IoT Security
Integrate IoT Security with Microsoft Entra ID
Table of Contents
Expand All
|
Collapse All
IoT Security Docs
-
-
- Firewall Deployment Options for IoT Security
- Use a Tap Interface for DHCP Visibility
- Use a Virtual Wire Interface for DHCP Visibility
- Use SNMP Network Discovery to Learn about Devices from Switches
- Use Network Discovery Polling to Discover Devices
- Use ERSPAN to Send Mirrored Traffic through GRE Tunnels
- Use DHCP Server Logs to Increase Device Visibility
- Control Allowed Traffic for Onboarding Devices
- Support Isolated Network Segments
-
Integrate IoT Security with Microsoft Entra ID
Integrate IoT Security through Cortex XSOAR with Microsoft Entra ID via
Microsoft Intune.
Where Can I Use This? | What Do I Need? |
---|---|
|
One of the following Cortex XSOAR setups:
|
IoT Security integrates with Microsoft Entra ID (formerly Azure Active
Directory) through Cortex XSOAR to learn about devices and device attributes
stored as device identities. As an identity and access management solution,
Microsoft Entra ID provides information about device enrollment status and user
information, in addition to device attributes.
Integrating with Microsoft Entra ID requires having
a Microsoft Intune license. Microsoft Intune provides the MAC addresses
that IoT Security uses to match assets from Microsoft Entra ID to the
IoT Security asset inventory. Microsoft Entra ID uses device identities to
store device information, and Microsoft Intune helps facilitate the
registration and enrollment of devices for access to internal resources.
IoT Security uses the information learned from Microsoft Entra ID and
Microsoft Intune to enrich the asset inventory with new assets, additional
asset attributes, and user enrollment information related to devices.
Through the integration, IoT Security can learn the following device attributes
from Microsoft Entra ID:
- Device name
- OS group
- OS version
- Ethernet address
- Wi-Fi MAC address
- Email address of the user registered to a device
- Microsoft Entra ID device ID
- Device enrollment type
- User principal name
- Model
- Manufacturer
- Serial number
When IoT Security receives information for devices already in its inventory, it
incorporates any additional information from Microsoft Entra ID into the data it
previously gathered from network traffic and behavior analysis. For devices that are
not already in the IoT Security assets inventory, IoT Security creates new
entries with the data that Microsoft Entra ID provides.
Integrating with Microsoft Entra ID requires either a
full-featured Cortex XSOAR server
or the purchase and activation
of an IoT Security third-party integration add-on license, which comes with a free
cohosted Cortex XSOAR instance.
The basic plan includes a license for three integration add-ons, one of which can be
used for Microsoft Entra ID. The advanced plan includes a license for all
supported third-party integrations.