← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrConfigurationCriticalAssetManagementClassificationSchema

Retrieves the schema for Critical Asset Management rules from Microsoft Defender XDR.

View source ↗

Gets the schema definition for the Critical Asset Management query builder. This includes the available asset types (Devices, Identities, CloudResources) and their filterable properties that can be used when creating custom critical asset rules.

Each property includes its name and type (e.g., ClosedList, Boolean, String, Array). This information is useful for understanding what criteria can be used to identify critical assets in your organization.

Syntax

Get-XdrConfigurationCriticalAssetManagementClassificationSchema [[-AssetType] <string>] [-Force] [<CommonParameters>]

Parameters

-AssetType

Property Value
Type String
Required No
Position 1
Pipeline input No
Default Not documented

Filter the schema to a specific asset type. Valid values are:

  • Devices: Properties for device-based rules
  • Identities: Properties for identity/user-based rules
  • CloudResources: Properties for cloud resource-based rules

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrConfigurationCriticalAssetManagementClassificationSchema
Retrieves the full schema for all asset types.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Identities
Retrieves only the schema for identity-based rules.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Devices |
    Select-Object -ExpandProperty properties
Lists all available properties for device-based critical asset rules.
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -Force
Forces a fresh retrieval of the schema, bypassing the cache.
# Discover schema and create a rule based on available properties
$deviceProps = Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Devices |
    Select-Object -ExpandProperty properties

Display available properties

$deviceProps | Format-Table name, propertyType

Create a rule using one of the discovered properties

New-XdrConfigurationCriticalAssetManagementClassification -RuleName "Critical Servers" -RuleDescription “Servers with critical tag” -AssetType Devices -CriticalityLevel VeryHigh -Property "Tags" -Operator Contains ` -Value “Critical”

Discovers available properties and creates a rule using one of them.

Output

Type: PSCustomObject[]

Returns an array of asset type schemas, each containing:

  • assetType: The type of asset (Devices, Identities, CloudResources)
  • properties: An array of property definitions with name and propertyType

View source