POWERSHELL COMMAND
Set-XdrConfigurationCriticalAssetManagementClassification
Updates critical asset management classification rule metadata in Microsoft Defender XDR.
Modifies critical asset management rules in the Microsoft Defender XDR portal. This function allows enabling or disabling rules by updating their metadata.
Critical asset management allows you to define classification rules that identify high-value assets in your organization, such as privileged accounts, critical servers, or sensitive data repositories.
Syntax
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId <string> -Enabled <bool> [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]
Set-XdrConfigurationCriticalAssetManagementClassification -InputObject <psobject> -Enabled <bool> [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-RuleId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The unique identifier of the rule to update. This parameter is mandatory when not using -InputObject.
-InputObject
| Property | Value |
|---|---|
| Type | PSObject |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
A rule object from Get-XdrConfigurationCriticalAssetManagementClassification. When provided, avoids an extra API call to fetch rule details. Can be piped directly to this cmdlet.
-Enabled
| Property | Value |
|---|---|
| Type | Boolean |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Sets whether the rule should be enabled or disabled. Use $true to enable the rule or $false to disable it.
-PassThru
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified, returns the updated rule object after the operation completes. By default, this cmdlet does not generate any output.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before running the cmdlet.
Examples
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $true
Enables the critical asset management rule with the specified ID.
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $false
Disables the critical asset management rule with the specified ID.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType Predefined -Enabled $false |
Set-XdrConfigurationCriticalAssetManagementClassification -Enabled $true
Enables all disabled predefined critical asset management rules using pipeline.
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $true -PassThru
Enables the rule and returns the updated rule object.
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $true -WhatIf
Shows what would happen if the rule were enabled, without making any changes.
# Create a rule, then disable it
$rule = New-XdrConfigurationCriticalAssetManagementClassification `
-RuleName "Temp Rule" -RuleDescription "Test" `
-AssetType Devices -CriticalityLevel Low `
-Property "Tags" -Operator Contains -Value "Test" -PassThru
$rule | Set-XdrConfigurationCriticalAssetManagementClassification -Enabled $false
Creates a new rule and immediately disables it using the pipeline.
Output
Type: None by default. System.Object if -PassThru is specified.
When PassThru is used, returns the updated rule object from Get-XdrConfigurationCriticalAssetManagementClassification.