mirror of
https://github.com/EvotecIT/GPOZaurr.git
synced 2026-09-03 14:17:57 +00:00
Update
This commit is contained in:
+1
-1
@@ -8,7 +8,7 @@
|
|||||||
Description = 'Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.'
|
Description = 'Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.'
|
||||||
FunctionsToExport = @('Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Clear-GPOZaurrSysvolDFSR', 'ConvertFrom-CSExtension', 'Find-CSExtension', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrBroken', 'Get-GPOZaurrDictionary', 'Get-GPOZaurrFiles', 'Get-GPOZaurrFilesPolicyDefinition', 'Get-GPOZaurrFolders', 'Get-GPOZaurrInheritance', 'Get-GPOZaurrLegacyFiles', 'Get-GPOZaurrLink', 'Get-GPOZaurrLinkSummary', 'Get-GPOZaurrNetLogon', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrPermissionRoot', 'Get-GPOZaurrPermissionSummary', 'Get-GPOZaurrSysvolDFSR', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurr', 'Invoke-GPOZaurrPermission', 'Invoke-GPOZaurrSupport', 'New-GPOZaurrWMI', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrBroken', 'Remove-GPOZaurrFolders', 'Remove-GPOZaurrLegacyFiles', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Set-GPOOwner', 'Set-GPOZaurrOwner', 'Show-GPOZaurr')
|
FunctionsToExport = @('Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Clear-GPOZaurrSysvolDFSR', 'ConvertFrom-CSExtension', 'Find-CSExtension', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrBroken', 'Get-GPOZaurrDictionary', 'Get-GPOZaurrFiles', 'Get-GPOZaurrFilesPolicyDefinition', 'Get-GPOZaurrFolders', 'Get-GPOZaurrInheritance', 'Get-GPOZaurrLegacyFiles', 'Get-GPOZaurrLink', 'Get-GPOZaurrLinkSummary', 'Get-GPOZaurrNetLogon', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrPermissionRoot', 'Get-GPOZaurrPermissionSummary', 'Get-GPOZaurrSysvolDFSR', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurr', 'Invoke-GPOZaurrPermission', 'Invoke-GPOZaurrSupport', 'New-GPOZaurrWMI', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrBroken', 'Remove-GPOZaurrFolders', 'Remove-GPOZaurrLegacyFiles', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Set-GPOOwner', 'Set-GPOZaurrOwner', 'Show-GPOZaurr')
|
||||||
GUID = 'f7d4c9e4-0298-4f51-ad77-e8e3febebbde'
|
GUID = 'f7d4c9e4-0298-4f51-ad77-e8e3febebbde'
|
||||||
ModuleVersion = '0.0.65'
|
ModuleVersion = '0.0.66'
|
||||||
PowerShellVersion = '5.1'
|
PowerShellVersion = '5.1'
|
||||||
PrivateData = @{
|
PrivateData = @{
|
||||||
PSData = @{
|
PSData = @{
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
$GPOGUIDS = $GPOs.ID.GUID
|
$GPOGUIDS = $GPOs.ID.GUID
|
||||||
$SysVolPath = "\\$($Server)\SYSVOL\$Domain\Policies"
|
$SysVolPath = "\\$($Server)\SYSVOL\$Domain\Policies"
|
||||||
try {
|
try {
|
||||||
$SYSVOL = Get-ChildItem -Path "\\$($Server)\SYSVOL\$Domain\Policies" -Exclude 'PolicyDefinitions' -ErrorAction Stop
