Microsoft Defender for IoT
Incidents and response

Respond to an alert in the Azure portal - Microsoft Defender for IoT

In brief

Updated the article’s wording for Azure portal alerts, source and destination devices, remediation steps, and learning or unlearning alert traffic. The free-account link and document metadata were also refreshed.

What Defender admins need to know

No administrator action is required; use the updated guidance when investigating OT alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Investigate and respond to an OT network alert

Before you start, make sure that you have:

After updating the status, check the alert details page for the following details to aid in your investigation:

  • Source and destination device details. Source and destination devices are listed in Alert details tab, and also in the Entities area below, as Microsoft Sentinel entities, with their own entity pages. In the Entities area, you'll use the links in the Name column to open the relevant device details pages for further investigation.to investigate related alerts, as described in the next section.

  • Site and/or zone. These values help you understand the geographic and network location of the alert and if there are areas of the network that are now more vulnerable to attack.

  • Sensor information. Review the Sensor, SiteDisplayName, and other sensor information to provide context about the sensor that triggered the alert.

  • MITRE ATT&CK tactics and techniques. Scroll down in the left pane to view all MITRE ATT&CK details. In addition to descriptions of the tactics and techniques, select the links to the MITRE ATT&CK site to learn more about each one.

The timing for when you take remediation actions may depend on the severity of the alert. For example, for high severity alerts, you might want to take action even before investigating, such as if you need to immediately quarantine an area of your network.

For lower severity alerts, or for operational alerts, you might want to fully investigate before taking action.remediation steps.

To remediate an alert, use the following Defender for IoT resources:

  • On an alert details page on either the Azure portal or the OT sensor, select the Take action tab to view details about recommended steps to mitigate the risk.

  • On a device details page in the Azure portal, for both the source and destination devices:source and destination devices listed on the alert:

    • Select the Vulnerabilities tab and check for detected vulnerabilities on each device.
  1. Check the alert details and investigate as needed before you take any alert action. When you're ready, take action on an alert details page for a specific alert, or on the Alerts page for bulk actions.

    For example, update alert status or severity, or learn and unlearn alert traffic an alert to authorize the detected traffic. Learned alerts are not triggered again if the same exact traffic is detected again.

    :::image type="content" source="media/iot-solution/learn-alert.png" alt-text="Screenshot of a Learn button on the alert details page.":::