← All XDRInternals commands

POWERSHELL COMMAND

Connect-XdrByPhoneSignIn

Authenticates to Microsoft Defender XDR using Microsoft Authenticator phone sign-in.

View source ↗

Starts the Defender portal phone sign-in flow without launching a browser, shows the number returned by Entra ID when available, waits for Microsoft Authenticator approval, captures the resulting ESTSAUTH cookie, and then passes it to Connect-XdrByEstsCookie to establish the Defender XDR session.

Syntax

Connect-XdrByPhoneSignIn [[-Username] <string>] [[-TenantId] <string>] [[-TimeoutSeconds] <int>] [[-UserAgent] <string>] [<CommonParameters>]

Parameters

-Username

Property Value
Type String
Required No
Position 1
Pipeline input No
Default Not documented

Optional username to use for phone sign-in. If omitted, you are prompted interactively.

-TenantId

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Not documented

Optional tenant ID to use when bootstrapping the Defender XDR session.

-TimeoutSeconds

Property Value
Type Int32
Required No
Position 3
Pipeline input No
Default 300

Maximum time to wait for the phone sign-in approval to complete.

-UserAgent

Property Value
Type String
Required No
Position 4
Pipeline input No
Default (Get-XdrDefaultUserAgent)

User-Agent string for HTTP requests. Defaults to a browser-compatible Edge user agent.

Examples

Connect-XdrByPhoneSignIn -Username 'admin@contoso.com'

Starts the headless phone sign-in flow and connects to Defender XDR.

Connect-XdrByPhoneSignIn -Username 'admin@contoso.com' -TenantId '8612f621-73ca-4c12-973c-0da732bc44c2'

Starts the headless phone sign-in flow and connects to the specified tenant.

View source