> For the complete documentation index, see [llms.txt](https://docs.realmjoin.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.realmjoin.com/ja/zi-dong-hua/runbooks/runbook-references/org/devices/outphase-devices.md).

# 廃止デバイス

### 説明

この runbook は、デバイス ID またはシリアル番号のカンマ区切りリストに基づいて、複数のデバイスを段階的に廃止します。必要に応じて、Intune でデバイスをワイプし、対応する Entra ID デバイス オブジェクトを削除または無効化できます。オプションとして、各デバイスを Microsoft Defender for Endpoint でタグ付けし、修復対象外であることを示すことができます。注: 除外タグはデバイスに適用されますが、Defender ポータルの "Tags" フィルターに表示されるのは、ポータル経由で一度作成された後だけです (Device > Manage tags > "Create new tag")。

### Microsoft Defender for Endpoint の除外タグ

Microsoft Defender for Endpoint にはネイティブの **除外状態** (Device Inventory フィルターでは *Excluded* / *Not Excluded*と表示されます)。この状態は Defender ポータルからのみ設定でき、 **API はありません** デバイスのネイティブな除外状態をプログラムで設定することはできません。

ネイティブな除外状態は自動化できないため、この runbook では代わりにカスタムのデバイス タグ (既定値 `ExcludeFromRemediation`) を適用します。 *Exclude devices from Defender for Endpoint* が有効な場合、リスト内の各デバイスは Entra ID のデバイス ID で検索され、 `POST /api/machines/{id}/tags`を通じてタグ付けされ、除外されたデバイスをフィルターして対象にできるマーカーが提供されます。

#### 一度だけのセットアップ: タグをフィルター可能にする

ポータルの **Tags** フィルターには、ポータル経由で作成されたタグのみが表示されます。API だけで設定したタグはデバイスに付加され、デバイス ページには表示されますが、 **表示されません** Tags フィルターには自動では表示されません。

除外タグを表示して [Defender Device Inventory](https://security.microsoft.com/machines)でフィルターに使用できるようにするには、1 台のクライアントをポータル経由で一度手動でタグ付けする必要があります (デバイスを選択 > **Manage tags** > "Create new tag"、同じタグ値を正確に使用)。この一度だけの手順の後、タグは既知のフィルター可能なタグとなり、この runbook はそれを大規模にデバイスへ適用できるようになります。

> **注:** このタグは単なるラベルであり、デバイスのネイティブな Exclusion state を設定するものではなく、それ自体に修復効果はありません。効果を持つのは、Defender のデバイス グループまたは自動化ルールがこのタグ値に一致するよう明示的に構成されている場合のみです。このようなルールはポータル **Tags** フィルターとは独立してタグ値そのものに一致するため、1 回の手動手順はポータル UI でそのタグをフィルタリング用に選択できるかどうかにのみ影響します。

シリアル番号で指定されたデバイスで、Intune で見つからないものは Entra ID のデバイス ID を持たないため、Defender ではタグ付けされません。

参照 [デバイス タグの作成と管理](https://learn.microsoft.com/defender-endpoint/machine-tags#create-tags) を参照してください。

### 場所

Organization → Devices → Outphase Devices

**Runbook の完全名**

rjgit-org\_devices\_outphase-devices

### 詳細

| プロパティ    | 値                                  |
| -------- | ---------------------------------- |
| バージョン    | 1.2.1                              |
| 必要なモジュール | RealmJoin.RunbookHelper (>= 0.8.9) |
| スケジュール可能 | いいえ                                |

### アクセス許可

#### アプリケーションのアクセス許可

* **種類**：Microsoft Graph
  * DeviceManagementManagedDevices.PrivilegedOperations.All
    * *ワイプ アクションが選択されたときに managedDevices/{id}/wipe を介してデバイスのワイプをトリガーします*
  * DeviceManagementManagedDevices.ReadWrite.All
    * *シリアル番号または azureADDeviceId で Intune デバイスを検索し、削除します*
  * DeviceManagementServiceConfig.ReadWrite.All
    * *デバイスの Autopilot レコードを検索して削除します*
  * Device.Read.All
    * *レポート用に Entra デバイス オブジェクトとその登録済み所有者を検索します*
* **種類**: WindowsDefenderATP
  * Machine.Read.All
    * *aadDeviceId でフィルターされた /machines 経由で Microsoft Defender for Endpoint 内のデバイスを検索します*
  * Machine.ReadWrite.All
    * *excludeFromDefender が有効な場合、/machines/{id}/tags 経由で除外タグを追加します*

#### RBAC ロール

* Cloud Device Administrator
  * */devices/{id} 経由で Entra デバイス オブジェクトを無効化および削除するために必要です*

