PowerShell新手技术问询:如何筛选Microsoft Defender处于Passive状态的Intune设备
Hey there! As a fellow PowerShell user who's worked with Intune and Defender, let's get this sorted for you.
The command you're already using gives you the AMRunning status, and filtering for "Passive" is straightforward with PowerShell's Where-Object cmdlet—this is the go-to tool for filtering objects based on specific property values.
Basic Filter Command
Here's the simplest way to get only devices where Defender is in Passive mode:
GetMPComputerStatus | Where-Object { $_.AMRunning -eq "Passive" }
Let me break this down:
GetMPComputerStatusretrieves the Defender status dataWhere-Object { $_.AMRunning -eq "Passive" }checks each result'sAMRunningproperty and keeps only those that match "Passive"
Get More Context (Optional)
If you want to see additional details like the device name or whether the Defender service is enabled, expand the command with Select-Object to pick specific properties:
GetMPComputerStatus | Where-Object { $_.AMRunning -eq "Passive" } | Select-Object ComputerName, AMRunning, AMServiceEnabled, QuickScanLastRun
This will give you a more useful output that ties the Passive status to the actual device and other relevant Defender metrics.
Note for Intune Management
If you're working with a fleet of Intune-managed devices, you might need to run this command remotely across devices (using tools like Invoke-Command or Intune's dedicated PowerShell modules). But the core filtering logic using Where-Object stays the same regardless of how you retrieve the Defender status data.
内容的提问来源于stack exchange,提问作者ProgramToddler

