POWERSHELL COMMAND
Get-XdrIdentityConfigurationDirectoryServiceAccount
Retrieves directory service accounts for Microsoft Defender for Identity.
Gets the directory service accounts (gMSA) configured for Microsoft Defender for Identity sensors. These accounts are used by MDI sensors to query Active Directory. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrIdentityConfigurationDirectoryServiceAccount [-PageSize <int>] [-Skip <int>] [-Force] [<CommonParameters>]
Get-XdrIdentityConfigurationDirectoryServiceAccount -All [-Force] [<CommonParameters>]
Parameters
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 20 |
The number of accounts to retrieve per page. Default is 20.
-Skip
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
The number of accounts to skip. Used for pagination. Default is 0.
-All
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves all directory service accounts by automatically paging through all results. When specified, PageSize and Skip parameters are ignored.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrIdentityConfigurationDirectoryServiceAccount
Retrieves the first 20 directory service accounts using cached data if available.
Get-XdrIdentityConfigurationDirectoryServiceAccount -PageSize 50 -Skip 20
Retrieves 50 accounts, skipping the first 20 (for pagination).
Get-XdrIdentityConfigurationDirectoryServiceAccount -All
Retrieves all directory service accounts by automatically paging through all results.
Get-XdrIdentityConfigurationDirectoryServiceAccount -Force
Forces a fresh retrieval of directory service accounts, bypassing the cache.
Get-XdrIdentityConfigurationDirectoryServiceAccount -All |
Where-Object { $_.IsGroupManagedServiceAccount -eq $true }
Retrieves all directory service accounts and filters for gMSAs.
Output
Type: Object[]
Returns an array of directory service account objects containing:
- Id: User Principal Name of the account
- AccountName: Account name without domain
- DomainDnsName: Fully qualified domain name
- AccountPassword: Always null for gMSA accounts
- IsGroupManagedServiceAccount: Boolean indicating if account is a gMSA
- IsSingleLabelAccountDomainName: Boolean for single-label domain configuration