Compare commits

...
53 Commits
Author SHA1 Message Date
Mikael Karlsson 5bb84c8561 Merge Development with Master 2026-05-12 19:50:19 +10:00
Mikael Karlsson b6b9e9e34c 3.10.3.1 2026-05-12 19:40:20 +10:00
Mikael Karlsson bd84a61522 3.10.3 2026-05-12 19:39:29 +10:00
Mikael Karlsson e09b3f71fa 3.10.1.19
Added support for importing Win32 app with Install/Uninstall script.
2026-04-11 15:09:39 +10:00
Mikael Karlsson 836c8a0c2e 3.10.1.18
Fixed issues: 402, 403 and 404
Added support for Install/Uninstall Script on Win32 apps
Rebuilt Strings
2026-03-07 14:01:52 +11:00
Mikael Karlsson b6c94e78d5 3.10.1.17
Issue 400 - Country names when documenting named locations
2026-02-22 20:40:45 +11:00
Mikael Karlsson e242865ef4 3.10.1.16
Issue 378 - Fixed issue when "Sort Json Properties" is enabled. Arrays were broken e.g. empty array ended up as null and single item ended up as string. This broke export/import of Conditional Access policies.
2026-01-26 22:08:24 +11:00
Mikael Karlsson f7043ae4a2 3.10.1.15
Issue 306 - Add additional support for clearing cache during Export/Import
2025-12-14 19:15:17 +11:00
Mikael Karlsson 71bb111a00 3.10.1.14
Issue 387 - Add support for Windows Update Profiles
2025-12-13 17:06:17 +11:00
Mikael Karlsson 9ca756bfed 3.10.1.13
Issue 383 - Fixed issue with document bool values in App Config with XML settings.
2025-12-07 21:23:01 +11:00
Mikael Karlsson 4053b5c672 3.10.1.12
Issue 380 - XML formatting
2025-11-25 21:25:26 +11:00
Mikael Karlsson 469408d29f 3.10.1.11
Issue 380 - Additional format of XML for ADMX and Reg value
2025-11-25 20:14:00 +11:00
Mikael Karlsson 7b87325776 3.10.1.10
Issue 380 - ADMX Import / Reg Values fails because of XML format.
2025-11-24 21:56:42 +11:00
Mikael Karlsson 7657fac645 3.10.1.9
Issue 378 - Add support for sorting exported json files.
2025-11-23 17:08:27 +11:00
Mikael Karlsson 37700847b5 3.10.1.8
Issue 381 - Fix issue with Device Categories and Expand Assignments enabled.
2025-11-20 22:32:54 +11:00
Mikael Karlsson e37a44dd87 3.10.1.7
Issue 375 - Additional error handling in the Word output provider.
2025-11-13 20:24:03 +11:00
Mikael Karlsson cd26450a10 3.10.1.6
Issues 375 - Add support for Strict Open XML document
2025-11-11 18:59:35 +11:00
Mikael Karlsson f1fdf5c078 3.10.1.5
Issue 367
2025-10-15 09:54:33 +11:00
Mikael Karlsson 03b27b1775 3.10.1.4
Issue 364 - Paging issues
Issue 367 - Login with App in UI
2025-10-11 13:40:24 +11:00
Mikael Karlsson 9bb966015e 3.10.1.3
Issue 364 - Conditional Access policies does not support paging.
2025-09-28 14:20:28 +10:00
Mikael Karlsson 286f238fde 3.10.1.1
Issue 364 - Failed to create group caused by wrong mailNickname
2025-09-23 20:18:22 +10:00
Mikael Karlsson 8368af379f 3.10.1.1
Fix Issue 364 - Conditional Access does not return Next page. Fall back to default for now.
2025-09-14 18:57:39 +10:00
Mikael Karlsson faffa95d8a Merge pull request #363 from Micke-K/Development
3.10.1 Release
2025-09-14 14:19:01 +10:00
Mikael Karlsson 485a9de855 3.10.1 2025-09-14 14:15:15 +10:00
Mikael Karlsson 951b583dd2 3.10.0.11
Added full support for BIOS Config polices eg export and edit file + documentation
2025-08-09 13:30:51 +10:00
Mikael Karlsson f27175d543 3.10.0.10
Added support for BIOS Confiuration policies
2025-08-06 20:19:13 +10:00
Mikael Karlsson 1ab13bf2dd 3.10.0.9
Fixed issue with Not Configured for Custom Compliance script.
Added option to skip date when generating MD document.
2025-08-03 20:42:46 +10:00
Mikael Karlsson 8952e2894a 3.10.0.8
Fix renaming Settings Catalog policies
2025-08-03 20:12:34 +10:00
Mikael Karlsson a0bac61ba4 Merge pull request #339 from MrR0bert/FixExportDirectoryNaming
Add Trim() to sanitize the organization displayName property
2025-08-03 19:12:08 +10:00
Mikael Karlsson 8fab983b25 Merge pull request #347 from brefra/Fix-Upload
Fix .intunewin uploads when using powershell 7.4+
2025-08-03 19:06:36 +10:00
Frank 6f6eba6959 Fix content upload at powershell 7.4+ 2025-07-29 21:08:56 +02:00
Mikael Karlsson b69cc227a4 3.10.0.7
Fixed issue with ADMX import and different enum format
Fixed issue with skipping Not Configured for Compliance Policies
Added support for documenting Compliance Policy V2 (Linux)
2025-07-28 21:11:17 +10:00
Mikael Karlsson 4253901249 3.10.0.6
Fixed import order for Compliance Scripts
2025-07-16 04:23:32 +10:00
Robert Kooistra cfb0e5f6e4 Moved trim of org displayName to the moment it is loaded instead of where it's used 2025-06-24 10:07:17 +02:00
MrR0b3rt 125d2e2b44 Forgot brackets before calling Trim() 2025-06-23 15:10:33 +02:00
MrR0b3rt 95c38a2b3d Add Trim() to sanitize the organization displayName property 2025-06-23 14:29:07 +02:00
Mikael Karlsson 9586ffb3fa 3.10.0.5
Removed deviceStates property for Conditional Access policy import. The property is depricated
2025-06-17 02:04:35 +10:00
Mikael Karlsson 5984acfca0 3.10.0.4
Fixed issue with Word Interop not loading
Added support for PDF output
2025-05-25 21:07:57 +10:00
Mikael Karlsson e1328ac7dd 3.10.0.3
Added documenting for file content eg MacOS Custom Settings
2025-05-03 15:42:03 +10:00
Mikael Karlsson 968fb4866c 3.10.0.2
Fixed issue with importing Security Baseline 24H2.
2025-04-19 14:53:57 +10:00
Mikael Karlsson 2169e91c9c 3.10.0
Fixed bad trimming
2025-03-16 20:59:19 +11:00
Mikael Karlsson ad5d6df95e 3.10.0
Added additional logging
2025-03-16 20:59:01 +11:00
Mikael Karlsson 9232769d5b Fixed Compare Issues
Fixed issues with Compare and Settings Catalog
2025-03-09 19:57:41 +11:00
Mikael Karlsson 06ab2c2023 Paging issues
Device settings does not return next page so get top 500
Found a rare issue where Settings Catalog could return next page after all items were returned. This caused the app to crash when scrolling the list.
2025-03-01 12:08:16 +11:00
Mikael Karlsson 8601a5b38e Initial 3.10.0 upload 2025-02-22 21:52:13 +11:00
Mikael Karlsson 17e9b786be Merge pull request #296 from Mykhailo-Roit/master
feat: replace_with_assignments import type
2025-01-12 17:20:36 +11:00
Mikael Karlsson e2c40b0a67 Merge pull request #290 from Systems-Liam/patch-1
Update DocumentationWordOptions.xaml
2025-01-12 17:17:14 +11:00
Mykhailo-Roit 381967c8cf fix conditions 2025-01-09 15:40:21 +02:00
Mykhailo-Roit 28022615a1 feat: add tooltip description for 'Replace with assignments' option in import forms 2025-01-08 18:58:36 +02:00
Mykhailo-Roit ff539f9ec1 feat: replace_with_assignments import type 2025-01-08 18:45:48 +02:00
Liam 7bab923a1f Update DocumentationWordOptions.xaml
Update typo on line 251.  Ducument to Document
2025-01-04 21:36:09 +00:00
Mikael Karlsson 4deea9a051 Updated release date 2024-10-12 12:54:40 +11:00
Mikael Karlsson c6fcf58d4d 3.9.8 2024-10-12 12:53:24 +11:00
114 changed files with 116444 additions and 121133 deletions
+1
View File
@@ -8,5 +8,6 @@
/*.new
/*.old
/Extensions/*.zip
Extensions_dev/
.gitignore
CloudAPIPowerShellManagement.log
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+1 -1
View File
@@ -12,7 +12,7 @@
RootModule = 'CloudAPIPowerShellManagement.psm1'
# Version number of this module.
ModuleVersion = '3.9.7'
ModuleVersion = '3.10.3'
# Supported PSEditions
# CompatiblePSEditions = @()
+53 -1
View File
@@ -85,7 +85,12 @@ function Initialize-CloudAPIManagement
[string]
$secret,
[string]
$certificate
$certificate,
[string]
$GraphEnvironment,
[string]
$GCCType
)
$PSModuleAutoloadingPreference = "none"
@@ -102,10 +107,57 @@ function Initialize-CloudAPIManagement
if($tenantId)
{
Write-Host "Using Tenant Id: $tenantId"
$global:AzureAppId = $appId
$global:ClientSecret = $secret
$global:ClientCert = $certificate
$global:UseGraphEnvironment = $GraphEnvironment
$global:UseGCCType = $GCCType
if($global:AzureAppId)
{
Write-Host "Using Azure App Id: $($global:AzureAppId)"
}
else
{
Write-Warning "Azure App Id is missing. Use -AppId <AppID> on the command line"
}
if($global:ClientSecret -or $global:ClientCert)
{
if($global:ClientSecret)
{
Write-Host "Using Azure App Secret"
}
else
{
Write-Host "Using Azure App Certificate"
}
}
else
{
Write-Warning "Azure App Secret or Certificate is missing. Use -Secret <Secret> or -Certificate <Certificate> on the command line"
}
if($global:UseGraphEnvironment)
{
Write-Host "Using Azure Graph Environment: $($global:UseGraphEnvironment)"
}
if($global:UseGCCType)
{
Write-Host "Using Graph Environment type: $($global:UseGCCType)"
}
}
elseif($secret)
{
$global:ClientSecret = $secret
}
if($certificate)
{
$global:ClientCert = $certificate
}
if($global:hideUI -ne $true)
{
+67 -9
View File
@@ -86,9 +86,13 @@ function Start-CoreApp
Write-Log "#####################################################################################"
Write-Log "PowerShell version: $($PSVersionTable.PSVersion.ToString())"
Write-Log "PowerShell build: $($PSVersionTable.BuildVersion.ToString())"
Write-Log "PowerShell CLR: $($PSVersionTable.CLRVersion.ToString())"
Write-Log "PowerShell edition: $($PSVersionTable.PSEdition)"
if($PSVersionTable.BuildVersion) {
Write-Log "PowerShell build: $($PSVersionTable.BuildVersion.ToString())"
}
if($PSVersionTable.CLRVersion) {
Write-Log "PowerShell CLR: $($PSVersionTable.CLRVersion.ToString())"
}
Write-Log "PowerShell edition: $($PSVersionTable.PSEdition)"
try
{
@@ -344,6 +348,14 @@ function Write-LogError
}
Write-Log $Text 3
if((Get-SettingValue "ShowStackTrace") -eq $true)
{
Write-Log "Stack trace:`n $($Exception.StackTrace)"
Write-Log "Script stack trace:`n $($Exception.ScriptStackTrace)"
}
}
function Write-Status
@@ -1069,7 +1081,7 @@ function Get-Folder
{
if($global:WindowsAPICodePackLoaded -eq $false)
{
$apiCodec = Join-Path $global:AppRootFolder "Microsoft.WindowsAPICodePack.Shell.dll"
$apiCodec = Join-Path $global:AppRootFolder "Bin\Microsoft.WindowsAPICodePack.Shell.dll"
if([IO.File]::Exists($apiCodec))
{
Add-Type -Path $apiCodec | Out-Null
@@ -1100,7 +1112,7 @@ function Get-Folder
{
$dlgCOFD.InitialDirectory = $path
}
if($dlgCOFD.ShowDialog($window) = [Microsoft.WindowsAPICodePack.Dialogs.CommonFileDialogResult]::Ok)
if($dlgCOFD.ShowDialog($window) -eq [Microsoft.WindowsAPICodePack.Dialogs.CommonFileDialogResult]::Ok)
{
$dlgCofd.FileName
}
@@ -1398,7 +1410,7 @@ function Remove-Setting
try
{
$temp = Get-Item -LiteralPath $regPath -ErrorAction SilentlyContinue
if(($temp.Property -contains $Key))
if(($temp -and $temp.Property -contains $Key))
{
Remove-ItemProperty -Path $regPath -Name $Key -Force -ErrorAction Stop
}
@@ -1412,7 +1424,7 @@ function Remove-Setting
function Get-Setting
{
param($SubPath = "", $Key = "", $defautValue)
param($SubPath = "", $Key = "", $defaultValue)
if(-not $key)
{
@@ -1477,7 +1489,7 @@ function Get-Setting
if(-not $val)
{
$defautValue
$defaultValue
}
else
{
@@ -1700,7 +1712,11 @@ function Add-SettingsItem
{
if($settingValue.Description)
{
$descriptionInfo = "<Rectangle Style=`"{DynamicResource InfoIcon}`" ToolTip=`"$($settingValue.Description)`" Margin=`"5,0,0,0`" />"
$descriptionInfo = "<Rectangle Style=`"{DynamicResource InfoIcon}`" Margin=`"5,0,0,0`">" +
"<Rectangle.ToolTip><TextBlock>" +
$settingValue.Description +
"</TextBlock></Rectangle.ToolTip>" +
"</Rectangle>"
}
$xaml = @"
@@ -1990,6 +2006,14 @@ function Add-DefaultSettings
DefaultValue = $true
}) "General"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Show stack error"
Key = "ShowStackTrace"
Type = "Boolean"
Description = "Write exception stack trace info to the log."
DefaultValue = $false
}) "General"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Debug"
Key = "Debug"
@@ -2737,6 +2761,27 @@ function Format-XML
$StringWriter.ToString()
}
function Update-XmlFormatting {
[CmdletBinding()]
param(
[Parameter(Mandatory, ValueFromPipeline)]
[string]$Xml
)
process {
$Xml = $Xml -replace '<([^\s/>]+)([^>]*)\s/>' , '<$1$2/>'
$Xml = ($Xml -split "`r?`n") |
Where-Object { $_.Trim().Length -gt 0 } |
ForEach-Object { $_ } |
Out-String
$Xml = $Xml -replace "`r`n", "`n"
return $Xml.Trim()
}
}
function Show-LogView
{
if($script:LogViewObject -and -not $script:LogViewObject.ViewPanel)
@@ -2890,6 +2935,19 @@ function Get-DataGridValues
($dataGrid.ItemsSource | Select -Property $properties)
}
function Get-GUIDs
{
param($text)
$regExpGuid = "[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}"
$uniqueGuids = New-Object System.Collections.Generic.HashSet[String]
# Use regular expressions to extract the GUIDs
[regex]::Matches($text, $regExpGuid) | ForEach-Object { $uniqueGuids.Add($_.Value) | Out-Null }
$uniqueGuids
}
New-Alias -Name ?? -value Invoke-Coalesce
New-Alias -Name ?: -value Invoke-IfTrue
+69
View File
@@ -101,6 +101,75 @@ The json files contains a definition of each property to document. This includes
The `DocumentationCustom.psm1` file also takes care of custom documentation for some object types e.g. Conditional Access. App Configuration policies etc. These objects are documented via a PowerShell function in the script.
**dataTypes Reference**
The following `dataType` values are supported in property-based ObjectInfo json files:
| Value | Name | Description |
|---|---|---|
| `0` | Boolean | Translated via the `booleanActions` field |
| `1` | Base64 | Certificate or binary data decoded to a UTF-8 string; filename used if `filenameEntityKey` is set |
| `2` | Multiline String | Multiline text or XML decoded from Base64 if needed; stored to a payload file if `filenameEntityKey` is set |
| `3` | Image | Binary image; outputs "Image file" when a value is present |
| `4` | Linked Certificate | Certificate resolved via OData navigation link |
| `5` | Complex Options | Iterates child `complexOptions` as a sub-section |
| `6` | Complex Option (sub-property) | Iterates `complexOptions` resolved via `entityKey` sub-property |
| `7` | OMA DateTime | Raw OMA DateTime string |
| `8` | Sub-category | Sets the current sub-category label from `nameResourceKey` |
| `9` | Label / OData Type | Skipped — UI label or `@odata.type` property |
| `10` | Information Box | Skipped — UI-only information box |
| `11` | App Picker | Application picker |
| `12` | Multiline String Array | Array of strings joined with the object separator |
| `13` | Multi Option | Multiple selection; translated via `Invoke-TranslateMultiOption` |
| `14` | Int32 | 32-bit integer |
| `15` | Int64 | 64-bit integer |
| `16` | Option | Single-select option; translated via `Invoke-TranslateOption` |
| `19` | Option (variant) | Single-select option; translated via `Invoke-TranslateOption` |
| `20` | String | Plain string |
| `21` | Table | Sub-table; translated via `Invoke-TranslateTable` |
| `22` | Scale Value | Numeric value combined with a unit from `scaleOptions` (e.g. "4 Years") |
| `99` | Reserved | No-op placeholder |
| `100` | Duration | Custom `Edm.Duration` formatting via `Invoke-TranslateDuration` |
| `101` | Static Label | Language string taken from the `value` field |
| `102` | Culture Name | Language/culture name string |
| `103` | Boolean (hide on false) | Boolean via `booleanActions`; hides child properties when `false` |
| `104` | Multi Option Boolean | Multi-option via boolean; hides children when `false` |
| `105` | Multi Option Boolean (inverted) | Like `104` but treats `false` as the selected state |
| `106` | Language Array | Array of culture/language names joined with the object separator |
| `107` | Static Value | Literal string taken directly from the `value` field |
| `108` | String with Format | String formatted using the `formatStringKey` language template |
| `200` | Multi Option (language key) | Translated string looked up via `entityKey` as a language string ID |
**booleanActions Reference**
The `booleanActions` field controls the text shown for `true`/`false` values when `dataType` is `0`, `103`, `104`, or `105`.
Values `0`–`9` and `107`–`108` only display a custom label when `true`; a `false` value falls through to *Not Configured*.
| Value | `true` → | `false` → |
|---|---|---|
| `0` | Allow | *(Not Configured)* |
| `1` | Require | *(Not Configured)* |
| `2` | Enable | *(Not Configured)* |
| `3` | Block | *(Not Configured)* |
| `4` | Configured | *(Not Configured)* |
| `5` | Disable | *(Not Configured)* |
| `6` | Limit | *(Not Configured)* |
| `7` | Show | *(Not Configured)* |
| `8` | Hide | *(Not Configured)* |
| `9` | Yes | *(Not Configured)* |
| `100` | Block | Allow |
| `101` | Require | Not Required |
| `102` | Enable | Disable |
| `107` | Show | *(Not Configured)* |
| `108` | Hide | *(Not Configured)* |
| `109` | Yes | No |
| `110` | No | Yes |
| `120` | On | Off |
| `200` | Allow | Block |
| `201` | Not Required | Require |
| `220` | Off | On |
**Language Support**
The Settings based objects get their language strings from Graph APIs with a few exceptions.
+3 -1
View File
@@ -151,5 +151,7 @@
"149": "WiredNetwork",
"150": "DefenderAntivirus",
"151": "CustomCompliance",
"152": "IosDefenderAtp"
"152": "IosDefenderAtp",
"153": "WSLCompliance",
"154": "WindowsZtdns"
}
+28 -1
View File
@@ -314,6 +314,15 @@
]
},
{
"ObjectType": "#microsoft.graph.androidWorkProfileMigrationConfiguration",
"PolicyType": "AndroidForWorkMigrationPolicy",
"PolicyTypeLanguageId": "androidForWorkMigrationPolicy",
"PlatformLanguageId": "AndroidForWork",
"Categories": [
]
},
{
"ObjectType": "#microsoft.graph.androidForWorkVpnConfiguration",
"PolicyType": "AndroidForWorkVpn",
@@ -470,7 +479,7 @@
]
},
{
"ObjectType": "#microsoft.graph.hardwareConfiguration",
"ObjectType": "#microsoft.graph.hardwareConfigurations",
"PolicyType": "HardwareConfigurations",
"PolicyTypeLanguageId": "hardwareConfigurations",
"PlatformLanguageId": "Windows10",
@@ -625,6 +634,15 @@
]
},
{
"ObjectType": "#microsoft.graph.iosWiredNetworkConfiguration",
"PolicyType": "IosWiredNetwork",
"PolicyTypeLanguageId": "wiredNetwork",
"PlatformLanguageId": "Ios",
"Categories": [
]
},
{
"ObjectType": "#microsoft.graph.iosEnterpriseWiFiConfiguration",
"PolicyType": "IosWiFi",
@@ -1197,6 +1215,15 @@
"HealthMonitoring"
]
},
{
"ObjectType": "#microsoft.graph.windowsZtdnsConfiguration",
"PolicyType": "Windows10Ztdns",
"PolicyTypeLanguageId": "windowsZeroTrustDns",
"PlatformLanguageId": "Windows10",
"Categories": [
]
},
{
"ObjectType": "#microsoft.graph.windows10XWifiConfiguration",
"PolicyType": "Windows10XWifi",
+108 -6
View File
@@ -856,20 +856,122 @@
},
"complexOptions": [
{
"nameResourceKey": "Win32Program.installCommand",
"nameResourceKey": "Win32Program.installerTypeText",
"descriptionResourceKey": "",
"entityKey": "installCommandLine",
"entityKey": "installerType",
"dataType": 20,
"booleanActions": 0,
"category": "Win32Program.selectorLabel"
"category": "Win32Program.selectorLabel",
"Children": [
{
"nameResourceKey": "Win32Program.installCommand",
"descriptionResourceKey": "",
"entityKey": "installCommandLine",
"dataType": 20,
"booleanActions": 0,
"category": "Win32Program.selectorLabel",
"Condition": {
"Expressions": [
{
"property": "installCommandLine"
}
]
}
},
{
"nameResourceKey": "Win32Program.installScript",
"descriptionResourceKey": "",
"entityKey": "activeInstallScript",
"dataType": 6,
"booleanActions": 0,
"category": "Win32Program.selectorLabel",
"complexOptions": [
{
"nameResourceKey": "TableHeaders.scriptName",
"descriptionResourceKey": "",
"entityKey": "scriptName",
"dataType": 20,
"booleanActions": 0,
"category": "Win32Program.selectorLabel"
},
{
"nameResourceKey": "Win32Requirements.AdditionalRequirements.Script.enforceSignatureCheck",
"descriptionResourceKey": "Win32Requirements.AdditionalRequirements.Script.enforceSignatureCheckTooltip",
"entityKey": "enforceSignatureCheck",
"dataType": 0,
"booleanActions": 109,
"category": "Win32Program.selectorLabel"
},
{
"nameResourceKey": "DetectionRules.CustomScript.runAs32Bit",
"descriptionResourceKey": "DetectionRules.CustomScript.runAs32BitTooltip",
"entityKey": "runAs32Bit",
"dataType": 0,
"booleanActions": 109,
"category": "Win32Program.selectorLabel"
}
]
}
]
},
{
"nameResourceKey": "Win32Program.uninstallCommand",
"nameResourceKey": "Win32Program.uninstallerTypeText",
"descriptionResourceKey": "",
"entityKey": "uninstallCommandLine",
"entityKey": "uninstallerType",
"dataType": 20,
"booleanActions": 0,
"category": "Win32Program.selectorLabel"
"category": "Win32Program.selectorLabel",
"Children": [
{
"nameResourceKey": "Win32Program.uninstallCommand",
"descriptionResourceKey": "",
"entityKey": "uninstallCommandLine",
"dataType": 20,
"booleanActions": 0,
"category": "Win32Program.selectorLabel",
"Condition": {
"Expressions": [
{
"property": "uninstallCommandLine"
}
]
}
},
{
"nameResourceKey": "Win32Program.uninstallScript",
"descriptionResourceKey": "",
"entityKey": "activeUninstallScript",
"dataType": 6,
"booleanActions": 0,
"category": "Win32Program.selectorLabel",
"complexOptions": [
{
"nameResourceKey": "TableHeaders.scriptName",
"descriptionResourceKey": "",
"entityKey": "scriptName",
"dataType": 20,
"booleanActions": 0,
"category": "Win32Program.selectorLabel"
},
{
"nameResourceKey": "Win32Requirements.AdditionalRequirements.Script.enforceSignatureCheck",
"descriptionResourceKey": "Win32Requirements.AdditionalRequirements.Script.enforceSignatureCheckTooltip",
"entityKey": "enforceSignatureCheck",
"dataType": 0,
"booleanActions": 109,
"category": "Win32Program.selectorLabel"
},
{
"nameResourceKey": "DetectionRules.CustomScript.runAs32Bit",
"descriptionResourceKey": "DetectionRules.CustomScript.runAs32BitTooltip",
"entityKey": "runAs32Bit",
"dataType": 0,
"booleanActions": 109,
"category": "Win32Program.selectorLabel"
}
]
}
]
},
{
"nameResourceKey": "",
@@ -0,0 +1,34 @@
[
{
"nameResourceKey": "TableHeaders.configurationType",
"descriptionResourceKey": "",
"entityKey": "PolicyType.hardwareConfigurations",
"dataType": 200,
"booleanActions": 0,
"category": 1000
},
{
"nameResourceKey": "HardwareConfig.Settings.Tab.Configurations.hardware",
"descriptionResourceKey": "",
"entityKey": "vendor",
"dataType": 20,
"booleanActions": 0,
"category": "SettingDetails.configurations"
},
{
"nameResourceKey": "HardwareConfig.Settings.Tab.Configurations.perDevicePassword",
"descriptionResourceKey": "",
"entityKey": "perDevicePasswordDisabled",
"dataType": 109,
"booleanActions": 9,
"category": "SettingDetails.configurations"
},
{
"nameResourceKey": "HardwareConfig.Settings.Tab.Configurations.file",
"descriptionResourceKey": "",
"entityKey": "fileName",
"dataType": 20,
"booleanActions": 0,
"category": "SettingDetails.configurations"
}
]
@@ -11,89 +11,123 @@
"nameResourceKey": "EnrollmentStatusScreen.progressToggle",
"descriptionResourceKey": "",
"entityKey": "showInstallationProgress",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.timeout",
"descriptionResourceKey": "",
"entityKey": "installProgressTimeoutInMinutes",
"dataType": 14,
"booleanActions": 0,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.customMessageToggle",
"descriptionResourceKey": "",
"entityKey": "showCustomErrorMessage",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.customMessageTextBox",
"descriptionResourceKey": "",
"entityKey": "customErrorMessage",
"dataType": 20,
"booleanActions": 0,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.collectLogToggle",
"descriptionResourceKey": "",
"entityKey": "allowLogCollectionOnInstallFailure",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.enableForAutopilotOnlyToggle",
"descriptionResourceKey": "",
"entityKey": "trackInstallProgressForAutopilotOnly",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.blockToggle",
"descriptionResourceKey": "",
"entityKey": "blockDeviceSetupRetryByUser",
"dataType": 16,
"booleanActions": 0,
"booleanActions": 109,
"category": "TableHeaders.settings",
"options": [
{
"nameResourceKey": "SettingDetails.no",
"value": "true"
"value": "false"
},
{
"nameResourceKey": "BooleanActions.yes",
"value": "false",
"value": "true",
"Children": [
{
"nameResourceKey": "EnrollmentStatusScreen.resetToggle",
"nameResourceKey": "EnrollmentStatusScreen.timeout",
"descriptionResourceKey": "",
"entityKey": "allowDeviceResetOnInstallFailure",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.allowToUseToggle",
"descriptionResourceKey": "",
"entityKey": "allowDeviceUseOnInstallFailure",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.Apps.useSelectedAppsToggleLabel",
"descriptionResourceKey": "",
"entityKey": "waitForApps",
"entityKey": "InstallProgressTimeout",
"dataType": 14,
"booleanActions": 0,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.customMessageToggle",
"descriptionResourceKey": "",
"entityKey": "showCustomErrorMessage",
"dataType": 16,
"booleanActions": 109,
"category": "TableHeaders.settings",
"options": [
{
"nameResourceKey": "SettingDetails.no",
"value": "false"
},
{
"nameResourceKey": "BooleanActions.yes",
"value": "true",
"Children": [
{
"nameResourceKey": "EnrollmentStatusScreen.customMessageTextBox",
"descriptionResourceKey": "",
"entityKey": "customErrorMessage",
"dataType": 20,
"booleanActions": 0,
"category": "TableHeaders.settings"
}
]
}
]
},
{
"nameResourceKey": "EnrollmentStatusScreen.collectLogToggle",
"descriptionResourceKey": "",
"entityKey": "allowLogCollectionOnInstallFailure",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.enableForAutopilotOnlyToggle",
"descriptionResourceKey": "",
"entityKey": "trackInstallProgressForAutopilotOnly",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.blockToggle",
"descriptionResourceKey": "",
"entityKey": "blockDeviceSetupRetryByUser",
"dataType": 16,
"booleanActions": 0,
"category": "TableHeaders.settings",
"options": [
{
"nameResourceKey": "SettingDetails.no",
"value": "true"
},
{
"nameResourceKey": "BooleanActions.yes",
"value": "false",
"Children": [
{
"nameResourceKey": "EnrollmentStatusScreen.resetToggle",
"descriptionResourceKey": "",
"entityKey": "allowDeviceResetOnInstallFailure",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.allowToUseToggle",
"descriptionResourceKey": "",
"entityKey": "allowDeviceUseOnInstallFailure",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
},
{
"nameResourceKey": "EnrollmentStatusScreen.Apps.useSelectedAppsToggleLabel",
"descriptionResourceKey": "",
"entityKey": "waitForApps",
"dataType": 14,
"booleanActions": 0,
"category": "TableHeaders.settings",
"Children": [
{
"nameResourceKey": "EnrollmentStatusScreen.Apps.allowNonBlockingAppInstallation",
"descriptionResourceKey": "",
"entityKey": "allowNonBlockingAppInstallation",
"dataType": 0,
"booleanActions": 109,
"category": "TableHeaders.settings"
}
]
}
]
}
]
}
]
}
@@ -85,32 +85,48 @@
"enabled": true
},
{
"dataType": 0,
"dataType": 16,
"category": 2,
"nameResourceKey": "publicPlayStoreEnabledName",
"descriptionResourceKey": "publicPlayStoreEnabledDescription",
"childSettings": [
{
"dataType": 10,
"category": 2,
"nameResourceKey": "publicPlayStoreEnabledWarning",
"childSettings": [
],
"options": [
],
"options": [
{
"nameResourceKey": "publicPlayStoreSelectionNotConfigured",
"value": "notConfigured",
"enabled": true
},
{
"nameResourceKey": "publicPlayStoreSelectionAllowList",
"value": "allowList",
"enabled": true
},
{
"nameResourceKey": "publicPlayStoreSelectionBlockList",
"value": "blockList",
"enabled": true
}
],
"entityKey": "playStoreMode",
"booleanActions": 0,
"defaultValue": "notConfigured",
"unconfiguredValue": "notConfigured",
"policyType": 2,
"enabled": true
},
{
"dataType": 10,
"category": 2,
"nameResourceKey": "publicPlayStoreEnabledWarning",
"childSettings": [
],
"booleanActions": 0,
"policyType": 2,
"enabled": true
}
],
"options": [
],
"entityKey": "publicPlayStoreEnabled",
"booleanActions": 0,
"defaultValue": false,
"policyType": 2,
"enabled": true
},
@@ -1,14 +1,31 @@
{
"customcompliance_compliancewindows10": {
"dataType": 25,
"dataType": 0,
"category": 151,
