← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIdentityUser

Retrieves detailed user identity information from Microsoft Defender for Identity.

View source ↗

Gets comprehensive user identity information by resolving identifiers across multiple workloads including Microsoft Graph, RADIUS, MCAS, MTP, MDI, and Sentinel.

This cmdlet calls the user/resolve API to get full identity details including:

  • All user identifiers (AAD ID, SID, UPN, radiusUserId, complexId, armId)
  • User profile information (displayName, email, phone, department, jobTitle)
  • Security information (riskLevel, status, PIM roles)
  • Activity timestamps (firstSeen, lastSeen, created)
  • Cloud app accounts, activity period, devices count, and manager details when available

The returned object can be piped to Get-XdrIdentityUserTimeline for timeline retrieval.

Syntax

Get-XdrIdentityUser -Upn <string> [-Force] [<CommonParameters>]

Get-XdrIdentityUser -AadId <string> [-Force] [<CommonParameters>]

Get-XdrIdentityUser -Sid <string> [-Force] [<CommonParameters>]

Get-XdrIdentityUser -RadiusUserId <string> [-Force] [<CommonParameters>]

Parameters

-AadId

Property Value
Type String
Required Yes
Position named
Pipeline input true (ByPropertyName)
Default Not documented

The Azure AD object ID of the user.

-Upn

Property Value
Type String
Required Yes
Position named
Pipeline input true (ByValue, ByPropertyName)
Default Not documented

The User Principal Name (email address) of the user.

-Sid

Property Value
Type String
Required Yes
Position named
Pipeline input true (ByPropertyName)
Default Not documented

The Security Identifier (SID) of the user.

-RadiusUserId

Property Value
Type String
Required Yes
Position named
Pipeline input true (ByPropertyName)
Default Not documented

The RADIUS user ID in format “User_{tenantId}_{userId}”.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypass cache and force a fresh API call.

Examples

Get-XdrIdentityUser -Upn "nathan@contoso.com"

Retrieves user identity information by UPN.

Get-XdrIdentityUser -AadId "a2307c5a-76df-4513-b575-0537842c1d8b"

Retrieves user identity information by Azure AD object ID.

Get-XdrIdentityUser -Upn "nathan@contoso.com"

Retrieves user identity including enrichment data (accounts, activity period, devices count, manager when available).

Get-XdrIdentityUser -Upn "nathan@contoso.com" | Get-XdrIdentityUserTimeline -LastNDays 7

Retrieves user identity and pipes to timeline cmdlet.

Output

Type: XdrIdentityUser

Returns a typed user identity object containing resolved identifiers and profile data.

View source