Microsoft Defender for IoT
Identity protection

Maintain Defender for IoT OT network sensors from the GUI - Microsoft Defender for IoT

In brief

The page now clarifies prerequisites, certificate-validation wording, interface update behavior, analytics-engine guidance, and related links. An alert callout was also added.

What Defender admins need to know

Review the clarified prerequisites and operational notes before maintaining sensors, especially when changing interfaces or validation settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Maintain OT network sensors from the sensor console

This article describes extra Operational Technology (OT) sensor maintenance activities that you might perform outside of a larger deployment process.

OT sensors can also be maintained from the OT sensor OT sensor CLI or the Azure portal. Before you begin, make sure you meet the prerequisites.

[!INCLUDE caution do not use manual configurations]

Before performing the procedures in this article, make sure that you have:

  1. In the Validation of OT sensor certificate area, select Mandatory if SSL/TLS certificate validation is required. Otherwise, select None.

    If thisthe Mandatory validation option is toggled on and validation fails, communication between relevant components is halted, and a validation error is shown on the sensor. For more information, see CRT file requirements.

  2. Select Save to save your certificate settings.

Update the OT sensor network configuration

After configuring your OT sensor network during OT sensor installation, you might need to make changes as part of OT sensor maintenance, such as modifying network values or setting up a proxy configuration.

To update the OT sensor configuration:

Turn off learning mode manually

An OT network sensor starts monitoring your network automatically as soon as it connects to your network and you sign in to the sensor console. Network devices start appearing in your device inventory, and alerts are triggered for any security or operational incidents that occur in your network.

There are three stages to the monitoring process. For more information, see overview of the multi stage monitoring process.

For more information, see ERSPAN ports.

    |Name  |Description  |
    |---------|---------|
    |**Mode**     | Select one of the following: <br><br>- **SPAN Traffic (no encapsulation)** to use the default SPAN port mirroring. <br>- **Tunneling** if you're using ERSPAN mirroring. <br><br>For more information, see [Choose a traffic mirroring method for OT sensors](best-practices/traffic-mirroring-methods.md).       |
    |**Description**     |  Enter an optional description for the interface. You'll see the description later on in the sensor's **System settings > Interface configurations** page, and descriptions might be helpful in understanding the purpose of each interface.  |
    |**Interface IP**     | The ERSPAN IP on the sensor side. <br> - The management interface IP and the ERSPAN interface IP must be configured on separate network subnets. <br>  - Configuring both the management and ERSPAN IP addresses on the same subnet might lead to asymmetric routing issues.   |
    | **Subnet** | The subnet mask of the ERSPAN interface IP. |
    |**Name**     | Enter a unique name for the virtual ERSPAN interface.|

By default, each OT network sensor analyzes ingested data using built-in analytics engines, and triggers alerts based on both real-time and prerecorded traffic.

While weWe recommend that you keep all analytics engines on,on. However, you might want to turn off specific analytics engines on your OT sensors to limit the type of anomalies and risks monitored by that the OT sensor.sensor monitors.

If you need to relocate or erase your OT sensor, reset it to clear all detected or learned data on the OT sensor.

After clearing data on a cloud-connected sensor:

  • The device inventory on the Azure portal is updated in parallel.

Manage sensor plugins and monitor plugin performance

View data for each protocol monitored by your sensor using the Protocols DPI (Horizon Plugins) page in the sensor console.

  1. Sign into your OT sensor console and select System settings > Network monitoring > Protocols DPI (Horizon Plugins).

After clearing data on a cloud-connected sensor:

  • The device inventory on the Azure portal is updated in parallel.

Manage sensor plugins and monitor plugin performance

Horizon Plugins are protocol analysis plugins that use Deep Packet Inspection (DPI) to inspect monitored traffic and expose protocol-specific performance and error data. View data for each protocol monitored by your sensor using the Protocols DPI (Horizon Plugins) page in the sensor console.

  1. Sign into your OT sensor console and select System settings > Network monitoring > Protocols DPI (Horizon Plugins).