POWERSHELL COMMAND
Get-XdrTenantWorkloadStatus
Retrieves and evaluates the workload status from Microsoft Defender XDR tenant context.
Gets the tenant context information and evaluates all properties named “Is*Active” to determine which Microsoft Defender workloads are active in the tenant. Provides friendly names and descriptions for known workloads.
Syntax
Get-XdrTenantWorkloadStatus [[-Workload] <string>] [-Force] [<CommonParameters>]
Parameters
-Workload
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
Filter results to a specific workload. Can match either the OriginalProperty or WorkloadName. Supports wildcards.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
Examples
Get-XdrTenantWorkloadStatus
Retrieves and evaluates all workload statuses using cached data if available.
Get-XdrTenantWorkloadStatus -Workload "IsMdeActive"
Retrieves only the Microsoft Defender for Endpoint workload status.
Get-XdrTenantWorkloadStatus -Workload "IsMdatpActive"
Retrieves the workload status using the original property name.
Get-XdrTenantWorkloadStatus -Workload "*Sentinel*"
Retrieves workload statuses that match the Sentinel pattern.
Get-XdrTenantWorkloadStatus -Force
Forces a fresh retrieval of the tenant context and evaluates workload statuses.
Output
Type: Array
Returns an array of objects containing the workload name, status, and description.