← All XDRInternals commands

POWERSHELL COMMAND

Set-XdrEndpointAdvancedFeatures

Configures advanced features settings for Microsoft Defender for Endpoint.

View source ↗

Sets advanced features configuration for Microsoft Defender for Endpoint. This function updates various advanced features across different configuration endpoints.

Note: AlwaysRemediatePUA and EnableAutomaticAttackDisruption cannot be changed through this function as they are part of PotentiallyUnwantedApplications which is read-only.

Syntax

Set-XdrEndpointAdvancedFeatures [[-EnableEDRInBlockMode] <bool>] [[-EnableMicrosoftDefenderAntivirusInAuditMode] <bool>] [[-DeviceDiscovery] <bool>] [[-HidePotentialDuplicateDeviceRecords] <bool>] [[-AllowOrBlockFile] <bool>] [[-SkypeForBusinessIntegration] <bool>] [[-ShowUserDetails] <bool>] [[-MicrosoftDefenderForIdentityIntegration] <bool>] [[-AutomaticallyResolveAlerts] <bool>] [[-MicrosoftDefenderForCloudApps] <bool>] [[-AzureInformationProtection] <bool>] [[-TamperProtection] <bool>] [[-CustomNetworkIndicators] <bool>] [[-WebContentFiltering] <bool>] [[-MicrosoftEndpointDLP] <bool>] [[-DownloadQuarantinedFiles] <bool>] [[-RestrictCorrelationToWithinScopedDeviceGroups] <bool>] [[-ExcludeDevices] <bool>] [[-ActiveIncidentResponse] <bool>] [[-AggregatedReporting] <bool>] [[-LowFidelityEnrichmentEnabled] <bool>] [[-IsolationExclusionRules] <bool>] [[-DefaultToStreamlinedConnectivityWhenOnboardingDevicesInDefenderPortal] <bool>] [[-ApplyStreamlinedConnectivitySettingsToDevicesManagedByIntuneAndDefenderForCloud] <bool>] [[-PreviewFeatures] <bool>] [[-PurviewSharing] <bool>] [[-MicrosoftIntuneConnection] <bool>] [[-AuthenticatedTelemetry] <bool>] [[-LiveResponse] <bool>] [[-LiveResponseForServers] <bool>] [[-LiveResponseUnsignedScriptExecution] <bool>] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-EnableEDRInBlockMode

Property Value
Type Boolean
Required No
Position 1
Pipeline input true (ByPropertyName)
Default False

Enable EDR in block mode.

-EnableMicrosoftDefenderAntivirusInAuditMode

Property Value
Type Boolean
Required No
Position 2
Pipeline input true (ByPropertyName)
Default False

Enable Microsoft Defender Antivirus in audit mode.

-DeviceDiscovery

Property Value
Type Boolean
Required No
Position 3
Pipeline input true (ByPropertyName)
Default False

Enable device discovery.

-HidePotentialDuplicateDeviceRecords

Property Value
Type Boolean
Required No
Position 4
Pipeline input true (ByPropertyName)
Default False

Hide potential duplicate device records.

-AllowOrBlockFile

Property Value
Type Boolean
Required No
Position 5
Pipeline input true (ByPropertyName)
Default False

Enable allow or block file feature.

-SkypeForBusinessIntegration

Property Value
Type Boolean
Required No
Position 6
Pipeline input true (ByPropertyName)
Default False

Enable Skype for Business integration.

-ShowUserDetails

Property Value
Type Boolean
Required No
Position 7
Pipeline input true (ByPropertyName)
Default False

Show user details.

-MicrosoftDefenderForIdentityIntegration

Property Value
Type Boolean
Required No
Position 8
Pipeline input true (ByPropertyName)
Default False

Enable Microsoft Defender for Identity integration.

-AutomaticallyResolveAlerts

Property Value
Type Boolean
Required No
Position 9
Pipeline input true (ByPropertyName)
Default False

Automatically resolve alerts.

-MicrosoftDefenderForCloudApps

Property Value
Type Boolean
Required No
Position 10
Pipeline input true (ByPropertyName)
Default False

Enable Microsoft Defender for Cloud Apps integration.

-AzureInformationProtection

Property Value
Type Boolean
Required No
Position 11
Pipeline input true (ByPropertyName)
Default False

Enable Azure Information Protection integration.

