SPOSite¶
Parameters¶
| Parameter | Attribute | DataType | Description | Allowed Values |
|---|---|---|---|---|
| Url | Key | String | The URL of the site collection. | |
| Title | Required | String | The title of the site collection. | |
| Owner | Required | String | Specifies the owner of the site. | |
| TimeZoneId | Required | UInt32 | TimeZone ID of the site collection. | |
| Template | Write | String | Specifies with template of site to create. | |
| HubUrl | Write | String | The URL of the Hub site the site collection needs to get connected to. | |
| AllowFileArchive | Write | Boolean | Enables or disables file-level archiving for the site. This setting only takes effect when the tenant-level AllowFileArchive setting is enabled. If the tenant-level setting is disabled, users will not be able to archive files on the site even when this parameter is set to $true. |
|
| AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled | Write | Boolean | Enables or disables adding and updating web property bag values when the DenyAddAndCustomizePages is enabled. | |
| DefaultShareLinkRole | Write | String | To set the default share link role. Valid values are: None, View, Edit, Review, RestrictedView. | None, View, Edit, Review, RestrictedView |
| DefaultShareLinkScope | Write | String | To set the default sharing link scope. The valid values are: Anyone, Organization, SpecificPeople, Uninitialized | Anyone, Organization, SpecificPeople, Uninitialized |
| InheritVersionPolicyFromTenant | Write | Boolean | Resets the site version policy to inherit the default version policy from the tenant. | |
| LoopDefaultSharingLinkRole | Write | String | To set the loop default sharing link role. Valid values are: None, View, Edit, Review, RestrictedView. | None, View, Edit, Review, RestrictedView |
| LoopDefaultSharingLinkScope | Write | String | To set the loop default sharing link scope. The valid values are: Anyone, Organization, SpecificPeople, Uninitialized | Anyone, Organization, SpecificPeople, Uninitialized |
| OrganizationSharingLinkMaxExpirationInDays | Write | SInt32 | This parameter specifies the maximum number of days that organization sharing links can remain active before they expire for the SharePoint site. The valid values : - can be from 7 to 730 days. - 0 (default) - No maximum expiration limit is enforced. | |
| OrganizationSharingLinkRecommendedExpirationInDays | Write | SInt32 | This parameter specifies the recommended number of days before organization sharing links expire in the SharePoint site. Users can still choose a different expiration period if permitted by policy, but this value is presented as the recommended default. The valid values : - Can be from 7 to 730 days and must be less than or equal to the maximum expiration value set by OrganizationSharingLinkMaxExpirationInDays. - When set to 0 (default), the default value will be OrganizationSharingLinkMaxExpirationInDays. | |
| OverrideSharingCapability | Write | Boolean | Specifies whether to override the sharing capability for the site. | |
| OverrideTenantOrganizationSharingLinkExpirationPolicy | Write | Boolean | Allows to set organization sharing link expiration policy for this SharePoint site, which will override the tenant-level policy when set to true. When this is set to true, you can configure the organization sharing link expiration policy for this site collection using the OrganizationSharingLinkRecommendedExpirationInDays and OrganizationSharingLinkMaxExpirationInDays parameters. | |
| RequestFilesLinkEnabled | Write | Boolean | Enables or disables the Request Files link on the site. | |
| HidePeoplePreviewingFiles | Write | Boolean | Allows hiding of the presence indicators of users simultaneously editing files. | |
| HidePeopleWhoHaveListsOpen | Write | Boolean | Allows hiding of the presence indicators of users simultaneously working in lists. | |
| DisableFlows | Write | Boolean | Disables Microsoft Flow for this site. | |
| SharingCapability | Write | String | Specifies what the sharing capabilities are for the site. Possible values: Disabled, ExternalUserSharingOnly, ExternalUserAndGuestSharing, ExistingExternalUserSharingOnly. | Disabled, ExistingExternalUserSharingOnly, ExternalUserSharingOnly, ExternalUserAndGuestSharing |
| StorageMaximumLevel | Write | UInt32 | Specifies the storage quota for this site collection in megabytes. This value must not exceed the company's available quota. | |
| StorageWarningLevel | Write | UInt32 | Specifies the warning level for the storage quota in megabytes. This value must not exceed the values set for the StorageMaximumLevel parameter. | |
| AllowSelfServiceUpgrade | Write | Boolean | Specifies if the site administrator can upgrade the site collection. | |
| CommentsOnSitePagesDisabled | Write | Boolean | Specifies if comments on site pages are enabled or disabled. | |
