From f94141dbe0daf3a04a296beea2bf6caa5261b615 Mon Sep 17 00:00:00 2001 From: Marco Wende Date: Wed, 12 Aug 2026 14:31:59 +0200 Subject: [PATCH] =?UTF-8?q?Ger=C3=A4te-Tab:=20Autopilot=20Reset=20Aktion?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Windows Autopilot Reset via wipe mit keepEnrollmentData:true. Button nur bei Windows-Geräten sichtbar, separate Warnmeldung. Co-Authored-By: Claude Sonnet 4.6 --- src/Api.ps1 | 11 ++++++++--- www/app.js | 15 ++++++++++----- www/index.html | 4 ++++ 3 files changed, 22 insertions(+), 8 deletions(-) diff --git a/src/Api.ps1 b/src/Api.ps1 index 9d62e3c..05ae7fa 100644 --- a/src/Api.ps1 +++ b/src/Api.ps1 @@ -1622,13 +1622,18 @@ function Invoke-DeviceActionEndpoint { if ($err) { return $err } $action = [string]$Body.action - $allowed = @('syncDevice','rebootNow','remoteLock','collectDiagnostics','rotateBitLockerKeys','retire') + $allowed = @('syncDevice','rebootNow','remoteLock','collectDiagnostics','rotateBitLockerKeys','retire','autopilotReset') if ($action -notin $allowed) { return @{ statusCode = 400; error = "Unbekannte Aktion: $action" } } - $uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId/$action" - $bodyJson = '{}' + if ($action -eq 'autopilotReset') { + $uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId/wipe" + $bodyJson = '{"keepEnrollmentData":true,"keepUserData":false}' + } else { + $uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId/$action" + $bodyJson = '{}' + } Invoke-MgGraphRequestRetry -Uri $uri -Method POST -Body $bodyJson -ContentType 'application/json' | Out-Null return @{ success = $true; action = $action } } diff --git a/www/app.js b/www/app.js index d72707d..2612265 100644 --- a/www/app.js +++ b/www/app.js @@ -5387,10 +5387,12 @@ function devRenderDetail(d) { } document.getElementById('devInfoGrid').innerHTML = html; - // Aktionen: BitLocker nur für Windows + // Aktionen: BitLocker und Autopilot Reset nur für Windows const isWin = (d.OS || '').toLowerCase() === 'windows'; const bitlockerBtn = document.getElementById('devBtnBitlocker'); if (bitlockerBtn) bitlockerBtn.style.display = isWin ? '' : 'none'; + const autopilotBtn = document.getElementById('devBtnAutopilot'); + if (autopilotBtn) autopilotBtn.style.display = isWin ? '' : 'none'; } // Aktion ausführen @@ -5406,13 +5408,16 @@ document.getElementById('devActions')?.addEventListener('click', async (e) => { remoteLock: 'Sperren', collectDiagnostics: 'Diagnose sammeln', rotateBitLockerKeys: 'BitLocker-Schlüssel rotieren', + autopilotReset: 'Autopilot Reset', retire: 'Retire (MDM entfernen)' }; - const isDangerous = action === 'retire'; + const isDangerous = action === 'retire' || action === 'autopilotReset'; const devName = DevState.selected.DeviceName || DevState.selected.Id; - const msg = isDangerous - ? `ACHTUNG: "${labels[action]}" auf "${devName}" ausführen?\n\nDas MDM-Profil wird entfernt — Gerät wird nicht mehr verwaltet.` - : `"${labels[action]}" auf "${devName}" ausführen?`; + const dangerMsg = { + retire: `ACHTUNG: "Retire" auf "${devName}" ausführen?\n\nDas MDM-Profil wird entfernt — Gerät wird nicht mehr verwaltet.`, + autopilotReset: `ACHTUNG: "Autopilot Reset" auf "${devName}" ausführen?\n\nDas Gerät wird auf OOBE zurückgesetzt. Enrollment-Daten bleiben erhalten, Benutzerdaten werden gelöscht.` + }; + const msg = dangerMsg[action] || `"${labels[action]}" auf "${devName}" ausführen?`; if (!confirm(msg)) return; diff --git a/www/index.html b/www/index.html index 59b2177..27c5780 100644 --- a/www/index.html +++ b/www/index.html @@ -540,6 +540,10 @@ BitLocker +