mirror of
https://github.com/Micke-K/IntuneManagement.git
synced 2026-09-28 10:55:38 +02:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6ac211a2bf | ||
|
|
83c845fc33 | ||
|
|
f5613442bd | ||
|
|
ab7b062946 | ||
|
|
ea3af64316 | ||
|
|
e6ec048df0 |
@@ -0,0 +1,42 @@
|
||||
using System;
|
||||
using System.Net;
|
||||
using System.Net.Http;
|
||||
using Microsoft.Identity.Client;
|
||||
|
||||
public class HttpFactoryWithProxy : IMsalHttpClientFactory
|
||||
{
|
||||
private static HttpClient _httpClient;
|
||||
|
||||
public HttpFactoryWithProxy(string proxyURI) : this(proxyURI, null, null)
|
||||
{
|
||||
|
||||
}
|
||||
|
||||
public HttpFactoryWithProxy(string proxyURI, string proxyUserName = null, string proxyPassword = null)
|
||||
{
|
||||
if (_httpClient == null)
|
||||
{
|
||||
var proxy = new WebProxy
|
||||
{
|
||||
Address = new Uri(proxyURI),
|
||||
BypassProxyOnLocal = false,
|
||||
UseDefaultCredentials = false,
|
||||
Credentials = new NetworkCredential(
|
||||
userName: proxyUserName,
|
||||
password: proxyPassword)
|
||||
};
|
||||
|
||||
var httpClientHandler = new HttpClientHandler
|
||||
{
|
||||
Proxy = proxy,
|
||||
};
|
||||
|
||||
_httpClient = new HttpClient(handler: httpClientHandler);
|
||||
}
|
||||
}
|
||||
|
||||
public HttpClient GetHttpClient()
|
||||
{
|
||||
return _httpClient;
|
||||
}
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -12,7 +12,7 @@
|
||||
RootModule = 'CloudAPIPowerShellManagement.psm1'
|
||||
|
||||
# Version number of this module.
|
||||
ModuleVersion = '3.8.1'
|
||||
ModuleVersion = '3.9.4'
|
||||
|
||||
# Supported PSEditions
|
||||
# CompatiblePSEditions = @()
|
||||
@@ -27,7 +27,7 @@ Author = 'Mikael Karlsson'
|
||||
# CompanyName = ''
|
||||
|
||||
# Copyright statement for this module
|
||||
Copyright = '(c) 2022 Mikael Karlsson. Software released under MIT License.'
|
||||
Copyright = '(c) 2023 Mikael Karlsson. Software released under MIT License.'
|
||||
|
||||
# Description of the functionality provided by this module
|
||||
Description = 'Management of Intune and Azure via Cloud APIs like Microsoft Graph API'
|
||||
@@ -69,7 +69,7 @@ Description = 'Management of Intune and Azure via Cloud APIs like Microsoft Grap
|
||||
NestedModules = @()
|
||||
|
||||
# Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export.
|
||||
FunctionsToExport = @("Initialize-CloudAPIManagement","Initialize-CloudAPIManagement")
|
||||
FunctionsToExport = @("Initialize-CloudAPIManagement")
|
||||
|
||||
# Cmdlets to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no cmdlets to export.
|
||||
# CmdletsToExport = @()
|
||||
|
||||
@@ -93,9 +93,18 @@ function Initialize-CloudAPIManagement
|
||||
[void] [System.Reflection.Assembly]::LoadWithPartialName("System.Windows.Forms")
|
||||
Add-Type -AssemblyName PresentationFramework
|
||||
|
||||
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
|
||||
|
||||
$global:hideUI = ($Silent -eq $true)
|
||||
$global:SilentBatchFile = $SilentBatchFile
|
||||
|
||||
if($tenantId)
|
||||
{
|
||||
$global:AzureAppId = $appId
|
||||
$global:ClientSecret = $secret
|
||||
$global:ClientCert = $certificate
|
||||
}
|
||||
|
||||
if($global:hideUI -ne $true)
|
||||
{
|
||||
# Run with UI
|
||||
@@ -126,12 +135,11 @@ function Initialize-CloudAPIManagement
|
||||
Write-Error "Tenant Id is missing. Use -TenantId <Tenant-guid> on the command line to run silent batch jobs"
|
||||
return
|
||||
}
|
||||
$global:TenantId = $tenantId
|
||||
$global:AzureAppId = $appId
|
||||
$global:ClientSecret = $secret
|
||||
$global:ClientCert = $certificate
|
||||
}
|
||||
|
||||
$global:TenantId = $tenantId
|
||||
|
||||
|
||||
if($ShowConsoleWindow -ne $true)
|
||||
{
|
||||
Hide-Console
|
||||
|
||||
@@ -11,7 +11,7 @@ This module handles the WPF UI
|
||||
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'3.8.1'
|
||||
'3.9.3'
|
||||
}
|
||||
|
||||
function Initialize-Window
|
||||
@@ -58,6 +58,7 @@ function Start-CoreApp
|
||||
|
||||
$global:useDefaultFolderDialog = $false
|
||||
$global:WindowsAPICodePackLoaded = $false
|
||||
$script:proxyURI = $null
|
||||
|
||||
$global:loadedModules = @()
|
||||
$global:viewObjects = @()
|
||||
@@ -235,6 +236,8 @@ function Write-Log
|
||||
|
||||
if(-not $global:logFileMaxSize) { [Int64]$global:logFileMaxSize = Get-SettingValue "LogFileSize" 1024; $global:logFileMaxSize = $global:logFileMaxSize * 1kb }
|
||||
|
||||
if($null -eq $global:logOutputError) { $global:logOutputError = Get-SettingValue "LogOutputError" }
|
||||
|
||||
$fi = [IO.FileInfo]$global:logFile
|
||||
|
||||
if($fi.Length -gt $global:logFileMaxSize)
|
||||
@@ -286,12 +289,19 @@ function Write-Log
|
||||
if($type -eq 2)
|
||||
{
|
||||
Write-Warning $Text
|
||||
$typeStr = "Error"
|
||||
$typeStr = "Warning"
|
||||
}
|
||||
elseif($type -eq 3)
|
||||
{
|
||||
if($global:logOutputError -ne $false)
|
||||
{
|
||||
$host.ui.WriteErrorLine($Text)
|
||||
$typeStr = "Warning"
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Warning $Text
|
||||
}
|
||||
$typeStr = "Error"
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -667,8 +677,15 @@ function Show-UpdatesDialog
|
||||
{
|
||||
if($mystream) { $mystream.Dispose() }
|
||||
}
|
||||
$params = @{}
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
$params.Add("UseBasicParsing", $true)
|
||||
}
|
||||
|
||||
$content = Invoke-RestMethod "https://api.github.com/repos/Micke-K/IntuneManagement/contents/ReleaseNotes.md"
|
||||
$content = Invoke-RestMethod "https://api.github.com/repos/Micke-K/IntuneManagement/contents/ReleaseNotes.md" @params
|
||||
if($content)
|
||||
{
|
||||
$txt = [System.Text.Encoding]::UTF8.GetString(([System.Convert]::FromBase64String($content.content)))
|
||||
@@ -703,7 +720,15 @@ function Get-IsLatestVersion
|
||||
|
||||
$gitHubVer = $null
|
||||
|
||||
$content = Invoke-RestMethod "https://api.github.com/repos/Micke-K/IntuneManagement/releases/latest"
|
||||
$params = @{}
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
$params.Add("UseBasicParsing", $true)
|
||||
}
|
||||
|
||||
$content = Invoke-RestMethod "https://api.github.com/repos/Micke-K/IntuneManagement/releases/latest" @params
|
||||
if($content.Name)
|
||||
{
|
||||
try
|
||||
@@ -715,7 +740,15 @@ function Get-IsLatestVersion
|
||||
|
||||
if($null -eq $gitHubVer)
|
||||
{
|
||||
$content = Invoke-RestMethod "https://api.github.com/repos/Micke-K/IntuneManagement/contents/CloudAPIPowerShellManagement.psd1"
|
||||
$params = @{}
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
$params.Add("UseBasicParsing", $true)
|
||||
}
|
||||
|
||||
$content = Invoke-RestMethod "https://api.github.com/repos/Micke-K/IntuneManagement/contents/CloudAPIPowerShellManagement.psd1" @params
|
||||
$gitHubText = [System.Text.Encoding]::UTF8.GetString(([System.Convert]::FromBase64String($content.content)))
|
||||
$gitHubInfo = Get-ModuleDataTable $gitHubText
|
||||
try
|
||||
@@ -1150,6 +1183,10 @@ function Expand-FileName
|
||||
[Environment]::SetEnvironmentVariable("DateTime",$null,[System.EnvironmentVariableTarget]::Process)
|
||||
[Environment]::SetEnvironmentVariable("Organization",$null,[System.EnvironmentVariableTarget]::Process)
|
||||
|
||||
# Remove invalid path characters
|
||||
$re = "[{0}]" -f [RegEx]::Escape(([IO.Path]::GetInvalidPathChars() -join ''))
|
||||
$fileName = $fileName -replace $re
|
||||
|
||||
$fileName
|
||||
}
|
||||
|
||||
@@ -1168,6 +1205,8 @@ function Initialize-Settings
|
||||
$global:Debug = Get-SettingValue "Debug"
|
||||
$global:logFile = $null
|
||||
$global:logFileMaxSize = $null
|
||||
$global:logOutputError = $null
|
||||
$script:proxyURI = $null
|
||||
|
||||
if($Updated -eq $true)
|
||||
{
|
||||
@@ -1943,6 +1982,14 @@ function Add-DefaultSettings
|
||||
DefaultValue = 1024
|
||||
}) "General"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Add errors to PowerShell output"
|
||||
Key = "LogOutputError"
|
||||
Type = "Boolean"
|
||||
Description = "Write errors to the Error Output of the PS Host. If disabled, errors will be written as a Warning. Eg. disable this if automation should skip logging PowerShell errors."
|
||||
DefaultValue = $true
|
||||
}) "General"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Debug"
|
||||
Key = "Debug"
|
||||
@@ -1998,6 +2045,12 @@ function Add-DefaultSettings
|
||||
Description = "Adds the organization name next to the login info on the menu bar"
|
||||
}) "General"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Proxy URI"
|
||||
Key = "ProxyURI"
|
||||
Description = "Specify the URI for the proxy eg http://<server>:<port>"
|
||||
}) "General"
|
||||
|
||||
}
|
||||
|
||||
function Add-SettingsObject
|
||||
@@ -2435,6 +2488,15 @@ function Get-MainWindow
|
||||
|
||||
Show-ModalForm $window.Title $script:welcomeForm -HideButtons
|
||||
}
|
||||
else
|
||||
{
|
||||
###!!! Force login here
|
||||
if($global:currentViewObject.ViewInfo.Authenticate)
|
||||
{
|
||||
# Skip for now...need additional code to skip previous login and force this based on setting.
|
||||
#!!!& $global:currentViewObject.ViewInfo.Authenticate -Params (@{"Interactve"=$true})
|
||||
}
|
||||
}
|
||||
})
|
||||
|
||||
foreach($view in $global:viewObjects)
|
||||
@@ -2694,6 +2756,110 @@ function Get-Base64ScriptContent
|
||||
}
|
||||
}
|
||||
|
||||
function Get-ProxyURI
|
||||
{
|
||||
if($null -eq $script:proxyURI)
|
||||
{
|
||||
$script:proxyUri = Get-SettingValue "ProxyURI"
|
||||
}
|
||||
|
||||
if($null -eq $script:proxyURI)
|
||||
{
|
||||
$script:proxyUri = ""
|
||||
}
|
||||
return $script:proxyURI
|
||||
}
|
||||
|
||||
function Start-DownloadFile
|
||||
{
|
||||
param($sourceURL, $targetFile)
|
||||
|
||||
Write-Log "Download file from $sourceURL"
|
||||
if(-not $sourceURL)
|
||||
{
|
||||
return
|
||||
}
|
||||
|
||||
if(-not $targetFile)
|
||||
{
|
||||
Write-Log "Target file is missing"
|
||||
return
|
||||
}
|
||||
|
||||
[void][System.Reflection.Assembly]::LoadWithPartialName("System.Web.Extensions")
|
||||
$wc = New-Object System.Net.WebClient
|
||||
$wc.Encoding = [System.Text.Encoding]::UTF8
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$wc.Proxy = $proxyURI
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
$title = $sourceURL.Split("/")[-1]
|
||||
$title = $title.Split("/")[0]
|
||||
}
|
||||
catch
|
||||
{
|
||||
$title = $sourceURL
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
Write-Status "Download file: `n$title"
|
||||
$wc.DownloadFile($sourceURL, $targetFile)
|
||||
Write-Log "File downloaded to $targetFile"
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-LogError "Failed to download file" $_.Exception
|
||||
}
|
||||
finally
|
||||
{
|
||||
$wc.Dispose()
|
||||
}
|
||||
}
|
||||
|
||||
function Get-ASCIIBytes
|
||||
{
|
||||
param($String)
|
||||
|
||||
$bytes = [System.Text.Encoding]::ASCII.GetBytes($String)
|
||||
|
||||
if ($bytes[0] -eq 0x2b -and $bytes[1] -eq 0x2f -and $bytes[2] -eq 0x76)
|
||||
{ [Text.Encoding]::UTF7.GetBytes($String) }
|
||||
elseif ($bytes[0] -eq 0xff -and $bytes[1] -eq 0xfe)
|
||||
{ [Text.Encoding]::Unicode.GetBytes($String) }
|
||||
elseif ($bytes[0] -eq 0xfe -and $bytes[1] -eq 0xff)
|
||||
{ [Text.Encoding]::BigEndianUnicode.GetBytes($String) }
|
||||
elseif ($bytes[0] -eq 0x00 -and $bytes[1] -eq 0x00 -and $bytes[2] -eq 0xfe -and $bytes[3] -eq 0xff)
|
||||
{ [Text.Encoding]::UTF32.GetBytes($String) }
|
||||
elseif ($bytes[0] -eq 0xef -and $bytes[1] -eq 0xbb -and $bytes[2] -eq 0xbf)
|
||||
{ [Text.Encoding]::UTF8.GetBytes($String) }
|
||||
|
||||
$bytes
|
||||
}
|
||||
|
||||
function Get-DataGridValues
|
||||
{
|
||||
param($dataGrid)
|
||||
|
||||
$dgColumns = $dataGrid.Columns
|
||||
|
||||
$properties = @()
|
||||
|
||||
foreach($tmpCol in $dgColumns)
|
||||
{
|
||||
if(-not $tmpCol.Binding.Path.Path) { continue }
|
||||
$propName = $tmpCol.Binding.Path.Path
|
||||
$properties += @{n=$tmpCol.Header;e=([Scriptblock]::Create("`$_.$propName"))}
|
||||
}
|
||||
|
||||
($dataGrid.ItemsSource | Select -Property $properties)
|
||||
}
|
||||
|
||||
|
||||
New-Alias -Name ?? -value Invoke-Coalesce
|
||||
New-Alias -Name ?: -value Invoke-IfTrue
|
||||
Export-ModuleMember -alias * -function *
|
||||
@@ -1099,12 +1099,12 @@
|
||||
"category": "SettingDetails.dependencyCategory"
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "supersedenceCategory",
|
||||
"nameResourceKey": "AppRelationshipStatus.Tabs.supersedence",
|
||||
"descriptionResourceKey": "",
|
||||
"entityKey": "supersededApps",
|
||||
"dataType": 20,
|
||||
"booleanActions": 0,
|
||||
"category": "SettingDetails.supersedenceCategory"
|
||||
"category": "AppRelationshipStatus.Tabs.supersedence"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -0,0 +1,69 @@
|
||||
[
|
||||
{
|
||||
"nameResourceKey": "TableHeaders.policyType",
|
||||
"descriptionResourceKey": "",
|
||||
"entityKey": "WindowsDriverUpdateProfile.Subtitle.automatic",
|
||||
"dataType": 200,
|
||||
"booleanActions": 0,
|
||||
"category": 1000,
|
||||
"Condition": {
|
||||
"Expressions": [
|
||||
{
|
||||
"property": "approvalType",
|
||||
"value": "automatic"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "TableHeaders.policyType",
|
||||
"descriptionResourceKey": "",
|
||||
"entityKey": "WindowsDriverUpdateProfile.Subtitle.manual",
|
||||
"dataType": 200,
|
||||
"booleanActions": 0,
|
||||
"category": 1000,
|
||||
"Condition": {
|
||||
"Expressions": [
|
||||
{
|
||||
"property": "approvalType",
|
||||
"value": "manual"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "WindowsDriverUpdateProfile.Details.ApprovalMethod.label",
|
||||
"descriptionResourceKey": "",
|
||||
"entityKey": "approvalType",
|
||||
"dataType": 16,
|
||||
"booleanActions": 0,
|
||||
"category": "TableHeaders.settings",
|
||||
"options": [
|
||||
{
|
||||
"nameResourceKey": "WindowsDriverUpdateProfile.ApprovalMethod.automatic",
|
||||
"value": "automatic"
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "WindowsDriverUpdateProfile.ApprovalMethod.manual",
|
||||
"value": "manual"
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "WindowsDriverUpdateProfile.Details.DeploymentDeferralInDays.label",
|
||||
"descriptionResourceKey": "",
|
||||
"entityKey": "deploymentDeferralInDays",
|
||||
"formatStringKey": "WindowsDriverUpdateProfile.Details.DeploymentDeferralInDays.value",
|
||||
"dataType": 108,
|
||||
"booleanActions": 0,
|
||||
"category": "TableHeaders.settings",
|
||||
"Condition": {
|
||||
"Expressions": [
|
||||
{
|
||||
"property": "approvalType",
|
||||
"value": "automatic"
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
+158
@@ -113,6 +113,164 @@
|
||||
"defaultValue": false,
|
||||
"policyType": 2,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"columns": [
|
||||
{
|
||||
"metadata": {
|
||||
"dataType": 20,
|
||||
"category": 2,
|
||||
"nameResourceKey": "appNameName",
|
||||
"descriptionResourceKey": "Empty",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "name",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
}
|
||||
},
|
||||
{
|
||||
"metadata": {
|
||||
"dataType": 20,
|
||||
"category": 2,
|
||||
"nameResourceKey": "packageName",
|
||||
"descriptionResourceKey": "Empty",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "appId",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
}
|
||||
},
|
||||
{
|
||||
"metadata": {
|
||||
"dataType": 20,
|
||||
"category": 2,
|
||||
"nameResourceKey": "appUrlName",
|
||||
"descriptionResourceKey": "Empty",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "appStoreUrl",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
}
|
||||
},
|
||||
{
|
||||
"metadata": {
|
||||
"dataType": 20,
|
||||
"category": 2,
|
||||
"nameResourceKey": "appPublisherName",
|
||||
"descriptionResourceKey": "Empty",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "publisher",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
}
|
||||
}
|
||||
],
|
||||
"dataType": 21,
|
||||
"category": 2,
|
||||
"nameResourceKey": "certificateInstallTitle",
|
||||
"descriptionResourceKey": "certificateInstallDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "certInstallApps",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"complexOptions": [
|
||||
{
|
||||
"dataType": 11,
|
||||
"category": 2,
|
||||
"nameResourceKey": "selectSecurityApp",
|
||||
"descriptionResourceKey": "empty",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "securityLogAppId",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"dataType": 5,
|
||||
"category": 2,
|
||||
"nameResourceKey": "securityLogsTitle",
|
||||
"emptyValueResourceKey": "selectSecurityApp",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "securityLogApp",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"complexOptions": [
|
||||
{
|
||||
"dataType": 11,
|
||||
"category": 2,
|
||||
"nameResourceKey": "selectNetworkApp",
|
||||
"descriptionResourceKey": "empty",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "networkLogAppId",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"dataType": 5,
|
||||
"category": 2,
|
||||
"nameResourceKey": "networkLogsTitle",
|
||||
"emptyValueResourceKey": "selectNetworkApp",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "networkLogApp",
|
||||
"booleanActions": 0,
|
||||
"policyType": 2,
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"options": [
|
||||
|
||||
@@ -154,8 +154,8 @@
|
||||
{
|
||||
"dataType": 16,
|
||||
"category": 39,
|
||||
"nameResourceKey": "safetyNetAttestationOptionsName",
|
||||
"descriptionResourceKey": "safetyNetAttestationOptionsDescription",
|
||||
"nameResourceKey": "playIntegrityVerdictOptionsName",
|
||||
"descriptionResourceKey": "playIntegrityVerdictOptionsDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
@@ -166,17 +166,17 @@
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "androidSafetyNetbasicIntegrity",
|
||||
"nameResourceKey": "androidPlayIntegrityVerdictBasicIntegrity",
|
||||
"value": "basicIntegrity",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "androidSafetyNetBasicIntegrityAndCertified",
|
||||
"nameResourceKey": "androidPlayIntegrityVerdictBasicAndDeviceIntegrity",
|
||||
"value": "basicIntegrityAndCertified",
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"entityKey": "androidSafetyNetAttestationOptions",
|
||||
"entityKey": "androidPlayIntegrityVerdictOptions",
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "notConfigured",
|
||||
"unconfiguredValue": "notConfigured",
|
||||
|
||||
@@ -52,8 +52,8 @@
|
||||
{
|
||||
"dataType": 16,
|
||||
"category": 39,
|
||||
"nameResourceKey": "safetyNetAttestationOptionsName",
|
||||
"descriptionResourceKey": "safetyNetAttestationOptionsDescription",
|
||||
"nameResourceKey": "playIntegrityVerdictOptionsName",
|
||||
"descriptionResourceKey": "playIntegrityVerdictOptionsDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
@@ -64,17 +64,17 @@
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "androidSafetyNetbasicIntegrity",
|
||||
"nameResourceKey": "androidPlayIntegrityVerdictBasicIntegrity",
|
||||
"value": "basicIntegrity",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "androidSafetyNetBasicIntegrityAndCertified",
|
||||
"nameResourceKey": "androidPlayIntegrityVerdictBasicAndDeviceIntegrity",
|
||||
"value": "basicIntegrityAndCertified",
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"entityKey": "androidSafetyNetAttestationOptions",
|
||||
"entityKey": "androidPlayIntegrityVerdictOptions",
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "notConfigured",
|
||||
"unconfiguredValue": "notConfigured",
|
||||
|
||||
@@ -103,8 +103,8 @@
|
||||
{
|
||||
"dataType": 16,
|
||||
"category": 39,
|
||||
"nameResourceKey": "safetyNetAttestationOptionsName",
|
||||
"descriptionResourceKey": "safetyNetAttestationOptionsDescription",
|
||||
"nameResourceKey": "playIntegrityVerdictOptionsName",
|
||||
"descriptionResourceKey": "playIntegrityVerdictOptionsDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
@@ -115,25 +115,25 @@
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "androidSafetyNetbasicIntegrity",
|
||||
"nameResourceKey": "androidPlayIntegrityVerdictBasicIntegrity",
|
||||
"value": "basicIntegrity",
|
||||
"children": [
|
||||
{
|
||||
"dataType": 16,
|
||||
"category": 39,
|
||||
"nameResourceKey": "requiredAndroidSafetyNetEvaluationTypeName",
|
||||
"descriptionResourceKey": "requiredAndroidSafetyNetEvaluationTypeDescription",
|
||||
"nameResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeName",
|
||||
"descriptionResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
{
|
||||
"nameResourceKey": "requiredAndroidSafetyNetEvaluationTypeBasic",
|
||||
"nameResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeBasic",
|
||||
"value": "basic",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "requiredAndroidSafetyNetEvaluationTypeHardwareBacked",
|
||||
"nameResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeHardwareBacked",
|
||||
"value": "hardwareBacked",
|
||||
"enabled": true
|
||||
}
|
||||
@@ -149,25 +149,25 @@
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "androidSafetyNetBasicIntegrityAndCertified",
|
||||
"nameResourceKey": "androidPlayIntegrityVerdictBasicAndDeviceIntegrity",
|
||||
"value": "basicIntegrityAndCertified",
|
||||
"children": [
|
||||
{
|
||||
"dataType": 16,
|
||||
"category": 39,
|
||||
"nameResourceKey": "requiredAndroidSafetyNetEvaluationTypeName",
|
||||
"descriptionResourceKey": "requiredAndroidSafetyNetEvaluationTypeDescription",
|
||||
"nameResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeName",
|
||||
"descriptionResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
{
|
||||
"nameResourceKey": "requiredAndroidSafetyNetEvaluationTypeBasic",
|
||||
"nameResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeBasic",
|
||||
"value": "basic",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "requiredAndroidSafetyNetEvaluationTypeHardwareBacked",
|
||||
"nameResourceKey": "requiredAndroidPlayIntegrityVerdictEvaluationTypeHardwareBacked",
|
||||
"value": "hardwareBacked",
|
||||
"enabled": true
|
||||
}
|
||||
@@ -183,7 +183,7 @@
|
||||
"enabled": true
|
||||
}
|
||||
],
|
||||
"entityKey": "androidSafetyNetAttestationOptions",
|
||||
"entityKey": "androidPlayIntegrityVerdictOptions",
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "notConfigured",
|
||||
"unconfiguredValue": "notConfigured",
|
||||
|
||||
@@ -1,16 +1,32 @@
|
||||
{
|
||||
"devicehealth_compliancewindows10": {
|
||||
"devicehealth_compliancewindows10": [
|
||||
{
|
||||
"isSettingDescription": false,
|
||||
"showAsSectionHeader": false,
|
||||
"dataType": 8,
|
||||
"category": 39,
|
||||
"nameResourceKey": "complianceWindowsDeviceHealthAttestationHeader",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"booleanActions": 0,
|
||||
"policyType": 35,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"isSettingDescription": false,
|
||||
"showAsSectionHeader": false,
|
||||
"dataType": 8,
|
||||
"category": 39,
|
||||
"nameResourceKey": "complianceWindows10DeviceHealthAttestationHeader",
|
||||
"childSettings": [
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "bitLockerEnabledName",
|
||||
"descriptionResourceKey": "bitLockerEnabledDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
@@ -27,7 +43,6 @@
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "secureBootEnabledName",
|
||||
"descriptionResourceKey": "secureBootEnabledDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
@@ -44,7 +59,6 @@
