arazzo: 1.0.1
info:
title: Microsoft Endpoint Configuration Management Lost Device Lockdown
summary: Locate a managed device, remotely lock it, and reset its passcode.
description: >-
A security response flow for a reported lost or stolen device. The
workflow reads the managed device to confirm it exists, issues a remote
lock to immediately secure it, and then resets the passcode so the device
cannot be unlocked with the previously known code. Every step spells out
its request inline so the flow can be read and executed without opening
the underlying OpenAPI description.
version: 1.0.0
x-realizes-capability-ids:
- BC-600
x-capability-derivation:
method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
min_confidence: 0.7
sources:
- capability_id: BC-600
capability_name: Information Technology Management
spec: microsoft-endpoint-configuration-management-device-actions-api-openapi.yml
confidence: 0.8
model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: deviceActionsApi
url: ../openapi/microsoft-endpoint-configuration-management-device-actions-api-openapi.yml
type: openapi
- name: devicesApi
url: ../openapi/microsoft-endpoint-configuration-management-devices-api-openapi.yml
type: openapi
workflows:
- workflowId: lost-device-lockdown
summary: Confirm a device, remote lock it, then reset its passcode.
description: >-
Reads the managedDevice by id, issues a remote lock, and resets the
passcode to secure a lost or stolen device.
inputs:
type: object
required:
- managedDeviceId
properties:
accessToken:
type: string
description: OAuth 2.0 bearer token for Microsoft Graph (DeviceManagementManagedDevices.ReadWrite.All).
managedDeviceId:
type: string
description: The unique identifier of the managed device to secure.
steps:
- stepId: confirmDevice
description: Read the managed device to confirm it exists before taking action.
operationId: getManagedDevice
parameters:
- name: managedDeviceId
in: path
value: $inputs.managedDeviceId
- name: Authorization
in: header
value: "Bearer $inputs.accessToken"
successCriteria:
- condition: $statusCode == 200
outputs:
deviceName: $response.body#/deviceName
- stepId: remoteLock
description: Remotely lock the device to immediately secure it.
operationId: remoteLockManagedDevice
parameters:
- name: managedDeviceId
in: path
value: $inputs.managedDeviceId
- name: Authorization
in: header
value: "Bearer $inputs.accessToken"
successCriteria:
- condition: $statusCode == 204
outputs:
lockStatus: $statusCode
- stepId: resetPasscode
description: Reset the passcode so the device cannot be unlocked with the previously known code.
operationId: resetPasscode
parameters:
- name: managedDeviceId
in: path
value: $inputs.managedDeviceId
- name: Authorization
in: header
value: "Bearer $inputs.accessToken"
successCriteria:
- condition: $statusCode == 204
outputs:
resetStatus: $statusCode
outputs:
deviceName: $steps.confirmDevice.outputs.deviceName
lockStatus: $steps.remoteLock.outputs.lockStatus
resetStatus: $steps.resetPasscode.outputs.resetStatus
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.