POWERSHELL COMMAND
Stop-XdrEndpointDeviceAction
Cancels a pending device action in Microsoft Defender XDR.
Cancels a device response action that is currently in a pending/submitted state. Uses the request GUID from the original action submission to identify the action to cancel.
Syntax
Stop-XdrEndpointDeviceAction [-RequestGuid] <string> [[-Comment] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-RequestGuid
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The GUID of the request to cancel. This is returned when an action is submitted.
-Comment
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | "Action cancelled - Performed by $env:USERNAME via XDRInternals" |
A comment explaining the reason for the cancellation.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the command runs. The command is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before making changes.
Examples
Stop-XdrEndpointDeviceAction -RequestGuid "b28b630c-d1a1-4b1d-9676-680c15366a52" -Comment "Action no longer needed"
Cancels the specified device action with a comment.
Stop-XdrEndpointDeviceAction -RequestGuid "b28b630c-d1a1-4b1d-9676-680c15366a52"
Cancels the specified device action.
Output
Type: Object
Returns the API response.