Geräte-Tab: Autopilot Reset Aktion

Windows Autopilot Reset via wipe mit keepEnrollmentData:true.
Button nur bei Windows-Geräten sichtbar, separate Warnmeldung.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-08-12 14:31:59 +02:00
co-authored by Claude Sonnet 4.6
parent 78dc8d5c01
commit f94141dbe0
3 changed files with 22 additions and 8 deletions
+8 -3
View File
@@ -1622,13 +1622,18 @@ function Invoke-DeviceActionEndpoint {
if ($err) { return $err } if ($err) { return $err }
$action = [string]$Body.action $action = [string]$Body.action
$allowed = @('syncDevice','rebootNow','remoteLock','collectDiagnostics','rotateBitLockerKeys','retire') $allowed = @('syncDevice','rebootNow','remoteLock','collectDiagnostics','rotateBitLockerKeys','retire','autopilotReset')
if ($action -notin $allowed) { if ($action -notin $allowed) {
return @{ statusCode = 400; error = "Unbekannte Aktion: $action" } return @{ statusCode = 400; error = "Unbekannte Aktion: $action" }
} }
$uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId/$action" if ($action -eq 'autopilotReset') {
$bodyJson = '{}' $uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId/wipe"
$bodyJson = '{"keepEnrollmentData":true,"keepUserData":false}'
} else {
$uri = "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/$DeviceId/$action"
$bodyJson = '{}'
}
Invoke-MgGraphRequestRetry -Uri $uri -Method POST -Body $bodyJson -ContentType 'application/json' | Out-Null Invoke-MgGraphRequestRetry -Uri $uri -Method POST -Body $bodyJson -ContentType 'application/json' | Out-Null
return @{ success = $true; action = $action } return @{ success = $true; action = $action }
} }
+10 -5
View File
@@ -5387,10 +5387,12 @@ function devRenderDetail(d) {
} }
document.getElementById('devInfoGrid').innerHTML = html; document.getElementById('devInfoGrid').innerHTML = html;
// Aktionen: BitLocker nur für Windows // Aktionen: BitLocker und Autopilot Reset nur für Windows
const isWin = (d.OS || '').toLowerCase() === 'windows'; const isWin = (d.OS || '').toLowerCase() === 'windows';
const bitlockerBtn = document.getElementById('devBtnBitlocker'); const bitlockerBtn = document.getElementById('devBtnBitlocker');
if (bitlockerBtn) bitlockerBtn.style.display = isWin ? '' : 'none'; if (bitlockerBtn) bitlockerBtn.style.display = isWin ? '' : 'none';
const autopilotBtn = document.getElementById('devBtnAutopilot');
if (autopilotBtn) autopilotBtn.style.display = isWin ? '' : 'none';
} }
// Aktion ausführen // Aktion ausführen
@@ -5406,13 +5408,16 @@ document.getElementById('devActions')?.addEventListener('click', async (e) => {
remoteLock: 'Sperren', remoteLock: 'Sperren',
collectDiagnostics: 'Diagnose sammeln', collectDiagnostics: 'Diagnose sammeln',
rotateBitLockerKeys: 'BitLocker-Schlüssel rotieren', rotateBitLockerKeys: 'BitLocker-Schlüssel rotieren',
autopilotReset: 'Autopilot Reset',
retire: 'Retire (MDM entfernen)' retire: 'Retire (MDM entfernen)'
}; };
const isDangerous = action === 'retire'; const isDangerous = action === 'retire' || action === 'autopilotReset';
const devName = DevState.selected.DeviceName || DevState.selected.Id; const devName = DevState.selected.DeviceName || DevState.selected.Id;
const msg = isDangerous const dangerMsg = {
? `ACHTUNG: "${labels[action]}" auf "${devName}" ausführen?\n\nDas MDM-Profil wird entfernt — Gerät wird nicht mehr verwaltet.` retire: `ACHTUNG: "Retire" auf "${devName}" ausführen?\n\nDas MDM-Profil wird entfernt — Gerät wird nicht mehr verwaltet.`,
: `"${labels[action]}" auf "${devName}" ausführen?`; autopilotReset: `ACHTUNG: "Autopilot Reset" auf "${devName}" ausführen?\n\nDas Gerät wird auf OOBE zurückgesetzt. Enrollment-Daten bleiben erhalten, Benutzerdaten werden gelöscht.`
};
const msg = dangerMsg[action] || `"${labels[action]}" auf "${devName}" ausführen?`;
if (!confirm(msg)) return; if (!confirm(msg)) return;
+4
View File
@@ -540,6 +540,10 @@
<svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2"><rect x="3" y="11" width="18" height="11" rx="2"/><path d="M7 11V7a5 5 0 0 1 10 0v4"/><circle cx="12" cy="16" r="1"/></svg> <svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2"><rect x="3" y="11" width="18" height="11" rx="2"/><path d="M7 11V7a5 5 0 0 1 10 0v4"/><circle cx="12" cy="16" r="1"/></svg>
BitLocker BitLocker
</button> </button>
<button class="btn btn-danger btn-sm dev-action-btn" data-action="autopilotReset" title="Windows Autopilot Reset (Gerät wird zurückgesetzt, bleibt aber enrolliert)" id="devBtnAutopilot">
<svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2"><path d="M3 12a9 9 0 0 1 9-9 9.75 9.75 0 0 1 6.74 2.74L21 8"/><path d="M21 3v5h-5"/><path d="M21 12a9 9 0 0 1-9 9 9.75 9.75 0 0 1-6.74-2.74L3 16"/><path d="M8 16H3v5"/></svg>
Autopilot Reset
</button>
<button class="btn btn-danger btn-sm dev-action-btn" data-action="retire" title="MDM-Profil entfernen (Retire)"> <button class="btn btn-danger btn-sm dev-action-btn" data-action="retire" title="MDM-Profil entfernen (Retire)">
<svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2"><polyline points="3 6 5 6 21 6"/><path d="M19 6l-1 14H6L5 6"/><path d="M10 11v6"/><path d="M14 11v6"/><path d="M9 6V4h6v2"/></svg> <svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2"><polyline points="3 6 5 6 21 6"/><path d="M19 6l-1 14H6L5 6"/><path d="M10 11v6"/><path d="M14 11v6"/><path d="M9 6V4h6v2"/></svg>
Retire Retire