New-ComplianceSearch
DestructiveSearch & purge mail
New-ComplianceSearch -Name <s> -ExchangeLocation All -ContentMatchQuery '<KQL>'
Finds a malicious message across every mailbox and purges it — the standard phishing-response play.
Examples
New-ComplianceSearchAction -SearchName 'phish-0612' -Purge -PurgeType SoftDeletePurge the search hits
Syntax
New-ComplianceSearch ... / Start-ComplianceSearch / New-ComplianceSearchAction -SearchName s -Purge
Before you run it
Purge deletes user mail; review hits first.
Related commands
- Get-MessageTraceTrace mail flow
- Search-UnifiedAuditLogAudit log search
Check it once more before you run it
Some commands cannot be undone if one flag is wrong. An on-device reference works with no connection. Free to install, no ads.
Get it free on the App Store