Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

CMDB classes targeted in the Service Graph Connector for Microsoft Defender for IoT (Azure)

When you complete the guided setup, you can configure the integration to periodically pull data from a Service Graph Connector for Microsoft Defender for IoT (Azure) (Azure) project. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.

Viewing class mappings

You can view the available class mappings for the Service Graph Connector for Microsoft Defender for IoT (Azure) by navigating to All > Service Graph for MSFT D4IoT (Azure) > Class Mappings. In the class mappings table, you can view the following attributes.

FieldDescription
Source ClassThe device type from the source system \(Azure\).
Target CMDB classThe expected ServiceNow class for the CI.
OT Device type

The category type that the OT device is classified as. The device type is also the function that the device plays on the OT network. For example:An IT device, such as a server, can be converted to an OT device, and the function it plays on the network is an HMI. Therefore, its class is server and its device type is HMI.

Note: In some cases, there are OT devices with no OT function or OT devices where the device type is unknown. For OT devices with no OT function, select No OT Function. For OT devices where the device type is unknown, select Unknown.

Allow OS classificationWhen set to True, if an operating system is found on the CI, the target is switched away from the target CMDB class to a ServiceNow class that matches its OS.
ActiveWhen checked, the class mapping is set to Active.

Computer [cmdb_ci_computer]

The following attributes in the Computer [cmdb_ci_computer] table are populated by collected data:

Attribute labelAttribute name
Most recent discoverylast_discovered
Operating Systemos
OS Address Width (bits)os_address_width
OS Domainos_domain
OS Versionos_version

External system metadata [cmdb_key_value_v2]

The following attributes in the External system metadata [cmdb_key_value_v2] table are populated by collected data:

Attribute labelAttribute name
Discovery sourcediscovery_source
Keykey
Source keysource_key
String valuestring_value
URL valueurl_value
Value typevalue_type

Hardware [cmdb_ci_hardware]

The following attributes in the Hardware [cmdb_ci_hardware] table are populated by collected data:

Attribute labelAttribute name
Classsys_class_name
Model numbermodel_number
Most recent discoverylast_discovered
Locationlocation
Model IDmodel_id
Manufacturermanufacturer
First discoveredfirst_discovered
Owned byowned_by
Approval groupchange_control
Managed By Groupmanaged_by_group
Managed bymanaged_by
Namename
Companycompany
Support groupsupport_group
Change Groupassignment_group
Assigned toassigned_to
Supported bysupported_by
Parent classRelationship typeChild class
Hardware [cmdb_ci_hardware]Owns::Owned byIP Address [cmdb_ci_ip_address]
Hardware [cmdb_ci_hardware]Owns::Owned byNetwork Adapter [cmdb_ci_network_adapter]
Hardware [cmdb_ci_hardware]ReferenceExternal system metadata [cmdb_key_value_v2]
Hardware [cmdb_ci_hardware]ReferenceOT Device [cmdb_ot_entity]

IP Address [cmdb_ci_ip_address]

The following attributes in the IP Address [cmdb_ci_ip_address] table are populated by collected data:

Attribute labelAttribute name
IP Addressip_address
IP versionip_version
Owned By Configuration Itemowned_by_cmdb_ci
Parent classRelationship typeChild class
IP Address [cmdb_ci_ip_address]ReferenceNetwork Intrusion Detection System [cmdb_ci_nids]
IP Address [cmdb_ci_ip_address]ReferenceHardware [cmdb_ci_hardware]

Network Adapter [cmdb_ci_network_adapter]

The following attributes in the Network Adapter [cmdb_ci_network_adapter] table are populated by collected data:

Attribute labelAttribute name
MAC Addressmac_address
Namename
Discovery sourcediscovery_source
Parent classRelationship typeChild class
Network Adapter [cmdb_ci_network_adapter]ReferenceNetwork Intrusion Detection System [cmdb_ci_nids]
Network Adapter [cmdb_ci_network_adapter]ReferenceHardware [cmdb_ci_hardware]

Network Intrusion Detection System [cmdb_ci_nids]

The following attributes in the Network Intrusion Detection System [cmdb_ci_nids] table are populated by collected data:

Attribute labelAttribute name
First discoveredfirst_discovered
NIDS source namesource_name
Life Cycle Stagelife_cycle_stage
Life Cycle Stage Statuslife_cycle_stage_status
Namename
Correlation IDcorrelation_id
Firmware versionfirmware_version
Fully qualified domain namefqdn
NIDS assignment zonezone
NIDS manager connection stateconnection_state
Validatedvalidated
Manufacturermanufacturer
Parent classRelationship typeChild class
Network Intrusion Detection System [cmdb_ci_nids]Detects::Detected byHardware [cmdb_ci_hardware]
Network Intrusion Detection System [cmdb_ci_nids]Owns::Owned byIP Address [cmdb_ci_ip_address]
Network Intrusion Detection System [cmdb_ci_nids]Owns::Owned byNetwork Adapter [cmdb_ci_network_adapter]

Operational Technology (OT) [cmdb_ci_ot]

The following attributes in the Operational Technology (OT) [cmdb_ci_ot] table are populated by collected data:

Attribute labelAttribute name
Most recent discoverylast_discovered

OT Control Module [cmdb_ci_ot_control_module]

The following attributes in the OT Control Module [cmdb_ci_ot_control_module] table are populated by collected data:

Attribute labelAttribute name
Vendorvendor
Support groupsupport_group
Serial numberserial_number
Classsys_class_name
First discoveredfirst_discovered
Approval groupchange_control
Managed bymanaged_by
Managed By Groupmanaged_by_group
Change Groupassignment_group
Companycompany
Rack numberrack_number
Slot numberslot_number
Locationlocation
Namename
Firmware versionfirmware_version
Most recent discoverylast_discovered
Assigned toassigned_to
Owned byowned_by
Supported bysupported_by
Model IDmodel_id
Parent classRelationship typeChild class
OT Control Module [cmdb_ci_ot_control_module]ReferenceOT Device [cmdb_ot_entity]

OT Control System [cmdb_ci_ot_control]

The following attributes in the OT Control System [cmdb_ci_ot_control] table are populated by collected data:

Attribute labelAttribute name
Has modulehas_module
Most recent discoverylast_discovered
Parent classRelationship typeChild class
OT Control System [cmdb_ci_ot_control]Owns::Owned byOT Control Module [cmdb_ci_ot_control_module]

OT Device [cmdb_ot_entity]

The following attributes in the OT Device [cmdb_ot_entity] table are populated by collected data:

Attribute labelAttribute name
ISA entity siteisa_entity_site
OT discovery source IDot_correlation_id
Device criticalitybusiness_criticality
Purdue levelpurdue_level
Zonezone
OT device typeot_asset_type
IRE criterion attributeire_criterion_attribute

PLC [cmdb_ci_ot_plc]

The following attributes in the PLC [cmdb_ci_ot_plc] table are populated by collected data:

Attribute labelAttribute name
Most recent discoverylast_discovered
Switch positionswitch_position
Switch remoteswitch_remote_mode

Serial Number [cmdb_serial_number]

The following attributes in the Serial Number [cmdb_serial_number] table are populated by collected data:

Attribute labelAttribute name
Serial Numberserial_number
Serial Number Typeserial_number_type
Validvalid
Parent classRelationship typeChild class
Serial Number [cmdb_serial_number]ReferenceHardware [cmdb_ci_hardware]
Network Adapter [cmdb_ci_network_adapter]ReferenceHardware [cmdb_ci_hardware]

Parent Topic:Service Graph Connector for Microsoft Defender for IoT (Azure)