POWERSHELL COMMAND
Set-XdrIdentityConfigurationRemediationActionAccount
Configures the remediation action account type for Microsoft Defender for Identity.
Sets whether Microsoft Defender for Identity uses the Local System account or a dedicated account for remediation actions. This configuration determines which account type is used when MDI performs automatic remediation actions on identified threats.
Syntax
Set-XdrIdentityConfigurationRemediationActionAccount [[-UseLocalSystem] <bool>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-UseLocalSystem
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 1 |
| Pipeline input | No |
| Default | True |
Boolean parameter that controls whether remediation actions use the Local System account. Defaults to $true. Use -UseLocalSystem:$false to configure a dedicated remediation account.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before creating each rule.
Examples
Set-XdrIdentityConfigurationRemediationActionAccount -UseLocalSystem:$true
Configures MDI to use the Local System account for remediation actions.
Set-XdrIdentityConfigurationRemediationActionAccount -UseLocalSystem:$false
Configures MDI to use a dedicated account for remediation actions.
Output
Type: Object
Returns the configuration response from the API.