From ad2067c71478a1da1cda8f99238cfc915f598d1a Mon Sep 17 00:00:00 2001 From: Przemyslaw Klys Date: Thu, 5 Nov 2020 16:36:48 +0100 Subject: [PATCH] Update --- Private/Invoke.GPOZaurrAnalysis.ps1 | 4 +- Private/Invoke.GPOZaurrFiles.ps1 | 4 +- Private/Invoke.GPOZaurrList.ps1 | 150 ++++++++++-------- .../Invoke.GPOZaurrNetLogonPermissions.ps1 | 33 +++- Private/Invoke.GPOZaurrOrphans.ps1 | 67 +++++--- Private/Invoke.GPOZaurrPermissions.ps1 | 7 +- Private/Invoke.GPOZaurrPermissionsRoot.ps1 | 4 +- Private/Invoke.GPOZaurrSysVolLegacyFiles.ps1 | 4 +- Public/Invoke-GPOZaurr.ps1 | 92 ++--------- 9 files changed, 187 insertions(+), 178 deletions(-) diff --git a/Private/Invoke.GPOZaurrAnalysis.ps1 b/Private/Invoke.GPOZaurrAnalysis.ps1 index 355d42a..b7e2f18 100644 --- a/Private/Invoke.GPOZaurrAnalysis.ps1 +++ b/Private/Invoke.GPOZaurrAnalysis.ps1 @@ -2,7 +2,9 @@ Name = 'GPO Permissions Consistency' Enabled = $true Data = $null - Execute = { } + Execute = { + $GPOContent = Invoke-GPOZaurrContent + } Processing = { } diff --git a/Private/Invoke.GPOZaurrFiles.ps1 b/Private/Invoke.GPOZaurrFiles.ps1 index 16c0ed5..9ff3a7c 100644 --- a/Private/Invoke.GPOZaurrFiles.ps1 +++ b/Private/Invoke.GPOZaurrFiles.ps1 @@ -2,7 +2,9 @@ Name = 'GPO Permissions Consistency' Enabled = $true Data = $null - Execute = { } + Execute = { + $GPOFiles = Get-GPOZaurrFiles + } Processing = { } diff --git a/Private/Invoke.GPOZaurrList.ps1 b/Private/Invoke.GPOZaurrList.ps1 index ab26db5..56bc44b 100644 --- a/Private/Invoke.GPOZaurrList.ps1 +++ b/Private/Invoke.GPOZaurrList.ps1 @@ -1,69 +1,70 @@ $GPOZaurrList = [ordered] @{ - Name = 'GPO Permissions Consistency' + Name = 'Group Policy Empty & Unlinked' Enabled = $true Data = $null - Execute = { } + Execute = { + Get-GPOZaurr + } Processing = { - $GPOSummary = Get-GPOZaurr - $GPONotLinked = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOLinked = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOEmpty = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPONotEmpty = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOEmptyAndUnlinked = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOEmptyOrUnlinked = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOLinkedButEmpty = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOValid = [System.Collections.Generic.List[PSCustomObject]]::new() - $GPOLinkedButLinkDisabled = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($GPO in $GPOSummary) { + foreach ($GPO in $GPOZaurrList['Data']) { if ($GPO.Linked -eq $false -and $GPO.Empty -eq $true) { # Not linked, Empty - $GPOEmptyAndUnlinked.Add($GPO) - $GPOEmptyOrUnlinked.Add($GPO) - $GPONotLinked.Add($GPO) - $GPOEmpty.Add($GPO) + $GPOZaurrList['Variables']['GPOEmptyAndUnlinked']++ + $GPOZaurrList['Variables']['GPOEmptyOrUnlinked']++ + $GPOZaurrList['Variables']['GPONotLinked']++ + $GPOZaurrList['Variables']['GPOEmpty']++ } elseif ($GPO.Linked -eq $true -and $GPO.Empty -eq $true) { # Linked, But EMPTY - $GPOLinkedButEmpty.Add($GPO) - $GPOEmptyOrUnlinked.Add($GPO) - $GPOEmpty.Add($GPO) - $GPOLinked.Add($GPO) + $GPOZaurrList['Variables']['GPOLinkedButEmpty']++ + $GPOZaurrList['Variables']['GPOEmptyOrUnlinked']++ + $GPOZaurrList['Variables']['GPOEmpty']++ + $GPOZaurrList['Variables']['GPOLinked']++ } elseif ($GPO.Linked -eq $false) { # Not linked, but not EMPTY - $GPONotLinked.Add($GPO) - $GPOEmptyOrUnlinked.Add($GPO) - $GPONotEmpty.Add($GPO) + $GPOZaurrList['Variables']['GPONotLinked']++ + $GPOZaurrList['Variables']['GPOEmptyOrUnlinked']++ + $GPOZaurrList['Variables']['GPONotEmpty']++ } elseif ($GPO.Empty -eq $true) { # Linked, But EMPTY - $GPOEmpty.Add($GPO) - $GPOEmptyOrUnlinked.Add($GPO) - $GPOLinked.Add($GPO) + $GPOZaurrList['Variables']['GPOEmpty']++ + $GPOZaurrList['Variables']['GPOEmptyOrUnlinked']++ + $GPOZaurrList['Variables']['GPOLinked']++ } else { # Linked, not EMPTY - $GPOValid.Add($GPO) - $GPOLinked.Add($GPO) - $GPONotEmpty.Add($GPO) + $GPOZaurrList['Variables']['GPOValid']++ + $GPOZaurrList['Variables']['GPOLinked']++ + $GPOZaurrList['Variables']['GPONotEmpty']++ } if ($GPO.LinksDisabledCount -eq $GPO.LinksCount -and $GPO.LinksCount -gt 0) { - $GPOLinkedButLinkDisabled.Add($GPO) + $GPOZaurrList['Variables']['GPOLinkedButLinkDisabled']++ } } - $GPOTotal = $GPOSummary.Count + $GPOZaurrList['Variables']['GPOTotal'] = $GPOZaurrList['Data'].Count } - Variables = @{ - + Variables = [ordered] @{ + GPONotLinked = 0 + GPOLinked = 0 + GPOEmpty = 0 + GPONotEmpty = 0 + GPOEmptyAndUnlinked = 0 + GPOEmptyOrUnlinked = 0 + GPOLinkedButEmpty = 0 + GPOValid = 0 + GPOLinkedButLinkDisabled = 0 + GPOTotal = 0 } Overview = { New-HTMLPanel { New-HTMLText -Text 'Following chart presents ', 'Linked / Empty and Unlinked Group Policies' -FontSize 10pt -FontWeight normal, bold New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Group Policies total: ', $GPOTotal -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies valid: ", $GPOValid.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies to delete: ", $GPOEmptyOrUnlinked.Count -FontWeight normal, bold { + New-HTMLListItem -Text 'Group Policies total: ', $GPOZaurrList['Variables']['GPOTotal'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies valid: ", $GPOZaurrList['Variables']['GPOValid'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies to delete: ", $GPOZaurrList['Variables']['GPOEmptyOrUnlinked'] -FontWeight normal, bold { New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Group Policies that are unlinked (are not doing anything currently): ', $GPONotLinked.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies that are empty (have no settings): ", $GPOEmpty.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies that are linked, but empty: ", $GPOLinkedButEmpty.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies that are linked, but link disabled: ", $GPOLinkedButLinkDisabled.Count -FontWeight normal, bold + New-HTMLListItem -Text 'Group Policies that are unlinked (are not doing anything currently): ', $GPOZaurrList['Variables']['GPONotLinked'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies that are empty (have no settings): ", $GPOZaurrList['Variables']['GPOEmpty'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies that are linked, but empty: ", $GPOZaurrList['Variables']['GPOLinkedButEmpty'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies that are linked, but link disabled: ", $GPOZaurrList['Variables']['GPOLinkedButLinkDisabled'] -FontWeight normal, bold } } } -FontSize 10pt @@ -72,40 +73,53 @@ New-ChartBarOptions -Type barStacked #New-ChartLegend -Names 'Unlinked', 'Linked', 'Empty', 'Total' -Color Salmon, PaleGreen, PaleVioletRed, PaleTurquoise New-ChartLegend -Names 'Good', 'Bad' -Color PaleGreen, Salmon - #New-ChartBar -Name 'Group Policies' -Value $GPONotLinked.Count, $GPOLinked.Count, $GPOEmpty.Count, $GPOTotal - New-ChartBar -Name 'Linked' -Value $GPOLinked.Count, $GPONotLinked.Count - New-ChartBar -Name 'Empty' -Value $GPONotEmpty.Count, $GPOEmpty.Count - New-ChartBar -Name 'Valid' -Value $GPOValid.Count, $GPOEmptyOrUnlinked.Count + #New-ChartBar -Name 'Group