Microsoft Defender for IoT
Identity protection

Configure OT sensor settings from the Azure portal - Microsoft Defender for IoT

In brief

The documentation adds a warning that deleting a sensor setting permanently removes it and requires recreation. It also clarifies disconnected-sensor editing, ICS subnet behavior, and backup server setup and troubleshooting.

What Defender admins need to know

Review the deletion warning before removing settings and use the clarified procedures when managing disconnected sensors or backup servers.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure OT sensor settings from the Azure portal (Public preview)

Delete an existing OT sensor setting

To delete an OT sensor setting altogether:

  1. On the Sensor settings (Preview) page, locate the setting you want to delete.

Edit settings for disconnected OT sensors

The following procedure describes how to edit OT sensor settings when your OT sensor is currently disconnected from Azure, such as during an ongoing security incident.

By default, if you configure any settings from the Azure portal, all settings that are configurable from both the Azure portal and the OT sensor are set to read-only on the OT sensor itself. For example, if you configure a VLAN from the Azure portal, then bandwidth cap, subnet, and VLAN settings are all set to read-only, and blocked from modifications on the OT sensor.

:::image type="content" source="media/how-to-manage-individual-sensors/remote-config-sensor.png" alt-text="Screenshot of the Azure Remote Config option." lightbox="media/how-to-manage-individual-sensors/remote-config-sensor.png":::

Continue by updating the unblocked sensor setting directly on the OT network sensor console. For more information, see Manage individual sensors.

To delete an

OT sensor setting altogether:
  1. On the Sensor settings (Preview) page, locate the setting you want to delete.

Edit settings for disconnected OT sensorsreference

This procedure describes how to edit OT sensor settings if your OT sensor is currently disconnected from Azure, such as during an ongoing security incident.

By default, if you configure any settings from the Azure portal, all settings that are configurable from both the Azure portal and the OT sensor are set to read-only on the OT sensor itself. For example, if you configure a VLAN from the Azure portal, then bandwidth cap, subnet, and VLAN settings are all set to read-only, and blocked from modifications on the OT sensor.

:::image type="content" source="media/how-to-manage-individual-sensors/remote-config-sensor.png" alt-text="Screenshot of the Azure Remote Config option." lightbox="media/how-to-manage-individual-sensors/remote-config-sensor.png":::

Continue by updating the relevant setting directly on the OT network sensor. For more information, see Manage individual sensors.

Add sensor settings

This section describesThe following subsections describe the individual OT sensor setting types that you can configure from the Azure portal. Each subsection provides field-level details for one setting type.

The available sensor setting types in the Type dropdown list are:

To focus the Azure device inventory on devices that are in your OT scope, you need to manually edit the subnet list to include only the locally monitored subnets that are in your OT scope.

SubnetsDefender for IoT marks subnets in the subnet list are automatically configured as ICS subnets,(industrial control system) subnets by default, which means that Defender for IoTit recognizes these subnets as OT networks. You can edit the ICS subnet setting when you configure subnets in the Azure portal.

Once the subnets are configured, the network location of the devices is shown in the Network location (Public preview) column in the Azure device inventory. All of the devices associated with the listed subnets are displayed as local, while devices associated with detected subnets not included in the list are displayed as routed.

Configure a backup server

Your OT sensorYou can haveset up a backup server setupfor your OT sensor during its initiallyfirst deployment or later on. In both cases, followlater. Use this procedure to confirm that the backup server is correctly configured once it's setup.set up correctly.

A misconfigured backup server might falsely recognizeflag normal traffic as malware andmalware. This can trigger a Malware engine alert. If you thinksee a false Suspicion of Malicious Activity malware alert was triggered falsely, consider following this procedure toalert, check the backup server configuration.setup by using the steps below.

To configure the backup server: