← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrEndpointDeviceAutomatedInvestigation

Starts an automated investigation on an endpoint device in Microsoft Defender XDR.

View source ↗

Triggers an automated investigation (AutoIR) for the specified endpoint device. This initiates the Defender XDR automated investigation and remediation workflow.

Syntax

Invoke-XdrEndpointDeviceAutomatedInvestigation [-DeviceId] <string> [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-DeviceId

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByPropertyName)
Default Not documented

The device ID (SenseMachineId) of the target device.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the command runs. The command is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before making changes.

Examples

Invoke-XdrEndpointDeviceAutomatedInvestigation -DeviceId "abc123"
Starts an automated investigation on the specified device.

Output

Type: Object

Returns the API response with investigation details.

View source