POWERSHELL COMMAND
Get-XdrIdentityConfigurationRemediationActionAccount
Retrieves the remediation action account configuration for Microsoft Defender for Identity.
Gets the remediation action account configuration from Microsoft Defender for Identity. If remediation is configured to use Local System, returns the configuration status. If remediation uses a dedicated account, returns both the configuration status and the account details. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrIdentityConfigurationRemediationActionAccount [-Force] [<CommonParameters>]
Parameters
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrIdentityConfigurationRemediationActionAccount
Retrieves the remediation action account configuration using cached data if available.
Get-XdrIdentityConfigurationRemediationActionAccount -Force
Forces a fresh retrieval of the remediation action account configuration, bypassing the cache.
$config = Get-XdrIdentityConfigurationRemediationActionAccount
if ($config.IsRemediationWithLocalSystemEnabled) {
Write-Host "Using Local System account for remediation"
} else {
Write-Host "Using dedicated account: $($config.RemediationAccounts[0].AccountName)"
}
Retrieves the configuration and checks which account type is being used.
Output
Type: Object
Returns a configuration object containing:
- IsRemediationWithLocalSystemEnabled: Boolean indicating if Local System is used
- RemediationAccounts: Array of remediation account details (only if not using Local System)