{"id":468,"date":"2023-02-15T13:02:06","date_gmt":"2023-02-15T04:02:06","guid":{"rendered":"https:\/\/m365jp.xyz\/?p=468"},"modified":"2023-02-15T13:03:06","modified_gmt":"2023-02-15T04:03:06","slug":"mc515529-microsoft-purview-compliance-portal-ediscovery-powershell-cmdlet-support-for-certificate-based-authentication","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2023-02-15-mc515529-microsoft-purview-compliance-portal-ediscovery-powershell-cmdlet-support-for-certificate-based-authentication","title":{"rendered":"MC515529 | Microsoft Purview compliance portal: eDiscovery PowerShell cmdlet support for certificate-based authentication"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC515529 | Microsoft Purview compliance portal: eDiscovery PowerShell cmdlet support for certificate-based authentication<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>stayInformed<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>2\/15\/2023 3:42:57 AM<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>2\/15\/2023 3:42:19 AM<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>4\/30\/2023 7:00:00 AM<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<p>We are announcing eDiscovery PowerShell cmdlet?s official support for certificate-based authentication (CBA).<\/p>\n<p>  <\/p>\n<p>This message is associated with Microsoft 365 Roadmap ID <a href=\"https:\/\/www.microsoft.com\/microsoft-365\/roadmap?filters=&amp;searchterms=106112\" target=\"_blank\" rel=\"noopener\">  106112<\/a>.<\/p>\n<p>[When this will happen:]  <\/p>\n<p>Rollout will begin in late February and is expected to be complete by late March.<\/p>\n<p>[How this will affect your organization:]  <\/p>\n<p>Many organizations rely on unattended scripts built using the <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/scc-powershell?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">  security and compliance PowerShell cmdlet<\/a> to automate eDiscovery workflow. In the past, any unattended script relied on basic authentication techniques where it required the user to store the username and password in a local file or in a secret vault accessed   at run-time. This method is no longer recommended as it poses the risk of stolen credentials. See  <a href=\"https:\/\/learn.microsoft.com\/exchange\/clients-and-mobile-in-exchange-online\/deprecation-of-basic-authentication-exchange-online\" target=\"_blank\" rel=\"noopener\">  Deprecation of Basic authentication in Exchange Online<\/a>.   <\/p>\n<p>  <\/p>\n<p>eDiscovery cmdlets will support CBA or app-only authentication as described in this  <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/app-only-auth-powershell-v2?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">  article <\/a>by end of February 2023. It supports unattended script and automation scenarios by using Azure AD apps and self-signed certificates. Certificate-based authentication provides admins the ability to run scripts without the need to create service-accounts   or store credentials locally.  <\/p>\n<p>  <\/p>\n<p>  <\/p>\n<p>We encourage all eDiscovery users who rely on basic authentication with their unattended script to migrate the script authentication to use CBA as soon as possible. Please note that Service Principal will be needed to run eDiscovery cmdlets. Refer to this  <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/app-only-auth-powershell-v2?view=exchange-ps#assign-custom-exchange-online-role-groups-to-the-application\" target=\"_blank\" rel=\"noopener\">  article <\/a>for the steps.  <\/p>\n<p>  <\/p>\n<p>  <\/p>\n<p>Note:&nbsp;  <\/p>\n<ul>\n<li>This change will affect the authentication method of your organization?s eDiscovery unattended script.&nbsp;  <\/li>\n<li>After basic authentication is changed to CBA your script should be more secure against potential attackers who may be interested in stealing your locally stored credentials.&nbsp;  <\/li>\n<\/ul>\n<p>[What you need to do to prepare:]<\/p>\n<p>  <\/p>\n<p>Assess if the changes will change your organization?s eDiscovery automation workflow. If so, you may wish to update internal documentation and script authentication and provide training to all eDiscovery users in your organization.    <\/p>\n<p>  <\/p>\n<p>Get started with eDiscovery in the Microsoft Purview compliance portal:&nbsp;  <\/p>\n<ul>\n<li><a href=\"https:\/\/purview.microsoft.com\/compliance\" target=\"_blank\" rel=\"noopener\">Microsoft Purview compliance portal for WW and GCC cloud environments&nbsp;<\/a>  <\/li>\n<li><a href=\"https:\/\/compliance.microsoft.us\/\" target=\"_blank\" rel=\"noopener\">Microsoft Purview compliance portal for GCC-High cloud environments&nbsp;<\/a>  <\/li>\n<li><a href=\"https:\/\/compliance.apps.mil\/\" target=\"_blank\" rel=\"noopener\">Microsoft Purview compliance portal for DoD cloud environments&nbsp;<\/a>  <\/li>\n<\/ul>\n<p>Learn more: <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/app-only-auth-powershell-v2?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">  App-only authentication in Exchange Online PowerShell and Security &amp; Compliance PowerShell<\/a><\/p>\n<\/td>\n<\/tr>\n<tr>\n<th>\u6a5f\u68b0\u7ffb\u8a33<\/th>\n<td>\n<p>\u96fb\u5b50\u60c5\u5831\u958b\u793a PowerShell \u30b3\u30de\u30f3\u30c9\u30ec\u30c3\u30c8\u306e\u8a3c\u660e\u66f8\u30d9\u30fc\u30b9\u306e\u8a8d\u8a3c (CBA) \u306e\u6b63\u5f0f\u306a\u30b5\u30dd\u30fc\u30c8\u3092\u767a\u8868\u3057\u307e\u3059\u3002<\/p>\n<p>  <\/p>\n<p>\u3053\u306e\u30e1\u30c3\u30bb\u30fc\u30b8\u306f\u3001Microsoft 365 \u30ed\u30fc\u30c9\u30de\u30c3\u30d7 ID <a href=\"https:\/\/www.microsoft.com\/microsoft-365\/roadmap?filters=&amp;searchterms=106112\" target=\"_blank\" rel=\"noopener\">  106112<\/a>\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>[\u3053\u308c\u304c\u8d77\u3053\u308b\u3068\u304d:]  <\/p>\n<p>\u30ed\u30fc\u30eb\u30a2\u30a6\u30c8\u306f2\u6708\u4e0b\u65ec\u306b\u958b\u59cb\u3055\u308c\u30013\u6708\u4e0b\u65ec\u307e\u3067\u306b\u5b8c\u4e86\u3059\u308b\u4e88\u5b9a\u3067\u3059\u3002<\/p>\n<p>[\u3053\u308c\u304c\u7d44\u7e54\u306b\u4e0e\u3048\u308b\u5f71\u97ff:]  <\/p>\n<p>\u591a\u304f\u306e\u7d44\u7e54\u306f\u3001\u96fb\u5b50\u60c5\u5831\u958b\u793a\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u3092\u81ea\u52d5\u5316\u3059\u308b\u305f\u3081\u306b <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/scc-powershell?