"nameResourceKey": "AdminConfiguredComplianceSettingName",
"descriptionResourceKey": "CustomComplianceToolTip",
"childSettings": [
{
"dataType": 25,
"category": 151,
"childSettings": [
],
"options": [
],
"entityKey": "customCompliance",
"booleanActions": 0,
"policyType": 35,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"entityKey": "customComplianceRequired",
"booleanActions": 1,
"defaultValue": false,
"policyType": 35,
"enabled": true
}
File diff suppressed because it is too large Load Diff
@@ -1,5 +1,22 @@
{
"devicehealth_complianceandroiddeviceowner": [
{
"dataType": 0,
"category": 39,
"nameResourceKey": "complianceRootedAllowedName",
"descriptionResourceKey": "complianceRootedAllowedDescription",
"childSettings": [
],
"options": [
],
"entityKey": "securityBlockJailbrokenDevices",
"booleanActions": 3,
"defaultValue": false,
"policyType": 31,
"enabled": true
},
{
"dataType": 16,
"category": 39,
@@ -12,7 +12,7 @@
"dataType": 16,
"category": 42,
"nameResourceKey": "requiredPasswordTypeName",
"descriptionResourceKey": "androidEnterpriseRequiredPasswordTypeDescription",
"descriptionResourceKey": "androidEnterpriseConfigurationRequiredPasswordTypeDescription",
"emptyValueResourceKey": "passwordExpirationInDaysEmptyValueKey",
"childSettings": [
@@ -4,7 +4,7 @@
"dataType": 16,
"category": 42,
"nameResourceKey": "requiredPasswordTypeName",
"descriptionResourceKey": "androidEnterpriseRequiredPasswordTypeDescription",
"descriptionResourceKey": "aospConfigurationRequiredPasswordTypeDescription",
"emptyValueResourceKey": "passwordExpirationInDaysEmptyValueKey",
"childSettings": [
@@ -1150,8 +1150,8 @@
"showAsSectionHeader": true,
"dataType": 8,
"category": 44,
"nameResourceKey": "dedicatedAndroidEnrollmentTypesHeaderName",
"descriptionResourceKey": "dedicatedAndroidEnrollmentTypesHeaderDescription",
"nameResourceKey": "fullyManagedAndDedicatedAndroidEnrollmentTypesWithKioskHeaderName",
"descriptionResourceKey": "fullyManagedAndDedicatedAndroidEnrollmentTypesWithKioskHeaderDescription",
"childSettings": [
{
"dataType": 0,
@@ -1267,7 +1267,23 @@
"defaultValue": false,
"policyType": 2,
"enabled": false
},
}
],
"options": [
],
"booleanActions": 0,
"policyType": 2,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": true,
"dataType": 8,
"category": 44,
"nameResourceKey": "dedicatedAndroidEnrollmentTypesHeaderName",
"descriptionResourceKey": "dedicatedAndroidEnrollmentTypesHeaderDescription",
"childSettings": [
{
"dataType": 0,
"category": 44,
@@ -105,8 +105,8 @@
{
"dataType": 16,
"category": 44,
"nameResourceKey": "WifiTypeName",
"descriptionResourceKey": "WiFiTypeDescription",
"nameResourceKey": "wiFiPolicySecurityTypeName",
"descriptionResourceKey": "wiFiPolicySecurityTypeDescription",
"childSettings": [
],
@@ -274,7 +274,7 @@
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 9,
"enabled": true
},
@@ -1421,7 +1421,7 @@
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 9,
"enabled": true
},
@@ -1,36 +1,64 @@
{
"importedpfx_macimportedpfx": {
"dataType": 16,
"category": 69,
"nameResourceKey": "PFXImportPolicyIntendedPurpose",
"descriptionResourceKey": "empty",
"childSettings": [
"importedpfx_macimportedpfx": [
{
"dataType": 16,
"category": 69,
"nameResourceKey": "MacOSDeploymentChannelName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "notConfigured",
"enabled": true
},
{
"nameResourceKey": "PFXImportPolicyIntendedPurposeUnassigned",
"value": "unassigned",
"enabled": true
},
{
"nameResourceKey": "PFXImportPolicyIntendedPurposeSmimeEncryption",
"value": "smimeEncryption",
"enabled": true
},
{
"nameResourceKey": "PFXImportPolicyIntendedPurposeSmimeSigning",
"value": "smimeSigning",
"enabled": true
}
],
"entityKey": "intendedPurpose",
"booleanActions": 0,
"policyType": 62,
"enabled": true
}
],
"options": [
{
"nameResourceKey": "MacOSDeploymentChannelUserChannel",
"value": "userChannel",
"enabled": true
},
{
"nameResourceKey": "MacOSDeploymentChannelDeviceChannel",
"value": "deviceChannel",
"enabled": true
}
],
"entityKey": "deploymentChannel",
"booleanActions": 0,
"defaultValue": "deviceChannel",
"policyType": 62,
"enabled": true
},
{
"dataType": 16,
"category": 69,
"nameResourceKey": "PFXImportPolicyIntendedPurpose",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "notConfigured",
"enabled": true
},
{
"nameResourceKey": "PFXImportPolicyIntendedPurposeUnassigned",
"value": "unassigned",
"enabled": true
},
{
"nameResourceKey": "PFXImportPolicyIntendedPurposeSmimeEncryption",
"value": "smimeEncryption",
"enabled": true
},
{
"nameResourceKey": "PFXImportPolicyIntendedPurposeSmimeSigning",
"value": "smimeSigning",
"enabled": true
}
],
"entityKey": "intendedPurpose",
"booleanActions": 0,
"policyType": 62,
"enabled": true
}
]
}
@@ -1,36 +1,5 @@
{
"password_androidgeneral": [
{
"dataType": 0,
"category": 90,
"nameResourceKey": "requireEncryptionName",
"descriptionResourceKey": "requireEncryptionDescription",
"childSettings": [
],
"options": [
],
"entityKey": "storageRequireDeviceEncryption",
"booleanActions": 1,
"defaultValue": false,
"policyType": 20,
"enabled": true
},
{
"dataType": 10,
"category": 90,
"nameResourceKey": "androidTenDeprecationInfoBox",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 20,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": true,
@@ -62,6 +31,23 @@
"policyType": 20,
"enabled": true
},
{
"dataType": 0,
"category": 90,
"nameResourceKey": "knoxRequireEncryptionName",
"descriptionResourceKey": "requireEncryptionDescription",
"childSettings": [
],
"options": [
],
"entityKey": "storageRequireDeviceEncryption",
"booleanActions": 1,
"defaultValue": false,
"policyType": 20,
"enabled": true
},
{
"dataType": 16,
"category": 90,
@@ -203,14 +189,14 @@
"showAsSectionHeader": true,
"dataType": 8,
"category": 90,
"nameResourceKey": "androidNineAndBelowPasswordHeader",
"nameResourceKey": "knoxFifteenAndroidNineAndBelowPasswordHeader",
"childSettings": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 90,
"nameResourceKey": "androidNineAndBelowPasswordHeaderDescription",
"nameResourceKey": "knoxFifteenAndroidNineAndBelowPasswordHeaderDescription",
"childSettings": [
],
@@ -438,7 +438,7 @@
"dataType": 4,
"category": 93,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -412,7 +412,7 @@
"dataType": 4,
"category": 93,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -279,7 +279,7 @@
"dataType": 4,
"category": 93,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -438,7 +438,7 @@
"dataType": 4,
"category": 93,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
+615 -319
View File
@@ -1,373 +1,669 @@
{
"pkcs_macospkcs": [
{
"dataType": 14,
"category": 93,
"nameResourceKey": "sCEPPolicyRenewalThresholdName",
"descriptionResourceKey": "sCEPPolicyRenewalThresholdDescription",
"childSettings": [
"pkcs_macospkcs": {
"dataType": 16,
"category": 93,
"nameResourceKey": "MacOSDeploymentChannelName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"options": [
{
"nameResourceKey": "MacOSDeploymentChannelUserChannel",
"value": "userChannel",
"children": [
{
"dataType": 14,
"category": 93,
"nameResourceKey": "sCEPPolicyRenewalThresholdName",
"descriptionResourceKey": "sCEPPolicyRenewalThresholdDescription",
"childSettings": [
],
"entityKey": "renewalThresholdPercentage",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"scaleOptions": [
{
"nameResourceKey": "days",
"value": "days",
"enabled": true
},
{
"nameResourceKey": "months",
"value": "months",
"enabled": true
},
{
"nameResourceKey": "years",
"value": "years",
"enabled": true
}
],
"scaleEntityKey": "certificateValidityPeriodScale",
"defaultScale": "years",
"dataType": 22,
"category": 93,
"nameResourceKey": "sCEPPolicyCertificateValidityPeriodName",
"descriptionResourceKey": "sCEPPolicyCertificateValidityPeriodDescription",
"childSettings": [
],
"options": [
],
"options": [
],
"entityKey": "renewalThresholdPercentage",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"scaleOptions": [
{
"nameResourceKey": "days",
"value": "days",
"enabled": true
},
{
"nameResourceKey": "months",
"value": "months",
"enabled": true
},
{
"nameResourceKey": "years",
"value": "years",
"enabled": true
}
],
"scaleEntityKey": "certificateValidityPeriodScale",
"defaultScale": "years",
"dataType": 22,
"category": 93,
"nameResourceKey": "sCEPPolicyCertificateValidityPeriodName",
"descriptionResourceKey": "sCEPPolicyCertificateValidityPeriodDescription",
"childSettings": [
],
"entityKey": "certificateValidityPeriodValue",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificationAuthorityName",
"descriptionResourceKey": "pKCSPolicyCertificationAuthorityNameDescription",
"childSettings": [
],
"options": [
],
"options": [
],
"entityKey": "certificateValidityPeriodValue",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificationAuthorityName",
"descriptionResourceKey": "pKCSPolicyCertificationAuthorityNameDescription",
"childSettings": [
],
"entityKey": "certificationAuthority",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificationAuthorityNameName",
"descriptionResourceKey": "pKCSPolicyCertificationAuthorityNameNameDescription",
"childSettings": [
],
"options": [
],
"options": [
],
"entityKey": "certificationAuthority",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificationAuthorityNameName",
"descriptionResourceKey": "pKCSPolicyCertificationAuthorityNameNameDescription",
"childSettings": [
],
"entityKey": "certificationAuthorityName",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificateTemplateNameName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"options": [
],
"entityKey": "certificationAuthorityName",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificateTemplateNameName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"entityKey": "certificateTemplateName",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 16,
"category": 93,
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"options": [
{
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreUser",
"value": "user",
"children": [
{
"value": "custom",
"dataType": 9,
"category": 93,
"childSettings": [
],
"entityKey": "certificateTemplateName",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 16,
"category": 93,
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormat",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "SCEPPolicySubjectNameFormatName",
"descriptionResourceKey": "sCEPPolicyCustomSubjectNameWithAadFormatDescription",
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormatString",
"booleanActions": 0,
"defaultValue": "CN={{UserName}},E={{EmailAddress}}",
"policyType": 64,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 16,
],
"options": [
{
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreUser",
"value": "user",
"children": [
{
"value": "custom",
"dataType": 9,
"category": 93,
"nameResourceKey": "attribute",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "PolicyEmailAddress",
"value": "emailAddress",
"enabled": true
},
{
"nameResourceKey": "PolicyUserPrincipalName",
"value": "userPrincipalName",
"enabled": true
},
{
"nameResourceKey": "PolicyDomainNameService",
"value": "domainNameService",
"enabled": true
},
{
"nameResourceKey": "PolicyUniversalResourceIdentifier",
"value": "universalResourceIdentifier",
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyCustomAADAttribute",
"value": "customAzureADAttribute",
"enabled": true
}
],
"entityKey": "sanType",
"entityKey": "subjectNameFormat",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
},
{
"metadata": {
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "value",
"descriptionResourceKey": "empty",
"nameResourceKey": "SCEPPolicySubjectNameFormatName",
"descriptionResourceKey": "sCEPPolicyCustomSubjectNameWithAadFormatDescription",
"childSettings": [
],
"options": [
],
"entityKey": "name",
"entityKey": "subjectNameFormatString",
"booleanActions": 0,
"defaultValue": "CN={{UserName}},E={{EmailAddress}}",
"policyType": 64,
"enabled": true
}
}
],
"dataType": 21,
"category": 93,
"nameResourceKey": "PolicySubjectAlternativeName",
"descriptionResourceKey": "PolicySubjectAlternativeNameDescription",
"childSettings": [
],
"options": [
],
"entityKey": "customSubjectAlternativeNames",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreMachine",
"value": "machine",
"children": [
{
"value": "custom",
"dataType": 9,
"category": 93,
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormat",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "sCEPPolicySubjectNameFormatName",
"descriptionResourceKey": "sCEPPolicySubjectNameFormatDescription",
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormatString",
"booleanActions": 0,
"defaultValue": "CN={{AAD_Device_ID}}",
"policyType": 64,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 16,
"category": 93,
"nameResourceKey": "attribute",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
},
{
"columns": [
{
"nameResourceKey": "PolicyEmailAddress",
"value": "emailAddress",
"enabled": true
"metadata": {
"dataType": 16,
"category": 93,
"nameResourceKey": "attribute",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "PolicyEmailAddress",
"value": "emailAddress",
"enabled": true
},
{
"nameResourceKey": "PolicyUserPrincipalName",
"value": "userPrincipalName",
"enabled": true
},
{
"nameResourceKey": "PolicyDomainNameService",
"value": "domainNameService",
"enabled": true
},
{
"nameResourceKey": "PolicyUniversalResourceIdentifier",
"value": "universalResourceIdentifier",
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyCustomAADAttribute",
"value": "customAzureADAttribute",
"enabled": true
}
],
"entityKey": "sanType",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
},
{
"nameResourceKey": "PolicyUserPrincipalName",
"value": "userPrincipalName",
"enabled": true
},
{
"nameResourceKey": "PolicyDomainNameService",
"value": "domainNameService",
"enabled": true
},
{
"nameResourceKey": "PolicyUniversalResourceIdentifier",
"value": "universalResourceIdentifier",
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyCustomAADAttribute",
"value": "customAzureADAttribute",
"enabled": true
"metadata": {
"dataType": 20,
"category": 93,
"nameResourceKey": "value",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "name",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
}
],
"entityKey": "sanType",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"dataType": 21,
"category": 93,
"nameResourceKey": "value",
"descriptionResourceKey": "empty",
"nameResourceKey": "PolicySubjectAlternativeName",
"descriptionResourceKey": "PolicySubjectAlternativeNameDescription",
"childSettings": [
],
"options": [
],
"entityKey": "name",
"entityKey": "customSubjectAlternativeNames",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
}
],
"dataType": 21,
"category": 93,
"nameResourceKey": "PolicySubjectAlternativeName",
"descriptionResourceKey": "PolicySubjectAlternativeNameDescription",
"childSettings": [
],
"enabled": true
}
],
"entityKey": "certificateStore",
"booleanActions": 0,
"defaultValue": "user",
"policyType": 64,
"enabled": true
},
{
"dataType": 0,
"category": 93,
"nameResourceKey": "MacOSAllowAllAppsAccess",
"descriptionResourceKey": "MacOSAllowAllAppsAccess",
"emptyValueResourceKey": "macOSAllowAllAppsAccessEmptyValueKey",
"childSettings": [
],
"options": [
],
"options": [
],
"entityKey": "customSubjectAlternativeNames",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "certificateStore",
"booleanActions": 0,
"defaultValue": "user",
"policyType": 64,
"enabled": true
},
{
"dataType": 0,
"category": 93,
"nameResourceKey": "MacOSAllowAllAppsAccess",
"descriptionResourceKey": "MacOSAllowAllAppsAccess",
"emptyValueResourceKey": "macOSAllowAllAppsAccessEmptyValueKey",
"childSettings": [
],
"entityKey": "allowAllAppsAccess",
"booleanActions": 2,
"policyType": 64,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "MacOSDeploymentChannelDeviceChannel",
"value": "deviceChannel",
"children": [
{
"dataType": 14,
"category": 93,
"nameResourceKey": "sCEPPolicyRenewalThresholdName",
"descriptionResourceKey": "sCEPPolicyRenewalThresholdDescription",
"childSettings": [
],
"options": [
],
"options": [
],
"entityKey": "allowAllAppsAccess",
"booleanActions": 2,
"policyType": 64,
"enabled": true
}
]
],
"entityKey": "renewalThresholdPercentage",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"scaleOptions": [
{
"nameResourceKey": "days",
"value": "days",
"enabled": true
},
{
"nameResourceKey": "months",
"value": "months",
"enabled": true
},
{
"nameResourceKey": "years",
"value": "years",
"enabled": true
}
],
"scaleEntityKey": "certificateValidityPeriodScale",
"defaultScale": "years",
"dataType": 22,
"category": 93,
"nameResourceKey": "sCEPPolicyCertificateValidityPeriodName",
"descriptionResourceKey": "sCEPPolicyCertificateValidityPeriodDescription",
"childSettings": [
],
"options": [
],
"entityKey": "certificateValidityPeriodValue",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificationAuthorityName",
"descriptionResourceKey": "pKCSPolicyCertificationAuthorityNameDescription",
"childSettings": [
],
"options": [
],
"entityKey": "certificationAuthority",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificationAuthorityNameName",
"descriptionResourceKey": "pKCSPolicyCertificationAuthorityNameNameDescription",
"childSettings": [
],
"options": [
],
"entityKey": "certificationAuthorityName",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "pKCSPolicyCertificateTemplateNameName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "certificateTemplateName",
"booleanActions": 0,
"defaultValue": "",
"policyType": 64,
"enabled": true
},
{
"dataType": 16,
"category": 93,
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreUser",
"value": "user",
"children": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 93,
"nameResourceKey": "MacOSDeploymentChannelWarningBanner",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"value": "custom",
"dataType": 9,
"category": 93,
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormat",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "SCEPPolicySubjectNameFormatName",
"descriptionResourceKey": "sCEPPolicyCustomSubjectNameWithAadFormatDescription",
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormatString",
"booleanActions": 0,
"defaultValue": "CN={{UserName}},E={{EmailAddress}}",
"policyType": 64,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 16,
"category": 93,
"nameResourceKey": "attribute",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "PolicyEmailAddress",
"value": "emailAddress",
"enabled": true
},
{
"nameResourceKey": "PolicyUserPrincipalName",
"value": "userPrincipalName",
"enabled": true
},
{
"nameResourceKey": "PolicyDomainNameService",
"value": "domainNameService",
"enabled": true
},
{
"nameResourceKey": "PolicyUniversalResourceIdentifier",
"value": "universalResourceIdentifier",
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyCustomAADAttribute",
"value": "customAzureADAttribute",
"enabled": true
}
],
"entityKey": "sanType",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 93,
"nameResourceKey": "value",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "name",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
}
],
"dataType": 21,
"category": 93,
"nameResourceKey": "PolicySubjectAlternativeName",
"descriptionResourceKey": "PolicySubjectAlternativeNameDescription",
"childSettings": [
],
"options": [
],
"entityKey": "customSubjectAlternativeNames",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyWindowsCertificateStoreMachine",
"value": "machine",
"children": [
{
"value": "custom",
"dataType": 9,
"category": 93,
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormat",
"booleanActions": 0,
"policyType": 64,
"enabled": true
},
{
"dataType": 20,
"category": 93,
"nameResourceKey": "sCEPPolicySubjectNameFormatName",
"descriptionResourceKey": "sCEPPolicySubjectNameFormatDescription",
"childSettings": [
],
"options": [
],
"entityKey": "subjectNameFormatString",
"booleanActions": 0,
"defaultValue": "CN={{AAD_Device_ID}}",
"policyType": 64,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 16,
"category": 93,
"nameResourceKey": "attribute",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "PolicyEmailAddress",
"value": "emailAddress",
"enabled": true
},
{
"nameResourceKey": "PolicyUserPrincipalName",
"value": "userPrincipalName",
"enabled": true
},
{
"nameResourceKey": "PolicyDomainNameService",
"value": "domainNameService",
"enabled": true
},
{
"nameResourceKey": "PolicyUniversalResourceIdentifier",
"value": "universalResourceIdentifier",
"enabled": true
},
{
"nameResourceKey": "SCEPPolicyCustomAADAttribute",
"value": "customAzureADAttribute",
"enabled": true
}
],
"entityKey": "sanType",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 93,
"nameResourceKey": "value",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "name",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
}
],
"dataType": 21,
"category": 93,
"nameResourceKey": "PolicySubjectAlternativeName",
"descriptionResourceKey": "PolicySubjectAlternativeNameDescription",
"childSettings": [
],
"options": [
],
"entityKey": "customSubjectAlternativeNames",
"booleanActions": 0,
"policyType": 64,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "certificateStore",
"booleanActions": 0,
"defaultValue": "machine",
"policyType": 64,
"enabled": true
},
{
"dataType": 0,
"category": 93,
"nameResourceKey": "MacOSAllowAllAppsAccess",
"descriptionResourceKey": "MacOSAllowAllAppsAccess",
"emptyValueResourceKey": "macOSAllowAllAppsAccessEmptyValueKey",
"childSettings": [
],
"options": [
],
"entityKey": "allowAllAppsAccess",
"booleanActions": 2,
"policyType": 64,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "deploymentChannel",
"booleanActions": 0,
"defaultValue": "deviceChannel",
"policyType": 64,
"enabled": true
}
}
@@ -492,7 +492,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -462,7 +462,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -239,7 +239,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -462,7 +462,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -558,7 +558,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
File diff suppressed because it is too large Load Diff
@@ -501,7 +501,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -501,7 +501,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -278,7 +278,7 @@
"dataType": 4,
"category": 103,
"nameResourceKey": "sCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "SCEPPolicySelectRootCertificateName",
"descriptionResourceKey": "sCEPPolicySelectRootCertificateDescription",
"childSettings": [
],
@@ -187,51 +187,6 @@
"policyType": 29,
"enabled": true
},
{
"dataType": 10,
"category": 113,
"nameResourceKey": "androidTenDeprecationInfoBox",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 29,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": true,
"dataType": 8,
"category": 113,
"nameResourceKey": "allAndroidVersionsPasswordHeader",
"childSettings": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 113,
"nameResourceKey": "allAndroidVersionsPasswordHeaderDescription",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 29,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 29,
"enabled": true
},
{
"dataType": 16,
"category": 113,
@@ -370,14 +325,14 @@
"showAsSectionHeader": true,
"dataType": 8,
"category": 113,
"nameResourceKey": "androidNineAndBelowPasswordHeader",
"nameResourceKey": "knoxFifteenAndroidNineAndBelowPasswordHeader",
"childSettings": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 113,
"nameResourceKey": "androidNineAndBelowPasswordHeaderDescription",
"nameResourceKey": "knoxFifteenAndroidNineAndBelowPasswordHeaderDescription",
"childSettings": [
],
@@ -33,7 +33,7 @@
"dataType": 16,
"category": 113,
"nameResourceKey": "requiredPasswordTypeName",
"descriptionResourceKey": "androidEnterpriseRequiredPasswordTypeDescription",
"descriptionResourceKey": "androidEnterpriseComplianceRequiredPasswordTypeDescription",
"emptyValueResourceKey": "passwordExpirationInDaysEmptyValueKey",
"childSettings": [
@@ -41,7 +41,7 @@
"dataType": 16,
"category": 113,
"nameResourceKey": "requiredPasswordTypeName",
"descriptionResourceKey": "androidEnterpriseRequiredPasswordTypeDescription",
"descriptionResourceKey": "aospComplianceRequiredPasswordTypeDescription",
"emptyValueResourceKey": "passwordExpirationInDaysEmptyValueKey",
"childSettings": [
@@ -1,20 +1,48 @@
{
"trustedcert_mactrustedcertificate": {
"dataEntityKey": "trustedRootCertificate",
"filenameEntityKey": "certFileName",
"dataType": 1,
"category": 115,
"nameResourceKey": "trustedCertPolicySelectCertificateName",
"descriptionResourceKey": "empty",
"childSettings": [
"trustedcert_mactrustedcertificate": [
{
"dataType": 16,
"category": 115,
"nameResourceKey": "MacOSDeploymentChannelName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"options": [
{
"nameResourceKey": "MacOSDeploymentChannelUserChannel",
"value": "userChannel",
"enabled": true
},
{
"nameResourceKey": "MacOSDeploymentChannelDeviceChannel",
"value": "deviceChannel",
"enabled": true
}
],
"entityKey": "deploymentChannel",
"booleanActions": 0,
"defaultValue": "deviceChannel",
"policyType": 65,
"enabled": true
},
{
"dataEntityKey": "trustedRootCertificate",
"filenameEntityKey": "certFileName",
"dataType": 1,
"category": 115,
"nameResourceKey": "trustedCertPolicySelectCertificateName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"entityKey": "trustedRootCertificate",
"booleanActions": 0,
"policyType": 65,
"enabled": true
}
],
"options": [
],
"entityKey": "trustedRootCertificate",
"booleanActions": 0,
"policyType": 65,
"enabled": true
}
]
}
File diff suppressed because it is too large Load Diff
@@ -4078,6 +4078,124 @@
"defaultValue": false,
"policyType": 19,
"enabled": true
},
{
"dataType": 16,
"category": 121,
"nameResourceKey": "wiFiPolicySecurityTypeName",
"descriptionResourceKey": "wiFiPolicySecurityTypeDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "notConfigured",
"enabled": true
},
{
"nameResourceKey": "openOption",
"value": "open",
"enabled": true
},
{
"nameResourceKey": "wEPPSKOption",
"value": "wep",
"children": [
{
"dataType": 20,
"category": 121,
"nameResourceKey": "preSharedKeyName",
"descriptionResourceKey": "preSharedKeyDescription",
"emptyValueResourceKey": "wifiPasswordExample",
"childSettings": [
],
"options": [
],
"entityKey": "preSharedKey",
"booleanActions": 0,
"policyType": 19,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "wPAPSKOption",
"value": "wpaPersonal",
"children": [
{
"dataType": 20,
"category": 121,
"nameResourceKey": "preSharedKeyName",
"descriptionResourceKey": "preSharedKeyDescription",
"emptyValueResourceKey": "wifiPasswordExample",
"childSettings": [
],
"options": [
],
"entityKey": "preSharedKey",
"booleanActions": 0,
"policyType": 19,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "wiFiSecurityType",
"booleanActions": 0,
"policyType": 19,
"enabled": true
},
{
"dataType": 16,
"category": 121,
"nameResourceKey": "wiFiPolicyProxySettingsName",
"descriptionResourceKey": "wiFiPolicyProxySettingsDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "noneOption",
"value": "none",
"enabled": true
},
{
"nameResourceKey": "automaticOption",
"value": "automatic",
"children": [
{
"dataType": 20,
"category": 121,
"nameResourceKey": "proxyServerURLName",
"descriptionResourceKey": "proxyServerURLDescription",
"emptyValueResourceKey": "proxyUrlExample",
"childSettings": [
],
"options": [
],
"entityKey": "proxyAutomaticConfigurationUrl",
"booleanActions": 0,
