Skip to content

EXOTransportRule

Parameters

Parameter Attribute DataType Description Allowed Values
Name Key String The Name parameter specifies the display name of the transport rule to be created. The maximum length is 64 characters.
ADComparisonAttribute Write String This parameter specifies a condition or part of a condition for the rule. The name of the corresponding exception parameter starts with ExceptIf.
ADComparisonOperator Write String This parameter specifies a condition or part of a condition for the rule. The name of the corresponding exception parameter starts with ExceptIf. Equal, NotEqual
ActivationDate Write String The ActivationDate parameter specifies when the rule starts processing messages. The rule won't take any action on messages until the specified date/time.
AddManagerAsRecipientType Write String The AddManagerAsRecipientType parameter specifies an action that delivers or redirects messages to the user that's defined in the sender's Manager attribute. To, Cc, Bcc, Redirect
AddToRecipients Write String[] The AddToRecipients parameter specifies an action that adds recipients to the To field of messages.
AnyOfCcHeader Write String[] The AnyOfCcHeader parameter specifies a condition that looks for recipients in the Cc field of messages.
AnyOfCcHeaderMemberOf Write String[] The AnyOfCcHeaderMemberOf parameter specifies a condition that looks for group members in the Cc field of messages.
AnyOfRecipientAddressContainsWords Write String[] The AnyOfRecipientAddressContainsWords parameter specifies a condition that looks for words in recipient email addresses.
AnyOfRecipientAddressMatchesPatterns Write String[] The AnyOfRecipientAddressMatchesPatterns parameter specifies a condition that looks for text patterns in recipient email addresses by using regular expressions.
AnyOfToCcHeader Write String[] The AnyOfToCcHeader parameter specifies a condition that looks for recipients in the To or Cc fields of messages.
AnyOfToCcHeaderMemberOf Write String[] The AnyOfToCcHeaderMemberOf parameter specifies a condition that looks for group members in the To and Cc fields of messages.
AnyOfToHeader Write String[] The AnyOfToHeader parameter specifies a condition that looks for recipients in the To field of messages.
AnyOfToHeaderMemberOf Write String[] The AnyOfToHeaderMemberOf parameter specifies a condition that looks for group members in the To field of messages.
ApplyClassification Write String The ApplyClassification parameter specifies an action that applies a message classification to messages.
ApplyHtmlDisclaimerFallbackAction Write String The ApplyHtmlDisclaimerFallbackAction parameter specifies what to do if the HTML disclaimer can't be added to a message. Wrap, Ignore, Reject
ApplyHtmlDisclaimerLocation Write String The ApplyHtmlDisclaimerLocation parameter specifies where to insert the HTML disclaimer text in the body of messages. Append, Prepend
ApplyHtmlDisclaimerText Write String The ApplyHtmlDisclaimerText parameter specifies an action that adds the disclaimer text to messages.
ApplyRightsProtectionCustomizationTemplate Write String The ApplyRightsProtectionCustomizationTemplate parameter specifies an action that applies a custom branding template for OME encrypted messages.
ApplyRightsProtectionTemplate Write String The ApplyRightsProtectionTemplate parameter specifies an action that applies rights management service (RMS) templates to messages.
AttachmentContainsWords Write String[] The AttachmentContainsWords parameter specifies a condition that looks for words in message attachments.
AttachmentExtensionMatchesWords Write String[] The AttachmentExtensionMatchesWords parameter specifies a condition that looks for words in the file name extensions of message attachments.
AttachmentHasExecutableContent Write Boolean The AttachmentHasExecutableContent parameter specifies a condition that looks for executable content in message attachments.
AttachmentIsPasswordProtected Write Boolean The AttachmentIsPasswordProtected parameter specifies a condition that looks for password protected files in messages (because the contents of the file can't be inspected).
AttachmentIsUnsupported Write Boolean The AttachmentIsUnsupported parameter specifies a condition that looks for unsupported file types in messages.
AttachmentMatchesPatterns Write String[] The AttachmentMatchesPatterns parameter specifies a condition that looks for text patterns in the content of message attachments by using regular expressions.
AttachmentNameMatchesPatterns Write String[] The AttachmentNameMatchesPatterns parameter specifies a condition that looks for text patterns in the file name of message attachments by using regular expressions.
AttachmentProcessingLimitExceeded Write Boolean The AttachmentProcessingLimitExceeded parameter specifies a condition that looks for messages where attachment scanning didn't complete.
AttachmentPropertyContainsWords Write String[] The AttachmentPropertyContainsWords parameter specifies a condition that looks for words in the properties of attached Office documents.
AttachmentSizeOver Write String The AttachmentSizeOver parameter specifies a condition that looks for messages where any attachment is greater than the specified size.
BetweenMemberOf1 Write String[] The BetweenMemberOf1 parameter specifies a condition that looks for messages that are sent between group members.
BetweenMemberOf2 Write String[] The BetweenMemberOf2 parameter specifies a condition that looks for messages that are sent between group members.
BlindCopyTo Write String[] The BlindCopyTo parameter specifies an action that adds recipients to the Bcc field of messages.
Comments Write String The Comments parameter specifies optional descriptive text for the rule. The length of the comment can't exceed 1024 characters.
ContentCharacterSetContainsWords Write String[] The ContentCharacterSetContainsWords parameter specifies a condition that looks for character set names in messages.
CopyTo Write String[] The CopyTo parameter specifies an action that adds recipients to the Cc field of messages.
DeleteMessage Write Boolean The DeleteMessage parameter specifies an action that silently drops messages without an NDR.
DlpPolicy Write String The DlpPolicy parameter specifies the data loss prevention (DLP) policy that's associated with the rule.
Enabled Write Boolean The Enabled parameter specifies whether the new rule is created as enabled or disabled.
ExceptIfADComparisonAttribute Write String The ExceptIfADComparisonAttribute parameter specifies an exception that compares an Active Directory attribute between the sender and all recipients of the message.
ExceptIfADComparisonOperator Write String The ExceptIfADComparisonOperator parameter specifies the comparison operator for the ExceptIfADComparisonAttribute parameter. Equal, NotEqual
ExceptIfAnyOfCcHeader Write String[] The ExceptIfAnyOfCcHeader parameter specifies an exception that looks for recipients in the Cc field of messages.
ExceptIfAnyOfCcHeaderMemberOf Write String[] The ExceptIfAnyOfCcHeaderMemberOf parameter specifies an exception that looks for group members in the Cc field of messages. You can use any value that uniquely identifies the group.
