Commands › Exchange Online

Remove-ExchangeCertificate

Exchange Online ExchangeOnlineManagement Remove-*

Remove existing Exchange certificates or pending certificate requests (also known as certificate signing requests or CSRs) from Exchange servers.

Quick start script

# Remove-ExchangeCertificate — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-ExchangeCertificate
$before | Format-List

# 3. Make the change (dry run first)
Remove-ExchangeCertificate -Thumbprint <String> -WhatIf
Remove-ExchangeCertificate -Thumbprint <String>

# 4. Verify and diff
$after = Get-ExchangeCertificate
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax — 2 parameter sets

Thumbprint

Remove-ExchangeCertificate [-Thumbprint] <String>
 [-Server <ServerIdParameter>]
 [-Confirm]
 [-DomainController <Fqdn>]
 [-WhatIf]
 [<CommonParameters>]

Identity

Remove-ExchangeCertificate [[-Identity] <ExchangeCertificateIdParameter>]
 [-Confirm]
 [-DomainController <Fqdn>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (6)

ParameterTypeRequiredWhat it controls
-Thumbprint String yes The Thumbprint parameter specifies the certificate that you want to remove. You can find the thumbprint value by using the Get-ExchangeCertificate cmdlet.
-Identity ExchangeCertificateIdParameter The Identity parameter specifies the certificate that you want to remove. Valid values are:
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-Server ServerIdParameter The Server parameter specifies the Exchange server where you want to run this command. You can use any value that uniquely identifies the server. For example:
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.