Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The Internet of Things (IoT) connects billions of smart devices used in homes and businesses, while Operational Technology (OT) focuses on industrial systems like factory equipment and critical infrastructure. Securing OT/IoT environments comes with unique challenges, like unmanaged devices, increased attack surfaces, and the absence of traditional security controls (review more security challenges).
To maintain operational reliability and safety, organizations must use tailored IoT/OT security approaches due to the unique risks in these environments. Microsoft Defender for IoT addresses these unique risks, providing comprehensive OT security, including visibility into OT environments and advanced threat protection.
In this article, you learn about IoT/OT security challenges, and how Defender leverages Defender for IoT to detect and monitor enterprise IoT and OT devices.
Note
Microsoft E5 and E5 Security customers can enable enterprise IoT security as part of their license. Learn more about the Enterprise IoT device protection supported for different licenses.
Enterprise IoT security challenges
When IoT/OT devices can't be protected by traditional security monitoring systems, each new wave of innovation increases the risk and possible attack surfaces across those IoT devices and OT networks.
Specifically, enterprise IoT security challenges include:
- Lack of visibility into unmanaged IoT devices, which create significant blind spots and increase the enterprise attack surface.
- Complex device authentication and identity management, where traditional security models like password-based authentication are often insufficient.
- Large amounts of sensitive data with insufficient data encryption.
- Lack of built-in security controls and security best practices, making enterprise IoT devices easy targets for sophisticated attacks.
- Limited computational capacity, making it difficult to implement standard security measures like encryption, authentication, and firmware updates.
Enterprise IoT device protection in Defender for Endpoint and Defender
Enterprise IoT security in Microsoft Defender for Endpoint and Defender provides IoT-specific security value for IoT devices, including risk and exposure levels, vulnerabilities, and recommendations.
While monitoring endpoints on the network, the existing Defender for Endpoint agent detects, identifies, assesses, and secures enterprise IoT assets on the monitored endpoints.
This table describes the supported protection for different licenses.
| License | Device discovery | Threat detection - managed/unmanaged devices | VM | Security recommendations | How to enable |
|---|---|---|---|---|---|
| Microsoft Defender for Endpoint P2 | ✅ | ✅ | ❌ | ❌ | - Start with a free trial- Purchase the standalone full license. |
| Enterprise IoT add-on device license (add-on to MDE P2) | ✅ | ✅ | ✅ | ✅ | Enable enterprise IoT security |
| E51 | ✅ | ✅ | ✅ | ✅ | Enable enterprise IoT security |
1Includes the MDE P2 license and the enterprise IoT add-on. Each E5 user license supports five enterprise IoT add-on device licenses.
Supported devices
Enterprise IoT protection includes devices connected to an IT network (for example, Voice over Internet Protocol (VoIP), printers, and smart TVs).
Main features
| Feature | Location | More details |
|---|---|---|
| Discover enterprise IoT assets for a full enterprise IoT inventory | Assets > Devices > IoT devices | Device inventory overview |
| Review alerts triggered by enterprise IoT assets | Device details page > Alerts tab | - Learn more about Defender for Endpoint alerts. - Simulate alerts in Microsoft 365 Defender for Enterprise IoT using the Raspberry Pi scenario available in the Microsoft 365 Defender Evaluation & Tutorials page. |
| Review security recommendations for enterprise IoT assets | Device details page > Security recommendations tab | Security recommendations in Defender for Endpoint |
| Discover vulnerabilities associated with enterprise IoT assets | Device details page > Discovered vulnerabilities tab | Vulnerabilities in your organization |
| Use advanced hunting queries to create custom alert rules or to collect vulnerabilities across all your devices | Advanced hunting page in the Defender portal |
Extend protection to OT devices
To go beyond the protection that the Defender for Endpoint agent provides for enterprise IoT assets, Defender for IoT provides full visibility and security protection into OT assets in relevant internal networks.
For more information:
- Onboard Defender for IoT to enable OT protection.
- Learn about the OT-specific security use-cases that Defender for IoT addresses.