Compare commits

...

51 Commits

Author SHA1 Message Date
Przemyslaw Klys 97a189eda5 Added Example for cleanup dfsr 2020-08-02 14:01:28 +02:00
Przemyslaw Klys 0759d1cb85 Update readme 2020-08-02 14:01:18 +02:00
Przemyslaw Klys 424e9d2f5c Update PSD1 2020-08-02 14:01:11 +02:00
Przemyslaw Klys 794f6997b8 Some updates to Get-GPOZaurrSysvolDFSR 2020-08-02 14:01:05 +02:00
Przemyslaw Klys 175b6dede2 added Clear-GPOZaurrSysvolDFSR 2020-08-02 14:00:49 +02:00
Przemyslaw Klys 91bace0a05 Added Get-GPOZaurrSysvolDFSR 2020-08-02 13:46:36 +02:00
Przemyslaw Klys 7d829ac78d Update Example 2020-08-02 00:54:28 +02:00
Przemyslaw Klys caa9585906 removed dead code 2020-08-02 00:50:41 +02:00
Przemyslaw Klys d0d6427b38 removed dead code 2020-08-02 00:50:32 +02:00
Przemyslaw Klys 7c5622f682 Removed dead code 2020-08-02 00:50:25 +02:00
Przemyslaw Klys 12e183b45c Removed dead code 2020-08-02 00:50:11 +02:00
Przemyslaw Klys e52dc71857 Update PSD1 2020-08-02 00:50:02 +02:00
Przemyslaw Klys 9041f4cdbc Removed dead code 2020-08-02 00:43:43 +02:00
Przemyslaw Klys 6f503f735f Why was it even here? 2020-08-02 00:43:36 +02:00
Przemyslaw Klys 27830e9f8a Removing dead code 2020-08-02 00:41:43 +02:00
Przemyslaw Klys d8c63ce949 Uploading just to have backup 2020-08-02 00:41:21 +02:00
Przemyslaw Klys 33b2854d63 Cleaning up dead code 2020-08-02 00:41:05 +02:00
Przemyslaw Klys acb51d4444 Update Invoke-GPOZaurr 2020-08-02 00:32:30 +02:00
Przemyslaw Klys 3bc9bb5f9c A lot more policy types supported 2020-08-02 00:32:18 +02:00
Przemyslaw Klys 58d94edac0 Great policy, with update for ListBox 2020-08-02 00:32:04 +02:00
Przemyslaw Klys d76ae5cd1d Lithnet update, but most likely to remove 2020-08-02 00:31:52 +02:00
Przemyslaw Klys a11d563704 Bitlocker update, but most likely to remove 2020-08-02 00:31:41 +02:00
Przemyslaw Klys 34c55c8482 Example update 2020-08-02 00:31:20 +02:00
Przemyslaw Klys c6fdfccc61 Update PSD1 2020-08-02 00:31:10 +02:00
Przemyslaw Klys e512c0b0de Update - but maybe we should remove this 2020-08-01 00:12:03 +02:00
Przemyslaw Klys 7afd104b7b Update psd1 2020-07-31 15:26:56 +02:00
Przemyslaw Klys 60511fa602 Removed dead examples 2020-07-31 15:26:48 +02:00
Przemyslaw Klys 9b3924cc00 Added Lithnet filter 2020-07-31 15:24:03 +02:00
Przemyslaw Klys 0bf093351f Added LAPS support 2020-07-31 11:00:57 +02:00
Przemyslaw Klys 2d164750f1 Update 2020-07-30 22:56:17 +02:00
Przemyslaw Klys b8d440f547 Better audit report 2020-07-30 22:56:09 +02:00
Przemyslaw Klys f25ace130c Audit update to to advanced events 2020-07-30 22:55:58 +02:00
Przemyslaw Klys 8b17f9e3a2 Updated policies to use int instead of strings 2020-07-30 22:55:01 +02:00
Przemyslaw Klys b97cf1fd9d Update 2020-07-30 22:04:13 +02:00
Przemyslaw Klys 416b3f0273 Update 2020-07-30 22:03:51 +02:00
Przemyslaw Klys d3c31e9651 Update example 2020-07-30 21:58:41 +02:00
Przemyslaw Klys 8b963c6b82 Rewritten Autologon using Reports on Reports 2020-07-30 21:58:28 +02:00
Przemyslaw Klys 989d3ba9f0 Added functionality reports based on reports 2020-07-30 21:58:15 +02:00
Przemyslaw Klys f3e2d3cc11 Removed verbose messages 2020-07-30 21:57:54 +02:00
Przemyslaw Klys a7b8b5f6ea Update 2020-07-30 13:41:58 +02:00
Przemyslaw Klys 7f2adbbb13 Update 2020-07-30 12:23:52 +02:00
Przemyslaw Klys a82e460406 Update 2020-07-30 12:23:38 +02:00
Przemyslaw Klys a0e990bf2a Update to example 2020-07-30 11:28:56 +02:00
Przemyslaw Klys ddc5630244 Small update 2020-07-30 11:28:47 +02:00
Przemyslaw Klys d377e92fb5 Fixed reading Registry XML 2020-07-30 11:26:47 +02:00
Przemyslaw Klys b8c3f1e8f8 Updates to Printer XML 2020-07-30 11:26:37 +02:00
Przemyslaw Klys a827afab39 Fix for argument completer 2020-07-29 23:20:27 +02:00
Przemyslaw Klys 61bb568c94 Fix for nested XML, still collection name is wrong 2020-07-29 23:20:07 +02:00
Przemyslaw Klys 3f4d8c9907 Better assesment of empty and linked gpos 2020-07-29 22:13:11 +02:00
Przemyslaw Klys f6466c2ca7 Update PSD1 2020-07-29 22:12:36 +02:00
Przemyslaw Klys 609d93118b Fix for lack of value 2020-07-29 22:12:30 +02:00
37 changed files with 860 additions and 833 deletions
@@ -2,4 +2,4 @@
# Remove GPOS
$BackupPath = "$Env:UserProfile\Desktop\GPO"
Remove-GPOZaurr -Type Empty, Unlinked -BackupPath $BackupPath -BackupDated -LimitProcessing 2 -Verbose
Remove-GPOZaurr -Type Empty, Unlinked -BackupPath $BackupPath -BackupDated -LimitProcessing 2 -Verbose -WhatIf
+1 -1
View File
@@ -1,7 +1,7 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
$GPOS = Get-GPOZaurr
$GPOS | Format-Table -AutoSize
$GPOS | Format-Table -AutoSize *
$GPOS[0] | Format-List
@@ -1,34 +0,0 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# Use Save-GPOZaurrFiles -GPOPath $ENV:USERPROFILE\Desktop\GPOExport
#$OutputNoTranslation = Invoke-GPOZaurr -GPOPath $Env:UserProfile\Desktop\GPOExport -NoTranslation
#$OutputNoTranslation = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' -NoTranslation
$OutputNoTranslation | Format-Table *
<#
New-HTML {
foreach ($GPOCategory in $OutputNoTranslation.Keys) {
New-HTMLTab -Name $GPOCategory {
if ($OutputNoTranslation["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $OutputNoTranslation["$GPOCategory"].Keys) {
New-HTMLTab -Name $GpoSettings {
New-HTMLTable -DataTable $OutputNoTranslation[$GPOCategory][$GpoSettings] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
} else {
New-HTMLTable -DataTable $OutputNoTranslation[$GPOCategory] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
}
} -Online -ShowHTML -FilePath $Env:UserProfile\Desktop\OutputFromFindGPO-NoTranslationFromDisk.html
#>
foreach ($GPOCategory in $OutputNoTranslation.Keys) {
if ($OutputNoTranslation["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $OutputNoTranslation["$GPOCategory"].Keys) {
ConvertTo-Excel -DataTable $OutputNoTranslation[$GPOCategory][$GpoSettings] -AllProperties -ExcelWorkSheetName $GpoSettings -FilePath $Env:UserProfile\Desktop\Export\$GpoSettings.xlsx -AutoFilter -AutoFit
}
} else {
ConvertTo-Excel -DataTable $OutputNoTranslation[$GPOCategory][$GpoSettings] -AllProperties -ExcelWorkSheetName $GpoSettings -FilePath $Env:UserProfile\Desktop\Export\$GpoSettings.xlsx -AutoFilter -AutoFit
}
}
+10 -45
View File
@@ -1,47 +1,12 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
#Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
#Invoke-GPOZaurr -OutputType Excel, Object, HTML -Open | Format-Table
#$Output = Invoke-GPOZaurr -GPOPath $Env:USERPROFILE\Desktop\GPOExport -NoTranslation #| Format-Table
#$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTestRegistryCheck' -NoTranslation
$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' -NoTranslation -Verbose
#$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExport' -NoTranslation #-OutputType HTML, Object -Open #| Format-Table
#$Output.Categories | Out-HtmlView
#$Output.Categories | Format-Table
$Output | Format-Table
#$Output.CategoriesFull | Format-Table
#$Output.Count
# Asses GPO based on exported data
$Output = Invoke-GPOZaurr -GPOPath $Env:USERPROFILE\Desktop\GPOExport -Verbose
#$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' -Verbose
$Output | Format-Table *
$Output.Reports | Format-Table
#$Output.Reports.Scripts | Format-Table *
#$Output.Reports.AccountPolicies | Format-Table *
#$Output.Reports.Audit | Format-Table *
#$Output.Reports.Autologon | Format-Table *
#$Output.Reports.EventLog | Format-Table *
#$Output.Reports.SoftwareInstallation | Format-Table *
#$Output.Reports.Policies | Format-Table *
#Output.Reports.RegistrySettings | Format-Table *
#$Output.Reports.SecurityOptions | Format-Table *
#$Output.Reports.SystemServices | Format-Table *
#$Output.Reports.SystemServicesNT | Format-Table *
#$Output.Reports.LocalUsers | Format-Table *
#$Output.Reports.LocalGroups | Format-Table *
#$Output.Reports.DriveMapping | Format-Table *
#$Output.Reports.Printers | Format-Table *
$Output.Reports.TaskScheduler | Format-Table *
return
# This is section that treats 1 GPO as single object - if there are 5 scripts in 1 GPO there's only one value
$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' -NoTranslation -SingleObject
#$Output
#$Output.Reports | Format-Table
#$Output.Reports.Scripts | Format-Table *
#$Output.Reports.SoftwareInstallation | Format-Table *
#$Output.Reports.Policies | Format-Table *
#$Output.Reports.RegistrySettings | Format-Table *
#$Output.Reports.SecurityOptions | Format-Table *
#$Output.Reports.SystemServices | Format-Table *
#$Output.Reports.SystemServicesNT | Format-Table *
#$Output.Reports.LocalUsers | Format-Table *
#$Output.Reports.LocalGroups | Format-Table *
#$Output.Reports.DriveMapping | Format-Table *
$Output.Reports.Printers | Format-Table *
# Export to Excel
foreach ($Key in $Output.Reports.Keys) {
$Output.Reports[$Key] | ConvertTo-Excel -FilePath $Env:USERPROFILE\Desktop\EFGPOAnalysis.xlsx -ExcelWorkSheetName $Key -AutoFilter -AutoFit -FreezeTopRowFirstColumn
}
Start-Process "$Env:USERPROFILE\Desktop\EFGPOAnalysis.xlsx"
+11 -13
View File
@@ -1,20 +1,18 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
$Output = Invoke-GPOZaurr #-NoTranslation
$Output = Invoke-GPOZaurr
$Output | Format-Table
# Report to Excel of translated reports
foreach ($Key in $Output.Reports.Keys) {
$Output.Reports[$Key] | ConvertTo-Excel -FilePath $Env:USERPROFILE\Desktop\GPOAnalysis.xlsx -ExcelWorkSheetName $Key -AutoFilter -AutoFit -FreezeTopRowFirstColumn
}
# Report to HTML of translated reports
New-HTML {
foreach ($GPOCategory in $Output.Keys) {
New-HTMLTab -Name $GPOCategory {
if ($Output["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $Output["$GPOCategory"].Keys) {
New-HTMLTab -Name $GpoSettings {
New-HTMLTable -DataTable $Output[$GPOCategory][$GpoSettings] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
} else {
New-HTMLTable -DataTable $Output[$GPOCategory] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
foreach ($Key in $Output.Reports.Keys) {
New-HTMLTab -Name $Key {
New-HTMLTable -DataTable $Output.Reports[$Key] -Filtering
}
}
} -Online -ShowHTML -FilePath $Env:UserProfile\Desktop\OutputFromFindGPO.html
} -FilePath $Env:USERPROFILE\Desktop\GPOAnalysis.html -ShowHTML -Online
@@ -1,20 +0,0 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
$Output = Invoke-GPOZaurr -NoTranslation
$Output | Format-Table
New-HTML {
foreach ($GPOCategory in $Output.Keys) {
New-HTMLTab -Name $GPOCategory {
if ($Output["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $Output["$GPOCategory"].Keys) {
New-HTMLTab -Name $GpoSettings {
New-HTMLTable -DataTable $Output[$GPOCategory][$GpoSettings] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
} else {
New-HTMLTable -DataTable $Output[$GPOCategory] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
}
} -Online -ShowHTML -FilePath $Env:UserProfile\Desktop\OutputFromFindGPO-NoTranslation.html
+8
View File
@@ -0,0 +1,8 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# This gets the same thing as earlier examples
