diff --git a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOSite.md b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOSite.md index 27aaa0c02..e487df0d9 100644 --- a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOSite.md +++ b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOSite.md @@ -162,6 +162,14 @@ Get-SPOSite -Filter "Owner -like '$($userUPN)'" ``` This example retrieves all sites filtering by the specified owner using a variable. +### EXAMPLE 13 + +```powershell +Get-SPOSite -Identity https://contoso.sharepoint.com/sites/site1 | Select-Object Url, RestrictAccessControlForAgenticUser +``` + +This example returns whether Agent Users are restricted from accessing the site. + ## PARAMETERS ### -ArchiveStatus diff --git a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOTenant.md b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOTenant.md index 8782b4b87..0f536ef71 100644 --- a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOTenant.md +++ b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Get-SPOTenant.md @@ -42,6 +42,14 @@ Get-SPOTenant This example returns the organization-level site collection properties such as StorageQuota, StorageQuotaAllocated, ResourceQuota, ResourceQuotaAllocated, SiteCreationMode and OneDriveStorageQuota. +### Example 2 + +```powershell +Get-SPOTenant | Select-Object RestrictAccessControlForAgenticUser +``` + +This example returns whether Agent Users are restricted from accessing all sites in the organization. + ## PARAMETERS ### CommonParameters diff --git a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOSite.md b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOSite.md index b973a9a97..ad7466c73 100644 --- a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOSite.md +++ b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOSite.md @@ -63,6 +63,7 @@ Set-SPOSite [-Identity] [-Owner ] [-Title ] [- [-DefaultShareLinkRole ] [-BlockGuestsAsSiteAdmin ] [-FileAnonymousLinkType ] [-FolderAnonymousLinkType ] [-RestrictContentOrgWideSearch ] [-RestrictedContentDiscoveryforCopilotAndAgents ] + [-RestrictAccessControlForAgenticUser ] [-RestrictedAccessControl ] [-RestrictedAccessControlGroups ] [-ListsShowHeaderAndNavigation ] [-HidePeoplePreviewingFiles ] [-HidePeopleWhoHaveListsOpen ] [-IsAuthoritative ] [-AllowFileArchive ] @@ -388,13 +389,21 @@ Example 24 removes the version history limit override for video and audio file t ### Example 25 - ```powershell Set-SPOSite -Identity https://contoso.sharepoint.com/sites/site1 -FolderAnonymousLinkType ViewUpload -FileAnonymousLinkType None ``` Example 25 sets a site level override for FolderAnonymousLinkType to limit anonymous and request files folder sharing to only support view and upload permissions and clears any site level override for the FileAnonymousLinkType by setting it to None. +### Example 26 + +```powershell +Set-SPOSite -Identity https://contoso.sharepoint.com/sites/site1 -RestrictAccessControlForAgenticUser $true +Get-SPOSite -Identity https://contoso.sharepoint.com/sites/site1 | Select-Object Url, RestrictAccessControlForAgenticUser +``` + +Example 26 restricts Agent Users from accessing the site and then returns the configured value. The policy is enforced at runtime and doesn't remove existing permissions. + ## PARAMETERS ### -AddInformationSegment @@ -2167,6 +2176,24 @@ Accept pipeline input: False Accept wildcard characters: False ``` +### -RestrictAccessControlForAgenticUser + +> Applicable: SharePoint Online + +Specifies whether Agent Users are restricted from accessing the site. Set this parameter to `$true` to block Agent Users at runtime, or `$false` to remove the site restriction. Changing this setting doesn't remove existing permissions. + +```yaml +Type: System.Boolean +Parameter Sets: ParamSet1 +Aliases: + +Required: False +Position: Named +Default value: None +Accept pipeline input: False +Accept wildcard characters: False +``` + ### -RestrictedToGeo > Applicable: SharePoint Online diff --git a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOTenant.md b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOTenant.md index ad508da05..7a7e1a2b0 100644 --- a/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOTenant.md +++ b/sharepoint/sharepoint-ps/Microsoft.Online.SharePoint.PowerShell/Set-SPOTenant.md @@ -113,7 +113,8 @@ Set-SPOTenant [-MinCompatibilityLevel ] [-MaxCompatibilityLevel ] [-ViewInFileExplorerEnabled ] [-AuthContextResilienceMode ] [-ReduceTempTokenLifetimeEnabled ] [-ReduceTempTokenLifetimeValue ] [-ShowOpenInDesktopOptionForSyncedFiles ] [-ShowPeoplePickerGroupSuggestionsForIB ] - [-EnableRestrictedAccessControl ] [-BlockDownloadFileTypePolicy ] + [-EnableRestrictedAccessControl ] [-RestrictAccessControlForAgenticUser ] + [-BlockDownloadFileTypePolicy ] [-BlockDownloadFileTypeIds ] [-ExcludedBlockDownloadGroupIds ] [-TlsTokenBindingPolicyValue ] [-RecycleBinRetentionPeriod ] [-IsEnableAppAuthPopUpEnabled ] [-IsDataAccessInCardDesignerEnabled ] @@ -251,7 +252,8 @@ Set-SPOTenant [-MinCompatibilityLevel ] [-MaxCompatibilityLevel ] [-ViewInFileExplorerEnabled ] [-AuthContextResilienceMode ] [-ReduceTempTokenLifetimeEnabled ] [-ReduceTempTokenLifetimeValue ] [-ShowOpenInDesktopOptionForSyncedFiles ] [-ShowPeoplePickerGroupSuggestionsForIB ] - [-EnableRestrictedAccessControl ] [-BlockDownloadFileTypePolicy ] + [-EnableRestrictedAccessControl ] [-RestrictAccessControlForAgenticUser ] + [-BlockDownloadFileTypePolicy ] [-BlockDownloadFileTypeIds ] [-ExcludedBlockDownloadGroupIds ] [-TlsTokenBindingPolicyValue ] [-RecycleBinRetentionPeriod ] [-IsEnableAppAuthPopUpEnabled ] [-IsDataAccessInCardDesignerEnabled ] @@ -390,7 +392,8 @@ Set-SPOTenant [-MinCompatibilityLevel ] [-MaxCompatibilityLevel ] [-ViewInFileExplorerEnabled ] [-AuthContextResilienceMode ] [-ReduceTempTokenLifetimeEnabled ] [-ReduceTempTokenLifetimeValue ] [-ShowOpenInDesktopOptionForSyncedFiles ] [-ShowPeoplePickerGroupSuggestionsForIB ] - [-EnableRestrictedAccessControl ] [-BlockDownloadFileTypePolicy ] + [-EnableRestrictedAccessControl ] [-RestrictAccessControlForAgenticUser ] + [-BlockDownloadFileTypePolicy ] [-BlockDownloadFileTypeIds ] [-ExcludedBlockDownloadGroupIds ] [-TlsTokenBindingPolicyValue ] [-RecycleBinRetentionPeriod ] [-IsEnableAppAuthPopUpEnabled ] [-IsDataAccessInCardDesignerEnabled ] @@ -527,7 +530,8 @@ Set-SPOTenant [-MinCompatibilityLevel ] [-MaxCompatibilityLevel ] [-ViewInFileExplorerEnabled ] [-AuthContextResilienceMode ] [-ReduceTempTokenLifetimeEnabled ] [-ReduceTempTokenLifetimeValue ] [-ShowOpenInDesktopOptionForSyncedFiles ] [-ShowPeoplePickerGroupSuggestionsForIB ] - [-EnableRestrictedAccessControl ] [-BlockDownloadFileTypePolicy ] + [-EnableRestrictedAccessControl ] [-RestrictAccessControlForAgenticUser ] + [-BlockDownloadFileTypePolicy ] [-BlockDownloadFileTypeIds ] [-ExcludedBlockDownloadGroupIds ] [-TlsTokenBindingPolicyValue ] [-RecycleBinRetentionPeriod ] [-IsEnableAppAuthPopUpEnabled ] [-IsDataAccessInCardDesignerEnabled ] @@ -664,7 +668,8 @@ Set-SPOTenant [-MinCompatibilityLevel ] [-MaxCompatibilityLevel ] [-ViewInFileExplorerEnabled ] [-AuthContextResilienceMode ] [-ReduceTempTokenLifetimeEnabled ] [-ReduceTempTokenLifetimeValue ] [-ShowOpenInDesktopOptionForSyncedFiles ] [-ShowPeoplePickerGroupSuggestionsForIB ] - [-EnableRestrictedAccessControl ] [-BlockDownloadFileTypePolicy ] + [-EnableRestrictedAccessControl ] [-RestrictAccessControlForAgenticUser ] + [-BlockDownloadFileTypePolicy ] [-BlockDownloadFileTypeIds ] [-ExcludedBlockDownloadGroupIds ] [-TlsTokenBindingPolicyValue ] [-RecycleBinRetentionPeriod ] [-IsEnableAppAuthPopUpEnabled ] [-IsDataAccessInCardDesignerEnabled ] @@ -975,6 +980,15 @@ Get-SPOTenant | Select-Object SmartWikiEntryScope, SmartWikiEntrySelectedSitesLi This example adds a site to the current selected sites list for the Smart Wiki library entry point without changing the scope. It then displays the current scope and the selected sites. +### EXAMPLE 32 + +```powershell +Set-SPOTenant -RestrictAccessControlForAgenticUser $true +Get-SPOTenant | Select-Object RestrictAccessControlForAgenticUser +``` + +This example restricts Agent Users from accessing all sites in the organization and then returns the configured value. The policy is enforced at runtime and doesn't remove existing permissions. + ## PARAMETERS ### -AIBuilderModelScope @@ -5439,6 +5453,24 @@ Accept pipeline input: False Accept wildcard characters: False ``` +### -RestrictAccessControlForAgenticUser + +> Applicable: SharePoint Online + +Specifies whether Agent Users are restricted from accessing all sites in the organization. Set this parameter to `$true` to block Agent Users at runtime, or `$false` to remove the organization-wide restriction. Changing this setting doesn't remove existing permissions. + +```yaml +Type: System.Boolean +Parameter Sets: (All) +Aliases: + +Required: False +Position: Named +Default value: None +Accept pipeline input: False +Accept wildcard characters: False +``` + ### -RestrictExternalSharing > Applicable: SharePoint Online