Microsoft Defender for IoT
Endpoint protection

Configure Windows Endpoint Monitoring for OT active monitoring - Microsoft Defender for IoT

In brief

The article now explicitly describes active probing, required OT sensor and active monitoring prerequisites, WMI namespace permissions, and related content. Links and metadata were also updated.

What Defender admins need to know

Verify the prerequisites and follow the WMI permission steps, especially when using a non-admin account for scans.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Windows Endpoint monitoring

This article describes how to configure Windows Endpoint Monitoring (WEM) to have Microsoft Defender for IoT selectively and actively probe Windows systems.

WEM can provide more focused and accurate information about your Windows devices, such as service pack levels. Before you begin, make sure you meet the prerequisites, including a configured OT sensor and active monitoring setup.

Supported protocols

Before performing the procedures in this article, you must have:

Configure permissions for your WMI namespace

This procedure describes how toThe following steps define permissions for your WMI namespace, andnamespace. You can't be completedcomplete this configuration with a regular GPO.

If you'll be using a non-admin account to run your WEM scans, this procedureconfiguring WMI namespace permissions is critical and must be performed exactly as instructed to allow sign-in attempts using WMI.

  1. On your Windows machine, open a Run dialog and enter wmimgmt.msc.
  1. Select OK until all dialog boxes you'd opened in this procedure are closed.

  2. Select Add and then, in the Enter the object names to select, enter wmiuser to add the wmiuser to the group. Select Check Names and then OK until all dialog boxes you'd opened in this procedure are closed.

Configure a WEM scan on your sensor console

To configure a WEM scan:

  1. Select View Scan Results. A .csv file with the scan results is downloaded to your computer.

Related content