Microsoft Defender for IoT
General

Microsoft Defender for IoT alerts

In brief

The article now includes an overview of viewing, investigating, and managing alerts across supported locations, with clearer terminology, navigation links, synchronization wording, and remediation references.

What Defender admins need to know

Administrators get clearer guidance for finding and managing alerts; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Microsoft Defender for IoT alerts description: Learn about Microsoft Defender for IoT alerts across the Azure portal and OT network sensors. ms.date: 06/12/07/03/2026 ms.topic: how-to ms.custom: msecd-doc-authoring-10141016

  • enterprise-iot
  • sfi-image-nochange ai-usage: ai-assisted

Microsoft Defender for IoT alerts

Overview

Microsoft Defender for IoT alerts enhance your network security and operations with real-time details about events logged in your network. Alerts are triggered when OT network sensors detect changes or suspicious activity in network traffic that needs your attention.

This article describes how to view, investigate, and manage Defender for IoT alerts across the Azure portal, OT network sensors, and Microsoft 365 Defender, including alert statuses, triaging options, and remediation workflows.

For example:

:::image type="content" source="media/how-to-view-manage-cloud-alerts/main-alert-page.png" alt-text="Screenshot of the Alerts page in the Azure portal." lightbox="media/how-to-view-manage-cloud-alerts/main-alert-page.png":::

Alert management considerations

Consider the following behaviors and limitations when managing alerts:

Focused alerts in OT/IT environments

Organizations where sensors are deployed between OToperational technology (OT) and ITinformation technology (IT) networks deal with many alerts, related to both OT and IT traffic. The amount of alerts, some of which are irrelevant, can cause alert fatigue and affect overall performance. To address these challenges, Defender for IoT's detection policy steers its different alert engines to focus on alerts with business impact and relevance to an OT network, and reduce low-value IT related alerts. For example, the Unauthorized internet connectivity alert is highly relevant in an OT network, but has relatively low value in an IT network.

To focus the alerts triggered in these environments, all alert engines, except for the Malware engine, trigger alerts only if they detect a related OT subnet or protocol.

Alert statuses are otherwise fully synchronized between the Azure portal and the OT sensor. This synchronization means that regardless of whether you manage the alert in the Azure portal or on the OT sensor, the alert is updated in both locations.

Setting an alert status to Closed or Muted on a sensor updates the alert status to Closed on the Azure portal.

Use learning mode to perform an initial triage on the alerts in your network, learning those you want to mark as authorized, expected activity. Learned traffic doesn't generate new alerts the next time the same traffic is detected.

For more information about learning mode, see Create a learned baseline of OT alerts.

Alert investigation and remediation

After you triage and investigate an alert, you can take remediation actions to resolve any issues identified during your investigation.

For more information,information about investigating and remediating OT alerts, see Investigate and respond to an OT network alert.

Next steps

Review alert types and messages to help you understand and plan remediation actions and playbook integrations. For more information, see OT monitoring alert types and descriptions.

Next steps

[!div class="nextstepaction"] View and manage alerts from the Azure portal