Commands › Exchange Online

Set-DataClassification

Exchange Online ExchangeOnlineManagement Set-*

This cmdlet is functional only in on-premises Exchange. In Exchange Online, this cmdlet is replaced by the Set-DlpSensitiveInformationType cmdlet in Security & Compliance PowerShell. Use the Set-DataClassification cmdlet to modify data classification rules that use document fingerprints.

Quick start script

# Set-DataClassification — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-DataClassification
$before | Format-List

# 3. Make the change (dry run first)
Set-DataClassification -Identity <DataClassificationIdParameter> -WhatIf
Set-DataClassification -Identity <DataClassificationIdParameter>

# 4. Verify and diff
$after = Get-DataClassification
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

Set-DataClassification [-Identity] <DataClassificationIdParameter>
 [-Confirm]
 [-Description <String>]
 [-DomainController <Fqdn>]
 [-Fingerprints <MultiValuedProperty>]
 [-IsDefault]
 [-Locale <CultureInfo>]
 [-Name <String>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (9)

ParameterTypeRequiredWhat it controls
-Identity DataClassificationIdParameter yes The Identity parameter specifies the data classification rule that you want to modify. You can use any value that uniquely identifies the data classification rule. For example:
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-Description String The Description parameter specifies a description for the data classification rule. You use the Description parameter with the Locale and Name parameters to specify descriptions for the data classification rule in...
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-Fingerprints MultiValuedProperty The Fingerprints parameter specifies the byte-encoded document files that are used as fingerprints by the data classification rule. For instructions on how to import documents to use as templates for fingerprints,...
-IsDefault SwitchParameter The IsDefault switch is used with the Locale parameter to specify the default language for the data classification rule. You don't need to specify a value with this switch.
-Locale CultureInfo The Locale parameter adds or removes languages that are associated with the data classification rule.
-Name String The Name parameter specifies a name for the data classification rule. The value must be less than 256 characters.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.