Skip to content

Commit ad1ac5c

Browse files
Merge pull request #887 from MicrosoftDocs/main
Publish main to live, 07/03, 3:30 PM IST
2 parents 4ced374 + c42b1b8 commit ad1ac5c

File tree

4 files changed

+16
-18
lines changed

4 files changed

+16
-18
lines changed

defender-for-iot/get-started.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,6 @@ To add a trial license for Microsoft Defender for IoT:
4343

4444
Once you have a trial license, [set up a new site](set-up-sites.md) so that Microsoft Defender for IoT can begin sending data to the Defender portal.
4545

46-
## Public preview features
46+
## Turn on Public preview features
4747

48-
We recommend that you also turn on and benefit from the available [Defender portal preview features](/defender-xdr/preview#turn-on-preview-features).
48+
Turn on the public preview features in the Microsoft Defender XDR settings to enable the site security features. Directions to change the settings are available in [Defender portal preview features](/defender-xdr/preview#turn-on-preview-features).

defender-for-iot/investigate-threats.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -11,19 +11,19 @@ ms.topic: how-to
1111

1212
# Investigate incidents and alerts
1313

14-
Microsoft Defender for IoT in the Microsoft Defender portal displays incidents and alerts, which enhance your network security and operations with real-time details about events logged in your operational technology (OT) network.
14+
Microsoft Defender for IoT in the Microsoft Defender portal displays incidents and alerts, which enhance your network security and operations with real-time details about events logged in your operational technology (OT) network.
1515

16-
Alerts are the basis of all incidents and indicate the occurrence of malicious or suspicious events in your environment. Within an incident, you analyze the alerts that affect your network, understand what they mean, and collate the evidence so that you can devise an effective remediation plan.
16+
Alerts are the basis of all incidents and indicate the occurrence of malicious or suspicious events in your environment. Within an incident, you analyze the alerts that affect your network, understand what they mean, and collate the evidence so that you can devise an effective remediation plan.
1717

1818
Learn more about [alerts](/defender-xdr/investigate-alerts) and [incidents](/defender-xdr/investigate-incidents) in the Defender portal.
1919

2020
In this article, you learn how to investigate a Microsoft Defender for IoT incident and its associated alerts, and how to remediate the security issues raised by the alert.
2121

22-
Alerts in the **Incidents** page uniquely combine IT and OT environment signals to detect potential threats and data leaks. The **Incidents** page displays:
22+
Alerts in the **Incidents** page uniquely combine IT and OT environment signals to detect potential threats and data leaks. The **Incidents** page displays:
2323

2424
- A history of the alerts connected to the incident and an incident graph. The graph shows other devices connected to the affected OT device that might also be compromised.
2525
- Alert descriptions, which explain the type of detected security issue.
26-
- Remediation options to solve the security problem.
26+
- Remediation options to solve the security problem.
2727

2828
> [!NOTE]
2929
> Incident and alert data for Defender for IoT only appear once you have a site set up and your devices are sending data to the Defender portal. Learn how to [set up a site](set-up-sites.md).
@@ -45,13 +45,13 @@ To investigate an alert:
4545

4646
1. Locate and select an incident.
4747

48-
The specific incident page shows the attack story made up of the alert timeline, an incident graph and the incident details. The incident graph displays the OT device and the other IT or IoT devices connected to this alert, to show possible compromised connections.
48+
The specific incident page shows the attack story made up of the alert timeline, an incident graph and the incident details.
4949

5050
1. Select an alert from the alerts list.
5151

5252
The incident graph and incident details display specific data for this alert.
5353

54-
1. In the **Incident** panel, review the information, read the **Alert description** and follow the **Alert recommended actions** to remediate the issue.
54+
1. In the **Incident** panel, review the information, read the **Alert description**, **Evidence** and **Impacted assetts** and follow the **Alert recommended actions** to remediate the issue.
5555

5656
## Defender for IoT alert
5757

defender-for-iot/manage-sites.md

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,11 @@ When you manage a site, you might need to edit or delete the site information li
2222
To edit or delete a site:
2323

2424
1. In the [Microsoft Defender portal](https://security.microsoft.com/machines) menu, select **Operational technology** > **Site security**.
25-
1. Select the ellipsis (:::image type="icon" source="media/manage-sites/menu-ellipsis.png" alt-text="menu vertical ellipsis button":::) to the right of the site name.
25+
1. Select the ellipsis (:::image type="icon" source="media/manage-sites/menu-ellipsis.png" alt-text="menu vertical ellipsis button":::) to the right of the site name.
2626
1. Select one of the following:
2727