### パラメーター

#### DeviceListChoice

リストにデバイス ID が含まれるか、シリアル番号が含まれるかを決定します。

| プロパティ   | 値         |
| ------- | --------- |
| 必須      | はい        |
| 既定値     | 0         |
| 種類      | Int32     |
| ポータル表示名 | リストの種類を選択 |

**ポータルのオプション**

| ポータルオプション          | 値 |
| ------------------ | - |
| デバイス ID のカンマ区切りリスト | 0 |
| シリアル番号のカンマ区切りリスト   | 1 |

#### DeviceList

デバイス ID またはシリアル番号のカンマ区切りリスト。

| プロパティ   | 値         |
| ------- | --------- |
| 必須      | はい        |
| 既定値     |           |
| 種類      | 文字列       |
| ポータル表示名 | カンマ区切りリスト |

#### intuneAction

デバイスをワイプするか、Intune から削除するか、Intune の操作をスキップするかを決定します。

| プロパティ   | 値               |
| ------- | --------------- |
| 必須      | いいえ             |
| 既定値     | 2               |
| 種類      | Int32           |
| ポータル表示名 | このデバイスをワイプしますか? |

**ポータルのオプション**

| ポータルオプション                            | 値 |
| ------------------------------------ | - |
| デバイスを完全にワイプする (ユーザー データや登録データは保持しない) | 2 |
| Intune からデバイスを削除                     | 1 |
| デバイスをワイプせず、Intune からも削除しない           | 0 |

#### aadAction

Entra ID デバイスを削除するか、無効化するか、Entra ID の操作をスキップするかを決定します。

| プロパティ   | 値                       |
| ------- | ----------------------- |
| 必須      | いいえ                     |
| 既定値     | 2                       |
| 種類      | Int32                   |
| ポータル表示名 | Entra ID からデバイスを削除しますか? |

**ポータルのオプション**

| ポータルオプション                 | 値 |
| ------------------------- | - |
| Entra ID でデバイスを削除         | 2 |
| Entra ID でデバイスを無効化        | 1 |
| Entra ID デバイスを削除または無効化しない | 0 |

#### wipeDevice

intuneAction から派生した内部フラグ。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      | はい                       |
| 種類       | ブール値                     |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### removeIntuneDevice

intuneAction から派生した内部フラグ。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      | False                    |
| 種類       | ブール値                     |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### removeAutopilotDevice

"Remove the device from Autopilot" (最終値: true) または "Keep device in Autopilot" (最終値: false) により、Autopilot データベースからデバイスを削除するかどうかを制御します。

| プロパティ   | 値                         |
| ------- | ------------------------- |
| 必須      | いいえ                       |
| 既定値     | はい                        |
| 種類      | ブール値                      |
| ポータル表示名 | Autopilot データベースからデバイスを削除 |

**ポータルのオプション**

| ポータルオプション           | 値   |
| ------------------- | --- |
| Autopilot からデバイスを削除 | はい  |
| デバイスを保持             | いいえ |

#### removeAADDevice

aadAction から派生した内部フラグ。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      | はい                       |
| 種類       | ブール値                     |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### disableAADDevice

aadAction から派生した内部フラグ。

| プロパティ    | 値                        |
| -------- | ------------------------ |
| 必須       | いいえ                      |
| 既定値      | False                    |
| 種類       | ブール値                     |
| ポータルで非表示 | はい（Runbook のカスタマイズで事前設定） |

#### excludeFromDefender

true に設定すると、各デバイスは指定された除外タグで Microsoft Defender for Endpoint にタグ付けされます。false に設定すると、Defender の手順は完全にスキップされます。

| プロパティ   | 値                                              |
| ------- | ---------------------------------------------- |
| 必須      | いいえ                                            |
| 既定値     | False                                          |
| 種類      | ブール値                                           |
| ポータル表示名 | Microsoft Defender for Endpoint からデバイスを除外しますか? |

**ポータルのオプション**

| ポータルオプション                               | 値   |
| --------------------------------------- | --- |
| Defender for Endpoint でデバイスを除外済みとしてタグ付け | はい  |
| Defender の操作をスキップ                       | いいえ |

#### defenderExclusionTag

Microsoft Defender for Endpoint でデバイスに追加され、除外済みであることを示すタグです。既定値は "ExcludeFromRemediation" です。

| プロパティ   | 値                      |
| ------- | ---------------------- |
| 必須      | いいえ                    |
| 既定値     | ExcludeFromRemediation |
| 種類      | 文字列                    |
| ポータル表示名 | Defender 除外タグ          |

[Runbook Reference の概要に戻る](/ja/zi-dong-hua/runbooks/runbook-references.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.realmjoin.com/ja/zi-dong-hua/runbooks/runbook-references/org/devices/outphase-devices.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
