Hello Shaun Lewis,
As per the description, we understand that you have configured sensor with a network block with Defender for IOT that you don't want to monitor, still the devices are surfacing to monitor.
As you mentioned that configuration has been done with a network segment, all the devices which comes under that network block should not be visible in Defender monitor.
Please confirm if these devices are having the same IP address at all times (configured with static IP address or through DHCP reservation).
If you have configured DHCP without reservation, there is a chance to get IP addresses outside of this network block which you have configured to block on these devices.
When a device is excluded to monitor, it will not trigger new alerts or be included in Defender for IoT's active monitoring. However, historical data for the device will still remain available for auditing or investigation purposes.
Reference:
We recommend checking the characteristics of the devices you expect each sensor to detect, such as IP and MAC addresses. Devices that are detected in the same zone with the same logical set of device characteristics are automatically consolidated and are identified as the same device.
For example, if you're working with multiple networks and recurring IP addresses, make sure that you plan each sensor with a different zone so that devices are identified correctly as separate and unique devices.
I suggest you refer the example at the below link.