← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrTenantWorkloadStatus

Retrieves and evaluates the workload status from Microsoft Defender XDR tenant context.

View source ↗

Gets the tenant context information and evaluates all properties named “Is*Active” to determine which Microsoft Defender workloads are active in the tenant. Provides friendly names and descriptions for known workloads.

Syntax

Get-XdrTenantWorkloadStatus [[-Workload] <string>] [-Force] [<CommonParameters>]

Parameters

-Workload

Property Value
Type String
Required No
Position 1
Pipeline input No
Default Not documented

Filter results to a specific workload. Can match either the OriginalProperty or WorkloadName. Supports wildcards.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses the cache and forces a fresh retrieval from the API.

Examples

Get-XdrTenantWorkloadStatus
Retrieves and evaluates all workload statuses using cached data if available.
Get-XdrTenantWorkloadStatus -Workload "IsMdeActive"
Retrieves only the Microsoft Defender for Endpoint workload status.
Get-XdrTenantWorkloadStatus -Workload "IsMdatpActive"
Retrieves the workload status using the original property name.
Get-XdrTenantWorkloadStatus -Workload "*Sentinel*"
Retrieves workload statuses that match the Sentinel pattern.
Get-XdrTenantWorkloadStatus -Force
Forces a fresh retrieval of the tenant context and evaluates workload statuses.

Output

Type: Array

Returns an array of objects containing the workload name, status, and description.

View source