Skip to content

SPOTenantSettings

Parameters

Parameter Attribute DataType Description Allowed Values
IsSingleInstance Key String Specifies the resource is a single instance, the value must be 'Yes' Yes
EnableAzureADB2BIntegration Write Boolean Enables OneDrive and SharePoint integration with Microsoft Entra B2B.
MinCompatibilityLevel Write UInt32 Specifies the lower bound on the compatibility level for new sites.
MaxCompatibilityLevel Write UInt32 Specifies the upper bound on the compatibility level for new sites.
SearchResolveExactEmailOrUPN Write Boolean Removes the search capability from People Picker. Note, recently resolved names will still appear in the list until browser cache is cleared or expired.
OfficeClientADALDisabled Write Boolean When set to true this will disable the ability to use Modern Authentication that leverages ADAL across the tenant.
OneDriveRequestFilesLinkEnabled Write Boolean Allows configuring whether users will be able to create anonymous requests for people to upload files regardless of the Share with anyone link configuration setting.
OneDriveRequestFilesLinkExpirationInDays Write UInt32 Specifies the number of days before a Request files link expires for all OneDrive sites. The value can be from 0 to 730 days. To remove the expiration requirement, set the value to zero (0).
LegacyAuthProtocolsEnabled Write Boolean Setting this parameter prevents Office clients using non-modern authentication protocols from accessing SharePoint Online resources.
SignInAccelerationDomain Write String Specifies the home realm discovery value to be sent to Azure Active Directory (AAD) during the user sign-in process.
UsePersistentCookiesForExplorerView Write Boolean Lets SharePoint issue a special cookie that will allow this feature to work even when Keep Me Signed In is not selected.
PublicCdnEnabled Write Boolean Configure PublicCDN
PublicCdnAllowedFileTypes Write String Configure filetypes allowed for PublicCDN
UseFindPeopleInPeoplePicker Write Boolean When set to $true, users aren't able to share with security groups or SharePoint groups.
NotificationsInSharePointEnabled Write Boolean When set to $true, users aren't able to share with security groups or SharePoint groups.
OwnerAnonymousNotification Write Boolean Specifies whether an email notification should be sent to the OneDrive for Business owners when an anonymous links are created or changed.
AllowCommentsTextOnEmailEnabled Write Boolean When this parameter is set to true, an email notification that user receives when is mentioned, includes the surrounding document context. Set it to false to disable this feature.
AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled Write Boolean Enables or disables web property bag update when DenyAddAndCustomizePages is enabled. When AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled is set to $true, web property bag can be updated even if DenyAddAndCustomizePages is turned on when the user had AddAndCustomizePages (prior to DenyAddAndCustomizePages removing it).
AppBypassInformationBarriers Write Boolean Enables of disables applications running in app-only mode to access IB sites.
ApplyAppEnforcedRestrictionsToAdHocRecipients Write Boolean When the feature is enabled, all guest users are subject to conditional access policy. By default guest users who are accessing SharePoint Online files with pass code are exempt from the conditional access policy.
ArchiveRedirectUrl Write String Can be used to configure a custom page to show when a user is navigating to a SharePoint Online site that has been archived using Microsoft Syntex Archiving.
BlockDownloadFileTypeIds Write String[] The File Type IDs which need to specified to prevent download. Allowed values: TeamsMeetingRecording.
BlockDownloadFileTypePolicy Write Boolean You can block the download of Teams meeting recording files from SharePoint or OneDrive. This allows users to remain productive while addressing the risk of accidental data loss. Users have browser-only access to play the meeting recordings with no ability to download or sync files or access them through apps.
BlockSendLabelMismatchEmail Write Boolean Allows blocking of the automated e-mail being sent when somebody uploads a document to a site that's protected with a sensitivity label and their document has a higher priority sensitivity label than the sensitivity label applied to the site.
CoreRequestFilesLinkExpirationInDays Write UInt32 Specifies the number of days before a Request files link expires for all SharePoint sites (not including OneDrive sites). The value can be from 0 to 730 days.
CoreRequestFilesLinkEnabled Write Boolean Enable or disable the Request files link on the core partition for all SharePoint sites (not including OneDrive sites). If this value is not set, Request files will only show for OneDrives with Anyone links enabled.
