Jan 09 2024 05:07 AM
Hi,
I would like to know if there is a way to use PowerShell instead of the 365 portal in order to track user activity log (user timeline).
user timeline is really helpful but it would be great if I could use powershell to extract data for a specific user.
Kind regard,
GS
Jan 09 2024 06:05 AM - edited Jan 09 2024 06:06 AM
Hi @geostylianou,
retrieving the user activity timeline directly from Microsoft 365 Defender through PowerShell is not possible.
The Microsoft Defender for Endpoint device timeline provides a chronological presentation of events and associated alerts observed on a particular device.
While it allows exploration of specific events and endpoints for investigating potential attacks within the organization, it's important to know that this information is specific to devices and not individual users.
Microsoft Defender for Endpoint device timeline | Microsoft Learn
Please click Mark as Best Response & Like if my post helped you to solve your issue.
This will help others to find the correct solution easily. It also closes the item.
If the post was useful in other ways, please consider giving it Like.
Kindest regards,
Leon Pavesic
(LinkedIn)