POWERSHELL COMMAND
Remove-XdrConfigurationCriticalAssetManagementClassification
Removes a Critical Asset Management classification rule from Microsoft Defender XDR.
Deletes a user-created Critical Asset Management classification rule. This operation marks the rule as deleted and it will no longer be evaluated against assets.
Note: Only user-created rules (ruleType = “CreatedByUser”) can be deleted. Predefined rules cannot be deleted, only disabled.
Syntax
Remove-XdrConfigurationCriticalAssetManagementClassification [-RuleId] <string> [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
Remove-XdrConfigurationCriticalAssetManagementClassification -InputObject <psobject> [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-RuleId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The unique identifier of the rule to delete.
-InputObject
| Property | Value |
|---|---|
| Type | PSObject |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
A rule object from Get-XdrConfigurationCriticalAssetManagementClassification to delete. Can be piped to this cmdlet.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Suppresses the confirmation prompt before deleting the rule.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before running the cmdlet.
Examples
Remove-XdrConfigurationCriticalAssetManagementClassification -RuleId "b2ccb988-5761-4947-93da-12e7c0ae6171"
Deletes the specified rule after confirmation.
Remove-XdrConfigurationCriticalAssetManagementClassification -RuleId "b2ccb988-5761-4947-93da-12e7c0ae6171" -Force
Deletes the specified rule without confirmation.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleId "b2ccb988-5761-4947-93da-12e7c0ae6171" |
Remove-XdrConfigurationCriticalAssetManagementClassification
Pipes a rule object to delete it.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType CreatedByUser |
Where-Object { $_.ruleName -like "*Test*" } |
Remove-XdrConfigurationCriticalAssetManagementClassification -Force
Deletes all user-created rules with "Test" in the name.
# Full create and cleanup workflow
$rule = New-XdrConfigurationCriticalAssetManagementClassification `
-RuleName "Temporary Test Rule" `
-RuleDescription "Rule for testing" `
-AssetType Devices -CriticalityLevel Low `
-Property "Tags" -Operator Contains -Value "TestTag" `
-PassThru
Verify creation
Get-XdrConfigurationCriticalAssetManagementClassification -RuleId $rule.ruleId
Remove when done testing
$rule | Remove-XdrConfigurationCriticalAssetManagementClassification -Force
Creates a rule, verifies it exists, then removes it.
Output
Type: None
This cmdlet does not return any output on success.