List and get tools for retention policies and labels
Add CRUD coverage for Purview retention policies and retention labels, with list and get, not delete-only. CIPP has four retention tools, and two of the four (cipp_delete_retention_policies, cipp_delete_retention_tags) only delete, with no list or get tool to check what exists first. Use case: confirm what retention already applies to a mailbox or site before changing it.
Log in to comment and vote
Comments1
Christopher Scaminaci
Oct 5
All six shipped in one release. Every CIPP tool here needs CIPP 10.5.0 or later.
Sensitivity labels and label policies: list, deploy (create or update), edit and remove labels. Label policies are read and deployed with the label. CIPP has no label policy delete.
DLP: list, deploy with rules, edit and remove policies; read rules. CIPP has no standalone rule delete; disable a rule through the deploy.
Retention: every read you asked for (the rule and scope detail on the retention policy list needs CIPP 10.10.0 or later), plus retention policy deploy, edit and remove on CIPP. Retention label create, update and delete are on Microsoft Graph (graph_create_retention_label, graph_update_retention_label, graph_delete_retention_label).
Insider Risk Management: alerts ship as graph_list_insider_risk_alerts. IRM policies have no Microsoft API or PowerShell cmdlet.
Communication Compliance: policy and rule reads ship. Microsoft does not support creating or managing these policies from PowerShell or any API.
Custom sensitive information types: list, rule package read, deploy from a regex or a rule pack, remove. These need CIPP 10.6.0 or later.
The Graph label tools use two new Microsoft permissions. Each Microsoft connection picks them up on its next sign-in; in a tenant where users cannot approve admin permissions, an admin approves once.