Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Attribute mapping and classification for Service Graph Connector for Microsoft Defender for IoT (Azure)

The following tables describe the attribute mapping and classification for sensors and devices.

Payload field nameData typeMapped to tableMapped to fieldDescription
idString format: /subscriptions/<subscription-id>/provider/<provider>/locations/<location>/sites/<site>/sensor/<sensor-name>- sys\_object\_source - cmdb\_ci\_nids- snk in sys\_object\_source - correlation\_idUnique ID for the sensor.
nameStringcmdb\_ci\_nidsnameName of the sensor.
properties.hostnameStringcmdb\_ci\_nidsfqdnHost name of the sensor.
properties.ipStringcmdb\_ci\_ip\_addressip\_addressIP address of the sensor.
properties.learningModeBooleancmdb\_ci\_nidsFalse or unavailable: Life Cycle Stage \(life\_cycle\_stage\) : Operational Life Cycle Stage Status \(life\_cycle\_stage\_status\): In Use True: Life Cycle Stage \(life\_cycle\_stage\) : Operational Life Cycle Stage Status \(life\_cycle\_stage\_status\): LearningLearning mode status of the IoT sensor.
properties.macStringcmdb\_ci\_network\_adaptername, mac\_addressMAC address of the sensor.
properties.sensorStatusStringcmdb\_ci\_nidsconnection\_stateStatus of the IoT sensor.
properties.sensorVersionStringcmdb\_ci\_nidsfirmware\_versionVersion of the IoT sensor.
properties.upSince\_utcDate and time as stringcmdb\_ci\_nidsfirst\_discoveredStartup time.
properties.zoneStringcmdb\_ci\_nidszoneZone of the IoT sensor.
Payload field nameData typeMapped to tableMapped to fieldDescription
idString format: /subscriptions/subscription-id>/providers/<providers-id>/location/<location>/deviceGroups/<device-Group>/devices/<name-field>- sys\_object\_source - cmdb\_ot\_entity - cmdb\_key\_value\_v2- snk in sys\_object\_source - discovery\_source\_id in cmdb\_ot\_entityUnique ID for the device.
resourceGroup\(Empty\)cmdb\_key\_value\_v2\(Empty\)Resource group
tenantId\(Empty\)cmdb\_key\_value\_v2\(Empty\)Tenant ID
properties.authorizedStateStringcmdb\_key\_value\_v2\(Empty\)Authorized state of the device
properties.criticalityStringcmdb\_ot\_entitybusiness\_criticalityCriticality of the device
properties.deviceNameStringcmdb\_cinameName of the device.
properties.deviceSubTypeDisplayNameStringcmdb\_cisys\_class\_nameDevice subtype display name.
properties.firstSeenDate and time as string- cmdb\_ci - cmdb\_ci\_ot\_control\_module \(if control modules are present\)first\_discoveredFirst time the device was seen.
properties.lastSeenDate and time as string- cmdb\_ci - cmdb\_ci\_ot\_control\_module \(if control modules are present\)most\_recent\_discoveryLast time the device was seen.
properties.purdueLevelStringcmdb\_ot\_entitypurdue\_levelPurdue level of the device.
properties.operatingSystem.distributionStringcmdb\_ci\_computerosOS distribution
properties.operatingSystem.versionStringcmdb\_ci\_computeros\_versionOS version
properties.operatingSystem.platformStringcmdb\_ci\_computeros\_domainOS platform
properties.operatingSystem.architectureStringcmdb\_ci\_computeros\_address\_widthOS architecture
properties.additionalFields.plcKeyState\(Empty\)cmdb\_ci\_ot\_plcswitch\_positionPLC key state
properties.additionalFields.plcRunState\(Empty\)cmdb\_ci\_ot\_plcswitch\_remote\_modePLC run state
properties.hardwareObject\(Empty\)\(Empty\)Device hardware data
properties.hardware.modelStringcmdb\_ci\(Empty\)Hardware model
properties.hardware.serialNumberStringcmdb\_serial\_numberserial\_numberHardware serial number
properties.hardware.vendorStringcmdb\_cimanufacturerHardware vendor
properties.nicsArray of Objects\(Empty\)\(Empty\)List of the device network interface cards.