DefaultOneDriveInformationBarrierMode Write String The DefaultOneDriveInformationBarrierMode sets the information barrier mode for all OneDrive sites. The valid values are: Open, Explicit, Implicit, OwnerModerated, Mixed. Open, Explicit, Implicit, OwnerModerated, Mixed
AllowAnonymousMeetingParticipantsToAccessWhiteboards Write String Allows temporary whiteboard collaboration for anonymous meeting participants during Teams meetings. Unspecified, On, Off
ExcludedBlockDownloadGroupIds Write String[] This parameter exempts users in the specified security groups from this policy so that they can download meeting recording files.
DisableDocumentLibraryDefaultLabeling Write Boolean Use this to turn off setting the default sensitivity label for a document library.
IsEnableAppAuthPopUpEnabled Write Boolean Enables or disables users in the organization to authenticate SharePoint applications using popups.
ExpireVersionsAfterDays Write UInt32 Specifies the number of days to keep versions when version history limits are managed manually.
MajorVersionLimit Write UInt32 Specifies the number of major versions to keep when version history limits are managed manually.
EnableAutoExpirationVersionTrim Write Boolean Enables or disables AutoExpiration version trim for document libraries. Parameter ExpireVersionsAfterDays is required when EnableAutoExpirationVersionTrim is false. Set ExpireVersionsAfterDays to 0 for NoExpiration, set it to greater or equal 30 for ExpireAfter.
DisableVivaConnectionsAnalytics Write Boolean Use this parameter to disable or enable Viva Connections analytics.
CoreBlockGuestsAsSiteAdmin Write String Determines whether guest users can be site collection administrators on SharePoint sites. Valid values are: Unspecified, On, Off Unspecified, On, Off
IsWBFluidEnabled Write Boolean Sets whether Whiteboard is enabled or disabled for OneDrive for Business users.
IsCollabMeetingNotesFluidEnabled Write Boolean Gets or sets a value to specify whether CollabMeetingNotes Fluid Framework is enabled.
IBImplicitGroupBased Write Boolean Gets or sets the IBImplicitGroupBased value.
ShowOpenInDesktopOptionForSyncedFiles Write Boolean Displays the Open in desktop option for files synchronized with the OneDrive sync app.
ShowPeoplePickerGroupSuggestionsForIB Write Boolean Allows showing group suggestions for information barriers in the People Picker.
ReduceTempTokenLifetimeEnabled Write Boolean Enables reduced session timeout for temporary URLs used by apps for document download scenarios. Reduction occurs when an app redeeming an IP address does not match the original requesting IP. The default value is 15 minutes if ReduceTempTokenLifetimeValue is not set.
ReduceTempTokenLifetimeValue Write UInt32 Optional value, in minutes, to set the session timeout for temporary URLs. Allowed values are from 5 to 15. The default value is 15 minutes.
ViewersCanCommentOnMediaDisabled Write Boolean Controls whether viewers commenting on media items is disabled or not.
ConditionalAccessPolicyErrorHelpLink Write String Specifies a help link shown when Conditional Access Policy blocks a user. The value must be a valid URL starting with http:// or https://.
CustomizedExternalSharingServiceUrl Write String Specifies a URL appended to the external sharing policy block message to direct users to internal guidance or request portals.
IncludeAtAGlanceInShareEmails Write Boolean Enables or disables the At A Glance feature in sharing e-mails.
MassDeleteNotificationDisabled Write Boolean Enables or disables mass delete detection notifications.
OneDriveBlockGuestsAsSiteAdmin Write String Sets the sharing state for blocking guests as site admin in OneDrive. Valid values are: On, Off, Unspecified On, Off, Unspecified
RecycleBinRetentionPeriod Write UInt32 Sets the retention period for the recycle bin. The value of Recycle Bin Retention Period must be between 14 and 93. By default it is set to 93.
LegacyBrowserAuthProtocolsEnabled Write Boolean Enables or disables legacy browser authentication protocols.
EnableDiscoverableByOrganizationForVideos Write Boolean Enables or disables showing the organization-wide sharing option in the sharing dialog for videos.
RestrictedAccessControlforSitesErrorHelpLink Write String Sets a custom learn more link to inform users denied access due to restricted site access control policy.
Workflow2010Disabled Write Boolean Sets a value to specify whether Workflow 2010 is disabled.
HideSyncButtonOnDocLib Write Boolean Sets a value to specify whether the sync button on document libraries is hidden.
StreamLaunchConfig Write SInt32 Sets the default destination for the Stream app launcher tile.
EnableMediaReactions Write Boolean Controls whether media reactions are enabled.
ContentSecurityPolicyEnforcement Write Boolean Controls whether content security policy is enabled.
