POWERSHELL COMMAND
Get-XdrCloudAppsApp
Retrieves app-focused Microsoft Defender for Cloud Apps data.
Retrieves app catalog, discovered app, OAuth app permission, file, service, and tag data through one grouped command.
Syntax
Get-XdrCloudAppsApp [[-Type] <string>] [[-AppId] <string>] [[-StreamId] <string>] [[-StreamName] <string>] [[-Timeframe] <int>] [[-Limit] <int>] [[-Skip] <int>] [[-SortField] <string>] [[-SortDirection] <string>] [[-Filters] <hashtable>] [-Metadata] [-CountOnly] [-Raw] [-Force] [<CommonParameters>]
Parameters
-Type
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Discovered |
App data surface to retrieve. Defaults to Discovered.
-Metadata
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves metadata for surfaces that expose filter or table metadata.
-CountOnly
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves only a count for surfaces that expose count endpoints.
-AppId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
App identifier used by app-specific data types.
-StreamId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Discovery stream identifier for discovered app queries.
-StreamName
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | Not documented |
Discovery stream display name pattern for discovered app queries.
-Timeframe
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 5 |
| Pipeline input | No |
| Default | 30 |
Discovery timeframe in days.
-Limit
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 6 |
| Pipeline input | No |
| Default | 100 |
Maximum number of records to request.
-Skip
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 7 |
| Pipeline input | No |
| Default | 0 |
Number of records to skip.
-SortField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 8 |
| Pipeline input | No |
| Default | score |
Field used to sort grid results.
-SortDirection
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 9 |
| Pipeline input | No |
| Default | desc |
Sort direction for grid results.
-Filters
| Property | Value |
|---|---|
| Type | Hashtable |
| Required | No |
| Position | 10 |
| Pipeline input | No |
| Default | @{} |
Cloud Apps filters to include in the query body.
-Raw
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns the API response shape instead of typed admin-friendly objects.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses cache-backed requests.
Examples
Get-XdrCloudAppsApp -Type Discovered -Limit 50
Retrieves discovered cloud apps.
Get-XdrCloudAppsApp -Type OAuth -Metadata
Retrieves OAuth app permission metadata.