Skillquality 0.70

azure-defender-for-iot

Expert knowledge for Azure Defender For Iot development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when deploying OT sensors, configuring

Price
free
Protocol
skill
Verified
no

What it does

Azure Defender For Iot Skill

This skill provides expert guidance for Azure Defender For Iot. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L45Troubleshooting Defender for IoT micro agents and OT sensors, validating sensor installs, interpreting sensor health messages, and understanding built‑in sensor alert types.
Best PracticesL46-L53Best practices for OT/ICS: using CIS benchmarks, designing monitoring topology, planning sensor placement at sites, and optimizing alert triage and response workflows.
Decision MakingL54-L65Guidance on choosing OT traffic mirroring methods, licenses, and appliances, plus planning billing, console retirement, cloud transition, and tracking Defender for IoT OT software versions.
Architecture & Design PatternsL66-L72OT network architectures for connecting sensors to Azure, sample connectivity models, and mapping Defender for IoT components to Purdue OT network layers.
Limits & QuotasL73-L83Data residency, retention limits, feature lifecycle, supported/archived OT sensors, virtual appliance requirements, and networking/port prerequisites for Defender for IoT.
SecurityL84-L107Security alerts, recommendations, roles, auth, and certificates for Defender for IoT/IoT Hub/OT sensors, including RBAC, SSO, PAM auditing, and Zero Trust monitoring.
ConfigurationL108-L131Configuring Defender for IoT micro agents and OT sensors: setup, OS dependencies, monitoring modes, networking/proxy/DNS/firewall, sensor management, maintenance, and auditing activity.
Integrations & Coding PatternsL132-L166Integrating Defender for IoT with SIEMs, firewalls, ServiceNow, Sentinel, and partner tools, plus APIs, micro agent provisioning, traffic mirroring, and automation patterns.
DeploymentL167-L189Hardware/VM requirements and step-by-step guides to deploy, configure, mirror traffic, back up, restore, and update Defender for IoT OT sensor appliances and VMs.

Troubleshooting

TopicURL
Troubleshoot Defender for IoT micro agent issueshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/troubleshoot-defender-micro-agent
Reference for Defender for IoT sensor alert typeshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/alert-engine-messages
Troubleshoot Microsoft Defender for IoT OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-troubleshoot-sensor
Validate Defender for IoT OT sensor software installationhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/post-install-validation-ot-software
Interpret Defender for IoT sensor health messageshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/sensor-health-messages

Best Practices

TopicURL
Investigate CIS benchmark recommendations in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-investigate-cis-benchmark
Plan OT monitoring topology with Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-corporate-monitoring
Prepare OT sites and sensor placement for Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-prepare-deploy
Optimize OT alert workflows on Defender for IoT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-accelerate-alert-incident-response

Decision Making

TopicURL
Choose OT traffic mirroring methods for Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/traffic-mirroring-methods
Decide between SPAN, RSPAN, ERSPAN for OT mirroringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/traffic-mirroring-methods
Plan Defender for IoT billing and licensinghttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/billing
Choose and extend Defender for IoT licenseshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/license-and-trial-license-extention
Select appropriate OT appliances for Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-appliance-sizing
Plan for Defender for IoT on-premises console retirementhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/on-premises-management-console-retirement
Transition Defender for IoT management from on-premises to cloudhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/transition-on-premises-management-console-to-cloud
Track Defender for IoT OT software versions and supporthttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/release-notes

Architecture & Design Patterns

TopicURL
Select architectures to connect OT sensors to Azurehttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/architecture-connections
Use sample OT network connectivity models for sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/sample-connectivity-models
Map Defender for IoT to Purdue OT network layershttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/understand-network-architecture

Limits & Quotas

TopicURL
Understand Defender for IoT data residency mappinghttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-data-processing
Review Defender for IoT feature support lifecyclehttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/edge-security-module-deprecation
Networking requirements and ports for Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/networking-requirements
Review catalog of preconfigured OT monitoring applianceshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-pre-configured-appliances
Check system requirements for virtual OT applianceshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-virtual-appliances
Understand Defender for IoT data retention limitshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/references-data-retention
Review archived Defender for IoT OT sensor versionshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/release-notes-ot-monitoring-sensor-archive

