Skip to content

Commit e7d659b

Browse files
authored
Merge pull request #292060 from limwainstein/cm-deprecation-whats-new
Cm deprecation whats new
2 parents a8dd065 + 31f6f37 commit e7d659b

File tree

9 files changed

+114
-70
lines changed

9 files changed

+114
-70
lines changed

articles/defender-for-iot/organizations/TOC.yml

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@
5656
- name: Deploy OT monitoring
5757
items:
5858
- name: OT deployment path
59-
href: ot-deploy/ot-deploy-path.md
59+
href: ot-deploy/ot-deploy-path.md
6060
- name: Plan and prepare for an OT deployment
6161
items:
6262
- name: Plan your OT monitoring system
@@ -130,8 +130,17 @@
130130
href: ot-deploy/update-device-inventory.md
131131
- name: Create a learned baseline of OT alerts
132132
href: ot-deploy/create-learned-baseline.md
133-
- name: Deploy in hybrid or air-gapped environments
134-
href: ot-deploy/air-gapped-deploy.md
133+
- name: Hybrid or air-gapped environments
134+
items:
135+
- name: Deploy hybrid or air-gapped
136+
href: ot-deploy/air-gapped-deploy.md
137+
- name: On-premises management console
138+
items:
139+
- name: On-premises management console retirement
140+
href: ot-deploy/on-premises-management-console-retirement.md
141+
- name: Transition to the cloud
142+
href: ot-deploy/transition-on-premises-management-console-to-cloud.md
143+
135144
- name: Tutorials
136145
items:
137146
- name: Onboard and activate a virtual OT sensor
63 KB
Loading

articles/defender-for-iot/organizations/ot-deploy/air-gapped-deploy.md

Lines changed: 6 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,13 @@ ms.date: 09/19/2023
99

1010
Microsoft Defender for IoT helps organizations achieve and maintain compliance of their OT environment by providing a comprehensive solution for threat detection and management, including coverage across parallel networks. Defender for IoT supports organizations across the industrial, energy, and utility fields, and compliance organizations like NERC CIP or IEC62443.
1111

12+
> [!IMPORTANT]
13+
> The legacy on-premises management console won't be supported or available for download after January 1st, 2025. We recommend transitioning to the new architecture using the full spectrum of on-premises and cloud APIs before this date. For more information, see [On-premises management console retirement](on-premises-management-console-retirement.md).
14+
>
15+
1216
Certain industries, such as governmental organizations, financial services, nuclear power operators, and industrial manufacturing, maintain air-gapped networks. Air-gapped networks are physically separated from other, unsecured networks like enterprise networks, guest networks, or the internet. Defender for IoT helps these organizations comply with global standards for threat detection and management, network segmentation, and more.
1317

14-
While digital transformation has helped businesses to streamline their operations and improve their bottom lines, they often face friction with air-gapped networks. The isolation in air-gapped networks provides security but also complicates digital transformation. For example, architectural designs such as Zero Trust, which include the use of multi-factor authentication, are challenging to apply across air-gapped networks.
18+
While digital transformation has helped businesses to streamline their operations and improve their bottom lines, they often face friction with air-gapped networks. The isolation in air-gapped networks provides security but also complicates digital transformation. For example, architectural designs such as Zero Trust, which include the use of multifactor authentication, are challenging to apply across air-gapped networks.
1519

1620
Air-gapped networks are often used to store sensitive data or control cyber physical systems that are not connected to any external network, making them less vulnerable to cyberattacks. However, air-gapped networks are not completely secure and can still be breached. It's therefore imperative to monitor air-gapped networks to detect and respond to any potential threats.
1721

@@ -61,52 +65,8 @@ Use the following steps to deploy a Defender for IoT system in an air-gapped or
6165

6266
- **Configure a backup server**, including configurations to save your backup to an external server. For more information, see [Back up and restore OT network sensors from the sensor console](../back-up-restore-sensor.md).
6367

