POWERSHELL COMMAND
Get-XdrIdentityAlertThreshold
Retrieves alert threshold configuration for Microsoft Defender for Identity.
Gets the alert threshold settings for Microsoft Defender for Identity detections. Alert thresholds determine the sensitivity level (High/Medium/Low) for various security alerts. The function maps internal alert names to user-friendly titles for better readability. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrIdentityAlertThreshold [-Force] [<CommonParameters>]
Parameters
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrIdentityAlertThreshold
Retrieves the alert threshold configuration using cached data if available.
Get-XdrIdentityAlertThreshold -Force
Forces a fresh retrieval of the alert threshold configuration, bypassing the cache.
$thresholds = Get-XdrIdentityAlertThreshold
$thresholds | Where-Object { $_.Threshold -eq "Low" }
Retrieves all alerts configured with Low threshold.
Get-XdrIdentityAlertThreshold | Format-Table AlertTitle, Threshold, AvailableThresholds -AutoSize
Displays alert thresholds in a formatted table.
Output
Type: Object
Returns an array of alert threshold configurations with friendly names. Each object contains:
- AlertName: Internal alert identifier
- AlertTitle: User-friendly alert name
- Threshold: Current threshold level (High/Medium/Low)
- AvailableThresholds: Array of available threshold levels for this alert