diff --git a/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 b/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 index c0495df..f7e9086 100644 --- a/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 +++ b/Private/Invoke.GPOZaurrNetLogonPermissions.ps1 @@ -1,76 +1,98 @@ $GPOZaurrNetLogonPermissions = [ordered] @{ - Name = 'NetLogon Permissions' - Enabled = $true - Data = $null - Execute = { - - $NetLogon = Get-GPOZaurrNetLogon - $NetLogonOwners = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersAdministrators = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersNotAdministrative = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersAdministrative = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersAdministrativeNotAdministrators = [System.Collections.Generic.List[PSCustomObject]]::new() - $NetLogonOwnersToFix = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($File in $Netlogon) { + Name = 'NetLogon Permissions' + Enabled = $true + Data = $null + DataOwner = [System.Collections.Generic.List[PSCustomObject]]::new() + DataNonOwner = [System.Collections.Generic.List[PSCustomObject]]::new() + Execute = { + Get-GPOZaurrNetLogon + } + Processing = { + foreach ($File in $GPOZaurrNetLogonPermissions['Data']) { if ($File.FileSystemRights -eq 'Owner') { - $NetLogonOwners.Add($File) - + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwners']++ if ($File.PrincipalType -eq 'WellKnownAdministrative') { - $NetLogonOwnersAdministrative.Add($File) + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrative']++ } elseif ($File.PrincipalType -eq 'Administrative') { - $NetLogonOwnersAdministrative.Add($File) + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrative']++ } else { - $NetLogonOwnersNotAdministrative.Add($File) + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersNotAdministrative']++ } - if ($File.PrincipalSid -eq 'S-1-5-32-544') { - $NetLogonOwnersAdministrators.Add($File) + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrators']++ } elseif ($File.PrincipalType -in 'WellKnownAdministrative', 'Administrative') { - $NetLogonOwnersAdministrativeNotAdministrators.Add($File) - $NetLogonOwnersToFix.Add($File) + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrativeNotAdministrators']++ + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersToFix']++ } else { - $NetLogonOwnersToFix.Add($File) + $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersToFix']++ } + $GPOZaurrNetLogonPermissions['DataOwner'].Add($File) + } else { + $GPOZaurrNetLogonPermissions['DataNonOwner'].Add($File) } } - } - Processing = { - } - Variables = @{ - + Variables = @{ + NetLogonOwners = 0 + NetLogonOwnersAdministrators = 0 + NetLogonOwnersNotAdministrative = 0 + NetLogonOwnersAdministrative = 0 + NetLogonOwnersAdministrativeNotAdministrators = 0 + NetLogonOwnersToFix = 0 } - Overview = { + Overview = { New-HTMLPanel { New-HTMLText -Text 'Following chart presents ', 'NetLogon Summary' -FontSize 10pt -FontWeight normal, bold New-HTMLList -Type Unordered { - & $Script:GPOConfiguration['NetLogon']['List'] + New-HTMLListItem -Text 'NetLogon Files in Total: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwners'] -FontWeight normal, bold + New-HTMLListItem -Text 'NetLogon BUILTIN\Administrators as Owner: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrators'] -FontWeight normal, bold + New-HTMLListItem -Text "NetLogon Owners requiring change: ", $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersToFix'] -FontWeight normal, bold { + New-HTMLList -Type Unordered { + New-HTMLListItem -Text 'Not Administrative: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersNotAdministrative'] -FontWeight normal, bold + New-HTMLListItem -Text 'Administrative, but not BUILTIN\Administrators: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrativeNotAdministrators'] -FontWeight normal, bold + } + } } -FontSize 10pt #New-HTMLText -FontSize 10pt -Text 'Those problems must be resolved before doing other clenaup activities.' New-HTMLChart { - New-ChartPie -Name 'Correct Owners' -Value $NetLogonOwnersAdministrators.Count -Color LightGreen - New-ChartPie -Name 'Incorrect Owners' -Value $NetLogonOwnersToFix.Count -Color Crimson + New-ChartPie -Name 'Correct Owners' -Value $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrators'] -Color LightGreen + New-ChartPie -Name 'Incorrect Owners' -Value $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersToFix'] -Color Crimson } -Title 'NetLogon Owners' -TitleAlignment center } New-HTMLPanel { } } - Solution = { + Solution = { New-HTMLTab -Name 'NetLogon Owners' { - New-HTMLPanel { - New-HTMLText -TextBlock { - "Following table shows NetLogon file owners. It's important that NetLogon file owners are set to BUILTIN\Administrators (SID: S-1-5-32-544). " - "Owners have full control over the file object. Current owner of the file may be an Administrator but it doesn't guarentee that he will be in the future. " - "That's why as a best-practice it's recommended to change any non-administrative owners to BUILTIN\Administrators, and even Administrative accounts should be replaced with it. " - } -FontSize 10pt - New-HTMLList -Type Unordered { - & $Script:GPOConfiguration['NetLogon']['List'] - } -FontSize 10pt - New-HTMLText -Text "Follow the steps below table to get NetLogon Owners into compliant state." -FontSize 10pt + New-HTMLSection -Invisible { + New-HTMLPanel { + New-HTMLText -TextBlock { + "Following table shows NetLogon file owners. It's important that NetLogon file owners are set to BUILTIN\Administrators (SID: S-1-5-32-544). " + "Owners have full control over the file object. Current owner of the file may be an Administrator but it doesn't guarentee that he will be in the future. " + "That's why as a best-practice it's recommended to change any non-administrative owners to BUILTIN\Administrators, and even Administrative accounts should be replaced with it. " + } -FontSize 10pt + New-HTMLList -Type Unordered { + New-HTMLListItem -Text 'NetLogon Files in Total: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwners'] -FontWeight normal, bold + New-HTMLListItem -Text 'NetLogon BUILTIN\Administrators as Owner: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrators'] -FontWeight normal, bold + New-HTMLListItem -Text "NetLogon Owners requiring change: ", $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersToFix'] -FontWeight normal, bold { + New-HTMLList -Type Unordered { + New-HTMLListItem -Text 'Not Administrative: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersNotAdministrative'] -FontWeight normal, bold + New-HTMLListItem -Text 'Administrative, but not BUILTIN\Administrators: ', $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrativeNotAdministrators'] -FontWeight normal, bold + } + } + } -FontSize 10pt + New-HTMLText -Text "Follow the steps below table to get NetLogon Owners into compliant state." -FontSize 10pt + } + New-HTMLPanel { + New-HTMLChart { + New-ChartPie -Name 'Correct Owners' -Value $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersAdministrators'] -Color LightGreen + New-ChartPie -Name 'Incorrect Owners' -Value $GPOZaurrNetLogonPermissions['Variables']['NetLogonOwnersToFix'] -Color Crimson + } -Title 'NetLogon Owners' -TitleAlignment center + } } New-HTMLSection -Name 'NetLogon Files List' { - New-HTMLTable -DataTable $NetLogonOwners -Filtering { + New-HTMLTable -DataTable $GPOZaurrNetLogonPermissions['DataOwner'] -Filtering { New-HTMLTableCondition -Name 'PrincipalSid' -Value "S-1-5-32-544" -BackgroundColor LightGreen -ComparisonType string New-HTMLTableCondition -Name 'PrincipalSid' -Value "S-1-5-32-544" -BackgroundColor Salmon -ComparisonType string -Operator ne New-HTMLTableCondition -Name 'PrincipalType' -Value "WellKnownAdministrative" -BackgroundColor LightGreen -ComparisonType string -Operator eq @@ -81,7 +103,57 @@ New-HTMLSpanStyle -FontSize 10pt { New-HTMLText -Text 'Following steps will guide you how to fix NetLogon Owners and make them compliant.' New-HTMLWizard { - & $Script:GPOConfiguration['NetLogon']['Wizard'] + New-HTMLWizardStep -Name 'Prepare environment' { + New-HTMLText -Text "To be able to execute actions in automated way please install required