POWERSHELL COMMAND
Get-XdrConfigurationCriticalAssetManagementClassificationSchema
Retrieves the schema for Critical Asset Management rules from Microsoft Defender XDR.
Gets the schema definition for the Critical Asset Management query builder. This includes the available asset types (Devices, Identities, CloudResources) and their filterable properties that can be used when creating custom critical asset rules.
Each property includes its name and type (e.g., ClosedList, Boolean, String, Array). This information is useful for understanding what criteria can be used to identify critical assets in your organization.
Syntax
Get-XdrConfigurationCriticalAssetManagementClassificationSchema [[-AssetType] <string>] [-Force] [<CommonParameters>]
Parameters
-AssetType
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
Filter the schema to a specific asset type. Valid values are:
- Devices: Properties for device-based rules
- Identities: Properties for identity/user-based rules
- CloudResources: Properties for cloud resource-based rules
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrConfigurationCriticalAssetManagementClassificationSchema
Retrieves the full schema for all asset types.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Identities
Retrieves only the schema for identity-based rules.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Devices |
Select-Object -ExpandProperty properties
Lists all available properties for device-based critical asset rules.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -Force
Forces a fresh retrieval of the schema, bypassing the cache.
# Discover schema and create a rule based on available properties
$deviceProps = Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Devices |
Select-Object -ExpandProperty properties
Display available properties
$deviceProps | Format-Table name, propertyType
Create a rule using one of the discovered properties
New-XdrConfigurationCriticalAssetManagementClassification -RuleName "Critical Servers"
-RuleDescription “Servers with critical tag” -AssetType Devices
-CriticalityLevel VeryHigh -Property "Tags"
-Operator Contains `
-Value “Critical”
Discovers available properties and creates a rule using one of them.
Output
Type: PSCustomObject[]
Returns an array of asset type schemas, each containing:
- assetType: The type of asset (Devices, Identities, CloudResources)
- properties: An array of property definitions with name and propertyType