如何让PowerShell针对GPO链接的非终止错误返回自定义信息
PowerShell脚本:捕获GPO链接的非终止错误并返回自定义信息
需求说明
编写PowerShell脚本时,需要捕获New-GPLink的两种预期非终止错误,替换系统默认的冗长错误文本为自定义提示:
- 当目标GPO未链接到OU,导致无法确定链接顺序时,返回:用于定位顺序的GPO未链接到此OU,新GPO将不会被链接
- 当GPO已链接到目标OU时,返回:GPO已链接到此OU
系统默认错误示例
场景1:目标GPO未链接到OU的参数绑定错误
New-GPLink : Cannot bind parameter 'Order' to the target. Exception setting "Order": "Cannot convert null to type \"System.Int32\"." At line:23 char:36 Name -order ((Get-GPInheritance -Target $parentDN).GpoLinks | Where-O ... CategoryInfo : WriteError: (:) [New-GPLink], ParameterBindingException FullyQualifiedErrorId : ParameterBindingFailed,Microsoft.GroupPolicy.Commands.NewGPLinkCommand
场景2:GPO已链接的参数无效错误
New-GPLink : The GPO named 'Test-Do-Not-Use' is already linked to a Scope of Management with Path 'OU=Blah,OU=Blah,DC=Something,DC=Somewhere,DC=Sometime,DC=Here,DC=There'. At line:23 char:3 New-GPLink -Name $gpoName -order ((Get-GPInheritance -Target $paren ... CategoryInfo : InvalidArgument: (Microsoft.Group...ewGPLinkCommand:NewGPLinkCommand) [New-GPLink], ArgumentException FullyQualifiedErrorId : UnableToCreateNewLink,Microsoft.GroupPolicy.Commands.NewGPLinkCommand
原始脚本
$SG = Read-Host -Prompt 'Enter the name of the Security Group you want to get the members for' $GPOType = Read-Host -Prompt 'Are you Linking a User or Computer GPO - Type either User or Computer' $gpoName = Read-Host -Prompt 'Enter the Group Policy Name you want to Link' $targetGpoName = Read-Host -Prompt 'Enter the Group Policy name of the policy that you want to link new one above - For example if the Target policy link order is 10 this will put the new Policy in Link Order 10 moving the target Polciy to Link Order 11' $EnableLink = Read-Host -Prompt 'Enter Yes or No to enable link or not' $GPO = get-gpo -Name $targetGpoName $OUlists = get-adgroupmember -identity $SG | where-object {$_.samaccountname -notlike '*svc*' -and $_.objectclass -like $GPOType} | ForEach-Object -process { $DN = $_.distinguishedname; $null,$trailingRDNs = $DN -split '(?<!\\),' $parentDNs = $trailingRDNs -join ',' foreach ($parentDN in $parentDNs) { Write-Host "Working on ($parentDN )" New-GPLink -Name $gpoName -order ((Get-GPInheritance -Target $parentDN).GpoLinks | Where-Object DisplayName -eq $targetGpoName | select -expandproperty order) -Target $parentDN -LinkEnabled $EnableLink } }
解决后的工作脚本
核心修改:给New-GPLink添加-ErrorAction Stop参数,将非终止错误转换为终止错误,从而可以通过try/catch块捕获特定异常类型,返回自定义提示。
$SG = Read-Host -Prompt 'Enter the name of the Security Group you want to get the members for' $GPOType = Read-Host -Prompt 'Are you Linking a User or Computer GPO - Type either User or Computer' $gpoName = Read-Host -Prompt 'Enter the Group Policy Name you want to Link' $targetGpoName = Read-Host -Prompt 'Enter the Group Policy name of the policy that you want to link new one above - For example if the Target policy link order is 10 this will put the new Policy in Link Order 10 moving the target Polciy to Link Order 11' $EnableLink = Read-Host -Prompt 'Enter Yes or No to enable link or not' $GPO = get-gpo -Name $targetGpoName $OUlists = get-adgroupmember -identity $SG | where-object {$_.samaccountname -notlike '*svc*' -and $_.objectclass -like $GPOType} | ForEach-Object -process { $DN = $_.distinguishedname; $null,$trailingRDNs = $DN -split '(?<!\\),' $parentDNs = $trailingRDNs -join ',' foreach ($parentDN in $parentDNs){ Write-Host "Working on ($parentDN )" try { New-GPLink -Name $gpoName -order ((Get-GPInheritance -Target $parentDN).GpoLinks | Where-Object DisplayName -eq $targetGpoName | select -expandproperty order) -Target $parentDN -LinkEnabled $EnableLink -ErrorAction Stop }catch [System.ArgumentException]{ write-warning "GPO已链接到此OU" } catch [System.Management.Automation.ParameterBindingException]{ write-warning "用于定位顺序的GPO未链接到此OU,新GPO将不会被链接" } } }
内容的提问来源于stack exchange,提问作者NuckinFutz
相关产品推荐
相关产品推荐

