You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-manage-cloud-alerts.md
+27-17Lines changed: 27 additions & 17 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -181,34 +181,44 @@ Defender for IoT provides remediation steps you can carry out for the alert. Rem
181
181
182
182
## Manage alert status and severity
183
183
184
-
You can change the alert status and severity for a single alert or for a group of alerts.
184
+
You can update alert status or severity for a single alert or for a group of alerts.
185
185
186
-
**To change the alert status:**
186
+
*Learn* an alert to indicate to Defender for IoT that the detected network traffic is authorized. Learned alerts won't be triggered again the next time the same traffic is detected on your network. For more information, see [Learn and unlearn alert traffic](how-to-manage-the-alert-event.md#learn-and-unlearn-alert-traffic).
187
187
188
-
1. Select an alert or group of alerts.
189
-
1. Select **Change status** and select a status (New, Active, Closed).
188
+
-**To manage a single alert**:
190
189
191
-
Changes to status aren't reflected in the on-premises management console or sensor.
190
+
1. Select an alert in the grid.
191
+
1. Either on the details pane on the right, or in an alert details page itself, select the new status and/or severity.
192
192
193
-
**To change the alert severity:**
193
+
-**To manage multiple alerts in bulk**:
194
+
195
+
1. Select the alerts in the grid that you want to modify.
196
+
1. Use the :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/status-icon.png" border="false"::: **Change status** and/or :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/severity-icon.png" border="false"::: **Change severity** options in the toolbar to update the status and/or the severity for all the selected alerts.
197
+
198
+
-**To learn one or more alerts**, do one of the following:
199
+
200
+
- Select one or more alerts in the grid and then select :::image type="icon" source="media/how-to-manage-sensors-on-the-cloud/learn-icon.png" border="false"::: **Learn** in the toolbar.
201
+
- On an alert details page, in the **Take Action** tab, select **Learn**.
194
202
195
-
1. Select an alert or group of alerts.
196
-
1. Select **Change severity** and select a severity.
197
203
198
204
Changes to severity aren't reflected in the on-premises management console or sensor.
199
205
200
-
## On-premises alert management
206
+
### Managing alerts in a hybrid deployment
207
+
208
+
Users working in hybrid deployments may be managing alerts in Defender for IoT on the Azure portal, the sensor, and an on-premises management console.
209
+
210
+
Alert management across all interfaces functions as follows:
211
+
212
+
-**Alert statuses are fully synchronized** between the Azure portal and the sensor. This means that when you set an alert status to **Closed** on either the Azure portal or the sensor, the alert status is updated in the other location as well.
213
+
214
+
Setting an alert status to **Closed** or **Muted** on a sensor updates the alert status to **Closed** on the Azure portal. Alert statuses are also synchronized between the sensor and the on-premises management console to keep all management sources updated with the correct alert statuses.
201
215
202
-
Users working in hybrid deployments may be managing alerts on both the Microsoft Defender for IoT portal, Alerts page, and on on-premises sensors and the management console.
216
+
[Learning](#manage-alert-status-and-severity) an alert in Azure also updates the alert in the sensor console.
203
217
204
-
Users working with alerts in Azure and on-premises should understand how alert management between the portal and the on-premises components operates.
218
+
-**Alert Exclusion rules**: If you're working with an on-premises management console, you may have defined alert *Exclusion rules* to determine the rules detected by relevant sensors.
205
219
206
-
Parameter | Description
207
-
|--|--|
208
-
| **Alert Exclusion rules**| Alert *Exclusion rules* defined in the on-premises management console affect the rules detected by managed sensors. As a result, the alerts excluded be these rules won't be displayed in the Alerts page. See [Create alert exclusion rules](how-to-work-with-alerts-on-premises-management-console.md#create-alert-exclusion-rules) for more information.
209
-
| **Managing alerts on-premises** | Alerts **Learned**, **Acknowledged**, or **Muted** in the on-premises management console or in sensors aren't simultaneously updated in Alerts page on the Defender for IoT Cloud Alerts page. This means that this alert will stay open on the Cloud. However another alert won't be triggered from the on-premises components for this activity.
210
-
| **Managing alert in the portal Alerts page** | Changing the status of an alert to **New**, **Active**, or **Closed** on the Alerts page or changing the alert severity on the Alerts page doesn't affect the alert status or severity in the on-premises management console or sensors.
