The timeline of comments and audit events associated with the case.
Supports $expand.
To construct, see NOTES section for ACTIVITIES properties and create a hash table.
Evidence files and metadata associated with the case.
Supports $expand.
To construct, see NOTES section for ATTACHMENTS properties and create a hash table.
The tenant-defined lifecycle status of the case.
Use a displayName value returned in the status tree by List statuses from /security/caseManagement/caseTypeConfigurations/genericCase/statuses or /security/caseManagement/caseTypeConfigurations/incidentCase/statuses, depending on the case type.
Supports $filter (eq).
Parameter properties
Type:
System.String
Supports wildcards:
False
DontShow:
False
Parameter sets
CreateExpanded
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
-Tasks
Tasks used to track work required to resolve the case.
Supports $expand.
To construct, see NOTES section for TASKS properties and create a hash table.
Runs the command in a mode that only reports what would happen without performing the actions.
Parameter properties
Type:
System.Management.Automation.SwitchParameter
Supports wildcards:
False
DontShow:
False
Aliases:
wi
Parameter sets
(All)
Position:
Named
Mandatory:
False
Value from pipeline:
False
Value from pipeline by property name:
False
Value from remaining arguments:
False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable,
-InformationAction, -InformationVariable, -OutBuffer, -OutVariable, -PipelineVariable,
-ProgressAction, -Verbose, -WarningAction, and -WarningVariable. For more information, see
about_CommonParameters.
To create the parameters described below, construct a hash table containing the appropriate properties.
For information on hash tables, run Get-Help about_Hash_Tables.
ACTIVITIES <IMicrosoftGraphSecurityCaseManagementActivity[]>: The timeline of comments and audit events associated with the case.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
ATTACHMENTS <IMicrosoftGraphSecurityCaseManagementAttachment[]>: Evidence files and metadata associated with the case.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[Content <Byte[]>]: The binary content stream for the attachment.
Use the Upload content and Download content methods to access it.
[Description <String>]: The description of the attachment.
[DisplayName <String>]: The display name of the attachment.
[FileExtension <String>]: The file extension of the attachment.
The service normalizes the value to include a leading period.
[FileSize <Int64?>]: The size of the attachment in bytes.
The maximum file size is 100 MB.
[Origin <IMicrosoftGraphSecurityCaseManagementAttachmentOrigin>]: attachmentOrigin
[(Any) <Object>]: This indicates any property can be added to this object.
[ResourceId <String>]: The identifier of the origin resource.
[ResourceType <String>]: attachmentOriginType
[ScanResult <String>]: attachmentScanResult
BODYPARAMETER <IMicrosoftGraphSecurityCaseManagementCase>: case
[(Any) <Object>]: This indicates any property can be added to this object.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[Activities <IMicrosoftGraphSecurityCaseManagementActivity[]>]: The timeline of comments and audit events associated with the case.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[Attachments <IMicrosoftGraphSecurityCaseManagementAttachment[]>]: Evidence files and metadata associated with the case.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[Content <Byte[]>]: The binary content stream for the attachment.
Use the Upload content and Download content methods to access it.
[Description <String>]: The description of the attachment.
[DisplayName <String>]: The display name of the attachment.
[FileExtension <String>]: The file extension of the attachment.
The service normalizes the value to include a leading period.
[FileSize <Int64?>]: The size of the attachment in bytes.
The maximum file size is 100 MB.
[Origin <IMicrosoftGraphSecurityCaseManagementAttachmentOrigin>]: attachmentOrigin
[(Any) <Object>]: This indicates any property can be added to this object.
[ResourceId <String>]: The identifier of the origin resource.
[ResourceType <String>]: attachmentOriginType
[ScanResult <String>]: attachmentScanResult
[CustomFields <IMicrosoftGraphSecurityCaseManagementCustomFieldValues>]: customFieldValues
[(Any) <Object>]: This indicates any property can be added to this object.
[DisplayName <String>]: The display name of the case.
Supports $filter and $orderby.
[Relations <IMicrosoftGraphSecurityCaseManagementRelation[]>]: Links from the case to related security resources.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[RelatedResourceId <String>]: The identifier of the related external resource.
[Status <String>]: The tenant-defined lifecycle status of the case.
Use a displayName value returned in the status tree by List statuses from /security/caseManagement/caseTypeConfigurations/genericCase/statuses or /security/caseManagement/caseTypeConfigurations/incidentCase/statuses, depending on the case type.
Supports $filter (eq).
[Tasks <IMicrosoftGraphSecurityCaseManagementTask[]>]: Tasks used to track work required to resolve the case.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[AssignedTo <String>]: The user assigned to the task.
Supports $filter.
[Category <String>]: caseTaskCategory
[ClosingNotes <String>]: Notes recorded when the task is completed.
Supports $filter.
[Description <String>]: The description of the task.
Supports $filter.
[DisplayName <String>]: The title of the task.
Supports $filter.
[DueDateTime <DateTime?>]: The target completion date and time for the task.
Supports $filter.
[Priority <String>]: caseTaskPriority
[Status <String>]: taskStatus
RELATIONS <IMicrosoftGraphSecurityCaseManagementRelation[]>: Links from the case to related security resources.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[RelatedResourceId <String>]: The identifier of the related external resource.
TASKS <IMicrosoftGraphSecurityCaseManagementTask[]>: Tasks used to track work required to resolve the case.
Supports $expand.
[CreatedBy <String>]: The user or service that created the resource.
[CreatedDateTime <DateTime?>]: The date and time when the resource was created.
[LastModifiedBy <String>]: The user or service that last modified the resource.
[LastModifiedDateTime <DateTime?>]: The date and time when the resource was last modified.
[Id <String>]: The unique identifier for an entity.
Read-only.
[AssignedTo <String>]: The user assigned to the task.
Supports $filter.
[Category <String>]: caseTaskCategory
[ClosingNotes <String>]: Notes recorded when the task is completed.
Supports $filter.
[Description <String>]: The description of the task.
Supports $filter.
[DisplayName <String>]: The title of the task.
Supports $filter.
[DueDateTime <DateTime?>]: The target completion date and time for the task.
Supports $filter.
[Priority <String>]: caseTaskPriority
[Status <String>]: taskStatus