ExceptIfAnyOfRecipientAddressContainsWords Write String[] The ExceptIfAnyOfRecipientAddressContainsWords parameter specifies an exception that looks for words in recipient email addresses.
ExceptIfAnyOfRecipientAddressMatchesPatterns Write String[] The ExceptIfAnyOfRecipientAddressMatchesPatterns parameter specifies an exception that looks for text patterns in recipient email addresses by using regular expressions.
ExceptIfAnyOfToCcHeader Write String[] The ExceptIfAnyOfToCcHeader parameter specifies an exception that looks for recipients in the To or Cc fields of messages.
ExceptIfAnyOfToCcHeaderMemberOf Write String[] The ExceptIfAnyOfToCcHeaderMemberOf parameter specifies an exception that looks for group members in the To and Cc fields of messages.
ExceptIfAnyOfToHeader Write String[] The ExceptIfAnyOfToHeader parameter specifies an exception that looks for recipients in the To field of messages.
ExceptIfAnyOfToHeaderMemberOf Write String[] The ExceptIfAnyOfToHeaderMemberOf parameter specifies an exception that looks for group members in the To field of messages.
ExceptIfAttachmentContainsWords Write String[] The ExceptIfAttachmentContainsWords parameter specifies an exception that looks for words in message attachments.
ExceptIfAttachmentExtensionMatchesWords Write String[] The ExceptIfAttachmentExtensionMatchesWords parameter specifies an exception that looks for words in the file name extensions of message attachments.
ExceptIfAttachmentHasExecutableContent Write Boolean The ExceptIfAttachmentHasExecutableContent parameter specifies an exception that looks for executable content in message attachments.
ExceptIfAttachmentIsPasswordProtected Write Boolean The ExceptIfAttachmentIsPasswordProtected parameter specifies an exception that looks for password protected files in messages (because the contents of the file can't be inspected).
ExceptIfAttachmentIsUnsupported Write Boolean The ExceptIfAttachmentIsUnsupported parameter specifies an exception that looks for unsupported file types in messages.
ExceptIfAttachmentMatchesPatterns Write String[] The ExceptIfAttachmentMatchesPatterns parameter specifies an exception that looks for text patterns in the content of message attachments by using regular expressions.
ExceptIfAttachmentNameMatchesPatterns Write String[] The ExceptIfAttachmentNameMatchesPatterns parameter specifies an exception that looks for text patterns in the file name of message attachments by using regular expressions.
ExceptIfAttachmentPropertyContainsWords Write String[] The ExceptIfAttachmentPropertyContainsWords parameter specifies an exception that looks for words in the properties of attached Office documents.
ExceptIfAttachmentProcessingLimitExceeded Write Boolean The ExceptIfAttachmentProcessingLimitExceeded parameter specifies an exception that looks for messages where attachment scanning didn't complete.
ExceptIfAttachmentSizeOver Write String The ExceptIfAttachmentSizeOver parameter specifies an exception that looks for messages where any attachment is greater than the specified size.
ExceptIfBetweenMemberOf1 Write String[] The ExceptIfBetweenMemberOf1 parameter specifies an exception that looks for messages that are sent between group members.
ExceptIfBetweenMemberOf2 Write String[] The ExceptIfBetweenMemberOf2 parameter specifies an exception that looks for messages that are sent between group members.
ExceptIfContentCharacterSetContainsWords Write String[] The ExceptIfContentCharacterSetContainsWords parameter specifies an exception that looks for character set names in messages.
ExceptIfFrom Write String[] The ExceptIfFrom parameter specifies an exception that looks for messages from specific senders.
ExceptIfFromAddressContainsWords Write String[] The ExceptIfFromAddressContainsWords parameter specifies an exception that looks for words in the sender's email address.
ExceptIfFromAddressMatchesPatterns Write String[] The ExceptIfFromAddressMatchesPatterns parameter specifies an exception that looks for text patterns in the sender's email address by using regular expressions.
ExceptIfFromMemberOf Write String[] The ExceptIfFromMemberOf parameter specifies an exception that looks for messages sent by group members.
ExceptIfFromScope Write String The ExceptIfFromScope parameter specifies an exception that looks for the location of message senders. InOrganization, NotInOrganization
ExceptIfHasClassification Write String The ExceptIfHasClassification parameter specifies an exception that looks for messages with the specified message classification.
ExceptIfHasNoClassification Write Boolean The ExceptIfHasNoClassification parameter specifies an exception that looks for messages with or without any message classifications.
ExceptIfHeaderContainsMessageHeader Write String The ExceptIfHeaderContainsMessageHeader parameter specifies the name of header field in the message header when searching for the words specified by the ExceptIfHeaderContainsWords parameter.
ExceptIfHeaderContainsWords Write String[] The ExceptIfHeaderContainsWords parameter specifies an exception that looks for words in a header field.
ExceptIfHeaderMatchesMessageHeader Write String The ExceptIfHeaderMatchesMessageHeader parameter specifies the name of header field in the message header when searching for the text patterns specified by the ExceptIfHeaderMatchesPatterns parameter.
ExceptIfHeaderMatchesPatterns Write String[] The ExceptIfHeaderMatchesPatterns parameter specifies an exception that looks for text patterns in a header field by using regular expressions.
ExceptIfManagerAddresses Write String[] The ExceptIfManagerAddresses parameter specifies the users (managers) for the ExceptIfManagerForEvaluatedUser parameter.
ExceptIfManagerForEvaluatedUser Write String The ExceptIfManagerForEvaluatedUser parameter specifies an exception that looks for users in the Manager attribute of senders or recipients.
ExceptIfMessageTypeMatches Write String The ExceptIfMessageTypeMatches parameter specifies an exception that looks for messages of the specified type. OOF, AutoForward, Encrypted, Calendaring, PermissionControlled, Voicemail, Signed, ApprovalRequest, ReadReceipt
ExceptIfMessageSizeOver Write String The ExceptIfMessageSizeOver parameter specifies an exception that looks for messages larger than the specified size.
ExceptIfRecipientADAttributeContainsWords Write String[] The ExceptIfRecipientADAttributeContainsWords parameter specifies an exception that looks for words in the Active Directory attributes of recipients.
ExceptIfRecipientADAttributeMatchesPatterns Write String[] The ExceptIfRecipientADAttributeMatchesPatterns parameter specifies an exception that looks for text patterns in the Active Directory attributes of recipients by using regular expressions.
ExceptIfRecipientAddressContainsWords Write String[] The ExceptIfRecipientAddressContainsWords parameter specifies an exception that looks for words in recipient email addresses.
