Maintain Threat Intelligence Packages on OT Network Sensors
In brief
The article now explains Automatic and Manual update modes, provides a direct onboarding link, clarifies portal navigation and package status details, and links the Sites and sensors page.
What Defender admins need to know
No action is required. Administrators can more easily choose an update mode and find onboarding and status information.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Permissions required to manage threat intelligence packages
To manage threat intelligence packages on OT network sensors, make sure that you have:
One or more OT sensors onboarded to Defender for IoT. For onboarding steps, see Onboard OT sensors to Defender for IoT.
Relevant permissions on the Azure portal and any OT network sensors you want to update.
View the most recent threat intelligence package
To view the most recent package available from Defender for IoT:
In the Azure portal, select Sites and sensors > Threat intelligence update (Preview) > Local update. DetailsThe Sensor TI update pane shows details about the most recent package available are shown in the Sensor TI update pane.package. For example:
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/ti-local-update.png" alt-text="Screenshot of the Sensor TI update pane with the most recent threat intelligence package." lightbox="media/how-to-work-with-threat-intelligence-packages/ti-local-update.png":::
Update threat intelligence packages
Defender for IoT supports two update modes: Automatic (packages install on sensors as soon as they're released) and Manual (you push packages to sensors when needed).
Update threat intelligence packages on your OT sensors using any of the following methods:
- Automatically push updates to cloud-connected OT sensors as they're released.
Automatically push updates to cloud-connected sensors
Threat intelligence packages can be automatically updated to cloud-connected sensors as they'rethe packages are released by Defender for IoT.
Ensure automatic threat intelligence package updates by onboarding your cloud-connected sensor with the Automatic Threat Intelligence Updates option enabled. For more information, see Onboard OT sensors to Defender for IoT.
To change the update mode after you've onboarded your OT sensor:sensor:
- In Defender for IoT on the Azure portal, select Sites and sensors, and then locate the sensor you want to change.
- Select the options (...) menu for the selected OT sensor > Edit.
Your cloud-connected sensors can be automatically updated with threat intelligence packages. However, if you would like to take a more conservative approach, you can push packages from Defender for IoT to sensors only when you feel it's required. Pushing updates manually gives you the ability to control when a package is installed, without the need to download and then upload it to your sensors.
To manually push updates to a single OT sensor:sensor:
- In Defender for IoT on the Azure portal, select Sites and sensors, and locate the OT sensor you want to update.
- Select the options (...) menu for the selected sensor and then select Push Threat Intelligence update.
The manual download-and-upload method can also be used for cloud-connected sensors if you don't want to push the updates from the Azure portal.
To download threat intelligence packages:packages:
- In Defender for IoT on the Azure portal, select Sites and sensors > Threat intelligence update (Preview) > Local update.
On each OT sensor, the threat intelligence update status and version information are shown in the sensor's System settings > Threat intelligence settings.
For cloud-connected OT sensors, threat intelligence data is also shown on the Sites and sensors page in the Sites and sensors page.Azure portal. To view threat intelligence statuesstatuses from the Azure portal:
- In Defender for IoT on the Azure portal, select Site and sensors.
Related content
@@ -1,10 +1,10 @@ ----title: Maintain threat intelligence packages on OT network sensors - Microsoft Defender for IoT+title: Maintain Threat Intelligence Packages on OT Network Sensors description: Learn how to maintain threat intelligence packages on OT network sensors.-ms.date: 06/12/2026+ms.date: 07/03/2026 ms.topic: how-to ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- @@ -21,14 +21,14 @@ CVE scores shown are aligned with the [National Vulnerability Database (NVD)](ht > [!TIP] > We recommend ensuring that your OT network sensors always have the latest threat intelligence package installed so that you always have the full context of a threat before an environment is affected, and increased relevancy, accuracy, and actionable recommendations. >-> Announcements about new packages are available from our [TechCommunity blog](https://techcommunity.microsoft.com/t5/azure-defender-for-iot/bd-p/AzureDefenderIoT).+> Announcements about new packages are available from the [Defender for IoT TechCommunity blog](https://techcommunity.microsoft.com/t5/azure-defender-for-iot/bd-p/AzureDefenderIoT). <a name="permissions"></a> ## Permissions required to manage threat intelligence packages To manage threat intelligence packages on OT network sensors, make sure that you have: -- One or more OT sensors [onboarded to Defender for IoT](onboard-sensors.md).