Azure defender for iot
Skill MicrosoftDocs/Agent-Skills/skills/azure-defender-for-iot
Expert knowledge for Azure Defender For Iot development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring OT sensors/micro agents, traffic mirroring, Sentinel/SIEM integration, RBAC, or SSL/TLS certs, and other Azure Defender For Iot related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure Sentinel (use azure-sentinel), Azure IoT Hub (use azure-iot-hub).From its SKILL.md
npx -y skills add MicrosoftDocs/Agent-Skills --skill azure-defender-for-iotAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
23.3 KB, ~5.3k tokens by cl100k_base, as published. Nobody here has run it
Azure Defender For Iot Skill
This skill provides expert guidance for Azure Defender For Iot. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
How to Use This Skill
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
- Preferred: Use
mcp_microsoftdocs:microsoft_docs_fetchwith query stringfrom=learn-agent-skill. Returns Markdown. - Fallback: Use
fetch_webpagewith query stringfrom=learn-agent-skill&accept=text/markdown. Returns Markdown.
Category Index
| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L37-L47 | Diagnosing and resolving Defender for IoT issues: CIS benchmark findings, micro agent problems, OT sensor install/health, and investigating alert types and responses. |
| Best Practices | L48-L53 | Designing OT monitoring architectures and preparing industrial sites, including sensor placement, network topology, and deployment planning for Defender for IoT. |
| Decision Making | L54-L66 | Guidance on planning and choosing OT mirroring methods, appliances, licensing/billing, tracking versions, and transitioning from on‑prem to cloud or retired Defender for IoT components. |
| Architecture & Design Patterns | L67-L73 | OT network architectures for connecting sensors to Azure, sample connectivity models, and mapping Defender for IoT components to Purdue OT network layers. |
| Limits & Quotas | L74-L83 | Data residency, retention limits, networking/port requirements, supported OT sensor/virtual appliance versions, and hardware/software specs for Defender for IoT deployments. |
| Security | L84-L102 | Security alerts, recommendations, auth, and access control for Defender for IoT: configuring alerts/micro agents, SSL/TLS and CA certs, RBAC/roles, SSO, and Zero Trust for OT sensors and IoT Hub. |
| Configuration | L103-L132 | Configuring and managing Defender for IoT micro agents and OT sensors: installation, dependencies, monitoring modes, connectivity, alert forwarding, maintenance, and Azure/Defender for Endpoint integration. |
| Integrations & Coding Patterns | L133-L164 | Integrating Defender for IoT with APIs, SIEMs, firewalls, ServiceNow, Sentinel, and configuring traffic mirroring and micro agent patterns for OT monitoring and automation |
| Deployment | L165-L190 | Guides for deploying, upgrading, and moving Defender for IoT OT sensors and micro agents, including hardware/VM appliance setups, traffic mirroring, and hybrid/air-gapped planning. |
Troubleshooting
Best Practices
| Topic | URL |
|---|---|
| Plan OT monitoring architecture with Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-corporate-monitoring |
| Prepare OT sites and sensor placement for Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-prepare-deploy |
Decision Making
Architecture & Design Patterns
| Topic | URL |
|---|---|
| Select architectures to connect OT sensors to Azure | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/architecture-connections |
| Use sample OT network connectivity models for sensors | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/sample-connectivity-models |
| Map Defender for IoT to Purdue OT network layers | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/understand-network-architecture |
Limits & Quotas
| Topic | URL |
|---|---|
| Understand Defender for IoT data residency mapping | https://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/concept-data-processing |
| Networking requirements and ports for Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/networking-requirements |
| Review catalog of preconfigured OT monitoring appliances | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-pre-configured-appliances |
| Check system requirements for virtual OT appliances | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-virtual-appliances |
| Understand Defender for IoT data retention limits | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/references-data-retention |
| Review archived Defender for IoT OT sensor versions | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/release-notes-ot-monitoring-sensor-archive |
Security
Configuration
Integrations & Coding Patterns
Deployment
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.