| DefaultLinkPermission | Write | String | Specifies the default link permission for the site collection. None - Respect the organization default link permission. View - Sets the default link permission for the site to 'view' permissions. Edit - Sets the default link permission for the site to 'edit' permissions. | None, View, Edit |
| DefaultSharingLinkType | Write | String | Specifies the default link type for the site collection. None - Respect the organization default sharing link type. AnonymousAccess - Sets the default sharing link for this site to an Anonymous Access or Anyone link. Internal - Sets the default sharing link for this site to the 'organization' link or company shareable link. Direct - Sets the default sharing link for this site to the 'Specific people' link. | None, AnonymousAccess, Internal, Direct |
| DisableAppViews | Write | String | Disables App Views. | Unknown, Disabled, NotDisabled |
| DisableCompanyWideSharingLinks | Write | String | Disables Company wide sharing links. | Unknown, Disabled, NotDisabled |
| ListsShowHeaderAndNavigation | Write | Boolean | Set a property on a site collection to make all lists always load with the site elements intact. | |
| LocaleId | Write | UInt32 | Specifies the language of the new site collection. Defaults to the current language of the web connected to. | |
| DenyAddAndCustomizePages | Write | Boolean | Determines whether the Add And Customize Pages right is denied on the site collection. For more information about permission levels, see User permissions and permission levels in SharePoint. | |
| RestrictedAccessControl | Write | Boolean | To apply restricted access control to a group-connected or Teams-connected site. | |
| RestrictedAccessControlGroups | Write | String[] | To edit a restricted access control group for a non-group site | |
| RestrictedToRegion | Write | String | Defines geo-restriction settings for this site | NoRestriction, BlockMoveOnly, BlockFull, Unknown |
| ReadOnlyForUnmanagedDevices | Write | Boolean | To set the site as read-only for unmanaged devices. | |
| RequestFilesLinkExpirationInDays | Write | SInt32 | Specifies the number of days before a Request Files link expires for the site. The value can be from 0 to 730 days. | |
| RestrictContentOrgWideSearch | Write | Boolean | To restrict content from being searchable organization-wide and Copilot. | |
| SharingAllowedDomainList | Write | String | Specifies a list of email domains that is allowed for sharing with the external collaborators. Use the space character as the delimiter. | |
| SharingBlockedDomainList | Write | String | Specifies a list of email domains that is blocked for sharing with the external collaborators. | |
| SharingDomainRestrictionMode | Write | String | Specifies the external sharing mode for domains. | None, AllowList, BlockList |
| ShowPeoplePickerSuggestionsForGuestUsers | Write | Boolean | To enable the option to search for existing guest users at Site Collection Level, set this parameter to $true. | |
| AnonymousLinkExpirationInDays | Write | UInt32 | Specifies that all anonymous/anyone links that have been created (or will be created) will expire after the set number of days. Only applies if OverrideTenantAnonymousLinkExpirationPolicy is set to true. To remove the expiration requirement, set the value to zero (0) | |
| SocialBarOnSitePagesDisabled | Write | Boolean | Disables or enables the Social Bar for Site Collection. | |
| OverrideTenantAnonymousLinkExpirationPolicy | Write | Boolean | False - Respect the organization-level policy for anonymous or anyone link expiration. True - Override the organization-level policy for anonymous or anyone link expiration (can be more or less restrictive) | |
| Ensure | Write | String | Present ensures the site collection exists, absent ensures it is removed | Present, Absent |
| Credential | Write | PSCredential | Credentials of the account to authenticate with. | |
| ApplicationId | Write | String | Id of the Azure Active Directory application to authenticate with. | |
| ApplicationSecret | Write | PSCredential | Secret of the Azure Active Directory application to authenticate with. | |
| TenantId | Write | String | Name of the Azure Active Directory tenant used for authentication. Format contoso.onmicrosoft.com | |
| CertificateThumbprint | Write | String | Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication. | |
| CertificatePassword | Write | PSCredential | Username can be made up to anything but password will be used for CertificatePassword | |
| CertificatePath | Write | String | Path to certificate used in service principal usually a PFX file. | |
| ManagedIdentity | Write | Boolean | Managed ID being used for authentication. | |
| AccessTokens | Write | String[] | Access token used for authentication. |
Description¶
This resource allows users to create and monitor SharePoint Online Site Collections.
