Microsoft Defender for IoT
Incidents and response

Forward on-premises OT alert information to partners - Microsoft Defender for IoT

In brief

The article now highlights prerequisites, explicitly lists Email, Syslog server, and NetWitness action types, and adds a certificate-validation troubleshooting subsection. Metadata and heading formatting were also updated.

What Defender admins need to know

Administrators can use the clearer guidance when configuring or troubleshooting OT sensor alert forwarding; no required configuration change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Forward on-premises OT alert information

Prerequisites

Before you create forwarding rules, make sure the following prerequisites are met:

Edit or delete forwarding rules on an OT sensor

Configure alert forwarding rule actions

OT sensor alert forwarding rules support these action types: Email, Syslog server, and NetWitness.

Configure the email address action

Troubleshoot forwarding rules

If your forwarding alert rules aren't working as expected, check the following details:details.

  • Troubleshoot certificate validation for forwarded alerts

    Certificate validation. Forwarding rules for Syslog CEF, Microsoft Sentinel, and QRadar support encryption and certificate validation.

    If your OT sensors are configured to verify CRL server access for SSL certificates and the certificate can't be verified, the alerts aren't forwarded.

    In these cases, the sensor is the session's client and initiator. Certificates are typically received from the server or use asymmetric encryption, where a specific certificate is provided to set up the integration.

Next stepsstep

[!div class="nextstepaction"] Microsoft Defender for IoT alerts