ExceptIfRecipientAddressMatchesPatterns Write String[] The ExceptIfRecipientAddressMatchesPatterns parameter specifies an exception that looks for text patterns in recipient email addresses by using regular expressions.
ExceptIfRecipientDomainIs Write String[] The ExceptIfRecipientDomainIs parameter specifies an exception that looks for recipients with email address in the specified domains.
ExceptIfRecipientInSenderList Write String[] This parameter is reserved for internal Microsoft use.
ExceptIfSCLOver Write String The ExceptIfSCLOver parameter specifies an exception that looks for the SCL value of messages
ExceptIfSenderADAttributeContainsWords Write String[] The ExceptIfSenderADAttributeContainsWords parameter specifies an exception that looks for words in Active Directory attributes of message senders.
ExceptIfSenderADAttributeMatchesPatterns Write String[] The ExceptIfSenderADAttributeMatchesPatterns parameter specifies an exception that looks for text patterns in Active Directory attributes of message senders by using regular expressions.
ExceptIfSenderDomainIs Write String[] The ExceptIfSenderDomainIs parameter specifies an exception that looks for senders with email address in the specified domains.
ExceptIfSenderInRecipientList Write String[] This parameter is reserved for internal Microsoft use.
ExceptIfSenderIpRanges Write String[] The ExceptIfSenderIpRanges parameter specifies an exception that looks for senders whose IP addresses matches the specified value, or fall within the specified ranges.
ExceptIfSenderManagementRelationship Write String The ExceptIfSenderManagementRelationship parameter specifies an exception that looks for the relationship between the sender and recipients in messages. Manager, DirectReport
ExceptIfSentTo Write String[] The ExceptIfSentTo parameter specifies an exception that looks for recipients in messages. You can use any value that uniquely identifies the recipient.
ExceptIfSentToMemberOf Write String[] The ExceptIfSentToMemberOf parameter specifies an exception that looks for messages sent to members of groups. You can use any value that uniquely identifies the group.
ExceptIfSentToScope Write String The ExceptIfSentToScope parameter specifies an exception that looks for the location of a recipient. InOrganization, NotInOrganization, ExternalPartner, ExternalNonPartner
ExceptIfSubjectContainsWords Write String[] The ExceptIfSubjectContainsWords parameter specifies an exception that looks for words in the Subject field of messages.
ExceptIfSubjectMatchesPatterns Write String[] The ExceptIfSubjectMatchesPatterns parameter specifies an exception that looks for text patterns in the Subject field of messages by using regular expressions.
ExceptIfSubjectOrBodyContainsWords Write String[] The ExceptIfSubjectOrBodyContainsWords parameter specifies an exception that looks for words in the Subject field or body of messages.
ExceptIfSubjectOrBodyMatchesPatterns Write String[] The ExceptIfSubjectOrBodyMatchesPatterns parameter specifies an exception that looks for text patterns in the Subject field or body of messages.
ExceptIfWithImportance Write String The ExceptIfWithImportance parameter specifies an exception that looks for messages with the specified importance level. Low, Normal, High
ExpiryDate Write String The ExpiryDate parameter specifies when this rule will stop processing messages. The rule won't take any action on messages after the specified date/time.
From Write String[] The From parameter specifies a condition that looks for messages from specific senders. You can use any value that uniquely identifies the sender.
FromAddressContainsWords Write String[] The FromAddressContainsWords parameter specifies a condition that looks for words in the sender's email address.
FromAddressMatchesPatterns Write String[] The FromAddressMatchesPatterns parameter specifies a condition that looks for text patterns in the sender's email address by using regular expressions.
FromMemberOf Write String[] The FromMemberOf parameter specifies a condition that looks for messages sent by group members.
FromScope Write String The FromScope parameter specifies a condition that looks for the location of message senders. InOrganization, NotInOrganization
GenerateIncidentReport Write String The GenerateIncidentReport parameter specifies where to send the incident report that's defined by the IncidentReportContent parameter.
GenerateNotification Write String The GenerateNotification parameter specifies an action that sends a notification message to recipients.
HasClassification Write String The HasClassification parameter specifies a condition that looks for messages with the specified message classification.
HasNoClassification Write Boolean The HasNoClassification parameter specifies a condition that looks for messages with or without any message classifications.
HeaderContainsMessageHeader Write String The HeaderContainsMessageHeader parameter specifies the name of header field in the message header when searching for the words specified by the HeaderContainsWords parameter.
HeaderContainsWords Write String[] The HeaderContainsWords parameter specifies a condition that looks for words in a header field.
HeaderMatchesMessageHeader Write String The HeaderMatchesMessageHeader parameter specifies the name of header field in the message header when searching for the text patterns specified by the HeaderMatchesPatterns parameter.
HeaderMatchesPatterns Write String[] The HeaderMatchesPatterns parameter specifies a condition that looks for text patterns in a header field by using regular expressions.
IncidentReportContent Write String[] The IncidentReportContent parameter specifies the message properties that are included in the incident report that's generated when a message violates a DLP policy.
ManagerAddresses Write String[] The ManagerAddresses parameter specifies the users (managers) for the ExceptIfManagerForEvaluatedUser parameter.
ManagerForEvaluatedUser Write String The ManagerForEvaluatedUser parameter specifies a condition that looks for users in the Manager attribute of senders or recipients. Recipient, Sender
MessageSizeOver Write String The MessageSizeOver parameter specifies a condition that looks for messages larger than the specified size. The size includes the message and all attachments.
MessageTypeMatches Write String The MessageTypeMatches parameter specifies a condition that looks for messages of the specified type. OOF, AutoForward, Encrypted, Calendaring, PermissionControlled, Voicemail, Signed, ApprovalRequest, ReadReceipt
Mode Write String The Mode parameter specifies how the rule operates. Audit, AuditAndNotify, Enforce
ModerateMessageByManager Write Boolean The ModerateMessageByManager parameter specifies an action that forwards messages for approval to the user that's specified in the sender's Manager attribute.
ModerateMessageByUser Write String[] The ModerateMessageByUser parameter specifies an action that forwards messages for approval to the specified users.
PrependSubject Write String The PrependSubject parameter specifies an action that adds text to add to the beginning of the Subject field of messages.
