POWERSHELL COMMAND
Invoke-XdrEndpointDeviceAutomatedInvestigation
Starts an automated investigation on an endpoint device in Microsoft Defender XDR.
Triggers an automated investigation (AutoIR) for the specified endpoint device. This initiates the Defender XDR automated investigation and remediation workflow.
Syntax
Invoke-XdrEndpointDeviceAutomatedInvestigation [-DeviceId] <string> [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The device ID (SenseMachineId) of the target device.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the command runs. The command is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before making changes.
Examples
Invoke-XdrEndpointDeviceAutomatedInvestigation -DeviceId "abc123"
Starts an automated investigation on the specified device.
Output
Type: Object
Returns the API response with investigation details.