Microsoft Defender for IoT explained
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Defender for IoT secures the devices EDR can't reach — OT, ICS, and IoT. Here's how it works and when it's worth deploying.
Microsoft Defender for IoT is the Defender product for the devices that Defender for Endpoint cannot touch: operational technology (OT), industrial control systems (ICS), and IoT devices. PLCs on a factory floor, building automation controllers, medical equipment, energy infrastructure, badge readers, IP cameras — devices that run no agent, get patched rarely if ever, and often speak protocols your security stack has never heard of.
Why EDR doesn't reach these devices
Defender for Endpoint works by installing (or activating) an agent on the operating system. That model collapses in OT environments:
- Many devices run embedded or proprietary firmware with no way to install anything.
- Even where an OS exists, vendors frequently void support contracts if you modify the device.
- OT devices prioritise availability over everything — an agent update that reboots a controller can stop a production line, which is precisely why plant engineers keep security software away from them.
The result in most organisations is a class of networked, exploitable, unmonitored devices that no one in IT security can even enumerate. Defender for IoT exists to close that gap.
How it works
The core design is agentless, passive network monitoring:
- Network sensors (physical or virtual appliances) connect to a SPAN/mirror port or network TAP on switches in the OT network. They observe traffic; they never inject any.
- The sensors perform deep packet inspection with industrial-protocol awareness — Modbus, DNP3, Siemens S7, BACnet, EtherNet/IP, OPC UA, and many others.
- From that traffic, Defender for IoT builds a device inventory (vendor, model, firmware version, network behaviour), maps communication paths, flags vulnerabilities, and raises alerts on anomalous or malicious activity — an engineering workstation issuing unexpected write commands to a PLC, a controller talking to the internet, firmware changes outside a maintenance window.
Because everything is passive, it's deployable in environments where active scanning is forbidden — which is most OT environments. Sensors can run cloud-connected (feeding Defender XDR) or fully air-gapped with an on-premises management console, for sites that have no route to the internet by policy.
There's a second, lighter mode: enterprise IoT security. Corporate networks are full of printers, VoIP phones, smart TVs, and conference-room hardware. If you have Defender for Endpoint, its onboarded devices already see this traffic, and enabling enterprise IoT security lights up discovery, vulnerability findings, and alerts for those devices in the same Defender XDR portal — no sensors required.
Integration with Defender XDR
Cloud-connected sensors feed Microsoft Defender XDR, so OT alerts land in the same incident queue as endpoint, email, and identity alerts, and the device inventory appears alongside your managed endpoints. That matters because real OT attacks almost always start on the IT side — a phished engineer, a compromised remote-access jump box — and cross over. Correlating both halves in one incident is the whole point of the Defender XDR story.
Deployment realities
This is not a tick-a-box-in-the-portal product:
- Sensor placement is a network engineering exercise. You need SPAN or TAP access at the right aggregation points, and OT network teams — often a different team, sometimes a different company — have to agree to it.
- Discovery takes time. The inventory builds from observed traffic, so devices that rarely talk take longer to appear.
- Alert tuning needs OT context. What looks anomalous to a security analyst may be a legitimate maintenance procedure. Plan for the plant engineers to be in the triage loop, at least initially.
- Purdue-model segmentation questions surface immediately. The inventory usually reveals IT/OT crossover paths nobody documented. Treat that as the first win, not a distraction.
Licensing
Two separate models, matching the two modes:
- OT monitoring is licensed per site, in tiers based on the number of devices at the site, bought through the Microsoft 365 admin centre.
- Enterprise IoT security is an add-on tied to Defender for Endpoint; Microsoft 365 E5 and E5 Security include an allowance of enterprise IoT devices per user licence, with standalone per-device pricing beyond that.
Check the current tiers and allowances in the official docs before quoting — this is an area Microsoft has restructured before.
When it's worth it
If your organisation runs manufacturing, utilities, logistics, healthcare equipment, or serious building automation, Defender for IoT is the natural extension of an existing Defender investment — one portal, correlated incidents, and coverage for the devices your auditors keep asking about. If your "IoT estate" is a handful of printers and meeting-room screens, start with enterprise IoT security on top of Defender for Endpoint and see what discovery finds; the full sensor deployment can wait until there's an OT network that justifies it.
Further reading
Spot something wrong or want a topic covered? Send it through the contact form.