← All XDRInternals commands

POWERSHELL COMMAND

Connect-XdrByBrowser

Authenticates to Microsoft Defender XDR using an interactive browser sign-in.

View source ↗

Launches a dedicated Chromium-based browser profile, waits for you to complete the browser sign-in flow, captures the resulting authentication cookies, and establishes the Defender XDR session.

This browser-driven flow is intended for interactive authentication branches such as FIDO2/passkeys and Temporary Access Pass.

By default the cmdlet uses a dedicated secondary Chromium profile named XDRInternals so browser and device state can participate in authentication without reusing the user’s primary profile. That dedicated profile is configured to open cleanly instead of restoring tabs from previous runs.

On macOS and Linux, this cmdlet remains interactive. Complete any browser prompts until Microsoft Defender XDR finishes loading so the cmdlet can capture the final session cookies.

Syntax

Connect-XdrByBrowser [[-Username] <string>] [[-TenantId] <string>] [[-TimeoutSeconds] <int>] [[-BrowserPath] <string>] [[-ProfilePath] <string>] [[-UserAgent] <string>] [-ResetProfile] [-PrivateSession] [<CommonParameters>]

Parameters

-Username

Property Value
Type String
Required No
Position 1
Pipeline input No
Default Not documented

Optional username to display while completing the browser sign-in. If omitted, the browser sign-in flow lets you choose an account interactively.

-TenantId

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Not documented

Optional tenant ID to use when bootstrapping the Defender XDR session.

-TimeoutSeconds

Property Value
Type Int32
Required No
Position 3
Pipeline input No
Default 300

Maximum time to wait for the browser sign-in to complete.

-BrowserPath

Property Value
Type String
Required No
Position 4
Pipeline input No
Default Not documented

Optional browser executable path or command name. When omitted, a supported Chromium-based browser is auto-discovered.

-ProfilePath

Property Value
Type String
Required No
Position 5
Pipeline input No
Default Not documented

Optional dedicated browser user data directory. When omitted, a default secondary profile location is used for the XDRInternals profile.

-ResetProfile

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Clears the dedicated browser profile before launching the sign-in flow.

-PrivateSession

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Uses a temporary private/incognito browser session instead of the default dedicated profile.

-UserAgent

Property Value
Type String
Required No
Position 6
Pipeline input No
Default Not documented

Optional User-Agent override for the launched browser.

Examples

Connect-XdrByBrowser -Username 'admin@contoso.com'

Launches the browser sign-in flow and connects to Defender XDR.

View source