AzStackHci.DiagnosticSettings

0.7.0

Microsoft Azure Local - Diagnostics settings and connectivity tests support module

Minimum PowerShell version

5.1

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name AzStackHci.DiagnosticSettings

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name AzStackHci.DiagnosticSettings

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Microsoft Corporation. All rights reserved.

Package Details

Author(s)

  • Microsoft Corporation

Tags

Microsoft AzStackHci Diagnostic Settings Connectivity AzureLocal

Functions

Get-AzStackHciMemoryDumpSettings Set-AzStackHciMemoryDumpSettings Restore-AzStackHciMemoryDumpSettings Get-AzStackHciPageFileSettings Restore-AzStackHciPageFileSettings Set-AzStackHciPageFileSettings Set-AzStackHciPageFileSettingsMinimal Get-AzStackHciUserModeCrashDumpSettings Set-AzStackHciUserModeCrashDumpSettings Restore-AzStackHciUserModeCrashDumpSettings Test-AzStackHciSSLInspection Send-ClusterPerformanceHistory Test-AzureLocalConnectivity Test-Layer7Connectivity Test-TCPConnectivity Get-AzStackHciOsConfigSettings Test-ArcMachinePrivateLinkScopeEnabled Remove-AzStackHciDiagnosticArtifact Get-AzStackHciVMCheckpointHealth

PSEditions

Desktop Core

Dependencies

This module has no dependencies.

Release Notes

## v0.7.0

- OSConfig schema 1.4 adds SecurityBaselineHealth/DefenderHealth, baseline/ASR tabs and evidence in reports, PassThru and HealthSummaryOnly. Deltas warn; missing evidence never passes.
- Read-only LSA rights, nine local-account/SAM fallbacks and Schannel TLS/DTLS minima extend coverage. Collects configured policy limits, not password ages/secrets; no policy/authentication changes.
- Exact Base64 REG_BINARY comparison preserves bytes. Multi-string, hardened-path and local-lockout comparisons retain types/values.
- Stored security data is supporting, not effective evidence. Suppress known empty merged-export noise; retain rejected bytes. Complexity/reversible-password/anonymous-lookup gaps and blank NTP expectations remain unevaluated.
- Defender/ASR separates findings from coverage, preserves NotConfigured and validates attribution without enforcement/writer inference.
- Query cluster metadata once; improve responsive summaries, themes and links. Retain partial-node/copy-back errors and fatal stage context; contain Drift Control/GPO failures.
- Connectivity schema 1.2 adds redirect disposition/reason/origin/target and diagnostic TCP/DNS evidence. Advisory redirects warn; raw failures remain. DNS diagnostics never replace Layer-7 health. IP text prefers IPv4, with IPv6 fallback.
- Manual tests honor inventory ports/Arc Gateway, reuse results and skip unmatched hosts. Refresh bundled endpoints.
- Downloads validate transfers and share one retry deadline. WebException transport recovery preserves trust/access/protocol exclusions. Unavailable speed does not abort reports.

## v0.6.9

- OSConfig schema 1.3 reports component evidence; partial healthy evidence is SKIPPED.
- Layer 7 retries transient connection failures once.
- Test-ArcMachinePrivateLinkScopeEnabled validates full Arc machine IDs and queries the encoded subscription instead of relying on the active Az context.
- Reconciles Get-AzStackHciVMCheckpointHealth through upstream v0.2.33: bounded historic jobs with explicit incomplete coverage, evidence-incomplete report totals, corrected VmEvents example, VM-associated ImageStore AVHDX classification, aggregate attached-chain size, and all v0.2.32 identity/event/artifact/confidence improvements.
- Initializes StrictMode cleanup and fallback state before exception-prone proxy parsing, range-probe, TLS-request, diagnostic-upload, preference-restoration, and cluster page-file paths. Normal single-proxy connectivity tests now reach download testing and final HTML/CSV report-location output.
- Separates canonical reports and restore backups into typed Reports and Backups folders. Report producers warn about recognized artifacts older than 180 days without deleting them. Remove-AzStackHciDiagnosticArtifact provides explicit WhatIf/ShouldProcess cleanup; backups require explicit selection, valid checksums, 730-day age by default, and retention of at least five newest valid files. Restore prefers typed backup folders and falls back to the legacy root. ACLs are unchanged.
- Page-file backups now use a versioned SHA-256 payload; restore validates path, filename, schema, target, and sizes before mutation. Unsigned legacy backups require -AllowLegacyUnsignedBackup, and page-file restore reports rollback outcome.
- Page-file, memory-dump, and user-mode crash-dump cluster restores now return one result per target node with AttemptedNodeCount, ReturnedNodeCount, and Complete telemetry; failed apply operations include rollback telemetry.
- Connectivity fan-out, checkpoint diagnostic and ownership fan-outs, and OS-config Drift Control collection now use a shared 30-minute deadline, stop timed-out jobs, preserve completed evidence, and report incomplete outcomes explicitly.
- Introduces Get-AzStackHciVMCheckpointHealth, a read-only checkpoint, differencing-disk, Hyper-V Replica, storage, event, and VSS health assessment with TXT, CSV, HTML, telemetry, debug-log, and ZIP artifacts.
- The command indexes events by VM identity, identifies the audited VM in event CSV rows, guarantees event CSV artifacts for early exits, classifies cluster-role/Hyper-V inventory mismatches explicitly, and distinguishes VHD topology completeness from file-metadata completeness.
- CSVs reporting IncompatibleFileSystemFilter receive conditional read-only validation guidance for CSV state, cross-node minifilters, and recent Failover Clustering events. FileSystemReFs alone remains expected, and the report does not instruct operators to unload a filter.
- Base disks use Disk age while Checkpoint age is reserved for attached AVHDX layers; per-VM TXT tables show VM-attributed events and summarize node-wide context separately; CSVs include CollectedAsConcern plus typed classification/disposition. Replica advisories remain explicit in OK prose, sustained fleet-only 15268 context is linked inside storage health, and housekeeping distinguishes unreferenced VM-folder disks from owner/folder mismatches without filename-based ownership inference. This command is supported and tested only with Windows PowerShell 5.1; invoking it from PowerShell 7 fails with an actionable runtime message.
- Test-AzureLocalConnectivity now warns when -ForceGitHubEndpointsUpdate is used WITHOUT -NoAutoUpdate (the GitHub endpoint refresh is already attempted by default, so the switch is a no-op on its own) — mirrors the existing -InstallMissingModuleOnNodes guidance.
- Get-AzStackHciOsConfigSettings pending-reboot detection regex tightened to require both "reboot" and "pending" so it can never accidentally match the "No pending reboot" line.
- Cluster -PassThru JSONReportPath is now derived with [IO.Path]::ChangeExtension, so it always carries a .json extension and can never accidentally equal ReportPath.
- Output handling is hardened so -NoOutput state does not affect later calls, machine-level verbose/debug preferences do not leak into module output, and normal progress remains visible. Test-ArcMachinePrivateLinkScopeEnabled now also confirms when the Arc machine uses the expected public endpoints with no Private Link Scope assigned.
- Get-AzStackHciOsConfigSettings aligns HTML and -PassThru health outcomes: detected domain GPOs and Arc Agent version drift are warnings, complete local-only GPO evidence passes, and unavailable or N/A GPO evidence is shown as Unknown and skipped rather than reported as healthy.
- Pending reboot warnings now propagate through each affected node's HTML section, Events & Reboots sub-tab, and node tab. JSON and -PassThru expose typed trigger reasons under PendingRebootHealth.Details[] and every Nodes[].PendingReboot entry; the additive OS-config health-summary schema advances from 1.1 to 1.2.
- OSConfig CSV evidence is array-normalized for Windows PowerShell 5.1 single-row correctness. Power Plan consistency now measures agreement only; NTP-source and installed-program differences are warnings. Missing Drift Control is emitted as SKIPPED with node details, and StabilityEvents adds a uniform Details alias while preserving Events. Schema remains 1.2 before release.
- Connectivity HTML summaries now classify findings and distinguish configuration gaps from connectivity failures. OSConfig summaries wrap on mobile. Contracts are unchanged.

