Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Attribute mapping and classification for the Service Graph Connector for Microsoft Defender for IoT (On-premises Management Console)

The following tables describe the attribute mapping and classification for sensors and devices.

Payload field nameData typeMapped to tableMapped to fieldDescription
idString format: /subscriptions/<subscription-id>/provider/<provider>/locations/<location>/sites/<site>/sensor/<sensor-name>- sys\_object\_source - cmdb\_ci\_nids- snk in sys\_object\_source - correlation\_idUnique ID for the sensor.
nameStringcmdb\_ci\_nidsnameName of the sensor.
properties.hostnameStringcmdb\_ci\_nidsfqdnHost name of the sensor.
properties.ipStringcmdb\_ci\_ip\_addressip\_addressIP address of the sensor.
properties.learningModeBooleancmdb\_ci\_nidsFalse or unavailable: Life Cycle Stage \(life\_cycle\_stage\) : Operational Life Cycle Stage Status \(life\_cycle\_stage\_status\): In Use True: Life Cycle Stage \(life\_cycle\_stage\) : Operational Life Cycle Stage Status \(life\_cycle\_stage\_status\): LearningLearning mode status of the IoT sensor.
properties.macStringcmdb\_ci\_network\_adaptername, mac\_addressMAC address of the sensor.
properties.sensorStatusStringcmdb\_ci\_nidsconnection\_stateStatus of the IoT sensor.
properties.sensorVersionStringcmdb\_ci\_nidsfirmware\_versionVersion of the IoT sensor.
properties.upSince\_utcDate and time as stringcmdb\_ci\_nidsfirst\_discoveredStartup time.
properties.zoneStringcmdb\_ci\_nidszoneZone of the IoT sensor.
Payload field nameData typeMapped to tableMapped to fieldDescription
idString format: /subscriptions/subscription-id>/providers/<providers-id>/location/<location>/deviceGroups/<device-Group>/devices/<name-field>- sys\_object\_source - cmdb\_ot\_entity - cmdb\_key\_value\_v2- snk in sys\_object\_source - discovery\_source\_id in cmdb\_ot\_entityUnique ID for the device.
resourceGroup\(Empty\)cmdb\_key\_value\_v2\(Empty\)Resource group
tenantId\(Empty\)cmdb\_key\_value\_v2\(Empty\)Tenant ID
properties.authorizedStateStringcmdb\_key\_value\_v2\(Empty\)Authorized state of the device
properties.criticalityStringcmdb\_ot\_entitybusiness\_criticalityCriticality of the device
properties.deviceNameStringcmdb\_cinameName of the device.
properties.deviceSubTypeDisplayNameStringcmdb\_cisys\_class\_nameDevice subtype display name.
properties.firstSeenDate and time as string- cmdb\_ci - cmdb\_ci\_ot\_control\_module \(if control modules are present\)first\_discoveredFirst time the device was seen.
properties.lastSeenDate and time as string- cmdb\_ci - cmdb\_ci\_ot\_control\_module \(if control modules are present\)most\_recent\_discoveryLast time the device was seen.
properties.purdueLevelStringcmdb\_ot\_entitypurdue\_levelPurdue level of the device.
properties.operatingSystem.distributionStringcmdb\_ci\_computerosOS distribution
properties.operatingSystem.versionStringcmdb\_ci\_computeros\_versionOS version
properties.operatingSystem.platformStringcmdb\_ci\_computeros\_domainOS platform
properties.operatingSystem.architectureStringcmdb\_ci\_computeros\_address\_widthOS architecture
properties.additionalFields.plcKeyState\(Empty\)cmdb\_ci\_ot\_plcswitch\_positionPLC key state
properties.additionalFields.plcRunState\(Empty\)cmdb\_ci\_ot\_plcswitch\_remote\_modePLC run state
properties.hardwareObject\(Empty\)\(Empty\)Device hardware data
properties.hardware.modelStringcmdb\_ci\(Empty\)Hardware model
properties.hardware.serialNumberStringcmdb\_serial\_numberserial\_numberHardware serial number
properties.hardware.vendorStringcmdb\_cimanufacturerHardware vendor
properties.nicsArray of Objects\(Empty\)\(Empty\)List of the device network interface cards.