64-
## Transitioning from a legacy on-premises management console
65-
66-
> [!IMPORTANT]
67-
> The [legacy on-premises management console](../legacy-central-management/legacy-air-gapped-deploy.md) won't be supported or available for download after January 1st, 2025. We recommend transitioning to the new architecture using the full spectrum of on-premises and cloud APIs before this date.
68-
>
69-
70-
Our [current architecture guidance](#architecture-recommendations) is designed to be more efficient, secure, and reliable than using the legacy on-premises management console. The updated guidance has fewer components, which makes it easier to maintain and troubleshoot. The smart sensor technology used in the new architecture allows for on-premises processing, reducing the need for cloud resources and improving performance. The updated guidance keeps your data within your own network, providing better security than cloud computing.
71-
72-
If you're an existing customer using an on-premises management console to manage your OT sensors, we recommend transitioning to the updated architecture guidance. The following image shows a graphical representation of the transition steps to the new recommendations:
73-
74-
:::image type="content" source="../media/on-premises-architecture/transition.png" alt-text="Diagram of the transition from a legacy on-premises management console to the newer recommendations." border="false" lightbox="../media/on-premises-architecture/transition.png":::
75-
76-
- **In your legacy configuration**, all sensors are connected to the on-premises management console.
77-
- **During the transition period**, your sensors remain connected to the on-premises management console while you connect any sensors possible to the cloud.
78-
- **After fully transitioning**, you'll remove the connection to the on-premises management console, keeping cloud connections where possible. Any sensors that must remain air-gapped are accessible directly from the sensor UI.
79-
80-
**Use the following steps to transition your architecture:**
81-
82-
1. For each of your OT sensors, identify the legacy integrations in use and the permissions currently configured for on-premises security teams. For example, what backup systems are in place? Which user groups access the sensor data?
83-
84-
1. Connect your sensors to on-premises, Azure, and other cloud resources, as needed for each site. For example, connect to an on-premises SIEM, proxy servers, backup storage, and other partner systems. You may have multiple sites and adopt a hybrid approach, where only specific sites are kept completely air-gapped or isolated using data-diodes.
85-
86-
For more information, see the information linked in the [air-gapped deployment procedure](#deployment-steps), as well as the following cloud resources:
87-
88-
- [Provision sensors for cloud management](provision-cloud-management.md)
89-
- [OT threat monitoring in enterprise SOCs](../concept-sentinel-integration.md)
90-
- [Securing IoT devices in the enterprise](../concept-enterprise.md)
91-
92-
1. Set up permissions and update procedures for accessing your sensors to match the new deployment architecture.
93-
94-
1. Review and validate that all security use cases and procedures have transitioned to the new architecture.
95-
96-
1. After your transition is complete, decommission the on-premises management console.
97-
98-
### Retirement timeline of the Central Manager
99-
100-
The on-premises management console will be retired on **January 1, 2025** with the following updates/changes:
101-
102-
- Sensor versions released after **January 1, 2025** won't be managed by an on-premises management console.
103-
- Air-gapped sensor support isn't affected by these changes to the on-premises management console support. We continue to support air-gapped deployments and assist with the transition to the cloud. The sensors retain a full user interface so that they can be used in "lights out" scenarios and continue to analyze and secure the network in the event of an outage.
104-
- Air-gapped sensors that can't <!-- or don't / aren't connected to-->connect to the cloud can be managed directly via the sensor console GUI, CLI, or API.
105-
- Sensor software versions released between **January 1st, 2024 – January 1st, 2025** still support the on-premises management console.
106-
107-
For more information, see [OT monitoring software versions](../release-notes.md).
10868

