POWERSHELL COMMAND
Connect-XdrByTemporaryAccessPass
Authenticates to Microsoft Defender XDR using a Temporary Access Pass (TAP).
Performs the Entra ID TAP web sign-in flow programmatically (no browser required), extracts the ESTSAUTH cookie, and then passes it to Connect-XdrByEstsCookie to establish an authenticated Defender XDR session.
TAP sign-in is tenant-scoped. If TenantId is omitted, the cmdlet attempts to resolve the tenant automatically from the supplied username before starting the Entra authorize flow.
Syntax
Connect-XdrByTemporaryAccessPass [[-Username] <string>] [[-TemporaryAccessPass] <securestring>] [[-TenantId] <string>] [[-UserAgent] <string>] [<CommonParameters>]
Parameters
-Username
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The user principal name (e.g., admin@contoso.com). If omitted, you are prompted interactively.
-TemporaryAccessPass
| Property | Value |
|---|---|
| Type | SecureString |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The Temporary Access Pass as a SecureString. If omitted, you are prompted interactively.
-TenantId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Not documented |
The Entra tenant ID used for TAP authentication and the Defender XDR connection. If omitted, the cmdlet resolves the tenant from Username.
-UserAgent
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | (Get-XdrDefaultUserAgent) |
User-Agent string for HTTP requests. Defaults to a browser-compatible Edge user agent.
Examples
$tap = ConvertTo-SecureString '+&YZuead' -AsPlainText -Force
Connect-XdrByTemporaryAccessPass -Username 'admin@contoso.com' -TemporaryAccessPass $tap -TenantId '8612f621-73ca-4c12-973c-0da732bc44c2'
Authenticates using the supplied TAP and connects to Defender XDR.
Connect-XdrByTemporaryAccessPass -TenantId '8612f621-73ca-4c12-973c-0da732bc44c2'
Prompts for username and TAP, then authenticates and connects.
Connect-XdrByTemporaryAccessPass -Username 'admin@contoso.com'
Prompts for the TAP, resolves the tenant automatically from the username, then authenticates and connects.