POWERSHELL COMMAND
New-XdrConfigurationCriticalAssetManagementClassification
Creates a new Critical Asset Management classification rule in Microsoft Defender XDR.
Creates a custom Critical Asset Management classification rule to identify and classify critical assets in your organization. Rules can target Devices, Identities, or CloudResources and use property-based conditions to match assets.
Use Get-XdrConfigurationCriticalAssetManagementClassificationSchema to discover available properties and their types for building rule conditions.
Syntax
New-XdrConfigurationCriticalAssetManagementClassification -RuleName <string> -RuleDescription <string> -AssetType <string> -CriticalityLevel <Object> -Property <string> -Operator <string> -Value <string[]> [-Disabled] [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]
New-XdrConfigurationCriticalAssetManagementClassification -RuleName <string> -RuleDescription <string> -AssetType <string> -CriticalityLevel <Object> -RuleDefinition <hashtable> [-Disabled] [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-RuleName
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The display name for the new classification rule. Must be unique.
-RuleDescription
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
A description explaining what the rule identifies and its purpose.
-AssetType
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The type of assets this rule applies to. Valid values are:
- Devices: Target device/endpoint assets
- Identities: Target user/identity assets
- CloudResources: Target cloud resource assets
-CriticalityLevel
| Property | Value |
|---|---|
| Type | Object |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The criticality level to assign to matching assets. Accepts either numeric values or friendly names:
- 0 or ‘VeryHigh’: Very High criticality
- 1 or ‘High’: High criticality
- 2 or ‘Medium’: Medium criticality
- 3 or ‘Low’: Low criticality
-Property
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The property name to filter on. Use Get-XdrConfigurationCriticalAssetManagementClassificationSchema to see available properties for each asset type.
-Operator
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The comparison operator. Valid values are:
- Equals: Exact match
- NotEquals: Does not match
- Contains: Contains the value (for string properties)
- NotContains: Does not contain the value
-Value
| Property | Value |
|---|---|
| Type | String[] |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The value(s) to match against. Can be a single value or an array of values.
-RuleDefinition
| Property | Value |
|---|---|
| Type | Hashtable |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Advanced: A complete rule definition hashtable for complex rules with multiple conditions. When specified, Property, Operator, and Value parameters are ignored.
Example structure: @{ conditionType = “Operational” logicalOperator = “AND” # or “OR” conditions = @( @{ conditionType = “Simple” predicate = @{ property = “Property Name” operator = “Equals” value = @(“value1”, “value2”) } } ) }
-Disabled
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
If specified, creates the rule in a disabled state.
-PassThru
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified, returns the full rule object after creation. By default, only the ruleId is returned.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before running the cmdlet.
Examples
New-XdrConfigurationCriticalAssetManagementClassification -RuleName "Executive Accounts" `
-RuleDescription "Identifies executive user accounts" `
-AssetType Identities `
-CriticalityLevel VeryHigh `
-Property "Job Title" `
-Operator Equals `
-Value "CEO", "CFO", "CTO"
Creates a Very High criticality rule for executive accounts using the friendly name.
New-XdrConfigurationCriticalAssetManagementClassification -RuleName "Domain Controllers" `
-RuleDescription "Identifies domain controller servers" `
-AssetType Devices `
-CriticalityLevel 1 `
-Property "Device Role" `
-Operator Equals `
-Value "DomainController"
Creates a High criticality rule for domain controllers using numeric level.
# Discover available properties for Devices, then create a rule
Get-XdrConfigurationCriticalAssetManagementClassificationSchema -AssetType Devices |
Select-Object -ExpandProperty properties
New-XdrConfigurationCriticalAssetManagementClassification -RuleName “Windows Servers” -RuleDescription "Windows Server devices"
-AssetType Devices -CriticalityLevel High
-Property “OS Platform” -Operator Equals
-Value “Windows” `
-PassThru
Discovers schema properties, then creates a rule and returns the full rule object.
$rule = @{
conditionType = "Operational"
logicalOperator = "AND"
conditions = @(
@{
conditionType = "Simple"
predicate = @{
property = "Device Type"
operator = "Equals"
value = @("Server")
}
},
@{
conditionType = "Simple"
predicate = @{
property = "Tags"
operator = "Contains"
value = @("Production")
}
}
)
}
New-XdrConfigurationCriticalAssetManagementClassification -RuleName "Production Servers" `
-RuleDescription "Production server devices" `
-AssetType Devices `
-CriticalityLevel High `
-RuleDefinition $rule
Creates a rule with multiple conditions using AND logic.
# Full workflow: Create, verify, check affected assets, then clean up
$newRule = New-XdrConfigurationCriticalAssetManagementClassification `
-RuleName "Test Rule" `
-RuleDescription "Temporary test rule" `
-AssetType Devices `
-CriticalityLevel Low `
-Property "Tags" `
-Operator Contains `
-Value "Test" `
-PassThru
View the created rule with affected assets
Get-XdrConfigurationCriticalAssetManagementClassification -RuleId $newRule.ruleId -IncludeAffectedAssets
Clean up test rule
$newRule | Remove-XdrConfigurationCriticalAssetManagementClassification -Force
Demonstrates a complete workflow of creating, verifying, and removing a rule.
Output
Type: PSCustomObject
Returns an object containing the ruleId of the newly created rule.