| Troubleshooting | L37-L47 | Diagnosing and resolving Defender for IoT issues: CIS benchmark findings, micro agent problems, OT sensor install/health, and investigating alert types and responses. |
| Best Practices | L48-L53 | Designing OT monitoring architectures and preparing industrial sites, including sensor placement, network topology, and deployment planning for Defender for IoT. |
| Decision Making | L54-L67 | Guidance for planning and choosing Defender for IoT deployment options: OT traffic mirroring methods, appliance selection, licensing/billing, micro agent and console retirement, and version/support tracking. |
| Architecture & Design Patterns | L68-L74 | OT network architectures for connecting sensors to Azure, sample connectivity models, and mapping Defender for IoT components to Purdue OT network layers. |
| Limits & Quotas | L75-L84 | Data residency, retention limits, networking/port requirements, supported OT sensor/virtual appliance versions, and hardware/software specs for Defender for IoT deployments. |
| Security | L85-L104 | Security alerts, recommendations, roles, RBAC, SSO, certificates, and sensor auth for securing Defender for IoT hubs, OT sensors, and monitoring OT networks with Zero Trust. |
| Configuration | L105-L133 | Configuring Defender for IoT micro agents and OT sensors: installation, dependencies, behavior, monitoring methods, alerts, networking, integrations, and sensor management/maintenance. |
| Integrations & Coding Patterns | L134-L165 | Integrating Defender for IoT with APIs, SIEM/SOAR, firewalls, OT tools, and configuring traffic mirroring and scripts for alert, inventory, and vulnerability data handling. |
| Deployment | L166-L191 | Guides for deploying, upgrading, and configuring Defender for IoT OT sensors and micro agents, including hardware/VM appliance setups, traffic mirroring, regional moves, and hybrid/air-gapped installs. |