mirror of
https://github.com/EvotecIT/GPOZaurr.git
synced 2026-08-27 10:46:49 +00:00
Update
This commit is contained in:
+153
-17
@@ -4,19 +4,23 @@
|
|||||||
[System.Xml.XmlElement]$Content,
|
[System.Xml.XmlElement]$Content,
|
||||||
[string] $ResultsType,
|
[string] $ResultsType,
|
||||||
[Microsoft.GroupPolicy.GPRsop] $ResultantSetPolicy,
|
[Microsoft.GroupPolicy.GPRsop] $ResultantSetPolicy,
|
||||||
[string] $ComputerName,
|
|
||||||
[string] $Splitter = [System.Environment]::NewLine
|
[string] $Splitter = [System.Environment]::NewLine
|
||||||
)
|
)
|
||||||
$GPOPrimary = [ordered] @{
|
$GPOPrimary = [ordered] @{
|
||||||
Summary = $null
|
Summary = $null
|
||||||
SummaryDetails = $null
|
SummaryDetails = $null
|
||||||
ResultantSetPolicy = $ResultantSetPolicy
|
SummaryDownload = $null
|
||||||
|
ResultantSetPolicy = $ResultantSetPolicy
|
||||||
|
|
||||||
|
GroupPolicies = $null
|
||||||
|
GroupPoliciesLinks = $null
|
||||||
|
GroupPoliciesApplied = $null
|
||||||
|
GroupPoliciesDenied = $null
|
||||||
}
|
}
|
||||||
|
|
||||||
$Object = [ordered] @{
|
$Object = [ordered] @{
|
||||||
ComputerName = $ComputerName
|
|
||||||
ReadTime = [DateTime] $Content.ReadTime
|
ReadTime = [DateTime] $Content.ReadTime
|
||||||
ComputerName1 = $Content.$ResultsType.Name
|
ComputerName = $Content.$ResultsType.Name
|
||||||
DomainName = $Content.$ResultsType.Domain
|
DomainName = $Content.$ResultsType.Domain
|
||||||
OrganizationalUnit = $Content.$ResultsType.SOM
|
OrganizationalUnit = $Content.$ResultsType.SOM
|
||||||
Site = $Content.$ResultsType.Site
|
Site = $Content.$ResultsType.Site
|
||||||
@@ -33,16 +37,22 @@
|
|||||||
}
|
}
|
||||||
[Array] $GPOPrimary['GroupPolicies'] = foreach ($GPO in $Content.$ResultsType.GPO) {
|
[Array] $GPOPrimary['GroupPolicies'] = foreach ($GPO in $Content.$ResultsType.GPO) {
|
||||||
[PSCustomObject] @{
|
[PSCustomObject] @{
|
||||||
Name = $GPO.Name
|
Name = $GPO.Name
|
||||||
#Path = $GPO.Path
|
#Path = $GPO.Path
|
||||||
Identifier = $GPO.Path.Identifier.'#text'
|
Identifier = $GPO.Path.Identifier.'#text'
|
||||||
DomainName = $GPO.Path.Domain.'#text'
|
DomainName = $GPO.Path.Domain.'#text'
|
||||||
VersionDirectory = $GPO.VersionDirectory
|
#VersionDirectory = $GPO.VersionDirectory
|
||||||
VersionSysvol = $GPO.VersionSysvol
|
#VersionSysvol = $GPO.VersionSysvol
|
||||||
IsValid = if ($GPO.IsValid -eq 'true') { $true } else { $false };
|
Revision = -join ('AD (', $GPO.VersionDirectory, '), SYSVOL (', $GPO.VersionSysvol, ')')
|
||||||
FilterAllowed = if ($GPO.FilterAllowed -eq 'true') { $true } else { $false };
|
IsValid = if ($GPO.IsValid -eq 'true') { $true } else { $false };
|
||||||
AccessDenied = if ($GPO.AccessDenied -eq 'true') { $true } else { $false };
|
Status = if ($GPO.FilterAllowed -eq 'true' -and $GPO.AccessDenied -eq 'false') { 'Applied' } else { 'Denied' }
|
||||||
Link = $GPO.Link
|
FilterAllowed = if ($GPO.FilterAllowed -eq 'true') { $true } else { $false };
|
||||||
|
AccessAllowed = if ($GPO.AccessDenied -eq 'true') { $false } else { $true };
|
||||||
|
FilterId = $GPO.FilterID # : MSFT_SomFilter.ID="{ff08bc72-dae6-4890-b4cf-85a9c3b00056}",Domain="ad.evotec.xyz"
|
||||||
|
FilterName = $GPO.FilterName # : Test
|
||||||
|
SecurityFilter = $GPO.SecurityFilter -join '; ' # SecurityFilter : {NT AUTHORITY\Authenticated Users, EVOTEC\GDS-TestGroup3}
|
||||||
|
Link = $GPO.Link
|
||||||
|
ExtensionName = $GPO.ExtensionName -join '; '
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -91,6 +101,20 @@
|
|||||||
}
|
}
|
||||||
[Array] $GPOPrimary['ExtensionData'] = $Content.$ResultsType.ExtensionData.Extension
|
[Array] $GPOPrimary['ExtensionData'] = $Content.$ResultsType.ExtensionData.Extension
|
||||||
|
|
||||||
|
$EventsLevel = @{
|
||||||
|
'5' = 'Verbose'
|
||||||
|
'4' = 'Informational'
|
||||||
|
'3' = 'Warning'
|
||||||
|
'2' = 'Error'
|
||||||
|
'1' = 'Critical'
|
||||||
|
'0' = 'LogAlways'
|
||||||
|
}
|
||||||
|
$EventsReason = @{
|
||||||
|
'NOTAPPLIED-EMPTY' = 'Not Applied (Empty)'
|
||||||
|
'DENIED-WMIFILTER' = 'Denied (WMI Filter)'
|
||||||
|
'DENIED-SECURITY' = 'Denied (Security)'
|
||||||
|
}
|
||||||
|
|
||||||
[Array] $GPOPrimary['Events'] = foreach ($Event in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.EventRecord) {
|
[Array] $GPOPrimary['Events'] = foreach ($Event in $Content.$ResultsType.EventsDetails.SinglePassEventsDetails.EventRecord) {
|
||||||
[xml] $EventDetails = $Event.EventXML
|
[xml] $EventDetails = $Event.EventXML
|
||||||
$EventInformation = [ordered] @{
|
$EventInformation = [ordered] @{
|
||||||
@@ -99,7 +123,7 @@
|
|||||||
ProviderGUID = $EventDetails.Event.System.Provider.Guid
|
ProviderGUID = $EventDetails.Event.System.Provider.Guid
|
||||||
EventID = $EventDetails.Event.System.EventID # : 4006
|
EventID = $EventDetails.Event.System.EventID # : 4006
|
||||||
Version = $EventDetails.Event.System.Version # : 1
|
Version = $EventDetails.Event.System.Version # : 1
|
||||||
Level = $EventDetails.Event.System.Level # : 4
|
Level = $EventsLevel[$EventDetails.Event.System.Level] # : 4
|
||||||
Task = $EventDetails.Event.System.Task # : 0
|
Task = $EventDetails.Event.System.Task # : 0
|
||||||
Opcode = $EventDetails.Event.System.Opcode # : 1
|
Opcode = $EventDetails.Event.System.Opcode # : 1
|
||||||
Keywords = $EventDetails.Event.System.Keywords # : 0x4000000000000000
|
Keywords = $EventDetails.Event.System.Keywords # : 0x4000000000000000
|
||||||
@@ -117,5 +141,117 @@
|
|||||||
[PSCustomObject] $EventInformation
|
[PSCustomObject] $EventInformation
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Lets build events by ID, this will be useful for better/easier processing
|
||||||
|
$GPOPrimary['EventsByID'] = [ordered] @{}
|
||||||
|
$GroupedEvents = $GPOPrimary['Events'] | Group-Object -Property EventId
|
||||||
|
foreach ($Events in $GroupedEvents) {
|
||||||
|
$GPOPrimary['EventsByID'][$Events.Name] = $Events.Group
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
$GPOPrimary['News'] = foreach ($Event in $GPOPrimary['Events']) {
|
||||||
|
|
||||||
|
#$Event
|
||||||
|
}
|
||||||
|
|
||||||
|
$GPOPrimary['GroupPoliciesApplied'] = & {
|
||||||
|
if ($GPOPrimary['EventsByID']['5312']) {
|
||||||
|
[xml] $GPODetailsApplied = -join ('<Details>', $GPOPrimary['EventsByID']['5312'].GPOinfoList, '</Details>')
|
||||||
|
foreach ($GPO in $GPODetailsApplied.Details.GPO) {
|
||||||
|
[PSCustomObject] @{
|
||||||
|
GUID = $GPO.ID # : { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }
|
||||||
|
DisplayName = $GPO.Name # : DC | Event Log Settings
|
||||||
|
Version = $GPO.Version # : 851981
|
||||||
|
Link = $GPO.SOM # : LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz
|
||||||
|
SysvolPath = $GPO.FSPath # : \\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\ { 4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B }\Machine
|
||||||
|
GPOTypes = $GPO.Extensions -join '; ' # : [ { 35378EAC-683F-11D2-A89A-00C04FBBCFA2 } { D02B1F72 - 3407 - 48AE-BA88-E8213C6761F1 }]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
$GPOPrimary['GroupPoliciesDenied'] = & {
|
||||||
|
if ($GPOPrimary['EventsByID']['5312']) {
|
||||||
|
[xml] $GPODetailsDenied = -join ('<Details>', $GPOPrimary['EventsByID']['5313'].GPOinfoList, '</Details>')
|
||||||
|
foreach ($GPO in $GPODetailsDenied.Details.GPO) {
|
||||||
|
[PSCustomObject] @{
|
||||||
|
GUID = $GPO.ID #: { 6AC1786C-016F-11D2-945F-00C04fB984F9 }
|
||||||
|
DisplayName = $GPO.Name #: Default Domain Controllers Policy
|
||||||
|
Version = $GPO.Version #: 131074
|
||||||
|
Link = $GPO.SOM #: LDAP: / / OU = Domain Controllers, DC = ad, DC = evotec, DC = xyz
|
||||||
|
SysvolPath = $GPO.FSPath #: \\ad.evotec.xyz\sysvol\ad.evotec.xyz\Policies\ { 6AC1786C-016F-11D2-945F-00C04fB984F9 }\Machine
|
||||||
|
GPOTypes = $EventsReason["$($GPO.Reason)"] #: DENIED-WMIFILTER
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$GPOPrimary['SummaryDownload'] = & {
|
||||||
|
if ($GPOPrimary['EventsByID']['5126']) {
|
||||||
|
[PSCustomObject] @{
|
||||||
|
IsBackgroundProcessing = $GPOPrimary['EventsByID']['5126'].IsBackgroundProcessing # : true
|
||||||
|
IsAsyncProcessing = $GPOPrimary['EventsByID']['5126'].IsAsyncProcessing # : false
|
||||||
|
NumberOfGPOsDownloaded = $GPOPrimary['EventsByID']['5126'].NumberOfGPOsDownloaded # : 7
|
||||||
|
NumberOfGPOsApplicable = $GPOPrimary['EventsByID']['5126'].NumberOfGPOsApplicable # : 6
|
||||||
|
GPODownloadTimeElapsedInMilliseconds = $GPOPrimary['EventsByID']['5126'].GPODownloadTimeElapsedInMilliseconds # : 375
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
|
}
|
||||||
$GPOPrimary
|
$GPOPrimary
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
<#
|
||||||
|
Description : Group Policy successfully got applicable GPOs from the domain controller.
