POWERSHELL COMMAND
Invoke-XdrMtoAdvancedHunting
Executes an Advanced Hunting query across multiple tenants in MTO (Multi-Tenant Organization).
Runs a KQL (Kusto Query Language) Advanced Hunting query across one or more tenants in the Microsoft Defender XDR multi-tenant view. Supports querying across tenants with configurable time ranges and optional workspace selection.
Syntax
Invoke-XdrMtoAdvancedHunting -QueryText <string> [-TenantIds <string[]>] [-DaysAgo <int>] [-EndTime <datetime>] [-MaxRecordCount <int>] [-SelectedWorkspaces <hashtable>] [<CommonParameters>]
Invoke-XdrMtoAdvancedHunting -QueryText <string> [-TenantIds <string[]>] [-MinutesAgo <int>] [-EndTime <datetime>] [-MaxRecordCount <int>] [-SelectedWorkspaces <hashtable>] [<CommonParameters>]
Invoke-XdrMtoAdvancedHunting -QueryText <string> [-TenantIds <string[]>] [-StartTime <datetime>] [-EndTime <datetime>] [-MaxRecordCount <int>] [-SelectedWorkspaces <hashtable>] [<CommonParameters>]
Parameters
-QueryText
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The KQL query to execute. This is a required parameter.
-TenantIds
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | named |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
Array of tenant IDs (GUIDs) to query. If not provided, uses the tenant ID from the cache (the currently selected tenant in MTO view).
-DaysAgo
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 7 |
Number of days to look back from now for the query time range. Default is 7 days. Cannot be used with -StartTime or -MinutesAgo parameters.
-MinutesAgo
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
Number of minutes to look back from now for the query time range. Cannot be used with -StartTime or -DaysAgo parameters.
-StartTime
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Custom start time for the query (DateTime object or string in ISO 8601 format). Cannot be used with -DaysAgo or -MinutesAgo parameters.
-EndTime
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | (Get-Date) |
End time for the query (DateTime object or string in ISO 8601 format). Default is the current time.
-MaxRecordCount
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
Maximum number of records to return. If not specified, the API default is used.
-SelectedWorkspaces
| Property | Value |
|---|---|
| Type | Hashtable |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Hashtable mapping tenant IDs to arrays of workspace IDs for querying specific workspaces. Example: @{ “tenantId1” = @(“workspaceId1”, “workspaceId2”); “tenantId2” = @(“workspaceId3”) }
Examples
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10"
Executes a simple query across the current tenant for the last 7 days.
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10" -DaysAgo 30
Executes a query across the current tenant for the last 30 days.
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10" -MinutesAgo 60
Executes a query for the last 60 minutes.
$tenants = @("e3686c4f-af27-4f22-b9de-062f05b93aac", "48315f62-774c-49c9-884b-34a8931b2b1f")
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceInfo | take 5" -TenantIds $tenants
Executes a query across multiple specified tenants.
$query = @"
DeviceProcessEvents
| where Timestamp > ago(1h)
| where FileName =~ "powershell.exe"
| take 100
"@
Invoke-XdrMtoAdvancedHunting -QueryText $query -DaysAgo 1 -Verbose
Executes a multi-line query with verbose output showing per-tenant latency.
$workspaces = @{
"e3686c4f-af27-4f22-b9de-062f05b93aac" = @("008e3d12-e648-46e1-83ec-f631d94bf434")
}
Invoke-XdrMtoAdvancedHunting -QueryText "DeviceEvents | limit 10" -SelectedWorkspaces $workspaces
Executes a query with specific workspace selection.
Output
Type: PSCustomObject
Returns a custom object containing:
- Schema: Array of column definitions with Name, Type, and Entity properties
- Results: Array of result objects containing the query results
- Quota: Array of quota information per tenant
- ChartVisualization: Array of chart type information per tenant