A category of Azure services for internet of things devices.
Deleting devices from the OT sensor console or from Defender for IoT inventories is not reversible. There is no supported way to “recover” previously discovered devices once they have been manually deleted from the inventory.
On an OT sensor, when devices are deleted from the Device map or Device inventory, they are removed from the inventory database. The guidance for merge operations explicitly notes that incorrect merges must be corrected by deleting and waiting for rediscovery, which also applies conceptually here: the only way to get devices back is for the sensor to rediscover them from live network traffic.
For rediscovery to occur:
- The OT sensor must still be properly connected and monitoring the relevant SPAN/TAP or network segment.
- The devices must generate sufficient network traffic again so the sensor can identify them as devices.
- Once rediscovered on the sensor, cloud-connected sensors will repopulate the Azure portal device inventory based on the new detections.
If traffic is very low (around 30 PPS), rediscovery can take time or may not occur until the devices communicate in ways that allow the sensor to fingerprint them again.
Regarding firmware versions: the provided context does not describe any specific requirement or guarantee that firmware versions will always be populated. Defender for IoT device inventory surfaces device data detected from network traffic; if the observed protocols and traffic do not expose firmware information, the firmware field can remain empty even when devices are discovered and listed.
Summary:
- Manually deleted devices cannot be restored from a backup or recycle bin in Defender for IoT.
- Devices will reappear only when the OT sensor rediscovers them from network traffic.
- Firmware version fields may remain blank if the traffic being inspected does not reveal that information.
References: