Microsoft Defender for IoT
Identity protection

Investigate Devices in the OT Sensor Device Map

In brief

The article now highlights prerequisites, including an activated sensor and required permissions, and warns that deleting a device permanently removes it from inventory. It also refreshes wording and navigation labels throughout the device map and notification guidance.

What Defender admins need to know

Review the prerequisites before using the map and verify a device record is no longer needed before deleting it.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use a device map to retrieve, analyze, and manage device information, either all at once or by network segment, such as specific interest groups or Purdue layers. If you're working in an air-gapped environment with an OT sensor, use a zone map to view devices across all connected OT sensors in a specific zone.

Before you start, make sure you meet the prerequisites, including a deployed and activated OT sensor and the required user permissions.

Prerequisites

To perform the procedures in this article, make sure that you have:

Name Description
Refresh map Select to refresh the map with updated data.
Notifications Select to view and Manage device notifications.
Search by IP / MAC Filter the map to display only devices connected to a specific IP or MAC address.
Multicast/broadcast Select to edit the filter that shows or hides multicast and broadcast devices. By default, multicast and broadcast traffic is hidden.
Add filter (Last seen) Select to filter devices displayed by those shown in a specific time period, from the last five minutes to the last seven days.
Reset filters Select to reset the Last seen filter.
Highlight Select to highlight the devices in a specific built-in device map groups. category. Highlighted devices are shown on the map in blue.

Use the Search groups box to search for device groups to highlight, or expand your group options, and then select the group you want to highlight.
Filter Select to filter the map to show only the devices in a specific built-in device map groups. category.

Use the Search groups box to search for device groups, or expand your group options, and then select the group you want to filter by.
Zoom
:::image type="icon" source="media/how-to-work-with-maps/zoom-in-icon-v2.png" border="false"::: / :::image type="icon" source="media/how-to-work-with-maps/zoom-out-icon-v2.png" border="false":::
Zoom in on the map to view the connections between each device, either using the mouse or the +/- buttons on the right of the map.
Fit to screen
:::image type="icon" source="media/how-to-work-with-maps/fit-to-screen-icon.png" border="false":::
Zooms out to fit all devices on the screen
Fit to selection
:::image type="icon" source="media/how-to-work-with-maps/fit-to-selection-icon.png" border="false":::
Zooms out enough to fit all selected devices on the screen

By default, IT devices are automatically aggregated by OT and IoT subnet definitions, so that the map focuses on your local OT and IoT networks.

To expand an IT subnet:subnet:

  1. Sign into your OT sensor and select Device map.

  2. Locate your subnet on the map. You might need to zoom in on the map to view a subnet icon, which looks like several machines inside a box. For example:

  3. In the confirmation message that appears above the map, select OK.

To collapse an IT subnet:

  1. Sign into your OT sensor and select Device map.
  2. Select one or more expanded subnets and then select Collapse All.

View traffic details between connected devices

To view traffic details between connected devices:devices:

  1. Sign into your OT sensor and select Device map.
  2. Locate two connected devices on the map. You might need to zoom in on the map to view a device icon, which looks like a monitor. | Activity Report | Generates an activity report for the device for the selected timespan. | | Simulate Attack Vectors | Generates an attack vector simulation for the selected device. For more information, see Create attack vector reports. | | Add to custom group | Creates a new custom group with the selected device. | | Delete | Deletes the device from the inventory. Warning: Deleting a device permanently removes it from the inventory. Make sure you no longer need the device record before proceeding. |

Merge devices

You maymight want to merge devices if the OT sensor detected multiple network entities associated with a unique device, such as a PLC with four network cards, or a single laptop with both WiFi and a physical network card.

You can only merge authorized devices. For more information, see Unauthorized devices in Device inventory.

To merge multiple devices:

  1. Sign into your OT sensor and select Device map.

For example, you might receive a notification about an inactive device that needs to be reconnected, or removed if it's no longer part of the network.

To view and handle device notifications:

  1. Sign into the OT sensor and select Device map > Notifications.

    :::image type="content" source="media/how-to-work-with-maps/device-notifications.png" alt-text="Screenshot of device notifications on an OT sensor's Device map page." lightbox="media/how-to-work-with-maps/device-notifications.png":::

  2. Each notification might have different mitigation options. Do one of the following:

    • Handle one notification at a time, selecting a specific mitigation action, or selecting Dismiss to close the notification with no activity.
    • Select Select All to show which notifications can be handled together. Clear selections for specific notifications, and then select Accept All or Dismiss All to handle any remaining selected notifications together.

Handle multiple notifications together

You maymight have situations where you'd want to handle multiple notifications together, such as:

  • IT upgraded the OS across multiple network servers and you want to learn all of the new server versions.

  • A group of devices is no longer active, and you want to instruct the OT sensor to remove the devices from the OT sensor.

When you handle multiple notifications together, you maymight still have remaining notifications that need to be handled manually, such as for new IP addresses or no subnets detected.

Respond to device notifications

Type Description Available responses Auto-resolve
New IP detected A new IP address is associated with the device. This maymight occur in the following scenarios:

- A new or additional IP address was associated with a device already detected, with an existing MAC address.

- A new IP address was detected for a device that's using a NetBIOS name.

- An IP address was detected as the management interface for a device associated with a MAC address.

- A new IP address was detected for a device that's using a virtual IP address.
- Set Additional IP to Device: Merge the devices
- Replace Existing IP: Replaces any existing IP address with the new address
- Dismiss: Remove the notification.
Dismiss
No subnets configured No subnets are currently configured in your network.

We recommend configuring subnets for the ability to differentiate between OT and IT devices on the map.
- Open Subnet Configuration and configure subnets.
- Dismiss: Remove the notification.
Dismiss
Operating system changes One or more new operating systems have been associated with the device. - Select the name of the new OS that you want to associate with the device.
- Dismiss: Remove the notification.
Set with new operating system only if not already configured manually.

If the operating system has already been configured: Dismiss.
New subnets New subnets were discovered. - Learn: Automatically add the subnet.
- Open Subnet Configuration: Add all missing subnet information.
- Dismiss:
Remove the notification.
Dismiss

On the OT sensor console, zone maps show all network elements related to a selected zone, including OT sensors, detected devices, and more.

To view a zone map:map:

  1. Sign into an OT sensor and select Site Management > View Zone Map for the zone you want to view. For example:

| Subnets | Devices that belong to a specific subnet. | | VLAN | Devices associated with a specific VLAN ID. |

Next stepsRelated content

For more information, see Investigate sensor detections in a Device Inventory.