properties.nics\[\{\}\]Object\(Empty\)\(Empty\)Network interface card properties
properties.nics\[\{\}\].ipv4AddressStringcmdb\_ci\_ip\_addressip\_addressIPv4 address
properties.nics\[\{\}\].macAddressStringcmdb\_ci\_network\_adaptername, macMAC Address
properties.slotsArray of Objects\(Empty\)\(Empty\)List of the device slot in the backplane.
properties.slots\[\{\}\]Object\(Empty\)\(Empty\)Slot data in PLC backplane.
properties.slots\[\{\}\].firmwareVersionStringcmdb\_ci\_ot\_control\_modulefirmware\_versionFirmware version of the slot.
properties.slots\[\{\}\].modelStringcmdb\_ci\_ot\_control\_modulemodel\_idModel of the slot.
properties.slots\[\{\}\].rackNumberIntegercmdb\_ci\_ot\_control\_modulerack\_numberRack number in the backplane
properties.slots\[\{\}\].serialNumberStringcmdb\_ci\_ot\_control\_moduleserial\_numberSerial number of the slot.
properties.slots\[\{\}\].slotNumberIntegercmdb\_ci\_ot\_control\_moduleslot\_numberSlot number inside the rack.
properties.slots\[\{\}\].hardwareVendorStringcmdb\_ci\_ot\_control\_modulevendorHardware vendor of the slot.
Microsoft Azure device sub type nameMicrosoft Azure device type nameOperating system/firmwareNOW classNOW tableNOW OT type
Alarm Siren\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Alarm System\(Empty\)\(Empty\)OT Control Systemcmdb\_ci\_ot\_controlOT Control System
ATM\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Backup Server\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
Barcode Scanner\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
DB Server\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
DCS ControllerIndustrial\(Empty\)DCScmdb\_ci\_ot\_dcsNULL
Domain Controller\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
Door Control Panel\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
DVR\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Elevator\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Engineering StationIndustrial\(Empty\)EWScmdb\_ci\_ot\_ewsEWS
Fire Alarm\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Fire Detector\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Firewall\(Empty\)\(Empty\)IP Firewallcmdb\_ci\_ip\_firewallNULL
Game console\(Empty\)\(Empty\)Game Consolecmdb\_ci\_game\_consoleNULL
Historian\(Empty\)\(Empty\)Historiancmdb\_ci\_ot\_historianHistorian
HMIIndustrial\(Empty\)HMIcmdb\_ci\_ot\_hmiHMI
Humidity Sensor\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
HVAC\(Empty\)\(Empty\)HVAC Equipmentcmdb\_ci\_hvacNULL
I/O Adapter\(Empty\)\(Empty\)Network Adapter\(Empty\)NA
IED\(Empty\)\(Empty\)IEDcmdb\_ci\_ot\_iedied
Industrial Packaging System\(Empty\)\(Empty\)OT Field Devicecmdb\_ci\_ot\_field\_deviceOT Field Device
Industrial Robot\(Empty\)\(Empty\)Industrial Robotcmdb\_ci\_ot\_industrial\_robotIndustrial Robot
Industrial Scale\(Empty\)\(Empty\)OT Field Devicecmdb\_ci\_ot\_field\_deviceOT Field Device
Intercom\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
IP Camera\(Empty\)\(Empty\)IP Cameracmdb\_ci\_ip\_cameraNULL
IP Telephone\(Empty\)\(Empty\)IP phonecmdb\_ci\_ip\_phoneNULL
Marquee\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Meter\(Empty\)\(Empty\)Industrial Sensorcmdb\_ci\_ot\_industrial\_sensorIndustrial Sensor
Motion Detector\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Multicast/Broadcast\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
NTP Server\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
People Counter System\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Physical Location\(Empty\)\(Empty\)\(Empty\)\(Empty\)NULL
PLCIndustrial\(Empty\)PLCcmdb\_ci\_ot\_plcPLC
Pneumatic Device\(Empty\)\(Empty\)Industrial Actuatorcmdb\_ci\_ot\_industrial\_actuatorIndustrial Actuator
Printer\(Empty\)\(Empty\)Printercmdb\_ci\_printerNULL
Protocol Converter\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
Punch Clock\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Robot Controller\(Empty\)\(Empty\)OT Control Systemcmdb\_ci\_ot\_controlOT Control System
