← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrActionsCenterPending

Retrieves pending actions from the Microsoft Defender XDR Action Center.

View source ↗

Gets a list of pending actions from the Microsoft Defender XDR Action Center with options to sort and paginate the results.

Syntax

Get-XdrActionsCenterPending [[-SortByField] <string>] [[-SortOrder] <string>] [[-PageIndex] <int>] [[-PageSize] <int>] [[-UseMtpApi] <bool>] [<CommonParameters>]

Parameters

-SortByField

Property Value
Type String
Required No
Position 1
Pipeline input No
Default ActionUpdateTime

The field to sort actions by. Valid values are: InvestigationId, ApprovalId, ActionType, EntityType, Asset, Decision, DecidedBy, ActionSource, Status, ActionUpdateTime. Defaults to ‘ActionUpdateTime’.

-SortOrder

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Descending

The sort order for results. Valid values are ‘Ascending’ or ‘Descending’. Defaults to ‘Descending’.

-PageIndex

Property Value
Type Int32
Required No
Position 3
Pipeline input No
Default 1

The page index for pagination. Defaults to 1.

-PageSize

Property Value
Type Int32
Required No
Position 4
Pipeline input No
Default 100

The number of actions to return per page. Defaults to 100.

-UseMtpApi

Property Value
Type Boolean
Required No
Position 5
Pipeline input No
Default True

Whether to use the MTP API. Defaults to $true.

Examples

Get-XdrActionsCenterPending
Retrieves pending actions from the Action Center with default settings.
Get-XdrActionsCenterPending -PageSize 50 -PageIndex 2
Retrieves the second page of 50 pending actions.
Get-XdrActionsCenterPending -SortByField "ActionUpdateTime" -SortOrder "Ascending"
Retrieves pending actions sorted by action update time in ascending order.

Output

Type: Object

Returns the pending actions from the Action Center.

View source