Private/Get-IslFilterProperty.ps1
|
function Get-IslFilterProperty { <# .SYNOPSIS The device properties a Windows assignment filter rule can use, with their operators and values. .DESCRIPTION One entry per property of the device entity on the "Windows 10 and later" platform, as the filter reference documents them and as the service's validateFilter accepted or refused them in the lab (Validation\Findings.md, "Assignment filter rules"): the operators each property allows, the kind of value it takes (a string, one of an enumerated set, a version) and, for an enumerated property, the values a Windows device can report. A rule the service refuses is what ConvertFrom-IslFilterRule refuses; a value outside the enumerated set is accepted by the service and never matches, which is what the parser warns about. isTpmAttested is not in the reference but the service accepts it and its evaluator returns it, so it is listed as undocumented. Managed-app properties (app.*) are refused on a device filter and are not listed; isRooted and deviceManagementType are refused on the Windows platform and are not listed either. .EXAMPLE (Get-IslFilterProperty)['cpuarchitecture'].Values amd64, x86, arm64, unknown: the values a Windows device reports (an x64 device is amd64). .EXAMPLE (Get-IslFilterProperty)['operatingsystemversion'].Operators eq, ne, gt, ge, lt, le: the only property with ordering operators, and no string operators. #> [CmdletBinding()] [OutputType([hashtable])] param() $stringOperators = @('eq', 'ne', 'in', 'notIn', 'startsWith', 'contains', 'notContains') $enumOperators = @('eq', 'ne', 'in', 'notIn') # The SKU names the reference lists for operatingSystemSKU; the number in the comment is the # Win32_OperatingSystem.OperatingSystemSKU each name stands for (Get-IslFilterDeviceFact maps it) $skuNames = @( 'BusinessN', 'CloudEdition', 'CloudEditionN', 'Core', 'CoreCountrySpecific', 'CoreN' 'CoreSingleLanguage', 'Education', 'EducationN', 'Enterprise', 'EnterpriseEval', 'EnterpriseG' 'EnterpriseGN', 'EnterpriseN', 'EnterpriseNEval', 'EnterpriseS', 'EnterpriseSEval', 'EnterpriseSN' 'Holographic', 'IoTUAP', 'IoTUAPCommercial', 'IoTEnterprise', 'PPIPro', 'Professional' 'ProfessionalEducation', 'ProfessionalEducationN', 'ProfessionalWorkstation', 'ProfessionalN' 'ProfessionalSingleLanguage', 'ServerRdsh' ) $entries = @( @{ Name = 'deviceName'; Kind = 'String'; Operators = $stringOperators } @{ Name = 'manufacturer'; Kind = 'String'; Operators = $stringOperators } @{ Name = 'model'; Kind = 'String'; Operators = $stringOperators } @{ Name = 'deviceCategory'; Kind = 'String'; Operators = $stringOperators } @{ Name = 'enrollmentProfileName'; Kind = 'String'; Operators = $stringOperators } @{ Name = 'osVersion'; Kind = 'String'; Operators = $stringOperators; Deprecated = $true } @{ Name = 'operatingSystemSKU'; Kind = 'String'; Operators = $stringOperators; Values = $skuNames } @{ Name = 'operatingSystemVersion'; Kind = 'Version'; Operators = @('eq', 'ne', 'gt', 'ge', 'lt', 'le') } @{ Name = 'cpuArchitecture'; Kind = 'Enum'; Operators = $enumOperators Values = @('amd64', 'x86', 'arm64', 'unknown') } @{ Name = 'deviceTrustType'; Kind = 'Enum'; Operators = $enumOperators Values = @('Azure AD joined', 'Azure AD registered', 'Hybrid Azure AD joined', 'Unknown') } @{ Name = 'deviceOwnership'; Kind = 'Enum'; Operators = @('eq', 'ne') Values = @('Personal', 'Corporate', 'Unknown') } @{ Name = 'isTpmAttested'; Kind = 'Enum'; Operators = @('eq', 'ne'); Values = @('True', 'False') Documented = $false } ) $table = @{} foreach ($entry in $entries) { if (-not $entry.ContainsKey('Documented')) { $entry.Documented = $true } if (-not $entry.ContainsKey('Deprecated')) { $entry.Deprecated = $false } $table[$entry.Name.ToLowerInvariant()] = $entry } $table } |