Microsoft Defender for IoT
General

Investigate CIS benchmark recommendation

In brief

The article’s publication date changed from June 12 to July 3, 2026, and its custom authoring metadata was updated. The supplied content excerpt is unchanged.

What Defender admins need to know

No administrator action is required; the article has only been refreshed and its metadata updated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate OS baseline (based on CIS benchmark) recommendation

Microsoft Defender for IoT evaluates OS configurations against CIS benchmarks and raises recommendations when a device doesn't meet baseline security checks. This article walks you through two investigation approaches: a basic investigation using the Defender for IoT portal, and an advanced investigation that uses Azure Log Analytics to query OS baseline test results, identify failed checks, and pinpoint affected devices across your fleet. The advanced investigation requires a Log Analytics workspace connected to Defender for IoT. For details, see the Prerequisites for advanced OS baseline investigation in the advanced investigation section..

Basic OS baseline security recommendation investigation