Microsoft Defender for IoT
Identity protection

Import extra data for detected OT devices - Microsoft Defender for IoT

In brief

The article now clarifies the OT sensor prerequisite, adds the need for a CSV-capable editor, restructures the import steps, updates terminology, and specifies that devices omitted from an authorized-devices import are marked not authorized and can generate new traffic alerts.

What Defender admins need to know

Administrators have clearer preparation and import instructions and should verify that all authorized devices are included in the import file.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Import extra data for detected OT devices

Before performing the procedures in this article, you must have:

  • An OT network sensor with OT sensor software installed, and configured and activated.

  • Access to your OT network sensor as an Admin user. For more information, see On-premises users and roles for OT monitoring with Defender for IoT.

  • An understanding of the extra device data you want to import. Use that understanding to choose one of the following import methods:

    • Import data from the device map to import device names, operating systems, groups, or Purdue layer
    • Import data from system settings to import device IP addresses, operating systems, patch levels, or authorization statuses
  • Excel or another application that can create and edit .csv files.

  1. In your .csv file, type the following details for each device:

    • IP Address. Enter the device's IP address.
    • Device OS. Enter one of the device operating systems listed in the supported device operating system values.
    • Last Update. Enter the date that the device was last updated, in YYYY-MM-DD format.

To fill in the Device OS column, use the example device information CSV entry for sample device details and the supported device operating system values table for supported operating system values.reference.

Device information example

|---------|---------|---------| |192.168.19.200 | Windows 7 | 2017-11-01 |

Supported values for Device operating system

The following table lists the supported values you can enter in the Device OS column. | Windows Vista 64 | | | | Windows XP | | |

  1. Sign into your OT sensor and select System settings > Import settings > Device information.

  2. In the Device information pane, select + Import file and then select your edited .csv file.

  3. Select Close to save your changes.

Import device authorization status

After importing device authorization status, any devices not included in the authorized devices import list are newly defined as not-authorized, and you'll start to receive new alerts about any traffic on each of these devices.

  1. Download the Defender for IoT device authorization file and open it for editing.

  2. Select Close to save your changes.

Next stepsRelated content