← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrCloudAppsPolicy

Retrieves policies from Microsoft Defender for Cloud Apps.

View source ↗

The Get-XdrCloudAppsPolicy cmdlet retrieves policies from Microsoft Defender for Cloud Apps. Policies help control and govern cloud application usage and data protection within your organization. You can filter, sort, and paginate the results using the available parameters.

Use -Type to retrieve specific policy types (ConditionalAccess, File, InformationProtection, OAuth, ShadowIT, Template, ThreatDetection). Use -Metadata with -Type to get filter and field definitions for that policy type. Use -Setting to retrieve policy settings.

For File and OAuth policies, additional options are available:

  • Use -PolicyId with -Type to retrieve a specific policy by ID
  • Use -Action with -Type File or -Type OAuth to get available actions
  • Use -PolicyLimit with -Type File to get file policy limits

Syntax

Get-XdrCloudAppsPolicy [-Limit <int>] [-Skip <int>] [-SortField <string>] [-SortDirection <string>] [-Filters <hashtable>] [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -Type <string> -PolicyId <string> [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -Type <string> -PolicyLimit [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -Type <string> -Action [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -Type <string> -Metadata [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -Type <string> [-Limit <int>] [-Skip <int>] [-SortField <string>] [-SortDirection <string>] [-Filters <hashtable>] [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -PolicyId <string> [-Force] [<CommonParameters>]

Get-XdrCloudAppsPolicy -Setting [-Force] [<CommonParameters>]

Parameters

-Type

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The type of policies to retrieve. Valid values are:

  • ConditionalAccess: Policies controlling access based on conditions
  • File: File policies for data protection
  • InformationProtection: Policies protecting sensitive data
  • OAuth: OAuth app policies for third-party app governance
  • ShadowIT: Policies detecting unsanctioned cloud app usage
  • Template: Pre-configured policy templates
  • ThreatDetection: Policies identifying security threats

-PolicyId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The unique identifier of a specific policy to retrieve. If -Type is specified, retrieves from that policy type’s endpoint. If -Type is not specified, attempts to discover the policy type automatically.

-Metadata

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

When specified with -Type, retrieves metadata including available filters, fields, and configuration options instead of the policies themselves.

-Action

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

When specified with -Type File or -Type OAuth, retrieves available actions that can be configured for those policy types.

-PolicyLimit

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

When specified with -Type File, retrieves file policy limits and constraints.

-Setting

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

When specified, retrieves policy settings configuration.

-Limit

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 20

The maximum number of policies to return. Default is 20.

-Skip

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 0

The number of policies to skip for pagination. Default is 0.

-SortField

Property Value
Type String
Required No
Position named
Pipeline input No
Default severity

The field to sort results by. Default is “severity”.

-SortDirection

Property Value
Type String
Required No
Position named
Pipeline input No
Default desc

The sort direction. Valid values are “asc” or “desc”. Default is “desc”.

-Filters

Property Value
Type Hashtable
Required No
Position named
Pipeline input No
Default @{}

A hashtable of filters to apply to the policies query.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and retrieves fresh data from the API.

Examples

Get-XdrCloudAppsPolicy

Retrieves all policies sorted by severity (highest first).

Get-XdrCloudAppsPolicy -Type ConditionalAccess

Retrieves conditional access policies.

Get-XdrCloudAppsPolicy -Type File

Retrieves file policies.

Get-XdrCloudAppsPolicy -Type OAuth

Retrieves OAuth app policies.

Get-XdrCloudAppsPolicy -Type File -PolicyId "abc123"

Retrieves a specific file policy by ID.

Get-XdrCloudAppsPolicy -PolicyId "abc123"

Retrieves a policy by ID, automatically discovering the policy type.

Get-XdrCloudAppsPolicy -Type ThreatDetection -Metadata

Retrieves metadata for threat detection policies including available filters.

Get-XdrCloudAppsPolicy -Type OAuth -Metadata

Retrieves metadata for OAuth policies including available filters.

Get-XdrCloudAppsPolicy -Type File -Action

Retrieves available actions for file policies.

Get-XdrCloudAppsPolicy -Type OAuth -Action

Retrieves available actions for OAuth policies.

Get-XdrCloudAppsPolicy -Type File -PolicyLimit

Retrieves file policy limits and constraints.

Get-XdrCloudAppsPolicy -Type ShadowIT -Limit 50 -SortField "name" -SortDirection "asc"

Retrieves 50 Shadow IT policies sorted by name ascending.

Get-XdrCloudAppsPolicy -Type Template

Retrieves policy templates.

$filters = @{ "enabled" = @{ "eq" = @($true) } }
Get-XdrCloudAppsPolicy -Type InformationProtection -Filters $filters

Retrieves enabled information protection policies.

Get-XdrCloudAppsPolicy -Setting

Retrieves policy settings configuration.

Get-XdrCloudAppsPolicy -Force

Forces a fresh retrieval of all policies, bypassing the cache.

Output

Type: System.Management.Automation.PSObject

View source