← All XDRInternals commands

POWERSHELL COMMAND

Set-XdrConfigurationCriticalAssetManagementClassification

Updates critical asset management classification rule metadata in Microsoft Defender XDR.

View source ↗

Modifies critical asset management rules in the Microsoft Defender XDR portal. This function allows enabling or disabling rules by updating their metadata.

Critical asset management allows you to define classification rules that identify high-value assets in your organization, such as privileged accounts, critical servers, or sensitive data repositories.

Syntax

Set-XdrConfigurationCriticalAssetManagementClassification -RuleId <string> -Enabled <bool> [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]

Set-XdrConfigurationCriticalAssetManagementClassification -InputObject <psobject> -Enabled <bool> [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-RuleId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The unique identifier of the rule to update. This parameter is mandatory when not using -InputObject.

-InputObject

Property Value
Type PSObject
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

A rule object from Get-XdrConfigurationCriticalAssetManagementClassification. When provided, avoids an extra API call to fetch rule details. Can be piped directly to this cmdlet.

-Enabled

Property Value
Type Boolean
Required Yes
Position named
Pipeline input No
Default False

Sets whether the rule should be enabled or disabled. Use $true to enable the rule or $false to disable it.

-PassThru

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

When specified, returns the updated rule object after the operation completes. By default, this cmdlet does not generate any output.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The cmdlet is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts you for confirmation before running the cmdlet.

Examples

Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $true
Enables the critical asset management rule with the specified ID.
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $false
Disables the critical asset management rule with the specified ID.
Get-XdrConfigurationCriticalAssetManagementClassification -RuleType Predefined -Enabled $false |
    Set-XdrConfigurationCriticalAssetManagementClassification -Enabled $true
Enables all disabled predefined critical asset management rules using pipeline.
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $true -PassThru
Enables the rule and returns the updated rule object.
Set-XdrConfigurationCriticalAssetManagementClassification -RuleId "55a3f458c38a4b53b7d6a5564e0d1ac7" -Enabled $true -WhatIf
Shows what would happen if the rule were enabled, without making any changes.
# Create a rule, then disable it
$rule = New-XdrConfigurationCriticalAssetManagementClassification `
    -RuleName "Temp Rule" -RuleDescription "Test" `
    -AssetType Devices -CriticalityLevel Low `
    -Property "Tags" -Operator Contains -Value "Test" -PassThru

$rule | Set-XdrConfigurationCriticalAssetManagementClassification -Enabled $false

Creates a new rule and immediately disables it using the pipeline.

Output

Type: None by default. System.Object if -PassThru is specified.

When PassThru is used, returns the updated rule object from Get-XdrConfigurationCriticalAssetManagementClassification.

View source