Commands › Exchange Online

Set-DlpPolicy

Exchange Online ExchangeOnlineManagement Set-*

**Note**: This cmdlet is retired from the cloud-based service. For more information, see this blog post. Use the Set-DlpCompliancePolicy and Set-DlpComplianceRule cmdlets instead. This cmdlet is functional only in on-premises Exchange. Use the Set-DlpPolicy cmdlet to modify data loss prevention (DLP) policies that are based on transport rules (mail flow rules) in your organization.

Quick start script

# Set-DlpPolicy — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-DlpPolicy
$before | Format-List

# 3. Make the change (dry run first)
Set-DlpPolicy -Identity <DlpPolicyIdParameter> -WhatIf
Set-DlpPolicy -Identity <DlpPolicyIdParameter>

# 4. Verify and diff
$after = Get-DlpPolicy
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax

Set-DlpPolicy [-Identity] <DlpPolicyIdParameter>
 [-Confirm]
 [-Description <String>]
 [-DomainController <Fqdn>]
 [-Mode <RuleMode>]
 [-Name <String>]
 [-State <RuleState>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (8)

ParameterTypeRequiredWhat it controls
-Identity DlpPolicyIdParameter yes The Identity parameter specifies the DLP policy that you want to modify. You can use any value that uniquely identifies the policy. For example:
-Confirm SwitchParameter The Confirm switch specifies whether to show or hide the confirmation prompt. How this switch affects the cmdlet depends on whether the cmdlet requires confirmation before proceeding.
-Description String The Description parameter specifies an optional description for the DLP policy.
-DomainController Fqdn The DomainController parameter specifies the domain controller that's used by this cmdlet to read data from or write data to Active Directory. You identify the domain controller by its fully qualified domain name...
-Mode RuleMode The Mode parameter specifies the action and notification level of the DLP policy. Valid values for this parameter are:
-Name String The Name parameter specifies a unique name for the DLP policy.
-State RuleState The State parameter enables or disables the DLP policy. Valid input for this parameter is Enabled or Disabled.
-WhatIf SwitchParameter The WhatIf switch shows what the command does without making any changes. You don't need to specify a value with this switch.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.