10969
## Next steps
11070

11171
> [!div class="step-by-step"]
112-
> [Maintain OT network sensors from the sensor console](../how-to-manage-individual-sensors.md)
72+
> [Transition from a legacy on-premises management console to the cloud](transition-on-premises-management-console-to-cloud.md)
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
---
2+
title: On-premises management console retirement - Microsoft Defender for IoT
3+
description: This article describes the retirement of the on-premises management console from **January 1, 2025**.
4+
ms.topic: conceptual
5+
ms.date: 12/17/2024
6+
---
7+
8+
# On-premises management console retirement
9+
10+
This article describes the retirement of the on-premises management console from **January 1, 2025**.
11+
12+
## Retirement details
13+
14+
The on-premises management console will be retired on **January 1, 2025** with the following updates/changes:
15+
16+
- Sensor versions released after **January 1, 2025** won't connect to the on-premises management console.
17+
- For versions released prior to **January 1, 2025**:
18+
- You can still use the on-premises management console.
19+
- Defender for IoT no longer provides support service or maintains the on-premises management console.
20+
21+
For a list of supported versions, see [OT monitoring software versions](../release-notes.md)
22+
23+
## Air-gapped sensor support
24+
25+
Air-gapped sensor support isn't affected by the on-premises management console retirement. We continue to support air-gapped deployments and assist with the [transition to the cloud](transition-on-premises-management-console-to-cloud.md). The sensors retain a full user interface so that they can be used in "lights out" scenarios and continue to analyze and secure the network in the event of an outage.
26+
27+
If your organization enforces a policy where sensors can't access the internet (air-gapped), you can continue to manage sensors using:
28+
- [The sensor console UI](../how-to-investigate-sensor-detections-in-a-device-inventory.md) or the [CLI](../cli-ot-sensor.md) to directly manage individual sensors.
29+
- [APIs](../references-work-with-defender-for-iot-apis.md) to send data to third-party management systems, such as a Security Information and Event Management (SIEM).
30+
31+
## Next steps
32+
33+
> [!div class="step-by-step"]
34+
> [Transition from a legacy on-premises management console to the cloud](transition-on-premises-management-console-to-cloud.md)
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
---
2+
title: Transition from a legacy on-premises management console to the cloud
3+
description: This article describes how to transition from the on-premises management console to the cloud.
4+
ms.topic: how-to
5+
ms.date: 12/17/2024
6+
---
7+
8+
# Transition from a legacy on-premises management console to the cloud
9+
10+
This article describes how to transition from the on-premises management console to the cloud.
11+
12+
> [!IMPORTANT]
13+
> The on-premises management console won't be supported or available for download after January 1st, 2025. For more information, see [on-premises management console retirement](on-premises-management-console-retirement.md).
14+
>
15+
16+
Our [current architecture guidance](#architecture-guidance) is designed to be more efficient, secure, and reliable than using the legacy on-premises management console. The updated guidance has fewer components, which makes it easier to maintain and troubleshoot. The smart sensor technology used in the new architecture allows for on-premises processing, reducing the need for cloud resources and improving performance. The updated guidance keeps your data within your own network, providing better security than cloud computing.
17+
18+
## Architecture guidance
19+
20+
If you're an existing customer using an on-premises management console to manage your OT sensors, we recommend transitioning to the updated architecture guidance. The following image shows a graphical representation of the transition steps to the new recommendations:
21+
22+
:::image type="content" source="../media/on-premises-architecture/transition-new.png" alt-text="Diagram of the transition from a legacy on-premises management console to the newer recommendations." border="false":::
23+
24+
## How to manage the transition period
25+
26+
- **In your legacy configuration**, all sensors are connected to the on-premises management console.
27+
- **During the transition period**, your sensors remain connected to the on-premises management console while you connect any sensors possible to the cloud.
28+
- **After fully transitioning**, you'll remove the connection to the on-premises management console, keeping cloud connections where possible. Any sensors that must remain air-gapped are accessible directly from the sensor UI.
29+
30+
## Transition your architecture
31+
32+
1. For each of your OT sensors, identify the legacy integrations in use and the permissions currently configured for on-premises security teams. For example, what backup systems are in place? Which user groups access the sensor data?
33+
34+
1. Connect your sensors to on-premises, Azure, and other cloud resources, as needed for each site. For example, connect to an on-premises SIEM, proxy servers, backup storage, and other partner systems. You may have multiple sites and adopt a hybrid approach, where only specific sites are kept completely air-gapped or isolated using data-diodes.
35+
36+
For more information, see the information linked in the [air-gapped deployment procedure](air-gapped-deploy.md#deployment-steps), as well as the following cloud resources:
37+
38+
- [Provision sensors for cloud management](provision-cloud-management.md)
39+
- [OT threat monitoring in enterprise SOCs](../concept-sentinel-integration.md)
40+
- [Securing IoT devices in the enterprise](../concept-enterprise.md)
41+
42+
1. Set up permissions and update procedures for accessing your sensors to match the new deployment architecture.
43+
44+
1. Review and validate that all security use cases and procedures have transitioned to the new architecture.
45+
46+
1. After your transition is complete, decommission the on-premises management console.
47+
48+
## Next steps
49+
50+
> [!div class="step-by-step"]
51+
> [Maintain OT network sensors from the sensor console](../how-to-manage-individual-sensors.md)

articles/defender-for-iot/organizations/release-notes.md

Lines changed: 6 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -31,10 +31,14 @@ When updating your on-premises software, we recommend:
3131
3232
For more information, see [Update Defender for IoT OT monitoring software](update-ot-software.md).
3333

