assign-offline-profile

作成者: microsoft

ユーザーがユーザーやチームをモバイルオフラインプロファイルにバインドして、デバイスで実際にオフライン同期を受け取れるようにする必要がある場合に使用します。これがないと、プロファイルは…

npx skills add https://github.com/microsoft/power-platform-skills --skill assign-offline-profile

Shared instructions: shared-instructions.md — read first.

References:

Assign Offline Profile

Bind one or more users and/or teams to an existing Mobile Offline Profile. Without this step, the profile exists in Dataverse but is unbound — no one's app actually uses it for offline sync.

Per the maker portal's UX (the "Assign profile to user" dialog under env settings), this is a separate operation from profile creation. Many users hit "I created the profile but offline still doesn't work" — the missing piece is membership.

Workflow

  1. Verify project + locate profile → 2. Pick users/teams → 3. Discover existing memberships → 4. Confirm diff (single gate) → 5. POST memberships → 6. Verify → 7. Summary

Step 1 — Verify project + locate profile

test -f power.config.json
node "${PLUGIN_ROOT}/scripts/resolve-environment.js" "$(node -e \"console.log(require('./power.config.json').environmentId)\")"

Profile ID resolution (in order):

SourceUsed when
$ARGUMENTS contains --profile-id <guid>Explicit override
$ARGUMENTS contains --profile-name <name>Resolve via GET /mobileofflineprofiles?$filter=name eq '<name>'&$select=mobileofflineprofileid
offline-profile.json in cwdRead top-level profileId field
OtherwiseGET /mobileofflineprofiles and present AskUserQuestion with the list (max 4 options)

STOP if no profile can be resolved. Print: Run /setup-offline-profile first, or pass --profile-id.

power.config.json is intentionally NOT consulted here. That file is owned by npx power-apps init. The profile ID lives in offline-profile.json only.

Step 2 — Pick users/teams

$ARGUMENTS parsing:

FlagEffect
--user <upn> (repeatable)Add specific user(s) by UPN (user@domain.com)
--team <name> (repeatable)Add specific team(s) by name
--meAdd the current Dataverse user from WhoAmI / systemusers(<UserId>) — useful for solo dev demos
--all-app-usersAdd every user with System User role in the current env (broad; intended for prod rollout — confirm at gate)
--unassign-user <upn> / --unassign-team <name>Remove an existing membership rather than add

If no flags passed, present AskUserQuestion:

Question: "Who should receive this offline profile?"

Options (max 4):

  • Just me (the current user) — equivalent to --me
  • Pick specific users by UPN — you reply with comma-separated emails in the next message
  • Pick a team — list env's teams and pick one
  • All users with System User role — equivalent to --all-app-users; broad scope, confirm at gate

For pick-users flow: after the choice, print:

"Reply with comma-separated UPNs (e.g. rm1@contoso.com, rm2@contoso.com)"

Then read the next user message and parse.

Step 3 — Discover existing memberships

Telemetry checkpoint: discover_offline_profile_memberships

For idempotency:

# Existing user memberships for this profile
node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> GET \
  "usermobileofflineprofilememberships?\$filter=_mobileofflineprofileid_value eq <profileId>&\$select=usermobileofflineprofilemembershipid,_systemuserid_value&\$expand=systemuserid_systemuser(\$select=domainname)"

# Existing team memberships for this profile
node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> GET \
  "teammobileofflineprofilememberships?\$filter=_mobileofflineprofileid_value eq <profileId>&\$select=teammobileofflineprofilemembershipid,_teamid_value&\$expand=teamid_team(\$select=name)"

Build the set of already-bound UPNs and team names.

For each candidate user/team from Step 2, look up their systemuserid / teamid (skip if already in already-bound):

node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> GET \
  "systemusers?\$filter=domainname eq '<upn>'&\$select=systemuserid,fullname,domainname&\$top=1"

node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> GET \
  "teams?\$filter=name eq '<team-name>' and teamtype eq 0&\$select=teamid,name&\$top=1"

(teamtype eq 0 excludes Access Teams and Owner Teams — only Manage Teams get profile assignments.)

Construct three lists:

  • to_add — resolved IDs to POST
  • to_remove — resolved IDs to DELETE (from --unassign-* flags)
  • not_found — UPNs/team-names that didn't resolve (warn)
  • already_bound — skipped no-ops

Step 4 — Confirm diff (single gate)

Telemetry checkpoint: confirm_offline_profile_assignment_diff

AskUserQuestion:

Question header: Confirm membership changes

Question body:

Profile: <name> (<profileId>)

Will ADD:
  - User: rahul@contoso.com (Rahul Bansal)
  - User: charanma@... (Charan Mahankali)
  - Team: Field Service RMs (12 members)

Will REMOVE:
  (none)

Already bound (skipping):
  - User: admin@... (no-op)

Could not resolve:
  - someone@external.com — not in this env's system users

Proceed?

Options:

  • Proceed
  • Cancel

Step 5 — POST memberships

Telemetry checkpoint: assign_offline_profile_memberships

For each in to_add, POST sequentially (parallel POSTs occasionally return 429):

User membership:

node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> POST \
  "usermobileofflineprofilememberships" \
  --body '{
    "MobileOfflineProfileId@odata.bind": "/mobileofflineprofiles(<profileId>)",
    "SystemUserId@odata.bind": "/systemusers(<systemuserid>)"
  }' \
  --include-headers

Expected 204 with OData-EntityId → capture membership GUID.

