3.11.0: system browser sign-in, update check limited to 3.x, GitHub templates

This commit is contained in:
Mikael Karlsson
2026-09-23 19:48:02 +10:00
parent 0492b784a1
commit f96037a9d0
14 changed files with 657 additions and 31 deletions
+39
View File
@@ -0,0 +1,39 @@
title: ""
body:
- type: markdown
attributes:
value: |
Ideas is for shaping something before it becomes a request. Say what you
are trying to achieve rather than the control you picture, and it will be
clear whether the application should grow a feature or already has one.
- type: dropdown
id: version
attributes:
label: Which version are you using?
options:
- 4.0 beta
- 3.x
- Neither yet, just looking
validations:
required: true
- type: textarea
id: goal
attributes:
label: What are you trying to achieve?
validations:
required: true
- type: textarea
id: idea
attributes:
label: How do you picture it working?
- type: textarea
id: scale
attributes:
label: How often, and at what scale?
description: >
How many tenants, how many policies, how often you do it. Scale changes
the answer more than anything else here.
+64
View File
@@ -0,0 +1,64 @@
title: "[Question] "
labels: ["needs-triage"]
body:
- type: markdown
attributes:
value: |
Most questions here turn out to be one of four things: a sign-in method
the embedded window cannot complete, a list that looks short because the
version you are on stops paging, a permission the app registration does
not hold, or an object type that has no public Graph endpoint. The fields
below let that be spotted straight away.
- type: dropdown
id: version
attributes:
label: Version
options:
- 4.0 beta
- 3.x
validations:
required: true
- type: dropdown
id: signin
attributes:
label: How do you sign in?
options:
- Interactive, embedded window (the default in v3)
- Interactive, Web Account Manager (WAM)
- Interactive, system browser (the default in v4)
- Device code
- Application and secret
- Application and certificate
- Managed identity or federated credential
- Bring your own token
validations:
required: true
- type: dropdown
id: cloud
attributes:
label: Cloud
options:
- Public (commercial)
- US Government (GCC High)
- US Government (DoD)
- China (21Vianet)
validations:
required: true
- type: textarea
id: question
attributes:
label: What are you trying to do?
validations:
required: true
- type: textarea
id: tried
attributes:
label: What have you tried, and what happened?
description: >
Paste any error text here. **Remove tenant identifiers, user names and
tokens first.**
+4
View File
@@ -0,0 +1,4 @@
# GitHub renders this as the "Sponsor" button on the repository page
# (public repositories, default branch). Buy Me a Coffee takes the
# username, not the URL: https://buymeacoffee.com/MickeK
buy_me_a_coffee: MickeK
+116
View File
@@ -0,0 +1,116 @@
name: Bug report (version 3.x)
description: Something is wrong in the current release. Windows only.
title: "[3.x] "
labels: ["bug", "v3", "needs-triage"]
body:
- type: markdown
attributes:
value: |
Version 3 stays supported until 4.0 leaves beta.
Before filing, check whether 4.0 already fixes it. Several long-standing
reports here are addressed there: sign-in with passkeys and other
phishing-resistant methods, lists that stopped at 20, 100 or a few
hundred objects, sovereign cloud sign-in, and running without a user
present. The 4.0 beta lives on the `v4` branch.
- type: checkboxes
id: preflight
attributes:
label: Before reporting
options:
- label: >
If my sign-in involves a passkey, security key, Windows Hello or a
phishing-resistant policy: I know the embedded sign-in window cannot
complete those, and I have said so below rather than reporting it as
a broken login.
required: true
- label: >
I searched existing issues and discussions, including closed ones.
required: true
- type: input
id: version
attributes:
label: Version
placeholder: 3.10.3
validations:
required: true
- type: dropdown
id: signin
attributes:
label: How did you sign in?
options:
- Interactive, embedded window (the default)
- Interactive, other
- Application and secret
- Application and certificate
- Not signed in / sign-in is the problem
validations:
required: true
- type: dropdown
id: cloud
attributes:
label: Cloud
options:
- Public (commercial)
- US Government (GCC High)
- US Government (DoD)
- China (21Vianet)
validations:
required: true
- type: input
id: powershell
attributes:
label: PowerShell version
description: Run `$PSVersionTable.PSVersion`.
