Commands › Exchange Online

New-DlpPolicy

Exchange Online ExchangeOnlineManagement New-*

**Note**: This cmdlet is retired from the cloud-based service. For more information, see this blog post. Use the New-DlpCompliancePolicy and New-DlpComplianceRule cmdlets instead. This cmdlet is functional only in on-premises Exchange. Use the New-DlpPolicy cmdlet to create data loss prevention (DLP) policies that are based on transport rules (mail flow rules) in your organization.

Quick start script

# New-DlpPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-DlpPolicy
$before | Format-List

# 3. Make the change (dry run first)
New-DlpPolicy  -WhatIf
New-DlpPolicy

# 4. Verify and diff
$after = Get-DlpPolicy
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

New-DlpPolicy [[-Name] <String>]
 [-Confirm]
 [-Description <String>]
 [-DomainController <Fqdn>]
 [-Mode <RuleMode>]
 [-Parameters <Hashtable>]
 [-State <RuleState>]
 [-Template <String>]
 [-TemplateData <Byte[]>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (10)

ParameterTypeRequiredWhat it controls
-Name String The Name parameter specifies a descriptive name for the DLP policy.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-Description String The Description parameter specifies an optional description for the DLP policy.
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-Mode RuleMode The Mode parameter specifies the action and notification level of the DLP policy. Valid values for this parameter are:
-Parameters Hashtable The Parameters parameter specifies the parameter values that are required by the DLP policy template that you specify using the Template or TemplateData parameters. DLP policy templates might contain parameters that...
-State RuleState The State parameter enables or disables the DLP policy. Valid input for this parameter is Enabled or Disabled. By default, a new DLP policy that you create is enabled. If you want to create a disabled DLP policy,...
-Template String The Template parameter specifies the existing DLP policy template from which you can create a new DLP policy. You can't use the Template and TemplateData parameters in the same command.
-TemplateData Byte[] The TemplateData parameter specifies an external DLP policy template file from which you can create a new DLP policy. You can't use the TemplateData and Template parameters in the same command.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.