Microsoft Defender for IoT
General

Control the OT traffic monitored by Microsoft Defender for IoT

In brief

The article now uses clearer terminology and navigation for the OT sensor deployment path, subnet configuration, ICS subnet definition, port and VLAN naming, DNS lookup, and DHCP procedures. Metadata and section formatting were also updated.

What Defender admins need to know

Administrators can follow the clarified procedures more easily when configuring OT sensor subnet and device-display settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Control the OT traffic monitored by Microsoft Defender for IoT

This article is one in a series of articles describing the OT sensor deployment path for OT monitoring with Microsoft Defender for IoT.

:::image type="content" source="media/deployment-paths/progress-fine-tuning-ot-monitoring.png" alt-text="Diagram of a progress bar with Fine-tune OT monitoring highlighted." border="false" lightbox="media/deployment-paths/progress-fine-tuning-ot-monitoring.png":::

Before performing the procedures in this article, you must have:

Fine tune your subnet list

After having analyzed the traffic your sensor is monitoring and fine tuning the deployment, you may need to further fine tune your subnet list. Use thisthe following subnet configuration procedure to ensure that your subnets are configured correctly.

While your OT sensor automatically learns your network subnets during the initial deployment, we recommend analyzing the detected traffic and updating the subnets as needed to optimize your map views and device inventory.

AlsoYou can also use thisthe subnet configuration procedure to also define subnet settings, determining how devices are displayed in the OT sensor device map and the Azure device inventory.

  • In the device map, IT devices are automatically aggregated by subnet, where you can expand and collapse each subnet view to drill down as needed.

  • In the Azure device inventory, once the subnets have been configured, use the Network location (Public preview) filter to view local or routed devices as defined in your subnets list. All of the devices associated with the listed subnets are displayed as local, while devices associated with detected subnets not included in the list will be displayed as routed. |Segregated | Select to show this subnet separately when displaying the device map according to Purdue level. | | Remove subnet | Select to remove any subnets that aren't related to your IoT/OT network scope.|

    In the subnet grid, subnets marked as ICS subnet are recognized as OT networks. The ICS subnet setting is read-only in this grid, but you can manually define a subnet as ICS if there's an OT subnet not being recognized correctly.correctly, you can manually define a subnet as ICS by changing the device type.

  1. When you're done, select Save to save your updates.

Manually define a subnet as ICS

If you have an OT subnet that isn't being marked automatically as an ICS subnet by the sensor, edit the device type for any of the devices in the relevant subnet to an ICS or IoT device type. The subnet will then be automatically marked by the sensor as an ICS subnet.

To change the device type to manually update the subnet:

Customize port and VLAN names

Use the followingport naming and VLAN naming procedures in this section to enrich the device data shown in Defender for IoT by customizing port and VLAN names on your OT network sensors.

For example, you might want to assign a name to a nonreserved port that shows unusually high activity in order to call it out, or to assign a name to a VLAN number in order to identify it quicker.

Port names are shown in Defender for IoT when viewing device groups from the OT sensor device map, or when you create OT sensor reports that include port information.

To customize a port name:

  1. Sign into your OT sensor as an Admin user.

VLAN's support is based on 802.1q (up to VLAN ID 4094).

To configure VLAN names on an OT network sensor:

  1. Sign in to your OT sensor as an Admin user.

Enhance device data enrichment by configuring multiple DNS servers to carryout reverse lookups and resolve host names or FQDNs associated with the IP addresses detected in network subnets. For example, if a sensor discovers an IP address, it might query multiple DNS servers to resolve the host name. You need the DNS server address, server port and the subnet addresses.

To define the DNS server lookup:lookup:

  1. On your OT sensor console, select System settings > Network monitoring and under Active Discovery, select Reverse DNS Lookup.

Test the DNS configuration

Use a test device to verify that the reverse DNS lookup settings configured in the Define DNS servers section work as expected.

  1. On your sensor console, select System settings > Network monitoring and under Active Discovery, select Reverse DNS Lookup.

If you're working with dynamic networks, you need to handle IP addresses changes as they occur, by defining DHCP address ranges on each OT network sensor. When an IP address is defined as a DHCP address, Defender for IoT identifies any activity happening on the same device, regardless of IP address changes.

To define DHCP address ranges:ranges:

  1. Sign into your OT sensor and select System settings > Network monitoring > DHCP Ranges.