Priority Write UInt32 The Priority parameter specifies a priority value for the rule that determines the order of rule processing.
Quarantine Write Boolean The Quarantine parameter specifies an action that quarantines messages.
RecipientADAttributeContainsWords Write String[] The RecipientADAttributeContainsWords parameter specifies a condition that looks for words in the Active Directory attributes of recipients.
RecipientADAttributeMatchesPatterns Write String[] The RecipientADAttributeMatchesPatterns parameter specifies a condition that looks for text patterns in the Active Directory attributes of recipients by using regular expressions.
RecipientAddressContainsWords Write String[] The RecipientAddressContainsWords parameter specifies a condition that looks for words in recipient email addresses.
RecipientAddressMatchesPatterns Write String[] The RecipientAddressMatchesPatterns parameter specifies a condition that looks for text patterns in recipient email addresses by using regular expressions.
RecipientAddressType Write String The RecipientAddressType parameter specifies how conditions and exceptions check recipient email addresses. Original, Resolved
RecipientDomainIs Write String[] The RecipientDomainIs parameter specifies a condition that looks for recipients with email address in the specified domains.
RecipientInSenderList Write String[] This parameter is reserved for internal Microsoft use.
RedirectMessageTo Write String[] The RedirectMessageTo parameter specifies a rule action that redirects messages to the specified recipients.
RejectMessageEnhancedStatusCode Write String The RejectMessageEnhancedStatusCode parameter specifies the enhanced status code that's used when the rule rejects messages.
RejectMessageReasonText Write String The RejectMessageReasonText parameter specifies the explanation text that's used when the rule rejects messages.
RemoveHeader Write String The RemoveHeader parameter specifies an action that removes a header field from the message header.
RemoveOMEv2 Write Boolean The RemoveOMEv2 parameter specifies an action that removes Office 365 Message Encryption from messages and their attachments.
RemoveRMSAttachmentEncryption Write Boolean This parameter specifies an action or part of an action for the rule.
RouteMessageOutboundConnector Write String The RouteMessageOutboundConnector parameter specifies an action that routes messages through the specified Outbound connector in Office 365.
RouteMessageOutboundRequireTls Write Boolean The RouteMessageOutboundRequireTls parameter specifies an action that uses Transport Layer Security (TLS) encryption to deliver messages outside your organization.
RuleErrorAction Write String The RuleErrorAction parameter specifies what to do if rule processing can't be completed on messages. Ignore, Defer
RuleSubType Write String The RuleSubType parameter specifies the rule type. Dlp, None
SCLOver Write String The SCLOver parameter specifies a condition that looks for the SCL value of messages
SenderADAttributeContainsWords Write String[] The SenderADAttributeContainsWords parameter specifies a condition that looks for words in Active Directory attributes of message senders.
SenderADAttributeMatchesPatterns Write String[] The SenderADAttributeMatchesPatterns parameter specifies a condition that looks for text patterns in Active Directory attributes of message senders by using regular expressions.
SenderAddressLocation Write String The SenderAddressLocation parameter specifies where to look for sender addresses in conditions and exceptions that examine sender email addresses. Header, Envelope, HeaderOrEnvelope
SenderDomainIs Write String[] The SenderDomainIs parameter specifies a condition that looks for senders with email address in the specified domains.
SenderInRecipientList Write String[] This parameter is reserved for internal Microsoft use.
SenderIpRanges Write String[] The SenderIpRanges parameter specifies a condition that looks for senders whose IP addresses matches the specified value, or fall within the specified ranges.
SenderManagementRelationship Write String The SenderManagementRelationship parameter specifies a condition that looks for the relationship between the sender and recipients in messages. Manager, DirectReport
SentTo Write String[] The SentTo parameter specifies a condition that looks for recipients in messages.
SentToMemberOf Write String[] The SentToMemberOf parameter specifies a condition that looks for messages sent to members of distribution groups, dynamic distribution groups, or mail-enabled security groups.
SentToScope Write String The SentToScope parameter specifies a condition that looks for the location of recipients. InOrganization, NotInOrganization, ExternalPartner, ExternalNonPartner
SetAuditSeverity Write String The SetAuditSeverity parameter specifies an action that sets the severity level of the incident report and the corresponding entry that's written to the message tracking log when messages violate DLP policies. DoNotAudit, Low, Medium, High
SetHeaderName Write String The SetHeaderName parameter specifies an action that adds or modifies a header field in the message header.
SetHeaderValue Write String The SetHeaderValue parameter specifies an action that adds or modifies a header field in the message header.
SetSCL Write String The SetSCL parameter specifies an action that adds or modifies the SCL value of messages.
StopRuleProcessing Write Boolean The StopRuleProcessing parameter specifies an action that stops processing more rules.
SubjectContainsWords Write String[] The SubjectContainsWords parameter specifies a condition that looks for words in the Subject field of messages.
SubjectMatchesPatterns Write String[] The SubjectMatchesPatterns parameter specifies a condition that looks for text patterns in the Subject field of messages by using regular expressions.
SubjectOrBodyContainsWords Write String[] The SubjectOrBodyContainsWords parameter specifies a condition that looks for words in the Subject field or body of messages.
SubjectOrBodyMatchesPatterns Write String[] The SubjectOrBodyMatchesPatterns parameter specifies a condition that looks for text patterns in the Subject field or body of messages.
WithImportance Write String The WithImportance parameter specifies a condition that looks for messages with the specified importance level. Low, Normal, High
Ensure Write String Specify if the Transport Rule should exist or not. Present, Absent
Credential Write PSCredential Credentials of the Exchange Global Admin
ApplicationId Write String Id of the Azure Active Directory application to authenticate with.
TenantId Write String Id of the Azure Active Directory tenant used for authentication.
CertificateThumbprint Write String Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
CertificatePassword Write PSCredential Username can be made up to anything but password will be used for CertificatePassword
CertificatePath Write String Path to certificate used in service principal usually a PFX file.
ManagedIdentity Write Boolean Managed ID being used for authentication.
AccessTokens Write String[] Access token used for authentication.

