POWERSHELL COMMAND
Disconnect-XdrEndpointDeviceLiveResponse
Closes an active Live Response session in Microsoft Defender XDR.
Closes an active Live Response session by calling the close_session API. This should be called when done with a Live Response session to free resources. Also clears the script-scoped LiveResponseSession variable if it matches.
Syntax
Disconnect-XdrEndpointDeviceLiveResponse [-SessionId] <string> [<CommonParameters>]
Parameters
-SessionId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | Not documented |
The Live Response session ID to close (starts with CLR prefix).
Examples
Disconnect-XdrEndpointDeviceLiveResponse -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb"
Closes the specified Live Response session.
$sessions | Disconnect-XdrEndpointDeviceLiveResponse
Closes Live Response sessions passed through the pipeline.
Output
Type: Object
Returns the API response.