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "codeIntegrityEnabledName",
|
||||
"descriptionResourceKey": "codeIntegrityEnabledDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
@@ -64,5 +78,101 @@
|
||||
"booleanActions": 0,
|
||||
"policyType": 35,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"isSettingDescription": false,
|
||||
"showAsSectionHeader": false,
|
||||
"dataType": 8,
|
||||
"category": 39,
|
||||
"nameResourceKey": "complianceWindows11DeviceHealthAttestationHeader",
|
||||
"childSettings": [
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "earlyLaunchAntiMalwareDriverEnabledName",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "earlyLaunchAntiMalwareDriverEnabled",
|
||||
"booleanActions": 1,
|
||||
"defaultValue": false,
|
||||
"policyType": 35,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "firmwareProtectionEnabledName",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "firmwareProtectionEnabled",
|
||||
"booleanActions": 1,
|
||||
"defaultValue": false,
|
||||
"policyType": 35,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "hvciEnabledName",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "memoryIntegrityEnabled",
|
||||
"booleanActions": 1,
|
||||
"defaultValue": false,
|
||||
"policyType": 35,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "memoryAccessProtectionEnabledName",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "kernelDmaProtectionEnabled",
|
||||
"booleanActions": 1,
|
||||
"defaultValue": false,
|
||||
"policyType": 35,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 39,
|
||||
"nameResourceKey": "virtualizationBasedSecurityEnabledName",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "virtualizationBasedSecurityEnabled",
|
||||
"booleanActions": 1,
|
||||
"defaultValue": false,
|
||||
"policyType": 35,
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"booleanActions": 0,
|
||||
"policyType": 35,
|
||||
"enabled": false
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -448,6 +448,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -418,6 +418,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -195,6 +195,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -418,6 +418,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -457,6 +457,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -457,6 +457,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -234,6 +234,12 @@
|
||||
"displayText": "2048",
|
||||
"value": "size2048",
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"nameResourceKey": "",
|
||||
"displayText": "4096",
|
||||
"value": "size4096",
|
||||
"enabled": false
|
||||
}
|
||||
],
|
||||
"entityKey": "keySize",
|
||||
|
||||
@@ -584,7 +584,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -2329,7 +2329,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -4074,7 +4074,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -5819,7 +5819,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -8052,7 +8052,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -9797,7 +9797,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -11542,7 +11542,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -13272,7 +13272,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -15390,7 +15390,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -17120,7 +17120,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -18850,7 +18850,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -20622,7 +20622,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -22367,7 +22367,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -24112,7 +24112,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -25857,7 +25857,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -28090,7 +28090,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -29835,7 +29835,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -31580,7 +31580,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -33310,7 +33310,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -35428,7 +35428,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -37158,7 +37158,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -38888,7 +38888,7 @@
|
||||
"booleanActions": 0,
|
||||
"defaultValue": "outbound",
|
||||
"policyType": 89,
|
||||
"enabled": false
|
||||
"enabled": true
|
||||
}
|
||||
},
|
||||
{
|
||||
|
||||
@@ -613,6 +613,23 @@
|
||||
"policyType": 13,
|
||||
"enabled": true
|
||||
},
|
||||
{
|
||||
"dataType": 0,
|
||||
"category": 127,
|
||||
"nameResourceKey": "blockUnifiedPasswordForWorkProfileName",
|
||||
"descriptionResourceKey": "blockUnifiedPasswordForWorkProfileDescription",
|
||||
"childSettings": [
|
||||
|
||||
],
|
||||
"options": [
|
||||
|
||||
],
|
||||
"entityKey": "blockUnifiedPasswordForWorkProfile",
|
||||
"booleanActions": 3,
|
||||
"defaultValue": false,
|
||||
"policyType": 13,
|
||||
"enabled": false
|
||||
},
|
||||
{
|
||||
"isSettingDescription": false,
|
||||
"showAsSectionHeader": true,
|
||||
|
||||
+2751
-1620
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
+2751
-1620
File diff suppressed because it is too large
Load Diff
+2751
-1620
File diff suppressed because it is too large
Load Diff
+2751
-1620
File diff suppressed because it is too large
Load Diff
+2751
-1620
File diff suppressed because it is too large
Load Diff
+2752
-1621
File diff suppressed because it is too large
Load Diff
+2753
-1622
File diff suppressed because it is too large
Load Diff
+2749
-1618
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
+2752
-1621
File diff suppressed because it is too large
Load Diff
+2751
-1620
File diff suppressed because it is too large
Load Diff
+2752
-1621
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
+2752
-1621
File diff suppressed because it is too large
Load Diff
+2753
-1622
File diff suppressed because it is too large
Load Diff
+2750
-1619
File diff suppressed because it is too large
Load Diff
@@ -20,7 +20,7 @@ $global:documentationProviders = @()
|
||||
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'2.0.1'
|
||||
'2.0.3'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -61,6 +61,7 @@ function Invoke-InitializeModule
|
||||
Settings="TableHeaders.settings"
|
||||
returnCode='Win32ReturnCodes.Columns.returnCode'
|
||||
type='Win32ReturnCodes.Columns.codeType'
|
||||
RecommendedValue="AzureIAMCommon.Recommended"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -227,6 +228,7 @@ function Get-ObjectDocumentation
|
||||
$script:applicabilityRules = @()
|
||||
$script:objectAssignments = @()
|
||||
$script:objectScripts = @()
|
||||
$script:admxCategories = $null
|
||||
|
||||
$script:ObjectTypeFullTable = @{} # Hash table with objects that should be documented in a single table eg ScopeTags
|
||||
|
||||
@@ -290,7 +292,8 @@ function Get-ObjectDocumentation
|
||||
elseif($type -eq "#microsoft.graph.deviceManagementIntent")
|
||||
{
|
||||
Invoke-TranslateIntentObject $obj $objectType | Out-Null
|
||||
$properties = @("Name","Value","Category","FullValueTable","RawValue","SettingId","Description")
|
||||
$properties = @("Name","Value","Category","FullValueTable","RawValue","RecommendedValue","SettingId","Description")
|
||||
$defaultDocumentationProperties = @("Name","Value","RecommendedValue")
|
||||
}
|
||||
#endregion
|
||||
#region Administrative Templates
|
||||
@@ -382,6 +385,7 @@ function Invoke-ObjectDocumentation
|
||||
$global:catRecommendedSettings = $null
|
||||
$global:intentCategoryDefs = $null
|
||||
$global:cfgCategories = $null
|
||||
$script:admxCategories = $null
|
||||
|
||||
$script:DocumentationLanguage = "en"
|
||||
$script:objectSeparator = [System.Environment]::NewLine
|
||||
@@ -541,6 +545,10 @@ function Get-ObjectTypeString
|
||||
{
|
||||
return (Get-LanguageString "Titles.windows10QualityUpdate")
|
||||
}
|
||||
elseif($objTypeId -eq "WinDriverUpdatePolicies")
|
||||
{
|
||||
return (Get-LanguageString "Titles.windows10DriverUpdate")
|
||||
}
|
||||
elseif($objTypeId -eq "TenantAdmin")
|
||||
{
|
||||
return (Get-LanguageString "Titles.tenantAdmin")
|
||||
@@ -873,7 +881,8 @@ function Invoke-TranslateADMXObject
|
||||
{
|
||||
if(-not $definitionValue.definition -and $definitionValues.'definition@odata.bind')
|
||||
{
|
||||
$definition = Invoke-GraphRequest -Url $definitionValue.'definition@odata.bind' -ODataMetadata "minimal" @params
|
||||
$url = $definitionValue.'definition@odata.bind' -replace $global:graphURL, ("https://$((?? $global:MSALGraphEnvironment "graph.microsoft.com"))/beta")
|
||||
$definition = Invoke-GraphRequest -Url $url -ODataMetadata "minimal" @params
|
||||
if($definition)
|
||||
{
|
||||
$definitionValue | Add-Member -MemberType NoteProperty -Name "definition" -Value $definition
|
||||
@@ -1488,6 +1497,12 @@ function Add-IntentSettingObjectToList
|
||||
$objSetting.Level = $objSetting.Level + 1
|
||||
}
|
||||
|
||||
$recommendedSetting = $global:catRecommendedSettings[$objSetting.CategoryObject.Id] | Where definitionId -eq $objSetting.SettingId
|
||||
|
||||
if($recommendedSetting.valueJson -and ($objSetting.ValueSet -eq $false -or $recommendedSetting.valueJson -ne ($objSetting.RawValue | ConvertTo-Json -Compress))) {
|
||||
$objSetting | Add-Member Noteproperty -Name "RecommendedValue" -Value ($recommendedSetting.valueJson | ConvertFrom-Json) -Force
|
||||
}
|
||||
|
||||
$script:objectSettingsData += $objSetting
|
||||
|
||||
if($objSetting.ValueSet -eq $false) { return }
|
||||
@@ -1912,7 +1927,8 @@ function Get-LanguageString
|
||||
|
||||
if(-not $script:languageStrings)
|
||||
{
|
||||
$fileContent = Get-Content ($global:AppRootFolder + "\Documentation\Strings-$($script:DocumentationLanguage).json") -Encoding UTF8
|
||||
$lng = ?? $script:DocumentationLanguage "en"
|
||||
$fileContent = Get-Content ($global:AppRootFolder + "\Documentation\Strings-$($lng).json") -Encoding UTF8
|
||||
$script:languageStrings = $fileContent | ConvertFrom-Json
|
||||
}
|
||||
|
||||
@@ -2415,6 +2431,17 @@ function Invoke-TranslateSection
|
||||
}
|
||||
$value = $arrTmp -join $script:objectSeparator
|
||||
}
|
||||
elseif($prop.dataType -eq 108) # String with format
|
||||
{
|
||||
$value = $propValue
|
||||
if($prop.formatStringKey) {
|
||||
$str = Get-LanguageString $prop.formatStringKey
|
||||
if($str)
|
||||
{
|
||||
$value = $str -f $propValue
|
||||
}
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Unsupported property '$((Get-LanguageString "SettingDetails.$($prop.nameResourceKey)"))' ($($prop.nameResourceKey)) for object property $($prop.entityKey). Type: $($prop.dataType)" 2
|
||||
@@ -4409,7 +4436,7 @@ function local:Invoke-StartDocumentatiom
|
||||
# Add each object to the documentation
|
||||
foreach($curGroupId in ($sourceList.ObjectType | Select GroupID -Unique).GroupID)
|
||||
{
|
||||
# New object group e.g. Script, Tennant, Device Configuration
|
||||
# New object group e.g. Script, Tenant, Device Configuration
|
||||
# A group matches a menu item in the protal but can contain multiple object types
|
||||
if($global:cbDocumentationType.SelectedItem.NewObjectGroup)
|
||||
{
|
||||
@@ -5018,3 +5045,18 @@ function Set-TableObjects
|
||||
$script:ObjectTypeFullTable.Add($objectInfo.ObjectType.Id, $objectInfo)
|
||||
}
|
||||
}
|
||||
|
||||
function Get-PolicyTypeName
|
||||
{
|
||||
param($type, $default = $null)
|
||||
|
||||
$categoryObj = Get-TranslationFiles $type
|
||||
|
||||
if($null -eq $categoryObj) { return $default }
|
||||
|
||||
$lngStr = Get-LanguageString "PolicyType.$($categoryObj.PolicyTypeLanguageId)"
|
||||
|
||||
if($lngStr) { return $lngStr }
|
||||
|
||||
return $defult
|
||||
}
|
||||
@@ -10,7 +10,7 @@ This module will also document some objects based on PowerShell functions
|
||||
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'1.6.0'
|
||||
'1.6.3'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -267,7 +267,7 @@ function Invoke-CDDocumentCustomPostAdd
|
||||
|
||||
if($prop.EntityKey -eq "featureUpdatesRollbackWindowInDays")
|
||||
{
|
||||
if($obj.businessReadyUpdatesOnly -eq "businessReadyOnly")
|
||||
if($obj.businessReadyUpdatesOnly -eq "businessReadyOnly" -or $obj.businessReadyUpdatesOnly -eq "all" -or $obj.businessReadyUpdatesOnly -eq "userDefined")
|
||||
{
|
||||
$propValue = Get-LanguageString "BooleanActions.notConfigured"
|
||||
}
|
||||
@@ -288,7 +288,7 @@ function Invoke-CDDocumentCustomPostAdd
|
||||
|
||||
Add-PropertyInfo $tmpProp $propValue -originalValue $obj.businessReadyUpdatesOnly
|
||||
|
||||
if($obj.businessReadyUpdatesOnly -ne "businessReadyOnly")
|
||||
if($obj.businessReadyUpdatesOnly -ne "businessReadyOnly" -and $obj.businessReadyUpdatesOnly -ne "all" -and $obj.businessReadyUpdatesOnly -ne "userDefined")
|
||||
{
|
||||
# Pre-release channel selected. Inject info
|
||||
$propValue = Get-LanguageString "SettingDetails.$($obj.businessReadyUpdatesOnly)Option"
|
||||
@@ -2029,17 +2029,17 @@ function Invoke-CDDocumentCountryNamedLocation
|
||||
###################################################
|
||||
|
||||
Add-BasicDefaultValues $obj $objectType
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureIAM.menuItemNamedNetworks")
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureCA.menuItemNamedNetworks")
|
||||
Add-BasicAdditionalValues $obj $objectType
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.NamedLocation.Form.CountryLookup.ariaLabel"
|
||||
Value = Get-LanguageString "AzureIAM.NamedLocation.Form.CountryLookup.$((?: ($obj.countryLookupMethod -eq "clientIpAddress") "ip" "gps"))"
|
||||
Name = Get-LanguageString "AzureCA.NamedLocation.Form.CountryLookup.ariaLabel"
|
||||
Value = Get-LanguageString "AzureCA.NamedLocation.Form.CountryLookup.$((?: ($obj.countryLookupMethod -eq "clientIpAddress") "ip" "gps"))"
|
||||
EntityKey = "countryLookupMethod"
|
||||
})
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.NamedLocation.Form.Include.label"
|
||||
Name = Get-LanguageString "AzureCA.NamedLocation.Form.Include.label"
|
||||
Value = Get-LanguageString (?: ($obj.includeUnknownCountriesAndRegions -eq $true) "Inputs.enabled" "Inputs.disabled")
|
||||
EntityKey = "includeUnknownCountriesAndRegions"
|
||||
})
|
||||
@@ -2047,11 +2047,11 @@ function Invoke-CDDocumentCountryNamedLocation
|
||||
$countryList = @()
|
||||
foreach($country in $obj.countriesAndRegions)
|
||||
{
|
||||
$countryList += Get-LanguageString "AzureIAMCommon.CountryNames.countryName$($country.ToLower())"
|
||||
$countryList += Get-LanguageString "CountryNames.countryName$($country.ToLower())"
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.NamedLocation.Type.countries"
|
||||
Name = Get-LanguageString "AzureCA.NamedLocation.Type.countries"
|
||||
Value = $countryList -join $script:objectSeparator
|
||||
EntityKey = "countriesAndRegions"
|
||||
})
|
||||
@@ -2072,11 +2072,11 @@ function Invoke-CDDocumentIPNamedLocation
|
||||
###################################################
|
||||
|
||||
Add-BasicDefaultValues $obj $objectType
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureIAM.menuItemNamedNetworks")
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureCA.menuItemNamedNetworks")
|
||||
Add-BasicAdditionalValues $obj $objectType
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.NamedLocation.Form.Trusted.label"
|
||||
Name = Get-LanguageString "AzureCA.NamedLocation.Form.Trusted.label"
|
||||
Value = Get-LanguageString (?: ($obj.isTrusted -eq $true) "Inputs.enabled" "Inputs.disabled")
|
||||
EntityKey = "isTrusted"
|
||||
})
|
||||
@@ -2088,7 +2088,7 @@ function Invoke-CDDocumentIPNamedLocation
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.NamedLocation.Type.ipRanges"
|
||||
Name = Get-LanguageString "AzureCA.NamedLocation.Type.ipRanges"
|
||||
Value = $ipList -join $script:objectSeparator
|
||||
EntityKey = "ipRanges"
|
||||
})
|
||||
@@ -2113,7 +2113,7 @@ function Invoke-CDDocumentTermsOfUse
|
||||
###################################################
|
||||
|
||||
Add-BasicPropertyValue (Get-LanguageString "SettingDetails.nameName") $obj.displayName
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureIAM.menuItemTermsOfUse")
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureCA.menuItemTermsOfUse")
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "TermsOfUse.Wizard.agreementIsViewingBeforeAcceptanceRequiredLabel"
|
||||
@@ -2222,25 +2222,156 @@ function Invoke-CDDocumentConditionalAccess
|
||||
|
||||
#Add-BasicDefaultValues $obj $objectType
|
||||
Add-BasicPropertyValue (Get-LanguageString "SettingDetails.nameName") $obj.displayName
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureIAM.conditionalAccessBladeTitle")
|
||||
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "AzureCA.conditionalAccessBladeTitle")
|
||||
|
||||
if($obj.state -eq "enabledForReportingButNotEnforced")
|
||||
{
|
||||
$state = Get-LanguageString "AzureIAM.PolicyState.reportOnly"
|
||||
$state = Get-LanguageString "AzureCA.PolicyState.reportOnly"
|
||||
}
|
||||
elseif($obj.state -eq "disabled")
|
||||
{
|
||||
$state = Get-LanguageString "AzureIAM.PolicyState.off"
|
||||
$state = Get-LanguageString "AzureCA.PolicyState.off"
|
||||
}
|
||||
else
|
||||
{
|
||||
$state = Get-LanguageString "AzureIAM.PolicyState.on"
|
||||
$state = Get-LanguageString "AzureCA.PolicyState.on"
|
||||
}
|
||||
|
||||
Add-BasicPropertyValue (Get-LanguageString "AzureIAM.policyEnforceLabel") $state
|
||||
Add-BasicPropertyValue (Get-LanguageString "AzureCA.policyEnforceLabel") $state
|
||||
|
||||
Add-BasicAdditionalValues $obj $objectType
|
||||
|
||||
$includeLabel = Get-LanguageString "AzureCA.userSelectionBladeIncludeTabTitle"
|
||||
$excludeLabel = Get-LanguageString "AzureCA.userSelectionBladeExcludeTabTitle"
|
||||
|
||||
if($obj.conditions.clientApplications.includeServicePrincipals -or $obj.conditions.clientApplications.excludeServicePrincipals)
|
||||
{
|
||||
###################################################
|
||||
# Workload
|
||||
###################################################
|
||||
|
||||
$ids = @()
|
||||
foreach($id in ($obj.conditions.clientApplications.includeServicePrincipals + $obj.conditions.clientApplications.excludeServicePrincipals))
|
||||
{
|
||||
if($id -in $ids) { continue }
|
||||
elseif($id -eq "ServicePrincipalsInMyTenant") { continue }
|
||||
|
||||
$ids += $id
|
||||
}
|
||||
|
||||
$category = Get-LanguageString "AzureCA.workloadIdentities"
|
||||
|
||||
$idInfo = $null
|
||||
|
||||
if($ids.Count -gt 0)
|
||||
{
|
||||
$ht = @{}
|
||||
$ht.Add("ids", @($ids | Unique))
|
||||
|
||||
$body = $ht | ConvertTo-Json
|
||||
|
||||
# ToDo: Get from MigFile for Offline
|
||||
$idInfo = (Invoke-GraphRequest -Url "/directoryObjects/getByIds?`$select=displayName,id" -Content $body -Method "Post").Value
|
||||
}
|
||||
|
||||
if((($obj.conditions.clientApplications.includeServicePrincipals | Where { $_ -eq "ServicePrincipalsInMyTenant"}) -ne $null))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureCA.servicePrincipalRadioAll"
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
EntityKey = "includeServicePrincipals"
|
||||
})
|
||||
}
|
||||
elseif((($obj.conditions.clientApplications.includeServicePrincipals | Where { $_ -eq "None"}) -ne $null))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureCA.chooseApplicationsNone"
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
EntityKey = "includeServicePrincipals"
|
||||
})
|
||||
}
|
||||
elseif($ids.Count -gt 0 -and $obj.conditions.clientApplications.includeServicePrincipals)
|
||||
{
|
||||
#$category = Get-LanguageString "AzureCA.selectedSP"
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.clientApplications.includeServicePrincipals))
|
||||
{
|
||||
$idObj = $idInfo | Where Id -eq $id
|
||||
$tmpObjs += ?? $idObj.displayName $id
|
||||
}
|
||||
|
||||
if($tmpObjs.count -gt 0)
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $category
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
EntityKey = "includeServicePrincipals"
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
if($obj.conditions.clientApplications.servicePrincipalFilter)
|
||||
{
|
||||
if($obj.conditions.clientApplications.servicePrincipalFilter.mode -eq "include")
|
||||
{
|
||||
$filterMode = "included"
|
||||
}
|
||||
else
|
||||
{
|
||||
$filterMode = "excluded"
|
||||
}
|
||||
|
||||
#AzureCA.PolicyBlade.Conditions.DeviceAttributes.AssignmentFilter.Blade
|
||||
#AzureCA.PolicyBlade.Conditions.DeviceAttributes.Blade.title
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureCA.PolicyBlade.Conditions.DeviceAttributes.Blade.AppliesTo.$filterMode"
|
||||
Value = $obj.conditions.clientApplications.servicePrincipalFilter.rule
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureCA.PolicyBlade.Conditions.DeviceAttributes.Blade.title"
|
||||
EntityKey = "excludeServicePrincipalDevices"
|
||||
})
|
||||
}
|
||||
|
||||
if((($obj.conditions.clientApplications.excludeServicePrincipals | Where { $_ -eq "ServicePrincipalsInMyTenant"}) -ne $null))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureCA.servicePrincipalRadioAll"
|
||||
Category = $category
|
||||
SubCategory = $excludeLabel
|
||||
EntityKey = "excludeServicePrincipals"
|
||||
})
|
||||
}
|
||||
elseif($ids.Count -gt 0)
|
||||
{
|
||||
#$category = Get-LanguageString "AzureCA.selectedSP"
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.clientApplications.excludeServicePrincipals))
|
||||
{
|
||||
$idObj = $idInfo | Where Id -eq $id
|
||||
$tmpObjs += ?? $idObj.displayName $id
|
||||
}
|
||||
|
||||
if($tmpObjs.count -gt 0)
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $category
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = $excludeLabel
|
||||
EntityKey = "excludeServicePrincipals"
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
###################################################
|
||||
# User and groups
|
||||
###################################################
|
||||
@@ -2281,16 +2412,13 @@ function Invoke-CDDocumentConditionalAccess
|
||||
$script:allAadRoles =(Invoke-GraphRequest -url "/directoryRoleTemplates?`$select=Id,displayName" -ODataMetadata "minimal").value
|
||||
}
|
||||
|
||||
$includeLabel = Get-LanguageString "AzureIAM.userSelectionBladeIncludeTabTitle"
|
||||
$excludeLabel = Get-LanguageString "AzureIAM.userSelectionBladeExcludeTabTitle"
|
||||
|
||||
$category = Get-LanguageString "AzureIAM.usersGroupsLabel"
|
||||
$category = Get-LanguageString "AzureCA.usersGroupsLabel"
|
||||
|
||||
if((($obj.conditions.users.includeUsers | Where { $_ -eq "All"}) -ne $null))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureIAM.allUsersString"
|
||||
Value = Get-LanguageString "AzureCA.allUsersString"
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
EntityKey = "includeUsers"
|
||||
@@ -2300,7 +2428,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureIAM.chooseApplicationsNone"
|
||||
Value = Get-LanguageString "AzureCA.chooseApplicationsNone"
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
EntityKey = "includeUsers"
|
||||
@@ -2310,7 +2438,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureIAM.userSelectionBladeSelectedUsers"
|
||||
Value = Get-LanguageString "AzureCA.userSelectionBladeSelectedUsers"
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
EntityKey = "includeUsers"
|
||||
@@ -2319,7 +2447,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if((($obj.conditions.users.includeUsers | Where { $_ -eq "GuestsOrExternalUsers"}) -ne $null))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.allGuestUserLabel"
