Policies: Zuweisungen sichtbar, Ergebnis-Report, Post-Import-Parität (#1 #4 #5)

- #1 Spalte "Zuweisungen" in der Policy-Liste (Anzahl); Klick öffnet eine
  Detailansicht mit den konkreten Include-/Exclude-Gruppen und Alle Geräte/
  Benutzer. Get-GraphPolicyList lädt jetzt $expand=assignments und löst
  Gruppennamen in einem Bulk-Lookup (Resolve-GroupNamesBulk) auf.
- #4 Bulk-Zuweisung zeigt statt nur eines Toasts einen Ergebnis-Report pro
  Policy (zugewiesen / übersprungen / Fehler) und lädt die Liste neu.
- #5 Post-Import-Zuweisung erhält Alle Geräte/Alle Benutzer (Parität zur
  Bulk-Zuweisung) und nutzt dieselbe Ergebnisansicht.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-09-16 12:23:10 +02:00
co-authored by Claude Opus 4.8
parent a7c8e88793
commit 9fb42b4d7e
4 changed files with 182 additions and 23 deletions
+42 -2
View File
@@ -154,14 +154,35 @@ function Get-GraphPolicyList {
param([Parameter(Mandatory=$true)][string]$Type)
$cfg = Get-PolicyTypeConfig $Type
if (-not $cfg) { throw "Unbekannter Policy-Typ: $Type" }
$raw = Get-GraphPaged -Uri "https://graph.microsoft.com/beta/deviceManagement/$($cfg.Collection)"
$items = @()
# Zuweisungen gleich mitladen ($expand=assignments), damit die Liste je Policy
# Anzahl + aufgeloeste Ziele zeigen kann.
$raw = Get-GraphPaged -Uri "https://graph.microsoft.com/beta/deviceManagement/$($cfg.Collection)?`$expand=assignments"
$items = @()
$needGroups = @{} # eindeutige Gruppen-Ids ueber alle Policies (fuer 1 Bulk-Lookup)
foreach ($r in $raw) {
$id = Get-PolicyProp $r 'id'
if (-not $id) { continue }
$name = Get-PolicyProp $r $cfg.NameField
if (-not $name) { $name = Get-PolicyProp $r 'displayName' }
if (-not $name) { $name = Get-PolicyProp $r 'name' }
$asg = @()
foreach ($a in @(Get-PolicyProp $r 'assignments')) {
$t = Get-PolicyProp $a 'target'
if (-not $t) { continue }
$ot = [string](Get-PolicyProp $t '@odata.type')
$gid = [string](Get-PolicyProp $t 'groupId')
$entry = $null
if ($ot -like '*exclusionGroupAssignmentTarget') { $entry = [ordered]@{ mode = 'exclude'; kind = 'group'; groupId = $gid } }
elseif ($ot -like '*groupAssignmentTarget') { $entry = [ordered]@{ mode = 'include'; kind = 'group'; groupId = $gid } }
elseif ($ot -like '*allDevicesAssignmentTarget') { $entry = [ordered]@{ mode = 'include'; kind = 'allDevices'; groupId = '' } }
elseif ($ot -like '*allLicensedUsersAssignmentTarget') { $entry = [ordered]@{ mode = 'include'; kind = 'allUsers'; groupId = '' } }
if ($entry) {
if ($gid) { $needGroups[$gid] = $true }
$asg += $entry
}
}
$items += [ordered]@{
id = [string]$id
name = [string]$name
@@ -170,6 +191,25 @@ function Get-GraphPolicyList {
platform = Get-PolicyPlatformLabel -Raw $r -Type $cfg.Key
odataType = [string](Get-PolicyProp $r '@odata.type')
lastModifiedDateTime = Get-PolicyProp $r 'lastModifiedDateTime'
assignments = $asg
assignmentCount = @($asg).Count
}
}
# Gruppennamen in EINEM Bulk-Lookup aufloesen (bereits bekannte aus dem Cache).
$lookup = @{}
try {
foreach ($g in @($script:State.Groups)) { if ($g.Id) { $lookup[[string]$g.Id] = [string]$g.DisplayName } }
foreach ($g in @($script:State.RpaGroups)) { if ($g.Id) { $lookup[[string]$g.Id] = [string]$g.DisplayName } }
} catch {}
$unknown = [string[]]@($needGroups.Keys | ForEach-Object { [string]$_ } | Where-Object { $_ -and -not $lookup.ContainsKey($_) })
if ($unknown.Count -gt 0) { try { Resolve-GroupNamesBulk -Ids $unknown -Lookup $lookup } catch {} }
foreach ($it in $items) {
foreach ($a in @($it.assignments)) {
if ($a.kind -eq 'group') {
$gid = [string]$a.groupId
$a.groupName = if ($lookup.ContainsKey($gid)) { $lookup[$gid] } else { $gid }
}
}
}
return $items