---
sourceDocument: Yokohama Operational Technology Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/operational-technology

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Operational Technology Management

ft:clusterId :

    - optm

bundleId :

    - optm

workflow :

    - Technology


---

# CMDB classes targeted

# CMDB classes targeted in the Service Graph Connector for Microsoft Defender for IoT (Azure) {#ariaid-title1}

Release version: Yokohama  
Updated January 30, 2025  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read  
When you complete the guided setup, you can configure the integration to periodically pull data from a Service Graph Connector for Microsoft Defender for IoT (Azure) (Azure) project. The data is saved in tables that extend from the Configuration item \[cmdb_ci\] table.

## Viewing class mappings {#sgc-microsoft-d4iot-azure-classes__section_s45_bv1_x2c}

You can view the available class mappings for the Service Graph Connector for Microsoft Defender for IoT (Azure) by navigating to AllService Graph for MSFT D4IoT (Azure)Class Mappings. In the class mappings table, you can view the following attributes.{#sgc-microsoft-d4iot-azure-classes__table_b2z_zgx_cdc__entry__2}

| Field | Description |
|-|-|
| Source Class | The device type from the source system (Azure). |
| Target CMDB class | The expected ServiceNow class for the CI. |
| OT Device type | The category type that the OT device is classified as. The device type is also the function that the device plays on the OT network. For example: An IT device, such as a server, can be converted to an OT device, and the function it plays on the network is an HMI. Therefore, its class is server and its device type is HMI. Note: In some cases, there are OT devices with no OT function or OT devices where the device type is unknown. For OT devices with no OT function, select No OT Function. For OT devices where the device type is unknown, select Unknown. |
| Allow OS classification | When set to True, if an operating system is found on the CI, the target is switched away from the target CMDB class to a ServiceNow class that matches its OS. |
| Active | When checked, the class mapping is set to Active. |
[Table 1. Class mapping attributes]

{#sgc-microsoft-d4iot-azure-classes__table_b2z_zgx_cdc}

## Computer \[cmdb_ci_computer\] {#sgc-microsoft-d4iot-azure-classes__section_rkb_dwz_dbc}

The following attributes in the Computer \[cmdb_ci_computer\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_skb_dwz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Most recent discovery | last_discovered |
| Operating System | os |
| OS Address Width (bits) | os_address_width |
| OS Domain | os_domain |
| OS Version | os_version |
[Table 2. Computer \[cmdb_ci_computer\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_skb_dwz_dbc}

## External system metadata \[cmdb_key_value_v2\] {#sgc-microsoft-d4iot-azure-classes__section_xsp_kwz_dbc}

The following attributes in the External system metadata \[cmdb_key_value_v2\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_ysp_kwz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Discovery source | discovery_source |
| Key | key |
| Source key | source_key |
| String value | string_value |
| URL value | url_value |
| Value type | value_type |
[Table 3. External system metadata \[cmdb_key_value_v2\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_ysp_kwz_dbc}

## Hardware \[cmdb_ci_hardware\] {#sgc-microsoft-d4iot-azure-classes__section_zwn_s5z_dbc}

The following attributes in the Hardware \[cmdb_ci_hardware\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_g32_t5z_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Class | sys_class_name |
| Model number | model_number |
| Most recent discovery | last_discovered |
| Location | location |
| Model ID | model_id |
| Manufacturer | manufacturer |
| First discovered | first_discovered |
| Owned by | owned_by |
| Approval group | change_control |
| Managed By Group | managed_by_group |
| Managed by | managed_by |
| Name | name |
| Company | company |
| Support group | support_group |
| Change Group | assignment_group |
| Assigned to | assigned_to |
| Supported by | supported_by |
[Table 4. Hardware \[cmdb_ci_hardware\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_g32_t5z_dbc}{#sgc-microsoft-d4iot-azure-classes__table_gvn_v5z_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| Hardware \[cmdb_ci_hardware\] | Owns::Owned by | IP Address \[cmdb_ci_ip_address\] |
| Hardware \[cmdb_ci_hardware\] | Owns::Owned by | Network Adapter \[cmdb_ci_network_adapter\] |
| Hardware \[cmdb_ci_hardware\] | Reference | External system metadata \[cmdb_key_value_v2\] |
| Hardware \[cmdb_ci_hardware\] | Reference | OT Device \[cmdb_ot_entity\] |
[Table 5. Relationships created for Hardware]

