mirror of
https://github.com/EvotecIT/GPOZaurr.git
synced 2026-07-26 11:49:17 +00:00
Compare commits
214 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9dfc4d01c3 | |||
| a59a418e98 | |||
| 5a1f7da921 | |||
| 8bdb157330 | |||
| 096c6354d7 | |||
| a3427496e9 | |||
| 9fb76d701f | |||
| 7b4d31781c | |||
| 21bcf2c3a6 | |||
| 46947e0ee9 | |||
| 12d4dfc634 | |||
| 44be1f8d97 | |||
| 864d2cd516 | |||
| 0db67a6d70 | |||
| 189401d62b | |||
| 212f59dd38 | |||
| 7b80dc2d8e | |||
| 5afa032042 | |||
| 00b8586edc | |||
| 08b07de729 | |||
| 3b04efcbc8 | |||
| 051544f353 | |||
| 307dec14df | |||
| 9ec8f5128b | |||
| 7b68b12b02 | |||
| 029225a65c | |||
| ae2a0bd84c | |||
| cb473ae5fa | |||
| e156ef9a24 | |||
| 40cd4dc8ad | |||
| 92f3fcb692 | |||
| bd103a513b | |||
| 8268002ac0 | |||
| 038e4036b9 | |||
| 632f2b0c26 | |||
| 84805cf134 | |||
| d7ebc89d54 | |||
| 4288829415 | |||
| f3d426ba93 | |||
| fef37130bb | |||
| d62b8e47f7 | |||
| 63f1ccd232 | |||
| e61ef74920 | |||
| b63e333fd0 | |||
| 9b0ab0c1c2 | |||
| ee3b25ee88 | |||
| 25c13b54aa | |||
| 2b9faa4e61 | |||
| 42f3053896 | |||
| edcba71e7f | |||
| c8ee2cca56 | |||
| 3b4617af83 | |||
| 6830b1e219 | |||
| 28c55deaa7 | |||
| c757c8281b | |||
| e3e5582696 | |||
| 8e2f4f1552 | |||
| 863c9fabc9 | |||
| 972b51b472 | |||
| 060fb95064 | |||
| fdfc700c6f | |||
| 81eaac3fd1 | |||
| cf9164766e | |||
| 4de2e2a57e | |||
| 663e6058e6 | |||
| f681a5586e | |||
| 4c022bfc16 | |||
| c03f158b77 | |||
| 4824633787 | |||
| 8dc7e5b26d | |||
| 68ed20f3e8 | |||
| df2bacdba7 | |||
| f67ade6341 | |||
| 5855ca2a7c | |||
| b5d69c8a1f | |||
| 32dc6ac661 | |||
| 300d6f63c5 | |||
| 1f43816804 | |||
| 5d50536f5a | |||
| 4da232a1be | |||
| fb5fa00dce | |||
| 970080bfad | |||
| 845c2124bd | |||
| 14d33aa2a6 | |||
| d596fd31fc | |||
| a5cf96398c | |||
| 68921b7fc7 | |||
| ab8443d450 | |||
| 386af088ae | |||
| ad0903e4d9 | |||
| 91ff9da014 | |||
| a262ba531f | |||
| ea7b4f1bd8 | |||
| 09cbd6ca27 | |||
| ddd2139ebd | |||
| ca6e90f399 | |||
| 90931d5c80 | |||
| bfd45c0604 | |||
| 231c2951e0 | |||
| faea9753ae | |||
| 4c49406a6c | |||
| f3d73abed4 | |||
| 620ce6cd61 | |||
| b336f73eda | |||
| bfefb7f943 | |||
| 18226c172a | |||
| 3320b26bd4 | |||
| ec91c69673 | |||
| 31e9b3b4d3 | |||
| d7eedc97b9 | |||
| 42d3ba67dc | |||
| cdc9c1cbc5 | |||
| de28c53842 | |||
| be0be57994 | |||
| 652f553e71 | |||
| 5d2a4725f1 | |||
| 4081a5ead1 | |||
| 796c69de37 | |||
| 9929d827f5 | |||
| 4781b91e23 | |||
| 1ca78cf5f5 | |||
| 768e32cf7e | |||
| 0d43c4e809 | |||
| ac4a9bb43d | |||
| 0abde822f5 | |||
| bf3ec81ea6 | |||
| c0d1f4de1c | |||
| 65719b8c4c | |||
| 096e6983c6 | |||
| ea4ef03e4f | |||
| 61ca7fede4 | |||
| 5cc0db1031 | |||
| d748afda1d | |||
| 9165f23f1b | |||
| 1c700cd27c | |||
| a566d4716a | |||
| 196163cc1f | |||
| a546a023ff | |||
| f5a38b4351 | |||
| 9c668ac869 | |||
| a50dd3cc9a | |||
| 45be7cd432 | |||
| cab639239f | |||
| 5a578278d0 | |||
| 408c4a5530 | |||
| 40905c67ec | |||
| cf8c687e57 | |||
| 580ef74486 | |||
| ebecd56dff | |||
| d5700d873a | |||
| 89c216bb55 | |||
| fe2ff87120 | |||
| 0c756b6f0d | |||
| 3dc5dc7be4 | |||
| d75172e6b1 | |||
| ee12a4f619 | |||
| c96c8285bf | |||
| 8c3ed61142 | |||
| 2934acafeb | |||
| 7203b7f544 | |||
| d22e79b657 | |||
| e07c2dae9a | |||
| 8b1b225ce1 | |||
| 1a54d62b2e | |||
| 352ddc18f3 | |||
| 017007d8c9 | |||
| 4803d3e183 | |||
| 92fcb80005 | |||
| 4985a114dc | |||
| 3ad4a92c66 | |||
| e78db61695 | |||
| 781e95d042 | |||
| 4e1f35f433 | |||
| 74eb14753e | |||
| 1a7bb0273f | |||
| 65eea07b6f | |||
| fe917d70b0 | |||
| 9786186a59 | |||
| b6fc7a676b | |||
| 46e6815314 | |||
| b3e9ddeb64 | |||
| e5f67d8f2e | |||
| 24f81647fa | |||
| cdeb2b4a2d | |||
| f7cf18500d | |||
| 1becfbca60 | |||
| 82c21edcc2 | |||
| e56cf3bde3 | |||
| 996139ab4a | |||
| 5590e3bf31 | |||
| 9db54b338b | |||
| e79d95c0fd | |||
| 8c1f95b1b8 | |||
| 4d9f1e7fba | |||
| 88fb1651a9 | |||
| 9696fb0cab | |||
| bb77785ea8 | |||
| 168919d7d9 | |||
| 5effe5face | |||
| 6d15363caa | |||
| 6c62a11767 | |||
| 61bfe5bd4d | |||
| 5043767e8d | |||
| e4ecafaea5 | |||
| 154e3428e6 | |||
| a6c2ac1226 | |||
| 2b0a395abc | |||
| 04b7242bde | |||
| 48af562bfd | |||
| a5d447b28c | |||
| e649a489bc | |||
| bf3cfb8d21 | |||
| f250453536 | |||
| 34902ab6d8 |
@@ -0,0 +1,8 @@
|
||||
Ignore/*
|
||||
.vs/*
|
||||
.vscode/*
|
||||
Releases/*
|
||||
ReleasesUnpacked/*
|
||||
*.log
|
||||
*.html
|
||||
Artefacts/*
|
||||
@@ -0,0 +1,226 @@
|
||||
Clear-Host
|
||||
|
||||
Import-Module "PSPublishModule" -Force
|
||||
|
||||
Invoke-ModuleBuild -ModuleName 'GPOZaurr' {
|
||||
# Usual defaults as per standard module
|
||||
$Manifest = @{
|
||||
# Version number of this module.
|
||||
ModuleVersion = '1.1.X'
|
||||
# Supported PSEditions
|
||||
CompatiblePSEditions = @('Desktop')
|
||||
# ID used to uniquely identify this module
|
||||
GUID = 'f7d4c9e4-0298-4f51-ad77-e8e3febebbde'
|
||||
# Author of this module
|
||||
Author = 'Przemyslaw Klys'
|
||||
# Company or vendor of this module
|
||||
CompanyName = 'Evotec'
|
||||
# Copyright statement for this module
|
||||
Copyright = "(c) 2011 - $((Get-Date).Year) Przemyslaw Klys @ Evotec. All rights reserved."
|
||||
# Description of the functionality provided by this module
|
||||
Description = 'Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.'
|
||||
# Minimum version of the Windows PowerShell engine required by this module
|
||||
PowerShellVersion = '5.1'
|
||||
# Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export.
|
||||
Tags = @('Windows', 'ActiveDirectory', 'GPO', 'GroupPolicy')
|
||||
#IconUri = 'https://evotec.xyz/wp-content/uploads/2019/02/PSPublishModule.png'
|
||||
|
||||
ProjectUri = 'https://github.com/EvotecIT/GPOZaurr'
|
||||
}
|
||||
New-ConfigurationManifest @Manifest
|
||||
|
||||
New-ConfigurationModule -Type RequiredModule -Name 'PSWriteColor', 'PSSharedGoods', 'ADEssentials', 'PSWriteHTML' -Guid Auto -Version Latest
|
||||
#New-ConfigurationModule -Type ExternalModule -Name 'Microsoft.PowerShell.Utility', 'Microsoft.PowerShell.Management','Microsoft.PowerShell.Security'
|
||||
New-ConfigurationModule -Type ApprovedModule -Name 'PSSharedGoods', 'PSWriteColor', 'Connectimo', 'PSUnifi', 'PSWebToolbox', 'PSMyPassword', 'ADEssentials'
|
||||
|
||||
New-ConfigurationModule -Type ExternalModule -Name @(
|
||||
"CimCmdlets"
|
||||
'Microsoft.PowerShell.Management'
|
||||
'Microsoft.PowerShell.Utility'
|
||||
'Microsoft.PowerShell.Security'
|
||||
)
|
||||
|
||||
New-ConfigurationModuleSkip -IgnoreModuleName @(
|
||||
# this are builtin into PowerShell, so not critical
|
||||
'powershellget'
|
||||
'GroupPolicy'
|
||||
'ScheduledTasks'
|
||||
'ActiveDirectory'
|
||||
'Microsoft.WSMan.Management'
|
||||
'NetConnection'
|
||||
'NetSecurity'
|
||||
'NetTCPIP'
|
||||
) -IgnoreFunctionName @(
|
||||
'Select-Unique'
|
||||
)
|
||||
|
||||
New-ConfigurationCommand -ModuleName 'ActiveDirectory' -CommandName @(
|
||||
'Add-GPOPermission'
|
||||
'Add-GPOZaurrPermission'
|
||||
'Backup-GPOZaurr'
|
||||
'Clear-GPOZaurrSysvolDFSR'
|
||||
'ConvertFrom-CSExtension'
|
||||
'Find-CSExtension'
|
||||
'Get-GPOZaurr'
|
||||
'Get-GPOZaurrAD'
|
||||
'Get-GPOZaurrBackupInformation'
|
||||
'Get-GPOZaurrBroken'
|
||||
'Get-GPOZaurrDictionary'
|
||||
'Get-GPOZaurrDuplicateObject'
|
||||
'Get-GPOZaurrFiles'
|
||||
'Get-GPOZaurrFilesPolicyDefinition'
|
||||
'Get-GPOZaurrFolders'
|
||||
'Get-GPOZaurrInheritance'
|
||||
'Get-GPOZaurrLegacyFiles'
|
||||
'Get-GPOZaurrLink'
|
||||
'Get-GPOZaurrLinkSummary'
|
||||
'Get-GPOZaurrNetLogon'
|
||||
'Get-GPOZaurrOwner'
|
||||
'Get-GPOZaurrPassword'
|
||||
'Get-GPOZaurrPermission'
|
||||
'Get-GPOZaurrPermissionConsistency'
|
||||
'Get-GPOZaurrPermissionRoot'
|
||||
'Get-GPOZaurrPermissionSummary'
|
||||
'Get-GPOZaurrSysvolDFSR'
|
||||
'Get-GPOZaurrWMI'
|
||||
'Invoke-GPOZaurr'
|
||||
#'Invoke-GPOZaurrContent'
|
||||
'Invoke-GPOZaurrPermission'
|
||||
'Invoke-GPOZaurrSupport'
|
||||
'New-GPOZaurrWMI'
|
||||
'Optimize-GPOZaurr'
|
||||
'Remove-GPOPermission'
|
||||
'Remove-GPOZaurr'
|
||||
'Remove-GPOZaurrBroken'
|
||||
'Remove-GPOZaurrDuplicateObject'
|
||||
'Remove-GPOZaurrFolders'
|
||||
'Remove-GPOZaurrLegacyFiles'
|
||||
'Remove-GPOZaurrPermission'
|
||||
'Remove-GPOZaurrWMI'
|
||||
'Repair-GPOZaurrNetLogonOwner'
|
||||
'Repair-GPOZaurrPermissionConsistency'
|
||||
'Restore-GPOZaurr'
|
||||
'Save-GPOZaurrFiles'
|
||||
'Set-GPOOwner'
|
||||
'Set-GPOZaurrOwner'
|
||||
'Find-GPO'
|
||||
'Get-GPOZaurrFilesPolicyDefinitions'
|
||||
'Get-GPOZaurrSysvol'
|
||||
'Remove-GPOZaurrOrphaned'
|
||||
'Show-GPO'
|
||||
'Show-GPOZaurr'
|
||||
)
|
||||
New-ConfigurationCommand -ModuleName 'GroupPolicy' -CommandName @(
|
||||
'Add-GPOPermission'
|
||||
'Add-GPOZaurrPermission'
|
||||
'Backup-GPOZaurr'
|
||||
'Clear-GPOZaurrSysvolDFSR'
|
||||
'ConvertFrom-CSExtension'
|
||||
'Find-CSExtension'
|
||||
'Get-GPOZaurr'
|
||||
'Get-GPOZaurrAD'
|
||||
'Get-GPOZaurrBackupInformation'
|
||||
'Get-GPOZaurrBroken'
|
||||
'Get-GPOZaurrDictionary'
|
||||
'Get-GPOZaurrDuplicateObject'
|
||||
'Get-GPOZaurrFiles'
|
||||
'Get-GPOZaurrFilesPolicyDefinition'
|
||||
'Get-GPOZaurrFolders'
|
||||
'Get-GPOZaurrInheritance'
|
||||
'Get-GPOZaurrLegacyFiles'
|
||||
'Get-GPOZaurrLink'
|
||||
'Get-GPOZaurrLinkSummary'
|
||||
'Get-GPOZaurrNetLogon'
|
||||
'Get-GPOZaurrOwner'
|
||||
'Get-GPOZaurrPassword'
|
||||
'Get-GPOZaurrPermission'
|
||||
'Get-GPOZaurrPermissionConsistency'
|
||||
'Get-GPOZaurrPermissionRoot'
|
||||
'Get-GPOZaurrPermissionSummary'
|
||||
'Get-GPOZaurrSysvolDFSR'
|
||||
'Get-GPOZaurrWMI'
|
||||
'Invoke-GPOZaurr'
|
||||
#'Invoke-GPOZaurrContent'
|
||||
'Invoke-GPOZaurrPermission'
|
||||
'Invoke-GPOZaurrSupport'
|
||||
'New-GPOZaurrWMI'
|
||||
'Optimize-GPOZaurr'
|
||||
'Remove-GPOPermission'
|
||||
'Remove-GPOZaurr'
|
||||
'Remove-GPOZaurrBroken'
|
||||
'Remove-GPOZaurrDuplicateObject'
|
||||
'Remove-GPOZaurrFolders'
|
||||
'Remove-GPOZaurrLegacyFiles'
|
||||
'Remove-GPOZaurrPermission'
|
||||
'Remove-GPOZaurrWMI'
|
||||
'Repair-GPOZaurrNetLogonOwner'
|
||||
'Repair-GPOZaurrPermissionConsistency'
|
||||
'Restore-GPOZaurr'
|
||||
'Save-GPOZaurrFiles'
|
||||
'Set-GPOOwner'
|
||||
'Set-GPOZaurrOwner'
|
||||
'Find-GPO'
|
||||
'Get-GPOZaurrFilesPolicyDefinitions'
|
||||
'Get-GPOZaurrSysvol'
|
||||
'Remove-GPOZaurrOrphaned'
|
||||
'Show-GPO'
|
||||
'Show-GPOZaurr'
|
||||
)
|
||||
|
||||
|
||||
$ConfigurationFormat = [ordered] @{
|
||||
RemoveComments = $true
|
||||
RemoveEmptyLines = $true
|
||||
|
||||
PlaceOpenBraceEnable = $true
|
||||
PlaceOpenBraceOnSameLine = $true
|
||||
PlaceOpenBraceNewLineAfter = $true
|
||||
PlaceOpenBraceIgnoreOneLineBlock = $false
|
||||
|
||||
PlaceCloseBraceEnable = $true
|
||||
PlaceCloseBraceNewLineAfter = $true
|
||||
PlaceCloseBraceIgnoreOneLineBlock = $false
|
||||
PlaceCloseBraceNoEmptyLineBefore = $true
|
||||
|
||||
UseConsistentIndentationEnable = $true
|
||||
UseConsistentIndentationKind = 'space'
|
||||
UseConsistentIndentationPipelineIndentation = 'IncreaseIndentationAfterEveryPipeline'
|
||||
UseConsistentIndentationIndentationSize = 4
|
||||
|
||||
UseConsistentWhitespaceEnable = $true
|
||||
UseConsistentWhitespaceCheckInnerBrace = $true
|
||||
UseConsistentWhitespaceCheckOpenBrace = $true
|
||||
UseConsistentWhitespaceCheckOpenParen = $true
|
||||
UseConsistentWhitespaceCheckOperator = $true
|
||||
UseConsistentWhitespaceCheckPipe = $true
|
||||
UseConsistentWhitespaceCheckSeparator = $true
|
||||
|
||||
AlignAssignmentStatementEnable = $true
|
||||
AlignAssignmentStatementCheckHashtable = $true
|
||||
|
||||
UseCorrectCasingEnable = $true
|
||||
}
|
||||
# format PSD1 and PSM1 files when merging into a single file
|
||||
# enable formatting is not required as Configuration is provided
|
||||
New-ConfigurationFormat -ApplyTo 'OnMergePSM1', 'OnMergePSD1' -Sort None @ConfigurationFormat
|
||||
# format PSD1 and PSM1 files within the module
|
||||
# enable formatting is required to make sure that formatting is applied (with default settings)
|
||||
New-ConfigurationFormat -ApplyTo 'DefaultPSD1', 'DefaultPSM1' -EnableFormatting -Sort None
|
||||
# when creating PSD1 use special style without comments and with only required parameters
|
||||
New-ConfigurationFormat -ApplyTo 'DefaultPSD1', 'OnMergePSD1' -PSD1Style 'Minimal'
|
||||
# configuration for documentation, at the same time it enables documentation processing
|
||||
New-ConfigurationDocumentation -Enable:$false -StartClean -UpdateWhenNew -PathReadme 'Docs\Readme.md' -Path 'Docs'
|
||||
|
||||
New-ConfigurationImportModule -ImportSelf
|
||||
|
||||
New-ConfigurationBuild -Enable:$true -SignModule -MergeModuleOnBuild -MergeFunctionsFromApprovedModules -CertificateThumbprint '483292C9E317AA13B07BB7A96AE9D1A5ED9E7703'
|
||||
|
||||
# New-ConfigurationTest -TestsPath "$PSScriptRoot\..\Tests" -Enable
|
||||
|
||||
New-ConfigurationArtefact -Type Unpacked -Enable -Path "$PSScriptRoot\..\Artefacts\Unpacked" -AddRequiredModules
|
||||
New-ConfigurationArtefact -Type Packed -Enable -Path "$PSScriptRoot\..\Artefacts\Packed" -ArtefactName '<ModuleName>.v<ModuleVersion>.zip' -AddRequiredModules
|
||||
|
||||
# options for publishing to github/psgallery
|
||||
#New-ConfigurationPublish -Type PowerShellGallery -FilePath 'C:\Support\Important\PowerShellGalleryAPI.txt' -Enabled:$true
|
||||
#New-ConfigurationPublish -Type GitHub -FilePath 'C:\Support\Important\GitHubAPI.txt' -UserName 'EvotecIT' -Enabled:$true
|
||||
} -ExitCode
|
||||
+571
@@ -0,0 +1,571 @@
|
||||
# GPOZaurr Release History
|
||||
|
||||
## 1.1.6
|
||||
- Improve HTML reports with `ScrollX`
|
||||
- Improve HTML reports by hiding some unnesecary columns
|
||||
- Added `SizeMB` and `Size` to reports around files/GPOs which could help analyze performance issues
|
||||
|
||||
## 1.1.5 - 2024.07.06
|
||||
* Added or improved help on all functions. by @neztach in https://github.com/EvotecIT/GPOZaurr/pull/56
|
||||
|
||||
### New Contributors
|
||||
* @neztach made their first contribution in https://github.com/EvotecIT/GPOZaurr/pull/56
|
||||
|
||||
## 1.1.4 - 2024.06.11
|
||||
- Small improvements & fixes
|
||||
|
||||
## 1.1.3 - 2024.04.16
|
||||
- Fixes report showing unessecary `WhatIf` [#53](https://github.com/EvotecIT/GPOZaurr/issues/53)
|
||||
|
||||
## 1.1.2 - 2024.04.16
|
||||
- Fixes `Forest` parameter for GPOAnalysis [#54](https://github.com/EvotecIT/GPOZaurr/issues/54)
|
||||
|
||||
## 1.1.1 - 2024.02.07
|
||||
- Force specific DC for `Invoke-GPOZaurrContent`
|
||||
- Update to Duplicate Object detection for error handling [#52](https://github.com/EvotecIT/GPOZaurr/issues/52)
|
||||
|
||||
## 1.1.0 - 2024.04.02
|
||||
- Improve `Invoke-GPOZaurr` - by adding `GPOName` and `GPOGUID` parameters, providing ability to analyse single/multiple GPOs
|
||||
- Those parameters are only applicable to `GPOAnalysis`,`GPOBrokenPartially` for now (need to be expanded further)
|
||||
- Improve `Invoke-GPOZaurrContent` by allowing `GPOName` and `GPOGUID` parameters, providing ability to analyse single/multiple GPOs
|
||||
- Small verbose message improvement for `Export-GPOZaurrContent`
|
||||
- Added `Get-GPOZaurrMissingFiles` to detect missing files for GPOs
|
||||
- Added `Invoke-GPOZaurr` - type `GPOBrokenPartially` to detect missing files for GPOs
|
||||
- Improve detection of empty GPOs by including check for GPF files
|
||||
- Added `FilesCount` to `Get-GPOZaurr` to detect number of files in GPO
|
||||
|
||||
## 1.0.0 - 2023.09.17
|
||||
- `Get-GPOZaurrUpdates` fix small typo
|
||||
- `Get-GPOZaurrAD` improve performance a bit
|
||||
- `Get-GPOZaurrAD` changed pipeline into standard foreach to improve performance and potential problems for large domains
|
||||
- Added `Get-GPOZaurrRedirect` to detect if GPO path was redirected (security issue)
|
||||
- Added `GPORedirect` report type to `Invoke-GPOZaurr` to detect if GPO path was redirected (security issue)
|
||||
|
||||
## 0.0.160 - 2023.05.26
|
||||
- Fixes `Remove-GPOZaurr` limit processing feature which would not stop in some cases
|
||||
|
||||
## 0.0.159
|
||||
- Fixes [#44 Extra spaces in property name 'Id' in Get-GPOZaurrPermissionConsistency?](https://github.com/EvotecIT/GPOZaurr/issues/44)
|
||||
- Fixes typos [#43](https://github.com/EvotecIT/GPOZaurr/pull/43)
|
||||
|
||||
## 0.0.158 - 2023.03.07
|
||||
- Improve detection of empty OUs by including AD printers.
|
||||
|
||||
## 0.0.157 - 2022.12.16
|
||||
- Resolves *Group Policy Content - GPO Subfolders for Google Chrome* [#38](https://github.com/EvotecIT/GPOZaurr/issues/38)
|
||||
- Resolves *Filename processing issue* [#37](https://github.com/EvotecIT/GPOZaurr/issues/37)
|
||||
|
||||
## 0.0.156 - 2022.12.04
|
||||
- Fixes `Get-LocalComputerSid - Error: You cannot call a method on a null-valued expression` in some rare cases [#34](https://github.com/EvotecIT/GPOZaurr/issues/34)
|
||||
|
||||
## 0.0.155 - 2022.10.27
|
||||
- Fixes `Invoke-GPOZaurr` SplitReports functionality (again! and again!) [#35](https://github.com/EvotecIT/GPOZaurr/issues/35)
|
||||
|
||||
## 0.0.154 - 2022.10.20
|
||||
- Fixes `Invoke-GPOZaurr` SplitReports functionality (again!) [#33](https://github.com/EvotecIT/GPOZaurr/issues/33)
|
||||
- Fixes Sysvol property in object returned by Get-GPOZaurrPermissionConsistency contains whitespace [#31](https://github.com/EvotecIT/GPOZaurr/issues/31)
|
||||
|
||||
## 0.0.153 - 2022.09.12
|
||||
- Fixes `Invoke-GPOZaurr` SplitReports functionality that would generate main report anyways.
|
||||
|
||||
## 0.0.152 - 2022.09.11
|
||||
- ℹ️ Improved `Invoke-GPOZaurr` - disable deprecated reports if user doesn't ask for them but asks for all reports to be generated. Those reports are now disabled by default: GPOPermissionsAdministrative,GPOPermissionsRead,GPOPermissionsRoot,GPOPermissionsUnknown
|
||||
- ℹ️ Improved `Invoke-GPOZaurr` SplitReports functionality to start creating HTML reports every report
|
||||
- Add `Export-GPOZaurrContent` to simplify quick export of all XML/HTML reports from GPO
|
||||
|
||||
## 0.0.151 - 2022.07.26
|
||||
- ℹ️ Improved `Invoke-GPOZaurr` by adding `SplitReports` functionality. This will allow you to split the reports into multiple files with a single request.