DisableSpacesActivation Write Boolean Enables or disables activation of spaces.
AllowAppsBypassOfUnmanagedDevicePolicy Write Boolean Controls whether apps can bypass the unmanaged device policy.
DisabledAdaptiveCardExtensionIds Write String[] Allows administrators to prevent specific Adaptive Card Extensions from being added to pages or rendering on pages where they were previously added.
EnableNotificationsSubscriptions Write Boolean Enables or disables writing SharePoint News and Announcement notification data to each user's NewsNotificationList.
EnforceRequestDigest Write Boolean When set to true, a valid request digest is required for state-changing SOAP API calls.
TlsTokenBindingPolicyValue Write String Sets the Transport Layer Security (TLS) token binding policy setting. Audit, None, PassiveEnforcement, StrictEnforcement
AuthContextResilienceMode Write String Sets the authentication context resilience mode. DefaultAAD, Disabled, Enabled
AllOrganizationSecurityGroupId Write String Sets the All-Organization Security Group by object ID.
ContentTypeSyncSiteTemplatesList Write String[] Sets the site templates that receive content type hub synchronization.
FilePickerExternalImageSearchEnabled Write Boolean Sets whether webparts that support inserting images, like for example Image or Hero webpart, the Web search (Powered by Bing) should allow choosing external images.
HideDefaultThemes Write Boolean Defines if the default themes are visible or hidden
HideSyncButtonOnTeamSite Write Boolean To enable or disable Sync button on Team sites
IsDataAccessInCardDesignerEnabled Write Boolean Allows turning on support for data access in the Viva Connections Adaptive Card Designer.
MarkNewFilesSensitiveByDefault Write String Allow or block external sharing until at least one Office DLP policy scans the content of the file. AllowExternalSharing, BlockExternalSharing
MediaTranscription Write String When the feature is enabled, videos can have transcripts generated on demand or generated automatically in certain scenarios. This is the default because the policy is default on. If a video owner decides they don't want the transcript, they can always hide or delete it from that video. Possible values: Enabled, Disabled. Disabled, Enabled
MediaTranscriptionAutomaticFeatures Write String When the feature is enabled, videos can have transcripts generated automatically on upload. The policy is default on. If a tenant admin decides to disable the feature, he can do so by disabling the policy at tenant level. This feature can not be enabled or disabled at site level. Possible values: Enabled, Disabled. Disabled, Enabled
DisabledWebPartIds Write String[] Provide GUID for the Web Parts that are to be disabled on the Sharepoint Site
SiteOwnerManageLegacyServicePrincipalEnabled Write Boolean This parameter allows site owners to create or update the service principal.
SocialBarOnSitePagesDisabled Write Boolean Disables or enables the Social Bar. It will give users the ability to like a page, see the number of views, likes, and comments on a page, and see the people who have liked a page.
CommentsOnSitePagesDisabled Write Boolean Set to false to enable a comment section on all site pages, users who have access to the pages can leave comments. Set to true to disable this feature.
EnableAIPIntegration Write Boolean Boolean indicating if Azure Information Protection (AIP) should be enabled on the tenant.
EnableSensitivityLabelForPDF Write Boolean Allows turning on support for PDFs with sensitivity labels.
ExemptNativeUsersFromTenantLevelRestricedAccessControl Write Boolean Determines whether or not we need to include external participants in shared channels for SharePoint access restriction.
AllowSelectSGsInODBListInTenant Write String[] List of security groups to include in OneDrive access restrictions
DenySelectSGsInODBListInTenant Write String[] List of security groups to exclude in OneDrive access restrictions
DenySelectSecurityGroupsInSPSitesList Write String[] List of security groups to exclude in SharePoint access restrictions
AllowSelectSecurityGroupsInSPSitesList Write String[] List of security groups to include in SharePoint access restrictions.
TenantDefaultTimezone Write String The default timezone of a tenant for newly created sites.
MobileFriendlyUrlEnabledInTenant Write Boolean Gets or sets a value to specify if user checks handle mobile friendly url.
AllowDownloadingNonWebViewableFiles Write Boolean Gets or sets a value to specify the advanced setting of the conditional access policy.
AllowEditing Write Boolean Prevents users from editing Office files in the browser and copying and pasting Office file contents out of the browser window.
AllowFileArchive Write Boolean Enables or disables file-level archiving for SharePoint Online sites in the tenant. When set to $false, users can no longer archive files on any site even if the site-level setting is enabled. Existing archived files remain archived and can still be reactivated.