"policyType": 19,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "none",
"policyType": 19,
"enabled": true
}
],
"enabled": true
@@ -4954,7 +5072,7 @@
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 19,
"enabled": true
}
@@ -105,8 +105,8 @@
{
"dataType": 16,
"category": 121,
"nameResourceKey": "WifiTypeName",
"descriptionResourceKey": "WiFiTypeDescription",
"nameResourceKey": "wiFiPolicySecurityTypeName",
"descriptionResourceKey": "wiFiPolicySecurityTypeDescription",
"childSettings": [
],
@@ -274,7 +274,7 @@
"entityKey": "proxySetting",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 124,
"enabled": false
}
@@ -1106,7 +1106,7 @@
"entityKey": "proxySetting",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 124,
"enabled": false
}
+51 -3
View File
@@ -144,6 +144,54 @@
],
"enabled": true
},
{
"nameResourceKey": "wPA2PersonalOption",
"value": "wpa2Personal",
"children": [
{
"dataType": 20,
"category": 121,
"nameResourceKey": "preSharedKeyName",
"descriptionResourceKey": "preSharedKeyDescription",
"emptyValueResourceKey": "wifiPasswordExample",
"childSettings": [
],
"options": [
],
"entityKey": "preSharedKey",
"booleanActions": 0,
"policyType": 54,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "wPA3PersonalOption",
"value": "wpa3Personal",
"children": [
{
"dataType": 20,
"category": 121,
"nameResourceKey": "preSharedKeyName",
"descriptionResourceKey": "preSharedKeyDescription",
"emptyValueResourceKey": "wifiPasswordExample",
"childSettings": [
],
"options": [
],
"entityKey": "preSharedKey",
"booleanActions": 0,
"policyType": 54,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "wEPOption",
"value": "wep",
@@ -238,7 +286,7 @@
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 54,
"enabled": true
},
@@ -1494,7 +1542,7 @@
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 54,
"enabled": true
},
@@ -1940,7 +1988,7 @@
"entityKey": "proxySettings",
"booleanActions": 0,
"defaultValue": "none",
"unconfiguredValue": "noneOption",
"unconfiguredValue": "none",
"policyType": 54,
"enabled": true
},
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,909 @@
{
"windowsztdns_windows10ztdns": [
{
"dataType": 10,
"category": 154,
"nameResourceKey": "ztdnsMinimumBuildInfoboxName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"dataType": 9,
"category": 154,
"childSettings": [
{
"complexOptions": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsModeHeaderName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"dataType": 16,
"category": 154,
"nameResourceKey": "ztdnsModeSelectionName",
"childSettings": [
],
"options": [
{
"nameResourceKey": "ZtdnsNotConfiguredName",
"enabled": true
},
{
"nameResourceKey": "ztdnsModeSelectionAuditName",
"value": "true",
"enabled": true
},
{
"nameResourceKey": "ztdnsModeSelectionEnforceName",
"value": "false",
"children": [
{
"dataType": 10,
"category": 154,
"nameResourceKey": "ztdnsModeWarningName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "auditModeEnabled",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsModeChevronName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerHeaderName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDisplayNameName",
"descriptionResourceKey": "ztdnsSecureDnsServerDisplayNameDescription",
"emptyValueResourceKey": "ztdnsSecureDnsServerDisplayNamePlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "displayName",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerIpAddressName",
"descriptionResourceKey": "ztdnsSecureDnsServerIpAddressDescription",
"emptyValueResourceKey": "ztdnsSecureDnsServerIpAddressPlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "ipAddress",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 16,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerTypeName",
"descriptionResourceKey": "ztdnsSecureDnsServerTypeDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "ZtdnsNotConfiguredName",
"enabled": true
},
{
"nameResourceKey": "ztdnsSecureDnsServerDohOptionName",
"value": "doh",
"children": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohHeaderName",
"childSettings": [
{
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohUrlName",
"descriptionResourceKey": "ztdnsSecureDnsServerDohUrlDescription",
"emptyValueResourceKey": "ztdnsSecureDnsServerDohUrlPlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "dohQueryUrl",
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohPortName",
"descriptionResourceKey": "ztdnsSecureDnsServerDohPortDescription",
"childSettings": [
],
"options": [
],
"entityKey": "dohHttpsPort",
"booleanActions": 0,
"defaultValue": 443,
"policyType": 130,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "ztdnsSecureDnsServerDotOptionName",
"value": "dot",
"children": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotHeaderName",
"childSettings": [
{
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotHostnameName",
"descriptionResourceKey": "ztdnsSecureDnsServerDotHostnameDescription",
"emptyValueResourceKey": "ztdnsSecureDnsServerDotHostnamePlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "dotCertificateSubjectName",
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotPortName",
"descriptionResourceKey": "ztdnsSecureDnsServerDotPortDescription",
"childSettings": [
],
"options": [
],
"entityKey": "dotTlsPort",
"booleanActions": 0,
"defaultValue": 853,
"policyType": 130,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "ztdnsSecureDnsServerDohAndDotOptionName",
"value": "dohAndDot",
"children": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohHeaderName",
"childSettings": [
{
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohUrlName",
"descriptionResourceKey": "ztdnsSecureDnsServerDohUrlDescription",
"emptyValueResourceKey": "ztdnsSecureDnsServerDohUrlPlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "dohQueryUrl",
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohPortName",
"descriptionResourceKey": "ztdnsSecureDnsServerDohPortDescription",
"childSettings": [
],
"options": [
],
"entityKey": "dohHttpsPort",
"booleanActions": 0,
"defaultValue": 443,
"policyType": 130,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotHeaderName",
"childSettings": [
{
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotHostnameName",
"descriptionResourceKey": "ztdnsSecureDnsServerDotHostnameDescription",
"emptyValueResourceKey": "ztdnsSecureDnsServerDotHostnamePlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "dotCertificateSubjectName",
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotPortName",
"descriptionResourceKey": "ztdnsSecureDnsServerDotPortDescription",
"childSettings": [
],
"options": [
],
"entityKey": "dotTlsPort",
"booleanActions": 0,
"defaultValue": 853,
"policyType": 130,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "serverType",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotHostnameName",
"childSettings": [
],
"options": [
],
"entityKey": "dotCertificateSubjectName",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDotPortName",
"childSettings": [
],
"options": [
],
"entityKey": "dotTlsPort",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohUrlName",
"childSettings": [
],
"options": [
],
"entityKey": "dohQueryUrl",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerDohPortName",
"childSettings": [
],
"options": [
],
"entityKey": "dohHttpsPort",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
}
],
"dataType": 21,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerName",
"childSettings": [
],
"options": [
],
"entityKey": "secureDnsServers",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsSecureDnsServerChevronName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsTrustedCAHeaderName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 4,
"category": 154,
"nameResourceKey": "ztdnsServerRootCertificateHeader",
"descriptionResourceKey": "ztdnsRootCertificateDescription",
"childSettings": [
],
"options": [
],
"entityKey": "rootCertificatesForServerValidation",
"booleanActions": 0,
"unconfiguredValue": "notConfigured",
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsServerRootCertificateHeader",
"descriptionResourceKey": "ztdnsRootCertificateDescription",
"emptyValueResourceKey": "selectCertificate",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsTrustedCAChevronName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsExemptionRulesHeaderName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsExemptionRuleDisplayNameName",
"emptyValueResourceKey": "ztdnsExemptionRuleDisplayNamePlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "displayName",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"columns": [
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsExemptionRuleIpAddressName",
"emptyValueResourceKey": "ztdnsExemptionRuleIpAddressPlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "ipAddress",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
}
],
"dataType": 21,
"category": 154,
"nameResourceKey": "ztdnsExemptionRuleIpAddressesName",
"descriptionResourceKey": "ztdnsExemptionRuleIpAddressesDescription",
"childSettings": [
],
"options": [
],
"entityKey": "ipAddresses",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "ztdnsExemptionRuleDescriptionName",
"emptyValueResourceKey": "ztdnsExemptionRuleDescriptionPlaceholder",
"childSettings": [
],
"options": [
],
"entityKey": "description",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
}
],
"dataType": 21,
"category": 154,
"nameResourceKey": "ztdnsExemptionRulesName",
"descriptionResourceKey": "ztdnsExemptionRulesDescription",
"childSettings": [
],
"options": [
],
"entityKey": "exemptionRules",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsExemptionRulesChevronName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsClientCertificateHeaderName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 4,
"category": 154,
"nameResourceKey": "ztdnsClientRootCertificateHeader",
"descriptionResourceKey": "ztdnsRootCertificateDescription",
"childSettings": [
],
"options": [
],
"entityKey": "rootCertificatesForClientValidation",
"booleanActions": 0,
"unconfiguredValue": "notConfigured",
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsClientRootCertificateHeader",
"descriptionResourceKey": "ztdnsRootCertificateDescription",
"emptyValueResourceKey": "selectCertificate",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"isSettingDescription": true,
"showAsSectionHeader": false,
"dataType": 8,
"category": 154,
"nameResourceKey": "ztdnsClientCertificateEkuHeaderName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "eDPPolicyAppsListNameName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "name",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 154,
"nameResourceKey": "sCEPPolicyObjectIdentifierColumnName",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "objectIdentifier",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
}
],
"dataType": 21,
"category": 154,
"nameResourceKey": "sCEPPolicyExtendedKeyUsageName",
"childSettings": [
],
"options": [
],
"entityKey": "extendedKeyUsagesForClientAuthentication",
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsClientCertificateChevronName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 0,
"category": 154,
"nameResourceKey": "ztdnsAdvancedSettingsLoopbackTrafficBlockedName",
"descriptionResourceKey": "ztdnsAdvancedSettingsLoopbackTrafficBlockedDescription",
"childSettings": [
{
"dataType": 0,
"category": 154,
"nameResourceKey": "ztdnsAdvancedSettingsLoopbackDnsForwarderEnabledName",
"descriptionResourceKey": "ztdnsAdvancedSettingsLoopbackDnsForwarderEnabledDescription",
"childSettings": [
],
"options": [
],
"entityKey": "loopbackDnsForwarderEnabled",
"booleanActions": 0,
"defaultValue": false,
"policyType": 130,
"enabled": true
}
],
"options": [
],
"entityKey": "loopbackTrafficBlocked",
"booleanActions": 3,
"defaultValue": false,
"policyType": 130,
"enabled": true
},
{
"dataType": 0,
"category": 154,
"nameResourceKey": "ztdnsAdvancedSettingsHostsFileResolutionEnabledName",
"descriptionResourceKey": "ztdnsAdvancedSettingsHostsFileResolutionEnabledDescription",
"childSettings": [
],
"options": [
],
"entityKey": "hostsFileResolutionEnabled",
"booleanActions": 3,
"defaultValue": false,
"policyType": 130,
"enabled": true
},
{
"dataType": 14,
"category": 154,
"nameResourceKey": "ztdnsAdvancedSettingsMaximumConnectionTimeInSecondsName",
"descriptionResourceKey": "ztdnsAdvancedSettingsMaximumConnectionTimeInSecondsDescription",
"childSettings": [
],
"options": [
],
"entityKey": "maximumConnectionTimeInSeconds",
"booleanActions": 0,
"defaultValue": 86400,
"policyType": 130,
"enabled": true
}
],
"dataType": 5,
"category": 154,
"nameResourceKey": "ztdnsAdvancedSettingsChevronName",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 130,
"enabled": true
}
]
}
@@ -0,0 +1,735 @@
{
"wirednetwork_ioswirednetwork": [
{
"dataType": 16,
"category": 149,
"nameResourceKey": "networkInterface",
"descriptionResourceKey": "networkInterfaceDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "anyEthernet",
"value": "anyEthernet",
"enabled": true
}
],
"entityKey": "networkInterface",
"booleanActions": 0,
"defaultValue": "anyEthernet",
"policyType": 131,
"enabled": true
},
{
"dataType": 16,
"category": 149,
"nameResourceKey": "eAPTypeName",
"descriptionResourceKey": "eAPTypeDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "selectEAP",
"enabled": true
},
{
"nameResourceKey": "eAPFASTName",
"value": "eapFast",
"children": [
{
"dataType": 16,
"category": 149,
"nameResourceKey": "pACHeading",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
{
"nameResourceKey": "dontUsePACName",
"value": "noProtectedAccessCredential",
"enabled": true
},
{
"nameResourceKey": "usePACName",
"value": "useProtectedAccessCredential",
"enabled": true
},
{
"nameResourceKey": "provisionPACName",
"value": "useProtectedAccessCredentialAndProvision",
"enabled": true
},
{
"nameResourceKey": "provisionPACAnonName",
"value": "useProtectedAccessCredentialAndProvisionAnonymously",
"enabled": true
}
],
"entityKey": "eapFastConfiguration",
"booleanActions": 0,
"defaultValue": "noProtectedAccessCredential",
"policyType": 131,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "eAPTLSName",
"value": "eapTls",
"children": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 149,
"nameResourceKey": "trust",
"descriptionResourceKey": "trustDescription",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 149,
"nameResourceKey": "empty",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "trustedServerCertificateNameExample",
"childSettings": [
],
"options": [
],
"entityKey": "trustedServerCertificateNamesName",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
}
],
"dataType": 21,
"category": 149,
"nameResourceKey": "trustedServerCertificateNamesName",
"descriptionResourceKey": "trustedServerCertificateNamesDescription",
"childSettings": [
],
"options": [
],
"entityKey": "trustedServerCertificateNames",
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 4,
"category": 149,
"nameResourceKey": "selectCertificateProfiles",
"descriptionResourceKey": "selectRootCertificatesForServerValidationName",
"childSettings": [
],
"options": [
],
"entityKey": "rootCertificatesForServerValidation",
"booleanActions": 0,
"unconfiguredValue": "notConfigured",
"policyType": 131,
"enabled": true
}
],
"dataType": 5,
"category": 149,
"nameResourceKey": "selectRootCertificatesForServerValidationName",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "selectCertificates",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 149,
"nameResourceKey": "authentication",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"value": "certificate",
"dataType": 9,
"category": 149,
"childSettings": [
],
"options": [
],
"entityKey": "authenticationMethod",
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 4,
"category": 149,
"nameResourceKey": "selectCertificateProfile",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "identityCertificateForClientAuthentication",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"dataType": 5,
"category": 149,
"nameResourceKey": "certificatesOption",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "selectCertificate",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"dataType": 20,
"category": 149,
"nameResourceKey": "enableIdentityPrivacyName",
"descriptionResourceKey": "enableIdentityPrivacyDescription",
"emptyValueResourceKey": "identityPrivacyExample",
"childSettings": [
],
"options": [
],
"entityKey": "enableOuterIdentityPrivacy",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "eAPTTLSName",
"value": "eapTtls",
"children": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 149,
"nameResourceKey": "trust",
"descriptionResourceKey": "trustDescription",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 149,
"nameResourceKey": "empty",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "trustedServerCertificateNameExample",
"childSettings": [
],
"options": [
],
"entityKey": "trustedServerCertificateNamesName",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
}
],
"dataType": 21,
"category": 149,
"nameResourceKey": "trustedServerCertificateNamesName",
"descriptionResourceKey": "trustedServerCertificateNamesDescription",
"childSettings": [
],
"options": [
],
"entityKey": "trustedServerCertificateNames",
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 4,
"category": 149,
"nameResourceKey": "selectCertificateProfiles",
"descriptionResourceKey": "selectRootCertificatesForServerValidationName",
"childSettings": [
],
"options": [
],
"entityKey": "rootCertificatesForServerValidation",
"booleanActions": 0,
"unconfiguredValue": "notConfigured",
"policyType": 131,
"enabled": true
}
],
"dataType": 5,
"category": 149,
"nameResourceKey": "selectRootCertificatesForServerValidationName",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "selectCertificates",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 149,
"nameResourceKey": "authentication",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"dataType": 16,
"category": 149,
"nameResourceKey": "authenticationMethodName",
"descriptionResourceKey": "authenticationMethodTTLSDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "notConfigured",
"enabled": true
},
{
"nameResourceKey": "usernameAndPasswordOption",
"value": "usernameAndPassword",
"children": [
{
"dataType": 16,
"category": 149,
"nameResourceKey": "nonEapMethodName",
"descriptionResourceKey": "nonEapMethodDescription",
"childSettings": [
],
"options": [
{
"nameResourceKey": "selectNonEapMethod",
"enabled": true
},
{
"nameResourceKey": "pAPName",
"value": "unencryptedPassword",
"enabled": true
},
{
"nameResourceKey": "cHAPName",
"value": "challengeHandshakeAuthenticationProtocol",
"enabled": true
},
{
"nameResourceKey": "mSCHAPName",
"value": "microsoftChap",
"enabled": true
},
{
"nameResourceKey": "cHAPTWOName",
"value": "microsoftChapVersionTwo",
"enabled": true
}
],
"entityKey": "nonEapAuthenticationMethodForEapTtls",
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"dataType": 20,
"category": 149,
"nameResourceKey": "enableIdentityPrivacyName",
"descriptionResourceKey": "enableIdentityPrivacyDescription",
"emptyValueResourceKey": "identityPrivacyExample",
"childSettings": [
],
"options": [
],
"entityKey": "enableOuterIdentityPrivacy",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "certificatesOption",
"value": "certificate",
"children": [
{
"complexOptions": [
{
"dataType": 4,
"category": 149,
"nameResourceKey": "selectCertificateProfile",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "identityCertificateForClientAuthentication",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"dataType": 5,
"category": 149,
"nameResourceKey": "certificatesOption",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "selectCertificate",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"dataType": 20,
"category": 149,
"nameResourceKey": "enableIdentityPrivacyName",
"descriptionResourceKey": "enableIdentityPrivacyDescription",
"emptyValueResourceKey": "identityPrivacyExample",
"childSettings": [
],
"options": [
],
"entityKey": "enableOuterIdentityPrivacy",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "authenticationMethod",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "eAPAKAName",
"value": "eapAka",
"enabled": true
},
{
"nameResourceKey": "pEAPName",
"value": "peap",
"children": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 149,
"nameResourceKey": "trust",
"descriptionResourceKey": "trustDescription",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 149,
"nameResourceKey": "empty",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "trustedServerCertificateNameExample",
"childSettings": [
],
"options": [
],
"entityKey": "trustedServerCertificateNamesName",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
}
],
"dataType": 21,
"category": 149,
"nameResourceKey": "trustedServerCertificateNamesName",
"descriptionResourceKey": "trustedServerCertificateNamesDescription",
"childSettings": [
],
"options": [
],
"entityKey": "trustedServerCertificateNames",
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"complexOptions": [
{
"dataType": 4,
"category": 149,
"nameResourceKey": "selectCertificateProfiles",
"descriptionResourceKey": "selectRootCertificatesForServerValidationName",
"childSettings": [
],
"options": [
],
"entityKey": "rootCertificatesForServerValidation",
"booleanActions": 0,
"unconfiguredValue": "notConfigured",
"policyType": 131,
"enabled": true
}
],
"dataType": 5,
"category": 149,
"nameResourceKey": "selectRootCertificatesForServerValidationName",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "selectCertificates",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 149,
"nameResourceKey": "authentication",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"dataType": 16,
"category": 149,
"nameResourceKey": "authenticationMethodName",
"descriptionResourceKey": "authenticationMethodName",
"childSettings": [
],
"options": [
{
"nameResourceKey": "notConfigured",
"enabled": true
},
{
"nameResourceKey": "usernameAndPasswordOption",
"value": "usernameAndPassword",
"children": [
{
"dataType": 20,
"category": 149,
"nameResourceKey": "enableIdentityPrivacyName",
"descriptionResourceKey": "enableIdentityPrivacyDescription",
"emptyValueResourceKey": "identityPrivacyExample",
"childSettings": [
],
"options": [
],
"entityKey": "outerIdentityPrivacyMaskValue",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
},
{
"nameResourceKey": "certificatesOption",
"value": "certificate",
"children": [
{
"complexOptions": [
{
"dataType": 4,
"category": 149,
"nameResourceKey": "selectCertificateProfile",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "identityCertificateForClientAuthentication",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"dataType": 5,
"category": 149,
"nameResourceKey": "certificatesOption",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "selectCertificate",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 131,
"enabled": true
},
{
"dataType": 20,
"category": 149,
"nameResourceKey": "enableIdentityPrivacyName",
"descriptionResourceKey": "enableIdentityPrivacyDescription",
"emptyValueResourceKey": "identityPrivacyExample",
"childSettings": [
],
"options": [
],
"entityKey": "enableOuterIdentityPrivacy",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "authenticationMethod",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
],
"enabled": true
}
],
"entityKey": "eapType",
"booleanActions": 0,
"policyType": 131,
"enabled": true
}
]
}
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,50 @@
{
"workprofile_androidforworkmigrationpolicy": [
{
"dataType": 10,
"category": 127,
"nameResourceKey": "migrationPolicyCannotBeUnassigned",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 129,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 127,
"nameResourceKey": "androidForWorkMigrationPolicyDescriptionParagraph1",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 129,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 127,
"nameResourceKey": "androidForWorkMigrationPolicyLearnMoreText",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 129,
"enabled": true
}
]
}
@@ -0,0 +1,140 @@
{
"wslcompliance_compliancewindows10": [
{
"dataType": 10,
"category": 153,
"nameResourceKey": "windowsSubsystemLinuxComplianceInfoBox",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 35,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 153,
"nameResourceKey": "windowsSubsystemLinuxComplianceDescription",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 35,
"enabled": true
},
{
"isSettingDescription": false,
"showAsSectionHeader": true,
"dataType": 8,
"category": 153,
"nameResourceKey": "windowsSubsystemLinuxComplianceHeader",
"childSettings": [
{
"isSettingDescription": false,
"showAsSectionHeader": false,
"dataType": 8,
"category": 153,
"nameResourceKey": "windowsSubsystemLinuxComplianceLearnMore",
"childSettings": [
],
"options": [
],
"booleanActions": 0,
"policyType": 35,
"enabled": true
}
],
"options": [
],
"booleanActions": 0,
"policyType": 35,
"enabled": true
},
{
"columns": [
{
"metadata": {
"dataType": 20,
"category": 153,
"nameResourceKey": "wSLPolicyDistributionName",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "distribution",
"booleanActions": 0,
"policyType": 35,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 153,
"nameResourceKey": "wSLPolicyMinOSVersionName",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "optionalValue",
"childSettings": [
],
"options": [
],
"entityKey": "minimumOSVersion",
"booleanActions": 0,
"policyType": 35,
"enabled": true
}
},
{
"metadata": {
"dataType": 20,
"category": 153,
"nameResourceKey": "wSLPolicyMaxOSVersionName",
"descriptionResourceKey": "empty",
"emptyValueResourceKey": "optionalValue",
"childSettings": [
],
"options": [
],
"entityKey": "maximumOSVersion",
"booleanActions": 0,
"policyType": 35,
"enabled": true
}
}
],
"dataType": 21,
"category": 153,
"nameResourceKey": "empty",
"descriptionResourceKey": "empty",
"childSettings": [
],
"options": [
],
"entityKey": "wslDistributions",
"booleanActions": 0,
"policyType": 35,
"enabled": true
}
]
}
+5182 -4767
View File
File diff suppressed because it is too large Load Diff
+5183 -4768
View File
File diff suppressed because it is too large Load Diff
+5169 -4754
View File
File diff suppressed because it is too large Load Diff
+5171 -4756
View File
File diff suppressed because it is too large Load Diff
+5214 -4799
View File
File diff suppressed because it is too large Load Diff
+5166 -4751
View File
File diff suppressed because it is too large Load Diff
+5205 -4790
View File
File diff suppressed because it is too large Load Diff
+5197 -4782
View File
File diff suppressed because it is too large Load Diff
+5173 -4758
View File
File diff suppressed because it is too large Load Diff
+5165 -4750
View File
File diff suppressed because it is too large Load Diff
+5065 -4650
View File
File diff suppressed because it is too large Load Diff
+5169 -4754
View File
File diff suppressed because it is too large Load Diff
+5139 -4724
View File
File diff suppressed because it is too large Load Diff
+5200 -4785
View File
File diff suppressed because it is too large Load Diff
+5123 -4708
View File
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+5169 -4754
View File
File diff suppressed because it is too large Load Diff
+148 -27
View File
@@ -11,7 +11,7 @@ Objects can be compared based on Properties or Documentatation info.