|
$SYSVOL = Get-ChildItem -Path "\\$($Server)\SYSVOL\$Domain\Policies" -Exclude 'PolicyDefinitions' -ErrorAction Stop -Verbose:$false
|
||||||
} catch {
|
} catch {
|
||||||
$Sysvol = $Null
|
$Sysvol = $Null
|
||||||
}
|
}
|
||||||
@@ -50,11 +50,11 @@
|
|||||||
if ($null -ne $SysvolHash[$GPO.Id.GUID].FullName) {
|
if ($null -ne $SysvolHash[$GPO.Id.GUID].FullName) {
|
||||||
$FullPath = $SysvolHash[$GPO.Id.GUID].FullName
|
$FullPath = $SysvolHash[$GPO.Id.GUID].FullName
|
||||||
try {
|
try {
|
||||||
$ACL = Get-Acl -Path $SysvolHash[$GPO.Id.GUID].FullName -ErrorAction Stop
|
$ACL = Get-Acl -Path $SysvolHash[$GPO.Id.GUID].FullName -ErrorAction Stop -Verbose:$false
|
||||||
$Owner = $ACL.Owner
|
$Owner = $ACL.Owner
|
||||||
$ErrorMessage = ''
|
$ErrorMessage = ''
|
||||||
} catch {
|
} catch {
|
||||||
Write-Warning "Get-GPOZaurrSysvol - ACL reading (1) failed for $FullPath with error: $($_.Exception.Message)"
|
Write-Warning "Get-GPOZaurrBroken - ACL reading (1) failed for $FullPath with error: $($_.Exception.Message)"
|
||||||
$ACL = $null
|
$ACL = $null
|
||||||
$Owner = ''
|
$Owner = ''
|
||||||
$ErrorMessage = $_.Exception.Message
|
$ErrorMessage = $_.Exception.Message
|
||||||
@@ -100,7 +100,7 @@
|
|||||||
$Owner = $ACL.Owner
|
$Owner = $ACL.Owner
|
||||||
$ErrorMessage = ''
|
$ErrorMessage = ''
|
||||||
} catch {
|
} catch {
|
||||||
Write-Warning "Get-GPOZaurrSysvol - ACL reading (2) failed for $FullPath with error: $($_.Exception.Message)"
|
Write-Warning "Get-GPOZaurrBroken - ACL reading (2) failed for $FullPath with error: $($_.Exception.Message)"
|
||||||
$ACL = $null
|
$ACL = $null
|
||||||
$Owner = $null
|
$Owner = $null
|
||||||
$ErrorMessage = $_.Exception.Message
|
$ErrorMessage = $_.Exception.Message
|
||||||
|
|||||||
@@ -14,7 +14,8 @@
|
|||||||
)
|
)
|
||||||
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExcludeDomainControllers $ExcludeDomainControllers -IncludeDomainControllers $IncludeDomainControllers -SkipRODC:$SkipRODC -ExtendedForestInformation $ExtendedForestInformation -Extended
|
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExcludeDomainControllers $ExcludeDomainControllers -IncludeDomainControllers $IncludeDomainControllers -SkipRODC:$SkipRODC -ExtendedForestInformation $ExtendedForestInformation -Extended
|
||||||
foreach ($Domain in $ForestInformation.Domains) {
|
foreach ($Domain in $ForestInformation.Domains) {
|
||||||
Write-Verbose "Get-WinADGPOSysvolFolders - Processing $Domain"
|
$TimeLog = Start-TimeLog
|
||||||
|
Write-Verbose "Get-GPOZaurrBroken - Starting process for $Domain"
|
||||||
$QueryServer = $ForestInformation['QueryServers']["$Domain"].HostName[0]
|
$QueryServer = $ForestInformation['QueryServers']["$Domain"].HostName[0]
|
||||||