Policies' -Value $GPOZaurrList['Variables']['GPONotLinked'], $GPOZaurrList['Variables']['GPOLinked'], $GPOZaurrList['Variables']['GPOEmpty'], $GPOZaurrList['Variables']['GPOTotal'] + New-ChartBar -Name 'Linked' -Value $GPOZaurrList['Variables']['GPOLinked'], $GPOZaurrList['Variables']['GPONotLinked'] + New-ChartBar -Name 'Empty' -Value $GPOZaurrList['Variables']['GPONotEmpty'], $GPOZaurrList['Variables']['GPOEmpty'] + New-ChartBar -Name 'Valid' -Value $GPOZaurrList['Variables']['GPOValid'], $GPOZaurrList['Variables']['GPOEmptyOrUnlinked'] } -TitleAlignment center } } Solution = { - New-HTMLPanel { - $newHTMLTextSplat = @{ - Text = @( - 'Following table shows a list of group policies.', - 'By using following table you can easily find which GPOs can be safely deleted because those are empty or unlinked or linked, but link disabled.' - ) - FontSize = '10pt' - FontWeight = 'normal', 'bold' - } - New-HTMLText @newHTMLTextSplat - New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Group Policies total: ', $GPOTotal -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies valid: ", $GPOValid.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies to delete: ", $GPOEmptyOrUnlinked.Count -FontWeight normal, bold { - New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Group Policies that are unlinked (are not doing anything currently): ', $GPONotLinked.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies that are empty (have no settings): ", $GPOEmpty.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies that are linked, but empty: ", $GPOLinkedButEmpty.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies that are linked, but link disabled: ", $GPOLinkedButLinkDisabled.Count -FontWeight normal, bold - } + New-HTMLSection -Invisible { + New-HTMLPanel { + $newHTMLTextSplat = @{ + Text = @( + 'Following table shows a list of group policies.', + 'By using following table you can easily find which GPOs can be safely deleted because those are empty or unlinked or linked, but link disabled.' + ) + FontSize = '10pt' + FontWeight = 'normal', 'bold' } - } -FontSize 10pt - New-HTMLText -Text 'All those mentioned Group Policies can be automatically deleted following the steps below the table.' -FontSize 10pt + New-HTMLText @newHTMLTextSplat + New-HTMLList -Type Unordered { + New-HTMLListItem -Text 'Group Policies total: ', $GPOZaurrList['Variables']['GPOTotal'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies valid: ", $GPOZaurrList['Variables']['GPOValid'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies to delete: ", $GPOZaurrList['Variables']['GPOEmptyOrUnlinked'] -FontWeight normal, bold { + New-HTMLList -Type Unordered { + New-HTMLListItem -Text 'Group Policies that are unlinked (are not doing anything currently): ', $GPOZaurrList['Variables']['GPONotLinked'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies that are empty (have no settings): ", $GPOZaurrList['Variables']['GPOEmpty'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies that are linked, but empty: ", $GPOZaurrList['Variables']['GPOLinkedButEmpty'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies that are linked, but link disabled: ", $GPOZaurrList['Variables']['GPOLinkedButLinkDisabled'] -FontWeight normal, bold + } + } + } -FontSize 10pt + New-HTMLText -Text 'All those mentioned Group Policies can be automatically deleted following the steps below the table.' -FontSize 10pt + } + New-HTMLPanel { + New-HTMLChart -Title 'Group Policies Empty & Unlinked' { + New-ChartBarOptions -Type barStacked + #New-ChartLegend -Names 'Unlinked', 'Linked', 'Empty', 'Total' -Color Salmon, PaleGreen, PaleVioletRed, PaleTurquoise + New-ChartLegend -Names 'Good', 'Bad' -Color PaleGreen, Salmon + #New-ChartBar -Name 'Group Policies' -Value $GPOZaurrList['Variables']['GPONotLinked'], $GPOZaurrList['Variables']['GPOLinked'], $GPOZaurrList['Variables']['GPOEmpty'], $GPOZaurrList['Variables']['GPOTotal'] + New-ChartBar -Name 'Linked' -Value $GPOZaurrList['Variables']['GPOLinked'], $GPOZaurrList['Variables']['GPONotLinked'] + New-ChartBar -Name 'Empty' -Value $GPOZaurrList['Variables']['GPONotEmpty'], $GPOZaurrList['Variables']['GPOEmpty'] + New-ChartBar -Name 'Valid' -Value $GPOZaurrList['Variables']['GPOValid'], $GPOZaurrList['Variables']['GPOEmptyOrUnlinked'] + } -TitleAlignment center + } } New-HTMLSection -Name 'Group Policies List' { - New-HTMLTable -DataTable $GPOSummary -Filtering { + New-HTMLTable -DataTable $GPOZaurrList['Data'] -Filtering { New-HTMLTableCondition -Name 'Empty' -Value $true -BackgroundColor Salmon -TextTransform capitalize -ComparisonType string New-HTMLTableCondition -Name 'Linked' -Value $false -BackgroundColor Salmon -TextTransform capitalize -ComparisonType string } -PagingOptions 10, 20, 30, 40, 50 diff --git a/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 b/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 index 0f6a512..c0495df 100644 --- a/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 +++ b/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 @@ -2,7 +2,38 @@ Name = 'NetLogon Permissions' Enabled = $true Data = $null - Execute = { } + Execute = { + + $NetLogon = Get-GPOZaurrNetLogon + $NetLogonOwners = [System.Collections.Generic.List[PSCustomObject]]::new() + $NetLogonOwnersAdministrators = [System.Collections.Generic.List[PSCustomObject]]::new() + $NetLogonOwnersNotAdministrative = [System.Collections.Generic.List[PSCustomObject]]::new() + $NetLogonOwnersAdministrative = [System.Collections.Generic.List[PSCustomObject]]::new() + $NetLogonOwnersAdministrativeNotAdministrators = [System.Collections.Generic.List[PSCustomObject]]::new() + $NetLogonOwnersToFix = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($File in $Netlogon) { + if ($File.FileSystemRights -eq 'Owner') { + $NetLogonOwners.Add($File) + + if ($File.PrincipalType -eq 'WellKnownAdministrative') { + $NetLogonOwnersAdministrative.Add($File) + } elseif ($File.PrincipalType -eq 'Administrative') { + $NetLogonOwnersAdministrative.Add($File) + } else { + $NetLogonOwnersNotAdministrative.Add($File) + } + + if ($File.PrincipalSid -eq 'S-1-5-32-544') { + $NetLogonOwnersAdministrators.Add($File) + } elseif ($File.PrincipalType -in 'WellKnownAdministrative', 'Administrative') { + $NetLogonOwnersAdministrativeNotAdministrators.Add($File) + $NetLogonOwnersToFix.Add($File) + } else { + $NetLogonOwnersToFix.Add($File) + } + } + } + } Processing = { } diff --git a/Private/Invoke.GPOZaurrOrphans.ps1 b/Private/Invoke.GPOZaurrOrphans.ps1 index 2a31dfa..f92ec7f 100644 --- a/Private/Invoke.GPOZaurrOrphans.ps1 +++ b/Private/Invoke.GPOZaurrOrphans.ps1 @@ -1,45 +1,72 @@ $GPOZaurrOrphans = [ordered] @{ - Name = 'GPO Permissions Consistency' + Name = 'Orphaned GPO (SysVol or Active Directory)' Enabled = $true Data = $null - Execute = { } + Execute = { + Get-GPOZaurrBroken + } Processing = { - + #$NotAvailableInAD = [System.Collections.Generic.List[PSCustomObject]]::new() + #$NotAvailableOnSysvol = [System.Collections.Generic.List[PSCustomObject]]::new() + #$NotAvailablePermissionIssue = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($GPO in $GPOZaurrOrphans['Data']) { + if ($GPO.Status -eq 'Not available in AD') { + #$NotAvailableInAD.Add($NotAvailableInAD) + $GPOZaurrOrphans['Variables']['NotAvailableInAD']++ + } elseif ($GPO.Status -eq 'Not available on SYSVOL') { + #$NotAvailableOnSysvol.Add($NotAvailableInAD) + $GPOZaurrOrphans['Variables']['NotAvailableOnSysvol']++ + } elseif ($GPO.Status -eq 'Permissions issue') { + #$NotAvailablePermissionIssue.Add($NotAvailableInAD) + $GPOZaurrOrphans['Variables']['NotAvailablePermissionIssue']++ + } + } } Variables = @{ - + NotAvailableInAD = 0 + NotAvailableOnSysvol = 0 + NotAvailablePermissionIssue = 0 } Overview = { New-HTMLPanel { New-HTMLText -Text 'Following chart presents ', 'Broken / Orphaned Group Policies' -FontSize 10pt -FontWeight normal, bold New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Group Policies on SYSVOL, but no details in AD: ', $NotAvailableInAD.Count -FontWeight normal, bold - New-HTMLListItem -Text 'Group Policies in AD, but no content on SYSVOL: ', $NotAvailableOnSysvol.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies which couldn't be assed due to permissions issue: ", $NotAvailablePermissionIssue.Count -FontWeight normal, bold + New-HTMLListItem -Text 'Group Policies on SYSVOL, but no details in AD: ', $GPOZaurrOrphans['Variables']['NotAvailableInAD'] -FontWeight normal, bold + New-HTMLListItem -Text 'Group Policies in AD, but no content on SYSVOL: ', $GPOZaurrOrphans['Variables']['NotAvailableOnSysvol'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies which couldn't be assed due to permissions issue: ", $GPOZaurrOrphans['Variables']['NotAvailablePermissionIssue'] -FontWeight normal, bold } -FontSize 10pt New-HTMLText -FontSize 10pt -Text 'Those problems must be resolved before doing other clenaup activities.' New-HTMLChart { New-ChartBarOptions -Type barStacked New-ChartLegend -Name 'Not in AD', 'Not on SYSVOL', 'Permissions Issue' -Color Crimson, LightCoral, IndianRed - New-ChartBar -Name 'Orphans' -Value $NotAvailableInAD.Count, $NotAvailableOnSysvol.Count, $NotAvailablePermissionIssue.Count + New-ChartBar -Name 'Orphans' -Value $GPOZaurrOrphans['Variables']['NotAvailableInAD'], $GPOZaurrOrphans['Variables']['NotAvailableOnSysvol'], $GPOZaurrOrphans['Variables']['NotAvailablePermissionIssue'] } -Title 'Broken / Orphaned Group Policies' -TitleAlignment center } } Solution = { - New-HTMLPanel { - New-HTMLText -TextBlock { - "Following table shows list of all group policies and their status in AD and SYSVOL. Due to different reasons it's " - "possible that " - } -FontSize 10pt - New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Group Policies on SYSVOL, but no details in AD: ', $NotAvailableInAD.Count -FontWeight normal, bold - New-HTMLListItem -Text 'Group Policies in AD, but no content on SYSVOL: ', $NotAvailableOnSysvol.Count -FontWeight normal, bold - New-HTMLListItem -Text "Group Policies which couldn't be assed due to permissions issue: ", $NotAvailablePermissionIssue.Count -FontWeight normal, bold - } -FontSize 10pt - New-HTMLText -Text "Follow the steps below table to get Active Directory Group Policies in healthy state." -FontSize 10pt + New-HTMLSection -Invisible { + New-HTMLPanel { + New-HTMLText -TextBlock { + "Following table shows list of all group policies and their status in AD and SYSVOL. Due to different reasons it's " + "possible that " + } -FontSize 10pt + New-HTMLList -Type Unordered { + New-HTMLListItem -Text 'Group Policies on SYSVOL, but no details in