Commands › Exchange Online

Get-ConfigAnalyzerPolicyRecommendation

Exchange Online ExchangeOnlineManagement Get-*

Compare the settings in your existing security policies to the settings that are used in the Standard or Strict preset security policies. Settings that are below the recommend value are returned in the results.

Quick start script

# Get-ConfigAnalyzerPolicyRecommendation — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-ConfigAnalyzerPolicyRecommendation -RecommendedPolicyType <RecommendedPolicyType> | Format-List

# 3. Export for evidence / drift tracking
Get-ConfigAnalyzerPolicyRecommendation | Export-Clixml .\ConfigAnalyzerPolicyRecommendation-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-ConfigAnalyzerPolicyRecommendation -RecommendedPolicyType <RecommendedPolicyType>
 [[-Identity] <ConfigAnalyzerPolicyRecommendationIdParameter>]
 [-IsAppliedToDisabled]
 [<CommonParameters>]

Parameters (3)

ParameterTypeRequiredWhat it controls
-Identity ConfigAnalyzerPolicyRecommendationIdParameter This parameter is reserved for internal Microsoft use.
-RecommendedPolicyType RecommendedPolicyType yes The RecommendedPolicyType parameter specifies the preset security policy that you want to use as a baseline. Valid values are:
-IsAppliedToDisabled SwitchParameter The IsAppliedToDisabled switch filters the results by policies that aren't applied to anyone (the AppliedTo property is blank). You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.