You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell实现Microsoft Company Portal应用静默安装方案问询

问题描述

我编写了一段PowerShell脚本,用于调用Microsoft Company Portal中的应用并自动完成安装。但该脚本运行时会启动Company Portal窗口,可能干扰终端用户的工作流程。我尝试添加参数列表以实现后台运行,但仍会弹出Company Portal窗口,请问有可行的解决办法吗?

当前使用的脚本如下:

$OutputFile = "$env:WINDIR\TEMP\PythoncpInstall.log"
$Process = "companyportal:ApplicationId=e60a5520-dc39-4156-9223-825264cd5145"
$ProcessArgs = " /s -Wait -NoNewWindow"

##########ERROR LOGGING#####
Function Set-WriteToLog ($Write1)
{
    Write-Host "$(Get-Date -format yyyy-MM-dd-hh-mm-ss)`t-`t$Write1"
}
#########START OF SCRIPT BODY#############
Start-Transcript -Path $OutputFile
start-process $Process -ArgumentList $ProcessArgs
sleep 10
[void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms')
[System.Windows.Forms.SendKeys]::SendWait("^{i}")

Stop-Transcript
解决方案

1. 使用MSGraph API静默触发安装(推荐)

companyportal:协议调用本质是唤起前台应用,要彻底避免弹窗,建议改用Microsoft Graph API的deviceAppManagement/mobileApps/{appId}/assign接口,直接向目标设备推送安装指令,全程在后台执行,不会唤起Company Portal窗口。

步骤要点:

  • 确保脚本拥有DeviceManagementApps.ReadWrite.All的Graph API权限
  • 调用API时指定目标设备ID,将安装类型设为required实现强制后台静默安装

示例代码片段:

$tenantId = "你的租户ID"
$clientId = "你的应用注册ID"
$clientSecret = "你的应用密钥"
$appId = "e60a5520-dc39-4156-9223-825264cd5145"
$deviceId = "目标设备的ID"

# 获取Graph访问令牌
$tokenBody = @{
    Grant_Type    = "client_credentials"
    Scope         = "https://graph.microsoft.com/.default"
    Client_Id     = $clientId
    Client_Secret = $clientSecret
}
$tokenResponse = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token" -Method POST -Body $tokenBody

# 推送静默安装指令
$assignUrl = "https://graph.microsoft.com/v1.0/deviceAppManagement/mobileApps/$appId/assign"
$assignBody = @{
    assignments = @(
        @{
            target = @{
                "@odata.type" = "#microsoft.graph.deviceGroupAssignment"
                deviceId = $deviceId
            }
            intent = "required"
            settings = @{
                "@odata.type" = "#microsoft.graph.win32LobAppAssignmentSettings"
                installTimeSettings = @{
                    useLocalTime = $true
                }
            }
        }
    )
} | ConvertTo-Json -Depth 5

Invoke-RestMethod -Uri $assignUrl -Headers @{Authorization = "Bearer $($tokenResponse.access_token)"} -Method POST -Body $assignBody -ContentType "application/json"

2. 尝试隐藏窗口的替代参数(仅当无法使用Graph时)

如果暂时无法使用Graph API,可以尝试通过cmd.exe间接调用协议链接,并设置-WindowStyle Hidden,有可能抑制窗口弹出(但受系统URL协议处理逻辑限制,不一定100%生效):

修改后的脚本片段:

Start-Process -FilePath "cmd.exe" -ArgumentList "/c start """" $Process" -WindowStyle Hidden -Wait

3. 替代方案:直接调用Win32应用安装包

如果目标应用是Win32类型,可直接从Intune控制台导出部署包的安装文件,用传统静默安装命令执行,完全绕过Company Portal:

# 示例:假设安装包为python.exe,静默参数为/qn
Start-Process -FilePath "python.exe" -ArgumentList "/qn" -WindowStyle Hidden -Wait

内容的提问来源于stack exchange,提问作者GrayVi02

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 08:15:35