function Get-ModuleVersion
{
'1.1.0'
'1.2.0'
}
function Invoke-InitializeModule
@@ -188,6 +188,12 @@ function Show-CompareBulkForm
$global:chkSkipCompareAssignments.IsChecked = (Get-Setting "Compare" "SkipCompareAssignments") -eq "true"
$global:chkSkipMissingSourcePolicies.IsChecked = (Get-Setting "Compare" "SkipMissingSourcePolicies") -eq "true"
$global:chkSkipMissingDestinationPolicies.IsChecked = (Get-Setting "Compare" "SkipMissingDestinationPolicies") -eq "true"
$global:chkBulkCompareSaveJson.IsChecked = (Get-Setting "Compare" "SaveJson") -eq "true"
$global:chkBulkCompareRemoveOData.IsChecked = (Get-Setting "Compare" "RemoveOData") -eq "true"
$objectSeparator = "[ { Name: `"New line`",Value: `"$([System.Environment]::NewLine)`" }, {Name: `";`",Value: `";`" }, {Name: `"|`",Value: `"|`" }]" | ConvertFrom-Json
$global:cbCompareMultiValueDelimiter.ItemsSource = $objectSeparator
$global:cbCompareMultiValueDelimiter.SelectedValue = (Get-Setting "Compare" "ObjectSeparator" ([System.Environment]::NewLine))
$script:compareObjects = @()
foreach($objType in $global:lstMenuItems.ItemsSource)
@@ -239,6 +245,9 @@ function Show-CompareBulkForm
Save-Setting "Compare" "SkipCompareAssignments" $global:chkSkipCompareAssignments.IsChecked
Save-Setting "Compare" "SkipMissingSourcePolicies" $global:chkSkipMissingSourcePolicies.IsChecked
Save-Setting "Compare" "SkipMissingDestinationPolicies" $global:chkSkipMissingDestinationPolicies.IsChecked
Save-Setting "Compare" "SaveJson" $global:chkBulkCompareSaveJson.IsChecked
Save-Setting "Compare" "RemoveOData" $global:chkBulkCompareRemoveOData.IsChecked
Save-Setting "Compare" "ObjectSeparator" $global:cbCompareMultiValueDelimiter.SelectedValue
if($global:cbCompareProvider.SelectedItem.BulkCompare)
{
@@ -534,18 +543,26 @@ function Invoke-BulkCompareNamedObjects
{
$fileName = Remove-InvalidFileNameChars (Expand-FileName "Compare-$($graphObj.ObjectType.Id)-$sourcePattern-$comparePattern-%DateTime%.csv")
Save-BulkCompareResults $compResultValues (Join-Path $outputFolder $fileName) $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
$fileName = Remove-InvalidFileNameChars (Expand-FileName "Compare-$($graphObj.ObjectType.Id)-$sourcePattern-$comparePattern-%DateTime%.json")
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder $fileName)
}
}
}
#$fileName = Expand-FileName $fileName
if($compareObjectsResult.Count -eq 0)
{
[System.Windows.MessageBox]::Show("No objects were comparced. Verify name patterns", "Error", "OK", "Error")
[System.Windows.MessageBox]::Show("No objects were compared. Verify name patterns", "Error", "OK", "Error")
}
elseif($outputType -eq "all")
{
$fileName = Remove-InvalidFileNameChars (Expand-FileName "Compare-$sourcePattern-$comparePattern-%DateTime%.csv")
Save-BulkCompareResults $compResultValues (Join-Path $outputFolder $fileName) $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
$fileName = Remove-InvalidFileNameChars (Expand-FileName "Compare-$($graphObj.ObjectType.Id)-$sourcePattern-$comparePattern-%DateTime%.json")
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder $fileName)
}
}
}
@@ -640,6 +657,7 @@ function Start-BulkCompareExportObjects
{
$sourceObj = Get-GraphObject $curObject.Object $curObject.ObjectType
$fileObj.Object | Add-Member Noteproperty -Name "@ObjectFromFile" -Value $true -Force
$fileObj.Object | Add-Member Noteproperty -Name "@ObjectFileName" -Value $fileObj.FileInfo.FullName -Force
$compareProperties = Compare-Objects $sourceObj.Object $fileObj.Object $item.ObjectType
}
@@ -688,7 +706,7 @@ function Start-BulkCompareExportObjects
$objName = Get-GraphObjectName (?? $compObj.Object1 $compObj.Object2) $item.ObjectType
foreach($compValue in $compObj.Result)
{
$compResultValues += [PSCustomObject]@{
$compValue += [PSCustomObject]@{
ObjectName = $objName
Id = $compObj.Id
Type = $compObj.ObjectType.Title
@@ -700,12 +718,34 @@ function Start-BulkCompareExportObjects
SubCategory = $compValue.SubCategory
Match = $compValue.Match
}
if($global:chkBulkCompareRemoveOData.IsChecked -and ($compValue.Value1 -like "@odata*" -or $compValue.Value2 -like "@odata*")) {
foreach($prop in $('Value1','Value2'))
{
$tmpValue1 = ""
$tmpValue2 = ""
$vauleString = $compValue.$prop
if($vauleString -is [String]) {
$vauleString = $vauleString -replace $compValue.Id, ""
$tmpObj = $compValue.$prop | ConvertFrom-Json
if($compValue.$prop -and $compValue.$prop -like "@odata*") {
Remove-GraphODataProperties $tmpObj.$prop | ConvertTo-Json -Depth 50 | Set-Variable -Name "tmp$prop"
}
}
}
$compValue.Match = $tmpValue1 -eq $tmpValue2
}
$compResultValues += $compValue
}
}
if($outputType -eq "objectType")
{
Save-BulkCompareResults $compResultValues (Join-Path $folder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).csv") $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
Save-BulkCompareJsonResults $compResultValues (Join-Path $folder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).json")
}
}
}
else
@@ -716,7 +756,10 @@ function Start-BulkCompareExportObjects
if($outputType -eq "all" -and $compResultValues.Count -gt 0)
{
Save-BulkCompareResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMDD-HHmm"))).csv") $compareProps
Save-BulkCompareResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).csv") $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).json")
}
}
Write-Log "****************************************************************"
@@ -725,7 +768,7 @@ function Start-BulkCompareExportObjects
Write-Status ""
if($compareObjectsResult.Count -eq 0)
{
[System.Windows.MessageBox]::Show("No objects were comparced. Verify folder and exported files", "Error", "OK", "Error")
[System.Windows.MessageBox]::Show("No objects were compared. Verify folder and exported files", "Error", "OK", "Error")
}
}
@@ -795,6 +838,7 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
if($txtNameFilter -and $objName -notmatch [RegEx]::Escape($txtNameFilter))
{
Write-LogDebug "Excluded based on filter. Intune object name: '$($objName)'"
continue
}
@@ -802,7 +846,7 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
if(-not $fileObj)
{
# Add objects that are exported but deleted
# Add objects that are in Intune but no exported file found
if($global:chkSkipMissingDestinationPolicies.IsChecked -ne $true) {
Write-Log "Object '$($objName)' with id $($fileObj.Object.Id) not found in exported folder. New Object?" 2
$compareProperties = @([PSCustomObject]@{
@@ -814,7 +858,7 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
}
elseif(($fileObj | measure).Count -gt 1)
{
# Add objects that are exported but deleted
# Add objects where multiple files match based on name
Write-Log "Multiple exported objects found with name '$($objName)" 2
$compareProperties = @([PSCustomObject]@{
Object1Value = $objName
@@ -826,6 +870,7 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
{
$sourceObj = Get-GraphObject $graphObject.Object $graphObject.ObjectType
$fileObj.Object | Add-Member Noteproperty -Name "@ObjectFromFile" -Value $true -Force
$fileObj.Object | Add-Member Noteproperty -Name "@ObjectFileName" -Value $fileObj.FileInfo.FullName -Force
$compareProperties = Compare-Objects $sourceObj.Object $fileObj.Object $item.ObjectType
}
@@ -841,12 +886,16 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
if($global:chkSkipMissingSourcePolicies.IsChecked -ne $true) {
foreach ($fileObj in @($fileObjects))
{
# Add objects that are exported but not in Intune
if(($compareObjectsResult | Where { $_.FileInfo.FullName -eq $fileObj.FileInfo.FullName})) { continue }
# Skip objects if they are already processed
if(($compareObjectsResult | Where { $_.Object2 -eq $fileObj.Object})) {
Write-LogDebug "Skip already processed file '$($fileObj.FileInfo.FullName)'"
continue
}
$objName = Get-GraphObjectName $fileObj.Object $item.ObjectType
if($txtNameFilter -and $objName -notmatch [RegEx]::Escape($txtNameFilter))
{
Write-LogDebug "Excluded based on filter. File: '$($fileObj.FileInfo.FullName)'"
continue
}
@@ -892,6 +941,9 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
if($outputType -eq "objectType")
{
Save-BulkCompareResults $compResultValues (Join-Path $folder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).csv") $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).json")
}
}
}
else
@@ -902,7 +954,10 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
if($outputType -eq "all" -and $compResultValues.Count -gt 0)
{
Save-BulkCompareResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMDD-HHmm"))).csv") $compareProps
Save-BulkCompareResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).csv") $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).json")
}
}
Write-Log "****************************************************************"
@@ -911,7 +966,7 @@ function Start-BulkCompareExportIntuneToNamedExportedObjects
Write-Status ""
if($compareObjectsResult.Count -eq 0)
{
[System.Windows.MessageBox]::Show("No objects were comparced. Verify folder and exported files", "Error", "OK", "Error")
[System.Windows.MessageBox]::Show("No objects were compared. Verify folder and exported files", "Error", "OK", "Error")
}
}
@@ -1009,7 +1064,9 @@ function Start-BulkCompareExportFolders
else
{
$fileSourceObj.Object | Add-Member Noteproperty -Name "@ObjectFromFile" -Value $true -Force
$fileSourceObj.Object | Add-Member Noteproperty -Name "@ObjectFileName" -Value $fileSourceObj.FileInfo.FullName -Force
$compareObject.Object | Add-Member Noteproperty -Name "@ObjectFromFile" -Value $true -Force
$compareObject.Object | Add-Member Noteproperty -Name "@ObjectFileName" -Value $compareObject.FileInfo.FullName -Force
$compareProperties = Compare-Objects $compareObject.Object $fileSourceObj.Object $item.ObjectType
}
@@ -1076,6 +1133,9 @@ function Start-BulkCompareExportFolders
if($outputType -eq "objectType")
{
Save-BulkCompareResults $compResultValues (Join-Path $folderSource "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).csv") $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).json")
}
}
}
else
@@ -1086,7 +1146,10 @@ function Start-BulkCompareExportFolders
if($outputType -eq "all" -and $compResultValues.Count -gt 0)
{
Save-BulkCompareResults $compResultValues (Join-Path $rootFolderSource "Compare_$(((Get-Date).ToString("yyyyMMDD-HHmm"))).csv") $compareProps
Save-BulkCompareResults $compResultValues (Join-Path $rootFolderSource "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).csv") $compareProps
if($global:chkBulkCompareSaveJson.IsChecked) {
Save-BulkCompareJsonResults $compResultValues (Join-Path $rootFolder "Compare_$(((Get-Date).ToString("yyyyMMdd-HHmm"))).json")
}
}
Write-Log "****************************************************************"
@@ -1099,6 +1162,13 @@ function Start-BulkCompareExportFolders
}
}
function Save-BulkCompareJsonResults
{
param($CompareResults, $FileName)
$CompareResults | ConvertTo-Json -Depth 50 | Out-File $FileName -Force -Encoding UTF8
}
function Save-BulkCompareResults
{
param($compResultValues, $file, $props)
@@ -1297,6 +1367,7 @@ function Start-CompareExportObject
}
}
$compareObj | Add-Member Noteproperty -Name "@ObjectFileName" -Value $global:txtCompareFile.Text -Force
$compareObj | Add-Member Noteproperty -Name "@ObjectFromFile" -Value $true -Force
$compareResult = Compare-Objects $obj.Object $compareObj $obj.ObjectType
@@ -1354,7 +1425,7 @@ function Add-CompareProperty
$value1 = if($value1 -eq $null) { "" } else { $value1.ToString().Trim("`"") }
$value2 = if($value2 -eq $null) { "" } else { $value2.ToString().Trim("`"") }
$compare += [PSCustomObject]@{
$compare = [PSCustomObject]@{
PropertyName = $name
Object1Value = $value1 #if($value1 -ne $null) { $value1.ToString().Trim("`"") } else { "" }
Object2Value = $value2 #if($value2 -ne $null) { $value2.ToString().Trim("`"") } else { "" }
@@ -1362,10 +1433,12 @@ function Add-CompareProperty
SubCategory = $subCategory
Match = ?? $match ($value1 -eq $value2)
}
if($skip -eq $true) {
$compare.Match = $null
}
Write-LogDebug "Add property $($compare.PropertyName)"
$script:compareProperties += $compare
}
@@ -1381,7 +1454,7 @@ function Compare-ObjectsBasedonProperty
$coreProps = @((?? $objectType.NameProperty "displayName"), "Description", "Id", "createdDateTime", "lastModifiedDateTime", "version")
$postProps = @("Advertisements")
$skipProps = @("@ObjectFromFile")
$skipProps = @("@ObjectFromFile","@ObjectFileName")
$skipPropertiesToCompare = @()
if($skipBasicProperties) {
$skipPropertiesToCompare += "roleScopeTagIds"
@@ -1469,17 +1542,19 @@ function Compare-ObjectsBasedonDocumentation
# ToDo: set this based on configuration value
$script:assignmentOutput = "simpleFullCompare"
$docObj1 = Invoke-ObjectDocumentation ([PSCustomObject]@{
$tmpObj1 = ([PSCustomObject]@{
Object = $obj1
ObjectType = $objectType
})
ObjectType = $objectType})
$docObj1 = Invoke-ObjectDocumentation $tmpObj1 -ObjectSeparator ($global:cbCompareMultiValueDelimiter.SelectedValue)
$docObj2 = Invoke-ObjectDocumentation ([PSCustomObject]@{
$tmpObj2 = ([PSCustomObject]@{
Object = $obj2
ObjectType = $objectType
})
$docObj2 = Invoke-ObjectDocumentation $tmpObj2 -ObjectSeparator ($global:cbCompareMultiValueDelimiter.SelectedValue)
$settingsValue = ?? $objectType.CompareValue "Value"
$skipBasicProperties = Get-XamlProperty $script:cmpForm "chkSkipCompareBasicProperties" "IsChecked"
@@ -1500,8 +1575,10 @@ function Compare-ObjectsBasedonDocumentation
$addedProperties = @()
if($docObj1.InputType -eq "Settings")
if($docObj1.InputType -eq "Intent")
{
Set-ColumnVisibility $true ($null -ne ($docObj1.Settings | Where ParentSettingId -ne $null))
foreach ($prop in $docObj1.Settings)
{
if(($prop.SettingId + $prop.ParentSettingId + $prop.RowIndex) -in $addedProperties) { continue }
@@ -1575,8 +1652,48 @@ function Compare-ObjectsBasedonDocumentation
Add-CompareProperty $prop.Name $val1 $val2 $prop.Category
}
}
elseif($docObj1.InputType -eq "Settings")
{
Set-ColumnVisibility $true ($null -ne ($docObj1.Settings | Where SubCategory -ne $null))
foreach ($prop in $docObj1.Settings)
{
if(($prop.SettingId + $prop.CategoryId + $prop.SubCategoryDefinition.Id) -in $addedProperties) { continue }
$addedProperties += ($prop.SettingId + $prop.CategoryId + $prop.SubCategoryDefinition.Id)
$val1 = $prop.$settingsValue
$prop2 = $docObj2.Settings | Where { $_.SettingId -eq $prop.SettingId -and $_.CategoryId -eq $prop.CategoryId -and $_.SubCategoryDefinition.Id -eq $prop.SubCategoryDefinition.Id }
$val2 = $prop2.$settingsValue
if($val1 -isnot [array] -and $val2 -is [array] -and $val2.Count -gt 1)
{
Write-Log "Multiple compare results returend for $($prop.Name). Using first result" 2
$val2 = $val2[0]
}
Add-CompareProperty $prop.Name $val1 $val2 $prop.Category $prop.SubCategory
}
# These objects are defined only on Object 2. They will be last in the table
foreach ($prop in $docObj2.Settings)
{
if(($prop.SettingId + $prop.CategoryId + $prop.SubCategoryDefinition.Id) -in $addedProperties) { continue }
$addedProperties += ($prop.SettingId + $prop.CategoryId + $prop.SubCategoryDefinition.Id)
$val2 = $prop.$settingsValue
$prop2 = $docObj1.Settings | Where { $_.SettingId -eq $prop.SettingId -and $_.CategoryId -eq $prop.CategoryId -and $_.SubCategoryDefinition.Id -eq $prop.SubCategoryDefinition.Id }
$val1 = $prop2.$settingsValue
if($val2 -isnot [array] -and $val1 -is [array] -and $val1.Count -gt 1)
{
Write-Log "Multiple compare results returend for $($prop.Name). Using first result" 2
$val1 = $val1[0]
}
Add-CompareProperty $prop.Name $val1 $val2 $prop.Category $prop.SubCategory
}
}
else
{
Set-ColumnVisibility $true ($null -ne ($docObj1.Settings | Where SubCategory -ne $null))
foreach ($prop in $docObj1.Settings)
{
if(($prop.EntityKey + $prop.Category + $prop.SubCategory) -in $addedProperties) { continue }
@@ -1618,8 +1735,8 @@ function Compare-ObjectsBasedonDocumentation
{
$applicabilityRule2 = $docObj2.ApplicabilityRules | Where { $_.Id -eq $applicabilityRule.Id }
$applicabilityRulesAdded += $applicabilityRule.Id
$val1 = ($applicabilityRule.Rule + [environment]::NewLine + $applicabilityRule.Value)
$val2 = ($applicabilityRule2.Rule + [environment]::NewLine + $applicabilityRule2.Value)
$val1 = ($applicabilityRule.Rule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $applicabilityRule.Value)
$val2 = ($applicabilityRule2.Rule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $applicabilityRule2.Value)
Add-CompareProperty $applicabilityRule.Property $val1 $val2 $applicabilityRule.Category
}
@@ -1629,8 +1746,8 @@ function Compare-ObjectsBasedonDocumentation
if(($applicabilityRule.Id) -in $applicabilityRulesAdded) { continue }
$applicabilityRule2 = $docObj1.ApplicabilityRules | Where { $_.Id -eq $applicabilityRule.Id }
$script:applicabilityRulesAdded += $applicabilityRule.Id
$val2 = ($applicabilityRule.Rule + [environment]::NewLine + $applicabilityRule.Value)
$val1 = ($applicabilityRule2.Rule + [environment]::NewLine + $applicabilityRule2.Value)
$val2 = ($applicabilityRule.Rule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $applicabilityRule.Value)
$val1 = ($applicabilityRule2.Rule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $applicabilityRule2.Value)
Add-CompareProperty $applicabilityRule.Property $val1 $val2 $applicabilityRule.Category
}
@@ -1640,8 +1757,8 @@ function Compare-ObjectsBasedonDocumentation
{
$complianceAction2 = $docObj2.ComplianceActions | Where { $_.IdStr -eq $complianceAction.IdStr }
$complianceActionsAdded += $complianceAction.IdStr
$val1 = ($complianceAction.Action + [environment]::NewLine + $complianceAction.Schedule + [environment]::NewLine + $complianceAction.MessageTemplateId + [environment]::NewLine + $complianceAction.EmailCCIds)
$val2 = ($complianceAction2.Action + [environment]::NewLine + $complianceAction2.Schedule + [environment]::NewLine + $complianceAction2.MessageTemplateId + [environment]::NewLine + $complianceAction2.EmailCCIds)
$val1 = ($complianceAction.Action + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction.Schedule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction.MessageTemplateId + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction.EmailCCIds)
$val2 = ($complianceAction2.Action + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction2.Schedule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction2.MessageTemplateId + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction2.EmailCCIds)
Add-CompareProperty $complianceAction.Category $val1 $val2
}
@@ -1651,8 +1768,8 @@ function Compare-ObjectsBasedonDocumentation
if(($complianceAction.IdStr) -in $complianceActionsAdded) { continue }
$complianceAction2 = $docObj1.ComplianceActions | Where { $_.IdStr -eq $complianceAction.IdStr }
$complianceActionsAdded += $complianceAction.IdStr
$val2 = ($complianceAction.Action + [environment]::NewLine + $complianceAction.Schedule + [environment]::NewLine + $complianceAction.MessageTemplateId + [environment]::NewLine + $complianceAction.EmailCCIds)
$val1 = ($complianceAction2.Action + [environment]::NewLine + $complianceAction2.Schedule + [environment]::NewLine + $complianceAction2.MessageTemplateId + [environment]::NewLine + $complianceAction2.EmailCCIds)
$val2 = ($complianceAction.Action + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction.Schedule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction.MessageTemplateId + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction.EmailCCIds)
$val1 = ($complianceAction2.Action + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction2.Schedule + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction2.MessageTemplateId + ($global:cbCompareMultiValueDelimiter.SelectedValue) + $complianceAction2.EmailCCIds)
Add-CompareProperty $complianceAction.Category $val1 $val2
}
@@ -1778,6 +1895,10 @@ function Invoke-SilentBatchJob
$global:cbCompareCSVDelimiter.ItemsSource = @("", ",",";","-","|")
$global:cbCompareCSVDelimiter.SelectedValue = ($settingsObj.BulkCompare | Where Name -eq "cbCompareCSVDelimiter").Value
$objectSeparator = "[ { Name: `"New line`",Value: `"$([System.Environment]::NewLine)`" }, {Name: `";`",Value: `";`" }, {Name: `"|`",Value: `"|`" }]" | ConvertFrom-Json
$global:cbCompareMultiValueDelimiter.ItemsSource = $objectSeparator
$global:cbCompareMultiValueDelimiter.SelectedValue = (Get-Setting "Compare" "ObjectSeparator" ([System.Environment]::NewLine))
Set-CompareProviderOptions $global:cbCompareProvider
Set-BatchProperties $settingsObj.BulkCompare $script:cmpForm -SkipMissingControlWarning
+222 -20
View File
@@ -20,7 +20,7 @@ $global:documentationProviders = @()
function Get-ModuleVersion
{
'2.2.1'
'2.3.0'
}
function Invoke-InitializeModule
@@ -40,6 +40,7 @@ function Invoke-InitializeModule
useDeviceContext="SettingDetails.installContextLabel"
uninstallOnDeviceRemoval="SettingDetails.UninstallOnRemoval"
isRemovable="SettingDetails.installAsRemovable"
preventManagedAppBackup="AppResources.AppSettingsUx.preventManagedAppBackup"
vpnConfigurationId="PolicyType.vpn"
Action="SettingDetails.actionColumnName"
Schedule="ScheduledAction.List.schedule"
@@ -228,6 +229,7 @@ function Get-ObjectDocumentation
$script:applicabilityRules = @()
$script:objectAssignments = @()
$script:objectScripts = @()
$script:customTables = @()
$script:admxCategories = $null
$script:ObjectTypeFullTable = @{} # Hash table with objects that should be documented in a single table eg ScopeTags
@@ -288,12 +290,20 @@ function Get-ObjectDocumentation
$properties = @("Name","Value","RootCategory","Category","RawValue","RawJsonValue","DefaultValue","Description")
}
#endregion
#region Compliance Policies V2
elseif($type -eq "#microsoft.graph.deviceManagementCompliancePolicy")
{
Invoke-TranslateComplianceV2Object $obj $objectType | Out-Null
$properties = @("Name","Value","RootCategory","Category","RawValue","RawJsonValue","DefaultValue","Description")
}
#endregion
#region Endpoint Security
elseif($type -eq "#microsoft.graph.deviceManagementIntent")
{
Invoke-TranslateIntentObject $obj $objectType | Out-Null
$properties = @("Name","Value","Category","FullValueTable","RawValue","RecommendedValue","SettingId","Description")
$defaultDocumentationProperties = @("Name","Value","RecommendedValue")
$inputType = "Intent"
}
#endregion
#region Administrative Templates
@@ -351,6 +361,7 @@ function Get-ObjectDocumentation
Settings = $script:objectSettingsData
ComplianceActions = $script:objectComplianceActionData
ApplicabilityRules = $script:applicabilityRules
CustomTables = $script:customTables
Assignments = $script:objectAssignments
Scripts = $script:objectScripts
DisplayProperties = $properties
@@ -379,17 +390,51 @@ function Get-DocumentedSettings
function Invoke-ObjectDocumentation
{
param($documentationObj)
param($documentationObj,
$ObjectSeparator,
$PropertySeparator,
$DocumentationLanguage
)
$global:intentCategories = $null
$global:catRecommendedSettings = $null
$global:intentCategoryDefs = $null
$global:cfgCategories = $null
$script:admxCategories = $null
$script:migTable = $null
$script:offlineObjects = @{}
$script:DocumentationLanguage = "en"
$script:objectSeparator = [System.Environment]::NewLine
$script:propertySeparator = ","
$script:DocumentationLanguage = ?? $DocumentationLanguage "en"
$script:objectSeparator = ?? $ObjectSeparator ([System.Environment]::NewLine)
$script:propertySeparator = ?? $PropertySeparator ","
$loadExportedInfo = $false
if($documentationObj.Object."@ObjectFileName") {
$path = [IO.Path]::GetDirectoryName($documentationObj.Object."@ObjectFileName")
for($i = 0;$i -lt 2;$i++)
{
if($i -gt 0)
{
# Get parent directory
$path = [io.path]::GetDirectoryName($path)
}
$migFileName = Join-Path $path "MigrationTable.json"
try
{
if([IO.File]::Exists($migFileName))
{
Write-Log "Load Migration table from $migFileName"
$script:migTable = ConvertFrom-Json (Get-Content $migFileName -Raw)
}
}
catch {}
}
if(-not $script:migTable) {
Write-Log "Migration table not found" 2
}
}
Get-ObjectDocumentation $documentationObj
}
@@ -561,7 +606,7 @@ function Get-ObjectTypeString
function Add-BasicDefaultValues
{
param($obj, $objectType)
param($obj, $objectType, $profileTypeName = $null)
Add-BasicPropertyValue (Get-LanguageString "SettingDetails.nameName") (Get-GraphObjectName $obj $objectType)
Add-BasicPropertyValue (Get-LanguageString "SettingDetails.descriptionName") $obj.description
@@ -572,7 +617,7 @@ function Add-BasicDefaultValues
if($objInfo)
{
$platformType = Get-LanguageString "Platform.$($objInfo.PlatformLanguageId)"
$profileType = Get-LanguageString "ConfigurationTypes.$($objInfo.PolicyType)"
$profileType = (?? $profileTypeName (Get-LanguageString "ConfigurationTypes.$($objInfo.PolicyType)"))
if($platformType) { Add-BasicPropertyValue (Get-LanguageString "SettingDetails.platformSupported") $platformType }
if($profileType) { Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") $profileType }
@@ -636,6 +681,19 @@ function Add-BasicDefaultValues
