Commands › Exchange Online

Set-ActiveSyncDeviceAutoblockThreshold

Exchange Online ExchangeOnlineManagement Set-*

Change settings for autoblocking mobile devices.

Quick start script

# Set-ActiveSyncDeviceAutoblockThreshold — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-ActiveSyncDeviceAutoblockThreshold
$before | Format-List

# 3. Make the change (dry run first)
Set-ActiveSyncDeviceAutoblockThreshold -Identity <ActiveSyncDeviceAutoblockThresholdIdParameter> -WhatIf
Set-ActiveSyncDeviceAutoblockThreshold -Identity <ActiveSyncDeviceAutoblockThresholdIdParameter>

# 4. Verify and diff
$after = Get-ActiveSyncDeviceAutoblockThreshold
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

Set-ActiveSyncDeviceAutoblockThreshold [-Identity] <ActiveSyncDeviceAutoblockThresholdIdParameter>
 [-AdminEmailInsert <String>]
 [-BehaviorTypeIncidenceDuration <EnhancedTimeSpan>]
 [-BehaviorTypeIncidenceLimit <Int32>]
 [-Confirm]
 [-DeviceBlockDuration <EnhancedTimeSpan>]
 [-DomainController <Fqdn>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (8)

ParameterTypeRequiredWhat it controls
-Identity ActiveSyncDeviceAutoblockThresholdIdParameter yes The Identity parameter specifies the name of the autoblock threshold rule.
-AdminEmailInsert String The AdminEmailInsert parameter specifies the text to include in the email sent to the user when a mobile device triggers an autoblock threshold rule.
-BehaviorTypeIncidenceDuration EnhancedTimeSpan The BehaviorTypeIncidenceDuration parameter specifies the interval (in minutes) within which the BehaviorType must occur to trigger the autoblock rule.
-BehaviorTypeIncidenceLimit Int32 The BehaviorTypeIncidenceLimit parameter specifies the number of occurrences of the behavior type needed to trigger blocking.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-DeviceBlockDuration EnhancedTimeSpan The DeviceBlockDuration parameter specifies the length of time (in minutes) that the mobile device is blocked.
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.