Изменить

Поделиться через


Remove-EntraConditionalAccessPolicy

Deletes a conditional access policy in Microsoft Entra ID by Id.

Syntax

Remove-EntraConditionalAccessPolicy
      -PolicyId <String>
      [<CommonParameters>]

Description

This cmdlet allows an admin to delete a conditional access policy in Microsoft Entra ID by Id.

Conditional access policies are custom rules that define an access scenario.

In delegated scenarios with work or school accounts, when acting on another user, the signed-in user must have a supported Microsoft Entra role or custom role with the necessary permissions. The least privileged roles for this operation are:

  • Security Administrator
  • Conditional Access Administrator

Examples

Example 1: Deletes a conditional access policy in Microsoft Entra ID by PolicyId

Connect-Entra -Scopes 'Policy.ReadWrite.ConditionalAccess','Policy.Read.All'
$policy = Get-EntraConditionalAccessPolicy | Where-Object {$_.DisplayName -eq 'MFA policy'}
Remove-EntraConditionalAccessPolicy -PolicyId $policy.Id

This command deletes a conditional access policy in Microsoft Entra ID.

  • -PolicyId parameter specifies the Id of a conditional access policy.

Parameters

-PolicyId

Specifies the policy Id of a conditional access policy in Microsoft Entra ID.

Type:System.String
Position:Named
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False