POWERSHELL COMMAND
Get-XdrEndpointDeviceActionResult
Gets device action results and download URIs from Microsoft Defender XDR.
Retrieves the latest device action results for a device, or downloads completed investigation package or support log collection results.
When called with just -DeviceId, returns the latest action results for each action type including status, requestor, timestamps, and request GUIDs.
When called with -DownloadInvestigationPackage or -DownloadSupportLogs, retrieves the download URI for completed collection results. You can provide either a DeviceId (which auto-resolves the latest RequestGuid from machine state) or a RequestGuid directly.
Syntax
Get-XdrEndpointDeviceActionResult -DeviceId <string> [-RequestGuid <string>] [<CommonParameters>]
Get-XdrEndpointDeviceActionResult -DeviceId <string> -DownloadSupportLogs [<CommonParameters>]
Get-XdrEndpointDeviceActionResult -DeviceId <string> -DownloadInvestigationPackage [<CommonParameters>]
Get-XdrEndpointDeviceActionResult -DownloadInvestigationPackage -RequestGuid <string> [<CommonParameters>]
Get-XdrEndpointDeviceActionResult -DownloadSupportLogs -RequestGuid <string> [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The device identifier (SenseMachineId) to query action results for. Accepts pipeline input by property name and supports MachineId/SenseMachineId aliases.
-DownloadInvestigationPackage
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieve the download URI for the latest investigation package (forensics) collection.
-DownloadSupportLogs
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieve the download URI for the latest support logs collection.
-RequestGuid
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The GUID of a specific request. When used with -DeviceId (List mode), filters the results to the matching request. When used with -DownloadInvestigationPackage or -DownloadSupportLogs, specifies the completed request to download results for.
Examples
Get-XdrEndpointDeviceActionResult -DeviceId "55a5db7b474470725e0131dec38c07b2f54bf2ad"
Gets the latest action results for the specified device.
Get-XdrEndpointDeviceActionResult -DeviceId "55a5db7b474470725e0131dec38c07b2f54bf2ad" -RequestGuid "1b2010b8-143e-441b-b5e9-c0b56c090a24"
Gets the action result for a specific request on the device.
Get-XdrEndpointDevice -DeviceId $deviceId | Get-XdrEndpointDeviceActionResult
Gets action results for a device using pipeline input.
Get-XdrEndpointDeviceActionResult -DownloadInvestigationPackage -DeviceId "55a5db7b474470725e0131dec38c07b2f54bf2ad"
Auto-resolves the latest investigation package request and returns its download URI.
Get-XdrEndpointDevice -DeviceId $deviceId | Get-XdrEndpointDeviceActionResult -DownloadSupportLogs
Gets the download URI for the latest support logs collection using pipeline input.
Get-XdrEndpointDeviceActionResult -DownloadInvestigationPackage -RequestGuid "b28b630c-d1a1-4b1d-9676-680c15366a52"
Downloads the investigation package for a specific request to the current working directory.
Get-XdrEndpointDeviceActionResult -DownloadSupportLogs -RequestGuid "abc12345-6789-0123-4567-890abcdef012"
Downloads the support logs for a specific request to the current working directory.
Output
Type: PSCustomObject[]
When listing: Returns an array of action result objects with Type, RequestStatus, Requestor, timestamps, etc.
System.IO.FileInfo When downloading: Returns a FileInfo object for the downloaded file in the current working directory.