}
}
function Add-CustomTable
{
param($TableId, $Columns = @("Name", "Value"), $Values, [int]$Order = 100, $LanguageId = "")
$script:customTables += [PSCustomObject]@{
Id = $TableId
Columns = $Columns
Values = $Values
LanguageId = $LanguageId
Order = $Order
}
}
function Add-BasicAdditionalValues
{
param($obj, $objectType)
@@ -647,6 +705,10 @@ function Add-BasicAdditionalValues
if($obj.createdDateTime -is [DateTime])
{
$tmpDate = $obj.createdDateTime
if($tmpDate.Kind -eq "UTC")
{
$tmpDate = $tmpDate.ToLocalTime()
}
}
else
{
@@ -670,6 +732,10 @@ function Add-BasicAdditionalValues
if($obj.lastModifiedDateTime -is [DateTime])
{
$tmpDate = $obj.lastModifiedDateTime
if($tmpDate.Kind -eq "UTC")
{
$tmpDate = $tmpDate.ToLocalTime()
}
}
else
{
@@ -691,6 +757,10 @@ function Add-BasicAdditionalValues
if($obj.modifiedDateTime -is [DateTime])
{
$tmpDate = $obj.modifiedDateTime
if($tmpDate.Kind -eq "UTC")
{
$tmpDate = $tmpDate.ToLocalTime()
}
}
else
{
@@ -993,15 +1063,26 @@ function Invoke-TranslateADMXObject
$rawValues += $rawValue
}
$status = (?: ($definitionValue.enabled -eq $true) $enabledStr $disabledStr)
$combinedValue = $status
if($values) {
$combinedValue += $script:objectSeparator + ($values -join $script:objectSeparator)
}
$combinedValueWithLabel = $status
if($valuesWithLabel) {
$combinedValueWithLabel += $script:objectSeparator + ($valuesWithLabel -join $script:objectSeparator)
}
$script:objectSettingsData += New-Object PSObject -Property @{
Name = $definitionValue.definition.displayName
Description = $definitionValue.definition.explainText
Status = $status
Value = $values -join $script:objectSeparator
CombinedValue = ($status + $script:objectSeparator + ($values -join $script:objectSeparator))
CombinedValue = $combinedValue #($status + $script:objectSeparator + ($values -join $script:objectSeparator))
ValueWithLabel = $valuesWithLabel -join $script:objectSeparator
FullValueTable = $tableValue
CombinedValueWithLabel = ($status + $script:objectSeparator + ($valuesWithLabel -join $script:objectSeparator))
CombinedValueWithLabel = $combinedValueWithLabel #($status + $script:objectSeparator + ($valuesWithLabel -join $script:objectSeparator))
RawValue = $rawValues -join $script:propertySeparator
Class = $definitionValue.definition.classType
DefinitionId = $definitionValue.definition.id
@@ -1065,9 +1146,9 @@ function Invoke-TranslateSettingsObject
$cfgSettings = $obj.Settings
}
if(-not $global:cfgCategories)
if(-not $global:cfgCategories -or -not ($global:cfgCategories | where { $_.settingUsage -eq "configuration" }))
{
$global:cfgCategories = (Invoke-GraphRequest "/deviceManagement/configurationCategories?`$filter=platforms has 'windows10' and technologies has 'mdm'" -ODataMetadata "minimal" @params).Value
$global:cfgCategories += (Invoke-GraphRequest "/deviceManagement/configurationCategories?`$filter=platforms has 'windows10' and technologies has 'mdm'" -ODataMetadata "minimal" @params).Value
}
if(-not $global:cachedCfgSettings)
@@ -1166,13 +1247,23 @@ function Add-SettingsSetting
$objCategory = $categoryDef
}
$settingName = ""
$settingDescription = ""
if($settingsDef.displayName) {
$settingName = $settingsDef.displayName.Trim([Environment]::NewLine).Trim("`n")
}
if($settingsDef.description) {
$settingDescription = $settingsDef.description.Trim([Environment]::NewLine).Trim("`n")
}
$settingInfo = [PSCustomObject]@{
SettingId = $settingsDef.Id
SettingKey = ""
SettingName = $settingsDef.Name
Name = $settingsDef.displayName
Description=$settingsDef.description
CategortyId = $objCategory.id
Name = $settingName
Description = $settingDescription
CategoryId = $objCategory.id
Category=$objCategory.displayName
CategoryDefinition=$objCategory
SubCategory=$subCategory.displayName
@@ -1348,6 +1439,85 @@ function Add-SettingsSetting
#endregion
#region Compliance V2 Policies - Based on Settings Catalog
function Invoke-TranslateComplianceV2Object
{
param($obj, $objectType)
$platformType = Get-LanguageString "Platform.$($obj.platforms)"
Add-BasicDefaultValues $obj $objectType
Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "ConfigurationTypes.settingsCatalog")
Add-BasicPropertyValue (Get-LanguageString "SettingDetails.platformSupported") $platformType
Add-BasicAdditionalValues $obj $objectType
$params = @{}
## Set language
if($script:DocumentationLanguage)
{
$params.Add("AdditionalHeaders", @{"Accept-Language"=$script:DocumentationLanguage})
}
$cfgSettings = (Invoke-GraphRequest "/deviceManagement/compliancePolicies('$($obj.Id)')/settings?`$expand=settingDefinitions&top=1000" -ODataMetadata "minimal" @params).Value
if($obj.'@ObjectFromFile')
{
$cfgSettings = $obj.Settings
}
if(-not $global:cfgCategories -or -not ($global:cfgCategories | where { $_.settingUsage -eq "compliance" }))
{
$global:cfgCategories += (Invoke-GraphRequest "/deviceManagement/complianceCategories?`$templateCategory=True&`$filter=platforms has 'linux' and technologies has 'linuxMdm'" -ODataMetadata "minimal" @params).Value
}
if(-not $global:cachedCfgSettings)
{
$global:cachedCfgSettings = @{}
}
$script:settingCatalogasCategories = @{}
foreach($cfgSetting in $cfgSettings)
{
if($obj.'@ObjectFromFile' -and -not $cfgSetting.settingDefinitions)
{
if($global:cachedCfgSettings.ContainsKey($cfgSetting.settingInstance.settingDefinitionId) -eq $false)
{
$defObj = Invoke-GraphRequest "/deviceManagement/configurationSettings/$($cfgSetting.settingInstance.settingDefinitionId)"
$global:cachedCfgSettings.Add($defObj.Id, $defObj)
}
}
else
{
$defObj = $cfgSetting.settingDefinitions | Where id -eq $cfgSetting.settingInstance.settingDefinitionId
if($global:cachedCfgSettings.ContainsKey($cfgSetting.settingInstance.settingDefinitionId) -eq $false)
{
$global:cachedCfgSettings.Add($defObj.Id, $defObj)
}
}
if(-not $defObj -or $script:settingCatalogasCategories.ContainsKey($defObj.categoryId)) { continue }
$catObj = $global:cfgCategories | Where Id -eq $defObj.categoryId
$rootCatObj = $global:cfgCategories | Where Id -eq $catObj.rootCategoryId
$script:settingCatalogasCategories.Add($defObj.categoryId, (New-Object PSObject -Property @{
Category=$catObj
RootCategory=$rootCatObj
}))
}
$script:curSettingsCatologPolicy = @()
$cfgSettings | % { Add-SettingsSetting $_.settingInstance $_.settingDefinitions } | Out-Null
foreach($item in ($script:curSettingsCatologPolicy | Select @{l="CategoryID";e={$_.CategoryDefinition.Id}}, @{l="SubCategoryID";e={$_.SubCategoryDefinition.Id}} -Unique))
{
$script:objectSettingsData += ($script:curSettingsCatologPolicy | Where { $_.CategoryDefinition.Id -eq $item.CategoryID -and $_.SubCategoryDefinition.Id -eq $item.SubCategoryID })
}
}
#endregion
#region Intent Objects (Endpoint Security)
function Get-IntentCategory
@@ -1530,7 +1700,7 @@ function Add-IntentSettingObjectToList
{
$passConstraint = ($dependencyItemObj.RawValue -ne $null -and $dependencyItemObj.RawValue.ToString() -ne "NotConfigured" -and $dependencyItemObj.RawValue.ToString() -ne "False")
}
if(-not $passConstraint) { break ]}
if(-not $passConstraint) { break }
}
if(-not $passConstraint)
@@ -2122,6 +2292,7 @@ function Invoke-TranslateSection
$value = $null
$valueSet = $false
$useParentProp = $false
$payloadFile = $false
#if($prop.enabled -eq $false -and $objInfo.ShowDisabled -ne $true) { continue }
@@ -2353,6 +2524,7 @@ function Invoke-TranslateSection
if($prop.filenameEntityKey -and $obj."$($prop.filenameEntityKey)")
{
$value = $obj."$($prop.filenameEntityKey)"
$payloadFile = $true
}
else
{
@@ -2506,6 +2678,23 @@ function Invoke-TranslateSection
if($addPropertyInfo)
{
Add-PropertyInfo (?: ($useParentProp -and $parent) $parent $prop) $value $rawValue
if($payloadFile -eq $true -and $obj.payload)
{
# Add payload file conetent as a property
$tmpProp = [PSCustomObject]@{
nameResourceKey = "uploadResult"
descriptionResourceKey = ""
entityKey = "payloadData"
dataType = 20
booleanActions = 0
category = $prop.Category
}
$propValue = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($obj.payload))
Add-PropertyInfo $tmpProp $propValue -originalValue $obj.payload
}
}
}
else
@@ -3592,6 +3781,7 @@ function Invoke-TranslateAssignments
"uninstallOnDeviceRemoval",
"isRemovable",
"useDeviceLicensing",
"preventManagedAppBackup",
"androidManagedStoreAppTrackIds",
"deliveryOptimizationPriority",
"installTimeSettings",
@@ -3692,7 +3882,7 @@ function Invoke-TranslateAssignments
}
$value = $tmpStr -f $tmpType
}
elseif($assignment.settings.$settingProp -eq "notConfigured")
elseif("$($assignment.settings.$settingProp)" -eq "notConfigured")
{
$value = Get-LanguageString "BooleanActions.notConfigured"
}
@@ -4234,7 +4424,7 @@ function local:Invoke-StartDocumentatiom
$script:migTable = $null
$script:scopeTags = $null
$diSource = $nul
$diSource = $null
$global:intentCategories = $null
$global:catRecommendedSettings = $null
$global:intentCategoryDefs = $null
@@ -4296,7 +4486,7 @@ function local:Invoke-StartDocumentatiom
$tmpObj | Add-Member Noteproperty -Name "GroupName" -Value (Get-ObjectTypeGroupName $tmpObj.ObjectType) -Force
}
if($groupSourceList.Count -eq 0) { contnue }
if($groupSourceList.Count -eq 0) { continue }
if($curObjectType.GroupId -eq "EndpointSecurity")
{
@@ -4550,13 +4740,21 @@ function local:Invoke-StartDocumentatiom
{
Write-Status "Process $((Get-GraphObjectName $tmpObj.Object $tmpObj.ObjectType)) ($($obj.ObjectType.Title)) - $($global:cbDocumentationType.SelectedItem.Name)"
$hasRawValue = $false
$documentedObj.Settings | % { if(($_.PSObject.Properties | Where Name -eq "RawValue")) { $hasRawValue=$true } }
$hasRawValue
$filteredSettings = @()
foreach($item in $documentedObj.Settings)
{
if(-not ($item.PSObject.Properties | Where Name -eq "RawValue") -or $documentedObj.UpdateFilteredObject -eq $false)
{
$filteredSettings = $documentedObj.Settings
break
if($hasRawValue -eq $false) {
$filteredSettings = $documentedObj.Settings
break
}
$filteredSettings += $item
continue
}
if($item.AlwaysAddValue -eq $true)
@@ -4929,6 +5127,10 @@ function Invoke-CSVProcessItem
{
$properties = @("GroupMode","Group","Category","SubCategory")
}
elseif($documentedObj.Assignments[0].Group)
{
$properties = @("GroupMode","Group","Category")
}
else
{
$properties = @("GroupMode","Groups","Category")
+189 -26
View File
@@ -10,7 +10,7 @@ This module will also document some objects based on PowerShell functions
function Get-ModuleVersion
{
'1.6.5'
'1.6.6'
}
function Invoke-InitializeModule
@@ -76,7 +76,8 @@ function Invoke-CDDocumentObject
Properties = @("Name","Value")
}
}
elseif($type -eq '#microsoft.graph.androidManagedStoreAppConfiguration') {
elseif($type -eq '#microsoft.graph.androidForWorkMobileAppConfiguration' -or
$type -eq '#microsoft.graph.androidManagedStoreAppConfiguration') {
Invoke-CDDocumentAndroidManagedStoreAppConfiguration $documentationObj
@@ -84,8 +85,7 @@ function Invoke-CDDocumentObject
Properties = @("Name","Value","Category","SubCategory")
}
}
elseif($type -eq '#microsoft.graph.androidForWorkMobileAppConfiguration' -or
$type -eq '#microsoft.graph.iosMobileAppConfiguration')
elseif($type -eq '#microsoft.graph.iosMobileAppConfiguration')
{
Invoke-CDDocumentMobileAppConfiguration $documentationObj
return [PSCustomObject]@{
@@ -186,7 +186,7 @@ function Get-CDAllCloudApps
{
if(-not $script:allCloudApps)
{
$script:allCloudApps = (Invoke-GraphRequest -url "/servicePrincipals?`$select=displayName,appId&top=999" -ODataMetadata "minimal").value
$script:allCloudApps = (Invoke-GraphRequest -url "/servicePrincipals?`$select=displayName,appId&top=999" -ODataMetadata "minimal" -AllPages).value
}
$script:allCloudApps
}
@@ -198,7 +198,7 @@ function Get-CDAllTenantApps
$script:allTenantApps = Get-DocOfflineObjects "Applications"
if(-not $script:allTenantApps)
{
$script:allTenantApps =(Invoke-GraphRequest -url "/deviceAppManagement/mobileApps?`$select=displayName,id&top=999" -ODataMetadata "minimal").value
$script:allTenantApps =(Invoke-GraphRequest -url "/deviceAppManagement/mobileApps?`$select=displayName,id&top=999" -ODataMetadata "minimal" -AllPages).value
}
}
$script:allTenantApps
@@ -422,7 +422,7 @@ function Add-CDDocumentCustomProfileValue
$value = $obj.startMenuAppListVisibility
if($value.IndexOf(", ") -eq -1)
{
$value = $value -replace ",",", " # Option values in json file has space afte , but value in object don't
$value = $value -replace ",",", " # Option values in json file has space after , but value in object don't
}
Invoke-TranslateOption $obj $prop -PropValue $value
return $false
@@ -908,6 +908,27 @@ function Add-CDDocumentCustomProfileProperty
}
elseif($obj.'@OData.Type' -like "#microsoft.graph.iosDeviceFeaturesConfiguration")
{
foreach($configuration in $obj.iosSingleSignOnExtension.configurations)
{
$configurationType = "notConfigured"
if($configuration."@OData.Type" -eq "#microsoft.graph.keyStringValuePair")
{
$configurationType = Get-LanguageString "SettingDetails.singleSignOnExtensionConfigurationsTypeColumnOptionString"
}
elseif($configuration."@OData.Type" -eq "#microsoft.graph.keyBooleanValuePair")
{
$configurationType = Get-LanguageString "SettingDetails.singleSignOnExtensionConfigurationsTypeColumnOptionBoolean"
}
elseif($configuration."@OData.Type" -eq "#microsoft.graph.keyIntegerValuePair")
{
$configurationType = Get-LanguageString "SettingDetails.singleSignOnExtensionConfigurationsTypeColumnOptionInteger"
}
$configuration | Add-Member Noteproperty -Name "configurationKey" -Value $configuration.key -Force
$configuration | Add-Member Noteproperty -Name "configurationValue" -Value $configuration.value -Force
$configuration | Add-Member Noteproperty -Name "configurationType" -Value $configurationType -Force
}
#singleSignOnSettings
$obj | Add-Member Noteproperty -Name "kerberosPrincipalName" -Value (?? $obj.singleSignOnSettings.kerberosPrincipalName "notConfigured") -Force
@@ -1180,6 +1201,12 @@ function Add-CDDocumentCustomProfileProperty
}
elseif($obj.'@OData.Type' -eq "#microsoft.graph.windows10EnrollmentCompletionPageConfiguration")
{
$installProgressTimeout = $obj.installProgressTimeoutInMinutes
if($installProgressTimeout -eq 0) {
$installProgressTimeout = 60
}
$obj | Add-Member Noteproperty -Name "InstallProgressTimeout" -Value $installProgressTimeout
if($obj.selectedMobileAppIds.Count -eq 0)
{
$apps = Get-LanguageString "EnrollmentStatusScreen.Apps.useSelectedAppsAll"
@@ -1212,6 +1239,10 @@ function Add-CDDocumentCustomProfileProperty
$returnCodes = @()
$detectionRules = @()
$requirementRules = @()
$activeScripts = @()
$activeInstallScript = $null
$activeUninstallScript = $null
foreach($rc in $obj.returnCodes)
{
$returnCodes += [PSCustomObject]@{
@@ -1240,6 +1271,46 @@ function Add-CDDocumentCustomProfileProperty
}
}
if($obj.activeInstallScript.'#ScriptInfo')
{
$scriptType = "install"
$obj.installCommandLine = $null
$installType = "Win32Program.installScript"
$activeInstallScript = [PSCustomObject]@{
scriptType = $scriptType
scriptName = $obj.activeInstallScript.'#ScriptInfo'.displayName
scriptContent = $obj.activeInstallScript.'#ScriptInfo'.ScriptContent
enforceSignatureCheck = $obj.activeInstallScript.'#ScriptInfo'.enforceSignatureCheck
runAs32Bit = $obj.activeInstallScript.'#ScriptInfo'.runAs32Bit
}
Add-ObjectScript $header ("{0} - {1}" -f @($obj.displayName,$obj.activeInstallScript.'#ScriptInfo'.displayName)) $obj.activeInstallScript.'#ScriptInfo'.content
}
else
{
$installType = "Win32Program.installCommand"
}
if($obj.activeUninstallScript.'#ScriptInfo')
{
$scriptType = "uninstall"
$obj.uninstallCommandLine = $null
$uninstallType = "Win32Program.uninstallScript"
$activeUninstallScript = [PSCustomObject]@{
scriptType = $scriptType
scriptName = $obj.activeUninstallScript.'#ScriptInfo'.displayName
scriptContent = $obj.activeUninstallScript.'#ScriptInfo'.ScriptContent
enforceSignatureCheck = $obj.activeUninstallScript.'#ScriptInfo'.enforceSignatureCheck
runAs32Bit = $obj.activeUninstallScript.'#ScriptInfo'.runAs32Bit
}
Add-ObjectScript $header ("{0} - {1}" -f @($obj.displayName,$obj.activeUninstallScript.'#ScriptInfo'.displayName)) $obj.activeUninstallScript.'#ScriptInfo'.content
}
else
{
$uninstallType = "Win32Program.uninstallCommand"
}
foreach($rule in $obj.requirementRules)
{
if($rule.'@OData.Type' -eq "#microsoft.graph.win32LobAppFileSystemRequirement")
@@ -1308,7 +1379,11 @@ function Add-CDDocumentCustomProfileProperty
$obj | Add-Member Noteproperty -Name "requirementRulesTranslated" -Value $requirementRules -Force
$obj | Add-Member Noteproperty -Name "detectionRulesTranslated" -Value $detectionRules -Force
$obj | Add-Member Noteproperty -Name "returnCodes" -Value $returnCodes -Force
$obj | Add-Member Noteproperty -Name "activeInstallScript" -Value $activeInstallScript -Force
$obj | Add-Member Noteproperty -Name "activeUninstallScript" -Value $activeUninstallScript -Force
$obj | Add-Member Noteproperty -Name "win10Release" -Value (Get-LanguageString "MinimumOperatingSystem.Windows.V10Release.release$($obj.minimumSupportedWindowsRelease)") -Force
$obj | Add-Member Noteproperty -Name "installerType" -Value (Get-LanguageString $installType) -Force
$obj | Add-Member Noteproperty -Name "uninstallerType" -Value (Get-LanguageString $uninstallType) -Force
}
elseif($obj.'@OData.Type' -eq "#microsoft.graph.deviceHealthScript")
{
@@ -1329,6 +1404,17 @@ function Add-CDDocumentCustomProfileProperty
Add-ObjectScript $header ("{1} - {0}" -f $obj.displayName,$header) $obj.remediationScriptContent
}
}
elseif($obj.'@OData.Type' -eq "#microsoft.graph.hardwareConfiguration")
{
$vendor = ?? (Get-LanguageString "HardwareConfig.Settings.Tab.HardwareDropDown.$($obj.hardwareConfigurationFormat)" -IgnoreMissing) $obj.hardwareConfigurationFormat
$obj | Add-Member Noteproperty -Name "vendor" -Value $vendor
if($obj.configurationFileContent)
{
$obj | Add-Member Noteproperty -Name "configurationFileContentString" -Value ([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String(($obj.configurationFileContent))))
$header = Get-LanguageString "HardwareConfig.Settings.Tab.Configurations.perDevicePassword"
Add-ObjectScript $header ("{1} - {0}" -f $obj.displayName,$header) $obj.configurationFileContent
}
}
elseif($obj.'@OData.Type' -eq "#microsoft.graph.deviceManagementScript")
{
if($obj.ScriptContent)
@@ -1852,8 +1938,21 @@ function Invoke-CDDocumentAndroidManagedStoreAppConfiguration
###################################################
# Basic info
###################################################
$profileString = $null
if($obj.profileApplicability -eq "default")
{
$profileString = Get-LanguageString "ProfileType.workProfileAndDeviceOwner"
}
elseif($obj.profileApplicability -eq "androidWorkProfile")
{
$profileString = Get-LanguageString "ProfileType.workProfileOnly"
}
elseif($obj.profileApplicability -eq "androidDeviceOwner")
{
$profileString = Get-LanguageString "ProfileType.deviceOwnerOnly"
}
Add-BasicDefaultValues $obj $objectType
Add-BasicDefaultValues $obj $objectType $profileString
Add-BasicAdditionalValues $obj $objectType
#Add-BasicPropertyValue (Get-LanguageString "TableHeaders.configurationType") (Get-LanguageString "SettingDetails.appConfiguration")
#Add-BasicPropertyValue (Get-LanguageString "Inputs.enrollmentTypeLabel") (Get-LanguageString "EnrollmentType.devicesWithEnrollment")
@@ -1885,26 +1984,20 @@ function Invoke-CDDocumentAndroidManagedStoreAppConfiguration
}
# Not the best way. BundleId should be used but then full app info is required
if($obj.packageId -eq "com.microsoft.office.outlook*")
if($obj.packageId -eq "com.microsoft.office.outlook")
{
if([IO.File]::Exists(($global:AppRootFolder + "\Documentation\ObjectInfo\#AppConfigOutlookDevice.json")))
{
$tmp = $obj.settings | Where { $_.appConfigKey -eq "com.microsoft.outlook.EmailProfile.AccountType" }
$tmp = $payloadData.managedProperty | Where { $_.key -eq "com.microsoft.outlook.EmailProfile.AccountType" }
if($tmp){ $configEmail=$true }else{ $configEmail=$false }
$outlookSettings = [PSCustomObject]@{
configureEmail = $configEmail
}
foreach($setting in $obj.settings)
foreach($managedProperty in $payloadData.managedProperty)
{
if($setting.appConfigKeyType -eq "booleanType")
{
$value = $setting.appConfigKeyValue -eq "true"
}
else
{
$value = $setting.appConfigKeyValue
}
$outlookSettings | Add-Member Noteproperty -Name $setting.appConfigKey -Value $value -Force
$valueProperty = $managedProperty.PSObject.Properties | Where-Object Name -like "value*"
$outlookSettings | Add-Member Noteproperty -Name $managedProperty.key -Value $valueProperty.Value -Force
}
$jsonObj = Get-Content ($global:AppRootFolder + "\Documentation\ObjectInfo\#AppConfigOutlookDevice.json") | ConvertFrom-Json
@@ -1914,6 +2007,8 @@ function Invoke-CDDocumentAndroidManagedStoreAppConfiguration
$addedSettings = Get-DocumentedSettings
$additionalSettings = @()
foreach($managedProperty in $payloadData.managedProperty)
{
if(($addedSettings | Where EntityKey -eq $managedProperty.key)) { continue }
@@ -1926,14 +2021,44 @@ function Invoke-CDDocumentAndroidManagedStoreAppConfiguration
$value = $value -join ","
}
Add-CustomSettingObject ([PSCustomObject]@{
$additionalSettings += ([PSCustomObject]@{
Name = $managedProperty.key
ValueType = $valueProperty.Name.SubString(5)
Value = $value
EntityKey = $managedProperty.key
Category = Get-LanguageString "TACSettings.generalSettings"
SubCategory = Get-LanguageString "SettingDetails.additionalConfiguration"
})
}
if($additionalSettings.Count -gt 0) {
Add-CustomTable "AdditionalSettings" @("Name","ValueType","Value") $additionalSettings -Order 110
}
$permissions = @()
foreach($permission in $obj.permissionActions)
{
$permissionTemp = $permission.permission.Split('.')[-1]
if($permissionTemp) {
$permissionLngId = $permissionTemp -replace "_", ""
$permissionStr = ?? (Get-LanguageString "AndroidForWorkAppPermissions.Permissions.$($permissionLngId)") $permissionTemp
}
else {
$permissionStr = $permission.permission
}
$permissions += ([PSCustomObject]@{
Permission = $permissionStr
Action = ?? (Get-LanguageString "AndroidForWorkAppPermissions.Action.$($permission.action)") $permission.action
EntityKey = $permission.permission
})
}
if($permissions.Count -gt 0) {
Add-CustomTable "Permissions" @("Permission","Action") $permissions -Order 115 -LanguageId "AndroidForWorkAppPermissions.permissionsTitle"
}
}
}
@@ -1990,11 +2115,22 @@ function Invoke-CDDocumentMobileAppConfiguration
{
$name = $xml.dict.ChildNodes[$i].'#text'
$i++
$value = $xml.dict.ChildNodes[$i].'#text'
if($xml.dict.ChildNodes[$i].Name -eq "true" -or $xml.dict.ChildNodes[$i].Name -eq "false")
{
$value = $xml.dict.ChildNodes[$i].Name
$type = "boolean"
}
else
{
$value = $xml.dict.ChildNodes[$i].'#text'
$type = $xml.dict.ChildNodes[$i].Name
}
Add-CustomSettingObject ([PSCustomObject]@{
Name = $name
Value = $value
ValueType = $type
EntityKey = $name
Category = $category
})
@@ -2002,8 +2138,18 @@ function Invoke-CDDocumentMobileAppConfiguration
}
else
{
$isOutlook = $false
foreach($targetedAppId in $obj.targetedMobileApps) {
$app = $allApps | Where Id -eq $targetedAppId
if($app.displayName -eq "Microsoft Outlook") {
$isOutlook = $true
break
}
}
# Not the best way. BundleId should be used but then full app info is required
if(($obj.packageId | Where { $_.appConfigKey -like "com.microsoft.outlook*" }))
if($isOutlook -or ($obj.packageId | Where { $_.appConfigKey -like "com.microsoft.outlook*" }))
{
if([IO.File]::Exists(($global:AppRootFolder + "\Documentation\ObjectInfo\#AppConfigOutlookDevice.json")))
{
@@ -2164,7 +2310,7 @@ function Invoke-CDDocumentCountryNamedLocation
$countryList = @()
foreach($country in $obj.countriesAndRegions)
{
$countryList += Get-LanguageString "CountryNames.countryName$($country.ToLower())"
$countryList += Get-LanguageString "AzureIAMCommon.CountryNames.countryName$($country.ToUpper())"
}
Add-CustomSettingObject ([PSCustomObject]@{
@@ -2263,6 +2409,10 @@ function Invoke-CDDocumentTermsOfUse
if($obj.termsExpiration.startDateTime -is [DateTime])
{
$tmpDate = $obj.termsExpiration.startDateTime
if($tmpDate.Kind -eq "UTC")
{
$tmpDate = $tmpDate.ToLocalTime()
}
}
else
{
@@ -3139,7 +3289,7 @@ function Invoke-CDDocumentConditionalAccess
Add-CustomSettingObject ([PSCustomObject]@{
Name = Get-LanguageString "AzureCA.WhatIfBlade.authenticationStrength"
Value = $termsOfUse -join $script:objectSeparator
Value = $authenticationStrngth -join $script:objectSeparator
Category = $category
SubCategory = ""
EntityKey = "authenticationStrength"
@@ -4118,7 +4268,17 @@ function Invoke-CDDocumentWindowsKioskConfiguration
{
try
{
$startDateObj = Get-Date $obj.windowsKioskForceUpdateSchedule.startDateTime -ErrorAction Stop
if($obj.windowsKioskForceUpdateSchedule.startDateTime -is [DateTime]) {
$startDateObj = $obj.windowsKioskForceUpdateSchedule.startDateTime
if($startDateObj.Kind -eq "UTC")
{
$startDateObj = $startDateObj.ToLocalTime()
}
}
else
{
$startDateObj = Get-Date $obj.windowsKioskForceUpdateSchedule.startDateTime -ErrorAction Stop
