve** column in the table [below](#device-notification-responses).
181
+
>
182
+
183
+
### Handling multiple notifications together
184
+
185
+
You may have situations where you'd want to handle multiple notifications together, such as:
186
+
187
+
- IT upgraded the OS across multiple network servers and you want to learn all of the new server versions.
188
+
189
+
- A group of devices is no longer active, and you want to instruct the OT sensor to remove the devices from the OT sensor.
190
+
191
+
When you handle multiple notifications together, you may still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected.
186
192
187
193
### Device notification responses
188
194
189
195
The following table lists available responses for each notification, and when we recommend using each one:
190
196
191
-
| Type | Description | Available responses |
192
-
|--|--|--|
193
-
|**New IP detected**| A new IP address is associated with the device. This may occur in the following scenarios: <br><br>- A new or additional IP address was associated with a device already detected, with an existing MAC address.<br><br> - A new IP address was detected for a device that's using a NetBIOS name. <br /><br /> - An IP address was detected as the management interface for a device associated with a MAC address. <br /><br /> - A new IP address was detected for a device that's using a virtual IP address. | - **Set Additional IP to Device**: Merge the devices <br />- **Replace Existing IP**: Replaces any existing IP address with the new address <br /> - **Dismiss**: Remove the notification. |
194
-
|**Inactive devices**| Traffic wasn't detected on a device for more than 60 days. | - **Delete**: Delete any devices that aren't part of your network anymore.<br />- **Dismiss**: Remove the notification if the device is still part of your network. You may want to reconnect the device if it's been disconnected by accident.|
195
-
|**New OT devices**| A subnet includes an OT device that's not defined in an ICS subnet. <br><br>This may occur when a device is detected that can be defined as an ICS subnet. We recommend defining such devices as ICS subnets to differentiate between OT and IT devices on the map. | - **Set as ICS Subnet**: Define the device as an ICS subnet. <br>- **Dismiss**: Remove the notification if the device isn't part of the subnet. |
196
-
|**No subnets configured**| No subnets are currently configured in your network. <br /><br /> We recommend configuring subnets for the ability to differentiate between OT and IT devices on the map. | - **Open Subnets Configuration** and [configure subnets](how-to-control-what-traffic-is-monitored.md#configure-subnets). <br />- **Dismiss**: Remove the notification. |
197
-
|**Operating system changes**| One or more new operating systems have been associated with the device. | - Select the name of the new OS that you want to associate with the device.<br /> - **Dismiss**: Remove the notification. |
198
-
|**New subnets**| New subnets were discovered. |- **Learn**: Automatically add the subnet.<br />- **Open Subnet Configuration**: Add all missing subnet information.<br />- **Dismiss**<br />Remove the notification. |
199
-
|**Device type changes**| A new device type has been associated with the device. | - **Set as {…}**: Associate the new type with the device.<br />- **Dismiss**: Remove the notification. |
197
+
| Type | Description | Available responses | Auto-resolve|
198
+
|--|--|--|--|
199
+
|**New IP detected**| A new IP address is associated with the device. This may occur in the following scenarios: <br><br>- A new or additional IP address was associated with a device already detected, with an existing MAC address.<br><br> - A new IP address was detected for a device that's using a NetBIOS name. <br /><br /> - An IP address was detected as the management interface for a device associated with a MAC address. <br /><br /> - A new IP address was detected for a device that's using a virtual IP address. | - **Set Additional IP to Device**: Merge the devices <br />- **Replace Existing IP**: Replaces any existing IP address with the new address <br /> - **Dismiss**: Remove the notification. |**Dismiss**|
200
+
|**Inactive devices**| Traffic wasn't detected on a device for more than 60 days. | - **Delete**: Delete any devices that aren't part of your network anymore.<br />- **Dismiss**: Remove the notification if the device is still part of your network. You may want to reconnect the device if it's been disconnected by accident.|**Delete**|
201
+
|**New OT devices**| A subnet includes an OT device that's not defined in an ICS subnet. <br><br>This may occur when a device is detected that can be defined as an ICS subnet. We recommend defining such devices as ICS subnets to differentiate between OT and IT devices on the map. | - **Set as ICS Subnet**: Define the device as an ICS subnet. <br>- **Dismiss**: Remove the notification if the device isn't part of the subnet. |No automatic handling|
202
+
|**No subnets configured**| No subnets are currently configured in your network. <br /><br /> We recommend configuring subnets for the ability to differentiate between OT and IT devices on the map. | - **Open Subnets Configuration** and [configure subnets](how-to-control-what-traffic-is-monitored.md#configure-subnets). <br />- **Dismiss**: Remove the notification. |**Dismiss**|
203
+
|**Operating system changes**| One or more new operating systems have been associated with the device. | - Select the name of the new OS that you want to associate with the device.<br /> - **Dismiss**: Remove the notification. |No automatic handling<!--Set with new operating system only if not already configured manually. <br><br>If the operating system has already been configured: **Dismiss**.-->|
204
+
|**New subnets**| New subnets were discovered. |- **Learn**: Automatically add the subnet.<br />- **Open Subnet Configuration**: Add all missing subnet information.<br />- **Dismiss**<br />Remove the notification. |**Dismiss**|
205
+
|**Device type changes**| A new device type has been associated with the device. | - **Set as {…}**: Associate the new type with the device.<br />- **Dismiss**: Remove the notification. |No automatic handling<!--Set with new device type only if not already configured manually. <br><br>If the device type has already been configured: **Dismiss**.-->|
0 commit comments