POWERSHELL COMMAND
Get-XdrIdentityUserTimeline
Retrieves the timeline of events for a specific user from Microsoft Defender for Identity.
Gets the timeline of security events for a user from Microsoft Defender for Identity with options to filter by date range, event types, and other parameters.
Uses parallel chunked requests (1-day intervals) to improve performance and support longer date ranges up to 180 days.
Supports two levels of parallelism:
- Parallel day chunks for a single user
- Parallel users when processing multiple users via pipeline
Final merged results are strictly filtered to the requested [FromDate, ToDate) range.
Syntax
Get-XdrIdentityUserTimeline -Upn <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -AadId <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -AadId <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -Upn <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -Sid <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -Sid <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -RadiusUserId <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -RadiusUserId <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -InputObject <psobject> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -InputObject <psobject> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -ListEventTypes [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Get-XdrIdentityUserTimeline -LastNDays <int> -ListEventTypes [-EventType <string[]>] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]
Parameters
-AadId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The Entra (Azure AD) object ID of the user.
-Upn
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The User Principal Name of the user.
-Sid
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The Security Identifier (SID) of the user.
-RadiusUserId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The RADIUS user ID in format “User_{tenantId}_{userId}”.
-InputObject
| Property | Value |
|---|---|
| Type | PSObject |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
A user object from Get-XdrIdentityUser containing resolved identifiers. Accepts pipeline input.
-FromDate
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | ((Get-Date).AddDays(-1)) |
The start date for the timeline. Defaults to 1 day before current time.
-ToDate
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | (Get-Date) |
The end date for the timeline. Defaults to current time.
-LastNDays
| Property | Value |
|---|---|
| Type | Int32 |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | 0 |
Specifies the number of days to look back from current time. Cannot be used with FromDate or ToDate parameters. Maximum is 180 days.
-EventType
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Filter events by type. Available types are retrieved dynamically from the FilterOptions API. Use -ListEventTypes to see available options.
-ListEventTypes
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Lists available event types for filtering for the specified user and time range. Returns pipeline objects with EventType, Scope, and User properties. If no user identifier is supplied, returns global event types for the selected time range.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 1000 |
The number of events to return per page. Defaults to 1000.
-IncludeSentinelEvents
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Include Microsoft Sentinel UEBA anomaly events in the timeline results. Requires the user to have an armId (Sentinel entity ID) which is auto-detected from the resolved user identifiers.
-ThrottleLimit
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 32 |
The maximum number of concurrent requests. Defaults to 32.
-TimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 3600 |
Maximum time in seconds to wait for all requests to complete. Defaults to 3600 (1 hour).
-MaxRetries
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 3 |
Maximum number of retry attempts for failed API requests. Defaults to 3.
-RetryDelaySeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 5 |
Base delay in seconds between retry attempts (uses exponential backoff). Defaults to 5.
-ChunkSizeHours
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 72 |
Maximum size of each time chunk in hours (1-168). Defaults to 72 hours. By default, adaptive chunking may reduce this value based on the requested range to improve throughput and avoid oversized identity timeline windows.
-DisableAdaptiveChunking
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Disables adaptive chunk sizing and forces fixed-size chunks based on ChunkSizeHours.
-RequestTimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 30 |
Timeout in seconds for individual HTTP requests (10-120). Defaults to 30. If a single API call takes longer than this, it will timeout and retry.
-OutputPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional. The path to store temporary JSON files. Defaults to a temp folder.
-KeepTempFiles
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
If specified, keeps the temporary JSON files after merging.
-ExportPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional. Export results directly to a JSON file at the specified path.
Examples
Get-XdrIdentityUserTimeline -Upn "user@domain.com"
Retrieves the last day of timeline events for the specified user.
Get-XdrIdentityUserTimeline -AadId "a2307c5a-76df-4513-b575-0537842c1d8b" -LastNDays 7
Retrieves 7 days of timeline events.
Get-XdrIdentityUser -Upn "user@domain.com" | Get-XdrIdentityUserTimeline -LastNDays 30
Retrieves user identity and pipes to timeline cmdlet for 30 days of events.
Get-XdrIdentityUserTimeline -Upn "user@domain.com" -LastNDays 7 -IncludeSentinelEvents
Retrieves timeline events including Sentinel UEBA anomalies.
Get-XdrIdentityUserTimeline -Upn "user@domain.com" -LastNDays 7 -ListEventTypes
Lists available event types for filtering for the specified user and time range.
Get-XdrIdentityUserTimeline -LastNDays 7 -ListEventTypes
Lists global event types for the selected time range.
Get-XdrIdentityUserTimeline -LastNDays 7 -ListEventTypes | Select-Object -ExpandProperty EventType
Returns only event type names for automation or downstream filtering.
Get-XdrIdentityUserTimeline -Upn "user@domain.com" -LastNDays 90 -ExportPath "C:\Reports\user_timeline.json"
Retrieves 90 days of timeline events and exports to JSON file.
Output
Type: XdrIdentityUserTimelineEvent[]
Returned when -ListEventTypes is not specified.
PSCustomObject Returned when -ListEventTypes is specified, with EventType, Scope, and User properties.