AllowFileArchiveOnNewSitesByDefault Write Boolean Controls whether newly created SharePoint Online sites have file-level archiving enabled by default. Use this together with -AllowFileArchive $true when you want new sites to inherit file archiving automatically instead of enabling it site by site.
HideSyncButtonOnODB Write Boolean Set whether to hide the sync button on OneDrive for Business sites.
DisableCustomAppAuthentication Write Boolean Configure if ACS-based app-only authentication should be disabled or not.
DisabledModernListTemplateIds Write String[] Guids of out of the box modern list templates to hide when creating a new list.
DisablePersonalListCreation Write Boolean Allows configuring whether personal lists created within the OneDrive for Business site of the user is enabled or disabled in the tenant. If set to $false, personal lists will be allowed to be created in the tenant. If set to $true, it will be disabled in the tenant.
DisplayNamesOfFileViewersInSpo Write Boolean Allows configuring whether display name of people who view the file are visible in the property pane of the site in SharePoint site collection.
IsFluidEnabled Write Boolean Allows configuration on whether Fluid components are enabled or disabled in the tenant. If set to $true, then this feature will be enabled on all sites in the tenant. If set to $false, it will be disabled on all sites in the tenant.
IsLoopEnabled Write Boolean Allows configuring whether loop components are enabled or disabled in the tenant. If set to $true, loop components will be allowed to be created in the tenant. If set to $false, it will be disabled in the tenant.
IsSharePointAddInsDisabled Write Boolean When the feature is enabled, all the add-ins features will be disabled.
IsSharePointNewsfeedEnabled Write Boolean Indicates whether the newsfeed is allowed on the modern site pages in SharePoint.
IsSiteCreationEnabled Write Boolean Indicates whether users are allowed to create sites.
IsSiteCreationUiEnabled Write Boolean Indicates whether the UI commands for creating sites are shown.
IsSitePagesCreationEnabled Write Boolean Indicates whether creating new modern pages is allowed on SharePoint sites.
KnowledgeAgentEnabled Write Boolean Enables or disables the Knowledge Agent feature tenant-wide. When set to $true, the Knowledge Agent functionality is enabled for the tenant; when set to $false it is disabled. Use this parameter to control tenant-level Knowledge Agent behavior.
KnowledgeAgentSelectedSitesList Write String[] Specifies a list of site collection URLs that should be selected for the tenant Knowledge Agent. Each entry must be a full site URL (for example: https://contoso.sharepoint.com/sites/team1). The cmdlet will resolve each URL to the corresponding site id and configure the tenant Knowledge Agent to target those sites.
NoAccessRedirectUrl Write String Specifies the URL of the redirected site for those site collections which have the locked state 'NoAccess'. The valid values are: '' (default) - Blank by default, this will also remove or clear any value that has been set. Full URL - Example: https://contoso.sharepoint.com/Pages/Locked.aspx
RequireAcceptingAccountMatchInvitedAccount Write Boolean Ensures that an external user can only accept an external sharing invitation with an account matching the invited email address. Note, this only applies to new external users accepting new sharing invitations. Also, the resource owner must share with an organizational or Microsoft account or the external user will be unable to access the resource.
SpecialCharactersStateInFileFolderNames Write String Permits the use of special characters in file and folder names in SharePoint Online and OneDrive for Business document libraries. The only two characters that can be managed at this time are the # and % characters. NoPreference, Allowed, Disallowed
Ensure Write String Only accepted value is 'Present'. Present, Absent
Credential Write PSCredential Credentials of the account to authenticate with.
ApplicationId Write String Id of the Azure Active Directory application to authenticate with.
ApplicationSecret Write PSCredential Secret of the Azure Active Directory application to authenticate with.
TenantId Write String Name of the Azure Active Directory tenant used for authentication. Format contoso.onmicrosoft.com
CertificateThumbprint Write String Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
CertificatePassword Write PSCredential Username can be made up to anything but password will be used for CertificatePassword
CertificatePath Write String Path to certificate used in service principal usually a PFX file.
ManagedIdentity Write Boolean Managed ID being used for authentication.
AccessTokens Write String[] Access token used for authentication.

