Defender for Endpoint

Download 23
Last updated Jun 30, 2024

defender-endpoint-machines

Get machines from Microsoft Defender for Endpoint service.

defender-endpoint-machines [profile=PROFILE]
profile=PROFILE
Defender endpoint connect profile code

Output Fields

FieldTypeNameDescription
machine_idStringMachine ID
private_ipIP addressPrivate IP
public_ipIP addressPublic IP
hostnameStringHostname
os_nameStringOS Namee.g. Windows11
os_verStringOS Versione.g. 22H2
os_archStringOS Architecturee.g. x64
os_buildStringOS Builde.g. 22621
device_valueStringDevice Valuee.g. Normal
risk_levelStringRisk Levele.g. None, Informational, Low, Medium, High
exposure_levelStringExposure Levele.g. None, Low, Medium, High
health_statusStringHealth Statuse.g. Active, Inactive, NoSensorData
onboarding_statusStringOnboarding Statuse.g. Onboarded, CanBeOnboarded, InsufficientInfo, Unsupported
defender_av_statusStringDefender AV Statuse.g. NotSupported, NotUpdated, Unknown, Updated
agent_versionStringAgent Versione.g. 1.1500
first_seenDateFirst Seen
last_seenDateLast Seen
risk_scoreIntegerRisk Scoree.g. 0, 1, 2, 3, 4
exposure_scoreIntegerExposure Scoree.g. 0, 1, 2, 3
entra_device_idStringENTRA Device ID
exclusion_reasonStringExclusion Reasone.g. DeviceDoesNotExist, DuplicateDevice
is_entra_joinedBoolIs ENTRA Joined
is_excludedBoolIs Excluded
is_potential_duplicationBoolIs Potential Duplication
machine_tagsStringMachine Tags
managed_byStringManaged Bye.g. Unknown
managed_by_statusStringManaged By Statuse.g. Unknown
rbac_group_idIntegerRBAC Group ID
rbac_group_nameStringRBAC Group Name
nicsListNICs