Commands › Exchange Online
New-DeviceConditionalAccessPolicy
For more information, see Security & Compliance PowerShell. Use the New-DeviceConditionalAccessPolicy cmdlet to create mobile device conditional access policies in Basic Mobility and Security in Microsoft 365.
Quick start script
# New-DeviceConditionalAccessPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org
# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-DeviceConditionalAccessPolicy
$before | Format-List
# 3. Make the change (dry run first)
New-DeviceConditionalAccessPolicy -Name <String> -WhatIf
New-DeviceConditionalAccessPolicy -Name <String>
# 4. Verify and diff
$after = Get-DeviceConditionalAccessPolicy
Compare-Object ($before | Out-String) ($after | Out-String)
Syntax
New-DeviceConditionalAccessPolicy [-Name] <String>
[-Comment <String>]
[-Confirm]
[-Enabled <Boolean>]
[-Force]
[-WhatIf]
[<CommonParameters>]
Parameters (6)
Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.