Description

This resource allows users to configure and monitor the tenant settings for their SPO tenant settings.

Permissions

Graph

To authenticate with the Graph API, this resource requires the following permissions:

Delegated permissions

  • Read
  • Domain.Read.All, SharePointTenantSettings.Read.All

  • Update

  • Domain.Read.All, SharePointTenantSettings.ReadWrite.All

Application permissions

  • Read
  • Domain.Read.All, SharePointTenantSettings.Read.All

  • Update

  • Domain.Read.All, SharePointTenantSettings.ReadWrite.All

Sharepoint

To authenticate with the Sharepoint API, this resource requires the following permissions:

Delegated permissions

  • Read
  • Sites.FullControl.All

  • Update

  • Sites.FullControl.All

Application permissions

  • Read
  • Sites.FullControl.All

  • Update

  • Sites.FullControl.All

Examples

Example 1

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        SPOTenantSettings 'SPOTenantSettings-Example'
        {
            IsSingleInstance                                               = "Yes"
            EnableAzureADB2BIntegration                                    = $true
            MinCompatibilityLevel                                          = 16
            MaxCompatibilityLevel                                          = 16
            SearchResolveExactEmailOrUPN                                   = $false
            OfficeClientADALDisabled                                       = $false
            OneDriveRequestFilesLinkEnabled                                = $false
            LegacyAuthProtocolsEnabled                                     = $true
            LegacyBrowserAuthProtocolsEnabled                              = $true
            SignInAccelerationDomain                                       = ""
            UsePersistentCookiesForExplorerView                            = $false
            PublicCdnEnabled                                               = $false
            UseFindPeopleInPeoplePicker                                    = $false
            NotificationsInSharePointEnabled                               = $true
            EnableNotificationsSubscriptions                               = $true
            OwnerAnonymousNotification                                     = $true
            AllowCommentsTextOnEmailEnabled                                = $true
            AllowWebPropertyBagUpdateWhenDenyAddAndCustomizePagesIsEnabled = $true
            AppBypassInformationBarriers                                   = $false
            ApplyAppEnforcedRestrictionsToAdHocRecipients                  = $true
            ArchiveRedirectUrl                                             = "https://contoso.sharepoint.com/sites/intranet/SitePages/Archived-site.aspx"
            NoAccessRedirectUrl                                            = "https://contoso.sharepoint.com/sites/intranet/SitePages/Site-locked.aspx"
            ConditionalAccessPolicyErrorHelpLink                           = "https://contoso.sharepoint.com/sites/intranet/SitePages/Access-blocked.aspx"
            CustomizedExternalSharingServiceUrl                            = "https://contoso.sharepoint.com/sites/intranet/SitePages/External-sharing-guidance.aspx"
            RestrictedAccessControlforSitesErrorHelpLink                   = "https://contoso.sharepoint.com/sites/intranet/SitePages/Request-site-access.aspx"
            BlockDownloadFileTypePolicy                                    = $false
            BlockSendLabelMismatchEmail                                    = $false
            CoreRequestFilesLinkEnabled                                    = $false
            DefaultOneDriveInformationBarrierMode                          = "Open"
            AllowAnonymousMeetingParticipantsToAccessWhiteboards           = "Off"
            DisableDocumentLibraryDefaultLabeling                          = $false
            IsEnableAppAuthPopUpEnabled                                    = $true
            EnableAutoExpirationVersionTrim                                = $false
            ExpireVersionsAfterDays                                        = 180
            MajorVersionLimit                                              = 500
            RecycleBinRetentionPeriod                                      = 93
            DisableVivaConnectionsAnalytics                                = $false
            CoreBlockGuestsAsSiteAdmin                                     = "On"
            OneDriveBlockGuestsAsSiteAdmin                                 = "On"
            IsWBFluidEnabled                                               = $true
            IsCollabMeetingNotesFluidEnabled                               = $true
            IsFluidEnabled                                                 = $true
            IsLoopEnabled                                                  = $true
            IBImplicitGroupBased                                           = $false
            ShowOpenInDesktopOptionForSyncedFiles                          = $true
