| Troubleshooting |
L37-L46 |
Diagnosing and resolving Defender for IoT issues: CIS benchmark findings, micro agent problems, OT sensor installation/health, and understanding alert types and sensor health messages. |
| Best Practices |
L47-L54 |
Designing OT monitoring architectures, placing sensors, tuning OT alert workflows, and investigating OT controller/programming changes with Defender for IoT |
| Decision Making |
L55-L67 |
Guidance for planning and choosing Defender for IoT deployment options: OT traffic mirroring methods, appliance selection, licensing/billing, micro agent and console retirement, and version/support tracking. |
| Architecture & Design Patterns |
L68-L74 |
OT network architectures for connecting sensors to Azure, sample connectivity models, and mapping Defender for IoT components to Purdue OT network layers. |
| Limits & Quotas |
L75-L85 |
Data residency, retention limits, networking/port requirements, supported OT/virtual appliances, and version/feature lifecycle details for Defender for IoT deployments. |
| Security |
L86-L105 |
Security alerts, recommendations, roles, RBAC, SSO, certificates, and sensor auth for securing Defender for IoT hubs, OT sensors, and monitoring OT networks with Zero Trust. |
| Configuration |
L106-L134 |
Configuring Defender for IoT micro agents and OT sensors, including installation, tuning, dependencies, alerting, monitoring, metadata import, networking, proxies, firewalls, and integrations. |
| Integrations & Coding Patterns |
L135-L165 |
Integrating Defender for IoT with APIs, SIEM/SOAR, firewalls, OT tools, and configuring traffic mirroring and scripts for alert, inventory, and vulnerability data handling. |
| Deployment |
L166-L192 |
Deploying and managing Defender for IoT sensors and micro agents, including hardware/VM appliance setup, traffic mirroring, upgrades, backups, region moves, and hybrid/air-gapped deployments. |