{#sgc-microsoft-d4iot-azure-classes__table_gvn_v5z_dbc}

## IP Address \[cmdb_ci_ip_address\] {#sgc-microsoft-d4iot-azure-classes__section_htc_ywz_dbc}

The following attributes in the IP Address \[cmdb_ci_ip_address\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_itc_ywz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| IP Address | ip_address |
| IP version | ip_version |
| Owned By Configuration Item | owned_by_cmdb_ci |
[Table 6. IP Address \[cmdb_ci_ip_address\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_itc_ywz_dbc}{#sgc-microsoft-d4iot-azure-classes__table_jtc_ywz_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| IP Address \[cmdb_ci_ip_address\] | Reference | Network Intrusion Detection System \[cmdb_ci_nids\] |
| IP Address \[cmdb_ci_ip_address\] | Reference | Hardware \[cmdb_ci_hardware\] |
[Table 7. Relationships created for IP Address]

{#sgc-microsoft-d4iot-azure-classes__table_jtc_ywz_dbc}

## Network Adapter \[cmdb_ci_network_adapter\] {#sgc-microsoft-d4iot-azure-classes__section_tsm_hvz_dbc}

The following attributes in the Network Adapter \[cmdb_ci_network_adapter\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_usm_hvz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| MAC Address | mac_address |
| Name | name |
| Discovery source | discovery_source |
[Table 8. Network Adapter \[cmdb_ci_network_adapter\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_usm_hvz_dbc}{#sgc-microsoft-d4iot-azure-classes__table_vsm_hvz_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| Network Adapter \[cmdb_ci_network_adapter\] | Reference | Network Intrusion Detection System \[cmdb_ci_nids\] |
| Network Adapter \[cmdb_ci_network_adapter\] | Reference | Hardware \[cmdb_ci_hardware\] |
[Table 9. Relationships created for Network Adapter]

{#sgc-microsoft-d4iot-azure-classes__table_vsm_hvz_dbc}

## Network Intrusion Detection System \[cmdb_ci_nids\] {#sgc-microsoft-d4iot-azure-classes__section_acw_y5z_dbc}

The following attributes in the Network Intrusion Detection System \[cmdb_ci_nids\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_msh_1vz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| First discovered | first_discovered |
| NIDS source name | source_name |
| Life Cycle Stage | life_cycle_stage |
| Life Cycle Stage Status | life_cycle_stage_status |
| Name | name |
| Correlation ID | correlation_id |
| Firmware version | firmware_version |
| Fully qualified domain name | fqdn |
| NIDS assignment zone | zone |
| NIDS manager connection state | connection_state |
| Validated | validated |
| Manufacturer | manufacturer |
[Table 10. Network Intrusion Detection System \[cmdb_ci_nids\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_msh_1vz_dbc}{#sgc-microsoft-d4iot-azure-classes__table_nsh_1vz_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| Network Intrusion Detection System \[cmdb_ci_nids\] | Detects::Detected by | Hardware \[cmdb_ci_hardware\] |
| Network Intrusion Detection System \[cmdb_ci_nids\] | Owns::Owned by | IP Address \[cmdb_ci_ip_address\] |
| Network Intrusion Detection System \[cmdb_ci_nids\] | Owns::Owned by | Network Adapter \[cmdb_ci_network_adapter\] |
[Table 11. Relationships created for NIDS]

{#sgc-microsoft-d4iot-azure-classes__table_nsh_1vz_dbc}

## Operational Technology (OT) \[cmdb_ci_ot\] {#sgc-microsoft-d4iot-azure-classes__section_tp5_swz_dbc}

The following attributes in the Operational Technology (OT) \[cmdb_ci_ot\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_up5_swz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Most recent discovery | last_discovered |
[Table 12. Operational Technology (OT) \[cmdb_ci_ot\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_up5_swz_dbc}

