mirror of
https://github.com/EvotecIT/GPOZaurr.git
synced 2026-08-30 20:29:06 +00:00
Improved Get-GPOZaurrOrganizationalUnit
This commit is contained in:
@@ -4,16 +4,33 @@
|
|||||||
[alias('ForestName')][string] $Forest,
|
[alias('ForestName')][string] $Forest,
|
||||||
[string[]] $ExcludeDomains,
|
[string[]] $ExcludeDomains,
|
||||||
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
|
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
|
||||||
[System.Collections.IDictionary] $ExtendedForestInformation
|
[System.Collections.IDictionary] $ExtendedForestInformation,
|
||||||
|
|
||||||
|
[ValidateSet('OK', 'Unlink', 'Delete')][string[]] $Option
|
||||||
)
|
)
|
||||||
$CachedOu = [ordered] @{}
|
$CachedOu = [ordered] @{}
|
||||||
|
$CachedGPO = [ordered] @{}
|
||||||
$ForestInformation = Get-WinADForestDetails -Extended -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
|
$ForestInformation = Get-WinADForestDetails -Extended -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
|
||||||
|
$GroupPolicies = Get-GPOZaurrAD -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
|
||||||
|
foreach ($GPO in $GroupPolicies) {
|
||||||
|
$CachedGPO[$GPO.GPODistinguishedName] = $GPO
|
||||||
|
}
|
||||||
foreach ($Domain in $ForestInformation.Domains) {
|
foreach ($Domain in $ForestInformation.Domains) {
|
||||||
|
Write-Verbose "Get-GPOZaurrOrganizationalUnit - Processing $($Domain)"
|
||||||
|
$CountTop = 0
|
||||||
$TopOrganizationalUnits = Get-ADOrganizationalUnit -Filter * -Properties LinkedGroupPolicyObjects, DistinguishedName, ntSecurityDescriptor -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0] -SearchScope OneLevel
|
$TopOrganizationalUnits = Get-ADOrganizationalUnit -Filter * -Properties LinkedGroupPolicyObjects, DistinguishedName, ntSecurityDescriptor -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0] -SearchScope OneLevel
|
||||||
foreach ($TopOU in $TopOrganizationalUnits) {
|
foreach ($TopOU in $TopOrganizationalUnits) {
|
||||||
|
$CountTop++
|
||||||
|
Write-Verbose "Get-GPOZaurrOrganizationalUnit - Processing $($Domain) / $($TOPOU.DistinguishedName) [$CountTop/$($TopOrganizationalUnits.Count)]"
|
||||||
# cache top ou
|
# cache top ou
|
||||||
|
if ($TopOU.LinkedGroupPolicyObjects) {
|
||||||
|
$LinkedGPOs = $CachedGPO[$TopOU.LinkedGroupPolicyObjects]
|
||||||
|
} else {
|
||||||
|
$LinkedGPOs = $null
|
||||||
|
}
|
||||||
$CachedOu[$TopOU.DistinguishedName] = [ordered]@{
|
$CachedOu[$TopOU.DistinguishedName] = [ordered]@{
|
||||||
'LinkedGroupPolicyObjects' = $TopOU.LinkedGroupPolicyObjects
|
'LinkedGroupPolicyObjects' = $TopOU.LinkedGroupPolicyObjects
|
||||||
|
'LinkedGroupPolicy' = $LinkedGPOs
|
||||||
'Objects' = [ordered] @{}
|
'Objects' = [ordered] @{}
|
||||||
'ObjectsClasses' = [ordered] @{}
|
'ObjectsClasses' = [ordered] @{}
|
||||||
'ObjectsCountDirect' = 0
|
'ObjectsCountDirect' = 0
|
||||||
@@ -25,10 +42,17 @@
|
|||||||
|
|
||||||
# cache children OUs
|
# cache children OUs
|
||||||
$OUs = Get-ADOrganizationalUnit -SearchScope Subtree -SearchBase $TopOU.DistinguishedName -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0] -Properties LinkedGroupPolicyObjects, DistinguishedName -Filter *
|
$OUs = Get-ADOrganizationalUnit -SearchScope Subtree -SearchBase $TopOU.DistinguishedName -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0] -Properties LinkedGroupPolicyObjects, DistinguishedName -Filter *
|
||||||
|
Write-Verbose "Get-GPOZaurrOrganizationalUnit - Processing $($Domain) / $($TOPOU.DistinguishedName) [$CountTop/$($TopOrganizationalUnits.Count)], found $($OUs.Count) OU's to process."
