Microsoft Intune自定义合规策略报错65007(脚本返回失败)求助
Intune自定义合规策略错误65007(脚本执行失败)排查思路
我们在为Microsoft Intune环境创建自定义合规策略时,反复遇到错误65007(Script returned failure)。该脚本在客户端本地运行完全正常,但通过Intune执行时就会触发这个错误,求排查方向。
涉及的PowerShell脚本
# 设置允许的更新最大过期天数 $DayOffset = -8 $AvailableUpdates = @() $objUpdateSession = New-Object -ComObject Microsoft.Update.Session $objUpdateSearcher = $objUpdateSession.CreateupdateSearcher() $arrAvailableUpdates = @($objUpdateSearcher.Search("IsAssigned=1 and IsHidden=0 and IsInstalled=0").Updates) $arrAvailableUpdates | ForEach-Object { $CategoryID = $_.Categories | Select CategoryID -ExpandProperty CategoryID # 各类更新对应的CategoryID # Application 5c9376ab-8ce6-464a-b136-22113dd69801 # Connectors 434de588-ed14-48f5-8eed-a15e09a991f6 # CriticalUpdates e6cf1350-c01b-414d-a61f-263d14d133b4 # DefinitionUpdates e0789628-ce08-4437-be74-2495b842f43b # DeveloperKits e140075d-8433-45c3-ad87-e72345b36078 # FeaturePacks b54e7d24-7add-428f-8b75-90a396fa584f # Guidance 9511d615-35b2-47bb-927f-f73d8e9260bb # SecurityUpdates 0fa1201d-4330-4fa8-8ae9-b877473b6441 # ServicePacks 68c5b0a3-d1a6-4553-ae49-01d3a7827828 # Tools b4832bd8-e735-4761-8daf-37f882276dab # UpdateRollups 28bc880e-0592-4cbf-8f95-c79b17911d5f # Updates cd5ffd1e-e932-4e3a-bf74-18bf0b1bbd83 If(($CategoryID -eq 'e6cf1350-c01b-414d-a61f-263d14d133b4' -or $CategoryID -eq '0fa1201d-4330-4fa8-8ae9-b877473b6441' -or $CategoryID -eq '28bc880e-0592-4cbf-8f95-c79b17911d5f') -and $_.LastDeploymentChangeTime -le ([datetime]::NOW).AddDays($DayOffset)) { $AvailableUpdates += $_ } } If($AvailableUpdates.Count -gt 0) { $strUpdateStatus = @{"Update status" = "Not up-to-date"} } Else { $strUpdateStatus = @{"Update status" = "Up-to-date"} } return $strUpdateStatus | ConvertTo-Json -Compress
对应的JSON规则文件
{ "Rules":[ { "SettingName":"Update status", "Operator":"IsEquals", "DataType":"String", "Operand":"Up-to-date", "MoreInfoUrl":"https://testurl.com", "RemediationStrings":[ { "Language":"en_US", "Title":"Device must be running the latest cumulative update for Windows.", "Description": "Please make sure that the latest cumulative update for Windows is installed." } ] } ] }
排查思路
- 权限差异问题:Intune以
NT AUTHORITY\SYSTEM身份执行脚本,和本地用户权限不同。用psexec工具在本地模拟SYSTEM身份运行脚本,验证是否有权限访问Windows Update COM对象或执行相关操作。 - 执行超时问题:Intune合规脚本有默认执行时长限制,若更新搜索耗时过长会触发失败。在脚本中添加日志记录每步耗时,或优化搜索条件减少结果量。
- COM对象初始化失败:系统上下文下创建
Microsoft.Update.Session可能失败,检查目标设备的wuauserv服务是否运行,或重建Windows Update组件。 - 输出格式问题:Intune要求脚本仅返回严格JSON格式,不能有额外警告、错误输出。在脚本开头添加
$ErrorActionPreference = 'Stop',或重定向所有输出确保只有目标JSON返回。 - 日期/时区问题:
[datetime]::NOW使用本地时间,系统上下文的时区可能与本地用户不一致;检查LastDeploymentChangeTime的格式解析是否正常,避免条件判断出错。 - 脚本编码问题:确保脚本保存为UTF-8无BOM格式,错误编码会导致Intune解析失败。
- 空结果处理问题:若
$objUpdateSearcher.Search()返回空,需处理$arrAvailableUpdates可能的null情况,避免后续ForEach-Object执行出错。
内容的提问来源于stack exchange,提问作者zyntrax
相关产品推荐
相关产品推荐