## OT Control Module \[cmdb_ci_ot_control_module\] {#sgc-microsoft-d4iot-azure-classes__section_ddz_gwz_dbc}

The following attributes in the OT Control Module \[cmdb_ci_ot_control_module\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_edz_gwz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Vendor | vendor |
| Support group | support_group |
| Serial number | serial_number |
| Class | sys_class_name |
| First discovered | first_discovered |
| Approval group | change_control |
| Managed by | managed_by |
| Managed By Group | managed_by_group |
| Change Group | assignment_group |
| Company | company |
| Rack number | rack_number |
| Slot number | slot_number |
| Location | location |
| Name | name |
| Firmware version | firmware_version |
| Most recent discovery | last_discovered |
| Assigned to | assigned_to |
| Owned by | owned_by |
| Supported by | supported_by |
| Model ID | model_id |
[Table 13. OT Control Module \[cmdb_ci_ot_control_module\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_edz_gwz_dbc}{#sgc-microsoft-d4iot-azure-classes__table_fdz_gwz_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| OT Control Module \[cmdb_ci_ot_control_module\] | Reference | OT Device \[cmdb_ot_entity\] |
[Table 14. Relationships created for OT Control Module]

{#sgc-microsoft-d4iot-azure-classes__table_fdz_gwz_dbc}

## OT Control System \[cmdb_ci_ot_control\] {#sgc-microsoft-d4iot-azure-classes__section_p3l_xvz_dbc}

The following attributes in the OT Control System \[cmdb_ci_ot_control\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_q3l_xvz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Has module | has_module |
| Most recent discovery | last_discovered |
[Table 15. OT Control System \[cmdb_ci_ot_control\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_q3l_xvz_dbc}{#sgc-microsoft-d4iot-azure-classes__table_r3l_xvz_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| OT Control System \[cmdb_ci_ot_control\] | Owns::Owned by | OT Control Module \[cmdb_ci_ot_control_module\] |
[Table 16. Relationships created for OT Control System]

{#sgc-microsoft-d4iot-azure-classes__table_r3l_xvz_dbc}

## OT Device \[cmdb_ot_entity\] {#sgc-microsoft-d4iot-azure-classes__section_mg1_qvz_dbc}

The following attributes in the OT Device \[cmdb_ot_entity\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_ng1_qvz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| ISA entity site | isa_entity_site |
| OT discovery source ID | ot_correlation_id |
| Device criticality | business_criticality |
| Purdue level | purdue_level |
| Zone | zone |
| OT device type | ot_asset_type |
| IRE criterion attribute | ire_criterion_attribute |
[Table 17. OT Device \[cmdb_ot_entity\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_ng1_qvz_dbc}

## PLC \[cmdb_ci_ot_plc\] {#sgc-microsoft-d4iot-azure-classes__section_zb3_15z_dbc}

The following attributes in the PLC \[cmdb_ci_ot_plc\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_zt4_l5z_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Most recent discovery | last_discovered |
| Switch position | switch_position |
| Switch remote | switch_remote_mode |
[Table 18. PLC \[cmdb_ci_ot_plc\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_zt4_l5z_dbc}

## Serial Number \[cmdb_serial_number\] {#sgc-microsoft-d4iot-azure-classes__section_xkv_vtz_dbc}

The following attributes in the Serial Number \[cmdb_serial_number\] table are populated by collected data:{#sgc-microsoft-d4iot-azure-classes__table_zbs_xtz_dbc__entry__2}

| Attribute label | Attribute name |
|-|-|
| Serial Number | serial_number |
| Serial Number Type | serial_number_type |
| Valid | valid |
[Table 19. Serial Number \[cmdb_serial_number\] attributes]

{#sgc-microsoft-d4iot-azure-classes__table_zbs_xtz_dbc}{#sgc-microsoft-d4iot-azure-classes__table_pms_25z_dbc__entry__3}

| Parent class | Relationship type | Child class |
|-|-|-|
| Serial Number \[cmdb_serial_number\] | Reference | Hardware \[cmdb_ci_hardware\] |
| Network Adapter \[cmdb_ci_network_adapter\] | Reference | Hardware \[cmdb_ci_hardware\] |
[Table 20. Relationships created for Serial Number]

{#sgc-microsoft-d4iot-azure-classes__table_pms_25z_dbc}

*[\>]: and then