|
||||||
|
Provider : Microsoft-Windows-GroupPolicy
|
||||||
|
ProviderGUID : {aea1b4fa-97d1-45f2-a64c-4d69fffd92c9}
|
||||||
|
EventID : 5126
|
||||||
|
Computer : AD1.ad.evotec.xyz
|
||||||
|
IsBackgroundProcessing : true
|
||||||
|
IsAsyncProcessing : false
|
||||||
|
NumberOfGPOsDownloaded : 7
|
||||||
|
NumberOfGPOsApplicable : 6
|
||||||
|
GPODownloadTimeElapsedInMilliseconds : 375
|
||||||
|
#>
|
||||||
|
|
||||||
|
<#
|
||||||
|
Description : List of applicable Group Policy objects:
|
||||||
|
|
||||||
|
ALL | Certificates
|
||||||
|
New Group Policy Object
|
||||||
|
COMPUTERS | Enable Sets
|
||||||
|
Default Domain Policy
|
||||||
|
DC | Event Log Audit Rules
|
||||||
|
DC | Event Log Settings
|
||||||
|
|
||||||
|
Provider : Microsoft-Windows-GroupPolicy
|
||||||
|
ProviderGUID : {aea1b4fa-97d1-45f2-a64c-4d69fffd92c9}
|
||||||
|
EventID : 5312
|
||||||
|
Version : 0
|
||||||
|
Level : 4
|
||||||
|
Task : 0
|
||||||
|
Opcode : 0
|
||||||
|
Keywords : 0x4000000000000000
|
||||||
|
TimeCreated : 12.08.2020 14:07:07
|
||||||
|
EventRecordID : 10675722
|
||||||
|
Correlation : {c2ca0749-6bb7-474e-8ff5-372d18279493}
|
||||||
|
Execution : ProcessID: 1368 ThreadID: 3720
|
||||||
|
Channel : Microsoft-Windows-GroupPolicy/Operational
|
||||||
|
Computer : AD1.ad.evotec.xyz
|
||||||
|
Security : S-1-5-18
|
||||||
|
DescriptionString : ALL | Certificates
|
||||||
|
New Group Policy Object
|
||||||
|
COMPUTERS | Enable Sets
|
||||||
|
Default Domain Policy
|
||||||
|
DC | Event Log Audit Rules
|
||||||
|
DC | Event Log Settings
|
||||||
|
|
||||||
|
GPOInfoList : <GPO ID="{2C7652BB-C1A1-42C1-BBA6-D620A70E0356}"><Name>ALL | Certificates</Name><Version>131074</Version><SOM>LDAP://DC=ad,DC=evotec,DC=xyz</SOM><FSPath>\\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\{2C7652BB-C1A1-42C1-BBA6-D620A70E0356}\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1D-2488-11D1-A28C-00C04FB94F17}][{
|
||||||
|
B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1D-2488-11D1-A28C-00C04FB94F17}]</Extensions></GPO><GPO ID="{8A7BC515-D7FD-4D1F-90B8-E47C15F89295}"><Name>New Group Policy Object</Name><Version>65537</Version><SOM>LDAP://DC=ad,DC=evotec,DC=xyz</SOM><FSPath>\\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\{8A7BC515-D7FD-4D1F-90B8-E47C15F89295}\Machine</
|
||||||
|
FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{D02B1F72-3407-48AE-BA88-E8213C6761F1}]</Extensions></GPO><GPO ID="{64AD41CA-BF07-4DB3-BFC0-20F9999ADAD6}"><Name>COMPUTERS | Enable Sets</Name><Version>65537</Version><SOM>LDAP://DC=ad,DC=evotec,DC=xyz</SOM><FSPath>\\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\{64AD41CA-BF07-4DB3-BFC0-20
|
||||||
|
F9999ADAD6}\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{D02B1F72-3407-48AE-BA88-E8213C6761F1}]</Extensions></GPO><GPO ID="{31B2F340-016D-11D2-945F-00C04FB984F9}"><Name>Default Domain Policy</Name><Version>2293795</Version><SOM>LDAP://DC=ad,DC=evotec,DC=xyz</SOM><FSPath>\\ad.evotec.xyz\sysvol\ad.evotec.xyz\Policies\{31B2F
|
||||||
|
