Commands › Exchange Online

Get-DlpDetectionsReport

Exchange Online ExchangeOnlineManagement Get-*

**Note**: This cmdlet will be retired. Use the Export-ActivityExplorerData cmdlet to view DLP information. Data from Export-ActivityExplorerData is the same as the retired Get-DlpIncidentDetailReport cmdlet. Use the Get-DlpDetectionsReport cmdlet to list a summary of data loss prevention (DLP) rule matches for Exchange Online, SharePoint and OneDrive in your cloud-based organization for the last 30 days.

Quick start script

# Get-DlpDetectionsReport — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-DlpDetectionsReport | Format-List

# 3. Export for evidence / drift tracking
Get-DlpDetectionsReport | Export-Clixml .\DlpDetectionsReport-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-DlpDetectionsReport [-Action <MultiValuedProperty>]
 [-AggregateBy <String>]
 [-DlpCompliancePolicy <MultiValuedProperty>]
 [-DlpComplianceRule <MultiValuedProperty>]
 [-EndDate <DateTime>]
 [-Expression <Expression>]
 [-EventType <MultiValuedProperty>]
 [-Page <Int32>]
 [-PageSize <Int32>]
 [-Source <MultiValuedProperty>]
 [-StartDate <DateTime>]
 [-SummarizeBy <MultiValuedProperty>]
 [<CommonParameters>]

Parameters (12)

ParameterTypeRequiredWhat it controls
-Action MultiValuedProperty The Action parameter filters the report by the action taken by DLP policies. Valid values are:
-AggregateBy String The AggregateBy parameter specifies the reporting period. Valid values are Hour, Day, or Summary. The default value is Day.
-DlpCompliancePolicy MultiValuedProperty The DlpCompliancePolicy parameter filters the report by the name of the DLP compliance policy. You can specify multiple policies separated by commas.
-DlpComplianceRule MultiValuedProperty The DlpComplianceRule parameter filters the report by the name of the DLP compliance rule. You can specify multiple rules separated by commas.
-EndDate DateTime The EndDate parameter specifies the end date of the date range.
-EventType MultiValuedProperty The EventType parameter filters the report by the event type. Valid values are:
-Expression Expression This parameter is available only in Security & Compliance PowerShell
-Page Int32 The Page parameter specifies the page number of the results you want to view. Valid input for this parameter is an integer between 1 and 1000. The default value is 1.
-PageSize Int32 The PageSize parameter specifies the maximum number of entries per page. Valid input for this parameter is an integer between 1 and 5000. The default value is 1000.
-Source MultiValuedProperty The Source parameter filters the report by workload. Valid values are:
-StartDate DateTime The StartDate parameter specifies the start date of the date range.
-SummarizeBy MultiValuedProperty The SummarizeBy parameter returns totals based on the values you specify. If your report filters data using any of the values accepted by this parameter, you can use the SummarizeBy parameter to summarize the results...

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.