POWERSHELL COMMAND
Set-XdrEndpointAdvancedFeatures
Configures advanced features settings for Microsoft Defender for Endpoint.
Sets advanced features configuration for Microsoft Defender for Endpoint. This function updates various advanced features across different configuration endpoints.
Note: AlwaysRemediatePUA and EnableAutomaticAttackDisruption cannot be changed through this function as they are part of PotentiallyUnwantedApplications which is read-only.
Syntax
Set-XdrEndpointAdvancedFeatures [[-EnableEDRInBlockMode] <bool>] [[-EnableMicrosoftDefenderAntivirusInAuditMode] <bool>] [[-DeviceDiscovery] <bool>] [[-HidePotentialDuplicateDeviceRecords] <bool>] [[-AllowOrBlockFile] <bool>] [[-SkypeForBusinessIntegration] <bool>] [[-ShowUserDetails] <bool>] [[-MicrosoftDefenderForIdentityIntegration] <bool>] [[-AutomaticallyResolveAlerts] <bool>] [[-MicrosoftDefenderForCloudApps] <bool>] [[-AzureInformationProtection] <bool>] [[-TamperProtection] <bool>] [[-CustomNetworkIndicators] <bool>] [[-WebContentFiltering] <bool>] [[-MicrosoftEndpointDLP] <bool>] [[-DownloadQuarantinedFiles] <bool>] [[-RestrictCorrelationToWithinScopedDeviceGroups] <bool>] [[-ExcludeDevices] <bool>] [[-ActiveIncidentResponse] <bool>] [[-AggregatedReporting] <bool>] [[-LowFidelityEnrichmentEnabled] <bool>] [[-IsolationExclusionRules] <bool>] [[-DefaultToStreamlinedConnectivityWhenOnboardingDevicesInDefenderPortal] <bool>] [[-ApplyStreamlinedConnectivitySettingsToDevicesManagedByIntuneAndDefenderForCloud] <bool>] [[-PreviewFeatures] <bool>] [[-PurviewSharing] <bool>] [[-MicrosoftIntuneConnection] <bool>] [[-AuthenticatedTelemetry] <bool>] [[-LiveResponse] <bool>] [[-LiveResponseForServers] <bool>] [[-LiveResponseUnsignedScriptExecution] <bool>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-EnableEDRInBlockMode
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable EDR in block mode.
-EnableMicrosoftDefenderAntivirusInAuditMode
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 2 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Microsoft Defender Antivirus in audit mode.
-DeviceDiscovery
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 3 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable device discovery.
-HidePotentialDuplicateDeviceRecords
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 4 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Hide potential duplicate device records.
-AllowOrBlockFile
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 5 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable allow or block file feature.
-SkypeForBusinessIntegration
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 6 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Skype for Business integration.
-ShowUserDetails
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 7 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Show user details.
-MicrosoftDefenderForIdentityIntegration
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 8 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Microsoft Defender for Identity integration.
-AutomaticallyResolveAlerts
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 9 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Automatically resolve alerts.
-MicrosoftDefenderForCloudApps
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 10 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Microsoft Defender for Cloud Apps integration.
-AzureInformationProtection
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 11 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Azure Information Protection integration.
-TamperProtection
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 12 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable tamper protection.
-CustomNetworkIndicators
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 13 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable custom network indicators.
-WebContentFiltering
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 14 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable web content filtering.
-MicrosoftEndpointDLP
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 15 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Microsoft Endpoint DLP.
-DownloadQuarantinedFiles
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 16 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable download of quarantined files.
-RestrictCorrelationToWithinScopedDeviceGroups
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 17 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Restrict correlation to within scoped device groups.
-ExcludeDevices
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 18 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable exclude devices feature.
-ActiveIncidentResponse
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 19 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Active Incident Response (DART).
-AggregatedReporting
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 20 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable aggregated reporting.
-LowFidelityEnrichmentEnabled
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 21 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Low fidelity enrichment enabled.
-IsolationExclusionRules
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 22 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable isolation exclusion rules.
-DefaultToStreamlinedConnectivityWhenOnboardingDevicesInDefenderPortal
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 23 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Default to streamlined connectivity when onboarding devices.
-ApplyStreamlinedConnectivitySettingsToDevicesManagedByIntuneAndDefenderForCloud
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 24 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Apply streamlined connectivity settings to devices managed by Intune and Defender for Cloud.
-PreviewFeatures
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 25 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable preview features.
-PurviewSharing
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 26 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Purview alert sharing.
-MicrosoftIntuneConnection
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 27 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Microsoft Intune connection to share onboarding information and threat levels.
-AuthenticatedTelemetry
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 28 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable authenticated telemetry to prevent spoofing telemetry into your dashboard.
-LiveResponse
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 29 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Live Response.
-LiveResponseForServers
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 30 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable Live Response for servers.
-LiveResponseUnsignedScriptExecution
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 31 |
| Pipeline input | true (ByPropertyName) |
| Default | False |
Enable unsigned script execution in Live Response.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the command runs. The command is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before making changes.
Examples
Set-XdrEndpointAdvancedFeatures -EnableEDRInBlockMode $true
Enables EDR in block mode.
Set-XdrEndpointAdvancedFeatures -PreviewFeatures $true -WhatIf
Shows what would happen when enabling preview features without actually making the change.
Set-XdrEndpointAdvancedFeatures -LiveResponse $true -LiveResponseForServers $true
Enables Live Response for both workstations and servers.
Set-XdrEndpointAdvancedFeatures -MicrosoftIntuneConnection $true
Enables the Microsoft Intune connection.
Set-XdrEndpointAdvancedFeatures -AuthenticatedTelemetry $true
Enables authenticated telemetry.