You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-for-iot/device-discovery.md
+8-6Lines changed: 8 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,15 +43,15 @@ The key device discovery capabilities are:
43
43
44
44
|Capability|Description|
45
45
|---|---|
46
-
|OT device management|[Manage OT devices](manage-devices-inventory.md):<br>- Build an up-to-date inventory that includes all your managed and unmanaged devices.<br>- Classify critical devices to ensure that the most important assets in your organization are protected.<br>- Add organization-specific information to emphasize your organization preferences.|
46
+
|OT device management|[Manage OT devices](manage-devices-inventory.md):<br>- Build an up-to-date inventory that includes all your managed and unmanaged devices.<br>- Discover your organization Building Management Systems (BMS) devices such as **Motion detector**, **Fire Alarm**, and **Elevators**.<br>- Classify critical devices to ensure that the most important assets in your organization are protected.<br>- Add organization-specific information to emphasize your organization preferences.|
47
47
|Device protection with risk-based approach|Identify risks such as missing patches, vulnerabilities and prioritize fixes based on risk scoring and automated threat modeling.|
48
48
|Device alignment with physical sites|Allows contextual security monitoring. Use the **Site** filter to manage each site separately. Learn more about [filters](/defender-endpoint/machines-view-overview#use-filters-to-customize-the-device-inventory-views).|
49
49
|Device groups|Allows different teams in your organization to monitor and manage relevant assets only. Learn more about [creating a device group](/defender-endpoint/machine-groups#create-a-device-group).|
50
50
|Device criticality|Reflects how critical a device is for your organization and allows you to identify a device as a business critical asset. Learn more about [device criticality](/defender-endpoint/machines-view-overview#device-inventory-overview).|
51
51
52
52
## Supported devices
53
53
54
-
Defender for IoT's device inventory supports the following device classes:
54
+
Defender for IoT's device inventory supports the following device categories:
55
55
56
56
|Devices|Example|
57
57
|---|---|
@@ -60,10 +60,12 @@ Defender for IoT's device inventory supports the following device classes:
60
60
|**Health care**|Glucose meters, monitors|
61
61
|**Transportation / Utilities**|Turnstiles, people counters, motion sensors, fire and safety systems, intercoms|
62
62
|**Energy and resources**|DCS controllers, PLCs, historian devices, HMIs|
63
-
|**Endpoint devices**|Workstations, servers, or mobile devices|
64
-
|**Enterprise**|Smart devices, printers, communication devices, or audio/video devices|
For Enterprise device discovery information, see [Enterprise device discovery](/defender-for-iot/enterprise-iot).
66
+
67
+
For Endpoint device discovery information, see [Endpoint device discovery](/defender-endpoint/device-discovery).
68
+
67
69
### Identified, unique devices
68
70
69
71
Defender for IoT can discover all devices, of any type, across all environments. Devices are listed in the Defender for IoT **Device inventory** pages based on a unique IP and MAC address coupling.
@@ -72,8 +74,8 @@ Defender for IoT identifies single and unique devices as follows:
72
74
73
75
|Type |Description |
74
76
|---------|---------|
75
-
|**Identified as individual devices**| Devices identified as *individual* devices include:<br>**IT, OT, or IoT devices with one or more NICs**, including network infrastructure devices such as switches and routers<br><br>**Note**: A device with modules or backplane components, such as racks or slots, is counted as a single device, including all modules or backplane components.|
76
-
|**Not identified as individual devices**| The following items *aren't* considered as individual devices, and do not count against your license:<br><br>- **Public internet IP addresses** <br>- **Multi-cast groups**<br>- **Broadcast groups**<br>- **Inactive devices**<br><br> Network-monitored devices are marked as *inactive* when there's no network activity detected within a specified time:<br><br> - **OT networks**: No network activity detected for more than 60 days<br> - **Enterprise IoT networks**: No network activity detected for more than 30 days<br><br>**Note**: Endpoints already managed by Defender for Endpoint are not considered as separate devices by Defender for IoT. |
77
+
|**Identified as individual devices**| Devices identified as *individual* devices include:<br>**OT or BMS unmanaged devices with one or more NICs**, including network infrastructure devices such as switches and routers<br><br>**Note**: A device with modules or backplane components, such as racks or slots, is counted as a single device, including all modules or backplane components.|
78
+
|**Not identified as individual devices**| The following items *aren't* considered as individual devices, and don't count against your license:<br><br>- **Public internet IP addresses** <br>- **Multi-cast groups**<br>- **Broadcast groups**<br>- **Inactive devices**<br><br> Network-monitored devices are marked as *inactive* when there's no network activity detected within a specified time:<br><br> - **OT networks**: No network activity detected for more than 60 days<br><br>**Note**: Endpoints already managed by Defender for Endpoint aren't considered as separate devices by Defender for IoT. |
Copy file name to clipboardExpand all lines: defender-for-iot/prerequisites.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,7 @@ Before you start, you need:
25
25
26
26
For more information, see [Buy or remove licenses for a Microsoft business subscription](/microsoft-365/commerce/licenses/buy-licenses) and [About admin roles in the Microsoft 365 admin center](/microsoft-365/admin/add-users/about-admin-roles).
27
27
28
-
- A Microsoft 365 E5/ Defender for Endpoint Plan 2/ E5 security license.
28
+
- A Microsoft 365 E5 or E5 security license or a Defender for Endpoint P2 license.
29
29
30
30
- Microsoft Defender for Endpoint agents deployed in your environment. For more information, see [onboard Microsoft Defender for Endpoint](/defender-endpoint/onboarding).
|**OT networks**| - [New Device Category Added – Building Management Systems (BMS)](#new-device-category-added--building-management-systems-bms)|
24
+
25
+
### New Device Category Added – Building Management Systems (BMS)
26
+
27
+
A new BMS device category has been added to the MDIoT license aiming to improve BMS device discovery and security. The BMS category includes a subset of Smart Facility and Surveillance devices (previously under the IoT category) such as fire alarms, humidity sensors, security radars, etc. These devices now require an Microsoft Defender for IoT site-based license for full protection.
28
+
29
+
Cameras devices will remain under the IoT category.
30
+
31
+
For more information, see [overview of device discovery](device-discovery.md).
0 commit comments