POWERSHELL COMMAND
Invoke-XdrEndpointDevicePolicySync
Forces a policy sync on an endpoint device in Microsoft Defender XDR.
Triggers a forced policy synchronization for a managed endpoint device. This is useful when policy changes need to be applied immediately.
Syntax
Invoke-XdrEndpointDevicePolicySync [-DeviceId] <string> [[-Comment] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
The device ID (SenseMachineId) of the target device.
-Comment
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | "Force policy sync - Performed by $env:USERNAME via XDRInternals" |
A comment describing the reason for the policy sync.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the command runs. The command is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before making changes.
Examples
Invoke-XdrEndpointDevicePolicySync -DeviceId "abc123"
Forces a policy sync on the specified device.
Invoke-XdrEndpointDevicePolicySync -DeviceId "abc123" -Comment "Apply new AV exclusions"
Forces a policy sync with a descriptive comment.
Output
Type: Object
Returns the API response.