POWERSHELL COMMAND
Get-XdrSuppressionRule
Retrieves alert suppression rules from Microsoft Defender XDR.
Gets the list of alert suppression rules configured in the Microsoft Defender XDR portal, including rule details such as title, conditions, scope, status, and matching alert counts. This function includes caching support with a 30-minute TTL to reduce API calls.
Syntax
Get-XdrSuppressionRule [-Force] [<CommonParameters>]
Parameters
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrSuppressionRule
Retrieves all suppression rules using cached data if available.
Get-XdrSuppressionRule -Force
Forces a fresh retrieval of suppression rules, bypassing the cache.
Get-XdrSuppressionRule | Where-Object { $_.IsEnabled }
Retrieves only enabled suppression rules.
Get-XdrSuppressionRule | Where-Object { $_.CreatedBy -eq 'Microsoft' }
Retrieves only Microsoft-created suppression rules.
Get-XdrSuppressionRule | Where-Object { $_.MatchingAlertsCount -gt 0 }
Retrieves suppression rules that have matched alerts.
Output
Type: Object[]
Returns an array of suppression rule objects with properties:
- Id: Unique identifier for the suppression rule
- RuleTitle: The title of the suppression rule
- SenseMachineId: Machine ID if rule is scoped to specific device
- ComputerDnsName: DNS name if rule is scoped to specific computer
- CreatedBy: User or system that created the rule
- CreationTime: When the rule was created
- UpdateTime: When the rule was last updated
- Scope: Scope type (1=Organizational, 2=Device group)
- IoaDefinitionId: Associated IOA definition GUID
- IsEnabled: Whether the rule is currently enabled
- IsSilent: Whether alerts are silently suppressed
- IsTestRule: Whether this is a test rule
- OrderIndex: Rule ordering index
- Action: Action type (1=Alert, 2=Suppress)
- RuleConditions: JSON string of rule conditions
- AlertTitle: Title of alerts this rule applies to
- MatchingAlertsCount: Number of alerts matched by this rule
- RbacGroupIds: RBAC group IDs (if scoped)
- DeserializedRbacGroupIds: Deserialized RBAC group IDs
- FullDeserializedRbacGroupIds: Full deserialized RBAC group IDs
- IsReadOnly: Whether the rule is read-only
- ThreatFamilyName: Associated threat family name
- LastActivity: Last activity timestamp
- RuleType: Type of rule (1=Alert-based, 2=IOA-based)
- RuleSource: Source of the rule (1=Microsoft, 2=Custom)
- ScopeConditions: JSON string of scope conditions
- AdditionalDetails: Additional rule details
- Description: Rule description
- DeserializedScopeConditions: Deserialized scope conditions array
- BitwiseServiceSources: Bitwise service sources flag