POWERSHELL COMMAND
Connect-XdrByEstsCookie
Establishes an authenticated session to the Microsoft Defender XDR portal.
Connects to security.microsoft.com using an ESTSAUTH cookie value to establish an authenticated web session. This function creates global session and headers variables that can be used by other XDR cmdlets to interact with the portal APIs.
You can provide the cookie value as either a plain string or as a secure string.
Syntax
Connect-XdrByEstsCookie -EstsAuthCookieValue <string> [-TenantId <string>] [-UserAgent <string>] [<CommonParameters>]
Connect-XdrByEstsCookie -SecureEstsAuthCookieValue <securestring> [-TenantId <string>] [-UserAgent <string>] [<CommonParameters>]
Parameters
-EstsAuthCookieValue
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
The ESTSAUTH cookie value from an authenticated browser session as a plain string. Use this parameter set when you have the cookie as a plain text value.
-SecureEstsAuthCookieValue
| Property | Value |
|---|---|
| Type | SecureString |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
The ESTSAUTH cookie value from an authenticated browser session as a secure string. Use this parameter set when you want to pass the cookie value securely (e.g., from credential object).
-TenantId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The Tenant ID to use for the connection. If not provided, the default tenant will be used.
-UserAgent
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | (Get-XdrDefaultUserAgent) |
The User-Agent string to use for the web requests. By default, uses the value returned by Get-XdrDefaultUserAgent.
Examples
Connect-XdrByEstsCookie -EstsAuthCookieValue "your_cookie_value_here"
Connects to the XDR portal using the provided authentication cookie as plain text.
$secureCookie = ConvertTo-SecureString -String "your_cookie_value_here" -AsPlainText -Force
Connect-XdrByEstsCookie -SecureEstsAuthCookieValue $secureCookie
Connects to the XDR portal using the provided authentication cookie as a secure string.
Read-Host -AsSecureString "Enter ESTSAUTH cookie" | Connect-XdrByEstsCookie
Prompts for the cookie value securely via pipeline and connects to the XDR portal.
Output
Type: String
Returns a confirmation message when successfully connected.