340-016D-11D2-945F-00C04FB984F9}\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}][{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}][{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}]</Extensions></GPO><GPO ID="{55FB3860-74C9-4262-AD7
|
||||||
|
7-30197EAB9999}"><Name>DC | Event Log Audit Rules</Name><Version>655370</Version><SOM>LDAP://OU=Domain Controllers,DC=ad,DC=evotec,DC=xyz</SOM><FSPath>\\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\{55FB3860-74C9-4262-AD77-30197EAB9999}\Machine</FSPath><Extensions>[{F3CCC681-B74C-4060-9F26-CD84525DCA2A}{0F3F3735-573D-9804-99E4-AB2A69BA5FD4}]</Ex
|
||||||
|
tensions></GPO><GPO ID="{4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B}"><Name>DC | Event Log Settings</Name><Version>851981</Version><SOM>LDAP://OU=Domain Controllers,DC=ad,DC=evotec,DC=xyz</SOM><FSPath>\\ad.evotec.xyz\SysVol\ad.evotec.xyz\Policies\{4E1F9C70-1DDB-4AB6-BBA3-14A8E07F0B4B}\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2
|
||||||
|
}{D02B1F72-3407-48AE-BA88-E8213C6761F1}]</Extensions></GPO>
|
||||||
|
#>
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
function New-GPOZaurrReportHTML {
|
||||||
|
[cmdletBinding()]
|
||||||
|
param(
|
||||||
|
[System.Collections.IDictionary] $Support,
|
||||||
|
[string] $Path,
|
||||||
|
[switch] $Offline,
|
||||||
|
[switch] $Open
|
||||||
|
)
|
||||||
|
$PSDefaultParameterValues = @{
|
||||||
|
"New-HTMLTable:WarningAction" = 'SilentlyContinue'
|
||||||
|
}
|
||||||
|
if (-not $Path) {
|
||||||
|
$Path = [io.path]::GetTempFileName().Replace('.tmp', ".html")
|
||||||
|
}
|
||||||
|
$ComputerName = $($Support.ResultantSetPolicy.LoggingComputer)
|
||||||
|
$UserName = $($Support.ResultantSetPolicy.UserName)
|
||||||
|
$LoggingMode = $($Support.ResultantSetPolicy.LoggingMode)
|
||||||
|
New-HTML -TitleText "Group Policy Report - $ComputerName / $UserName / $LoggingMode" {
|
||||||
|
#New-HTMLTabOptions -SlimTabs -Transition -LinearGradient -SelectorColor Akaroa
|
||||||
|
New-HTMLTabOptions -SlimTabs `
|
||||||
|
-BorderBottomStyleActive solid -BorderBottomColorActive LightSkyBlue -BackgroundColorActive none `
|
||||||
|
-TextColorActive Black -Align left -BorderRadius 0px -RemoveShadow -TextColor Grey -TextTransform capitalize
|
||||||
|
New-HTMLTab -Name 'Information' {
|
||||||
|
New-HTMLTable -DataTable $Support.ResultantSetPolicy -HideFooter
|
||||||
|
}
|
||||||
|
foreach ($Key in $Support.Keys) {
|
||||||
|
if ($Key -eq 'ResultantSetPolicy') {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
New-HTMLTab -Name $Key {
|
||||||
|
New-HTMLTab -Name 'Summary' {
|
||||||
|
New-HTMLSection -Invisible {
|
||||||
|
New-HTMLSection -HeaderText 'Summary' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.Summary -Filtering -PagingOptions @(7, 14 )
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.SummaryDetails -Filtering -PagingOptions @(7, 14)
|
||||||
|
}
|
||||||
|
New-HTMLSection -HeaderText 'Part of Security Groups' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.SecurityGroups -Filtering -PagingOptions @(7, 14)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLSection -HeaderText 'Part of Security Groups' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.ResultantSetPolicy -HideFooter
