Przemyslaw Klys b70cccf0db Update
2020-11-08 15:25:26 +01:00
2020-06-17 23:22:50 +02:00
2020-04-26 19:43:02 +02:00
2020-11-07 23:06:02 +01:00
2020-11-08 15:25:26 +01:00
2020-11-08 15:25:26 +01:00
2020-11-08 15:25:26 +01:00
2020-02-17 20:36:55 +01:00
2020-11-07 22:50:08 +01:00

GPOZaurr

To install

GPOZaurr requires RSAT installed to provide results. If you don't have them you can install them as below. Keep in mind it also installs GUI tools so it shouldn't be installed on user workstations.

# Windows 10 Latest
Add-WindowsCapability -Online -Name 'Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0'
Add-WindowsCapability -Online -Name 'Rsat.GroupPolicy.Management.Tools~~~~0.0.1.0'

Finally just install module:

Install-Module -Name GPOZaurr -AllowClobber -Force

Force and AllowClobber aren't necessary, but they do skip errors in case some appear.

And to update

Update-Module -Name GPOZaurr

That's it. Whenever there's a new version, you run the command, and you can enjoy it. Remember that you may need to close, reopen PowerShell session if you have already used module before updating it.

The essential thing is if something works for you on production, keep using it till you test the new version on a test computer. I do changes that may not be big, but big enough that auto-update may break your code. For example, small rename to a parameter and your code stops working! Be responsible!