## v0.6.8

Focus: make the -PassThru object contracts robust for consumption by other modules (e.g. AzStack.Insights). SchemaVersion bumps 1.0 -> 1.1 (additive only — new fields, nothing removed or renamed).

### Get-AzStackHciOsConfigSettings — predictable -ExportPath + first-class output location + opt-in inventory
- -ExportPath is the destination root, created if missing. Node and Cluster runs create <ExportPath>\<ClusterOrNodeName>-<yyyyMMdd-HHmmss>\ instead of rewriting the caller's leaf as a sibling folder.
- New default root = C:\ProgramData\AzStackHci.DiagnosticSettings (always writable on a locked-down Azure Local node, unlike C:\Temp). The automatic mirror of the HTML + JSON reports to ProgramData is retained.
- New -PassThru properties: OutputDirectory (the resolved run folder) and DataCollectionDirectory (<OutputDirectory>\Data-Collection, or null when no on-disk data was written), alongside HTMLReportPath / JSONReportPath. All four are null in -HealthSummaryOnly mode.
- New -IncludeInventoryData switch (default OFF): nests per-node InstalledPrograms / WindowsFeatures / Hotfixes / DriverVersions under each Nodes[] entry so consumers get typed data without parsing CSVs. Default OFF keeps casual -PassThru calls lightweight.
- Deep PSCustomObject normalization makes live results behave like JSON round-trips. Inventory strings and placeholder values are normalized; key order and on-disk JSON are preserved.

### Test-AzureLocalConnectivity — -PassThru reshaped into a structured object
- -PassThru returns a PSCustomObject with run-level properties and per-URL .Results, matching JSON and replacing ArrayList NoteProperties. Filtering .Results preserves run-level fields.
- SchemaVersion ("1.1") added to the connectivity object + JSON summary (parity with OsConfig).
- Cluster -PassThru unified: -Scope Cluster -PassThru returns the same structured shape, nesting each node's structured object (flat run-level fields + Detections + .Results) under .Nodes[]. The internal HTML/CSV cluster report is unchanged.
- BREAKING for anything that read the old container NoteProperties or iterated the return as rows. The module's own tests + Helpers\Compare-*Performance.ps1 / automated-test-all-azure-regions.ps1 were updated to read run-level data from $r.<field> and rows from $r.Results.

## v0.6.7 (recap)

Connectivity gained HEAD/GET selection, process-isolated parallel tests, cluster fan-out, and per-row MachineName. OSConfig gained the versioned health-summary contract and -HealthSummaryOnly. See CHANGELOG.md for details.

For full version history (including v0.6.7 detail, v0.6.6 and earlier) see CHANGELOG.md shipped with this module.

FileList

Version History

Version Downloads Last updated
0.7.0 (current version) 11 9/25/2026
0.6.9 104 8/28/2026
0.6.8 217 7/15/2026
0.6.7 58 7/7/2026
0.6.6 754 4/28/2026
0.6.5 61 4/20/2026
0.6.4 29 4/17/2026
0.6.2 161 3/18/2026
0.6.1 296 12/4/2025
0.6.0 207 9/17/2025
0.5.9 34 9/10/2025
Show more