Commands › Exchange Online

Remove-ATPProtectionPolicyRule

Exchange Online ExchangeOnlineManagement Remove-*

Remove rules from Microsoft Defender for Office 365 protections in preset security policies. The rules specify recipient conditions and exceptions for the protection, and also allow you to turn on and turn off the associated preset security policies. **Note**: Use this cmdlet to remove a rule only if you plan to immediately recreate the rule using the New-ATPProtectionPolicyRule cmdlet. The affected preset security policy doesn't function without a corresponding rule.

Quick start script

# Remove-ATPProtectionPolicyRule — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-ATPProtectionPolicyRule
$before | Format-List

# 3. Make the change (dry run first)
Remove-ATPProtectionPolicyRule -Identity <RuleIdParameter> -WhatIf
Remove-ATPProtectionPolicyRule -Identity <RuleIdParameter>

# 4. Verify and diff
$after = Get-ATPProtectionPolicyRule
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

Remove-ATPProtectionPolicyRule [-Identity] <RuleIdParameter>
 [-Confirm]
 [-WhatIf]
 [<CommonParameters>]

Parameters (3)

ParameterTypeRequiredWhat it controls
-Identity RuleIdParameter yes The Identity parameter specifies the rule that you want to remove. You can use any value that uniquely identifies the rule. For example:
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.