PowerShell实现Microsoft Company Portal应用静默安装方案问询
问题描述
我编写了一段PowerShell脚本,用于调用Microsoft Company Portal中的应用并自动完成安装。但该脚本运行时会启动Company Portal窗口,可能干扰终端用户的工作流程。我尝试添加参数列表以实现后台运行,但仍会弹出Company Portal窗口,请问有可行的解决办法吗?
当前使用的脚本如下:
$OutputFile = "$env:WINDIR\TEMP\PythoncpInstall.log" $Process = "companyportal:ApplicationId=e60a5520-dc39-4156-9223-825264cd5145" $ProcessArgs = " /s -Wait -NoNewWindow" ##########ERROR LOGGING##### Function Set-WriteToLog ($Write1) { Write-Host "$(Get-Date -format yyyy-MM-dd-hh-mm-ss)`t-`t$Write1" } #########START OF SCRIPT BODY############# Start-Transcript -Path $OutputFile start-process $Process -ArgumentList $ProcessArgs sleep 10 [void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms') [System.Windows.Forms.SendKeys]::SendWait("^{i}") Stop-Transcript
解决方案
1. 使用MSGraph API静默触发安装(推荐)
companyportal:协议调用本质是唤起前台应用,要彻底避免弹窗,建议改用Microsoft Graph API的deviceAppManagement/mobileApps/{appId}/assign接口,直接向目标设备推送安装指令,全程在后台执行,不会唤起Company Portal窗口。
步骤要点:
- 确保脚本拥有
DeviceManagementApps.ReadWrite.All的Graph API权限 - 调用API时指定目标设备ID,将安装类型设为
required实现强制后台静默安装
示例代码片段:
$tenantId = "你的租户ID" $clientId = "你的应用注册ID" $clientSecret = "你的应用密钥" $appId = "e60a5520-dc39-4156-9223-825264cd5145" $deviceId = "目标设备的ID" # 获取Graph访问令牌 $tokenBody = @{ Grant_Type = "client_credentials" Scope = "https://graph.microsoft.com/.default" Client_Id = $clientId Client_Secret = $clientSecret } $tokenResponse = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token" -Method POST -Body $tokenBody # 推送静默安装指令 $assignUrl = "https://graph.microsoft.com/v1.0/deviceAppManagement/mobileApps/$appId/assign" $assignBody = @{ assignments = @( @{ target = @{ "@odata.type" = "#microsoft.graph.deviceGroupAssignment" deviceId = $deviceId } intent = "required" settings = @{ "@odata.type" = "#microsoft.graph.win32LobAppAssignmentSettings" installTimeSettings = @{ useLocalTime = $true } } } ) } | ConvertTo-Json -Depth 5 Invoke-RestMethod -Uri $assignUrl -Headers @{Authorization = "Bearer $($tokenResponse.access_token)"} -Method POST -Body $assignBody -ContentType "application/json"
2. 尝试隐藏窗口的替代参数(仅当无法使用Graph时)
如果暂时无法使用Graph API,可以尝试通过cmd.exe间接调用协议链接,并设置-WindowStyle Hidden,有可能抑制窗口弹出(但受系统URL协议处理逻辑限制,不一定100%生效):
修改后的脚本片段:
Start-Process -FilePath "cmd.exe" -ArgumentList "/c start """" $Process" -WindowStyle Hidden -Wait
3. 替代方案:直接调用Win32应用安装包
如果目标应用是Win32类型,可直接从Intune控制台导出部署包的安装文件,用传统静默安装命令执行,完全绕过Company Portal:
# 示例:假设安装包为python.exe,静默参数为/qn Start-Process -FilePath "python.exe" -ArgumentList "/qn" -WindowStyle Hidden -Wait
内容的提问来源于stack exchange,提问作者GrayVi02
相关产品推荐
相关产品推荐

