|
2 | 2 | title: What's new in Microsoft Defender for IoT for device builders |
3 | 3 | description: Learn about the latest updates for Defender for IoT device builders. |
4 | 4 | ms.topic: conceptual |
5 | | -ms.date: 04/17/2024 |
| 5 | +ms.date: 10/05/2025 |
6 | 6 | --- |
7 | 7 |
|
8 | | -# What's new in Microsoft Defender for IoT |
| 8 | +# What's new in Microsoft Defender for IoT for device builders |
9 | 9 |
|
10 | | -[!INCLUDE [Banner for top of topics](../includes/banner.md)] |
11 | 10 |
|
12 | 11 | This article lists new features and feature enhancements in Microsoft Defender for IoT for device builders. |
13 | 12 |
|
@@ -86,7 +85,6 @@ For more information, see [Firmware analysis for device builders](overview-firmw |
86 | 85 |
|
87 | 86 | :::image type="content" source="media/whats-new-firmware-analysis/overview.png" alt-text="Screenshot that shows clicking view results button for a detailed analysis of the firmware image." lightbox="media/whats-new-firmware-analysis/overview.png"::: |
88 | 87 |
|
89 | | - |
90 | 88 | ## December 2022 |
91 | 89 |
|
92 | 90 | **Version 4.6.2**: |
@@ -117,101 +115,6 @@ When upgrading the micro agent from version 4.2.* to 4.6.2, you would first need |
117 | 115 |
|
118 | 116 | - **22.04 Ubuntu support**: Now supporting Ubuntu 22.04 devices. For more information, see [Agent portfolio overview and OS support](concept-agent-portfolio-overview-os-support.md). |
119 | 117 |
|
120 | | -## September 2022 |
121 | | - |
122 | | -**Micro agent GA announcement** |
123 | | - |
124 | | -Microsoft Defender for IoT micro agent is now generally available. |
125 | | - |
126 | | -## July 2022 |
127 | | - |
128 | | -**Version 4.2.4**: |
129 | | - |
130 | | -- **Proxy connection updates**: Now you can connect your micro-agent to an IoT Hub via a proxy. For more information, see [Connect via a proxy](tutorial-standalone-agent-binary-installation.md#connect-via-a-proxy). |
131 | | - |
132 | | -- **Support for TPM-backed certificates**: Now you can use OpenSSL certificates backed by TPM. For more information, see [Authenticate using a certificate](tutorial-standalone-agent-binary-installation.md#authenticate-using-a-certificate). |
133 | | - |
134 | | -- **AMQP support**: Now you can add AMQP support after installing your micro-agent. For more information, see [Add AMQP protocol support](tutorial-standalone-agent-binary-installation.md#add-amqp-protocol-support). |
135 | | - |
136 | | -- **Baseline collector updates**: The baseline collector now sends *pass* and *skip* checks to the cloud in addition to *failed* results. For more information, see [Baseline (trigger-based collector)](concept-event-aggregation.md#baseline-trigger-based-collector). |
137 | | - |
138 | | -- **Login collector via UTMP**: The login collector now supports UTMP to catch SSH interactive events, telnet events, and terminal logins, including failed login events. For more information, see [Login collector (event-based collector)](concept-event-aggregation.md#login-collector-event-based-collector). |
139 | | - |
140 | | -- **SBoM collector known issue**: The SBoM collector currently only collects the first 500 packages ingested. For more information, see [SBoM (trigger-based collector)](concept-event-aggregation.md#sbom-trigger-based-collector). |
141 | | - |
142 | | -## February 2022 |
143 | | - |
144 | | -**Version 4.1.2**: |
145 | | - |
146 | | -- **Micro agent for Edge is now in Public Preview**: The micro-agent supports IoT Edge devices, with an easy installation and identity provisioning process that uses an automatically provisioned module identity to authenticate Edge devices without the need to perform any manual authentication. |
147 | | - |
148 | | - For more information, see [Install Defender for IoT micro agent for Edge (Preview)](how-to-install-micro-agent-for-edge.md). |
149 | | - |
150 | | -- **New directory structure**: Now aligned with the standard Linux installation directory structure. |
151 | | - |
152 | | - Due to this change, updates to version 4.1.2 require you to reauthenticate the micro agent and save your connection string in the new location. For more information, see [Upgrade the Microsoft Defender for IoT micro agent](upgrade-micro-agent.md). |
153 | | - |
154 | | -- **SBoM collector**: The SBoM collector now collects the packages installed on the device periodically. For more information, see [Micro agent event collection (Preview)](concept-event-aggregation.md). |
155 | | - |
156 | | -- **CIS benchmarks**: The micro agent now supports recommendations based on CIS Distribution Independent Linux Benchmarks, version 2.0.0, and the ability to disable specific CIS Benchmark checks or groups using twin configurations. For more information, see [Micro agent configurations (Preview)](concept-micro-agent-configuration.md). |
157 | | - |
