POWERSHELL COMMAND
Get-XdrIdentityUser
Retrieves detailed user identity information from Microsoft Defender for Identity.
Gets comprehensive user identity information by resolving identifiers across multiple workloads including Microsoft Graph, RADIUS, MCAS, MTP, MDI, and Sentinel.
This cmdlet calls the user/resolve API to get full identity details including:
- All user identifiers (AAD ID, SID, UPN, radiusUserId, complexId, armId)
- User profile information (displayName, email, phone, department, jobTitle)
- Security information (riskLevel, status, PIM roles)
- Activity timestamps (firstSeen, lastSeen, created)
- Cloud app accounts, activity period, devices count, and manager details when available
The returned object can be piped to Get-XdrIdentityUserTimeline for timeline retrieval.
Syntax
Get-XdrIdentityUser -Upn <string> [-Force] [<CommonParameters>]
Get-XdrIdentityUser -AadId <string> [-Force] [<CommonParameters>]
Get-XdrIdentityUser -Sid <string> [-Force] [<CommonParameters>]
Get-XdrIdentityUser -RadiusUserId <string> [-Force] [<CommonParameters>]
Parameters
-AadId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The Azure AD object ID of the user.
-Upn
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | Not documented |
The User Principal Name (email address) of the user.
-Sid
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The Security Identifier (SID) of the user.
-RadiusUserId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The RADIUS user ID in format “User_{tenantId}_{userId}”.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypass cache and force a fresh API call.
Examples
Get-XdrIdentityUser -Upn "nathan@contoso.com"
Retrieves user identity information by UPN.
Get-XdrIdentityUser -AadId "a2307c5a-76df-4513-b575-0537842c1d8b"
Retrieves user identity information by Azure AD object ID.
Get-XdrIdentityUser -Upn "nathan@contoso.com"
Retrieves user identity including enrichment data (accounts, activity period, devices count, manager when available).
Get-XdrIdentityUser -Upn "nathan@contoso.com" | Get-XdrIdentityUserTimeline -LastNDays 7
Retrieves user identity and pipes to timeline cmdlet.
Output
Type: XdrIdentityUser
Returns a typed user identity object containing resolved identifiers and profile data.