Microsoft Windows Server Attribute Reference
Focus
Focus
Device Security

Microsoft Windows Server Attribute Reference

Table of Contents

Microsoft Windows Server Attribute Reference

This reference lists the attributes that Device Security collects from Microsoft Windows Server, their names as stored in Device Security, and the Device Security fields they map to.
Device Security integrates with Microsoft Windows Server to collect network data that enriches the device inventory. The attributes in this reference cover DHCP lease records and detailed device information gathered from the Windows Server DHCP service.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Dhcp Leases Attributes

Device Security collects dhcp leases attributes from Microsoft Windows Server. The following table lists each Microsoft Windows Server attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Windows Server Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
LeaseExpiryTime
microsoft_windows_server.LeaseExpiryTime
dhcp_lease_expiry_time
Lease expiry time
HostName
microsoft_windows_server.HostName
hostname
Host name
IPAddress.IPAddressToString
microsoft_windows_server.IPAddress.IPAddressToString
IP Address
IP address to string
Type
microsoft_windows_server.is_ip_address_static
is_ip_address_static
Type
ClientId
microsoft_windows_server.ClientId
MAC; id
Client ID
AddressState
microsoft_windows_server.AddressState
—
Address state
ClientType
microsoft_windows_server.ClientType
—
Client type
Description
microsoft_windows_server.Description
—
Description
DnsRegistration
microsoft_windows_server.DnsRegistration
—
DNS registration
DnsRR
microsoft_windows_server.DnsRR
—
DNS rr
IPAddress.Address
microsoft_windows_server.IPAddress.Address
—
Address
IPAddress.AddressFamily
microsoft_windows_server.IPAddress.AddressFamily
—
Address family
IPAddress.IsIPv4MappedToIPv6
microsoft_windows_server.IPAddress.IsIPv4MappedToIPv6
—
Is i pv4 mapped to i pv6
IPAddress.IsIPv6LinkLocal
microsoft_windows_server.IPAddress.IsIPv6LinkLocal
—
Is i pv6 link local
IPAddress.IsIPv6Multicast
microsoft_windows_server.IPAddress.IsIPv6Multicast
—
Is i pv6 multicast
IPAddress.IsIPv6SiteLocal
microsoft_windows_server.IPAddress.IsIPv6SiteLocal
—
Is i pv6 site local
IPAddress.IsIPv6Teredo
microsoft_windows_server.IPAddress.IsIPv6Teredo
—
Is i pv6 teredo
IPAddress.ScopeId
microsoft_windows_server.IPAddress.ScopeId
—
Scope ID
NapCapable
microsoft_windows_server.NapCapable
—
Nap capable
NapStatus
microsoft_windows_server.NapStatus
—
Nap status
PolicyName
microsoft_windows_server.PolicyName
—
Policy name
ProbationEnds
microsoft_windows_server.ProbationEnds
—
Probation ends
PSComputerName
microsoft_windows_server.PSComputerName
—
Ps computer name
ScopeId.Address
microsoft_windows_server.ScopeId.Address
—
Address
ScopeId.AddressFamily
microsoft_windows_server.ScopeId.AddressFamily
—
Address family
ScopeId.IPAddressToString
microsoft_windows_server.ScopeId.IPAddressToString
—
IP address to string
ScopeId.IsIPv4MappedToIPv6
microsoft_windows_server.ScopeId.IsIPv4MappedToIPv6
—
Is i pv4 mapped to i pv6
ScopeId.IsIPv6LinkLocal
microsoft_windows_server.ScopeId.IsIPv6LinkLocal
—
Is i pv6 link local
ScopeId.IsIPv6Multicast
microsoft_windows_server.ScopeId.IsIPv6Multicast
—
Is i pv6 multicast
ScopeId.IsIPv6SiteLocal
microsoft_windows_server.ScopeId.IsIPv6SiteLocal
—
Is i pv6 site local
ScopeId.IsIPv6Teredo
microsoft_windows_server.ScopeId.IsIPv6Teredo
—
Is i pv6 teredo
ScopeId.ScopeId
microsoft_windows_server.ScopeId.ScopeId
—
Scope ID
ServerIP
microsoft_windows_server.ServerIP
—
Server IP