|
||||
- ℹ️ Improved `Get-GPOZaurrInheritance` with some error handling
|
||||
|
||||
## 0.0.150 - 2021.12.06
|
||||
- ℹ️ Improves `GPOUpdates` report from `Invoke-GPOZaurr` - additional property
|
||||
## 0.0.149 - 2021.12.05
|
||||
- ℹ️ Improved docs
|
||||
## 0.0.148 - 2021.12.05
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOOrganizationalUnit` - excludes default redirected computers/users OUs [#30](https://github.com/EvotecIT/GPOZaurr/issues/30)
|
||||
- ☑ Improved `Get-GPOZaurrOrganizationalUnit` - excludes default redirected computers/users OUs as per [#30](https://github.com/EvotecIT/GPOZaurr/issues/30)
|
||||
## 0.0.147 - 2021.12.03
|
||||
- 📃 Updates documentation
|
||||
## 0.0.146 - 2021.11.02
|
||||
- ℹ️ Improves `GPOUpdates` report from `Invoke-GPOZaurr` - should be 7 days, not 14 days
|
||||
## 0.0.145 - 2021.11.02
|
||||
- ℹ️ Improves `GPOUpdates` report from `Invoke-GPOZaurr` by fixing conditional formatting
|
||||
## 0.0.144 - 2021.10.24
|
||||
- ℹ️ Improves `Get-GPOZaurrUpdates`
|
||||
- Adds `GPOUpdates` report to `Invoke-GPOZaurr`
|
||||
## 0.0.143 - 2021.10.19
|
||||
- ℹ️ Improves `Get-GPOZaurrUpdates` with more verbose messages
|
||||
## 0.0.142 - 2021.10.18
|
||||
- 🐛 Fixes `Get-GPOZaurrUpdates` when GPO is not linked
|
||||
## 0.0.141 - 2021.10.17
|
||||
- 🛑 Removed property from `Get-GPOZaurrAD` - `FunctionalityVersion`
|
||||
- ➕ Added property to `Get-GPOZaurrAD` - `Owner`
|
||||
- ➕ Added ability to choose date ranges for `Get-GPOZaurrAD`
|
||||
- ➕ Added `Get-GPOZaurrUpdates` which shows last gpos added to forest
|
||||
## 0.0.140 - 2021.08.24
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOAnalysis` - added folder redirection type - [tnx PatrickOnGit](https://github.com/EvotecIT/GPOZaurr/pull/24)
|
||||
## 0.0.139 - 2021.08.19
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOOrganizationalUnit` - adding RootLevel information
|
||||
## 0.0.138 - 2021.08.18
|
||||
- 🐛 Fix for exclusions using GUID with brackets for Invoke-GPOZaurr `GPOList` and related options
|
||||
## 0.0.137 - 2021.08.17
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOOrganizationalUnit` - moving delete of OU as non-mandatory option
|
||||
## 0.0.136 - 2021.08.17
|
||||
- ☑ Improved wording
|
||||
## 0.0.135 - 2021.08.17
|
||||
- ☑ Improved exclusions
|
||||
## 0.0.134 - 2021.08.16
|
||||
- ☑ Improved exclusions for email use
|
||||
## 0.0.133 - 2021.08.16
|
||||
- ☑ Improved exclusions for email use
|
||||
## 0.0.132 - 2021.08.16
|
||||
- ☑ Improved exclusions for email use
|
||||
## 0.0.131 - 2021.08.16
|
||||
- ☑ Improved exclusions for email use
|
||||
## 0.0.130 - 2021.08.13
|
||||
- 💡 Updated HTML to new version of `PSWriteHTML` that fixes complains about `SearchBuilder` option
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOOrganizationalUnit` with exclusions
|
||||
|
||||
```powershell
|
||||
Invoke-GPOZaurr -Type GPOOrganizationalUnit -Online -FilePath $PSScriptRoot\Reports\GPOZaurrOU.html -Exclusions @(
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
'*DC=ad,DC=evotec,DC=pl'
|
||||
)
|
||||
```
|
||||
|
||||
- ☑ Improved `Get-GPOZaurrOrganizationalUnit` with exclusions
|
||||
|
||||
```powershell
|
||||
Get-GPOZaurrOrganizationalUnit -Verbose -ExcludeOrganizationalUnit @(
|
||||
'*,OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
) | Format-Table
|
||||
```
|
||||
|
||||
- ☑ Improved `Remove-GPOZaurrLinkEmptyOU` with exclusions
|
||||
|
||||
```powershell
|
||||
$Exclude = @(
|
||||
"OU=Groups,OU=Production,DC=ad,DC=evotec,DC=pl"
|
||||
"OU=Test \, OU,OU=ITR02,DC=ad,DC=evotec,DC=xyz"
|
||||
)
|
||||
|
||||
Remove-GPOZaurrLinkEmptyOU -Verbose -LimitProcessing 3 -WhatIf -ExcludeOrganizationalUnit $Exclude
|
||||
```
|
||||
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOOwners` with exclusions
|
||||
|
||||
```powershell
|
||||
Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurrGPOOwners.html -Type GPOOwners -Online -Exclusions @(
|
||||
'EVOTEC\przemyslaw.klys'
|
||||
)
|
||||
```
|
||||
|
||||
- ☑ Improved `Set-GPOZaurrOwner` with exclusions/approved owners
|
||||
|
||||
```powershell
|
||||
Set-GPOZaurrOwner -Type All -Verbose -LimitProcessing 2 -WhatIf -IncludeDomains 'ad.evotec.xyz' -ApprovedOwner @(
|
||||
'EVOTEC\przemyslaw.klys'
|
||||
)
|
||||
```
|
||||
|
||||
- ☑ Improved `Get-GPOZaurrOwner` with exclusions/approved owners
|
||||
|
||||
```powershell
|
||||
$T = Get-GPOZaurrOwner -Verbose -IncludeSysvol -ApprovedOwner @('EVOTEC\przemyslaw.klys')
|
||||
$T | Format-Table *
|
||||
```
|
||||
|
||||
- ☑ Improved `Get-GPOZaurr` with exclusions and support for GUID, strings
|
||||
|
||||
```powershell
|
||||
$GPOS = Get-GPOZaurr -ExcludeGroupPolicies {
|
||||
Skip-GroupPolicy -Name 'de14_usr_std'
|
||||
Skip-GroupPolicy -Name 'de14_usr_std' -DomaiName 'ad.evotec.xyz'
|
||||
Skip-GroupPolicy -Name 'All | Trusted Websites' #-DomaiName 'ad.evotec.xyz'
|
||||
'{D39BF08A-87BF-4662-BFA0-E56240EBD5A2}'
|
||||
'COMPUTERS | Enable Sets'
|
||||
}
|
||||
$GPOS | Format-Table -AutoSize *
|
||||
```
|
||||
|
||||
- ☑ Improved `Invoke-GPOZaurr` with exclusions and support for GUID, strings
|
||||
|
||||
```powershell
|
||||
Invoke-GPOZaurr -Type GPOList -Exclusions {
|
||||
Skip-GroupPolicy -Name 'All | Trusted Websites' -DomaiName 'ad.evotec.xyz'
|
||||
'{D39BF08A-87BF-4662-BFA0-E56240EBD5A2}'
|
||||
'COMPUTERS | Enable Sets'
|
||||
}
|
||||
```
|
||||
|
||||
## 0.0.129 - 2021.08.06
|
||||
- Added `Get-GPOZaurrOrganizationalUnit` and added `GPOOrganizationalUnit` in `Invoke-GPOZaurr` (preview)
|
||||
- Added `Remove-GPOZaurrLinkEmptyOU` which allows removing links from Empty OUs (preview)
|
||||
- Small update to parameter sets for `Set-GPOZaurrOwner`
|
||||
## 0.0.128 - 2021.05.26
|
||||
- ☑ Improved `Invoke-GPOZaurrContent` - type `PublicKeyPoliciesCertificates` - added more certificate information
|
||||
- ☑ Improved `Invoke-GPOZaurr` - type `GPOAnalysis` - added more certificate information
|
||||
## 0.0.128 Alpha 1 - 2021.05.17
|
||||
- 🐛 Fixes errors when normalizing properties [#17](https://github.com/EvotecIT/GPOZaurr/issues/17)
|
||||
## 0.0.127 - 2021.04.15
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Report `GPOList` - moved description closer to statuses
|
||||
- ☑ Improved `Get-GPOZaurr` - moved description closer to statuses
|
||||
## 0.0.126 - 2021.04.12
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Report `GPOBlockedInheritance` - hidden DistinguishedName, fixed some small typos
|
||||
## 0.0.125 - 2021.04.11
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Report `GPOBlockedInheritance` - small fixes
|
||||
## 0.0.124 - 2021.04.11
|
||||
- ☑ Added `SearchBuilder` to all tables
|
||||
- ☑ Automatically joins arrays in tables in `Invoke-GPOZaurr`
|
||||
- ☑ Improved `Get-GPOZaurrInheritance` with Exclusions and some help information
|
||||
- ☑ Improved `Invoke-GPOZaurr` with some Exclusions
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- 🔥 Report `GPOBlockedInheritance` - heavily improved functionality and data
|
||||
## 0.0.123 - 2021.03.21
|
||||
- ☑ Fixes `Get-GPOZaurrLinkSummary`
|
||||
## 0.0.122 - 2021.02.11
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Report `GPOAnalysis` - added `WindowsFirewallRules`,`WindowsFirewallProfiles`,`WindowsFirewallConnectionSecurityAuthentication`,`WindowsFirewallConnectionSecurityRules`
|
||||
- ☑ Improved `Invoke-GPOZaurrContent` as mentioned above for `GPOAnalysis`
|
||||
## 0.0.121 - 2021.02.10
|
||||
- ☑ Improvement to `Get-GPOZaurr` - added description [#13](https://github.com/EvotecIT/GPOZaurr/issues/13)
|
||||
- ☑ Improvement to `Invoke-GPOZaurr -Type GPOList` - added description [#13](https://github.com/EvotecIT/GPOZaurr/issues/13)
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Report GPOAnalysis - added `FolderRedirection`
|
||||
- ☑ Report GPOAnalysis - renamed `FolderRedirection` to `FolderRedirectionPolicy`
|
||||
- ☑ Improved `Invoke-GPOZaurrContent` as mentioned above for `GPOAnalysis`
|
||||
## 0.0.120 - 2021.02.10
|
||||
- ☑ Improvement to `Get-GPOZaurr` to warn if there is potential issue with EMPTY (which can happen on non-english system)
|
||||
- ☑ In such case GPOZaurr will asses EMPTY or not using old method which doesn't detect all EMPTY cases but shouldn't provide false positives
|
||||
## 0.0.119
|
||||
- Broken release - weird
|
||||
## 0.0.118 - 2021.02.09
|
||||
- ☑ Added information where the report is saved
|
||||
- ☑ Small improvement to `Get-GPOZaurr` to exlicitly define variable types
|
||||
## 0.0.117 - 2021.02.09
|
||||
- ☑ Small fix to `Get-GPOZaurr` to exclude GPOList.xml which is used in offline mode by `Save-GPOZaurrFiles`
|
||||
## 0.0.116 - 2021.02.08
|
||||
- ☑ Improved `Remove-GPOZaurrBroken` to handle ObjectClass problem, and removed reduntant check
|
||||
## 0.0.115 - 2021.02.07
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ `GPOList` - clarified some texts, changed 7 days to 30 days as default
|
||||
- ☑ `NetLogonPermissions` - fixed missing text
|
||||
- ☑ Fixes `Get-GPOZaurrNetLogon` error on empty Owner - [#9](https://github.com/EvotecIT/GPOZaurr/issues/9)
|
||||
## 0.0.114 - 2021.01.27
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ HTML now uses offline mode by default (no CDN) - increase in size of HTML up to 3MB
|
||||
- ☑ Using Online switch forces use of CDN - smaller files. For example `Invoke-GPOZaurr -Type GPOList -Online`
|
||||
- [ ] Improved `Invoke-GPOZaurrSupport`
|
||||
- ☑ HTML now uses offline mode by default (no CDN) - increase in size of HTML up to 3MB
|
||||
- ☑ Using Online switch forces use of CDN - smaller files. For example `Invoke-GPOZaurrSupport -Online`
|
||||
- ☑ Removed parameter Offline, added parameter Online
|
||||
- ☑ The cmdlet is not really production ready. It's work in progress
|
||||
## 0.0.113 - 2021.01.25
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Report GPOAnalysis - added WindowsTimeService
|
||||
- ☑ Improved `Invoke-GPOZaurrContent`
|
||||
- ☑ Added `WindowsTimeService` type
|
||||
## 0.0.112 - 2021.01.25
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
## 0.0.111 - 2021.01.24
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
## 0.0.110 - 2021.01.22
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
## 0.0.109 - 2021.01.11
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
## 0.0.108 - 2021.01.11
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Improved `GPOConsistency`
|
||||
## 0.0.107 - 2021.01.11
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
## 0.0.106 - 2021.01.11
|
||||
- ☑ Improved `Invoke-GPOZaurrContent`
|
||||
## 0.0.105 - 2021.01.05
|
||||
- ☑ Improved `Get-GPOZaurr`
|
||||
- ☑ Improved report `GPOBrokenLink`
|
||||
## 0.0.104 - 2021.01.04
|
||||
- ☑ Improved `Get-GPOZaurrBrokenLink`
|
||||
- ☑ Improved `Repair-GPOZaurrBrokenLink`
|
||||
- ☑ Improved `Get-GPOZaurr`
|
||||
- ☑ Improved report `GPOBrokenLink`
|
||||
## 0.0.103 - 2021.01.04
|
||||
- ☑ Improved `Get-GPOZaurr`
|
||||
- ☑ Added new report `GPOBrokenLink`
|
||||
- ☑ Added `Get-GPOZaurrBrokenLink`
|
||||
- ☑ Added `Repair-GPOZaurrBrokenLink`
|
||||
## 0.0.102 - 2021.01.02
|
||||
- ☑ Improved `Get-GPOZaurrLink`
|
||||
- ☑ Supports all links across forest
|
||||
- ☑ Renamed Linked validate set from `Other` to `OrganizationalUnit`
|
||||
- ☑ Improved `Get-GPOZaurrLinkSummary`
|
||||
- ☑ Improved/BugFix `Get-GPOZaurr` to properly detect linked GPOs in sites/cross-domain
|
||||
- ☑ Improved `Invoke-GPOZaurrPermission`
|
||||
- ☑ Renamed Linked validate set from `Other` to `OrganizationalUnit`
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Added `GPOLinks` basic list
|
||||
## 0.0.101 - 23.12.2020
|
||||
- ☑ Improved `Get-GPOZaurrBroken`
|
||||
- ☑ It now detects `ObjectClass Issue`
|
||||
- ☑ Heavily improved performance
|
||||
- ☑ Removed some useless properties for this particular cmdlet
|
||||
- ☑ All states: `Not available on SYSVOL`, `Not available in AD`, `Exists`, `Permissions Issue`, `ObjectClass Issue`
|
||||
- ☑ Improved help
|
||||
- ☑ Improved `Remove-GPOZaurrBroken`
|
||||
- ☑ It now deals with `ObjectClass Issue`
|
||||
- ☑ Heavily improved performance
|
||||
- ☑ Removed some useless properties for this particular cmdlet
|
||||
- ☑ Now requires manual type insert AD, SYSVOL or ObjectClass (or all of them). Before it was auto using AD/SYSVOL.
|
||||
- ☑ Improved help
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList`
|
||||
- ☑ Renamed `GPOOrphans` to `GPOBroken`
|
||||
- ☑ Improved `GPOBroken` with `ObjectClass issue`
|
||||
## 0.0.100 - 21.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOPermissionsRead`
|
||||
- ☑ Type `GPOPermissions`
|
||||
## 0.0.99 - 13.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` - require GPO to be 7 days old for deletion to be proposed
|
||||
- ☑ Type `GPOPermissions` - one stop for permissions
|
||||
- ☑ Allows Steps to be chosen via their menu and out-of-order
|
||||
- ☑ Improved `Remove-GPOZaurr` - added `RequireDays` parameter to prevent deletion of just modified GPOs
|
||||
- ☑ Added `Get-GPOZaurrPermissionAnalysis`
|
||||
- ☑ Added `Repair-GPOZaurrPermission`
|
||||
## 0.0.98 - 10.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` - fixed unexpected ending of cmdlet when error occurs (for example deleted GPO while script is running) which could impact results
|
||||
- ☑ Other types - small color adjustment
|
||||
- ☑ Fixed/Improved `Get-GPOZaurr` - fixed unexpected ending of cmdlet when error occurs (for example deleted GPO while script is running), improved code base
|
||||
- ☑ Improved `Invoke-GPOZaurrSupport`
|
||||
## 0.0.97 - 07.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` - added more data, did small reorganization
|
||||
## 0.0.96 - 07.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` - added more data, added Optimization Step
|
||||
- ☑ Added `Set-GPOZaurrStatus`
|
||||
- ☑ Added `Optimize-GPOZaurr`
|
||||
- ☑ Fixed `Invoke-GPOZaurrPermission` which would not remove permission due to internal changes earlier on
|
||||
- ☑ Small change to `Backup-GPOZaurr`
|
||||
- ☑ Added support for `Disabled`. It's now possbile to backup `All` (default), `Empty`,`Unlinked`,`Disabled` or a mix of them
|
||||
- ☑ Removed useless `GPOPath` parameter
|
||||
## 0.0.95 - 04.12.2020
|
||||
- ☑ Fix for too big int - [#4](https://github.com/EvotecIT/GPOZaurr/issues/4) - tnx neztach
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` - added ability for Exclusions
|
||||
- ☑ All other types, small improvements
|
||||
- ☑ Added HideSteps, ShowError, ShowWarning -> Disabled Warnings/Errors by default as they tend to show too much information
|
||||
- ☑ Improved `Remove-GPOZaurr` - added Exclusions
|
||||
## 0.0.93 - 03.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` reverted charts colors for entries to match colors
|
||||
- [ ] Added `Skip-GroupPolicy` to use within `Invoke-GPOZaurr`
|
||||
- ☑ Improved `Invoke-GPOZaurr` with basic support for Exclusions
|
||||
- ☑ Improved `Get-GPOZaurr` with basic support for Exclusions
|
||||
- ☑ Improved `Remove-GPOZaurrPermission` error handling
|
||||
## 0.0.92 - 01.12.2020
|
||||
- ☑ Improved `Invoke-GPOZaurrSupport`
|
||||
- ☑ Improved `Invoke-GPOZaurr`
|
||||
- ☑ Type `GPOList` improved with more data, more problems and clearer information
|
||||
- ☑ Improved `Remove-GPOZaurr`
|
||||
- ☑ Added ability do remove disabed GPO
|
||||
- ☑ Improved `Get-GPOZaurr` detecting more issues, delivering more data
|
||||
## 0.0.91 - 24.11.2020
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Improve Type `GPOPermissionsUnknown`
|
||||
## 0.0.90 - 23.11.2020
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Improves Type `GPODuplicates`
|
||||
- ☑ Fix for chart color to be RED
|
||||
- ☑ Add Type `GPOPermissionsUnknown`
|
||||
- ☑ Improves logic for Data with 0/1 element
|
||||
- ☑ Improves `Remove-GPOZaurrDuplicateObject` - removed `Confirm` requirement
|
||||
- ☑ Improves `Get-GPOZaurrNetLogon` with more verbose
|
||||
- ☑ Improves `Repair-GPOZaurrNetLogonOwner` with more verbose and fix for `LimitProcessing`
|
||||
## 0.0.89 - 22.11.2020
|
||||
- ☑ Small update `Add-GPOZaurrPermission`
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Added Type `GPOPermissionsAdministrative`
|
||||
## 0.0.88 - 18.11.2020
|
||||
- ☑ Fix for `Add-GPOZaurrPermission`
|
||||
## 0.0.87 - 18.11.2020
|
||||
- ☑ Improve error handling `Remove-GPOZaurrBroken`
|
||||
## 0.0.86 - 18.11.2020
|
||||
- ☑ Improve error handling `Remove-GPOZaurrBroken`
|
||||
## 0.0.85 - 17.11.2020
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Split `NetLogonPermissions` into `NetLogonPermissions` and `NetLogonOwners`
|
||||
- ☑ Improved type `NetLogonPermissions`
|
||||
- ☑ Improved type `NetLogonOwners`
|
||||
- ☑ Improves `Get-GPOZaurrFiles`
|
||||
- ☑ Improves `Get-GPOZaurrNetLogon`
|
||||
- ☑ Fix for `Get-GPOZaurrNetLogon`
|
||||
## 0.0.84 - 16.11.2020
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Type `NetLogonPermissions`
|
||||
- ☑ Fix for `Get-GPOZaurrNetLogon`
|
||||
## 0.0.83 - 14.11.2020
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Fix for wrong ActionRequired count
|
||||
## 0.0.82 - 14.11.2020
|
||||
- ☑ Added `Get-GPOZaurrPermissionIssue` to detect permission issue with no rights
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Type `GPOPermissionsRead` improved detection of problems with low permissions
|
||||
## 0.0.81 - 12.11.2020
|
||||
- ☑ Fix for `Set-GPOZaurrOwner` in case of missing permissions to not throw errors
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Type `GPOPermissionsRead` added
|
||||
## 0.0.80 - 12.11.2020
|
||||
- ☑ Improves `Invoke-GPOZaurr` (WIP)
|
||||
- ☑ Type `GPOOrphans` clearer options, updated texts, split per domain
|
||||
- ☑ Type `GPOOwners` clearer options, updated texts, split per domain
|
||||
- ☑ Improves `Add-GPOZaurrPermission`
|
||||
- ☑ Fixes LimitProcessing to work correctly
|
||||
- ☑ Added `All` to process all GPOs
|
||||
- ☑ Fixes `Remove-GPOZaurrPermission`
|
||||
- ☑ Improves `Set-GPOZaurrOwner`
|
||||
- ☑ Added `Force` to force `GPO Owner` to any principal (normally only Domain Admins)
|
||||
## 0.0.79 - 10.11.2020
|
||||
- Improved `Invoke-GPOZaurr` - type `GPOOrphans`
|
||||
## 0.0.78 - 10.11.2020
|
||||
- Improved `Remove-GPOZaurrBroken` more verbose
|
||||
- Improved `Get-GPOZaurrBroken` more verbose
|
||||
- Improved `Invoke-GPOZaurr` - type `GPOOrphans`
|
||||
- Improved `Invoke-GPOZaurr` - type `GPOList` - needs more work
|
||||
- Improved `Get-GPOZaurr` with better detection of Empty Policies (needs testing)
|
||||
## 0.0.77 - 9.11.2020
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
## 0.0.76 - 8.11.2020
|
||||
- Improved `Get-GPOZaurrNetLogon` to better handle errors
|
||||
## 0.0.75 - 8.11.2020
|
||||
- Improved `Get-GPOZaurrPermissionConsistency` to stop checking consistency if path doesn't exists
|
||||
## 0.0.74 - 8.11.2020
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
## 0.0.73 - 7.11.2020
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
- Improved `Get-GPOZaurr`
|
||||
## 0.0.72 - 6.11.2020
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
## 0.0.71 - 3.11.2020
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
## 0.0.70 - 29.10.2020
|
||||
- Added `Get-GPOZaurrDuplicateObject`
|
||||
- Added `Remove-GPOZaurrDuplicateObject`
|
||||
## 0.0.69 - 29.10.2020
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
- Improved `Get-GPOZaurrNetLogon`
|
||||
- Improved `Get-GPOZaurrOwner`
|
||||
- Improved `Set-GPOZaurrOwner`
|
||||
- Added `Repair-GPOZaurrNetLogonOwner`
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
## 0.0.68 - 28.10.2020
|
||||
- Renamed `Show-GPOZaurr` to `Invoke-GPOZaurr`
|
||||
- Renamed `Invoke-GPOZaurr` to `Invoke-GPOZaurrContent`
|
||||
- Improvements to `Get-GPOZaurrPermissionConsistency` - don't check for inherited permissions if top level ones are inconsistent
|
||||
- Improved `Invoke-GPOZaurr` (WIP)
|
||||
## 0.0.67 - 22.10.2020
|
||||
- Improved `Show-GPOZaurr` (WIP)
|
||||
## 0.0.66 - 22.10.2020
|
||||
- Improved `Show-GPOZaurr` (WIP)
|
||||
## 0.0.65 - 22.10.2020
|
||||
- Improved `Show-GPOZaurr` (WIP)
|
||||
## 0.0.64 - 21.10.2020
|
||||
- Renamed `Remove-GPOZaurrOrphaned` to `Remove-GPOZaurrBroken` keeping it as an alias
|
||||
- Renamed `Get-GPOZaurrSysvol` to `Get-GPOZaurrBroken` keeping it as an alias
|
||||
- Improved `Show-GPOZaurr` (WIP)
|
||||
## 0.0.63 - 19.10.2020
|
||||
- Renamed `Invoke-GPOZaurrContent` back to `Invoke-GPOZaurr`
|
||||
- Added `Show-GPOZaurr` (WIP)
|
||||
- Added `OutputType`,`OutputType`,`Open`,`Online` parameters to `Invoke-GPOZaurr`
|
||||
- Added `Get-GPOZaurrNetLogon`
|
||||
- Improved `Get-GPOZaurrOwner`
|
||||
- Fixes `Get-GPOZaurrSysvol`
|
||||
## 0.0.62 - 14.10.2020
|
||||
- Renamed `Invoke-GPOZaurr` to `Invoke-GPOZaurrContent` - I want to use `Invoke-GPOZaurr` for something else
|
||||
- Improvements to `Get-GPOZaurrPermissionConsistency` for GPOs without SYSVOL to be reported properly
|
||||
- Added `Get-GPOZaurrPermissionRoot`
|
||||
- Renamed `Remove-GPOZaurrOrphanedSysvolFolders` to `Remove-GPOZaurrOrphaned`
|
||||
- Improved `Remove-GPOZaurrOrphaned` to deal with orphaned folders but also orphaned AD GPO (No sysvol data)
|
||||
- Improved `Get-GPOZaurrSysVol` to detect orphaned SYSVOL or AD GPO objects
|
||||
- Improved `Get-GPOZaurrSysVol` to detect permissions issue when reading AD GPO objects
|
||||
- Added `Get-GPOZaurrPermissionRoot` to show which users/groups have control over all GPOs (allowed to create/modify)
|
||||
- Improved `Get-GPOZaurrPermissionSummary` to include `Get-GPOZaurrPermissionRoot` custom permissions
|
||||
- Updated `Remove-GPOZaurrPermission`
|
||||
- Updated `Get-GpoZaurrPermission`
|
||||
- Updated `Get-GPOZaurrFiles` to better handle access issue
|
||||
- Reversed parameters `Get-GPOZaurrFiles` from `Limited` to `ExtendedMetaData` and fixed missing columns
|
||||
## 0.0.61 - 31.08.2020
|
||||
- Improvement to `Get-GPOZaurrPermissionSummary`
|
||||
- Fixes to `ConvertFrom-CSExtension`
|
||||
- Fixes to `Find-CSExtension`
|
||||
## 0.0.59 - 26.08.2020
|
||||
- Improvement to `Get-GPOZaurrPermissionSummary`
|
||||
## 0.0.58 - 26.08.2020
|
||||
- Improvement to `Get-GPOZaurrPermissionSummary`
|
||||
## 0.0.57 - 26.08.2020
|
||||
- Improvement to `Get-GPOZaurrPermissionSummary`
|
||||
## 0.0.56 - 26.08.2020
|
||||
- Added `Get-GPOZaurrPermissionSummary`
|
||||
## 0.0.55 - 17.08.2020
|
||||
- Improved `Get-GPOZaurrInheritance`
|
||||
## 0.0.54 - 16.08.2020
|
||||
- Added `Invoke-GPOZaurrSupport` (WIP)
|
||||
- Added `ConvertFrom-CSExtension`
|
||||
- Added `Find-CSExtension`
|
||||
- Added `Get-GPOZaurrInheritance`
|
||||
## 0.0.53 - 16.08.2020
|
||||
- Bad release
|
||||
## 0.0.52 - 16.08.2020
|
||||
- Bad release
|
||||
## 0.0.51 - 2.08.2020
|
||||
- Updates to `Invoke-GPOZaurr` - still work in progress
|
||||
- Added `Get-GPOZaurrSysvolDFSR`
|
||||
- Added `Clear-GPOZaurrSysvolDFSR` (requires testing)
|
||||
## 0.0.50 - 29.07.2020
|
||||
- Updates to couple of commands
|
||||
## 0.0.49 - 23.07.2020
|
||||
- Hidden files were skipped - and people do crazy things with them
|
||||
## 0.0.48 - 21.07.2020
|
||||
- Added `Get-GPOZaurrFilesPolicyDefinition`
|
||||
- Updates to `Invoke-GPOZaurr` - still work in progress
|
||||
- Updates to `Get-GPOZaurrFiles` - still work in progress
|
||||
- Updates to `Remove-GPOZaurrOrphanedSysvolFolders` with backup and support for domains
|
||||
- Module will now be signed
|
||||
## 0.0.47 - 29.06.2020
|
||||
- Update to `Get-GPOZaurrAD` for better error reporting
|
||||
- Updates to `Invoke-GPOZaurr` - still work in progress
|
||||
## 0.0.46 - 28.06.2020
|
||||
- Additional protection for `Get-GPOZaurrAD` for CNF duplicates
|
||||
- Update to `Save-GPOZaurrFiles`
|
||||
- Added `Invoke-GPOZaurr` (alias: `Find-GPO`) (heavy work in progress)
|
||||
## 0.0.45 - 26.06.2020
|
||||
- During publishing ADEssentials required functions are now merged to prevent cyclic dependency bug [Using ModuleSpec syntax in RequiredModules causes incorrect "cyclic dependency" failures](https://github.com/PowerShell/PowerShell/issues/2607)
|
||||
## 0.0.44 - 24.06.2020
|
||||
- Improvement to `Get-GPOZaurrLinkSummary`
|
||||
## 0.0.43 - 21.06.2020
|
||||
- Added `Get-GPOZaurrFiles` to list files on NETLOGON/SYSVOL shares with a lot of details
|
||||
## 0.0.42 - 19.06.2020
|
||||
- Fix for `Get-GPOZaurrLink` and `SearchBase` parameter
|
||||
- Fix for `Get-GPOZaurrLink` - canonical link Trim() throwing errors if empty
|
||||
## 0.0.41 - 18.06.2020
|
||||
- Added paramerter `SkipDuplicates` to `Invoke-GPOZaurrPermission` which prevents applying permissions over and over again if 1 GPO is linked to a multiple OU's within another OU
|
||||
## 0.0.40 - 18.06.2020
|
||||
- Fix for error `Get-GPOZaurrLink` - same issue as described on my [earlier blog - Get-ADObject : The server has returned the following error: invalid enumeration context.](https://evotec.xyz/get-adobject-the-server-has-returned-the-following-error-invalid-enumeration-context/).
|
||||
- `WARNING: Get-GPOZaurrLink - Processing error The server has returned the following error: invalid enumeration context.`
|
||||
- `WARNING: Get-GPOZaurrLink - Processing error A referral was returned from the server`
|
||||
- Added `SkipDuplicates` for `Get-GPOZaurrLink`
|
||||
## 0.0.39 - 17.06.2020
|
||||
- Updates to `Invoke-GPOZaurrPermission` with new parameter `LimitAdministrativeGroupsToDomain`
|
||||
- This will get administrative based on IncludeDomains if given. It means that if GPO has Domain admins added from multiple domains it will only find one, and remove all other Domain Admins (if working with Domain Admins that is)
|
||||
## 0.0.38 - 17.06.2020
|
||||
- Update to Get-PrivGPOZaurrLink which would cause problems to `Invoke-GPOZaurrPermission` if it would be run without Administrative permission and GPO wouldn't be accessible for that user
|
||||
## 0.0.37 - 16.06.2020
|
||||
- Updates to `Invoke-GPOZaurrPermission` with new parameterset `Level`
|
||||
- Updates to `Get-GPOZaurrLinkSummary`
|
||||
## 0.0.36 - 15.06.2020
|
||||
- Initial release
|
||||
@@ -0,0 +1,73 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Export-GPOZaurrContent
|
||||
|
||||
## SYNOPSIS
|
||||
Saves GPOs to XML or HTML files.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Export-GPOZaurrContent [-FolderOutput] <String> [[-ReportType] <String>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
Saves GPOs to XML or HTML files.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### EXAMPLE 1
|
||||
```
|
||||
An example
|
||||
```
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -FolderOutput
|
||||
The folder where the GPOs will be saved.
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: Path
|
||||
|
||||
Required: True
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ReportType
|
||||
The type of report to generate.
|
||||
Valid values are XML or HTML.
|
||||
Default is XML.
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: XML
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
+152
-146
@@ -8,7 +8,8 @@ schema: 2.0.0
|
||||
# Get-GPOZaurr
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Gets information about all Group Policies.
|
||||
Similar to what Get-GPO provides by default.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
@@ -16,121 +17,52 @@ schema: 2.0.0
|
||||
Get-GPOZaurr [[-ExcludeGroupPolicies] <ScriptBlock>] [[-GPOName] <String>] [[-GPOGuid] <String>]
|
||||
[[-Type] <String[]>] [[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-IncludeDomains] <String[]>]
|
||||
[[-ExtendedForestInformation] <IDictionary>] [[-GPOPath] <String[]>] [-PermissionsOnly] [-OwnerOnly]
|
||||
[-Limited] [-ReturnObject] [[-ADAdministrativeGroups] <IDictionary>] [<CommonParameters>]
|
||||
[-Limited] [[-ADAdministrativeGroups] <IDictionary>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Gets information about all Group Policies.
|
||||
Similar to what Get-GPO provides by default.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
$GPOs = Get-GPOZaurr
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
$GPOs | Format-Table DisplayName, Owner, OwnerSID, OwnerType
|
||||
|
||||
### EXAMPLE 2
|
||||
```
|
||||
$GPO = Get-GPOZaurr -GPOName 'ALL | Allow use of biometrics'
|
||||
```
|
||||
|
||||
$GPO | Format-List *
|
||||
|
||||
### EXAMPLE 3
|
||||
```
|
||||
$GPOS = Get-GPOZaurr -ExcludeGroupPolicies {
|
||||
```
|
||||
|
||||
Skip-GroupPolicy -Name 'de14_usr_std'
|
||||
Skip-GroupPolicy -Name 'de14_usr_std' -DomaiName 'ad.evotec.xyz'
|
||||
Skip-GroupPolicy -Name 'All | Trusted Websites' #-DomaiName 'ad.evotec.xyz'
|
||||
'{D39BF08A-87BF-4662-BFA0-E56240EBD5A2}'
|
||||
'COMPUTERS | Enable Sets'
|
||||
}
|
||||
$GPOS | Format-Table -AutoSize *
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ADAdministrativeGroups
|
||||
{{ Fill ADAdministrativeGroups Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 9
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeGroupPolicies
|
||||
{{ Fill ExcludeGroupPolicies Description }}
|
||||
Marks the GPO as excluded from the list.
|
||||
|
||||
```yaml
|
||||
Type: ScriptBlock
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 7
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GPOGuid
|
||||
{{ Fill GPOGuid Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: GUID, GPOID
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GPOName
|
||||
{{ Fill GPOName Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
@@ -138,14 +70,106 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GPOPath
|
||||
{{ Fill GPOPath Description }}
|
||||
### -GPOName
|
||||
Provide a GPOName to get information about a specific GPO.
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GPOGuid
|
||||
Provide a GPOGuid to get information about a specific GPO.
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: GUID, GPOID
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
Choose a specific type of GPO.
|
||||
Options are: 'Empty', 'Unlinked', 'Disabled', 'NoApplyPermission', 'All'.
|
||||
Default is All.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 6
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 7
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 8
|
||||
Default value: None
|
||||
@@ -153,53 +177,23 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
### -GPOPath
|
||||
Define GPOPath where the XML files are located to be analyzed instead of asking Active Directory
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 6
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Limited
|
||||
{{ Fill Limited Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -OwnerOnly
|
||||
{{ Fill OwnerOnly Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Position: 9
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -PermissionsOnly
|
||||
{{ Fill PermissionsOnly Description }}
|
||||
Only show permissions, by default all information is shown
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
@@ -208,13 +202,13 @@ Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ReturnObject
|
||||
{{ Fill ReturnObject Description }}
|
||||
### -OwnerOnly
|
||||
only show owner information, by default all information is shown
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
@@ -223,22 +217,36 @@ Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
{{ Fill Type Description }}
|
||||
### -Limited
|
||||
Provide limited output without analyzing XML data
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: Empty, Unlinked, Disabled, All
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ADAdministrativeGroups
|
||||
Ability to provide ADAdministrativeGroups from different function to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 10
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
@@ -249,11 +257,9 @@ This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -15,18 +15,21 @@ schema: 2.0.0
|
||||
### Default (Default)
|
||||
```
|
||||
Get-GPOZaurrAD [-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-DateFrom <DateTime>] [-DateTo <DateTime>] [-DateRange <String>] [-DateProperty <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### GPOName
|
||||
```
|
||||
Get-GPOZaurrAD [-GPOName <String>] [-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-DateFrom <DateTime>] [-DateTo <DateTime>] [-DateRange <String>] [-DateProperty <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### GPOGUID
|
||||
```
|
||||
Get-GPOZaurrAD [-GPOGuid <String>] [-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-DateFrom <DateTime>] [-DateTo <DateTime>] [-DateRange <String>] [-DateProperty <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
@@ -44,6 +47,68 @@ PS C:\> {{ Add example code here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -DateFrom
|
||||
{{ Fill DateFrom Description }}
|
||||
|
||||
```yaml
|
||||
Type: DateTime
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateProperty
|
||||
{{ Fill DateProperty Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: WhenCreated, WhenChanged
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateRange
|
||||
{{ Fill DateRange Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: PastHour, CurrentHour, PastDay, CurrentDay, PastMonth, CurrentMonth, PastQuarter, CurrentQuarter, Last14Days, Last21Days, Last30Days, Last7Days, Last3Days, Last1Days
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateTo
|
||||
{{ Fill DateTo Description }}
|
||||
|
||||
```yaml
|
||||
Type: DateTime
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
|
||||
+84
-94
@@ -8,32 +8,51 @@ schema: 2.0.0
|
||||
# Get-GPOZaurrBroken
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Detects broken or otherwise damaged Group Policies
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Get-GPOZaurrBroken [[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-ExcludeDomainControllers] <String[]>]
|
||||
[[-IncludeDomains] <String[]>] [[-IncludeDomainControllers] <String[]>] [-SkipRODC] [[-GPOs] <Array>]
|
||||
[[-IncludeDomains] <String[]>] [[-IncludeDomainControllers] <String[]>] [-SkipRODC]
|
||||
[[-ExtendedForestInformation] <IDictionary>] [-VerifyDomainControllers] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Detects broken or otherwise damaged Group Policies providing insight whether GPO exists in both AD and SYSVOL.
|
||||
It provides few statuses:
|
||||
- Permissions issue - means account couldn't read GPO due to permissions
|
||||
- ObjectClass issue - means that ObjectClass is of type Container, rather than expected groupPolicyContainer
|
||||
- Not available on SYSVOL - means SYSVOL data is missing, yet AD metadata is available
|
||||
- Not available in AD - means AD metadata is missing, yet SYSVOL data is available
|
||||
- Exists - means AD metadata and SYSVOL data are available
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Get-GPOZaurrBroken -Verbose | Format-Table
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ExcludeDomainControllers
|
||||
{{ Fill ExcludeDomainControllers Description }}
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -47,8 +66,9 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
### -ExcludeDomainControllers
|
||||
Exclude specific domain controllers, by default there are no exclusions, as long as VerifyDomainControllers switch is enabled.
|
||||
Otherwise this parameter is ignored.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -56,14 +76,61 @@ Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomainControllers
|
||||
Include only specific domain controllers, by default all domain controllers are included, as long as VerifyDomainControllers switch is enabled.
|
||||
Otherwise this parameter is ignored.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: DomainControllers
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -SkipRODC
|
||||
Skip Read-Only Domain Controllers.
|
||||
By default all domain controllers are included.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
@@ -77,83 +144,8 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GPOs
|
||||
{{ Fill GPOs Description }}
|
||||
|
||||
```yaml
|
||||
Type: Array
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomainControllers
|
||||
{{ Fill IncludeDomainControllers Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: DomainControllers
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -SkipRODC
|
||||
{{ Fill SkipRODC Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -VerifyDomainControllers
|
||||
{{ Fill VerifyDomainControllers Description }}
|
||||
Forces cmdlet to check GPO Existance on Domain Controllers rather then per domain
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
@@ -162,7 +154,7 @@ Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
@@ -172,11 +164,9 @@ This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -0,0 +1,107 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Get-GPOZaurrBrokenLink
|
||||
|
||||
## SYNOPSIS
|
||||
Finds any GPO link that doesn't have a matching GPO (already removed GPO).
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Get-GPOZaurrBrokenLink [[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-IncludeDomains] <String[]>]
|
||||
[[-ExtendedForestInformation] <IDictionary>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
Finds any GPO link that doesn't have a matching GPO (already removed GPO).
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Get-GPOZaurrBrokenLink -Verbose | Format-Table -AutoSize *
|
||||
```
|
||||
|
||||
### EXAMPLE 2
|
||||
```
|
||||
Get-GPOZaurrBrokenLink -Verbose -IncludeDomains ad.evotec.pl | Format-Table -AutoSize *
|
||||
```
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
@@ -8,32 +8,96 @@ schema: 2.0.0
|
||||
# Get-GPOZaurrInheritance
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Short description
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Get-GPOZaurrInheritance [-IncludeBlockedObjects] [-OnlyBlockedInheritance] [[-Forest] <String>]
|
||||
Get-GPOZaurrInheritance [-IncludeBlockedObjects] [-OnlyBlockedInheritance] [-IncludeExcludedObjects]
|
||||
[-IncludeGroupPoliciesForBlockedObjects] [[-Exclusions] <String[]>] [[-Forest] <String>]
|
||||
[[-ExcludeDomains] <String[]>] [[-IncludeDomains] <String[]>] [[-ExtendedForestInformation] <IDictionary>]
|
||||
[<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Long description
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
$Objects = Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance -Exclusions $ExcludedOU
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
$Objects | Format-Table
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
### -IncludeBlockedObjects
|
||||
Include OU's with blocked inheritance.
|
||||
Default disabled
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -OnlyBlockedInheritance
|
||||
Show only OU's with blocked inheritance
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeExcludedObjects
|
||||
Show excluded objets.
|
||||
Default disabled
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeGroupPoliciesForBlockedObjects
|
||||
{{ Fill IncludeGroupPoliciesForBlockedObjects Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Exclusions
|
||||
Provide exclusions for OU's approved by IT.
|
||||
You can provide OU by canonical name or distinguishedName
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -47,11 +111,26 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
@@ -62,38 +141,8 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeBlockedObjects
|
||||
{{ Fill IncludeBlockedObjects Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -101,22 +150,22 @@ Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -OnlyBlockedInheritance
|
||||
{{ Fill OnlyBlockedInheritance Description }}
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
@@ -127,11 +176,9 @@ This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -12,24 +12,32 @@ schema: 2.0.0
|
||||
|
||||
## SYNTAX
|
||||
|
||||
### Linked (Default)
|
||||
```
|
||||
Get-GPOZaurrLink [-Linked <String[]>] [-Limited] [-SkipDuplicates] [-GPOCache <IDictionary>] [-Forest <String>]
|
||||
[-ExcludeDomains <String[]>] [-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>]
|
||||
[-AsHashTable] [-Summary] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### ADObject
|
||||
```
|
||||
Get-GPOZaurrLink -ADObject <ADObject[]> [-Limited] [-SkipDuplicates] [-GPOCache <IDictionary>]
|
||||
[-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [<CommonParameters>]
|
||||
[-ExtendedForestInformation <IDictionary>] [-AsHashTable] [-Summary] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### Filter
|
||||
```
|
||||
Get-GPOZaurrLink [-Filter <String>] [-SearchBase <String>] [-SearchScope <ADSearchScope>] [-Limited]
|
||||
[-SkipDuplicates] [-GPOCache <IDictionary>] [-Forest <String>] [-ExcludeDomains <String[]>]
|
||||
[-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>] [<CommonParameters>]
|
||||
[-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>] [-AsHashTable] [-Summary]
|
||||
[<CommonParameters>]
|
||||
```
|
||||
|
||||
### Linked
|
||||
### Site
|
||||
```
|
||||
Get-GPOZaurrLink -Linked <String> [-Limited] [-SkipDuplicates] [-GPOCache <IDictionary>] [-Forest <String>]
|
||||
[-ExcludeDomains <String[]>] [-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>]
|
||||
Get-GPOZaurrLink [-Site <String[]>] [-GPOCache <IDictionary>] [-Forest <String>] [-ExcludeDomains <String[]>]
|
||||
[-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>] [-AsHashTable] [-Summary]
|
||||
[<CommonParameters>]
|
||||
```
|
||||
|
||||
@@ -62,6 +70,21 @@ Accept pipeline input: True (ByPropertyName, ByValue)
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -AsHashTable
|
||||
{{ Fill AsHashTable Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
@@ -157,7 +180,7 @@ Accept wildcard characters: False
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Parameter Sets: Linked, ADObject, Filter
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
@@ -171,12 +194,12 @@ Accept wildcard characters: False
|
||||
{{ Fill Linked Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Type: String[]
|
||||
Parameter Sets: Linked
|
||||
Aliases:
|
||||
Accepted values: Root, DomainControllers, Site, Other
|
||||
Accepted values: All, Root, DomainControllers, Site, OrganizationalUnit
|
||||
|
||||
Required: True
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
@@ -214,9 +237,39 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Site
|
||||
{{ Fill Site Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: Site
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -SkipDuplicates
|
||||
{{ Fill SkipDuplicates Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: Linked, ADObject, Filter
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Summary
|
||||
{{ Fill Summary Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
|
||||
@@ -0,0 +1,138 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Get-GPOZaurrOrganizationalUnit
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Get-GPOZaurrOrganizationalUnit [[-Forest] <String>] [[-ExcludeDomains] <String[]>]
|
||||
[[-IncludeDomains] <String[]>] [[-ExtendedForestInformation] <IDictionary>] [[-Option] <String[]>]
|
||||
[[-ExcludeOrganizationalUnit] <String[]>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeOrganizationalUnit
|
||||
{{ Fill ExcludeOrganizationalUnit Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: ExcludeOU, Exclusions
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Option
|
||||
{{ Fill Option Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: OK, Unlink, Delete
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
|
||||
## RELATED LINKS
|
||||
@@ -16,21 +16,21 @@ Gets owners of GPOs from Active Directory and SYSVOL
|
||||
```
|
||||
Get-GPOZaurrOwner [-IncludeSysvol] [-SkipBroken] [-Forest <String>] [-ExcludeDomains <String[]>]
|
||||
[-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>]
|
||||
[-ADAdministrativeGroups <IDictionary>] [<CommonParameters>]
|
||||
[-ADAdministrativeGroups <IDictionary>] [-ApprovedOwner <String[]>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### GPOName
|
||||
```
|
||||
Get-GPOZaurrOwner [-GPOName <String>] [-IncludeSysvol] [-SkipBroken] [-Forest <String>]
|
||||
[-ExcludeDomains <String[]>] [-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>]
|
||||
[-ADAdministrativeGroups <IDictionary>] [<CommonParameters>]
|
||||
[-ADAdministrativeGroups <IDictionary>] [-ApprovedOwner <String[]>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### GPOGUID
|
||||
```
|
||||
Get-GPOZaurrOwner [-GPOGuid <String>] [-IncludeSysvol] [-SkipBroken] [-Forest <String>]
|
||||
[-ExcludeDomains <String[]>] [-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>]
|
||||
[-ADAdministrativeGroups <IDictionary>] [<CommonParameters>]
|
||||
[-ADAdministrativeGroups <IDictionary>] [-ApprovedOwner <String[]>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
@@ -187,6 +187,21 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ApprovedOwner
|
||||
Ability to provide different owner (non administrative that still is approved for use)
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Exclusion, Exclusions
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
|
||||
@@ -0,0 +1,106 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Get-GPOZaurrPermissionAnalysis
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Get-GPOZaurrPermissionAnalysis [[-Forest] <String>] [[-ExcludeDomains] <String[]>]
|
||||
[[-IncludeDomains] <String[]>] [[-Permissions] <Array>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Permissions
|
||||
{{ Fill Permissions Description }}
|
||||
|
||||
```yaml
|
||||
Type: Array
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
|
||||
## RELATED LINKS
|
||||
@@ -8,7 +8,7 @@ schema: 2.0.0
|
||||
# Get-GPOZaurrSysvolDFSR
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Gets DFSR information from the SYSVOL DFSR
|
||||
|
||||
## SYNTAX
|
||||
|
||||
@@ -20,21 +20,36 @@ Get-GPOZaurrSysvolDFSR [[-Forest] <String>] [[-ExcludeDomains] <String[]>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Gets DFSR information from the SYSVOL DFSR
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
$DFSR = Get-GPOZaurrSysvolDFSR
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
$DFSR | Format-Table *
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ExcludeDomainControllers
|
||||
{{ Fill ExcludeDomainControllers Description }}
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -48,74 +63,15 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
### -ExcludeDomainControllers
|
||||
Exclude specific domain controllers, by default there are no exclusions, as long as VerifyDomainControllers switch is enabled.
|
||||
Otherwise this parameter is ignored.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomainControllers
|
||||
{{ Fill IncludeDomainControllers Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: DomainControllers
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
@@ -123,11 +79,58 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -SearchDFSR
|
||||
{{ Fill SearchDFSR Description }}
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomainControllers
|
||||
Include only specific domain controllers, by default all domain controllers are included, as long as VerifyDomainControllers switch is enabled.
|
||||
Otherwise this parameter is ignored.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: DomainControllers
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -SkipRODC
|
||||
Skip Read-Only Domain Controllers.
|
||||
By default all domain controllers are included.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
@@ -138,17 +141,18 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -SkipRODC
|
||||
{{ Fill SkipRODC Description }}
|
||||
### -SearchDFSR
|
||||
Define DFSR Share.
|
||||
By default it uses SYSVOL Share
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Position: 7
|
||||
Default value: SYSVOL Share
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
@@ -158,11 +162,9 @@ This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -0,0 +1,178 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Get-GPOZaurrUpdates
|
||||
|
||||
## SYNOPSIS
|
||||
Gets the list of GPOs created or updated in the last X number of days.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
### DateRange (Default)
|
||||
```
|
||||
Get-GPOZaurrUpdates [-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
-DateRange <String> [-DateProperty <String[]>] [-ExtendedForestInformation <IDictionary>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### Dates
|
||||
```
|
||||
Get-GPOZaurrUpdates [-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
-DateFrom <DateTime> -DateTo <DateTime> [-DateProperty <String[]>] [-ExtendedForestInformation <IDictionary>]
|
||||
[<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
Gets the list of GPOs created or updated in the last X number of days.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Get-GPOZaurrUpdates -DateRange Last14Days -DateProperty WhenCreated, WhenChanged -Verbose -IncludeDomains 'ad.evotec.pl' | Format-List
|
||||
```
|
||||
|
||||
### EXAMPLE 2
|
||||
```
|
||||
Get-GPOZaurrUpdates -DateRange Last14Days -DateProperty WhenCreated -Verbose | Format-Table
|
||||
```
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
ą
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateFrom
|
||||
Provide a date from which to start the search, by default the last X days are used
|
||||
|
||||
```yaml
|
||||
Type: DateTime
|
||||
Parameter Sets: Dates
|
||||
Aliases:
|
||||
|
||||
Required: True
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateTo
|
||||
Provide a date to which to end the search, by default the last X days are used
|
||||
|
||||
```yaml
|
||||
Type: DateTime
|
||||
Parameter Sets: Dates
|
||||
Aliases:
|
||||
|
||||
Required: True
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateRange
|
||||
Provide a date range to search for, by default the last X days are used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: DateRange
|
||||
Aliases:
|
||||
|
||||
Required: True
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DateProperty
|
||||
Choose a date property.
|
||||
It can be WhenCreated or WhenChanged or both.
|
||||
By default whenCreated is used for comparison purposes
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: WhenCreated
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
+130
-89
@@ -8,62 +8,57 @@ schema: 2.0.0
|
||||
# Invoke-GPOZaurr
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Single cmdlet that provides 360 degree overview of Group Policies in Active Directory Forest.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Invoke-GPOZaurr [[-ExcludeGroupPolicies] <ScriptBlock>] [-FilePath <String>] [[-Type] <String[]>] [-PassThru]
|
||||
[-HideHTML] [-HideSteps] [-ShowError] [-ShowWarning] [-Forest <String>] [-ExcludeDomains <String[]>]
|
||||
[-IncludeDomains <String[]>] [<CommonParameters>]
|
||||
Invoke-GPOZaurr [[-Exclusions] <Object>] [-FilePath <String>] [[-Type] <String[]>] [-PassThru] [-HideHTML]
|
||||
[-HideSteps] [-ShowError] [-ShowWarning] [-Forest <String>] [-ExcludeDomains <String[]>]
|
||||
[-IncludeDomains <String[]>] [-Online] [-SplitReports] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Single cmdlet that provides 360 degree overview of Group Policies in Active Directory Forest with ability to pick reports and export to HTML.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Invoke-GPOZaurr
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
### EXAMPLE 2
|
||||
```
|
||||
Invoke-GPOZaurr -Type GPOOrganizationalUnit -Online -FilePath $PSScriptRoot\Reports\GPOZaurrOU.html -Exclusions @(
|
||||
```
|
||||
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
)
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
### -Exclusions
|
||||
Allows to mark as excluded some Group Policies or Organizational Units depending on type.
|
||||
Can be a scriptblock or array depending on supported way by underlying report.
|
||||
Not every report support exclusions.
|
||||
Not every report support exclusions the same way.
|
||||
Exclusions should be used only if there is single report being asked for.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Type: Object
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Aliases: ExcludeGroupPolicies, ExclusionsCode
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeGroupPolicies
|
||||
{{ Fill ExcludeGroupPolicies Description }}
|
||||
|
||||
```yaml
|
||||
Type: ScriptBlock
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -FilePath
|
||||
{{ Fill FilePath Description }}
|
||||
Path to the file where the report will be saved.
