<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[gOxiA=苏繁=SuFan Blog]]></title> 
<link>https://goxia.maytide.net/index.php</link> 
<description><![CDATA[gOxiA,苏繁,sufan,Microsoft MVP]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[gOxiA=苏繁=SuFan Blog]]></copyright>
<item>
<link>https://goxia.maytide.net/read.php/2090.htm</link>
<title><![CDATA[HOWTO: 为Autopilot设备取消分配用户]]></title> 
<author>gOxiA &lt;sufan_cn@msn.com&gt;</author>
<category><![CDATA[Microsoft Cloud]]></category>
<pubDate>Sat, 14 Oct 2023 03:37:56 +0000</pubDate> 
<guid>https://goxia.maytide.net/read.php/2090.htm</guid> 
<description>
<![CDATA[ 
	<p><img alt="logo_intune" src="http://goxia.maytide.net/ftpup/2018/83837cef08fa_F50A/logo_intune_thumb.png"></p><p><strong><font color="#fd3f0d" size="4">HOWTO: 为Autopilot设备取消用户分配</font></strong></p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 在开始前，我们先了解一下为什么会将Autopilot设备分配给用户？！在设备注册到<a href="https://learn.microsoft.com/en-us/autopilot/windows-autopilot/?WT.mc_id=WDIT-MVP-4000544" target="_blank">Autopilot</a>后，默认情况下处于共享设备模式，即有权限的用户可以在 OOBE 阶段输入账号密码来准备设备（即：注册依据）。但如果 IT 管理员 在 Autopilot 设备管理中将其分配给用户，则在 OOBE 阶段的用户登录页面上会预先填充账号名称，我们仅输入密码进行验证即可，并且还会自动应用分配给用户的策略和应用程序，对于用户而言，以及已经在实施 <a href="https://learn.microsoft.com/en-us/autopilot/tutorial/pre-provisioning/azure-ad-join-workflow/?WT.mc_id=WDIT-MVP-4000544" target="_blank">Autopilot for pre-provisioning deployment</a> 的组织，都将获得更好的体验。</p><p><a href="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/oobe-login.png"><img width="625" height="417" title="oobe-login" style="display: inline; background-image: none;" alt="oobe-login" src="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/oobe-login_thumb.png" border="0"></a></p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 要将 Autopilot 设备分配给用户，可以通过 <a href="https://intune.microsoft.com" target="_blank">Intune 管理中心</a>，进入“<strong>设备 - 注册设备 - Windows Autopilot 设备</strong>”，找到需要分配用户的设备，然后点击“<strong>分配用户</strong>”，跟随向导完成即可。注意：仅能将设备分配一个账号。</p><p><a href="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/assignuserfromdevice.png"><img width="634" height="399" title="assignuserfromdevice" style="display: inline; background-image: none;" alt="assignuserfromdevice" src="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/assignuserfromdevice_thumb.png" border="0"></a></p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 如果需要在 Autopilot 注册设备时就标记分配用户信息，可以在 CSV 文件中添加“<a href="https://learn.microsoft.com/en-us/autopilot/add-devices/?WT.mc_id=WDIT-MVP-4000544" target="_blank">Assigned User</a><strong></strong>”列。</p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; OK，从以上步骤中可以看出过程中的 UI 和操作逻辑还是比较清晰易用的。但是……如果我们现在需要取消分配用户呢？！你会发现很难找到这个选项。最后 <a href="http://goxia.maytide.net" target="_blank">gOxiA</a> 没辙只能祭出“<a href="https://developer.microsoft.com/en-us/graph/graph-explorer" target="_blank">Microsoft Graph</a>”。</p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 首先，我们先获取到 Autopilot 设备的 ID，可以使用“<a href="https://learn.microsoft.com/en-us/graph/api/intune-enrollment-windowsautopilotdeviceidentity-list?view=graph-rest-1.0&amp;tabs=http/?WT.mc_id=WDIT-MVP-4000544" target="_blank">windowsAutopilotDeviceIdentities</a>”，所需权限“<strong><em>DeviceManagementServiceConfig.Read.All</em></strong>”。即：“<strong><em>GET </em></strong><strong><em>https://graph.microsoft.com/v1.0/deviceManagement/windowsAutopilotDeviceIdentities</em></strong>”，如果成功将会获得如下的视图和内容，将 ID 信息记录下来。</p><p><a href="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/unassignuserfromdevice-1.png"><img width="634" height="314" title="unassignuserfromdevice-1" style="display: inline; background-image: none;" alt="unassignuserfromdevice-1" src="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/unassignuserfromdevice-1_thumb.png" border="0"></a></p><p><a href="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/windowsAutopilotDeviceIdentities.png"><img width="555" height="417" title="windowsAutopilotDeviceIdentities" style="display: inline; background-image: none;" alt="windowsAutopilotDeviceIdentities" src="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/windowsAutopilotDeviceIdentities_thumb.png" border="0"></a></p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 之后，就可以使用“<a href="https://learn.microsoft.com/en-us/graph/api/intune-enrollment-windowsautopilotdeviceidentity-unassignuserfromdevice?view=graph-rest-1.0&amp;tabs=http/?WT.mc_id=WDIT-MVP-4000544" target="_blank">unassignUserFromDevice</a>”进行取消分配用户的操作，所需权限“<strong><em>DeviceManagementServiceConfig.ReadWrite.All</em></strong>”。即“<strong><em>POST https://graph.microsoft.com/v1.0/deviceManagement/windowsAutopilotDeviceIdentities/&#123;windowsAutopilotDeviceIdentity-id&#125;/microsoft.graph.unassignUserFromDevice</em></strong>”，其中<strong>&#123;&#125;</strong>替换为前面获取到的 ID。如果成功将返回 OK - 200 响应。</p><p><a href="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/unassignuserfromdevice-response.png"><img width="634" height="82" title="unassignuserfromdevice-response" style="display: inline; background-image: none;" alt="unassignuserfromdevice-response" src="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/unassignuserfromdevice-response_thumb.png" border="0"></a></p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 搞定之后久久不能平静，总觉得在 UI 下应该会提供选项才对啊，开个 Case 才了解到原来“取消分配用户”的选项位于 Autopilot 设备列表中每个设备的最右边“<strong>…</strong>”中，OMG！！！</p><p><a href="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/unassignuserfromdevice.png"><img width="634" height="239" title="unassignuserfromdevice" style="display: inline; background-image: none;" alt="unassignuserfromdevice" src="http://goxia.maytide.net/ftpup/2018/HOWTO-Autopilot_7EEE/unassignuserfromdevice_thumb.png" border="0"></a></p>
]]>
</description>
</item>
</channel>
</rss>