GPO TOOL to get reports on all of AD.
https://github.com/EvotecIT/GPOZaurrGPOZaurr
Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.
GPOZaurr provides 360 degrees of information about Group Policies and their settings.
Just a single command (
Invoke-GPOZaurr) provides following reports:
- GPOBroken
- GPOBrokenLink
- GPOOwners
- GPOConsistency
- GPODuplicates
- GPOOrganizationalUnit
- GPOList
- GPOLinks
- GPOPassword
- GPOPermissions
- GPOPermissionsAdministrative
- GPOPermissionsRead
- GPOPermissionsRoot
- GPOPermissionsUnknown
- GPOFiles
- GPOBlockedInheritance
- GPOAnalysis
- GPOUpdates
- NetLogonOwners
- NetLogonPermissions
- SysVolLegacyFiles
But that's not all. There are over 50 other commands available that make it even more powerful helping with day to day tasks to manage Group Policies.
To understand the usage of
Invoke-GPOZaurr I've created blog post you may find useful
Installing
GPOZaurr requires
RSAT installed to provide results. If you don't have them you can install them as below. Keep in mind it also installs GUI tools so it shouldn't be installed on user workstations.
# Windows 10 Latest
Add-WindowsCapability-Online
-Name
'Rsat.ActiveDirectory.DS-LDS.Tools~~~~0.0.1.0'
Add-WindowsCapability-Online
-Name
'Rsat.GroupPolicy.Management.Tools~~~~0.0.1.0'
Finally just install module:
Install-Module-Name GPOZaurr
-AllowClobber
-Force
Force and AllowClobber aren't necessary, but they do skip errors in case some appear.
Updating
Update-Module-Name GPOZaurr