Microsoft Defender for IoT
Identity protection

Manage your OT device inventory from a sensor console

In brief

The article now describes viewing, filtering, editing, exporting, merging duplicate devices, and deleting inactive devices. It also clarifies that deletion applies to devices matching the current Last Activity filter and updates export time-zone guidance.

What Defender admins need to know

Administrators have clearer procedures for managing inventory and should verify the Last Activity filter and machine region settings before deleting or exporting data.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage your OT device inventory from a sensor console

Use the Device inventory page from a sensor console to manage all OT and IT devices detected by that console. Identify newThis article describes how to view, filter, and edit devices detected, devices that might need troubleshooting,in the inventory, export inventory data to CSV, merge duplicate devices, and more.delete inactive devices.

For more information, see Devices monitored by Defender for IoT.

View the device inventory

This procedure describes how toTo view devices detected devices inby your OT sensor, use the Device inventory page in an OT sensor console.page.

  1. Sign-in to your OT sensor console, and then select Device inventory.

The device inventory is exported with any filters currently applied, and you can save the file locally.

Merge devices

  • You can only merge authorized devices.
  • Device merges are irreversible. If you merge devices incorrectly, you'll have to delete the merged device and wait for the sensor to rediscover both devices.
  • Alternately, merge devices from the Device map page.

When merging, you instruct the sensor to combine the device properties of two devices into one. When you merge the devices, the Device Properties window and sensor reports will be updated with the new device property details.

For example, if you merge two devices, each with an IP address, both IP addresses will appear as separate interfaces in the Device Properties window.

To merge duplicate devices from the device inventory:inventory, perform the following steps:

  1. In the Device inventory page, select the devices you want to merge, and then select Merge in the toolbar at the top of the page.

You may want to view devices in your network that have been inactive and delete them.

For example, devices may become inactive because of misconfigured SPAN ports, changes in network coverage, or by unplugging thebecause devices were unplugged from the network

To view inactive devices, filter the device inventory to display devices that have been inactive.

  1. Select Apply.
  2. Select Delete Inactive Devices. In the prompt displayed, enter the reason you're deleting the devices, and then select Delete.

All devices detected within the range of the currently applied Last Activityfilter will be deleted. If you delete a large number of devices, the delete process may take a few minutes.

For more information, see Default privileged on-premises users.

Next stepsRelated content

For more information, see: