From 914dcfb0c4614206182db21a57f598324f8dd7c9 Mon Sep 17 00:00:00 2001 From: Przemyslaw Klys Date: Sun, 11 Apr 2021 19:01:33 +0200 Subject: [PATCH] Improved --- Private/Invoke.GPOZaurrBlockedInheritance.ps1 | 170 +++++++++++++++++- Public/Get-GPOZaurrInheritance.ps1 | 1 + 2 files changed, 168 insertions(+), 3 deletions(-) diff --git a/Private/Invoke.GPOZaurrBlockedInheritance.ps1 b/Private/Invoke.GPOZaurrBlockedInheritance.ps1 index 006c347..241d114 100644 --- a/Private/Invoke.GPOZaurrBlockedInheritance.ps1 +++ b/Private/Invoke.GPOZaurrBlockedInheritance.ps1 @@ -4,19 +4,183 @@ ActionRequired = $null Data = $null Execute = { - Get-GPOZaurrInheritance -IncludeBlockedObjects -OnlyBlockedInheritance -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains + Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains } Processing = { + foreach ($GPO in $Script:Reporting['GPOBlockedInheritance']['Data']) { + if (-not $Script:Reporting['GPOBlockedInheritance']['Variables']['DeletionHarmlessPerDomain'][$GPO.DomainName]) { + $Script:Reporting['GPOBlockedInheritance']['Variables']['DeletionHarmlessPerDomain'][$GPO.DomainName] = 0 + } + if (-not $Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigationPerDomain'][$GPO.DomainName]) { + $Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigationPerDomain'][$GPO.DomainName] = 0 + } + if ($GPO.Excluded -eq $true) { + $Script:Reporting['GPOBlockedInheritance']['Variables']['Excluded']++ + $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffectedExcluded'] = $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffectedExcluded'] + $GPO.UsersCount + $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffectedExcluded'] = $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffectedExcluded'] + $GPO.ComputersCount + } else { + $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffected'] = $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffected'] + $GPO.UsersCount + $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffected'] = $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffected'] + $GPO.ComputersCount + } + $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffectedIncludingExcluded'] = $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffectedIncludingExcluded'] + $GPO.UsersCount + $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffectedIncludingExcluded'] = $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffectedIncludingExcluded'] + $GPO.ComputersCount + if ($GPO.Excluded -eq $false -and ($GPO.UsersCount -gt 0 -or $GPO.ComputersCount -gt 0)) { + $Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigation']++ + $Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigationPerDomain'][$GPO.DomainName]++ + } + if ($GPO.Excluded -eq $false -and ($GPO.UsersCount -eq 0 -and $GPO.ComputersCount -eq 0)) { + $Script:Reporting['GPOBlockedInheritance']['Variables']['DeletionHarmless']++ + $Script:Reporting['GPOBlockedInheritance']['Variables']['DeletionHarmlessPerDomain'][$GPO.DomainName]++ + } + } + if ($Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigation'] -gt 0 -or $Script:Reporting['GPOBlockedInheritance']['Variables']['DeletionHarmless'] -gt 0) { + $Script:Reporting['GPOBlockedInheritance']['ActionRequired'] = $true + } else { + $Script:Reporting['GPOBlockedInheritance']['ActionRequired'] = $false + } } + Resources = @( + 'http://www.firewall.cx/microsoft-knowledgebase/windows-2012/1056-windows-2012-group-policy-enforcement.html' + ) Variables = @{ - + Total = 0 + Excluded = 0 + RequiresInvesigation = 0 + RequiresInvesigationPerDomain = [ordered] @{} + DeletionHarmless = 0 + DeletionHarmlessPerDomain = [ordered] @{} + UsersAffected = 0 + UsersAffectedExcluded = 0 + UsersAffectedIncludingExcluded = 0 + ComputersAffected = 0 + ComputersAffectedIncludingExcluded = 0 + ComputersAffectedExcluded = 0 } Overview = { + } + Summary = { + New-HTMLText -FontSize 10pt -TextBlock { + "By default, group policy settings that are linked to parent objects are inherited to the child objects in the active directory