Attributes

Device Security collects attributes from Microsoft Windows Server. The following table lists each Microsoft Windows Server attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Windows Server Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
Name
microsoft_windows_server.Name
hostname
Name
IPAddress
microsoft_windows_server.IPAddress
IP Address
IP address
MacAddress
microsoft_windows_server.MacAddress
MAC Address; id
MAC address
OSName
microsoft_windows_server.OSName
OS Name
Os name
OSVersion
microsoft_windows_server.OSVersion
OS Version
OS version
ChassisSerialNumber
microsoft_windows_server.ChassisSerialNumber
Serial Number
Chassis serial number
InstalledSoftware
—
third_party_learned_installed_software
Installed software
NetworkAdapters
—
third_party_learned_network_interfaces
Network adapters
SystemManufacturer
microsoft_windows_server.SystemManufacturer
Vendor
System manufacturer
BitlockerStatus.AutoUnlockEnabled
microsoft_windows_server.BitlockerStatus.AutoUnlockEnabled
—
Auto unlock enabled
BitlockerStatus.AutoUnlockKeyStored
microsoft_windows_server.BitlockerStatus.AutoUnlockKeyStored
—
Auto unlock key stored
BitlockerStatus.CapacityGB
microsoft_windows_server.BitlockerStatus.CapacityGB
—
Capacity gb
BitlockerStatus.ComputerName
microsoft_windows_server.BitlockerStatus.ComputerName
—
Computer name
BitlockerStatus.EncryptionMethod
microsoft_windows_server.BitlockerStatus.EncryptionMethod
—
Encryption method
BitlockerStatus.EncryptionMethodFlags
microsoft_windows_server.BitlockerStatus.EncryptionMethodFlags
—
Encryption method flags
BitlockerStatus.EncryptionPercentage
microsoft_windows_server.BitlockerStatus.EncryptionPercentage
—
Encryption percentage
BitlockerStatus.KeyProtector
microsoft_windows_server.BitlockerStatus.KeyProtector
—
Key protector
BitlockerStatus.LockStatus
microsoft_windows_server.BitlockerStatus.LockStatus
—
Lock status
BitlockerStatus.MetadataVersion
microsoft_windows_server.BitlockerStatus.MetadataVersion
—
Metadata version
BitlockerStatus.MountPoint
microsoft_windows_server.BitlockerStatus.MountPoint
—
Mount point
BitlockerStatus.ProtectionStatus
microsoft_windows_server.BitlockerStatus.ProtectionStatus
—
Protection status
BitlockerStatus.VolumeStatus
microsoft_windows_server.BitlockerStatus.VolumeStatus
—
Volume status
BitlockerStatus.VolumeType
microsoft_windows_server.BitlockerStatus.VolumeType
—
Volume type
BitlockerStatus.WipePercentage
microsoft_windows_server.BitlockerStatus.WipePercentage
—
Wipe percentage
CollectedDateTime
microsoft_windows_server.CollectedDateTime
—
Collected date time
Model
microsoft_windows_server.Model
—
Model
NumberOfCores
microsoft_windows_server.NumberOfCores
—
Number of cores
NumberOfLogicalProcessors
microsoft_windows_server.NumberOfLogicalProcessors
—
Number of logical processors
NumberOfProcessors
microsoft_windows_server.NumberOfProcessors
—
Number of processors
OSSku
microsoft_windows_server.OSSku
—
OS sku
OSSuite
microsoft_windows_server.OSSuite
—
OS suite
OSSuiteMask
microsoft_windows_server.OSSuiteMask
—
OS suite mask
ProcessorFamily
microsoft_windows_server.ProcessorFamily
—
Processor family
ProcessorManufacturer
microsoft_windows_server.ProcessorManufacturer
—
Processor manufacturer
ProcessorName
microsoft_windows_server.ProcessorName
—
Processor name
PSComputerName
microsoft_windows_server.PSComputerName
—
Ps computer name
* Only some attributes map to a Device Security Common Attribute.