diff --git a/GPOZaurr.psd1 b/GPOZaurr.psd1 index 131caee..a716508 100644 --- a/GPOZaurr.psd1 +++ b/GPOZaurr.psd1 @@ -18,7 +18,7 @@ } } RequiredModules = @(@{ - ModuleVersion = '0.0.184' + ModuleVersion = '0.0.185' ModuleName = 'PSSharedGoods' Guid = 'ee272aa8-baaa-4edf-9f45-b6d6f7d844fe' }, @{ @@ -26,7 +26,7 @@ ModuleName = 'ADEssentials' Guid = '9fc9fd61-7f11-4f4b-a527-084086f1905f' }, @{ - ModuleVersion = '0.0.114' + ModuleVersion = '0.0.116' ModuleName = 'PSWriteHTML' Guid = 'a7bdf640-f5cb-4acf-9de0-365b322d245c' }, 'CimCmdlets', 'Microsoft.PowerShell.Management', 'Microsoft.PowerShell.Utility') diff --git a/Public/Show-GPOZaurr.ps1 b/Public/Show-GPOZaurr.ps1 index 07961a7..a8f31c7 100644 --- a/Public/Show-GPOZaurr.ps1 +++ b/Public/Show-GPOZaurr.ps1 @@ -65,7 +65,7 @@ New-HTMLTabStyle -BorderRadius 0px -TextTransform capitalize -BackgroundColorActive SlateGrey New-HTMLSectionStyle -BorderRadius 0px -HeaderBackGroundColor Grey -RemoveShadow New-HTMLPanelStyle -BorderRadius 0px -RemoveShadow - New-HTMLTableOption -DataStore JavaScript + New-HTMLTableOption -DataStore JavaScript -BoolAsString New-HTMLTab -Name 'Overview' { if ($Type -contains 'GPOConsistency' -or $Type -contains 'GPOList' -or $null -eq $Type) { New-HTMLSection -Invisible { @@ -151,9 +151,9 @@ } New-HTMLSection -Name 'Group Policies List' { New-HTMLTable -DataTable $GPOSummary -Filtering { - New-HTMLTableCondition -Name 'Empty' -Value $true -BackgroundColor Salmon -TextTransform capitalize -ComparisonType bool - New-HTMLTableCondition -Name 'Linked' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType bool - } + New-HTMLTableCondition -Name 'Empty' -Value $true -BackgroundColor Salmon -TextTransform capitalize -ComparisonType string + New-HTMLTableCondition -Name 'Linked' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType string + } -PagingOptions 10, 20, 30, 40, 50 } New-HTMLSection -Name 'Steps to fix - Empty & Unlinked Group Policies' { New-HTMLContainer { @@ -188,7 +188,7 @@ New-HTMLTableCondition -Name 'Status' -Value "Not available in AD" -BackgroundColor Salmon -ComparisonType string New-HTMLTableCondition -Name 'Status' -Value "Not available on SYSVOL" -BackgroundColor LightCoral -ComparisonType string New-HTMLTableCondition -Name 'Status' -Value "Permissions issue" -BackgroundColor MediumVioletRed -ComparisonType string -Color White - } -PagingLength 10 -PagingOptions 10, 20, 30, 50 + } -PagingOptions 10, 20, 30, 40, 50 } New-HTMLSection -Name 'Steps to fix - Not available on SYSVOL / Active Directory' { New-HTMLContainer { @@ -201,7 +201,7 @@ Install-Module GPOZaurr -Force Import-Module GPOZaurr -Force } -Style powershell - New-HTMLText -Text "Using force makes sure newest version is downloaded from PowerShellGallery regardless of wha is currently installed. Once installed you're ready for next step." + New-HTMLText -Text "Using force makes sure newest version is downloaded from PowerShellGallery regardless of what is currently installed. Once installed you're ready for next step." } New-HTMLWizardStep -Name 'Prepare report' { New-HTMLText -Text "Depending when this report was run you may want to prepare new report before proceeding with removal. To generate new report please use:" @@ -312,19 +312,75 @@ } New-HTMLSection -Name 'Group Policy Permissions Consistency' { New-HTMLTable -DataTable $GPOPermissionsConsistency -Filtering { - New-HTMLTableCondition -Name 'ACLConsistent' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType bool - New-HTMLTableCondition -Name 'ACLConsistentInside' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType bool + New-HTMLTableCondition -Name 'ACLConsistent' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType string + New-HTMLTableCondition -Name 'ACLConsistentInside' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType string + New-HTMLTableCondition -Name 'ACLConsistent' -Value $true -BackgroundColor PaleGreen -TextTransform capitalize -ComparisonType string + New-HTMLTableCondition -Name 'ACLConsistentInside' -Value $true -BackgroundColor PaleGreen -TextTransform capitalize -ComparisonType string New-HTMLTableCondition -Name 'ACLConsistent' -Value 'Not available' -BackgroundColor Crimson -ComparisonType string New-HTMLTableCondition -Name 'ACLConsistentInside' -Value 'Not available' -BackgroundColor Crimson -ComparisonType string - } + } -PagingOptions 10, 20, 30, 40, 50 } New-HTMLSection -Name 'Steps to fix - Permissions Consistency' { New-HTMLContainer { New-HTMLSpanStyle -FontSize 10pt { New-HTMLText -Text 'Following steps will guide you how to fix permissions consistency' New-HTMLWizard { - New-HTMLWizardStep { + New-HTMLWizardStep -Name 'Prepare environment' { + New-HTMLText -Text "To be able to execute actions in automated way please install required modules. Those modules will be installed straight from Microsoft PowerShell Gallery." + New-HTMLCodeBlock -Code { + Install-Module GPOZaurr -Force + Import-Module GPOZaurr -Force + } -Style powershell + New-HTMLText -Text "Using force makes sure newest version is downloaded from PowerShellGallery regardless of what is currently installed. Once installed you're ready for next step." + } + New-HTMLWizardStep -Name 'Prepare report' { + New-HTMLText -Text "Depending when this report was run you may want to prepare new report before proceeding fixing permissions inconsistencies. To generate new report please use:" + New-HTMLCodeBlock -Code { + Show-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrPermissionsInconsistentBefore.html -Verbose -Type GPOConsistency + } + New-HTMLText -Text { + "When executed it will take a while to generate all data and provide you with new report depending on size of environment." + "Once confirmed that data is still showing issues and requires fixing please proceed with next step." + } + New-HTMLText -Text "Alternatively if you prefer working with console you can run: " + New-HTMLCodeBlock -Code { + $GPOOutput = Get-GPOZaurrPermissionConsistency + $GPOOutput | Format-Table # do your actions as desired + } + New-HTMLText -Text "It provides same data as you see in table above just doesn't prettify it for you." + } + New-HTMLWizardStep -Name 'Fix inconsistent permissions' { + New-HTMLText -Text "Following command when executed fixes inconsistent permissions." + New-HTMLText -Text "Make sure when running it for the first time to run it with ", "WhatIf", " parameter as shown below to prevent accidental removal." -FontWeight normal, bold, normal -Color Black, Red, Black + New-HTMLText -Text "Make sure to fill in TargetDomain to match your Domain Admin permission account" + New-HTMLCodeBlock -Code { + Repair-GPOZaurrPermissionConsistency -IncludeDomains "TargetDomain" -Verbose -WhatIf + } + New-HTMLText -TextBlock { + "After execution please make sure there are no errors, make sure to review provided output, and confirm that what is about to be deleted matches expected data. Once happy with results please follow with command: " + } + New-HTMLCodeBlock -Code { + Repair-GPOZaurrPermissionConsistency -LimitProcessing 2 -IncludeDomains "TargetDomain" + } + New-HTMLText -TextBlock { + "This command when executed repairs only first X inconsistent permissions. Use LimitProcessing parameter to prevent mass fixing and increase the counter when no errors occur." + "Repeat step above as much as needed increasing LimitProcessing count till there's nothing left. In case of any issues please review and action accordingly." + } + New-HTMLText -Text "If there's nothing else to be fixed, we can skip to next step step" + } + New-HTMLWizardStep -Name 'Fix inconsistent downlevel permissions' { + New-HTMLText -Text "Unfortunetly this step is manual until automation is developed. " + New-HTMLText -Text "If there are inconsistent permissions found inside GPO one has to fix them manually by going into SYSVOL and making sure inheritance is enabled, and that permissions are consistent across all files." + } + New-HTMLWizardStep -Name 'Verification report' { + New-HTMLText -TextBlock { + "Once cleanup task was executed properly, we need to verify that report now shows no problems." + } + New-HTMLCodeBlock -Code { + Show-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrPermissionsInconsistentAfter.html -Verbose -Type GPOConsistency + } + New-HTMLText -Text "If everything is health in the report you're done! Enjoy rest of the day!" -Color BlueDiamond } } -RemoveDoneStepOnNavigateBack -Theme arrows -ToolbarButtonPosition center }