34-
### On-premises monitoring software versions
34+
### OT monitoring software versions (sensor versions)
3535

3636
Cloud features may be dependent on a specific sensor version. Such features are listed below for the relevant software versions, and are only available for data coming from sensors that have the required version installed, or higher.
3737

38+
> [!IMPORTANT]
39+
> The on-premises management console won't be supported or available for download after January 1st, 2025. For more information, see [on-premises management console retirement](ot-deploy/on-premises-management-console-retirement.md).
40+
>
41+
3842
| Version / Patch | Release date | Scope | Supported until |
3943
| ------- | ------------ | ----------- | ------------------- |
4044
| **24.1** | | | |
@@ -59,24 +63,6 @@ Cloud features may be dependent on a specific sensor version. Such features are
5963
| 22.3.4 | 01/2023 | Major | 12/2023 |
6064
| **22.2** | | | |
6165
| 22.2.9 | 01/2023 | Patch | 12/2023 |
62-
| 22.2.8 | 11/2022 | Patch | 10/2023 |
63-
| 22.2.7| 10/2022 | Patch | 09/2023 |
64-
| 22.2.6|09/2022 |Patch | 04/2023|
65-
|22.2.5 |08/2022 | Patch| 04/2023 |
66-
|22.2.4 |07/2022 |Patch |04/2023 |
67-
| 22.2.3| 07/2022| Major| 04/2023|
68-
| **22.1** | | | |
69-
| 22.1.7| 07/2022 |Patch | 06/2023 |
70-
| 22.1.6| 06/2022 |Patch |10/2022 |
71-
| 22.1.5| 06/2022 |Patch | 10/2022 |
72-
| 22.1.4|04/2022 | Patch|10/2022 |
73-
| 22.1.3|03/2022 |Patch | 10/2022|
74-
| 22.1.2| 02/2022 | Major|10/2022 |
75-
| **10.5** | | | |
76-
|10.5.5 |12/2021 |Patch | 09/2022|
77-
|10.5.4 |12/2021 |Patch | 09/2022|
78-
| 10.5.3| 10/2021 |Patch | 07/2022|
79-
| 10.5.2| 10/2021 | Major| 07/2022|
8066

8167
### Threat intelligence updates
8268

@@ -88,7 +74,7 @@ For more information, see [Threat intelligence research and packages](how-to-wor
8874

8975
Defender for IoT provides **1 year of support** for every new version, starting with versions **22.1.7** and **22.2.7**. For example, version **22.2.7** was released in **October 2022** and is supported through **September 2023**.
9076

91-
Earlier versions use a legacy support model, with support dates [detailed for each version](#on-premises-monitoring-software-versions).
77+
Earlier versions use a legacy support model, with support dates [detailed for each version](#ot-monitoring-software-versions).
9278

9379
### On-premises appliance security
9480

80 KB
Loading

articles/defender-for-iot/organizations/whats-new.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,10 @@ Features released earlier than nine months ago are described in the [What's new
1818
1919
[!INCLUDE [defender-iot-defender-reference](../includes/defender-for-iot-defender-reference.md)]
2020

21+
## On-premises management console retirement
22+
23+
The legacy on-premises management console won't be available for download after **January 1st, 2025**. We recommend transitioning to the new architecture using the full spectrum of on-premises and cloud APIs before this date. For more information, see [on-premises management console retirement](ot-deploy/on-premises-management-console-retirement.md).
24+
2125
## October 2024
2226

2327
|Service area |Updates |
@@ -244,7 +248,7 @@ The [legacy on-premises management console](legacy-central-management/legacy-air
244248

245249
For more information, see:
246250

247-
- [Transitioning from a legacy on-premises management console](ot-deploy/air-gapped-deploy.md#transitioning-from-a-legacy-on-premises-management-console).
251+
- [Transitioning from a legacy on-premises management console](ot-deploy/transition-on-premises-management-console-to-cloud.md)
248252
- [Versioning and support for on-premises software versions](release-notes.md#versioning-and-support-for-on-premises-software-versions)
249253

250254
### Live statuses for cloud-based sensor updates

0 commit comments

Comments
 (0)