Update to make sure it works properly for domains

This commit is contained in:
Przemyslaw Klys
2021-01-04 21:15:49 +01:00
parent d094344f9f
commit 37d8db92f7
3 changed files with 66 additions and 3 deletions
+1
View File
@@ -42,6 +42,7 @@
$DomainCN = ConvertFrom-DistinguishedName -DistinguishedName $DN -ToDomainCN
$Output = [ordered] @{
DistinguishedName = $Object.DistinguishedName
#Domain = ConvertFrom-DistinguishedName -DistinguishedName $Object.DistinguishedName -ToDomainCN
CanonicalName = if ($Object.CanonicalName) { $Object.CanonicalName.TrimEnd('/') } else { $Object.CanonicalName }
Guid = [Regex]::Match($DN, '(?={)(.*)(?<=})').Value -replace '{' -replace '}'
Enforced = $Enforced
+33 -1
View File
@@ -1,4 +1,32 @@
function Get-GPOZaurrBrokenLink {
<#
.SYNOPSIS
Finds any GPO link that doesn't have a matching GPO (already removed GPO).
.DESCRIPTION
Finds any GPO link that doesn't have a matching GPO (already removed GPO).
.PARAMETER Forest
Target different Forest, by default current forest is used
.PARAMETER ExcludeDomains
Exclude domain from search, by default whole forest is scanned
.PARAMETER IncludeDomains
Include only specific domains, by default whole forest is scanned
.PARAMETER ExtendedForestInformation
Ability to provide Forest Information from another command to speed up processing
.EXAMPLE
Get-GPOZaurrBrokenLink -Verbose | Format-Table -AutoSize *
.EXAMPLE
Get-GPOZaurrBrokenLink -Verbose -IncludeDomains ad.evotec.pl | Format-Table -AutoSize *
.NOTES
General notes
#>
[cmdletBinding()]
param(
[alias('ForestName')][string] $Forest,
@@ -7,7 +35,8 @@ function Get-GPOZaurrBrokenLink {
[System.Collections.IDictionary] $ExtendedForestInformation
)
$PoliciesAD = @{}
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExcludeDomainControllers $ExcludeDomainControllers -IncludeDomainControllers $IncludeDomainControllers -SkipRODC:$SkipRODC -ExtendedForestInformation $ExtendedForestInformation -Extended
# We need to request all GPOS from Forest. Requesting just for any domain won't be enough
$ForestInformation = Get-WinADForestDetails -Forest $Forest -Extended # -Extended
foreach ($Domain in $ForestInformation.Domains) {
$QueryServer = $ForestInformation['QueryServers']["$Domain"].HostName[0]
$SystemsContainer = $ForestInformation['DomainsExtended'][$Domain].SystemsContainer
@@ -34,6 +63,9 @@ function Get-GPOZaurrBrokenLink {
Write-Warning "Get-GPOZaurrBroken - Couldn't get GPOs from $Domain. Skipping"
}
}
# In case of links we can request here whatever user requested.
# This will search for broken links in domain user requested
$ForestInformation = Get-WinADForestDetails -Forest $Forest -Extended -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
$Links = Get-GPOZaurrLinkLoop -Linked 'All' -ForestInformation $ForestInformation
foreach ($Link in $Links) {
if (-not $PoliciesAD[$Link.GPODistinguishedName]) {
+32 -2
View File
@@ -1,4 +1,35 @@
function Repair-GPOZaurrBrokenLink {
<#
.SYNOPSIS
Removes any link to GPO that no longer exists.
.DESCRIPTION
Removes any link to GPO that no longer exists. It scans all site, organizational unit or domain root making sure every single link that may be linking to GPO that doesn't exists anymore is gone.
.PARAMETER Forest
Target different Forest, by default current forest is used
.PARAMETER ExcludeDomains
Exclude domain from search, by default whole forest is scanned
.PARAMETER IncludeDomains
Include only specific domains, by default whole forest is scanned
.PARAMETER ExtendedForestInformation
Ability to provide Forest Information from another command to speed up processing
.PARAMETER LimitProcessing
Allows to specify maximum number of items that will be fixed in a single run. It doesn't affect amount of GPOs processed
.EXAMPLE
Repair-GPOZaurrBrokenLink -Verbose -LimitProcessing 1 -WhatIf
.EXAMPLE
Repair-GPOZaurrBrokenLink -Verbose -IncludeDomains ad.evotec.pl -LimitProcessing 1 -WhatIf
.NOTES
General notes
#>
[cmdletBinding(SupportsShouldProcess)]
param(
[alias('ForestName')][string] $Forest,
@@ -7,7 +38,7 @@ function Repair-GPOZaurrBrokenLink {
[System.Collections.IDictionary] $ExtendedForestInformation,
[int] $LimitProcessing
)
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation -Extended
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -Extended
$Links = Get-GPOZaurrBrokenLink -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ForestInformation
$Cache = @{}
foreach ($Link in $Links) {
@@ -38,7 +69,6 @@ function Repair-GPOZaurrBrokenLink {
Write-Verbose "Repair-GPOZaurrBrokenLink - preparing for removal link to $GPODN ($Key)"
}
}
#
if ($Found) {
$NewGpLink = $($FixedLinks -join '')
try {