Public/generated/Get-KritTcmEXOAntiPhishPolicy.ps1
|
<# ·· × × × ··· SirJ's Deaddrop ··· × × × ··· — If you found this, you were meant to — ---------------- A Seriously Kritical™ Production ---------------- [] → (¯`·.¸¸.·´¯) .·´ `·. [] → `·.______________.·´ | +------------------+ | | | Kritical™ | | | | [] [] | | | | | | | | [] [] [] | | | +------------------+ | (._.·´¯`·.¸_) Your last call. And your first move. ★ ☆ ★ +61 1300 274 655 sales at kritical dot net ----------------------------------------------------------------- .COPYRIGHT (c) 2026 Kritical Pty Ltd. All rights reserved. .AUTHOR Joshua Finley <joshua.finley@kritical.net> .COMPANY Kritical Pty Ltd | ABN 39 687 048 086 Level 4 / 60 Moorabool St Geelong VIC 3220 1300 274 655 | sales@kritical.net | https://kritical.net/ .NOTES HARD RULE 13 canonical Kritical branding — do not overlay other agent banners. Auto-generated by Generate-KritTcmFromM365DscSchema.ps1 (.1507o30+). Upstream reference: Microsoft365DSC by Microsoft (MIT). This shim provides literal search-replace equivalence — see Krit.TCM/generated/index.md. #> function Get-KritTcmEXOAntiPhishPolicy { <# .SYNOPSIS Krit.TCM shim for M365DSC resource EXOAntiPhishPolicy. .DESCRIPTION Auto-generated from M365DSC .schema.mof by scripts/m365-setup/Generate-KritTcmFromM365DscSchema.ps1 (.1507o30). Search-replace safe: callers that today invoke Get-M365DSCEXOAntiPhishPolicy -Credential $cred -TenantId $tid can rename to Get-KritTcmEXOAntiPhishPolicy -Credential $cred -TenantId $tid with ZERO other edits. Parameter shape matches the M365DSC .schema.mof exactly. Per operator direction, -PreferM365DscBehavior defaults to true. Actual Graph dispatch is delegated to Invoke-KritTcmM365DscSchemaBridge. Bridge maps resource → Graph endpoint per per-resource wave; where mapping is not yet shipped, bridge returns an object with Verdict='UNMAPPED'. .NOTES Workload: Exchange Original mof: C:\Users\joshl\OneDrive - Kritical Pty Ltd\Github\KRTPax8ToShopifyConnector\.kritm365-mine\Microsoft365DSC\Modules\Microsoft365DSC\DSCResources\MSFT_EXOAntiPhishPolicy\MSFT_EXOAntiPhishPolicy.schema.mof Param count: 37 Generator wave: .1507o30 #> [CmdletBinding()] param( # The Identity parameter specifies the name of the antiphishing policy that you want to modify. [Parameter(Mandatory)] [string]$Identity, # Specify if this policy should exist or not. [ValidateSet('Present','Absent')] [string]$Ensure, # The AdminDisplayName parameter specifies a description for the policy. [string]$AdminDisplayName, # The PhishThresholdLevel parameter specifies the tolerance level that's used by machine learning in the handling of phishing messages. [ValidateSet('1','2','3','4')] [int]$PhishThresholdLevel, # The AuthenticationFailAction parameter specifies the action to take when the message fails composite authentication. [ValidateSet('MoveToJmf','Quarantine')] [string]$AuthenticationFailAction, # The TargetedUserProtectionAction parameter specifies the action to take on detected user impersonation messages for the users specified by the TargetedUsersToProtect parameter. [ValidateSet('BccMessage','Delete','MoveToJmf','NoAction','Quarantine','Redirect')] [string]$TargetedUserProtectionAction, # Specify if this policy should be enabled. Default is $true. [bool]$Enabled, # The EnableFirstContactSafetyTips parameter specifies whether to enable or disable the safety tip that's shown when recipients first receive an email from a sender or do not often receive email from a sender. [bool]$EnableFirstContactSafetyTips, # The EnableMailboxIntelligence parameter specifies whether to enable or disable mailbox intelligence (the first contact graph) in domain and user impersonation protection. [bool]$EnableMailboxIntelligence, # The EnableMailboxIntelligenceProtection specifies whether to enable or disable enhanced impersonation results based on each user's individual sender map. This intelligence allows Microsoft 365 to customize user impersonation detection and better handle false positives. [bool]$EnableMailboxIntelligenceProtection, # The EnableOrganizationDomainsProtection parameter specifies whether to enable domain impersonation protection for all registered domains in the Office 365 