POWERSHELL COMMAND
Get-XdrEndpointDevice
Retrieves endpoint devices from Microsoft Defender XDR.
Gets endpoint devices from the Microsoft Defender XDR portal. Supports two modes:
- List (default): Retrieves devices with options to filter, sort, and paginate results.
- DeviceId: Retrieves detailed information for a single device by its identifier. Uses the getMachine API and caches results for 5 minutes.
Syntax
Get-XdrEndpointDevice [-MachineSearchPrefix <string>] [-LookingBackInDays <int>] [-PageIndex <int>] [-PageSize <int>] [-SortByField <string>] [-SortOrder <string>] [-HideLowFidelityDevices <bool>] [<CommonParameters>]
Get-XdrEndpointDevice -DeviceId <string> [-Force] [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The device identifier (also known as MachineId or SenseMachineId). When specified, retrieves detailed information for a single device. Results are cached for 5 minutes.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache when using -DeviceId and forces a fresh retrieval from the API.
-MachineSearchPrefix
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional. Search for devices by name prefix. Use this to filter devices whose names start with the specified string.
-LookingBackInDays
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 30 |
The number of days to look back for device data. Defaults to 30 days.
-PageIndex
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 1 |
The page index for pagination. Defaults to 1.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 25 |
The number of devices to return per page. Defaults to 25.
-SortByField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | riskscore |
The field to sort devices by. Defaults to ‘riskscore’.
-SortOrder
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Descending |
The sort order for results. Valid values are ‘Ascending’ or ‘Descending’. Defaults to ‘Descending’.
-HideLowFidelityDevices
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | True |
Whether to hide low fidelity devices from the results. Defaults to $true.
Examples
Get-XdrEndpointDevice
Retrieves the first 25 devices sorted by risk score in descending order using default settings.
Get-XdrEndpointDevice -PageSize 100 -PageIndex 2
Retrieves the second page of 100 devices.
Get-XdrEndpointDevice -SortByField "lastSeen" -SortOrder "Ascending"
Retrieves devices sorted by last seen date in ascending order.
Get-XdrEndpointDevice -HideLowFidelityDevices $false -LookingBackInDays 90
Retrieves devices including low fidelity devices with a 90-day lookback period.
Get-XdrEndpointDevice -MachineSearchPrefix "DESKTOP"
Retrieves devices whose names start with "DESKTOP".
Get-XdrEndpointDevice -DeviceId "abc123def456"
Retrieves detailed information for a single device by its identifier.