Microsoft Defender for IoT
Identity protection

Create and manage Users on an OT Network Sensor

In brief

The article now clearly covers creating, editing, and removing sensor users, Active Directory integration, and privileged-access recovery. Prerequisites are presented as notes, and headings, links, metadata, and related-content formatting were updated.

What Defender admins need to know

Administrators can more easily identify the required roles and accounts for each procedure. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Create and manage users on an OT network sensor

Microsoft Defender for IoT provides tools for managing on-premises user access in the OT network sensor. Azure users are managed at the Azure subscription level. For more information, see Defender for IoT user management overview.

This article describes how to managecreate, edit, and remove on-premises users directly on an OT network sensor.sensor, configure Active Directory integration, and recover privileged access. Some procedures require the Admin role or a privileged user account. For details, see the prerequisites listed in each section.

Default privileged users

Configure an Active Directory connection

We recommend configuring on-premises users on your OT sensor with Active Directory,Directory in order to allow Active Directory users to sign in to your sensor and use Active Directory groups, with collective permissions assigned to all users in the group.

For example, use Active Directory when you have a large number of users that you want to assign Read Only access to, and you want to manage those permissions at the group level.

To integrate with Active Directory:Directory:

  1. Sign in to your OT sensor and select System Settings > Integrations > Active Directory.

  2. When you've added all your Active Directory servers, select Save.

    For example:

    :::image type="content" source="media/manage-users-sensor/active-directory-integration-example.png" alt-text="Screenshot of the active directory integration configuration on the sensor.":::

Add new OT sensor users

This procedure describes how to create new users for a specific OT network sensor.

Prerequisites: This procedure is available for the admin, cyberx, and cyberx_host users, and any user with the Admin role.

To add a user:

  1. Sign in to the sensor console and select Users > + Add user.

To add a user:

  1. Sign in to the sensor console and select Users > + Add user.

Change a sensor user's password

Prerequisites:[!NOTE] This procedure is available only for the cyberx, admin, or cyberx_host users, or for users with the Admin role.

To change a user's password on a sensor:sensor:

  1. Sign into the sensor and select Users.

This procedure describes how to recover privileged access to a sensor, for the cyberx, admin, or cyberx_host users. For more information, see Default privileged on-premises users.

Prerequisites: This procedure is available only for the cyberx, admin, or cyberx_host users.

To recover privileged access to a sensor:

  1. Start signing in to the OT network sensor. On the sign-in screen, select the Reset link. For example:

    :::image type="content" source="media/manage-users-sensor/password-recovery-sensor.png" alt-text="Screenshot of the Reset password dialog on the OT sensor.":::

  2. Go the Defender for IoT Sites and sensors page in the Azure portal. You may want to open the Azure portal in a new browser tab or window, keeping your sensor tab open.

    In your Azure portal settings > Directories + subscriptions, make sure that you've selected the subscription where your sensor was onboarded to Defender for IoT.

  3. Back on the sensor tab, on the Password recovery screen, select Select file. Navigate to and upload the password_recovery.zip file you'd downloaded earlier from the Azure portal.

To recover privileged access to a sensor:

  1. Start signing in to the OT network sensor. On the sign-in screen, select the Reset link. For example:

    :::image type="content" source="media/manage-users-sensor/password-recovery-sensor.png" alt-text="Screenshot of the Reset password dialog on the OT sensor.":::

  2. Go the Defender for IoT Sites and sensors page in the Azure portal. You might want to open the Azure portal in a new browser tab or window, keeping your sensor tab open.

    In your Azure portal settings > Directories + subscriptions, make sure that you've selected the subscription where your sensor was onboarded to Defender for IoT.

  3. Back on the sensor tab, on the Password recovery screen, select Select file. Navigate to and upload the password_recovery.zip file you'd downloaded earlier from the Azure portal.

For more information, see Defender for IoT CLI users and access.

Prerequisites: This procedure is available for the cyberx user only.

  1. Sign into your OT sensor via SSH and run:

  2. Exit the file and run sudo monit restart all to apply your changes.

Related content

Audit user activity

  1. Sign into your OT sensor via SSH and run:

  2. Exit the file and run sudo monit restart all to apply your changes.

Next steps

For more information, see Audit user activity.