}
Add-CustomSettingObject ([PSCustomObject]@{
Name = Get-LanguageString "SettingDetails.kioskStartDateTime"
@@ -4572,15 +4732,18 @@ function Invoke-CDDocumentTranslateSectionFile
if($null -eq $obj.deviceCompliancePolicyScript)
{
$propValue = Get-LanguageString "BooleanActions.notConfigured"
$rawValue = "notConfigured"
}
else
{
$propValue = Get-LanguageString "BooleanActions.require"
$rawValue = "require"
}
Add-CustomSettingObject ([PSCustomObject]@{
Name = Get-LanguageString "SettingDetails.adminConfiguredComplianceSettingName"
Value = $propValue
EntityKey = "deviceCompliancePolicyScript"
RawValue = $rawValue
Category = $category
SubCategory = $null
})
+10 -3
View File
@@ -1,6 +1,6 @@
function Get-ModuleVersion
{
'1.0.1'
'1.1.0'
}
function Invoke-InitializeModule
@@ -74,7 +74,7 @@ function Invoke-HTMLPreProcessItems
Write-Log "CSS file not specified. Using default" 2
$HTMLCssFile = $defaultCSSFile
}
elseif([IO.File]::Exists($HTMLCssFile) -eq -$false)
elseif([IO.File]::Exists($HTMLCssFile) -eq $false)
{
Write-Log "CSS file $($HTMLCssFile) not found. Using default" 2
$HTMLCssFile = $defaultCSSFile
@@ -332,7 +332,9 @@ function Invoke-HTMLProcessItem
$lngId = ?: ($tableType -eq "BasicInfo") "SettingDetails.basics" "TableHeaders.settings" -AddCategories
Add-HTMLTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId -AddCategories -AddSubcategories
if(($documentedObj.$tableType).Count -gt 0) {
Add-HTMLTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId -AddCategories -AddSubcategories
}
}
if(($documentedObj.ComplianceActions | measure).Count -gt 0)
@@ -351,6 +353,11 @@ function Invoke-HTMLProcessItem
Add-HTMLObjectSettings $obj $objectType $documentedObj
foreach($customTable in ($documentedObj.CustomTables | Sort-Object -Property Order))
{
Add-HTMLTableItems $obj $objectType $customTable.Values $customTable.Columns $customTable.LanguageId -AddCategories -AddSubcategories
}
if(($documentedObj.Assignments | measure).Count -gt 0)
{
if($documentedObj.Assignments[0].RawIntent)
+265
View File
@@ -0,0 +1,265 @@
function Get-ModuleVersion
{
'1.0.0'
}
function Invoke-InitializeModule
{
Add-OutputType ([PSCustomObject]@{
Name = "Json"
Value = "json"
OutputOptions = (Add-JsonOptionsControl)
PreProcess = { Invoke-JsonPreProcessItems @args }
NewObjectGroup = { Invoke-JsonNewObjectGroup @args }
NewObjectType = { Invoke-JsonNewObjectType @args }
Process = { Invoke-JsonProcessItem @args }
PostProcess = { Invoke-JsonPostProcessItems @args }
})
}
function Add-JsonOptionsControl
{
$script:jsonForm = Get-XamlObject ($global:AppRootFolder + "\Xaml\DocumentationJsonOptions.xaml") -AddVariables
Set-XamlProperty $script:jsonForm "txtJsonFileName" "Text" (Get-Setting "Documentation" "JsonDocumentName" "")
Set-XamlProperty $script:jsonForm "chkJsonOpenDocument" "IsChecked" (Get-Setting "Documentation" "JsonOpenFile" $true)
$outputFileTypes = '[ { "Name": "Single file", "Value": "Full" }, { "Name": "One file per object type", "Value": "ObjectType" } ]' | ConvertFrom-Json
Set-XamlProperty $script:jsonForm "cbJsonOutputFile" "ItemsSource" $outputFileTypes
Set-XamlProperty $script:jsonForm "cbJsonOutputFile" "SelectedValue" (Get-Setting "Documentation" "JsonOutputFileType" "Full")
Add-XamlEvent $script:jsonForm "browseJsonFileName" "add_click" {
$sf = [System.Windows.Forms.SaveFileDialog]::new()
$sf.DefaultExt = "json"
$sf.Filter = "Json (*.json)|*.json|All files (*.*)|*.*"
if ($sf.ShowDialog() -eq "OK")
{
Set-XamlProperty $script:jsonForm "txtJsonFileName" "Text" $sf.FileName
Save-Setting "Documentation" "JsonDocumentName" $sf.FileName
}
}
$script:jsonForm
}
function Invoke-JsonPreProcessItems
{
$script:jsonAllObjects = [System.Collections.Generic.List[object]]::new()
$script:jsonCurrentTypeObjects = [System.Collections.Generic.List[object]]::new()
$script:jsonCurrentTypeName = $null
$script:jsonOutputType = Get-XamlProperty $script:jsonForm "cbJsonOutputFile" "SelectedValue" "Full"
$jsonFileName = Get-XamlProperty $script:jsonForm "txtJsonFileName" "Text" ""
Save-Setting "Documentation" "JsonDocumentName" $jsonFileName
Save-Setting "Documentation" "JsonOpenFile" (Get-XamlProperty $script:jsonForm "chkJsonOpenDocument" "IsChecked")
Save-Setting "Documentation" "JsonOutputFileType" $script:jsonOutputType
$script:jsonOutFile = Expand-FileName (?? $jsonFileName "%MyDocuments%\%Organization%-%Date%.json")
$script:jsonDocumentPath = [IO.Path]::GetDirectoryName($script:jsonOutFile)
}
function Invoke-JsonNewObjectGroup
{
param($groupId)
# Groups are not used in flat Json output
}
function Invoke-JsonNewObjectType
{
param($objectTypeName)
if ($script:jsonOutputType -eq "ObjectType" -and
$script:jsonCurrentTypeName -and
$script:jsonCurrentTypeObjects.Count -gt 0)
{
Save-JsonTypeFile $script:jsonCurrentTypeName $script:jsonCurrentTypeObjects
}
$script:jsonCurrentTypeName = $objectTypeName
$script:jsonCurrentTypeObjects = [System.Collections.Generic.List[object]]::new()
}
function Invoke-JsonProcessItem
{
param($obj, $objectType, $documentedObj)
if (-not $documentedObj -or -not $obj -or -not $objectType) { return }
$objName = Get-GraphObjectName $obj $objectType
try
{
$jsonObj = [ordered]@{
objectType = $objectType.Title
name = $objName
}
# BasicInfo as a flat key/value object
if ($documentedObj.BasicInfo.Count -gt 0)
{
$basicInfo = [ordered]@{}
foreach ($item in $documentedObj.BasicInfo)
{
if ($item.Name) { $basicInfo[$item.Name] = $item.Value }
}
$jsonObj.basicInfo = $basicInfo
}
# Detailed settings as an array
if ($documentedObj.FilteredSettings.Count -gt 0)
{
$settings = [System.Collections.Generic.List[object]]::new()
foreach ($item in $documentedObj.FilteredSettings)
{
$setting = [ordered]@{ name = $item.Name; value = $item.Value }
if ($item.Category) { $setting.category = $item.Category }
if ($item.SubCategory) { $setting.subCategory = $item.SubCategory }
$settings.Add($setting)
}
$jsonObj.settings = $settings
}
# Compliance actions
if (($documentedObj.ComplianceActions | Measure-Object).Count -gt 0)
{
$actions = [System.Collections.Generic.List[object]]::new()
foreach ($item in $documentedObj.ComplianceActions)
{
$actions.Add([ordered]@{
action = $item.Action
schedule = $item.Schedule
messageTemplate = $item.MessageTemplate
emailCC = $item.EmailCC
})
}
$jsonObj.complianceActions = $actions
}
# Applicability rules
if (($documentedObj.ApplicabilityRules | Measure-Object).Count -gt 0)
{
$rules = [System.Collections.Generic.List[object]]::new()
foreach ($item in $documentedObj.ApplicabilityRules)
{
$rules.Add([ordered]@{
rule = $item.Rule
property = $item.Property
value = $item.Value
})
}
$jsonObj.applicabilityRules = $rules
}
# Custom tables — each becomes a top-level array keyed by the last segment of the language ID
foreach ($customTable in ($documentedObj.CustomTables | Sort-Object -Property Order))
{
if (-not $customTable.Values -or ($customTable.Values | Measure-Object).Count -eq 0) { continue }
$tableKey = if ($customTable.LanguageId) { $customTable.LanguageId.Split('.')[-1] } else { "customTable" }
$tableArr = [System.Collections.Generic.List[object]]::new()
foreach ($item in $customTable.Values)
{
$tableObj = [ordered]@{}
foreach ($col in $customTable.Columns)
{
$colName = $col.Split('.')[-1]
$tableObj[$colName] = "$($item.$colName)"
}
$tableArr.Add($tableObj)
}
$jsonObj[$tableKey] = $tableArr
}
# Assignments
if (($documentedObj.Assignments | Measure-Object).Count -gt 0)
{
$assignments = [System.Collections.Generic.List[object]]::new()
$hasRawIntent = $null -ne $documentedObj.Assignments[0].RawIntent
foreach ($item in $documentedObj.Assignments)
{
if ($hasRawIntent)
{
$assignObj = [ordered]@{
groupMode = $item.GroupMode
group = $item.Group
}
if ($null -ne $item.Filter) { $assignObj.filter = $item.Filter }
if ($null -ne $item.FilterMode) { $assignObj.filterMode = $item.FilterMode }
if ($item.Settings)
{
$settingsObj = [ordered]@{}
foreach ($key in $item.Settings.Keys)
{
if ($key -in @("Category","RawIntent")) { continue }
$settingsObj[$key] = $item.Settings[$key]
}
$assignObj.settings = $settingsObj
}
}
else
{
$assignObj = [ordered]@{ group = $item.Group }
if ($item.PSObject.Properties.Name -contains "Filter") { $assignObj.filter = $item.Filter }
if ($item.PSObject.Properties.Name -contains "FilterMode") { $assignObj.filterMode = $item.FilterMode }
}
$assignments.Add($assignObj)
}
$jsonObj.assignments = $assignments
}
# Scripts — included when "Document scripts" is checked in the documentation form
if ($global:chkIncludeScripts.IsChecked -and ($documentedObj.Scripts | Measure-Object).Count -gt 0)
{
$scripts = [System.Collections.Generic.List[object]]::new()
foreach ($scriptItem in $documentedObj.Scripts)
{
if (-not $scriptItem.ScriptContent) { continue }
$scripts.Add([ordered]@{
caption = $scriptItem.Caption
content = $scriptItem.ScriptContent
})
}
if ($scripts.Count -gt 0) { $jsonObj.scripts = $scripts }
}
$script:jsonCurrentTypeObjects.Add($jsonObj)
if ($script:jsonOutputType -ne "ObjectType") { $script:jsonAllObjects.Add($jsonObj) }
}
catch
{
Write-LogError "Failed to process object $objName" $_.Exception
}
}
function Invoke-JsonPostProcessItems
{
$openFile = (Get-XamlProperty $script:jsonForm "chkJsonOpenDocument" "IsChecked") -eq $true
if ($script:jsonOutputType -eq "ObjectType")
{
if ($script:jsonCurrentTypeName -and $script:jsonCurrentTypeObjects.Count -gt 0)
{
Save-JsonTypeFile $script:jsonCurrentTypeName $script:jsonCurrentTypeObjects
}
Write-Log "Json documentation saved to folder: $($script:jsonDocumentPath)"
}
else
{
$jsonContent = ConvertTo-Json -InputObject @($script:jsonAllObjects) -Depth 20
Save-DocumentationFile $jsonContent $script:jsonOutFile -OpenFile:$openFile
}
}
function Save-JsonTypeFile
{
param($typeName, $objects)
$safeTypeName = Remove-InvalidFileNameChars ($typeName.Replace(" ", "_"))
$typeFileName = [IO.Path]::Combine($script:jsonDocumentPath, "$safeTypeName.json")
$jsonContent = ConvertTo-Json -InputObject @($objects) -Depth 20
Save-DocumentationFile $jsonContent $typeFileName
Write-Log "Saved $($objects.Count) objects to $typeFileName"
}
+16 -5
View File
@@ -1,6 +1,6 @@
function Get-ModuleVersion
{
'1.1.1'
'1.2.0'
}
function Invoke-InitializeModule
@@ -29,6 +29,7 @@ function Add-MDOptionsControl
Set-XamlProperty $script:mdForm "chkMDOpenDocument" "IsChecked" (Get-Setting "Documentation" "MDOpenFile" $true)
Set-XamlProperty $script:mdForm "cbMDDocumentOutputFile" "ItemsSource" ("[ { Name: `"Single file`",Value: `"Full`" }, { Name: `"One file per object`",Value: `"Object`" }]" | ConvertFrom-Json)
Set-XamlProperty $script:mdForm "cbMDDocumentOutputFile" "SelectedValue" (Get-Setting "Documentation" "MDDocumentFileType" "Full")
Set-XamlProperty $script:mdForm "cbMDDocumentSkipDate" "IsChecked" ((Get-Setting "Documentation" "MDDocumentSkipDate" "False") -eq "True")
Add-XamlEvent $script:mdForm "browseMDDocumentName" "add_click" {
$sf = [System.Windows.Forms.SaveFileDialog]::new()
@@ -72,6 +73,7 @@ function Invoke-MDPreProcessItems
Save-Setting "Documentation" "MDCSSFile" (Get-XamlProperty $script:mdForm "txtMDCSSFile" "Text" "")
Save-Setting "Documentation" "MDOpenFile" (Get-XamlProperty $script:mdForm "chkMDOpenDocument" "IsChecked")
Save-Setting "Documentation" "MDDocumentFileType" (Get-XamlProperty $script:mdForm "cbMDDocumentOutputFile" "SelectedValue" '')
Save-Setting "Documentation" "MDDocumentSkipDate" (Get-XamlProperty $script:mdForm "cbMDDocumentSkipDate" "IsChecked")
$defaultCSSFile = $global:AppRootFolder + "\Documentation\DefaultMDStyle.css"
$MDCssFile = Get-XamlProperty $script:mdForm "txtMDCSSFile" "Text" $defaultCSSFile
@@ -81,7 +83,7 @@ function Invoke-MDPreProcessItems
Write-Log "CSS file not specified. Using default" 2
$MDCssFile = $defaultCSSFile
}
elseif([IO.File]::Exists($MDCssFile) -eq -$false)
elseif([IO.File]::Exists($MDCssFile) -eq $false)
{
Write-Log "CSS file $($MDCssFile) not found. Using default" 2
$MDCssFile = $defaultCSSFile
@@ -142,7 +144,9 @@ function Invoke-MDPostProcessItems
$script:mdContent.AppendLine("*Organization:* $($global:Organization.displayName)`n")
$script:mdContent.AppendLine("*Generated by:* $userName$mail`n")
$script:mdContent.AppendLine("*Generated:* $((Get-Date).ToShortDateString()) $((Get-Date).ToLongTimeString())`n")
if((Get-XamlProperty $script:mdForm "cbMDDocumentSkipDate" "IsChecked") -ne $true) {
$script:mdContent.AppendLine("*Generated:* $((Get-Date).ToShortDateString()) $((Get-Date).ToLongTimeString())`n")
}
if($script:sectionAnchors.Count -gt 0)
{
@@ -265,7 +269,7 @@ function Invoke-MDProcessItem
foreach($prop in $global:txtMDCustomProperties.Text.Split(","))
{
# This will add language support for custom columens (or replacing existing header)
# This will add language support for custom columns (or replacing existing header)
$propInfo = $prop.Split('=')
if(($propInfo | measure).Count -gt 1)
{
@@ -285,7 +289,9 @@ function Invoke-MDProcessItem
$lngId = ?: ($tableType -eq "BasicInfo") "SettingDetails.basics" "TableHeaders.settings" -AddCategories
Add-MDTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId -AddCategories -AddSubcategories
if(($documentedObj.$tableType).Count -gt 0) {
Add-MDTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId -AddCategories -AddSubcategories
}
#Add-MDTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId `
# -AddCategories:($global:chkMDAddCategories.IsChecked -eq $true) `
@@ -308,6 +314,11 @@ function Invoke-MDProcessItem
Add-MDObjectSettings $obj $objectType $documentedObj
foreach($customTable in ($documentedObj.CustomTables | Sort-Object -Property Order))
{
Add-MDTableItems $obj $objectType $customTable.Values $customTable.Columns $customTable.LanguageId -AddCategories -AddSubcategories
}
if(($documentedObj.Assignments | measure).Count -gt 0)
{
if($documentedObj.Assignments[0].RawIntent)
+118 -19
View File
@@ -3,22 +3,39 @@
#https://docs.microsoft.com/en-us/office/vba/api/overview/word
function Get-ModuleVersion
{
'1.6.0'
'1.7.0'
}
function Invoke-InitializeModule
{
if(!("Microsoft.Office.Interop.Word.Application" -as [Type]))
{
$loaded = $false
try
{
Add-Type -AssemblyName Microsoft.Office.Interop.Word
$loaded = $true
}
catch { }
try
{
$wordFile = Get-ChildItem -path "$($env:windir)\assembly\GAC_MSIL" -Filter "Microsoft.Office.Interop.Word.dll" -Recurse
if($wordFile -and $wordFile.Exists)
{
Add-Type -Path $wordFile.FullName
$loaded = $true
}
}
catch
{
Write-LogError "Failed to add Word Interop type. Cannot create word documents. Verify that Word is installed properly." $_.Exception
return
}
if(-not $loaded) {
Write-LogError "Word Interop type not found. Cannot create word documents. Verify that Word is installed properly." $_.Exception
return
}
}
Add-OutputType ([PSCustomObject]@{
@@ -46,6 +63,18 @@ function Add-WordOptionsControl
$global:spWordCustomProperties.Visibility = (?: ($global:cbWordDocumentationProperties.SelectedValue -ne "custom") "Collapsed" "Visible")
$global:txtWordCustomProperties.Visibility = (?: ($global:cbWordDocumentationProperties.SelectedValue -ne "custom") "Collapsed" "Visible")
$global:cbWordDocumentationFormat.ItemsSource = ("[ { Name: `"Word default document (docx)`",Value: `"wdFormatDocumentDefault`" }, { Name: `"Strict Open XML document`",Value: `"wdFormatStrictOpenXMLDocument`" }, { Name: `"PDF`",Value: `"wdFormatPDF`" }]" | ConvertFrom-Json)
$currentFormat = (Get-Setting "Documentation" "WordDocumentFormat" "wdFormatDocumentDefault")
if($currentFormat -eq "pdf")
{
$currentFormat = "wdFormatPDF"
}
elseif($currentFormat -eq "docx")
{
$currentFormat = "wdFormatDocumentDefault"
}
$global:cbWordDocumentationFormat.SelectedValue = $currentFormat
$global:cbWordDocumentationLevel.ItemsSource = ("[ { Name: `"Full`",Value: `"full`" }, { Name: `"Limited`",Value: `"limited`" }, { Name: `"Basic`",Value: `"basic`" }]" | ConvertFrom-Json)
$global:cbWordDocumentationLevel.SelectedValue = (Get-Setting "Documentation" "WordDocumentationLevel" "full")
@@ -114,6 +143,7 @@ function Invoke-WordPreProcessItems
{
Save-Setting "Documentation" "WordExportProperties" $global:cbWordDocumentationProperties.SelectedValue
Save-Setting "Documentation" "WordCustomDisplayProperties" $global:txtWordCustomProperties.Text
Save-Setting "Documentation" "WordDocumentFormat" $global:cbWordDocumentationFormat.SelectedValue
Save-Setting "Documentation" "WordDocumentTemplate" $global:txtWordDocumentTemplate.Text
Save-Setting "Documentation" "WordDocumentName" $global:txtWordDocumentName.Text
@@ -208,7 +238,7 @@ function Invoke-WordPreProcessItems
{
try
{
$script:doc = $wordApp.Documents.Add($global:txtWordDocumentTemplate.Text)
$script:doc = $script:wordApp.Documents.Add($global:txtWordDocumentTemplate.Text)
}
catch
{
@@ -217,7 +247,7 @@ function Invoke-WordPreProcessItems
}
else
{
$script:doc = $wordApp.Documents.Add()
$script:doc = $script:wordApp.Documents.Add()
}
#Get BuiltIn properties
@@ -262,7 +292,7 @@ function Invoke-WordPreProcessItems
$script:wordStyles = @()
$script:doc.Styles | foreach {
$script:wordStyles += [PSCUstomObject]@{
$script:wordStyles += [PSCustomObject]@{
Name=$_.NameLocal
Type=$_.Type
Style=$_
@@ -379,10 +409,51 @@ function Invoke-WordPostProcessItems
catch {}
#update fields, ToC etc.
$script:doc.Fields | ForEach-Object -Process { $_.Update() | Out-Null }
$script:doc.TablesOfContents | ForEach-Object -Process { $_.Update() | Out-Null }
$script:doc.TablesOfFigures | ForEach-Object -Process { $_.Update() | Out-Null }
$script:doc.TablesOfAuthorities | ForEach-Object -Process { $_.Update() | Out-Null }
try {
$script:doc.Fields | ForEach-Object -Process { $_.Update() | Out-Null }
}
catch {
Write-LogError "Failed to update document fields" $_.Exception
}
try {
$script:doc.TablesOfContents | ForEach-Object -Process { $_.Update() | Out-Null }
}
catch {
Write-LogError "Failed to update Table of Contents" $_.Exception
}
try {
$script:doc.TablesOfFigures | ForEach-Object -Process { $_.Update() | Out-Null }
}
catch {
Write-LogError "Failed to update Table of Figures" $_.Exception
}
try {
$script:doc.TablesOfAuthorities | ForEach-Object -Process { $_.Update() | Out-Null }
}
catch {
Write-LogError "Failed to update Table of Authorities" $_.Exception
}
Write-Log "Using document format: $($global:cbWordDocumentationFormat.SelectedValue)"
try {
$format = [Microsoft.Office.Interop.Word.WdSaveFormat]$global:cbWordDocumentationFormat.SelectedValue
}
catch
{
Write-LogError "Document validation failed" $_.Exception
$format = [Microsoft.Office.Interop.Word.WdSaveFormat]::wdFormatDocumentDefault
}
<#
if($global:cbWordDocumentationFormat.SelectedValue -eq "pdf")
{
$format = [Microsoft.Office.Interop.Word.WdSaveFormat]::wdFormatPDF
}
else {
$format = [Microsoft.Office.Interop.Word.WdSaveFormat]::wdFormatDocumentDefault
}
#>
$fileName = $global:txtWordDocumentName.Text
if(-not $fileName)
@@ -392,7 +463,10 @@ function Invoke-WordPostProcessItems
$fileName = Expand-FileName $fileName
$format = [Microsoft.Office.Interop.Word.WdSaveFormat]::wdFormatDocumentDefault
if($format -eq [Microsoft.Office.Interop.Word.WdSaveFormat]::wdFormatPDF -and $fileName -notlike "*.pdf")
{
$fileName = [IO.Path]::ChangeExtension($fileName, ".pdf")
}
try
{
@@ -404,17 +478,28 @@ function Invoke-WordPostProcessItems
Write-LogError "Failed to save file $fileName" $_.Excption
}
if($global:chkWordOpenDocument.IsChecked -eq $true -and $global:hideUI -ne $true)
{
$script:wordApp.Visible = $true
$script:wordApp.WindowState = [Microsoft.Office.Interop.Word.WdWindowState]::wdWindowStateMaximize
$script:wordApp.Activate()
[Console.Window]::SetForegroundWindow($script:wordApp.ActiveWindow.Hwnd) | Out-Null
try {
if($global:chkWordOpenDocument.IsChecked -eq $true -and $global:hideUI -ne $true)
{
$script:wordApp.Visible = $true
$script:wordApp.WindowState = [Microsoft.Office.Interop.Word.WdWindowState]::wdWindowStateMaximize
$script:wordApp.Activate()
[Console.Window]::SetForegroundWindow($script:wordApp.ActiveWindow.Hwnd) | Out-Null
}
else
{
$script:doc.Close([Microsoft.Office.Interop.Word.WdSaveOptions]::wdDoNotSaveChanges)
$script:wordApp.Quit()
}
}
else
catch
{
$script:doc.Close([Microsoft.Office.Interop.Word.WdSaveOptions]::wdDoNotSaveChanges)
$script:wordApp.Quit()
Write-LogError "Failed to close the Word application" $_.Exception
}
finally {
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($script:doc)
[void][Runtime.InteropServices.Marshal]::ReleaseComObject($script:wordApp)
[GC]::Collect(); [GC]::WaitForPendingFinalizers()
}
}
@@ -547,10 +632,12 @@ function Invoke-WordProcessItem
$lngId = ?: ($tableType -eq "BasicInfo") "SettingDetails.basics" "TableHeaders.settings" -AddCategories
Add-DocTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId `
if(($documentedObj.$tableType).Count -gt 0) {
Add-DocTableItems $obj $objectType ($documentedObj.$tableType) $properties $lngId `
-AddCategories:($global:chkWordAddCategories.IsChecked -eq $true) `
-AddSubcategories:($global:chkWordAddSubCategories.IsChecked -eq $true) `
-ForceFullValue:($tableType -eq "BasicInfo")
}
}
if($global:cbWordDocumentationLevel.SelectedValue -ne "basic")
@@ -570,6 +657,11 @@ function Invoke-WordProcessItem
}
Add-DocObjectSettings $obj $objectType $documentedObj
foreach($customTable in ($documentedObj.CustomTables | Sort-Object -Property Order))
{
Add-DocTableItems $obj $objectType $customTable.Values $customTable.Columns $customTable.LanguageId -AddCategories -AddSubcategories
}
}
if(($documentedObj.Assignments | measure).Count -gt 0)
@@ -671,6 +763,10 @@ function Set-DocTableSettingsItems
$cellRow = $row
foreach($settingProp in $properties)
{
if([String]::IsNullOrEmpty($settingProp)) {
continue
}
$script:docTable.Cell($cellRow, $firstColumn).Range.Text = (Invoke-DocTranslateColumnHeader ($settingProp.Split('.')[-1]))
$propArr = $settingProp.Split('.')
@@ -772,6 +868,9 @@ function Add-DocTableItems
$i = 1
foreach($prop in $properties)
{
if([String]::IsNullOrEmpty($prop)) {
continue
}
$script:docTable.Cell(1, $i).Range.Text = (Invoke-DocTranslateColumnHeader ($prop.Split(".")[-1]))
$i++
}
File diff suppressed because it is too large Load Diff
+14 -1
View File
@@ -35,7 +35,7 @@ function Invoke-InitializeModule
Add-ViewObject $global:EMInfoViewObject
Add-ViewItem (New-Object PSObject -Property @{
Title = "Baseline Templates"
Title = "Baseline Templates - Intent"
Id = "BaselineTemplates"
ViewID = "EMInfoGraphAPI"
API = "/deviceManagement/templates"
@@ -45,6 +45,19 @@ function Invoke-InitializeModule
ExpandAssignmentsList = $false
})
Add-ViewItem (New-Object PSObject -Property @{
Title = "Baseline Templates - Settings Catalog"
Id = "BaselineTemplatesSettingsCatalog"
ViewID = "EMInfoGraphAPI"
API = "/deviceManagement/configurationPolicyTemplates"
QUERYLIST = "`$filter=(templateFamily eq 'Baseline')"
ShowButtons = @("Export","View")
DefaultColumns = "0,displayName=Template Name,displayVersion=Version,lifecycleState=State,baseId=Template Id,id"
Permissons=@("DeviceManagementConfiguration.ReadWrite.All")
Icon="EndpointSecurity"
ExpandAssignmentsList = $false
})
Add-ViewItem (New-Object PSObject -Property @{
Title = "Android Google Play"
Id = "AndroidGooglePlay"
+8 -1
View File
@@ -521,6 +521,13 @@ function Write-AzureStorageChunk
"Content-Type" = "application/octet-stream"
}
# In PowerShell (Core) 7 v7.4+, the web cmdlets (Invoke-WebRequest, Invoke-RestMethod)
# consistently encode text-based request bodies as UTF-8, unless explicitly specified otherwise.
if ($PSVersionTable.PSVersion -ge [Version]"7.4")
{
$headers["Content-Type"] += "; charset=iso-8859-1"
}
$curProgressPreference = $ProgressPreference
$ProgressPreference = 'SilentlyContinue'
@@ -783,7 +790,7 @@ function Start-DownloadAppContent
{
foreach($file in $contentFiles.value)
{
if($contentFiles.value[-1].Id -eq $file.id) { continune }
if($contentFiles.value[-1].Id -eq $file.id) { continue }
# NOT happy about this. file objects are not always returned in the order of upload.
$contentFile = Invoke-GraphRequest -Url "/deviceAppManagement/mobileApps/$appId/$appType/contentVersions/$contentVerId/files/$($file.Id)" -NoError
+1 -1
View File
@@ -348,7 +348,7 @@ function Get-EMIntuneFilterUsage
foreach($groupID in $loadedGroups.Keys)
{
$filterObjs = $script:objFilterUsage | WHere GroupID -eq $groupID
$filterObjs = $script:objFilterUsage | Where GroupID -eq $groupID
if($filterObjs -and $loadedGroups[$groupID])
{
foreach($filterObj in $filterObjs) {
+59 -13
View File
@@ -55,10 +55,25 @@ function Invoke-InitializeModule
<elements>
</elements>
</policy>
</policy>
</policies>
</policyDefinitions>
"@
# Add settings
$global:appSettingSections += (New-Object PSObject -Property @{
Title = "Intune Tools"
Id = "IntuneTools"
Values = @()
})
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Format OM-URI Settings"
Key = "FormatOMAURI"
Type = "Boolean"
DefaultValue = $false
Description = "Formats the XML for OMA-URI settings e.g. removes unnecessary spaces and empty lines."
