Commands › Exchange Online

New-TenantAllowBlockListItems

Exchange Online ExchangeOnlineManagement New-*

Add entries to the Tenant Allow/Block List in the Microsoft Defender portal.

Quick start script

# New-TenantAllowBlockListItems — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-TenantAllowBlockListItems
$before | Format-List

# 3. Make the change
New-TenantAllowBlockListItems -Entries <String[]> -ListType <ListType> -NoExpiration <SwitchParameter>

# 4. Verify and diff
$after = Get-TenantAllowBlockListItems
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax — 2 parameter sets

Expiration

New-TenantAllowBlockListItems -Entries <String[]> -ListType <ListType> [-ExpirationDate <DateTime>]
 [-Allow]
 [-Block]
 [-ListSubType <ListSubType>]
 [-LogExtraDetails]
 [-Notes <String>]
 [-OutputJson]
 [-RemoveAfter <Int32>]
 [-SubmissionID <String>]
 [<CommonParameters>]

NoExpiration

New-TenantAllowBlockListItems -Entries <String[]> -ListType <ListType> [-NoExpiration]
 [-Allow]
 [-Block]
 [-ListSubType <ListSubType>]
 [-LogExtraDetails]
 [-Notes <String>]
 [-OutputJson]
 [-RemoveAfter <Int32>]
 [-SubmissionID <String>]
 [<CommonParameters>]

Parameters (12)

ParameterTypeRequiredWhat it controls
-Entries String[] yes The Entries parameter specifies the values that you want to add to the Tenant Allow/Block List based on the ListType parameter value:
-ExpirationDate DateTime The ExpirationDate parameter set the expiration date of the entry in Coordinated Universal Time (UTC).
-ListType ListType yes The ListType parameter specifies the type of entry to add. Valid values are:
-NoExpiration SwitchParameter yes The NoExpiration switch specifies that the entry should never expire. You don't need to specify a value with this switch.
-Allow SwitchParameter The Allow switch specifies that you're creating an allow entry. You don't need to specify a value with this switch.
-Block SwitchParameter The Allow switch specifies that you're creating a block entry. You don't need to specify a value with this switch.
-ListSubType ListSubType The ListSubType parameter specifies the subtype for this entry. Valid values are:
-LogExtraDetails SwitchParameter {{ Fill LogExtraDetails Description }}
-Notes String The Notes parameters specifies additional information about the object. If the value contains spaces, enclose the value in quotation marks ("). If the value contains quotation marks, add a backslash ( \ ) before the...
-RemoveAfter Int32 The RemoveAfter parameter enables the **Remove on** \> **45 days after last used date** feature for an allow entry. The LastUsedDate property is populated when the bad entity in the allow entry is encountered by the...
-OutputJson SwitchParameter The OutputJson switch specifies whether to return all entries in a single JSON value. You don't need to specify a value with this switch.
-SubmissionID String This parameter is reserved for internal Microsoft use.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.