← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrEndpointDevicePolicySync

Forces a policy sync on an endpoint device in Microsoft Defender XDR.

View source ↗

Triggers a forced policy synchronization for a managed endpoint device. This is useful when policy changes need to be applied immediately.

Syntax

Invoke-XdrEndpointDevicePolicySync [-DeviceId] <string> [[-Comment] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-DeviceId

Property Value
Type String
Required Yes
Position 1
Pipeline input true (ByPropertyName)
Default Not documented

The device ID (SenseMachineId) of the target device.

-Comment

Property Value
Type String
Required No
Position 2
Pipeline input No
Default "Force policy sync - Performed by $env:USERNAME via XDRInternals"

A comment describing the reason for the policy sync.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the command runs. The command is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before making changes.

Examples

Invoke-XdrEndpointDevicePolicySync -DeviceId "abc123"
Forces a policy sync on the specified device.
Invoke-XdrEndpointDevicePolicySync -DeviceId "abc123" -Comment "Apply new AV exclusions"
Forces a policy sync with a descriptive comment.

Output

Type: Object

Returns the API response.

View source