Repository navigation
Expand file tree
/
Copy pathGroupPolicyManager.ps1
More file actions
180 lines (147 loc) · 8.33 KB
/
Copy pathGroupPolicyManager.ps1
File metadata and controls
180 lines (147 loc) · 8.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
# Group Policy Management Script
# This script configures various Group Policy settings for security and standardization
# Import required modules
Import-Module GroupPolicy
Import-Module ActiveDirectory
# Configuration
$gpoConfig = @{
GpoName = "Standard Security Settings"
Description = "Standard security and user experience settings for all computers"
ReportPath = "C:\Reports\GPO"
LogPath = "C:\Logs\GPO"
}
# Create necessary directories
New-Item -Path $gpoConfig.ReportPath -ItemType Directory -Force -ErrorAction SilentlyContinue
New-Item -Path $gpoConfig.LogPath -ItemType Directory -Force -ErrorAction SilentlyContinue
# Function to create and configure GPO
function Set-StandardGPO {
param (
[string]$GpoName = $gpoConfig.GpoName
)
$logFile = Join-Path $gpoConfig.LogPath "gpo_config_$(Get-Date -Format 'yyyy-MM-dd_HH-mm').log"
try {
# Create new GPO if it doesn't exist
if (-not (Get-GPO -Name $GpoName -ErrorAction SilentlyContinue)) {
New-GPO -Name $GpoName -Comment $gpoConfig.Description
Write-Host "Created new GPO: $GpoName" -ForegroundColor Green
}
# Computer Configuration Settings
$computerSettings = @{
# Security Settings
"Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy\Minimum password length" = 12
"Computer Configuration\Windows Settings\Security Settings\Account Policies\Password Policy\Password must meet complexity requirements" = "Enabled"
"Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy\Account lockout threshold" = 5
"Computer Configuration\Windows Settings\Security Settings\Account Policies\Account Lockout Policy\Account lockout duration" = 30
# Windows Components
"Computer Configuration\Administrative Templates\Windows Components\Windows Update\Configure Automatic Updates" = "Enabled"
"Computer Configuration\Administrative Templates\Windows Components\Windows Update\No auto-restart with logged on users for scheduled automatic updates installations" = "Disabled"
# System
"Computer Configuration\Administrative Templates\System\Power Management\Button Settings\Turn off the display (on battery)" = "Enabled"
"Computer Configuration\Administrative Templates\System\Power Management\Button Settings\Turn off the display (plugged in)" = "Enabled"
# Network
"Computer Configuration\Administrative Templates\Network\Windows Connection Manager\Prohibit connection to non-domain networks when connected to domain authenticated network" = "Enabled"
# Bluetooth
"Computer Configuration\Administrative Templates\Windows Components\Bluetooth\Turn off Bluetooth" = "Enabled"
# Windows Store
"Computer Configuration\Administrative Templates\Windows Components\Store\Turn off the Store application" = "Enabled"
# Remote Desktop
"Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Connections\Allow users to connect remotely using Remote Desktop Services" = "Disabled"
}
# User Configuration Settings
$userSettings = @{
# Control Panel
"User Configuration\Administrative Templates\Control Panel\Personalization\Prevent changing desktop background" = "Enabled"
"User Configuration\Administrative Templates\Control Panel\Personalization\Prevent changing theme" = "Enabled"
"User Configuration\Administrative Templates\Control Panel\Personalization\Prevent changing screen saver" = "Enabled"
# Start Menu and Taskbar
"User Configuration\Administrative Templates\Start Menu and Taskbar\Remove user's folders from the Start Menu" = "Enabled"
