You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Intune部署PowerShell脚本失败:PnP模块加载异常求助

问题分析

你的问题核心是Intune执行脚本的上下文环境与本地运行存在差异,叠加模块兼容性问题导致失败:

  • 错误提示的System.Management.Automation Version=7.2.0.0是PowerShell 7的依赖组件,而Intune默认使用Windows PowerShell 5.1执行脚本,若安装的PnP.PowerShell版本仅兼容PS7,会出现加载失败。
  • 若Intune以**设备上下文(系统账户)**执行脚本,-Scope CurrentUser安装的模块会被放到系统账户的模块目录,而非目标用户的目录,导致用户上下文无法加载模块。
  • Intune执行环境中,Unregister-PSRepository/Register-PSRepository操作可能被系统策略限制,导致PSGallery访问异常、模块安装不完整。
解决方案

1. 强制以用户上下文执行脚本

在Intune添加脚本时必须选择**“在用户上下文运行”**:

  • 进入Intune > 设备 > 脚本 > 添加脚本
  • 在“设置”步骤勾选“在用户上下文运行”选项
  • 这样$ENV:Appdata会指向当前登录用户的目录,-Scope CurrentUser安装的模块也会对应用户的模块路径。

2. 指定兼容PS5.1的模块版本

最新版PnP.PowerShell部分版本对PS5.1兼容性下降,修改脚本中安装模块的命令,指定稳定兼容版本:

# 安装兼容PS5.1的PnP版本
Install-Module -Name PnP.PowerShell -Scope CurrentUser -Force -Confirm:$false -Verbose:$false -RequiredVersion 1.12.0
# 安装兼容PS5.1的Az.Keyvault版本
Install-Module -Name Az.Keyvault -Scope CurrentUser -Force -Confirm:$false -Verbose:$false -RequiredVersion 4.8.0

3. 移除PSRepository注册操作

Intune环境中默认已注册PSGallery,重复注册/注销可能触发策略限制,直接删除以下两行:

Unregister-PSRepository -Name PSGallery
Register-PSRepository -Default

4. 显式指定模块加载路径

在调用Connect-PnPOnline前手动导入模块,避免自动加载失败:

# 导入PnP模块
$pnpModulePath = Join-Path $ENV:USERPROFILE "Documents\WindowsPowerShell\Modules\PnP.PowerShell\1.12.0"
Import-Module $pnpModulePath -Force
# 导入Az.Keyvault模块
$azModulePath = Join-Path $ENV:USERPROFILE "Documents\WindowsPowerShell\Modules\Az.Keyvault\4.8.0"
Import-Module $azModulePath -Force

5. 预打包模块为Win32应用(推荐)

动态安装模块在Intune环境易出问题,建议先部署模块再执行脚本:

  • 在本地PS5.1环境中保存模块:
    Save-Module -Name PnP.PowerShell -Path "C:\Temp\Modules" -RequiredVersion 1.12.0
    Save-Module -Name Az.Keyvault -Path "C:\Temp\Modules" -RequiredVersion 4.8.0
    
  • 将Modules文件夹打包为zip,用Intune Win32 App Tool转换为.intunewin文件
  • 部署该Win32应用,目标路径设为C:\Users\%USERNAME%\Documents\WindowsPowerShell\Modules
  • 执行简化后的脚本(无需再安装模块)
修改后的简化脚本示例
#Script for uploading Teams Corporate Backgrounds 
Start-Transcript -Path "C:\Apps\Teams_Background.log"

# 验证并导入预安装的模块
$pnpModule = Get-Module -Name PnP.PowerShell -ListAvailable | Where-Object {$_.Version -eq "1.12.0"}
if ($null -eq $pnpModule) {
    Write-Host "PnP.PowerShell module not found, exiting"
    Stop-Transcript
    exit 1
}
Import-Module $pnpModule.Path -Force

$azModule = Get-Module -Name Az.Keyvault -ListAvailable | Where-Object {$_.Version -eq "4.8.0"}
if ($null -eq $azModule) {
    Write-Host "Az.Keyvault module not found, exiting"
    Stop-Transcript
    exit 1
}
Import-Module $azModule.Path -Force

# 配置SharePoint与本地路径变量
$tenant = "company.onmicrosoft.com"
$siteURL = "https://company.sharepoint.com/library"
$applicationID = "xxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
$library = "/Shared Documents/Templates & Branding/MS Teams Backgrounds"
$filename1 = "Teams_Background_file.jpg"
$filename2 = "Teams_Background_file_thumb.jpg"
$sourcepath1 = Join-Path $library $filename1
$sourcepath2 = Join-Path $library $filename2
$pathdir = Join-Path $ENV:Appdata "Microsoft\Teams\Backgrounds\Uploads"
    
# 创建Teams背景目录
If (!(Test-Path $pathdir)) {
    New-Item -ItemType Directory -Path $pathdir -Force | Out-Null
}

# Azure Key Vault认证
$VaultName = "SharePointAuthentication"
$certName = "Certname"
$clientID = "xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxx"
$key = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
$SecurePassword = $key | ConvertTo-SecureString -AsPlainText -Force
$cred = New-Object -typename System.Management.Automation.PSCredential -argumentlist $clientID, $SecurePassword
$tenantID = "xxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"

Connect-AzAccount -Credential $cred -TenantId $tenantID -ServicePrincipal
$secret = Get-AzKeyVaultSecret -VaultName $vaultName -Name $certName
$bstr = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($secret.SecretValue)
$secretValueText = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($bstr)

# 连接SharePoint并复制文件
Connect-PnPOnline -Url $siteUrl -ClientId $applicationID -Tenant $tenant -CertificateBase64Encoded $secretValueText
Get-PnPFile $sourcepath1 -Path $pathdir -Filename $filename1 -AsFile -Force
Get-PnPFile $sourcepath2 -Path $pathdir -Filename $filename2 -AsFile -Force

# 断开连接
Disconnect-PnPOnline
Stop-Transcript

内容的提问来源于stack exchange,提问作者Micksta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 00:07:07