Security

TopicURL
Use Defender micro agent built-in security alertshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-agent-based-security-alerts
Define custom Defender for IoT Hub alertshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-customizable-security-alerts
Apply Defender for IoT Hub security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-recommendations
Use Defender for IoT Hub built-in alertshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-security-alerts
Use ThreadX micro agent alerts and recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-threadx-security-alerts-recommendations
Configure PAM auditing for Defender sign-in eventshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/configure-pam-to-audit-sign-in-events
Create and assign custom Defender device alertshttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/quickstart-create-custom-alerts
Call Defender for IoT sensor authentication APIshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/api/sensor-auth-apis
Meet SSL/TLS certificate requirements for OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/certificate-requirements
Review Defender for IoT compliance and certificationshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/compliance
Enable enterprise IoT security in Defender for Endpointhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/eiot-defender-for-endpoint
Manage Defender for IoT users and roleshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/manage-users-overview
Assign Azure RBAC roles for Defender for IoT accesshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/manage-users-portal
Manage on-premises users on Defender for IoT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/manage-users-sensor
Apply Zero Trust monitoring to OT networks with Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/monitor-zero-trust
Create CA-signed SSL/TLS certificates for OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/create-ssl-certificates
Use Defender for IoT security recommendations to reduce OT riskhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/recommendations
Map Azure RBAC roles to Defender for IoT actionshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/roles-azure
Configure on-premises Defender for IoT user roleshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/roles-on-premises
Configure SSO with Entra ID for IoT sensor consolehttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/set-up-sso

Configuration

TopicURL
Configure Defender for IoT micro agent behaviorhttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-micro-agent-configuration
Review Linux OS dependencies for Defender micro agenthttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-micro-agent-linux-dependencies
Configure DMI decoder for Defender micro agenthttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-configure-dmi-decoder
Configure Defender for IoT micro agent twinhttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-configure-micro-agent-twin
Configure Defender micro agent for Eclipse ThreadXhttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-threadx-security-module
Use Defender for IoT OT sensor CLI commandshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/cli-ot-sensor
Configure OT active monitoring methods in Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/configure-active-monitoring
Configure reverse DNS lookup for OT device enrichmenthttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/configure-reverse-dns-lookup
Configure OT sensor settings centrally from Azure portalhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/configure-sensor-settings-portal
Set up Windows Endpoint Monitoring for OT networkshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/configure-windows-endpoint-monitoring
Configure OT sensor proxy connections to Azurehttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/connect-sensors
Import supplemental OT device data into sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-import-device-information
Perform OT sensor maintenance via sensor console GUIhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-manage-individual-sensors
Manage Defender for IoT sensors in Azure portalhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-manage-sensors-on-the-cloud
Set up SNMP MIB health monitoring for OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-set-up-snmp-mib-monitoring
Manage threat intelligence package updates on OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-work-with-threat-intelligence-packages
Onboard OT sensors to Defender for IoT in Azurehttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/onboard-sensors
Configure and activate Microsoft Defender for IoT OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/activate-deploy-sensor
Configure firewall endpoints for OT sensor cloud managementhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/provision-cloud-management
Audit and track Defender for IoT user activityhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/track-user-activity