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
@@ -77,8 +72,100 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
Type of report to be generated from a list of available reports.
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -PassThru
|
||||
Returns created objects after the report is done
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -HideHTML
|
||||
Do not auto open HTML report in default browser
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -HideSteps
|
||||
Do not show steps in report
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ShowError
|
||||
Show errors in HTML report.
|
||||
Useful in case the report is being run as Scheduled Task
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ShowWarning
|
||||
Show warnings in HTML report.
|
||||
Useful in case the report is being run as Scheduled Task
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
@@ -92,26 +179,11 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -HideHTML
|
||||
{{ Fill HideHTML Description }}
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -HideSteps
|
||||
{{ Fill HideSteps Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
@@ -123,7 +195,7 @@ Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -137,8 +209,8 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -PassThru
|
||||
{{ Fill PassThru Description }}
|
||||
### -Online
|
||||
Forces report to use online resources in HTML (using CDN most of the time), by default it is run offline, and inlines all CSS/JS code.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
@@ -147,13 +219,14 @@ Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ShowError
|
||||
{{ Fill ShowError Description }}
|
||||
### -SplitReports
|
||||
Split report into multiple files, one for each report.
|
||||
This can be useful for large domains with huge reports.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
@@ -162,37 +235,7 @@ Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ShowWarning
|
||||
{{ Fill ShowWarning Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
{{ Fill Type Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
@@ -202,11 +245,9 @@ This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -298,7 +298,7 @@ Accept wildcard characters: False
|
||||
Type: String
|
||||
Parameter Sets: Linked
|
||||
Aliases:
|
||||
Accepted values: Root, DomainControllers, Site, Other
|
||||
Accepted values: Root, DomainControllers, Site, OrganizationalUnit
|
||||
|
||||
Required: True
|
||||
Position: Named
|
||||
|
||||
@@ -14,7 +14,7 @@ schema: 2.0.0
|
||||
|
||||
```
|
||||
Invoke-GPOZaurrSupport [[-Type] <String>] [[-ComputerName] <String>] [[-UserName] <String>] [[-Path] <String>]
|
||||
[[-Splitter] <String>] [-PreventShow] [-Offline] [-ForceGPResult] [<CommonParameters>]
|
||||
[[-Splitter] <String>] [-PreventShow] [-Online] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
@@ -46,23 +46,8 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ForceGPResult
|
||||
{{ Fill ForceGPResult Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Offline
|
||||
{{ Fill Offline Description }}
|
||||
### -Online
|
||||
{{ Fill Online Description }}
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
|
||||
+32
-7
@@ -26,11 +26,15 @@ Provides Backup functionality to Group Policies
|
||||
### [ConvertFrom-CSExtension](ConvertFrom-CSExtension.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Export-GPOZaurrContent](Export-GPOZaurrContent.md)
|
||||
Saves GPOs to XML or HTML files.
|
||||
|
||||
### [Find-CSExtension](Find-CSExtension.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurr](Get-GPOZaurr.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Gets information about all Group Policies.
|
||||
Similar to what Get-GPO provides by default.
|
||||
|
||||
### [Get-GPOZaurrAD](Get-GPOZaurrAD.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
@@ -39,7 +43,10 @@ Provides Backup functionality to Group Policies
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrBroken](Get-GPOZaurrBroken.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Detects broken or otherwise damaged Group Policies
|
||||
|
||||
### [Get-GPOZaurrBrokenLink](Get-GPOZaurrBrokenLink.md)
|
||||
Finds any GPO link that doesn't have a matching GPO (already removed GPO).
|
||||
|
||||
### [Get-GPOZaurrDictionary](Get-GPOZaurrDictionary.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
@@ -57,7 +64,7 @@ Provides Backup functionality to Group Policies
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrInheritance](Get-GPOZaurrInheritance.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Short description
|
||||
|
||||
### [Get-GPOZaurrLegacyFiles](Get-GPOZaurrLegacyFiles.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
@@ -71,6 +78,9 @@ Provides Backup functionality to Group Policies
|
||||
### [Get-GPOZaurrNetLogon](Get-GPOZaurrNetLogon.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrOrganizationalUnit](Get-GPOZaurrOrganizationalUnit.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrOwner](Get-GPOZaurrOwner.md)
|
||||
Gets owners of GPOs from Active Directory and SYSVOL
|
||||
|
||||
@@ -80,6 +90,9 @@ Tries to find CPassword in Group Policies or given path and translate it to read
|
||||
### [Get-GPOZaurrPermission](Get-GPOZaurrPermission.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrPermissionAnalysis](Get-GPOZaurrPermissionAnalysis.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrPermissionConsistency](Get-GPOZaurrPermissionConsistency.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
@@ -93,13 +106,16 @@ Detects Group Policy missing Authenticated Users permission while not having hig
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Get-GPOZaurrSysvolDFSR](Get-GPOZaurrSysvolDFSR.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Gets DFSR information from the SYSVOL DFSR
|
||||
|
||||
### [Get-GPOZaurrUpdates](Get-GPOZaurrUpdates.md)
|
||||
Gets the list of GPOs created or updated in the last X number of days.
|
||||
|
||||
### [Get-GPOZaurrWMI](Get-GPOZaurrWMI.md)
|
||||
Get Group Policy WMI filter
|
||||
|
||||
### [Invoke-GPOZaurr](Invoke-GPOZaurr.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Single cmdlet that provides 360 degree overview of Group Policies in Active Directory Forest.
|
||||
|
||||
### [Invoke-GPOZaurrContent](Invoke-GPOZaurrContent.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
@@ -123,7 +139,7 @@ Enables or disables user/computer section of group policy based on it's content.
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Remove-GPOZaurrBroken](Remove-GPOZaurrBroken.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Finds and removes broken Group Policies from SYSVOL or AD or both.
|
||||
|
||||
### [Remove-GPOZaurrDuplicateObject](Remove-GPOZaurrDuplicateObject.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
@@ -134,13 +150,22 @@ Enables or disables user/computer section of group policy based on it's content.
|
||||
### [Remove-GPOZaurrLegacyFiles](Remove-GPOZaurrLegacyFiles.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Remove-GPOZaurrLinkEmptyOU](Remove-GPOZaurrLinkEmptyOU.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Remove-GPOZaurrPermission](Remove-GPOZaurrPermission.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Remove-GPOZaurrWMI](Remove-GPOZaurrWMI.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Repair-GPOZaurrBrokenLink](Repair-GPOZaurrBrokenLink.md)
|
||||
Removes any link to GPO that no longer exists.
|
||||
|
||||
### [Repair-GPOZaurrNetLogonOwner](Repair-GPOZaurrNetLogonOwner.md)
|
||||
Sets new owner to each file in NetLogon share.
|
||||
|
||||
### [Repair-GPOZaurrPermission](Repair-GPOZaurrPermission.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Repair-GPOZaurrPermissionConsistency](Repair-GPOZaurrPermissionConsistency.md)
|
||||
@@ -150,7 +175,7 @@ Enables or disables user/computer section of group policy based on it's content.
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
### [Save-GPOZaurrFiles](Save-GPOZaurrFiles.md)
|
||||
{{ Fill in the Synopsis }}
|
||||
Exports GPO XML data to files and saves it to a given path
|
||||
|
||||
### [Set-GPOOwner](Set-GPOOwner.md)
|
||||
Used within Invoke-GPOZaurrPermission only.
|
||||
|
||||
+17
-2
@@ -16,7 +16,7 @@ schema: 2.0.0
|
||||
Remove-GPOZaurr [[-ExcludeGroupPolicies] <ScriptBlock>] [-Type] <String[]> [-LimitProcessing <Int32>]
|
||||
[-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [-GPOPath <String[]>] [-BackupPath <String>] [-BackupDated]
|
||||
[-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
[-RequireDays <Int32>] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
@@ -183,6 +183,21 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -RequireDays
|
||||
{{ Fill RequireDays Description }}
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
{{ Fill Type Description }}
|
||||
|
||||
@@ -190,7 +205,7 @@ Accept wildcard characters: False
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: Empty, Unlinked, Disabled
|
||||
Accepted values: Empty, Unlinked, Disabled, NoApplyPermission
|
||||
|
||||
Required: True
|
||||
Position: 0
|
||||
|
||||
@@ -8,35 +8,63 @@ schema: 2.0.0
|
||||
# Remove-GPOZaurrBroken
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Finds and removes broken Group Policies from SYSVOL or AD or both.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Remove-GPOZaurrBroken [[-Type] <String[]>] [[-BackupPath] <String>] [-BackupDated] [[-LimitProcessing] <Int32>]
|
||||
[[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-IncludeDomains] <String[]>]
|
||||
[[-ExtendedForestInformation] <IDictionary>] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
Remove-GPOZaurrBroken [-Type] <String[]> [-BackupPath <String>] [-BackupDated] [-LimitProcessing <Int32>]
|
||||
[-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Finds and removes broken Group Policies from SYSVOL or AD or both.
|
||||
Assesment is based on Get-GPOZaurrBroken and there are 3 supported types:
|
||||
- AD - meaning GPOs which have no SYSVOL content will be deleted from AD
|
||||
- SYSVOL - meaning GPOs which have no AD content will be deleted from SYSVOL
|
||||
- ObjectClass - meaning GPOs which have ObjectClass category of Container rather than groupPolicyContainer will be deleted from AD & SYSVOL
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Remove-GPOZaurrBroken -Verbose -WhatIf -Type AD, SYSVOL
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
### EXAMPLE 2
|
||||
```
|
||||
Remove-GPOZaurrBroken -Verbose -WhatIf -Type AD, SYSVOL -IncludeDomains 'ad.evotec.pl' -LimitProcessing 2
|
||||
```
|
||||
|
||||
### EXAMPLE 3
|
||||
```
|
||||
Remove-GPOZaurrBroken -Verbose -IncludeDomains 'ad.evotec.xyz' -BackupPath $Env:UserProfile\Desktop\MyBackup1 -WhatIf -Type AD, SYSVOL
|
||||
```
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -BackupDated
|
||||
{{ Fill BackupDated Description }}
|
||||
### -Type
|
||||
Choose one or more types to delete.
|
||||
Options are AD, ObjectClass, SYSVOL
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: True
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -BackupPath
|
||||
Path to optional backup of SYSVOL content before deletion
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
@@ -47,28 +75,44 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -BackupPath
|
||||
{{ Fill BackupPath Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
### -BackupDated
|
||||
Forces backup to be created within folder that has date in it
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
Allows to specify maximum number of items that will be fixed in a single run.
|
||||
It doesn't affect amount of GPOs processed
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: 2147483647
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
@@ -78,7 +122,7 @@ Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -86,44 +130,14 @@ Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 6
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
@@ -131,38 +145,22 @@ Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
{{ Fill LimitProcessing Description }}
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
{{ Fill Type Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: SYSVOL, AD
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
@@ -184,16 +182,29 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -0,0 +1,168 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Remove-GPOZaurrLinkEmptyOU
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Remove-GPOZaurrLinkEmptyOU [[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-IncludeDomains] <String[]>]
|
||||
[[-ExtendedForestInformation] <IDictionary>] [[-ExcludeOrganizationalUnit] <String[]>]
|
||||
[[-LimitProcessing] <Int32>] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeOrganizationalUnit
|
||||
{{ Fill ExcludeOrganizationalUnit Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
{{ Fill LimitProcessing Description }}
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -WhatIf
|
||||
Shows what would happen if the cmdlet runs.
|
||||
The cmdlet is not run.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: wi
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
|
||||
## RELATED LINKS
|
||||
@@ -0,0 +1,156 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Repair-GPOZaurrBrokenLink
|
||||
|
||||
## SYNOPSIS
|
||||
Removes any link to GPO that no longer exists.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Repair-GPOZaurrBrokenLink [[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-IncludeDomains] <String[]>]
|
||||
[[-ExtendedForestInformation] <IDictionary>] [[-LimitProcessing] <Int32>] [-WhatIf] [-Confirm]
|
||||
[<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
Removes any link to GPO that no longer exists.
|
||||
It scans all site, organizational unit or domain root making sure every single link that may be linking to GPO that doesn't exists anymore is gone.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Repair-GPOZaurrBrokenLink -Verbose -LimitProcessing 1 -WhatIf
|
||||
```
|
||||
|
||||
### EXAMPLE 2
|
||||
```
|
||||
Repair-GPOZaurrBrokenLink -Verbose -IncludeDomains ad.evotec.pl -LimitProcessing 1 -WhatIf
|
||||
```
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
Allows to specify maximum number of items that will be fixed in a single run.
|
||||
It doesn't affect amount of GPOs processed
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: 0
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -WhatIf
|
||||
Shows what would happen if the cmdlet runs.
|
||||
The cmdlet is not run.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: wi
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
@@ -8,7 +8,7 @@ schema: 2.0.0
|
||||
# Repair-GPOZaurrNetLogonOwner
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Sets new owner to each file in NetLogon share.
|
||||
|
||||
## SYNTAX
|
||||
|
||||
@@ -19,41 +19,24 @@ Repair-GPOZaurrNetLogonOwner [[-Forest] <String>] [[-ExcludeDomains] <String[]>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Sets new owner to each file in NetLogon share.
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Repair-GPOZaurrNetLogonOwner -WhatIf -Verbose -IncludeDomains ad.evotec.pl
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
@@ -62,43 +45,13 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
@@ -107,23 +60,39 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
{{ Fill LimitProcessing Description }}
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Principal
|
||||
{{ Fill Principal Description }}
|
||||
Provide named owner.
|
||||
If not provided default S-1-5-32-544 is used.
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
@@ -131,8 +100,24 @@ Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Position: 5
|
||||
Default value: S-1-5-32-544
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
Allows to specify maximum number of items that will be fixed in a single run.
|
||||
It doesn't affect amount of GPOs processed
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 6
|
||||
Default value: 2147483647
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
@@ -153,16 +138,29 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -0,0 +1,169 @@
|
||||
---
|
||||
external help file: GPOZaurr-help.xml
|
||||
Module Name: GPOZaurr
|
||||
online version:
|
||||
schema: 2.0.0
|
||||
---
|
||||
|
||||
# Repair-GPOZaurrPermission
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
|
||||
## SYNTAX
|
||||
|
||||
```
|
||||
Repair-GPOZaurrPermission [-Type] <String[]> [[-Forest] <String>] [[-ExcludeDomains] <String[]>]
|
||||
[[-IncludeDomains] <String[]>] [[-ExtendedForestInformation] <IDictionary>] [[-LimitProcessing] <Int32>]
|
||||
[-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -Confirm
|
||||
Prompts you for confirmation before running the cmdlet.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: cf
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 4
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -LimitProcessing
|
||||
{{ Fill LimitProcessing Description }}
|
||||
|
||||
```yaml
|
||||
Type: Int32
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Type
|
||||
{{ Fill Type Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Accepted values: AuthenticatedUsers, Unknown, System, Administrative, All
|
||||
|
||||
Required: True
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -WhatIf
|
||||
Shows what would happen if the cmdlet runs.
|
||||
The cmdlet is not run.
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases: wi
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
|
||||
## RELATED LINKS
|
||||
+50
-54
@@ -8,7 +8,7 @@ schema: 2.0.0
|
||||
# Save-GPOZaurrFiles
|
||||
|
||||
## SYNOPSIS
|
||||
{{ Fill in the Synopsis }}
|
||||
Exports GPO XML data to files and saves it to a given path
|
||||
|
||||
## SYNTAX
|
||||
|
||||
@@ -18,41 +18,24 @@ Save-GPOZaurrFiles [[-Forest] <String>] [[-ExcludeDomains] <String[]>] [[-Includ
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
{{ Fill in the Description }}
|
||||
Exports GPO XML data to files and saves it to a given path
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Example 1
|
||||
```powershell
|
||||
PS C:\> {{ Add example code here }}
|
||||
### EXAMPLE 1
|
||||
```
|
||||
Save-GPOZaurrFiles -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportEvotec' -DeleteExisting -Verbose
|
||||
```
|
||||
|
||||
{{ Add example description here }}
|
||||
|
||||
## PARAMETERS
|
||||
|
||||
### -DeleteExisting
|
||||
{{ Fill DeleteExisting Description }}
|
||||
### -Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExcludeDomains
|
||||
{{ Fill ExcludeDomains Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
@@ -61,14 +44,29 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ExtendedForestInformation
|
||||
{{ Fill ExtendedForestInformation Description }}
|
||||
### -ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: IDictionary
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
|
||||
Required: False
|
||||
Position: 3
|
||||
Default value: None
|
||||
@@ -76,26 +74,11 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Forest
|
||||
{{ Fill Forest Description }}
|
||||
### -ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases: ForestName
|
||||
|
||||
Required: False
|
||||
Position: 0
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GPOPath
|
||||
{{ Fill GPOPath Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Type: IDictionary
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
@@ -106,31 +89,44 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -IncludeDomains
|
||||
{{ Fill IncludeDomains Description }}
|
||||
### -GPOPath
|
||||
Path where to save XML files from GPOReport
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Domain, Domains
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Position: 5
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -DeleteExisting
|
||||
Delete existing files before saving new ones
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: False
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### CommonParameters
|
||||
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216).
|
||||
|
||||
## INPUTS
|
||||
|
||||
### None
|
||||
|
||||
## OUTPUTS
|
||||
|
||||
### System.Object
|
||||
## NOTES
|
||||
General notes
|
||||
|
||||
## RELATED LINKS
|
||||
|
||||
@@ -16,14 +16,15 @@ Sets GPO Owner to Domain Admins or other choosen account
|
||||
```
|
||||
Set-GPOZaurrOwner -Type <String> [-Forest <String>] [-ExcludeDomains <String[]>] [-IncludeDomains <String[]>]
|
||||
[-ExtendedForestInformation <IDictionary>] [-Principal <String>] [-SkipSysvol] [-LimitProcessing <Int32>]
|
||||
[-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
[-ApprovedOwner <String[]>] [-Action <String>] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### Named
|
||||
```
|
||||
Set-GPOZaurrOwner [-GPOName <String>] [-GPOGuid <String>] [-Forest <String>] [-ExcludeDomains <String[]>]
|
||||
[-IncludeDomains <String[]>] [-ExtendedForestInformation <IDictionary>] [-Principal <String>] [-SkipSysvol]
|
||||
[-LimitProcessing <Int32>] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
|
||||
[-LimitProcessing <Int32>] [-ApprovedOwner <String[]>] [-Action <String>] [-Force] [-WhatIf] [-Confirm]
|
||||
[<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
@@ -43,6 +44,7 @@ Set-GPOZaurrOwner -Type All -Verbose -WhatIf -LimitProcessing 2
|
||||
### -Type
|
||||
Unknown - finds unknown Owners and sets them to Administrative (Domain Admins) or chosen principal
|
||||
NotMatching - find administrative groups only and if sysvol and gpo doesn't match - replace with chosen principal or Domain Admins if not specified
|
||||
Inconsistent - same as not NotMatching
|
||||
NotAdministrative - combination of Unknown/NotMatching and NotAdministrative - replace with chosen principal or Domain Admins if not specified
|
||||
All - if Owner is known it checks if it's Administrative, if it sn't it fixes that.
|
||||
If owner is unknown it fixes it
|
||||
@@ -198,8 +200,38 @@ Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -ApprovedOwner
|
||||
{{ Fill ApprovedOwner Description }}
|
||||
|
||||
```yaml
|
||||
Type: String[]
|
||||
Parameter Sets: (All)
|
||||
Aliases: Exclusion, Exclusions
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Action
|
||||
{{ Fill Action Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -Force
|
||||
{{ Fill Force Description }}
|
||||
Pushes new owner regardless if it's already set or not
|
||||
|
||||
```yaml
|
||||
Type: SwitchParameter
|
||||
|
||||
@@ -13,8 +13,14 @@ Allows to exclude Group Policy from being affected by fixes
|
||||
|
||||
## SYNTAX
|
||||
|
||||
### Name (Default)
|
||||
```
|
||||
Skip-GroupPolicy [[-Name] <String>] [[-DomaiName] <String>] [<CommonParameters>]
|
||||
Skip-GroupPolicy [-Name <String>] [-DomaiName <String>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
### Guid
|
||||
```
|
||||
Skip-GroupPolicy [-GUID <String>] [-DomaiName <String>] [<CommonParameters>]
|
||||
```
|
||||
|
||||
## DESCRIPTION
|
||||
@@ -50,11 +56,26 @@ Define Group Policy Name to skip
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: (All)
|
||||
Parameter Sets: Name
|
||||
Aliases: GpoName, DisplayName
|
||||
|
||||
Required: False
|
||||
Position: 1
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
```
|
||||
|
||||
### -GUID
|
||||
{{ Fill GUID Description }}
|
||||
|
||||
```yaml
|
||||
Type: String
|
||||
Parameter Sets: Guid
|
||||
Aliases: ID
|
||||
|
||||
Required: False
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
@@ -70,7 +91,7 @@ Parameter Sets: (All)
|
||||
Aliases:
|
||||
|
||||
Required: False
|
||||
Position: 2
|
||||
Position: Named
|
||||
Default value: None
|
||||
Accept pipeline input: False
|
||||
Accept wildcard characters: False
|
||||
|
||||
@@ -1,7 +1,11 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
# Remove GPOS
|
||||
Remove-GPOZaurr -Type Empty, Unlinked -BackupPath "$Env:UserProfile\Desktop\GPO" -BackupDated -LimitProcessing 2 -Verbose -WhatIf
|
||||
# Remove GPOS, but don't touch 2 defined exclusions
|
||||
$ExcludeGroupPolicies = {
|
||||
'TEST | Drive Mapping 1',
|
||||
'TEST | Drive Mapping 2'
|
||||
}
|
||||
Remove-GPOZaurr -Type Empty -BackupPath "$Env:UserProfile\Desktop\GPO" -BackupDated -LimitProcessing 3 -Verbose -WhatIf -ExcludeGroupPolicies $ExcludeGroupPolicies
|
||||
|
||||
# Remove GPOS, but don't touch 2 defined exclusions
|
||||
Remove-GPOZaurr -Type Empty, Unlinked -BackupPath "$Env:UserProfile\Desktop\GPO" -BackupDated -LimitProcessing 2 -Verbose -WhatIf {
|
||||
|
||||
@@ -3,5 +3,5 @@
|
||||
#$GPOS = Get-GPOZaurr -GPOName 'TEST | Office Configuration'
|
||||
#$GPOS | Format-Table -AutoSize *
|
||||
|
||||
$GPOS = Get-GPOZaurr -GPOName 'New Group Policy Object3'
|
||||
$GPOS = Get-GPOZaurr -GPOName 'TEST | EmptyWITHGPF'
|
||||
$GPOS | Format-Table -AutoSize *
|
||||
@@ -1,3 +1,3 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
#Clear-Host
|
||||
Remove-GPOZaurrPermission -Verbose -Type Unknown -LimitProcessing 1 #-WhatIf
|
||||
Remove-GPOZaurrPermission -Verbose -Type Unknown -LimitProcessing 5 -GPOName 'CA TEST'