220
+
Alerts excluded because they meet criteria for a specific exclusion rule are not displayed on the sensor, or in the Azure portal. For more information, see [Create alert exclusion rules](how-to-work-with-alerts-on-premises-management-console.md#create-alert-exclusion-rules).
211
221
212
222
## Next steps
213
223
214
-
For more information, see [Gain insight into global, regional, and local threats](how-to-gain-insight-into-global-regional-and-local-threats.md#gain-insight-into-global-regional-and-local-threats).
224
+
For more information, see [Gain insight into global, regional, and local threats](how-to-gain-insight-into-global-regional-and-local-threats.md#gain-insight-into-global-regional-and-local-threats).
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/release-notes.md
+25-5Lines changed: 25 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: What's new in Microsoft Defender for IoT
3
3
description: This article lets you know what's new in the latest release of Defender for IoT.
4
4
ms.topic: overview
5
-
ms.date: 05/25/2022
5
+
ms.date: 07/05/2022
6
6
---
7
7
8
8
# What's new in Microsoft Defender for IoT?
@@ -33,6 +33,8 @@ For more information, see the [Microsoft Security Development Lifecycle practice
33
33
34
34
| Version | Date released | End support date |
35
35
|--|--|--|
36
+
| 22.2.3 | 07/2022 | 04/2023 |
37
+
| 22.1.5 | 06/2022 | 03/2022 |
36
38
| 22.1.5 | 06/2022 | 03/2023 |
37
39
| 22.1.4 | 04/2022 | 12/2022 |
38
40
| 22.1.3 | 03/2022 | 11/2022 |
@@ -44,6 +46,12 @@ For more information, see the [Microsoft Security Development Lifecycle practice
44
46
45
47
## July 2022
46
48
49
+
-[Enterprise IoT purchase experience and Defender for Endpoint integration in GA](#enterprise-iot-purchase-experience-and-defender-for-endpoint-integration-in-ga)
50
+
51
+
**Sensor software version**: 22.2.3
52
+
53
+
-[Bi-directional alert synch between sensors and the Azure portal (Public preview)](#bi-directional-alert-synch-between-sensors-and-the-azure-portal-public-preview)
54
+
47
55
### Enterprise IoT purchase experience and Defender for Endpoint integration in GA
48
56
49
57
Defender for IoT’s new purchase experience and the Enterprise IoT integration with Microsoft Defender for Endpoint is now in General Availability (GA). With this update, we've made the following updates and improvements:
@@ -57,19 +65,31 @@ Defender for IoT’s new purchase experience and the Enterprise IoT integration
57
65
> [!NOTE]
58
66
> The Enterprise IoT network sensor and all detections remain in Public Preview.
59
67
60
-
##June 2022
68
+
### Bi-directional alert synch between sensors and the Azure portal (Public preview)
61
69
62
-
**Sensor software version**: 22.1.5
70
+
For sensors updated to version 22.2.1, alert statuses and learn statuses are now fully synchronized between the sensor console and the Azure portal. For example, this means that you can close an alert on the Azure portal or the sensor console, and the alert status is updated in both locations.
71
+
72
+
*Learn* an alert from either the Azure portal or the sensor console to ensure that it's not triggered again the next time the same network traffic is detected.
63
73
64
-
- Bug fixes related to OT monitoring software updates and sensor-cloud connections.
74
+
The sensor console is also synchronized with an on-premises management console, so that alert statuses and learn statuses remain up-to-date across your management interfaces.
65
75
66
-
## May 2022
76
+
For more information, see:
77
+
78
+
-[View and manage alerts from the Azure portal](how-to-manage-cloud-alerts.md)
79
+
-[View alerts on your sensor](how-to-view-alerts.md)
80
+
-[Manage alerts from the sensor console](how-to-manage-the-alert-event.md)
81
+
-[Work with alerts on the on-premises management console](how-to-work-with-alerts-on-premises-management-console.md)
82
+
83
+
## June 2022
84
+
85
+
**Sensor software version**: 22.1.5
67
86
68
87
We've recently optimized and enhanced our documentation as follows:
69
88
70
89
-[Updated appliance catalog for OT environments](#updated-appliance-catalog-for-ot-environments)
71
90
-[Documentation reorganization for end-user organizations](#documentation-reorganization-for-end-user-organizations)
72
91
92
+
73
93
### Updated appliance catalog for OT environments
74
94
75
95
We've refreshed and revamped the catalog of supported appliances for monitoring OT environments. These appliances support flexible deployment options for environments of all sizes and can be used to host both the OT monitoring sensor and on-premises management consoles.
0 commit comments