← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrEndpointDevice

Retrieves endpoint devices from Microsoft Defender XDR.

View source ↗

Gets endpoint devices from the Microsoft Defender XDR portal. Supports two modes:

  • List (default): Retrieves devices with options to filter, sort, and paginate results.
  • DeviceId: Retrieves detailed information for a single device by its identifier. Uses the getMachine API and caches results for 5 minutes.

Syntax

Get-XdrEndpointDevice [-MachineSearchPrefix <string>] [-LookingBackInDays <int>] [-PageIndex <int>] [-PageSize <int>] [-SortByField <string>] [-SortOrder <string>] [-HideLowFidelityDevices <bool>] [<CommonParameters>]

Get-XdrEndpointDevice -DeviceId <string> [-Force] [<CommonParameters>]

Parameters

-DeviceId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The device identifier (also known as MachineId or SenseMachineId). When specified, retrieves detailed information for a single device. Results are cached for 5 minutes.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache when using -DeviceId and forces a fresh retrieval from the API.

-MachineSearchPrefix

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional. Search for devices by name prefix. Use this to filter devices whose names start with the specified string.

-LookingBackInDays

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 30

The number of days to look back for device data. Defaults to 30 days.

-PageIndex

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 1

The page index for pagination. Defaults to 1.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 25

The number of devices to return per page. Defaults to 25.

-SortByField

Property Value
Type String
Required No
Position named
Pipeline input No
Default riskscore

The field to sort devices by. Defaults to ‘riskscore’.

-SortOrder

Property Value
Type String
Required No
Position named
Pipeline input No
Default Descending

The sort order for results. Valid values are ‘Ascending’ or ‘Descending’. Defaults to ‘Descending’.

-HideLowFidelityDevices

Property Value
Type Boolean
Required No
Position named
Pipeline input No
Default True

Whether to hide low fidelity devices from the results. Defaults to $true.

Examples

Get-XdrEndpointDevice
Retrieves the first 25 devices sorted by risk score in descending order using default settings.
Get-XdrEndpointDevice -PageSize 100 -PageIndex 2
Retrieves the second page of 100 devices.
Get-XdrEndpointDevice -SortByField "lastSeen" -SortOrder "Ascending"
Retrieves devices sorted by last seen date in ascending order.
Get-XdrEndpointDevice -HideLowFidelityDevices $false -LookingBackInDays 90
Retrieves devices including low fidelity devices with a 90-day lookback period.
Get-XdrEndpointDevice -MachineSearchPrefix "DESKTOP"
Retrieves devices whose names start with "DESKTOP".
Get-XdrEndpointDevice -DeviceId "abc123def456"
Retrieves detailed information for a single device by its identifier.

View source