Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f2b6a44169 | ||
|
|
1c582e7b0d |
@@ -0,0 +1,29 @@
|
|||||||
|
# Define the username of the provisioning admin account
|
||||||
|
$ProvisioningAdminUsername = "ek-provisioningadmin"
|
||||||
|
|
||||||
|
# Get the provisioning admin user account
|
||||||
|
$ProvisioningAdmin = Get-LocalUser -Name $ProvisioningAdminUsername -ErrorAction SilentlyContinue
|
||||||
|
|
||||||
|
# Exit if the provisioning admin account does not exist
|
||||||
|
If ( $ProvisioningAdmin -eq $false ) { Write-Output "Provisioning Admin account does not exist" ; Exit 0 }
|
||||||
|
|
||||||
|
# Exit if the user is logged in
|
||||||
|
If ( $(Get-CimInstance -Class Win32_Process -Filter 'name = "explorer.exe"' | Invoke-CimMethod -MethodName getowner).User -contains $ProvisioningAdminUsername ) {
|
||||||
|
Write-Output "User is logged in, cannot complete removal of provisioning admin account"
|
||||||
|
Exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# Remove the provisioning admin account
|
||||||
|
Try { Remove-LocalUser -SID $ProvisioningAdmin.SID.Value -ErrorAction Stop }
|
||||||
|
Catch { Write-Error "The provisioning admin account could not be removed`n"+$_.Exception.Message ; Exit 1 }
|
||||||
|
|
||||||
|
# Fully remove the provisioning admin profile
|
||||||
|
Try { Get-CimInstance -Class Win32_UserProfile | Where-Object { $_.SID -eq $ProvisioningAdmin.SID.Value } -ErrorAction SilentlyContinue | Remove-CimInstance }
|
||||||
|
Catch { Write-Error "The provisioning admin profile could not be removed`n"+$_.Exception.Message ; Exit 1 }
|
||||||
|
|
||||||
|
# Delete any remaining provisioning admin directories
|
||||||
|
$ProfilePath = "${Env:SystemDrive}\Users\$ProvisioningAdminUsername"
|
||||||
|
If ( Test-Path $ProfilePath ) {
|
||||||
|
Write-Output "Deleting ""$ProfilePath"""
|
||||||
|
Remove-Item $ProfilePath -Recurse -Force
|
||||||
|
}
|
||||||
@@ -708,12 +708,14 @@ Function IsRunning ([Parameter(ValueFromPipeline=$true)][string]$Name) {
|
|||||||
Function New-LocalAccount {
|
Function New-LocalAccount {
|
||||||
param(
|
param(
|
||||||
[Parameter(Mandatory=$true)][string]$Username,
|
[Parameter(Mandatory=$true)][string]$Username,
|
||||||
[Parameter(Mandatory=$true)][SecureString]$Password,
|
[Parameter(Mandatory=$true)][string]$Password,
|
||||||
[Parameter(Mandatory=$true)][string]$FullName,
|
[Parameter(Mandatory=$true)][string]$FullName,
|
||||||
[Parameter(Mandatory=$true)][string]$Description,
|
[Parameter(Mandatory=$true)][string]$Description,
|
||||||
[Parameter(Mandatory=$false)][switch]$MakeAdmin=$false,
|
[Parameter(Mandatory=$false)][switch]$MakeAdmin=$false,
|
||||||
[Parameter(Mandatory=$false)][switch]$Hide=$false
|
[Parameter(Mandatory=$false)][switch]$Hide=$false
|
||||||
)
|
)
|
||||||
|
$SecurePassword = ConvertTo-SecureString -String $Password -AsPlainText -Force
|
||||||
|
$Password = $null
|
||||||
If ( -not (IsAdmin) ) {
|
If ( -not (IsAdmin) ) {
|
||||||
Write-Output "Cannot create or modify a local account without administrative privileges"
|
Write-Output "Cannot create or modify a local account without administrative privileges"
|
||||||
Return
|
Return
|
||||||
@@ -738,8 +740,21 @@ Function New-LocalAccount {
|
|||||||
Catch { Write-Error $_.Exception.Message ; Exit }
|
Catch { Write-Error $_.Exception.Message ; Exit }
|
||||||
}
|
}
|
||||||
If ( $Hide ) {
|
If ( $Hide ) {
|
||||||
# TODO: Hide account from logon screen
|
$RegPath = "HKLM:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
|
||||||
#Get-ChildItem "HKLM:SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
|
$HideUser = $true
|
||||||
|
If ( -not (Test-Path $RegPath) ) {
|
||||||
|
New-Item -Path $RegPath -Force | Out-Null
|
||||||
|
} Else {
|
||||||
|
$UserList = Get-ItemProperty -Path $RegPath
|
||||||
|
ForEach ( $User in $UserList.PSObject.Properties ) {
|
||||||
|
If ( $User.Name -ieq $Username ) {
|
||||||
|
Write-Output "The user ""${Username}"" is already hidden from the login screen"
|
||||||
|
$HideUser = $false
|
||||||
|
Break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
If ( $HideUser ) { New-ItemProperty -Path $RegPath -Name $Username -Value 0 -PropertyType DWord -Force | Out-Null }
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user