POWERSHELL COMMAND
Get-XdrActionsCenterPending
Retrieves pending actions from the Microsoft Defender XDR Action Center.
Gets a list of pending actions from the Microsoft Defender XDR Action Center with options to sort and paginate the results.
Syntax
Get-XdrActionsCenterPending [[-SortByField] <string>] [[-SortOrder] <string>] [[-PageIndex] <int>] [[-PageSize] <int>] [[-UseMtpApi] <bool>] [<CommonParameters>]
Parameters
-SortByField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | ActionUpdateTime |
The field to sort actions by. Valid values are: InvestigationId, ApprovalId, ActionType, EntityType, Asset, Decision, DecidedBy, ActionSource, Status, ActionUpdateTime. Defaults to ‘ActionUpdateTime’.
-SortOrder
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Descending |
The sort order for results. Valid values are ‘Ascending’ or ‘Descending’. Defaults to ‘Descending’.
-PageIndex
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | 1 |
The page index for pagination. Defaults to 1.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | 100 |
The number of actions to return per page. Defaults to 100.
-UseMtpApi
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 5 |
| Pipeline input | No |
| Default | True |
Whether to use the MTP API. Defaults to $true.
Examples
Get-XdrActionsCenterPending
Retrieves pending actions from the Action Center with default settings.
Get-XdrActionsCenterPending -PageSize 50 -PageIndex 2
Retrieves the second page of 50 pending actions.
Get-XdrActionsCenterPending -SortByField "ActionUpdateTime" -SortOrder "Ascending"
Retrieves pending actions sorted by action update time in ascending order.
Output
Type: Object
Returns the pending actions from the Action Center.