In this tutorial i will be shpwing you how to delete an email from anyone’s or everyone’s mailbox in Office 365 using Microsoft 365 Compliance Centre and PowerShell.
You will learn how to search for the email, and delete the email from all users mailboxes using powershell.
Updated: This is now a video post.
The Script – UPDATED 2023 (Use new Script Below)
If you already have the Exchange Online Management Module installed, please update it before running the script by opening an elevated PowerShell window and using the following cmdlet
Update-Module -Name ExchangeOnlineManagement
# Get Microsoft 365 login credentials
##Import Module
Import-Module ExchangeOnlineManagement
#Connect To Security and Compliance Powershell
Connect-IPPSSession
#Purge/Delete Emails
New-ComplianceSearchAction -SearchName "Search Name" -Purge -PurgeType HardDelete
#Change HardDelete to SoftDelete if you wish to test first, Soft Delete will store the email in users 'Recoverable items' folder

#EdTech Network Manager, experienced in Microsoft 365, Server 2019, Intune, SCCM and anything inbetween.

Thank you for this clear explanation. 🙂
how to know if it worked?
The UI has changed Core is not a thing anymore. I can trace and find emails by same criteria doesn’t work in new UI
The UI has changed but the process should still be the same, i will try and update with the new UI
Can you help me
A parameter cannot be found that matches parameter name ‘Purge’.
+ CategoryInfo : InvalidArgument : (:) [New-ComplianceSearchAction], ParameterBindingException
+ FullyQualifiedErrorId : NamedParameterNotFound,New-ComplianceSearchAction
+ PSComputerName : eur03b.ps.compliance.protection.outlook.com
You have to be a member of the Organization Management role group or be assigned the Search And Purge role in the compliance centre, please check you are part of the correct groups, you need to do this even if you are global administrator.
The Script It used to work perfectly for me a while ago, but now it doesn’t work. I tried on different days the same problem. Is there an update or something changed? Check the error
New-PSSession : [eur03b.ps.compliance.protection.outlook.com] Connecting to remote server eur03b.ps.compliance.protection.outlook.com failed
with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.
At line:5 char:12
+ $Session = New-PSSession -ConfigurationName Microsoft.Exchange -Conne …
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : OpenError: (System.Manageme….RemoteRunspace:RemoteRunspace) [New-PSSession], PSRemotingTransportException
+ FullyQualifiedErrorId : AccessDenied,PSSessionOpenFailed
Import-PSSession : Cannot validate argument on parameter ‘Session’. The argument is null. Provide a valid value for the argument, and then
try running the command again.
At line:8 char:18
+ Import-PSSession $Session -AllowClobber -DisableNameChecking
+ ~~~~~~~~
+ CategoryInfo : InvalidData: (:) [Import-PSSession], ParameterBindingValidationException
+ FullyQualifiedErrorId : ParameterArgumentValidationError,Microsoft.PowerShell.Commands.ImportPSSessionCommand
New-ComplianceSearchAction : The term ‘New-ComplianceSearchAction’ is not recognized as the name of a cmdlet, function, script file, or
operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again.
At line:11 char:1
+ New-ComplianceSearchAction -SearchName ” Test” -Purge -PurgeType …
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (New-ComplianceSearchAction:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException
Hi Mohamed, Since Microsoft have phased out legacy authentication there is another way you can do this which works with MFA too. i’ve updated the script for you, give that a try!
Dear, Liam
I hope that you are well
Thank you very much
I tried the new script, it works, thanks
I just ran the command, and it looks like it went through
How Can I check if it worked?
I am interested in this too, that’s exactly what I was going to ask. How can I see if the purge is complete and possibly the metrics. Hello Liam, I will appreciate if you can give us a direction. Thanks
You could try run the compliance search again after the purge, they should no longer show up (I haven’t tested this though). I normally check certain mailboxes and can see it has been removed, depending on your tenant size it could take around 10 mins to purge.