Modernize OT Security. Keep Your Microsoft Investment.
Forescout replaces the Defender for IoT sensing layer while your Microsoft ecosystem keeps working exactly as it does today.
The retirement of the on-premises console changed how Defender for IoT customers run their day-to-day operations, but moving forward doesn’t mean starting over. Forescout gives you a practical transition path: reuse eligible hardware, keep your integrations, and migrate at your own pace.
Why Defender for IoT Customers Choose Forescout
Organizations moving beyond Defender for IoT need deeper industrial visibility, broader OT and IoT discovery, stronger threat and anomaly detection, and a path that preserves their Microsoft investments. Here’s how Forescout’s purpose-built OT expertise strengthens operational resilience.
Extend your coverage as you need
Run sensors on any hardware: Forescout appliances, reuse eligible existing appliances, COTS, VMs, and containers.
AI-assisted analysis
Explore asset and risk data with natural-language search and AI-supported reporting.
Industrial discovery
Discover more OT and IoT assets with broader protocol support and both passive and active discovery.
Asset visibility & intelligence
More depth, more context, more actionability across specialized industrial devices as well as all your other devices.
Risk management
Cyber, operational, and network risk, prioritized by impact with Vedere Labs and CISA KEV intelligence.
Security controls
Hundreds of preconfigured security checks to expose misconfigurations and weak points, zero configuration, one click.
Threat & anomaly detection
Detect cyber threats and operational anomalies before they lead to costly production downtime, using deep packet inspection and behavioral analysis of OT and IoT traffic.
Configuration & change monitoring
Track changes to industrial devices, configurations, and communications that could affect operations.
Reporting & compliance
Reporting aligned to the frameworks you answer to: IEC 62443, NIS2, NIST, and MITRE ATT&CK for ICS.
Microsoft ecosystem
Share Forescout OT asset, risk, and threat context with Microsoft Sentinel and Microsoft Security Exposure Management. Available through Microsoft Marketplace and MACC-eligible.
Migration on Your Terms
No forced rip-and-replace. Forescout migrations follow the approach that fits your environment, your risk tolerance, and your operational windows:
Whichever path you choose, Forescout’s dedicated Defender for IoT Migration Services cover assessment and scoping, appliance reimaging, transfer of supported asset and network information, rebuilding of configurations and integrations, and validation of traffic coverage and workflows before handover.
Available through the Microsoft Marketplace
Cyber Resilience for OT/IoT is available through Microsoft Marketplace and is MACC-eligible.
What you can keep:
- Eligible Defender for IoT appliances, reimaged as Forescout sensors
- Existing SPAN, TAP, and mirrored-traffic feeds
- Your asset inventory and monitored-network definitions, transferred and validated
- Your Microsoft security integrations and workflows
FAQ – Migration & Services
How does the migration from Defender for IoT work?
Choose the approach that fits your environment: side-by-side, phased, or cut-over. Every migration runs through four stages: planning, preparation, installation, and validation.
Can I reuse my existing Defender for IoT hardware?
Eligible appliances can be reimaged as Forescout sensors, validated model by model during scoping. You can also deploy on Forescout appliances, COTS hardware, VMs, or containers.
What transfers during migration and what doesn't?
Asset inventory and monitored-network definitions transfer. Configurations, users, and integrations are rebuilt; risk and communication context is re-established through live observation.
What does the Defender for IoT Migration Services include?
Assessment and scoping, appliance reimaging, data transfer, rebuilding of configurations and integrations, and validation before handover. Onboarding and Adoption services cover deployment and optimization.
Will my existing integrations keep working?
Yes. Sentinel, SIEM, ITSM, and other workflows are reconfigured and validated as part of the migration.
Can I keep monitoring during the transition?
Yes. Side-by-side and phased approaches keep coverage in place until the new environment is validated.
How long does migration take?
It depends on scope and approach. The Migration Assessment gives you a concrete plan and timeline for your environment.