Forward on-premises OT alert information to partners - Microsoft Defender for IoT
In brief
The article now highlights prerequisites, explicitly lists Email, Syslog server, and NetWitness action types, and adds a certificate-validation troubleshooting subsection. Metadata and heading formatting were also updated.
What Defender admins need to know
Administrators can use the clearer guidance when configuring or troubleshooting OT sensor alert forwarding; no required configuration change is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Forward on-premises OT alert information
Prerequisites
Before you create forwarding rules, make sure the following prerequisites are met:
Depending on where you want to create your forwarding alert rules, you need to have either an OT network sensor installed, with access as an Admin user.
For more information, see Install OT agentless monitoring software and On-premises users and roles for OT monitoring with Defender for IoT.
Edit or delete forwarding rules on an OT sensor
Configure alert forwarding rule actions
OT sensor alert forwarding rules support these action types: Email, Syslog server, and NetWitness.
Configure the email address action
Troubleshoot forwarding rules
If your forwarding alert rules aren't working as expected, check the following details:details.
Troubleshoot certificate validation for forwarded alerts
Certificate validation. Forwarding rules for Syslog CEF, Microsoft Sentinel, and QRadar support encryption and certificate validation.
If your OT sensors are configured to verify CRL server access for SSL certificates and the certificate can't be verified, the alerts aren't forwarded.
In these cases, the sensor is the session's client and initiator. Certificates are typically received from the server or use asymmetric encryption, where a specific certificate is provided to set up the integration.
Next stepsstep
[!div class="nextstepaction"] Microsoft Defender for IoT alerts
@@ -1,10 +1,10 @@ --- title: Forward on-premises OT alert information to partners - Microsoft Defender for IoT description: Configure your OT sensor to forward alert details to partner services, syslog servers, email recipients, and other external destinations.-ms.date: 06/12/2026+ms.date: 07/03/2026 ms.topic: how-to ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Forward on-premises OT alert information@@ -33,6 +33,8 @@ This article describes how to configure your OT sensor to forward alerts to part ## Prerequisites +Before you create forwarding rules, make sure the following prerequisites are met:+ - Depending on where you want to create your forwarding alert rules, you need to have either an [OT network sensor installed](how-to-install-software.md), with access as an **Admin** user. For more information, see [Install OT agentless monitoring software](how-to-install-software.md) and [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md).@@ -63,7 +65,6 @@ This article describes how to configure your OT sensor to forward alerts to part ### Edit or delete forwarding rules on an OT sensor - > [!WARNING] > Deleting a forwarding rule is irreversible. @@ -79,7 +80,7 @@ To edit or delete an existing rule: ## Configure alert forwarding rule actions -The following action types are supported for OT sensor alert forwarding rules.+OT sensor alert forwarding rules support these action types: Email, Syslog server, and NetWitness. <a name="email-address-action"></a> ### Configure the email address action@@ -230,15 +231,17 @@ For more information and to create custom alert groups, contact [Microsoft Suppo ## Troubleshoot forwarding rules -If your forwarding alert rules aren't working as expected, check the following details:+If your forwarding alert rules aren't working as expected, check the following details.++### Troubleshoot certificate validation for forwarded alerts -- **Certificate validation**. Forwarding rules for [Syslog CEF](#syslog-server-actions), [Microsoft Sentinel](integrate-overview.md#microsoft-sentinel), and [QRadar](tutorial-qradar.md) support encryption and certificate validation.+**Certificate validation**. Forwarding rules for [Syslog CEF](#syslog-server-actions), [Microsoft Sentinel](integrate-overview.md#microsoft-sentinel), and [QRadar](tutorial-qradar.md) support encryption and certificate validation. - If your OT sensors are configured to [verify CRL server access for SSL certificates](ot-deploy/create-ssl-certificates.md#verify-crl-server-access) and the certificate can't be verified, the alerts aren't forwarded.+If your OT sensors are configured to [verify CRL server access for SSL certificates](ot-deploy/create-ssl-certificates.md#verify-crl-server-access) and the certificate can't be verified, the alerts aren't forwarded. - In these cases, the sensor is the session's client and initiator. Certificates are typically received from the server or use asymmetric encryption, where a specific certificate is provided to set up the integration.+In these cases, the sensor is the session's client and initiator. Certificates are typically received from the server or use asymmetric encryption, where a specific certificate is provided to set up the integration. -## Next steps+## Next step > [!div class="nextstepaction"] > [Microsoft Defender for IoT alerts](alerts.md) 