Changelog

  • 0.0.73 - 7.11.2020
    • Improved Invoke-GPOZaurr (WIP)
    • Improved Get-GPOZaurr
  • 0.0.72 - 6.11.2020
    • Improved Invoke-GPOZaurr (WIP)
  • 0.0.71 - 3.11.2020
    • Improved Invoke-GPOZaurr (WIP)
  • 0.0.70 - 29.10.2020
    • Added Get-GPOZaurrDuplicateObject
    • Added Remove-GPOZaurrDuplicateObject
  • 0.0.69 - 29.10.2020
    • Improved Invoke-GPOZaurr (WIP)
    • Improved Get-GPOZaurrNetLogon
    • Improved Get-GPOZaurrOwner
    • Improved Set-GPOZaurrOwner
    • Added Repair-GPOZaurrNetLogonOwner
    • Improved Invoke-GPOZaurr (WIP)
  • 0.0.68 - 28.10.2020
    • Renamed Show-GPOZaurr to Invoke-GPOZaurr
    • Renamed Invoke-GPOZaurr to Invoke-GPOZaurrContent
    • Improvements to Get-GPOZaurrPermissionConsistency - don't check for inherited permissions if top level ones are inconsistent
    • Improved Invoke-GPOZaurr (WIP)
  • 0.0.67 - 22.10.2020
    • Improved Show-GPOZaurr (WIP)
  • 0.0.66 - 22.10.2020
    • Improved Show-GPOZaurr (WIP)
  • 0.0.65 - 22.10.2020
    • Improved Show-GPOZaurr (WIP)
  • 0.0.64 - 21.10.2020
    • Renamed Remove-GPOZaurrOrphaned to Remove-GPOZaurrBroken keeping it as an alias
    • Renamed Get-GPOZaurrSysvol to Get-GPOZaurrBroken keeping it as an alias
    • Improved Show-GPOZaurr (WIP)
  • 0.0.63 - 19.10.2020
    • Renamed Invoke-GPOZaurrContent back to Invoke-GPOZaurr
    • Added Show-GPOZaurr (WIP)
    • Added OutputType,OutputType,Open,Online parameters to Invoke-GPOZaurr
    • Added Get-GPOZaurrNetLogon
    • Improved Get-GPOZaurrOwner
    • Fixes Get-GPOZaurrSysvol
  • 0.0.62 - 14.10.2020
    • Renamed Invoke-GPOZaurr to Invoke-GPOZaurrContent - I want to use Invoke-GPOZaurr for something else
    • Improvements to Get-GPOZaurrPermissionConsistency for GPOs without SYSVOL to be reported properly
    • Added Get-GPOZaurrPermissionRoot
    • Renamed Remove-GPOZaurrOrphanedSysvolFolders to Remove-GPOZaurrOrphaned
    • Improved Remove-GPOZaurrOrphaned to deal with orphaned folders but also orphaned AD GPO (No sysvol data)
    • Improved Get-GPOZaurrSysVol to detect orphaned SYSVOL or AD GPO objects
    • Improved Get-GPOZaurrSysVol to detect permissions issue when reading AD GPO objects
    • Added Get-GPOZaurrPermissionRoot to show which users/groups have control over all GPOs (allowed to create/modify)
    • Improved Get-GPOZaurrPermissionSummary to include Get-GPOZaurrPermissionRoot custom permissions
    • Updated Remove-GPOZaurrPermission
    • Updated Get-GpoZaurrPermission
    • Updated Get-GPOZaurrFiles to better handle access issue
    • Reversed parameters Get-GPOZaurrFiles from Limited to ExtendedMetaData and fixed missing columns
  • 0.0.61 - 31.08.2020
    • Improvement to Get-GPOZaurrPermissionSummary
    • Fixes to ConvertFrom-CSExtension
    • Fixes to Find-CSExtension
  • 0.0.59 - 26.08.2020
    • Improvement to Get-GPOZaurrPermissionSummary
  • 0.0.58 - 26.08.2020
    • Improvement to Get-GPOZaurrPermissionSummary
  • 0.0.57 - 26.08.2020
    • Improvement to Get-GPOZaurrPermissionSummary
  • 0.0.56 - 26.08.2020
    • Added Get-GPOZaurrPermissionSummary
  • 0.0.55 - 17.08.2020
    • Improved Get-GPOZaurrInheritance
  • 0.0.54 - 16.08.2020
    • Added Invoke-GPOZaurrSupport (WIP)
    • Added ConvertFrom-CSExtension
    • Added Find-CSExtension
    • Added Get-GPOZaurrInheritance
  • 0.0.53 - 16.08.2020
    • Bad release
  • 0.0.52 - 16.08.2020
    • Bad release
  • 0.0.51 - 2.08.2020
    • Updates to Invoke-GPOZaurr - still work in progress
    • Added Get-GPOZaurrSysvolDFSR
    • Added Clear-GPOZaurrSysvolDFSR (requires testing)
  • 0.0.50 - 29.07.2020
    • Updates to couple of commands
  • 0.0.49 - 23.07.2020
    • Hidden files were skipped - and people do crazy things with them
  • 0.0.48 - 21.07.2020
    • Added Get-GPOZaurrFilesPolicyDefinition
    • Updates to Invoke-GPOZaurr - still work in progress
    • Updates to Get-GPOZaurrFiles - still work in progress
    • Updates to Remove-GPOZaurrOrphanedSysvolFolders with backup and support for domains
    • Module will now be signed
  • 0.0.47 - 29.06.2020
    • Update to Get-GPOZaurrAD for better error reporting
    • Updates to Invoke-GPOZaurr - still work in progress
  • 0.0.46 - 28.06.2020
    • Additional protection for Get-GPOZaurrAD for CNF duplicates
    • Update to Save-GPOZaurrFiles
    • Added Invoke-GPOZaurr (alias: Find-GPO) (heavy work in progress)
  • 0.0.45 - 26.06.2020
  • 0.0.44 - 24.06.2020
    • Improvement to Get-GPOZaurrLinkSummary
  • 0.0.43 - 21.06.2020
    • Added Get-GPOZaurrFiles to list files on NETLOGON/SYSVOL shares with a lot of details
  • 0.0.42 - 19.06.2020
    • Fix for Get-GPOZaurrLink and SearchBase parameter
    • Fix for Get-GPOZaurrLink - canonical link Trim() throwing errors if empty
  • 0.0.41 - 18.06.2020
    • Added paramerter SkipDuplicates to Invoke-GPOZaurrPermission which prevents applying permissions over and over again if 1 GPO is linked to a multiple OU's within another OU
  • 0.0.40 - 18.06.2020
  • 0.0.39 - 17.06.2020
    • Updates to Invoke-GPOZaurrPermission with new parameter LimitAdministrativeGroupsToDomain
      • This will get administrative based on IncludeDomains if given. It means that if GPO has Domain admins added from multiple domains it will only find one, and remove all other Domain Admins (if working with Domain Admins that is)
  • 0.0.38 - 17.06.2020
    • Update to Get-PrivGPOZaurrLink which would cause problems to Invoke-GPOZaurrPermission if it would be run without Administrative permission and GPO wouldn't be accessible for that user
  • 0.0.37 - 16.06.2020
    • Updates to Invoke-GPOZaurrPermission with new parameterset Level
    • Updates to Get-GPOZaurrLinkSummary
  • 0.0.36 - 15.06.2020
    • Initial release
S
Description
Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.
Readme 2.2 MiB
Languages
PowerShell 100%