← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrMtoAdvancedHunting

Executes an Advanced Hunting query across multiple tenants in MTO (Multi-Tenant Organization).

View source ↗

Runs a KQL (Kusto Query Language) Advanced Hunting query across one or more tenants in the Microsoft Defender XDR multi-tenant view. Supports querying across tenants with configurable time ranges and optional workspace selection.

Syntax

Invoke-XdrMtoAdvancedHunting -QueryText <string> [-TenantIds <string[]>] [-DaysAgo <int>] [-EndTime <datetime>] [-MaxRecordCount <int>] [-SelectedWorkspaces <hashtable>] [<CommonParameters>]

Invoke-XdrMtoAdvancedHunting -QueryText <string> [-TenantIds <string[]>] [-MinutesAgo <int>] [-EndTime <datetime>] [-MaxRecordCount <int>] [-SelectedWorkspaces <hashtable>] [<CommonParameters>]

Invoke-XdrMtoAdvancedHunting -QueryText <string> [-TenantIds <string[]>] [-StartTime <datetime>] [-EndTime <datetime>] [-MaxRecordCount <int>] [-SelectedWorkspaces <hashtable>] [<CommonParameters>]

Parameters

-QueryText

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The KQL query to execute. This is a required parameter.

-TenantIds

Property Value
Type String[]
Required No
Position named
Pipeline input true (ByPropertyName)
Default Not documented

Array of tenant IDs (GUIDs) to query. If not provided, uses the tenant ID from the cache (the currently selected tenant in MTO view).

-DaysAgo

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 7

Number of days to look back from now for the query time range. Default is 7 days. Cannot be used with -StartTime or -MinutesAgo parameters.

-MinutesAgo

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 0

Number of minutes to look back from now for the query time range. Cannot be used with -StartTime or -DaysAgo parameters.

-StartTime

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default Not documented

Custom start time for the query (DateTime object or string in ISO 8601 format). Cannot be used with -DaysAgo or -MinutesAgo parameters.

-EndTime

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default (Get-Date)

End time for the query (DateTime object or string in ISO 8601 format). Default is the current time.

-MaxRecordCount

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 0

Maximum number of records to return. If not specified, the API default is used.

-SelectedWorkspaces

Property Value
Type Hashtable
Required No
Position named
Pipeline input No
Default Not documented

Hashtable mapping tenant IDs to arrays of workspace IDs for querying specific workspaces. Example: @{ “tenantId1” = @(“workspaceId1”, “workspaceId2”); “tenantId2” = @(“workspaceId3”) }

Examples

Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10"
Executes a simple query across the current tenant for the last 7 days.
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10" -DaysAgo 30
Executes a query across the current tenant for the last 30 days.
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10" -MinutesAgo 60
Executes a query for the last 60 minutes.
$tenants = @("e3686c4f-af27-4f22-b9de-062f05b93aac", "48315f62-774c-49c9-884b-34a8931b2b1f")
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceInfo | take 5" -TenantIds $tenants
Executes a query across multiple specified tenants.
$query = @"
DeviceProcessEvents
| where Timestamp > ago(1h)
| where FileName =~ "powershell.exe"
| take 100
"@
Invoke-XdrMtoAdvancedHunting -QueryText $query -DaysAgo 1 -Verbose
Executes a multi-line query with verbose output showing per-tenant latency.
$workspaces = @{
    "e3686c4f-af27-4f22-b9de-062f05b93aac" = @("008e3d12-e648-46e1-83ec-f631d94bf434")
}
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10" -SelectedWorkspaces $workspaces
Executes a query with specific workspace selection.

Output

Type: PSCustomObject

Returns a custom object containing:

  • Schema: Array of column definitions with Name, Type, and Entity properties
  • Results: Array of result objects containing the query results
  • Quota: Array of quota information per tenant
  • ChartVisualization: Array of chart type information per tenant

View source