← All XDRInternals commands

POWERSHELL COMMAND

Connect-XdrByEstsCookie

Establishes an authenticated session to the Microsoft Defender XDR portal.

View source ↗

Connects to security.microsoft.com using an ESTSAUTH cookie value to establish an authenticated web session. This function creates global session and headers variables that can be used by other XDR cmdlets to interact with the portal APIs.

You can provide the cookie value as either a plain string or as a secure string.

Syntax

Connect-XdrByEstsCookie -EstsAuthCookieValue <string> [-TenantId <string>] [-UserAgent <string>] [<CommonParameters>]

Connect-XdrByEstsCookie -SecureEstsAuthCookieValue <securestring> [-TenantId <string>] [-UserAgent <string>] [<CommonParameters>]

Parameters

-EstsAuthCookieValue

Property Value
Type String
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

The ESTSAUTH cookie value from an authenticated browser session as a plain string. Use this parameter set when you have the cookie as a plain text value.

-SecureEstsAuthCookieValue

Property Value
Type SecureString
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

The ESTSAUTH cookie value from an authenticated browser session as a secure string. Use this parameter set when you want to pass the cookie value securely (e.g., from credential object).

-TenantId

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

The Tenant ID to use for the connection. If not provided, the default tenant will be used.

-UserAgent

Property Value
Type String
Required No
Position named
Pipeline input No
Default (Get-XdrDefaultUserAgent)

The User-Agent string to use for the web requests. By default, uses the value returned by Get-XdrDefaultUserAgent.

Examples

Connect-XdrByEstsCookie -EstsAuthCookieValue "your_cookie_value_here"
Connects to the XDR portal using the provided authentication cookie as plain text.
$secureCookie = ConvertTo-SecureString -String "your_cookie_value_here" -AsPlainText -Force
Connect-XdrByEstsCookie -SecureEstsAuthCookieValue $secureCookie
Connects to the XDR portal using the provided authentication cookie as a secure string.
Read-Host -AsSecureString "Enter ESTSAUTH cookie" | Connect-XdrByEstsCookie
Prompts for the cookie value securely via pipeline and connects to the XDR portal.

Output

Type: String

Returns a confirmation message when successfully connected.

View source