$SystemsContainer = $ForestInformation['DomainsExtended'][$Domain].SystemsContainer
|
$SystemsContainer = $ForestInformation['DomainsExtended'][$Domain].SystemsContainer
|
||||||
$PoliciesAD = @{}
|
$PoliciesAD = @{}
|
||||||
@@ -35,7 +36,7 @@
|
|||||||
Try {
|
Try {
|
||||||
[Array]$GPOs = Get-GPO -All -Domain $Domain -Server $QueryServer
|
[Array]$GPOs = Get-GPO -All -Domain $Domain -Server $QueryServer
|
||||||
} catch {
|
} catch {
|
||||||
Write-Warning "Get-GPOZaurrSysvol - Couldn't get GPOs from $Domain. Error: $($_.Exception.Message)"
|
Write-Warning "Get-GPOZaurrBroken - Couldn't get GPOs from $Domain. Error: $($_.Exception.Message)"
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
if ($GPOs.Count -ge 2) {
|
if ($GPOs.Count -ge 2) {
|
||||||
@@ -43,12 +44,14 @@
|
|||||||
Test-SysVolFolders -GPOs $GPOs -Server $Domain -Domain $Domain -PoliciesAD $PoliciesAD -PoliciesSearchBase $PoliciesSearchBase
|
Test-SysVolFolders -GPOs $GPOs -Server $Domain -Domain $Domain -PoliciesAD $PoliciesAD -PoliciesSearchBase $PoliciesSearchBase
|
||||||
} else {
|
} else {
|
||||||
foreach ($Server in $ForestInformation['DomainDomainControllers']["$Domain"]) {
|
foreach ($Server in $ForestInformation['DomainDomainControllers']["$Domain"]) {
|
||||||
Write-Verbose "Get-GPOZaurrSysvol - Processing $Domain \ $($Server.HostName.Trim())"
|
Write-Verbose "Get-GPOZaurrBroken - Processing $Domain \ $($Server.HostName.Trim())"
|
||||||
Test-SysVolFolders -GPOs $GPOs -Server $Server.Hostname -Domain $Domain -PoliciesAD $PoliciesAD -PoliciesSearchBase $PoliciesSearchBase
|
Test-SysVolFolders -GPOs $GPOs -Server $Server.Hostname -Domain $Domain -PoliciesAD $PoliciesAD -PoliciesSearchBase $PoliciesSearchBase
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
Write-Warning "Get-GPOZaurrSysvol - GPO count for $Domain is less then 2. This is not expected for fully functioning domain. Skipping processing SYSVOL folder."
|
Write-Warning "Get-GPOZaurrBroken - GPO count for $Domain is less then 2. This is not expected for fully functioning domain. Skipping processing SYSVOL folder."
|
||||||
}
|
}
|
||||||
|
$TimeEnd = Stop-TimeLog -Time $TimeLog -Option OneLiner
|
||||||
|
Write-Verbose "Get-GPOZaurrBroken - Finishing process for $Domain (Time to process: $TimeEnd)"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -16,6 +16,8 @@
|
|||||||
}
|
}
|
||||||
Process {
|
Process {
|
||||||
foreach ($Domain in $ForestInformation.Domains) {
|
foreach ($Domain in $ForestInformation.Domains) {
|
||||||
|
$TimeLog = Start-TimeLog
|
||||||
|
Write-Verbose "Get-GPOZaurrPermissionConsistency - Starting process for $Domain"
|
||||||
$QueryServer = $ForestInformation['QueryServers'][$Domain]['HostName'][0]
|
$QueryServer = $ForestInformation['QueryServers'][$Domain]['HostName'][0]
|
||||||
if ($GPOName) {
