POWERSHELL COMMAND
Connect-XdrByPhoneSignIn
Authenticates to Microsoft Defender XDR using Microsoft Authenticator phone sign-in.
Starts the Defender portal phone sign-in flow without launching a browser, shows the number returned by Entra ID when available, waits for Microsoft Authenticator approval, captures the resulting ESTSAUTH cookie, and then passes it to Connect-XdrByEstsCookie to establish the Defender XDR session.
Syntax
Connect-XdrByPhoneSignIn [[-Username] <string>] [[-TenantId] <string>] [[-TimeoutSeconds] <int>] [[-UserAgent] <string>] [<CommonParameters>]
Parameters
-Username
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
Optional username to use for phone sign-in. If omitted, you are prompted interactively.
-TenantId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
Optional tenant ID to use when bootstrapping the Defender XDR session.
-TimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | 300 |
Maximum time to wait for the phone sign-in approval to complete.
-UserAgent
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | (Get-XdrDefaultUserAgent) |
User-Agent string for HTTP requests. Defaults to a browser-compatible Edge user agent.
Examples
Connect-XdrByPhoneSignIn -Username 'admin@contoso.com'
Starts the headless phone sign-in flow and connects to Defender XDR.
Connect-XdrByPhoneSignIn -Username 'admin@contoso.com' -TenantId '8612f621-73ca-4c12-973c-0da732bc44c2'
Starts the headless phone sign-in flow and connects to the specified tenant.