Public/generated/Get-KriticalUtcmEXOOutboundConnector.ps1

# Kritical.PS.UTCM | Microsoft Graph UTCM REST API toolkit
# (c) 2026 Kritical Pty Ltd | https://kritical.net
# Kritical brand banner is rendered at module load via Write-KriticalUtcmBanner.

function Get-KriticalUtcmEXOOutboundConnector {
<#
.SYNOPSIS
    Kritical.UTCM shim for M365DSC resource EXOOutboundConnector.

.DESCRIPTION

    Search-replace safe: callers that today invoke
        Get-M365DSCEXOOutboundConnector -Credential $cred -TenantId $tid
    can rename to
        Get-KriticalUtcmEXOOutboundConnector -Credential $cred -TenantId $tid
    with ZERO other edits. Parameter shape matches the M365DSC .schema.mof
    exactly. By default -PreferM365DscBehavior is true.

    Actual Graph dispatch is delegated to Invoke-KriticalUtcmM365DscSchemaBridge.
    Bridge maps resource → Graph endpoint per per-resource wave; where mapping
    is not yet shipped, bridge returns an object with Verdict='UNMAPPED'.

.NOTES
    Workload: Exchange
    Param count: 22
#>

[CmdletBinding()]
param(
        # The Identity parameter specifies the outbound connector that you want to modify.
[Parameter(Mandatory)] [string]$Identity,
        # Specifies whether connector is enabled.
[bool]$Enabled,
        # Specifies whether connector should use MXRecords for target resolution.
[bool]$UseMXRecord,
        # The Comment parameter specifies an optional comment.
[string]$Comment,
        # The ConnectorSource parameter specifies how the connector is created. DO NOT CHANGE THIS!
[ValidateSet('Default','Migrated','HybridWizard')] [string]$ConnectorSource,
        # The ConnectorType parameter specifies a category for the domains that are serviced by the connector.
[ValidateSet('Partner','OnPremises')] [string]$ConnectorType,
        # The TlsDomain parameter specifies the domain name that the Outbound connector uses to verify the FQDN of the target certificate when establishing a TLS secured connection. This parameter is only used if the TlsSettings parameter is set to DomainValidation. Valid input for the TlsDomain parameter is an SMTP domain. You can use a wildcard character to specify all subdomains of a specified domain, as shown in the following example: *.contoso.com. However, you can't embed a wildcard character, as shown in the following example: domain.*.contoso.com
[string]$TlsDomain,
        # The TlsSettings parameter specifies the TLS authentication level that's used for outbound TLS connections established by this Outbound connector.
[ValidateSet('EncryptionOnly','CertificateValidation','DomainValidation')] [string]$TlsSettings,
        # The IsTransportRuleScoped parameter specifies whether the Outbound connector is associated with a transport rule (also known as a mail flow rule).
[bool]$IsTransportRuleScoped,
        # The RouteAllMessagesViaOnPremises parameter specifies that all messages serviced by this connector are first routed through the on-premises messaging system (Centralized mailrouting).
[bool]$RouteAllMessagesViaOnPremises,
        # The CloudServicesMailEnabled parameter specifies whether the connector is used for hybrid mail flow between an on-premises Exchange environment and Microsoft Office 365. Specifically, this parameter controls how certain internal X-MS-Exchange-Organization-* message headers are handled in messages that are sent between accepted domains in the on-premises and cloud organizations. These headers are collectively known as cross-premises headers. DO NOT USE MANUALLY!
[bool]$CloudServicesMailEnabled,
        # The AllAcceptedDomains parameter specifies whether the Outbound connector is used in hybrid organizations where message recipients are in accepted domains of the cloud-based organization.
[bool]$AllAcceptedDomains,
        # The SenderRewritingEnabled parameter specifies that all messages that normally qualify for SRS rewriting are rewritten for routing through the on-premises email system.
[bool]$SenderRewritingEnabled,
        # The TestMode parameter specifies whether you want to enabled or disable test mode for the Outbound connector.
[bool]$TestMode,
        # Specifies if this Outbound connector should exist.
[ValidateSet('Present','Absent')] [string]$Ensure,
        # Credentials of the Exchange Global Admin
[string]$Credential,
        # Id of the Azure Active Directory application to authenticate with.
[string]$ApplicationId,
        # Id of the Azure Active Directory tenant used for authentication.
[string]$TenantId,
        # Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
[string]$CertificateThumbprint,
        # Username can be made up to anything but password will be used for CertificatePassword
[string]$CertificatePassword,
        # Path to certificate used in service principal usually a PFX file.
[string]$CertificatePath,
        # Managed ID being used for authentication.
[bool]$ManagedIdentity
)
    Invoke-KriticalUtcmM365DscSchemaBridge -ResourceName 'EXOOutboundConnector' -Workload 'Exchange' -Verb 'Get' -CallerParams $PSBoundParameters
}