Commands › Exchange Online

Enable-ExchangeCertificate

Exchange Online ExchangeOnlineManagement Enable-*

Enable an existing certificate on the Exchange server for Exchange services such as Internet Information Services (IIS), SMTP, POP, IMAP and Unified Messaging (UM). Once you enable a certificate for a service, you can't disable it. To see the existing certificates that are used for Exchange services, use Get-ExchangeCertificate.

Quick start script

# Enable-ExchangeCertificate — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-ExchangeCertificate
$before | Format-List

# 3. Make the change (dry run first)
Enable-ExchangeCertificate -Thumbprint <String> -Services <AllowedServices> -WhatIf
Enable-ExchangeCertificate -Thumbprint <String> -Services <AllowedServices>

# 4. Verify and diff
$after = Get-ExchangeCertificate
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax — 2 parameter sets

Thumbprint

Enable-ExchangeCertificate [-Thumbprint] <String> -Services <AllowedServices>
 [-Confirm]
 [-DomainController <Fqdn>]
 [-DoNotRequireSsl]
 [-Force]
 [-NetworkServiceAllowed]
 [-Server <ServerIdParameter>]
 [-WhatIf]
 [<CommonParameters>]

Identity

Enable-ExchangeCertificate [[-Identity] <ExchangeCertificateIdParameter>] -Services <AllowedServices>
 [-Confirm]
 [-DomainController <Fqdn>]
 [-DoNotRequireSsl]
 [-Force]
 [-NetworkServiceAllowed]
 [-WhatIf]
 [<CommonParameters>]

Parameters (10)

ParameterTypeRequiredWhat it controls
-Thumbprint String yes The Thumbprint parameter specifies the certificate that you want to configure. You can find the thumbprint value by using the Get-ExchangeCertificate cmdlet.
-Identity ExchangeCertificateIdParameter The Identity parameter specifies the certificate that you want to configure. Valid values are:
-Services AllowedServices yes The Services parameter specifies the Exchange services that the certificate is enabled for. Valid values are:
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-DoNotRequireSsl SwitchParameter The DoNotRequireSsl switch prevents the command from enabling the "Require SSL" setting on the default web site when you enable the certificate for IIS. You don't need to specify a value with this switch.
-Force SwitchParameter The Force switch hides warning or confirmation messages. You don't need to specify a value with this switch.
-NetworkServiceAllowed SwitchParameter The NetworkServiceAllowed switch gives the built-in Network Service account permission to read the certificate's private key without enabling the certificate for SMTP. You don't need to specify a value with this switch.
-Server ServerIdParameter The Server parameter specifies the Exchange server where you want to run this command. You can use any value that uniquely identifies the server. For example:
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.