properties.nics\[\{\}\]Object\(Empty\)\(Empty\)Network interface card properties
properties.nics\[\{\}\].ipv4AddressStringcmdb\_ci\_ip\_addressip\_addressIPv4 address
properties.nics\[\{\}\].macAddressStringcmdb\_ci\_network\_adaptername, macMAC Address
properties.slotsArray of Objects\(Empty\)\(Empty\)List of the device slot in the backplane.
properties.slots\[\{\}\]Object\(Empty\)\(Empty\)Slot data in PLC backplane.
properties.slots\[\{\}\].firmwareVersionStringcmdb\_ci\_ot\_control\_modulefirmware\_versionFirmware version of the slot.
properties.slots\[\{\}\].modelStringcmdb\_ci\_ot\_control\_modulemodel\_idModel of the slot.
properties.slots\[\{\}\].rackNumberIntegercmdb\_ci\_ot\_control\_modulerack\_numberRack number in the backplane
properties.slots\[\{\}\].serialNumberStringcmdb\_ci\_ot\_control\_moduleserial\_numberSerial number of the slot.
properties.slots\[\{\}\].slotNumberIntegercmdb\_ci\_ot\_control\_moduleslot\_numberSlot number inside the rack.
properties.slots\[\{\}\].hardwareVendorStringcmdb\_ci\_ot\_control\_modulevendorHardware vendor of the slot.
Microsoft Azure device sub type nameMicrosoft Azure device type nameOperating system/firmwareNOW classNOW tableNOW OT type
Alarm Siren\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Alarm System\(Empty\)\(Empty\)OT Control Systemcmdb\_ci\_ot\_controlOT Control System
ATM\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Backup Server\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
Barcode Scanner\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
DB Server\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
DCS ControllerIndustrial\(Empty\)DCScmdb\_ci\_ot\_dcsNULL
Domain Controller\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
Door Control Panel\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
DVR\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Elevator\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Engineering StationIndustrial\(Empty\)EWScmdb\_ci\_ot\_ewsEWS
Fire Alarm\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Fire Detector\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Firewall\(Empty\)\(Empty\)IP Firewallcmdb\_ci\_ip\_firewallNULL
Game console\(Empty\)\(Empty\)Game Consolecmdb\_ci\_game\_consoleNULL
Historian\(Empty\)\(Empty\)Historiancmdb\_ci\_ot\_historianHistorian
HMIIndustrial\(Empty\)HMIcmdb\_ci\_ot\_hmiHMI
Humidity Sensor\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
HVAC\(Empty\)\(Empty\)HVAC Equipmentcmdb\_ci\_hvacNULL
I/O Adapter\(Empty\)\(Empty\)Network Adapter\(Empty\)NA
IED\(Empty\)\(Empty\)IEDcmdb\_ci\_ot\_iedied
Industrial Packaging System\(Empty\)\(Empty\)OT Field Devicecmdb\_ci\_ot\_field\_deviceOT Field Device
Industrial Robot\(Empty\)\(Empty\)Industrial Robotcmdb\_ci\_ot\_industrial\_robotIndustrial Robot
Industrial Scale\(Empty\)\(Empty\)OT Field Devicecmdb\_ci\_ot\_field\_deviceOT Field Device
Intercom\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
IP Camera\(Empty\)\(Empty\)IP Cameracmdb\_ci\_ip\_cameraNULL
IP Telephone\(Empty\)\(Empty\)IP phonecmdb\_ci\_ip\_phoneNULL
Marquee\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Meter\(Empty\)\(Empty\)Industrial Sensorcmdb\_ci\_ot\_industrial\_sensorIndustrial Sensor
Motion Detector\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Multicast/Broadcast\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
NTP Server\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
People Counter System\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Physical Location\(Empty\)\(Empty\)\(Empty\)\(Empty\)NULL
PLCIndustrial\(Empty\)PLCcmdb\_ci\_ot\_plcPLC
Pneumatic Device\(Empty\)\(Empty\)Industrial Actuatorcmdb\_ci\_ot\_industrial\_actuatorIndustrial Actuator
Printer\(Empty\)\(Empty\)Printercmdb\_ci\_printerNULL
Protocol Converter\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
Punch Clock\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Robot Controller\(Empty\)\(Empty\)OT Control Systemcmdb\_ci\_ot\_controlOT Control System
