Can't enable data collection for Enable Microsoft Defender for IoT

Przemyslaw Zebik 0 Reputation points
2024-05-20T13:48:58.0533333+00:00

Hi, I can't enable data collection for Microsoft Defender for IoT. Enable data collection button turns on successfully but it doesn't seems to work. Once you go again to IOT Hub>Defender for IOT>Settings>Data collection and Enable Microsoft Defender for IoT it turns green but it doesn't work. I believe all necessary prerequisites are enabled for IOT Hub.

Defender for IOT Add-ON is enabled

IOT Hub resource is created in a Standard Tier

LA is in the same subscription as IOT Hub

Azure IoT Hub
Azure IoT Hub
An Azure service that enables bidirectional communication between internet of things (IoT) devices and applications.
1,205 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Przemyslaw Zebik 0 Reputation points
    2024-05-21T09:59:31.9566667+00:00

    Hi Sander, Thanks I should have been more precise. Let me explain the end goal and the steps I've taken:

    • This is Defender for IOT environment with pre-hydrated content from PCAP files. I have two sensors in offline and online mode. Both are working fine with device inventory populated and alerts showing in offline D4IOT console, once I connect my online sensor I can see same data (alerts and device inventory) in Azure console.
    • The end goal is to send D4IOT alerts to Microsoft Sentinel Environment and for this purpose I need online Sensor witch is registered and connected to IOT Hub
    • D4IOT online sensor has been registered in previously created IOT Hub (Defender for IOT add-on is enabled)
    • By "it doesn't work" I mean Data collection and Enable Microsoft Defender for IoT button. Than click on save and I get "Data Collection successfully updated" message. Once you go back in Enable Microsoft Defender for IoT button is disabled again. Please see screenshot. Screenshot 2024-05-21 115322.jpg
    • Integration does not work as I can't see any data in Overview section of Defender for IOT in IOT Hub. Please see screenshot Screenshot 2024-05-21 115740.jpg
    • There are no error messages in Azure or Activity Logs
    • I checked few times permissions in my subscription/IOT Hub/Log Analytics workspace
    0 comments No comments

  2. Przemyslaw Zebik 0 Reputation points
    2024-05-21T17:31:56.32+00:00

    Hi, I've resolved the issue by reregistering MD4IOT OT online sensor. I can see MD4IOT Security alerts forwarded to LA workspace and incidents created in MSFT Sentinel. Thanks!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.