}) "IntuneTools"
}
function Add-EMToolsViewItem
@@ -704,7 +719,10 @@ function Invoke-LoadADMXSettings
$tvItem | Add-Member -MemberType NoteProperty -Name "AllPolicies" -Value $true
}
$global:tvADMXCategories.Items[1].Items.Add($tvItem) | Out-Null
try {
$global:tvADMXCategories.Items[1].Items.Add($tvItem) | Out-Null
}
catch{}
}
function Set-ADMXSettingStatusText
@@ -854,6 +872,7 @@ function Get-ADMXCategoryNamePath
}
$catObj = $script:admxXML.policyDefinitions.categories.selectSingleNode("$($script:xmlNSPrefix)category[@name='$($categoryId)']",$script:xmlNS)
#$catObj = $script:admxXML.policyDefinitions.categories.category | Where Name -eq "$categoryId"
$categories = @()
while($catObj)
@@ -862,6 +881,7 @@ function Get-ADMXCategoryNamePath
if($catObj.parentCategory.ref)
{
$catObj = $script:admxXML.policyDefinitions.categories.selectSingleNode("$($script:xmlNSPrefix)category[@name='$($catObj.parentCategory.ref)']", $script:xmlNS)
#$catObj = $script:admxXML.policyDefinitions.categories.category | where name -eq $catObj.parentCategory.ref
}
else
{
@@ -1037,17 +1057,18 @@ function Set-ADMXElementsPanel
}
elseif($valItem.value.longDecimal)
{
$value = $valItem.value.longDecimal.'#text'
$value = ?? $valItem.value.longDecimal.'#text' $valItem.value.longDecimal
}
elseif($valItem.value.string)
{
$value = $valItem.value.string.'#text'
$value = ?? $valItem.value.string.'#text' $valItem.value.string
}
else
{
Write-Log "Unsupported value type for $($elementNode.Id): $($valItem.value.InnerXml)" 2
$value = "<SET MANUALLY!!!>"
}
$valItems += [PSCustomObject]@{
Name = $displayName
Value = $value
@@ -1151,7 +1172,7 @@ function Set-ADMXElementsPanel
}
elseif($valItem.value.string)
{
$value = $valItem.value.string.'#text'
$value = ?? $valItem.value.string.'#text' $valItem.value.string
}
else
{
@@ -1403,20 +1424,25 @@ function Import-ADMXPolicy
{
if($admxPolicy.SettingStatus -eq 0)
{
$policyValue = "<disabled />"
$policyValue = "<disabled/>"
}
else
{
$policyValue = "<enabled />"
$policyValue = "<enabled/>"
$strValue = $admxPolicy.PolicySettings
if($strValue)
{
$policyValue += "`n`n$strValue"
$policyValue += "`n$strValue"
}
}
if((Get-SettingValue "FormatOMAURI") -eq $true)
{
$policyValue = Update-XmlFormatting $policyValue
}
$catPath = Get-ADMXCategoryOMAURIPath $admxPolicy.Definition.parentCategory.ref
$omaUriPath = "./$($admxPolicy.SettingClass)/Vendor/MSFT/Policy/Config/$($global:txtADMXPolicyAppName.Text)~Policy~$catPath/$($admxPolicy.Definition.name)"
@@ -1458,12 +1484,18 @@ function Import-ADMXPolicy
if($global:chkADMXPolicyIngest.IsChecked)
{
$xmlString = Format-XML $script:admxXML
if((Get-SettingValue "FormatOMAURI") -eq $true)
{
$xmlString = Update-XmlFormatting $xmlString
}
$intuneObj.omaSettings += [PSCustomObject]@{
"@odata.type" = "#microsoft.graph.omaSettingString"
"displayName" = (?? $global:txtADMXPolicyIngestName.Text ("$($script:currentADMXFile.Name) Ingestion"))
"description" = $null
"omaUri" = "./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/$($global:txtADMXPolicyAppName.Text)/Policy/$($global:txtADMXPolicyFileName.Text)"
"value" = (Format-XML $script:admxXML)
"value" = $xmlString
}
}
@@ -1780,7 +1812,7 @@ function Get-ADMXRegIsKeySupported
if($blockedSource)
{
[System.Windows.MessageBox]::Show("The registry key '$($global:txtADMXRegKey.Text)' is not supported" + [Environment]::NewLine + [Environment]::NewLine + "Blocked by root key: $blockedSource", "Unsupported reg ket", "OK", "Error")
[System.Windows.MessageBox]::Show("The registry key '$($global:txtADMXRegKey.Text)' is not supported" + [Environment]::NewLine + [Environment]::NewLine + "Blocked by root key: $blockedSource", "Unsupported reg key", "OK", "Error")
return $false
}
return $true
@@ -1927,6 +1959,11 @@ function Import-ADMXRegProfile
$OMAURIString = ($OMAURIString + [Environment]::NewLine + [Environment]::NewLine + ($omaUriItems -join [Environment]::NewLine))
}
if((Get-SettingValue "FormatOMAURI") -eq $true)
{
$OMAURIString = Update-XmlFormatting $OMAURIString
}
$xml.policyDefinitions.SelectSingleNode("policies").AppendChild($newNode) | Out-Null
$admxRegSettings += [PSCustomObject]@{
@@ -1939,12 +1976,18 @@ function Import-ADMXRegProfile
$xml.policyDefinitions.SelectSingleNode("policies").RemoveChild($xml.policyDefinitions.policies.SelectSingleNode("policy")) | Out-Null
$xmlString = Format-XML $xml
if((Get-SettingValue "FormatOMAURI") -eq $true)
{
$xmlString = Update-XmlFormatting $xmlString
}
$intuneObj.omaSettings += [PSCustomObject]@{
"@odata.type" = "#microsoft.graph.omaSettingString"
"displayName" = "Reg ADMX Ingestion"
"description" = "This XML is generated by Intune Managemet tool"
"omaUri" = "./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/IntuneManagementReg/$(($script:frmADMXRegProfile.DataContext.PolicyType))/$($rgPolicyFileName)"
"value" = (Format-XML $xml)
"value" = $xmlString
}
$intuneObj.omaSettings += $admxRegSettings
@@ -1981,9 +2024,11 @@ function Add-ADMXRegClasses
}
$classDef = @"
using System;
using System.ComponentModel;
using System.Collections.ObjectModel;
public class ADMXRegPolicyElement : INotifyPropertyChanged
public class ADMXRegPolicyElement : System.ComponentModel.INotifyPropertyChanged
{
public string DataType { get { return _dataType; } set { _dataType = value; NotifyPropertyChanged("DataType"); NotifyPropertyChanged("DataTypeDisplayString"); } }
private string _dataType = null;
@@ -2069,8 +2114,9 @@ function Add-ADMXRegClasses
}
}
"@
[Reflection.Assembly]::LoadWithPartialName("mscorlib") | Out-Null
[Reflection.Assembly]::LoadWithPartialName("System.ComponentModel") | Out-Null
Add-Type -TypeDefinition $classDef -IgnoreWarnings -ReferencedAssemblies @('System.ComponentModel')
Add-Type -TypeDefinition $classDef
}
#endregion
+226 -33
View File
@@ -10,7 +10,7 @@ This module manages Authentication for the application with MSAL. It is also res
#>
function Get-ModuleVersion
{
'3.9.7'
'3.9.8a'
}
$global:msalAuthenticator = $null
@@ -121,6 +121,28 @@ function Invoke-InitializeModule
Description = "Sort the list of cached accounts based on user name. Updated at restart or account change"
}) "MSAL"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Sort Tenant List"
Key = "SortTenantList"
Type = "Boolean"
DefaultValue = $false
Description = "Sort the list of available tenants based on Tenant name. Updated at restart or account change"
}) "MSAL"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Use WAM for enhanced login methods"
Key = "UseWAM"
Type = "Boolean"
DefaultValue = $false
Description = "Use WAM for enhanced login methods"
}) "MSAL"
$script:MSALUseWAM = Get-SettingValue "UseWAM"
if($script:MSALUseWAM -and $PSVersionTable.PSVersion.Major -lt 7) {
Write-Log "WAM is only supported in PowerShell 7 and later. Disabling WAM" 2
$script:MSALUseWAM = $false
}
Add-MSALPrereq
}
@@ -192,6 +214,9 @@ function Set-MSALGraphEnvironment
{
$curAADEnv = $script:lstAADEnvironments | Where URL -eq $user.Environment
}
elseif($global:UseGraphEnvironment) {
$curAADEnv = $script:lstAADEnvironments | Where value -eq $global:UseGraphEnvironment
}
else
{
$curAADEnv = $script:lstAADEnvironments | Where value -eq (Get-Setting "" "MSALCloudType" "public")
@@ -199,7 +224,14 @@ function Set-MSALGraphEnvironment
if($curAADEnv.Value -eq "usGov")
{
$gccEnv = (Get-Setting "" "MSALGCCType" "gcc")
if($global:UseGCCType)
{
$gccEnv = $global:UseGCCType
}
else {
$gccEnv = (Get-Setting "" "MSALGCCType" "gcc")
}
if($gccEnv)
{
$GCCEnvObj = $script:lstGCCEnvironments | Where Value -eq $gccEnv
@@ -251,6 +283,7 @@ function Get-MSALUserInfo
if($global:Organization)
{
if($global:Organization -is [array]) { $global:Organization = $global:Organization[0]}
$global:Organization.displayName = ($global:Organization.displayName).Trim()
Save-Setting $global:Organization.Id "_Name" $global:Organization.displayName
}
Set-EnvironmentInfo $global:Organization.displayName
@@ -479,6 +512,129 @@ function Install-MSALDependencyModule
}
function Add-MSALPrereq
{
$ScriptRoot = $global:AppRootFolder
$DLLFiles = @()
if($PSVersionTable.PSVersion.Major -ge 7) {
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\Bin\Microsoft.IdentityModel.Abstractions.dll")
}
else {
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\Bin\6.35.0\Microsoft.IdentityModel.Abstractions.dll")
}
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\Bin\Microsoft.Identity.Client.dll")
if($script:MSALUseWAM) {
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\BIN\$MSALDLLPath\Microsoft.Identity.Client.Extensions.Msal.dll")
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\BIN\$MSALDLLPath\Microsoft.Identity.Client.Broker.dll")
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\BIN\$MSALDLLPath\Microsoft.Identity.Client.Desktop.dll")
$DLLFiles += [IO.FileInfo]($ScriptRoot + "\BIN\$MSALDLLPath\Microsoft.Identity.Client.NativeInterop.dll")
}
$DLLFiles | ForEach-Object {
$dllFile = $_
# ToDo: Unblock files
if($_.Exists) {
try {
[void][System.Reflection.Assembly]::LoadFrom($_.FullName)
Write-Log "Loaded $($_.Name) version $($_.VersionInfo.FileVersion)"
}
catch {
$loadedFile = [Appdomain]::CurrentDomain.GetAssemblies() | Where Location -like "*\$($dllFile.Name)"
if($loadedFile) {
$loadedFI = [IO.FileInfo]($loadedFile.Location)
Write-Log "Failed to load $($dllFile.Name) version $($dllFile.VersionInfo.FileVersion). File already loaded: $($loadedFI.FullName) version $($loadedFI.VersionInfo.FileVersion)" 2
}
else {
Write-LogError "Failed to load $($dllFile.Name) version $($dllFile.VersionInfo.FileVersion)" $_.Exception
}
}
}
else {
Write-LogError "Microsoft.Identity file not found: $($_.FullName)"
}
}
if (-not ("TokenCacheHelperEx" -as [type]))
{
[System.Collections.Generic.List[string]] $RequiredAssemblies = New-Object System.Collections.Generic.List[string]
foreach($file in $DLLFiles) {
$RequiredAssemblies.Add($file.FullName)
}
$RequiredAssemblies.Add('System.Security.dll')
$RequiredAssemblies.Add('mscorlib.dll')
if($PSVersionTable.PSVersion.Major -ge 7) {
$RequiredAssemblies.Add('System.Security.Cryptography.ProtectedData.dll')
}
$RequiredAssemblies.Add('System.Threading.dll')
try
{
Add-Type -Path ($ScriptRoot + "\CS\TokenCacheHelperEx.cs") -ReferencedAssemblies $RequiredAssemblies -IgnoreWarnings
}
catch
{
Write-LogError "Failed to compile TokenCacheHelperEx. The access token will not be cached. Check write access to the CS folder and ASR policies" $_.Exception
}
}
if($script:MSALUseWAM) {
[System.Collections.Generic.List[string]] $RequiredAssemblies = New-Object System.Collections.Generic.List[string]
foreach($file in $DLLFiles) {
$RequiredAssemblies.Add($file.FullName)
}
$RequiredAssemblies.Add('mscorlib.dll')
$RequiredAssemblies.Add('System.dll')
$RequiredAssemblies.Add('System.Windows.Forms')
# Import necessary methods from user32.dll and kernel32.dll
Add-Type @"
using System;
using System.Runtime.InteropServices;
using Microsoft.Identity.Client;
//using Microsoft.Identity.Client.Desktop;
using Microsoft.Identity.Client.Broker;
using System.Windows.Forms;
public class MSALMethods
{
enum GetAncestorFlags {
GetParent = 1,
GetRoot = 2,
GetRootOwner = 3
}
[DllImport("user32.dll", ExactSpelling = true)]
public static extern IntPtr GetAncestor(IntPtr hwnd, int flags);
[DllImport("kernel32.dll")]
public static extern IntPtr GetConsoleWindow();
// This is your window handle!
public static IntPtr GetConsoleOrTerminalWindow()
{
IntPtr consoleHandle = GetConsoleWindow();
IntPtr handle = GetAncestor(consoleHandle, (int)GetAncestorFlags.GetRootOwner );
return handle;
}
public static void AddParentActivirtyOrWindow(PublicClientApplicationBuilder appBuilder)
{
appBuilder.WithParentActivityOrWindow(GetConsoleOrTerminalWindow);
}
public static void AddWithBroker(PublicClientApplicationBuilder appBuilder, BrokerOptions options)
{
appBuilder.WithBroker(options);
}
}
"@ -ReferencedAssemblies $RequiredAssemblies -IgnoreWarnings
}
}
function Add-MSALPrereq_old
{
$msalPath = ""
@@ -557,7 +713,15 @@ function Add-MSALPrereq
$RequiredAssemblies.Add($msalPath)
$script:msalFile = $msalPath
}
$RequiredAssemblies.Add('System.Security.dll')
$RequiredAssemblies.Add('mscorlib.dll')
if($PSVersionTable.PSVersion.Major -ge 7)
{
$RequiredAssemblies.Add('System.Security.Cryptography.ProtectedData.dll')
}
$RequiredAssemblies.Add('System.Threading.dll')
try
{
@@ -578,6 +742,10 @@ function Connect-MSALClientApp
if(-not $script:MSALApp)
{
if($global:UseGraphEnvironment) {
Set-MSALGraphEnvironment $null $null
}
$authority = "https://login.microsoftonline.com/$tenantId"
#$redirectUri = "http://localhost"
@@ -739,7 +907,7 @@ function Get-MSALApp
{
param($appInfo, $loginHint)
$msalApp = $script:MSALAllApps | Where { $_.ClientId -eq $appInfo.ClientID -and (-not $appInfo.RedirectUri -or $_.AppConfig.RedirectUri -eq $appInfo.RedirectUri)}
$msalApp = $script:MSALAllApps | Where { $_.AppConfig.ClientId -eq $appInfo.ClientID -and (-not $appInfo.RedirectUri -or $_.AppConfig.RedirectUri -eq $appInfo.RedirectUri)}
$tenant = ?? $appInfo.TenantId "organizations"
@@ -762,14 +930,21 @@ function Get-MSALApp
$appBuilder = [Microsoft.Identity.Client.PublicClientApplicationBuilder]::Create($appInfo.ClientID)
[void]$appBuilder.WithAuthority($authority)
#if($appInfo.TenantId) { [void]$appBuilder.WithAuthority("https://$((?? $loginHint.Environment (Get-MSALLoginEnvironment)))/$($appInfo.TenantId)/") }
#elseif ($appInfo.Authority) { [void]$appBuilder.WithAuthority($appInfo.Authority) }
if($appInfo.RedirectUri) { [void]$appBuilder.WithRedirectUri($appInfo.RedirectUri) }
[void] $appBuilder.WithClientName("CloudAPIPowerShellManagement")
[void] $appBuilder.WithClientVersion($PSVersionTable.PSVersion)
if($script:MSALUseWAM) {
[MSALMethods]::AddParentActivirtyOrWindow($appBuilder)
$options = [Microsoft.Identity.Client.BrokerOptions]::new([Microsoft.Identity.Client.BrokerOptions+OperatingSystems]::Windows)
$options.Title = "Intune Manager"
[MSALMethods]::AddWithBroker($appBuilder, $options)
}
Add-MSALProxy $appBuilder
# Ceck if correct version...
@@ -850,6 +1025,11 @@ function Connect-MSALUser
if($global:MainAppStarted -eq $false)
{
$script:AppLogin = (Get-SettingValue "GraphAzureAppLogin") -or ($global:TenantId -and $global:AzureAppId -and ($global:ClientSecret -or $global:ClientCert))
if((Get-SettingValue "GraphAzureAppLogin") -and -not $global:TenantId)
{
$global:TenantId = Get-SettingValue "GraphAzureTenantId"
}
}
if($script:AppLogin)
@@ -900,8 +1080,6 @@ function Connect-MSALUser
Add-MSALPrereq
}
$curTicks = $global:MSALToken.ExpiresOn.LocalDateTime.Ticks
$currentLoggedInUserApp = ($global:MSALToken.Account.HomeAccountId.Identifier + $global:MSALToken.TenantId + $global:MSALApp.ClientId)
$currentLoggedInUserId = $global:MSALToken.Account.HomeAccountId.Identifier
if($Interactive -eq $true)
@@ -938,7 +1116,6 @@ function Connect-MSALUser
}
else
{
$lastUser =
$lastUserId = Get-Setting "" "LastLoggedOnUserId"
if($lastUserId)
{
@@ -1007,15 +1184,6 @@ function Connect-MSALUser
return
}
if($authResult -and $authResult.ExpiresOn.LocalDateTime.Ticks -ne $curTicks)
{
Write-Log "$($authResult.Account.UserName) authenticated successfully (Silent). CorrelationId: $($global:MSALToken.CorrelationId)"
}
else
{
Write-LogDebug "$($authResult.Account.UserName) authenticated successfully (Silent). CorrelationId: $($global:MSALToken.CorrelationId)"
}
#AADSTS65001
if($script:authenticationFailure.Classification -eq "ConsentRequired")
{
@@ -1105,6 +1273,10 @@ function Connect-MSALUser
{
Write-Log "Login hint: $loginHintName"
[void]$AquireTokenObj.WithLoginHint($loginHintName)
[void]$AquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::NoPrompt)
}
else {
[void]$AquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::SelectAccount)
}
if($script:authenticationFailure.Claims)
@@ -1125,11 +1297,6 @@ function Connect-MSALUser
Write-Log "Interactive login with Consent prompt"
[void]$aquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::Consent)
}
elseif(-not $loginHintName)
{
Write-Log "Interactive login with Select account prompt"
[void]$AquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::SelectAccount)
}
$authResult = Get-MsalAuthenticationToken $aquireTokenObj
if($authResult)
@@ -1138,6 +1305,31 @@ function Connect-MSALUser
}
}
if($authResult) {
$telemetry = $null
$wamTelemetry = $null
if($authResult.AuthenticationResultMetadata.Telemetry) {
try {
$telemetry = $authResult.AuthenticationResultMetadata.Telemetry | ConvertFrom-Json
if($telemetry.wam_telemetry) {
$wamTelemetry = $telemetry.wam_telemetry | ConvertFrom-Json
}
}
catch {}
}
if($authResult.AuthenticationResultMetadata.TokenSource -eq "Broker" -and $telemetry.broker_app_used -eq "true") {
Write-Log "Token received from Broker. Time (ms): $($authResult.AuthenticationResultMetadata.DurationTotalInMs). CorrelationId: $($authResult.CorrelationId)"
}
elseif($authResult.AuthenticationResultMetadata.TokenSource -eq "IdentityProvider") {
Write-Log "Token received from IdentityProvider. Time (ms) $($authResult.AuthenticationResultMetadata.DurationTotalInMs)"
}
else {
# ToDo: Change to debug
Write-Log "Token received from Cache. Time (ms) $($authResult.AuthenticationResultMetadata.DurationTotalInMs)"
}
}
if($currentLoggedInUserId -ne $authResult.Account.HomeAccountId.Identifier)
{
$script:AccessableTenants = $null
@@ -1217,15 +1409,6 @@ function Connect-MSALUser
Save-Setting "" "LastLoggedOnUserId" $authResult.Account.HomeAccountId.ObjectId
}
Invoke-MSALAuthenticationUpdated $authResult
<#
Write-LogDebug "User, tenant or app has changed"
Get-MSALUserInfo
if($authResult)
{
Invoke-MSALCheckObjectViewAccess $authResult
}
Invoke-ModuleFunction "Invoke-GraphAuthenticationUpdated"
#>
}
}
@@ -1804,8 +1987,18 @@ function Get-MSALProfileEllipse
$lbObj = [Windows.Markup.XamlReader]::Parse("<TextBlock $wpfNS><Bold>Tenants:</Bold></TextBlock>")
$lbObj.Margin = "0,5,0,0"
if((Get-SettingValue "SortTenantList") -eq $true)
{
$tenants = $script:AccessableTenants | Sort -Property DisplayName
}
else
{
$tenants = $script:AccessableTenants
}
Add-GridObject $otherLogins $lbObj
foreach($tenant in $script:AccessableTenants)
foreach($tenant in $tenants)
{
try
{
@@ -2143,7 +2336,7 @@ function Show-MSALDecodedToken {
{
if($prop.Name -in @("exp","iat","nbf","xms_tcdt"))
{
$value =[datetime]::new(1970, 1, 1, 0, 0, 0, 0, "UTC").AddSeconds(($tokenData.Payload."$($prop.Name)")).ToLocalTime()
$value = [datetime]::new(1970, 1, 1, 0, 0, 0, 0, [System.DateTimeKind]::Utc).AddSeconds(($tokenData.Payload."$($prop.Name)")).ToLocalTime()
}
elseif($prop.Name -in @("acrs","amr"))
{
+444 -34
View File
@@ -10,7 +10,7 @@ This module manages Microsoft Grap fuctions like calling APIs, managing graph ob
#>
function Get-ModuleVersion
{
'3.9.6'
'3.9.8a'
}
$global:MSGraphGlobalApps = @(
@@ -43,12 +43,85 @@ function Invoke-InitializeModule
Name = "Replace (Preview)"
Value = "replace"
},
[PSCustomObject]@{
Name = "Replace with assignments (Preview)"
Value = "replace_with_assignments"
},
[PSCustomObject]@{
Name = "Update (Preview)"
Value = "update"
}
)
$script:lstConditionalAccessState = @(
[PSCustomObject]@{
Name = "As Exported - Change On to Report-only"
Value = "AsExportedReportOnly"
},
[PSCustomObject]@{
Name = "As Exported"
Value = "AsExported"
},
[PSCustomObject]@{
Name = "Report-only"
Value = "enabledForReportingButNotEnforced"
},
[PSCustomObject]@{
Name = "Off"
Value = "disabled"
}
)
$script:lstGraphPageSize = @(
[PSCustomObject]@{
Name = "Graph API Default"
Value = "0"
},
[PSCustomObject]@{
Name = "5"
Value = "5"
},
[PSCustomObject]@{
Name = "20"
Value = "20"
},
[PSCustomObject]@{
Name = "50"
Value = "50"
},
[PSCustomObject]@{
Name = "100"
Value = "100"
},
[PSCustomObject]@{
Name = "All"
Value = "All"
}
)
# Bit 1: Bulk export
# Bit 2: Manual export
# Bit 3: Bulk import
# Bit 4: Manual import
$script:lstClearCacheTypes = @(
[PSCustomObject]@{
Name = "Bulk export (Default)"
Value = "1" # Bulk export only
},
[PSCustomObject]@{
Name = "Bulk and manual export"
Value = "3"
},
[PSCustomObject]@{
Name = "Bulk export/import"
Value = "7" #
},
[PSCustomObject]@{
Name = "Bulk and manual import/export"
Value = "15" # Both bulk and manual
}
)
# Make sure MS Graph settings are added before exiting before App Id and Tenant Id is missing
Write-Log "Add settings and menu items"
@@ -195,6 +268,13 @@ function Invoke-InitializeModule
Description = "Login with specified app in the UI. Note: Change will require app restart"
}) "GraphSilent"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "TenantId"
Key = "GraphAzureTenantId"
Type = "String"
Description = "Tenent Id used when logging in with App in UI"
}) "GraphSilent"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Refresh Objects after copy"
Key = "RefreshObjectsAfterCopy"
@@ -235,6 +315,59 @@ function Invoke-InitializeModule
Description = "This will use production verionof graph, v1.0. Note: Thot officially supported since this can have unpredicted results. Some parts will require Beta version of Graph."
}) "GraphGeneral"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "API Page Size"
Key = "GraphPageSize"
Type = "List"
ItemsSource = $script:lstGraphPageSize
DefaultValue = "100"
Description = "How many items load at a time"
}) "GraphGeneral"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Default Conditional Access Policy State"
Key = "ConditionalAccessState"
Type = "List"
ItemsSource = $script:lstConditionalAccessState
DefaultValue = "disabled"
Description = "Define the default option of the Conditional Access policy state. It is recommended to have this to disabled to avoid accidental tenant lock out"
}) "ImportExport"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Sort Json Properties"
Key = "SortJsonProperties"
Type = "Boolean"
DefaultValue = $false
Description = "This will use sorted JSON properties when exporting JSON data. Making sure that properties are in the same order in each export."
}) "ImportExport"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Clear Cache Before Export"
Key = "ClearCacheBeforeExportImport"
Type = "List"
ItemsSource = $script:lstClearCacheTypes
DefaultValue = "1"
Description = "Specifies when objects should be cleared from cache.<LineBreak />" +
"<Bold>Bulk export (Default)</Bold> - Clear objects from cache before bulk export.<LineBreak />" +
"<Bold>Bulk and manual export</Bold> - Clear objects from cache before bulk and manual export.<LineBreak />" +
"<Bold>Bulk export/import</Bold> - Clear objects from cache before bulk export or import.<LineBreak />" +
"<Bold>Bulk and manual export/import</Bold> - Clear objects from cache before bulk or manual export or import.<LineBreak /><LineBreak />" +
"<Bold>Note:</Bold> - Only Entra objects are cleared by default. Enable <Bold>Clear all objects from cache</Bold> to clear MigTable etc.."
}) "ImportExport"
Add-SettingsObject (New-Object PSObject -Property @{
Title = "Clear all objects from cache"
Key = "ClearAllObjectsFromCache"
Type = "Boolean"
DefaultValue = $false
Description = "This will clear all objects from cache e.g. groups, MigTabole etc.<LineBreak />" +
"This can be used if objects have been changed outside of the application to make sure the latest info e.g.<LineBreak />" +
"* New groups added<LineBreak />" +
"* New dependencies added<LineBreak />" +
"<Bold>Note:</Bold> - Clearing all cached object might cause import/export to take long timw or even reimport deleted policies/groups etc."
}) "ImportExport"
}
function Get-GraphAppInfo
@@ -453,7 +586,8 @@ function Invoke-GraphRequest
do
{
$ret = Invoke-RestMethod -Uri $Url -Method $HttpMethod @params
if($? -eq $false)
$callSucceeded = $?
if($callSucceeded -eq $false)
{
throw $global:error[0]
}
@@ -489,7 +623,6 @@ function Invoke-GraphRequest
if($_.Exception.Response.StatusCode -eq 429 -and $retryCount -le $retryMax)
{
# NOT OK - Should use the date property but could not replicate the issue
$retryCount++
$retryRequest = $true
Write-Log "429 - Too many requests received. Wait 5 s before retry" 2
Start-Sleep -Seconds 5
@@ -554,7 +687,9 @@ function Get-GraphObjects
[switch]
$SingleObject,
[string]
$filter)
$filter,
[int]
$pageSize = -1)
$params = @{}
if($objectType.ODataMetadata)
@@ -589,6 +724,10 @@ function Get-GraphObjects
{
#Use default page size or use below for a specific page size for testing
#$params.Add("pageSize",5) #!!!
