How to delete devices without them popping back up?

Shaun Lewis 0 Reputation points
2025-04-28T15:24:26.92+00:00

I have configured sensor with subnet mask then within Azure portal for Defender4IOT yet workstations I do not want to monitor continues to resurface.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,528 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Venkata Jagadeep 1,085 Reputation points Microsoft External Staff
    2025-04-29T09:35:09.06+00:00

    Hello Shaun Lewis,

    As per the description, we understand that you have configured sensor with a network block with Defender for IOT that you don't want to monitor, still the devices are surfacing to monitor.

    As you mentioned that configuration has been done with a network segment, all the devices which comes under that network block should not be visible in Defender monitor.

    Please confirm if these devices are having the same IP address at all times (configured with static IP address or through DHCP reservation).

    If you have configured DHCP without reservation, there is a chance to get IP addresses outside of this network block which you have configured to block on these devices.

    When a device is excluded to monitor, it will not trigger new alerts or be included in Defender for IoT's active monitoring. However, historical data for the device will still remain available for auditing or investigation purposes.

    Reference:

    https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/configure-sensor-settings-portal

    We recommend checking the characteristics of the devices you expect each sensor to detect, such as IP and MAC addresses. Devices that are detected in the same zone with the same logical set of device characteristics are automatically consolidated and are identified as the same device.

    For example, if you're working with multiple networks and recurring IP addresses, make sure that you plan each sensor with a different zone so that devices are identified correctly as separate and unique devices.

    I suggest you refer the example at the below link.

    https://learn.microsoft.com/en-us/azure/defender-for-iot/organizations/best-practices/plan-corporate-monitoring#separating-zones-for-recurring-ip-ranges

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.