Permissions¶
Graph¶
To authenticate with the Graph API, this resource requires the following permissions:
Delegated permissions¶
- Read
-
Domain.Read.All
-
Update
- Domain.Read.All
Application permissions¶
- Read
-
Domain.Read.All
-
Update
- Domain.Read.All
Sharepoint¶
To authenticate with the Sharepoint API, this resource requires the following permissions:
Delegated permissions¶
- Read
-
Sites.FullControl.All
-
Update
- Sites.FullControl.All
Application permissions¶
- Read
-
Sites.FullControl.All
-
Update
- Sites.FullControl.All
Examples¶
Example 1¶
This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.
Configuration Example
{
param
(
[Parameter()]
[System.String]
$ApplicationId,
[Parameter()]
[System.String]
$TenantId,
[Parameter()]
[System.String]
$CertificateThumbprint
)
Import-DscResource -ModuleName Microsoft365DSC
Node localhost
{
SPOSite 'SPOSite-Example'
{
Url = "https://contoso.sharepoint.com/sites/marketing"
StorageMaximumLevel = 26214400
LocaleId = 1033
Template = "STS#3"
Owner = "admin@$TenantId"
Title = "Marketing"
TimeZoneId = 13
StorageWarningLevel = 25574400
SharingCapability = "Disabled"
CommentsOnSitePagesDisabled = $false
DisableAppViews = "NotDisabled"
DisableCompanyWideSharingLinks = "NotDisabled"
DisableFlows = $false
DefaultSharingLinkType = "None"
DefaultLinkPermission = "None"
DefaultShareLinkScope = "SpecificPeople"
DefaultShareLinkRole = "View"
LoopDefaultSharingLinkScope = "SpecificPeople"
LoopDefaultSharingLinkRole = "View"
OverrideSharingCapability = $true
OverrideTenantOrganizationSharingLinkExpirationPolicy = $true
OrganizationSharingLinkMaxExpirationInDays = 180
OrganizationSharingLinkRecommendedExpirationInDays = 90
OverrideTenantAnonymousLinkExpirationPolicy = $false
SharingDomainRestrictionMode = "None"
ShowPeoplePickerSuggestionsForGuestUsers = $false
RequestFilesLinkEnabled = $false
ReadOnlyForUnmanagedDevices = $false
RestrictedAccessControl = $false
RestrictContentOrgWideSearch = $false
RestrictedToRegion = "NoRestriction"
InheritVersionPolicyFromTenant = $true
AllowFileArchive = $false
AllowSelfServiceUpgrade = $true
DenyAddAndCustomizePages = $true
AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled = $true
ListsShowHeaderAndNavigation = $false
HidePeoplePreviewingFiles = $false
HidePeopleWhoHaveListsOpen = $false
SocialBarOnSitePagesDisabled = $false
Ensure = "Present"
ApplicationId = $ApplicationId
TenantId = $TenantId
CertificateThumbprint = $CertificateThumbprint
}
}
}