|
||||
@@ -2,7 +2,16 @@
|
||||
|
||||
# This gets the same thing as earlier examples
|
||||
# with a difference where one entry per gpo and all settings for that GPO is stored under settings property.
|
||||
$Output = Invoke-GPOZaurrContent -SingleObject -Verbose
|
||||
#$Output = Invoke-GPOZaurrContent -Verbose #-SingleObject -Verbose
|
||||
#$Output | Format-Table
|
||||
|
||||
|
||||
$Output = Invoke-GPOZaurrContent -Verbose -GPOName 'Default Domain Policy'
|
||||
$Output | Format-Table
|
||||
|
||||
Invoke-GPOZaurr -Type GPOAnalysis -GPOName 'Default Domain Policy' -Verbose
|
||||
|
||||
|
||||
return
|
||||
$Output.Reports.RegistrySettings | Format-Table *
|
||||
$Output.Reports.RegistrySettings[0].Settings | Format-Table *
|
||||
@@ -1,4 +1,4 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
$Output = Invoke-GPOZaurrContent -Verbose -OutputType HTML, Object -Open -GPOPath "C:\Support\GitHub\GpoZaurr\Ignore\NewExamples" ##-Type LocalGroups
|
||||
$Output = Invoke-GPOZaurrContent -SingleObject -Verbose -OutputType HTML, Object -Open -GPOPath "C:\Users\przemyslaw.klys\OneDrive - Evotec\Desktop\Test"
|
||||
$Output | Format-Table
|
||||
@@ -1,16 +1,30 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
#$Output = Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -PassThru -Type GPOConsistency, GPOList, GPODuplicates, GPOBroken, GPOOwners, NetLogonOwners, GPOPermissionsRead, GPOPermissionsAdministrative,GPOPermissionsUnknown
|
||||
# # Shows how to use exclusions for GPOList (different way)
|
||||
# Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPOList -Online -Exclusions {
|
||||
# Skip-GroupPolicy -Name 'de14_usr_std'
|
||||
# Skip-GroupPolicy -Name 'ALL | Enable RDP' -DomaiName 'ad.evotec.xyz'
|
||||
# '01446204-d2b5-4c9a-a539-5d0f64f27fbc'
|
||||
# '{01cef2e1-ea5c-4c4a-bd43-94d89d8a7810}'
|
||||
# }
|
||||
|
||||
# Shows how to use exclusions (supported only in GPOBlockedInheritance)
|
||||
Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPOBlockedInheritance -Online -Exclusions @(
|
||||
'OU=Test,OU=ITR02,DC=ad,DC=evotec,DC=xyz'
|
||||
)
|
||||
# Invoke-GPOZaurr -Type GPOOrganizationalUnit -Online -FilePath $PSScriptRoot\Reports\GPOZaurr.html
|
||||
|
||||
<#
|
||||
# Shows how to use exclusions for GPOList (different way)
|
||||
Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPOList -Online -Exclusions {
|
||||
Skip-GroupPolicy -Name 'de14_usr_std'
|
||||
Skip-GroupPolicy -Name 'ALL | Enable RDP' -DomaiName 'ad.evotec.xyz'
|
||||
}
|
||||
#>
|
||||
# # Shows how to use exclusions (supported only in GPOBlockedInheritance)
|
||||
# Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPOBlockedInheritance -Online -Exclusions @(
|
||||
# 'OU=Test,OU=ITR02,DC=ad,DC=evotec,DC=xyz'
|
||||
# )
|
||||
|
||||
# # different approach to query multiple reports or just one
|
||||
# Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -PassThru -Type GPOConsistency, GPOList, GPODuplicates, GPOBroken, GPOOwners, NetLogonOwners, GPOPermissionsRead, GPOPermissionsAdministrative, GPOPermissionsUnknown
|
||||
|
||||
#Invoke-GPOZaurr -Type GPOOwners,GPOConsistency -Online -FilePath $PSScriptRoot\Reports\GPOZaurr.html
|
||||
|
||||
#Invoke-GPOZaurr -Type GPOOwners -Online -FilePath $PSScriptRoot\Reports\GPOZaurr.html
|
||||
|
||||
##Invoke-GPOZaurr -Type GPOOwners,GPOConsistency -Online -FilePath $PSScriptRoot\Reports\GPOZaurr.html -SplitReports
|
||||
#invoke-gpozaurr -Type GPOOrganizationalUnit
|
||||
#Invoke-GPOZaurr -Online -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPOAnalysis #-SplitReports -Forest test.evotec.pl
|
||||
|
||||
|
||||
Invoke-GPOZaurr -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPOBlockedInheritance -Forest 'ad.evotec.xyz'
|
||||
@@ -9,8 +9,14 @@ $GPOS = Get-GPOZaurr -ExcludeGroupPolicies {
|
||||
}
|
||||
$GPOS | Format-Table -AutoSize *
|
||||
|
||||
Invoke-GPOZaurr -Type GPOList -Exclusions {
|
||||
$Output = Invoke-GPOZaurr -Type GPOList -Exclusions {
|
||||
Skip-GroupPolicy -Name 'All | Trusted Websites' -DomaiName 'ad.evotec.xyz'
|
||||
'{D39BF08A-87BF-4662-BFA0-E56240EBD5A2}'
|
||||
"104da6a7-c7d2-48da-b24b-8fa584f7b0b6"
|
||||
"{087b4f69-c541-429f-8dfd-0eb3ed133910}"
|
||||
'COMPUTERS | Enable Sets'
|
||||
}
|
||||
'24194523-bb82-439c-a533-abf4f30fa2c4'
|
||||
'{31b2f340-016d-11d2-945f-00c04fb984f9 } '
|
||||
} -PassThru
|
||||
|
||||
$Output.GPOList
|
||||
@@ -0,0 +1,3 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
Invoke-GPOZaurr -Online -Verbose -FilePath $PSScriptRoot\Reports\GPOZaurr.html -SplitReports
|
||||
@@ -0,0 +1,16 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
#Save-GPOZaurrFiles -GPOPath $Env:USERPROFILE\Desktop\TestF
|
||||
|
||||
#Get-GPOZaurr -GPOPath "$Env:USERPROFILE\Desktop\TestF" | Sort-Object -Property DisplayName | Where-Object { $_.EMpty -eq $true } | Format-Table *
|
||||
|
||||
|
||||
|
||||
return
|
||||
$GPO = Get-GPOZaurr -GPOName 'ALL | Allow use of biometrics'
|
||||
$GPO | Format-List *
|
||||
|
||||
#$GPO.Count
|
||||
#$GPO | Where-Object { $_.Empty -eq $true } | Format-Table *
|
||||
#($GPO | Where-Object { $_.Empty -eq $true }).Count
|
||||
#$GPO | Where-Object { $_.DisplayName -like "*TEST*" } | Format-Table *
|
||||
@@ -1,5 +1,8 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
$OUs = Get-GPOZaurrOrganizationalUnit
|
||||
$Ous | Format-Table
|
||||
|
||||
Get-GPOZaurrOrganizationalUnit -Verbose -Option Unlink -Exclusions @(
|
||||
'OU=Groups,OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
) | Format-Table
|
||||
@@ -8,9 +11,7 @@ Get-GPOZaurrOrganizationalUnit -Verbose -ExcludeOrganizationalUnit @(
|
||||
'*,OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
) | Format-Table
|
||||
|
||||
|
||||
Invoke-GPOZaurr -Type GPOOrganizationalUnit -Online -FilePath $PSScriptRoot\Reports\GPOZaurrOU.html -Exclusions @(
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
'*OU=Production,DC=ad,DC=evotec,DC=pl'
|
||||
'*OU=Accounts,OU=Administration,DC=ad,DC=evotec,DC=xyz'
|
||||
)
|
||||
@@ -0,0 +1,4 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
Get-GPOZaurrUpdates -DateRange Last14Days -DateProperty WhenCreated, WhenChanged -Verbose -IncludeDomains 'ad.evotec.pl' | Format-List
|
||||
Get-GPOZaurrUpdates -DateRange Last14Days -DateProperty WhenCreated -Verbose | Format-Table
|
||||
@@ -0,0 +1,3 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
Export-GPOZaurrContent -FolderOutput $PSScriptRoot\ExportedXML -ReportType XML
|
||||
@@ -0,0 +1,4 @@
|
||||
Import-Module .\GPoZaurr.psd1 -Force
|
||||
|
||||
$Data = Invoke-GPOZaurr -Online -FilePath $PSScriptRoot\Reports\GPOZaurr.html -Type GPORedirect -PassThru
|
||||
$Data.GPORedirect
|
||||
@@ -0,0 +1,11 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
$Output = Invoke-GPOZaurrContent -Verbose -GPOName 'Default Domain Policy'
|
||||
$Output | Format-Table
|
||||
|
||||
# You need PSWriteOffice for that
|
||||
foreach ($Key in $Output.Keys) {
|
||||
$Output[$Key] | Export-OfficeExcel -FilePath $Env:USERPROFILE\Desktop\GPOAnalysis.xlsx -WorkSheetName $Key
|
||||
}
|
||||
|
||||
Invoke-GPOZaurr -Type GPOAnalysis -GPOName 'ALL | Allow use of biometrics', 'ALL | Enable RDP' -GPOGUID '{31B2F340-016D-11D2-945F-00C04FB984F9}' -IncludeDomains 'ad.evotec.xyz' -Verbose
|
||||
@@ -0,0 +1,10 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
# search by guid or name for specific GPOs
|
||||
#Get-GPOZaurrMissingFiles -GPOGUID '{2F326111-C21B-4892-B7BC-9BDCB201FFCC}' | Format-Table
|
||||
|
||||
# search for all GPOs with missing files
|
||||
#Get-GPOZaurrMissingFiles -BrokenOnly | Format-Table
|
||||
|
||||
# search for all GPOs with missing files for everythin
|
||||
Invoke-GPOZaurr -Type GPOBrokenPartially #, GPOBroken, GPOBrokenLink
|
||||
@@ -0,0 +1,4 @@
|
||||
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
|
||||
|
||||
Get-GPOZaurrDuplicateObject -Verbose
|
||||
|
||||
@@ -3097,7 +3097,7 @@ Import-Module GPOZaurr -Force</pre><div class="defaultText"><span>Using force ma
|
||||
"When executed it will take a while to generate all data and provide you with new report depending on size of environment."
|
||||
"Once confirmed that data is still showing issues and requires fixing please proceed with next step."
|
||||
</span></div><div class="defaultText"><span>Alternatively if you prefer working with console you can run: </span></div><pre data-enlighter-language="powershell">$GPOOutput = Get-GPOZaurrPermissionConsistency
|
||||
$GPOOutput | Format-Table # do your actions as desired</pre><div class="defaultText"><span>It provides same data as you see in table above just doesn't prettify it for you.</span></div></div><div style="padding:0px" id="WizardStep-0tiejcyn" class="tab-pane flexElement" role="tabpanel"><div class="defaultText"><span>Following command when executed fixes inconsistent permissions.</span></div><div class="defaultText"><span style="color:#000000;font-weight:normal">Make sure when running it for the first time to run it with </span><span style="color:#ff0000;font-weight:bold">WhatIf</span><span style="color:#000000;font-weight:normal"> parameter as shown below to prevent accidental removal.</span></div><div class="defaultText"><span>Make sure to fill in TargetDomain to match your Domain Admin permission account</span></div><pre data-enlighter-language="powershell">Repair-GPOZaurrPermissionConsistency -IncludeDomains "TargetDomain" -Verbose -WhatIf</pre><div class="defaultText"><span>After execution please make sure there are no errors, make sure to review provided output, and confirm that what is about to be deleted matches expected data. Once happy with results please follow with command: </span></div><pre data-enlighter-language="powershell">Repair-GPOZaurrPermissionConsistency -LimitProcessing 2 -IncludeDomains "TargetDomain"</pre><div class="defaultText"><span>This command when executed repairs only first X inconsistent permissions. Use LimitProcessing parameter to prevent mass fixing and increase the counter when no errors occur. </span><span>Repeat step above as much as needed increasing LimitProcessing count till there's nothing left. In case of any issues please review and action accordingly. </span></div><div class="defaultText"><span>If there's nothing else to be fixed, we can skip to next step step</span></div></div><div style="padding:0px" id="WizardStep-rj10lm2s" class="tab-pane flexElement" role="tabpanel"><div class="defaultText"><span>Unfortunetly this step is manual until automation is developed. </span></div><div class="defaultText"><span>If there are inconsistent permissions found inside GPO one has to fix them manually by going into SYSVOL and making sure inheritance is enabled, and that permissions are consistent across all files.</span></div></div><div style="padding:0px" id="WizardStep-xg65antb" class="tab-pane flexElement" role="tabpanel"><div class="defaultText"><span>Once cleanup task was executed properly, we need to verify that report now shows no problems.</span></div><pre data-enlighter-language="powershell">Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrPermissionsInconsistentAfter.html -Verbose -Type GPOConsistency</pre><div class="defaultText"><span style="color:#4d1a7f">If everything is healthy in the report you're done! Enjoy rest of the day!</span></div></div></div><script> $(document).ready(function(){
|
||||
$GPOOutput | Format-Table # do your actions as desired</pre><div class="defaultText"><span>It provides same data as you see in table above just doesn't prettify it for you.</span></div></div><div style="padding:0px" id="WizardStep-0tiejcyn" class="tab-pane flexElement" role="tabpanel"><div class="defaultText"><span>Following command when executed fixes inconsistent permissions.</span></div><div class="defaultText"><span style="color:#000000;font-weight:normal">Make sure when running it for the first time to run it with </span><span style="color:#ff0000;font-weight:bold">WhatIf</span><span style="color:#000000;font-weight:normal"> parameter as shown below to prevent accidental removal.</span></div><div class="defaultText"><span>Make sure to fill in TargetDomain to match your Domain Admin permission account</span></div><pre data-enlighter-language="powershell">Repair-GPOZaurrPermissionConsistency -IncludeDomains "TargetDomain" -Verbose -WhatIf</pre><div class="defaultText"><span>After execution please make sure there are no errors, make sure to review provided output, and confirm that what is about to be deleted matches expected data. Once happy with results please follow with command: </span></div><pre data-enlighter-language="powershell">Repair-GPOZaurrPermissionConsistency -LimitProcessing 2 -IncludeDomains "TargetDomain"</pre><div class="defaultText"><span>This command when executed repairs only first X inconsistent permissions. Use LimitProcessing parameter to prevent mass fixing and increase the counter when no errors occur. </span><span>Repeat step above as much as needed increasing LimitProcessing count till there's nothing left. In case of any issues please review and action accordingly. </span></div><div class="defaultText"><span>If there's nothing else to be fixed, we can skip to next step step</span></div></div><div style="padding:0px" id="WizardStep-rj10lm2s" class="tab-pane flexElement" role="tabpanel"><div class="defaultText"><span>Unfortunately this step is manual until automation is developed. </span></div><div class="defaultText"><span>If there are inconsistent permissions found inside GPO one has to fix them manually by going into SYSVOL and making sure inheritance is enabled, and that permissions are consistent across all files.</span></div></div><div style="padding:0px" id="WizardStep-xg65antb" class="tab-pane flexElement" role="tabpanel"><div class="defaultText"><span>Once cleanup task was executed properly, we need to verify that report now shows no problems.</span></div><pre data-enlighter-language="powershell">Invoke-GPOZaurr -FilePath $Env:UserProfile\Desktop\GPOZaurrPermissionsInconsistentAfter.html -Verbose -Type GPOConsistency</pre><div class="defaultText"><span style="color:#4d1a7f">If everything is healthy in the report you're done! Enjoy rest of the day!</span></div></div></div><script> $(document).ready(function(){
|
||||
// SmartWizard initialize
|
||||
$('#TabPanel-fbsgNINg').smartWizard({
|
||||
"autoAdjustHeight": false,
|
||||
|
||||
+15
-11
@@ -4,31 +4,35 @@
|
||||
CmdletsToExport = @()
|
||||
CompanyName = 'Evotec'
|
||||
CompatiblePSEditions = @('Desktop')
|
||||
Copyright = '(c) 2011 - 2021 Przemyslaw Klys @ Evotec. All rights reserved.'
|
||||
Copyright = '(c) 2011 - 2024 Przemyslaw Klys @ Evotec. All rights reserved.'
|
||||
Description = 'Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.'
|
||||
FunctionsToExport = @('Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Clear-GPOZaurrSysvolDFSR', 'ConvertFrom-CSExtension', 'Find-CSExtension', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrBroken', 'Get-GPOZaurrBrokenLink', 'Get-GPOZaurrDictionary', 'Get-GPOZaurrDuplicateObject', 'Get-GPOZaurrFiles', 'Get-GPOZaurrFilesPolicyDefinition', 'Get-GPOZaurrFolders', 'Get-GPOZaurrInheritance', 'Get-GPOZaurrLegacyFiles', 'Get-GPOZaurrLink', 'Get-GPOZaurrLinkSummary', 'Get-GPOZaurrNetLogon', 'Get-GPOZaurrOrganizationalUnit', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionAnalysis', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrPermissionIssue', 'Get-GPOZaurrPermissionRoot', 'Get-GPOZaurrPermissionSummary', 'Get-GPOZaurrSysvolDFSR', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurr', 'Invoke-GPOZaurrContent', 'Invoke-GPOZaurrPermission', 'Invoke-GPOZaurrSupport', 'New-GPOZaurrWMI', 'Optimize-GPOZaurr', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrBroken', 'Remove-GPOZaurrDuplicateObject', 'Remove-GPOZaurrFolders', 'Remove-GPOZaurrLegacyFiles', 'Remove-GPOZaurrLinkEmptyOU', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrBrokenLink', 'Repair-GPOZaurrNetLogonOwner', 'Repair-GPOZaurrPermission', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Set-GPOOwner', 'Set-GPOZaurrOwner', 'Set-GPOZaurrStatus', 'Skip-GroupPolicy')
|
||||
FunctionsToExport = @('Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Clear-GPOZaurrSysvolDFSR', 'ConvertFrom-CSExtension', 'Export-GPOZaurrContent', 'Find-CSExtension', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrBroken', 'Get-GPOZaurrBrokenLink', 'Get-GPOZaurrDictionary', 'Get-GPOZaurrDuplicateObject', 'Get-GPOZaurrFiles', 'Get-GPOZaurrFilesPolicyDefinition', 'Get-GPOZaurrFolders', 'Get-GPOZaurrInheritance', 'Get-GPOZaurrLegacyFiles', 'Get-GPOZaurrLink', 'Get-GPOZaurrLinkSummary', 'Get-GPOZaurrMissingFiles', 'Get-GPOZaurrNetLogon', 'Get-GPOZaurrOrganizationalUnit', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionAnalysis', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrPermissionIssue', 'Get-GPOZaurrPermissionRoot', 'Get-GPOZaurrPermissionSummary', 'Get-GPOZaurrRedirect', 'Get-GPOZaurrSysvolDFSR', 'Get-GPOZaurrUpdates', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurr', 'Invoke-GPOZaurrContent', 'Invoke-GPOZaurrPermission', 'Invoke-GPOZaurrSupport', 'New-GPOZaurrWMI', 'Optimize-GPOZaurr', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrBroken', 'Remove-GPOZaurrDuplicateObject', 'Remove-GPOZaurrFolders', 'Remove-GPOZaurrLegacyFiles', 'Remove-GPOZaurrLinkEmptyOU', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrBrokenLink', 'Repair-GPOZaurrNetLogonOwner', 'Repair-GPOZaurrPermission', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Set-GPOOwner', 'Set-GPOZaurrOwner', 'Set-GPOZaurrStatus', 'Skip-GroupPolicy')
|
||||
GUID = 'f7d4c9e4-0298-4f51-ad77-e8e3febebbde'
|
||||
ModuleVersion = '0.0.130'
|
||||
ModuleVersion = '1.1.6'
|
||||
PowerShellVersion = '5.1'
|
||||
PrivateData = @{
|
||||
PSData = @{
|
||||
Tags = @('Windows', 'ActiveDirectory', 'GPO', 'GroupPolicy')
|
||||
ProjectUri = 'https://github.com/EvotecIT/GPOZaurr'
|
||||
ExternalModuleDependencies = @('CimCmdlets', 'Microsoft.PowerShell.Management', 'Microsoft.PowerShell.Utility', 'Microsoft.PowerShell.Security')
|
||||
ProjectUri = 'https://github.com/EvotecIT/GPOZaurr'
|
||||
Tags = @('Windows', 'ActiveDirectory', 'GPO', 'GroupPolicy')
|
||||
}
|
||||
}
|
||||
RequiredModules = @(@{
|
||||
ModuleVersion = '0.0.210'
|
||||
ModuleName = 'PSSharedGoods'
|
||||
Guid = '0b0ba5c5-ec85-4c2b-a718-874e55a8bc3f'
|
||||
ModuleName = 'PSWriteColor'
|
||||
ModuleVersion = '1.0.1'
|
||||
}, @{
|
||||
Guid = 'ee272aa8-baaa-4edf-9f45-b6d6f7d844fe'
|
||||
ModuleName = 'PSSharedGoods'
|
||||
ModuleVersion = '0.0.297'
|
||||
}, @{
|
||||
ModuleVersion = '0.0.130'
|
||||
ModuleName = 'ADEssentials'
|
||||
Guid = '9fc9fd61-7f11-4f4b-a527-084086f1905f'
|
||||
ModuleName = 'ADEssentials'
|
||||
ModuleVersion = '0.0.221'
|
||||
}, @{
|
||||
ModuleVersion = '0.0.158'
|
||||
ModuleName = 'PSWriteHTML'
|
||||
Guid = 'a7bdf640-f5cb-4acf-9de0-365b322d245c'
|
||||
ModuleName = 'PSWriteHTML'
|
||||
ModuleVersion = '1.27.0'
|
||||
}, 'CimCmdlets', 'Microsoft.PowerShell.Management', 'Microsoft.PowerShell.Utility', 'Microsoft.PowerShell.Security')
|
||||
RootModule = 'GPOZaurr.psm1'
|
||||
}
|
||||
@@ -1,4 +1,32 @@
|
||||
function ConvertFrom-XMLRSOP {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts XML data representing Resultant Set of Policy (RSOP) into a structured PowerShell object.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes XML data representing RSOP and converts it into a structured PowerShell object for easier manipulation and analysis.
|
||||
|
||||
.PARAMETER Content
|
||||
The XML content representing the RSOP data.
|
||||
|
||||
.PARAMETER ResultsType
|
||||
The type of results being processed.
|
||||
|
||||
.PARAMETER Splitter
|
||||
The delimiter used to split certain data elements.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertFrom-XMLRSOP -Content $xmlData -ResultsType "Computer" -Splitter "`n"
|
||||
|
||||
Description:
|
||||
Converts the XML data in $xmlData representing computer RSOP results using a newline as the splitter.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertFrom-XMLRSOP -Content $xmlData -ResultsType "User" -Splitter ","
|
||||
|
||||
Description:
|
||||
Converts the XML data in $xmlData representing user RSOP results using a comma as the splitter.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[System.Xml.XmlElement]$Content,
|
||||
|
||||
@@ -1,4 +1,29 @@
|
||||
function ConvertTo-XMLAccountPolicy {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PowerShell custom object representing an account policy into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PowerShell custom object representing an account policy and converts it into XML format for storage or transmission.
|
||||
|
||||
.PARAMETER GPO
|
||||
The PowerShell custom object representing the account policy.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLAccountPolicy -GPO $accountPolicyObject -SingleObject
|
||||
|
||||
Description:
|
||||
Converts the $accountPolicyObject into XML format for a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$accountPolicies | ConvertTo-XMLAccountPolicy -SingleObject
|
||||
|
||||
Description:
|
||||
Converts multiple account policies in $accountPolicies into XML format for each object.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,29 @@
|
||||
function ConvertTo-XMLAudit {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PowerShell custom object representing an audit policy into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PowerShell custom object representing an audit policy and converts it into XML format for storage or transmission.
|
||||
|
||||
.PARAMETER GPO
|
||||
The PowerShell custom object representing the audit policy.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLAudit -GPO $auditPolicyObject -SingleObject
|
||||
|
||||
Description:
|
||||
Converts the $auditPolicyObject into XML format for a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$auditPolicies | ConvertTo-XMLAudit -SingleObject
|
||||
|
||||
Description:
|
||||
Converts multiple audit policies in $auditPolicies into XML format for each object.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,32 @@
|
||||
function ConvertTo-XMLCertificates {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PowerShell custom object representing certificate data into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PowerShell custom object representing certificate data and converts it into XML format for storage or transmission.
|
||||
|
||||
.PARAMETER GPO
|
||||
The PowerShell custom object representing the certificate data.
|
||||
|
||||
.PARAMETER Category
|
||||
An array of categories for the certificate data.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLCertificates -GPO $certificateDataObject -Category @('Category1', 'Category2') -SingleObject
|
||||
|
||||
Description:
|
||||
Converts the $certificateDataObject into XML format for multiple categories as a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$certificateDataObjects | ConvertTo-XMLCertificates -Category @('Category1') -SingleObject
|
||||
|
||||
Description:
|
||||
Converts multiple certificate data objects in $certificateDataObjects into XML format for a single category.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,29 @@
|
||||
function ConvertTo-XMLDriveMapSettings {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PowerShell custom object representing drive mapping settings into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PowerShell custom object representing drive mapping settings and converts it into XML format for storage or transmission.
|
||||
|
||||
.PARAMETER GPO
|
||||
The PowerShell custom object representing the drive mapping settings.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLDriveMapSettings -GPO $driveMapSettingsObject -SingleObject
|
||||
|
||||
Description:
|
||||
Converts the $driveMapSettingsObject into XML format for a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$driveMapSettings | ConvertTo-XMLDriveMapSettings -SingleObject
|
||||
|
||||
Description:
|
||||
Converts multiple drive mapping settings in $driveMapSettings into XML format for each object.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,38 @@
|
||||
function ConvertTo-XMLEventLog {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Object (GPO) data to an XML event log format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PSCustomObject representing GPO data and converts it to an XML event log format. It creates a structured XML output with specific GPO properties.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the PSCustomObject containing GPO data to be converted.
|
||||
|
||||
.EXAMPLE
|
||||
$GPOData = [PSCustomObject]@{
|
||||
DisplayName = 'Example GPO'
|
||||
DomainName = 'example.com'
|
||||
GUID = '12345678-1234-1234-1234-1234567890AB'
|
||||
GpoType = 'Security'
|
||||
DataSet = @(
|
||||
[PSCustomObject]@{
|
||||
Log = 'Application'
|
||||
Name = 'AuditLogRetentionPeriod'
|
||||
SettingNumber = '1'
|
||||
},
|
||||
[PSCustomObject]@{
|
||||
Log = 'System'
|
||||
Name = 'MaximumLogSize'
|
||||
SettingNumber = '1024'
|
||||
}
|
||||
)
|
||||
Linked = $true
|
||||
LinksCount = 2
|
||||
Links = @('OU=Finance,DC=example,DC=com', 'OU=IT,DC=example,DC=com')
|
||||
}
|
||||
ConvertTo-XMLEventLog -GPO $GPOData
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO
|
||||
|
||||
@@ -1,9 +1,50 @@
|
||||
function ConvertTo-XMLFolderRedirection {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PowerShell custom object representing folder redirection settings into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PowerShell custom object representing folder redirection settings and converts it into XML format for storage or transmission.
|
||||
|
||||
.PARAMETER GPO
|
||||
The PowerShell custom object representing the folder redirection settings.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLFolderRedirection -GPO $folderRedirectionSettingsObject -SingleObject
|
||||
|
||||
Description:
|
||||
Converts the $folderRedirectionSettingsObject into XML format for a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$folderRedirectionSettings | ConvertTo-XMLFolderRedirection -SingleObject
|
||||
|
||||
Description:
|
||||
Converts multiple folder redirection settings in $folderRedirectionSettings into XML format for each object.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
[switch] $SingleObject
|
||||
)
|
||||
# Redirection types a stored as GUID in GPOs. This hash is used to translate into readable text.
|
||||
$FolderID = @{
|
||||
"{1777F761-68AD-4D8A-87BD-30B759FA33DD}" = "Favorites"
|
||||
"{FDD39AD0-238F-46AF-ADB4-6C85480369C7}" = "Documents"
|
||||
"{33E28130-4E1E-4676-835A-98395C3BC3BB}" = "Pictures"
|
||||
"{4BD8D571-6D19-48D3-BE97-422220080E43}" = "Music"
|
||||
"{18989B1D-99B5-455B-841C-AB7C74E4DDFC}" = "Videos"
|
||||
"{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}" = "AppDataRoaming"
|
||||
"{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}" = "Desktop"
|
||||
"{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}" = "StartMenu"
|
||||
"{374DE290-123F-4565-9164-39C4925E467B}" = "Downloads"
|
||||
"{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}" = "Saved Games"
|
||||
"{56784854-C6CB-462B-8169-88E350ACB882}" = "Contacts"
|
||||
"{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}" = "Searches"
|
||||
"{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}" = "Links"
|
||||
}
|
||||
if ($SingleObject) {
|
||||
$CreateGPO = [ordered]@{
|
||||
DisplayName = $GPO.DisplayName
|
||||
@@ -18,6 +59,8 @@
|
||||
[Array] $CreateGPO['Settings'] = foreach ($Folder in $GPO.DataSet) {
|
||||
foreach ($Location in $Folder.Location) {
|
||||
[PSCustomObject] @{
|
||||
ID = $Folder.ID
|
||||
FolderType = $FolderID[$Folder.Id]
|
||||
DestinationPath = $Location.DestinationPath
|
||||
SecuritySID = $Location.SecurityGroup.SID.'#text'
|
||||
SecurityName = $Location.SecurityGroup.Name.'#text'
|
||||
@@ -47,6 +90,7 @@
|
||||
GUID = $GPO.GUID
|
||||
GpoType = $GPO.GpoType
|
||||
Id = $Folder.Id
|
||||
FolderType = $FolderID[$Folder.Id]
|
||||
DestinationPath = $Location.DestinationPath
|
||||
SecuritySID = $Location.SecurityGroup.SID.'#text'
|
||||
SecurityName = $Location.SecurityGroup.Name.'#text'
|
||||
|
||||
@@ -1,4 +1,32 @@
|
||||
function ConvertTo-XMLGenericPolicy {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PowerShell custom object representing generic policy settings into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PowerShell custom object representing generic policy settings and converts it into XML format for storage or transmission.
|
||||
|
||||
.PARAMETER GPO
|
||||
The PowerShell custom object representing the generic policy settings.
|
||||
|
||||
.PARAMETER Category
|
||||
An array of categories for the generic policy settings.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLGenericPolicy -GPO $genericPolicyObject -Category @('Category1', 'Category2') -SingleObject
|
||||
|
||||
Description:
|
||||
Converts the $genericPolicyObject into XML format for multiple categories as a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$genericPolicyObjects | ConvertTo-XMLGenericPolicy -Category @('Category1') -SingleObject
|
||||
|
||||
Description:
|
||||
Converts multiple generic policy settings in $genericPolicyObjects into XML format for a single category.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,29 @@
|
||||
function ConvertTo-XMLGenericPublicKey {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a PSCustomObject representing a Group Policy Object (GPO) to an XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a PSCustomObject representing a GPO and converts it to an XML format. It extracts specific properties from the GPO object and organizes them into a structured XML output.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the PSCustomObject representing the GPO to be converted.
|
||||
|
||||
.PARAMETER Category
|
||||
Specifies an array of strings representing categories to include in the XML output.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLGenericPublicKey -GPO $MyGPO -Category @("Category1", "Category2") -SingleObject
|
||||
Converts the PSCustomObject $MyGPO to an XML format including categories "Category1" and "Category2" as a single object.
|
||||
|
||||
.EXAMPLE
|
||||
$GPOs | ConvertTo-XMLGenericPublicKey -Category @("Category1")
|
||||
Converts multiple GPOs in the $GPOs array to an XML format including category "Category1".