modules. Those modules will be installed straight from Microsoft PowerShell Gallery." + New-HTMLCodeBlock -Code { + Install-Module GPOZaurr -Force + Import-Module GPOZaurr -Force + } -Style powershell + New-HTMLText -Text "Using force makes sure newest version is downloaded from PowerShellGallery regardless of what is currently installed. Once installed you're ready for next step." + } + New-HTMLWizardStep -Name 'Prepare report' { + New-HTMLText -Text "Depending when this report was run you may want to prepare new report before proceeding with removal. To generate new report please use:" + New-HTMLCodeBlock -Code { + Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrNetLogonBefore.html -Verbose -Type NetLogon + } + New-HTMLText -TextBlock { + "When executed it will take a while to generate all data and provide you with new report depending on size of environment." + "Once confirmed that data is still showing issues and requires fixing please proceed with next step." + } + New-HTMLText -Text "Alternatively if you prefer working with console you can run: " + New-HTMLCodeBlock -Code { + $NetLogonOutput = Get-GPOZaurrNetLogon -Verbose + $NetLogonOutput | Format-Table + } + New-HTMLText -Text "It provides same data as you see in table above just doesn't prettify it for you." + } + New-HTMLWizardStep -Name 'Set non-compliant file owners to BUILTIN\Administrators' { + New-HTMLText -Text "Following command when executed runs internally command that lists all file owners and if it doesn't match changes it BUILTIN\Administrators. It doesn't change compliant owners." + New-HTMLText -Text "Make sure when running it for the first time to run it with ", "WhatIf", " parameter as shown below to prevent accidental removal." -FontWeight normal, bold, normal -Color Black, Red, Black + + New-HTMLCodeBlock -Code { + Repair-GPOZaurrNetLogonOwner -Verbose -WhatIf + } + New-HTMLText -TextBlock { + "After execution please make sure there are no errors, make sure to review provided output, and confirm that what is about to be changed matches expected data. Once happy with results please follow with command: " + } + New-HTMLCodeBlock -Code { + Repair-GPOZaurrNetLogonOwner -Verbose -LimitProcessing 2 + } + New-HTMLText -TextBlock { + "This command when executed sets new owner only on first X non-compliant NetLogon files. Use LimitProcessing parameter to prevent mass change and increase the counter when no errors occur." + "Repeat step above as much as needed increasing LimitProcessing count till there's nothing left. In case of any issues please review and action accordingly." + } + } + New-HTMLWizardStep -Name 'Verification report' { + New-HTMLText -TextBlock { + "Once cleanup task was executed properly, we need to verify that report now shows no problems." + } + New-HTMLCodeBlock -Code { + Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrNetLogonAfter.html -Verbose -Type NetLogon + } + New-HTMLText -Text "If everything is healthy in the report you're done! Enjoy rest of the day!" -Color BlueDiamond + } } -RemoveDoneStepOnNavigateBack -Theme arrows -ToolbarButtonPosition center } } @@ -89,7 +161,7 @@ } New-HTMLTab -Name 'NetLogon Permissions' { New-HTMLSection -Name 'NetLogon Files List' { - New-HTMLTable -DataTable $Netlogon -Filtering + New-HTMLTable -DataTable $GPOZaurrNetLogonPermissions['DataNonOwner'] -Filtering } } } diff --git a/Private/Script.GPOConfiguration.NetLogon.ps1 b/Private/Script.GPOConfiguration.NetLogon.ps1 deleted file mode 100644 index 6c86c46..0000000 --- a/Private/Script.GPOConfiguration.NetLogon.ps1 +++ /dev/null @@ -1,65 +0,0 @@ -$ScriptGPOConfigurationNetLogon = [ordered] @{ - List = { - New-HTMLListItem -Text 'NetLogon Files in Total: ', $NetLogonOwners.Count -FontWeight normal, bold - New-HTMLListItem -Text 'NetLogon BUILTIN\Administrators as Owner: ', $NetLogonOwnersAdministrators.Count -FontWeight normal, bold - New-HTMLListItem -Text "NetLogon Owners requiring change: ", $NetLogonOwnersToFix.Count -FontWeight normal, bold { - New-HTMLList -Type Unordered { - New-HTMLListItem -Text 'Not Administrative: ', $NetLogonOwnersNotAdministrative.Count -FontWeight normal, bold - New-HTMLListItem -Text 'Administrative, but not BUILTIN\Administrators: ', $NetLogonOwnersAdministrativeNotAdministrators.Count -FontWeight normal, bold - } - } - } - Wizard = { - New-HTMLWizardStep -Name 'Prepare environment' { - New-HTMLText -Text "To be able to execute actions in automated way please install required modules. Those modules will be installed straight from Microsoft PowerShell Gallery." - New-HTMLCodeBlock -Code { - Install-Module GPOZaurr -Force - Import-Module GPOZaurr -Force - } -Style powershell - New-HTMLText -Text "Using force makes sure newest version is downloaded from PowerShellGallery regardless of what is currently installed. Once installed you're ready for next step." - } - New-HTMLWizardStep -Name 'Prepare report' { - New-HTMLText -Text "Depending when this report was run you may want to prepare new report before proceeding with removal. To generate new report please use:" - New-HTMLCodeBlock -Code { - Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrNetLogonBefore.html -Verbose -Type NetLogon - } - New-HTMLText -TextBlock { - "When executed it will take a while to generate all data and provide you with new report depending on size of environment." - "Once confirmed that data is still showing issues and requires fixing please proceed with next step." - } - New-HTMLText -Text "Alternatively if you prefer working with console you can run: " - New-HTMLCodeBlock -Code { - $NetLogonOutput = Get-GPOZaurrNetLogon -Verbose - $NetLogonOutput | Format-Table - } - New-HTMLText -Text "It provides same data as you see in table above just doesn't prettify it for you." - } - New-HTMLWizardStep -Name 'Set non-compliant file owners to BUILTIN\Administrators' { - New-HTMLText -Text "Following command when executed runs internally command that lists all file owners and if it doesn't match changes it BUILTIN\Administrators. It doesn't change compliant owners." - New-HTMLText -Text "Make sure when running it for the first time to run it with ", "WhatIf", " parameter as shown below to prevent accidental removal." -FontWeight normal, bold, normal -Color Black, Red, Black - - New-HTMLCodeBlock -Code { - Repair-GPOZaurrNetLogonOwner -Verbose -WhatIf - } - New-HTMLText -TextBlock { - "After execution please make sure there are no errors, make sure to review provided output, and confirm that what is about to be changed matches expected data. Once happy with results please follow with command: " - } - New-HTMLCodeBlock -Code { - Repair-GPOZaurrNetLogonOwner -Verbose -LimitProcessing 2 - } - New-HTMLText -TextBlock { - "This command when executed sets new owner only on first X non-compliant NetLogon files. Use LimitProcessing parameter to prevent mass change and increase the counter when no errors occur." - "Repeat step above as much as needed increasing LimitProcessing count till there's nothing left. In case of any issues please review and action accordingly." - } - } - New-HTMLWizardStep -Name 'Verification report' { - New-HTMLText -TextBlock { - "Once cleanup task was executed properly, we need to verify that report now shows no problems." - } - New-HTMLCodeBlock -Code { - Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrNetLogonAfter.html -Verbose -Type NetLogon - } - New-HTMLText -Text "If everything is healthy in the report you're done! Enjoy rest of the day!" -Color BlueDiamond - } - } -} \ No newline at end of file diff --git a/Private/Script.GPOZaurrEmptyUnlinked.ps1 b/Private/Script.GPOZaurrEmptyUnlinked.ps1 deleted file mode 100644 index 4affded..0000000 --- a/Private/Script.GPOZaurrEmptyUnlinked.ps1 +++ /dev/null @@ -1,3 +0,0 @@ -$Script:GpoZaurrEmptyUnlinked = @{ - -} \ No newline at end of file diff --git a/Public/Invoke-GPOZaurr.ps1 b/Public/Invoke-GPOZaurr.ps1 index 6c94e5f..eb5a631 100644 --- a/Public/Invoke-GPOZaurr.ps1 +++ b/Public/Invoke-GPOZaurr.ps1 @@ -38,6 +38,7 @@ foreach ($T in $Script:GPOConfiguration.Keys) { $Script:GPOConfiguration[$T].Enabled = $false } + # Lets enable all requested ones foreach ($T in $Type) { $Script:GPOConfiguration[$T].Enabled = $true }