Commands › Exchange Online

New-ManagementRole

Exchange Online ExchangeOnlineManagement New-*

Create a management role based on an existing role or create an unscoped management role.

Quick start script

# New-ManagementRole — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-ManagementRole
$before | Format-List

# 3. Make the change (dry run first)
New-ManagementRole -Name <String> -Parent <RoleIdParameter> -UnScopedTopLevel <SwitchParameter> -WhatIf
New-ManagementRole -Name <String> -Parent <RoleIdParameter> -UnScopedTopLevel <SwitchParameter>

# 4. Verify and diff
$after = Get-ManagementRole
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax — 2 parameter sets

NewDerivedRole

New-ManagementRole [-Name] <String> -Parent <RoleIdParameter>
 [-EnabledCmdlets <String[]>]
 [-Confirm]
 [-Description <String>]
 [-DomainController <Fqdn>]
 [-Force]
 [-WhatIf]
 [<CommonParameters>]

UnScopedTopLevelRole

New-ManagementRole [-Name] <String>
 [-UnScopedTopLevel]
 [-Confirm]
 [-Description <String>]
 [-DomainController <Fqdn>]
 [-Force]
 [-WhatIf]
 [<CommonParameters>]

Parameters (9)

ParameterTypeRequiredWhat it controls
-Name String yes The Name parameter specifies the name of the role. The maximum length of the name is 64 characters. If the name contains spaces, enclose the name in quotation marks (").
-Parent RoleIdParameter yes The Parent parameter specifies the identity of the role to copy. If the name of the role contains spaces, enclose the name in quotation marks ("). If you specify the Parent parameter, you can't use the...
-UnScopedTopLevel SwitchParameter yes This parameter is available only in on-premises Exchange.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-Description String The Description parameter specifies the description that's displayed when the management role is viewed using the Get-ManagementRole cmdlet. Enclose the description in quotation marks (").
-DomainController Fqdn This parameter is available only in on-premises Exchange.
-EnabledCmdlets String[] The EnabledCmdlets parameter specifies the cmdlets that are copied from the parent role. You can specify multiple values separated by commas.
-Force SwitchParameter This parameter is available only in the cloud-based service.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.