-TamperProtection

Property Value
Type Boolean
Required No
Position 12
Pipeline input true (ByPropertyName)
Default False

Enable tamper protection.

-CustomNetworkIndicators

Property Value
Type Boolean
Required No
Position 13
Pipeline input true (ByPropertyName)
Default False

Enable custom network indicators.

-WebContentFiltering

Property Value
Type Boolean
Required No
Position 14
Pipeline input true (ByPropertyName)
Default False

Enable web content filtering.

-MicrosoftEndpointDLP

Property Value
Type Boolean
Required No
Position 15
Pipeline input true (ByPropertyName)
Default False

Enable Microsoft Endpoint DLP.

-DownloadQuarantinedFiles

Property Value
Type Boolean
Required No
Position 16
Pipeline input true (ByPropertyName)
Default False

Enable download of quarantined files.

-RestrictCorrelationToWithinScopedDeviceGroups

Property Value
Type Boolean
Required No
Position 17
Pipeline input true (ByPropertyName)
Default False

Restrict correlation to within scoped device groups.

-ExcludeDevices

Property Value
Type Boolean
Required No
Position 18
Pipeline input true (ByPropertyName)
Default False

Enable exclude devices feature.

-ActiveIncidentResponse

Property Value
Type Boolean
Required No
Position 19
Pipeline input true (ByPropertyName)
Default False

Enable Active Incident Response (DART).

-AggregatedReporting

Property Value
Type Boolean
Required No
Position 20
Pipeline input true (ByPropertyName)
Default False

Enable aggregated reporting.

-LowFidelityEnrichmentEnabled

Property Value
Type Boolean
Required No
Position 21
Pipeline input true (ByPropertyName)
Default False

Low fidelity enrichment enabled.

-IsolationExclusionRules

Property Value
Type Boolean
Required No
Position 22
Pipeline input true (ByPropertyName)
Default False

Enable isolation exclusion rules.

-DefaultToStreamlinedConnectivityWhenOnboardingDevicesInDefenderPortal

Property Value
Type Boolean
Required No
Position 23
Pipeline input true (ByPropertyName)
Default False

Default to streamlined connectivity when onboarding devices.

-ApplyStreamlinedConnectivitySettingsToDevicesManagedByIntuneAndDefenderForCloud

Property Value
Type Boolean
Required No
Position 24
Pipeline input true (ByPropertyName)
Default False

Apply streamlined connectivity settings to devices managed by Intune and Defender for Cloud.

-PreviewFeatures

Property Value
Type Boolean
Required No
Position 25
Pipeline input true (ByPropertyName)
Default False

Enable preview features.

-PurviewSharing

Property Value
Type Boolean
Required No
Position 26
Pipeline input true (ByPropertyName)
Default False

Enable Purview alert sharing.

-MicrosoftIntuneConnection

Property Value
Type Boolean
Required No
Position 27
Pipeline input true (ByPropertyName)
Default False

Enable Microsoft Intune connection to share onboarding information and threat levels.

-AuthenticatedTelemetry

Property Value
Type Boolean
Required No
Position 28
Pipeline input true (ByPropertyName)
Default False

Enable authenticated telemetry to prevent spoofing telemetry into your dashboard.

-LiveResponse

Property Value
Type Boolean
Required No
Position 29
Pipeline input true (ByPropertyName)
Default False

Enable Live Response.

-LiveResponseForServers

Property Value
Type Boolean
Required No
Position 30
Pipeline input true (ByPropertyName)
Default False

Enable Live Response for servers.

-LiveResponseUnsignedScriptExecution

Property Value
Type Boolean
Required No
Position 31
Pipeline input true (ByPropertyName)
Default False

Enable unsigned script execution in Live Response.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the command runs. The command is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before making changes.

Examples

Set-XdrEndpointAdvancedFeatures -EnableEDRInBlockMode $true
Enables EDR in block mode.
Set-XdrEndpointAdvancedFeatures -PreviewFeatures $true -WhatIf
Shows what would happen when enabling preview features without actually making the change.
Set-XdrEndpointAdvancedFeatures -LiveResponse $true -LiveResponseForServers $true
Enables Live Response for both workstations and servers.
Set-XdrEndpointAdvancedFeatures -MicrosoftIntuneConnection $true
Enables the Microsoft Intune connection.
Set-XdrEndpointAdvancedFeatures -AuthenticatedTelemetry $true
Enables authenticated telemetry.

View source