Description

This resource configures Transport Rules in Exchange Online.

Permissions

Exchange

To authenticate with Microsoft Exchange, this resource requires the following permissions:

Roles

  • Read
  • View-Only Configuration
  • Update
  • Transport Rules

Role Groups

  • Read
  • View-Only Organization Management
  • Update
  • Records Management

Office 365 Exchange Online

To authenticate with the Office 365 Exchange Online API, this resource requires the following permissions:

Delegated permissions

  • Read
  • None

  • Update

  • None

Application permissions

  • Read
  • Exchange.ManageAsApp

  • Update

  • Exchange.ManageAsApp

Examples

Example 1

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        EXOTransportRule 'EXOTransportRule-Example'
        {
            Name                                         = 'Ethical Wall - Sales and Executives Departments'
            ADComparisonAttribute                        = "Department"
            ADComparisonOperator                         = "NotEqual"
            ActivationDate                               = "2026-01-01T00:00:00.0000000Z"
            AddManagerAsRecipientType                    = "Cc"
            AddToRecipients                              = @("AlexW@$TenantId")
            AnyOfCcHeader                                = @("AlexW@$TenantId")
            AnyOfCcHeaderMemberOf                        = @("Executives@$TenantId")
            AnyOfRecipientAddressContainsWords           = @("sales", "executive")
            AnyOfRecipientAddressMatchesPatterns         = @("^exec")
            AnyOfToCcHeader                              = @("Executives@$TenantId")
            AnyOfToCcHeaderMemberOf                      = @("Executives@$TenantId")
            AnyOfToHeader                                = @("Executives@$TenantId")
            AnyOfToHeaderMemberOf                        = @("Executives@$TenantId")
            ApplyHtmlDisclaimerFallbackAction            = "Ignore"
            ApplyHtmlDisclaimerLocation                  = "Append"
            ApplyHtmlDisclaimerText                      = "<p>This message crossed the information barrier between the Sales and the Executives departments and has been recorded for compliance review.</p>"
            AttachmentContainsWords                      = @("Confidential", "Deal Sheet")
            AttachmentExtensionMatchesWords              = @("docx", "xlsx", "pptx")
            AttachmentHasExecutableContent               = $false
            AttachmentIsPasswordProtected                = $false
            AttachmentIsUnsupported                      = $false
            AttachmentMatchesPatterns                    = @("Project Aurora")
            AttachmentNameMatchesPatterns                = @("Board-", "Deal-")
            AttachmentProcessingLimitExceeded            = $false
            AttachmentPropertyContainsWords              = @("Classification:Confidential")
            AttachmentSizeOver                           = "2MB"
            BetweenMemberOf1                             = @("SalesTeam@$TenantId")
            BetweenMemberOf2                             = @("Executives@$TenantId")
            BlindCopyTo                                  = @("admin@$TenantId")
            Comments                                     = "Records mail crossing the information barrier between the Sales and the Executives departments while the barrier is being piloted."
            ContentCharacterSetContainsWords             = @("iso-8859-1", "windows-1252")
            CopyTo                                       = @("LegalTeam@$TenantId")
            Enabled                                      = $true
            ExceptIfADComparisonAttribute                = "Company"
            ExceptIfADComparisonOperator                 = "Equal"
            ExceptIfAnyOfCcHeader                        = @("LegalTeam@$TenantId")
            ExceptIfAnyOfCcHeaderMemberOf                = @("LegalTeam@$TenantId")
            ExceptIfAnyOfRecipientAddressContainsWords   = @("legal", "compliance")
            ExceptIfAnyOfRecipientAddressMatchesPatterns = @("^legal")
            ExceptIfAnyOfToCcHeader                      = @("LegalTeam@$TenantId")
            ExceptIfAnyOfToCcHeaderMemberOf              = @("LegalTeam@$TenantId")
            ExceptIfAnyOfToHeader                        = @("LegalTeam@$TenantId")
            ExceptIfAnyOfToHeaderMemberOf                = @("LegalTeam@$TenantId")
            ExceptIfAttachmentContainsWords              = @("Approved by Legal")
            ExceptIfAttachmentExtensionMatchesWords      = @("txt", "csv")
            ExceptIfAttachmentHasExecutableContent       = $true
            ExceptIfAttachmentIsPasswordProtected        = $true
            ExceptIfAttachmentIsUnsupported              = $true
            ExceptIfAttachmentMatchesPatterns            = @("Approved by Legal")
            ExceptIfAttachmentNameMatchesPatterns        = @("Public-")
            ExceptIfAttachmentPropertyContainsWords      = @("Classification:Public")
            ExceptIfAttachmentProcessingLimitExceeded    = $true
            ExceptIfAttachmentSizeOver                   = "20MB"
            ExceptIfBetweenMemberOf1                     = @("LegalTeam@$TenantId")
            ExceptIfBetweenMemberOf2                     = @("Executives@$TenantId")
            ExceptIfContentCharacterSetContainsWords     = @("utf-8")
            ExceptIfFrom                                 = @("AdeleV@$TenantId")
            ExceptIfFromAddressContainsWords             = @("legal")
            ExceptIfFromAddressMatchesPatterns           = @("^legal")
            ExceptIfFromMemberOf                         = @("LegalTeam@$TenantId")
            ExceptIfFromScope                            = "NotInOrganization"
            ExceptIfHasNoClassification                  = $true
            ExceptIfHeaderContainsMessageHeader          = "X-Legal-Review"
            ExceptIfHeaderContainsWords                  = @("Approved", "Cleared")
            ExceptIfHeaderMatchesMessageHeader           = "X-Legal-Exemption"
