v0.1.32 — Bulk-Offboarding aus dem Geraete-Tab, Geraete-Ladefehler behoben
Build & Release MSI / build-msi (push) Canceled after 0s

- Bulk-Offboarding aus dem Geraete-Tab (Checkboxen + Alle, POST /api/offboard/resolve)
- Fix "Geraete konnten nicht geladen werden" (400): managementState raus dem $select,
  $orderby entfernt, Namensfilter-Fallback auf deviceName, beta-Endpoint
- Bessere Graph-Fehler-Diagnose (Graph-Body an die Meldung anhaengen)
- Offboard: Grund fuer nicht gefundene Autopilot-Zuordnung sichtbar (autopilotNote)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-09-11 22:08:46 +02:00
co-authored by Claude Opus 4.8
parent bd73a9c3b2
commit 968f47b94f
10 changed files with 187 additions and 28 deletions
+35 -15
View File
@@ -63,6 +63,7 @@ function Invoke-ApiHandler {
"POST /api/pickfolder" { return Invoke-FolderPickerEndpoint -Body $Body }
"GET /api/offboard/search" { return Search-OffboardDevicesEndpoint -Query $Query }
"POST /api/offboard/resolve" { return Get-OffboardResolveEndpoint -Body $Body }
"POST /api/offboard/keys" { return Get-OffboardKeysEndpoint -Body $Body }
"POST /api/offboard/execute" { return Invoke-OffboardExecuteEndpoint -Body $Body }
}
@@ -1784,12 +1785,14 @@ function Search-DevicesEndpoint {
$err = Test-Connected
if ($err) { return $err }
$q = [string]$Query.q
$q = ([string]$Query.q) -replace "'", "''" # OData-Escape fuer Apostroph
$os = [string]$Query.os
$compliance = [string]$Query.compliance
$top = 50
$select = 'id,deviceName,userDisplayName,userPrincipalName,operatingSystem,osVersion,complianceState,lastSyncDateTime,managementState,serialNumber,model,manufacturer,enrolledDateTime'
# HINWEIS: 'managementState' ist KEIN gueltiges $select-Feld auf managedDevices
# -> fuehrt zu 400 BadRequest. Bewusst weggelassen.
$select = 'id,deviceName,userDisplayName,userPrincipalName,operatingSystem,osVersion,complianceState,lastSyncDateTime,serialNumber,model,manufacturer,enrolledDateTime'
# Ohne Suchbegriff: alle Geräte (erste Seite)
# Mit Suchbegriff: Graph unterstuetzt startswith nur auf deviceName/userDisplayName/userPrincipalName.
@@ -1798,22 +1801,36 @@ function Search-DevicesEndpoint {
$snItems = @()
if ($q -and $q.Length -ge 2) {
$filters = @()
$nameFilter = "(startswith(deviceName,'$q') or startswith(userDisplayName,'$q') or startswith(userPrincipalName,'$q'))"
$filters += $nameFilter
if ($os) { $filters += "operatingSystem eq '$os'" }
if ($compliance) { $filters += "complianceState eq '$compliance'" }
$filterStr = '$filter=' + [uri]::EscapeDataString(($filters -join ' and ')) + '&'
$uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?${filterStr}`$select=$select&`$top=$top&`$orderby=deviceName"
$resp = Invoke-MgGraphRequestRetry -Uri $uri -Method GET
$nameItems = @($resp.value)
$osComp = @()
