← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIdentityIdentity

Retrieves identities from Microsoft Defender for Identity.

View source ↗

Gets identities from Microsoft Defender for Identity with support for pagination, sorting, and search filtering. This function includes caching support with a 10-minute TTL to reduce API calls.

Syntax

Get-XdrIdentityIdentity [-SortByField <string>] [-SortDirection <string>] [-PageSize <int>] [-Skip <int>] [-SearchText <string>] [-IdentityProvider <string[]>] [-IdentityEnvironment <string[]>] [-Force] [<CommonParameters>]

Get-XdrIdentityIdentity -All [-SortByField <string>] [-SortDirection <string>] [-SearchText <string>] [-IdentityProvider <string[]>] [-IdentityEnvironment <string[]>] [-Force] [<CommonParameters>]

Parameters

-SortByField

Property Value
Type String
Required No
Position named
Pipeline input No
Default RepresentableName

The field to sort results by. Valid values are “RepresentableName”, “AccountDomain”, and “CreatedDateTime”. Default is “RepresentableName”.

-SortDirection

Property Value
Type String
Required No
Position named
Pipeline input No
Default Asc

The sort direction. Valid values are “Asc” (ascending) and “Dsc” (descending). Default is “Asc”.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 20

The number of identities to retrieve per page. Default is 20. Maximum is 100.

-Skip

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 0

The number of identities to skip. Used for pagination. Default is 0.

-SearchText

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Text to search for in identities. Only non-special characters are allowed.

-IdentityProvider

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Filters identities by identity provider. Valid values are “ActiveDirectory”, “EntraID”, and “Hybrid”. Multiple values can be specified.

-IdentityEnvironment

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Filters identities by primary identity provider. Valid values are “ActiveDirectory”, “EntraID”, and “Hybrid”. Multiple values can be specified.

-All

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Retrieves all identities by automatically paging through all results. When specified, PageSize and Skip parameters are ignored.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrIdentityIdentity
Retrieves the first 20 identities sorted by RepresentableName in ascending order.
Get-XdrIdentityIdentity -SortByField CreatedDateTime -SortDirection Dsc
Retrieves identities sorted by creation date in descending order (newest first).
Get-XdrIdentityIdentity -PageSize 50 -Skip 100
Retrieves 50 identities, skipping the first 100 (for pagination).
Get-XdrIdentityIdentity -SearchText "admin"
Retrieves identities matching the search text "admin".
Get-XdrIdentityIdentity -SortByField AccountDomain -PageSize 100 -SearchText "contoso"
Retrieves up to 100 identities containing "contoso", sorted by account domain.
Get-XdrIdentityIdentity -IdentityProvider ActiveDirectory
Retrieves identities from Active Directory only.
Get-XdrIdentityIdentity -IdentityProvider ActiveDirectory, EntraID
Retrieves identities from both Active Directory and Entra ID.
Get-XdrIdentityIdentity -IdentityEnvironment ActiveDirectory
Retrieves identities with Active Directory as primary identity provider.
Get-XdrIdentityIdentity -IdentityEnvironment ActiveDirectory, EntraID
Retrieves identities with Active Directory or Entra ID as primary identity provider.
Get-XdrIdentityIdentity -SearchText "bob" -IdentityEnvironment ActiveDirectory
Retrieves identities matching "bob" from Active Directory only.
Get-XdrIdentityIdentity -Force
Forces a fresh retrieval of identities, bypassing the cache.
Get-XdrIdentityIdentity -All
Retrieves all identities by automatically paging through all results.
Get-XdrIdentityIdentity -All -SearchText "admin"
Retrieves all identities matching "admin" by paging through all results.

Output

Type: Object

Returns the identities data from the API.

View source