POWERSHELL COMMAND
New-XdrIdentityConfigurationRemediationActionAccount
Registers a new remediation action account for Microsoft Defender for Identity.
Creates a new Group Managed Service Account (gMSA) registration for Microsoft Defender for Identity remediation actions. This account will be used by MDI to perform automatic remediation actions when the system is configured to use a dedicated account instead of Local System.
Syntax
New-XdrIdentityConfigurationRemediationActionAccount [-AccountName] <string> [-DomainDnsName] <string> [-IsSingleLabelAccountDomainName] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-AccountName
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The name of the Group Managed Service Account (without domain suffix).
-DomainDnsName
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The fully qualified domain name (FQDN) where the account exists.
-IsSingleLabelAccountDomainName
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Switch parameter indicating if the domain is a single-label domain name. Use this for non-standard domain configurations.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before registering the account.
Examples
New-XdrIdentityConfigurationRemediationActionAccount -AccountName "MDIRemediation" -DomainDnsName "contoso.com"
Registers a gMSA account named "MDIRemediation" in the contoso.com domain for MDI remediation actions.
New-XdrIdentityConfigurationRemediationActionAccount -AccountName "DefenderRemediator" -DomainDnsName "corp.contoso.com" -IsSingleLabelAccountDomainName
Registers a gMSA account with single-label domain name configuration.
Output
Type: Object
Returns the registration response from the API including the account configuration details.