POWERSHELL COMMAND
Get-XdrIdentityServiceAccount
Retrieves service accounts from Microsoft Defender for Identity.
Gets service accounts from Microsoft Defender for Identity, including account activity information. Supports filtering by service account type (gMSA, sMSA, User). This function includes caching support with a 10-minute TTL to reduce API calls.
Syntax
Get-XdrIdentityServiceAccount [[-AccountType] <string[]>] [[-PageSize] <int>] [[-Skip] <int>] [[-IncludeAccountActivity] <bool>] [-Force] [<CommonParameters>]
Parameters
-AccountType
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
Filters service accounts by type. Valid values are “gMSA”, “sMSA”, and “User”. Multiple values can be specified. If not specified, all service account types are returned.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | 20 |
The number of service accounts to retrieve per page. Default is 20. Maximum is 100.
-Skip
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | 0 |
The number of service accounts to skip. Used for pagination. Default is 0.
-IncludeAccountActivity
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | True |
Whether to include account activity information. Default is $true.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrIdentityServiceAccount
Retrieves all service accounts using cached data if available.
Get-XdrIdentityServiceAccount -AccountType gMSA
Retrieves only group Managed Service Accounts (gMSA).
Get-XdrIdentityServiceAccount -AccountType sMSA, User
Retrieves standalone Managed Service Accounts (sMSA) and User accounts.
Get-XdrIdentityServiceAccount -PageSize 50 -Skip 20
Retrieves 50 service accounts, skipping the first 20 (for pagination).
Get-XdrIdentityServiceAccount -IncludeAccountActivity $false
Retrieves service accounts without account activity information.
Get-XdrIdentityServiceAccount -Force
Forces a fresh retrieval of service accounts, bypassing the cache.
Output
Type: Array
Returns the ServiceAccounts array containing service account information.