POWERSHELL COMMAND
Get-XdrEndpointDeviceTotals
Retrieves the device totals from Microsoft Defender XDR.
Gets the total count of devices from the Microsoft Defender XDR portal with options to filter low fidelity devices and specify the lookback period.
Syntax
Get-XdrEndpointDeviceTotals [[-HideLowFidelityDevices] <bool>] [[-LookingBackInDays] <int>] [-Force] [<CommonParameters>]
Parameters
-HideLowFidelityDevices
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | True |
Whether to hide low fidelity devices from the results. Defaults to $true.
-LookingBackInDays
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | 30 |
The number of days to look back for device data. Defaults to 30 days.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Whether to force bypassing the cache and retrieve fresh data. Defaults to $false.
Examples
Get-XdrEndpointDeviceTotals
Retrieves device totals using default settings (hiding low fidelity devices, 30 days lookback).
Get-XdrEndpointDeviceTotals -HideLowFidelityDevices $false -LookingBackInDays 90
Retrieves device totals including low fidelity devices with a 90-day lookback period.
Get-XdrEndpointDeviceTotals -LookingBackInDays 7
Retrieves device totals for the last 7 days, hiding low fidelity devices.