hierarchy. " + "By default, Default Domain Policy is linked to the domain and is inherited to all the child objects of the domain hierarchy. " + "So does any other policies linked to the top level OU's. " + } + New-HTMLText -Text "Block Inheritance" -FontSize 10pt -FontWeight bold + New-HTMLText -FontSize 10pt -Text @( + "As GPOs can be inherited by default, they can also be blocked, if required using the Block Inheritance. " + "If the Block Inheritance setting is enabled, the inheritance of group policy setting is blocked. " + "This setting is mostly used when the OU contains users or computers that require different settings than what is applied to the domain level. " + "Unfortunetly blocking inheritance can have serious security consequences. " + ) + New-HTMLText -Text @( + 'As it stands currently there are ', + $Script:Reporting['GPOBlockedInheritance']['Data'].Count, + ' organiational units with ' + 'GPO Inheritance Block' + ' out of which ' + $Script:Reporting['GPOBlockedInheritance']['Variables']['Excluded'].Count, + ' are marked as excluded ' + '(approved by IT). ' + ) -FontSize 10pt -FontWeight normal, bold, normal, bold, normal, bold, normal, bold -LineBreak + if ($Script:Reporting['GPOBlockedInheritance']['Data'].Count -ne 0) { + New-HTMLText -Text 'Users & Computers affected by inheritance blocks:' -FontSize 10pt -FontWeight bold + New-HTMLList -Type Unordered { + New-HTMLListItem -Text $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffected'], ' users affected due to inheritance blocks' + New-HTMLListItem -Text $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffectedExcluded'], ' users affected, but approved/excluded, due to inheritance blocks' + New-HTMLListItem -Text $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffected'], ' computers affected due to inheritance blocks' + New-HTMLListItem -Text $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffectedExcluded'], ' computers affected, but approved/excluded, due to inheritance blocks' + } -FontSize 10pt + + New-HTMLText -Text 'Following domains require:' -FontSize 10pt -FontWeight bold + New-HTMLList -Type Unordered { + foreach ($Domain in $Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigationPerDomain'].Keys) { + New-HTMLListItem -Text "$Domain proposes ", $Script:Reporting['GPOBlockedInheritance']['Variables']['RequiresInvesigationPerDomain'][$Domain], " investigation (computers or users inside)." -FontWeight normal, bold, normal + New-HTMLListItem -Text "$Domain proposes ", $Script:Reporting['GPOBlockedInheritance']['Variables']['DeletionHarmlessPerDomain'][$Domain], " removal (mostly harmless due to no computers or users inside)." -FontWeight normal, bold, normal + } + } -FontSize 10pt + } + New-HTMLText -FontSize 10pt -Text "Please review output in table and follow the steps below table to get Active Directory Group Policies in healthy state." } Solution = { - New-HTMLTable -DataTable $Script:Reporting['GPOBlockedInheritance']['Data'] -Filtering + New-HTMLSection -Invisible { + New-HTMLPanel { + & $Script:GPOConfiguration['GPOBlockedInheritance']['Summary'] + } + New-HTMLPanel { + New-HTMLChart { + New-ChartLegend -Names 'Affected', 'Affected, but Excluded' -Color Salmon, PaleGreen + New-ChartBarOptions -Type barStacked + New-ChartBar -Name 'Users' -Value $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffected'], $Script:Reporting['GPOBlockedInheritance']['Variables']['UsersAffectedExcluded'] + New-ChartBar -Name 'Computers' -Value $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffected'], $Script:Reporting['GPOBlockedInheritance']['Variables']['ComputersAffectedExcluded'] + } -Title 'Users & Computers affected due to blocked inheritance' -TitleAlignment center + } + } + New-HTMLSection -Name 'Organizational Units with Group Policy Blocked Inheritance' { + New-HTMLTable -DataTable $Script:Reporting['GPOBlockedInheritance']['Data'] -Filtering { + New-TableConditionGroup { + New-TableCondition -Name 'BlockedInheritance' -Value $true + New-TableCondition -Name 'Excluded' -Value $false + } -BackgroundColor Salmon -FailBackgroundColor SpringGreen -HighlightHeaders 'BlockedInheritance', 'Excluded' + New-TableConditionGroup { + New-TableCondition -Name 'UsersCount' -Value 0 + New-TableCondition -Name 'ComputersCount' -Value 0 + } -BackgroundColor Salmon -FailBackgroundColor Amber -HighlightHeaders 'UsersCount', 'ComputersCount' + } -PagingOptions 10, 20, 30, 40, 50 -SearchBuilder + } + if ($Script:Reporting['Settings']['HideSteps'] -eq $false) { + New-HTMLSection -Name 'Steps to fix - Organizational Units with Group Policy Blocked Inheritance' { + New-HTMLContainer { + New-HTMLSpanStyle -FontSize 10pt { + New-HTMLWizard { + New-HTMLWizardStep -Name 'Prepare environment' { + New-HTMLText -Text "To be able to execute actions in automated way please install required modules. Those modules will be installed straight from Microsoft PowerShell Gallery." + New-HTMLCodeBlock -Code { + Install-Module GPOZaurr -Force + Import-Module GPOZaurr -Force + } -Style powershell + New-HTMLText -Text "Using force makes sure newest version is downloaded from PowerShellGallery regardless of what is currently installed. Once installed you're ready for next step." + } + New-HTMLWizardStep -Name 'Prepare report' { + New-HTMLText -Text @( + "Depending when this report was run you may want to prepare new report before proceeding removing Group Policy Inheritance Blocks. " + "Please keep in mind that if exclusions for some Organizational OU's were defined you need to pass them to cmdlet below to not remove approved GPO Inheritance Blocks. " + "To generate new report please use:" + ) + New-HTMLCodeBlock -Code { + Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrBlockedGPOInheritanceBefore.html -Verbose -Type GPOBlockedInheritance + } + New-HTMLText -TextBlock { + "When executed it will take a while to generate all data and provide you with new report depending on size of environment. " + "Once confirmed that data is still showing issues and requires fixing please proceed with next step. " + } + New-HTMLText -Text "Alternatively if you prefer working with console you can run: " + New-HTMLCodeBlock -Code { + $GPOOutput = Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance + $GPOOutput | Format-Table # do your actions as desired + } + New-HTMLText -Text "It provides same data as you see in table above just doesn't prettify it for you." + } + New-HTMLWizardStep -Name 'Remove OU GPO Inheritance Blocks' { + New-HTMLText -Text @( + "Removing inheritance blocks is quite trivial and can be done from GPO GUI. However knowing when to remove is the important part. " + "Please consult other Domain Admins before removing any inheritance blocks, and either approve exclusion or remove blocking inheritance. " + ) + } + New-HTMLWizardStep -Name 'Verification report' { + New-HTMLText -TextBlock { + "Once cleanup task was executed properly, we need to verify that report now shows no problems." + } + New-HTMLCodeBlock -Code { + Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrBlockedGPOInheritanceAfter.html -Verbose -Type GPOBlockedInheritance + } + New-HTMLText -Text "If everything is healthy in the report you're done! Enjoy rest of the day!" -Color BlueDiamond + } + } -RemoveDoneStepOnNavigateBack -Theme arrows -ToolbarButtonPosition center -EnableAllAnchors + } + } + } + } if ($Script:Reporting['GPOBlockedInheritance']['WarningsAndErrors']) { New-HTMLSection -Name 'Warnings & Errors to Review' { New-HTMLTable -DataTable $Script:Reporting['GPOBlockedInheritance']['WarningsAndErrors'] -Filtering { diff --git a/Public/Get-GPOZaurrInheritance.ps1 b/Public/Get-GPOZaurrInheritance.ps1 index 46ed54f..36915fa 100644 --- a/Public/Get-GPOZaurrInheritance.ps1 +++ b/Public/Get-GPOZaurrInheritance.ps1 @@ -64,6 +64,7 @@ CanonicalName = $OU.canonicalName BlockedInheritance = if ($OU.gpOptions -eq 1) { $true } else { $false } Excluded = $false + DomainName = ConvertFrom-DistinguishedName -ToDomainCN -DistinguishedName $OU.DistinguishedName } if ($Exclusions) { if ($ExclusionsCache[$OU.canonicalName]) {