← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrRestMethod

Invokes a REST API call to Microsoft Defender XDR with authenticated session.

View source ↗

Executes REST API requests to Microsoft Defender XDR endpoints using the authenticated session and headers. This is a wrapper function that ensures connection settings are updated before making the API call.

Syntax

Invoke-XdrRestMethod [-Uri] <string> [[-Method] <string>] [[-ContentType] <string>] [[-WebSession] <Object>] [[-Headers] <hashtable>] [[-Body] <Object>] [<CommonParameters>]

Parameters

-Uri

Property Value
Type String
Required Yes
Position 1
Pipeline input No
Default Not documented

The URI of the API endpoint to call.

-Method

Property Value
Type String
Required No
Position 2
Pipeline input No
Default GET

The HTTP method to use for the request. Defaults to “GET”.

-ContentType

Property Value
Type String
Required No
Position 3
Pipeline input No
Default application/json

The content type of the request. Defaults to “application/json”.

-WebSession

Property Value
Type Object
Required No
Position 4
Pipeline input No
Default $script:session

The web session to use for the request. Defaults to the script-scoped session variable.

-Headers

Property Value
Type Hashtable
Required No
Position 5
Pipeline input No
Default $script:headers

The headers to include in the request. Defaults to the script-scoped headers variable.

-Body

Property Value
Type Object
Required No
Position 6
Pipeline input No
Default Not documented

The body of the request, if applicable.

Examples

Invoke-XdrRestMethod -Uri "https://security.microsoft.com/apiproxy/mtp/settings/GetAdvancedFeaturesSetting"
Makes a GET request to the specified XDR API endpoint.
Invoke-XdrRestMethod -Uri "https://security.microsoft.com/apiproxy/mtp/..." -Method "POST"
Makes a POST request to the specified XDR API endpoint.

Output

Type: Object

Returns the response object from the API call.

View source