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLTab -Name 'Group Policies' {
|
||||||
|
New-HTMLSection -Invisible {
|
||||||
|
New-HTMLSection -HeaderText 'Processing Time' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.ProcessingTime -Filtering
|
||||||
|
}
|
||||||
|
New-HTMLSection -HeaderText 'ExtensionStatus' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.ExtensionStatus -Filtering
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLSection -HeaderText 'Group Policies' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.GroupPolicies -Filtering
|
||||||
|
}
|
||||||
|
New-HTMLSection -HeaderText 'Group Policies Applied' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.GroupPoliciesApplied -Filtering
|
||||||
|
}
|
||||||
|
New-HTMLSection -HeaderText 'Group Policies Denied' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.GroupPoliciesDenied -Filtering
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLTab -Name 'ExtensionData' {
|
||||||
|
New-HTMLSection -HeaderText 'ExtensionData' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.ExtensionData -Filtering
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLTab -Name 'Scope of Management' {
|
||||||
|
New-HTMLSection -HeaderText 'Scope of Management' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.ScopeOfManagement -Filtering
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLTab -Name 'Events By ID' {
|
||||||
|
foreach ($ID in $Support.$Key.EventsByID.Keys) {
|
||||||
|
New-HTMLSection -HeaderText "Event ID $ID" {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.EventsByID[$ID] -Filtering -AllProperties
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
New-HTMLTab -Name 'Events' {
|
||||||
|
New-HTMLSection -HeaderText 'Events' {
|
||||||
|
New-HTMLTable -DataTable $Support.$Key.Events -Filtering -AllProperties
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} -Online:(-not $Offline.IsPresent) -Open:$Open.IsPresent -FilePath $Path
|
||||||
|
}
|
||||||
@@ -1,4 +1,5 @@
|
|||||||
function Get-GPOZaurrFilesPolicyDefinitions {
|
function Get-GPOZaurrFilesPolicyDefinition {
|
||||||
|
[alias('Get-GPOZaurrFilesPolicyDefinitions')]
|
||||||
[cmdletbinding()]
|
[cmdletbinding()]
|
||||||
param(
|
param(
|
||||||
[alias('ForestName')][string] $Forest,
|
[alias('ForestName')][string] $Forest,
|
||||||
@@ -55,7 +56,7 @@ function Get-GPOZaurrFilesPolicyDefinitions {
|
|||||||
if ($FilesCache[$Domain][$FileLanguage.BaseName]) {
|
if ($FilesCache[$Domain][$FileLanguage.BaseName]) {
|
||||||
$FilesCache[$Domain][$FileLanguage.BaseName][$Directory.Name] = $true
|
$FilesCache[$Domain][$FileLanguage.BaseName][$Directory.Name] = $true
|
||||||
} else {
|
} else {
|
||||||
#Write-Warning "Get-GPOZaurrFilesPolicyDefinitions - File $($FileLanguage.FullName) doesn't have a match."
|
#Write-Warning "Get-GPOZaurrFilesPolicyDefinition - File $($FileLanguage.FullName) doesn't have a match."
