Repository navigation
Expand file tree
/
Copy pathIntuneScriptLab.psd1
More file actions
105 lines (102 loc) · 5.59 KB
/
Copy pathIntuneScriptLab.psd1
File metadata and controls
105 lines (102 loc) · 5.59 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
@{
# Module manifest for IntuneScriptLab
RootModule = 'IntuneScriptLab.psm1'
ModuleVersion = '0.29.0'
GUID = '3f6b2c9e-7d41-4a8f-9c2b-5e0d8a1f4b76'
Author = 'Jeffrey Stuhr'
CompanyName = ''
Copyright = '(c) 2026 Jeffrey Stuhr. All rights reserved.'
# Two lines, within the repository's 115-character limit; the README carries the long form
Description = @'
Test Intune scripts before Intune does: static rules, a runtime harness, Pester assertions, a Graph
pre-flight over the tenant's deployed scripts and readers for the agent's logs
'@
# The analyzer itself runs anywhere. The rules describe Windows PowerShell 5.1 behaviour
# because that is what the Intune Management Extension runs scripts with.
PowerShellVersion = '5.1'
CompatiblePSEditions = @('Desktop', 'Core')
RequiredModules = @()
FormatsToProcess = @('IntuneScriptLab.Format.ps1xml')
FunctionsToExport = @(
'Test-IntuneScript',
'Invoke-IntuneDetectionTest',
'Invoke-IntuneRemediationTest',
'Invoke-IntunePlatformScriptTest',
'Invoke-IntuneWin32AppTest',
'Invoke-IntuneRequirementTest',
'Test-IntuneWin32Rule',
'Test-IntuneWin32Requirement',
'Get-IntuneAgentLog',
'Get-IntuneAgentTimeline',
'Export-IntuneAgentDiagnostic',
'Get-IntuneAnalyzerRulePath',
'Test-IntuneDeployedScript',
'Compare-IntuneDeployedScript',
'Get-IntuneScriptHealth',
'Export-IntuneFindingSarif',
'Repair-IntuneScript',
'Test-IntuneAssignmentFilter',
'Assert-HaveIntuneStatus',
'Assert-BeIntuneDetected',
'Assert-NotBeIntuneDetected',
'Assert-HaveIntuneRunState',
'Assert-PassIntuneAnalysis',
'Assert-BeIntuneApplicable',
'Assert-NotBeIntuneApplicable'
)
CmdletsToExport = @()
VariablesToExport = @()
AliasesToExport = @(
'Should-HaveIntuneStatus',
'Should-BeIntuneDetected',
'Should-NotBeIntuneDetected',
'Should-HaveIntuneRunState',
'Should-PassIntuneAnalysis',
'Should-BeIntuneApplicable',
'Should-NotBeIntuneApplicable'
)
PrivateData = @{
PSData = @{
Tags = @('Intune', 'Remediation', 'Win32', 'PSScriptAnalyzer', 'Lint', 'Endpoint', 'Pester')
LicenseUri = 'https://github.com/fadwen/IntuneScriptLab/blob/main/LICENSE'
ProjectUri = 'https://github.com/fadwen/IntuneScriptLab'
ReleaseNotes = @'
0.29.0 - A remediation that writes to stderr is a script error on the device whatever its exit code:
RemediationStatus 3, Graph scriptError, the error text attached, no post-detection.
Invoke-IntuneRemediationTest reported Recurred for that run since round 1; it reports Failed,
skips the post-detection and warns that the exit code was 0. A detection's stderr still changes
nothing. IslOutputIssue warns about Write-Error and an unguarded cmdlet in a remediation script,
with -ErrorAction Stop as the fix. Measured in user context on the lab device with five one-off
remediations, recorded as round 11 (REM-STDERR-*). See CHANGELOG.md.
0.28.0 - Test-IntuneScript analyzes a script about two and a half times faster, with the syntax tree
walked once and indexed instead of once per rule; Get-IntuneAgentLog reads a large log
filtered in a fifth of the time. Repair-IntuneScript takes -Context, -Architecture and
-EnforceSignatureCheck like Test-IntuneScript, and applies eight more edits: -Force on
Install-Module and its kin, -ErrorAction SilentlyContinue on a probing cmdlet, exit 1 for an
exit code Intune reads as 1, $env:ProgramW6432, 'ARM64|AMD64', $PSScriptRoot, a
Get-Credential -Credential call that returns what it was handed, a Set-ExecutionPolicy or
#Requires -Version 7 line removed. Test-IntuneDeployedScript judges a device group by its
member counts rather than its first 20 members; every Graph request is retried on 429, 503
and 504. Invoke-IntuneDetectionTest, Invoke-IntunePlatformScriptTest and
Invoke-IntuneRequirementTest take script paths from the pipeline; every result type has a
format view. The in-box module table is held against the host's Windows PowerShell by a
test, as the PowerShell 7-only tables are. See CHANGELOG.md.
0.27.0 - Harness: a user-context run started from PowerShell 7 gave the 5.1 host PowerShell 7's
module path (no Cert: drive, Security cmdlets failing to load); -Credential did not find
a Microsoft Entra account's session, because Windows names such an account after its
display name and not its sign-in name; a refused folder grant lost its message under
-ErrorAction Stop on 5.1. Rules, from a tenth validation round: IslPowerShell7Syntax says
that a 7-only cmdlet, parameter or -Parallel fails where it stands and the script carries
on, and flags Out-File -Encoding utf8NoBOM, which was listed and never matched;
IslInteractiveCall warns instead of erring when Get-Credential -Credential is handed
something that may be a built credential; IslContextIssue's drive-letter finding is
Information, since the letter cannot say whether it is a mapped drive.
Repair-IntuneScript no longer turns 'return 1; exit 1' into '1; exit 0; exit 1' with no
finding left. Help: what Invoke-ScriptAnalyzer -Severity does with the custom rules. See
CHANGELOG.md.
Earlier versions, 0.1.0 to 0.26.0: CHANGELOG.md, which ships with the module.
'@
RequireLicenseAcceptance = $false
}
}
}