Investigate Devices in the OT Sensor Device Map
In brief
The article now highlights prerequisites, including an activated sensor and required permissions, and warns that deleting a device permanently removes it from inventory. It also refreshes wording and navigation labels throughout the device map and notification guidance.
What Defender admins need to know
Review the prerequisites before using the map and verify a device record is no longer needed before deleting it.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Use a device map to retrieve, analyze, and manage device information, either all at once or by network segment, such as specific interest groups or Purdue layers. If you're working in an air-gapped environment with an OT sensor, use a zone map to view devices across all connected OT sensors in a specific zone.
Before you start, make sure you meet the prerequisites, including a deployed and activated OT sensor and the required user permissions.
Prerequisites
To perform the procedures in this article, make sure that you have:
An OT network sensor Install OT sensor software, configure and activate your OT sensor, with network traffic ingested.
Access to your OT sensor. Users with the Viewer role can view data on the map. To import or export data or edit the map view, you need access as a Security Analyst or Admin user. For more information, see On-premises users and roles for OT monitoring with Defender for IoT.
| Name | Description |
|---|---|
| Refresh map | Select to refresh the map with updated data. |
| Notifications | Select to view and Manage device notifications. |
| Search by IP / MAC | Filter the map to display only devices connected to a specific IP or MAC address. |
| Multicast/broadcast | Select to edit the filter that shows or hides multicast and broadcast devices. By default, multicast and broadcast traffic is hidden. |
| Add filter (Last seen) | Select to filter devices displayed by those shown in a specific time period, from the last five minutes to the last seven days. |
| Reset filters | Select to reset the Last seen filter. |
| Highlight | Select to highlight the devices in a specific built-in device map groups Use the Search groups box to search for device groups to highlight, or expand your group options, and then select the group you want to highlight. |
| Filter | Select to filter the map to show only the devices in a specific built-in device map groups Use the Search groups box to search for device groups, or expand your group options, and then select the group you want to filter by. |
| Zoom :::image type="icon" source="media/how-to-work-with-maps/zoom-in-icon-v2.png" border="false"::: / :::image type="icon" source="media/how-to-work-with-maps/zoom-out-icon-v2.png" border="false"::: |
Zoom in on the map to view the connections between each device, either using the mouse or the +/- buttons on the right of the map. |
| Fit to screen :::image type="icon" source="media/how-to-work-with-maps/fit-to-screen-icon.png" border="false"::: |
Zooms out to fit all devices on the screen |
| Fit to selection :::image type="icon" source="media/how-to-work-with-maps/fit-to-selection-icon.png" border="false"::: |
Zooms out enough to fit all selected devices on the screen |
By default, IT devices are automatically aggregated by OT and IoT subnet definitions, so that the map focuses on your local OT and IoT networks.
To expand an IT subnet:subnet:
Sign into your OT sensor and select Device map.
Locate your subnet on the map. You might need to zoom in on the map to view a subnet icon, which looks like several machines inside a box. For example:
In the confirmation message that appears above the map, select OK.
To collapse an IT subnet:
- Sign into your OT sensor and select Device map.
- Select one or more expanded subnets and then select Collapse All.
View traffic details between connected devices
To view traffic details between connected devices:devices:
- Sign into your OT sensor and select Device map.
- Locate two connected devices on the map. You might need to zoom in on the map to view a device icon, which looks like a monitor. | Activity Report | Generates an activity report for the device for the selected timespan. | | Simulate Attack Vectors | Generates an attack vector simulation for the selected device. For more information, see Create attack vector reports. | | Add to custom group | Creates a new custom group with the selected device. | | Delete | Deletes the device from the inventory. Warning: Deleting a device permanently removes it from the inventory. Make sure you no longer need the device record before proceeding. |
Merge devices
You maymight want to merge devices if the OT sensor detected multiple network entities associated with a unique device, such as a PLC with four network cards, or a single laptop with both WiFi and a physical network card.
You can only merge authorized devices. For more information, see Unauthorized devices in Device inventory.
To merge multiple devices:
- Sign into your OT sensor and select Device map.
For example, you might receive a notification about an inactive device that needs to be reconnected, or removed if it's no longer part of the network.
To view and handle device notifications:
Sign into the OT sensor and select Device map > Notifications.
:::image type="content" source="media/how-to-work-with-maps/device-notifications.png" alt-text="Screenshot of device notifications on an OT sensor's Device map page." lightbox="media/how-to-work-with-maps/device-notifications.png":::
Each notification might have different mitigation options. Do one of the following:
- Handle one notification at a time, selecting a specific mitigation action, or selecting Dismiss to close the notification with no activity.
