如何通过PowerShell或其他方法导出GPME中的全部可用策略?
导出GPME所有可用策略列表的解决方案
一、理想方案:导出策略名称、配置状态及帮助描述
GPME中的可用策略全部来自系统的ADMX/ADML模板文件,通过解析这些XML格式的模板,可以提取完整的策略信息。以下是PowerShell脚本实现:
# 定义ADMX和对应语言ADML文件的路径 $admxRoot = "C:\Windows\PolicyDefinitions" $admlRoot = "C:\Windows\PolicyDefinitions\zh-CN" # 如需英文描述,改为en-US # 收集所有ADMX模板文件 $admxFiles = Get-ChildItem -Path $admxRoot -Filter "*.admx" -Recurse $policyCollection = @() foreach ($admxFile in $admxFiles) { # 加载ADMX XML内容 [xml]$admxContent = Get-Content $admxFile.FullName $policyNamespace = $admxContent.policyDefinitions.namespace.name # 匹配对应的ADML语言文件 $admlFilePath = Join-Path -Path $admlRoot -ChildPath "$($admxFile.BaseName).adml" if (-not (Test-Path -Path $admlFilePath)) { Write-Warning "未找到匹配的ADML文件:$admlFilePath" continue } [xml]$admlContent = Get-Content $admlFilePath # 处理用户配置下的策略 foreach ($policy in $admxContent.policyDefinitions.user.policies.policy) { # 获取策略显示名称和帮助文本 $displayName = $admlContent.resources.stringTable.string | Where-Object { $_.id -eq $policy.name } | Select-Object -ExpandProperty '#text' $helpDesc = $admlContent.resources.stringTable.string | Where-Object { $_.id -eq "$($policy.name)_Help" } | Select-Object -ExpandProperty '#text' $policyCollection += [PSCustomObject]@{ "完整路径" = "User Configuration;Policies;Administrative Templates;$($policy.parentCategory.ref);$displayName" "策略名称" = $displayName "配置状态" = "未配置" # 模板本身为可用策略,默认状态为未配置 "帮助描述" = $helpDesc } } # 处理计算机配置下的策略 foreach ($policy in $admxContent.policyDefinitions.computer.policies.policy) { $displayName = $admlContent.resources.stringTable.string | Where-Object { $_.id -eq $policy.name } | Select-Object -ExpandProperty '#text' $helpDesc = $admlContent.resources.stringTable.string | Where-Object { $_.id -eq "$($policy.name)_Help" } | Select-Object -ExpandProperty '#text' $policyCollection += [PSCustomObject]@{ "完整路径" = "Computer Configuration;Policies;Administrative Templates;$($policy.parentCategory.ref);$displayName" "策略名称" = $displayName "配置状态" = "未配置" "帮助描述" = $helpDesc } } } # 导出为CSV文件(方便审计分析) $policyCollection | Export-Csv -Path "可用组策略列表.csv" -Encoding UTF8 -NoTypeInformation # 导出为TXT文件(纯文本格式) $policyCollection | Format-Table -AutoSize | Out-File "可用组策略列表.txt" -Encoding UTF8
脚本说明
- 解析系统中所有ADMX模板(包括第三方软件添加的模板,如Office、SQL Server等)
- 自动匹配对应语言的ADML文件,提取本地化的策略名称和帮助描述
- 导出的CSV文件可直接用Excel打开,便于后续整理审计
二、简化方案:仅导出策略及分支路径
如果只需要策略的完整路径信息,可以简化脚本,去掉帮助描述和状态提取部分:
$admxRoot = "C:\Windows\PolicyDefinitions" $admlRoot = "C:\Windows\PolicyDefinitions\zh-CN" $policyPaths = @() foreach ($admxFile in Get-ChildItem -Path $admxRoot -Filter "*.admx" -Recurse) { [xml]$admxContent = Get-Content $admxFile.FullName $admlFilePath = Join-Path -Path $admlRoot -ChildPath "$($admxFile.BaseName).adml" if (-not (Test-Path $admlFilePath)) { continue } [xml]$admlContent = Get-Content $admlFilePath # 提取用户配置策略路径 foreach ($policy in $admxContent.policyDefinitions.user.policies.policy) { $displayName = $admlContent.resources.stringTable.string | Where-Object { $_.id -eq $policy.name } | Select-Object -ExpandProperty '#text' $policyPaths += "User Configuration;Policies;Administrative Templates;$($policy.parentCategory.ref);$displayName" } # 提取计算机配置策略路径 foreach ($policy in $admxContent.policyDefinitions.computer.policies.policy) { $displayName = $admlContent.resources.stringTable.string | Where-Object { $_.id -eq $policy.name } | Select-Object -ExpandProperty '#text' $policyPaths += "Computer Configuration;Policies;Administrative Templates;$($policy.parentCategory.ref);$displayName" } } # 导出为TXT文件 $policyPaths | Out-File "组策略路径列表.txt" -Encoding UTF8
内容的提问来源于stack exchange,提问作者LucasDT
相关产品推荐
相关产品推荐