            ExceptIfHeaderMatchesPatterns                = @("Legal-Hold")
            ExceptIfManagerAddresses                     = @("AlexW@$TenantId")
            ExceptIfManagerForEvaluatedUser              = "Recipient"
            ExceptIfMessageTypeMatches                   = "AutoForward"
            ExceptIfMessageSizeOver                      = "25MB"
            ExceptIfRecipientADAttributeContainsWords    = @("Department:Legal")
            ExceptIfRecipientADAttributeMatchesPatterns  = @("Title:^General Counsel")
            ExceptIfRecipientAddressContainsWords        = @("legal")
            ExceptIfRecipientAddressMatchesPatterns      = @("^legal")
            ExceptIfRecipientDomainIs                    = @("fabrikam.com")
            ExceptIfSCLOver                              = "8"
            ExceptIfSenderADAttributeContainsWords       = @("Department:Legal")
            ExceptIfSenderADAttributeMatchesPatterns     = @("Title:^General Counsel")
            ExceptIfSenderDomainIs                       = @("fabrikam.com")
            ExceptIfSenderIpRanges                       = @("192.168.20.0/24")
            ExceptIfSenderManagementRelationship         = "DirectReport"
            ExceptIfSentTo                               = @("AlexW@$TenantId")
            ExceptIfSentToMemberOf                       = @("LegalTeam@$TenantId")
            ExceptIfSentToScope                          = "ExternalPartner"
            ExceptIfSubjectContainsWords                 = @("Press Release", "Corporate Communication")
            ExceptIfSubjectMatchesPatterns               = @("^Approved")
            ExceptIfSubjectOrBodyContainsWords           = @("Approved by Legal")
            ExceptIfSubjectOrBodyMatchesPatterns         = @("Legal Review Complete")
            ExceptIfWithImportance                       = "Low"
            ExpiryDate                                   = "2027-01-01T00:00:00.0000000Z"
            From                                         = @("AlexW@$TenantId")
            FromAddressContainsWords                     = @("sales")
            FromAddressMatchesPatterns                   = @("^sales")
            FromMemberOf                                 = @("SalesTeam@$TenantId")
            FromScope                                    = "InOrganization"
            GenerateIncidentReport                       = "admin@$TenantId"
            GenerateNotification                         = "<p>Your message crossed the information barrier between the Sales and the Executives departments and has been recorded for compliance review.</p>"
            HasNoClassification                          = $false
            HeaderContainsMessageHeader                  = "X-Message-Classification"
            HeaderContainsWords                          = @("Confidential", "Restricted")
            HeaderMatchesMessageHeader                   = "X-Project-Code"
            HeaderMatchesPatterns                        = @("Aurora", "Northwind")
            IncidentReportContent                        = @("Sender", "Recipients", "Subject", "CreatedTime", "Severity")
            ManagerAddresses                             = @("AdeleV@$TenantId")
            ManagerForEvaluatedUser                      = "Sender"
            MessageSizeOver                              = "10MB"
            MessageTypeMatches                           = "Encrypted"
            Mode                                         = "Audit"
            PrependSubject                               = "[Ethical Wall]"
            Priority                                     = 0
            RecipientADAttributeContainsWords            = @("Department:Executives")
            RecipientADAttributeMatchesPatterns          = @("Title:^Chief")
            RecipientAddressContainsWords                = @("exec")
            RecipientAddressMatchesPatterns              = @("^exec")
            RecipientAddressType                         = "Resolved"
            RecipientDomainIs                            = @("$TenantId")
            RemoveHeader                                 = "X-Information-Barrier-Reviewed"
            RouteMessageOutboundRequireTls               = $true
            RuleErrorAction                              = "Ignore"
            RuleSubType                                  = "None"
            SCLOver                                      = "5"
            SenderADAttributeContainsWords               = @("Department:Sales")
            SenderADAttributeMatchesPatterns             = @("Title:^Account")
            SenderAddressLocation                        = "HeaderOrEnvelope"
            SenderDomainIs                               = @("$TenantId")
            SenderIpRanges                               = @("192.168.10.0/24")
            SenderManagementRelationship                 = "Manager"
            SentTo                                       = @("AdeleV@$TenantId")
            SentToMemberOf                               = @("Executives@$TenantId")
            SentToScope                                  = "InOrganization"
            SetAuditSeverity                             = "Medium"
            SetHeaderName                                = "X-Information-Barrier"
            SetHeaderValue                               = "Sales-Executives"
            SetSCL                                       = "0"
            StopRuleProcessing                           = $false
            SubjectContainsWords                         = @("Confidential", "Board Deck")
            SubjectMatchesPatterns                       = @("Project Aurora")
            SubjectOrBodyContainsWords                   = @("Deal Sheet", "Term Sheet")
            SubjectOrBodyMatchesPatterns                 = @("Project (Aurora|Northwind)")
            WithImportance                               = "High"
            Ensure                                       = 'Present'
            ApplicationId                                = $ApplicationId
            TenantId                                     = $TenantId
            CertificateThumbprint                        = $CertificateThumbprint
        }
    }
}