AD: ', $GPOZaurrOrphans['Variables']['NotAvailableInAD'] -FontWeight normal, bold + New-HTMLListItem -Text 'Group Policies in AD, but no content on SYSVOL: ', $GPOZaurrOrphans['Variables']['NotAvailableOnSysvol'] -FontWeight normal, bold + New-HTMLListItem -Text "Group Policies which couldn't be assed due to permissions issue: ", $GPOZaurrOrphans['Variables']['NotAvailablePermissionIssue'] -FontWeight normal, bold + } -FontSize 10pt + New-HTMLText -Text "Follow the steps below table to get Active Directory Group Policies in healthy state." -FontSize 10pt + } + New-HTMLPanel { + New-HTMLChart { + New-ChartBarOptions -Type barStacked + New-ChartLegend -Name 'Not in AD', 'Not on SYSVOL', 'Permissions Issue' -Color Crimson, LightCoral, IndianRed + New-ChartBar -Name 'Orphans' -Value $GPOZaurrOrphans['Variables']['NotAvailableInAD'], $GPOZaurrOrphans['Variables']['NotAvailableOnSysvol'], $GPOZaurrOrphans['Variables']['NotAvailablePermissionIssue'] + } -Title 'Broken / Orphaned Group Policies' -TitleAlignment center + } } New-HTMLSection -Name 'Health State of Group Policies' { - New-HTMLTable -DataTable $GPOOrphans -Filtering { + New-HTMLTable -DataTable $GPOZaurrOrphans['Data'] -Filtering { New-HTMLTableCondition -Name 'Status' -Value "Not available in AD" -BackgroundColor Salmon -ComparisonType string New-HTMLTableCondition -Name 'Status' -Value "Not available on SYSVOL" -BackgroundColor LightCoral -ComparisonType string New-HTMLTableCondition -Name 'Status' -Value "Permissions issue" -BackgroundColor MediumVioletRed -ComparisonType string -Color White diff --git a/Private/Invoke.GPOZaurrPermissions.ps1 b/Private/Invoke.GPOZaurrPermissions.ps1 index 48b156e..da9757b 100644 --- a/Private/Invoke.GPOZaurrPermissions.ps1 +++ b/Private/Invoke.GPOZaurrPermissions.ps1 @@ -1,8 +1,11 @@ $GPOZaurrPermissions = [ordered] @{ - Name = 'GPO Permissions Consistency' + Name = 'GPO Permissions' Enabled = $true Data = $null - Execute = { } + Execute = { + $GPOPermissions = Get-GPOZaurrPermission -Type All -IncludePermissionType GpoEditDeleteModifySecurity, GpoEdit, GpoCustom -IncludeOwner + + } Processing = { } diff --git a/Private/Invoke.GPOZaurrPermissionsRoot.ps1 b/Private/Invoke.GPOZaurrPermissionsRoot.ps1 index ecd8037..db68f96 100644 --- a/Private/Invoke.GPOZaurrPermissionsRoot.ps1 +++ b/Private/Invoke.GPOZaurrPermissionsRoot.ps1 @@ -2,7 +2,9 @@ Name = 'GPO Permissions Consistency' Enabled = $true Data = $null - Execute = { } + Execute = { + $GPOPermissionsRoot = Get-GPOZaurrPermissionRoot -SkipNames + } Processing = { } diff --git a/Private/Invoke.GPOZaurrSysVolLegacyFiles.ps1 b/Private/Invoke.GPOZaurrSysVolLegacyFiles.ps1 index 4f0dd77..6feb414 100644 --- a/Private/Invoke.GPOZaurrSysVolLegacyFiles.ps1 +++ b/Private/Invoke.GPOZaurrSysVolLegacyFiles.ps1 @@ -2,7 +2,9 @@ Name = 'SYSVOL Legacy ADM Files' Enabled = $false Data = $null - Execute = { } + Execute = { + $ADMLegacyFiles = Get-GPOZaurrLegacyFiles + } Processing = { } diff --git a/Public/Invoke-GPOZaurr.ps1 b/Public/Invoke-GPOZaurr.ps1 index 943940b..6c94e5f 100644 --- a/Public/Invoke-GPOZaurr.ps1 +++ b/Public/Invoke-GPOZaurr.ps1 @@ -54,86 +54,6 @@ } } - <# - # Gather data - $TimeLog = Start-TimeLog - if ($Type -contains 'GPOOrphans' -or $null -eq $Type) { - #Write-Color -Text "[Info] ", "Processing GPOOrphans" -Color Yellow, White - Write-Verbose -Message "Invoke-GPOZaurr - Processing GPO Sysvol" - $GPOOrphans = Get-GPOZaurrBroken - - $NotAvailableInAD = [System.Collections.Generic.List[PSCustomObject]]::new() - $NotAvailableOnSysvol = [System.Collections.Generic.List[PSCustomObject]]::new() - $NotAvailablePermissionIssue = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($_ in $GPOOrphans) { - if ($_.Status -eq 'Not available in AD') { - $NotAvailableInAD.Add($NotAvailableInAD) - } elseif ($_.Status -eq 'Not available on SYSVOL') { - $NotAvailableOnSysvol.Add($NotAvailableInAD) - } elseif ( $_.Status -eq 'Permissions issue') { - $NotAvailablePermissionIssue.Add($NotAvailableInAD) - } - } - } - if ($Type -contains 'GPOPermissions' -or $null -eq $Type) { - #Write-Color -Text "[Info] ", "Processing GPOPermissions" -Color Yellow, White - Write-Verbose -Message "Invoke-GPOZaurr - Processing GPO Permissions" - $GPOPermissions = Get-GPOZaurrPermission -Type All -IncludePermissionType GpoEditDeleteModifySecurity, GpoEdit, GpoCustom -IncludeOwner - } - if ($Type -contains 'GPOPermissionsRoot' -or $null -eq $Type) { - Write-Verbose -Message "Invoke-GPOZaurr - Processing GPO Permissions Root" - $GPOPermissionsRoot = Get-GPOZaurrPermissionRoot -SkipNames - } - if ($Type -contains 'NetLogon' -or $null -eq $Type) { - $TimeLogSection = Start-TimeLog - Write-Verbose "Get-GPOZaurrNetLogon - Processing NETLOGON Share" - $NetLogon = Get-GPOZaurrNetLogon - $NetLogonOwners = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersAdministrators = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersNotAdministrative = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersAdministrative = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersAdministrativeNotAdministrators = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersToFix = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($File in $Netlogon) { - if ($File.FileSystemRights -eq 'Owner') { - $NetLogonOwners.Add($File) - - if ($File.PrincipalType -eq 'WellKnownAdministrative') { - $NetLogonOwnersAdministrative.Add($File) - } elseif ($File.PrincipalType -eq 'Administrative') { - $NetLogonOwnersAdministrative.Add($File) - } else { - $NetLogonOwnersNotAdministrative.Add($File) - } - - if ($File.PrincipalSid -eq 'S-1-5-32-544') { - $NetLogonOwnersAdministrators.Add($File) - } elseif ($File.PrincipalType -in 'WellKnownAdministrative', 'Administrative') { - $NetLogonOwnersAdministrativeNotAdministrators.Add($File) - $NetLogonOwnersToFix.Add($File) - } else { - $NetLogonOwnersToFix.Add($File) - } - } - } - $TimeLogSectionEnd = Stop-TimeLog -Time $TimeLogSection -Option OneLiner - Write-Verbose "Get-GPOZaurrNetLogon - Processing NETLOGON Share $TimeLogSectionEnd" - } - if ($Type -contains 'GPOAnalysis' -or $null -eq $Type) { - Write-Verbose "Invoke-GPOZaurr - Processing GPO Analysis" - $GPOContent = Invoke-GPOZaurrContent - } - if ($Type -contains 'GPOFiles') { - Write-Verbose "Invoke-GPOZaurr - Processing GPOFiles" - $GPOFiles = Get-GPOZaurrFiles - } - if ($Type -contains 'LegacyADM') { - Write-Verbose "Invoke-GPOZaurr - Processing GPOFiles" - $ADMLegacyFiles = Get-GPOZaurrLegacyFiles - } - $TimeEnd = Stop-TimeLog -Time $TimeLog -Option OneLiner - Write-Verbose "Invoke-GPOZaurr - Data gathering time $TimeEnd" - #> # Generate pretty HTML Write-Verbose "Invoke-GPOZaurr - Generating HTML" New-HTML { @@ -162,11 +82,17 @@ } } } else { - + foreach ($T in $Script:GPOConfiguration.Keys) { + if ($Script:GPOConfiguration[$T].Enabled -eq $true) { + New-HTMLTab -Name $T { + if ($Script:GPOConfiguration[$T]['Data']) { + & $Script:GPOConfiguration[$T]['Solution'] + } + } + } + } } } -Online -ShowHTML -FilePath $FilePath - - Reset-GPOZaurrStatus # This makes sure types are at it's proper status }