diff --git a/Examples/Example-19-TestSysvolDomainControllers.ps1 b/Examples/Example-19-TestSysvolDomainControllers.ps1 index 00d3cab..1dfa1d1 100644 --- a/Examples/Example-19-TestSysvolDomainControllers.ps1 +++ b/Examples/Example-19-TestSysvolDomainControllers.ps1 @@ -1,3 +1,3 @@ Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force -Get-GPOZaurrSysvol -VerifyDomainControllers -Verbose | Format-Table \ No newline at end of file +Get-GPOZaurrSysvol -VerifyDomainControllers -Verbose | Format-Table * \ No newline at end of file diff --git a/GPOZaurr.psd1 b/GPOZaurr.psd1 index 2f69a72..28167b8 100644 --- a/GPOZaurr.psd1 +++ b/GPOZaurr.psd1 @@ -7,7 +7,7 @@ Description = 'Group Policy Eater' FunctionsToExport = 'Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrLink', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrSysvol', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurrPermission', 'New-GPOZaurrWMI', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Set-GPOOwner', 'Set-GPOZaurrOwner' GUID = 'f7d4c9e4-0298-4f51-ad77-e8e3febebbde' - ModuleVersion = '0.0.28' + ModuleVersion = '0.0.29' PowerShellVersion = '5.1' PrivateData = @{ PSData = @{ diff --git a/Private/Test-SysvolFolders.ps1 b/Private/Test-SysvolFolders.ps1 index bb52268..29ca0b0 100644 --- a/Private/Test-SysvolFolders.ps1 +++ b/Private/Test-SysvolFolders.ps1 @@ -39,9 +39,13 @@ if ($null -ne $SysvolHash[$GPO.Id.GUID].FullName) { try { $ACL = Get-Acl -Path $SysvolHash[$GPO.Id.GUID].FullName -ErrorAction Stop + $Owner = $ACL.Owner + $ErrorMessage = '' } catch { - Write-Warning "Get-WinADGPOSysvolFolders - ACL reading failed for $($SysvolHash[$GPO.Id.GUID].FullName) with error: $($_.Exception.Message)" + Write-Warning "Get-GPOZaurrSysvol - ACL reading failed for $($SysvolHash[$GPO.Id.GUID].FullName) with error: $($_.Exception.Message)" $ACL = $null + $Owner = '' + $ErrorMessage = $_.Exception.Message } } else { $ACL = $null @@ -58,7 +62,7 @@ SysvolServer = $Server SysvolStatus = $SysVolStatus Owner = $GPO.Owner - FileOwner = $ACL.Owner + FileOwner = $Owner Id = $GPO.Id.Guid GpoStatus = $GPO.GpoStatus Description = $GPO.Description @@ -67,17 +71,22 @@ UserVersion = $GPO.UserVersion ComputerVersion = $GPO.ComputerVersion WmiFilter = $GPO.WmiFilter + Error = $ErrorMessage } } # Now we need to list thru Sysvol files and fine those that do not exists as GPO and create dummy GPO objects to show orphaned gpos foreach ($_ in $Differences.Keys) { if ($Differences[$_] -eq 'Orphaned GPO') { if ($SysvolHash[$_].BaseName -notcontains 'PolicyDefinitions') { - - if ($null -ne $SysvolHash[$_].FullName) { - $ACL = Get-Acl -Path $SysvolHash[$_].FullName -ErrorAction SilentlyContinue - } else { + try { + $ACL = Get-Acl -Path $SysvolHash[$_].FullName -ErrorAction Stop + $Owner = $ACL.Owner + $ErrorMessage = '' + } catch { + Write-Warning "Get-GPOZaurrSysvol - ACL reading failed for $($SysvolHash[$_].FullName) with error: $($_.Exception.Message)" $ACL = $null + $Owner = $null + $ErrorMessage = $_.Exception.Message } [PSCustomObject] @{ @@ -86,8 +95,8 @@ DomainName = $Domain SysvolServer = $Server SysvolStatus = $Differences[$GPO.Id.Guid] - Owner = $ACL.Owner - FileOwner = $ACL.Owner + Owner = '' + FileOwner = $Owner Id = $_ GpoStatus = 'Orphaned' Description = $null @@ -96,6 +105,7 @@ UserVersion = $null ComputerVersion = $null WmiFilter = $null + Error = $ErrorMessage } } }