Skip to main content

Write counterpart for cipp_list_exo_request

Add a write counterpart to cipp_list_exo_request (an cipp_exec_exo_request or equivalent), matched to the same plan-gating and destructive-flag pattern already used for graph_raw_request and azure_raw_request. Exchange Online coverage is otherwise broader (mailbox permissions, forwarding, litigation hold, retention hold, quotas, connectors, transport rules, message trace, shared mailboxes), but has one structural gap: cipp_list_exo_request runs any read-only EXO cmdlet, but there is no write counterpart. Graph and Azure both ship a matched pair for this exact reason (graph_raw_get / graph_raw_request, azure_raw_get / azure_raw_request). Exchange does not, so any EXO write cmdlet that is not already wrapped as a named CIPP tool is completely unreachable, not just unguarded.

Status: In Progress1 comment

Log in to comment and vote

Comments1

  • Christopher Scaminaci

    Team•

    Oct 5

    Named Exchange tools: cipp_manage_group_members adds and removes members and owners on groups and distribution lists. Group create, edit and delete, inbound anti-spam, and turning malware, anti-phishing and Safe Attachments rules on or off were already covered by named CIPP tools. CIPP applies DKIM, mailbox auditing, the unified audit log and the outbound spam, malware and anti-phishing policy settings only through its standards engine, so those go through cipp_add_standards_template. The read tool's description now names the read cmdlets for each of those areas.

    Write counterpart for cipp_list_exo_request: CIPP's ListExoRequest runs only Get and Search cmdlets, and CIPP's only generic write route needs the CIPP SuperAdmin role, which StackJack will not ask for. A caller-named Exchange write needs a new CIPP endpoint. cipp_list_exo_request's description now says where each write lives.