Commands › Exchange Online

Get-ATPBuiltInProtectionRule

Exchange Online ExchangeOnlineManagement Get-*

View the rule for the Built-in protection preset security policy that effectively provides default policies for Safe Links and Safe Attachments in Microsoft Defender for Office 365. The rule specifies exceptions to the policy.

Quick start script

# Get-ATPBuiltInProtectionRule — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-ATPBuiltInProtectionRule | Format-List

# 3. Export for evidence / drift tracking
Get-ATPBuiltInProtectionRule | Export-Clixml .\ATPBuiltInProtectionRule-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-ATPBuiltInProtectionRule [[-Identity] <DehydrateableRuleIdParameter>] [-State <RuleState>] [<CommonParameters>]

Parameters (2)

ParameterTypeRequiredWhat it controls
-Identity DehydrateableRuleIdParameter The Identity parameter specifies the rule that you want to view. You can use any value that uniquely identifies the rule. For example:
-State RuleState The State parameter filters the results by the state of the rule. Valid values are:

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.