|
||||
Name = Get-LanguageString "AzureCA.allGuestUserLabel"
|
||||
Value = Get-LanguageString "Inputs.enabled" #$((?: (($obj.conditions.users.includeUsers | Where { $_ -eq "GuestsOrExternalUsers"}) -ne $null) "enabled" "disabled"))"
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
@@ -2337,7 +2465,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.directoryRolesLabel"
|
||||
Name = Get-LanguageString "AzureCA.directoryRolesLabel"
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = $includeLabel
|
||||
@@ -2367,7 +2495,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if((($obj.conditions.users.excludeUsers | Where { $_ -eq "GuestsOrExternalUsers"}) -ne $null))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.allGuestUserLabel"
|
||||
Name = Get-LanguageString "AzureCA.allGuestUserLabel"
|
||||
Value = Get-LanguageString "Inputs.enabled" #$((?: (($obj.conditions.users.excludeUsers | Where { $_ -eq "GuestsOrExternalUsers"}) -ne $null) "enabled" "disabled"))"
|
||||
Category = $category
|
||||
SubCategory = $excludeLabel
|
||||
@@ -2385,7 +2513,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.directoryRolesLabel"
|
||||
Name = Get-LanguageString "AzureCA.directoryRolesLabel"
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = $excludeLabel
|
||||
@@ -2411,13 +2539,14 @@ function Invoke-CDDocumentConditionalAccess
|
||||
EntityKey = "excludeUsersGroups"
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
###################################################
|
||||
# Cloud apps or actions
|
||||
###################################################
|
||||
|
||||
$category = Get-LanguageString "AzureIAM.UserActions.appsOrActionsTitle"
|
||||
$cloudAppsLabel = Get-LanguageString "AzureIAM.policyCloudAppsLabel"
|
||||
$category = Get-LanguageString "AzureCA.UserActions.appsOrActionsTitle"
|
||||
$cloudAppsLabel = Get-LanguageString "AzureCA.policyCloudAppsLabel"
|
||||
|
||||
$cloudApps = Get-CDAllCloudApps
|
||||
|
||||
@@ -2425,7 +2554,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureIAM.cloudappsSelectionBladeAllCloudapps" #Get-LanguageString "Inputs.enabled"
|
||||
Value = Get-LanguageString "AzureCA.cloudappsSelectionBladeAllCloudapps" #Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = $cloudAppsLabel
|
||||
EntityKey = "includeApplications"
|
||||
@@ -2435,7 +2564,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureIAM.chooseApplicationsNone" #Get-LanguageString "Inputs.enabled"
|
||||
Value = Get-LanguageString "AzureCA.chooseApplicationsNone" #Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = $cloudAppsLabel
|
||||
EntityKey = "includeApplications"
|
||||
@@ -2477,18 +2606,18 @@ function Invoke-CDDocumentConditionalAccess
|
||||
|
||||
if($obj.conditions.applications.includeUserActions.Count -gt 0)
|
||||
{
|
||||
$userActionsLabel = Get-LanguageString "AzureIAM.UserActions.label"
|
||||
$userActionsLabel = Get-LanguageString "AzureCA.UserActions.label"
|
||||
if(($obj.conditions.applications.includeUserActions | Where { $_ -eq "urn:user:registersecurityinfo" }))
|
||||
{
|
||||
$value = Get-LanguageString "AzureIAM.UserActions.registerSecurityInfo"
|
||||
$value = Get-LanguageString "AzureCA.UserActions.registerSecurityInfo"
|
||||
}
|
||||
else
|
||||
{
|
||||
$value = Get-LanguageString "AzureIAM.UserActions.registerOrJoinDevices"
|
||||
$value = Get-LanguageString "AzureCA.UserActions.registerOrJoinDevices"
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.UserActions.selectionInfo"
|
||||
Name = Get-LanguageString "AzureCA.UserActions.selectionInfo"
|
||||
Value = $value
|
||||
Category = $category
|
||||
SubCategory = $userActionsLabel
|
||||
@@ -2511,10 +2640,10 @@ function Invoke-CDDocumentConditionalAccess
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.AuthContext.checkBoxInfo"
|
||||
Name = Get-LanguageString "AzureCA.AuthContext.checkBoxInfo"
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.AuthContext.label"
|
||||
SubCategory = Get-LanguageString "AzureCA.AuthContext.label"
|
||||
EntityKey = "includeAuthenticationContextClassReferences"
|
||||
})
|
||||
}
|
||||
@@ -2523,23 +2652,23 @@ function Invoke-CDDocumentConditionalAccess
|
||||
# Conditions
|
||||
###################################################
|
||||
|
||||
$category = Get-LanguageString "AzureIAM.helpConditionsTitle"
|
||||
$category = Get-LanguageString "AzureCA.helpConditionsTitle"
|
||||
|
||||
#$category = Get-LanguageString "AzureIAM.policyConditionUserRisk"
|
||||
#$category = Get-LanguageString "AzureCA.policyConditionUserRisk"
|
||||
|
||||
if($obj.conditions.userRiskLevels.Count -gt 0)
|
||||
{
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.userRiskLevels))
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.$($id)Risk"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.$($id)Risk"
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.policyConditionUserRisk"
|
||||
SubCategory = Get-LanguageString "AzureCA.policyConditionUserRisk"
|
||||
EntityKey = "userRiskLevels"
|
||||
})
|
||||
}
|
||||
@@ -2549,14 +2678,14 @@ function Invoke-CDDocumentConditionalAccess
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.signInRiskLevels))
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.$($id)Risk"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.$($id)Risk"
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.policyConditionSigninRisk"
|
||||
SubCategory = Get-LanguageString "AzureCA.policyConditionSigninRisk"
|
||||
EntityKey = "signInRiskLevels"
|
||||
})
|
||||
}
|
||||
@@ -2568,11 +2697,11 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
if($id -eq "all")
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.allDevicePlatforms"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.allDevicePlatforms"
|
||||
}
|
||||
else
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.$($id)DisplayName"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.$($id)DisplayName"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2580,7 +2709,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
Name = $includeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.devicePlatform"
|
||||
SubCategory = Get-LanguageString "AzureCA.devicePlatform"
|
||||
EntityKey = "includePlatforms"
|
||||
})
|
||||
}
|
||||
@@ -2590,14 +2719,14 @@ function Invoke-CDDocumentConditionalAccess
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.platforms.excludePlatforms))
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.$($id)DisplayName"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.$($id)DisplayName"
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $excludeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.devicePlatform"
|
||||
SubCategory = Get-LanguageString "AzureCA.devicePlatform"
|
||||
EntityKey = "excludePlatforms"
|
||||
})
|
||||
}
|
||||
@@ -2614,7 +2743,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
elseif($script:allNamedLocations -isnot [Object[]]) { $script:allNamedLocations = @($script:allNamedLocations) }
|
||||
|
||||
$script:allNamedLocations += [PSCustomObject]@{
|
||||
displayName = Get-LanguageString "AzureIAM.chooseLocationTrustedIpsItem"
|
||||
displayName = Get-LanguageString "AzureCA.chooseLocationTrustedIpsItem"
|
||||
id = "00000000-0000-0000-0000-000000000000"
|
||||
}
|
||||
}
|
||||
@@ -2637,11 +2766,11 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
if($id -eq "AllTrusted")
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.allTrustedLocationLabel"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.allTrustedLocationLabel"
|
||||
}
|
||||
elseif($id -eq "All")
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.locationsAllLocationsLabel"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.locationsAllLocationsLabel"
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -2654,7 +2783,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
Name = $includeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.policyConditionLocation"
|
||||
SubCategory = Get-LanguageString "AzureCA.policyConditionLocation"
|
||||
EntityKey = "includeLocations"
|
||||
})
|
||||
}
|
||||
@@ -2666,11 +2795,11 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
if($id -eq "AllTrusted")
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.allTrustedLocationLabel"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.allTrustedLocationLabel"
|
||||
}
|
||||
elseif($id -eq "All")
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.locationsAllLocationsLabel"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.locationsAllLocationsLabel"
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -2683,7 +2812,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
Name = $excludeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.policyConditionLocation"
|
||||
SubCategory = Get-LanguageString "AzureCA.policyConditionLocation"
|
||||
EntityKey = "excludeLocations"
|
||||
})
|
||||
}
|
||||
@@ -2693,10 +2822,10 @@ function Invoke-CDDocumentConditionalAccess
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.clientAppTypes))
|
||||
{
|
||||
if($id -eq "browser") { $tmpObjs += Get-LanguageString "AzureIAM.clientAppWebBrowser" }
|
||||
elseif($id -eq "mobileAppsAndDesktopClients") { $tmpObjs += Get-LanguageString "AzureIAM.clientAppMobileDesktop" }
|
||||
elseif($id -eq "exchangeActiveSync") { $tmpObjs += Get-LanguageString "AzureIAM.clientAppExchangeActiveSync" }
|
||||
elseif($id -eq "other") { $tmpObjs += Get-LanguageString "AzureIAM.clientTypeOtherClients" }
|
||||
if($id -eq "browser") { $tmpObjs += Get-LanguageString "AzureCA.clientAppWebBrowser" }
|
||||
elseif($id -eq "mobileAppsAndDesktopClients") { $tmpObjs += Get-LanguageString "AzureCA.clientAppMobileDesktop" }
|
||||
elseif($id -eq "exchangeActiveSync") { $tmpObjs += Get-LanguageString "AzureCA.clientAppExchangeActiveSync" }
|
||||
elseif($id -eq "other") { $tmpObjs += Get-LanguageString "AzureCA.clientTypeOtherClients" }
|
||||
elseif($id -eq "all") { break } # Not configured
|
||||
else
|
||||
{
|
||||
@@ -2711,7 +2840,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
Name = $includeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.policyConditioniClientApp"
|
||||
SubCategory = Get-LanguageString "AzureCA.policyConditioniClientApp"
|
||||
EntityKey = "clientAppTypes"
|
||||
})
|
||||
}
|
||||
@@ -2721,9 +2850,9 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $includeLabel
|
||||
Value = Get-LanguageString "AzureIAM.deviceStateAll"
|
||||
Value = Get-LanguageString "AzureCA.deviceStateAll"
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.deviceStateConditionSelectorLabel"
|
||||
SubCategory = Get-LanguageString "AzureCA.deviceStateConditionSelectorLabel"
|
||||
EntityKey = "includeDevices"
|
||||
})
|
||||
}
|
||||
@@ -2733,27 +2862,49 @@ function Invoke-CDDocumentConditionalAccess
|
||||
$tmpObjs = @()
|
||||
foreach($id in ($obj.conditions.devices.excludeDevices))
|
||||
{
|
||||
$tmpObjs += Get-LanguageString "AzureIAM.classicPolicyControlRequire$($id)Device"
|
||||
$tmpObjs += Get-LanguageString "AzureCA.classicPolicyControlRequire$($id)Device"
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = $excludeLabel
|
||||
Value = $tmpObjs -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureIAM.deviceStateConditionSelectorLabel"
|
||||
SubCategory = Get-LanguageString "AzureCA.deviceStateConditionSelectorLabel"
|
||||
EntityKey = "excludeDevices"
|
||||
})
|
||||
}
|
||||
|
||||
if($obj.conditions.devices.deviceFilter)
|
||||
{
|
||||
if($obj.conditions.devices.deviceFilter.mode -eq "include")
|
||||
{
|
||||
$filterMode = "included"
|
||||
}
|
||||
else
|
||||
{
|
||||
$filterMode = "excluded"
|
||||
}
|
||||
|
||||
#AzureCA.PolicyBlade.Conditions.DeviceAttributes.AssignmentFilter.Blade
|
||||
#AzureCA.PolicyBlade.Conditions.DeviceAttributes.Blade.title
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureCA.PolicyBlade.Conditions.DeviceAttributes.Blade.AppliesTo.$filterMode"
|
||||
Value = $obj.conditions.devices.deviceFilter.rule
|
||||
Category = $category
|
||||
SubCategory = Get-LanguageString "AzureCA.PolicyBlade.Conditions.DeviceAttributes.Blade.title"
|
||||
EntityKey = "includeDevices"
|
||||
})
|
||||
}
|
||||
|
||||
###################################################
|
||||
# Grant
|
||||
###################################################
|
||||
|
||||
$category = Get-LanguageString "AzureIAM.policyControlBladeTitle"
|
||||
$category = Get-LanguageString "AzureCA.policyControlBladeTitle"
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlContentDescription"
|
||||
Value = Get-LanguageString "AzureIAM.$((?: (($obj.grantControls.builtInControls | Where { $_ -eq "block"}) -ne $null) "policyControlBlockAccessDisplayedName" "policyControlAllowAccessDisplayedName"))"
|
||||
Name = Get-LanguageString "AzureCA.policyControlContentDescription"
|
||||
Value = Get-LanguageString "AzureCA.$((?: (($obj.grantControls.builtInControls | Where { $_ -eq "block"}) -ne $null) "policyControlBlockAccessDisplayedName" "policyControlAllowAccessDisplayedName"))"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
EntityKey = "policyControl"
|
||||
@@ -2766,7 +2917,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if(($obj.grantControls.builtInControls | Where { $_ -eq "mfa"}))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlMfaChallengeDisplayedName"
|
||||
Name = Get-LanguageString "AzureCA.policyControlMfaChallengeDisplayedName"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2777,7 +2928,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if(($obj.grantControls.builtInControls | Where { $_ -eq "compliantDevice"}))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlCompliantDeviceDisplayedName"
|
||||
Name = Get-LanguageString "AzureCA.policyControlCompliantDeviceDisplayedName"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2788,7 +2939,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if(($obj.grantControls.builtInControls | Where { $_ -eq "domainJoinedDevice"}))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlRequireDomainJoinedDisplayedName"
|
||||
Name = Get-LanguageString "AzureCA.policyControlRequireDomainJoinedDisplayedName"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2799,7 +2950,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if(($obj.grantControls.builtInControls | Where { $_ -eq "approvedApplication"}))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlRequireMamDisplayedName"
|
||||
Name = Get-LanguageString "AzureCA.policyControlRequireMamDisplayedName"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2810,7 +2961,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if(($obj.grantControls.builtInControls | Where { $_ -eq "compliantApplication"}))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlRequireCompliantAppDisplayedName"
|
||||
Name = Get-LanguageString "AzureCA.policyControlRequireCompliantAppDisplayedName"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2821,7 +2972,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if(($obj.grantControls.builtInControls | Where { $_ -eq "passwordChange"}))
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.policyControlRequiredPasswordChangeDisplayedName"
|
||||
Name = Get-LanguageString "AzureCA.policyControlRequiredPasswordChangeDisplayedName"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2840,7 +2991,7 @@ function Invoke-CDDocumentConditionalAccess
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.menuItemTermsOfUse"
|
||||
Name = Get-LanguageString "AzureCA.menuItemTermsOfUse"
|
||||
Value = $termsOfUse -join $script:objectSeparator
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2849,8 +3000,8 @@ function Invoke-CDDocumentConditionalAccess
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.descriptionContentForControlsAndOr"
|
||||
Value = Get-LanguageString "AzureIAM.$((?: ($obj.grantControls.operator -eq "OR") "requireOneControlText" "requireAllControlsText"))"
|
||||
Name = Get-LanguageString "AzureCA.descriptionContentForControlsAndOr"
|
||||
Value = Get-LanguageString "AzureCA.$((?: ($obj.grantControls.operator -eq "OR") "requireOneControlText" "requireAllControlsText"))"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
EntityKey = "grantOperator"
|
||||
@@ -2861,12 +3012,12 @@ function Invoke-CDDocumentConditionalAccess
|
||||
# Session
|
||||
###################################################
|
||||
|
||||
$category = Get-LanguageString "AzureIAM.sessionControlBladeTitle"
|
||||
$category = Get-LanguageString "AzureCA.sessionControlBladeTitle"
|
||||
|
||||
if($obj.sessionControls.applicationEnforcedRestrictions.isEnabled -eq $true)
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.sessionControlsAppEnforcedLabel"
|
||||
Name = Get-LanguageString "AzureCA.sessionControlsAppEnforcedLabel"
|
||||
Value = Get-LanguageString "Inputs.enabled"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2881,8 +3032,8 @@ function Invoke-CDDocumentConditionalAccess
|
||||
elseif($obj.sessionControls.cloudAppSecurity.cloudAppSecurityType -eq "blockDownloads") { $strId = "blockDownloads" }
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.sessionControlsCasLabel"
|
||||
Value = Get-LanguageString "AzureIAM.CAS.BuiltinPolicy.Option.$strId"
|
||||
Name = Get-LanguageString "AzureCA.sessionControlsCasLabel"
|
||||
Value = Get-LanguageString "AzureCA.CAS.BuiltinPolicy.Option.$strId"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
EntityKey = "cloudAppSecurity"
|
||||
@@ -2899,27 +3050,27 @@ function Invoke-CDDocumentConditionalAccess
|
||||
{
|
||||
if($obj.sessionControls.signInFrequency.value -gt 1)
|
||||
{
|
||||
$value = (Get-LanguageString "AzureIAM.SessionLifetime.SignInFrequency.Option.Hour.plural") -f $obj.sessionControls.signInFrequency.value
|
||||
$value = (Get-LanguageString "AzureCA.SessionLifetime.SignInFrequency.Option.Hour.plural") -f $obj.sessionControls.signInFrequency.value
|
||||
}
|
||||
else
|
||||
{
|
||||
$value = Get-LanguageString "AzureIAM.SessionLifetime.SignInFrequency.Option.Hour.singular"
|
||||
$value = Get-LanguageString "AzureCA.SessionLifetime.SignInFrequency.Option.Hour.singular"
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
if($obj.sessionControls.signInFrequency.value -gt 1)
|
||||
{
|
||||
$value = (Get-LanguageString "AzureIAM.SessionLifetime.SignInFrequency.Option.Day.plural") -f $obj.sessionControls.signInFrequency.value
|
||||
$value = (Get-LanguageString "AzureCA.SessionLifetime.SignInFrequency.Option.Day.plural") -f $obj.sessionControls.signInFrequency.value
|
||||
}
|
||||
else
|
||||
{
|
||||
$value = Get-LanguageString "AzureIAM.SessionLifetime.SignInFrequency.Option.Day.singular"
|
||||
$value = Get-LanguageString "AzureCA.SessionLifetime.SignInFrequency.Option.Day.singular"
|
||||
}
|
||||
}
|
||||
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.SessionLifetime.SignInFrequency.Option.label"
|
||||
Name = Get-LanguageString "AzureCA.SessionLifetime.SignInFrequency.Option.label"
|
||||
Value = $value
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
@@ -2930,8 +3081,8 @@ function Invoke-CDDocumentConditionalAccess
|
||||
if($obj.sessionControls.persistentBrowser.isEnabled -eq $true)
|
||||
{
|
||||
Add-CustomSettingObject ([PSCustomObject]@{
|
||||
Name = Get-LanguageString "AzureIAM.SessionLifetime.PersistentBrowser.Option.label"
|
||||
Value = Get-LanguageString "AzureIAM.SessionLifetime.PersistentBrowser.Option.$($obj.sessionControls.persistentBrowser.mode)"
|
||||
Name = Get-LanguageString "AzureCA.SessionLifetime.PersistentBrowser.Option.label"
|
||||
Value = Get-LanguageString "AzureCA.SessionLifetime.PersistentBrowser.Option.$($obj.sessionControls.persistentBrowser.mode)"
|
||||
Category = $category
|
||||
SubCategory = ""
|
||||
EntityKey = "persistentBrowser"
|
||||
@@ -3899,7 +4050,7 @@ function Invoke-CDDocumentDeviceEnrollmentPlatformRestrictionConfiguration
|
||||
|
||||
if($obj.'@OData.Type' -eq '#microsoft.graph.deviceEnrollmentPlatformRestrictionsConfiguration')
|
||||
{
|
||||
$platform = Get-LanguageString "AzureIAM.classicPolicyAllPlatforms"
|
||||
$platform = Get-LanguageString "AzureCA.classicPolicyAllPlatforms"
|
||||
$properties = @("androidForWorkRestriction","androidRestriction","iosRestriction","macRestriction","windowsRestriction")
|
||||
$policyType = "all"
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'1.0.0'
|
||||
'1.0.1'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -374,7 +374,7 @@ function Invoke-HTMLProcessItem
|
||||
$isFilterAssignment = $false
|
||||
foreach($assignment in $documentedObj.Assignments)
|
||||
{
|
||||
if(($assignment.target.PSObject.Properties | Where Name -eq "deviceAndAppManagementAssignmentFilterType"))
|
||||
if(($assignment.PSObject.Properties | Where Name -eq "FilterMode"))
|
||||
{
|
||||
$isFilterAssignment = $true
|
||||
break
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'1.1.0'
|
||||
'1.1.1'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -331,7 +331,7 @@ function Invoke-MDProcessItem
|
||||
$isFilterAssignment = $false
|
||||
foreach($assignment in $documentedObj.Assignments)
|
||||
{
|
||||
if(($assignment.target.PSObject.Properties | Where Name -eq "deviceAndAppManagementAssignmentFilterType"))
|
||||
if(($assignment.PSObject.Properties | Where Name -eq "FilterMode"))
|
||||
{
|
||||
$isFilterAssignment = $true
|
||||
break
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
#https://docs.microsoft.com/en-us/office/vba/api/overview/word
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'1.5.0'
|
||||
'1.6.0'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -600,7 +600,7 @@ function Invoke-WordProcessItem
|
||||
$isFilterAssignment = $false
|
||||
foreach($assignment in $documentedObj.Assignments)
|
||||
{
|
||||
if(($assignment.target.PSObject.Properties | Where Name -eq "deviceAndAppManagementAssignmentFilterType"))
|
||||
if(($assignment.PSObject.Properties | Where Name -eq "FilterMode"))
|
||||
{
|
||||
$isFilterAssignment = $true
|
||||
break
|
||||
@@ -752,7 +752,7 @@ function Add-DocTableItems
|
||||
|
||||
$range = $script:doc.application.selection.range
|
||||
|
||||
$script:docTable = $script:doc.Tables.Add($range, ($items.Count + 1), $properties.Count, [Microsoft.Office.Interop.Word.WdDefaultTableBehavior]::wdWord9TableBehavior, [Microsoft.Office.Interop.Word.WdAutoFitBehavior]::wdAutoFitWindow)
|
||||
$script:docTable = $script:doc.Tables.Add($range, (($items | measure).Count + 1), $properties.Count, [Microsoft.Office.Interop.Word.WdDefaultTableBehavior]::wdWord9TableBehavior, [Microsoft.Office.Interop.Word.WdAutoFitBehavior]::wdAutoFitWindow)
|
||||
$script:docTable.ApplyStyleHeadingRows = $true
|
||||
Set-DocObjectStyle $script:docTable $global:txtWordTableStyle.Text | Out-null
|
||||
|
||||
|
||||
+406
-21
@@ -10,7 +10,7 @@ This module is for the Endpoint Manager/Intune View. It manages Export/Import/Co
|
||||
#>
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'3.9.0'
|
||||
'3.9.3'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -73,6 +73,21 @@ function Invoke-InitializeModule
|
||||
SubPath = "EndpointManager"
|
||||
}) "EndpointManager"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Save Encryption File"
|
||||
Key = "EMSaveEncryptionFile"
|
||||
Type = "Boolean"
|
||||
Description = "Save encryption file when uploading an app. This can then be used to when downloading the app file."