# with a difference where one entry per gpo and all settings for that GPO is stored under settings property.
$Output = Invoke-GPOZaurr -SingleObject
$Output | Format-Table
$Output.Reports.RegistrySettings | Format-Table *
$Output.Reports.RegistrySettings[0].Settings | Format-Table *
-22
View File
@@ -1,22 +0,0 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# Use Save-GPOZaurrFiles -GPOPath $ENV:USERPROFILE\Desktop\GPOExport
$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' # -NoTranslation
$Output | Format-Table *
New-HTML {
foreach ($GPOCategory in $Output.Keys) {
New-HTMLTab -Name $GPOCategory {
if ($Output["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $Output["$GPOCategory"].Keys) {
New-HTMLTab -Name $GpoSettings {
New-HTMLTable -DataTable $Output[$GPOCategory][$GpoSettings] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
} else {
New-HTMLTable -DataTable $Output[$GPOCategory] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
}
}
} -Online -ShowHTML -FilePath $Env:UserProfile\Desktop\OutputFromFindGPO-FromDisk.html
+13
View File
@@ -0,0 +1,13 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# Use Save-GPOZaurrFiles -GPOPath $ENV:USERPROFILE\Desktop\GPOExportAudit
$Output = Invoke-GPOZaurr -GPOPath $ENV:USERPROFILE\Desktop\GPOExportAudit -Verbose #-SkipCleanup #-Type PoliciesPrinters, Policies
$Output | Format-Table *
$Output.Reports | Format-Table
# Export to Excel
foreach ($Key in $Output.Reports.Keys) {
$Output.Reports[$Key] | ConvertTo-Excel -FilePath $Env:USERPROFILE\Desktop\GPOAnalysis.xlsx -ExcelWorkSheetName $Key -AutoFilter -AutoFit -FreezeTopRowFirstColumn
}
Start-Process "$Env:USERPROFILE\Desktop\GPOAnalysis.xlsx"
@@ -1,25 +0,0 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# Use Save-GPOZaurrFiles -GPOPath $ENV:USERPROFILE\Desktop\GPOExport
$OutputTranslation = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExport'
$OutputTranslation | Format-Table
$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExport' -NoTranslation
$Output | Format-Table *
#$Output.LugsSettings.LocalUsersAndGroups | Format-List *
$GPOEntry = $Output.LugsSettings.LocalUsersAndGroups[0]
$CreateGPO = @{}
foreach ($User in $GPOEntry.User) {
# $User | Format-Table
# $User.Properties | Format-Table
}
foreach ($Group in $GPOEntry.Group) {
#$Group | Format-Table
$Group.Properties | Format-Table
$Group.Properties.Members | Format-Table
}
@@ -1,6 +0,0 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# Use Save-GPOZaurrFiles -GPOPath $ENV:USERPROFILE\Desktop\GPOExport
$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' -NoTranslation
$Output | Format-Table *
@@ -1,11 +0,0 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# This is purely for building GPO Dictionary, mostly for development needs to help asses what is there
$Output = Invoke-GPOZaurr -GPOPath 'C:\Support\GitHub\GpoZaurr\Ignore\GPOExportTest' -NoTranslation
#$Output | Format-Table *
$LookingFor = $Output | Select-GPOTranslation -Category 'SecuritySettings' -Settings 'UserRightsAssignment'
$LookingFor | Format-Table
$LookingFor.Types | Format-Table
#$LookingFor.Data | Format-Table
@@ -0,0 +1,10 @@
Import-Module "$PSScriptRoot\..\GPoZaurr.psd1" -Force
# Cleanup based on https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/manually-clearing-the-conflictanddeleted-folder-in-dfsr/ba-p/395711
# Get dfsr information
$DFSR = Get-GPOZaurrSysvolDFSR
$DFSR | Format-Table
# Cleanup DFSR Conflict Path
Clear-GPOZaurrSysvolDFSR -WhatIf
+3 -3
View File
@@ -5,9 +5,9 @@
CompatiblePSEditions = 'Desktop'
Copyright = '(c) 2011 - 2020 Przemyslaw Klys @ Evotec. All rights reserved.'
Description = 'Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.'
FunctionsToExport = 'Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrFiles', 'Get-GPOZaurrFilesPolicyDefinitions', 'Get-GPOZaurrFolders', 'Get-GPOZaurrLegacyFiles', 'Get-GPOZaurrLink', 'Get-GPOZaurrLinkSummary', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrSysvol', 'Get-WMIFilter', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurr', 'Invoke-GPOZaurrPermission', 'New-GPOZaurrWMI', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrFolders', 'Remove-GPOZaurrLegacyFiles', 'Remove-GPOZaurrOrphanedSysvolFolders', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Select-GPOTranslation', 'Set-GPOOwner', 'Set-GPOZaurrOwner'
FunctionsToExport = 'Add-GPOPermission', 'Add-GPOZaurrPermission', 'Backup-GPOZaurr', 'Clear-GPOZaurrSysvolDFSR', 'Get-GPOZaurr', 'Get-GPOZaurrAD', 'Get-GPOZaurrBackupInformation', 'Get-GPOZaurrFiles', 'Get-GPOZaurrFilesPolicyDefinitions', 'Get-GPOZaurrFolders', 'Get-GPOZaurrLegacyFiles', 'Get-GPOZaurrLink', 'Get-GPOZaurrLinkSummary', 'Get-GPOZaurrOwner', 'Get-GPOZaurrPassword', 'Get-GPOZaurrPermission', 'Get-GPOZaurrPermissionConsistency', 'Get-GPOZaurrSysvol', 'Get-GPOZaurrSysvolDFSR', 'Get-GPOZaurrWMI', 'Invoke-GPOZaurr', 'Invoke-GPOZaurrPermission', 'New-GPOZaurrWMI', 'Remove-GPOPermission', 'Remove-GPOZaurr', 'Remove-GPOZaurrFolders', 'Remove-GPOZaurrLegacyFiles', 'Remove-GPOZaurrOrphanedSysvolFolders', 'Remove-GPOZaurrPermission', 'Remove-GPOZaurrWMI', 'Repair-GPOZaurrPermissionConsistency', 'Restore-GPOZaurr', 'Save-GPOZaurrFiles', 'Set-GPOOwner', 'Set-GPOZaurrOwner'
GUID = 'f7d4c9e4-0298-4f51-ad77-e8e3febebbde'
ModuleVersion = '0.0.50'
ModuleVersion = '0.0.51'
PowerShellVersion = '5.1'
PrivateData = @{
PSData = @{
@@ -17,7 +17,7 @@
}
}
RequiredModules = @{
ModuleVersion = '0.0.161'
ModuleVersion = '0.0.165'
ModuleName = 'PSSharedGoods'
Guid = 'ee272aa8-baaa-4edf-9f45-b6d6f7d844fe'
}, @{
+1 -1
View File
@@ -29,7 +29,7 @@
if ($GPOEntry.SettingBoolean) {
$CreateGPO[$($GPOEntry.Name)] = if ($GPOEntry.SettingBoolean -eq 'true') { 'Enabled' } elseif ($GPOEntry.SettingBoolean -eq 'false') { 'Disabled' } else { 'Not set' };
} elseif ($GPOEntry.SettingNumber) {
$CreateGPO[$($GPOEntry.Name)] = $GPOEntry.SettingNumber
$CreateGPO[$($GPOEntry.Name)] = [int] $GPOEntry.SettingNumber
}
}
$CreateGPO['Linked'] = $GPO.Linked
+97 -23
View File
@@ -4,36 +4,110 @@
[PSCustomObject] $GPO,
[switch] $FullObject
)
$SettingType = @{
'0' = 'No Auditing'
'1' = 'Success'
'2' = 'Failure'
'3' = 'Success, Failure'
}
$CreateGPO = [ordered]@{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
AuditAccountLogon = 'No auditing'
AuditAccountManage = 'No auditing'
AuditDSAccess = 'No auditing'
AuditLogonEvents = 'No auditing'
AuditObjectAccess = 'No auditing'
AuditPolicyChange = 'No auditing'
AuditPrivilegeUse = 'No auditing'
AuditProcessTracking = 'No auditing'
AuditSystemEvents = 'No auditing'
AuditAccountLogon = 'Not configured'
AuditAccountManage = 'Not configured'
AuditDSAccess = 'Not configured'
AuditLogonEvents = 'Not configured'
AuditObjectAccess = 'Not configured'
AuditPolicyChange = 'Not configured'
AuditPrivilegeUse = 'Not configured'
AuditProcessTracking = 'Not configured'
AuditSystemEvents = 'Not configured'
# Advanced Policies
AuditAccountLockout = 'Not configured'
AuditApplicationGenerated = 'Not configured'
AuditApplicationGroupManagement = 'Not configured'
AuditAuditPolicyChange = 'Not configured'
AuditAuthenticationPolicyChange = 'Not configured'
AuditAuthorizationPolicyChange = 'Not configured'
AuditCentralAccessPolicyStaging = 'Not configured'
AuditCertificationServices = 'Not configured'
AuditComputerAccountManagement = 'Not configured'
AuditCredentialValidation = 'Not configured'
AuditDetailedDirectoryServiceReplication = 'Not configured'
AuditDetailedFileShare = 'Not configured'
AuditDirectoryServiceAccess = 'Not configured'
AuditDirectoryServiceChanges = 'Not configured'
AuditDirectoryServiceReplication = 'Not configured'
AuditDistributionGroupManagement = 'Not configured'
AuditDPAPIActivity = 'Not configured'
AuditFileShare = 'Not configured'
AuditFileSystem = 'Not configured'
AuditFilteringPlatformConnection = 'Not configured'
AuditFilteringPlatformPacketDrop = 'Not configured'
AuditFilteringPlatformPolicyChange = 'Not configured'
AuditGroupMembership = 'Not configured'
AuditHandleManipulation = 'Not configured'
AuditIPsecDriver = 'Not configured'
AuditIPsecExtendedMode = 'Not configured'
AuditIPsecMainMode = 'Not configured'
AuditIPsecQuickMode = 'Not configured'
AuditKerberosAuthenticationService = 'Not configured'
AuditKerberosServiceTicketOperations = 'Not configured'
AuditKernelObject = 'Not configured'
AuditLogoff = 'Not configured'
AuditLogon = 'Not configured'
AuditMPSSVCRuleLevelPolicyChange = 'Not configured'
AuditNetworkPolicyServer = 'Not configured'
AuditNonSensitivePrivilegeUse = 'Not configured'
AuditOtherAccountLogonEvents = 'Not configured'
AuditOtherAccountManagementEvents = 'Not configured'
AuditOtherLogonLogoffEvents = 'Not configured'
AuditOtherObjectAccessEvents = 'Not configured'
AuditOtherPolicyChangeEvents = 'Not configured'
AuditOtherPrivilegeUseEvents = 'Not configured'
AuditOtherSystemEvents = 'Not configured'
AuditPNPActivity = 'Not configured'
AuditProcessCreation = 'Not configured'
AuditProcessTermination = 'Not configured'
AuditRegistry = 'Not configured'
AuditRemovableStorage = 'Not configured'
AuditRPCEvents = 'Not configured'
AuditSAM = 'Not configured'
AuditSecurityGroupManagement = 'Not configured'
AuditSecurityStateChange = 'Not configured'
AuditSecuritySystemExtension = 'Not configured'
AuditSensitivePrivilegeUse = 'Not configured'
AuditSpecialLogon = 'Not configured'
AuditSystemIntegrity = 'Not configured'
AuditUserDeviceClaims = 'Not configured'
AuditUserAccountManagement = 'Not configured'
}
foreach ($GPOEntry in $GPO.DataSet) {
$SuccessAttempts = try { [bool]::Parse($GPOEntry.SuccessAttempts) } catch { $null };
$FailureAttempts = try { [bool]::Parse($GPOEntry.FailureAttempts) } catch { $null };
if ($SuccessAttempts -and $FailureAttempts) {
$Setting = 'Success, Failure'
} elseif ($SuccessAttempts) {
$Setting = 'Success'
} elseif ($FailureAttempts) {
$Setting = 'Failure'
if ($GPOEntry.PolicyTarget) {
# Category = 'AuditSettings', Settings = 'AuditSetting'
$Category = $GPOEntry.SubcategoryName -replace ' ', '' -replace '-', '' -replace '/', ''
if ($CreateGPO["$($Category)"]) {
$CreateGPO["$($Category)"] = $SettingType["$($GPOEntry.SettingValue)"]
}
} else {
$Setting = 'No auditing'
# Category = 'SecuritySettings', Settings = 'Audit'
$SuccessAttempts = try { [bool]::Parse($GPOEntry.SuccessAttempts) } catch { $null };
$FailureAttempts = try { [bool]::Parse($GPOEntry.FailureAttempts) } catch { $null };
if ($SuccessAttempts -and $FailureAttempts) {
$Setting = 'Success, Failure'
} elseif ($SuccessAttempts) {
$Setting = 'Success'
} elseif ($FailureAttempts) {
$Setting = 'Failure'
} else {
$Setting = 'Not configured'
}
$CreateGPO["$($GPOEntry.Name)"] = $Setting
}
$CreateGPO["$($GPOEntry.Name)"] = $Setting
}
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
+112
View File
@@ -0,0 +1,112 @@
function ConvertTo-XMLGenericPolicy {
[cmdletBinding()]
param(
[PSCustomObject] $GPO,
[string[]] $Category
)
$CreateGPO = [ordered]@{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
}
$UsedNames = [System.Collections.Generic.List[string]]::new()
[Array] $Policies = foreach ($Cat in $Category) {
$GPO.DataSet | Where-Object { $_.Category -like $Cat }
}
#if ($GPO.DataSet.Category -like $Category) {
if ($Policies.Count -gt 0) {
foreach ($Policy in $Policies) {
#if ($Policy.Category -notlike $Category) {
# We check again for Category because one GPO can have multiple categories
# First check checks GPO globally,
# continue
#}
$Name = Format-ToTitleCase -Text $Policy.Name -RemoveWhiteSpace -RemoveChar ',', '-', "'", '\(', '\)', ':'
$CreateGPO[$Name] = $Policy.State
foreach ($Setting in @('DropDownList', 'Numeric', 'EditText', 'Text', 'CheckBox', 'ListBox')) {
if ($Policy.$Setting) {
foreach ($Value in $Policy.$Setting) {
if ($Value.Name) {
$SubName = Format-ToTitleCase -Text $Value.Name -RemoveWhiteSpace -RemoveChar ',', '-', "'", '\(', '\)', ':'
$SubName = -join ($Name, $SubName)
if ($SubName -notin $UsedNames) {
$UsedNames.Add($SubName)
} else {
$TimesUsed = $UsedNames | Group-Object | Where-Object { $_.Name -eq $SubName }
$NumberToUse = $TimesUsed.Count + 1
# We add same name 2nd and 3rd time to make sure we count properly
$UsedNames.Add($SubName)
# We now build property name based on amnount of times
$SubName = -join ($SubName, "$NumberToUse")
}
if ($Value.Value -is [string]) {
$CreateGPO["$SubName"] = $Value.Value
} elseif ($Value.Value -is [System.Xml.XmlElement]) {
<#
if ($null -eq $Value.Value.Name) {
# Shouldn't happen but lets see
Write-Verbose $Value
} else {
$CreateGPO["$SubName"] = $Value.Value.Name
}
#>
if ($Value.Value.Element) {
$CreateGPO["$SubName"] = $Value.Value.Element.Data -join '; '
} elseif ($null -eq $Value.Value.Name) {
# Shouldn't happen but lets see
Write-Verbose "Tracking $Value"
} else {
$CreateGPO["$SubName"] = $Value.Value.Name
}
} elseif ($Value.State) {
$CreateGPO["$SubName"] = $Value.State
} elseif ($null -eq $Value.Value) {
# This is most likely Setting 'Text
# Do nothing, usually it's just a text to display
#Write-Verbose "Skipping value for display because it's empty. Name: $($Value.Name)"
} else {
# shouldn't happen
Write-Verbose $Value
}
}
}
}
}
}
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
$CreateGPO['Links'] = $GPO.Links
[PSCustomObject] $CreateGPO
#}
}
}
<# ListBox - $Value
Name : Items to run at logon
State : Enabled
ExplicitValue : false
Additive : false
ValuePrefix :
Value : Value
ListBox - $Value.Value
Element
-------
Element
ListBox - $Value.Value.Element
Data
----
C:\Program Files (x86)\NetPhone Client\NetPhone Client.exe
#>
+2 -2
View File
@@ -10,7 +10,7 @@ function ConvertTo-XMLPrinterInternal {
$CreateGPO = [ordered]@{
Changed = try { [DateTime] $Entry.changed } catch { $Entry.Changed };
#uid = $Entry.uid
BypassErrors = if ($Entry.bypassErrors -eq '1') { $true } elseif ($Entry.bypassErrors -eq '0') { $false } else { $Entry.bypassErrors };
BypassErrors = if ($Entry.bypassErrors -eq '1') { $true } else { $false };
GPOSettingOrder = $Entry.GPOSettingOrder
Filter = $Entry.Filter
type = $Type
@@ -54,7 +54,7 @@ function ConvertTo-XMLPrinterInternal {
GpoSettings = $GPO.GpoSettings
Changed = try { [DateTime] $Entry.changed } catch { $Entry.Changed };
#uid = $Entry.uid
BypassErrors = if ($Entry.bypassErrors -eq '1') { $true } elseif ($Entry.bypassErrors -eq '0') { $false } else { $Entry.bypassErrors };
BypassErrors = if ($Entry.bypassErrors -eq '1') { $true } else { $false };
GPOSettingOrder = $Entry.GPOSettingOrder
Filter = $Entry.Filter
type = $Type
+3 -3
View File
@@ -41,9 +41,9 @@
$null -ne $CreateGPO['DefaultUserName'] -or
$null -ne $CreateGPO['DefaultPassword']
) {
$CreateGPO['Linked'] = $GPOEntry.Linked #: True
$CreateGPO['LinksCount'] = $GPOEntry.LinksCount #: 1
$CreateGPO['Links'] = $GPOEntry.Links #: area1.local
$CreateGPO['Linked'] = $GPOEntry.Linked
$CreateGPO['LinksCount'] = $GPOEntry.LinksCount
$CreateGPO['Links'] = $GPOEntry.Links
[PSCustomObject] $CreateGPO
}
}
@@ -0,0 +1,49 @@
function ConvertTo-XMLRegistryAutologonOnReport {
[cmdletBinding()]
param(
[PSCustomObject] $GPO
)
$CreateGPO = [ordered]@{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
AutoAdminLogon = $null
DefaultDomainName = $null
DefaultUserName = $null
DefaultPassword = $null
DateChangedAutoAdminLogon = $null
DateChangedDefaultDomainName = $null
DateChangedDefaultUserName = $null
DateChangedDefaultPassword = $null
}
foreach ($Registry in $GPO.Settings) {
if ($Registry.Key -eq 'SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon') {
if ($Registry.Name -eq 'AutoAdminLogon') {
$CreateGPO['AutoAdminLogon'] = [bool] $Registry.value
$CreateGPO['DateChangedAutoAdminLogon'] = [DateTime] $Registry.changed
} elseif ($Registry.Name -eq 'DefaultDomainName') {
$CreateGPO['DefaultDomainName'] = $Registry.value
$CreateGPO['DateChangedDefaultDomainName'] = [DateTime] $Registry.changed
} elseif ($Registry.Name -eq 'DefaultUserName') {
$CreateGPO['DefaultUserName'] = $Registry.value
$CreateGPO['DateChangedDefaultUserName'] = [DateTime] $Registry.changed
} elseif ($Registry.Name -eq 'DefaultPassword') {
$CreateGPO['DefaultPassword'] = $Registry.value
$CreateGPO['DateChangedDefaultPassword'] = [DateTime] $Registry.changed
}
}
}
if ($null -ne $CreateGPO['AutoAdminLogon'] -or
$null -ne $CreateGPO['DefaultDomainName'] -or
$null -ne $CreateGPO['DefaultUserName'] -or
$null -ne $CreateGPO['DefaultPassword']
) {
$CreateGPO['Linked'] = $GPOEntry.Linked #: True
$CreateGPO['LinksCount'] = $GPOEntry.LinksCount #: 1
$CreateGPO['Links'] = $GPOEntry.Links #: area1.local
[PSCustomObject] $CreateGPO
}
}
-47
View File
@@ -17,59 +17,12 @@
}
[Array] $CreateGPO['Settings'] = Get-XMLNestedRegistry -GPO $GPO -DataSet $GPO.DataSet
<#
[Array] $CreateGPO['Settings'] = foreach ($Registry in $GPO.DataSet.Registry) {
[PSCustomObject] @{
Changed = [DateTime] $Registry.changed
GPOSettingOrder = $Registry.GPOSettingOrder
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
}
}
#>
$CreateGPO['Count'] = $CreateGPO['Settings'].Count
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
$CreateGPO['Links'] = $GPO.Links
[PSCustomObject] $CreateGPO
} else {
<#
if ($GPO.DataSet.Registry) {
Get-XMLNestedRegistry -GPO $GPO -RegistryCollection $GPO.DataSet.Registry
}
if ($GPO.DataSet.Collection) {
Get-XMLNestedRegistry -GPO $GPO -RegistryCollection $GPO.DataSet.Collection
}
#>
Get-XMLNestedRegistry -GPO $GPO -DataSet $GPO.DataSet
<#
foreach ($Registry in $GPO.DataSet.Registry) {
$CreateGPO = [ordered]@{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
Changed = [DateTime] $Registry.changed
GPOSettingOrder = $Registry.GPOSettingOrder
