What is our primary use case?
I deployed
Microsoft Defender for IoT for a customer in the UK, specifically for a large utility company with over thirteen sites distributed across the UK and Scotland. The purpose of this solution was to implement a cybersecurity or network security system using
Azure, cloud, and AI to monitor the network for vulnerabilities. We deployed sensors across twelve sites, configured
Azure, and set up
Microsoft Defender for IoT. We are now working on adding another layer with
Sentinel.
What is most valuable?
The graphics and analysis in Microsoft Defender for IoT are very representative. It effectively detects vulnerabilities and connects to the cloud to monitor for vulnerable protocols or devices. Although no vulnerabilities have been detected on our system, the solution provides alarms if there are vulnerabilities detected elsewhere in the cloud.
What needs improvement?
The documentation for Microsoft Defender for IoT is lacking. There are no clear steps or guidance, and updates are frequent, which adds to the confusion. More detailed documentation with video instructions for tasks would be helpful. The system capabilities are not well-documented either. Importing device names and maintaining a list can be cumbersome, as it requires manual input for a large number of devices. The backup and restore process is limited to GUI for backup but lacks a GUI for restore, though future updates might address this.
Sentinel documentation is also poor, with limited guidance available.
For how long have I used the solution?
I have been using the solution since October last year.
What was my experience with deployment of the solution?
I followed Microsoft’s console steps for deployment, but many gaps in documentation required additional workarounds. Configuring hypervisors and integrating PowerShell commands required us to find solutions independently, as they were not documented.
What do I think about the stability of the solution?
The sensors often fail without any clear troubleshooting steps other than rebooting, which Microsoft support recommends until newer firmware updates might address the issue.
What do I think about the scalability of the solution?
The solution is scalable. Currently, it covers around 700 devices, and more are expected as deployment completes across additional sites.
How are customer service and support?
Technical support is responsive, but it often feels like they're encountering these issues for the first time. The process sometimes feels like testing in real-time with customer support learning alongside us.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I previously worked with Cisco's IoT security solutions around three to four years ago. Cisco had better documentation, support, and shorter problem resolution times.
How was the initial setup?
The initial setup was complex due to poor documentation and required independent problem-solving. The lack of detailed guides for hypervisor configuration and PowerShell command integration made it challenging.
What was our ROI?
The user interface provides good graphics and analysis of the system, representing a point of value for Microsoft Defender for IoT.
What's my experience with pricing, setup cost, and licensing?
I do not have a clear comparison between Microsoft Defender for IoT and Cisco's licensing costs, as my experience with Cisco was four years ago.
Which other solutions did I evaluate?
I have experience with Cisco's IoT security solutions previously, which had better integration and support processes.
What other advice do I have?
The biggest challenge is with the engineering aspects and the gaps in documentation. Despite the complexities and missing information, I would still recommend Microsoft Defender for IoT to others considering its implementation. I would rate the overall solution a six out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
*Disclosure: My company does not have a business relationship with this vendor other than being a customer.