← All XDRInternals commands

POWERSHELL COMMAND

Disconnect-XdrEndpointDeviceLiveResponse

Closes an active Live Response session in Microsoft Defender XDR.

View source ↗

Closes an active Live Response session by calling the close_session API. This should be called when done with a Live Response session to free resources. Also clears the script-scoped LiveResponseSession variable if it matches.

Syntax

Disconnect-XdrEndpointDeviceLiveResponse [-SessionId] <string> [<CommonParameters>]

Parameters

-SessionId

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByValue, ByPropertyName)
Default Not documented

The Live Response session ID to close (starts with CLR prefix).

Examples

Disconnect-XdrEndpointDeviceLiveResponse -SessionId "CLR0c33ce1c-1665-4e00-9059-8fa39da9e2cb"
Closes the specified Live Response session.
$sessions | Disconnect-XdrEndpointDeviceLiveResponse
Closes Live Response sessions passed through the pipeline.

Output

Type: Object

Returns the API response.

View source