Example 2

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        EXOTransportRule 'EXOTransportRule-Example'
        {
            Name                                         = 'Ethical Wall - Sales and Executives Departments'
            ADComparisonAttribute                        = "Department"
            ADComparisonOperator                         = "NotEqual"
            ActivationDate                               = "2026-01-01T00:00:00.0000000Z"
            AddManagerAsRecipientType                    = "Cc"
            AddToRecipients                              = @("AlexW@$TenantId")
            AnyOfCcHeader                                = @("AlexW@$TenantId")
            AnyOfCcHeaderMemberOf                        = @("Executives@$TenantId")
            AnyOfRecipientAddressContainsWords           = @("sales", "executive")
            AnyOfRecipientAddressMatchesPatterns         = @("^exec")
            AnyOfToCcHeader                              = @("Executives@$TenantId")
            AnyOfToCcHeaderMemberOf                      = @("Executives@$TenantId")
            AnyOfToHeader                                = @("Executives@$TenantId")
            AnyOfToHeaderMemberOf                        = @("Executives@$TenantId")
            ApplyHtmlDisclaimerFallbackAction            = "Ignore"
            ApplyHtmlDisclaimerLocation                  = "Append"
            ApplyHtmlDisclaimerText                      = "<p>This message crossed the information barrier between the Sales and the Executives departments and has been recorded for compliance review.</p>"
            AttachmentContainsWords                      = @("Confidential", "Deal Sheet")
            AttachmentExtensionMatchesWords              = @("docx", "xlsx", "pptx")
            AttachmentHasExecutableContent               = $false
            AttachmentIsPasswordProtected                = $false
            AttachmentIsUnsupported                      = $false
            AttachmentMatchesPatterns                    = @("Project Aurora")
            AttachmentNameMatchesPatterns                = @("Board-", "Deal-")
            AttachmentProcessingLimitExceeded            = $false
            AttachmentPropertyContainsWords              = @("Classification:Confidential")
            AttachmentSizeOver                           = "2MB"
            BetweenMemberOf1                             = @("SalesTeam@$TenantId")
            BetweenMemberOf2                             = @("Executives@$TenantId")
            BlindCopyTo                                  = @("admin@$TenantId")
            Comments                                     = "Records mail crossing the information barrier between the Sales and the Executives departments while the barrier is being piloted."
            ContentCharacterSetContainsWords             = @("iso-8859-1", "windows-1252")
            CopyTo                                       = @("LegalTeam@$TenantId")
            Enabled                                      = $false # Updated Property
            ExceptIfADComparisonAttribute                = "Company"
            ExceptIfADComparisonOperator                 = "Equal"
            ExceptIfAnyOfCcHeader                        = @("LegalTeam@$TenantId")
            ExceptIfAnyOfCcHeaderMemberOf                = @("LegalTeam@$TenantId")
            ExceptIfAnyOfRecipientAddressContainsWords   = @("legal", "compliance")
            ExceptIfAnyOfRecipientAddressMatchesPatterns = @("^legal")
            ExceptIfAnyOfToCcHeader                      = @("LegalTeam@$TenantId")
            ExceptIfAnyOfToCcHeaderMemberOf              = @("LegalTeam@$TenantId")
            ExceptIfAnyOfToHeader                        = @("LegalTeam@$TenantId")
            ExceptIfAnyOfToHeaderMemberOf                = @("LegalTeam@$TenantId")
            ExceptIfAttachmentContainsWords              = @("Approved by Legal")
            ExceptIfAttachmentExtensionMatchesWords      = @("txt", "csv")
            ExceptIfAttachmentHasExecutableContent       = $true
            ExceptIfAttachmentIsPasswordProtected        = $true
            ExceptIfAttachmentIsUnsupported              = $true
            ExceptIfAttachmentMatchesPatterns            = @("Approved by Legal")
            ExceptIfAttachmentNameMatchesPatterns        = @("Public-")
            ExceptIfAttachmentPropertyContainsWords      = @("Classification:Public")
            ExceptIfAttachmentProcessingLimitExceeded    = $true
            ExceptIfAttachmentSizeOver                   = "20MB"
            ExceptIfBetweenMemberOf1                     = @("LegalTeam@$TenantId")
            ExceptIfBetweenMemberOf2                     = @("Executives@$TenantId")
            ExceptIfContentCharacterSetContainsWords     = @("utf-8")
            ExceptIfFrom                                 = @("AdeleV@$TenantId")
            ExceptIfFromAddressContainsWords             = @("legal")
            ExceptIfFromAddressMatchesPatterns           = @("^legal")
            ExceptIfFromMemberOf                         = @("LegalTeam@$TenantId")
            ExceptIfFromScope                            = "NotInOrganization"
            ExceptIfHasNoClassification                  = $true
            ExceptIfHeaderContainsMessageHeader          = "X-Legal-Review"
            ExceptIfHeaderContainsWords                  = @("Approved", "Cleared")
            ExceptIfHeaderMatchesMessageHeader           = "X-Legal-Exemption"
            ExceptIfHeaderMatchesPatterns                = @("Legal-Hold")
            ExceptIfManagerAddresses                     = @("AlexW@$TenantId")
            ExceptIfManagerForEvaluatedUser              = "Recipient"
            ExceptIfMessageTypeMatches                   = "AutoForward"
            ExceptIfMessageSizeOver                      = "25MB"
            ExceptIfRecipientADAttributeContainsWords    = @("Department:Legal")
            ExceptIfRecipientADAttributeMatchesPatterns  = @("Title:^General Counsel")
            ExceptIfRecipientAddressContainsWords        = @("legal")