Integrations & Coding Patterns

TopicURL
Provision Defender micro agent with DPS and X.509https://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-provision-micro-agent
Use Defender micro agent API for Eclipse ThreadXhttps://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/threadx-security-module-api
Manage OT sensor alerts using Defender for IoT APIshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/api/sensor-alert-apis
Manage OT sensor inventory via Defender for IoT APIshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/api/sensor-inventory-apis
Access OT vulnerability data via Defender for IoT APIshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/api/sensor-vulnerability-apis
Automate OT sensor disconnection alerts with Sentinel playbookshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/automate-sensor-disconnection-alerts
Enrich Windows endpoint data using local scripthttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/detect-windows-endpoints-script
Forward OT sensor alerts to partner systems and sysloghttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-forward-alert-information-to-partners
Choose and configure Defender for IoT partner integrationshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrate-overview
Integrate ArcSight with Defender for IoT alert forwardinghttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrations/arcsight
Send Defender for IoT alerts to LogRhythm SIEMhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrations/logrhythm
Integrate RSA NetWitness with Defender for IoT alertshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrations/netwitness
Connect on-premises Defender for IoT sensors to Sentinel (legacy)https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrations/on-premises-sentinel
Stream Defender for IoT cloud alerts to third-party SIEMshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrations/send-cloud-data-to-partners
Configure legacy ServiceNow integration for Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/integrations/service-now-legacy
Use Sentinel solution to investigate Defender for IoT threatshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/iot-advanced-threat-monitoring
Connect Defender for IoT with Microsoft Sentinel via data connectorhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/iot-solution
Integrate with Microsoft Defender for IoT REST APIshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/references-work-with-defender-for-iot-apis
Configure Cisco ERSPAN for Defender for IoT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/traffic-mirroring/configure-mirror-erspan
Use ESXi vSwitch promiscuous mode for OT traffic mirroringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/traffic-mirroring/configure-mirror-esxi
Use Hyper-V vSwitch promiscuous mode for OT mirroringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/traffic-mirroring/configure-mirror-hyper-v
Configure Cisco RSPAN mirroring for OT monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/traffic-mirroring/configure-mirror-rspan
Configure Cisco SPAN ports for Defender for IoT traffic mirroringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/traffic-mirroring/configure-mirror-span
Integrate CyberArk with Defender for IoT for credential securityhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-cyberark
Integrate Forescout with Defender for IoT for OT visibilityhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-forescout
Integrate Fortinet firewalls with Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-fortinet
Integrate Palo Alto firewalls with Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-palo-alto
Integrate IBM QRadar with Defender for IoT alertshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-qradar
Integrate ServiceNow OT Manager with Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-servicenow
Integrate Splunk with Microsoft Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/tutorial-splunk
Visualize Defender for IoT data with Azure Monitor workbookshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/workbooks

Deployment

TopicURL
Select and use OT monitoring appliances for Defender for IoThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/
Deploy Dell PowerEdge R350 for OT sensor monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/dell-poweredge-r350-e1800
Deploy Dell PowerEdge R360 for OT sensor monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/dell-poweredge-r360-e1800
Deploy Dell PowerEdge R660 for OT sensor monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/dell-poweredge-r660
Deploy Heptagon YB3x appliance for OT monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/heptagon-yb3x
Use HPE ProLiant DL20 Gen 11 (4SFF) for OT monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl20-gen-11
Use HPE ProLiant DL20 Gen 11 (2LFF) for OT monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl20-gen-11-nhp-2lff
Use legacy HPE ProLiant DL20 for enterprise OT monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl20-legacy
Use HPE ProLiant DL20 Gen10 Plus for enterprise OThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl20-plus-enterprise
Use HPE ProLiant DL20 Gen10 Plus (2LFF) for SMB OThttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl20-plus-smb
Deploy Defender for IoT on HPE ProLiant DL360https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl360
Deploy Defender for IoT on HPE ProLiant DL360 Gen 11https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/hpe-proliant-dl360-gen11
Deploy Defender for IoT OT sensor VM on Hyper-V Gen 2https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/virtual-sensor-hyper-v
Deploy Defender for IoT OT sensor VM on VMware ESXihttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/virtual-sensor-vmware
Deploy YS-techsystems YS-FIT2 for OT monitoringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/appliance-catalog/ys-techsystems-ys-fit2
Back up and restore Defender for IoT OT sensorshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/back-up-restore-sensor
Plan hybrid or air-gapped Defender for IoT deploymentshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/air-gapped-deploy
Install and initially configure Defender for IoT OT sensor softwarehttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/install-software-ot-sensor
Deploy OT sensors with correct traffic mirroringhttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/traffic-mirroring/set-up-traffic-mirroring
Update Defender for IoT OT sensor software versionshttps://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/update-ot-software

Capabilities

skillsource-microsoftdocsskill-azure-defender-for-iottopic-agenttopic-agent-skillstopic-agentic-skillstopic-agentskilltopic-ai-agentstopic-ai-codingtopic-azuretopic-azure-functionstopic-azure-kubernetes-servicetopic-azure-openaitopic-azure-sql-databasetopic-azure-storage

Install

Quality

0.70/ 1.00

deterministic score 0.70 from registry signals: · indexed on github topic:agent-skills · 549 github stars · SKILL.md body (22,789 chars)

Provenance

Indexed fromgithub
Enriched2026-05-18 18:53:52Z · deterministic:skill-github:v1 · v1
First seen2026-04-18
Last seen2026-05-18

Agent access