POWERSHELL COMMAND
Get-XdrIdentityIdentity
Retrieves identities from Microsoft Defender for Identity.
Gets identities from Microsoft Defender for Identity with support for pagination, sorting, and search filtering. This function includes caching support with a 10-minute TTL to reduce API calls.
Syntax
Get-XdrIdentityIdentity [-SortByField <string>] [-SortDirection <string>] [-PageSize <int>] [-Skip <int>] [-SearchText <string>] [-IdentityProvider <string[]>] [-IdentityEnvironment <string[]>] [-Force] [<CommonParameters>]
Get-XdrIdentityIdentity -All [-SortByField <string>] [-SortDirection <string>] [-SearchText <string>] [-IdentityProvider <string[]>] [-IdentityEnvironment <string[]>] [-Force] [<CommonParameters>]
Parameters
-SortByField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | RepresentableName |
The field to sort results by. Valid values are “RepresentableName”, “AccountDomain”, and “CreatedDateTime”. Default is “RepresentableName”.
-SortDirection
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Asc |
The sort direction. Valid values are “Asc” (ascending) and “Dsc” (descending). Default is “Asc”.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 20 |
The number of identities to retrieve per page. Default is 20. Maximum is 100.
-Skip
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
The number of identities to skip. Used for pagination. Default is 0.
-SearchText
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Text to search for in identities. Only non-special characters are allowed.
-IdentityProvider
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Filters identities by identity provider. Valid values are “ActiveDirectory”, “EntraID”, and “Hybrid”. Multiple values can be specified.
-IdentityEnvironment
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Filters identities by primary identity provider. Valid values are “ActiveDirectory”, “EntraID”, and “Hybrid”. Multiple values can be specified.
-All
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves all identities by automatically paging through all results. When specified, PageSize and Skip parameters are ignored.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrIdentityIdentity
Retrieves the first 20 identities sorted by RepresentableName in ascending order.
Get-XdrIdentityIdentity -SortByField CreatedDateTime -SortDirection Dsc
Retrieves identities sorted by creation date in descending order (newest first).
Get-XdrIdentityIdentity -PageSize 50 -Skip 100
Retrieves 50 identities, skipping the first 100 (for pagination).
Get-XdrIdentityIdentity -SearchText "admin"
Retrieves identities matching the search text "admin".
Get-XdrIdentityIdentity -SortByField AccountDomain -PageSize 100 -SearchText "contoso"
Retrieves up to 100 identities containing "contoso", sorted by account domain.
Get-XdrIdentityIdentity -IdentityProvider ActiveDirectory
Retrieves identities from Active Directory only.
Get-XdrIdentityIdentity -IdentityProvider ActiveDirectory, EntraID
Retrieves identities from both Active Directory and Entra ID.
Get-XdrIdentityIdentity -IdentityEnvironment ActiveDirectory
Retrieves identities with Active Directory as primary identity provider.
Get-XdrIdentityIdentity -IdentityEnvironment ActiveDirectory, EntraID
Retrieves identities with Active Directory or Entra ID as primary identity provider.
Get-XdrIdentityIdentity -SearchText "bob" -IdentityEnvironment ActiveDirectory
Retrieves identities matching "bob" from Active Directory only.
Get-XdrIdentityIdentity -Force
Forces a fresh retrieval of identities, bypassing the cache.
Get-XdrIdentityIdentity -All
Retrieves all identities by automatically paging through all results.
Get-XdrIdentityIdentity -All -SearchText "admin"
Retrieves all identities matching "admin" by paging through all results.
Output
Type: Object
Returns the identities data from the API.