Router\(Empty\)\(Empty\)IP Routercmdb\_ci\_ip\_routerNULL
RTU\(Empty\)\(Empty\)RTUcmdb\_ci\_ot\_rtuNULL
ServerServer\(Empty\)Servercmdb\_ci\_serverNULL
Servo Drive\(Empty\)\(Empty\)Industrial Actuatorcmdb\_ci\_ot\_industrial\_actuatorIndustrial Actuator
Slot\(Empty\)\(Empty\)OT Control Modulecmdb\_ci\_ot\_control\_moduleOT Control Module
Smart Light\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Smart Phone\(Empty\)\(Empty\)Handheld Computing Devicecmdb\_ci\_handheld\_computingNULL
Smart Switch\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Smart TV\(Empty\)\(Empty\)Smart Televisioncmdb\_ci\_stvNULL
Storage\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
SwitchNetwork Device\(Empty\)IP Switchcmdb\_ci\_ip\_switchNULL
Tablet\(Empty\)\(Empty\)Handheld Computing Devicecmdb\_ci\_handheld\_computingNULL
Terminal Station\(Empty\)\(Empty\)Computercmdb\_ci\_computerNULL
Thermostat\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Turnstile\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iot 
Uninterruptable Power Supply\(Empty\)\(Empty\)UPScmdb\_ci\_upsNULL
Variable Frequency Drive\(Empty\)\(Empty\)Industrial Drivecmdb\_ci\_ot\_industrial\_driveIndustrial Drive
VPN Gateway\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
Wifi Pineapple\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
Wireless Access Point\(Empty\)\(Empty\)Wireless Access Pointcmdb\_ci\_wap\_networkNULL
WLAN access pointNetwork Device\(Empty\)Wireless Access Pointcmdb\_ci\_wap\_networkNULL
WorkstationWorkstation\(Empty\)Computercmdb\_ci\_computerNULL
UnknownAll\(Empty\)Operational Technology \(OT\)cmdb\_ci\_otOperational Technology \(OT\)
UnclassifiedUnclassified or All\(Empty\)Operational Technology \(OT\)cmdb\_ci\_otOperational Technology \(OT\)
Any other type\(Empty\)\(Empty\)Operational Technology \(OT\)cmdb\_ci\_otOperational Technology \(OT\)
Any above type value except with designation Network and IoT\(Empty\)- windows server - windows server, version 2004\[8\] - windows server, version 1909\[9\] - windows server, version 1903\[9\] - windows server 2019 - windows server 2016 - windows server 2012 r2 - windows server 2012 - windows server 2008 r2 - windows server 2008 - windows server 2003 r2 - windows server 2003 - windows 2000 server - windows nt 4.0 server - windows nt 3.51 server - windows nt 3.5 server - windows nt 3.1 serverWindows Servercmdb\_ci\_linux\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- linux - arch - centos - debian - fedora - suse - red hat - rhel - ubuntu - oracleLinux Servercmdb\_ci\_linux\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)aixAIX Servercmdb\_ci\_aix\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)esxESX Servercmdb\_ci\_esx\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- hp/ux - hpuxHP-UX Servercmdb\_ci\_hpux\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- hyper-v - hyperv - hyperHypverV Servercmdb\_ci\_hyper\_v\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- solaris - sunos - sun osSolaris Servercmdb\_ci\_solaris\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- macos x server - macos server - os x - osxOSX Servercmdb\_ci\_osx\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- unix - gnuUnix Servercmdb\_ci\_unix\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- win - windows - Microsoft - windows 1.0, 1.02, 1.03, 1.04, 2.03, 2.10, 2.11, 3.0, 3.1, 3.2, 7, 8, 8.1, 10, 98, 95 - windows 2000 - windows for workgroups 3.11 - windows me - windows nt 3.1, 3.5, 3.51, 4.0 - windows vista - windows xp - windows xp professional x64 editionBase Computer classcmdb\_ci\_computerSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)serverBase Server Classcmdb\_ci\_serverSame as when the operating system isn't present.

Parent Topic:Service Graph Connector for Microsoft Defender for IoT (On-premises Management Console)