← All XDRInternals commands

POWERSHELL COMMAND

Stop-XdrEndpointDeviceAction

Cancels a pending device action in Microsoft Defender XDR.

View source ↗

Cancels a device response action that is currently in a pending/submitted state. Uses the request GUID from the original action submission to identify the action to cancel.

Syntax

Stop-XdrEndpointDeviceAction [-RequestGuid] <string> [[-Comment] <string>] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-RequestGuid

Property Value
Type String
Required Yes
Position 1
Pipeline input No
Default Not documented

The GUID of the request to cancel. This is returned when an action is submitted.

-Comment

Property Value
Type String
Required No
Position 2
Pipeline input No
Default "Action cancelled - Performed by $env:USERNAME via XDRInternals"

A comment explaining the reason for the cancellation.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the command runs. The command is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before making changes.

Examples

Stop-XdrEndpointDeviceAction -RequestGuid "b28b630c-d1a1-4b1d-9676-680c15366a52" -Comment "Action no longer needed"
Cancels the specified device action with a comment.
Stop-XdrEndpointDeviceAction -RequestGuid "b28b630c-d1a1-4b1d-9676-680c15366a52"
Cancels the specified device action.

Output

Type: Object

Returns the API response.

View source