Team membership:

node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> POST \
  "teammobileofflineprofilememberships" \
  --body '{
    "MobileOfflineProfileId@odata.bind": "/mobileofflineprofiles(<profileId>)",
    "TeamId@odata.bind": "/teams(<teamid>)"
  }' \
  --include-headers

For each in to_remove, DELETE:

node "${PLUGIN_ROOT}/scripts/dataverse-request.js" <envUrl> DELETE \
  "usermobileofflineprofilememberships(<membershipid>)"

⚠️ Duplicate handling: POSTing a membership that already exists returns 409 Conflict. The dataverse-request.js wrapper's looksLikeDuplicate rescue treats this as silent success (the Step 3 dedup should catch most cases first). Re-runs are safe.

Step 6 — Verify

Telemetry checkpoint: verify_offline_profile_memberships

Re-query memberships from Step 3 and assert the diff applied:

  • Every to_add now appears in the GET response
  • Every to_remove no longer appears

If the verification disagrees, return BLOCKED: membership writes did not commit and print the discrepancy.

Step 7 — Summary

Print:

✓ Membership updates applied.

  Profile      : <name>
  Total members: <N users + M teams>
  Added        : <list>
  Removed      : <list>
  Skipped      : <list> (already bound)

Users will receive the profile on their next mobile app sign-in. Existing
sessions need to sign out + sign in to trigger the profile pull.

Update memory-bank.md ## Offline profile block:

membership:
  users: [rahul@..., charanma@...]
  teams: [Field Service RMs]
  lastAssignedAt: 2026-05-19T...

Status code (final line)

  • DONE — every requested add/remove applied; verify confirmed
  • DONE_WITH_CONCERNS: <list> — some UPNs/teams could not be resolved, or --all-app-users matched 0 users (env may not have the role granted yet)
  • NEEDS_CONTEXT: <missing> — couldn't determine profileId (no offline-profile.json, no --profile flags, no profiles in env)
  • BLOCKED: <reason> — auth failure, profile not found in env, or verification disagreement

Failure recovery

Memberships are individually committed (no transaction). If Step 5 fails mid-loop:

  • Partially-added memberships remain (visible in env)
  • Re-running with the same arguments is idempotent (Step 3 dedup catches what's already bound)
  • Use --unassign-* to undo specific bindings if needed

microsoftのその他のスキル

oss-growth
microsoft
OSS成長ハッカーのペルソナ
agent-framework-azure-ai-py
microsoft
Microsoft Agent Framework Python SDK(agent-framework-azure-ai)を使用してAzure AI Foundryエージェントを構築します。AzureAIAgentsProviderを使用した永続的なエージェントの作成、ホスト型ツール(コードインタープリター、ファイル検索、ウェブ検索)の使用、MCPサーバーの統合、会話スレッドの管理、ストリーミング応答の実装時に使用します。関数ツール、構造化出力、マルチツールエージェントをカバーします。
development
airunway-aks-setup
microsoft
AKS上でAI Runwayをセットアップ — ベアクラスターからモデル実行まで。クラスター検証、コントローラーインストール、GPU評価、プロバイダー設定、初回デプロイをカバー。対象: 「AI Runwayのセットアップ」「AKSクラスターのオンボード」「AI Runwayのインストール」「airunway setup」「AKSへのモデルデプロイ」「AKSでのGPU推論」「AKSでのKAITOセットアップ」「AKSでのLLM実行」「AKSでのvLLM」「AKSでのモデルサービング設定」「AI Runwayコントローラー」。
devops
appinsights-instrumentation
microsoft
Azure Application Insightsを使用したWebアプリのインストルメンテーションに関するガイダンス。テレメトリパターン、SDKセットアップ、構成リファレンスを提供します。対象: アプリのインストルメンテーション方法、App Insights SDK、テレメトリパターン、App Insightsとは何か、Application Insightsガイダンス、インストルメンテーション例、APMベストプラクティス。
devops
applicationinsights-web-ts
microsoft
Application Insights JavaScript SDK(@microsoft/applicationinsights-web)を使用してブラウザ/Webアプリを計測します。Real User Monitoring(RUM)— ページビュー、クリック、AJAX/fetch依存関係、例外、カスタムイベント、およびバックエンドのOpenTelemetryトレースに関連付けられたブラウザ側のGenAIエージェントトレースに使用します。SDKローダースクリプトとnpmセットアップ、フレームワーク拡張機能(React、React Native、Angular)、Click Analytics、テレメトリ初期化子、およびブラウザから生成されるエージェント/ツール/モデルスパンのOTel GenAIセマンティック規約をカバーします。
devops
azure-ai-anomalydetector-java
microsoft
Azure AI Anomaly Detector SDK for Javaを使用して異常検出アプリケーションを構築します。単変量/多変量異常検出、時系列分析、またはAIを活用したモニタリングを実装する際に使用します。
development
azure-ai-language-conversations-py
microsoft
azure-ai-language-conversations Python SDKを使用して会話言語理解(CLU)を実装します。ConversationAnalysisClientを使用して会話の意図とエンティティを分析する場合、NLP機能を構築する場合、またはアプリケーションに言語理解を統合する場合に使用します。
development
azure-ai-ml-py
microsoft
Azure Machine Learning SDK v2 for Python。MLワークスペース、ジョブ、モデル、データセット、コンピュート、パイプラインに使用します。 トリガー: 「azure-ai-ml」、「MLClient」、「ワークスペース」、「モデルレジストリ」、「トレーニングジョブ」、「データセット」。
development