Public/generated/Get-KriticalUtcmEXOQuarantinePolicy.ps1

# Kritical.PS.UTCM | Microsoft Graph UTCM REST API toolkit
# (c) 2026 Kritical Pty Ltd | https://kritical.net
# Kritical brand banner is rendered at module load via Write-KriticalUtcmBanner.

function Get-KriticalUtcmEXOQuarantinePolicy {
<#
.SYNOPSIS
    Kritical.UTCM shim for M365DSC resource EXOQuarantinePolicy.

.DESCRIPTION

    Search-replace safe: callers that today invoke
        Get-M365DSCEXOQuarantinePolicy -Credential $cred -TenantId $tid
    can rename to
        Get-KriticalUtcmEXOQuarantinePolicy -Credential $cred -TenantId $tid
    with ZERO other edits. Parameter shape matches the M365DSC .schema.mof
    exactly. By default -PreferM365DscBehavior is true.

    Actual Graph dispatch is delegated to Invoke-KriticalUtcmM365DscSchemaBridge.
    Bridge maps resource → Graph endpoint per per-resource wave; where mapping
    is not yet shipped, bridge returns an object with Verdict='UNMAPPED'.

.NOTES
    Workload: Exchange
    Param count: 17
#>

[CmdletBinding()]
param(
        # The Identity parameter specifies the QuarantinePolicy you want to modify.
[Parameter(Mandatory)] [string]$Identity,
        # The EndUserQuarantinePermissionsValue parameter specifies the end-user permissions for the quarantine policy.
[int]$EndUserQuarantinePermissionsValue,
        # The ESNEnabled parameter specifies whether to enable quarantine notifications (formerly known as end-user spam notifications) for the policy.
[bool]$ESNEnabled,
        # The OrganizationBrandingEnabled parameter enables or disables organization branding in the end-user quarantine notification messages.
[bool]$OrganizationBrandingEnabled,
        # Specifies if this QuarantinePolicy should exist.
[ValidateSet('Present','Absent')] [string]$Ensure,
        # Credentials of the Exchange Global Admin
[string]$Credential,
        # Id of the Azure Active Directory application to authenticate with.
[string]$ApplicationId,
        # Id of the Azure Active Directory tenant used for authentication.
[string]$TenantId,
        # Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
[string]$CertificateThumbprint,
        # Username can be made up to anything but password will be used for CertificatePassword
[string]$CertificatePassword,
        # Path to certificate used in service principal usually a PFX file.
[string]$CertificatePath,
        # Managed ID being used for authentication.
[bool]$ManagedIdentity,
        # The EndUserSpamNotificationFrequency parameter species how often quarantine notifications are sent to users. Valid values are: 04:00:00 (4 hours),1.00:00:00 (1 day),7.00:00:00 (7 days)
[string]$EndUserSpamNotificationFrequency,
        # The QuarantinePolicyType parameter filters the results by the specified quarantine policy type. Valid values are: QuarantinePolicy, GlobalQuarantinePolicy
[string]$QuarantinePolicyType,
        # This parameter is reserved for internal Microsoft use.
[string]$EndUserSpamNotificationFrequencyInDays,
        # This parameter is reserved for internal Microsoft use.
[string]$CustomDisclaimer,
        # The EndUserSpamNotificationCustomFromAddress specifies the email address of an existing internal sender to use as the sender for quarantine notifications. To set this parameter back to the default email address quarantine@messaging.microsoft.com, use the value $null.
[string]$EndUserSpamNotificationCustomFromAddress
)
    Invoke-KriticalUtcmM365DscSchemaBridge -ResourceName 'EXOQuarantinePolicy' -Workload 'Exchange' -Verb 'Get' -CallerParams $PSBoundParameters
}