|
if ($GPOName) {
|
||||||
$getGPOSplat = @{
|
$getGPOSplat = @{
|
||||||
@@ -120,6 +122,8 @@
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
$TimeEnd = Stop-TimeLog -Time $TimeLog -Option OneLiner
|
||||||
|
Write-Verbose "Get-GPOZaurrPermissionConsistency - Finishing process for $Domain (Time to process: $TimeEnd)"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
End {
|
End {
|
||||||
|
|||||||
@@ -23,9 +23,8 @@
|
|||||||
ADRightsAsArray = $true
|
ADRightsAsArray = $true
|
||||||
ResolveTypes = $true
|
ResolveTypes = $true
|
||||||
}
|
}
|
||||||
$GPOPermissionsGlobal = Get-ADACL @getADACLSplat #-Verbose
|
$GPOPermissionsGlobal = Get-ADACL @getADACLSplat -Verbose:$false
|
||||||
|
$GPOs = Get-ADObject -SearchBase "CN=Policies,CN=System,$DomainDistinguishedName" -SearchScope OneLevel -Filter * -Properties DisplayName -Server $QueryServer -Verbose:$false
|
||||||
$GPOs = Get-ADObject -SearchBase "CN=Policies,CN=System,$DomainDistinguishedName" -SearchScope OneLevel -Filter * -Properties DisplayName -Server $QueryServer
|
|
||||||
foreach ($Permission in $GPOPermissionsGlobal) {
|
foreach ($Permission in $GPOPermissionsGlobal) {
|
||||||
$CustomPermission = foreach ($_ in $Permission.ActiveDirectoryRights) {
|
$CustomPermission = foreach ($_ in $Permission.ActiveDirectoryRights) {
|
||||||
if ($_ -in 'WriteDACL', 'WriteOwner', 'GenericAll' ) {
|
if ($_ -in 'WriteDACL', 'WriteOwner', 'GenericAll' ) {
|
||||||
|
|||||||
@@ -7,8 +7,31 @@
|
|||||||
'GPOConsistency', 'GPOOwners', 'GPOAnalysis', 'NetLogon'
|
'GPOConsistency', 'GPOOwners', 'GPOAnalysis', 'NetLogon'
|
||||||
)][string[]] $Type
|
)][string[]] $Type
|
||||||
)
|
)
|
||||||
|
$Script:Reporting = [ordered] @{
|
||||||
|
|
||||||
|
}
|
||||||
|
# Provide version check for easy use
|
||||||
|
$GPOZaurrVersion = Get-Command -Name 'Show-GPOZaurr' -ErrorAction SilentlyContinue
|
||||||
|
|
||||||
|
[Array] $GitHubReleases = (Get-GitHubLatestRelease -Url "https://api.github.com/repos/evotecit/GpoZaurr/releases")
|
||||||
|
|
||||||
|
$LatestVersion = $GitHubReleases[0]
|
||||||
|
if (-not $LatestVersion.Errors) {
|
||||||
|
if ($GPOZaurrVersion.Version -eq $LatestVersion.Version) {
|
||||||
|
$Script:Reporting['Version'] = "GPOZaurr Current/Latest: $($LatestVersion.Version) at $($LatestVersion.PublishDate)"
|
||||||
|
} elseif ($GPOZaurrVersion.Version -lt $LatestVersion.Version) {
|
||||||
|
$Script:Reporting['Version'] = "GPOZaurr Current: $($GPOZaurrVersion.Version), Published: $($LatestVersion.Version) at $($LatestVersion.PublishDate). Update?"
|
||||||
|
} elseif ($GPOZaurrVersion.Version -gt $LatestVersion.Version) {
|
||||||
|
$Script:Reporting['Version'] = "GPOZaurr Current: $($GPOZaurrVersion.Version), Published: $($LatestVersion.Version) at $($LatestVersion.PublishDate). Lucky you!"