158 | | -- **Micro agent supported devices list expands**: The micro agent now supports Debian 11 AMD64 and ARM32v7 devices, and Ubuntu Server 18.04 ARM32 Linux devices & Ubuntu Server 20.04 ARM32 & ARM64 Linux devices. |
159 | | - |
160 | | - For more information, see [Agent portfolio overview and OS support (Preview)](concept-agent-portfolio-overview-os-support.md). |
161 | | - |
162 | | -- **DNS hit count**: network collector now includes DNS hit count field that can be visible through Log Analytics, which can help indicate if a DNS request was part of an automatic query. |
163 | | - |
164 | | - For more information, see [Network Activity events (event-based collector)](concept-event-aggregation.md#network-activity-events-event-based-collector). |
165 | | - |
166 | | -- **Login Collector**: Now supporting login collector using: SYSLOG collecting SSH login events and PAM collecting SSH, telnet and local login events using the pluggable authentication modules stack. For more information, see [Login collector (event-based collector)](concept-event-aggregation.md#login-collector-event-based-collector). |
167 | | - |
168 | | -## November 2021 |
169 | | - |
170 | | -**Version 3.13.1**: |
171 | | - |
172 | | -- DNS network activity on managed devices is now supported. Microsoft threat intelligence security graph can now detect suspicious activity based on DNS traffic. |
173 | | - |
174 | | -- [Leaf device proxying](../../iot-edge/how-to-connect-downstream-iot-edge-device.md#integrate-microsoft-defender-for-iot-with-iot-edge-gateway): There's now an enhanced integration with IoT Edge. This integration enhances the connectivity between the agent, and the cloud using leaf device proxying. |
175 | | - |
176 | | -## October 2021 |
177 | | - |
178 | | -**Version 3.12.2**: |
179 | | - |
180 | | -- More CIS benchmark checks are now supported for Debian 9: These extra checks allow you to make sure your network is compliant with the CIS best practices used to protect against pervasive cyber threats. |
181 | | - |
182 | | -- **[Twin configuration](concept-micro-agent-configuration.md)**: The micro agent’s behavior is configured by a set of module twin properties. You can configure the micro agent to best suit your needs. |
183 | | - |
184 | | -## September 2021 |
185 | | - |
186 | | -**Version 3.11**: |
187 | | - |
188 | | -- **[Login collector](concept-event-aggregation.md#login-collector-event-based-collector)** - The login collectors gather user logins, logouts, and failed login attempts. Such as SSH & telnet. |
189 | | - |
190 | | -- **[System information collector](concept-event-aggregation.md#system-information-trigger-based-collector)** - The system information collector gathers information related to the device’s operating system and hardware details. |
191 | | - |
192 | | -- **[Event aggregation](concept-event-aggregation.md#event-aggregation-for-process-and-network-collectors)** - The Defender for IoT agent aggregates events such as process, login, network events that reduce the number of messages sent and costs, all while maintaining your device's security. |
193 | | - |
194 | | -- **[Twin configuration](concept-micro-agent-configuration.md)** - The micro agent's behavior is configured by a set of module twin properties. (e.g event sending frequency and Aggregation mode). You can configure the micro agent to best suit your needs. |
195 | | - |
196 | | -## March 2021 |
197 | | - |
198 | | -### Device builder - new micro agent (Public preview) |
199 | | - |
200 | | -A new device builder module is available. The module, referred to as a micro-agent, allows: |
201 | | - |
202 | | -- **Integration with Azure IoT Hub and Defender for IoT** - build stronger endpoint security directly into your IoT devices by integrating it with the monitoring option provided by both the Azure IoT Hub and Defender for IoT. |
203 | | - |
204 | | -- **Flexible deployment options with support for standard IoT operating systems** - can be deployed either as a binary package or as modifiable source code, with support for standard IoT operating systems like Linux and Eclipse ThreadX. |
205 | | - |
206 | | -- **Minimal resource requirements with no OS kernel dependencies** - small footprint, low CPU consumption, and no OS kernel dependencies. |
207 | | - |
208 | | -- **Security posture management** – proactively monitor the security posture of your IoT devices. |
209 | | - |
210 | | -- **Continuous, real-time IoT/OT threat detection** - detect threats such as botnets, brute force attempts, crypto miners, and suspicious network activity |
211 | | - |
212 | | -The deprecated Defender-IoT-micro-agent documentation will be moved to the *Agent-based solution for device builders>Legacy* folder. |
213 | | - |
214 | | -This feature set is available with the current public preview cloud release. |
215 | 118 |
|
216 | 119 | ## Next steps |
217 | 120 |
|
|
0 commit comments