Commands › Exchange Online

Get-MailTrafficATPReport

Exchange Online ExchangeOnlineManagement Get-*

View the results of Microsoft Defender for Office 365 detections in your cloud-based organization for the last 90 days.

Quick start script

# Get-MailTrafficATPReport — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Get-MailTrafficATPReport | Format-List

# 3. Export for evidence / drift tracking
Get-MailTrafficATPReport | Export-Clixml .\MailTrafficATPReport-$(Get-Date -Format yyyyMMdd).xml

Syntax

Get-MailTrafficATPReport
 [-Action <MultiValuedProperty>]
 [-AggregateBy <String>]
 [-Direction <MultiValuedProperty>]
 [-Domain <MultiValuedProperty>]
 [-EndDate <DateTime>]
 [-EventType <MultiValuedProperty>]
 [-NumberOfRows <Int32>]
 [-Page <Int32>]
 [-PageSize <Int32>]
 [-PivotBy <MultiValuedProperty>]
 [-ProbeTag <String>]
 [-StartDate <DateTime>]
 [-SummarizeBy <MultiValuedProperty>]
 [-ThreatClassification <MultiValuedProperty>]
 [<CommonParameters>]

Parameters (14)

ParameterTypeRequiredWhat it controls
-Action MultiValuedProperty The Action parameter filters the report by the action taken on messages. To view the complete list of valid values for this parameter, run the command: `Get-MailFilterListReport -SelectionTarget Actions`. The action...
-AggregateBy String The AggregateBy parameter specifies the reporting period. Valid values are Hour, Day, or Summary. The default value is Day.
-Direction MultiValuedProperty The Direction parameter filters the results by incoming or outgoing messages. Valid values are:
-Domain MultiValuedProperty The Domain parameter filters the results by an accepted domain in the cloud-based organization. You can specify multiple domain values separated by commas.
-EndDate DateTime The EndDate parameter specifies the end of the date range in Coordinated Universal Time (UTC).
-EventType MultiValuedProperty The EventType parameter filters the report by the event type. Valid values are:
-NumberOfRows Int32 The NumberOfRows parameter specifies the number of rows to return in the report. The maximum value is 10000.
-Page Int32 The Page parameter specifies the page number of the results you want to view. Valid input for this parameter is an integer between 1 and 1000. The default value is 1.
-PageSize Int32 The PageSize parameter specifies the maximum number of entries per page. Valid input for this parameter is an integer between 1 and 5000. The default value is 1000.
-PivotBy MultiValuedProperty {{ Fill PivotBy Description }}
-ProbeTag String This parameter is reserved for internal Microsoft use.
-StartDate DateTime The StartDate parameter specifies the start of the date range in Coordinated Universal Time (UTC).
-SummarizeBy MultiValuedProperty The SummarizeBy parameter returns totals based on the values you specify. If your report filters data using any of the values accepted by this parameter, you can use the SummarizeBy parameter to summarize the results...
-ThreatClassification MultiValuedProperty {{ Fill ThreatClassification Description }}

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.