Create and manage Users on an OT Network Sensor
In brief
The article now clearly covers creating, editing, and removing sensor users, Active Directory integration, and privileged-access recovery. Prerequisites are presented as notes, and headings, links, metadata, and related-content formatting were updated.
What Defender admins need to know
Administrators can more easily identify the required roles and accounts for each procedure. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Create and manage users on an OT network sensor
Microsoft Defender for IoT provides tools for managing on-premises user access in the OT network sensor. Azure users are managed at the Azure subscription level. For more information, see Defender for IoT user management overview.
This article describes how to managecreate, edit, and remove on-premises users directly on an OT network sensor.sensor, configure Active Directory integration, and recover privileged access. Some procedures require the Admin role or a privileged user account. For details, see the prerequisites listed in each section.
Default privileged users
Configure an Active Directory connection
We recommend configuring on-premises users on your OT sensor with Active Directory,Directory in order to allow Active Directory users to sign in to your sensor and use Active Directory groups, with collective permissions assigned to all users in the group.
For example, use Active Directory when you have a large number of users that you want to assign Read Only access to, and you want to manage those permissions at the group level.
To integrate with Active Directory:Directory:
Sign in to your OT sensor and select System Settings > Integrations > Active Directory.
When you've added all your Active Directory servers, select Save.
For example:
:::image type="content" source="media/manage-users-sensor/active-directory-integration-example.png" alt-text="Screenshot of the active directory integration configuration on the sensor.":::
Add new OT sensor users
This procedure describes how to create new users for a specific OT network sensor.
Prerequisites: This procedure is available for the admin, cyberx, and cyberx_host users, and any user with the Admin role.
To add a user:
Sign in to the sensor console and selectUsers>+ Add user.
To add a user:
- Sign in to the sensor console and select Users > + Add user.
Change a sensor user's password
Prerequisites:[!NOTE]
This procedure is available only for the cyberx, admin, or cyberx_host users, or for users with the Admin role.
To change a user's password on a sensor:sensor:
- Sign into the sensor and select Users.
This procedure describes how to recover privileged access to a sensor, for the cyberx, admin, or cyberx_host users. For more information, see Default privileged on-premises users.
Prerequisites: This procedure is available only for the cyberx, admin, or cyberx_host users.
To recover privileged access to a sensor:
Start signing in to the OT network sensor. On the sign-in screen, select theResetlink. For example::::image type="content" source="media/manage-users-sensor/password-recovery-sensor.png" alt-text="Screenshot of the Reset password dialog on the OT sensor.":::Go the Defender for IoTSites and sensorspage in the Azure portal. You may want to open the Azure portal in a new browser tab or window, keeping your sensor tab open.In your Azure portal settings >Directories + subscriptions, make sure that you've selected the subscription where your sensor was onboarded to Defender for IoT.Back on the sensor tab, on thePassword recoveryscreen, selectSelect file. Navigate to and upload thepassword_recovery.zipfile you'd downloaded earlier from the Azure portal.
To recover privileged access to a sensor:
Start signing in to the OT network sensor. On the sign-in screen, select the Reset link. For example:
:::image type="content" source="media/manage-users-sensor/password-recovery-sensor.png" alt-text="Screenshot of the Reset password dialog on the OT sensor.":::
Go the Defender for IoT Sites and sensors page in the Azure portal. You might want to open the Azure portal in a new browser tab or window, keeping your sensor tab open.
In your Azure portal settings > Directories + subscriptions, make sure that you've selected the subscription where your sensor was onboarded to Defender for IoT.
Back on the sensor tab, on the Password recovery screen, select Select file. Navigate to and upload the password_recovery.zip file you'd downloaded earlier from the Azure portal.
For more information, see Defender for IoT CLI users and access.
Sign into your OT sensor via SSH and run:
Exit the file and run Prerequisites: This procedure is available for the cyberx user only.
sudo monit restart all to apply your changes.
Related content
Sign into your OT sensor via SSH and run:Exit the file and runsudo monit restart allto apply your changes.
Next steps
For more information, see Audit user activity.
