POWERSHELL COMMAND
Get-XdrConfigurationCriticalAssetManagementClassification
Retrieves critical asset management classification rules from Microsoft Defender XDR.
Gets the critical asset management rules from the Microsoft Defender XDR portal, including asset classification rules and conditions. This function includes caching support with a 30-minute TTL to reduce API calls.
Critical asset management allows you to define classification rules that identify high-value assets in your organization, such as privileged accounts, critical servers, or sensitive data repositories.
Syntax
Get-XdrConfigurationCriticalAssetManagementClassification [[-RuleId] <string>] [[-RuleType] <string>] [[-Enabled] <bool>] [-IncludeAffectedAssets] [-Force] [<CommonParameters>]
Parameters
-RuleId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The unique identifier of a specific rule to retrieve. If specified, returns only the rule with the matching ID.
-RuleType
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
Filters rules by type. Valid values are “Predefined” and “CreatedByUser”. If not specified, all rules are returned.
-Enabled
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | False |
Filters rules by enabled status. When specified, returns only rules where isEnabled matches the specified value.
-IncludeAffectedAssets
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified, retrieves the list of affected assets for each rule by making additional API calls to the querybuilder/assets endpoint. This adds an ‘affectedAssets’ property to each rule containing the detailed asset information.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrConfigurationCriticalAssetManagementClassification
Retrieves all critical asset management rules using cached data if available.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7"
Retrieves a specific critical asset management rule by its ID.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType Predefined
Retrieves only predefined critical asset management rules.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType CreatedByUser
Retrieves only user-created critical asset management rules.
Get-XdrConfigurationCriticalAssetManagementClassification -Enabled $true
Retrieves only enabled critical asset management rules.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType Predefined -Enabled $false
Retrieves predefined rules that are currently disabled.
Get-XdrConfigurationCriticalAssetManagementClassification -Force
Forces a fresh retrieval of the critical asset management configuration, bypassing the cache.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleId "b65d8e2e4e2f496d975a3987e43811f8" -IncludeAffectedAssets
Retrieves a specific rule and includes the list of affected assets.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType Predefined -IncludeAffectedAssets | Where-Object { $_.affectedAssetsCount -gt 0 }
Retrieves predefined rules that have affected assets and includes the asset details.
# Pipeline to Set: Enable all disabled predefined rules
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType Predefined -Enabled $false |
Set-XdrConfigurationCriticalAssetManagementClassification -Enabled $true
Enables all disabled predefined critical asset management rules.
# Pipeline to Remove: Clean up test rules
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType CreatedByUser |
Where-Object { $_.ruleName -like "*Test*" } |
Remove-XdrConfigurationCriticalAssetManagementClassification -Force
Removes all user-created rules with “Test” in the name.
Output
Type: System.Object[]
Returns the rules array containing critical asset management configuration. Each rule object contains properties such as:
- ruleId: Unique identifier for the rule
- ruleName: Display name of the rule
- ruleDescription: Description of what the rule identifies
- ruleType: Either “Predefined” or “CreatedByUser”
- isDisabled: Whether the rule is currently disabled
- criticalityLevel: The criticality level assigned to matching assets
- affectedAssetsCount: Number of assets matching this rule
- affectedAssets: (when -IncludeAffectedAssets) Array of asset objects with details