|
||||||
$Output.FilesToDelete.Add(
|
$Output.FilesToDelete.Add(
|
||||||
[PSCustomobject] @{
|
[PSCustomobject] @{
|
||||||
Name = $FileLanguage.BaseName
|
Name = $FileLanguage.BaseName
|
||||||
|
|||||||
@@ -1,41 +1,92 @@
|
|||||||
function Invoke-GPOZaurrSupport {
|
function Invoke-GPOZaurrSupport {
|
||||||
[cmdletBinding()]
|
[cmdletBinding()]
|
||||||
param(
|
param(
|
||||||
[ValidateSet('XML', 'Object')][string] $Type = 'Object',
|
[ValidateSet('NativeHTML', 'HTML', 'XML', 'Object')][string] $Type = 'HTML',
|
||||||
[alias('Server')][string] $ComputerName,
|
[alias('Server')][string] $ComputerName,
|
||||||
[alias('User')][string] $UserName,
|
[alias('User')][string] $UserName,
|
||||||
[string] $Path,
|
[string] $Path,
|
||||||
[string] $Splitter = [System.Environment]::NewLine
|
[string] $Splitter = [System.Environment]::NewLine,
|
||||||
|
[switch] $PreventShow,
|
||||||
|
[switch] $Offline
|
||||||
)
|
)
|
||||||
|
# if user didn't choose anything, lets run as currently logged in user locally
|
||||||
|
if (-not $UserName -and -not $ComputerName) {
|
||||||
|
$UserName = $Env:USERNAME
|
||||||
|
|
||||||
$SplatPolicy = @{
|
# we can also check if the session is Administrative and if so request computer policies
|
||||||
ReportType = 'xml'
|
if (([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole] "Administrator")) {
|
||||||
Path = [io.path]::GetTempFileName().Replace('.tmp', ".xml")
|
$ComputerName = $Env:COMPUTERNAME
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if ($PSBoundParameters.ContainsKey('ComputerName')) {
|
|
||||||
|
If ($Type -eq 'HTML') {
|
||||||
|
$Exists = Get-Command -Name 'New-HTML' -ErrorAction SilentlyContinue
|
||||||
|
if (-not $Exists) {
|
||||||
|
Write-Warning "Request-GPOZaurr - PSWriteHTML module is required for HTML functionality. Use XML, Object or NativeHTML option instead."
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
$SplatPolicy = @{}
|
||||||
|
if ($Type -in 'Object', 'XML', 'HTML') {
|
||||||
|
if ($Path) {
|
||||||
|
$SplatPolicy['Path'] = $Path
|
||||||
|
} else {
|
||||||
|
$SplatPolicy['Path'] = [io.path]::GetTempFileName().Replace('.tmp', ".xml")
|
||||||
|
}
|
||||||
|
$SplatPolicy['ReportType'] = 'xml'
|
||||||
|
} elseif ($Type -eq 'NativeHTML') {
|
||||||
|
if ($Path) {
|
||||||
|
$SplatPolicy['Path'] = $Path
|
||||||
|
} else {
|
||||||
|
$SplatPolicy['Path'] = [io.path]::GetTempFileName().Replace('.tmp', ".html")
|
||||||
|
}
|
||||||
|
$SplatPolicy['ReportType'] = 'html'
|
||||||
|
}
|
||||||
|
if ($ComputerName) {
|
||||||
$SplatPolicy['Computer'] = $ComputerName
|
$SplatPolicy['Computer'] = $ComputerName
|
||||||
}
|
}
|
||||||
if ($PSBoundParameters.ContainsKey('UserName')) {
|
if ($UserName) {
|
||||||
$SplatPolicy['User'] = $UserName
|
$SplatPolicy['User'] = $UserName
|
||||||
}
|
}
|
||||||
try {
|
try {
|
||||||
|
#Write-Verbose "Request-GPOZaurr - ComputerName: $($SplatPolicy['Computer']) UserName: $($SplatPolicy['User'])"
|
||||||
$ResultantSetPolicy = Get-GPResultantSetOfPolicy @SplatPolicy
|
$ResultantSetPolicy = Get-GPResultantSetOfPolicy @SplatPolicy
|
||||||
} catch {
|
} catch {
|
||||||
if ($_.Exception.Message -eq 'Exception from HRESULT: 0x80041003') {
|
if ($_.Exception.Message -eq 'Exception from HRESULT: 0x80041003') {
|
||||||
Write-Warning "Request-GPOZaurr - Are you running as admin? $($_.Exception.Message)"
|