placeholder: "5.1.22621.4391"
validations:
required: true
- type: dropdown
id: area
attributes:
label: Which part of the application?
options:
- Sign-in and authentication
- Export
- Import
- Copy
- Compare
- Documentation output
- Assignments, groups or filters
- Bulk or silent operations
- ADMX or tools
- The user interface itself
- Something else
validations:
required: true
- type: textarea
id: what
attributes:
label: What happened, and what did you expect instead?
validations:
required: true
- type: textarea
id: steps
attributes:
label: Steps to reproduce
validations:
required: true
- type: textarea
id: log
attributes:
label: Log
description: >
The relevant lines, or the error text. **Remove tenant identifiers, user
names, access tokens and secrets before pasting.**
render: text
validations:
required: true
+154
View File
@@ -0,0 +1,154 @@
name: Bug report (version 4.0 beta)
description: Something is wrong in 4.0. Runs on Windows, macOS and Linux.
title: "[4.0] "
labels: ["bug", "v4", "needs-triage"]
body:
- type: markdown
attributes:
value: |
Thanks for testing the beta. Four fields below do most of the work:
**how you signed in**, **which cloud**, **which operating system** and
**the log**. Reports without them usually need a round trip before
anything can happen.
- type: checkboxes
id: preflight
attributes:
label: Before reporting
description: These three cover the majority of beta reports so far.
options:
- label: >
I read the release notes for this beta, including the breaking changes.
required: true
- label: >
If my sign-in involves a passkey, security key, Windows Hello or any
phishing-resistant policy: I enabled **Use Web Account Manager (WAM)
for login** or **Use system browser for login** in Settings, and tried
again. The embedded window cannot complete those methods.
required: true
- label: >
My problem is not Inventory Policies returning 403. That endpoint is
not published on the public Graph API, so the application cannot read
it with a normal sign-in. It is a Microsoft limitation, not a bug.
A bring-your-own-token sign-in can reach it.
required: true
- type: input
id: version
attributes:
label: Version
description: The About dialog, or the ModuleVersion in IntuneManagement.psd1.
placeholder: 4.0.0-beta1
validations:
required: true
- type: dropdown
id: signin
attributes:
label: How did you sign in?
description: >
The single most useful field in this form. Roughly a third of all reports
on this project have turned out to be sign-in behaviour rather than the
feature being reported.
options:
- Interactive, embedded window
- Interactive, Web Account Manager (WAM)
- Interactive, system browser (the default)
- Device code
- Application and secret
- Application and certificate
- Managed identity or federated credential
- Bring your own token
- Not signed in / sign-in is the problem
validations:
required: true
- type: dropdown
id: cloud
attributes:
label: Cloud
options:
- Public (commercial)
- US Government (GCC High)
- US Government (DoD)
- China (21Vianet)
validations:
required: true
- type: dropdown
id: os
attributes:
label: Operating system
description: 4.0 runs the full application outside Windows, so this now matters.
options:
- Windows
- macOS (Apple Silicon)
- macOS (Intel)
- Linux
validations:
required: true
- type: input
id: powershell
attributes:
label: PowerShell edition and version
description: Run `$PSVersionTable.PSVersion` and `$PSVersionTable.PSEdition`.
placeholder: "7.4.6, Core"
validations:
required: true
- type: dropdown
id: area
attributes:
label: Which part of the application?
options:
- Sign-in and authentication
- Export
- Import
- Copy
- Compare
- Documentation output
- Assignments, groups or filters
- Bulk operations
- ADMX or tools
- The user interface itself
- Automation through the PowerShell commands
- Something else
validations:
required: true
- type: input
id: objecttype
attributes:
label: Which object type, if it is specific to one
placeholder: Settings Catalog, Conditional Access, Win32 app, ...
