refactor New-LocalAccount function to accept plain text password and hide user from login screen
This commit is contained in:
@@ -708,12 +708,14 @@ Function IsRunning ([Parameter(ValueFromPipeline=$true)][string]$Name) {
|
||||
Function New-LocalAccount {
|
||||
param(
|
||||
[Parameter(Mandatory=$true)][string]$Username,
|
||||
[Parameter(Mandatory=$true)][SecureString]$Password,
|
||||
[Parameter(Mandatory=$true)][string]$Password,
|
||||
[Parameter(Mandatory=$true)][string]$FullName,
|
||||
[Parameter(Mandatory=$true)][string]$Description,
|
||||
[Parameter(Mandatory=$false)][switch]$MakeAdmin=$false,
|
||||
[Parameter(Mandatory=$false)][switch]$Hide=$false
|
||||
)
|
||||
$SecurePassword = ConvertTo-SecureString -String $Password -AsPlainText -Force
|
||||
$Password = $null
|
||||
If ( -not (IsAdmin) ) {
|
||||
Write-Output "Cannot create or modify a local account without administrative privileges"
|
||||
Return
|
||||
@@ -738,8 +740,21 @@ Function New-LocalAccount {
|
||||
Catch { Write-Error $_.Exception.Message ; Exit }
|
||||
}
|
||||
If ( $Hide ) {
|
||||
# TODO: Hide account from logon screen
|
||||
#Get-ChildItem "HKLM:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
|
||||
$RegPath = "HKLM:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
|
||||
$HideUser = $true
|
||||
If ( -not (Test-Path $RegPath) ) {
|
||||
New-Item -Path $RegPath -Force | Out-Null
|
||||
} Else {
|
||||
$UserList = Get-ItemProperty -Path $RegPath
|
||||
ForEach ( $User in $UserList.PSObject.Properties ) {
|
||||
If ( $User.Name -ieq $Username ) {
|
||||
Write-Output "The user ""${Username}"" is already hidden from the login screen"
|
||||
$HideUser = $false
|
||||
Break
|
||||
}
|
||||
}
|
||||
}
|
||||
If ( $HideUser ) { New-ItemProperty -Path $RegPath -Name $Username -Value 0 -PropertyType DWord -Force | Out-Null }
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user