28-
- Select **Edit site**.to open the **Site details** pane, where you can make changes to the site. For more information, see [Site details](set-up-sites.md).
29-
- Select **Delete site** to remove a site from the site list.
30-
31-
This deletes all site-related information for the associated devices.
28+
- Select **Edit site** to open the **Site details** pane, where you can make changes to the site. For more information, see [Site details](set-up-sites.md).
29+
- Select **Delete site** to remove a site from the site list. This deletes all site-related information for the associated devices.
3230

3331
## Add device group
3432

@@ -39,7 +37,7 @@ You can set up a device group at different stages:
3937
- To set up a device group as part of the site setup, see [Add a device group](set-up-sites.md#add-device-group).
4038
- To set up a device group after you set up a site, see [Create and manage device groups](/defender-endpoint/machine-groups).
4139

42-
To get the full benefit of the device group, you might need to create roles and permission settings. For more information, see:
40+
To get the full benefit of the device group, you might need to create roles and permission settings. For more information, see:
4341

4442
- [Role based access control in Microsoft Defender for Endpoint](/defender-endpoint/rbac)
4543
- [Create and manage roles in Microsoft Defender for Endpoint](/defender-endpoint/user-roles)

defender-for-iot/monitor-site-security.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.topic: how-to
1111

1212
# Monitor site security
1313

14-
Microsoft Defender for IoT in the Microsoft Defender portal includes the **Site security** page, which offers an overview of the security state of your entire OT/IoT network. Your organization's security team can use this page to regularly monitor the security status of your production sites.
14+
Microsoft Defender for IoT in the Microsoft Defender portal includes the **Site security** page, which offers an overview of the security state of your entire OT environment. Your organization's security team can use this page to regularly monitor the security status of your production sites.
1515

1616
In this article, you learn how to gain an overview of your site security, so your security team can decide how to prioritize and assign security issues.
1717

@@ -31,7 +31,7 @@ The **Site security** page gives you an overview of the security status of your
3131
- [Review the top **How protected are your sites** section](#review-site-protection-information) to get a general overview of your entire network, including sites with the highest number of devices that are exposed or at risk.
3232
- [Review the site list](#review-the-site-list) to monitor specific security information for each site.
3333

34-
The data displayed in the **Site security** page is the total aggregated data for the entire network, and might include data for sites that you don't have access to. When you drill down into device data from the [site list](#review-the-site-list), the **Device Inventory** page only displays data for devices you can access.
34+
The data displayed in the **Site security** page is the total aggregated data for the entire environment, and might include data for sites that you don't have access to. When you drill down into device data from the [site list](#review-the-site-list), the **Device Inventory** page only displays data for devices you can access.
3535

3636
## Review site protection information
3737

@@ -49,11 +49,11 @@ Review the top **How protected are your sites** section to get the following inf
4949

5050
Review the site specific data in the sites list table.
5151

52-
Note that the data displayed in this table is the total aggregated data for the entire network, and might include data for sites that you don't have access to. When you drill down into device data, the **Device Inventory** page only displays data for devices you can access.
52+
Note that the data displayed in this table is the total aggregated data for the entire environment, and might include data for sites that you don't have access to. When you drill down into device data, the **Device Inventory** page only displays data for devices you can access.
5353

5454
|Column | Description|Next steps |
5555
|----|----|----|
5656
|**Site name** |The site name and description. |- Select the **Site name** to open the **Insights** panel. This panel displays site details, such as total devices, site location, and site owners. You can also select **Edit site** to make changes to the site.<br>- Select the ellipsis (:::image type="icon" source="media/monitor-site-security/menu-ellipsis.png" alt-text="menu vertical ellipsis button":::) to the right of the site name to [manage the site](manage-sites.md).
5757
|**Critical devices** |The number of critical devices at this site. A critical device is a self assigned device that has extra importance to your business or system, such as a server that contains confidential data. |- Use this data to prioritize protection for sites with critical devices.<br>- Select the number to open the **Device Inventory** page, filtered according to the site name and criticality level. |
5858
|**Highly-exposed devices** |The number of highly exposed devices at this site. |Select the number to open the **Device Inventory** page, filtered according to the site name and high exposure level. |
59-
|**Devices with high risk** |The number of high risk devices at this site. |Select the number to open the **Device Inventory** page, filtered according to the site name and high risk level. |
59+
|**Devices with high risk** |The number of high risk devices at this site. |Select the number to open the **Device Inventory** page, filtered according to the site name and high risk level. |

0 commit comments

Comments
 (0)