POWERSHELL COMMAND
Get-XdrCloudAppsPolicy
Retrieves policies from Microsoft Defender for Cloud Apps.
The Get-XdrCloudAppsPolicy cmdlet retrieves policies from Microsoft Defender for Cloud Apps. Policies help control and govern cloud application usage and data protection within your organization. You can filter, sort, and paginate the results using the available parameters.
Use -Type to retrieve specific policy types (ConditionalAccess, File, InformationProtection, OAuth, ShadowIT, Template, ThreatDetection). Use -Metadata with -Type to get filter and field definitions for that policy type. Use -Setting to retrieve policy settings.
For File and OAuth policies, additional options are available:
- Use -PolicyId with -Type to retrieve a specific policy by ID
- Use -Action with -Type File or -Type OAuth to get available actions
- Use -PolicyLimit with -Type File to get file policy limits
Syntax
Get-XdrCloudAppsPolicy [-Limit <int>] [-Skip <int>] [-SortField <string>] [-SortDirection <string>] [-Filters <hashtable>] [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -Type <string> -PolicyId <string> [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -Type <string> -PolicyLimit [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -Type <string> -Action [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -Type <string> -Metadata [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -Type <string> [-Limit <int>] [-Skip <int>] [-SortField <string>] [-SortDirection <string>] [-Filters <hashtable>] [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -PolicyId <string> [-Force] [<CommonParameters>]
Get-XdrCloudAppsPolicy -Setting [-Force] [<CommonParameters>]
Parameters
-Type
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The type of policies to retrieve. Valid values are:
- ConditionalAccess: Policies controlling access based on conditions
- File: File policies for data protection
- InformationProtection: Policies protecting sensitive data
- OAuth: OAuth app policies for third-party app governance
- ShadowIT: Policies detecting unsanctioned cloud app usage
- Template: Pre-configured policy templates
- ThreatDetection: Policies identifying security threats
-PolicyId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The unique identifier of a specific policy to retrieve. If -Type is specified, retrieves from that policy type’s endpoint. If -Type is not specified, attempts to discover the policy type automatically.
-Metadata
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified with -Type, retrieves metadata including available filters, fields, and configuration options instead of the policies themselves.
-Action
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified with -Type File or -Type OAuth, retrieves available actions that can be configured for those policy types.
-PolicyLimit
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified with -Type File, retrieves file policy limits and constraints.
-Setting
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified, retrieves policy settings configuration.
-Limit
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 20 |
The maximum number of policies to return. Default is 20.
-Skip
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
The number of policies to skip for pagination. Default is 0.
-SortField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | severity |
The field to sort results by. Default is “severity”.
-SortDirection
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | desc |
The sort direction. Valid values are “asc” or “desc”. Default is “desc”.
-Filters
| Property | Value |
|---|---|
| Type | Hashtable |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | @{} |
A hashtable of filters to apply to the policies query.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and retrieves fresh data from the API.
Examples
Get-XdrCloudAppsPolicy
Retrieves all policies sorted by severity (highest first).
Get-XdrCloudAppsPolicy -Type ConditionalAccess
Retrieves conditional access policies.
Get-XdrCloudAppsPolicy -Type File
Retrieves file policies.
Get-XdrCloudAppsPolicy -Type OAuth
Retrieves OAuth app policies.
Get-XdrCloudAppsPolicy -Type File -PolicyId "abc123"
Retrieves a specific file policy by ID.
Get-XdrCloudAppsPolicy -PolicyId "abc123"
Retrieves a policy by ID, automatically discovering the policy type.
Get-XdrCloudAppsPolicy -Type ThreatDetection -Metadata
Retrieves metadata for threat detection policies including available filters.
Get-XdrCloudAppsPolicy -Type OAuth -Metadata
Retrieves metadata for OAuth policies including available filters.
Get-XdrCloudAppsPolicy -Type File -Action
Retrieves available actions for file policies.
Get-XdrCloudAppsPolicy -Type OAuth -Action
Retrieves available actions for OAuth policies.
Get-XdrCloudAppsPolicy -Type File -PolicyLimit
Retrieves file policy limits and constraints.
Get-XdrCloudAppsPolicy -Type ShadowIT -Limit 50 -SortField "name" -SortDirection "asc"
Retrieves 50 Shadow IT policies sorted by name ascending.
Get-XdrCloudAppsPolicy -Type Template
Retrieves policy templates.
$filters = @{ "enabled" = @{ "eq" = @($true) } }
Get-XdrCloudAppsPolicy -Type InformationProtection -Filters $filters
Retrieves enabled information protection policies.
Get-XdrCloudAppsPolicy -Setting
Retrieves policy settings configuration.
Get-XdrCloudAppsPolicy -Force
Forces a fresh retrieval of all policies, bypassing the cache.
Output
Type: System.Management.Automation.PSObject