- type: textarea
id: what
attributes:
label: What happened, and what did you expect instead?
validations:
required: true
- type: textarea
id: steps
attributes:
label: Steps to reproduce
placeholder: |
1. Sign in to ...
2. Open ...
3. Click ...
validations:
required: true
- type: textarea
id: log
attributes:
label: Log
description: >
The relevant lines from the log file, or the error text. **Remove tenant
identifiers, user names, access tokens and secrets before pasting.** If
an exported policy file is needed, redact it or use one from a lab tenant.
render: text
validations:
required: true
+17
View File
@@ -0,0 +1,17 @@
# Turns off the "open a blank issue" escape hatch, so every report arrives
# through a form with the fields that make it answerable. Questions go to
# Discussions, which is where most of them already end up.
blank_issues_enabled: false
contact_links:
- name: Question, or not sure it is a bug
url: https://github.com/Micke-K/IntuneManagement/discussions/categories/q-a
about: Ask in Q&A. Most "it does not show my policies" reports are answered there in a day.
- name: Feature idea worth discussing first
url: https://github.com/Micke-K/IntuneManagement/discussions/categories/ideas
about: Ideas that are still taking shape belong here. A concrete request can go straight to an issue.
- name: Version 4.0 beta feedback
url: https://github.com/Micke-K/IntuneManagement/discussions/categories/announcements
about: Testing the 4.0 beta? Start at the pinned announcement, which lists what to try first.
- name: Security vulnerability
url: https://github.com/Micke-K/IntuneManagement/security/advisories/new
about: Never report a security problem in a public issue. Use private reporting.
+71
View File
@@ -0,0 +1,71 @@
name: Feature request
description: Something the application should do and does not.
title: "[Request] "
labels: ["enhancement", "needs-triage"]
body:
- type: markdown
attributes:
value: |
If the idea is still taking shape, [Ideas in
Discussions](https://github.com/Micke-K/IntuneManagement/discussions/categories/ideas)
is the better room. Use this form when you can describe the outcome you
want.
- type: dropdown
id: version
attributes:
label: Which version is this for?
description: >
This one is read by a human, not by automation, so say what you mean.
A request that 4.0 already covers is worth checking against the release
notes first.
options:
- Version 4.0
- Version 3.x
- Either
validations:
required: true
- type: textarea
id: problem
attributes:
label: What are you trying to do?
description: >
The situation, not the solution. "I move policies between two tenants
every month and have to redo the assignments by hand" tells more than
"add a button".
validations:
required: true
- type: textarea
id: proposal
attributes:
label: What would you like it to do?
validations:
required: true
- type: textarea
id: workaround
attributes:
label: How do you handle it today?
description: Including "not at all", which is useful to know.
- type: dropdown
id: area
attributes:
label: Which part of the application?
options:
- Export
- Import
- Copy
- Compare
- Documentation output
- Assignments, groups or filters
- Bulk operations
- ADMX or tools
- The user interface
- Automation through the PowerShell commands
- A policy type that is not supported yet
- Something else
validations:
required: true
+47
View File
@@ -0,0 +1,47 @@
<!--
Target branch
Fixing version 3? target Development
Fixing version 4? target v4
A pull request opened against the default branch is retargeted to
Development before review. Use the Edit button next to the title.
-->
<!--
How version 4 changes are applied during the beta
Version 4 is developed elsewhere and the v4 branch is published as one
snapshot per release, not as a running history. An accepted change is
applied upstream and appears in the next release, so your commit will not
show up in this branch. You are credited in the release notes instead.
Nothing is lost, and nothing needs doing on your side.
-->
## What does this change?
<!-- One or two sentences. What was wrong, or what is now possible. -->
## Related issue
<!-- "Fixes #123", or "none" if there isn't one. -->
## How was it tested?
<!--
Which version, which cloud, and which operating system, since 4.0 runs on
three. If it touches sign-in, say which method you used: embedded window,
Web Account Manager, system browser, device code, or an application identity.
-->
- Version:
- Cloud:
- Operating system and PowerShell version:
- Tests run:
## Anything a reviewer should know
<!--
Behaviour that changes for existing users, a setting that moves, a file format
that shifts. Say so here rather than leaving it to be discovered.
-->