Private/Get-IslFilterDeviceFact.ps1

function Get-IslFilterDeviceFact {
    <#
    .SYNOPSIS
        Reads this device's values for the properties an assignment filter rule compares.
 
    .DESCRIPTION
        The values the filter evaluator returned for the lab devices, read from the same places on
        the local machine: deviceName from the computer name; manufacturer and model from
        Win32_ComputerSystem; osVersion and operatingSystemVersion as major.minor.build.UBR from the
        CurrentVersion registry key (10.0.26100.9457 on the lab devices); operatingSystemSKU as the
        name the filter reference gives the Win32_OperatingSystem SKU number (129 was
        EnterpriseSEval); cpuArchitecture as amd64, x86 or arm64 (an x64 device is amd64, and a rule
        saying "x64" never matches); deviceTrustType from dsregcmd /status; deviceOwnership
        inferred from the join type (Corporate for a joined device, Personal for a registered one,
        as the lab devices reported). enrollmentProfileName, deviceCategory and isTpmAttested live
        in the tenant, not on the device, and are left null, which a rule can test with -eq $null.
 
        Windows only: it reads CIM, the registry and dsregcmd. Pass -Device to
        Test-IntuneAssignmentFilter on other platforms.
 
    .EXAMPLE
        Get-IslFilterDeviceFact
 
        A hashtable with one entry per filter property.
    #>

    [CmdletBinding()]
    [OutputType([hashtable])]
    param()

    $onWindows = $PSVersionTable.PSVersion.Major -lt 6 -or $IsWindows
    if (-not $onWindows) {
        throw 'The local device facts come from Windows (CIM, the registry, dsregcmd); pass -Device elsewhere'
    }

    $computer = Get-CimInstance -ClassName Win32_ComputerSystem -ErrorAction SilentlyContinue
    $operatingSystem = Get-CimInstance -ClassName Win32_OperatingSystem -ErrorAction SilentlyContinue
    $versionKey = 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
    $version = Get-ItemProperty -Path $versionKey -ErrorAction SilentlyContinue
    $osVersion = if ($version -and $version.CurrentMajorVersionNumber) {
        "$($version.CurrentMajorVersionNumber).$($version.CurrentMinorVersionNumber)." +
        "$($version.CurrentBuildNumber).$($version.UBR)"
    }
    else { [Environment]::OSVersion.Version.ToString() }

    $architecture = switch ("$([System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture)") {
        'Arm64' { 'arm64' }
        'X64' { 'amd64' }
        'X86' { 'x86' }
        default { 'unknown' }
    }

    # The reference's SKU names by Win32_OperatingSystem.OperatingSystemSKU. The reference prints
    # Home as "Core (10/111)" and Professional N as "BusinessN (49)"; the numbers here are what
    # Windows reports, the names what the service compares against.
    $skuNames = @{
        4 = 'Enterprise'; 27 = 'EnterpriseN'; 48 = 'Professional'; 49 = 'BusinessN'; 72 = 'EnterpriseEval'
        84 = 'EnterpriseNEval'; 98 = 'CoreN'; 99 = 'CoreCountrySpecific'; 100 = 'CoreSingleLanguage'
        101 = 'Core'; 119 = 'PPIPro'; 121 = 'Education'; 122 = 'EducationN'; 123 = 'IoTUAP'
        125 = 'EnterpriseS'; 126 = 'EnterpriseSN'; 129 = 'EnterpriseSEval'; 131 = 'IoTUAPCommercial'
        136 = 'Holographic'; 138 = 'ProfessionalSingleLanguage'; 161 = 'ProfessionalWorkstation'
        162 = 'ProfessionalN'; 164 = 'ProfessionalEducation'; 165 = 'ProfessionalEducationN'
        171 = 'EnterpriseG'; 172 = 'EnterpriseGN'; 175 = 'ServerRdsh'; 188 = 'IoTEnterprise'
        202 = 'CloudEditionN'; 203 = 'CloudEdition'
    }
    $skuNumber = if ($operatingSystem) { [int]$operatingSystem.OperatingSystemSKU } else { 0 }
    $sku = if ($skuNames.ContainsKey($skuNumber)) { $skuNames[$skuNumber] } else { "$skuNumber" }

    $status = @(Get-IslDsregStatus)
    $joined = [bool]($status | Where-Object { $_ -match '^\s*AzureAdJoined\s*:\s*YES' })
    $domainJoined = [bool]($status | Where-Object { $_ -match '^\s*DomainJoined\s*:\s*YES' })
    $registered = [bool]($status | Where-Object { $_ -match '^\s*WorkplaceJoined\s*:\s*YES' })
    $trustType = if ($joined -and $domainJoined) { 'Hybrid Azure AD joined' }
    elseif ($joined) { 'Azure AD joined' }
    elseif ($registered) { 'Azure AD registered' }
    else { 'Unknown' }
    $ownership = switch ($trustType) {
        'Azure AD registered' { 'Personal' }
        'Unknown' { 'Unknown' }
        default { 'Corporate' }
    }

    @{
        deviceName             = $env:COMPUTERNAME
        manufacturer           = if ($computer) { "$($computer.Manufacturer)" } else { '' }
        model                  = if ($computer) { "$($computer.Model)" } else { '' }
        osVersion              = $osVersion
        operatingSystemVersion = $osVersion
        operatingSystemSKU     = $sku
        cpuArchitecture        = $architecture
        deviceTrustType        = $trustType
        deviceOwnership        = $ownership
        enrollmentProfileName  = $null
        deviceCategory         = $null
        isTpmAttested          = $null
    }
}