- Select Select All to show which notifications can be handled together. Clear selections for specific notifications, and then select Accept All or Dismiss All to handle any remaining selected notifications together.
Handle multiple notifications together
You maymight have situations where you'd want to handle multiple notifications together, such as:
IT upgraded the OS across multiple network servers and you want to learn all of the new server versions.
A group of devices is no longer active, and you want to instruct the OT sensor to remove the devices from the OT sensor.
When you handle multiple notifications together, you maymight still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected.
Respond to device notifications
| Type | Description | Available responses | Auto-resolve |
|---|---|---|---|
| New IP detected | A new IP address is associated with the device. This - A new or additional IP address was associated with a device already detected, with an existing MAC address. - A new IP address was detected for a device that's using a NetBIOS name. - An IP address was detected as the management interface for a device associated with a MAC address. - A new IP address was detected for a device that's using a virtual IP address. |
- Set Additional IP to Device: Merge the devices - Replace Existing IP: Replaces any existing IP address with the new address - Dismiss: Remove the notification. |
Dismiss |
| No subnets configured | No subnets are currently configured in your network. We recommend configuring subnets for the ability to differentiate between OT and IT devices on the map. |
- Open Subnet Configuration and configure subnets. - Dismiss: Remove the notification. |
Dismiss |
| Operating system changes | One or more new operating systems have been associated with the device. | - Select the name of the new OS that you want to associate with the device. - Dismiss: Remove the notification. |
Set with new operating system only if not already configured manually. If the operating system has already been configured: Dismiss. |
| New subnets | New subnets were discovered. | - Learn: Automatically add the subnet. - Open Subnet Configuration: Add all missing subnet information. - Dismiss: Remove the notification. |
Dismiss |
On the OT sensor console, zone maps show all network elements related to a selected zone, including OT sensors, detected devices, and more.
To view a zone map:map:
- Sign into an OT sensor and select Site Management > View Zone Map for the zone you want to view. For example:
| Subnets | Devices that belong to a specific subnet. | | VLAN | Devices associated with a specific VLAN ID. |
Next stepsRelated content
For more information, see Investigate sensor detections in a Device Inventory.
@@ -1,9 +1,9 @@ ----title: Investigate devices in the OT sensor device map+title: Investigate Devices in the OT Sensor Device Map description: Learn how to use the device map on an OT sensor which provides a graphical representation of devices and the connections between them.-ms.date: 06/12/2026+ms.date: 07/03/2026 ms.topic: how-to-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- @@ -13,11 +13,13 @@ OT device maps provide a graphic representation of the network devices detected Use a device map to retrieve, analyze, and manage device information, either all at once or by network segment, such as specific interest groups or Purdue layers. If you're working in an air-gapped environment with an OT sensor, use a *zone map* to view devices across all connected OT sensors in a specific zone. +Before you start, make sure you meet the [prerequisites](#prerequisites), including a deployed and activated OT sensor and the required user permissions.+ ## Prerequisites To perform the procedures in this article, make sure that you have: -- An OT network sensor [Install OT sensor software](ot-deploy/install-software-ot-sensor.md), [configured and activated](ot-deploy/activate-deploy-sensor.md), with network traffic ingested.+- An OT network sensor [Install OT sensor software](ot-deploy/install-software-ot-sensor.md), [configure and activate your OT sensor](ot-deploy/activate-deploy-sensor.md), with network traffic ingested. - Access to your OT sensor. Users with the **Viewer** role can view data on the map. To import or export data or edit the map view, you need access as a **Security Analyst** or **Admin** user. For more information, see [On-premises users and roles for OT monitoring with Defender for IoT](roles-on-premises.md). @@ -56,13 +58,13 @@ Use any of the following map tools to modify the data shown and how it's display |Name |Description | |---------|---------| |**Refresh map** | Select to refresh the map with updated data. |-| **Notifications** | Select to view and [manage device notifications](#manage-device-notifications). |+| **Notifications** | Select to view and [Manage device notifications](#manage-device-notifications). | |**Search by IP / MAC** | Filter the map to display only devices connected to a specific IP or MAC address. | |**Multicast/broadcast** | Select to edit the filter that shows or hides multicast and broadcast devices. By default, multicast and broadcast traffic is hidden. | |**Add filter** (Last seen) | Select to filter devices displayed by those shown in a specific time period, from the last five minutes to the last seven days. | |**Reset filters** | Select to reset the *Last seen* filter. |-|**Highlight** | Select to highlight the devices in a specific [built-in device map