Skip to content

Commit e7f2109

Browse files
authored
Merge pull request #1349 from tarTech23/bms
Add BMS category
2 parents 8fb5007 + e4956b8 commit e7f2109

File tree

4 files changed

+24
-8
lines changed

4 files changed

+24
-8
lines changed

defender-for-iot/device-discovery.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -43,15 +43,15 @@ The key device discovery capabilities are:
4343

4444
|Capability|Description|
4545
|---|---|
46-
|OT device management|[Manage OT devices](manage-devices-inventory.md):<br>- Build an up-to-date inventory that includes all your managed and unmanaged devices.<br>- Classify critical devices to ensure that the most important assets in your organization are protected.<br>- Add organization-specific information to emphasize your organization preferences.|
46+
|OT device management|[Manage OT devices](manage-devices-inventory.md):<br>- Build an up-to-date inventory that includes all your managed and unmanaged devices.<br>- Discover your organization Building Management Systems (BMS) devices such as **Motion detector**, **Fire Alarm**, and **Elevators**.<br>- Classify critical devices to ensure that the most important assets in your organization are protected.<br>- Add organization-specific information to emphasize your organization preferences.|
4747
|Device protection with risk-based approach|Identify risks such as missing patches, vulnerabilities and prioritize fixes based on risk scoring and automated threat modeling.|
4848
|Device alignment with physical sites|Allows contextual security monitoring. Use the **Site** filter to manage each site separately. Learn more about [filters](/defender-endpoint/machines-view-overview#use-filters-to-customize-the-device-inventory-views).|
4949
|Device groups|Allows different teams in your organization to monitor and manage relevant assets only. Learn more about [creating a device group](/defender-endpoint/machine-groups#create-a-device-group).|
5050
|Device criticality|Reflects how critical a device is for your organization and allows you to identify a device as a business critical asset. Learn more about [device criticality](/defender-endpoint/machines-view-overview#device-inventory-overview).|
5151

5252
## Supported devices
5353

54-
Defender for IoT's device inventory supports the following device classes:
54+
Defender for IoT's device inventory supports the following device categories:
5555

5656
|Devices|Example|
5757
|---|---|
@@ -60,10 +60,12 @@ Defender for IoT's device inventory supports the following device classes:
6060
|**Health care**|Glucose meters, monitors|
6161
|**Transportation / Utilities**|Turnstiles, people counters, motion sensors, fire and safety systems, intercoms|
6262
|**Energy and resources**|DCS controllers, PLCs, historian devices, HMIs|
63-
|**Endpoint devices**|Workstations, servers, or mobile devices|
64-
|**Enterprise**|Smart devices, printers, communication devices, or audio/video devices|
6563
|**Retail**|Barcode scanners, humidity sensor, punch clocks|
6664

65+
For Enterprise device discovery information, see [Enterprise device discovery](/defender-for-iot/enterprise-iot).
66+
67+
For Endpoint device discovery information, see [Endpoint device discovery](/defender-endpoint/device-discovery).
68+
6769
### Identified, unique devices
6870

6971
Defender for IoT can discover all devices, of any type, across all environments. Devices are listed in the Defender for IoT **Device inventory** pages based on a unique IP and MAC address coupling.
@@ -72,8 +74,8 @@ Defender for IoT identifies single and unique devices as follows:
7274

7375
|Type |Description |
7476
|---------|---------|
75-
|**Identified as individual devices** | Devices identified as *individual* devices include:<br>**IT, OT, or IoT devices with one or more NICs**, including network infrastructure devices such as switches and routers<br><br>**Note**: A device with modules or backplane components, such as racks or slots, is counted as a single device, including all modules or backplane components.|
76-
|**Not identified as individual devices** | The following items *aren't* considered as individual devices, and do not count against your license:<br><br>- **Public internet IP addresses** <br>- **Multi-cast groups**<br>- **Broadcast groups**<br>- **Inactive devices**<br><br> Network-monitored devices are marked as *inactive* when there's no network activity detected within a specified time:<br><br> - **OT networks**: No network activity detected for more than 60 days<br> - **Enterprise IoT networks**: No network activity detected for more than 30 days<br><br>**Note**: Endpoints already managed by Defender for Endpoint are not considered as separate devices by Defender for IoT. |
77+
|**Identified as individual devices** | Devices identified as *individual* devices include:<br>**OT or BMS unmanaged devices with one or more NICs**, including network infrastructure devices such as switches and routers<br><br>**Note**: A device with modules or backplane components, such as racks or slots, is counted as a single device, including all modules or backplane components.|
78+
|**Not identified as individual devices** | The following items *aren't* considered as individual devices, and don't count against your license:<br><br>- **Public internet IP addresses** <br>- **Multi-cast groups**<br>- **Broadcast groups**<br>- **Inactive devices**<br><br> Network-monitored devices are marked as *inactive* when there's no network activity detected within a specified time:<br><br> - **OT networks**: No network activity detected for more than 60 days<br><br>**Note**: Endpoints already managed by Defender for Endpoint aren't considered as separate devices by Defender for IoT. |
7779

7880
## Next steps
7981

defender-for-iot/enterprise-iot-get-started.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ In this article you'll learn how to add enterprise IoT to your Microsoft Defende
2121

2222
## Prerequisites
2323

24-
Make sure that you have:
24+
Before you start, you need:
2525

2626
- IoT devices in your network, visible in the Microsoft Defender portal **Device inventory**
2727

defender-for-iot/prerequisites.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ Before you start, you need:
2525

2626
For more information, see [Buy or remove licenses for a Microsoft business subscription](/microsoft-365/commerce/licenses/buy-licenses) and [About admin roles in the Microsoft 365 admin center](/microsoft-365/admin/add-users/about-admin-roles).
2727

28-
- A Microsoft 365 E5/ Defender for Endpoint Plan 2/ E5 security license.
28+
- A Microsoft 365 E5 or E5 security license or a Defender for Endpoint P2 license.
2929

3030
- Microsoft Defender for Endpoint agents deployed in your environment. For more information, see [onboard Microsoft Defender for Endpoint](/defender-endpoint/onboarding).
3131

defender-for-iot/whats-new.md

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,20 @@ This article describes features available in Microsoft Defender for IoT in the D
1616

1717
[!INCLUDE [defender-iot-preview](../includes//defender-for-iot-defender-public-preview.md)]
1818

19+
## September 2024
20+
21+
|Service area |Updates |
22+
|---------|---------|
23+
| **OT networks** | - [New Device Category Added – Building Management Systems (BMS)](#new-device-category-added--building-management-systems-bms) |
24+
25+
### New Device Category Added – Building Management Systems (BMS)
26+
27+
A new BMS device category has been added to the MDIoT license aiming to improve BMS device discovery and security. The BMS category includes a subset of Smart Facility and Surveillance devices (previously under the IoT category) such as fire alarms, humidity sensors, security radars, etc. These devices now require an Microsoft Defender for IoT site-based license for full protection.
28+
29+
Cameras devices will remain under the IoT category.
30+
31+
For more information, see [overview of device discovery](device-discovery.md).
32+
1933
## July 2024
2034

2135
|Service area |Updates |

0 commit comments

Comments
 (0)