Write-Warning "Request-GPOZaurr - Are you running as admin? $($_.Exception.Message)"
|
||||||
|
return
|
||||||
} else {
|
} else {
|
||||||
Write-Warning "Request-GPOZaurr - Error: $($_.Exception.Message)"
|
Write-Warning "Request-GPOZaurr - Error: $($_.Exception.Message)"
|
||||||
|
return
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (-not $ComputerName) {
|
if ($Type -eq 'NativeHTML') {
|
||||||
# ComputerName is not set, lets use local
|
if (-not $PreventShow) {
|
||||||
$ComputerName = $Env:COMPUTERNAME
|
Write-Verbose "Invoke-GPOZaurrSupport - Opening up file $SplatPolicy['Path']"
|
||||||
|
Start-Process -FilePath $SplatPolicy['Path']
|
||||||
|
}
|
||||||
|
return
|
||||||
}
|
}
|
||||||
# Loads created XML by resultant Output
|
# Loads created XML by resultant Output
|
||||||
[xml] $PolicyContent = Get-Content -LiteralPath $SplatPolicy.Path
|
if ($SplatPolicy.Path -and (Test-Path -LiteralPath $SplatPolicy.Path)) {
|
||||||
if ($PolicyContent -and (Test-Path -LiteralPath $SplatPolicy.Path)) {
|
[xml] $PolicyContent = Get-Content -LiteralPath $SplatPolicy.Path
|
||||||
# lets remove temporary XML file
|
if ($PolicyContent) {
|
||||||
Remove-Item -LiteralPath $SplatPolicy.Path
|
# lets remove temporary XML file
|
||||||
|
Remove-Item -LiteralPath $SplatPolicy.Path
|
||||||
|
} else {
|
||||||
|
Write-Warning "Request-GPOZaurr - Couldn't load XML file from drive $($SplatPolicy.Path). Terminating."
|
||||||
|
return
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
Write-Warning "Request-GPOZaurr - Couldn't find XML file on drive $($SplatPolicy.Path). Terminating."
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if ($ComputerName) {
|
||||||
|
if (-not $PolicyContent.Rsop.'ComputerResults'.EventsDetails) {
|
||||||
|
Write-Warning "Request-GPOZaurr - Windows Events for Group Policy are missing. Amount of data will be limited. Firewall issue?"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
if ($Type -eq 'XML') {
|
if ($Type -eq 'XML') {
|
||||||
$PolicyContent.Rsop
|
$PolicyContent.Rsop
|
||||||
@@ -44,11 +95,15 @@
|
|||||||
ResultantSetPolicy = $ResultantSetPolicy
|
ResultantSetPolicy = $ResultantSetPolicy
|
||||||
}
|
}
|
||||||
if ($PolicyContent.Rsop.ComputerResults) {
|
if ($PolicyContent.Rsop.ComputerResults) {
|
||||||
$Output.ComputerResults = ConvertFrom-XMLRSOP -Content $PolicyContent.Rsop -ComputerName $ComputerName -ResultantSetPolicy $ResultantSetPolicy -ResultsType 'ComputerResults' -Splitter $Splitter
|
$Output.ComputerResults = ConvertFrom-XMLRSOP -Content $PolicyContent.Rsop -ResultantSetPolicy $ResultantSetPolicy -ResultsType 'ComputerResults' -Splitter $Splitter
|
||||||
}
|
}
|
||||||
if ($PolicyContent.Rsop.UserResults) {
|
if ($PolicyContent.Rsop.UserResults) {
|
||||||
$Output.UserResults = ConvertFrom-XMLRSOP -Content $PolicyContent.Rsop -ComputerName $ComputerName -ResultantSetPolicy $ResultantSetPolicy -ResultsType 'UserResults' -Splitter $Splitter
|
$Output.UserResults = ConvertFrom-XMLRSOP -Content $PolicyContent.Rsop -ResultantSetPolicy $ResultantSetPolicy -ResultsType 'UserResults' -Splitter $Splitter
|
||||||
|
}
|
||||||
|
if ($Type -eq 'Object') {
|
||||||
|
$Output
|
||||||
|
} elseif ($Type -eq 'HTML') {
|
||||||
|
New-GPOZaurrReportHTML -Path $Path -Offline:$Offline -Open:(-not $PreventShow) -Support $Output
|
||||||
}
|
}
|
||||||
$Output
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user