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,29 @@
|
||||
function ConvertTo-XMLGenericSecuritySettings {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Generic Security Settings to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts Generic Security Settings to XML format for further processing.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) to convert.
|
||||
|
||||
.PARAMETER Category
|
||||
Specifies the category of settings to convert.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLGenericSecuritySettings -GPO $GPOObject -Category 'Security'
|
||||
|
||||
Description:
|
||||
Converts the security settings of the specified GPO object to XML format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLGenericSecuritySettings -GPO $GPOObject -Category 'Network'
|
||||
|
||||
Description:
|
||||
Converts the network settings of the specified GPO object to XML format.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLLocalGroups {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Objects (GPO) to XML format for local groups.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts Group Policy Objects (GPO) to XML format for local groups. It takes a GPO object and an optional switch to process a single object.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) to be converted to XML format.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to process a single GPO object.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLLocalGroups -GPO $myGPO
|
||||
Converts the specified GPO object to XML format for local groups.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLLocalGroups -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object to XML format for local groups.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,27 @@
|
||||
function ConvertTo-XMLLocalUser {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Objects (GPO) data to XML format for local users.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts GPO data to XML format specifically for local users. It extracts relevant user settings from the GPO data and organizes them into a structured XML format.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object containing user data to be converted.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single user object or multiple user objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLLocalUser -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object to XML format for local users.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLLocalUser -GPO $myGPO
|
||||
Converts multiple GPO objects to XML format for local users.
|
||||
|
||||
#>
|
||||
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,35 @@
|
||||
function ConvertTo-XMLNested {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts nested XML elements to a structured format for further processing.
|
||||
|
||||
.DESCRIPTION
|
||||
This function recursively converts nested XML elements to a structured format for easier manipulation and analysis. It extracts properties from the XML elements and organizes them into a hierarchical structure.
|
||||
|
||||
.PARAMETER CreateGPO
|
||||
Specifies the dictionary representing the XML structure being created.
|
||||
|
||||
.PARAMETER Setting
|
||||
Specifies the XML element to be processed.
|
||||
|
||||
.PARAMETER SkipNames
|
||||
Specifies an array of property names to skip during processing.
|
||||
|
||||
.PARAMETER Name
|
||||
Specifies the name of the current XML element being processed.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLNested -CreateGPO $MyGPO -Setting $XmlSetting -SkipNames @('Name', 'Value') -Name 'Root'
|
||||
|
||||
Description:
|
||||
Converts the nested XML element $XmlSetting into a structured format stored in $MyGPO, skipping properties 'Name' and 'Value', with the root element named 'Root'.
|
||||
|
||||
.EXAMPLE
|
||||
$XmlElements | ForEach-Object { ConvertTo-XMLNested -CreateGPO $Output -Setting $_ -SkipNames @('ID') -Name 'Element' }
|
||||
|
||||
Description:
|
||||
Processes multiple XML elements in $XmlElements, converting each into a structured format stored in $Output, skipping property 'ID', and naming each element 'Element'.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[System.Collections.IDictionary] $CreateGPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLPolicies {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Object (GPO) data to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts the provided GPO data into XML format for easier processing and analysis.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object containing the data to be converted.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLPolicies -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object $myGPO to XML format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLPolicies -GPO $GPOList
|
||||
Converts multiple GPO objects in $GPOList to XML format.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLPrinter {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Objects (GPO) to an XML printer format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts GPO objects to an XML printer format, providing detailed information about printers and printer connections.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object to be converted.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLPrinter -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object $myGPO to an XML printer format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLPrinter -GPO $myGPO
|
||||
Converts multiple GPO objects to an XML printer format.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,32 @@
|
||||
function ConvertTo-XMLPrinterInternal {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts printer settings to XML format for internal use.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts printer settings to XML format for internal use. It takes a GPO object, entry details, type, and a switch for limited output. The output includes various printer settings in XML format.
|
||||
|
||||
.PARAMETER GPO
|
||||
The GPO object containing printer settings.
|
||||
|
||||
.PARAMETER Entry
|
||||
Details of the printer entry.
|
||||
|
||||
.PARAMETER Type
|
||||
The type of printer setting.
|
||||
|
||||
.PARAMETER Limited
|
||||
Switch to output limited printer settings.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLPrinterInternal -GPO $GPO -Entry $Entry -Type "Network" -Limited
|
||||
Converts the specified printer settings to XML format with limited output.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLPrinterInternal -GPO $GPO -Entry $Entry -Type "Local"
|
||||
Converts the specified printer settings to XML format without limited output.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,59 @@
|
||||
function ConvertTo-XMLRegistryAutologon {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a Group Policy Object (GPO) to an XML format for Registry Autologon settings.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a GPO object as input and extracts relevant Registry Autologon settings to create an XML representation.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) to be converted to XML format for Registry Autologon settings.
|
||||
|
||||
.EXAMPLE
|
||||
$GPO = [PSCustomObject]@{
|
||||
DisplayName = "Autologon GPO"
|
||||
DomainName = "example.com"
|
||||
GUID = "12345678-1234-5678-1234-567812345678"
|
||||
GpoType = "Registry"
|
||||
DataSet = [PSCustomObject]@{
|
||||
Registry = @(
|
||||
[PSCustomObject]@{
|
||||
Properties = [PSCustomObject]@{
|
||||
Key = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
|
||||
Name = "AutoAdminLogon"
|
||||
Value = $true
|
||||
Changed = Get-Date
|
||||
}
|
||||
},
|
||||
[PSCustomObject]@{
|
||||
Properties = [PSCustomObject]@{
|
||||
Key = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
|
||||
Name = "DefaultDomainName"
|
||||
Value = "example.com"
|
||||
Changed = Get-Date
|
||||
}
|
||||
},
|
||||
[PSCustomObject]@{
|
||||
Properties = [PSCustomObject]@{
|
||||
Key = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
|
||||
Name = "DefaultUserName"
|
||||
Value = "user"
|
||||
Changed = Get-Date
|
||||
}
|
||||
},
|
||||
[PSCustomObject]@{
|
||||
Properties = [PSCustomObject]@{
|
||||
Key = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
|
||||
Name = "DefaultPassword"
|
||||
Value = "password"
|
||||
Changed = Get-Date
|
||||
}
|
||||
}
|
||||
)
|
||||
}
|
||||
}
|
||||
ConvertTo-XMLRegistryAutologon -GPO $GPO
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO
|
||||
|
||||
@@ -1,4 +1,34 @@
|
||||
function ConvertTo-XMLRegistryAutologonOnReport {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Object (GPO) settings related to Autologon into an XML report.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a GPO object as input and extracts Autologon related settings to generate an XML report.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object containing Autologon settings.
|
||||
|
||||
.EXAMPLE
|
||||
$GPO = [PSCustomObject]@{
|
||||
DisplayName = "Autologon GPO"
|
||||
DomainName = "example.com"
|
||||
GUID = "12345678-1234-1234-1234-1234567890AB"
|
||||
GpoType = "Security"
|
||||
Settings = @(
|
||||
[PSCustomObject]@{
|
||||
Key = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
|
||||
Name = "AutoAdminLogon"
|
||||
Value = $true
|
||||
Changed = (Get-Date)
|
||||
}
|
||||
)
|
||||
Linked = $true
|
||||
LinksCount = 1
|
||||
Links = "area1.local"
|
||||
}
|
||||
ConvertTo-XMLRegistryAutologonOnReport -GPO $GPO
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO
|
||||
|
||||
@@ -1,4 +1,19 @@
|
||||
function ConvertTo-XMLRegistryInternetExplorerZones {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts registry settings related to Internet Explorer security zones into XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts registry settings from a Group Policy Object (GPO) related to Internet Explorer security zones into XML format. It extracts relevant information such as display name, domain name, GUID, GPO type, configuration, policy type, and security zone based on the registry settings provided.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) containing the registry settings to be converted.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLRegistryInternetExplorerZones -GPO $GPO
|
||||
Converts the registry settings from the specified Group Policy Object ($GPO) related to Internet Explorer security zones into XML format.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLRegistrySettings {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Object (GPO) settings to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts the settings of a Group Policy Object (GPO) to XML format. It can be used to export GPO settings for analysis or backup purposes.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) to convert to XML format.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLRegistrySettings -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object to XML format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLRegistrySettings -GPO $myGPO
|
||||
Converts multiple GPO objects to XML format.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLScripts {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Objects (GPO) to XML scripts.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts GPO objects to XML scripts for further processing.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object to be converted.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLScripts -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object to an XML script.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLScripts -GPO $myGPO
|
||||
Converts multiple GPO objects to XML scripts.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLSecurityOptions {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Object (GPO) data to XML security options.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts GPO data to XML security options for further processing.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object to convert.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSecurityOptions -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object to XML security options.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSecurityOptions -GPO $myGPO
|
||||
Converts multiple GPO objects to XML security options.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLSoftwareInstallation {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Object (GPO) data into XML format for software installation.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes GPO data and converts it into XML format suitable for software installation. It creates an XML structure with detailed information about each software installation entry.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object containing software installation data.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSoftwareInstallation -GPO $GPOObject -SingleObject
|
||||
Converts a single GPO object into XML format for software installation.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSoftwareInstallation -GPO $GPOObject
|
||||
Converts multiple GPO objects into XML format for software installation.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLSystemServices {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Group Policy Objects (GPO) data to an XML format for System Services.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a GPO object and converts its data into an XML format suitable for System Services. It organizes the GPO data including service names, startup modes, security auditing status, permissions, and security descriptors.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the GPO object to be converted to XML format.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSystemServices -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object $myGPO to XML format for System Services.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSystemServices -GPO $myGPO
|
||||
Converts multiple GPO objects to XML format for System Services.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,25 @@
|
||||
function ConvertTo-XMLSystemServicesNT {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a Group Policy Object (GPO) to an XML representation for System Services on Windows NT.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a GPO object and converts it into an XML format specifically tailored for System Services on Windows NT. It extracts relevant information about each service defined in the GPO and structures it in an XML format.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) to be converted to XML.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLSystemServicesNT -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object $myGPO to an XML representation for System Services on Windows NT.
|
||||
|
||||
.EXAMPLE
|
||||
$GPOs | ConvertTo-XMLSystemServicesNT
|
||||
Converts multiple GPO objects in the $GPOs array to XML representations for System Services on Windows NT.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,25 @@
|
||||
function ConvertTo-XMLTaskScheduler {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Task Scheduler settings to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts Task Scheduler settings from a PSCustomObject to XML format. It provides detailed information about the task settings for each task.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) containing the Task Scheduler settings.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLTaskScheduler -GPO $GPOObject -SingleObject
|
||||
Converts the Task Scheduler settings from the specified GPO object to XML format for a single object.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLTaskScheduler -GPO $GPOObject
|
||||
Converts the Task Scheduler settings from the specified GPO object to XML format for multiple objects.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLUserRightsAssignment {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts user rights assignments to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts user rights assignments to XML format based on the provided GPO object.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) to extract user rights assignments from.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to process a single object.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLUserRightsAssignment -GPO $GPOObject -SingleObject
|
||||
Converts user rights assignments from a single GPO object to XML format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLUserRightsAssignment -GPO $GPOObject
|
||||
Converts user rights assignments from multiple GPO objects to XML format.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLWindowsFirewall {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a Group Policy Object (GPO) to an XML representation for Windows Firewall settings.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a GPO object and converts it into an XML format suitable for Windows Firewall settings. It can handle single GPO objects or multiple GPO objects.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object to be converted to XML.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple GPO objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewall -GPO $myGPO -SingleObject
|
||||
Converts a single GPO object $myGPO to an XML representation for Windows Firewall settings.
|
||||
|
||||
.EXAMPLE
|
||||
$GPOs | ConvertTo-XMLWindowsFirewall
|
||||
Converts multiple GPO objects in the $GPOs array to XML representations for Windows Firewall settings.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,25 @@
|
||||
function ConvertTo-XMLWindowsFirewallConnectionSecurityAuthentiation {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Windows Firewall Connection Security Authentication settings to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts Windows Firewall Connection Security Authentication settings from a PSCustomObject to XML format. It provides detailed information about the authentication settings for each connection.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) containing the Windows Firewall Connection Security Authentication settings.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewallConnectionSecurityAuthentiation -GPO $GPOObject -SingleObject
|
||||
Converts the Windows Firewall Connection Security Authentication settings from the specified GPO object to XML format for a single object.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewallConnectionSecurityAuthentiation -GPO $GPOObject
|
||||
Converts the Windows Firewall Connection Security Authentication settings from the specified GPO object to XML format for multiple objects.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLWindowsFirewallProfile {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a Windows Firewall profile to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a Windows Firewall profile object and converts it to XML format for further processing.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Windows Firewall profile object to convert.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single object or multiple objects.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewallProfile -GPO $FirewallProfile -SingleObject
|
||||
Converts a single Windows Firewall profile object to XML format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewallProfile -GPO $FirewallProfiles -SingleObject:$false
|
||||
Converts multiple Windows Firewall profile objects to XML format.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,26 @@
|
||||
function ConvertTo-XMLWindowsFirewallRules {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Windows Firewall rules to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts Windows Firewall rules to XML format for easier management and analysis.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) containing the firewall rules to be converted.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single firewall rule object.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewallRules -GPO $GPOObject -SingleObject
|
||||
Converts all firewall rules in the specified GPO to XML format.
|
||||
|
||||
.EXAMPLE
|
||||
ConvertTo-XMLWindowsFirewallRules -GPO $GPOObject
|
||||
Converts all firewall rules in the specified GPO to XML format without creating a single object.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,28 @@
|
||||
function ConvertTo-XMLWindowsFirewallSecurityRules {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts Windows Firewall security rules data to XML format.
|
||||
|
||||
.DESCRIPTION
|
||||
This function converts Windows Firewall security rules data to XML format. It takes a GPO object as input and generates XML data representing the security rules.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) containing the security rules data.
|
||||
|
||||
.PARAMETER SingleObject
|
||||
Indicates whether to convert a single GPO object or multiple security rules.
|
||||
|
||||
.EXAMPLE
|
||||
$GPO = Get-GPO -Name "FirewallRules"
|
||||
ConvertTo-XMLWindowsFirewallSecurityRules -GPO $GPO -SingleObject
|
||||
Converts the security rules data from the GPO "FirewallRules" to XML format for a single GPO object.
|
||||
|
||||
.EXAMPLE
|
||||
$GPOs = Get-GPO -All
|
||||
ConvertTo-XMLWindowsFirewallSecurityRules -GPO $GPOs -SingleObject:$false
|
||||
Converts the security rules data from all GPOs to XML format for multiple security rules.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,19 @@
|
||||
function Find-GPOPassword {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Finds and decrypts the password stored in the cpassword attribute of a Group Policy Object (GPO) XML file.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes the path to a GPO XML file as input, searches for the cpassword attribute, decrypts it, and returns the password.
|
||||
|
||||
.PARAMETER Path
|
||||
Specifies the path to the GPO XML file.
|
||||
|
||||
.EXAMPLE
|
||||
Find-GPOPassword -Path "C:\GPOs\GPO1.xml"
|
||||
Searches for the cpassword attribute in the GPO XML file "GPO1.xml" and returns the decrypted password.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[string] $Path
|
||||
|
||||
@@ -1,4 +1,25 @@
|
||||
function Format-CamelCaseToDisplayName {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Converts a camelCase string to a display name with spaces.
|
||||
|
||||
.DESCRIPTION
|
||||
This function takes a camelCase string and converts it to a display name by adding spaces between words.
|
||||
|
||||
.PARAMETER Text
|
||||
The camelCase string(s) to be converted to display name.
|
||||
|
||||
.PARAMETER AddChar
|
||||
The character to add between words in the display name.
|
||||
|
||||
.EXAMPLE
|
||||
Format-CamelCaseToDisplayName -Text 'testString' -AddChar ' '
|
||||
Converts 'testString' to 'Test String'
|
||||
|
||||
.EXAMPLE
|
||||
Format-CamelCaseToDisplayName -Text 'anotherExample' -AddChar '-'
|
||||
Converts 'anotherExample' to 'Another-Example'
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[string[]] $Text,
|
||||
|
||||
@@ -0,0 +1,220 @@
|
||||
function Get-ADOrganizationalUnitObject {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Gets number of objects in a given OU/OUs with ability to find only those being affected by GPOs.
|
||||
|
||||
.DESCRIPTION
|
||||
Gets number of objects in a given OU/OUs with ability to find only those being affected by GPOs.
|
||||
|
||||
.PARAMETER OrganizationalUnit
|
||||
One or more organizational units to get the number of objects in.
|
||||
|
||||
.PARAMETER Extended
|
||||
Adds all objects affected for better understanding
|
||||
|
||||
.PARAMETER Summary
|
||||
Returns only summary for given OU/OUs
|
||||
|
||||
.PARAMETER IncludeAffectedOnly
|
||||
Ignores any object types that are not Users or Computers
|
||||
|
||||
.PARAMETER Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
.PARAMETER ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
.PARAMETER IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
.PARAMETER AsHashTable
|
||||
Returns results in form of hashtable
|
||||
|
||||
.PARAMETER ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
.EXAMPLE
|
||||
$OUs = @(
|
||||
'OU=SE,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=US,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=Users,OU=User,OU=SE1,OU=SE,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
)
|
||||
|
||||
Get-ADOrganizationalUnitObject -OrganizationalUnit $OUs -IncludeAffectedOnly | Format-Table
|
||||
|
||||
.EXAMPLE
|
||||
$OUs = @(
|
||||
'OU=SE,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=US,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=Users,OU=User,OU=SE1,OU=SE,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
)
|
||||
|
||||
Get-ADOrganizationalUnitObject -OrganizationalUnit $OUs | Format-Table
|
||||
|
||||
.EXAMPLE
|
||||
$OUs = @(
|
||||
#'OU=SE,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
#'OU=US,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=Users,OU=User,OU=SE1,OU=SE,OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
'OU=ITR01,DC=ad,DC=evotec,DC=xyz'
|
||||
)
|
||||
|
||||
Get-ADOrganizationalUnitObject -OrganizationalUnit $OUs -Summary -IncludeAffectedOnly | Format-List
|
||||
|
||||
.NOTES
|
||||
General notes
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[parameter(Mandatory)][Array] $OrganizationalUnit,
|
||||
[switch] $Extended,
|
||||
[switch] $Summary,
|
||||
[switch] $IncludeAffectedOnly,
|
||||
|
||||
[alias('ForestName')][string] $Forest,
|
||||
[string[]] $ExcludeDomains,
|
||||
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
|
||||
[switch] $AsHashTable,
|
||||
[System.Collections.IDictionary] $ExtendedForestInformation
|
||||
)
|
||||
|
||||
$CachedOu = [ordered] @{}
|
||||
$ListOU = @(
|
||||
foreach ($OU in $OrganizationalUnit) {
|
||||
if ($OU.DistinguishedName) {
|
||||
$OU.DistinguishedName
|
||||
} else {
|
||||
$OU
|
||||
}
|
||||
}
|
||||
)
|
||||
$ForestInformation = Get-WinADForestDetails -Extended -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
|
||||
$OUCache = Get-GPOBlockedInheritance -AsHashTable -ExtendedForestInformation $ForestInformation
|
||||
|
||||
if ($Summary) {
|
||||
$SummaryData = [ordered] @{
|
||||
ObjectsClasses = [ordered] @{}
|
||||
ObjectsTotalCount = 0
|
||||
ObjectsBlockedInheritanceCount = 0
|
||||
ObjectsTotal = [ordered] @{}
|
||||
ObjectsBlockedInheritance = [ordered] @{}
|
||||
DistinguishedName = [System.Collections.Generic.List[string]]::new()
|
||||
}
|
||||
}
|
||||
|
||||
foreach ($OU in $ListOU) {
|
||||
$Domain = ConvertFrom-DistinguishedName -ToDomainCN -DistinguishedName $OU
|
||||
$ObjectsInOu = Get-ADObject -LDAPFilter "(|(ObjectClass=user)(ObjectClass=contact)(ObjectClass=computer)(ObjectClass=group)(objectClass=inetOrgPerson)(ObjectClass=PrintQueue))" -SearchBase $OU -Server $ForestInformation['QueryServers'][$Domain]['hostname'][0]
|
||||
#Write-Verbose "Get-GPOZaurrOrganizationalUnit - Processing $($Domain) / $($TOPOU.DistinguishedName) [$CountTop/$($TopOrganizationalUnits.Count)], found $($ObjectsInOu.Count) objects to process."
|
||||
if (-not $CachedOu[$OU]) {
|
||||
$CachedOu[$OU] = [ordered] @{
|
||||
DistinguishedName = $OU
|
||||
Domain = $Domain
|
||||
'ObjectsClasses' = [ordered] @{} # only direct, indirect, but not with blocked inheritance
|
||||
'ObjectsDirectCount' = 0
|
||||
'ObjectsIndirectCount' = 0
|
||||
'ObjectsTotalCount' = 0
|
||||
'ObjectsTotalIncludingBlockedCount' = 0
|
||||
'ObjectsBlockedInheritanceCount' = 0
|
||||
}
|
||||
if ($Extended) {
|
||||
$CachedOu[$OU]['ObjectsDirect'] = [ordered] @{}
|
||||
$CachedOu[$OU]['ObjectsIndirect'] = [ordered] @{}
|
||||
$CachedOu[$OU]['ObjectsTotal'] = [ordered] @{}
|
||||
$CachedOu[$OU]['ObjectsTotalIncludingBlocked'] = [ordered] @{}
|
||||
$CachedOu[$OU]['ObjectsBlockedInheritance'] = [ordered] @{}
|
||||
}
|
||||
}
|
||||
foreach ($Object in $ObjectsInOu) {
|
||||
if ($IncludeAffectedOnly) {
|
||||
if ($Object.ObjectClass -notin 'User', 'computer') {
|
||||
continue
|
||||
}
|
||||
}
|
||||
|
||||
$Place = ConvertFrom-DistinguishedName -ToOrganizationalUnit -DistinguishedName $Object.DistinguishedName
|
||||
if (-not $Place) {
|
||||
# Write-Verbose -Message "Get-OrganizationalUnitObject - Processing object in container/root $($Object.DistinguishedName)"
|
||||
}
|
||||
|
||||
if ($Place -and $OUCache[$Place]) {
|
||||
$BlockedInheritance = $OUCache[$Place].BlockedInheritance
|
||||
} else {
|
||||
$BlockedInheritance = $false
|
||||
}
|
||||
|
||||
if ($Summary) {
|
||||
$SummaryData['DistinguishedName'].Add($OU)
|
||||
$SummaryData['ObjectsClasses'][$Object.ObjectClass] = ''
|
||||
if (-not $Place -or $Place -eq $OU) {
|
||||
$SummaryData['ObjectsTotal'][$Object.DistinguishedName] = $Object
|
||||
} else {
|
||||
if ($BlockedInheritance) {
|
||||
$SummaryData['ObjectsBlockedInheritance'][$Object.DistinguishedName] = $Object
|
||||
} else {
|
||||
$SummaryData['ObjectsTotal'][$Object.DistinguishedName] = $Object
|
||||
}
|
||||
}
|
||||
} else {
|
||||
# This is standard way of finding OU's
|
||||
if (-not $Place -or $Place -eq $OU) {
|
||||
$CachedOu[$OU]['ObjectsDirectCount']++
|
||||
$CachedOu[$OU]['ObjectsTotalCount']++
|
||||
# using hashtable to avoid duplicates
|
||||
$CachedOu[$OU]['ObjectsClasses'][$Object.ObjectClass] = ''
|
||||
# adding all objects to the list, excluding blocked inheritance
|
||||
if ($Extended) {
|
||||
$CachedOu[$OU]['ObjectsTotal'][$Object.DistinguishedName] = $Object
|
||||
$CachedOu[$OU]['ObjectsDirect'][$Object.DistinguishedName] = $Object
|
||||
}
|
||||
} else {
|
||||
if ($BlockedInheritance) {
|
||||
# We only check for blocked inheritance if the object is not in the same OU
|
||||
$CachedOu[$OU]['ObjectsBlockedInheritanceCount']++
|
||||
if ($Extended) {
|
||||
$CachedOu[$OU]['ObjectsBlockedInheritance'][$Object.DistinguishedName] = $Object
|
||||
}
|
||||
} else {
|
||||
$CachedOu[$OU]['ObjectsIndirectCount']++
|
||||
$CachedOu[$OU]['ObjectsTotalCount']++
|
||||
|
||||
# using hashtable to avoid duplicates
|
||||
$CachedOu[$OU]['ObjectsClasses'][$Object.ObjectClass] = ''
|
||||
# adding all objects to the list excluding blocked inheritance
|
||||
if ($Extended) {
|
||||
$CachedOu[$OU]['ObjectsTotal'][$Object.DistinguishedName] = $Object
|
||||
$CachedOu[$OU]['ObjectsIndirect'][$Object.DistinguishedName] = $Object
|
||||
}
|
||||
}
|
||||
}
|
||||
$CachedOu[$OU]['ObjectsTotalIncludingBlockedCount']++
|
||||
if ($Extended) {
|
||||
$CachedOu[$OU]['ObjectsTotalIncludingBlocked'][$Object.DistinguishedName] = $Object
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
if ($Summary) {
|
||||
foreach ($ObjectDistinguishedName in [string[]] $SummaryData['ObjectsBlockedInheritance'].Keys) {
|
||||
if ($SummaryData['ObjectsTotal'][$ObjectDistinguishedName]) {
|
||||
$SummaryData['ObjectsBlockedInheritance'].Remove($ObjectDistinguishedName)
|
||||
}
|
||||
}
|
||||
$SummaryData['ObjectsTotalCount'] = $SummaryData['ObjectsTotal'].Count
|
||||
$SummaryData['ObjectsBlockedInheritanceCount'] = $SummaryData['ObjectsBlockedInheritance'].Count
|
||||
if (-not $Extended) {
|
||||
$SummaryData.Remove('ObjectsTotal')
|
||||
$SummaryData.Remove('ObjectsBlockedInheritance')
|
||||
}
|
||||
[PSCustomObject] $SummaryData
|
||||
} else {
|
||||
if ($AsHashTable) {
|
||||
$CachedOu
|
||||
} else {
|
||||
$CachedOu.Values | ForEach-Object { [PSCustomObject] $_ }
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,136 @@
|
||||
function Get-ChoosenDates {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves dates based on the specified date range.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves dates based on the specified date range. The available date ranges are:
|
||||
- Everything
|
||||
- PastHour
|
||||
- CurrentHour
|
||||
- PastDay
|
||||
- CurrentDay
|
||||
- PastMonth
|
||||
- CurrentMonth
|
||||
- PastQuarter
|
||||
- CurrentQuarter
|
||||
- Last14Days
|
||||
- Last21Days
|
||||
- Last30Days
|
||||
- Last7Days
|
||||
- Last3Days
|
||||
- Last1Days
|
||||
|
||||
.PARAMETER DateRange
|
||||
Specifies the date range to retrieve dates for.
|
||||
|
||||
.EXAMPLE
|
||||
Get-ChoosenDates -DateRange PastHour
|
||||
Retrieves dates for the past hour.
|
||||
|
||||
.EXAMPLE
|
||||
Get-ChoosenDates -DateRange CurrentMonth
|
||||
Retrieves dates for the current month.
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[ValidateSet('Everything', 'PastHour', 'CurrentHour', 'PastDay', 'CurrentDay', 'PastMonth', 'CurrentMonth', 'PastQuarter', 'CurrentQuarter', 'Last14Days', 'Last21Days', 'Last30Days' , 'Last7Days', 'Last3Days', 'Last1Days')][string] $DateRange
|
||||
)
|
||||
# Report Per Hour
|
||||
if ($DateRange -eq 'PastHour') {
|
||||
$DatesPastHour = Find-DatesPastHour
|
||||
if ($DatesPastHour) {
|
||||
$DatesPastHour
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'CurrentHour') {
|
||||
$DatesCurrentHour = Find-DatesCurrentHour
|
||||
if ($DatesCurrentHour) {
|
||||
$DatesCurrentHour
|
||||
}
|
||||
}
|
||||
# Report Per Day
|
||||
if ($DateRange -eq 'PastDay') {
|
||||
$DatesDayPrevious = Find-DatesDayPrevious
|
||||
if ($DatesDayPrevious) {
|
||||
$DatesDayPrevious
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'CurrentDay') {
|
||||
$DatesDayToday = Find-DatesDayToday
|
||||
if ($DatesDayToday) {
|
||||
$DatesDayToday
|
||||
}
|
||||
}
|
||||
# Report Per Month
|
||||
if ($DateRange -eq 'PastMonth') {
|
||||
# Find-DatesMonthPast runs only on 1st of the month unless -Force is used
|
||||
$DatesMonthPrevious = Find-DatesMonthPast -Force $true
|
||||
if ($DatesMonthPrevious) {
|
||||
$DatesMonthPrevious
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'CurrentMonth') {
|
||||
$DatesMonthCurrent = Find-DatesMonthCurrent
|
||||
if ($DatesMonthCurrent) {
|
||||
$DatesMonthCurrent
|
||||
}
|
||||
}
|
||||
# Report Per Quarter
|
||||
if ($DateRange -eq 'PastQuarter') {
|
||||
# Find-DatesMonthPast runs only on 1st of the quarter unless -Force is used
|
||||
$DatesQuarterLast = Find-DatesQuarterLast -Force $true
|
||||
if ($DatesQuarterLast) {
|
||||
$DatesQuarterLast
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'CurrentQuarter') {
|
||||
$DatesQuarterCurrent = Find-DatesQuarterCurrent
|
||||
if ($DatesQuarterCurrent) {
|
||||
$DatesQuarterCurrent
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'Everything') {
|
||||
$DatesEverything = @{
|
||||
DateFrom = Get-Date -Year 1900 -Month 1 -Day 1
|
||||
DateTo = Get-Date -Year 2300 -Month 1 -Day 1
|
||||
}
|
||||
$DatesEverything
|
||||
}
|
||||
if ($DateRange -eq 'Last1days') {
|
||||
$DatesCurrentDayMinusDaysX = Find-DatesCurrentDayMinuxDaysX -days 1
|
||||
if ($DatesCurrentDayMinusDaysX) {
|
||||
$DatesCurrentDayMinusDaysX
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'Last3days') {
|
||||
$DatesCurrentDayMinusDaysX = Find-DatesCurrentDayMinuxDaysX -days 3
|
||||
if ($DatesCurrentDayMinusDaysX) {
|
||||
$DatesCurrentDayMinusDaysX
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'Last7days') {
|
||||
$DatesCurrentDayMinusDaysX = Find-DatesCurrentDayMinuxDaysX -days 7
|
||||
if ($DatesCurrentDayMinusDaysX) {
|
||||
$DatesCurrentDayMinusDaysX
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'Last14days') {
|
||||
$DatesCurrentDayMinusDaysX = Find-DatesCurrentDayMinuxDaysX -days 14
|
||||
if ($DatesCurrentDayMinusDaysX) {
|
||||
$DatesCurrentDayMinusDaysX
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'Last21days') {
|
||||
$DatesCurrentDayMinusDaysX = Find-DatesCurrentDayMinuxDaysX -days 21
|
||||
if ($DatesCurrentDayMinusDaysX) {
|
||||
$DatesCurrentDayMinusDaysX
|
||||
}
|
||||
}
|
||||
if ($DateRange -eq 'Last30Days') {
|
||||
$DatesCurrentDayMinusDaysX = Find-DatesCurrentDayMinuxDaysX -days 30
|
||||
if ($DatesCurrentDayMinusDaysX) {
|
||||
$DatesCurrentDayMinusDaysX
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,64 @@
|
||||
function Get-GPOBlockedInheritance {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves information about Organizational Units (OUs) with blocked inheritance of Group Policy Objects (GPOs).
|
||||
|
||||
.DESCRIPTION
|
||||
The Get-GPOBlockedInheritance function retrieves information about OUs within a specified forest that have blocked inheritance of GPOs. It returns a list of OUs with their distinguished names and whether they have blocked inheritance enabled.
|
||||
|
||||
.PARAMETER Filter
|
||||
Specifies a filter to select specific OUs. Default is '*'.
|
||||
|
||||
.PARAMETER Forest
|
||||
Specifies the name of the forest to query.
|
||||
|
||||
.PARAMETER ExcludeDomains
|
||||
Specifies an array of domain names to exclude from the query.
|
||||
|
||||
.PARAMETER IncludeDomains
|
||||
Specifies an array of domain names to include in the query.
|
||||
|
||||
.PARAMETER AsHashTable
|
||||
Indicates whether to return the results as a hashtable. If specified, the function returns a hashtable with OU distinguished names as keys and blocked inheritance status as values.
|
||||
|
||||
.PARAMETER ExtendedForestInformation
|
||||
Specifies additional forest information to include in the query.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOBlockedInheritance -Forest 'contoso.com'
|
||||
Retrieves a list of all OUs within the 'contoso.com' forest with blocked inheritance status.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOBlockedInheritance -Forest 'contoso.com' -IncludeDomains 'child1.contoso.com', 'child2.contoso.com' -AsHashTable
|
||||
Retrieves a hashtable of OUs within the 'contoso.com' forest from specified domains with blocked inheritance status.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[string] $Filter = '*',
|
||||
|
||||
[alias('ForestName')][string] $Forest,
|
||||
[string[]] $ExcludeDomains,
|
||||
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
|
||||
[switch] $AsHashTable,
|
||||
[System.Collections.IDictionary] $ExtendedForestInformation
|
||||
)
|
||||
$OUCache = [ordered] @{}
|
||||
|
||||
$ForestInformation = Get-WinADForestDetails -Extended -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
|
||||
|
||||
foreach ($Domain in $ForestInformation.Domains) {
|
||||
$OrganizationalUnits = Get-ADOrganizationalUnit -Filter $Filter -Properties gpOptions, canonicalName -Server $ForestInformation['QueryServers'][$Domain]['HostName'][0] #-SearchScope Subtree
|
||||
foreach ($OU in $OrganizationalUnits) {
|
||||
$OUCache[$OU.DistinguishedName] = [PSCustomObject] @{
|
||||
DistinguishedName = $OU.DistinguishedName
|
||||
BlockedInheritance = if ($OU.gpOptions -eq 1) { $true } else { $false } # blocked inheritance
|
||||
}
|
||||
}
|
||||
}
|
||||
if ($AsHashTable) {
|
||||
$OUCache
|
||||
} else {
|
||||
$OUCache.Values
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,33 @@
|
||||
function Get-GPOCategories {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves GPO categories based on the provided GPO object and XML output.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves GPO categories by analyzing the provided GPO object and XML output. It categorizes GPO settings based on different criteria.
|
||||
|
||||
.PARAMETER GPO
|
||||
The GPO object containing information about the Group Policy Object.
|
||||
|
||||
.PARAMETER GPOOutput
|
||||
An array of XML elements representing the GPO output.
|
||||
|
||||
.PARAMETER Splitter
|
||||
The delimiter used to split GPO settings.
|
||||
|
||||
.PARAMETER FullObjects
|
||||
A switch parameter to indicate whether to retrieve full GPO objects.
|
||||
|
||||
.PARAMETER CachedCategories
|
||||
A dictionary containing cached GPO categories.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOCategories -GPO $gpoObject -GPOOutput $xmlOutput -Splitter ":" -FullObjects
|
||||
|
||||
Description:
|
||||
Retrieves GPO categories for the specified GPO object and XML output, splitting settings using ":" as the delimiter and retrieving full GPO objects.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -1,4 +1,37 @@
|
||||
function Get-GPOPrivInheritance {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves the Group Policy Object (GPO) inheritance information for a given Active Directory object.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves the inheritance information of Group Policy Objects (GPOs) for a specified Active Directory object. It provides details on how GPOs are linked and inherited by the object.
|
||||
|
||||
.PARAMETER ADObject
|
||||
Specifies the Active Directory object for which to retrieve GPO inheritance information.
|
||||
|
||||
.PARAMETER CacheReturnedGPOs
|
||||
Specifies a dictionary containing cached GPO information to optimize retrieval.
|
||||
|
||||
.PARAMETER ForestInformation
|
||||
Specifies a dictionary containing information about the Active Directory forest.
|
||||
|
||||
.PARAMETER Domain
|
||||
Specifies the domain for which to retrieve GPO privilege link information.
|
||||
|
||||
.PARAMETER SkipDomainRoot
|
||||
Indicates whether to skip the Domain Root container.
|
||||
|
||||
.PARAMETER SkipDomainControllers
|
||||
Indicates whether to skip the Domain Controllers container.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOPrivInheritance -ADObject $ADObject -CacheReturnedGPOs $Cache -ForestInformation $ForestInfo -Domain "example.com" -SkipDomainRoot -SkipDomainControllers
|
||||
Retrieves GPO inheritance information for the specified ADObject in the "example.com" domain, skipping the Domain Root container and Domain Controllers container.
|
||||
|
||||
.NOTES
|
||||
File Name : Get-GPOPrivInheritance.ps1
|
||||
Prerequisite : This function requires the Get-GPInheritance function.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[parameter(ParameterSetName = 'ADObject', ValueFromPipeline, ValueFromPipelineByPropertyName, Mandatory)][Microsoft.ActiveDirectory.Management.ADObject[]] $ADObject,
|
||||
|
||||
@@ -1,4 +1,45 @@
|
||||
function Get-GPOPrivInheritanceLoop {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves the Group Policy Object (GPO) inheritance loop for a given Active Directory object.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves the GPO inheritance loop for a specified Active Directory object. It analyzes the inheritance of GPOs based on the object's location in the Active Directory structure.
|
||||
|
||||
.PARAMETER ADObject
|
||||
Specifies the Active Directory object for which the GPO inheritance loop needs to be determined.
|
||||
|
||||
.PARAMETER CacheReturnedGPOs
|
||||
Specifies a dictionary containing cached GPO information to optimize retrieval.
|
||||
|
||||
.PARAMETER ForestInformation
|
||||
Specifies a dictionary containing information about the Active Directory forest.
|
||||
|
||||
.PARAMETER Linked
|
||||
Specifies the types of linked objects to consider during the inheritance analysis. Valid values are 'Root', 'DomainControllers', 'OrganizationalUnit'.
|
||||
|
||||
.PARAMETER SearchBase
|
||||
Specifies the base location in Active Directory to start the search for GPO inheritance.
|
||||
|
||||
.PARAMETER SearchScope
|
||||
Specifies the scope of the search in Active Directory.
|
||||
|
||||
.PARAMETER Filter
|
||||
Specifies the filter to apply when searching for Active Directory objects.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOPrivInheritanceLoop -ADObject $ADObject -CacheReturnedGPOs $Cache -ForestInformation $ForestInfo -Linked 'Root' -SearchBase 'DC=contoso,DC=com' -SearchScope Subtree -Filter '(objectClass -eq "organizationalUnit")'
|
||||
|
||||
Description:
|
||||
Retrieves the GPO inheritance loop for the specified Active Directory object located in the 'contoso.com' domain starting from the root.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOPrivInheritanceLoop -ADObject $ADObject -CacheReturnedGPOs $Cache -ForestInformation $ForestInfo -Linked 'DomainControllers' -SearchBase 'DC=contoso,DC=com' -SearchScope Base -Filter '(objectClass -eq "organizationalUnit")'
|
||||
|
||||
Description:
|
||||
Retrieves the GPO inheritance loop for the specified Active Directory object located in the 'contoso.com' domain starting from the Domain Controllers container.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[Microsoft.ActiveDirectory.Management.ADObject[]] $ADObject,
|
||||
|
||||
@@ -1,4 +1,43 @@
|
||||
function Get-GPOPrivLink {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves the GPO (Group Policy Object) privilege link information for specified Active Directory objects.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves the GPO privilege link information for the specified Active Directory objects. It allows skipping certain default containers like Domain Root and Domain Controllers if needed. It also provides options to cache returned GPOs and skip duplicates.
|
||||
|
||||
.PARAMETER ADObject
|
||||
Specifies the Active Directory objects for which to retrieve GPO privilege link information.
|
||||
|
||||
.PARAMETER CacheReturnedGPOs
|
||||
Specifies a dictionary to cache returned GPOs for optimization.
|
||||
|
||||
.PARAMETER ForestInformation
|
||||
Specifies a dictionary containing forest information.
|
||||
|
||||
.PARAMETER Domain
|
||||
Specifies the domain for which to retrieve GPO privilege link information.
|
||||
|
||||
.PARAMETER SkipDomainRoot
|
||||
Indicates whether to skip the Domain Root container.
|
||||
|
||||
.PARAMETER SkipDomainControllers
|
||||
Indicates whether to skip the Domain Controllers container.
|
||||
|
||||
.PARAMETER AsHashTable
|
||||
Specifies whether to output the GPO information as a hash table.
|
||||
|
||||
.PARAMETER SkipDuplicates
|
||||
Indicates whether to skip duplicate GPOs.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOPrivLink -ADObject $ADObject -CacheReturnedGPOs $Cache -ForestInformation $ForestInfo -Domain "example.com" -SkipDomainRoot -SkipDuplicates
|
||||
Retrieves GPO privilege link information for the specified ADObject in the "example.com" domain, skipping the Domain Root container and duplicates.
|
||||
|
||||
.NOTES
|
||||
File Name : Get-GPOPrivLink.ps1
|
||||
Prerequisite : This function requires the Get-PrivGPOZaurrLink function.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[parameter(ParameterSetName = 'ADObject', ValueFromPipeline, ValueFromPipelineByPropertyName, Mandatory)][Microsoft.ActiveDirectory.Management.ADObject[]] $ADObject,
|
||||
|
||||
@@ -1,52 +1,52 @@
|
||||
function Get-GPOZaurrLinkInheritance {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Short description
|
||||
Retrieves the Group Policy Object (GPO) inheritance information for a given Active Directory object.
|
||||
|
||||
.DESCRIPTION
|
||||
Long description
|
||||
This function retrieves the inheritance information of Group Policy Objects (GPOs) for a specified Active Directory object. It provides details on how GPOs are linked and inherited by the object.
|
||||
|
||||
.PARAMETER ADObject
|
||||
Parameter description
|
||||
Specifies the Active Directory object for which to retrieve GPO inheritance information.
|
||||
|
||||
.PARAMETER Filter
|
||||
Parameter description
|
||||
Specifies the filter criteria for selecting the types of objects to include in the search. Default value includes 'organizationalUnit', 'domainDNS', and 'site' objects.
|
||||
|
||||
.PARAMETER SearchBase
|
||||
Parameter description
|
||||
Specifies the base distinguished name (DN) for the search operation.
|
||||
|
||||
.PARAMETER SearchScope
|
||||
Parameter description
|
||||
Specifies the scope of the search operation within Active Directory.
|
||||
|
||||
.PARAMETER Linked
|
||||
Parameter description
|
||||
Specifies the type of objects to include in the search. Valid values are 'Root', 'DomainControllers', and 'OrganizationalUnit'.
|
||||
|
||||
.PARAMETER Limited
|
||||
Parameter description
|
||||
Indicates whether to limit the search results. If specified, only a limited set of results will be returned.
|
||||
|
||||
.PARAMETER SkipDuplicates
|
||||
Parameter description
|
||||
Indicates whether to skip duplicate entries in the search results.
|
||||
|
||||
.PARAMETER GPOCache
|
||||
Parameter description
|
||||
Specifies a cache of Group Policy Objects to optimize performance.
|
||||
|
||||
.PARAMETER Forest
|
||||
Parameter description
|
||||
Specifies the target forest to search for GPO inheritance information. By default, the current forest is used.
|
||||
|
||||
.PARAMETER ExcludeDomains
|
||||
Parameter description
|
||||
Specifies the domains to exclude from the search operation. By default, the entire forest is scanned.
|
||||
|
||||
.PARAMETER IncludeDomains
|
||||
Parameter description
|
||||
Specifies the specific domains to include in the search operation. By default, the entire forest is scanned.
|
||||
|
||||
.PARAMETER ExtendedForestInformation
|
||||
Parameter description
|
||||
Specifies additional information about the forest to include in the search results.
|
||||
|
||||
.PARAMETER AsHashTable
|
||||
Parameter description
|
||||
Indicates whether to return the results as a hash table.
|
||||
|
||||
.PARAMETER Summary
|
||||
Parameter description
|
||||
Indicates whether to provide a summary of the GPO inheritance information.
|
||||
|
||||
.EXAMPLE
|
||||
$Output = Get-GPOZaurrLinkInheritance -Summary
|
||||
@@ -58,7 +58,7 @@ function Get-GPOZaurrLinkInheritance {
|
||||
$Output[5].LinksObjects | Format-Table
|
||||
|
||||
.NOTES
|
||||
This is based on Get-GPInheritance which isn't ideal and doesn't support sites. Get-GPOZaurrLink is better. Leaving in case I need it later on for private use only.
|
||||
This function is an improved version of Get-GPInheritance and provides better support for sites. It is recommended for retrieving GPO inheritance information.
|
||||
#>
|
||||
[cmdletbinding(DefaultParameterSetName = 'All')]
|
||||
param(
|
||||
@@ -123,9 +123,13 @@ function Get-GPOZaurrLinkInheritance {
|
||||
# While initially we used $ForestInformation.Domains but the thing is GPOs can be linked to other domains so we need to get them all so we can use cache of it later on even if we're processing just one domain
|
||||
# That's why we use $ForestInformation.Forest.Domains instead
|
||||
foreach ($Domain in $ForestInformation.Forest.Domains) {
|
||||
$QueryServer = $ForestInformation['QueryServers'][$Domain]['HostName'][0]
|
||||
Get-GPO -All -DomainName $Domain -Server $QueryServer | ForEach-Object {
|
||||
$GPOCache["$Domain$($_.ID.Guid)"] = $_
|
||||
if ($ForestInformation['QueryServers'][$Domain]) {
|
||||
$QueryServer = $ForestInformation['QueryServers'][$Domain]['HostName'][0]
|
||||
Get-GPO -All -DomainName $Domain -Server $QueryServer | ForEach-Object {
|
||||
$GPOCache["$Domain$($_.ID.Guid)"] = $_
|
||||
}
|
||||
} else {
|
||||
Write-Warning -Message "Get-GPOZaurrLinkInheritance - Couldn't get query server for $Domain. Skipped."
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,4 +1,51 @@
|
||||
function Get-GPOZaurrLinkLoop {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves Group Policy Object (GPO) links for Active Directory objects based on specified criteria.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves GPO links for Active Directory objects based on the provided parameters. It allows searching for GPO links within specific sites, domains, or organizational units. The function can handle duplicates and provides flexibility in defining search criteria.
|
||||
|
||||
.PARAMETER ADObject
|
||||
Specifies the Active Directory objects for which GPO links will be retrieved.
|
||||
|
||||
.PARAMETER CacheReturnedGPOs
|
||||
A dictionary cache of returned Group Policy Objects for efficient processing.
|
||||
|
||||
.PARAMETER ForestInformation
|
||||
Information about the forest structure and domains for targeted searches.
|
||||
|
||||
.PARAMETER Linked
|
||||
Specifies the type of objects to search for GPO links. Valid values are 'All', 'Root', 'DomainControllers', 'Site', or 'OrganizationalUnit'.
|
||||
|
||||
.PARAMETER SearchBase
|
||||
Specifies the base location for the search within Active Directory.
|
||||
|
||||
.PARAMETER SearchScope
|
||||
Specifies the scope of the search within Active Directory.
|
||||
|
||||
.PARAMETER Filter
|
||||
Specifies additional filters to apply during the search.
|
||||
|
||||
.PARAMETER SkipDuplicates
|
||||
Indicates whether to skip duplicate GPO links during processing.
|
||||
|
||||
.PARAMETER Site
|
||||
Specifies the site(s) to search for GPO links.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOZaurrLinkLoop -Site 'SiteA', 'SiteB' -ForestInformation $ForestInfo
|
||||
|
||||
Description:
|
||||
Retrieves GPO links for sites 'SiteA' and 'SiteB' within the forest using the provided forest information.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GPOZaurrLinkLoop -SearchBase 'OU=Users,DC=contoso,DC=com' -SearchScope Subtree -Filter '(objectClass -eq "user")'
|
||||
|
||||
Description:
|
||||
Retrieves GPO links for all user objects within the specified organizational unit 'Users' in the 'contoso.com' domain.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[Microsoft.ActiveDirectory.Management.ADObject[]] $ADObject,
|
||||
|
||||
@@ -1,4 +1,27 @@
|
||||
function Get-GitHubVersion {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves the latest version information from a GitHub repository and compares it with the currently installed version of a specified cmdlet.
|
||||
|
||||
.DESCRIPTION
|
||||
The Get-GitHubVersion function retrieves the latest version information from a specified GitHub repository and compares it with the version of a specified cmdlet. It then provides feedback on whether an update is available or if the installed version is up to date.
|
||||
|
||||
.PARAMETER Cmdlet
|
||||
The name of the cmdlet to check for updates.
|
||||
|
||||
.PARAMETER RepositoryOwner
|
||||
The owner of the GitHub repository where the releases are hosted.
|
||||
|
||||
.PARAMETER RepositoryName
|
||||
The name of the GitHub repository.
|
||||
|
||||
.EXAMPLE
|
||||
Get-GitHubVersion -Cmdlet "MyCmdlet" -RepositoryOwner "MyRepoOwner" -RepositoryName "MyRepo"
|
||||
|
||||
Description:
|
||||
Retrieves the latest version information for "MyCmdlet" from the GitHub repository owned by "MyRepoOwner" with the name "MyRepo".
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)][string] $Cmdlet,
|
||||
|
||||
@@ -1,4 +1,29 @@
|
||||
function Get-LinksFromXML {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves links from XML data.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves links from XML data provided as input. It processes the XML data to extract relevant information about the links.
|
||||
|
||||
.PARAMETER GPOOutput
|
||||
Specifies the XML data containing information about the links.
|
||||
|
||||
.PARAMETER Splitter
|
||||
Specifies the delimiter to use when joining multiple links.
|
||||
|
||||
.PARAMETER FullObjects
|
||||
Indicates whether to return full objects with additional properties for each link.
|
||||
|
||||
.EXAMPLE
|
||||
Get-LinksFromXML -GPOOutput $xmlData -Splitter ";" -FullObjects
|
||||
Retrieves links from the XML data $xmlData, separates them with a semicolon, and returns full objects for each link.
|
||||
|
||||
.EXAMPLE
|
||||
Get-LinksFromXML -GPOOutput $xmlData -Splitter "/"
|
||||
Retrieves links from the XML data $xmlData and joins them with a forward slash.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[System.Xml.XmlElement[]] $GPOOutput,
|
||||
|
||||
@@ -1,4 +1,48 @@
|
||||
function Get-PermissionsAnalysis {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Analyzes permissions for a specified Group Policy Object (GPO) based on provided criteria.
|
||||
|
||||
.DESCRIPTION
|
||||
This function analyzes permissions for a specified Group Policy Object (GPO) based on the given criteria. It checks for specific administrative groups, standard users, and well-known administrative groups to determine the type of permissions assigned.
|
||||
|
||||
.PARAMETER GPOPermissions
|
||||
An array of GPO permissions to analyze.
|
||||
|
||||
.PARAMETER Type
|
||||
Specifies the type of permissions to analyze. Valid values are 'WellKnownAdministrative', 'Administrative', 'AuthenticatedUsers', or 'Default'.
|
||||
|
||||
.PARAMETER PermissionType
|
||||
The specific permission type to include in the analysis.
|
||||
|
||||
.PARAMETER Forest
|
||||
Target different Forest, by default current forest is used.
|
||||
|
||||
.PARAMETER ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned.
|
||||
|
||||
.PARAMETER IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned.
|
||||
|
||||
.PARAMETER ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing.
|
||||
|
||||
.PARAMETER ADAdministrativeGroups
|
||||
Specifies the Active Directory administrative groups to consider.
|
||||
|
||||
.EXAMPLE
|
||||
Get-PermissionsAnalysis -GPOPermissions $GPOPermissions -Type 'Administrative' -PermissionType 'Read' -Forest 'Contoso' -IncludeDomains 'DomainA', 'DomainB'
|
||||
|
||||
Description:
|
||||
Analyzes permissions for the specified GPOPermissions array, focusing on administrative groups with 'Read' permission in the 'Contoso' forest for 'DomainA' and 'DomainB'.
|
||||
|
||||
.EXAMPLE
|
||||
Get-PermissionsAnalysis -GPOPermissions $GPOPermissions -Type 'WellKnownAdministrative' -PermissionType 'Write'
|
||||
|
||||
Description:
|
||||
Analyzes permissions for the specified GPOPermissions array, targeting well-known administrative groups with 'Write' permission.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPOPermissions,
|
||||
|
||||
@@ -1,4 +1,33 @@
|
||||
function Get-PrivGPOZaurrLink {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves and processes Group Policy Object (GPO) links associated with a given Active Directory object.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves and processes the GPO links associated with a specified Active Directory object. It parses the GPO links to extract relevant information such as distinguished name, canonical name, GUID, enforcement status, and enablement status.
|
||||
|
||||
.PARAMETER Object
|
||||
The Active Directory object for which GPO links will be retrieved and processed.
|
||||
|
||||
.PARAMETER Limited
|
||||
Indicates whether to provide limited information about the GPO links.
|
||||
|
||||
.PARAMETER GPOCache
|
||||
A dictionary cache of Group Policy Objects for efficient processing.
|
||||
|
||||
.EXAMPLE
|
||||
Get-PrivGPOZaurrLink -Object $ADObject
|
||||
|
||||
Description:
|
||||
Retrieves and processes the GPO links associated with the specified Active Directory object.
|
||||
|
||||
.EXAMPLE
|
||||
Get-PrivGPOZaurrLink -Object $ADObject -Limited
|
||||
|
||||
Description:
|
||||
Retrieves limited information about the GPO links associated with the specified Active Directory object.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[Microsoft.ActiveDirectory.Management.ADObject] $Object,
|
||||
|
||||
@@ -1,4 +1,69 @@
|
||||
function Get-PrivPermission {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves permissions for a specified Group Policy Object (GPO) based on various criteria.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves permissions for a specified Group Policy Object (GPO) based on the provided parameters. It allows filtering by principal, permission type, and other criteria.
|
||||
|
||||
.PARAMETER GPO
|
||||
Specifies the Group Policy Object (GPO) for which permissions will be retrieved.
|
||||
|
||||
.PARAMETER SecurityRights
|
||||
Specifies the security rights to be evaluated for the GPO.
|
||||
|
||||
.PARAMETER Principal
|
||||
Specifies the principal for which permissions will be retrieved.
|
||||
|
||||
.PARAMETER PrincipalType
|
||||
Specifies the type of principal to filter by. Valid values are 'DistinguishedName', 'Name', 'NetbiosName', or 'Sid'.
|
||||
|
||||
.PARAMETER SkipWellKnown
|
||||
Skips well-known principals when evaluating permissions.
|
||||
|
||||
.PARAMETER SkipAdministrative
|
||||
Skips administrative principals when evaluating permissions.
|
||||
|
||||
.PARAMETER IncludeOwner
|
||||
Includes the owner of the GPO in the permission results.
|
||||
|
||||
.PARAMETER IncludePermissionType
|
||||
Specifies the permission types to include in the results.
|
||||
|
||||
.PARAMETER ExcludePermissionType
|
||||
Specifies the permission types to exclude from the results.
|
||||
|
||||
.PARAMETER PermitType
|
||||
Specifies the type of permissions to include. Valid values are 'Allow', 'Deny', or 'All'.
|
||||
|
||||
.PARAMETER ExcludePrincipal
|
||||
Specifies principals to exclude from the results.
|
||||
|
||||
.PARAMETER ExcludePrincipalType
|
||||
Specifies the type of principal to exclude. Valid values are 'DistinguishedName', 'Name', or 'Sid'.
|
||||
|
||||
.PARAMETER IncludeGPOObject
|
||||
Includes the GPO object in the permission results.
|
||||
|
||||
.PARAMETER ADAdministrativeGroups
|
||||
Specifies the Active Directory administrative groups to consider.
|
||||
|
||||
.PARAMETER Type
|
||||
Specifies the type of principals to include. Valid values are 'AuthenticatedUsers', 'DomainComputers', 'Unknown', 'WellKnownAdministrative', 'NotWellKnown', 'NotWellKnownAdministrative', 'NotAdministrative', 'Administrative', or 'All'.
|
||||
|
||||
.PARAMETER ExtendedForestInformation
|
||||
Specifies extended forest information to be used in evaluation.
|
||||
|
||||
.EXAMPLE
|
||||
Get-PrivPermission -GPO $GPO -SecurityRights $SecurityRights -Principal 'Domain Admins' -PrincipalType 'Name' -PermitType 'Allow'
|
||||
|
||||
Retrieves permissions for the specified GPO where 'Domain Admins' have 'Allow' permissions.
|
||||
|
||||
.EXAMPLE
|
||||
Get-PrivPermission -GPO $GPO -SecurityRights $SecurityRights -Principal 'S-1-5-21-3623811015-3361044348-30300820-1013' -PrincipalType 'Sid' -PermitType 'Deny'
|
||||
|
||||
Retrieves permissions for the specified GPO where the principal with the SID 'S-1-5-21-3623811015-3361044348-30300820-1013' has 'Deny' permissions.
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[Microsoft.GroupPolicy.Gpo] $GPO,
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
function Get-WellKnownFolders {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Gets users and computers well known folders for a forest
|
||||
|
||||
.DESCRIPTION
|
||||
Gets users and computers well known folders for a forest
|
||||
|
||||
.PARAMETER Forest
|
||||
Target different Forest, by default current forest is used
|
||||
|
||||
.PARAMETER ExcludeDomains
|
||||
Exclude domain from search, by default whole forest is scanned
|
||||
|
||||
.PARAMETER IncludeDomains
|
||||
Include only specific domains, by default whole forest is scanned
|
||||
|
||||
.PARAMETER ExtendedForestInformation
|
||||
Ability to provide Forest Information from another command to speed up processing
|
||||
|
||||
.EXAMPLE
|
||||
Get-WellKnownFolders
|
||||
|
||||
.NOTES
|
||||
General notes
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[alias('ForestName')][string] $Forest,
|
||||
[string[]] $ExcludeDomains,
|
||||
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
|
||||
[System.Collections.IDictionary] $ExtendedForestInformation
|
||||
)
|
||||
|
||||
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation -Extended
|
||||
foreach ($Domain in $ForestInformation.Domains) {
|
||||
$ForestInformation.DomainsExtended[$Domain].ComputersContainer
|
||||
$ForestInformation.DomainsExtended[$Domain].UsersContainer
|
||||
}
|
||||
}
|
||||
+85
-7
@@ -1,4 +1,51 @@
|
||||
function Get-XMLGPO {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves information from an XML representation of a Group Policy Object (GPO).
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves various details from an XML representation of a GPO, such as GPO name, domain name, links information, etc.
|
||||
|
||||
.PARAMETER XMLContent
|
||||
The XML content representing the GPO.
|
||||
|
||||
.PARAMETER GPO
|
||||
The Microsoft.GroupPolicy.Gpo object representing the GPO.
|
||||
|
||||
.PARAMETER PermissionsOnly
|
||||
Indicates whether to retrieve only permissions information.
|
||||
|
||||
.PARAMETER OwnerOnly
|
||||
Indicates whether to retrieve only owner information.
|
||||
|
||||
.PARAMETER ADAdministrativeGroups
|
||||
A dictionary of Active Directory administrative groups.
|
||||
|
||||
.PARAMETER Splitter
|
||||
The string used to split values in the output.
|
||||
|
||||
.PARAMETER ExcludeGroupPolicies
|
||||
A dictionary of group policies to exclude.
|
||||
|
||||
.PARAMETER Type
|
||||
An array of types to filter the output.
|
||||
|
||||
.PARAMETER LinksSummaryCache
|
||||
A cache of links summary information.
|
||||
|
||||
.EXAMPLE
|
||||
Get-XMLGPO -XMLContent $xml -GPO $gpo
|
||||
|
||||
Description:
|
||||
Retrieves information from the XML content of a specific GPO.
|
||||
|
||||
.EXAMPLE
|
||||
Get-XMLGPO -XMLContent $xml -GPO $gpo -PermissionsOnly
|
||||
|
||||
Description:
|
||||
Retrieves only the permissions information from the XML content of a specific GPO.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[XML] $XMLContent,
|
||||
@@ -7,12 +54,13 @@
|
||||
[switch] $OwnerOnly,
|
||||
[System.Collections.IDictionary] $ADAdministrativeGroups,
|
||||
[string] $Splitter = [System.Environment]::NewLine,
|
||||
[switch] $ReturnObject,
|
||||
[System.Collections.IDictionary] $ExcludeGroupPolicies,
|
||||
[string[]] $Type,
|
||||
[System.Collections.IDictionary] $LinksSummaryCache
|
||||
)
|
||||
|
||||
$SysvolGpoPath = "\\$($GPO.DomainName)\SYSVOL\$($GPO.DomainName)\Policies\{$($GPO.ID)}"
|
||||
|
||||
$DisplayName = $XMLContent.GPO.Name
|
||||
$DomainName = $XMLContent.GPO.Identifier.Domain.'#text'
|
||||
|
||||
@@ -134,7 +182,7 @@
|
||||
# in some cases GPResult seems to return an error - this was first noticed by user when using Dutch based system
|
||||
# I am not sure if it's possible to fix this error for users, but once that happens checking if GPO is empty fails using the method below
|
||||
# therefore we will use the old method of assuming something is empty or not empty in such case
|
||||
Write-Warning "Get-XMLGPO - Reading GPO content [$DisplayName/$DomainName] returned an error. This may be because of non-english language. Assesing EMPTY using old method which can report false positives. Be careful please."
|
||||
Write-Warning "Get-XMLGPO - Reading GPO content [$DisplayName/$DomainName] returned an error. This may be because of non-english language. Assessing EMPTY using old method which can report false positives. Be careful please."
|
||||
$OutputUser = @()
|
||||
$OutputComputer = @()
|
||||
} else {
|
||||
@@ -167,7 +215,22 @@
|
||||
[bool] $UserSettingsAvailable = if ($OutputUser.Count -gt 0) { $true } else { $false }
|
||||
}
|
||||
|
||||
if ($ComputerSettingsAvailable -eq $false -and $UserSettingsAvailable -eq $false) {
|
||||
# Check if there are any GPF files in the GPO
|
||||
# those are special files that are used to store settings for some applications (maily Citrix?)
|
||||
# if there are any, then we can't say that GPO is empty, and they are not visible in the XML
|
||||
$GPFFile = $false
|
||||
$FilesCount = 0
|
||||
$TotalSize = 0
|
||||
Get-ChildItem -LiteralPath $SysvolGpoPath -Recurse -ErrorAction SilentlyContinue -File | ForEach-Object {
|
||||
if ($_.Extension -eq '.gpf') {
|
||||
#Write-Warning -Message "Get-XMLGPO - GPO [$DisplayName/$DomainName] has no data in XML, but it contains GPF files. Excluding from empty GPO list."
|
||||
$GPFFile = $true
|
||||
}
|
||||
$FilesCount++
|
||||
$TotalSize += $_.Length
|
||||
}
|
||||
|
||||
if ($ComputerSettingsAvailable -eq $false -and $UserSettingsAvailable -eq $false -and $GPFFile -eq $false) {
|
||||
$Empty = $true
|
||||
} else {
|
||||
$Empty = $false
|
||||
@@ -224,15 +287,24 @@
|
||||
} elseif ($ADAdministrativeGroups) {
|
||||
$OwnerType = 'Unknown'
|
||||
} else {
|
||||
$OwnerType = 'Unable to asses (local files?)'
|
||||
$OwnerType = 'Unable to assess (local files?)'
|
||||
}
|
||||
}
|
||||
# Mark GPO as excluded
|
||||
$Exclude = $false
|
||||
if ($ExcludeGroupPolicies) {
|
||||
$GUID = $XMLContent.GPO.Identifier.Identifier.'#text'
|
||||
$GUIDWithOutBrackets = $GUID.Replace('{', '').Replace('}', '')
|
||||
$PolicyWithDomain = -join ($XMLContent.GPO.Identifier.Domain.'#text', $XMLContent.GPO.Name)
|
||||
$PolicyWithDomainID = -join ($XMLContent.GPO.Identifier.Domain.'#text', $XMLContent.GPO.Identifier.Identifier.'#text')
|
||||
if ($ExcludeGroupPolicies[$XMLContent.GPO.Name] -or $ExcludeGroupPolicies[$PolicyWithDomain] -or $ExcludeGroupPolicies[$PolicyWithDomainID] -or $ExcludeGroupPolicies[$XMLContent.GPO.Identifier.Identifier.'#text']) {
|
||||
$PolicyWithDomainID = -join ($XMLContent.GPO.Identifier.Domain.'#text', $GUID)
|
||||
$PolicyWithDomainIDWithoutBrackets = -join ($XMLContent.GPO.Identifier.Domain.'#text', $GUIDWithOutBrackets)
|
||||
if ($ExcludeGroupPolicies[$XMLContent.GPO.Name] -or
|
||||
$ExcludeGroupPolicies[$PolicyWithDomain] -or
|
||||
$ExcludeGroupPolicies[$PolicyWithDomainID] -or
|
||||
$ExcludeGroupPolicies[$GUID] -or
|
||||
$ExcludeGroupPolicies[$GUIDWithOutBrackets] -or
|
||||
$ExcludeGroupPolicies[$PolicyWithDomainIDWithoutBrackets]
|
||||
) {
|
||||
$Exclude = $true
|
||||
}
|
||||
}
|
||||
@@ -249,6 +321,7 @@
|
||||
'Inherited' = $false
|
||||
'Permissions' = 'Owner'
|
||||
'GPODistinguishedName' = $GPO.Path
|
||||
'GPOSysvolPath' = $SysvolGpoPath
|
||||
}
|
||||
$XMLContent.GPO.SecurityDescriptor.Permissions.TrusteePermissions | ForEach-Object -Process {
|
||||
if ($_) {
|
||||
@@ -277,6 +350,7 @@
|
||||
'OwnerSID' = $XMLContent.GPO.SecurityDescriptor.Owner.SID.'#text'
|
||||
'OwnerType' = $OwnerType
|
||||
'GPODistinguishedName' = $GPO.Path
|
||||
'GPOSysvolPath' = $SysvolGpoPath
|
||||
}
|
||||
} else {
|
||||
$GPOOutput = [PsCustomObject] @{
|
||||
@@ -291,9 +365,12 @@
|
||||
'Problem' = $Problem
|
||||
'ApplyPermission' = $null
|
||||
'Exclude' = $Exclude
|
||||
'SizeMB' = [Math]::Round($TotalSize / 1MB, 2)
|
||||
'Size' = $TotalSize
|
||||
'Description' = $GPO.Description
|
||||
'ComputerPolicies' = $XMLContent.GPO.Computer.ExtensionData.Name -join ", "
|
||||
'UserPolicies' = $XMLContent.GPO.User.ExtensionData.Name -join ", "
|
||||
'FilesCount' = $FilesCount
|
||||
'LinksCount' = $LinksTotalCount
|
||||
'LinksEnabledCount' = $LinksEnabledCount
|
||||
'LinksDisabledCount' = $LinksDisabledCount
|
||||
@@ -323,6 +400,7 @@
|
||||
'WMIFilter' = $GPO.WmiFilter.name
|
||||
'WMIFilterDescription' = $GPO.WmiFilter.Description
|
||||
'GPODistinguishedName' = $GPO.Path
|
||||
'GPOSysvolPath' = $SysvolGpoPath
|
||||
'SDDL' = if ($Splitter -ne '') { $XMLContent.GPO.SecurityDescriptor.SDDL.'#text' -join $Splitter } else { $XMLContent.GPO.SecurityDescriptor.SDDL.'#text' }
|
||||
'Owner' = $XMLContent.GPO.SecurityDescriptor.Owner.Name.'#text'
|
||||
'OwnerSID' = $XMLContent.GPO.SecurityDescriptor.Owner.SID.'#text'
|
||||
@@ -390,4 +468,4 @@
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,4 +1,32 @@
|
||||
function Get-XMLNestedRegistry {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Retrieves registry settings from XML data and formats them for output.
|
||||
|
||||
.DESCRIPTION
|
||||
This function retrieves registry settings from XML data and formats them for output. It can either provide a limited set of information or the full details of each registry setting.
|
||||
|
||||
.PARAMETER GPO
|
||||
The Group Policy Object (GPO) associated with the registry settings.
|
||||
|
||||
.PARAMETER DataSet
|
||||
An array of XML elements containing the registry settings.
|
||||
|
||||
.PARAMETER Collection
|
||||
The name of the collection of registry settings.
|
||||
|
||||
.PARAMETER Limited
|
||||
Indicates whether to provide limited information about each registry setting.
|
||||
|
||||
.EXAMPLE
|
||||
Get-XMLNestedRegistry -GPO $GPO -DataSet $DataSet -Collection "SoftwareSettings" -Limited
|
||||
Retrieves limited information about the registry settings in the "SoftwareSettings" collection.
|
||||
|
||||
.EXAMPLE
|
||||
Get-XMLNestedRegistry -GPO $GPO -DataSet $DataSet -Collection "WindowsSettings"
|
||||
Retrieves full details of the registry settings in the "WindowsSettings" collection.
|
||||
|
||||
#>
|
||||
[cmdletBinding()]
|
||||
param(
|
||||
[PSCustomObject] $GPO,
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
ActionRequired = $null
|
||||
Data = $null
|
||||
Execute = {
|
||||
Invoke-GPOZaurrContent -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains
|
||||
Invoke-GPOZaurrContent -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -GPOName $GPOName -GPOGUID $GPOGUID
|
||||
}
|
||||
Processing = {
|
||||
|
||||
@@ -18,7 +18,7 @@
|
||||
Solution = {
|
||||
foreach ($Key in $Script:Reporting['GPOAnalysis']['Data'].Keys) {
|
||||
New-HTMLTab -Name $Key {
|
||||
New-HTMLTable -DataTable $Script:Reporting['GPOAnalysis']['Data'][$Key] -Filtering -Title $Key
|
||||
New-HTMLTable -DataTable $Script:Reporting['GPOAnalysis']['Data'][$Key] -Filtering -Title $Key -ScrollX
|
||||
}
|
||||
}
|
||||
if ($Script:Reporting['GPOAnalysis']['WarningsAndErrors']) {
|
||||
|
||||
@@ -5,9 +5,9 @@
|
||||
Data = $null
|
||||
Execute = {
|
||||
if ($Script:Reporting['GPOBlockedInheritance']['Exclusions']) {
|
||||
Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance -IncludeGroupPoliciesForBlockedObjects -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $Excludeomains -Exclusions $Script:Reporting['GPOBlockedInheritance']['Exclusions']
|
||||
Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance -IncludeGroupPoliciesForBlockedObjects -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -Exclusions $Script:Reporting['GPOBlockedInheritance']['Exclusions']
|
||||
} else {
|
||||
Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance -IncludeGroupPoliciesForBlockedObjects -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $Excludeomains
|
||||
Get-GPOZaurrInheritance -IncludeBlockedObjects -IncludeExcludedObjects -OnlyBlockedInheritance -IncludeGroupPoliciesForBlockedObjects -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains
|
||||
}
|
||||
}
|
||||
Processing = {
|
||||
@@ -80,7 +80,7 @@
|
||||
"As GPOs can be inherited by default, they can also be blocked, if required using the Block Inheritance. "
|
||||
"If the Block Inheritance setting is enabled, the inheritance of group policy setting is blocked. "
|
||||
"This setting is mostly used when the OU contains users or computers that require different settings than what is applied to the domain level. "
|
||||
"Unfortunetly blocking inheritance can have serious security consequences. "
|
||||
"Unfortunately blocking inheritance can have serious security consequences. "
|
||||
)
|
||||
New-HTMLText -Text @(
|
||||
'As it stands currently there are ',
|
||||
@@ -110,6 +110,22 @@
|
||||
} -FontSize 10pt
|
||||
}
|
||||
New-HTMLText -FontSize 10pt -Text "Please review output in table and follow the steps below table to get Active Directory Group Policies in healthy state."
|
||||
|
||||
if ($Script:Reporting['GPOBlockedInheritance']['Exclusions']) {
|
||||
New-HTMLText -LineBreak
|
||||
New-HTMLText -Text @(
|
||||
"While preparing this report following exclusions were defined. "
|
||||
"Please make sure that when you execute your steps to include those exclusions to prevent any issues. "
|
||||
) -FontSize 10pt -FontWeight bold, normal -Color Red, None -LineBreak
|
||||
|
||||
New-HTMLText -Text "Code to use for exclusions: " -FontSize 10pt -FontWeight bold -LineBreak
|
||||
|
||||
$Code = New-GPOZaurrExclusions -ExclusionsArray $Script:Reporting['GPOBlockedInheritance']['Exclusions']
|
||||
|
||||
if ($Code) {
|
||||
New-HTMLCodeBlock -Code $Code -Style powershell
|
||||
}
|
||||
}
|
||||
}
|
||||
Solution = {
|
||||
New-HTMLSection -Invisible {
|
||||
@@ -138,14 +154,14 @@
|
||||
New-TableCondition -Name 'ComputersCount' -Value 0
|
||||
} -BackgroundColor Salmon -FailBackgroundColor Amber -HighlightHeaders 'UsersCount', 'ComputersCount'
|
||||
New-TableColumnOption -Hidden $true -ColumnIndex 8
|
||||
} -PagingOptions 5, 10, 20, 30, 40, 50 -ExcludeProperty GroupPolicies
|
||||
} -PagingOptions 5, 10, 20, 30, 40, 50 -ExcludeProperty GroupPolicies -ScrollX
|
||||
}
|
||||
New-HTMLSection -Name 'Group Policies affecting objects in Organizational Units with Blocked Inheritance' {
|
||||
New-HTMLTable -DataTable $Script:Reporting['GPOBlockedInheritance']['Data'].GroupPolicies -Filtering {
|
||||
New-TableCondition -Name 'Enabled' -Value $true -BackgroundColor SpringGreen -FailBackgroundColor Salmon
|
||||
New-TableCondition -Name 'Enforced' -Value $true -BackgroundColor Amber -FailBackgroundColor AirForceBlue
|
||||
New-TableCondition -Name 'LinkedDirectly' -Value $true -BackgroundColor Amber -FailBackgroundColor AirForceBlue
|
||||
} -PagingOptions 5, 10, 20, 30, 40, 50 -DataTableID 'TableWithGroupPoliciesBlockedInheritance'
|
||||
} -PagingOptions 5, 10, 20, 30, 40, 50 -DataTableID 'TableWithGroupPoliciesBlockedInheritance' -ScrollX
|
||||
}
|
||||
if ($Script:Reporting['Settings']['HideSteps'] -eq $false) {
|
||||
New-HTMLSection -Name 'Steps to fix - Organizational Units with Group Policy Blocked Inheritance' {
|
||||
|
||||
@@ -76,7 +76,7 @@ $GPOZaurrBrokenLink = [ordered] @{
|
||||
New-HTMLSection -Name 'Group Policy Broken Links' {
|
||||
New-HTMLTable -DataTable $Script:Reporting['GPOBrokenLink']['Data'] -Filtering {
|
||||
|
||||
} -PagingOptions 10, 20, 30, 40, 50
|
||||
} -PagingOptions 7, 15, 30, 45, 60 -ScrollX
|
||||
}
|
||||
if ($Script:Reporting['Settings']['HideSteps'] -eq $false) {
|
||||
New-HTMLSection -Name 'Steps to remove Broken Links' {
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user