← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIdentityConfigurationDirectoryServiceAccount

Retrieves directory service accounts for Microsoft Defender for Identity.

View source ↗

Gets the directory service accounts (gMSA) configured for Microsoft Defender for Identity sensors. These accounts are used by MDI sensors to query Active Directory. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrIdentityConfigurationDirectoryServiceAccount [-PageSize <int>] [-Skip <int>] [-Force] [<CommonParameters>]

Get-XdrIdentityConfigurationDirectoryServiceAccount -All [-Force] [<CommonParameters>]

Parameters

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 20

The number of accounts to retrieve per page. Default is 20.

-Skip

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 0

The number of accounts to skip. Used for pagination. Default is 0.

-All

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Retrieves all directory service accounts by automatically paging through all results. When specified, PageSize and Skip parameters are ignored.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrIdentityConfigurationDirectoryServiceAccount
Retrieves the first 20 directory service accounts using cached data if available.
Get-XdrIdentityConfigurationDirectoryServiceAccount -PageSize 50 -Skip 20
Retrieves 50 accounts, skipping the first 20 (for pagination).
Get-XdrIdentityConfigurationDirectoryServiceAccount -All
Retrieves all directory service accounts by automatically paging through all results.
Get-XdrIdentityConfigurationDirectoryServiceAccount -Force
Forces a fresh retrieval of directory service accounts, bypassing the cache.
Get-XdrIdentityConfigurationDirectoryServiceAccount -All |
    Where-Object { $_.IsGroupManagedServiceAccount -eq $true }
Retrieves all directory service accounts and filters for gMSAs.

Output

Type: Object[]

Returns an array of directory service account objects containing:

  • Id: User Principal Name of the account
  • AccountName: Account name without domain
  • DomainDnsName: Fully qualified domain name
  • AccountPassword: Always null for gMSA accounts
  • IsGroupManagedServiceAccount: Boolean indicating if account is a gMSA
  • IsSingleLabelAccountDomainName: Boolean for single-label domain configuration

View source