← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrEndpointDeviceTag

Retrieves all device tags from Microsoft Defender for Endpoint.

View source ↗

Gets device tags from the Microsoft Defender XDR portal. Supports two modes:

  • All (default): Retrieves all device tags in the tenant.
  • DeviceId: Retrieves tags for a single device via the machineTags API. Returns an object with BuiltInTags, UserDefinedTags, and DynamicRulesTags arrays. Results are cached for 5 minutes. This function includes caching support to reduce API calls.

Syntax

Get-XdrEndpointDeviceTag [-Force] [<CommonParameters>]

Get-XdrEndpointDeviceTag -DeviceId <string> [-Force] [<CommonParameters>]

Parameters

-DeviceId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The device identifier (also known as MachineId or SenseMachineId). When specified, retrieves the tags for a single device. Results are cached for 5 minutes.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrEndpointDeviceTag
Retrieves all device tags using cached data if available.
Get-XdrEndpointDeviceTag -Force
Forces a fresh retrieval of device tags, bypassing the cache.
Get-XdrEndpointDeviceTag -DeviceId "abc123def456"
Returns an object with BuiltInTags, UserDefinedTags, and DynamicRulesTags arrays.
(Get-XdrEndpointDeviceTag -DeviceId "abc123def456").UserDefinedTags
Returns only the user-defined tags for a single device.

Output

Type: Object

When using -DeviceId, returns an object with BuiltInTags, UserDefinedTags, and DynamicRulesTags. When using default mode, returns an array of all device tag strings in the tenant.

View source