← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIdentityConfigurationRemediationActionAccount

Retrieves the remediation action account configuration for Microsoft Defender for Identity.

View source ↗

Gets the remediation action account configuration from Microsoft Defender for Identity. If remediation is configured to use Local System, returns the configuration status. If remediation uses a dedicated account, returns both the configuration status and the account details. This function includes caching support with a 30-minute TTL to reduce API calls.

Syntax

Get-XdrIdentityConfigurationRemediationActionAccount [-Force] [<CommonParameters>]

Parameters

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrIdentityConfigurationRemediationActionAccount
Retrieves the remediation action account configuration using cached data if available.
Get-XdrIdentityConfigurationRemediationActionAccount -Force
Forces a fresh retrieval of the remediation action account configuration, bypassing the cache.
$config = Get-XdrIdentityConfigurationRemediationActionAccount
if ($config.IsRemediationWithLocalSystemEnabled) {
    Write-Host "Using Local System account for remediation"
} else {
    Write-Host "Using dedicated account: $($config.RemediationAccounts[0].AccountName)"
}
Retrieves the configuration and checks which account type is being used.

Output

Type: Object

Returns a configuration object containing:

  • IsRemediationWithLocalSystemEnabled: Boolean indicating if Local System is used
  • RemediationAccounts: Array of remediation account details (only if not using Local System)

View source