如何通过GPO-Report XML检测GPO与指定OU的关联状态
问题:检查GPO与指定OU的关联状态
我需要在XML文件中搜索,确认特定组策略(GPO)是否关联了若干组织单元(OU)。OU的完整格式为**"OU=XXXXX-Name,OU=DEMO OU,dc=domain,dc=local"**,我已经提取了每个OU的distinguishedname属性,只保留第一部分的XXXXX-Name(去掉了开头的"OU="和后面的所有内容)作为要匹配的显示名称。
我需要利用GPO-Report -XML的输出,检查其中<SOMName>节点的值是否与目标OU名称匹配,以此判断GPO是否已关联该特定OU。相关XML节点片段如下:
<LinksTo> <SOMName>XXXXX-Name</SOMName> <SOMPath>domain.local/DEMO OUs</SOMPath> <Enabled>true</Enabled> <NoOverride>false</NoOverride> </LinksTo>
我之前尝试了一些正则表达式但没成功,现在更新内容后问题已解决。
更新
抱歉之前内容不全(我是新手),添加代码后问题已经解决,代码如下:
Clear-Host $gpoName = "TestGPO" $oulist=(Get-Content C:\temp\ou.txt|foreach { Get-ADOrganizationalUnit -Filter "name -like `"*$_*`"" -Properties distinguishedname|` select -ExpandProperty distinguishedname}) -replace '^OU=|,.*$' $xmlgpo=Get-GPO $gpoName |Get-GPOReport -ReportType XML foreach ($item in $oulist){ if ($xmlgpo -match $item){ Write-Warning "GPO '$gponame' has a link already to '$item'" } else{ Write-Warning "No link to OU '$item' found" } }
内容的提问来源于stack exchange,提问作者Ntinsky
相关产品推荐
相关产品推荐

