Skip to content

Commit fd470c8

Browse files
authored
Merge pull request #201053 from batamig/bi-directional-sync
Sensor version 22.2.3 bi-directional synch. Approved July 3
2 parents 6d90243 + dd03329 commit fd470c8

File tree

5 files changed

+52
-22
lines changed

5 files changed

+52
-22
lines changed

articles/defender-for-iot/organizations/how-to-manage-cloud-alerts.md

Lines changed: 27 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -181,34 +181,44 @@ Defender for IoT provides remediation steps you can carry out for the alert. Rem
181181

182182
## Manage alert status and severity
183183

184-
You can change the alert status and severity for a single alert or for a group of alerts.
184+
You can update alert status or severity for a single alert or for a group of alerts.
185185

186-
**To change the alert status:**
186+
*Learn* an alert to indicate to Defender for IoT that the detected network traffic is authorized. Learned alerts won't be triggered again the next time the same traffic is detected on your network. For more information, see [Learn and unlearn alert traffic](how-to-manage-the-alert-event.md#learn-and-unlearn-alert-traffic).
187187

188-
1. Select an alert or group of alerts.
189-
1. Select **Change status** and select a status (New, Active, Closed).
188+
- **To manage a single alert**:
190189

191-
Changes to status aren't reflected in the on-premises management console or sensor.
190+
1. Select an alert in the grid.
191+
1. Either on the details pane on the right, or in an alert details page itself, select the new status and/or severity.
192192

193-
**To change the alert severity:**
193+
- **To manage multiple alerts in bulk**:
194+
195+
1. Select the alerts in the grid that you want to modify.
196+
1. Use the :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/status-icon.png" border="false"::: **Change status** and/or :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/severity-icon.png" border="false"::: **Change severity** options in the toolbar to update the status and/or the severity for all the selected alerts.
197+
198+
- **To learn one or more alerts**, do one of the following:
199+
200+
- Select one or more alerts in the grid and then select :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/learn-icon.png" border="false"::: **Learn** in the toolbar.
201+
- On an alert details page, in the **Take Action** tab, select **Learn**.
194202

195-
1. Select an alert or group of alerts.
196-
1. Select **Change severity** and select a severity.
197203

198204
Changes to severity aren't reflected in the on-premises management console or sensor.
199205

200-
## On-premises alert management
206+
### Managing alerts in a hybrid deployment
207+
208+
Users working in hybrid deployments may be managing alerts in Defender for IoT on the Azure portal, the sensor, and an on-premises management console.
209+
210+
Alert management across all interfaces functions as follows:
211+
212+
- **Alert statuses are fully synchronized** between the Azure portal and the sensor. This means that when you set an alert status to **Closed** on either the Azure portal or the sensor, the alert status is updated in the other location as well.
213+
214+
Setting an alert status to **Closed** or **Muted** on a sensor updates the alert status to **Closed** on the Azure portal. Alert statuses are also synchronized between the sensor and the on-premises management console to keep all management sources updated with the correct alert statuses.
201215

202-
Users working in hybrid deployments may be managing alerts on both the Microsoft Defender for IoT portal, Alerts page, and on on-premises sensors and the management console.
216+
[Learning](#manage-alert-status-and-severity) an alert in Azure also updates the alert in the sensor console.
203217

204-
Users working with alerts in Azure and on-premises should understand how alert management between the portal and the on-premises components operates.
218+
- **Alert Exclusion rules**: If you're working with an on-premises management console, you may have defined alert *Exclusion rules* to determine the rules detected by relevant sensors.
205219

206-
Parameter | Description
207-
|--|--|
208-
| **Alert Exclusion rules**| Alert *Exclusion rules* defined in the on-premises management console affect the rules detected by managed sensors. As a result, the alerts excluded be these rules won't be displayed in the Alerts page. See [Create alert exclusion rules](how-to-work-with-alerts-on-premises-management-console.md#create-alert-exclusion-rules) for more information.
209-
| **Managing alerts on-premises** | Alerts **Learned**, **Acknowledged**, or **Muted** in the on-premises management console or in sensors aren't simultaneously updated in Alerts page on the Defender for IoT Cloud Alerts page. This means that this alert will stay open on the Cloud. However another alert won't be triggered from the on-premises components for this activity.
210-
| **Managing alert in the portal Alerts page** | Changing the status of an alert to **New**, **Active**, or **Closed** on the Alerts page or changing the alert severity on the Alerts page doesn't affect the alert status or severity in the on-premises management console or sensors.
220+
Alerts excluded because they meet criteria for a specific exclusion rule are not displayed on the sensor, or in the Azure portal. For more information, see [Create alert exclusion rules](how-to-work-with-alerts-on-premises-management-console.md#create-alert-exclusion-rules).
211221

