Harness module path under PowerShell 7, and rule fixes backed by validation round 10 - #4
Merged
Merged
Conversation
…7's modules A user-context run started from pwsh inherited the session's PSModulePath, so the Windows PowerShell child took Microsoft.PowerShell.Management, Utility and Security from PowerShell 7's folders: no Cert: drive, and Get-AuthenticodeSignature and ConvertTo-SecureString failed to load. The child now gets the session's path without the three folders PowerShell 7 adds for itself, the reset pwsh applies when it starts powershell.exe as a command. Runs started from Windows PowerShell and the scheduled-task runs are unchanged.
… that hid the finding Round 10 on the joined lab device (Validation/Findings.md): a cmdlet, parameter or value only PowerShell 7 has, and ForEach-Object -Parallel, fail where they stand and the detection runs on to its own exit 0; #Requires -Version 7 exits 1 and the remediation runs; Get-Credential handed a built credential returns it without a prompt; SYSTEM sees local volumes and not the drive the signed-in user mapped. IslPowerShell7Syntax cited the parse error's evidence for all of these; each finding now says what happens and cites its own experiment. Out-File -Encoding utf8NoBOM was in the rule's table and never matched; it is a finding. IslInteractiveCall keeps Get-Credential an error where it is sure to prompt and warns when -Credential is handed anything but a literal. IslContextIssue's drive-letter finding is Information and says which case fails. Repair-IntuneScript turned 'return 1; exit 1' into '1; exit 0; exit 1' and left no finding. A script-scope return with an exit other than 0 after it in the same block now carries no edit.
…rks, Repair's fixes by name PSScriptAnalyzer 1.25.0 filters -Severity on a custom rule's registered severity, Warning for every one, so -Severity Error returns none of the wrapper's records; the README and the help say so and an integration test pins it. The wrapper skips nested script blocks and its cache serves the other rules at the root. The about topic names Repair's three fixes. Changelog for the unreleased changes; a backtick continuation left in Get-IslSetting is gone.
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes a runtime-harness defect that made scripts fail locally that run fine under Intune, corrects four rule behaviours, and backs each rule change with a new validation round on a lab device (round 10 in
Validation/Findings.md).No command changes shape.
ModuleVersionis not bumped; the changes are under Unreleased in the changelog.Runtime harness
A user-context run started from PowerShell 7 launched the Windows PowerShell 5.1 host with PowerShell 7's
PSModulePath. The 5.1 host then loadedMicrosoft.PowerShell.Management,UtilityandSecurityfrom PowerShell 7's folders: noCert:drive, andGet-AuthenticodeSignatureandConvertTo-SecureStringfailed to load.The child now gets the session's path without the three folders PowerShell 7 adds for itself (
$PSHOME\Modules,Program Files\PowerShell\Modules,Documents\PowerShell\Modules). This is the same reset PowerShell 7 applies when it startspowershell.exeas a command; it does not apply it to a process started throughSystem.Diagnostics.Process, which is how the harness starts one. A folder the session added still reaches the child.Runs started from Windows PowerShell, and the scheduled-task runs (
-Context System,-Credential), are unchanged.Rules and
Repair-IntuneScriptRepair-IntuneScriptreturn 1; exit 1became1; exit 0; exit 1: same behaviour, the exit the author wrote unreachable, and no finding left.returnwith an exit other than 0 after it in the same block carries no edit and stays reported. Other returns are fixed as before.IslPowerShell7Syntax, 7-only cmdlets, parameters and-ParallelIslPowerShell7Syntax,#Requires -Version 7IslPowerShell7Syntax,Out-File -Encoding utf8NoBOMRename-Itementry was also inert.IslInteractiveCall,Get-CredentialGet-Credential -Credential $built, which does not prompt.-Message,-UserNameor-Title, or handed a literal name). Warning when-Credentialis handed anything else.IslContextIssue, drive lettersD:\toZ:\in a SYSTEM script was a Warning, "not mapped for SYSTEM".Validation round 10
Seven SYSTEM remediations on the Entra joined lab device (Windows PowerShell 5.1.26100.9444), read from the agent's own result records, the probe files and Graph
deviceRunStates.Test-Json)CommandNotFoundException, the next line ran, exit 0, "without issues", no remediationConvertFrom-Json -AsHashtable)NamedParameterNotFound, then the sameForEach-Object -Parallel)AmbiguousParameterSet, then the sameOut-File -Encoding utf8NoBOM)ParameterArgumentValidationError, no file written, then the same#Requires -Version 7.0)ScriptRequiresUnmatchedPSVersion), the remediation ran, status Recurred, Graphfail/remediationFailedGet-Credential -Credentialhanded aPSCredentialreturned it in 12 ms, no promptC:andD:and found noX:, while the signed-in user hadX:mapped to a share before and after the runValidation/New-IslDriveFixture.ps1creates and removes the drive state REM-DRIVES-SYS reports on, so the experiment can be repeated.One value is recorded and not explained: the REM-PS7-REQUIRES result record carries
RemediationExitCode1, although that remediation ends inexit 0and wrote its probe record.Documentation
Invoke-ScriptAnalyzer -Severityfilters the custom rules on their registered severity, which PSScriptAnalyzer 1.25.0 sets to Warning for every custom rule.-Severity Errortherefore returns none of the wrapper's records and-Severity Warningreturns all of them. The README and theGet-IntuneAnalyzerRulePathhelp now say so and point toWhere-Object Severity -eq Error. An integration test pins the behaviour, so a PSScriptAnalyzer release that changes it fails the test.Repair-IntuneScript's fixes. They are a script-scope return, the encoding and a padded requirement value.Validation/Findings.mdrecords thequery usercolumn layout seen on the lab device and states that a user name longer than the column is still unmeasured.Get-IslSettingis removed.Not changed
Get-IslLogonSessionparsesquery user. Fed a hand-made line with a 21-character name, it reads the name and the session name as one field, so the account would not match and the launcher would fall back to the stored-password task. No account with a name that long was available on the lab device, so the real output is unknown and the parser is left as it is.Validation/Invoke-ValidationRound.ps1 -Action Collectfailed on the lab device's accumulated probe records (about 11 MB;ConvertFrom-Jsonstopped at record 5,637). The round's seven experiments were read directly instead. The driver is not fixed here.Verification
docs/Rules.mdregenerated.Build/Publish-Module.ps1 -WhatIfstages and verifies the package.Cert:drive; after, the 3.x modules and a workingCert:drive. The new integration test asserts the same.ISL-*objects.