Router\(Empty\)\(Empty\)IP Routercmdb\_ci\_ip\_routerNULL
RTU\(Empty\)\(Empty\)RTUcmdb\_ci\_ot\_rtuNULL
ServerServer\(Empty\)Servercmdb\_ci\_serverNULL
Servo Drive\(Empty\)\(Empty\)Industrial Actuatorcmdb\_ci\_ot\_industrial\_actuatorIndustrial Actuator
Slot\(Empty\)\(Empty\)OT Control Modulecmdb\_ci\_ot\_control\_moduleOT Control Module
Smart Light\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Smart Phone\(Empty\)\(Empty\)Handheld Computing Devicecmdb\_ci\_handheld\_computingNULL
Smart Switch\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Smart TV\(Empty\)\(Empty\)Smart Televisioncmdb\_ci\_stvNULL
Storage\(Empty\)\(Empty\)Servercmdb\_ci\_serverNULL
SwitchNetwork Device\(Empty\)IP Switchcmdb\_ci\_ip\_switchNULL
Tablet\(Empty\)\(Empty\)Handheld Computing Devicecmdb\_ci\_handheld\_computingNULL
Terminal Station\(Empty\)\(Empty\)Computercmdb\_ci\_computerNULL
Thermostat\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iotNULL
Turnstile\(Empty\)\(Empty\)IoT devicecmdb\_ci\_iot 
Uninterruptable Power Supply\(Empty\)\(Empty\)UPScmdb\_ci\_upsNULL
Variable Frequency Drive\(Empty\)\(Empty\)Industrial Drivecmdb\_ci\_ot\_industrial\_driveIndustrial Drive
VPN Gateway\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
Wifi Pineapple\(Empty\)\(Empty\)Netgearcmdb\_ci\_netgearNULL
Wireless Access Point\(Empty\)\(Empty\)Wireless Access Pointcmdb\_ci\_wap\_networkNULL
WLAN access pointNetwork Device\(Empty\)Wireless Access Pointcmdb\_ci\_wap\_networkNULL
WorkstationWorkstation\(Empty\)Computercmdb\_ci\_computerNULL
UnknownAll\(Empty\)Operational Technology \(OT\)cmdb\_ci\_otOperational Technology \(OT\)
UnclassifiedUnclassified or All\(Empty\)Operational Technology \(OT\)cmdb\_ci\_otOperational Technology \(OT\)
Any other type\(Empty\)\(Empty\)Operational Technology \(OT\)cmdb\_ci\_otOperational Technology \(OT\)
Any above type value except with designation Network and IoT\(Empty\)- windows server - windows server, version 2004\[8\] - windows server, version 1909\[9\] - windows server, version 1903\[9\] - windows server 2019 - windows server 2016 - windows server 2012 r2 - windows server 2012 - windows server 2008 r2 - windows server 2008 - windows server 2003 r2 - windows server 2003 - windows 2000 server - windows nt 4.0 server - windows nt 3.51 server - windows nt 3.5 server - windows nt 3.1 serverWindows Servercmdb\_ci\_linux\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- linux - arch - centos - debian - fedora - suse - red hat - rhel - ubuntu - oracleLinux Servercmdb\_ci\_linux\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)aixAIX Servercmdb\_ci\_aix\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)esxESX Servercmdb\_ci\_esx\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- hp/ux - hpuxHP-UX Servercmdb\_ci\_hpux\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- hyper-v - hyperv - hyperHypverV Servercmdb\_ci\_hyper\_v\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- solaris - sunos - sun osSolaris Servercmdb\_ci\_solaris\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- macos x server - macos server - os x - osxOSX Servercmdb\_ci\_osx\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- unix - gnuUnix Servercmdb\_ci\_unix\_serverSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)- win - windows - Microsoft - windows 1.0, 1.02, 1.03, 1.04, 2.03, 2.10, 2.11, 3.0, 3.1, 3.2, 7, 8, 8.1, 10, 98, 95 - windows 2000 - windows for workgroups 3.11 - windows me - windows nt 3.1, 3.5, 3.51, 4.0 - windows vista - windows xp - windows xp professional x64 editionBase Computer classcmdb\_ci\_computerSame as when the operating system isn't present.
Any above type value except with designation Network and IoT\(Empty\)serverBase Server Classcmdb\_ci\_serverSame as when the operating system isn't present.

Parent Topic:Service Graph Connector for Microsoft Defender for IoT (Azure)