"User Configuration\Administrative Templates\Start Menu and Taskbar\Remove common program groups from Start Menu" = "Enabled"
# Windows Components
"User Configuration\Administrative Templates\Windows Components\Windows Media Player\Prevent automatic updates" = "Enabled"
"User Configuration\Administrative Templates\Windows Components\Windows Store\Turn off the Store application" = "Enabled"
# System
"User Configuration\Administrative Templates\System\Ctrl+Alt+Del Options\Remove Change Password" = "Enabled"
"User Configuration\Administrative Templates\System\Ctrl+Alt+Del Options\Remove Lock Computer" = "Enabled"
"User Configuration\Administrative Templates\System\Ctrl+Alt+Del Options\Remove Task Manager" = "Enabled"
# Desktop
"User Configuration\Administrative Templates\Desktop\Desktop\Remove Recycle Bin icon from desktop" = "Enabled"
"User Configuration\Administrative Templates\Desktop\Desktop\Remove Computer icon from desktop" = "Enabled"
"User Configuration\Administrative Templates\Desktop\Desktop\Remove Network icon from desktop" = "Enabled"
}
# Apply Computer Configuration Settings
foreach ($setting in $computerSettings.GetEnumerator()) {
Set-GPRegistryValue -Name $GpoName -Key $setting.Key -ValueName "Value" -Type DWord -Value $setting.Value
"Set computer setting: $($setting.Key)" | Out-File -FilePath $logFile -Append
}
# Apply User Configuration Settings
foreach ($setting in $userSettings.GetEnumerator()) {
Set-GPRegistryValue -Name $GpoName -Key $setting.Key -ValueName "Value" -Type DWord -Value $setting.Value
"Set user setting: $($setting.Key)" | Out-File -FilePath $logFile -Append
}
# Configure Software Installation
$softwarePaths = @{
"Adobe Reader" = "\\server\software\AdobeReader.msi"
"Microsoft Office" = "\\server\software\Office.msi"
"Antivirus" = "\\server\software\Antivirus.msi"
}
foreach ($software in $softwarePaths.GetEnumerator()) {
if (Test-Path $software.Value) {
New-GPO -Name "$GpoName - $($software.Key) Installation"
Set-GPRegistryValue -Name "$GpoName - $($software.Key) Installation" `
-Key "Software\Policies\Microsoft\Windows\Installer" `
-ValueName "EnableAdminTSRemote" `
-Type DWord `
-Value 1
"Configured software installation: $($software.Key)" | Out-File -FilePath $logFile -Append
}
}
Write-Host "GPO configuration completed successfully!" -ForegroundColor Green
}
catch {
$errorMessage = "GPO configuration failed: $_"
$errorMessage | Out-File -FilePath $logFile -Append
Write-Host $errorMessage -ForegroundColor Red
}
}
# Function to link GPO to OUs
function Set-GPOLinks {
param (
[string]$GpoName = $gpoConfig.GpoName,
[string[]]$OUs = @("Computers", "Users")
)
try {
foreach ($ou in $OUs) {
$ouPath = "OU=$ou,DC=lab,DC=local"
New-GPLink -Name $GpoName -Target $ouPath
Write-Host "Linked GPO to OU: $ou" -ForegroundColor Green
}
}
catch {
Write-Host "Failed to link GPO: $_" -ForegroundColor Red
}
}
# Function to generate GPO report
function Get-GPOReport {
param (
[string]$GpoName = $gpoConfig.GpoName
)
$timestamp = Get-Date -Format "yyyy-MM-dd_HH-mm"
$reportPath = Join-Path $gpoConfig.ReportPath "GPO_Report_${GpoName}_$timestamp.html"
Get-GPOReport -Name $GpoName -ReportType HTML -Path $reportPath
Write-Host "GPO report generated at: $reportPath" -ForegroundColor Green
}
# Function to backup GPOs
function Backup-GPOs {
$timestamp = Get-Date -Format "yyyy-MM-dd_HH-mm"
$backupPath = Join-Path $gpoConfig.ReportPath "GPO_Backup_$timestamp"
New-Item -Path $backupPath -ItemType Directory -Force | Out-Null
Get-GPO -All | ForEach-Object {
Backup-GPO -Guid $_.Id -Path $backupPath
}
Write-Host "GPOs backed up to: $backupPath" -ForegroundColor Green
}
# Example usage:
# Set-StandardGPO
# Set-GPOLinks
# Get-GPOReport
# Backup-GPOs