            ExceptIfRecipientAddressMatchesPatterns      = @("^legal")
            ExceptIfRecipientDomainIs                    = @("fabrikam.com")
            ExceptIfSCLOver                              = "8"
            ExceptIfSenderADAttributeContainsWords       = @("Department:Legal")
            ExceptIfSenderADAttributeMatchesPatterns     = @("Title:^General Counsel")
            ExceptIfSenderDomainIs                       = @("fabrikam.com")
            ExceptIfSenderIpRanges                       = @("192.168.20.0/24")
            ExceptIfSenderManagementRelationship         = "DirectReport"
            ExceptIfSentTo                               = @("AlexW@$TenantId")
            ExceptIfSentToMemberOf                       = @("LegalTeam@$TenantId")
            ExceptIfSentToScope                          = "ExternalPartner"
            ExceptIfSubjectContainsWords                 = @("Press Release", "Corporate Communication")
            ExceptIfSubjectMatchesPatterns               = @("^Approved")
            ExceptIfSubjectOrBodyContainsWords           = @("Approved by Legal")
            ExceptIfSubjectOrBodyMatchesPatterns         = @("Legal Review Complete")
            ExceptIfWithImportance                       = "Low"
            ExpiryDate                                   = "2027-01-01T00:00:00.0000000Z"
            From                                         = @("AlexW@$TenantId")
            FromAddressContainsWords                     = @("sales")
            FromAddressMatchesPatterns                   = @("^sales")
            FromMemberOf                                 = @("SalesTeam@$TenantId")
            FromScope                                    = "InOrganization"
            GenerateIncidentReport                       = "admin@$TenantId"
            GenerateNotification                         = "<p>Your message crossed the information barrier between the Sales and the Executives departments and has been recorded for compliance review.</p>"
            HasNoClassification                          = $false
            HeaderContainsMessageHeader                  = "X-Message-Classification"
            HeaderContainsWords                          = @("Confidential", "Restricted")
            HeaderMatchesMessageHeader                   = "X-Project-Code"
            HeaderMatchesPatterns                        = @("Aurora", "Northwind")
            IncidentReportContent                        = @("Sender", "Recipients", "Subject", "CreatedTime", "Severity")
            ManagerAddresses                             = @("AdeleV@$TenantId")
            ManagerForEvaluatedUser                      = "Sender"
            MessageSizeOver                              = "10MB"
            MessageTypeMatches                           = "Encrypted"
            Mode                                         = "Audit"
            PrependSubject                               = "[Ethical Wall]"
            Priority                                     = 0
            RecipientADAttributeContainsWords            = @("Department:Executives")
            RecipientADAttributeMatchesPatterns          = @("Title:^Chief")
            RecipientAddressContainsWords                = @("exec")
            RecipientAddressMatchesPatterns              = @("^exec")
            RecipientAddressType                         = "Resolved"
            RecipientDomainIs                            = @("$TenantId")
            RemoveHeader                                 = "X-Information-Barrier-Reviewed"
            RouteMessageOutboundRequireTls               = $true
            RuleErrorAction                              = "Ignore"
            RuleSubType                                  = "None"
            SCLOver                                      = "5"
            SenderADAttributeContainsWords               = @("Department:Sales")
            SenderADAttributeMatchesPatterns             = @("Title:^Account")
            SenderAddressLocation                        = "HeaderOrEnvelope"
            SenderDomainIs                               = @("$TenantId")
            SenderIpRanges                               = @("192.168.10.0/24")
            SenderManagementRelationship                 = "Manager"
            SentTo                                       = @("AdeleV@$TenantId")
            SentToMemberOf                               = @("Executives@$TenantId")
            SentToScope                                  = "InOrganization"
            SetAuditSeverity                             = "Medium"
            SetHeaderName                                = "X-Information-Barrier"
            SetHeaderValue                               = "Sales-Executives"
            SetSCL                                       = "0"
            StopRuleProcessing                           = $false
            SubjectContainsWords                         = @("Confidential", "Board Deck")
            SubjectMatchesPatterns                       = @("Project Aurora")
            SubjectOrBodyContainsWords                   = @("Deal Sheet", "Term Sheet")
            SubjectOrBodyMatchesPatterns                 = @("Project (Aurora|Northwind)")
            WithImportance                               = "High"
            Ensure                                       = 'Present'
            ApplicationId                                = $ApplicationId
            TenantId                                     = $TenantId
            CertificateThumbprint                        = $CertificateThumbprint
        }
    }
}

Example 3

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        EXOTransportRule 'EXOTransportRule-Example'
        {
            Name                  = "Ethical Wall - Sales and Executives Departments"
            Ensure                = "Absent"
            ApplicationId         = $ApplicationId
            TenantId              = $TenantId
            CertificateThumbprint = $CertificateThumbprint
        }
    }
}