Commands › Exchange Online

Set-TenantAllowBlockListItems

Exchange Online ExchangeOnlineManagement Set-*

Modify entries in the Tenant Allow/Block List in the Microsoft Defender portal.

Quick start script

# Set-TenantAllowBlockListItems — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Capture the current state first — you cannot roll back what you never recorded
$before = Get-TenantAllowBlockListItems
$before | Format-List

# 3. Make the change
Set-TenantAllowBlockListItems -Entries <String[]> -Ids <String[]> -ListType <ListType>

# 4. Verify and diff
$after = Get-TenantAllowBlockListItems
Compare-Object ($before | Out-String) ($after | Out-String)

Syntax — 2 parameter sets

Ids (Default)

Set-TenantAllowBlockListItems -Ids <String[]> -ListType <ListType>
 [-Allow]
 [-Block]
 [-ExpirationDate <DateTime>]
 [-ListSubType <ListSubType>]
 [-NoExpiration]
 [-Notes <String>]
 [-OutputJson]
 [-RemoveAfter <Int32>]
 [<CommonParameters>]

Entries

Set-TenantAllowBlockListItems -Entries <String[]> -ListType <ListType>
 [-Allow]
 [-Block]
 [-ExpirationDate <DateTime>]
 [-ListSubType <ListSubType>]
 [-NoExpiration]
 [-Notes <String>]
 [-OutputJson]
 [-RemoveAfter <Int32>]
 [<CommonParameters>]

Parameters (11)

ParameterTypeRequiredWhat it controls
-Entries String[] yes The Entries parameter specifies the entries that you want to modify based on the ListType parameter value. Valid values are:
-Ids String[] yes The Ids parameter specifies the entries that you want to modify. This value is shown in the Identity property in the output of the Get-TenantAllowBlockListItems cmdlet.
-ListType ListType yes The ListType parameter specifies the type of entry that you want to modify. Valid values are:
-NoExpiration SwitchParameter yes The NoExpiration switch specifies that the entry should never expire. You don't need to specify a value with this switch.
-Allow SwitchParameter The Allow switch specifies that you're modifying an allow entry. You don't need to specify a value with this switch.
-Block SwitchParameter The Block switch specifies that you're modifying a block entry. You don't need to specify a value with this switch.
-ExpirationDate DateTime The ExpirationDate parameter filters the results by expiration date in Coordinated Universal Time (UTC).
-ListSubType ListSubType The ListSubType parameter further specifies the entry that you want to modify. Valid values are:
-Notes String The Notes parameters specifies additional information about the object. If the value contains spaces, enclose the value in quotation marks ("). If the value contains quotation marks, add a backslash ( \ ) before the...
-OutputJson SwitchParameter The OutputJson switch specifies whether to return all entries in a single JSON value. You don't need to specify a value with this switch.
-RemoveAfter Int32 The RemoveAfter parameter enables the **Remove on** \> **45 days after last used date** feature for an allow entry. The LastUsedDate property is populated when the bad entity in the allow entry is encountered by the...

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.