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
$Script:Reporting['Version'] = "GPOZaurr Current: $($GPOZaurrVersion.Version)"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Gather data
|
||||||
|
$TimeLog = Start-TimeLog
|
||||||
if ($Type -contains 'GPOList' -or $null -eq $Type) {
|
if ($Type -contains 'GPOList' -or $null -eq $Type) {
|
||||||
#Write-Color -Text "[Info] ", "Processing GPO List" -Color Yellow, White
|
$TimeLogGPOList = Start-TimeLog
|
||||||
Write-Verbose -Message "Show-GPOZaurr - Processing GPO List"
|
Write-Verbose -Message "Show-GPOZaurr - Processing GPO List"
|
||||||
$GPOSummary = Get-GPOZaurr
|
$GPOSummary = Get-GPOZaurr
|
||||||
$GPOLinkedStatus = $GPOSummary.Where( { $_.Linked -eq $true }, 'split')
|
$GPOLinkedStatus = $GPOSummary.Where( { $_.Linked -eq $true }, 'split')
|
||||||
@@ -18,6 +41,7 @@
|
|||||||
[Array] $GPOEmpty = $GPOEmptyStatus[0]
|
[Array] $GPOEmpty = $GPOEmptyStatus[0]
|
||||||
[Array] $GPONotEmpty = $GPOEmptyStatus[1]
|
[Array] $GPONotEmpty = $GPOEmptyStatus[1]
|
||||||
$GPOTotal = $GPOSummary.Count
|
$GPOTotal = $GPOSummary.Count
|
||||||
|
$TimeEndGPOList = Stop-TimeLog -Time $TimeLog -Option OneLiner
|
||||||
}
|
}
|
||||||
if ($Type -contains 'GPOOrphans' -or $null -eq $Type) {
|
if ($Type -contains 'GPOOrphans' -or $null -eq $Type) {
|
||||||
#Write-Color -Text "[Info] ", "Processing GPOOrphans" -Color Yellow, White
|
#Write-Color -Text "[Info] ", "Processing GPOOrphans" -Color Yellow, White
|
||||||
@@ -70,13 +94,27 @@
|
|||||||
Write-Verbose "Show-GPOZaurr - Processing GPOFiles"
|
Write-Verbose "Show-GPOZaurr - Processing GPOFiles"
|
||||||
$GPOFiles = Get-GPOZaurrFiles
|
$GPOFiles = Get-GPOZaurrFiles
|
||||||
}
|
}
|
||||||
|
$TimeEnd = Stop-TimeLog -Time $TimeLog -Option OneLiner
|
||||||
|
|
||||||
|
# Generate pretty HTML
|
||||||
Write-Verbose "Show-GPOZaurr - Generating HTML"
|
Write-Verbose "Show-GPOZaurr - Generating HTML"
|
||||||
New-HTML {
|
New-HTML {
|
||||||
New-HTMLTabStyle -BorderRadius 0px -TextTransform capitalize -BackgroundColorActive SlateGrey
|
New-HTMLTabStyle -BorderRadius 0px -TextTransform capitalize -BackgroundColorActive SlateGrey
|
||||||
New-HTMLSectionStyle -BorderRadius 0px -HeaderBackGroundColor Grey -RemoveShadow
|
New-HTMLSectionStyle -BorderRadius 0px -HeaderBackGroundColor Grey -RemoveShadow
|
||||||
New-HTMLPanelStyle -BorderRadius 0px -RemoveShadow
|
New-HTMLPanelStyle -BorderRadius 0px -RemoveShadow
|
||||||
New-HTMLTableOption -DataStore JavaScript -BoolAsString
|
New-HTMLTableOption -DataStore JavaScript -BoolAsString
|
||||||
|
|
||||||
|
New-HTMLHeader {
|
||||||
|
New-HTMLSection -Invisible {
|
||||||
|
New-HTMLSection {
|
||||||
|
New-HTMLText -Text "Report generated on $(Get-Date)" -Color Blue
|
||||||
|
} -JustifyContent flex-start -Invisible
|
||||||
|
New-HTMLSection {
|
||||||
|
New-HTMLText -Text $Script:Reporting['Version'] -Color Blue
|
||||||
|
} -JustifyContent flex-end -Invisible
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
New-HTMLTab -Name 'Overview' {
|
New-HTMLTab -Name 'Overview' {
|
||||||
if ($Type -contains 'GPOConsistency' -or $Type -contains 'GPOList' -or $null -eq $Type) {
|
if ($Type -contains 'GPOConsistency' -or $Type -contains 'GPOList' -or $null -eq $Type) {
|
||||||
New-HTMLSection -Invisible {
|
New-HTMLSection -Invisible {
|
||||||
|
|||||||
Reference in New Issue
Block a user