Microsoft Defender for IoT
General

Provision the Microsoft Defender for IoT Micro Agent by using DPS

In brief

The article now specifies that the module twin and device module should use the same X.509 or CA certificate used for DPS enrollment. It also updates headings, links, metadata, and navigation structure.

What Defender admins need to know

Administrators have clearer certificate guidance when provisioning the micro agent through DPS; no required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Provision the Microsoft Defender for IoT micro agent using by DPS

This article explains how to provision the standalone Microsoft Defender for IoT micro agent by using Azure IoT Hub Device Provisioning Service with X.509 certificate attestation. Follow this procedure to enroll a standalone device through DPS, create and configure a micro agent module, and verify that the agent connects successfully. If you're provisioning IoT Edge devices instead, see the Edge-device guidance linked below.

To learn how to configure the Microsoft Defender for IoT micro agent for Edge devices see Create and provision IoT Edge devices at scale

Provision the device through DPS

Perform the following steps to provision the device through DPS:

  1. Navigate into your destination IoT Hub.

  2. Create a Defender for IoT micro agent module twin issued by the same certificate.X.509 certificate used for the DPS enrollment.

  3. Configure the micro agent to use the created module (note that the device does not have to exist yet).

  4. Navigate to the configured device in the destination IoT Hub.

  5. Create a new module for the device issued by the same CA authenticator.certificate used for the DPS enrollment.

  6. Run the micro agent that you configured to use the created module to confirm it connects to the device.

Related content

Configure pluggable Authentication Modules (PAM) to audit sign-in events (Preview) \ No newline at end of file