POWERSHELL COMMAND
Get-XdrVulnerabilityManagementExtensions
Retrieves browser extensions from Vulnerability Management.
Gets browser extension inventory data from TVM in Microsoft Defender XDR. This function includes caching support with a 30-minute TTL to reduce API calls. Supports various sub-endpoints for detailed extension information.
Syntax
Get-XdrVulnerabilityManagementExtensions [-Force] [-Top <int>] [<CommonParameters>]
Get-XdrVulnerabilityManagementExtensions [-Force] [-Top <int>] [-Summary] [<CommonParameters>]
Get-XdrVulnerabilityManagementExtensions -ExtensionId <string> -TargetSoftware <string> [-Force] [-Top <int>] [-Installations] [<CommonParameters>]
Get-XdrVulnerabilityManagementExtensions -ExtensionId <string> -TargetSoftware <string> [-Force] [-Top <int>] [-InstallationsAggregate] [<CommonParameters>]
Get-XdrVulnerabilityManagementExtensions -ExtensionId <string> -TargetSoftware <string> [-Force] [-Top <int>] [-Users] [<CommonParameters>]
Get-XdrVulnerabilityManagementExtensions [-Force] [-Top <int>] [-CountOnly] [<CommonParameters>]
Parameters
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses the cache and forces a fresh retrieval from the API.
-Top
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
Limits the number of results returned for paginated endpoints. Useful for previewing data.
-Summary
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves the extensions summary endpoint.
-Installations
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves extension installation details. Requires -ExtensionId and -TargetSoftware.
-InstallationsAggregate
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves aggregated extension installation data. Requires -ExtensionId and -TargetSoftware.
-Users
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves users with the extension installed. Requires -ExtensionId and -TargetSoftware.
-CountOnly
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Retrieves only the total count of extensions.
-ExtensionId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The extension ID required for -Installations, -InstallationsAggregate, and -Users parameters.
-TargetSoftware
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The target software (e.g., ’edge’, ‘chrome’) required for -Installations, -InstallationsAggregate, and -Users parameters.
Examples
Get-XdrVulnerabilityManagementExtensions
Retrieves all browser extensions using cached data if available.
Get-XdrVulnerabilityManagementExtensions -Force
Forces a fresh retrieval of browser extensions, bypassing the cache.
Get-XdrVulnerabilityManagementExtensions -Top 10
Retrieves only the first 10 browser extensions.
Get-XdrVulnerabilityManagementExtensions -Summary
Retrieves the extensions summary data.
Get-XdrVulnerabilityManagementExtensions -Installations -ExtensionId "ggjhpefgjjfobnfoldnjipclpcfbgbhl" -TargetSoftware "edge"
Retrieves installation details for a specific extension.
Get-XdrVulnerabilityManagementExtensions -CountOnly
Returns only the total count of extensions.
Output
Type: System.Object[]
Returns an array of extension objects for paginated endpoints.
System.Int64 When -CountOnly is specified, returns the total count as an integer.
System.Management.Automation.PSCustomObject Returns a single object for non-paginated endpoints (summary, aggregate).
Suppress false positive: Switch parameters are used via $PSCmdlet.ParameterSetName, not direct reference