POWERSHELL COMMAND
Set-XdrEndpointDeviceExclusionState
Sets the exclusion state on endpoint devices in Microsoft Defender XDR.
Updates the exclusion state for one or more endpoint devices. Devices can be excluded from or included in Defender for Endpoint monitoring.
Syntax
Set-XdrEndpointDeviceExclusionState [-DeviceId] <string[]> [-ExclusionState] <string> [[-Justification] <string>] [[-Notes] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-DeviceId
| Property | Value |
|---|---|
| Type | String[] |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByPropertyName) |
| Default | Not documented |
One or more device IDs (SenseMachineIds) identifying the target devices.
-ExclusionState
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The exclusion state to set. Valid values: Excluded, Included.
-Justification
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Not documented |
Justification for the exclusion state change. Required when excluding devices.
-Notes
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | Not documented |
Additional notes for the exclusion state change.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the command runs. The command is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before making changes.
Examples
Set-XdrEndpointDeviceExclusionState -DeviceId "abc123" -ExclusionState Excluded -Justification "MachineOutOfScope" -Notes "Lab device"
Excludes the device with a justification and notes.
Set-XdrEndpointDeviceExclusionState -DeviceId "abc123" -ExclusionState Included
Re-includes a previously excluded device.
Output
Type: Object
Returns the API response.