azure-defender-for-iot
Expert knowledge for Azure Defender For Iot development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring OT sensors/micro agents, traffic mirroring, Zero Trust OT monitoring, SIEM/SOAR integrations, or OT network design, and other Azure Defender For Iot related development tasks. Not for Azure Defender For Cloud (use azure-defender-for-cloud), Azure Security (use azure-security), Azure IoT (use azure-iot), Azure IoT Hub (use azure-iot-hub).
How do I install this agent skill?
npx skills add https://github.com/microsoftdocs/agent-skills --skill azure-defender-for-iotIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill provides expert knowledge and documentation access for Azure Defender for IoT. It functions by fetching official documentation from Microsoft's learning portal. The analysis found no malicious behavior, obfuscation, or safety risks. It follows standard practices for a documentation-focused AI skill.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- ZeroLeakspass
Score: 93/100 · 2 sections analyzed
What does this agent skill do?
Azure Defender For Iot Skill
This skill provides expert guidance for Azure Defender For Iot. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
How to Use This Skill
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
- Preferred: Use
mcp_microsoftdocs:microsoft_docs_fetchwith query stringfrom=learn-agent-skill. Returns Markdown. - Fallback: Use
fetch_webpagewith query stringfrom=learn-agent-skill&accept=text/markdown. Returns Markdown.
Category Index
| Category | Lines | Description |
|---|---|---|
| Troubleshooting | L37-L46 | Diagnosing and resolving Defender for IoT issues: CIS benchmark findings, micro agent problems, OT sensor installation/health, and understanding alert types and sensor health messages. |
| Best Practices | L47-L54 | Designing OT monitoring architectures, placing sensors, tuning OT alert workflows, and investigating OT controller/programming changes with Defender for IoT |
| Decision Making | L55-L67 | Guidance for planning and choosing Defender for IoT deployment options: OT traffic mirroring methods, appliance selection, licensing/billing, micro agent and console retirement, and version/support tracking. |
| Architecture & Design Patterns | L68-L74 | OT network architectures for connecting sensors to Azure, sample connectivity models, and mapping Defender for IoT components to Purdue OT network layers. |
| Limits & Quotas | L75-L85 | Data residency, retention limits, networking/port requirements, supported OT/virtual appliances, and version/feature lifecycle details for Defender for IoT deployments. |
| Security | L86-L105 | Security alerts, recommendations, roles, RBAC, SSO, certificates, and sensor auth for securing Defender for IoT hubs, OT sensors, and monitoring OT networks with Zero Trust. |
| Configuration | L106-L134 | Configuring Defender for IoT micro agents and OT sensors, including installation, tuning, dependencies, alerting, monitoring, metadata import, networking, proxies, firewalls, and integrations. |
| Integrations & Coding Patterns | L135-L165 | Integrating Defender for IoT with APIs, SIEM/SOAR, firewalls, OT tools, and configuring traffic mirroring and scripts for alert, inventory, and vulnerability data handling. |
| Deployment | L166-L192 | Deploying and managing Defender for IoT sensors and micro agents, including hardware/VM appliance setup, traffic mirroring, upgrades, backups, region moves, and hybrid/air-gapped deployments. |
Troubleshooting
| Topic | URL |
|---|---|
| Investigate CIS benchmark findings in Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/how-to-investigate-cis-benchmark |
| Troubleshoot Defender for IoT micro agent issues | https://learn.microsoft.com/en-us/azure/defender-for-iot/device-builders/troubleshoot-defender-micro-agent |
| Reference Microsoft Defender for IoT alert types | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/alert-engine-messages |
| Troubleshoot Microsoft Defender for IoT OT sensors | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-troubleshoot-sensor |
| Validate Defender for IoT OT sensor software installation | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/ot-deploy/post-install-validation-ot-software |
| Interpret Defender for IoT sensor health messages | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/sensor-health-messages |
Best Practices
| Topic | URL |
|---|---|
| Plan OT monitoring architecture with Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-corporate-monitoring |
| Prepare OT sites and sensor placement for Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-prepare-deploy |
| Optimize Defender for IoT OT alert workflows | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-accelerate-alert-incident-response |
| Investigate OT programming changes with Defender for IoT | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/how-to-analyze-programming-details-changes |
Decision Making
Architecture & Design Patterns
| Topic | URL |
|---|---|
| Select architectures to connect OT sensors to Azure | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/architecture-connections |
| Use sample OT network connectivity models for sensors | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/sample-connectivity-models |
| Map Defender for IoT to Purdue OT network layers | https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/understand-network-architecture |
Limits & Quotas
Security
Configuration
Integrations & Coding Patterns
Deployment
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/microsoftdocs/agent-skills/azure-defender-for-iot">View azure-defender-for-iot on skillZs</a>