|
||||
SubPath = "EndpointManager"
|
||||
}) "EndpointManager"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "App download folder"
|
||||
Key = "EMIntuneAppDownloadFolder"
|
||||
Type = "Folder"
|
||||
Description = "Folder where app packages will be downloaded and where encryption files will be saved"
|
||||
SubPath = "EndpointManager"
|
||||
}) "EndpointManager"
|
||||
|
||||
$viewPanel = Get-XamlObject ($global:AppRootFolder + "\Xaml\EndpointManagerPanel.xaml") -AddVariables
|
||||
|
||||
@@ -314,7 +329,7 @@ function Invoke-InitializeModule
|
||||
PostFileImportCommand = { Start-PostFileImportAdministrativeTemplate @args }
|
||||
PreImportCommand = { Start-PreImportAdministrativeTemplate @args }
|
||||
LoadObject = { Start-LoadAdministrativeTemplate @args }
|
||||
PropertiesToRemove = @("definitionValues")
|
||||
PropertiesToRemove = @("definitionValues","policyConfigurationIngestionType")
|
||||
Permissons=@("DeviceManagementConfiguration.ReadWrite.All")
|
||||
Icon="DeviceConfiguration"
|
||||
GroupId = "DeviceConfiguration"
|
||||
@@ -454,7 +469,10 @@ function Invoke-InitializeModule
|
||||
PreDeleteCommand = { Start-PreDeleteApplications @args }
|
||||
PostExportCommand = { Start-PostExportApplications @args }
|
||||
PostListCommand = { Start-PostListApplications @args }
|
||||
ExportExtension = { Add-ScriptExportExtensions @args }
|
||||
ExportExtension = { Add-ScriptExportApplications @args }
|
||||
PostGetCommand = { Start-PostGetApplications @args }
|
||||
PostImportCommand = { Start-PostImportApplications @args }
|
||||
PostFilesImportCommand = { Start-PostFilesImportApplications @args }
|
||||
GroupId = "Apps"
|
||||
ScopeTagsReturnedInList = $false
|
||||
})
|
||||
@@ -685,6 +703,7 @@ function Invoke-InitializeModule
|
||||
ExpandAssignmentsList = $false
|
||||
PreFilesImportCommand = { Start-PreFilesImportADMXFiles @args }
|
||||
PreImportCommand = { Start-PreImportADMXFiles @args }
|
||||
PostImportCommand = { Start-PostImportADMXFiles @args }
|
||||
PreDeleteCommand = { Start-PreDeleteADMXFiles @args }
|
||||
ViewProperties = @("fileName","status","Id")
|
||||
PropertiesToRemove = @("languageCodes","targetPrefix","targetNamespace","policyType","revision","status","uploadDateTime")
|
||||
@@ -767,6 +786,16 @@ function Invoke-InitializeModule
|
||||
Icon = "Devices"
|
||||
GroupId = "DeviceConfiguration"
|
||||
})
|
||||
|
||||
Add-ViewItem (New-Object PSObject -Property @{
|
||||
Title = "Driver Update Profiles"
|
||||
Id = "DriverUpdateProfiles"
|
||||
ViewID = "IntuneGraphAPI"
|
||||
API = "/deviceManagement/windowsDriverUpdateProfiles"
|
||||
Permissons = @("DeviceManagementConfiguration.ReadWrite.All")
|
||||
Icon = "UpdatePolicies"
|
||||
GroupId = "WinDriverUpdatePolicies"
|
||||
})
|
||||
}
|
||||
|
||||
function Invoke-EMAuthenticateToMSAL
|
||||
@@ -820,6 +849,8 @@ function Invoke-EMSaveSettings
|
||||
function Invoke-GraphAuthenticationUpdated
|
||||
{
|
||||
Set-EMUIStatus
|
||||
|
||||
$script:CustomADMXDefinitions = $null
|
||||
}
|
||||
|
||||
function Set-EMUIStatus
|
||||
@@ -1974,24 +2005,40 @@ function local:Start-ImportApp
|
||||
|
||||
if($appType -eq "microsoft.graph.win32LobApp")
|
||||
{
|
||||
Copy-Win32LOBPackage $packageFile $obj
|
||||
$fileEncryptionInfo = Copy-Win32LOBPackage $packageFile $obj
|
||||
}
|
||||
elseif($appType -eq "microsoft.graph.windowsMobileMSI")
|
||||
{
|
||||
Copy-MSILOB $packageFile $obj
|
||||
$fileEncryptionInfo = Copy-MSILOB $packageFile $obj
|
||||
}
|
||||
elseif($appType -eq "microsoft.graph.iosLOBApp")
|
||||
{
|
||||
Copy-iOSLOB $packageFile $obj
|
||||
$fileEncryptionInfo = Copy-iOSLOB $packageFile $obj
|
||||
}
|
||||
elseif($appType -eq "microsoft.graph.androidLOBApp")
|
||||
{
|
||||
Copy-AndroidLOB $packageFile $obj
|
||||
$fileEncryptionInfo = Copy-AndroidLOB $packageFile $obj
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Unsupported application type $appType. File will not be uploaded" 2
|
||||
}
|
||||
|
||||
if((Get-SettingValue "EMSaveEncryptionFile") -eq $true)
|
||||
{
|
||||
if($fileEncryptionInfo)
|
||||
{
|
||||
$jsonEncryptionInfo = $fileEncryptionInfo | ConvertTo-Json -Depth 10
|
||||
|
||||
$pkgPath = Get-SettingValue "EMIntuneAppDownloadFolder" (Get-SettingValue "EMIntuneAppPackages")
|
||||
if($pkgPath -and [IO.Directory]::Exists($pkgPath))
|
||||
{
|
||||
$obj = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$($obj.id)" -ODataMetadata "Minimal"
|
||||
$fullPath = $pkgPath + "\$($obj.displayName)_$($obj.id)_$($obj.committedContentVersion).json"
|
||||
$jsonEncryptionInfo | Out-File -FilePath $fullPath -Force -Encoding utf8
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function Start-PreUpdateApplication
|
||||
@@ -2081,6 +2128,98 @@ function Add-DetailExtensionApplications
|
||||
$tmp.Children.Insert($index, $btnUpload)
|
||||
}
|
||||
|
||||
$btnDownload = New-Object System.Windows.Controls.Button
|
||||
$btnDownload.Content = 'Download'
|
||||
$btnDownload.Name = 'btnDownloadAppfile'
|
||||
$btnDownload.Margin = "0,0,5,0"
|
||||
$btnDownload.Width = "100"
|
||||
|
||||
$btnDownload.Add_Click({
|
||||
Write-Status "Download file"
|
||||
$obj = $global:dgObjects.SelectedItem.Object
|
||||
#$obj = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$($obj.id)"
|
||||
|
||||
$pkgPath = Get-SettingValue "EMIntuneAppDownloadFolder" (Get-SettingValue "EMIntuneAppPackages")
|
||||
|
||||
$dlgSave = [System.Windows.Forms.SaveFileDialog]::new()
|
||||
$dlgSave.InitialDirectory = $pkgPath
|
||||
$dlgSave.FileName = ($obj.FileName + ".encrypted")
|
||||
if($dlgSave.ShowDialog() -eq [System.Windows.Forms.DialogResult]::OK -and $dlgSave.Filename)
|
||||
{
|
||||
$contentFileObj = Start-DownloadAppContent $obj $dlgSave.FileName
|
||||
|
||||
if([IO.File]::Exists($dlgSave.FileName))
|
||||
{
|
||||
$fullPath = Find-AppEncryptionFile $obj $contentFileObj $pkgPath
|
||||
if([IO.File]::Exists($fullPath) -eq $false)
|
||||
{
|
||||
if(([System.Windows.MessageBox]::Show("Could not find decryption file for $($obj.displayName)`nApp Id: $($obj.id)`nContent version $($obj.committedContentVersion)`n`nDo you want to browse for the file?", "Encryption file not found", "YesNo", "Warning")) -eq "Yes")
|
||||
{
|
||||
$of = [System.Windows.Forms.OpenFileDialog]::new()
|
||||
$of.InitialDirectory = $pkgPath
|
||||
$of.DefaultExt = "*.json"
|
||||
$of.Filter = "Json (*.json)|*.*"
|
||||
$of.Multiselect = $false
|
||||
|
||||
if($of.ShowDialog() -eq "OK")
|
||||
{
|
||||
$fullPath = $of.FileName
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if([IO.File]::Exists($fullPath))
|
||||
{
|
||||
Write-Status "Decrypting file"
|
||||
$encryptionInfo = ConvertFrom-Json (Get-Content -Path $fullPath -Raw)
|
||||
if($encryptionInfo.fileEncryptionInfo)
|
||||
{
|
||||
$encryptionInfo = $encryptionInfo.fileEncryptionInfo
|
||||
}
|
||||
$destination = $pkgPath + "\$($obj.FileName)"
|
||||
Start-DecryptFile $dlgSave.Filename $destination $encryptionInfo.encryptionKey $encryptionInfo.initializationVector
|
||||
try { [IO.File]::Delete($dlgSave.Filename) }
|
||||
catch {
|
||||
Write-LogError "Failed to delete exported encrypted file" $_.Exception
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Decryption file for $($obj.displayName) not found. Skipping decryption" 2
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Write-Status ""
|
||||
})
|
||||
|
||||
$tmp = $form.FindName($buttonPanel)
|
||||
if($tmp)
|
||||
{
|
||||
$tmp.Children.Insert($index, $btnDownload)
|
||||
}
|
||||
}
|
||||
|
||||
function Find-AppEncryptionFile
|
||||
{
|
||||
param($obj, $contentFileObj, $rootFolders)
|
||||
|
||||
$search = @()
|
||||
$search += "$($obj.displayName)_$($obj.id)_$($obj.committedContentVersion)"
|
||||
$search += "$([IO.Path]::GetFileNameWithoutExtension($obj.fileName))_$($contentFileObj.size)"
|
||||
$search += "$($obj.displayName)_$($contentFileObj.size)"
|
||||
|
||||
foreach($rootFolder in $rootFolders)
|
||||
{
|
||||
foreach($searchName in $search)
|
||||
{
|
||||
$fullName = ($rootFolder + "\$($searchName).json")
|
||||
if([IO.File]::Exists($fullName))
|
||||
{
|
||||
return $fullName
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function Start-PreImportAssignmentsApplications
|
||||
@@ -2166,6 +2305,47 @@ function Start-PostExportApplications
|
||||
Write-LogError "Failed to export scripts" $_.Exception
|
||||
}
|
||||
}
|
||||
|
||||
Save-Setting "Intune" "ExportAppFile" $global:chkExportApplicationFile.IsChecked
|
||||
if($global:chkExportApplicationFile.IsChecked)
|
||||
{
|
||||
$encryptionSource = Get-SettingValue "EMIntuneAppDownloadFolder" (Get-SettingValue "EMIntuneAppPackages")
|
||||
$pkgPath = $path
|
||||
|
||||
if($pkgPath)
|
||||
{
|
||||
Write-Status "Download file"
|
||||
|
||||
$exportFile = $pkgPath + "\$($obj.FileName).encrypted"
|
||||
$contentFileObj = Start-DownloadAppContent $obj $exportFile -GetContentFileInfoOnly
|
||||
$encryptionFile = Find-AppEncryptionFile $obj $contentFileObj $encryptionSource
|
||||
if($encryptionFile -and [IO.File]::Exists($encryptionFile))
|
||||
{
|
||||
Start-DownloadFile $contentFileObj.azureStorageUri $exportFile
|
||||
|
||||
if([IO.File]::Exists($exportFile))
|
||||
{
|
||||
Write-Status "Decrypting file"
|
||||
$encryptionInfo = ConvertFrom-Json (Get-Content -Path $encryptionFile -Raw)
|
||||
if($encryptionInfo.fileEncryptionInfo)
|
||||
{
|
||||
$encryptionInfo = $encryptionInfo.fileEncryptionInfo
|
||||
}
|
||||
$destination = $pkgPath + "\$($obj.FileName)"
|
||||
Start-DecryptFile $exportFile $destination $encryptionInfo.encryptionKey $encryptionInfo.initializationVector
|
||||
}
|
||||
|
||||
try { [IO.File]::Delete($exportFile) }
|
||||
catch {
|
||||
Write-LogError "Failed to delete exported encrypted file" $_.Exception
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Cound not file encryption file"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function Start-PostListApplications
|
||||
@@ -2193,6 +2373,177 @@ function Start-PostListApplications
|
||||
$objList
|
||||
}
|
||||
|
||||
function Add-ScriptExportApplications
|
||||
{
|
||||
param($form, $buttonPanel, $index = 0)
|
||||
|
||||
Add-ScriptExportExtensions $form $buttonPanel $index
|
||||
|
||||
$ctrl = $form.FindName("chkExportApplicationFile")
|
||||
if(-not $ctrl)
|
||||
{
|
||||
$xaml = @"
|
||||
<StackPanel $($global:wpfNS) Orientation="Horizontal" Margin="0,0,5,0">
|
||||
<Label Content="Export application file" />
|
||||
<Rectangle Style="{DynamicResource InfoIcon}" ToolTip="Export the application file. Note: Application file will only be exported if ecryption file is found." />
|
||||
</StackPanel>
|
||||
"@
|
||||
$label = [Windows.Markup.XamlReader]::Parse($xaml)
|
||||
|
||||
$global:chkExportApplicationFile = [System.Windows.Controls.CheckBox]::new()
|
||||
$global:chkExportApplicationFile.IsChecked = ((Get-Setting "Intune" "ExportAppFile" "false") -eq "true")
|
||||
$global:chkExportApplicationFile.VerticalAlignment = "Center"
|
||||
$global:chkExportApplicationFile.Name = "chkExportApplicationFile"
|
||||
|
||||
@($label, $global:chkExportApplicationFile)
|
||||
}
|
||||
}
|
||||
|
||||
function Start-PostGetApplications {
|
||||
param($obj, $objectType)
|
||||
|
||||
if($obj.Object.dependentAppCount -is [Int] -and ($obj.Object.dependentAppCount -gt 0 -or $obj.Object.supersededAppCount -gt 0)) {
|
||||
$relationships = (Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$($obj.Id)/relationships?`$filter=targetType%20eq%20microsoft.graph.mobileAppRelationshipType%27child%27").value
|
||||
$dependencyApps = @()
|
||||
$supersededApps = @()
|
||||
foreach ($rel in $relationships) {
|
||||
if ($rel."@odata.type" -eq "#microsoft.graph.mobileAppDependency") {
|
||||
$dependencyApps += "$($rel.targetDisplayName)|!|$($rel.targetDisplayVersion)|!|$($rel.targetId)|!|$($rel.dependencyType)"
|
||||
}
|
||||
elseif ($rel."@odata.type" -eq "#microsoft.graph.mobileAppSupersedence") {
|
||||
$supersededApps += "$($rel.targetDisplayName)|!|$($rel.targetDisplayVersion)|!|$($rel.targetId)|!|$($rel.supersedenceType)"
|
||||
}
|
||||
}
|
||||
if ($dependencyApps.Count -gt 0) {
|
||||
$obj.Object | Add-Member -MemberType NoteProperty -Name "#CustomRefDependency" -Value ($dependencyApps -join "|*|")
|
||||
}
|
||||
|
||||
if ($supersededApps.Count -gt 0) {
|
||||
$obj.Object | Add-Member -MemberType NoteProperty -Name "#CustomRefSupersedence" -Value ($supersededApps -join "|*|")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function Start-PostImportApplications
|
||||
{
|
||||
param($obj, $objectType, $file)
|
||||
|
||||
#$tmpObj = Get-GraphObjectFromFile $file
|
||||
}
|
||||
|
||||
function Start-PostFilesImportApplications
|
||||
{
|
||||
param($objType, $importedObjects, $importedFiles)
|
||||
|
||||
$refObjects = $importedFiles | Where { $null -ne $_.Object."#CustomRefDependency" -or $null -ne $_.Object."#CustomRefSupersedence" }
|
||||
|
||||
if(($refObjects | measure).Count -gt 0)
|
||||
{
|
||||
Write-Log "Applicetions with Depnedency or Supersedence detected"
|
||||
foreach($file in $refObjects)
|
||||
{
|
||||
Add-ApplicationReferences $file.ImportedObject $file.Object
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function local:Add-ApplicationReferences
|
||||
{
|
||||
param($obj, $fileObj)
|
||||
|
||||
if($fileObj."#CustomRefDependency" -or $fileObj."#CustomRefSupersedence")
|
||||
{
|
||||
Write-Log "Adding app references for $($obj.displayName)"
|
||||
|
||||
$depAppsInfo = $fileObj."#CustomRefDependency"
|
||||
$supAppsInfo = $fileObj."#CustomRefSupersedence"
|
||||
|
||||
$releationShips = [PSCustomObject]@{
|
||||
relationships = @()
|
||||
}
|
||||
|
||||
if($depAppsInfo)
|
||||
{
|
||||
foreach($depApp in ($depAppsInfo -split "[|][*][|]"))
|
||||
{
|
||||
$appName, $appVer, $appId, $appType = $depApp -split "[|][!][|]"
|
||||
if(-not $appName -or -not $appVer)
|
||||
{
|
||||
Write-Log "Could not get Name and Version from string: $appApp" 2
|
||||
continue
|
||||
}
|
||||
$tmpApps = (Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps?`$filter=displayName eq '$appName'").value
|
||||
if(-not $tmpApps)
|
||||
{
|
||||
Write-Log "No application found with name $appName" 2
|
||||
continue
|
||||
}
|
||||
$tmpApp = $tmpApps | Where displayVersion -eq $appVer
|
||||
if(-not $tmpApp)
|
||||
{
|
||||
Write-Log "No $appName application found with version $appVer" 2
|
||||
continue
|
||||
}
|
||||
elseif(-not ($tmpApp | measure).Count -gt 1)
|
||||
{
|
||||
Write-Log "Multiple $appName application found with version $appVer" 2
|
||||
continue
|
||||
}
|
||||
Write-Log "Add $appName ($appVer) to Dependency list"
|
||||
$releationShips.relationships += [PSCustomObject]@{
|
||||
"@odata.type" = "#microsoft.graph.mobileAppDependency"
|
||||
targetId = $tmpApp.Id
|
||||
dependencyType = $appType
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($supAppsInfo)
|
||||
{
|
||||
foreach($suppApp in ($supAppsInfo -split "[|][*][|]"))
|
||||
{
|
||||
$appName, $appVer, $appId, $appType = $suppApp -split "[|][!][|]"
|
||||
if(-not $appName -or -not $appVer)
|
||||
{
|
||||
Write-Log "Could not get Name and Version from string: $appApp" 2
|
||||
continue
|
||||
}
|
||||
$tmpApps = (Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps?`$filter=displayName eq '$appName'").value
|
||||
if(-not $tmpApps)
|
||||
{
|
||||
Write-Log "No application found with name $appName" 2
|
||||
continue
|
||||
}
|
||||
$tmpApp = $tmpApps | Where displayVersion -eq $appVer
|
||||
if(-not $tmpApp)
|
||||
{
|
||||
Write-Log "No $appName application found with version $appVer" 2
|
||||
continue
|
||||
}
|
||||
elseif(-not ($tmpApp | measure).Count -gt 1)
|
||||
{
|
||||
Write-Log "Multiple $appName application found with version $appVer" 2
|
||||
continue
|
||||
}
|
||||
Write-Log "Add $appName ($appVer) to Supersedence list"
|
||||
$releationShips.relationships += [PSCustomObject]@{
|
||||
"@odata.type" = "#microsoft.graph.mobileAppSupersedence"
|
||||
targetId = $tmpApp.Id
|
||||
supersedenceType = $appType
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($releationShips.relationships.Count -gt 0)
|
||||
{
|
||||
$json = Update-JsonForEnvironment (ConvertTo-Json $releationShips -Depth 20)
|
||||
|
||||
Write-Log "Update app references"
|
||||
Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$($obj.Id)/updateRelationships" -Method "POST" -Body $json
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#endregion
|
||||
|
||||
#region Group Policy/Administrative Templates functions
|
||||
@@ -2202,6 +2553,13 @@ function Get-GPOObjectSettings
|
||||
|
||||
$gpoSettings = @()
|
||||
|
||||
if ($GPOObj.policyConfigurationIngestionType -eq "unknown") {
|
||||
$tmpObj = (Invoke-GraphRequest -Url "/deviceManagement/groupPolicyConfigurations?`$filter=id eq '$($GPOObj.id)'").value[0]
|
||||
if ($tmpObj.policyConfigurationIngestionType) {
|
||||
$GPOObj.policyConfigurationIngestionType = $tmpObj.policyConfigurationIngestionType
|
||||
}
|
||||
}
|
||||
|
||||
# Get all configured policies in the Administrative Templates profile
|
||||
$GPODefinitionValues = Invoke-GraphRequest -Url "/deviceManagement/groupPolicyConfigurations/$($GPOObj.id)/definitionValues?`$expand=definition" -ODataMetadata "skip"
|
||||
foreach($definitionValue in $GPODefinitionValues.value)
