Azure Defender For Iot Skill
SkillCloud & infraExpert knowledge for Azure Defender For Iot development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring OT sensors/micro agents, traffic mirroring, Zero Trust OT monitoring, SIEM/SOAR integrations, or OT network design, and other Azure Defender For Iot related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure IoT (use azure-iot), Azure IoT Hub (use azure-iot-hub).
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Azure Defender For Iot Skill skill
What this skill tells your AI
The instructions your AI receives, as published by microsoftdocs/agent-skills in skills/azure-defender-for-iot/SKILL.md and read by ahel’s review.
This skill provides expert guidance for Azure Defender For Iot. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
How to Use This Skill
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
- Preferred: Use
mcp_microsoftdocs:microsoft_docs_fetchwith query stringfrom=learn-agent-skill. Returns Markdown. - Fallback: Use
fetch_webpagewith query stringfrom=learn-agent-skill&accept=text/markdown. Returns Markdown.
Category Index
| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L37-L46 | Diagnosing and resolving Defender for IoT issues: CIS benchmark findings, micro agent problems, OT sensor installation/health, and understanding alert types and sensor health messages. |
| Best Practices | L47-L54 | Designing OT monitoring architectures, placing sensors, tuning OT alert workflows, and investigating OT controller/programming changes with Defender for IoT |
| Decision Making | L55-L67 | Guidance for planning and choosing Defender for IoT deployment options: OT traffic mirroring methods, appliance selection, licensing/billing, micro agent and console retirement, and version/support tracking. |
| Architecture & Design Patterns | L68-L74 | OT network architectures for connecting sensors to Azure, sample connectivity models, and mapping Defender for IoT components to Purdue OT network layers. |
| Limits & Quotas | L75-L85 | Data residency, retention limits, networking/port requirements, supported OT/virtual appliances, and version/feature lifecycle details for Defender for IoT deployments. |
| Security | L86-L105 | Security alerts, recommendations, roles, RBAC, SSO, certificates, and sensor auth for securing Defender for IoT hubs, OT sensors, and monitoring OT networks with Zero Trust. |
| Configuration | L106-L134 | Configuring Defender for IoT micro agents and OT sensors, including installation, tuning, dependencies, alerting, monitoring, metadata import, networking, proxies, firewalls, and integrations. |
| Integrations & Coding Patterns | L135-L165 | Integrating Defender for IoT with APIs, SIEM/SOAR, firewalls, OT tools, and configuring traffic mirroring and scripts for alert, inventory, and vulnerability data handling. |
| Deployment | L166-L192 | Deploying and managing Defender for IoT sensors and micro agents, including hardware/VM appliance setup, traffic mirroring, upgrades, backups, region moves, and hybrid/air-gapped deployments. |
Troubleshooting
| Topic | URL |
|---|---|
| Investigate CIS benchmark findings in Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-investigate-cis-benchmark |
| Troubleshoot Defender for IoT micro agent issues | https://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/troubleshoot-defender-micro-agent |
| Reference Microsoft Defender for IoT alert types | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/alert-engine-messages |
| Troubleshoot Microsoft Defender for IoT OT sensors | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-troubleshoot-sensor |
| Validate Defender for IoT OT sensor software installation | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/post-install-validation-ot-software |
| Interpret Defender for IoT sensor health messages | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/sensor-health-messages |
Best Practices
| Topic | URL |
|---|---|
| Plan OT monitoring architecture with Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-corporate-monitoring |
| Prepare OT sites and sensor placement for Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-prepare-deploy |
| Optimize Defender for IoT OT alert workflows | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-accelerate-alert-incident-response |
| Investigate OT programming changes with Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-analyze-programming-details-changes |
Decision Making
Architecture & Design Patterns
| Topic | URL |
|---|---|
| Select architectures to connect OT sensors to Azure | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/architecture-connections |
| Use sample OT network connectivity models for sensors | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/sample-connectivity-models |
| Map Defender for IoT to Purdue OT network layers | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/understand-network-architecture |
Limits & Quotas
Security
Configuration
Integrations & Coding Patterns
Deployment
Signals
- GitHub stars
- 740
- Forks
- 119
- Last commit
- Sep 2026
ahel review
S4info
community integration — published by microsoftdocs, not azure
Automated review, not a security audit. Ruleset v1.
Advanced
- Catalog kind
- skill
- Gateway key
azure-defender-for-iot- Source
- github.com/microsoftdocs/agent-skills