+- One or more OT sensors onboarded to Defender for IoT. For onboarding steps, see [Onboard OT sensors to Defender for IoT](onboard-sensors.md). - Relevant permissions on the Azure portal and any OT network sensors you want to update. @@ -42,14 +42,16 @@ For more information, see [Azure user roles and permissions for Defender for IoT ## View the most recent threat intelligence package -**To view the most recent package available from Defender for IoT**: +**To view the most recent package available from Defender for IoT**: -In the Azure portal, select **Sites and sensors** > **Threat intelligence update (Preview)** > **Local update**. Details about the most recent package available are shown in the **Sensor TI update** pane. For example:+In the Azure portal, select **Sites and sensors** > **Threat intelligence update (Preview)** > **Local update**. The **Sensor TI update** pane shows details about the most recent package. For example: :::image type="content" source="media/how-to-work-with-threat-intelligence-packages/ti-local-update.png" alt-text="Screenshot of the Sensor TI update pane with the most recent threat intelligence package." lightbox="media/how-to-work-with-threat-intelligence-packages/ti-local-update.png"::: ## Update threat intelligence packages +Defender for IoT supports two update modes: *Automatic* (packages install on sensors as soon as they're released) and *Manual* (you push packages to sensors when needed).+ Update threat intelligence packages on your OT sensors using any of the following methods: - [Automatically push updates to cloud-connected OT sensors](#automatically-push-updates-to-cloud-connected-sensors) as they're released.@@ -58,11 +60,11 @@ Update threat intelligence packages on your OT sensors using any of the followin ### Automatically push updates to cloud-connected sensors -Threat intelligence packages can be automatically updated to cloud-connected sensors as they're released by Defender for IoT.+Threat intelligence packages can be automatically updated to cloud-connected sensors as the packages are released by Defender for IoT. Ensure automatic threat intelligence package updates by onboarding your cloud-connected sensor with the **Automatic Threat Intelligence Updates** option enabled. For more information, see [Onboard OT sensors to Defender for IoT](onboard-sensors.md). -**To change the update mode after you've onboarded your OT sensor**:+To change the update mode after you've onboarded your OT sensor: 1. In [Defender for IoT](https://portal.azure.com/#view/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/~/Getting_started) on the Azure portal, select **Sites and sensors**, and then locate the sensor you want to change. 1. Select the options (**...**) menu for the selected OT sensor > **Edit**.@@ -72,7 +74,7 @@ Ensure automatic threat intelligence package updates by onboarding your cloud-co Your cloud-connected sensors can be automatically updated with threat intelligence packages. However, if you would like to take a more conservative approach, you can push packages from Defender for IoT to sensors only when you feel it's required. Pushing updates manually gives you the ability to control when a package is installed, without the need to download and then upload it to your sensors. -**To manually push updates to a single OT sensor**:+To manually push updates to a single OT sensor: 1. In [Defender for IoT](https://portal.azure.com/#view/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/~/Getting_started) on the Azure portal, select **Sites and sensors**, and locate the OT sensor you want to update. 1. Select the options (**...**) menu for the selected sensor and then select **Push Threat Intelligence update**.@@ -94,7 +96,7 @@ If you're working with locally managed OT sensors, you need to download the upda > The manual download-and-upload method can also be used for cloud-connected sensors if you don't want to push the updates from the Azure portal. > -**To download threat intelligence packages**:+To download threat intelligence packages: 1. In [Defender for IoT](https://portal.azure.com/#view/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/~/Getting_started) on the Azure portal, select **Sites and sensors** > **Threat intelligence update (Preview)** > **Local update**. @@ -116,7 +118,7 @@ If you're working with locally managed OT sensors, you need to download the upda On each OT sensor, the threat intelligence update status and version information are shown in the sensor's **System settings > Threat intelligence** settings. -For cloud-connected OT sensors, threat intelligence data is also shown in the **Sites and sensors** page. To view threat intelligence statues from the Azure portal:+For cloud-connected OT sensors, threat intelligence data is also shown on the [**Sites and sensors** page](https://portal.azure.com/#view/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/~/Getting_started) in the Azure portal. To view threat intelligence statuses from the Azure portal: 1. In [Defender for IoT](https://portal.azure.com/#view/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/~/Getting_started) on the Azure portal, select **Site and sensors**. @@ -133,8 +135,6 @@ For cloud-connected OT sensors, threat intelligence data is also shown in the ** > [!TIP] > If a cloud-connected OT sensor shows that a threat intelligence update has failed, we recommend that your check your sensor connection details. On the **Sites and sensors** page, check the **Sensor status** and **Last connected UTC** columns. -## Next steps--For more information, see:+## Related content - [Onboard OT sensors to Defender for IoT](onboard-sensors.md) 