← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIdentityAlertThreshold

Retrieves alert threshold configuration for Microsoft Defender for Identity.

View source ↗

Gets the alert threshold settings for Microsoft Defender for Identity detections. Alert thresholds determine the sensitivity level (High/Medium/Low) for various security alerts. The function maps internal alert names to user-friendly titles for better readability. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrIdentityAlertThreshold [-Force] [<CommonParameters>]

Parameters

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrIdentityAlertThreshold
Retrieves the alert threshold configuration using cached data if available.
Get-XdrIdentityAlertThreshold -Force
Forces a fresh retrieval of the alert threshold configuration, bypassing the cache.
$thresholds = Get-XdrIdentityAlertThreshold
$thresholds | Where-Object { $_.Threshold -eq "Low" }
Retrieves all alerts configured with Low threshold.
Get-XdrIdentityAlertThreshold | Format-Table AlertTitle, Threshold, AvailableThresholds -AutoSize
Displays alert thresholds in a formatted table.

Output

Type: Object

Returns an array of alert threshold configurations with friendly names. Each object contains:

  • AlertName: Internal alert identifier
  • AlertTitle: User-friendly alert name
  • Threshold: Current threshold level (High/Medium/Low)
  • AvailableThresholds: Array of available threshold levels for this alert

View source