Skip to content

EXOActiveSyncOrganizationSettings

Parameters

Parameter Attribute DataType Description Allowed Values
IsSingleInstance Key String Only valid value is 'Yes'. Yes
AdminMailRecipients Write String[] The AdminMailRecipients parameter specifies the email addresses of the administrators for reporting purposes.
AllowRMSSupportForUnenlightenedApps Write Boolean The AllowRMSSupportForUnenlightenedApps parameter specifies whether to allow Rights Management Services protected messages for ActiveSync clients that do not support RMS.
DefaultAccessLevel Write String The DefaultAccessLevel parameter specifies the access level for new and existing device partnerships. Allow, Block, Quarantine
EnableMobileMailboxPolicyWhenCAInplace Write Boolean The EnableMobileMailboxPolicyWhenCAInplace parameter specifies whether the mobile mailbox policy applies when Conditional Access is in place.
OtaNotificationMailInsert Write String The OtaNotificationMailInsert parameter specifies the text to include in an email message that is sent to users who need to update their older devices.
TenantAdminPreference Write String The TenantAdminPreference parameter specifies the tenant administrator preference for ActiveSync organization settings.
UserMailInsert Write String The UserMailInsert parameter specifies an informational footer that is added to the email message sent to users when their mobile device is quarantined.
Credential Write PSCredential Credentials of the Exchange Global Admin
ApplicationId Write String Id of the Entra ID application to authenticate with.
TenantId Write String Id of the Entra ID tenant used for authentication.
CertificateThumbprint Write String Thumbprint of the Entra ID application's authentication certificate to use for authentication.
CertificatePassword Write PSCredential Username can be made up to anything but password will be used for CertificatePassword
CertificatePath Write String Path to certificate used in service principal usually a PFX file.
ManagedIdentity Write Boolean Managed ID being used for authentication.
AccessTokens Write String[] Access token used for authentication.

Description

This resource configures a EXO Active Sync Organization Settings.

Permissions

Office 365 Exchange Online

To authenticate with the Office 365 Exchange Online API, this resource requires the following permissions:

Delegated permissions

  • Read
  • None

  • Update

  • None

Application permissions

  • Read
  • Exchange.ManageAsApp

  • Update

  • Exchange.ManageAsApp

Examples

Example 1

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        EXOActiveSyncOrganizationSettings 'EXOActiveSyncOrganizationSettings-Example'
        {
            IsSingleInstance                       = "Yes";
            AdminMailRecipients                    = @("mobile-admins@$TenantId", "messaging-team@$TenantId");
            AllowRMSSupportForUnenlightenedApps    = $False;
            DefaultAccessLevel                     = "Quarantine";
            EnableMobileMailboxPolicyWhenCAInplace = $True;
            OtaNotificationMailInsert              = "Update your device software to the newest version to keep mail syncing.";
            TenantAdminPreference                  = "NoPreference";
            UserMailInsert                         = "Your device is quarantined. Call the help desk at extension 4000 to request access."; # Updated Property
            ApplicationId                          = $ApplicationId;
            TenantId                               = $TenantId;
            CertificateThumbprint                  = $CertificateThumbprint;
        }
    }
}