212222
## Next steps
213223

214-
For more information, see [Gain insight into global, regional, and local threats](how-to-gain-insight-into-global-regional-and-local-threats.md#gain-insight-into-global-regional-and-local-threats).
224+
For more information, see [Gain insight into global, regional, and local threats](how-to-gain-insight-into-global-regional-and-local-threats.md#gain-insight-into-global-regional-and-local-threats).
1.04 KB
Loading
744 Bytes
Loading
878 Bytes
Loading

articles/defender-for-iot/organizations/release-notes.md

Lines changed: 25 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: What's new in Microsoft Defender for IoT
33
description: This article lets you know what's new in the latest release of Defender for IoT.
44
ms.topic: overview
5-
ms.date: 05/25/2022
5+
ms.date: 07/05/2022
66
---
77

88
# What's new in Microsoft Defender for IoT?
@@ -33,6 +33,8 @@ For more information, see the [Microsoft Security Development Lifecycle practice
3333

3434
| Version | Date released | End support date |
3535
|--|--|--|
36+
| 22.2.3 | 07/2022 | 04/2023 |
37+
| 22.1.5 | 06/2022 | 03/2022 |
3638
| 22.1.5 | 06/2022 | 03/2023 |
3739
| 22.1.4 | 04/2022 | 12/2022 |
3840
| 22.1.3 | 03/2022 | 11/2022 |
@@ -44,6 +46,12 @@ For more information, see the [Microsoft Security Development Lifecycle practice
4446

4547
## July 2022
4648

49+
- [Enterprise IoT purchase experience and Defender for Endpoint integration in GA](#enterprise-iot-purchase-experience-and-defender-for-endpoint-integration-in-ga)
50+
51+
**Sensor software version**: 22.2.3
52+
53+
- [Bi-directional alert synch between sensors and the Azure portal (Public preview)](#bi-directional-alert-synch-between-sensors-and-the-azure-portal-public-preview)
54+
4755
### Enterprise IoT purchase experience and Defender for Endpoint integration in GA
4856

4957
Defender for IoT’s new purchase experience and the Enterprise IoT integration with Microsoft Defender for Endpoint is now in General Availability (GA). With this update, we've made the following updates and improvements:
@@ -57,19 +65,31 @@ Defender for IoT’s new purchase experience and the Enterprise IoT integration
5765
> [!NOTE]
5866
> The Enterprise IoT network sensor and all detections remain in Public Preview.
5967
60-
## June 2022
68+
### Bi-directional alert synch between sensors and the Azure portal (Public preview)
6169

62-
**Sensor software version**: 22.1.5
70+
For sensors updated to version 22.2.1, alert statuses and learn statuses are now fully synchronized between the sensor console and the Azure portal. For example, this means that you can close an alert on the Azure portal or the sensor console, and the alert status is updated in both locations.
71+
72+
*Learn* an alert from either the Azure portal or the sensor console to ensure that it's not triggered again the next time the same network traffic is detected.
6373

64-
- Bug fixes related to OT monitoring software updates and sensor-cloud connections.
74+
The sensor console is also synchronized with an on-premises management console, so that alert statuses and learn statuses remain up-to-date across your management interfaces.
6575

66-
## May 2022
76+
For more information, see:
77+
78+
- [View and manage alerts from the Azure portal](how-to-manage-cloud-alerts.md)
79+
- [View alerts on your sensor](how-to-view-alerts.md)
80+
- [Manage alerts from the sensor console](how-to-manage-the-alert-event.md)
81+
- [Work with alerts on the on-premises management console](how-to-work-with-alerts-on-premises-management-console.md)
82+
83+
## June 2022
84+
85+
**Sensor software version**: 22.1.5
6786

6887
We've recently optimized and enhanced our documentation as follows:
6988

7089
- [Updated appliance catalog for OT environments](#updated-appliance-catalog-for-ot-environments)
7190
- [Documentation reorganization for end-user organizations](#documentation-reorganization-for-end-user-organizations)
7291

92+
7393
### Updated appliance catalog for OT environments
7494

7595
We've refreshed and revamped the catalog of supported appliances for monitoring OT environments. These appliances support flexible deployment options for environments of all sizes and can be used to host both the OT monitoring sensor and on-premises management consoles.

0 commit comments

Comments
 (0)