            ShowPeoplePickerGroupSuggestionsForIB                          = $false
            ReduceTempTokenLifetimeEnabled                                 = $true
            ReduceTempTokenLifetimeValue                                   = 15
            ViewersCanCommentOnMediaDisabled                               = $false
            IncludeAtAGlanceInShareEmails                                  = $true
            MassDeleteNotificationDisabled                                 = $false
            EnableDiscoverableByOrganizationForVideos                      = $true
            Workflow2010Disabled                                           = $true
            HideSyncButtonOnDocLib                                         = $false
            HideSyncButtonOnTeamSite                                       = $false
            HideSyncButtonOnODB                                            = $false
            StreamLaunchConfig                                             = 1
            EnableMediaReactions                                           = $true
            ContentSecurityPolicyEnforcement                               = $false
            DisableSpacesActivation                                        = $false
            AllowAppsBypassOfUnmanagedDevicePolicy                         = $false
            DisabledAdaptiveCardExtensionIds                               = @()
            DisabledWebPartIds                                             = @()
            DisabledModernListTemplateIds                                  = @()
            EnforceRequestDigest                                           = $true
            TlsTokenBindingPolicyValue                                     = "None"
            AuthContextResilienceMode                                      = "DefaultAAD"
            ContentTypeSyncSiteTemplatesList                               = @("STS#3", "GROUP#0")
            FilePickerExternalImageSearchEnabled                           = $true
            HideDefaultThemes                                              = $false
            IsDataAccessInCardDesignerEnabled                              = $false
            MarkNewFilesSensitiveByDefault                                 = "AllowExternalSharing"
            MediaTranscription                                             = "Enabled"
            MediaTranscriptionAutomaticFeatures                            = "Enabled"
            SiteOwnerManageLegacyServicePrincipalEnabled                   = $false
            SocialBarOnSitePagesDisabled                                   = $false
            CommentsOnSitePagesDisabled                                    = $false
            EnableAIPIntegration                                           = $false
            EnableSensitivityLabelForPDF                                   = $true
            ExemptNativeUsersFromTenantLevelRestricedAccessControl         = $true
            AllowSelectSGsInODBListInTenant                                = @()
            DenySelectSGsInODBListInTenant                                 = @()
            AllowSelectSecurityGroupsInSPSitesList                         = @()
            DenySelectSecurityGroupsInSPSitesList                          = @()
            TenantDefaultTimezone                                          = "(UTC-08:00) Pacific Time (US and Canada)"
            MobileFriendlyUrlEnabledInTenant                               = $true
            AllowDownloadingNonWebViewableFiles                            = $true
            AllowEditing                                                   = $true
            AllowFileArchive                                               = $true
            AllowFileArchiveOnNewSitesByDefault                            = $false
            DisableCustomAppAuthentication                                 = $false
            DisablePersonalListCreation                                    = $false
            DisplayNamesOfFileViewersInSpo                                 = $true
            IsSharePointAddInsDisabled                                     = $false
            IsSharePointNewsfeedEnabled                                    = $true
            IsSiteCreationEnabled                                          = $true
            IsSiteCreationUiEnabled                                        = $true
            IsSitePagesCreationEnabled                                     = $true
            KnowledgeAgentEnabled                                          = $false
            RequireAcceptingAccountMatchInvitedAccount                     = $true
            SpecialCharactersStateInFileFolderNames                        = "Allowed"
            ApplicationId                                                  = $ApplicationId
            TenantId                                                       = $TenantId
            CertificateThumbprint                                          = $CertificateThumbprint
        }
    }
}