Modernize OT Security. Keep Your Microsoft Investment.

Forescout replaces the Defender for IoT sensing layer while your Microsoft ecosystem keeps working exactly as it does today.

The retirement of the on-premises console changed how Defender for IoT customers run their day-to-day operations, but moving forward doesn’t mean starting over. Forescout gives you a practical transition path: reuse eligible hardware, keep your integrations, and migrate at your own pace.

Why Defender for IoT Customers Choose Forescout

Organizations moving beyond Defender for IoT need deeper industrial visibility, broader OT and IoT discovery, stronger threat and anomaly detection, and a path that preserves their Microsoft investments. Here’s how Forescout’s purpose-built OT expertise strengthens operational resilience.

Extend your coverage as you need

Run sensors on any hardware: Forescout appliances, reuse eligible existing appliances, COTS, VMs, and containers.

AI-assisted analysis

Explore asset and risk data with natural-language search and AI-supported reporting.

Industrial discovery

Discover more OT and IoT assets with broader protocol support and both passive and active discovery.

Asset visibility & intelligence

More depth, more context, more actionability across specialized industrial devices as well as all your other devices.

Risk management

Cyber, operational, and network risk, prioritized by impact with Vedere Labs and CISA KEV intelligence.

Security controls

Hundreds of preconfigured security checks to expose misconfigurations and weak points, zero configuration, one click.

Threat & anomaly detection

Detect cyber threats and operational anomalies before they lead to costly production downtime, using deep packet inspection and behavioral analysis of OT and IoT traffic.

Configuration & change monitoring

Track changes to industrial devices, configurations, and communications that could affect operations.

Reporting & compliance

Reporting aligned to the frameworks you answer to: IEC 62443, NIS2, NIST, and MITRE ATT&CK for ICS.

Microsoft ecosystem

Share Forescout OT asset, risk, and threat context with Microsoft Sentinel and Microsoft Security Exposure Management. Available through Microsoft Marketplace and MACC-eligible.

Extend your OT security with Segmentation and Secure Remote Access. Find out what transfers, what you can reuse, and how fast you can move.

Talk to a Migration Expert

Migration on Your Terms

No forced rip-and-replace. Forescout migrations follow the approach that fits your environment, your risk tolerance, and your operational windows:

Continuous Assessmen

Side-by-side

Deploy Forescout alongside Defender for IoT and validate everything before you switch. Lowest risk.

150+ Classification Attributes

Phased

Migrate sites and sensors in controlled groups. Ideal for distributed environments.

Automate security policies

Cut-over

Back up, reimage eligible appliances, and return them to service. Fastest path, maximum hardware reuse.

Whichever path you choose, Forescout’s dedicated Defender for IoT Migration Services cover assessment and scoping, appliance reimaging, transfer of supported asset and network information, rebuilding of configurations and integrations, and validation of traffic coverage and workflows before handover.

Available through the Microsoft Marketplace

Cyber Resilience for OT/IoT is available through Microsoft Marketplace and is MACC-eligible.

What you can keep:

  • Eligible Defender for IoT appliances, reimaged as Forescout sensors
  • Existing SPAN, TAP, and mirrored-traffic feeds
  • Your asset inventory and monitored-network definitions, transferred and validated
  • Your Microsoft security integrations and workflows

Trusted Where OT Security Matters Most

Continuous visibility and control across distributed industrial sites, managed from a single platform.

OT security operations across critical infrastructure, including isolated environments — no cloud dependency.

Forescout is considered a trusted advisor and the #3 technology partner after IBM and Microsoft.

Forescout + Microsoft, better together

See how the two ecosystems work as one

Previous
Next

Recognized in Cyber-Physical Systems Protection

Forescout is recognized in the 2026 Gartner® Critical Capabilities for CPS Protection Platforms.

Read the Gartner Report

FAQ – Migration & Services

How does the migration from Defender for IoT work?

Choose the approach that fits your environment: side-by-side, phased, or cut-over. Every migration runs through four stages: planning, preparation, installation, and validation.

Can I reuse my existing Defender for IoT hardware?

Eligible appliances can be reimaged as Forescout sensors, validated model by model during scoping. You can also deploy on Forescout appliances, COTS hardware, VMs, or containers.

What transfers during migration and what doesn't?

Asset inventory and monitored-network definitions transfer. Configurations, users, and integrations are rebuilt; risk and communication context is re-established through live observation.

What does the Defender for IoT Migration Services include?

Assessment and scoping, appliance reimaging, data transfer, rebuilding of configurations and integrations, and validation before handover. Onboarding and Adoption services cover deployment and optimization.

Will my existing integrations keep working?

Yes. Sentinel, SIEM, ITSM, and other workflows are reconfigured and validated as part of the migration.

Can I keep monitoring during the transition?

Yes. Side-by-side and phased approaches keep coverage in place until the new environment is validated.

How long does migration take?

It depends on scope and approach. The Migration Assessment gives you a concrete plan and timeline for your environment.

Plan Your Move from Defender for IoT

Get a Migration Assessment: your sites and sensors mapped, reusable hardware identified, integrations scoped, and a practical transition plan built around your operational windows.

Demo RequestVistaro™ PlatformTop of Page