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">  \u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3068\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u306e PowerShell \u30b3\u30de\u30f3\u30c9\u30ec\u30c3\u30c8<\/a> \u3092\u4f7f\u7528\u3057\u3066\u69cb\u7bc9\u3055\u308c\u305f\u7121\u4eba\u30b9\u30af\u30ea\u30d7\u30c8\u306b\u4f9d\u5b58\u3057\u3066\u3044\u307e\u3059\u3002\u4ee5\u524d\u306f\u3001\u7121\u4eba\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u30e6\u30fc\u30b6\u30fc\u540d\u3068\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u30ed\u30fc\u30ab\u30eb\u30d5\u30a1\u30a4\u30eb\u307e\u305f\u306f\u5b9f\u884c\u6642\u306b\u30a2\u30af\u30bb\u30b9\u3055\u308c\u308b\u30b7\u30fc\u30af\u30ec\u30c3\u30c8\u30dc\u30fc\u30eb\u30c8\u306b\u4fdd\u5b58\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u57fa\u672c\u8a8d\u8a3c\u6280\u8853\u306b\u4f9d\u5b58\u3057\u3066\u3044\u307e\u3057\u305f\u3002\u3053\u306e\u65b9\u6cd5\u306f\u3001\u8cc7\u683c\u60c5\u5831\u304c\u76d7\u307e\u308c\u308b\u30ea\u30b9\u30af\u304c\u3042\u308b\u305f\u3081\u3001\u63a8\u5968\u3055\u308c\u306a\u304f\u306a\u308a\u307e\u3057\u305f\u3002\u300c  <a href=\"https:\/\/learn.microsoft.com\/exchange\/clients-and-mobile-in-exchange-online\/deprecation-of-basic-authentication-exchange-online\" target=\"_blank\" rel=\"noopener\">  Exchange Online \u3067\u306e\u57fa\u672c\u8a8d\u8a3c\u306e\u975e\u63a8\u5968<\/a>\u300d\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>  <\/p>\n<p>\u96fb\u5b50\u60c5\u5831\u958b\u793a\u30b3\u30de\u30f3\u30c9\u30ec\u30c3\u30c8\u306f\u30012023 \u5e74 2 \u6708\u672b\u307e\u3067\u306b\u3001 <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/app-only-auth-powershell-v2?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">  \u3053\u306e\u8a18\u4e8b <\/a>\u3067\u8aac\u660e\u3055\u308c\u3066\u3044\u308b\u3088\u3046\u306b CBA \u307e\u305f\u306f\u30a2\u30d7\u30ea\u5c02\u7528\u8a8d\u8a3c\u3092\u30b5\u30dd\u30fc\u30c8\u3057\u307e\u3059\u3002Azure AD \u30a2\u30d7\u30ea\u3068\u81ea\u5df1\u7f72\u540d\u8a3c\u660e\u66f8\u3092\u4f7f\u7528\u3057\u3066\u3001\u7121\u4eba\u30b9\u30af\u30ea\u30d7\u30c8\u3068\u81ea\u52d5\u5316\u306e\u30b7\u30ca\u30ea\u30aa\u3092\u30b5\u30dd\u30fc\u30c8\u3057\u307e\u3059\u3002\u8a3c\u660e\u66f8\u30d9\u30fc\u30b9\u306e\u8a8d\u8a3c\u306b\u3088\u308a\u3001\u7ba1\u7406\u8005\u306f\u30b5\u30fc\u30d3\u30b9 \u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u4f5c\u6210\u3057\u305f\u308a\u3001\u8cc7\u683c\u60c5\u5831\u3092\u30ed\u30fc\u30ab\u30eb\u306b\u4fdd\u5b58\u3057\u305f\u308a\u3059\u308b\u3053\u3068\u306a\u304f\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002  <\/p>\n<p>  <\/p>\n<p>  <\/p>\n<p>\u7121\u4eba\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4f7f\u7528\u3057\u305f\u57fa\u672c\u8a8d\u8a3c\u306b\u4f9d\u5b58\u3057\u3066\u3044\u308b\u3059\u3079\u3066\u306e\u96fb\u5b50\u60c5\u5831\u958b\u793a\u30e6\u30fc\u30b6\u30fc\u306f\u3001\u3067\u304d\u308b\u3060\u3051\u65e9\u304f CBA \u3092\u4f7f\u7528\u3059\u308b\u3088\u3046\u306b\u30b9\u30af\u30ea\u30d7\u30c8\u8a8d\u8a3c\u3092\u79fb\u884c\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002\u96fb\u5b50\u60c5\u5831\u958b\u793a\u30b3\u30de\u30f3\u30c9\u30ec\u30c3\u30c8\u3092\u5b9f\u884c\u3059\u308b\u306b\u306f\u3001\u30b5\u30fc\u30d3\u30b9 \u30d7\u30ea\u30f3\u30b7\u30d1\u30eb\u304c\u5fc5\u8981\u306b\u306a\u308b\u3053\u3068\u306b\u6ce8\u610f\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u624b\u9806\u306b\u3064\u3044\u3066\u306f\u3001  <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/app-only-auth-powershell-v2?view=exchange-ps#assign-custom-exchange-online-role-groups-to-the-application\" target=\"_blank\" rel=\"noopener\">  \u3053\u306e\u8a18\u4e8b <\/a>\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002  <\/p>\n<p>  <\/p>\n<p>  <\/p>\n<p>\u624b\u8a18\uff1a&nbsp;  <\/p>\n<ul>\n<li>\u3053\u306e\u5909\u66f4\u306f\u3001\u7d44\u7e54\u306e\u96fb\u5b50\u60c5\u5831\u958b\u793a\u7121\u4eba\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u8a8d\u8a3c\u65b9\u6cd5\u306b\u5f71\u97ff\u3057\u307e\u3059\u3002&nbsp;  <\/li>\n<li>\u57fa\u672c\u8a8d\u8a3c\u304cCBA\u306b\u5909\u66f4\u3055\u308c\u308b\u3068\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u306f\u3001\u30ed\u30fc\u30ab\u30eb\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u8cc7\u683c\u60c5\u5831\u3092\u76d7\u3080\u3053\u3068\u306b\u95a2\u5fc3\u304c\u3042\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u6f5c\u5728\u7684\u306a\u653b\u6483\u8005\u306b\u5bfe\u3057\u3066\u3088\u308a\u5b89\u5168\u306b\u306a\u308a\u307e\u3059\u3002&nbsp;  <\/li>\n<\/ul>\n<p>[\u6e96\u5099\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u3053\u3068:]<\/p>\n<p>  <\/p>\n<p>\u5909\u66f4\u306b\u3088\u3063\u3066\u7d44\u7e54\u306e\u96fb\u5b50\u60c5\u5831\u958b\u793a\u81ea\u52d5\u5316\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u304c\u5909\u66f4\u3055\u308c\u308b\u304b\u3069\u3046\u304b\u3092\u8a55\u4fa1\u3057\u307e\u3059\u3002\u305d\u306e\u5834\u5408\u306f\u3001\u5185\u90e8\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3068\u30b9\u30af\u30ea\u30d7\u30c8\u8a8d\u8a3c\u3092\u66f4\u65b0\u3057\u3001\u7d44\u7e54\u5185\u306e\u3059\u3079\u3066\u306e\u96fb\u5b50\u60c5\u5831\u958b\u793a\u30e6\u30fc\u30b6\u30fc\u306b\u30c8\u30ec\u30fc\u30cb\u30f3\u30b0\u3092\u63d0\u4f9b\u3059\u308b\u3053\u3068\u3092\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/p>\n<p>  <\/p>\n<p>Microsoft Purview \u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9 \u30dd\u30fc\u30bf\u30eb\u3067\u96fb\u5b50\u60c5\u5831\u958b\u793a\u306e\u4f7f\u7528\u3092\u958b\u59cb\u3059\u308b:&nbsp;  <\/p>\n<ul>\n<li><a href=\"https:\/\/purview.microsoft.com\/compliance\" target=\"_blank\" rel=\"noopener\">WW \u304a\u3088\u3073 GCC \u30af\u30e9\u30a6\u30c9\u74b0\u5883&nbsp;\u5411\u3051\u306e\u30de\u30a4\u30af\u30ed\u30bd\u30d5\u30c8 Purview \u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9 \u30dd\u30fc\u30bf\u30eb<\/a>  <\/li>\n<li><a href=\"https:\/\/compliance.microsoft.us\/\" target=\"_blank\" rel=\"noopener\">GCC-High \u30af\u30e9\u30a6\u30c9\u74b0\u5883&nbsp;\u5411\u3051\u306e\u30de\u30a4\u30af\u30ed\u30bd\u30d5\u30c8 Purview \u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9 \u30dd\u30fc\u30bf\u30eb<\/a>  <\/li>\n<li><a href=\"https:\/\/compliance.apps.mil\/\" target=\"_blank\" rel=\"noopener\">\u56fd\u9632\u7dcf\u7701\u30af\u30e9\u30a6\u30c9\u74b0\u5883&nbsp;\u5411\u3051\u306e\u30de\u30a4\u30af\u30ed\u30bd\u30d5\u30c8Purview\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u30dd\u30fc\u30bf\u30eb<\/a>  <\/li>\n<\/ul>\n<p>\u8a73\u7d30\u60c5\u5831: <a href=\"https:\/\/learn.microsoft.com\/powershell\/exchange\/app-only-auth-powershell-v2?view=exchange-ps\" target=\"_blank\" rel=\"noopener\">  Exchange Online PowerShell \u3067\u306e\u30a2\u30d7\u30ea\u5c02\u7528\u8a8d\u8a3c\u3068 Security &amp; Compliance PowerShell<\/a><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC515529 | Microsoft Purview compliance portal: eDiscovery PowerShell cmdlet support for certificate-based aut [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-468","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=468"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/468\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=468"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=468"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}