if ($pageSize -gt 0)
{
$params.Add("pageSize", $pageSize)
}
}
elseif($SingleObject -ne $true -and $SinglePage -ne $true)
{
@@ -717,7 +856,7 @@ function Add-GraphObjectProperties
function Show-GraphObjects
{
param($filter, [switch]$ObjectTypeChanged)
param($filter, [switch]$ObjectTypeChanged, $FromGraphObjects)
$global:curObjectType = $global:lstMenuItems.SelectedItem
@@ -760,7 +899,9 @@ function Show-GraphObjects
if(-not $global:lstMenuItems.SelectedItem) { return }
Write-Status "Loading $($global:curObjectType.Title) objects"
if(-not $FromGraphObjects) {
Write-Status "Loading $($global:curObjectType.Title) objects"
}
if($global:lstMenuItems.SelectedItem.ShowForm -ne $false)
{
@@ -776,7 +917,45 @@ function Show-GraphObjects
$script:nextGraphPage = $null
[array]$graphObjects = Get-GraphObjects -property $global:curObjectType.ViewProperties -objectType $global:curObjectType -SinglePage -Filter $filter
$params = @{}
$pageSize = 0
if($global:curObjectType.PageSize)
{
$tmpPageSize = $global:curObjectType.PageSize
}
else {
$tmpPageSize = Get-SettingValue "GraphPageSize"
}
if($global:curObjectType.SupportsPageSize -eq $false) {
# Do nothing - use default page size from API
}
elseif ($tmpPageSize -eq "All")
{
$params.Add("AllPages", $true)
}else
{
if($tmpPageSize) {
try {
$pageSize = [int]$tmpPageSize
}
catch {}
}
if($pageSize -gt 0)
{
$params.Add("PageSize", $pageSize)
}
$params.Add("SinglePage", $true)
}
if($FromGraphObjects) {
[array]$graphObjects = $FromGraphObjects
}
else {
[array]$graphObjects = Get-GraphObjects -property $global:curObjectType.ViewProperties -objectType $global:curObjectType -Filter $filter @params
}
$dgObjects.AutoGenerateColumns = $false
$dgObjects.Columns.Clear()
@@ -804,7 +983,7 @@ function Show-GraphObjects
$tableColumns = @()
$additionalColumns = @()
$additionalColsStr = Get-Setting "EndpointManager\ObjectColumns" "$($global:curObjectType.Id)"
$additionalColsStr = ?? (Get-Setting "EndpointManager\ObjectColumns" "$($global:curObjectType.Id)") $global:curObjectType.DefaultColumns
if($additionalColsStr)
{
$additionalColumns += $additionalColsStr.Split(',')
@@ -854,7 +1033,9 @@ function Show-GraphObjects
}
else
{
$dgObjects.ItemsSource = $null
$ocList = [System.Collections.ObjectModel.ObservableCollection[object]]::new()
$dgObjects.ItemsSource = [System.Windows.Data.CollectionViewSource]::GetDefaultView($ocList)
#$dgObjects.ItemsSource = $null
}
@@ -1047,6 +1228,34 @@ function Start-GraphPreImport
}
}
function Remove-GraphODataProperties
{
param($obj)
# Remove OData properties
foreach($odataProp in ($obj.PSObject.Properties | Where { $_.Name -like "*@*" }))
{
$removeProperties += $odataProp.Name
}
foreach($prop in $removeProperties)
{
Remove-Property $obj $prop
}
foreach($prop in ($obj.PSObject.Properties))
{
if($obj."$($prop.Name)"."@odata.type")
{
foreach($childObj in ($obj."$($prop.Name)"))
{
Remove-GraphODataProperties $childObj
}
}
}
}
function Get-GraphMetaData
{
if(-not $global:metaDataXML)
@@ -1428,7 +1637,14 @@ function Start-GraphObjectExport
$script:exportRoot = Expand-FileName (Get-XamlProperty $script:exportForm "txtExportPath" "Text")
Write-Log "Export root folder: $script:exportRoot"
$global:AADObjectCache = $null
if((Get-SettingValue "ClearAllObjectsFromCache"))
{
Invoke-GraphAuthenticationUpdated
}
else
{
$global:AADObjectCache = $null
}
foreach($item in $script:exportObjects)
{
@@ -1725,6 +1941,20 @@ function Show-GraphImportForm
Add-XamlEvent $script:importForm "btnImportSelected" "add_click" {
Write-Status "Import objects"
#Get-GraphDependencyDefaultObjects
$clearCacheValue = ?? ((Get-SettingValue "ClearCacheBeforeExportImport" "1") -as [int]) 1
if($clearCacheValue -band 8)
{
if((Get-SettingValue "ClearAllObjectsFromCache"))
{
Invoke-GraphAuthenticationUpdated
}
else
{
$global:AADObjectCache = $null
}
}
$allowUpdate = $true
$filesToImport = $global:dgObjectsToImport.ItemsSource | Where Selected -eq $true
if($global:curObjectType.PreFilesImportCommand)
@@ -1935,6 +2165,19 @@ function Start-GraphObjectImport
$tmpFolder = Expand-FileName (Get-XamlProperty $script:importForm "txtImportPath" "Text")
Write-Log "Import root folder: $tmpFolder"
$clearCacheValue = ?? ((Get-SettingValue "ClearCacheBeforeExportImport" "1") -as [int]) 1
if($clearCacheValue -band 4)
{
if((Get-SettingValue "ClearAllObjectsFromCache"))
{
Invoke-GraphAuthenticationUpdated
}
else
{
$global:AADObjectCache = $null
}
}
$importedObjects = 0
$txtNameFilter = $global:txtImportNameFilter.Text.Trim()
@@ -2001,7 +2244,7 @@ function Start-GraphObjectImport
ImportedObject = $importedObj
}
}
$arrImportedObjects = $importedObj
$arrImportedObjects += $importedObj
$importedObjects++
$importedObjectsCurType++
@@ -2353,7 +2596,10 @@ function Reset-GraphObject
# Clone the object before removing properties
$obj = $fileObj.Object | ConvertTo-Json -Depth 50 | ConvertFrom-Json
Start-GraphPreImport $obj $objectType
Remove-Property $obj "Assignments"
if ($global:cbImportType.SelectedValue -ne "replace_with_assignments"){
# will use the assignments from the file for "replace_with_assignments" type
Remove-Property $obj "Assignments"
}
Remove-Property $obj "isAssigned"
if($global:cbImportType.SelectedValue -eq "update")
@@ -2417,7 +2663,7 @@ function Reset-GraphObject
}
return $true
}
elseif($global:cbImportType.SelectedValue -eq "replace")
elseif($global:cbImportType.SelectedValue -in @("replace","replace_with_assignments"))
{
$replace = $true
$import = $true
@@ -2466,8 +2712,13 @@ function Reset-GraphObject
}
}
}
Import-GraphObjectAssignment $newObj $objectType $curObject.Object.Assignments $fileObj.FileInfo.FullName -CopyAssignments | Out-Null
if ($global:cbImportType.SelectedValue -eq "replace")
{
Import-GraphObjectAssignment $newObj $objectType $curObject.Object.Assignments $fileObj.FileInfo.FullName -CopyAssignments | Out-Null
}
else {
Import-GraphObjectAssignment $newObj $objectType $obj.Assignments $file.FileInfo.FullName | Out-Null
}
if($delete)
{
@@ -2635,7 +2886,8 @@ function Add-GraphMigrationInfo
$objType = $objInfo."@odata.type"
if($objType -eq "#microsoft.graph.groupAssignmentTarget" -or
$objType -eq "#microsoft.graph.exclusionGroupAssignmentTarget")
$objType -eq "#microsoft.graph.exclusionGroupAssignmentTarget" -or
$objType -eq "#microsoft.graph.cloudPcManagementGroupAssignmentTarget")
{
Add-GraphMigrationObject $objInfo.groupid "/groups" "Group"
}
@@ -2941,17 +3193,7 @@ function Get-GraphMigrationObjectsFromFile
{
$groupName = $migTableGroupName
Write-Log "No group object found for $groupName. Creating a cloud group with default settings" 2
$dateStr = ((Get-Date).ToString("yyMMddHHmmss"))
if(($groupName.Length + $dateStr.Length) -gt 64)
{
$nickName = $groupName.Substring(0,(64-$dateStr.Length))
}
else
{
$nickName = $groupName
}
$nickName = $nickName + $dateStr
$nickName = (New-Guid).Guid.SubString(0,10)
$groupJson = @"
{
@@ -3142,6 +3384,19 @@ function Export-GraphObjects
$objectType = $global:curObjectType
Write-Status "Export $($objectType.Title)"
$clearCacheValue = ?? ((Get-SettingValue "ClearCacheBeforeExportImport" "1") -as [int]) 1
if($clearCacheValue -band 2)
{
if((Get-SettingValue "ClearAllObjectsFromCache"))
{
Invoke-GraphAuthenticationUpdated
}
else
{
$global:AADObjectCache = $null
}
}
$script:ExportRoot = (Get-XamlProperty $script:exportForm "txtExportPath" "Text")
$folder = Get-GraphObjectFolder $objectType $script:ExportRoot (Get-XamlProperty $script:exportForm "chkAddObjectType" "IsChecked") (Get-XamlProperty $script:exportForm "chkAddCompanyName" "IsChecked")
@@ -3672,6 +3927,11 @@ function Import-GraphObject
{
$params.Add("AdditionalHeaders",$ret["AdditionalHeaders"])
}
if($ret.ContainsKey("JSON"))
{
$obj = $ret["JSON"] | ConvertFrom-Json
}
}
}
@@ -3972,8 +4232,8 @@ function Show-GraphObjectInfo
return
}
# Save settings here...
$nameProp = (?? $global:dgObjects.SelectedItem.Object.NameProperty "displayName")
$idProp = (?? $global:dgObjects.SelectedItem.Object.IDProperty "id")
$nameProp = (?? $global:dgObjects.SelectedItem.ObjectType.NameProperty "displayName")
$idProp = (?? $global:dgObjects.SelectedItem.ObjectType.IDProperty "id")
$updateObj = [PSCustomObject]@{
$idProp = $global:dgObjects.SelectedItem.Object."$idProp"
@@ -4135,9 +4395,10 @@ function local:Add-ObjectColumnInfoClass
}
$classDef = @"
using System;
using System.ComponentModel;
public class ObjectColumnInfo : INotifyPropertyChanged
public class ObjectColumnInfo : System.ComponentModel.INotifyPropertyChanged
{
public string Property { get { return _property; } set { _property = value; NotifyPropertyChanged("Property"); } }
private string _property = null;
@@ -4163,13 +4424,19 @@ function local:Add-ObjectColumnInfoClass
}
"@
[Reflection.Assembly]::LoadWithPartialName("System.ComponentModel") | Out-Null
Add-Type -TypeDefinition $classDef -IgnoreWarnings -ReferencedAssemblies @('System.ComponentModel')
try {
Add-Type -TypeDefinition $classDef -IgnoreWarnings #-ReferencedAssemblies @('System.ComponentModel')
}
catch
{
Write-LogError "Failed to add type ObjectColumnInfo" $_.Exception
}
}
function Local:Show-ObjectDefaultColumnsSettings
{
$strColSettings = Get-Setting "EndpointManager\ObjectColumns" "$($global:curObjectType.Id)"
$strColSettings = ?? (Get-Setting "EndpointManager\ObjectColumns" "$($global:curObjectType.Id)") $global:curObjectType.DefaultColumns
$script:colObjectProperties.Clear()
$defaultColumns = (?? $global:curObjectType.ViewProperties (@("displayName","description","id")))
if($strColSettings)
@@ -4393,7 +4660,12 @@ function Save-GraphObjectToFile
{
param($obj, $fileName)
$json = $obj | ConvertTo-Json -Depth 50
if(((Get-SettingValue "SortJsonProperties") -eq $true)) {
$json = $obj | ConvertTo-JsonSortedGraph -Depth 50
}
else {
$json = $obj | ConvertTo-Json -Depth 50
}
if($global:Organization.Id)
{
@@ -4489,3 +4761,141 @@ function Confirm-GraphMatchFilter
}
return $true
}
function Invoke-SortJsonGraphObject {
param(
[Parameter(Mandatory)]
$InputObject
)
if ($null -eq $InputObject) { return $null }
if ($InputObject -is [System.Collections.IList]) {
$new = @()
foreach ($item in $InputObject) {
$new += Invoke-SortJsonGraphObject $item
}
return ,$new
}
if ($InputObject -is [System.Collections.IDictionary] -or
$InputObject -is [System.Management.Automation.PSCustomObject]) {
$props =
if ($InputObject -is [System.Collections.IDictionary]) {
$InputObject.Keys
} else {
$InputObject.PSObject.Properties.Name
}
$baseGroups = @{}
foreach ($p in $props) {
if ($p -match '^(.+?)@(.+)$') {
$base = $matches[1]
if (-not $baseGroups.ContainsKey($base)) {
$baseGroups[$base] = @{
Base = $null
Meta = New-Object System.Collections.ArrayList
}
}
[void]$baseGroups[$base].Meta.Add($p)
}
}
foreach ($p in $props) {
if ($baseGroups.ContainsKey($p)) {
$baseGroups[$p].Base = $p
}
}
$atProps = @() # starts with @
$hashProps = @() # starts with #
$normal = @() # everything else
foreach ($p in $props) {
if ($p.StartsWith('@')) {
$atProps += $p
continue
}
if ($p.StartsWith('#')) {
$hashProps += $p
continue
}
# If in a baseGroup, skip for now (added later)
if ($baseGroups.ContainsKey($p)) {
continue
}
$normal += $p
}
$atProps = $atProps | Sort-Object
$normal = $normal | Sort-Object
$hashProps = $hashProps | Sort-Object
$orderedNames = @()
$orderedNames += $atProps
foreach ($base in ($baseGroups.Keys | Sort-Object)) {
$meta = $baseGroups[$base].Meta | Sort-Object
foreach ($m in $meta) {
$orderedNames += $m
}
if ($null -ne $InputObject.$base) {
$orderedNames += $base
}
}
$orderedNames += $normal
$orderedNames += $hashProps
$result = [ordered]@{}
foreach ($p in $orderedNames) {
$value =
if ($InputObject -is [System.Collections.IDictionary]) {
$InputObject[$p]
} else {
$InputObject.$p
}
if($null -ne $value) {
$result[$p] = Invoke-SortJsonGraphObject $value
}
else {
$result[$p] = $null
}
if($InputObject.$p -is [Array] -and $result[$p] -isnot [Array]) {
if($result[$p] -eq $null) {
$result[$p] = @()
}
else {
$result[$p] = @($result[$p])
}
}
}
return [pscustomobject]$result
}
return $InputObject
}
function ConvertTo-JsonSortedGraph {
param(
[Parameter(ValueFromPipeline, Mandatory)]
$InputObject,
[int]$Depth = 50
)
$sorted = Invoke-SortJsonGraphObject $InputObject
return $sorted | ConvertTo-Json -Depth $Depth
}
+53 -1
View File
@@ -10,7 +10,6 @@ See GitHub repository [MSAL for .Net](https://github.com/AzureAD/microsoft-authe
MSAL uses OAuth2 to authenticate to an Application in Azure. This script has two applications pre-defined in Settings:
- Microsoft Intune PowerShell (d1ddf0e4-d672-4dae-b554-9d5bdfd93547)
- Microsoft Graph PowerShell (14d82eec-204b-4c2f-b7e8-296a70dab67e)
Microsoft Intune PowerShell is the same application as the Intune PowerShell module uses and this is the default application for the script.
@@ -21,6 +20,59 @@ The script will detect if the selected app is missing permissions and prompt for
A Custom application can be specified in Settings. This could theoretically be a custom created app in Azure. However, if an App is registered in Azure, it will be single tenant only. This can be used to backup an existing environment but the Azure App cannot be used to import data in another tenant. Use Enterprise Apps and Common/Organizations authority to allow access to multiple tenants.
## Create Custom Application ##
Documentation by Microsoft: [Quickstart: Register an application with the Microsoft identity platform](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app)
Steps:
* Go to the Entra Portal
* Register a new App registration in Entra
Note Application Id
* Add Delegated permissions
* Microsoft Graph
For full support of the app requires:<br />
Application.Read.All<br />
Agreement.ReadWrite.All<br />
CloudPC.ReadWrite.All<br />
DeviceManagementApps.ReadWrite.All<br />
DeviceManagementConfiguration.ReadWrite.All<br />
DeviceManagementManagedDevices.ReadWrite.All<br />
DeviceManagementRBAC.ReadWrite.All<br />
DeviceManagementScripts.ReadWrite.All<br />
DeviceManagementServiceConfig.ReadWrite.All<br />
Organization.ReadWrite.All<br />
Policy.ReadWrite.ConditionalAccess<br /><br />
It will also need User.ReadWrite.All,Group.ReadWrite.All but you could set these to read only unless you will let the app create Groups.<br /><br />
**Note:** Change all **ReadWrite** to **Read** in the permissions above to create an Entra App with Read Only access.
* Grant permissions for the environment
* Go to Authentication
* Click **+ Add platform**
* Click on **Mobile and desktop applications**
* Check **https://login.microsoftonline.com/common/oauth2/nativeclient**<br />
msal value can also be used
* Start the Tool
* Go to Settings
* Change Application in Endpoint Manager/Intune section
* Set drop down to Empty. It will only use custom app if drop down is empty
* Specify App Id from the Entra App created earlier
* Specify Redirect URL to https://login.microsoftonline.com/common/oauth2/nativeclient<br />
This must match the setting in the Entra App.
* Save Settings
* Restart app
## Token
The MSAL authentication will create a token that is used when calling APIs in Microsoft Graph. This token is cached in an encrypted **msalcahce.bin3** file in the **%LOCALAPPDATA%\CloudAPIPowerShellManagement** folder. The file can only be decrypted by the same user. Caching the token can be disabled in Settings.
Binary file not shown.
File diff suppressed because it is too large Load Diff
+6 -2
View File
@@ -20,6 +20,8 @@ This PowerShell application is based on the foundation modules CloudAPIPowerShel
**Security note:** Since the scripts are not signed, a warning might be display when running it and files might be blocked. The script will unblock all files. This is to avoid issues that it fails to load the MSAL library etc. If there are any security concerns, the PowerShell code can be reviewed and the DLL files can be downloaded manually from Microsoft repositories, see links below. The DLL files *CAN* be removed but MSAL is a pre-requisite for authentication. The script will try to find the DLL in the Az or MSAL.PS module if not found in the script root directory. DLL files are included to reduce dependencies.
**Development release:** Changes will be uploaded to the [Development](https://github.com/Micke-K/IntuneManagement/tree/Development) branch. Changes and fixes will be implement to this branch. Any PRs must be merging thatto this branch.
## Starting the App
Before starting the app:
@@ -218,7 +220,7 @@ This will replace the default columns and add new columns with specific header.
See [Change Log](ReleaseNotes.md) for more information
## Authentication
See [MSAL Info](MSALInfo.md) for more information about authentication
See [MSAL Info](MSALInfo.md) for more information about authentication and how to create a custom application in Entra.
## Settings
@@ -250,6 +252,7 @@ Start-WithJson.cmd is included as an example on how to start the script with jso
* Apple Enrolment Types - NOT fully tested
* Autopilot profiles
* Baseline Security profiles
* BIOS Configuration
* Compliance policies
* Compliance policies v2
* Compliance scripts
@@ -273,7 +276,8 @@ Start-WithJson.cmd is included as an example on how to start the script with jso
* Scripts (PowerShell and Shell scripts, supports download of script)
* Terms and Conditions
* Terms of Use
* Update Policies
* Windows Update Policies
* Windows Updates Profiles
* Co-management Settings
[^1]: ADMX file must be located in the export folder or in the folder defined in Settings. Administrative Template policies based on ADMX files must be imported after the ADMX file is imported.
+242 -1
View File
@@ -1,4 +1,245 @@
# Release Notes
## 3.10.3 - 2026-05-11
**Fixes**
- **Import/Export**<br />
- Added support for Install/Uninstall scripts on Win32 apps<br />
It now supports importing Win32 apps that are configured with Install/Uninstall scripts.<br />
**Note:** The Win32 app must be exported with 3.10.1.18 or later since the Install/Uninstall script info is not availble with default json export.<br />
- Categories failed to import<br />
Based on [Issue 381](https://github.com/Micke-K/IntuneManagement/issues/381)<br />
- Orderchanges after export<br />
This caused issues when using the export for trackiing changes e.g. upload json to Github.<br />
Export changed the order of the properties causing a change in the json.<br />
This can be enabled in settings: **Sort Json properties**<br />
Based on [Issue 378](https://github.com/Micke-K/IntuneManagement/issues/378)<br />
- Importing registry values caused 2016281112 error<br />
Import was successful and reigstry value was correct but could caused a remediation error.<br />
It looks like CSP formats the XML before applying it, causing it not to match the XML in the policy.<br />
Based on [Issue 380](https://github.com/Micke-K/IntuneManagement/issues/380)<br />
- Added support for Windows Quality Updates (Policies)<br />
Based on [Issue 387](https://github.com/Micke-K/IntuneManagement/issues/387)<br />
- **Documentation**<br />
- Added Json output provider<br />
- Added support for Insall/Uninstall scriupt for Win32 apps<br />
- Added support for Strict Open XML document output<br />
Based on [Issue 375](https://github.com/Micke-K/IntuneManagement/issues/375)<br />
- Fixed issue with boolean values when documenting App Configuration policies<br />
Based on [Issue 383](https://github.com/Micke-K/IntuneManagement/issues/383)<br />
- Country names missing when documenting a Named Locations.<br />
Based on [Issue 400](https://github.com/Micke-K/IntuneManagement/issues/400)<br />
- Uninstall on device removal says Not Configured on Deployemnts<br />
Based on [Issue 402](https://github.com/Micke-K/IntuneManagement/issues/402)<br />
- iOS Single sign-on app extension config is empty<br />
Based on [Issue 403](https://github.com/Micke-K/IntuneManagement/issues/403)<br />
- Android App Config is not showing the correct Profile Type in Basic info<br />
Based on [Issue 404](https://github.com/Micke-K/IntuneManagement/issues/404)<br />
- **Generic**<br />
- Added support for configuring when the cache is cleared<br />
Cache is is cleared before a bulk export. <br />
If can now be changed in Settings with the **Clear Cache Before Export** and **Clear all objects from cache**.<br />
This can reaload all values if doing multiple manual imports but can also cause the imports to take longer.<br />
Based on [Issue 306](https://github.com/Micke-K/IntuneManagement/issues/306)<br />
- Lots of minor fixes<br />
## 3.10.2 - 2025-10-14
**Fixes**
- **Generic**<br />
- Paging<br />
Paging was introduce in 3.10 but was missed in the release notes and caused a lot of issues<br />
Turns out that far from all APIs supports paging<br />
Looks like Settings Catalog has a very weird paging solution where it returs the wrong number of objects<br />
Sometimes it reports it has more pages even if there are not objects to load e.g. I set page size to 5 and tried to load Android OEM Config<br />
Default page size is set to <b>100</b><br />
<b>Note:</b> Set <b>API Page size</b> in settings to <b>Graph API Default</b> to skip paging<br />
Based on [Issue 364](https://github.com/Micke-K/IntuneManagement/issues/364)<br />
- Entra Group Creation
Entra groups will now be created with random mailNickname to match the Entra portal.
- **Authentication**<br />
- Login with App in UI<br />
This was enabled before but Tenant ID was added to Settings to allow App Id login to a single tenant<br />
Based on [Issue 367](https://github.com/Micke-K/IntuneManagement/issues/367)<br />
<b>Note:</b>This is <b>NOT</b> recommended except for testing App permissions etc. The secret is stored in clear text
## 3.10.1 - 2025-09-14
<br />
A huge thank you to:<br />
- @befra for fixing uploads with PowerShell 7.5<br />
- @MrR0bert for fixing issues with Organization name with spaces<br />
<br />
**BREAKING CHANGE**<br />
Permission requirements has changed on script policies. **DeviceManagementScripts.ReadWrite.All** is now required and Consent Request might be required to add the permissions<br />
**New features**
- **Official PowerShell 7 Support**<br />
- PowerShell 7 is now supported<br />
This is now the recommended way of using the tool.<br />
PowerShell 7 has full support for WAM authentication which is required for strong authentication like FIDO2 etc.<br />
- **Authentication**<br />
- Added documentation on how to create a custom Entra app in [MSAL Info](MSALInfo.md)
- Changed permission requiremnt to **DeviceManagementScripts.ReadWrite.All** for
- Compliance Scripts
- Custom Attributes
- Health Scripts
- Scripts (PowerShell)
- Scripts (Shell)
**Fixes**
- **Generic**<br />
- Cannot rename Settings Catalog<br />
Based on [Issue 344](https://github.com/Micke-K/IntuneManagement/issues/344)<br />
- **Compare**<br />
- Compare added letter N to the string output<br />
Based on [Issue 320](https://github.com/Micke-K/IntuneManagement/issues/320)<br />
- Wrong Category when comparing Settings Catalog objects<br />
Based on [Issue 317](https://github.com/Micke-K/IntuneManagement/issues/317)<br />
- **Import/Export**<br />
- Basline Security Policy not imported<br />
Based on [Issue 241](https://github.com/Micke-K/IntuneManagement/issues/241)<br />
- Fixed import of old exported Compliance Policies<br />
DeviceSettings property support removed and cause import failure<br />
- Custom Compliance Scripts were not imported befor the Compliance Policy<br />
Based on [Issue 353](https://github.com/Micke-K/IntuneManagement/issues/353)<br />
- Added support for BIOS Configurations<br />
Based on [Issue 350](https://github.com/Micke-K/IntuneManagement/issues/350)<br />
- Set default Conditional Access state in Settings<br />
Based on [Issue 298](https://github.com/Micke-K/IntuneManagement/issues/298)<br />
- **Documentation**<br />
- "Not configured" valued added when Uncofigured settings was selected<br />
Based on [Issue 342](https://github.com/Micke-K/IntuneManagement/issues/342)<br />
- Add file content to documentation e.g. Custom Configuration profiles for MacOS<br />
Based on [Issue 329](https://github.com/Micke-K/IntuneManagement/issues/329)<br />
- Output type for Word export - PDF is now supported<br />
Based on [Discussion 329](https://github.com/Micke-K/IntuneManagement/discussions/331)<br />
- Skip date in documentation output<br />
Based on [Issue 336](https://github.com/Micke-K/IntuneManagement/issues/336)<br />
- Added support for Compliance Policies for Linux<br />
- Language files re-generated<br />
- AppTypes file re-generated<br />
- **ADMX Tool**<br />
- Failed to import settings for some ADMX files<br />
Based on [Issue 338](https://github.com/Micke-K/IntuneManagement/issues/338)<br />
## 3.10.0 - 2025-02-22 - Beta 1 (Development branch)
<br />
A huge thank you to:<br />
- @Mykhailo-Roit for the help with the paging<br />
- @Systems-Liam for Documentation updates<br />
- @ee61r for Documentation updates - This was missed in the previous release notes. Sorry!<br />
<br />
**New features**
- **PowerShell 7 Support**<br />
- PowerShell 7 is now supported. Tested with 7.5.0<br />
- Added CMD files for PowerShell 7<br />
- Not all features and polices are tested. Please report any issues<br />
PowerShell 7 handles dates differently in Json files etc which might cause some problems<br />
- **Authentication**<br />
- Microsoft Authentication Library Updated to 4.67.2.0<br />
- Added support for automation for GCC<br />
Based on [Issue 307](https://github.com/Micke-K/IntuneManagement/issues/307)<br />
- Added support for WAM - This allows for secure login scenarios eg Windows Hello, FIDO2<br />
WAM must be enabled in Settings. This will require a restart of the app<br />
**Note** WAM is only supported in PowerShell 7<br />
Based on [Issue 310](https://github.com/Micke-K/IntuneManagement/issues/310)<br />
Based on [Issue 167](https://github.com/Micke-K/IntuneManagement/issues/167)<br />
<br />
The Authentication update has been a long battle but it's hopefully working now<br />
**Fixes**
- **Generic**<br />
- Added support for setting the page size<br />
This can help with Settings Catalog missing policies<br />
Default page size is 20. This can be changed in Settings<br />
Based on [Issue 300](https://github.com/Micke-K/IntuneManagement/issues/300)<br />
[PR 301](https://github.com/Micke-K/IntuneManagement/pull/301)<br />
- **Compare**<br />
- Lots of Bulk Compare issues fixed<br />
- Compare can now export a Json file for futher analysing<br />
Based on [Issue 281](https://github.com/Micke-K/IntuneManagement/issues/281)<br />
- **Import/Export**<br />
- Added for support for export/import Device Categories<br />
Based on [Discussion 305](https://github.com/Micke-K/IntuneManagement/discussions/305)<br />
- Added API for export/import Inventory Policies<br />
**Note** These are not working but following Microsoft documentation.<br />
- **Documentation**<br />
- App Configuration (Device) documentation updated<br />
- Fixed bug with sub tables for MD and Word<br />
Based on [Issue 246](https://github.com/Micke-K/IntuneManagement/issues/246)<br />
## 3.9.8 - 2024-10-12
**New features**
- **Intune Info**<br />
- Added 'Baseline Templates - Settings Catalog'<br />
This list templates for Settings Catalog policies eg. Security Baseline for Windows 10 and later<br />
**Fixes**
- **Import/Export**<br />
- Fixed support for export/import App Configurations (Device) - Android between environments<br />
Based on [Issue 255](https://github.com/Micke-K/IntuneManagement/issues/255)<br />
Thank you @jimmywinberg for all the testing!<br />
- Fixed support for export/import App Configurations (Device) - iOS (VPP) between environments<br />
Based on [Issue 260](https://github.com/Micke-K/IntuneManagement/issues/260)<br />
Thank you @Arne-RFA for all the testing!<br />
- Added support for exporting Groups targeted in W365 assignments<br />
Based on [Issue 261](https://github.com/Micke-K/IntuneManagement/issues/261)<br />
- Added tooltip that variables are supported in the Export folder path<br />
Based on [Discussions 269](https://github.com/Micke-K/IntuneManagement/discussions/269)<br />
- **Documentation**<br />
- App Configuration (Device) documentation updated<br />
Added support for value type for Android policies<br />
Please continue discussion on the Issue below if this is still not working<br />
Based on [Issue 231](https://github.com/Micke-K/IntuneManagement/issues/231)<br />
This required some rewriting of the core documentation and an update to all output providers<br />
This will make it easier to add additional tables to the documentation in the future<br />
- Fixed issue with missing group name when exporting CSV<br />
Based on [Issue 274](https://github.com/Micke-K/IntuneManagement/issues/274)<br />
- Fixed issue with Authentication Strength when documenting Conditional Access policies<br />
- Language files re-generated<br />
- ObjectInfo files re-generated. Some Android updates<br />
- ObjectCategory file re-generated<br />
- **Compare**<br />
- Fixed issue with assignments on exported files when doing a Documentation compare<br />
The group name was not resolved from migration table file<br />
Based on [Issue 274](https://github.com/Micke-K/IntuneManagement/issues/274)<br />
- **Authentication**<br />
- Added setting to allow Sort Tenant List<br />
Based on [Issue 265](https://github.com/Micke-K/IntuneManagement/issues/265)<br />
<br />
## 3.9.7 - 2024-06-27
**New features**
@@ -29,7 +270,7 @@
- **Documentation**<br />
- App Configuration (Device) documentation updated<br />
Hopfully add support for Android. Not verified since I don't have one in my test environment<br />
Initial support for Android<br />
Please continue discussion on the Issue below if this is still not working<br />
Based on [Issue 231](https://github.com/Micke-K/IntuneManagement/issues/231)<br />
- Added support for documenting MacOS Custom attribute<br />
+2 -2
View File
@@ -117,7 +117,7 @@ function Export-EncryptionKeys
if($DetectionXML.ApplicationInfo.MsiInfo)
{
$msiInfo.MsiPublisher = $DetectionXML.ApplicationInfo.MsiInfo.MsiPublisher
$msiInfo.MsiProductCode = $DetectionXML.ApplicationInfo.MsiInfo.Publisher
$msiInfo.MsiProductCode = $DetectionXML.ApplicationInfo.MsiInfo.MsiProductCode
$msiInfo.MsiProductVersion = $DetectionXML.ApplicationInfo.MsiInfo.MsiProductVersion
$msiInfo.MsiPackageCode = $DetectionXML.ApplicationInfo.MsiInfo.MsiPackageCode
$msiInfo.MsiUpgradeCode = $DetectionXML.ApplicationInfo.MsiInfo.MsiUpgradeCode
@@ -141,7 +141,7 @@ function Export-EncryptionKeys
if([IO.Directory]::Exists($exportFolder) -eq $false)
{
md $exportFolder | Out-Null
New-Item -ItemType Directory -Path $exportFolder -Force | Out-Null
}
$fileName = $exportFolder + "\$($fileInfo.BaseName)_$($DetectionXML.ApplicationInfo.UnencryptedContentSize).json"

Some files were not shown because too many files have changed in this diff Show More