POWERSHELL COMMAND
Get-XdrEndpointDeviceTag
Retrieves all device tags from Microsoft Defender for Endpoint.
Gets device tags from the Microsoft Defender XDR portal. Supports two modes:
- All (default): Retrieves all device tags in the tenant.
- DeviceId: Retrieves tags for a single device via the machineTags API. Returns an object with BuiltInTags, UserDefinedTags, and DynamicRulesTags arrays. Results are cached for 5 minutes. This function includes caching support to reduce API calls.
Syntax
Get-XdrEndpointDeviceTag [-Force] [<CommonParameters>]
Get-XdrEndpointDeviceTag -DeviceId <string> [-Force] [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The device identifier (also known as MachineId or SenseMachineId). When specified, retrieves the tags for a single device. Results are cached for 5 minutes.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrEndpointDeviceTag
Retrieves all device tags using cached data if available.
Get-XdrEndpointDeviceTag -Force
Forces a fresh retrieval of device tags, bypassing the cache.
Get-XdrEndpointDeviceTag -DeviceId "abc123def456"
Returns an object with BuiltInTags, UserDefinedTags, and DynamicRulesTags arrays.
(Get-XdrEndpointDeviceTag -DeviceId "abc123def456").UserDefinedTags
Returns only the user-defined tags for a single device.
Output
Type: Object
When using -DeviceId, returns an object with BuiltInTags, UserDefinedTags, and DynamicRulesTags. When using default mode, returns an array of all device tag strings in the tenant.