Commands › Exchange Online

New-DataEncryptionPolicy

Exchange Online ExchangeOnlineManagement New-*

Create data encryption policies in Exchange Online.

Quick start script

# New-DataEncryptionPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-DataEncryptionPolicy
$before | Format-List

# 3. Make the change (dry run first)
New-DataEncryptionPolicy -Name <String> -AzureKeyIDs <MultiValuedProperty> -WhatIf
New-DataEncryptionPolicy -Name <String> -AzureKeyIDs <MultiValuedProperty>

# 4. Verify and diff
$after = Get-DataEncryptionPolicy
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

New-DataEncryptionPolicy [-Name] <String> -AzureKeyIDs <MultiValuedProperty>
 [-Confirm]
 [-Description <String>]
 [-DomainController <Fqdn>]
 [-Enabled <Boolean>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (7)

ParameterTypeRequiredWhat it controls
-Name String yes The Name parameter specifies the unique name for the data encryption policy. If the value contains spaces, enclose the value in quotation marks.
-AzureKeyIDs MultiValuedProperty yes The AzureKeyIDs parameter specifies the URI values of the Azure Key Vault keys to associate with the data encryption policy. You need to specify at least two Azure Key Vault keys separated by commas. For example,...
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-Description String The Description parameter specifies an optional description for the data encryption policy. If the value contains spaces, enclose the value in quotation marks.
-DomainController Fqdn This parameter is reserved for internal Microsoft use.
-Enabled Boolean The Enabled parameter enables or disable the data encryption policy. Valid values are:
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.