organization. [bool]$EnableOrganizationDomainsProtection, # The EnableSimilarDomainsSafetyTips parameter specifies whether to enable safety tips that are shown to recipients in messages for domain impersonation detections. [bool]$EnableSimilarDomainsSafetyTips, # The EnableSimilarUsersSafetyTips parameter specifies whether to enable safety tips that are shown to recipients in messages for user impersonation detections. [bool]$EnableSimilarUsersSafetyTips, # The EnableSpoofIntelligence parameter specifies whether to enable or disable antispoofing protection for the policy. [bool]$EnableSpoofIntelligence, # The EnableTargetedDomainsProtection parameter specifies whether to enable domain impersonation protection for a list of specified domains. [bool]$EnableTargetedDomainsProtection, # The EnableTargetedUserProtection parameter specifies whether to enable user impersonation protection for the users specified by the TargetedUsersToProtect parameter [bool]$EnableTargetedUserProtection, # The EnableUnauthenticatedSender parameter enables or disables unauthenticated sender identification in Outlook. [bool]$EnableUnauthenticatedSender, # The EnableUnusualCharactersSafetyTips parameter specifies whether to enable safety tips that are shown to recipients in messages for unusual characters in domain and user impersonation detections. [bool]$EnableUnusualCharactersSafetyTips, # This setting is part of spoof protection. The EnableViaTag parameter enables or disables adding the via tag to the From address in Outlook. [bool]$EnableViaTag, # Make this the default antiphishing policy [bool]$MakeDefault, # The HonorDmarcPolicy enables or disables using the sender's DMARC policy to determine what to do to messages that fail DMARC checks. [bool]$HonorDmarcPolicy, # The ImpersonationProtectionState parameter specifies the configuration of impersonation protection. [string]$ImpersonationProtectionState, # The MailboxIntelligenceProtectionAction parameter specifies what to do with messages that fail mailbox intelligence protection. [string]$MailboxIntelligenceProtectionAction, # The MailboxIntelligenceQuarantineTag specifies the quarantine policy that's used on messages that are quarantined by mailbox intelligence. [string]$MailboxIntelligenceQuarantineTag, # The SpoofQuarantineTag specifies the quarantine policy that's used on messages that are quarantined by spoof intelligence. [string]$SpoofQuarantineTag, # The TargetedDomainProtectionAction parameter specifies the action to take on detected domain impersonation messages. [ValidateSet('BccMessage','Delete','MoveToJmf','NoAction','Quarantine','Redirect')] [string]$TargetedDomainProtectionAction, # The TargetedDomainQuarantineTag specifies the quarantine policy that's used on messages that are quarantined by domain impersonation protection. [string]$TargetedDomainQuarantineTag, # The TargetedUserQuarantineTag specifies the quarantine policy that's used on messages that are quarantined by user impersonation protection. [string]$TargetedUserQuarantineTag, # The DmarcQuarantineAction parameter specifies the action to take when a message fails DMARC checks and the sender's DMARC policy is p=quarantine [ValidateSet('MoveToJmf','Quarantine')] [string]$DmarcQuarantineAction, # The DmarcRejectAction parameter specifies the action to take when a message fails DMARC checks and the sender's DMARC policy is p=reject. [ValidateSet('Quarantine','Reject')] [string]$DmarcRejectAction, # Credentials of the Exchange Global Admin [string]$Credential, # Id of the Azure Active Directory application to authenticate with. [string]$ApplicationId, # Id of the Azure Active Directory tenant used for authentication. [string]$TenantId, # Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication. [string]$CertificateThumbprint, # Username can be made up to anything but password will be used for CertificatePassword [string]$CertificatePassword, # Path to certificate used in service principal usually a PFX file. [string]$CertificatePath, # Managed ID being used for authentication. [bool]$ManagedIdentity ) Invoke-KritTcmM365DscSchemaBridge -ResourceName 'EXOAntiPhishPolicy' -Workload 'Exchange' -Verb 'Get' -CallerParams $PSBoundParameters } |