MC1213770 Medium
(Updated) Microsoft Purview | Data lifecycle Management cmdlet connectivity change
Summary AI-generated
Starting April 30, 2026, admins must use Exchange Online PowerShell v3.9.0+ and the -EnableSearchOnlySession parameter to run Data Lifecycle Management cmdlets for enhanced security.
Suggested actions AI-generated
- Update scripts to use -EnableSearchOnlySession
- Upgrade to Exchange Online PowerShell v3.9.0 or newer
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1238428 (Updated) Microsoft Purview eDiscovery Configuration change for PowerShell cmdlet case
- MC1455013 (Updated) Microsoft Purview: Data Lifecycle Management- Azure PST Import
- MC1281505 (Updated) Microsoft Purview: Data Lifecycle Management- Azure PST Import
- MC1248389 (Updated) Retirement of -Credential parameter when connecting to Exchange Online PowerShell
- MC1469565 Microsoft Purview | Data Lifecycle Management - Graph API Support for archive mailboxes
- MC1194077 Microsoft Purview | Data Lifecycle Management - New cmdlet to remove retention holds from inactive mailboxes
Original post from Microsoft
Updated April 20, 2026: We have updated the timeline. Thank you for your patience.
Introduction
Connectivity changes between cmdlets and Microsoft 365 services like SharePoint and Exchange now require a new parameter for improved security and modern authentication. Starting April 30, 2026, Admins must use Exchange Online PowerShell v3.9.0 or later and include the -EnableSearchOnlySession parameter when running Connect-IPPSession to execute Data Lifecycle Management cmdlets.
When this will happen:
Enforcement begins April 30, 2026.
How this affects your organization:
- Who is affected: Admins using Data Lifecycle Management cmdlets in Security & Compliance PowerShell.
- What will happen:
- You must use Exchange Online PowerShell v3.9.0 or later.
- You must include the
-EnableSearchOnlySessionparameter when runningConnect-IPPSession. - This applies to the following cmdlets:
New-RetentionCompliancePolicySet-RetentionCompliancePolicyNew-RetentionComplianceRuleSet-RetentionComplianceRuleNew-ComplianceTagSet-ComplianceTagRemove-ComplianceTagNew-ComplianceRetentionEventSet- ComplianceRetentionEventRemove- ComplianceRetentionEventNew-ComplianceRetentionEventTypeSet-ComplianceRetentionEventTypeRemove- ComplianceRetentionEventType
- No impact for users accessing Data Lifecycle Management through the Purview portal.
- Cmdlets remain incompatible with Certificate-Based Authentication (CBA).
What you can do to prepare:
- Update scripts and workflows to include the
-EnableSearchOnlySessionparameter. - Ensure your organization is using Exchange Online PowerShell version 3.9.0 or later.
- For more information, visit: Learn about Data Lifecycle Management solutions in Microsoft Purview.
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.
Additional details from Microsoft
- Summary
- Starting April 30, 2026, admins using Data Lifecycle Management cmdlets must use Exchange Online PowerShell v3.9.0+ and include the -EnableSearchOnlySession parameter with Connect-IPPSession for improved security. This change affects specific cmdlets but not the Purview portal, and cmdlets remain incompatible with Certificate-Based Authentication.