group](#built-in-device-map-groups). Highlighted devices are shown on the map in blue. <br><br>Use the **Search groups** box to search for device groups to highlight, or expand your group options, and then select the group you want to highlight. |-|**Filter** | Select to filter the map to show only the devices in a specific [built-in device map group](#built-in-device-map-groups). <br><br>Use the **Search groups** box to search for device groups, or expand your group options, and then select the group you want to filter by. |+|**Highlight** | Select to highlight the devices in a specific [built-in device map groups](#built-in-device-map-groups) category. Highlighted devices are shown on the map in blue. <br><br>Use the **Search groups** box to search for device groups to highlight, or expand your group options, and then select the group you want to highlight. |+|**Filter** | Select to filter the map to show only the devices in a specific [built-in device map groups](#built-in-device-map-groups) category. <br><br>Use the **Search groups** box to search for device groups, or expand your group options, and then select the group you want to filter by. | | **Zoom** <br>:::image type="icon" source="media/how-to-work-with-maps/zoom-in-icon-v2.png" border="false"::: / :::image type="icon" source="media/how-to-work-with-maps/zoom-out-icon-v2.png" border="false"::: | Zoom in on the map to view the connections between each device, either using the mouse or the **+**/**-** buttons on the right of the map. | | **Fit to screen** <br>:::image type="icon" source="media/how-to-work-with-maps/fit-to-screen-icon.png" border="false"::: | Zooms out to fit all devices on the screen | |**Fit to selection**<br>:::image type="icon" source="media/how-to-work-with-maps/fit-to-selection-icon.png" border="false"::: | Zooms out enough to fit all selected devices on the screen |@@ -79,7 +81,7 @@ To see device details, select a device and expand the device details pane on the By default, IT devices are automatically aggregated by [OT and IoT subnet definitions](../how-to-control-what-traffic-is-monitored.md#define-ot-and-iot-subnets), so that the map focuses on your local OT and IoT networks. -**To expand an IT subnet**:+To expand an IT subnet: 1. Sign into your OT sensor and select **Device map**. 1. Locate your subnet on the map. You might need to zoom in on the map to view a subnet icon, which looks like several machines inside a box. For example: @@ -90,14 +92,14 @@ By default, IT devices are automatically aggregated by [OT and IoT subnet defini 1. In the confirmation message that appears above the map, select **OK**. -**To collapse an IT subnet:**+To collapse an IT subnet: 1. Sign into your OT sensor and select **Device map**. 1. Select one or more expanded subnets and then select **Collapse All**. ### View traffic details between connected devices -**To view traffic details between connected devices**:+To view traffic details between connected devices: 1. Sign into your OT sensor and select **Device map**. 1. Locate two connected devices on the map. You might need to zoom in on the map to view a device icon, which looks like a monitor.@@ -152,18 +154,18 @@ To edit device properties or perform other actions on a device from the device m | **Activity Report** | Generates an activity report for the device for the selected timespan. | | **Simulate Attack Vectors** | Generates an attack vector simulation for the selected device. For more information, see [Create attack vector reports](how-to-create-attack-vector-reports.md). | | **Add to custom group** | Creates a new [custom group](#create-a-custom-device-group) with the selected device. |- | **Delete** | Deletes the device from the inventory. |+ | **Delete** | Deletes the device from the inventory. **Warning:** Deleting a device permanently removes it from the inventory. Make sure you no longer need the device record before proceeding. | ## Merge devices -You may want to merge devices if the OT sensor detected multiple network entities associated with a unique device, such as a PLC with four network cards, or a single laptop with both WiFi and a physical network card.+You might want to merge devices if the OT sensor detected multiple network entities associated with a unique device, such as a PLC with four network cards, or a single laptop with both WiFi and a physical network card. You can only merge authorized devices. For more information, see [Unauthorized devices in Device inventory](device-inventory.md#unauthorized-devices). > [!IMPORTANT] > You can't undo a device merge. If you mistakenly merged two devices, delete the devices and then wait for the sensor to rediscover both. -**To merge multiple devices**:+To merge multiple devices: 1. Sign into your OT sensor and select **Device map**. @@ -179,7 +181,7 @@ As opposed to alerts, which provide details about changes in your traffic that m For example, you might receive a notification about an inactive device that needs to be reconnected, or removed if it's no longer part of the network. -**To view and handle device notifications**:+To view and handle device notifications: 1. Sign into the OT sensor and select **Device map** > **Notifications**. @@ -189,10 +191,10 @@ For example, you might receive a notification about an inactive device that need :::image type="content" source="media/how-to-work-with-maps/device-notifications.png" alt-text="Screenshot of device notifications on an OT sensor's Device map page." lightbox="media/how-to-work-with-maps/device-notifications.png"::: -1. Each notification may have different mitigation options. Do one of the following:+1. Each notification might have different mitigation options. Do one of the following: - Handle one notification at a time, selecting a specific mitigation action, or selecting **Dismiss** to close the notification with no activity.