|
||||
@@ -2215,7 +2573,7 @@ function Get-GPOObjectSettings
|
||||
"definition@odata.bind" = "$($global:graphURL)/deviceManagement/groupPolicyDefinitions('$($definitionValue.definition.id)')"
|
||||
}
|
||||
|
||||
if($GPOObj.policyConfigurationIngestionType -eq "Custom")
|
||||
if($definitionValue.definition.categoryPath)
|
||||
{
|
||||
$obj.Add("#Definition_Id", $definitionValue.definition.id)
|
||||
$obj.Add("#Definition_displayName", $definitionValue.definition.displayName)
|
||||
@@ -2233,7 +2591,7 @@ function Get-GPOObjectSettings
|
||||
# Add presentation@odata.bind property that links the value to the presentation object
|
||||
$presentationValue | Add-Member -MemberType NoteProperty -Name "presentation@odata.bind" -Value "$($global:graphURL)/deviceManagement/groupPolicyDefinitions('$($definitionValue.definition.id)')/presentations('$($presentationValue.presentation.id)')"
|
||||
|
||||
if($GPOObj.policyConfigurationIngestionType -eq "Custom")
|
||||
if($definitionValue.definition.categoryPath)
|
||||
{
|
||||
$presentationValue | Add-Member -MemberType NoteProperty -Name "#Presentation_Id" -Value $presentationValue.presentation.id
|
||||
$presentationValue | Add-Member -MemberType NoteProperty -Name "#Presentation_Label" -Value $presentationValue.presentation.label
|
||||
@@ -2257,15 +2615,15 @@ function Get-GPOObjectSettings
|
||||
|
||||
function Import-GPOSetting
|
||||
{
|
||||
param($obj, $settings, [switch]$CustomADMX)
|
||||
param($obj, $settings)
|
||||
|
||||
if($obj)
|
||||
{
|
||||
Write-Status "Import settings for $($obj.displayName)"
|
||||
|
||||
$isCustomADMX = $CustomADMX -eq $true
|
||||
$hasCustomADMX = $null -ne ($settings | Where { $null -ne $_.'#Definition_categoryPath' })
|
||||
|
||||
if($isCustomADMX)
|
||||
if($hasCustomADMX)
|
||||
{
|
||||
Write-Status "Import custom ADMX settings"
|
||||
if(-not $script:CustomADMXDefinitions)
|
||||
@@ -2284,8 +2642,13 @@ function Import-GPOSetting
|
||||
Category = $tmpCat
|
||||
Presentations = $null
|
||||
}
|
||||
try {
|
||||
$script:CustomADMXDefinitions.Add($key, $val)
|
||||
}
|
||||
catch {
|
||||
Write-Log "Failed to add '$($tmpDef.displayName)' in category '$($tmpDef.categoryPath)' of class $($tmpDef.classType)" 3
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -2293,7 +2656,7 @@ function Import-GPOSetting
|
||||
|
||||
foreach($setting in $settings)
|
||||
{
|
||||
if($isCustomADMX -and $script:CustomADMXDefinitions -is [HashTable] -and $script:CustomADMXDefinitions.Count -gt 0)
|
||||
if($setting.'#Definition_categoryPath' -and $script:CustomADMXDefinitions -is [HashTable] -and $script:CustomADMXDefinitions.Count -gt 0)
|
||||
{
|
||||
$defVal = $null
|
||||
$key = ($setting.'#Definition_displayName' + $setting.'#Definition_categoryPath' + $setting.'#Definition_classType').ToLower()
|
||||
@@ -2348,7 +2711,7 @@ function Import-GPOSetting
|
||||
Write-Log "Settings might not be available if imported in another environment" 3
|
||||
}
|
||||
}
|
||||
elseif($isCustomADMX)
|
||||
elseif($setting.'#Definition_categoryPath')
|
||||
{
|
||||
Write-Log "Custom AMDX settings cannot be imported without ADMX file imported. Definitions not found" 2
|
||||
continue
|
||||
@@ -2356,7 +2719,7 @@ function Import-GPOSetting
|
||||
|
||||
Start-GraphPreImport $setting
|
||||
|
||||
if($true) #$isCustomADMX)
|
||||
if($true)
|
||||
{
|
||||
foreach($tmpProp in (($setting.PSObject.Properties | Where Name -like "#*").Name))
|
||||
{
|
||||
@@ -2421,7 +2784,7 @@ function Start-PostFileImportAdministrativeTemplate
|
||||
{
|
||||
$tmpObj = Get-GraphObjectFromFile $file
|
||||
|
||||
Import-GPOSetting $obj $settings -CustomADMX:($tmpObj.policyConfigurationIngestionType -eq "Custom")
|
||||
Import-GPOSetting $obj $settings
|
||||
}
|
||||
}
|
||||
|
||||
@@ -3146,6 +3509,8 @@ function Add-EMAssignmentsToExportFile
|
||||
{
|
||||
param($obj, $objectType, $path, $Url = "")
|
||||
|
||||
if($global:chkExportAssignments.IsChecked -ne $true) { return }
|
||||
|
||||
$fileName = (Get-GraphObjectName $obj $objectType)
|
||||
if((Get-SettingValue "AddIDToExportFile") -eq $true -and $obj.Id)
|
||||
{
|
||||
@@ -3253,6 +3618,11 @@ function Add-ConditionalAccessImportExtensions
|
||||
$label = [Windows.Markup.XamlReader]::Parse($xaml)
|
||||
|
||||
$CAStates = @()
|
||||
$CAStates += [PSCustomObject]@{
|
||||
Name = "As Exported - Change On to Report-only"
|
||||
Value = "AsExportedReportOnly"
|
||||
}
|
||||
|
||||
$CAStates += [PSCustomObject]@{
|
||||
Name = "As Exported"
|
||||
Value = "AsExported"
|
||||
@@ -3277,7 +3647,7 @@ function Add-ConditionalAccessImportExtensions
|
||||
$global:cbImportCAState.DisplayMemberPath = "Name"
|
||||
$global:cbImportCAState.SelectedValuePath = "Value"
|
||||
$global:cbImportCAState.ItemsSource = $CAStates
|
||||
$global:cbImportCAState.SelectedValue = "AsExported"
|
||||
$global:cbImportCAState.SelectedValue = "disabled"
|
||||
$global:cbImportCAState.Margin="0,5,0,0"
|
||||
$global:cbImportCAState.HorizontalAlignment="Left"
|
||||
$global:cbImportCAState.Width=250
|
||||
@@ -3290,10 +3660,15 @@ function Start-PreImportConditionalAccess
|
||||
{
|
||||
param($obj, $objectType, $file, $assignments)
|
||||
|
||||
if($global:cbImportCAState.SelectedValue -and $global:cbImportCAState.SelectedValue -ne "AsExported")
|
||||
{
|
||||
if ($global:cbImportCAState.SelectedValue -and $global:cbImportCAState.SelectedValue -ne "AsExported") {
|
||||
if ($global:cbImportCAState.SelectedValue -eq "AsExportedReportOnly" -and $obj.state -eq "enabled") {
|
||||
Write-Log "Change Enabled policy to Report-only"
|
||||
$obj.state = "enabledForReportingButNotEnforced"
|
||||
}
|
||||
else {
|
||||
$obj.state = $global:cbImportCAState.SelectedValue
|
||||
}
|
||||
}
|
||||
|
||||
if($obj.grantControls.authenticationStrength)
|
||||
{
|
||||
@@ -3464,10 +3839,13 @@ function Start-PreImportADMXFiles
|
||||
return
|
||||
}
|
||||
|
||||
$bytes = [IO.File]::ReadAllBytes($admxFile)
|
||||
#$bytes = [IO.File]::ReadAllBytes($admxFile)
|
||||
$bytes = Get-ASCIIBytes ([IO.File]::ReadAllText($admxFile))
|
||||
$obj.content = [Convert]::ToBase64String($bytes)
|
||||
|
||||
$bytes = [IO.File]::ReadAllBytes($admlFile)
|
||||
#$bytes = [IO.File]::ReadAllBytes($admlFile)
|
||||
$bytes = Get-ASCIIBytes ([IO.File]::ReadAllText($admlFile))
|
||||
|
||||
$obj.groupPolicyUploadedLanguageFiles += [PSCustomObject]@{
|
||||
fileName = [io.path]::GetFileName($admlFile)
|
||||
content = [Convert]::ToBase64String($bytes)
|
||||
@@ -3476,6 +3854,13 @@ function Start-PreImportADMXFiles
|
||||
$obj.defaultLanguageCode = ""
|
||||
}
|
||||
|
||||
function Start-PostImportADMXFiles
|
||||
{
|
||||
param($obj, $objectType, $file)
|
||||
|
||||
$script:CustomADMXDefinitions = $null
|
||||
}
|
||||
|
||||
function Start-PreDeleteADMXFiles
|
||||
{
|
||||
param($obj, $objectType)
|
||||
|
||||
@@ -10,7 +10,7 @@ This module manages Application objects in Intune e.g. uploading application fil
|
||||
#>
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'3.9.0'
|
||||
'3.9.3'
|
||||
}
|
||||
|
||||
#########################################################################################
|
||||
@@ -94,14 +94,18 @@ function Copy-MSILOB
|
||||
|
||||
$tmpFile = [IO.Path]::GetTempFileName()
|
||||
|
||||
$msiInfo = Get-MSIFileInformation $msiFile @("ProductName", "ProductCode", "ProductVersion", "ProductLanguage")
|
||||
$msiInfo = Get-MSIFileInformation $msiFile @("ProductName", "ProductCode", "ProductVersion", "ProductLanguage", "UpgradeCode", "ALLUSERS")
|
||||
|
||||
if(-not $msiInfo) { return }
|
||||
|
||||
$fileEncryptionInfo = New-IntuneEncryptedFile $msiFile $tmpFile
|
||||
|
||||
[xml]$manifestXML = '<MobileMsiData MsiExecutionContext="Any" MsiRequiresReboot="false" MsiUpgradeCode="" MsiIsMachineInstall="true" MsiIsUserInstall="false" MsiIncludesServices="false" MsiContainsSystemRegistryKeys="false" MsiContainsSystemFolders="false"></MobileMsiData>'
|
||||
$manifestXML.MobileMsiData.MsiUpgradeCode = $msiInfo["ProductCode"]
|
||||
$manifestXML.MobileMsiData.MsiUpgradeCode = $msiInfo["UpgradeCode"]
|
||||
if($msiInfo["ALLUSERS"] -eq 1)
|
||||
{
|
||||
$manifestXML.MobileMsiData.MsiExecutionContext = "System"
|
||||
}
|
||||
|
||||
$appFileBody = @{
|
||||
"@odata.type" = "#microsoft.graph.mobileAppContentFile"
|
||||
@@ -109,11 +113,14 @@ function Copy-MSILOB
|
||||
size = (Get-Item $msiFile).Length
|
||||
sizeEncrypted = (Get-Item $tmpFile).Length
|
||||
manifest = [Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes($manifestXML.OuterXml))
|
||||
isDependency = $false
|
||||
}
|
||||
|
||||
Add-FileToIntuneApp $appId $appType $tmpFile $appFileBody
|
||||
|
||||
Remove-Item $tmpFile -Force
|
||||
|
||||
$fileEncryptionInfo
|
||||
}
|
||||
|
||||
function Copy-iOSLOB
|
||||
@@ -149,6 +156,8 @@ function Copy-iOSLOB
|
||||
Add-FileToIntuneApp $appId $appType $tmpFile $appFileBody
|
||||
|
||||
Remove-Item $tmpFile -Force
|
||||
|
||||
$fileEncryptionInfo
|
||||
}
|
||||
|
||||
function Copy-AndroidLOB
|
||||
@@ -185,6 +194,8 @@ function Copy-AndroidLOB
|
||||
Add-FileToIntuneApp $appId $appType $tmpFile $appFileBody
|
||||
|
||||
Remove-Item $tmpFile -Force
|
||||
|
||||
$fileEncryptionInfo
|
||||
}
|
||||
|
||||
function Copy-Win32LOBPackage
|
||||
@@ -235,7 +246,7 @@ function Copy-Win32LOBPackage
|
||||
|
||||
$fileBody = @{
|
||||
"@odata.type" = "#microsoft.graph.mobileAppContentFile"
|
||||
name = $DetectionXML.ApplicationInfo.FileName
|
||||
name = "IntunePackage.intunewin"
|
||||
size = [int64]$DetectionXML.ApplicationInfo.UnencryptedContentSize
|
||||
sizeEncrypted = (Get-Item $tmpIntunewinFile).Length
|
||||
manifest = $null
|
||||
@@ -246,45 +257,58 @@ function Copy-Win32LOBPackage
|
||||
|
||||
# Remove extracted inintunewin file
|
||||
Remove-Item $tmpIntunewinPath -Force -Recurse
|
||||
|
||||
$fileEncryptionInfo
|
||||
}
|
||||
|
||||
function Add-FileToIntuneApp
|
||||
{
|
||||
param($appId, $appType, $appFile, $fileBody)
|
||||
|
||||
$contentVersion = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions" -HttpMethod POST -Content "{}"
|
||||
$contentVersion = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions" -HttpMethod POST -Content "{}" -ODataMetadata "Minimal"
|
||||
$contentVersionId = $contentVersion.id
|
||||
$fileObj = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files" -HttpMethod POST -Content (ConvertTo-Json $fileBody -Depth 5)
|
||||
$fileObj = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files" -HttpMethod POST -Content (ConvertTo-Json $fileBody -Depth 5) -ODataMetadata "Minimal"
|
||||
|
||||
if(-not $fileObj)
|
||||
{
|
||||
return
|
||||
}
|
||||
|
||||
Write-Log "File object created. ID: $($fileObj.id)"
|
||||
|
||||
# Wait for Azure storage URI
|
||||
$fileObj = Wait-IntuneFileState "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)" "AzureStorageUriRequest"
|
||||
if(-not $fileObj)
|
||||
{
|
||||
Write-Log "No File Object returned from commit. Upload failed" 3
|
||||
return
|
||||
}
|
||||
|
||||
# Upload file
|
||||
Send-IntuneFileToAzureStorage $fileObj.azureStorageUri $appFile "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)"
|
||||
Send-IntuneFileToAzureStorage $fileObj.azureStorageUri $appFile "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)" | Out-Null
|
||||
|
||||
# Commit the file
|
||||
$reponse = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)/commit" -HttpMethod POST -Content (ConvertTo-Json $fileEncryptionInfo -Depth 5)
|
||||
Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)/commit" -HttpMethod POST -Content (ConvertTo-Json $fileEncryptionInfo -Depth 5) | Out-Null
|
||||
|
||||
Wait-IntuneFileState "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)" "CommitFile"
|
||||
Wait-IntuneFileState "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVersionId/files/$($fileObj.Id)" "CommitFile" | Out-Null
|
||||
|
||||
$fiUpload = [IO.FileInfo]$appFile
|
||||
# Commit the content version
|
||||
$commitAppBody = @{
|
||||
"@odata.type" = "#$appType"
|
||||
committedContentVersion = $contentVersionId
|
||||
fileName = $fiUpload.Name
|
||||
}
|
||||
|
||||
$reponse = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId" -HttpMethod PATCH -Content (ConvertTo-Json $commitAppBody -Depth 5)
|
||||
# if($fileBody.Name) {
|
||||
# $fileUploadName = $fileBody.Name
|
||||
# }
|
||||
# else {
|
||||
$fiUpload = [IO.FileInfo]$appFile
|
||||
$fileUploadName = $fiUpload.Name
|
||||
# }
|
||||
$commitAppBody.Add("fileName",$fileUploadName)
|
||||
|
||||
Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId" -HttpMethod PATCH -Content (ConvertTo-Json $commitAppBody -Depth 5) | Out-Null
|
||||
Write-Log "Upload finished for file $fileUploadName version $contentVersionId"
|
||||
}
|
||||
|
||||
function Wait-IntuneFileState
|
||||
@@ -318,7 +342,7 @@ function Wait-IntuneFileState
|
||||
return
|
||||
}
|
||||
|
||||
Start-Sleep -s 5
|
||||
Start-Sleep -Seconds 1
|
||||
}
|
||||
|
||||
if($succes -eq $false)
|
||||
@@ -423,9 +447,17 @@ function Set-FinalizeAzureStorageUpload
|
||||
}
|
||||
$xml += '</BlockList>'
|
||||
|
||||
$params = @{}
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
$params.Add("UseBasicParsing", $true)
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
Invoke-RestMethod $uri -Method Put -Body $xml
|
||||
Invoke-RestMethod $uri -Method Put -Body $xml @params
|
||||
}
|
||||
catch
|
||||
{
|
||||
@@ -457,12 +489,18 @@ function Write-AzureStorageChunk
|
||||
|
||||
$success = $false
|
||||
$retryCount = 0
|
||||
$params = @{}
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
}
|
||||
|
||||
while($true)
|
||||
{
|
||||
|
||||
try
|
||||
{
|
||||
$response = Invoke-WebRequest $uri -Method Put -Headers $headers -Body $encodedBody -UseBasicParsing
|
||||
$response = Invoke-WebRequest $uri -Method Put -Headers $headers -Body $encodedBody -UseBasicParsing @params
|
||||
if($retryCount -gt 0)
|
||||
{
|
||||
Write-Log "Chunk uploaded successfully"
|
||||
@@ -622,3 +660,113 @@ function New-IntuneEncryptedFile
|
||||
|
||||
$fileEncryptionInfo
|
||||
}
|
||||
|
||||
function Start-DecryptFile
|
||||
{
|
||||
param($sourceFile, $targetFile, $encryptionKey, $initializationVector)
|
||||
|
||||
if([IO.File]::Exists($targetFile))
|
||||
{
|
||||
$fi = [IO.FileInfo]$targetFile
|
||||
$newName = $fi.Name + "_$((Get-Date).ToString("yyyyMMdd_HHmm"))" + $fi.Extension
|
||||
$targetFile = $fi.DirectoryName + "\$newName"
|
||||
Write-Log "Target file exists. Changing target file to $targetFile" 2
|
||||
}
|
||||
|
||||
$bufferBlockSize = 1024 * 4
|
||||
|
||||
try
|
||||
{
|
||||
$aes = [System.Security.Cryptography.Aes]::Create()
|
||||
|
||||
$buffer = New-Object byte[] $bufferBlockSize
|
||||
$bytesRead = 0
|
||||
|
||||
$targetStream = [System.IO.File]::Open($targetFile, [System.IO.FileMode]::Create, [System.IO.FileAccess]::ReadWrite, [System.IO.FileShare]::None)
|
||||
|
||||
try
|
||||
{
|
||||
$sourceStream = [System.IO.File]::Open($sourceFile, [System.IO.FileMode]::Open, [System.IO.FileAccess]::Read, [System.IO.FileShare]::None)
|
||||
|
||||
$decryptor = $aes.CreateDecryptor([Convert]::FromBase64String($encryptionKey), [Convert]::FromBase64String($initializationVector))
|
||||
|
||||
$decryptoStream = New-Object System.Security.Cryptography.CryptoStream -ArgumentList @($targetStream, $decryptor, [System.Security.Cryptography.CryptoStreamMode]::Write)
|
||||
|
||||
$sourceStream.Seek(48L, [System.IO.SeekOrigin]::Begin)
|
||||
|
||||
while (($bytesRead = $sourceStream.Read($buffer, 0, $bufferBlockSize)) -gt 0)
|
||||
{
|
||||
$decryptoStream.Write($buffer, 0, $bytesRead)
|
||||
$decryptoStream.Flush()
|
||||
}
|
||||
$decryptoStream.FlushFinalBlock()
|
||||
}
|
||||
finally
|
||||
{
|
||||
if ($null -ne $decryptoStream) { $decryptoStream.Dispose() }
|
||||
if ($null -ne $targetStream) { $targetStream.Dispose() }
|
||||
if ($null -ne $decryptor) { $decryptor.Dispose() }
|
||||
if ($null -ne $sourceStream) { $sourceStream.Dispose() }
|
||||
}
|
||||
}
|
||||
finally
|
||||
{
|
||||
if ($null -ne $sourceStream) { $sourceStream.Dispose() }
|
||||
if ($null -ne $aes) { $aes.Dispose() }
|
||||
}
|
||||
}
|
||||
|
||||
function Start-DownloadAppContent
|
||||
{
|
||||
param($obj, $destinationFile, [switch]$GetContentFileInfoOnly)
|
||||
# Not use but kept for reference. File can be download but it will be encrypted
|
||||
|
||||
if([IO.File]::Exists($destinationFile))
|
||||
{
|
||||
try { [IO.File]::Delete($encryptionFile) }
|
||||
catch {}
|
||||
}
|
||||
|
||||
$appId = $obj.Id
|
||||
|
||||
$appInfo = Invoke-GraphRequest -Url "$($global:graphURL)/deviceAppManagement/mobileApps/$appId"
|
||||
|
||||
$appType = $appInfo.'@odata.type'.Trim('#')
|
||||
|
||||
#$contentVersions = Invoke-GraphRequest -Url "$($global:graphURL)/deviceAppManagement/mobileApps/$appId/$appType/contentVersions"
|
||||
#$contentVerId = $contentVersions.Value[0].id
|
||||
|
||||
$contentVerId = $appInfo.committedContentVersion
|
||||
|
||||
$contentFiles = Invoke-GraphRequest "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVerId/files"
|
||||
|
||||
$contentFile = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVerId/files/$($contentFiles.value[-1].Id)" -NoError
|
||||
|
||||
if(-not $contentFile)
|
||||
{
|
||||
foreach($file in $contentFiles.value)
