← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrIdentityUserTimeline

Retrieves the timeline of events for a specific user from Microsoft Defender for Identity.

View source ↗

Gets the timeline of security events for a user from Microsoft Defender for Identity with options to filter by date range, event types, and other parameters.

Uses parallel chunked requests (1-day intervals) to improve performance and support longer date ranges up to 180 days.

Supports two levels of parallelism:

  • Parallel day chunks for a single user
  • Parallel users when processing multiple users via pipeline

Final merged results are strictly filtered to the requested [FromDate, ToDate) range.

Syntax

Get-XdrIdentityUserTimeline -Upn <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -AadId <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -AadId <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -Upn <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -Sid <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -Sid <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -RadiusUserId <string> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -RadiusUserId <string> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -InputObject <psobject> -LastNDays <int> [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -InputObject <psobject> [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-ListEventTypes] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -ListEventTypes [-FromDate <datetime>] [-ToDate <datetime>] [-EventType <string[]>] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Get-XdrIdentityUserTimeline -LastNDays <int> -ListEventTypes [-EventType <string[]>] [-PageSize <int>] [-IncludeSentinelEvents] [-ThrottleLimit <int>] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-ChunkSizeHours <int>] [-DisableAdaptiveChunking] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [<CommonParameters>]

Parameters

-AadId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The Entra (Azure AD) object ID of the user.

-Upn

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The User Principal Name of the user.

-Sid

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The Security Identifier (SID) of the user.

-RadiusUserId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The RADIUS user ID in format “User_{tenantId}_{userId}”.

-InputObject

Property Value
Type PSObject
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

A user object from Get-XdrIdentityUser containing resolved identifiers. Accepts pipeline input.

-FromDate

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default ((Get-Date).AddDays(-1))

The start date for the timeline. Defaults to 1 day before current time.

-ToDate

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default (Get-Date)

The end date for the timeline. Defaults to current time.

-LastNDays

Property Value
Type Int32
Required Yes
Position named
Pipeline input No
Default 0

Specifies the number of days to look back from current time. Cannot be used with FromDate or ToDate parameters. Maximum is 180 days.

-EventType

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Filter events by type. Available types are retrieved dynamically from the FilterOptions API. Use -ListEventTypes to see available options.

-ListEventTypes

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Lists available event types for filtering for the specified user and time range. Returns pipeline objects with EventType, Scope, and User properties. If no user identifier is supplied, returns global event types for the selected time range.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 1000

The number of events to return per page. Defaults to 1000.

-IncludeSentinelEvents

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Include Microsoft Sentinel UEBA anomaly events in the timeline results. Requires the user to have an armId (Sentinel entity ID) which is auto-detected from the resolved user identifiers.

-ThrottleLimit

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 32

The maximum number of concurrent requests. Defaults to 32.

-TimeoutSeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 3600

Maximum time in seconds to wait for all requests to complete. Defaults to 3600 (1 hour).

-MaxRetries

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 3

Maximum number of retry attempts for failed API requests. Defaults to 3.

-RetryDelaySeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 5

Base delay in seconds between retry attempts (uses exponential backoff). Defaults to 5.

-ChunkSizeHours

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 72

Maximum size of each time chunk in hours (1-168). Defaults to 72 hours. By default, adaptive chunking may reduce this value based on the requested range to improve throughput and avoid oversized identity timeline windows.

-DisableAdaptiveChunking

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Disables adaptive chunk sizing and forces fixed-size chunks based on ChunkSizeHours.

-RequestTimeoutSeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 30

Timeout in seconds for individual HTTP requests (10-120). Defaults to 30. If a single API call takes longer than this, it will timeout and retry.

-OutputPath

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional. The path to store temporary JSON files. Defaults to a temp folder.

-KeepTempFiles

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

If specified, keeps the temporary JSON files after merging.

-ExportPath

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional. Export results directly to a JSON file at the specified path.

Examples

Get-XdrIdentityUserTimeline -Upn "user@domain.com"

Retrieves the last day of timeline events for the specified user.

Get-XdrIdentityUserTimeline -AadId "a2307c5a-76df-4513-b575-0537842c1d8b" -LastNDays 7

Retrieves 7 days of timeline events.

Get-XdrIdentityUser -Upn "user@domain.com" | Get-XdrIdentityUserTimeline -LastNDays 30

Retrieves user identity and pipes to timeline cmdlet for 30 days of events.

Get-XdrIdentityUserTimeline -Upn "user@domain.com" -LastNDays 7 -IncludeSentinelEvents

Retrieves timeline events including Sentinel UEBA anomalies.

Get-XdrIdentityUserTimeline -Upn "user@domain.com" -LastNDays 7 -ListEventTypes

Lists available event types for filtering for the specified user and time range.

Get-XdrIdentityUserTimeline -LastNDays 7 -ListEventTypes

Lists global event types for the selected time range.

Get-XdrIdentityUserTimeline -LastNDays 7 -ListEventTypes | Select-Object -ExpandProperty EventType

Returns only event type names for automation or downstream filtering.

Get-XdrIdentityUserTimeline -Upn "user@domain.com" -LastNDays 90 -ExportPath "C:\Reports\user_timeline.json"

Retrieves 90 days of timeline events and exports to JSON file.

Output

Type: XdrIdentityUserTimelineEvent[]

Returned when -ListEventTypes is not specified.

PSCustomObject Returned when -ListEventTypes is specified, with EventType, Scope, and User properties.

View source