Ensure that Microsoft Defender for IoT is enabled for your Microsoft Azure IoT Hub resources so that it can act as a central security hub for the IoT devices connected to your organization's network. Microsoft Defender for IoT integrates directly with the standard tier of Azure IoT Hub and, once enabled, continuously monitors device identity management, device-to-cloud, and cloud-to-device communication patterns to generate security recommendations and real-time alerts, without requiring an additional agent to be installed on the connected devices. For all newly created standard tier IoT hubs, Microsoft Defender for IoT is set to On by default, but it must be manually onboarded for existing IoT hubs that were created before this feature was enabled or that had it turned off during setup.
IoT devices are frequently deployed with default credentials, rarely receive security patches, and often cannot run traditional endpoint security agents, making them a common entry point that attackers use to gain a foothold and move laterally within an enterprise network. By routing device identity management and communication patterns through Microsoft Defender for IoT, your security team can detect anomalous behavior, such as unauthorized devices, unusual communication endpoints, permissive firewall rules, or shared authentication credentials, early enough to contain a breach before it spreads to other parts of your Azure environment.
Enabling Microsoft Defender for IoT incurs additional charges that are calculated based on your usage level, such as the volume of monthly messages processed from your IoT hubs. Organizations should review the current pricing details before onboarding production IoT hubs. Microsoft Defender for IoT also supports hybrid and local (on-premises) deployment models that run on your own physical infrastructure; these deployment types require additional setup that is outside the scope of this Azure IoT Hub-level recommendation.
Audit
To determine if Microsoft Defender for IoT is enabled for your Azure IoT hubs, perform the following operations:
Remediation / Resolution
To enable Microsoft Defender for IoT for your existing Azure IoT hubs, perform the following operations:
Microsoft Defender for IoT currently only supports IoT hubs deployed with the standard pricing tier. Enabling Microsoft Defender for IoT incurs additional usage-based charges, as described in the Impact section.References
- Azure Official Documentation
- Quickstart: Enable Microsoft Defender for IoT on your Azure IoT Hub - Microsoft Defender for IoT
- Microsoft Defender for IoT
- Microsoft Defender for IoT Plans and Pricing
- Azure security baseline for Microsoft Defender for IoT
- Azure Command Line Interface (CLI) Documentation
- az account
- az account
- az iot hub
- az resource
- az resource
- az resource
- az resource