- - Select **Select All** to show which notifications can be [handling multiple notifications together](#handling-multiple-notifications-together). Clear selections for specific notifications, and then select **Accept All** or **Dismiss All** to handle any remaining selected notifications together.+ - Select **Select All** to show which notifications can be [handled together](#handling-multiple-notifications-together). Clear selections for specific notifications, and then select **Accept All** or **Dismiss All** to handle any remaining selected notifications together. > [!NOTE] > Selected notifications are automatically resolved if they aren't dismissed or otherwise handled within 14 days. For more information, see the **Auto-resolve** column in [Respond to device notifications](#device-notification-responses).@@ -201,13 +203,13 @@ For example, you might receive a notification about an inactive device that need <a name="handling-multiple-notifications-together"></a> ### Handle multiple notifications together -You may have situations where you'd want to handle multiple notifications together, such as:+You might have situations where you'd want to handle multiple notifications together, such as: - IT upgraded the OS across multiple network servers and you want to learn all of the new server versions. - A group of devices is no longer active, and you want to instruct the OT sensor to remove the devices from the OT sensor. -When you handle multiple notifications together, you may still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected.+When you handle multiple notifications together, you might still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected. <a name="device-notification-responses"></a> ### Respond to device notifications@@ -216,7 +218,7 @@ Each device notification type has specific available responses. Use the recommen | Type | Description | Available responses | Auto-resolve| |--|--|--|--|-| **New IP detected** | A new IP address is associated with the device. This may occur in the following scenarios: <br><br>- A new or additional IP address was associated with a device already detected, with an existing MAC address.<br><br> - A new IP address was detected for a device that's using a NetBIOS name. <br /><br /> - An IP address was detected as the management interface for a device associated with a MAC address. <br /><br /> - A new IP address was detected for a device that's using a virtual IP address. | - **Set Additional IP to Device**: Merge the devices <br />- **Replace Existing IP**: Replaces any existing IP address with the new address <br /> - **Dismiss**: Remove the notification. |**Dismiss** |+| **New IP detected** | A new IP address is associated with the device. This might occur in the following scenarios: <br><br>- A new or additional IP address was associated with a device already detected, with an existing MAC address.<br><br> - A new IP address was detected for a device that's using a NetBIOS name. <br /><br /> - An IP address was detected as the management interface for a device associated with a MAC address. <br /><br /> - A new IP address was detected for a device that's using a virtual IP address. | - **Set Additional IP to Device**: Merge the devices <br />- **Replace Existing IP**: Replaces any existing IP address with the new address <br /> - **Dismiss**: Remove the notification. |**Dismiss** | | **No subnets configured** | No subnets are currently configured in your network. <br /><br /> We recommend configuring subnets for the ability to differentiate between OT and IT devices on the map. | - **Open Subnet Configuration** and [configure subnets](how-to-manage-individual-sensors.md#update-the-ot-sensor-network-configuration). <br />- **Dismiss**: Remove the notification. |**Dismiss** | | **Operating system changes** | One or more new operating systems have been associated with the device. | - Select the name of the new OS that you want to associate with the device.<br /> - **Dismiss**: Remove the notification. | Set with new operating system only if not already configured manually. <br><br>If the operating system has already been configured: **Dismiss**. | | **New subnets** | New subnets were discovered. |- **Learn**: Automatically add the subnet.<br />- **Open Subnet Configuration**: Add all missing subnet information.<br />- **Dismiss**: <br />Remove the notification. |**Dismiss** |@@ -227,7 +229,7 @@ If you're working with an OT sensor with sites and zones configured, device maps On the OT sensor console, zone maps show all network elements related to a selected zone, including OT sensors, detected devices, and more. -**To view a zone map**:+To view a zone map: 1. Sign into an OT sensor and select **Site Management** > **View Zone Map** for the zone you want to view. For example: @@ -272,6 +274,6 @@ The following table lists the device groups available out-of-the-box on the OT s | **Subnets** | Devices that belong to a specific subnet. | | **VLAN** | Devices associated with a specific VLAN ID. | -## Next steps+## Related content For more information, see [Investigate sensor detections in a Device Inventory](how-to-investigate-sensor-detections-in-a-device-inventory.md). 