|
||||
{
|
||||
if($contentFiles.value[-1].Id -eq $file.id) { continune }
|
||||
|
||||
# NOT happy about this. file objects are not always returned in the order of upload.
|
||||
$contentFile = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVerId/files/$($file.Id)" -NoError
|
||||
if($contentFile)
|
||||
{
|
||||
break
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($contentFile.azureStorageUri)
|
||||
{
|
||||
if($GetContentFileInfoOnly -ne $true)
|
||||
{
|
||||
Start-DownloadFile $contentFile.azureStorageUri $destinationFile
|
||||
}
|
||||
return $contentFile
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Could not find file object for app $($obj.displayName) ($($appId))" 2
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,422 @@
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Module for listing Intune assignment filter usage
|
||||
|
||||
.DESCRIPTION
|
||||
|
||||
.NOTES
|
||||
Author: Mikael Karlsson
|
||||
#>
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'1.1.0'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
{
|
||||
Add-EMToolsViewItem (New-Object PSObject -Property @{
|
||||
Title = "Intune Filter Usage"
|
||||
Id = "IntuneFilterUsage"
|
||||
ViewID = "EMTools"
|
||||
Permissons=@("DeviceManagementConfiguration.ReadWrite.All")
|
||||
Icon="DeviceConfiguration"
|
||||
ShowViewItem = { Show-IntuneToolsFilterUsage }
|
||||
})
|
||||
}
|
||||
|
||||
function Show-IntuneToolsFilterUsage
|
||||
{
|
||||
if(-not $script:frmIntuneFilterUsage)
|
||||
{
|
||||
$script:frmIntuneFilterUsage = Get-XamlObject ($global:AppRootFolder + "\Xaml\IntuneToolsFiterUsage.xaml") #-AddVariables
|
||||
|
||||
if(-not $script:frmIntuneFilterUsage) { return }
|
||||
|
||||
Add-XamlEvent $script:frmIntuneFilterUsage "btnGetIntuneFilterUsage" "add_click" ({
|
||||
Write-Status "Get Intune Filter Usage"
|
||||
Get-EMIntuneFilterUsage
|
||||
Write-Status ""
|
||||
})
|
||||
|
||||
Add-XamlEvent $script:frmIntuneFilterUsage "btnIntuneFilterUsageCopy" "add_click" ({
|
||||
$dgValues = Get-DataGridValues ($script:frmIntuneFilterUsage.FindName("dgIntuneFilterUsage"))
|
||||
$dgValues | ConvertTo-Csv -NoTypeInformation | Set-Clipboard
|
||||
})
|
||||
|
||||
Add-XamlEvent $script:frmIntuneFilterUsage "btnIntuneFilterUsagesSave" "add_click" ({
|
||||
|
||||
$dlgSave = New-Object -Typename System.Windows.Forms.SaveFileDialog
|
||||
$dlgSave.FileName = $obj.FileName
|
||||
$dlgSave.DefaultExt = "*.csv"
|
||||
$dlgSave.Filter = "CSV (*.csv)|*.csv|All files (*.*)| *.*"
|
||||
if($dlgSave.ShowDialog() -eq [System.Windows.Forms.DialogResult]::OK -and $dlgSave.Filename)
|
||||
{
|
||||
$dgValues = Get-DataGridValues ($script:frmIntuneFilterUsage.FindName("dgIntuneFilterUsage"))
|
||||
$dgValues | ConvertTo-Csv -NoTypeInformation | Out-File -LiteralPath $dlgSave.Filename -Encoding UTF8 -Force
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
$global:grdToolsMain.Children.Clear()
|
||||
$global:grdToolsMain.Children.Add($frmIntuneFilterUsage)
|
||||
}
|
||||
|
||||
function Get-DataGridValues_old
|
||||
{
|
||||
param($dataGrid)
|
||||
|
||||
$dgColumns = $dataGrid.Columns
|
||||
#$dgColumns = Get-XamlProperty $script:frmIntuneFilterUsage "dgIntuneFilterUsage" "Columns"
|
||||
|
||||
$properties = @()
|
||||
|
||||
foreach($tmpCol in $dgColumns)
|
||||
{
|
||||
$propName = $tmpCol.Binding.Path.Path
|
||||
$properties += @{n=$tmpCol.Header;e=([Scriptblock]::Create("`$_.$propName"))}
|
||||
}
|
||||
|
||||
($script:objFilterUsage | Select -Property $properties)
|
||||
}
|
||||
|
||||
function Get-EMIntuneFilterUsage
|
||||
{
|
||||
param($rootDir)
|
||||
|
||||
Write-Status "Gather Intune Filter Information"
|
||||
|
||||
Set-XamlProperty $script:frmIntuneFilterUsage "dgIntuneFilterUsage" "ItemsSource" $null
|
||||
|
||||
$objectType = Get-GraphObjectType "AssignmentFilters"
|
||||
|
||||
$loadedGroups = @{}
|
||||
$loadedGroups.Add("adadadad-808e-44e2-905a-0b7873a8a531","All Devices")
|
||||
$loadedGroups.Add("acacacac-9df4-4c7d-9d50-4ef0226f57a9","All Users")
|
||||
|
||||
$script:objFilters = (Invoke-GraphRequest -Url $objectType.API).Value
|
||||
|
||||
$script:objFilterUsage = @()
|
||||
$groupIDs = @()
|
||||
|
||||
foreach($filter in $script:objFilters)
|
||||
{
|
||||
Write-Status "Get payloads for filter $($filter.displayName)"
|
||||
|
||||
$payloadsManual = @()
|
||||
|
||||
$payloads = (Invoke-GraphRequest -Url "$($objectType.API)/$($filter.ID)/payloads").value
|
||||
|
||||
$batchObjs = @()
|
||||
foreach($payload in $payloads)
|
||||
{
|
||||
$guid = (New-Guid).Guid
|
||||
|
||||
$payloadsObj = @{
|
||||
Payload = $payload
|
||||
ID = $guid
|
||||
Requests = @()
|
||||
}
|
||||
|
||||
if($groupIDs -notcontains $payload.groupId)
|
||||
{
|
||||
$groupIDs += $payload.groupId
|
||||
}
|
||||
|
||||
$batchObjs += $payloadsObj
|
||||
|
||||
if($payload.payloadType -eq "win32app")
|
||||
{
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_deviceHealthScripts"
|
||||
method = "GET"
|
||||
url = "/deviceManagement/deviceHealthScripts/$($payload.payloadId)/?`$select=displayName,isGlobalScript"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
}
|
||||
elseif($payload.payloadType -eq "application")
|
||||
{
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_mobileApps"
|
||||
method = "GET"
|
||||
url = "/deviceAppManagement/mobileApps/$($payload.payloadId)/?`$select=displayName"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
}
|
||||
elseif($payload.payloadType -eq "deviceManagmentConfigurationAndCompliancePolicy")
|
||||
{
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_configurationPolicies"
|
||||
method = "GET"
|
||||
url = "/deviceManagement/configurationPolicies/$($payload.payloadId)/?`$select=name,platforms,technologies,templateReference"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
}
|
||||
elseif($payload.payloadType -eq "groupPolicyConfiguration")
|
||||
{
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_groupPolicyConfigurations"
|
||||
method = "GET"
|
||||
url = "/deviceManagement/groupPolicyConfigurations/$($payload.payloadId)/?`$select=displayName"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
}
|
||||
elseif($payload.payloadType -eq "enrollmentConfiguration")
|
||||
{
|
||||
if(-not $script:enrolmentConfigurations)
|
||||
{
|
||||
$script:enrolmentConfigurations = @()
|
||||
$script:enrolmentConfigurations += (Invoke-GraphRequest -Url "/deviceManagement/deviceEnrollmentConfigurations?`$select=displayName,id,deviceEnrollmentConfigurationType").value
|
||||
$script:enrolmentConfigurations += (Invoke-GraphRequest -Url "/deviceManagement/deviceEnrollmentConfigurations?`$select=displayName,id,deviceEnrollmentConfigurationType&`$filter=deviceEnrollmentConfigurationType eq 'EnrollmentNotificationsConfiguration'").value
|
||||
}
|
||||
|
||||
$payloadsManual += $payload
|
||||
|
||||
<#
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_enrollmentConfiguration"
|
||||
method = "GET"
|
||||
url = "/deviceManagement/deviceEnrollmentConfigurations/$($enrolmentConfig.Id)/?`$select=displayName"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
#>
|
||||
}
|
||||
else
|
||||
{
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_deviceCompliancePolicies"
|
||||
method = "GET"
|
||||
url = "/deviceManagement/deviceCompliancePolicies/$($payload.payloadId)/?`$select=displayName"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_deviceConfigurations"
|
||||
method = "GET"
|
||||
url = "/deviceManagement/deviceConfigurations/$($payload.payloadId)/?`$select=displayName"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
|
||||
$payloadsObj.Requests += [ordered]@{
|
||||
id = "$($guid)_mobileAppConfigurations"
|
||||
method = "GET"
|
||||
url = "/deviceAppManagement/mobileAppConfigurations/$($payload.payloadId)/?`$select=displayName"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadNames_BatchItem"}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($batchObjs.Count -gt 0)
|
||||
{
|
||||
$objName = Get-GraphObjectName $filter $objectType
|
||||
$responses = Invoke-GraphBatchRequest $batchObjs.Requests $objName -SkipWarnings
|
||||
|
||||
foreach($response in ($responses | Where Status -lt 300))
|
||||
{
|
||||
$payload = ($batchObjs | Where { $response.id -like "$($_.ID)*"}).Payload
|
||||
|
||||
if($payload.assignmentFilterType -eq "Include")
|
||||
{
|
||||
$filterType = "Include"
|
||||
}
|
||||
else
|
||||
{
|
||||
$filterType = "Exclude"
|
||||
}
|
||||
|
||||
$typeStr = $null
|
||||
if($payload.payloadType -eq "application")
|
||||
{
|
||||
$typeStr = Get-LanguageString "AppType.windowsClassicApp"
|
||||
}
|
||||
elseif($payload.payloadType -eq "win32app")
|
||||
{
|
||||
$typeStr = "Proactive Remediations"
|
||||
}
|
||||
elseif($payload.payloadType -eq "groupPolicyConfiguration")
|
||||
{
|
||||
$typeStr = "Settings Catalog"
|
||||
}
|
||||
elseif($payload.payloadType -eq "deviceManagmentConfigurationAndCompliancePolicy")
|
||||
{
|
||||
$typeStr = "Administrative Templates"
|
||||
}
|
||||
else
|
||||
{
|
||||
$typeStr = (Get-PolicyTypeName $response.body.'@odata.type' $payload.payloadType)
|
||||
}
|
||||
|
||||
if(-not $typeStr) { $typeStr = $payload.payloadType}
|
||||
|
||||
$script:objFilterUsage += [PSCustomObject]@{
|
||||
FiterObject = $filter
|
||||
PayloadObject = $payload
|
||||
FilterName = $filter.displayName
|
||||
PolicyName = ?? $response.body.Name $response.body.displayName
|
||||
Type = $response.body.'@odata.type'
|
||||
PayloadType = $typeStr
|
||||
Mode = $filterType
|
||||
GroupID = $payload.groupId
|
||||
GroupName = $payload.groupId
|
||||
}
|
||||
}
|
||||
|
||||
foreach($response in ($responses | Where Status -ge 300))
|
||||
{
|
||||
$payload = ($batchObjs | Where { $response.id -like "$($_.ID)*"}).Payload
|
||||
Write-Log "Failed to get info for payload with id $($payload.payloadId) of type $($payload.payloadType). Might be deleted or not supported." 2
|
||||
}
|
||||
}
|
||||
|
||||
foreach($payload in $payloadsManual)
|
||||
{
|
||||
$payloadPolicy = $script:enrolmentConfigurations | Where Id -like "$($payload.payloadId)*" | Select -First 1
|
||||
|
||||
if($payloadPolicy)
|
||||
{
|
||||
if($payloadPolicy.deviceEnrollmentConfigurationType -eq "enrollmentNotificationsConfiguration")
|
||||
{
|
||||
$typeStr = "Enrollment notifications"
|
||||
}
|
||||
elseif($payloadPolicy.deviceEnrollmentConfigurationType -eq "windows10EnrollmentCompletionPageConfiguration")
|
||||
{
|
||||
$typeStr = "Enrollment Status Page"
|
||||
}
|
||||
else
|
||||
{
|
||||
$typeStr = (Get-PolicyTypeName $payloadPolicy.body.'@odata.type' $payload.payloadType)
|
||||
}
|
||||
|
||||
if($payload.assignmentFilterType -eq "Include")
|
||||
{
|
||||
$filterType = "Include"
|
||||
}
|
||||
else
|
||||
{
|
||||
$filterType = "Exclude"
|
||||
}
|
||||
|
||||
$script:objFilterUsage += [PSCustomObject]@{
|
||||
FiterObject = $filter
|
||||
PayloadObject = $payload
|
||||
FilterName = $filter.displayName
|
||||
PolicyName = ?? $payloadPolicy.Name $payloadPolicy.displayName
|
||||
Type = $payloadPolicy.'@odata.type'
|
||||
PayloadType = $typeStr
|
||||
Mode = $filterType
|
||||
GroupID = $payload.groupId
|
||||
GroupName = $payload.groupId
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($groupIDs.Count -gt 0)
|
||||
{
|
||||
$guid = (New-Guid).Guid
|
||||
$groupObjs = @()
|
||||
$x = 1
|
||||
foreach($groupID in $groupIDs)
|
||||
{
|
||||
if($loadedGroups.ContainsKey($groupID)) { continue }
|
||||
$groupObjs += [ordered]@{
|
||||
id= "$($guid)_$x"
|
||||
method="GET"
|
||||
url="/groups/$($groupID)/?`$select=displayName,id"
|
||||
headers = @{"x-ms-command-name"="AssignmentFilterPayloadProxy_resolvePayloadGroupAssignments_BatchItem"}
|
||||
}
|
||||
$x++
|
||||
}
|
||||
|
||||
if($groupObjs.Count -gt 0)
|
||||
{
|
||||
$responses = Invoke-GraphBatchRequest $groupObjs "Groups"
|
||||
|
||||
$batchObj = [ordered]@{
|
||||
requests = @($groupObjs)
|
||||
}
|
||||
|
||||
$responses = (Invoke-GraphRequest -Url "`$batch" -Body ($batchObj | ConvertTo-Json -Depth 50 -Compress) -Method "POST").responses
|
||||
|
||||
foreach($response in ($responses | Where Status -eq 200))
|
||||
{
|
||||
if($response.body.displayName -and $response.body.id -and $loadedGroups.ContainsKey($response.body.id) -eq $false)
|
||||
{
|
||||
$loadedGroups.Add($response.body.id, $response.body.displayName)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
foreach($groupID in $loadedGroups.Keys)
|
||||
{
|
||||
$filterObjs = $script:objFilterUsage | WHere GroupID -eq $groupID
|
||||
if($filterObjs -and $loadedGroups[$groupID])
|
||||
{
|
||||
foreach($filterObj in $filterObjs) {
|
||||
$filterObj.GroupName = $loadedGroups[$groupID]
|
||||
}
|
||||
}
|
||||
}
|
||||
$script:enrolmentConfigurations = $null
|
||||
}
|
||||
|
||||
Add-XamlEvent $script:frmIntuneFilterUsage "txtIntuneFilterUsageFilter" "Add_LostFocus" ({
|
||||
Invoke-IntueFilterUsageBoxChanged $this
|
||||
})
|
||||
|
||||
Add-XamlEvent $script:frmIntuneFilterUsage "txtIntuneFilterUsageFilter" "Add_GotFocus" ({
|
||||
if($this.Tag -eq "1" -and $this.Text -eq "Filter") { $this.Text = "" }
|
||||
Invoke-IntueFilterUsageBoxChanged $this ($script:frmIntuneFilterUsage.FindName("dgIntuneFilterUsage"))
|
||||
})
|
||||
|
||||
Add-XamlEvent $script:frmIntuneFilterUsage "txtIntuneFilterUsageFilter" "Add_TextChanged" ({
|
||||
Invoke-IntueFilterUsageBoxChanged $this ($script:frmIntuneFilterUsage.FindName("dgIntuneFilterUsage"))
|
||||
})
|
||||
|
||||
Invoke-IntueFilterUsageBoxChanged ($script:frmIntuneFilterUsage.FindName("txtIntuneFilterUsageFilter")) ($script:frmIntuneFilterUsage.FindName("dgIntuneFilterUsage"))
|
||||
|
||||
$ocList = [System.Collections.ObjectModel.ObservableCollection[object]]::new(@($script:objFilterUsage))
|
||||
|
||||
Set-XamlProperty $script:frmIntuneFilterUsage "dgIntuneFilterUsage" "ItemsSource" ([System.Windows.Data.CollectionViewSource]::GetDefaultView($ocList))
|
||||
}
|
||||
|
||||
function Invoke-IntueFilterUsageBoxChanged
|
||||
{
|
||||
param($txtBox, $dgObject)
|
||||
|
||||
$filter = $null
|
||||
|
||||
if($txtBox.Text.Trim() -eq "" -and $txtBox.IsFocused -eq $false)
|
||||
{
|
||||
$txtBox.FontStyle = "Italic"
|
||||
$txtBox.Tag = 1
|
||||
$txtBox.Text = "Filter"
|
||||
$txtBox.Foreground="Lightgray"
|
||||
}
|
||||
elseif($txtBox.Tag -eq "1" -and $txtBox.Text -eq "Filter" -and $txtBox.IsFocused -eq $false)
|
||||
{
|
||||
|
||||
}
|
||||
else
|
||||
{
|
||||
$txtBox.FontStyle = "Normal"
|
||||
$txtBox.Tag = $null
|
||||
$txtBox.Foreground="Black"
|
||||
$txtBox.Background="White"
|
||||
|
||||
if($txtBox.Text)
|
||||
{
|
||||
$filter = {
|
||||
param ($item)
|
||||
|
||||
return ($item.FilterName -match [regex]::Escape($txtBox.Text) -or $item.PolicyName -match [regex]::Escape($txtBox.Text) -or $item.GroupName -match [regex]::Escape($txtBox.Text) )
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($dgObject.ItemsSource -is [System.Windows.Data.ListCollectionView] -and $txtBox.IsFocused -eq $true)
|
||||
{
|
||||
# This causes odd behaviour with focus e.g. and item has to be clicked twice to be selected
|
||||
$dgObject.ItemsSource.Filter = $filter
|
||||
#$dgObject.ItemsSource.Refresh()
|
||||
}
|
||||
}
|
||||
@@ -22,7 +22,7 @@ $global:EMToolsViewObject = $null
|
||||
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'1.0.3'
|
||||
'1.0.4'
|
||||
}
|
||||
|
||||
function Invoke-InitializeModule
|
||||
@@ -82,7 +82,7 @@ function Add-EMToolsViewItem
|
||||
Activating = { Invoke-EMToolsActivatingView }
|
||||
Authentication = (Get-MSALAuthenticationObject)
|
||||
Authenticate = { Invoke-EMToolsAuthenticateToMSAL }
|
||||
AppInfo = (Get-GraphAppInfo "EM" "d1ddf0e4-d672-4dae-b554-9d5bdfd93547")
|
||||
AppInfo = (Get-GraphAppInfo "EMAzureApp" "d1ddf0e4-d672-4dae-b554-9d5bdfd93547")
|
||||
SaveSettings = { Invoke-EMSaveSettings }
|
||||
Permissions = @()
|
||||
})
|
||||
|
||||
@@ -10,7 +10,7 @@ This module manages Authentication for the application with MSAL. It is also res
|
||||
#>
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'3.8.1'
|
||||
'3.9.3'
|
||||
}
|
||||
|
||||
$global:msalAuthenticator = $null
|
||||
@@ -158,6 +158,10 @@ function Clear-MSALCurentUserVaiables
|
||||
{
|
||||
$global:MSALTenantId = $null
|
||||
$global:MSALGraphEnvironment = $null
|
||||
|
||||
$script:jwtAccessToken = $null
|
||||
$script:jwtIdToken = $null
|
||||
|
||||
}
|
||||
|
||||
function Get-MSALCurrentApp
|
||||
@@ -223,6 +227,9 @@ function Get-MSALUserInfo
|
||||
if($global:MSALToken)
|
||||
{
|
||||
Write-Log "Get current user"
|
||||
|
||||
if($script:jwtAccessToken.Payload.idtyp -ne "app")
|
||||
{
|
||||
$tmpMe = MSGraph\Invoke-GraphRequest -Url "ME" -SkipAuthentication -ODataMetadata "Skip"
|
||||
if($null -ne $tmpMe -and $tmpMe.creationType -ne "Invitation")
|
||||
{
|
||||
@@ -232,6 +239,12 @@ function Get-MSALUserInfo
|
||||
$global:profilePhoto = "$($env:LOCALAPPDATA)\CloudAPIPowerShellManagement\$($global:Me.Id).jpeg"
|
||||
MSGraph\Invoke-GraphRequest "me/photos/48x48/`$value" -OutFile $global:profilePhoto -SkipAuthentication -NoError | Out-Null
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$global:profilePhoto = $null
|
||||
$global:me = $script:jwtAccessToken.Payload.app_displayname
|
||||
}
|
||||
|
||||
Write-Log "Get organization info"
|
||||
$global:Organization = (MSGraph\Invoke-GraphRequest -Url "Organization" -SkipAuthentication -ODataMetadata "Skip").Value
|
||||
@@ -535,12 +548,14 @@ function Add-MSALPrereq
|
||||
Write-Log "Some MSAL features might not work!" 3
|
||||
Write-Log "This could happen if another version of MSAL.DLL was loaded beforethe script tried to load it" 3
|
||||
$RequiredAssemblies.Add($fiLoaded.FullName)
|
||||
$script:msalFile = $fiLoaded.FullName
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Using MSAL file $msalPath. Version: $($fi.VersionInfo.FileVersion)"
|
||||
[void][System.Reflection.Assembly]::LoadFile($msalPath)
|
||||
$RequiredAssemblies.Add($msalPath)
|
||||
$script:msalFile = $msalPath
|
||||
}
|
||||
$RequiredAssemblies.Add('System.Security.dll')
|
||||
|
||||
@@ -598,6 +613,7 @@ function Connect-MSALClientApp
|
||||
{
|
||||
return
|
||||
}
|
||||
Add-MSALProxy $ClientApplicationBuilder
|
||||
$script:MSALApp = $ClientApplicationBuilder.Build()
|
||||
}
|
||||
|
||||
@@ -677,6 +693,43 @@ function Get-MsalAuthenticationToken
|
||||
$authResult
|
||||
}
|
||||
|
||||
function Add-MSALProxy
|
||||
{
|
||||
param($appBuilder)
|
||||
|
||||
$proxy = Get-SettingValue "ProxyURI"
|
||||
if($proxy)
|
||||
{
|
||||
Write-Log "Use proxy $proxy"
|
||||
if(-not ("HttpFactoryWithProxy" -as [type]))
|
||||
{
|
||||
try
|
||||
{
|
||||
Write-Log "Add type HttpFactoryWithProxy"
|
||||
[System.Collections.Generic.List[string]] $RequiredAssemblies = New-Object System.Collections.Generic.List[string]
|
||||
$RequiredAssemblies.Add($script:msalFile)
|
||||
$RequiredAssemblies.Add('System.Net.Http.dll')
|
||||
$RequiredAssemblies.Add('System.Net.Primitives.dll')
|
||||
|
||||
Add-Type -Path ($global:AppRootFolder + "\CS\HttpFactoryWithProxy.cs") -ReferencedAssemblies $RequiredAssemblies
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-LogError "Failed to compile HttpFactoryWithProxy" $_.Exception
|
||||
}
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
$hcf = [HttpFactoryWithProxy]::new($proxy)
|
||||
[void] $appBuilder.WithHttpClientFactory($hcf)
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-LogError "Failed to set proxy for MSAL" $_.Exception
|
||||
}
|
||||
}
|
||||
}
|
||||
function Get-MSALLoginEnvironment
|
||||
{
|
||||
$loginEnv = $script:lstAADEnvironments | Where value -eq (Get-Setting "" "MSALCloudType" "public")
|
||||
@@ -717,6 +770,8 @@ function Get-MSALApp
|
||||
[void] $appBuilder.WithClientName("CloudAPIPowerShellManagement")
|
||||
[void] $appBuilder.WithClientVersion($PSVersionTable.PSVersion)
|
||||
|
||||
Add-MSALProxy $appBuilder
|
||||
|
||||
# Ceck if correct version...
|
||||
#$appBuilder.WithMultiCloudSupport($true)
|
||||
|
||||
@@ -792,6 +847,42 @@ function Connect-MSALUser
|
||||
|
||||
Write-LogDebug "Authenticate"
|
||||
|
||||
if($global:MainAppStarted -eq $false)
|
||||
{
|
||||
$script:AppLogin = (Get-SettingValue "GraphAzureAppLogin") -or ($global:TenantId -and $global:AzureAppId -and ($global:ClientSecret -or $global:ClientCert))
|
||||
}
|
||||
|
||||
if($script:AppLogin)
|
||||
{
|
||||
if($global:MSALToken -and $global:MSALToken.ExpiresOn.LocalDateTime.Ticks -gt ((Get-Date).AddMinutes(-5)).Ticks)
|
||||
{
|
||||
return
|
||||
}
|
||||
|
||||
# Get login info for silent job from settings
|
||||
if(-not $global:AzureAppId) { $global:AzureAppId = Get-SettingValue "GraphAzureAppId" -TenantID $global:TenantId }
|
||||
if(-not $global:ClientSecret -and -not $global:ClientCert) { $global:ClientSecret = Get-SettingValue "GraphAzureAppSecret" -TenantID $global:TenantId }
|
||||
if(-not $global:ClientSecret -and -not $global:ClientCert) { $global:ClientCert = Get-SettingValue "GraphAzureAppCert" -TenantID $global:TenantId }
|
||||
|
||||
if($global:AzureAppId -and $global:ClientSecret -and $global:TenantId)
|
||||
{
|
||||
Connect-MSALClientApp $global:AzureAppId $global:TenantId -secret $global:ClientSecret
|
||||
}
|
||||
elseif($global:AzureAppId -and $global:ClientCert -and $global:TenantId)
|
||||
{
|
||||
Connect-MSALClientApp $global:AzureAppId $global:TenantId -certificate $global:ClientCert
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "Azure AppId, Tenant Id and Sercret/Cert must be specified for App logins" 3
|
||||
}
|
||||
|
||||
Invoke-MSALAuthenticationUpdated $global:MSALToken
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
|
||||
if($ShowMenu -eq $true -and ((Get-SettingValue "AzureADLoginMenu") -eq $true))
|
||||
{
|
||||
if((Show-MSALLoginMenu) -eq $false) { return }
|
||||
@@ -1057,7 +1148,7 @@ function Connect-MSALUser
|
||||
#########################################################################################################
|
||||
try
|
||||
{
|
||||
Write-Log "Get tennant list"
|
||||
Write-Log "Get tenant list"
|
||||
|
||||
# Can we reuse the app used for login?
|
||||
$appBuilder = [Microsoft.Identity.Client.PublicClientApplicationBuilder]::Create($global:appObj.ClientID)
|
||||
@@ -1065,6 +1156,8 @@ function Connect-MSALUser
|
||||
else { [void]$appBuilder.WithAuthority($global:MSALApp.Authority) }
|
||||
if($global:appObj.RedirectUri) { [void]$appBuilder.WithRedirectUri($global:appObj.RedirectUri) }
|
||||
|
||||
Add-MSALProxy $appBuilder
|
||||
|
||||
$app = $appBuilder.Build()
|
||||
|
||||
if((Get-SettingValue "CacheMSALToken"))
|
||||
@@ -1093,7 +1186,15 @@ function Connect-MSALUser
|
||||
'ExpiresOn' = $tmpResults.ExpiresOn
|
||||
}
|
||||
|
||||
$ret = Invoke-RestMethod "https://management.azure.com/tenants?api-version=2020-01-01" -Headers $Headers
|
||||
$params = @{}
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
$params.Add("UseBasicParsing", $true)
|
||||
}
|
||||
|
||||
$ret = Invoke-RestMethod "https://management.azure.com/tenants?api-version=2020-01-01" -Headers $Headers @params
|
||||
if($ret)
|
||||
{
|
||||
$script:AccessableTenants = $ret.Value
|
||||
@@ -1115,7 +1216,8 @@ function Connect-MSALUser
|
||||
Save-Setting "" "LastLoggedOnUser" $authResult.Account.UserName
|
||||
Save-Setting "" "LastLoggedOnUserId" $authResult.Account.HomeAccountId.ObjectId
|
||||
}
|
||||
|
||||
Invoke-MSALAuthenticationUpdated $authResult
|
||||
<#
|
||||
Write-LogDebug "User, tenant or app has changed"
|
||||
Get-MSALUserInfo
|
||||
if($authResult)
|
||||
@@ -1123,9 +1225,26 @@ function Connect-MSALUser
|
||||
Invoke-MSALCheckObjectViewAccess $authResult
|
||||
}
|
||||
Invoke-ModuleFunction "Invoke-GraphAuthenticationUpdated"
|
||||
#>
|
||||
}
|
||||
}
|
||||
|
||||
function local:Invoke-MSALAuthenticationUpdated
|
||||
{
|
||||
param($authResult)
|
||||
|
||||
Write-LogDebug "User, tenant or app has changed"
|
||||
$script:jwtAccessToken = Get-JWTtoken $global:MSALToken.AccessToken
|
||||
$script:jwtIdToken = Get-JWTtoken $global:MSALToken.IdToken
|
||||
|
||||
Get-MSALUserInfo
|
||||
if($authResult)
|
||||
{
|
||||
Invoke-MSALCheckObjectViewAccess $authResult
|
||||
}
|
||||
Invoke-ModuleFunction "Invoke-GraphAuthenticationUpdated"
|
||||
}
|
||||
|
||||
function Start-MSALConsentPrompt
|
||||
{
|
||||
param([switch]$PassThru, $authToken)
|
||||
@@ -1202,6 +1321,22 @@ function Invoke-MSALCheckObjectViewAccess
|
||||
Set-XamlProperty $script:userEllipsGrid "lnkRequestConsent" "Visibility" "Visible"
|
||||
}
|
||||
|
||||
$accessToken = $null
|
||||
if($authToken)
|
||||
{
|
||||
$accessToken = Get-JWTtoken $authToken.AccessToken
|
||||
}
|
||||
|
||||
$curPermissions = $null
|
||||
if($accessToken.Payload.idtyp -eq "app")
|
||||
{
|
||||
$curPermissions = $accessToken.Payload.roles
|
||||
}
|
||||
elseif($accessToken.Payload.scp)
|
||||
{
|
||||
$curPermissions = $accessToken.Payload.scp.Split(" ")
|
||||
}
|
||||
|
||||
foreach($viewObjInfo in ($global:viewObjects | Where { $_.ViewInfo.AuthenticationID -eq "MSAL" }))
|
||||
{
|
||||
$viewObjInfo = $global:viewObjects | Where { $_.ViewInfo.Id -eq $global:EMViewObject.Id }
|
||||
@@ -1210,10 +1345,8 @@ function Invoke-MSALCheckObjectViewAccess
|
||||
{
|
||||
if($authToken)
|
||||
{
|
||||
$accessToken = Get-JWTtoken $authToken.AccessToken
|
||||
if($accessToken.Payload.scp)
|
||||
if($curPermissions)
|
||||
{
|
||||
$curPermissions = $accessToken.Payload.scp.Split(" ")
|
||||
foreach($viewItem in $viewObjInfo.ViewItems)
|
||||
{
|
||||
$full = 0
|
||||
@@ -1511,6 +1644,10 @@ function Get-MSALProfileEllipse
|
||||
{
|
||||
$initials = "$($global:me.userPrincipalName[0])".ToUpper()
|
||||
}
|
||||
elseif($script:jwtAccessToken.Payload.idtyp -eq "app")
|
||||
{
|
||||
$initials = "APP"
|
||||
}
|
||||
|
||||
$grd = Get-MSALUserPhotoEllips -size $size -fontSize $fontSize -Color $Color
|
||||
|
||||
@@ -1534,8 +1671,15 @@ function Get-MSALProfileEllipse
|
||||
$global:grdProfileInfo.Tag = $grd
|
||||
$grd.Tag = $global:grdProfileInfo
|
||||
Set-XamlProperty $global:grdProfileInfo "txtOrganization" "Text" $global:Organization.displayName
|
||||
if($script:jwtAccessToken.Payload.idtyp -eq "app")
|
||||
{
|
||||
Set-XamlProperty $global:grdProfileInfo "txtUsername" "Text" "App Login"
|
||||
}
|
||||
else
|
||||
{
|
||||
Set-XamlProperty $global:grdProfileInfo "txtUsername" "Text" $global:me.displayName
|
||||
Set-XamlProperty $global:grdProfileInfo "txtLogonName" "Text" $global:me.userPrincipalName
|
||||
}
|
||||
|
||||
$global:tokenInfo = Get-JWTtoken $global:MSALToken.AccessToken
|
||||
if($global:tokenInfo)
|
||||
@@ -1560,12 +1704,19 @@ function Get-MSALProfileEllipse
|
||||
$profileGrid.Children.Add($tmpObj) | Out-Null
|
||||
}
|
||||
|
||||
if($script:jwtAccessToken.Payload.idtyp -eq "app")
|
||||
{
|
||||
$tmpObj.Visibility = "Collapsed"
|
||||
}
|
||||
|
||||
$global:grdProfileInfo.Add_Loaded({param($obj, $e)
|
||||
$point = $obj.Tag.TransformToAncestor($window).Transform([System.Windows.Point]::new(0,0));
|
||||
[System.Windows.Controls.Canvas]::SetLeft($obj,($point.X - $obj.ActualWidth + $obj.Tag.ActualWidth))
|
||||
[System.Windows.Controls.Canvas]::SetTop($obj,($point.Y + $obj.Tag.ActualHeight))
|
||||
})
|
||||
|
||||
if($script:jwtAccessToken.Payload.idtyp -ne "app")
|
||||
{
|
||||
#########################################################################################################
|
||||
### Show / Hide consent button
|
||||
#########################################################################################################
|
||||
@@ -1696,6 +1847,7 @@ function Get-MSALProfileEllipse
|
||||
catch {}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#########################################################################################################
|
||||
### Add event handling
|
||||
@@ -1756,6 +1908,11 @@ function Get-MSALProfileEllipse
|
||||
Show-GraphObjects
|
||||
}
|
||||
}
|
||||
|
||||
if($script:jwtAccessToken.Payload.idtyp -eq "app")
|
||||
{
|
||||
Set-XamlProperty $tmpObj "lnkLogout" "Visibility" "Collapsed"
|
||||
}
|
||||
}
|
||||
catch {
|
||||
Write-LogError "Failed to create profile information object. Error: " $_.Exception
|
||||
@@ -1931,12 +2088,21 @@ function Get-MSALMissingScopes
|
||||
|
||||
$script:missingPermissions = @()
|
||||
|
||||
if($script:jwtAccessToken.Payload.idtyp -eq "app")
|
||||
{
|
||||
$curScopes = $script:jwtAccessToken.Payload.roles
|
||||
}
|
||||
else
|
||||
{
|
||||
$curScopes = $authToken.Scopes
|
||||
}
|
||||
|
||||
foreach($scope in $reqScopes)
|
||||
{
|
||||
$tmpScope = $scope.Split('/')[-1]
|
||||
if($tmpScope -eq ".default") { continue }
|
||||
if($authToken.Scopes -contains $tmpScope) { continue }
|
||||
if(($authToken.Scopes -like "*/$tmpScope")) { continue }
|
||||
if($curScopes -contains $tmpScope) { continue }
|
||||
if(($curScopes -like "*/$tmpScope")) { continue }
|
||||
$arrTemp = $tmpScope.Split(".")
|
||||
if($arrTemp[1] -eq "Read")
|
||||
{
|
||||
@@ -1960,6 +2126,9 @@ function Show-MSALDecodedToken {
|
||||
$tokenData,
|
||||
$title
|
||||
)
|
||||
|
||||
if(-not $tokenData.Header) { return }
|
||||
|
||||
$tokenArr = @()
|
||||
foreach($prop in ($tokenData.Header | GM | Where MemberType -eq NoteProperty))
|
||||
{
|
||||
|
||||
+151
-39
@@ -10,7 +10,7 @@ This module manages Microsoft Grap fuctions like calling APIs, managing graph ob
|
||||
#>
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'3.9.0'
|
||||
'3.9.3'
|
||||
}
|
||||
|
||||
$global:MSGraphGlobalApps = @(
|
||||
@@ -183,6 +183,14 @@ function Invoke-InitializeModule
|
||||
Description = "Certificate for Azure App"
|
||||
}) "GraphSilent"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Login with App in UI (Preview)"
|
||||
Key = "GraphAzureAppLogin"
|
||||
Type = "Boolean"
|
||||
DefaultValue = $false
|
||||
Description = "Login with specified app in the UI. Note: Change will require app restart"
|
||||
}) "GraphSilent"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Refresh Objects after copy"
|
||||
Key = "RefreshObjectsAfterCopy"
|
||||
@@ -214,6 +222,15 @@ function Invoke-InitializeModule
|
||||
DefaultValue = $false
|
||||
Description = "Expand assignments when listing objects. This can be used in custom columns based on assignment info"
|
||||
}) "GraphGeneral"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Use Graph 1.0 (Not Recommended)"
|
||||
Key = "UseGraphV1"
|
||||
Type = "Boolean"
|
||||
DefaultValue = $false
|
||||
Description = "This will use production verionof graph, v1.0. Note: Thot officially supported since this can have unpredicted results. Some parts will require Beta version of Graph."
|
||||
}) "GraphGeneral"
|
||||
|
||||
}
|
||||
|
||||
function Get-GraphAppInfo
|
||||
@@ -261,6 +278,7 @@ function Invoke-GraphAuthenticationUpdated
|
||||
$global:MigrationTableCacheId = $null
|
||||
$global:LoadedDependencyObjects = $null
|
||||
$global:migFileObj = $null
|
||||
$global:AADObjectCache = $null
|
||||
}
|
||||
|
||||
function Invoke-SettingsUpdated
|
||||
@@ -270,7 +288,7 @@ function Invoke-SettingsUpdated
|
||||
|
||||
function Initialize-GraphSettings
|
||||
{
|
||||
|
||||
$script:defaultVersion = ""
|
||||
}
|
||||
|
||||
function Invoke-GraphRequest
|
||||
@@ -297,7 +315,7 @@ function Invoke-GraphRequest
|
||||
$ODataMetadata = "full", # full, minimal, none or skip
|
||||
|
||||
[ValidateSet("beta","v1.0")]
|
||||
$GraphVersion = "beta",
|
||||
$GraphVersion = "",
|
||||
|
||||
[switch]
|
||||
$AllPages,
|
||||
@@ -317,6 +335,22 @@ function Invoke-GraphRequest
|
||||
Connect-MSALUser
|
||||
}
|
||||
|
||||
if(-not $GraphVersion)
|
||||
{
|
||||
if(-not $script:defaultVersion)
|
||||
{
|
||||
if((Get-SettingValue "UseGraphV1") -eq $true)
|
||||
{
|
||||
$script:defaultVersion = "v1.0"
|
||||
}
|
||||
else
|
||||
{
|
||||
$script:defaultVersion = "beta"
|
||||
}
|
||||
}
|
||||
$GraphVersion = $script:defaultVersion
|
||||
}
|
||||
|
||||
$params = @{}
|
||||
|
||||
$requestId = [Guid]::NewGuid().guid
|
||||
@@ -394,6 +428,13 @@ function Invoke-GraphRequest
|
||||
$url = "$($url.Trim())`$top=$($PageSize)"
|
||||
}
|
||||
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$params.Add("proxy", $proxyURI)
|
||||
$params.Add("UseBasicParsing", $true)
|
||||
}
|
||||
|
||||
$ret = $null
|
||||
|
||||
$retryCount = 0
|
||||
@@ -1028,6 +1069,12 @@ function Get-GraphMetaData
|
||||
[void][System.Reflection.Assembly]::LoadWithPartialName("System.Web.Extensions")
|
||||
$wc = New-Object System.Net.WebClient
|
||||
$wc.Encoding = [System.Text.Encoding]::UTF8
|
||||
$proxyURI = Get-ProxyURI
|
||||
if($proxyURI)
|
||||
{
|
||||
$wc.Proxy = $proxyURI
|
||||
}
|
||||
|
||||
try
|
||||
{
|
||||
[xml]$global:metaDataXML = $wc.DownloadString($url)
|
||||
@@ -1671,6 +1718,7 @@ function Show-GraphImportForm
|
||||
|
||||
$importedObjectsCurType = 0
|
||||
$navigationPropObjects = @()
|
||||
$arrImportedObjects = @()
|
||||
foreach ($fileObj in $filesToImport)
|
||||
{
|
||||
if($allowUpdate -and $global:cbImportType.SelectedValue -ne "alwaysImport" -and (Reset-GraphObject $fileObj $global:dgObjects.ItemsSource))
|
||||
@@ -1686,9 +1734,15 @@ function Show-GraphImportForm
|
||||
ImportedObject = $importedObj
|
||||
}
|
||||
}
|
||||
$arrImportedObjects += $importedObj
|
||||
$importedObjectsCurType++
|
||||
}
|
||||
|
||||
if($global:curObjectType.PostFilesImportCommand)
|
||||
{
|
||||
& $global:curObjectType.PostFilesImportCommand $global:curObjectType $arrImportedObjects $filesToImport
|
||||
}
|
||||
|
||||
if($importedObjectsCurType -gt 0 -and $global:LoadedDependencyObjects -is [HashTable] -and $global:LoadedDependencyObjects.ContainsKey($global:curObjectType.Id))
|
||||
{
|
||||
Write-Log "Remove $($global:curObjectType.Title) from dependency cache"
|
||||
@@ -1857,7 +1911,6 @@ function Show-GraphBulkImportForm
|
||||
|
||||
function Start-GraphObjectImport
|
||||
{
|
||||
|
||||
Write-Status "Import objects" -Block
|
||||
Write-Log "****************************************************************"
|
||||
Write-Log "Start bulk import"
|
||||
@@ -1907,6 +1960,8 @@ function Start-GraphObjectImport
|
||||
|
||||
$importedObjectsCurType = 0
|
||||
|
||||
$arrImportedObjects = @()
|
||||
|
||||
foreach ($fileObj in @($filesToImport))
|
||||
{
|
||||
$objName = Get-GraphObjectName $fileObj.Object $item.ObjectType
|
||||
@@ -1930,11 +1985,17 @@ function Start-GraphObjectImport
|
||||
ImportedObject = $importedObj
|
||||
}
|
||||
}
|
||||
$arrImportedObjects = $importedObj
|
||||
|
||||
$importedObjects++
|
||||
$importedObjectsCurType++
|
||||
}
|
||||
|
||||
if($item.ObjectType.PostFilesImportCommand)
|
||||
{
|
||||
& $item.ObjectType.PostFilesImportCommand $item.ObjectType $arrImportedObjects $filesToImport
|
||||
}
|
||||
|
||||
if($importedObjectsCurType -gt 0 -and $global:LoadedDependencyObjects -is [HashTable] -and $global:LoadedDependencyObjects.ContainsKey($item.ObjectType.Id))
|
||||
{
|
||||
Write-Log "Remove $($item.ObjectType.Title) from dependency cache"
|
||||
@@ -2230,6 +2291,11 @@ function Import-GraphFile
|
||||
Import-GraphObjectAssignment $newObj $file.ObjectType $objClone.Assignments $file.FileInfo.FullName | Out-Null
|
||||
}
|
||||
|
||||
if($newObj)
|
||||
{
|
||||
$file | Add-Member -NotePropertyName "ImportedObject" -NotePropertyValue $newObj
|
||||
}
|
||||
|
||||
if($PassThru -eq $true -and $newObj)
|
||||
{
|
||||
$newObj
|
||||
@@ -2497,6 +2563,15 @@ function Set-ScopeTags
|
||||
else { return }
|
||||
|
||||
$scopesIds = @()
|
||||
if($global:chkReplaceDependencyIDs.IsChecked -eq $false -and $global:chkReplaceDependencyIDs.IsEnabled -eq $false)
|
||||
{
|
||||
if($global:chkImportScopes.IsChecked -eq $true)
|
||||
{
|
||||
$scopesIds += $obj.$scopeTagProperty
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
$loadedScopeTags = $global:LoadedDependencyObjects["ScopeTags"]
|
||||
$usingDefault = (($obj."$scopeTagProperty" | measure).Count -eq 1 -and ($obj."$scopeTagProperty")[0] -eq "0")
|
||||
if($loadedScopeTags -and $global:chkImportScopes.IsChecked -eq $true -and $usingDefault -eq $false -and $loadedScopeTags)
|
||||
@@ -2516,6 +2591,8 @@ function Set-ScopeTags
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($scopesIds.Count -eq 0)
|
||||
{
|
||||
$scopesIds += "0" # Import with Default ScopeTag as default.
|
||||
@@ -2662,7 +2739,7 @@ function Add-GraphMigrationObject
|
||||
|
||||
# Check if object is already processed
|
||||
$graphObj = Get-GraphMigrationObject $objId
|
||||
if(-not $graphObj)
|
||||
if(-not $graphObj -and ($global:AADObjectCache.ContainsKey($objId) -eq $false))
|
||||
{
|
||||
# Get object info
|
||||
$graphObj = Invoke-GraphRequest "$($grapAPI)/$objId" -ODataMetadata "none" -NoError
|
||||
@@ -2688,7 +2765,8 @@ function Add-GraphMigrationObject
|
||||
}
|
||||
else
|
||||
{
|
||||
Write-Log "No $objTypeName found with ID $($groupId). It might be deleted." 2
|
||||
if($global:AADObjectCache.ContainsKey($objId) -eq $false) { $global:AADObjectCache.Add($objId, $null) }
|
||||
Write-Log "No $objTypeName found with ID $($objId). It might be deleted." 2
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2961,7 +3039,7 @@ function Add-GraphDependencyObjects
|
||||
{
|
||||
if($global:LoadedDependencyObjects.ContainsKey($dep)) { continue }
|
||||
|
||||
$depObjectType = $global:currentViewObject.ViewItems | Where Id -eq $Dep
|
||||
$depObjectType = $global:viewObjects.ViewItems | Where Id -eq $Dep
|
||||
|
||||
if(-not $depObjectType)
|
||||
{
|
||||
@@ -3122,7 +3200,7 @@ function Export-GraphObject
|
||||
[IO.Directory]::CreateDirectory($exportFolder) | Out-Null
|
||||
}
|
||||
|
||||
if($chkExportAssignments.IsChecked -ne $true -and $obj.Assignments)
|
||||
if($global:chkExportAssignments.IsChecked -ne $true -and $obj.Assignments)
|
||||
{
|
||||
Remove-Property $obj "Assignments"
|
||||
}
|
||||
@@ -3360,10 +3438,9 @@ function Get-GraphBatchObjects
|
||||
{
|
||||
param($objects, $txtNameFilter)
|
||||
|
||||
$curBatch = 1
|
||||
$batchResults = @()
|
||||
$batchArr = @()
|
||||
$batchTotal = 0
|
||||
$skipped = 0
|
||||
$objectType = $null
|
||||
|
||||
foreach($obj in $objects)
|
||||
@@ -3373,7 +3450,7 @@ function Get-GraphBatchObjects
|
||||
|
||||
if($objName -and $txtNameFilter -and $objName -notmatch [RegEx]::Escape($txtNameFilter))
|
||||
{
|
||||
$batchTotal++
|
||||
$skipped++
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -3385,17 +3462,59 @@ function Get-GraphBatchObjects
|
||||
headers = @{"Accept"="application/json;odata.metadata=$ometadata"}
|
||||
}
|
||||
}
|
||||
|
||||
if($batchArr.Count -eq 20 -or ($batchTotal + $batchArr.Count -eq $objects.Count))
|
||||
{
|
||||
$batchObj = [PSCustomObject]@{
|
||||
requests = $batchArr
|
||||
}
|
||||
|
||||
Write-Status "Get batch $curBatch $($obj.ObjectType.Title)" -Force
|
||||
if($batchArr.Count -eq 0) { return }
|
||||
|
||||
$batchResults = (Invoke-GraphBatchRequest $batchArr $objectType.Title).body
|
||||
|
||||
if($batchResults.Count -ne ($objects.Count - $skipped))
|
||||
{
|
||||
Write-Log "Not all batch objects returned. Expected $($objects.Count - $skipped) but only got $($batchResults.Count)"
|
||||
}
|
||||
|
||||
if($objectType -and $batchResults.Count -gt 0)
|
||||
{
|
||||
$batchResultsTmp = $batchResults
|
||||
$batchResults = Add-GraphObjectProperties $batchResultsTmp $objectType -property $objectType.ViewProperties
|
||||
|
||||
$curObj = 1
|
||||
foreach($obj in $batchResults)
|
||||
{
|
||||
if($obj.Object -and $obj.ObjectType.PostGetCommand)
|
||||
{
|
||||
Write-Status "Run PostGetCommand - $((Get-GraphObjectName $obj.Object $obj.ObjectType)) ($($curObj)/$(@($batchResults).Count))" -Force
|
||||
& $obj.ObjectType.PostGetCommand $obj $obj.ObjectType
|
||||
}
|
||||
$curObj++
|
||||
}
|
||||
}
|
||||
$batchResults
|
||||
}
|
||||
|
||||
function Invoke-GraphBatchRequest
|
||||
{
|
||||
param($batchObjects, $batchType, [switch]$SkipWarnings, [switch]$IncludedFailed)
|
||||
|
||||
$batchArr = @()
|
||||
$batchResults = @()
|
||||
$batchTotal = 0
|
||||
$curBatch = 1
|
||||
|
||||
foreach($obj in $batchObjects)
|
||||
{
|
||||
$batchArr += $obj
|
||||
|
||||
if($batchArr.Count -eq 20 -or (($batchTotal + $batchArr.Count) -eq $batchObjects.Count))
|
||||
{
|
||||
$batchObj = [PSCustomObject]@{
|
||||
requests = @($batchArr)
|
||||
}
|
||||
|
||||
Write-Status "Get batch $curBatch $batchType" -Force
|
||||
|
||||
$batchTotal += $batchArr.Count
|
||||
$json = $batchObj | ConvertTo-Json -Depth 50
|
||||
|
||||
$maxRetryCount = 10
|
||||
$curRetry = 0
|
||||
|
||||
@@ -3404,10 +3523,11 @@ function Get-GraphBatchObjects
|
||||
$retry = $false
|
||||
$retryArr = @()
|
||||
$retryAfter = 0
|
||||
$tmpResults = Invoke-GraphRequest -Url "`$batch" -Content $json -HttpMethod "POST" -Batch #-Url $api -property $obj.ObjectType.ViewProperties -objectType $obj.ObjectType -
|
||||
$tmpResults = Invoke-GraphRequest -Url "`$batch" -Body $json -Method "POST"
|
||||
|
||||
foreach($batchResult in ($tmpResults.responses | Sort -Property Id))
|
||||
{
|
||||
if($batchResult.Status -ne "200" -or -not $batchResult.body)
|
||||
if($batchResult.Status -ge 300 -or -not $batchResult.body)
|
||||
{
|
||||
$reqObj = $batchObj.requests | where id -eq $batchResult.Id
|
||||
if($batchResult.Status -eq 429 -and $reqObj)
|
||||
@@ -3423,12 +3543,20 @@ function Get-GraphBatchObjects
|
||||
$retryArr += $reqObj
|
||||
}
|
||||
else
|
||||
{
|
||||
if($SkipWarnings -ne $true)
|
||||
{
|
||||
Write-Log "Batch result $($batchResult.Status) for URL $($reqObj.URL). Skipping..." 2
|
||||
}
|
||||
|
||||
if($IncludedFailed -eq $true)
|
||||
{
|
||||
$batchResults += $batchResult
|
||||
}
|
||||
}
|
||||
continue
|
||||
}
|
||||
$batchResults += $batchResult.body
|
||||
$batchResults += $batchResult
|
||||
}
|
||||
|
||||
if($retryArr.Count -gt 0)
|
||||
@@ -3457,27 +3585,11 @@ function Get-GraphBatchObjects
|
||||
}
|
||||
}
|
||||
|
||||
if($batchResults.Count -ne $objects.Count)
|
||||
if($batchResults.Count -ne $batchObjects.Count -and $SkipWarnings -ne $true)
|
||||
{
|
||||
Write-Log "Not all batch objects returned. Expected $($objects.Count) but only got $($batchResults.Count)"
|
||||
Write-Log "Not all batch objects returned. Expected $($batchObjects.Count) but only got $($batchResults.Count)" 2
|
||||
}
|
||||
|
||||
if($objectType -and $batchResults.Count -gt 0)
|
||||
{
|
||||
$batchResultsTmp = $batchResults
|
||||
$batchResults = Add-GraphObjectProperties $batchResultsTmp $objectType -property $objectType.ViewProperties
|
||||
|
||||
$curObj = 1
|
||||
foreach($obj in $batchResults)
|
||||
{
|
||||
if($obj.Object -and $obj.ObjectType.PostGetCommand)
|
||||
{
|
||||
Write-Status "Get full info - $((Get-GraphObjectName $obj.Object $obj.ObjectType)) ($($curObj)/$(@($batchResults).Count))" -Force
|
||||
& $obj.ObjectType.PostGetCommand $obj $obj.ObjectType
|
||||
}
|
||||
$curObj++
|
||||
}
|
||||
}
|
||||
$batchResults
|
||||
}
|
||||
|
||||
|
||||
+160
@@ -1,4 +1,164 @@
|
||||
# Release Notes
|
||||
## 3.9.4 - 2023-12-18
|
||||
|
||||
**Fixes**
|
||||
- **Get Assignment Filter usage**<br />
|
||||
- All policies that supports filter should now be collected<br />
|
||||
Please create an issue if not all expected filters are listed<br />
|
||||
Based on [Issue 141](https://github.com/Micke-K/IntuneManagement/issues/141)<br />
|
||||
**NOTE:** Start the tool from: Views -> Intune Tools -> Intune Filter Usage<br />
|
||||
|
||||
- **Documentation**<br />
|
||||
- Added support for documenting Conditional Access policies based on Workloads<br />
|
||||
Not 100% tested. Please report if not documented correctly<br />
|
||||
<br />
|
||||
|
||||
## 3.9.3 - 2023-12-11
|
||||
|
||||
**New features**
|
||||
|
||||
- **New tool - Get Assignment Filter usage**<br />
|
||||
- List all policies and assignments with a Filter defined<br />
|
||||
Based on [Issue 141](https://github.com/Micke-K/IntuneManagement/issues/141)<br />
|
||||
**NOTE:** Start the tool from: Views -> Intune Tools -> Intune Filter Usage<br />
|
||||
|
||||
- **Batch Export of App Content Encryption Key from Intunewin files**<br />
|
||||
This script can export encryption keys from existing intunewin files<br />
|
||||
Example:<br />
|
||||
Export-EncrytionKeys -RootFolder C:\Intune\Packages -ExportFolder C:\Intune\Download<br />
|
||||
This will export the encryption key information for each .intunewinfiles under C:\Intune\Packages<br />
|
||||
One json file will be created (for each .intunwinfile) in the C:\Intune\Download folder<br />
|
||||
File name will be **<*IntunewinFileBaseName*>_<*UnencryptedFileSize*>.json**<br />
|
||||
Do **NOT** rename this file since the script will search for that file when downloading or exporting App content<br />
|
||||
The script will not require authentication and it will have no knowledge of apps in Intune<br />
|
||||
Filename and unencrypted file size is used as the identifier to match app content in Intune with encryption file<br />
|
||||
**Important notes:**<br />
|
||||
Exported and decrypted .intunewin files are not supported to use for import at the moment.<br />
|
||||
These files are just the "zip" version of the source and can be unzipped with any zip extraction tool<br />
|
||||
The .intunewin file used for import has the "zip" version of the file and an xml with the encryption information +<br />
|
||||
additional file information eg. msi properties, file size etc.<br />
|
||||
Use the exported unencrypted "zip" version to restore the original files. Re-run the packaging tool if it should be re-used as applications content<br />
|
||||
<br />
|
||||
Please report any issues or create a discussion if there are any questions<br />
|
||||
Script is located: **<*RootFolder*>\Scripts\Export-EncrytionKeys.ps1**<br />
|
||||
|
||||
<br />
|
||||
|
||||
**Fixes**
|
||||
- **Export**<br />
|
||||
- Fixed issue where Assignments were included in export even if 'Export Assignments' was unchecked<br />
|
||||
Based on [Issue 171](https://github.com/Micke-K/IntuneManagement/issues/171)<br />
|
||||
|
||||
- **Documentation**<br />
|
||||
- Fixed issue where filter was not documented on some policies<br />
|
||||
- Fixed issue with Word Output provider if a policy only had one settings<br />
|
||||
|
||||
- **Custom ADMX Files**<br />
|
||||
- Fixed bug with migrating custom policies between environments. Cache was not cleared when swapping tenants or imported additional ADMX files<br />
|
||||
- Fixed documentention issue with Administrative template policies in GCC environment. Name and Category was missing<br />
|
||||
Based on [Issue 174](https://github.com/Micke-K/IntuneManagement/issues/174)<br />
|
||||
- Custom ADMX based policies was missing properties when swapping tenant<br />
|
||||
Based on [Issue 124](https://github.com/Micke-K/IntuneManagement/issues/124)<br />
|
||||
|
||||
- **Generic**<br />
|
||||
- Fixed logging issues when processing objects with a group that was deleted. ID was not reported<br />
|
||||
- Generic Batch request function created to support other batch requests eg Groups<br />
|
||||
<br />
|
||||
|
||||
## 3.9.2 - 2023-10-17
|
||||
|
||||
**New features**
|
||||
|
||||
- **Application Content Export - Experimental**<br />
|
||||
- Added support for Exporting Appliction with decrypted content<br />
|
||||
App file can be downloaded during export or from the detail view of the Application<br />
|
||||
Enable "Save Encryption File" and specify "App download folder" in Settings<br />
|
||||
"App download folder" is used for encryption file and manual download<br />
|
||||
File content will be downloaded to the export foler during export<br />
|
||||
Files will be downloaded with .encrypted extension and then decrypted to original file name<br />
|
||||
Please report any issue or any suggestions<br />
|
||||
**NOTE:** This will ONLY work if the encryption file is exported and available<br />
|
||||
|
||||
- **Authentication**<br />
|
||||
- Login with application<br />
|
||||
This will login with specified Azure App ID and Secret/Certificate that is used for Batch processes<br />
|
||||
NOTE: This will require a restart of the app<br />
|
||||
Start with app **must** use -TenantID on command line. AppID and Secret/Certificate can be specified in Settings or command line<br />
|
||||
Example: Start-IntuneManagement.ps1 -tenantId \"<TenantID>\" -appid \"<AppID>\" -secret \"<Secret>\"<br />
|
||||
See *Start-WithApp.cmd* for samle file<br />
|
||||
Based on [Issue 122](https://github.com/Micke-K/IntuneManagement/issues/122) and [Issue 134](https://github.com/Micke-K/IntuneManagement/issues/134)<br />
|
||||
|
||||
- **Support for new Settings**<br />
|
||||
- Save encryption file - Saves a json file with encryption data when an application file is uploaded eg created or uploaded in details view<br />
|
||||
- App download folder - Folder where application files should be downloaded and decrypted<br />
|
||||
- Login with App in UI (Preview) - Use app batch login in UI<br />
|
||||
- Use Graph 1.0 (Not Recommended) - Use Graph v1.0 instead of Beta. **Note:** Some features will NOT work in v1.0<br />
|
||||
Based on [Issue 170](https://github.com/Micke-K/IntuneManagement/issues/170)<br />
|
||||
|
||||
**Fixes**
|
||||
- **Documentation**<br />
|
||||
- Language files re-generated eg Supersedence (preview) -> Supersedence<br />
|
||||
- Added support for documenting "Filter for devices" info for Conditional Access policies<br />
|
||||
Based on [Issue 168](https://github.com/Micke-K/IntuneManagement/issues/168)<br />
|
||||
|
||||
- **Custom ADMX Files**<br />
|
||||
- Fixed issues with migrating custom policies between environments (3rd time)<br />
|
||||
Based on [Issue 124](https://github.com/Micke-K/IntuneManagement/issues/124)<br />
|
||||
- Fixed issue when importing ADMX files - Encoding issue eg ADMX/ADML file was UTF8<br />
|
||||
Based on [Issue 169](https://github.com/Micke-K/IntuneManagement/issues/169)<br />
|
||||
|
||||
- **Importing Windows LoB Apps**<br />
|
||||
- Fixed issue when importing LoB Apps that was only targeted to System context<br />
|
||||
Available Assignment option was missing after import<br />
|
||||
Based on [Discussion 164](https://github.com/Micke-K/IntuneManagement/discussions/164)<br />
|
||||
- Added support for Depnedency and Supersedence reations at import<br />
|
||||
Application will need to be re-exported since additinal data is added to the export file<br />
|
||||
Based on [Discussion 159](https://github.com/Micke-K/IntuneManagement/discussions/159)<br />
|
||||
|
||||
- **Generic**<br />
|
||||
- Fixed issue when compiling Procxy CS file<br />
|
||||
- Tls 1.2 is now enforced.<br />
|
||||
Based on [Discussion 166](https://github.com/Micke-K/IntuneManagement/discussions/166)<br />
|
||||
<br />
|
||||
|
||||
## 3.9.1 - 2023-08-30
|
||||
|
||||
**New features**
|
||||
|
||||
- **Added support for Windows Update Driver Policies**<br />
|
||||
|
||||
- **Support for new Settings**<br />
|
||||
- Proxy configuration - If configured, Proxy will be used for authentication, APIs and upload<br />
|
||||
- Disable Write-Error output - Skip PowerShell errors in output<br />
|
||||
|
||||
**Default Settings Value Changes**
|
||||
- Conditional Access policies will now be imported as Disabled by default<br />
|
||||
- New import option added: As Exported - Change On to Report-only<br />
|
||||
- This is to avoid being locked out from the tenant when importing Conditional Access policies<br />
|
||||
- Based on [Discussion 139](https://github.com/Micke-K/IntuneManagement/discussions/139)<br />
|
||||
|
||||
**Fixes**
|
||||
- **Documentation**<br />
|
||||
- Fixed issues with some Feature Updates properties<br />
|
||||
- Added missing strings on Windows Update polices<br />
|
||||
- Regenerated Language files and Translation tables for Template policies<br />
|
||||
Note: Conditional Access string has changed file in background. Please report if there is anything missing<br />
|
||||
|
||||
- **Custom ADMX Files**<br />
|
||||
- Fixed issues with migrating custom policies between environments<br />
|
||||
- Case reopened due to something broke the initial functionality<br />
|
||||
- Only custom ADMX policies with #Definition properties can be imported into a new environment<br />
|
||||
- Based on [Issue 124](https://github.com/Micke-K/IntuneManagement/issues/124)<br />
|
||||
|
||||
- **Scope Tags**<br />
|
||||
- Fixed issues with importing policies with Scope Tags but they were not set<br />
|
||||
- Based on [Issue 133](https://github.com/Micke-K/IntuneManagement/issues/133)<br />
|
||||
|
||||
**Generic**<br />
|
||||
- Remove invalid characters from path.<br />
|
||||
- Based on [Issue 150](https://github.com/Micke-K/IntuneManagement/issues/150)<br />
|
||||
<br />
|
||||
|
||||
## 3.9.0 - 2023-05-04
|
||||
|
||||
**New features**
|
||||
|
||||
@@ -0,0 +1,159 @@
|
||||
<#
|
||||
Export encryption keys from .intunewin files.
|
||||
This can be used when downloading intunewin files from Intune.
|
||||
|
||||
This is a prt of the IntuneManage GitHub Repository
|
||||
https://github.com/Micke-K/IntuneManagement/
|
||||
(c) Mikael Karlsson MIT License - https://github.com/Micke-K/IntuneManagement/blob/master/LICENSE
|
||||
|
||||
Exprot file name will be <IntunewinFileBaseName>_<UnencryptedFileSize>.json
|
||||
Do NOT rename the exported file. The script will try to find excryption file based on the generated name.
|
||||
|
||||
Encryption information is file specific. If the same .intunewin file is imported in multiple tenants,
|
||||
the same ecryption file can be used to decrypt it when downloading or exporting the app content.
|
||||
|
||||
.Sample
|
||||
Export-EncrytionKeys -RootFolder C:\Intune\Packages -ExportFolder C:\Intune\Download
|
||||
This will search C:\Intune\Packages and all subfolder for .intunewin files and export
|
||||
the encryption keys to the C:\Intune\Download.
|
||||
#>
|
||||
param(
|
||||
[Alias("RF")]
|
||||
# Root folder where intunewin files are located.
|
||||
$RootFolder,
|
||||
[Alias("EF")]
|
||||
# Folder where encryption files should be exported to
|
||||
# If this is empty, the encryption file will be saved to the same folder as the intunewin file
|
||||
$ExportFolder)
|
||||
|
||||
function Export-IntunewinFileObject
|
||||
{
|
||||
param($file, $objectName, $toFile)
|
||||
|
||||
try
|
||||
{
|
||||
Add-Type -Assembly System.IO.Compression.FileSystem
|
||||
|
||||
$zip = [IO.Compression.ZipFile]::OpenRead($file)
|
||||
|
||||
$zip.Entries | where { $_.Name -like $objectName } | foreach {
|
||||
|
||||
[System.IO.Compression.ZipFileExtensions]::ExtractToFile($_, $toFile, $true)
|
||||
}
|
||||
|
||||
$zip.Dispose()
|
||||
return $true
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-Warning "Failed to get info from $file. Error: $($_.Exception.Message)"
|
||||
return $false
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
function Export-EncryptionKeys
|
||||
{
|
||||
param(
|
||||
[Parameter(ValueFromPipeline=$true)]
|
||||
$fileInfo,
|
||||
$exportFolder = $fileInfo.DirectoryName
|
||||
)
|
||||
|
||||
begin
|
||||
{
|
||||
}
|
||||
|
||||
process
|
||||
{
|
||||
if($fileInfo -isnot [IO.FileInfo]) { return }
|
||||
|
||||
if(-not $exportFolder) { $exportFolder = $fileInfo.DirectoryName }
|
||||
|
||||
$tmpFile = [IO.Path]::GetTempFileName()
|
||||
|
||||
if((Export-IntunewinFileObject $fileInfo.FullName "detection.xml" $tmpFile) -ne $true)
|
||||
{
|
||||
return
|
||||
}
|
||||
|
||||
$tmpFI = [IO.FileInfo]$tmpFile
|
||||
|
||||
try
|
||||
{
|
||||
if($tmpFI.Length -eq 0)
|
||||
{
|
||||
throw "Detection.xml not exported"
|
||||
}
|
||||
[xml]$DetectionXML = Get-Content $tmpFile
|
||||
}
|
||||
catch
|
||||
{
|
||||
Write-Warning "Failed to export detection.xml file. Error: $($_.Exception.Message)"
|
||||
return
|
||||
}
|
||||
finally
|
||||
{
|
||||
Remove-Item -Path $tmpFile -Force | Out-Null
|
||||
}
|
||||
|
||||
# Get encryption info from detection.xml and build encryptionInfo object
|
||||
|
||||
$encryptionInfo = @{}
|
||||
$encryptionInfo.encryptionKey = $DetectionXML.ApplicationInfo.EncryptionInfo.EncryptionKey
|
||||
$encryptionInfo.macKey = $DetectionXML.ApplicationInfo.EncryptionInfo.macKey
|
||||
$encryptionInfo.initializationVector = $DetectionXML.ApplicationInfo.EncryptionInfo.initializationVector
|
||||
$encryptionInfo.mac = $DetectionXML.ApplicationInfo.EncryptionInfo.mac
|
||||
$encryptionInfo.profileIdentifier = "ProfileVersion1"
|
||||
$encryptionInfo.fileDigest = $DetectionXML.ApplicationInfo.EncryptionInfo.fileDigest
|
||||
$encryptionInfo.fileDigestAlgorithm = $DetectionXML.ApplicationInfo.EncryptionInfo.fileDigestAlgorithm
|
||||
|
||||
$fileData = @{}
|
||||
$fileData.Name = $DetectionXML.ApplicationInfo.Name
|
||||
$fileData.UnencryptedContentSize = $DetectionXML.ApplicationInfo.UnencryptedContentSize
|
||||
$fileData.SetupFile = $DetectionXML.ApplicationInfo.SetupFile
|
||||
|
||||
$msiInfo = @{}
|
||||
if($DetectionXML.ApplicationInfo.MsiInfo)
|
||||
{
|
||||
$msiInfo.MsiPublisher = $DetectionXML.ApplicationInfo.MsiInfo.MsiPublisher
|
||||
$msiInfo.MsiProductCode = $DetectionXML.ApplicationInfo.MsiInfo.Publisher
|
||||
$msiInfo.MsiProductVersion = $DetectionXML.ApplicationInfo.MsiInfo.MsiProductVersion
|
||||
$msiInfo.MsiPackageCode = $DetectionXML.ApplicationInfo.MsiInfo.MsiPackageCode
|
||||
$msiInfo.MsiUpgradeCode = $DetectionXML.ApplicationInfo.MsiInfo.MsiUpgradeCode
|
||||
$msiInfo.MsiIsMachineInstall = $DetectionXML.ApplicationInfo.MsiInfo.MsiIsMachineInstall
|
||||
$msiInfo.MsiIsUserInstall = $DetectionXML.ApplicationInfo.MsiInfo.MsiIsUserInstall
|
||||
$msiInfo.MsiIncludesServices = $DetectionXML.ApplicationInfo.MsiInfo.MsiIncludesServices
|
||||
$msiInfo.MsiIncludesODBCDataSource = $DetectionXML.ApplicationInfo.MsiInfo.MsiIncludesODBCDataSource
|
||||
$msiInfo.MsiContainsSystemRegistryKeys = $DetectionXML.ApplicationInfo.MsiInfo.MsiContainsSystemRegistryKeys
|
||||
$msiInfo.MsiContainsSystemFolders = $DetectionXML.ApplicationInfo.MsiInfo.MsiContainsSystemFolders
|
||||
}
|
||||
# Create mobileAppContentFile object for the file
|
||||
$fileEncryptionInfo = @{}
|
||||
$fileEncryptionInfo.fileEncryptionInfo = $encryptionInfo
|
||||
$fileEncryptionInfo.fileData = $fileData
|
||||
if($msiInfo.Count -gt 0)
|
||||
{
|
||||
$fileEncryptionInfo.MsiInfo = $msiInfo
|
||||
}
|
||||
|
||||
$json = $fileEncryptionInfo | ConvertTo-Json -Depth 10
|
||||
|
||||
if([IO.Directory]::Exists($exportFolder) -eq $false)
|
||||
{
|
||||
md $exportFolder | Out-Null
|
||||
}
|
||||
|
||||
$fileName = $exportFolder + "\$($fileInfo.BaseName)_$($DetectionXML.ApplicationInfo.UnencryptedContentSize).json"
|
||||
|
||||
Write-Host "Save encryption for $($fileInfo.BaseName) file $fileName"
|
||||
$json | Out-File -FilePath $fileName -Force -Encoding utf8
|
||||
}
|
||||
|
||||
end
|
||||
{
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Get-ChildItem -Path $RootFolder -Filter "*.intunewin" -Recurse | Export-EncryptionKeys -exportFolder $ExportFolder
|
||||
@@ -0,0 +1 @@
|
||||
cmd /c powershell -version 5 -ex bypass -File "%~DP0Start-IntuneManagement.ps1" -tenantId "<TenantID>" -appid "<AppID>" -secret "<Secret>"
|
||||
@@ -41,22 +41,13 @@
|
||||
<Button Grid.Column="4" Name="btnGetIntuneAssignments" Padding="5,2,5,2" Content="Get Assignments" ToolTip="Get assignments from the selected exported folder" />
|
||||
</Grid>
|
||||
|
||||
<StackPanel Grid.Row='1' Orientation="Horizontal" Margin="0,0,5,5" >
|
||||
<StackPanel Grid.Row='1' Orientation="Horizontal" Margin="0,0,5,0" >
|
||||
<Label Content="Filter" />
|
||||
<Rectangle Style="{DynamicResource InfoIcon}" ToolTip="Filter rows" />
|
||||
</StackPanel>
|
||||
|
||||
<Grid Grid.Column='1' Grid.Row='1'>
|
||||
<Grid.ColumnDefinitions>
|
||||
<ColumnDefinition Width="*" />
|
||||
<ColumnDefinition Width="5" />
|
||||
<ColumnDefinition Width="Auto" />
|
||||
</Grid.ColumnDefinitions>
|
||||
<Grid.RowDefinitions>
|
||||
<RowDefinition Height="Auto"/>
|
||||
</Grid.RowDefinitions>
|
||||
<TextBox Text="" Name="txtIntuneAssignmentsFilter" ToolTip="Filter items" />
|
||||
</Grid>
|
||||
<TextBox Text="" Grid.Column='1' Grid.Row='1' Margin="0,2,0,2" Name="txtIntuneAssignmentsFilter" ToolTip="Filter items" />
|
||||
|
||||
</Grid>
|
||||
|
||||
<DataGrid Name="dgIntuneAssignments" Margin="0,5,0,0" Grid.Row="1"
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
<Grid xmlns="http://schemas.microsoft.com/winfx/2006/xaml/presentation" xmlns:x="http://schemas.microsoft.com/winfx/2006/xaml"
|
||||
Grid.IsSharedSizeScope='True'>
|
||||
|
||||
<Grid.RowDefinitions>
|
||||
<RowDefinition Height="Auto" />
|
||||
<RowDefinition Height="*" />
|
||||
<RowDefinition Height="Auto" />
|
||||
</Grid.RowDefinitions>
|
||||
<Grid.ColumnDefinitions>
|
||||
<ColumnDefinition Width="*" />
|
||||
</Grid.ColumnDefinitions>
|
||||
|
||||
<Grid >
|
||||
<Grid.RowDefinitions>
|
||||
<RowDefinition Height="Auto"/>
|
||||
<RowDefinition Height="5"/>
|
||||
<RowDefinition Height="Auto"/>
|
||||
</Grid.RowDefinitions>
|
||||
<Grid.ColumnDefinitions>
|
||||
<ColumnDefinition Width="Auto" SharedSizeGroup="TitleColumn" />
|
||||
<ColumnDefinition Width="*"/>
|
||||
</Grid.ColumnDefinitions>
|
||||
|
||||
<Button Name="btnGetIntuneFilterUsage" Grid.Column='1' Grid.Row='0' Width="150" Padding="5,2,5,2" Content="Get Filter Usage" ToolTip="Get all Intune Filter assignment usage" />
|
||||
|
||||
<StackPanel Grid.Row='2' Orientation="Horizontal" Margin="5,0,0,4" >
|
||||
<Label Content="Filter" />
|
||||
<Rectangle Style="{DynamicResource InfoIcon}" ToolTip="Filter rows" />
|
||||
</StackPanel>
|
||||
|
||||
<TextBox Grid.Column='1' Grid.Row='2' Text="" Margin="5,3,0,5" Name="txtIntuneFilterUsageFilter" ToolTip="Filter items" />
|
||||
|
||||
</Grid>
|
||||
|
||||
<DataGrid Name="dgIntuneFilterUsage" Margin="0,5,0,0" Grid.Row="1"
|
||||
AutoGenerateColumns="False"
|
||||
SelectionMode="Single"
|
||||
SelectionUnit="FullRow"
|
||||
CanUserAddRows="False"
|
||||
ItemsSource="">
|
||||
<DataGrid.Columns>
|
||||
<DataGridTextColumn Header="Filter Name" Binding="{Binding FilterName}" IsReadOnly="True" />
|
||||
<DataGridTextColumn Header="Policy Name" Binding="{Binding PolicyName}" IsReadOnly="True" />
|
||||
<DataGridTextColumn Header="Type" Binding="{Binding PayloadType, Mode=OneWay}" IsReadOnly="True" />
|
||||
<DataGridTextColumn Header="Mode" Binding="{Binding Mode}" IsReadOnly="True" />
|
||||
<DataGridTextColumn Header="Group" Binding="{Binding GroupName}" IsReadOnly="True" />
|
||||
</DataGrid.Columns>
|
||||
</DataGrid>
|
||||
|
||||
<StackPanel Grid.Row="2" Orientation="Horizontal" HorizontalAlignment="Right" Margin="0,5,0,0" >
|
||||
<Button Name="btnIntuneFilterUsageCopy" Content="Copy" MinWidth="100" Margin="0,0,5,0" ToolTip="Copy the Filter usage as a CSV to the clipboard" />
|
||||
<Button Name="btnIntuneFilterUsagesSave" Content="Save" MinWidth="100" />
|
||||
</StackPanel>
|
||||
</Grid>
|
||||
@@ -135,7 +135,7 @@
|
||||
<Label Content="Current settings:" />
|
||||
<Rectangle Style="{DynamicResource InfoIcon}" ToolTip="Current property settings. Only updated when saved" />
|
||||
</StackPanel>
|
||||
<Label Name="lblObjectColumnsConfig" Content="" Margin="0,0,5,0" Grid.Row="3" />
|
||||
<Label Name="lblObjectColumnsConfig" Content="" Margin="0,0,5,0" Grid.Row="3" Grid.ColumnSpan="2" />
|
||||
|
||||
<StackPanel Orientation="Horizontal" Grid.Column="1" Margin="5,5,5,0" Grid.Row="4" Grid.ColumnSpan="2" HorizontalAlignment="Right">
|
||||
<Button Name="btnObjectColumnsReset" Content="Reset" Margin="0,0,5,0" Width="100" ToolTip="Revert all changes" />
|
||||
|
||||
Reference in New Issue
Block a user