|
||||||
foreach ($OU in $OUs) {
|
foreach ($OU in $OUs) {
|
||||||
if (-not $CachedOu[$OU.DistinguishedName]) {
|
if (-not $CachedOu[$OU.DistinguishedName]) {
|
||||||
|
if ($OU.LinkedGroupPolicyObjects) {
|
||||||
|
$LinkedGPOs = $CachedGPO[$OU.LinkedGroupPolicyObjects]
|
||||||
|
} else {
|
||||||
|
$LinkedGPOs = $null
|
||||||
|
}
|
||||||
$CachedOu[$OU.DistinguishedName] = [ordered]@{
|
$CachedOu[$OU.DistinguishedName] = [ordered]@{
|
||||||
'LinkedGroupPolicyObjects' = $OU.LinkedGroupPolicyObjects
|
'LinkedGroupPolicyObjects' = $OU.LinkedGroupPolicyObjects
|
||||||
|
'LinkedGroupPolicy' = $LinkedGPOs
|
||||||
'Objects' = [ordered] @{}
|
'Objects' = [ordered] @{}
|
||||||
'ObjectsClasses' = [ordered] @{}
|
'ObjectsClasses' = [ordered] @{}
|
||||||
'ObjectsCountDirect' = 0
|
'ObjectsCountDirect' = 0
|
||||||
@@ -41,6 +65,7 @@
|
|||||||
}
|
}
|
||||||
# Find all objects in those OUs
|
# Find all objects in those OUs
|
||||||
$ObjectsInOu = Get-ADObject -LDAPFilter "(|(ObjectClass=user)(ObjectClass=contact)(ObjectClass=computer)(ObjectClass=group)(objectClass=inetOrgPerson))" -SearchBase $TopOU.distinguishedName -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0]
|
$ObjectsInOu = Get-ADObject -LDAPFilter "(|(ObjectClass=user)(ObjectClass=contact)(ObjectClass=computer)(ObjectClass=group)(objectClass=inetOrgPerson))" -SearchBase $TopOU.distinguishedName -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0]
|
||||||
|
Write-Verbose "Get-GPOZaurrOrganizationalUnit - Processing $($Domain) / $($TOPOU.DistinguishedName) [$CountTop/$($TopOrganizationalUnits.Count)], found $($ObjectsInOu.Count) objects to process."
|
||||||
foreach ($Object in $ObjectsInOu) {
|
foreach ($Object in $ObjectsInOu) {
|
||||||
$Place = ConvertFrom-DistinguishedName -ToOrganizationalUnit -DistinguishedName $Object.DistinguishedName
|
$Place = ConvertFrom-DistinguishedName -ToOrganizationalUnit -DistinguishedName $Object.DistinguishedName
|
||||||
$AllOUs = ConvertFrom-DistinguishedName -ToMultipleOrganizationalUnit -IncludeParent -DistinguishedName $Place
|
$AllOUs = ConvertFrom-DistinguishedName -ToMultipleOrganizationalUnit -IncludeParent -DistinguishedName $Place
|
||||||
@@ -72,6 +97,21 @@
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
if ($Option) {
|
||||||
|
$Found = $false
|
||||||
|
if ($Option -contains 'Ok' -and $Status -contains 'OK') {
|
||||||
|
$Found = $true
|
||||||
|
} elseif ($Option -contains 'Unlink' -and $Status -contains 'Unlink GPO') {
|
||||||
|
$Found = $true
|
||||||
|
} elseif ($Option -contains 'Delete' -and $Status -contains 'Delete OU') {
|
||||||
|
$Found = $true
|
||||||
|
}
|
||||||
|
if (-not $Found) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
[PSCustomObject] @{
|
[PSCustomObject] @{
|
||||||
Organizationalunit = $OU
|
Organizationalunit = $OU
|
||||||
Level = $CachedOu[$OU]['Level']
|
Level = $CachedOu[$OU]['Level']
|
||||||
@@ -82,15 +122,9 @@
|
|||||||
ObjectCountIndirect = $CachedOu[$OU]['ObjectsCountIndirect']
|
ObjectCountIndirect = $CachedOu[$OU]['ObjectsCountIndirect']
|
||||||
ObjectCountTotal = $CachedOu[$OU]['ObjectsCountTotal']
|
ObjectCountTotal = $CachedOu[$OU]['ObjectsCountTotal']
|
||||||
ObjectClasses = $ObjectClasses
|
ObjectClasses = $ObjectClasses
|
||||||
|
GPONames = $CachedOu[$OU]['LinkedGroupPolicy'].DisplayName
|
||||||
Objects = $CachedOu[$OU]['Objects'].Values.Name
|
Objects = $CachedOu[$OU]['Objects'].Values.Name
|
||||||
|
GPO = $CachedOu[$OU]['LinkedGroupPolicy']
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#$Values = Get-WinADOrganizationalUnits
|
|
||||||
#$Values | Format-Table
|
|
||||||
|
|
||||||
<#
|
|
||||||
$T = ([adsisearcher]'(objectcategory=organizationalunit)').FindAll() | Where-Object {
|
|
||||||
-not (-join $_.GetDirectoryEntry().psbase.children) }
|
|
||||||
#>
|
|
||||||
Reference in New Issue
Block a user