if ($os) { $osComp += "operatingSystem eq '$os'" }
if ($compliance) { $osComp += "complianceState eq '$compliance'" }
# Voller Namensfilter vs. nur deviceName. Manche Intune-Backends (DeviceFE)
# unterstuetzen startswith NUR auf deviceName -> bei "Unsupported parameter"
# (400) auf deviceName-only zurueckfallen. Kein $orderby mit $filter.
$nameVariants = @(
"(startswith(deviceName,'$q') or startswith(userDisplayName,'$q') or startswith(userPrincipalName,'$q'))",
"startswith(deviceName,'$q')"
)
for ($vi = 0; $vi -lt $nameVariants.Count; $vi++) {
$filters = @($nameVariants[$vi]) + $osComp
$filterStr = '$filter=' + [uri]::EscapeDataString(($filters -join ' and ')) + '&'
$uri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices?${filterStr}`$select=$select&`$top=$top"
try {
$resp = Invoke-MgGraphRequestRetry -Uri $uri -Method GET
$nameItems = @($resp.value)
break
} catch {
if ($vi -eq $nameVariants.Count - 1) { throw } # letzter Versuch -> durchreichen
Write-Host " [DEVICES] Namensfilter nicht unterstuetzt -> Fallback auf deviceName-only" -ForegroundColor DarkYellow
}
}
# Seriennummer: exakter Vergleich (Graph unterstuetzt kein startswith auf serialNumber)
$snFilters = @("serialNumber eq '$q'")
if ($os) { $snFilters += "operatingSystem eq '$os'" }
if ($compliance) { $snFilters += "complianceState eq '$compliance'" }
$snFilter = '$filter=' + [uri]::EscapeDataString(($snFilters -join ' and ')) + '&'
$snUri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?${snFilter}`$select=$select&`$top=10"
$snUri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices?${snFilter}`$select=$select&`$top=10"
try {
$snResp = Invoke-MgGraphRequestRetry -Uri $snUri -Method GET
$snItems = @($snResp.value)
@@ -1823,7 +1840,9 @@ function Search-DevicesEndpoint {
if ($os) { $filters += "operatingSystem eq '$os'" }
if ($compliance) { $filters += "complianceState eq '$compliance'" }
$filterStr = if ($filters.Count -gt 0) { '$filter=' + [uri]::EscapeDataString(($filters -join ' and ')) + '&' } else { '' }
$uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?${filterStr}`$select=$select&`$top=$top&`$orderby=deviceName"
# Kein $orderby: das Intune-DeviceFE-Backend lehnt es (mit/ohne Filter) teils ab.
# Die Sortierung macht ohnehin das Frontend.
$uri = "https://graph.microsoft.com/beta/deviceManagement/managedDevices?${filterStr}`$select=$select&`$top=$top"
$resp = Invoke-MgGraphRequestRetry -Uri $uri -Method GET
$nameItems = @($resp.value)
}
@@ -1859,8 +1878,9 @@ function Get-DeviceEndpoint {
$err = Test-Connected
if ($err) { return $err }
$select = 'id,deviceName,userDisplayName,userPrincipalName,operatingSystem,osVersion,complianceState,lastSyncDateTime,managementState,serialNumber,model,manufacturer,enrolledDateTime,imei,wiFiMacAddress,azureADDeviceId,joinType,deviceEnrollmentType,managedDeviceOwnerType,totalStorageSpaceInBytes,freeStorageSpaceInBytes'
$d = Invoke-MgGraphRequestRetry -Uri "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId`?`$select=$select" -Method GET
# 'managementState' entfernt: kein gueltiges $select-Feld auf managedDevices (400).
$select = 'id,deviceName,userDisplayName,userPrincipalName,operatingSystem,osVersion,complianceState,lastSyncDateTime,serialNumber,model,manufacturer,enrolledDateTime,imei,wiFiMacAddress,azureADDeviceId,joinType,deviceEnrollmentType,managedDeviceOwnerType,totalStorageSpaceInBytes,freeStorageSpaceInBytes'
$d = Invoke-MgGraphRequestRetry -Uri "https://graph.microsoft.com/beta/deviceManagement/managedDevices/$DeviceId`?`$select=$select" -Method GET
$totalGB = if ($d.totalStorageSpaceInBytes) { [math]::Round($d.totalStorageSpaceInBytes / 1GB, 1) } else { $null }
$freeGB = if ($d.freeStorageSpaceInBytes) { [math]::Round($d.freeStorageSpaceInBytes / 1GB, 1) } else { $null }