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
}
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
$CreateGPO['Links'] = $GPO.Links
[PSCustomObject] $CreateGPO
}
#>
}
}
-15
View File
@@ -1,15 +0,0 @@
function Find-MissingProperties {
[cmdletBinding()]
param(
[Array] $Objects,
[string[]] $PossibleProperties
)
$AllProperties = Select-Properties -AllProperties -Objects $Objects
$MissingProperties = $AllProperties | Where-Object { $_ -notin 'DisplayName', 'DomainName', 'GUID', 'Linked', 'LinksCount', 'Links', 'GPOType', 'GPOCategory', 'GPOSettings' }
[Array] $ConsiderAdding = foreach ($Property in $MissingProperties) {
if ($Property -notin $PossibleProperties) {
$Property
}
}
$ConsiderAdding
}
+36 -20
View File
@@ -5,15 +5,33 @@
[Microsoft.GroupPolicy.Gpo] $GPO,
[switch] $PermissionsOnly,
[switch] $OwnerOnly,
[System.Collections.IDictionary] $ADAdministrativeGroups
[System.Collections.IDictionary] $ADAdministrativeGroups,
[string] $Splitter = [System.Environment]::NewLine
)
if ($XMLContent.GPO.LinksTo) {
$Linked = $true
$LinksCount = ([Array] $XMLContent.GPO.LinksTo).Count
$LinkSplit = ([Array] $XMLContent.GPO.LinksTo).Where( { $_.Enabled -eq $true }, 'Split')
[Array] $LinksEnabled = $LinkSplit[0]
[Array] $LinksDisabled = $LinkSplit[1]
$LinksEnabledCount = $LinksEnabled.Count
$LinksDisabledCount = $LinksDisabled.Count
$LinksTotalCount = ([Array] $XMLContent.GPO.LinksTo).Count
if ($LinksEnabledCount -eq 0) {
$Linked = $false
} else {
$Linked = $true
}
} else {
$Linked = $false
$LinksCount = 0
$LinksEnabledCount = 0
$LinksDisabledCount = 0
$LinksTotalCount = 0
}
if ($null -eq $XMLContent.GPO.Computer.ExtensionData -and $null -eq $XMLContent.GPO.User.ExtensionData) {
$Empty = $true
} else {
$Empty = $false
}
# Find proper values for enabled/disabled user/computer settings
if ($XMLContent.GPO.Computer.Enabled -eq 'False') {
@@ -98,8 +116,11 @@
'DisplayName' = $XMLContent.GPO.Name
'DomainName' = $XMLContent.GPO.Identifier.Domain.'#text'
'GUID' = $XMLContent.GPO.Identifier.Identifier.InnerText -replace '{' -replace '}'
'Empty' = $Empty
'Linked' = $Linked
'LinksCount' = $LinksCount
'LinksCount' = $LinksTotalCount
'LinksEnabledCount' = $LinksEnabledCount
'LinksDisabledCount' = $LinksDisabledCount
'Enabled' = $Enabled
'ComputerEnabled' = $ComputerEnabled
'UserEnabled' = $UserEnabled
@@ -111,14 +132,11 @@
'UserSettingsStatus' = if ($XMLContent.GPO.User.VersionDirectory -eq 0 -and $XMLContent.GPO.User.VersionSysvol -eq 0) { "NeverModified" } else { "Modified" }
'UserSettingsVersionIdentical' = if ($XMLContent.GPO.User.VersionDirectory -eq $XMLContent.GPO.User.VersionSysvol) { $true } else { $false }
'UserSettings' = $XMLContent.GPO.User.ExtensionData.Extension
ComputerPolicies = $XMLContent.GPO.Computer.ExtensionData.Name -join ", "
UserPolicies = $XMLContent.GPO.User.ExtensionData.Name -join ", "
'ComputerPolicies' = $XMLContent.GPO.Computer.ExtensionData.Name -join ", "
'UserPolicies' = $XMLContent.GPO.User.ExtensionData.Name -join ", "
'CreationTime' = [DateTime] $XMLContent.GPO.CreatedTime
'ModificationTime' = [DateTime] $XMLContent.GPO.ModifiedTime
'ReadTime' = [DateTime] $XMLContent.GPO.ReadTime
'WMIFilter' = $GPO.WmiFilter.name
'WMIFilterDescription' = $GPO.WmiFilter.Description
'GPODistinguishedName' = $GPO.Path
@@ -147,7 +165,14 @@
}
)
'Auditing' = if ($XMLContent.GPO.SecurityDescriptor.AuditingPresent.'#text' -eq 'true') { $true } else { $false }
'Links' = $XMLContent.GPO.LinksTo | ForEach-Object -Process {
'Links' = @(
$XMLContent.GPO.LinksTo | ForEach-Object -Process {
if ($_) {
$_.SOMPath
}
}
) -join $Splitter
'LinksObjects' = $XMLContent.GPO.LinksTo | ForEach-Object -Process {
if ($_) {
[PSCustomObject] @{
CanonicalName = $_.SOMPath
@@ -156,15 +181,6 @@
}
}
}
<#
SOMName SOMPath Enabled NoOverride
------- ------- ------- ----------
ad ad.evotec.xyz true false
#>
#| Select-Object -ExpandProperty SOMPath
}
}
#break
}
+86 -50
View File
@@ -9,57 +9,23 @@ function Get-XMLNestedRegistry {
if ($DataSet.Properties) {
$Registry = $DataSet
foreach ($Registry in $DataSet) {
if ($Limited) {
[PSCustomObject] @{
Collection = $Collection
Changed = [DateTime] $Registry.changed
GPOSettingOrder = $Registry.GPOSettingOrder
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
}
} else {
$CreateGPO = [ordered]@{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
Collection = $Collection
Changed = [DateTime] $Registry.changed
GPOSettingOrder = $Registry.GPOSettingOrder
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
}
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
$CreateGPO['Links'] = $GPO.Links
[PSCustomObject] $CreateGPO
}
}
}
foreach ($Name in @('Registry', 'Collection')) {
foreach ($Registry in $DataSet.$Name) {
if ($Registry.Properties) {
if ($Limited) {
[PSCustomObject] @{
Collection = $Collection
Changed = [DateTime] $Registry.changed
GPOSettingOrder = $Registry.GPOSettingOrder
Description = $Registry.descr
Changed = try { [DateTime] $Registry.changed } catch { $Registry.changed };
GPOSettingOrder = [int] $Registry.GPOSettingOrder
Action = $Script:Actions[$Registry.Properties.action]
DisplayDecimal = if ($Registry.Properties.displayDecimal -eq '1') { $true } else { $false };
Default = if ($Registry.Properties.default -eq '1') { $true } else { $false };
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
BypassErrors = if ($Registry.bypassErrors -eq '1') { $true } else { $false };
}
} else {
$CreateGPO = [ordered]@{
@@ -70,14 +36,70 @@ function Get-XMLNestedRegistry {
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
Collection = $Collection
Changed = [DateTime] $Registry.changed
GPOSettingOrder = $Registry.GPOSettingOrder
Description = $Registry.descr
Changed = try { [DateTime] $Registry.changed } catch { $Registry.changed };
GPOSettingOrder = [int] $Registry.GPOSettingOrder
Action = $Script:Actions[$Registry.Properties.action]
DisplayDecimal = if ($Registry.Properties.displayDecimal -eq '1') { $true } else { $false };
Default = if ($Registry.Properties.default -eq '1') { $true } else { $false };
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
BypassErrors = if ($Registry.bypassErrors -eq '1') { $true } else { $false };
}
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
$CreateGPO['Links'] = $GPO.Links
[PSCustomObject] $CreateGPO
}
}
}
}
foreach ($Name in @('Registry', 'Collection')) {
foreach ($Registry in $DataSet.$Name) {
if ($Registry.Properties) {
if ($Limited) {
[PSCustomObject] @{
Collection = $Collection
Description = $Registry.descr
Changed = try { [DateTime] $Registry.changed } catch { $Registry.changed };
GPOSettingOrder = [int] $Registry.GPOSettingOrder
Action = $Script:Actions[$Registry.Properties.action]
DisplayDecimal = if ($Registry.Properties.displayDecimal -eq '1') { $true } else { $false };
Default = if ($Registry.Properties.default -eq '1') { $true } else { $false };
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
BypassErrors = if ($Registry.bypassErrors -eq '1') { $true } else { $false };
}
} else {
$CreateGPO = [ordered]@{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.GUID
GpoType = $GPO.GpoType
#GpoCategory = $GPOEntry.GpoCategory
#GpoSettings = $GPOEntry.GpoSettings
Collection = $Collection
Description = $Registry.descr
Changed = try { [DateTime] $Registry.changed } catch { $Registry.changed };
GPOSettingOrder = [int] $Registry.GPOSettingOrder
Action = $Script:Actions[$Registry.Properties.action]
DisplayDecimal = if ($Registry.Properties.displayDecimal -eq '1') { $true } else { $false }; ;
Default = if ($Registry.Properties.default -eq '1') { $true } else { $false };
Hive = $Registry.Properties.hive #: HKEY_LOCAL_MACHINE
Key = $Registry.Properties.key #: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Name = $Registry.Properties.name #: AutoAdminLogon
Type = $Registry.Properties.type #: REG_SZ
Value = $Registry.Properties.value #
Filters = $Registry.Filters
BypassErrors = if ($Registry.bypassErrors -eq '1') { $true } else { $false };
}
$CreateGPO['Linked'] = $GPO.Linked
$CreateGPO['LinksCount'] = $GPO.LinksCount
@@ -86,10 +108,12 @@ function Get-XMLNestedRegistry {
}
} else {
if ($Registry.Registry) {
#$Collection = $Registry.name
#if ($Registry.Name.Count -gt 1) {
#Write-Verbose "Registry Name count more than 1"
#}
$TempCollection = $Collection
if ($Collection) {
$Collection = "$Collection\$($Registry.name)"
$Collection = "$Collection/$($Registry.name)"
} else {
$Collection = $Registry.name
}
@@ -97,12 +121,24 @@ function Get-XMLNestedRegistry {
$Collection = $TempCollection
}
if ($Registry.Collection) {
if ($Collection) {
$Collection = "$Collection\$($Registry.Collection.name)"
} else {
$Collection = "$($Registry.name)\$($Registry.Collection.name)"
$TempCollection = $Collection
#if ($Registry.Collection.Count -gt 1) {
# Write-Verbose "Registry collection count more than 1"
#}
foreach ($MyCollection in $Registry.Collection) {
if ($Collection) {
#Write-Verbose "Collection1: $Collection - $($Registry.name) - $($MyCollection.name) - $($($MyCollection.name).Count)"
$Collection = "$Collection/$($Registry.name)/$($MyCollection.name)"
#Write-Verbose "Collection2: $Collection"
} else {
#Write-Verbose "Collection3: $Collection - $($Registry.name) - $($MyCollection.name)"
$Collection = "$($Registry.name)/$($MyCollection.name)"
#Write-Verbose "Collection4: $Collection"
}
Get-XMLNestedRegistry -GPO $GPO -DataSet $MyCollection -Collection $Collection
$Collection = $TempCollection
}
Get-XMLNestedRegistry -GPO $GPO -DataSet $Registry.Collection -Collection $Collection
}
}
}
-72
View File
@@ -1,72 +0,0 @@
function Get-XMLOutput {
[cmdletBinding()]
param(
[PSCustomObject] $GPO,
[System.Xml.XmlElement[]] $GPOOutput,
[string] $Splitter,
[switch] $FullObjects
)
$LinksInformation = Get-LinksFromXML -GPOOutput $GPOOutput -Splitter $Splitter -FullObjects:$FullObjects
foreach ($GpoType in @('User', 'Computer')) {
if ($GPOOutput.$GpoType.ExtensionData.Extension) {
foreach ($ExtensionType in $GPOOutput.$GpoType.ExtensionData.Extension) {
# It's possible that one of the ExtensionType records has value null. Weird but happend.
if ($ExtensionType) {
$GPOSettingTypeSplit = ($ExtensionType.type -split ':')
try {
$KeysToLoop = $ExtensionType | Get-Member -MemberType Properties -ErrorAction Stop | Where-Object { $_.Name -notin 'type', $GPOSettingTypeSplit[0] -and $_.Name -notin @('Blocked') }
} catch {
Write-Warning "Get-XMLStandard - things went sideways $($_.Exception.Message)"
continue
}
foreach ($GpoSettings in $KeysToLoop.Name) {
$Template = [ordered] @{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.Guid
GpoType = $GpoType
GpoCategory = $GPOSettingTypeSplit[1]
GpoSettings = $GpoSettings
}
[PSCustomObject] $Template
}
continue
foreach ($GpoSettings in $KeysToLoop.Name) {
foreach ($Key in $ExtensionType.$GpoSettings) {
$Template = [ordered] @{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.Guid
GpoType = $GpoType
GpoCategory = $GPOSettingTypeSplit[1]
GpoSettings = $GpoSettings
}
try {
$Properties = ($Key | Get-Member -MemberType Properties -ErrorAction Stop).Name
} catch {
Write-Warning "Get-XMLStandard - things went sideways 1 $($_.Exception.Message)"
$Properties = $null
}
foreach ($Property in $Properties) {
$Template["$Property"] = $Key.$Property
}
$Template['Linked'] = $LinksInformation.Linked
$Template['LinksCount'] = $LinksInformation.LinksCount
$Template['Links'] = $LinksInformation.Links
<#
$Template['IncludeComments'] = $GPOOutput.IncludeComments # : true #: true
$Template['CreatedTime'] = $GPOOutput.CreatedTime # : 2020-06-17T11:23:22 #: 2020-06-17T11:23:22
$Template['ModifiedTime'] = $GPOOutput.ModifiedTime # : 2020-06-28T15:49:52 #: 2020-06-28T15:49:52
$Template['ReadTime'] = $GPOOutput.ReadTime # : 2020-06-28T16:14:09.2209011Z #: 2020-06-28T16:14:09.2209011Z
$Template['SecurityDescriptor'] = $GPOOutput.SecurityDescriptor # : SecurityDescriptor #: SecurityDescriptor
$Template['FilterDataAvailable'] = $GPOOutput.FilterDataAvailable # : true #: true
#>
[PSCustomObject] $Template
}
}
}
}
}
}
}
-59
View File
@@ -1,59 +0,0 @@
function Get-XMLStandard {
[cmdletBinding()]
param(
[PSCustomObject] $GPO,
[System.Xml.XmlElement[]] $GPOOutput,
[string] $Splitter,
[switch] $FullObjects
)
$LinksInformation = Get-LinksFromXML -GPOOutput $GPOOutput -Splitter $Splitter -FullObjects:$FullObjects
foreach ($GpoType in @('User', 'Computer')) {
if ($GPOOutput.$GpoType.ExtensionData.Extension) {
foreach ($ExtensionType in $GPOOutput.$GpoType.ExtensionData.Extension) {
# It's possible that one of the ExtensionType records has value null. Weird but happend.
if ($ExtensionType) {
$GPOSettingTypeSplit = ($ExtensionType.type -split ':')
try {
$KeysToLoop = $ExtensionType | Get-Member -MemberType Properties -ErrorAction Stop | Where-Object { $_.Name -notin 'type', $GPOSettingTypeSplit[0] -and $_.Name -notin @('Blocked') }
} catch {
Write-Warning "Get-XMLStandard - things went sideways $($_.Exception.Message)"
continue
}
foreach ($GpoSettings in $KeysToLoop.Name) {
foreach ($Key in $ExtensionType.$GpoSettings) {
$Template = [ordered] @{
DisplayName = $GPO.DisplayName
DomainName = $GPO.DomainName
GUID = $GPO.Guid
GpoType = $GpoType
GpoCategory = $GPOSettingTypeSplit[1]
GpoSettings = $GpoSettings
}
try {
$Properties = ($Key | Get-Member -MemberType Properties -ErrorAction Stop).Name
} catch {
Write-Warning "Get-XMLStandard - things went sideways 1 $($_.Exception.Message)"
$Properties = $null
}
foreach ($Property in $Properties) {
$Template["$Property"] = $Key.$Property
}
$Template['Linked'] = $LinksInformation.Linked
$Template['LinksCount'] = $LinksInformation.LinksCount
$Template['Links'] = $LinksInformation.Links
<#
$Template['IncludeComments'] = $GPOOutput.IncludeComments # : true #: true
$Template['CreatedTime'] = $GPOOutput.CreatedTime # : 2020-06-17T11:23:22 #: 2020-06-17T11:23:22
$Template['ModifiedTime'] = $GPOOutput.ModifiedTime # : 2020-06-28T15:49:52 #: 2020-06-28T15:49:52
$Template['ReadTime'] = $GPOOutput.ReadTime # : 2020-06-28T16:14:09.2209011Z #: 2020-06-28T16:14:09.2209011Z
$Template['SecurityDescriptor'] = $GPOOutput.SecurityDescriptor # : SecurityDescriptor #: SecurityDescriptor
$Template['FilterDataAvailable'] = $GPOOutput.FilterDataAvailable # : true #: true
#>
[PSCustomObject] $Template
}
}
}
}
}
}
}
-15
View File
@@ -1,15 +0,0 @@
function Invoke-GPOTranslation {
[cmdletBinding()]
param(
[System.Collections.IDictionary] $InputData,
[string] $Report,
[string] $Category,
[string] $Settings
)
if ($Category -and $Settings -and $InputData) {
if ($Script:GPODitionary[$Report]['Code']) {
$Script:GPOList = $InputData.$Category.$Settings
return & $Script:GPODitionary[$Report]['Code']
}
}
}
-56
View File
@@ -1,56 +0,0 @@
function New-ADForestDrives {
[cmdletbinding()]
param(
[string] $ForestName,
[string] $ObjectDN
)
if (-not $Global:ADDrivesMapped) {
if ($ForestName) {
$Forest = Get-ADForest -Identity $ForestName
} else {
$Forest = Get-ADForest
}
if ($ObjectDN) {
# This doesn't work because no Domain and no $Server
$DNConverted = (ConvertFrom-Distinguishedname -DistinguishedName $ObjectDN -ToDC) -replace '=' -replace ','
if (-not(Get-PSDrive -Name $DNConverted -ErrorAction SilentlyContinue)) {
try {
if ($Server) {
$null = New-PSDrive -Name $DNConverted -Root '' -PsProvider ActiveDirectory -Server $Server.Hostname[0] -Scope Global -WhatIf:$false
Write-Verbose "New-ADForestDrives - Mapped drive $Domain / $($Server.Hostname[0])"
} else {
$null = New-PSDrive -Name $DNConverted -Root '' -PsProvider ActiveDirectory -Server $Domain -Scope Global -WhatIf:$false
}
} catch {
Write-Warning "New-ADForestDrives - Couldn't map new AD psdrive for $Domain / $($Server.Hostname[0])"
}
}
} else {
foreach ($Domain in $Forest.Domains) {
try {
$Server = Get-ADDomainController -Discover -DomainName $Domain
$DomainInformation = Get-ADDomain -Server $Server.Hostname[0]
} catch {
Write-Warning "New-ADForestDrives - Can't process domain $Domain - $($_.Exception.Message)"
continue
}
$ObjectDN = $DomainInformation.DistinguishedName
$DNConverted = (ConvertFrom-Distinguishedname -DistinguishedName $ObjectDN -ToDC) -replace '=' -replace ','
if (-not(Get-PSDrive -Name $DNConverted -ErrorAction SilentlyContinue)) {
try {
if ($Server) {
$null = New-PSDrive -Name $DNConverted -Root '' -PsProvider ActiveDirectory -Server $Server.Hostname[0] -Scope Global -WhatIf:$false
Write-Verbose "New-ADForestDrives - Mapped drive $Domain / $Server"
} else {
$null = New-PSDrive -Name $DNConverted -Root '' -PsProvider ActiveDirectory -Server $Domain -Scope Global -WhatIf:$false
}
} catch {
Write-Warning "New-ADForestDrives - Couldn't map new AD psdrive for $Domain / $Server $($_.Exception.Message)"
}
}
}
}
$Global:ADDrivesMapped = $true
}
}
+234 -16
View File
@@ -1,5 +1,5 @@
$Script:GPODitionary = [ordered] @{
AccountPolicies = [ordered] @{
AccountPolicies = [ordered] @{
Types = @(
@{
Category = 'SecuritySettings'
@@ -14,12 +14,16 @@
ConvertTo-XMLAccountPolicy -GPO $GPO
}
}
Audit = [ordered] @{
Audit = [ordered] @{
Types = @(
@{
Category = 'SecuritySettings'
Settings = 'Audit'
}
@{
Category = 'AuditSettings'
Settings = 'AuditSetting'
}
)
GPOPath = ''
Code = {
@@ -29,21 +33,93 @@
ConvertTo-XMLAudit -GPO $GPO
}
}
Autologon = [ordered] @{
Autologon = [ordered] @{
# We want to process this based on other report called RegistrySettings
# This is because registry settings can be stored in Collections or nested within other registry settings
# The original function ConvertTo-XMLRegistryAutologon was processing it in limited ordered and potentially would skip some entries.
<#
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'RegistrySettings'
}
)
#>
ByReports = @(
@{
Report = 'RegistrySettings'
}
)
<#
Code = {
ConvertTo-XMLRegistryAutologon -GPO $GPO
}
CodeSingle = {
ConvertTo-XMLRegistryAutologon -GPO $GPO
}
#>
CodeReport = {
ConvertTo-XMLRegistryAutologonOnReport -GPO $GPO
}
}
DriveMapping = [ordered] @{
Biometrics = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
#ConvertTo-XMLBitlocker -GPO $GPO
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/Biometrics*'
}
}
Bitlocker = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
#ConvertTo-XMLBitlocker -GPO $GPO
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/BitLocker Drive Encryption*'
}
}
CredentialsDelegation = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'System/Credentials Delegation*'
}
}
Desktop = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Desktop*'
}
}
DnsClient = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Network/DNS Client*'
}
}
DriveMapping = [ordered] @{
Types = @(
@{
Category = 'DriveMapSettings'
@@ -58,7 +134,7 @@
ConvertTo-XMLDriveMapSettings -GPO $GPO -SingleObject
}
}
EventLog = [ordered] @{
EventLog = [ordered] @{
Types = @(
@{
Category = 'SecuritySettings'
@@ -73,7 +149,64 @@
ConvertTo-XMLEventLog -GPO $GPO
}
}
LocalUsers = [ordered] @{
FileExplorer = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/File Explorer*'
}
}
GroupPolicy = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'System/Group Policy*'
}
}
InternetExplorer = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/Internet Explorer*'
}
}
LAPS = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
#ConvertTo-XMLLaps -GPO $GPO
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'LAPS'
}
}
Lithnet = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
#ConvertTo-XMLLithnetFilter -GPO $GPO
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Lithnet/Password Protection for Active Directory*'
}
}
LocalUsers = [ordered] @{
Types = @(
@{
Category = 'LugsSettings'
@@ -87,7 +220,7 @@
ConvertTo-XMLLocalUser -GPO $GPO -SingleObject
}
}
LocalGroups = [ordered] @{
LocalGroups = [ordered] @{
Types = @(
@{
Category = 'LugsSettings'
@@ -101,7 +234,37 @@
ConvertTo-XMLLocalGroups -GPO $GPO -SingleObject
}
}
Policies = @{
Logon = @{
Types = @(
@{ Category = 'RegistrySettings'; Settings = 'Policy' }
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'System/Logon*'
}
}
MicrosoftOutlook2010 = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Microsoft Outlook 2010*'
}
}
MicrosoftOutlook2016 = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Microsoft Outlook 2016*'
}
}
Policies = @{
Types = @(
@{
Category = 'RegistrySettings'
@@ -115,7 +278,7 @@
ConvertTo-XMLPolicies -GPO $GPO -SingleObject
}
}
Printers = @{
Printers = @{
Types = @(
@{
Category = 'PrintersSettings'
@@ -133,7 +296,18 @@
ConvertTo-XMLPrinter -GPO $GPO -SingleObject
}
}
RegistrySettings = [ordered] @{
PrintersPolicies = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Printers*', 'Control Panel/Printers*'
}
}
RegistrySettings = [ordered] @{
Types = @(
@{
Category = 'RegistrySettings'
@@ -147,7 +321,18 @@
ConvertTo-XMLRegistrySettings -GPO $GPO -SingleObject
}
}
Scripts = [ordered] @{
RemoteDesktopServices = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/Remote Desktop Services*'
}
}
Scripts = [ordered] @{
Types = @(
@{
Category = 'Scripts'
@@ -161,7 +346,7 @@
ConvertTo-XMLScripts -GPO $GPO -SingleObject
}
}
SecurityOptions = [ordered] @{
SecurityOptions = [ordered] @{
Types = @(
@{
Category = 'SecuritySettings'
@@ -175,7 +360,7 @@
ConvertTo-XMLSecurityOptions -GPO $GPO -SingleObject
}
}
SoftwareInstallation = [ordered] @{
SoftwareInstallation = [ordered] @{
Types = @(
@{
Category = 'SoftwareInstallationSettings'
@@ -189,7 +374,7 @@
ConvertTo-XMLSoftwareInstallation -GPO $GPO -SingleObject
}
}
SystemServices = [ordered] @{
SystemServices = [ordered] @{
Types = @(
@{
Category = 'SecuritySettings'
@@ -205,7 +390,7 @@
ConvertTo-XMLSystemServices -GPO $GPO -SingleObject
}
}
SystemServicesNT = [ordered] @{
SystemServicesNT = [ordered] @{
Types = @(
@{
Category = 'ServiceSettings'
@@ -221,7 +406,7 @@
ConvertTo-XMLSystemServicesNT -GPO $GPO -SingleObject
}
}
TaskScheduler = [ordered] @{
TaskScheduler = [ordered] @{
Types = @(
@{
Category = 'ScheduledTasksSettings'
@@ -237,4 +422,37 @@
ConvertTo-XMLTaskScheduler -GPO $GPO -SingleObject
}
}
WindowsHelloForBusiness = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/Windows Hello For Business*'
}
}
WindowsRemoteManagement = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/Windows Remote Management (WinRM)*'
}
}
WindowsUpdate = @{
Types = @(
@{
Category = 'RegistrySettings'
Settings = 'Policy'
}
)
Code = {
ConvertTo-XMLGenericPolicy -GPO $GPO -Category 'Windows Components/Windows Update*', 'Windows Components/Delivery Optimization*'
}
}
}
-52
View File
@@ -1,52 +0,0 @@
$Script:GPOPropetiesComputers = [ordered] @{
'Account' = ''
'Audit' = ''
'AuditSetting' = ''
'AutoEnrollmentSettings' = ''
'Blocked' = ''
'certSettingsTrustedPublishers' = ''
'DataSourcesSettings' = ''
'DomainProfile' = ''
'Dot3SvcSetting' = ''
'EFSRecoveryAgent' = ''
'EFSSettings' = ''
'EnvironmentVariables' = ''
'EventLog' = ''
'File' = ''
'FilesSettings' = ''
'Folders' = ''
'General' = ''
'Global' = ''
'GlobalSettings' = ''
'InboundFirewallRules' = ''
'IntermediateCACertificate' = ''
'InternetZoneRule' = ''
'LocalUsersAndGroups' = ''
'MsiApplication' = ''
'NetworkOptions' = ''
'NetworkShares' = ''
'NTServices' = ''
'OutboundFirewallRules' = ''
'PathRule' = ''
'Policy' = ''
'PowerOptions' = ''
'PrinterConnection' = ''
'Printers' = ''
'PrivateProfile' = ''
'PublicProfile' = ''
'Registry' = ''
'RegistrySetting' = ''
'RegistrySettings' = ''
'RestrictedGroups' = ''
'RootCertificate' = ''
'RootCertificateSettings' = ''
'ScheduledTasks' = ''
'Script' = ''
'SecurityOptions' = ''
'ShortcutSettings' = ''
'SystemServices' = ''
'TrustedPublishersCertificate' = ''
'type' = ''
'UserRightsAssignment' = ''
'WLanSvcSetting' = ''
}
-54
View File
@@ -1,54 +0,0 @@
$Script:GPOPropertiesUsers = [ordered] @{
'AutoDetectConfigSettings' = ''
'AutoEnrollmentSettings' = ''
'AutomaticConfiguration' = ''
'AutoSetupSetting' = ''
'Blocked' = ''
'BrowserTitle' = ''
'CustomSetupSetting' = ''
'DataSourcesSettings' = ''
'DefinesConnectionSettings' = ''
'DefinesEscOffSettings' = ''
'DefinesEscOnSettings' = ''
'DeleteChannels' = ''
'DriveMapSettings' = ''
'EscOffLocalSites' = ''
'EscOffSecurityZoneAndPrivacy' = ''
'EscOffTrustedSites' = ''
'EscOnLocalSites' = ''
'EscOnSecurityZoneAndPrivacy' = ''
'EscOnTrustedSites' = ''
'FavoriteURL' = ''
'FilesSettings' = ''
'Folder' = ''
'FolderOptions' = ''
'Folders' = ''
'General' = ''
'HomePage' = ''
'ImportedContentRatings' = ''
'InternetOptions' = ''
'LocalUsersAndGroups' = ''
'MsiApplication' = ''
'NetworkOptions' = ''
'PathRule' = ''
'PlaceFavoritesAtTop' = ''
'Policy' = ''
'PowerOptions' = ''
'PreferenceMode' = ''
'PrinterConnection' = ''
'Printers' = ''
'Programs' = ''
'ProxySettings' = ''
'RegionalOptionsSettings' = ''
'RegistrySetting' = ''
'RegistrySettings' = ''
'RestartSetupSetting' = ''
'ScheduledTasks' = ''
'Script' = ''
'SearchBar' = ''
'ShortcutSettings' = ''
'StartMenuSettings' = ''
'ToolsSetting' = ''
'TrustedPublisherLockdown' = ''
'type' = ''
}
+37
View File
@@ -0,0 +1,37 @@
function Clear-GPOZaurrSysvolDFSR {
[cmdletBinding(SupportsShouldProcess)]
param(
[alias('ForestName')][string] $Forest,
[string[]] $ExcludeDomains,
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
[System.Collections.IDictionary] $ExtendedForestInformation
)
# Based on https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/manually-clearing-the-conflictanddeleted-folder-in-dfsr/ba-p/395711
$StatusCodes = @{
'0' = 'Success' # MONITOR_STATUS_SUCCESS
'1' = 'Generic database error' #MONITOR_STATUS_GENERIC_DB_ERROR
'2' = 'ID record not found' # MONITOR_STATUS_IDRECORD_NOT_FOUND
'3' = 'Volume not found' # MONITOR_STATUS_VOLUME_NOT_FOUND
'4' = 'Access denied' #MONITOR_STATUS_ACCESS_DENIED
'5' = 'Generic error' #MONITOR_STATUS_GENERIC_ERROR
}
#WMIC.EXE /namespace:\\root\microsoftdfs path dfsrreplicatedfolderconfig get replicatedfolderguid, replicatedfoldername
#WMIC.EXE /namespace:\\root\microsoftdfs path dfsrreplicatedfolderinfo where "replicatedfolderguid='<RF GUID>'" call cleanupconflictdirectory
#WMIC.EXE /namespace:\\root\microsoftdfs path dfsrreplicatedfolderinfo where "replicatedfolderguid='70bebd41-d5ae-4524-b7df-4eadb89e511e'" call cleanupconflictdirectory
# https://docs.microsoft.com/en-us/previous-versions/windows/desktop/dfsr/dfsrreplicatedfolderinfo
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
foreach ($Domain in $ForestInformation.Domains) {
Write-Verbose "Clear-GPOZaurrSysvolDFSR - Processing $Domain"
$QueryServer = $ForestInformation['QueryServers']["$Domain"].HostName[0]
$DFSR = Get-GPOZaurrSysvolDFSR -IncludeDomains $Domain -ExtendedForestInformation $ForestInformation
$Executed = Invoke-CimMethod -InputObject $DFSR.DFSR -MethodName 'cleanupconflictdirectory' -CimSession $QueryServer
if ($Executed) {
[PSCustomObject] @{
Status = $StatusCodes["$($Executed.ReturnValue)"]
ComputerName = $Executed.PSComputerName
}
}
}
}
+34
View File
@@ -0,0 +1,34 @@
function Get-GPOZaurrSysvolDFSR {
[cmdletBinding()]
param(
[alias('ForestName')][string] $Forest,
[string[]] $ExcludeDomains,
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
[System.Collections.IDictionary] $ExtendedForestInformation,
[string] $SearchDFSR = 'SYSVOL Share'
)
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
foreach ($Domain in $ForestInformation.Domains) {
Write-Verbose "Get-GPOZaurrSysvolDFSR - Processing $Domain"
$QueryServer = $ForestInformation['QueryServers']["$Domain"].HostName[0]
$DFSRConfig = Get-CimInstance -Namespace 'root\microsoftdfs' -Class 'dfsrreplicatedfolderconfig' -ComputerName $QueryServer | Where-Object { $_.ReplicatedFolderName -eq $SearchDFSR }
$DFSR = Get-CimInstance -Namespace 'root\microsoftdfs' -Class 'dfsrreplicatedfolderinfo' -ComputerName $QueryServer | Where-Object { $_.ReplicatedFolderName -eq $SearchDFSR }
if ($DFSR -and $DFSRConfig -and ($DFSR.ReplicatedFolderGuid -eq $DFSRConfig.ReplicatedFolderGuid)) {
[PSCustomObject] @{
ComputerName = $DFSR.PSComputerName
DomainName = $Domain
ConflictPath = $DFSRConfig.ConflictPath
LastConflictCleanupTime = $DFSR.LastConflictCleanupTime
CurrentConflictSizeInMb = $DFSR.CurrentConflictSizeInMb
MaximumConflictSizeInMb = $DFSRConfig.ConflictSizeInMb
LastErrorCode = $DFSR.LastErrorCode
LastErrorMessageId = $DFSR.LastErrorMessageId
LastTombstoneCleanupTime = $DFSR.LastTombstoneCleanupTime
ReplicatedFolderGuid = $DFSR.ReplicatedFolderGuid
DFSRConfig = $DFSRConfig
DFSR = $DFSR
}
}
}
}
+4 -11
View File
@@ -1,11 +1,4 @@
function Get-WMIFilter {
param(
)
}
function Get-GPOZaurrWMI {
function Get-GPOZaurrWMI {
[cmdletBinding()]
Param(
[Guid[]] $Guid,
@@ -15,7 +8,7 @@ function Get-GPOZaurrWMI {
[alias('Domain', 'Domains')][string[]] $IncludeDomains,
[System.Collections.IDictionary] $ExtendedForestInformation
)
$wmiFilterAttr = "msWMI-Name", "msWMI-Parm1", "msWMI-Parm2", "msWMI-Author", "msWMI-ID", 'CanonicalName', 'Created', 'Modified'
$wmiFilterAttr = 'msWMI-Name', 'msWMI-Parm1', 'msWMI-Parm2', 'msWMI-Author', 'msWMI-ID', 'CanonicalName', 'Created', 'Modified'
$ForestInformation = Get-WinADForestDetails -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
foreach ($Domain in $ForestInformation.Domains) {
@@ -41,7 +34,7 @@ function Get-GPOZaurrWMI {
}
} else {
try {
$ldapFilter = "(objectClass=msWMI-Som)"
$ldapFilter = '(objectClass=msWMI-Som)'
Get-ADObject -LDAPFilter $ldapFilter -Properties $wmiFilterAttr -Server $QueryServer
} catch {
Write-Warning "Get-GPOZaurrWMI - Error processing WMI for $Domain`: $($_.Error.Exception)"
@@ -66,7 +59,7 @@ function Get-GPOZaurrWMI {
#NameSpace = $WMI[$i + 5]
#Query = $WMI[$i + 6]
QueryCount = $Data.Count
Query = $Data -join ","
Query = $Data -join ','
Author = $_.'msWMI-Author'
ID = $_.'msWMI-ID'
Created = $_.Created
+102 -134
View File
@@ -12,9 +12,6 @@
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[string[]] $Type,
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[switch] $NoTranslation,
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
@@ -24,10 +21,12 @@
[Parameter(ParameterSetName = 'Local')]
[switch] $FullObjects,
<#
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[ValidateSet('HTML', 'Object', 'Excel')][string[]] $OutputType = 'Object',
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[string] $OutputPath,
@@ -35,6 +34,7 @@
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[switch] $Open,
#>
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
@@ -42,21 +42,21 @@
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[switch] $SingleObject
[switch] $SingleObject,
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[switch] $SkipNormalize,
[Parameter(ParameterSetName = 'Default')]
[Parameter(ParameterSetName = 'Local')]
[switch] $SkipCleanup
)
if ($Type.Count -eq 0) {
$Type = $Script:GPODitionary.Keys
}
if ($GPOPath) {
if (Test-Path -LiteralPath $GPOPath) {
<#
$GPOListPath = [io.path]::Combine($GPOPath, "GPOList.xml")
if ($GPOListPath) {
$GPOs = Import-Clixml -Path $GPOListPath
} else {
}
#>
$GPOFiles = Get-ChildItem -LiteralPath $GPOPath -Recurse -File -Filter *.xml
[Array] $GPOs = foreach ($File in $GPOFiles) {
if ($File.Name -ne 'GPOList.xml') {
@@ -75,16 +75,19 @@
}
}
} else {
Write-Warning "Find-GPO - $GPOPath doesn't exists."
Write-Warning "Invoke-GPOZaurr - $GPOPath doesn't exists."
return
}
} else {
[Array] $GPOs = Get-GPOZaurrAD -Forest $Forest -IncludeDomains $IncludeDomains -ExcludeDomains $ExcludeDomains -ExtendedForestInformation $ExtendedForestInformation
}
# This caches single reports.
$TemporaryCachedSingleReports = [ordered] @{}
$TemporaryCachedSingleReports['ReportsSingle'] = [ordered] @{}
# This will be returned
$Output = [ordered] @{}
$OutputByGPO = [ordered] @{}
$TranslatedOutput = [ordered] @{}
$CachedCategories = [ordered] @{}
$Output['Reports'] = [ordered] @{}
$Output['CategoriesFull'] = [ordered] @{}
[Array] $GPOCategories = foreach ($GPO in $GPOs) {
if ($GPOPath) {
@@ -92,157 +95,122 @@
} else {
[xml] $GPOOutput = Get-GPOReport -Guid $GPO.GUID -Domain $GPO.DomainName -ReportType Xml
}
Get-GPOCategories -GPO $GPO -GPOOutput $GPOOutput.GPO -Splitter $Splitter -FullObjects:$FullObjects -CachedCategories $CachedCategories
Get-GPOCategories -GPO $GPO -GPOOutput $GPOOutput.GPO -Splitter $Splitter -FullObjects:$FullObjects -CachedCategories $Output['CategoriesFull']
}
# Return Categories or save it
$Output['Categories'] = $GPOCategories | Select-Object -Property * -ExcludeProperty DataSet
if ($CategoriesOnly) {
return $GPOCategories | Select-Object -Property * -ExcludeProperty DataSet
} else {
$Output['Categories'] = $GPOCategories | Select-Object -Property * -ExcludeProperty DataSet
# Return Categories only
return $Output['Categories']
}
# Save Cached Categories
$Output['CategoriesFull'] = $CachedCategories
# Process Reporting
$Output['Reports'] = [ordered] @{}
if ($CachedCategories.Count -gt 0) {
# We check our dictionary for reports that are based on reports to make sure we run CodeSingle separatly
[Array] $FindRequiredSingle = foreach ($Key in $Script:GPODitionary.Keys) {
$Script:GPODitionary[$Key].ByReports.Report
}
# Build reports based on categories
if ($Output['CategoriesFull'].Count -gt 0) {
foreach ($Report in $Type) {
foreach ($CategoryType in $Script:GPODitionary[$Report].Types) {
$Category = $CategoryType.Category
$Settings = $CategoryType.Settings
# Those are checks for making sure we have data to be even able to process it
if (-not $CachedCategories[$Category]) {
if (-not $Output['CategoriesFull'][$Category]) {
continue
}
if (-not $CachedCategories[$Category][$Settings]) {
if (-not $Output['CategoriesFull'][$Category][$Settings]) {
continue
}
# Translation
$CategorizedGPO = $CachedCategories[$Category][$Settings]
$CategorizedGPO = $Output['CategoriesFull'][$Category][$Settings]
foreach ($GPO in $CategorizedGPO) {
if (-not $Output['Reports'][$Report]) {
$Output['Reports'][$Report] = [System.Collections.Generic.List[PSCustomObject]]::new()
}
# Create temporary storage for "single gpo" reports
# it's required if we want to base reports on other reports later on
if (-not $TemporaryCachedSingleReports['ReportsSingle'][$Report]) {
$TemporaryCachedSingleReports['ReportsSingle'][$Report] = [System.Collections.Generic.List[PSCustomObject]]::new()
}
# Make sure translated gpo is null
$TranslatedGpo = $null
if ($SingleObject) {
if ($SingleObject -or ($Report -in $FindRequiredSingle)) {
# We either create 1 GPO with multiple settings to return it as user requested it
# Or we process it only because we need to base it for reports based on other reports
if (-not $Script:GPODitionary[$Report]['CodeSingle']) {
# sometimes code and code single are identical. To not define things two times, one can just skip it
If ($Script:GPODitionary[$Report]['Code']) {
$Script:GPODitionary[$Report]['CodeSingle'] = $Script:GPODitionary[$Report]['Code']
}
}
if ($Script:GPODitionary[$Report]['CodeSingle']) {
$TranslatedGpo = Invoke-Command -ScriptBlock $Script:GPODitionary[$Report]['CodeSingle']
}
} else {
if ($Script:GPODitionary[$Report]['Code']) {
$TranslatedGpo = Invoke-Command -ScriptBlock $Script:GPODitionary[$Report]['Code']
}
}
foreach ($T in $TranslatedGpo) {
$Output['Reports'][$Report].Add($T)
}
}
}
}
}
return $Output
<#
foreach ($GPO in $GPOs) {
if ($GPOPath) {
$GPOOutput = $GPO.GPOOutput
} else {
[xml] $GPOOutput = Get-GPOReport -Guid $GPO.GUID -Domain $GPO.DomainName -ReportType Xml
}
[Array] $Data = Get-XMLStandard -GPO $GPO -GPOOutput $GPOOutput.GPO -Splitter $Splitter -FullObjects:$FullObjects
foreach ($D in $Data) {
if (-not $Output["$($D.GpoCategory)"]) {
$Output["$($D.GpoCategory)"] = [ordered] @{}
}
if (-not $Output["$($D.GpoCategory)"]["$($D.GpoSettings)"]) {
$Output["$($D.GpoCategory)"]["$($D.GpoSettings)"] = [System.Collections.Generic.List[PSCustomObject]]::new()
}
$Output["$($D.GpoCategory)"]["$($D.GpoSettings)"].Add($D)
if (-not $OutputByGPO["$($D.DomainName)"]) {
$OutputByGPO["$($D.DomainName)"] = [ordered] @{}
}
if (-not $OutputByGPO[$D.DomainName][$D.DisplayName]) {
$OutputByGPO[$D.DomainName][$D.DisplayName] = [System.Collections.Generic.List[PSCustomObject]]::new()
}
$OutputByGPO[$D.DomainName][$D.DisplayName].Add($D)
}
}
if ($NoTranslation) {
if ($OutputType -contains 'Object') {
$Output
}
} else {
foreach ($Report in $Type) {
$Category = $Script:GPODitionary[$Report]['Category']
$Settings = $Script:GPODitionary[$Report]['Settings']
$TranslatedOutput[$Report] = Invoke-GPOTranslation -InputData $Output -Category $Category -Settings $Settings -Report $Report
}
if ($OutputType -contains 'Object') {
$TranslatedOutput
}
}
if ($NoTranslation) {
$SingleSource = $Output
} else {
$SingleSource = $TranslatedOutput
}
if ($OutputPath) {
$FolderPath = $OutputPath
} else {
$FolderPath = [io.path]::GetTempPath()
}
if ($OutputType -contains 'HTML') {
$FilePathHTML = [io.path]::Combine($FolderPath, "GPOZaurr-Summary-$((Get-Date).ToString('yyyy-MM-dd_HH_mm_ss')).html")
Write-Warning "Invoke-GPOZaurr - $FilePathHTML"
New-HTML {
foreach ($GPOCategory in $SingleSource.Keys) {
New-HTMLTab -Name $GPOCategory {
if ($SingleSource["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $SingleSource["$GPOCategory"].Keys) {
New-HTMLTab -Name $GpoSettings {
if ($SingleSource[$GPOCategory][$GpoSettings].Count -gt 0) {
New-HTMLTable -DataTable $SingleSource[$GPOCategory][$GpoSettings] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
if ($Report -in $FindRequiredSingle) {
foreach ($T in $TranslatedGpo) {
$TemporaryCachedSingleReports['ReportsSingle'][$Report].Add($T)
}
}
if ($SingleObject) {
foreach ($T in $TranslatedGpo) {
$Output['Reports'][$Report].Add($T)
}
}
}
} else {
if ($SingleSource[$GPOCategory].Count -gt 0) {
New-HTMLTable -DataTable $SingleSource[$GPOCategory] -ScrollX -DisablePaging -AllProperties -Title $GpoSettings
}
if (-not $SingleObject) {
# We want each GPO to be listed multiple times if it makes sense for reporting
# think drive mapping - showing 1 mapping of a drive per object even if there are 50 drive mappings within 1 gpo
# this would result in 50 objects created
if ($Script:GPODitionary[$Report]['Code']) {
$TranslatedGpo = Invoke-Command -ScriptBlock $Script:GPODitionary[$Report]['Code']
foreach ($T in $TranslatedGpo) {
$Output['Reports'][$Report].Add($T)
}
}
}
}
}
} -Online -ShowHTML:$Open.IsPresent -FilePath $FilePathHTML
}
}
if ($OutputType -contains 'Excel') {
$FilePathExcel = [io.path]::Combine($FolderPath, "GPOZaurr-Summary-$((Get-Date).ToString('yyyy-MM-dd_HH_mm_ss')).xlsx")
Write-Warning "Invoke-GPOZaurr - $FilePathExcel"
foreach ($GPOCategory in $SingleSource.Keys) {
if ($SingleSource["$GPOCategory"] -is [System.Collections.IDictionary]) {
foreach ($GpoSettings in $SingleSource["$GPOCategory"].Keys) {
if ($SingleSource[$GPOCategory][$GpoSettings].Count -gt 0) {
ConvertTo-Excel -DataTable $SingleSource[$GPOCategory][$GpoSettings] -AllProperties -ExcelWorkSheetName $GpoSettings -FilePath $FilePathExcel -AutoFilter -AutoFit -Option Rename
}
}
} else {
if ($SingleSource[$GPOCategory].Count -gt 0) {
ConvertTo-Excel -DataTable $SingleSource[$GPOCategory] -AllProperties -ExcelWorkSheetName $GPOCategory -FilePath $FilePathExcel -AutoFilter -AutoFit -Option Rename
# Those reports are based on other reports (for example already processed registry settings)
# This is useful where going thru registry collections may not be efficient enough to try and read it directly again
foreach ($Report in $Type) {
foreach ($ReportType in $Script:GPODitionary[$Report].ByReports) {
if (-not $Output['Reports'][$Report]) {
$Output['Reports'][$Report] = [System.Collections.Generic.List[PSCustomObject]]::new()
}
$FindReport = $ReportType.Report
foreach ($GPO in $TemporaryCachedSingleReports['ReportsSingle'][$FindReport]) {
$TranslatedGpo = Invoke-Command -ScriptBlock $Script:GPODitionary[$Report]['CodeReport']
foreach ($T in $TranslatedGpo) {
$Output['Reports'][$Report].Add($T)
}
}
}
if ($Open) {
Invoke-Item -Path $FilePathExcel
}
# Normalize - meaning that before we return each GPO report we make sure that each entry has the same column names regardless which one is first.
# Normally if you would have a GPO with just 2 entries for given subject (say LAPS), and then another GPO having 5 settings for the same type
# and you would display them one after another - all entries would be shown using first object which has less properties then 2nd or 3rd object
# to make sure all objects are having same (even empty) properties we "normalize" it
if (-not $SkipNormalize) {
foreach ($Report in [string[]] $Output['Reports'].Keys) {
$Properties = $Output['Reports'][$Report] | Select-Properties -ExcludeProperty DisplayName, DomainName, GUID, GpoType, Linked, LinksCount, Links -AllProperties -WarningAction SilentlyContinue
$DisplayProperties = @(
'DisplayName', 'DomainName', 'GUID', 'GpoType'
foreach ($Property in $Properties) {
$Property
}
'Linked', 'LinksCount', 'Links'
)
$Output['Reports'][$Report] = $Output['Reports'][$Report] | Select-Object -Property $DisplayProperties
}
}
#>
$Output['PoliciesTotal'] = $Output.Reports.Policies.PolicyCategory | Group-Object | Select-Object Name, Count | Sort-Object -Property Name #-Descending
#$Output['PoliciesTotal'] = $Output.Reports.Policies.PolicyCategory | Group-Object | Select-Object Name, Count | Sort-Object -Property Count -Descending
if (-not $SkipCleanup) {
Remove-EmptyValue -Hashtable $Output -Recursive
}
return $Output
}
[scriptblock] $SourcesAutoCompleter = {
@@ -250,4 +218,4 @@
$Script:GPODitionary.Keys | Sort-Object | Where-Object { $_ -like "*$wordToComplete*" }
}
Register-ArgumentCompleter -CommandName Find-GPO -ParameterName Type -ScriptBlock $SourcesAutoCompleter
Register-ArgumentCompleter -CommandName Invoke-GPOZaurr -ParameterName Type -ScriptBlock $SourcesAutoCompleter
-22
View File
@@ -1,22 +0,0 @@
function Select-GPOTranslation {
[cmdletbInding()]
param(
[Parameter(ValueFromPipeline)][System.Collections.IDictionary] $InputObject,
[string] $Category,
[string] $Settings
)
$Important = [ordered] @{}
$AllProperties = Select-Properties -AllProperties -Objects $InputObject.$Category.$Settings
$MissingProperties = $AllProperties | Where-Object { $_ -notin 'DisplayName', 'DomainName', 'GUID', 'Linked', 'LinksCount', 'Links', 'GPOType', 'GPOCategory', 'GPOSettings' }
$Types = foreach ($Property in $MissingProperties) {
($InputObject.$Category.$Settings | Where-Object { $null -ne $_.$Property }).$Property | ForEach-Object {
($_ | Get-Member -MemberType Properties) | Where-Object { $_.Name -notin 'Length' }
}
}
$Important['AllProperties'] = $AllProperties
$Important['MissingProperties'] = $MissingProperties
$Important['Types'] = $Types | Select-Object -Unique
$Important['Data'] = $InputObject.$Category.$Settings
$Important
}
+6
View File
@@ -39,6 +39,12 @@ That's it. Whenever there's a new version, you run the command, and you can enjo
## Changelog
- 0.0.51 - 2.08.2020
- Updates to `Invoke-GPOZaurr` - still work in progress
- Added `Get-GPOZaurrSysvolDFSR`
- Added `Clear-GPOZaurrSysvolDFSR` (requires testing)
- 0.0.50 - 29.07.2020
- Updates to couple of commands
- 0.0.49 - 23.07.2020
- Hidden files were skipped - and people do crazy things with them
- 0.0.48 - 21.07.2020