POWERSHELL COMMAND
Connect-XdrBySSO
Authenticates to Microsoft Defender XDR using browser-based single sign-on.
Starts a dedicated browser profile, attempts silent sign-in using the local browser and operating-system account state, captures Defender portal cookies, and configures the XDR session. This cmdlet is intended for Windows-first SSO scenarios, but it can also reuse existing Chromium browser session state on macOS and Linux when that browser state is already available.
Use -Visible when validating or troubleshooting the flow so you can confirm the browser reaches the Defender portal before the cmdlet captures the resulting session cookies.
Syntax
Connect-XdrBySSO [[-TenantId] <string>] [[-TimeoutSeconds] <int>] [[-BrowserPath] <string>] [[-ProfilePath] <string>] [[-UserAgent] <string>] [-Visible] [-SkipTenantSelection] [<CommonParameters>]
Parameters
-TenantId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
Optional tenant ID (GUID) to select from the authenticated SSO session. If only an ESTS cookie is captured, the requested tenant ID is passed to the ESTS bootstrap step.
-Visible
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Shows the browser window instead of using the default headless launch.
-SkipTenantSelection
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Automatically uses the selected tenant or the first available tenant when multiple tenants are available.
-TimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | 180 |
Maximum time to wait for SSO authentication to complete.
-BrowserPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Not documented |
Optional browser executable path or command name.
-ProfilePath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | Not documented |
Optional persistent browser profile path used for SSO.
-UserAgent
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 5 |
| Pipeline input | No |
| Default | Not documented |
Optional User-Agent override for the launched browser.
Examples
Connect-XdrBySSO
Attempts browser-based SSO using the default dedicated profile.
Connect-XdrBySSO -Visible
Shows the browser window while the SSO flow completes.