+5
View File
@@ -71,6 +71,11 @@ function Invoke-MgGraphRequestRetry {
Start-Sleep -Seconds $wait
continue
}
# Nicht-Retry-Fehler: den Graph-Fehler-Body (mit dem eigentlichen Grund)
# an die Meldung haengen — sonst steht im Log nur "BadRequest".
$gbody = $null
try { $gbody = [string]$_.ErrorDetails.Message } catch {}
if ($gbody) { throw [System.Exception]::new("$msg | Graph: $gbody", $_.Exception) }
throw
}
}
+52 -3
View File
@@ -55,6 +55,15 @@ function Search-OffboardDevicesEndpoint {
return @{ __status = 500; error = "Graph-Fehler bei der Suche: $m" }
}
if ($intune.Count -eq 0) { return @{ items = @(); count = 0 } }
return @{ items = @(Resolve-OffboardItems -IntuneDevices $intune); count = $intune.Count }
}
# Reichert Intune-managedDevice-Objekte mit Entra-Objekt-Id + Autopilot-Id an
# (per $batch) und liefert die Offboard-Item-Struktur fuers Frontend.
function Resolve-OffboardItems {
param([object[]]$IntuneDevices)
$intune = @($IntuneDevices)
if ($intune.Count -eq 0) { return @() }
# Entra-Objekt (fuer Delete) + Autopilot-Identity (fuer Delete) per Batch nachladen.
$reqs = @()
@@ -77,9 +86,23 @@ function Search-OffboardDevicesEndpoint {
$items = @()
$idx = 0
foreach ($d in $intune) {
$entra = $null; $autop = $null
$ser = [string]$d.serialNumber
$entra = $null; $autop = $null; $apNote = ''
$er = $batch["e$idx"]; if ($er -and [int]$er.status -eq 200) { $entra = @($er.body.value)[0] }
$ar = $batch["a$idx"]; if ($ar -and [int]$ar.status -eq 200) { $autop = @($ar.body.value)[0] }
$ar = $batch["a$idx"]
if ($ar) {
$ast = [int]$ar.status
if ($ast -eq 200) {
$autop = @($ar.body.value)[0]
if (-not $autop) { $apNote = 'Kein Autopilot-Treffer fuer Seriennummer' }
} else {
$acode = ''; try { $acode = [string]$ar.body.error.code } catch {}
$apNote = "Autopilot-Lookup fehlgeschlagen: HTTP $ast" + $(if ($acode) { " ($acode)" } else { '' })
Write-Host " [OFFBOARD] Autopilot-Lookup ($($d.deviceName), SN=$ser): HTTP $ast $acode" -ForegroundColor DarkYellow
}
} elseif (-not $ser) {
$apNote = 'Keine Seriennummer am Intune-Geraet'
}
$items += [pscustomobject]@{
deviceName = [string]$d.deviceName
serialNumber = [string]$d.serialNumber
@@ -94,13 +117,39 @@ function Search-OffboardDevicesEndpoint {
entraObjectId = if ($entra) { [string]$entra.id } else { '' }
entraEnabled = if ($entra) { [bool]$entra.accountEnabled } else { $null }
autopilotId = if ($autop) { [string]$autop.id } else { '' }
autopilotNote = $apNote
inIntune = $true
inEntra = [bool]$entra
inAutopilot = [bool]$autop
}
$idx++
}
return @{ items = @($items); count = $items.Count }
return @($items)
}
# Offboard-Items zu einer Liste von Intune-Device-Ids aufloesen (fuer Bulk-
# Offboarding aus dem Geraete-Tab). Body: { ids: [intuneDeviceId, ...] }
function Get-OffboardResolveEndpoint {
param($Body)
$err = Test-Connected
if ($err) { return $err }
$ids = @(Get-PolicyProp $Body 'ids') | Where-Object { $_ }
if (@($ids).Count -eq 0) { return @{ items = @(); count = 0 } }
$sel = 'id,deviceName,serialNumber,operatingSystem,osVersion,userPrincipalName,lastSyncDateTime,azureADDeviceId,managedDeviceOwnerType,managementAgent'
$reqs = @()
$i = 0
foreach ($id in $ids) {
$reqs += @{ id = "d$i"; method = 'GET'; url = "/deviceManagement/managedDevices/$([string]$id)?`$select=$sel" }
$i++
}
$batch = Invoke-GraphBatch -Requests $reqs
$devs = @()
foreach ($k in @($batch.Keys)) {
$r = $batch[$k]
if ($r -and [int]$r.status -eq 200 -and $r.body) { $devs += $r.body }
}
return @{ items = @(Resolve-OffboardItems -IntuneDevices $devs); count = @($devs).Count }
}
# Recovery-Keys eines Geraets holen (vor dem Loeschen). Body: