Commands › Exchange Online

Set-AuthenticationPolicy

Exchange Online ExchangeOnlineManagement Set-*

Modify authentication policies in your organization.

Quick start script

# Set-AuthenticationPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-AuthenticationPolicy
$before | Format-List

# 3. Make the change (dry run first)
Set-AuthenticationPolicy -Identity <AuthPolicyIdParameter> -WhatIf
Set-AuthenticationPolicy -Identity <AuthPolicyIdParameter>

# 4. Verify and diff
$after = Get-AuthenticationPolicy
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

Set-AuthenticationPolicy [-Identity] <AuthPolicyIdParameter>
 [-AllowBasicAuthActiveSync]
 [-AllowBasicAuthAutodiscover]
 [-AllowBasicAuthImap]
 [-AllowBasicAuthMapi]
 [-AllowBasicAuthOfflineAddressBook]
 [-AllowBasicAuthOutlookService]
 [-AllowBasicAuthPop]
 [-AllowBasicAuthPowershell]
 [-AllowBasicAuthReportingWebServices]
 [-AllowBasicAuthRpc]
 [-AllowBasicAuthSmtp]
 [-AllowBasicAuthWebServices]
 [-AllowLegacyExchangeTokens]
 [-BlockLegacyAuthActiveSync]
 [-BlockLegacyAuthAutodiscover]
 [-BlockLegacyAuthImap]
 [-BlockLegacyAuthMapi]
 [-BlockLegacyAuthOfflineAddressBook]
 [-BlockLegacyAuthPop]
 [-BlockLegacyAuthRpc]
 [-BlockLegacyAuthWebServices]
 [-BlockLegacyExchangeTokens]
 [-BlockModernAuthActiveSync]
 [-BlockModernAuthAutodiscover]
 [-BlockModernAuthImap]
 [-BlockModernAuthMapi]
 [-BlockModernAuthOfflineAddressBook]
 [-BlockModernAuthPop]
 [-BlockModernAuthRpc]
 [-BlockModernAuthWebServices]
 [-Confirm]
 [-TenantId <String>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (34)

ParameterTypeRequiredWhat it controls
-Identity AuthPolicyIdParameter yes The Identity parameter specifies the authentication policy you want to modify. You can use any value that uniquely identifies the policy. For example:
-AllowBasicAuthActiveSync SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthAutodiscover SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthImap SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthMapi SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthOfflineAddressBook SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthOutlookService SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthPop SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthPowershell SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthReportingWebServices SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthRpc SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthSmtp SwitchParameter This parameter is available only in the cloud-based service.
-AllowBasicAuthWebServices SwitchParameter This parameter is available only in the cloud-based service.
-AllowLegacyExchangeTokens SwitchParameter This parameter is available only in the cloud-based service.
-BlockLegacyAuthActiveSync SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthAutodiscover SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthImap SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthMapi SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthOfflineAddressBook SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthPop SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthRpc SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyAuthWebServices SwitchParameter This parameter is available only in on-premises Exchange.
-BlockLegacyExchangeTokens SwitchParameter This parameter is available only in the cloud-based service.
-BlockModernAuthActiveSync SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthAutodiscover SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthImap SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthMapi SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthOfflineAddressBook SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthPop SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthRpc SwitchParameter This parameter is available only in on-premises Exchange.
-BlockModernAuthWebServices SwitchParameter This parameter is available only in on-premises Exchange.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-TenantId String This parameter is available only in the cloud-based service.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.