Commands › Exchange Online

Set-ClientAccessServer

Exchange Online ExchangeOnlineManagement Set-*

Modify settings that are associated with the Client Access server role. **Note**: In Exchange 2013 or later, use the Set-ClientAccessService cmdlet instead. If you have scripts that use Set-ClientAccessServer, update them to use Set-ClientAccessService.

Quick start script

# Set-ClientAccessServer — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-ClientAccessServer
$before | Format-List

# 3. Make the change (dry run first)
Set-ClientAccessServer -Identity <ClientAccessServerIdParameter> -WhatIf
Set-ClientAccessServer -Identity <ClientAccessServerIdParameter>

# 4. Verify and diff
$after = Get-ClientAccessServer
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax — 2 parameter sets

AlternateServiceAccount

Set-ClientAccessServer [-Identity] <ClientAccessServerIdParameter>
 [-AlternateServiceAccountCredential <PSCredential[]>]
 [-CleanUpInvalidAlternateServiceAccountCredentials]
 [-Confirm]
 [-DomainController <Fqdn>]
 [-IrmLogEnabled <Boolean>]
 [-IrmLogMaxAge <EnhancedTimeSpan>]
 [-IrmLogMaxDirectorySize <Unlimited>]
 [-IrmLogMaxFileSize <ByteQuantifiedSize>]
 [-IrmLogPath <LocalLongFullPath>]
 [-IsOutOfService <Boolean>]
 [-RemoveAlternateServiceAccountCredentials]
 [-WhatIf]
 [<CommonParameters>]

Identity

Set-ClientAccessServer [-Identity] <ClientAccessServerIdParameter>
 [-Array <ClientAccessArrayIdParameter>]
 [-AutoDiscoverServiceInternalUri <Uri>]
 [-AutoDiscoverSiteScope <MultiValuedProperty>]
 [-Confirm]
 [-DomainController <Fqdn>]
 [-IrmLogEnabled <Boolean>]
 [-IrmLogMaxAge <EnhancedTimeSpan>]
 [-IrmLogMaxDirectorySize <Unlimited>]
 [-IrmLogMaxFileSize <ByteQuantifiedSize>]
 [-IrmLogPath <LocalLongFullPath>]
 [-IsOutOfService <Boolean>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (16)

ParameterTypeRequiredWhat it controls
-Identity ClientAccessServerIdParameter yes The Identity parameter specifies the server that you want to modify. You can use any value that uniquely identifies the server. For example:
-AlternateServiceAccountCredential PSCredential[] The AlternateServiceAccountCredential parameter specifies an alternative service account username and password that's typically used for Kerberos authentication in Exchange Server 2010 coexistence environments. You...
-Array ClientAccessArrayIdParameter This parameter is reserved for internal Microsoft use.
-AutoDiscoverServiceInternalUri Uri The AutoDiscoverServiceInternalUri parameter specifies the internal URL of the Autodiscover service.
-AutoDiscoverSiteScope MultiValuedProperty The AutoDiscoverSiteScope parameter specifies the Active Directory site that the Autodiscover service is authoritative for. Clients that connect to the Autodiscover service by using the internal URL need to exist in...
-CleanUpInvalidAlternateServiceAccountCredentials SwitchParameter The CleanUpInvalidAlternateServiceAccountCredentials switch specifies whether to remove a previously configured alternate service account that's no longer valid. You don't need to specify a value with this switch.
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-IrmLogEnabled Boolean The IrmLogEnabled parameter specifies whether logging is enabled for Information Rights Management (IRM). Valid values are $true or $false. The default value is $true.
-IrmLogMaxAge EnhancedTimeSpan The IrmLogMaxAge parameter specifies the max age for IRM logs. Logs older than the specified value are deleted.
-IrmLogMaxDirectorySize Unlimited The IrmLogMaxDirectorySize parameter specifies the maximum directory size for IRM logs. When the maximum directory size is reached, the server deletes the old log files first.
-IrmLogMaxFileSize ByteQuantifiedSize The IrmLogMaxFileSize parameter specifies the maximum size of the IRM log. This value can't be larger than the IrmLogMaxDirectorySize parameter value.
-IrmLogPath LocalLongFullPath The IrmLogPath parameter specifies the location of the IRM log files. The default location is %ExchangeInstallPath%Logging\\IRMLogs.
-IsOutOfService Boolean This parameter is reserved for internal Microsoft use.
-RemoveAlternateServiceAccountCredentials SwitchParameter The RemoveAlternateServiceAccountCredentials switch specifies whether to remove a previously distributed alternate service account. You don't need to specify a value with this switch.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.