## Define the MSP name $MSPName = "Emberkom" ## Setup the MSP management directories If ( Test-Path ${Env:ProgramData} ) { $MSPRoot = "${Env:ProgramData}\${MSPName}" } Else { $MSPRoot = "${Env:SystemDrive}\${MSPName}" } $MSPScripts = "${MSPRoot}\Scripts" $MSPTools = "${MSPRoot}\Tools" $MSPLogs = "${MSPRoot}\Logs" ## Make sure all the management directories exist $MSPRoot, $MSPScripts, $MSPTools, $MSPLogs | ForEach-Object { If ( !(Test-Path $_) ) { Try { New-Item -Path $_ -ItemType Directory -Force -ErrorAction SilentlyContinue | Out-Null } Catch { Write-Output $_.Exception.Message } } } ## Setup the log file for messages generated when this script is run $LogFile = '{0}\ManagementScript_{1}.log' -f $MSPLogs, (Get-Date -Format "yyyyMMddHHmmss") If ( !(Test-Path $LogFile) ) { New-Item -Path $LogFile -ItemType File -Force | Out-Null } ## Function to log activity to the configured log directory Function Log { param( [Parameter(Mandatory=$true,ValueFromPipeline=$true)][string]$Message, [Parameter(Mandatory=$false)][switch]$Error=$false, [Parameter(Mandatory=$false)][string]$Name ) $Timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" If ( $Error ) { $LogEntry = "${Timestamp} - Error: ${Message}" } Else { $LogEntry = "${Timestamp} - ${Message}" } Add-Content -Path $LogFile -Value $LogEntry Write-Output $LogEntry } ## Log a message to the log file Function LogMsg { param([Parameter(Mandatory=$true,ValueFromPipeline=$true)][string]$Message) $Timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" $LogEntry = "${Timestamp} - ${Message}" Add-Content -Path $LogFile -Value $LogEntry #Write-Output $LogEntry } ## Log an error to the log file Function LogErr { param([Parameter(Mandatory=$true,ValueFromPipeline=$true)][string]$Message) $Timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" $LogEntry = "${Timestamp} - Error: ${Message}" Add-Content -Path $LogFile -Value $LogEntry #Write-Output "Error: ${LogEntry}" } ## Function to determine if the current user context is an Administrator Function IsAdmin { If ( ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator) ) { Return $true } Else { Return $false } } ## Run a script from the live repo or from a local path Function Run-Script { param( ## Parameters for live-ps scripts [Parameter(Mandatory=$false,ParameterSetName='live-ps')] [string]$Type='management-scripts', [Parameter(Mandatory=$true,ParameterSetName='live-ps')] [string]$LivePSScript, ## Parameters for local scripts [Parameter(Mandatory=$true,ParameterSetName='local')] [string]$Path, #### $NoWait will prevent waiting for the specified script to finish running [Parameter(Mandatory=$false,ParameterSetName='local')] [switch]$NoWait=$false, ## Parameters for all scripts [Parameter(Mandatory=$false,ParameterSetName='live-ps')] [Parameter(Mandatory=$false,ParameterSetName='local')] [string]$Arguments='null', #### $HaltIfRunning is a collection of app names which, if running, will prevent the script from running [Parameter(Mandatory=$false,ParameterSetName='live-ps')] [Parameter(Mandatory=$false,ParameterSetName='local')] [string[]]$HaltIfRunning='null', #### $ForceClose will forcefully close all apps specified in $HaltIfRunning [Parameter(Mandatory=$false,ParameterSetName='live-ps')] [Parameter(Mandatory=$false,ParameterSetName='local')] [switch]$ForceClose=$false ) If ( $Arguments -eq "null" ) { $Arguments = $null } If ( $HaltIfRunning -eq "null" ) { $HaltIfRunning = $null } If ( $LivePSScript ) { $URL = "https://dev.emberkom.com/emberkom/${Type}/raw/branch/master/${LivePSScript}.ps1" If ( !(IsURLValid -URL $URL) ) { LogMsg "The specified script does not exist: ${LivePSScript}" ; Exit } } If ( $Path ) { If ( !(Test-Path $Path) ) { LogMsg "The specified script does not exist: ""${Path}""" ; Exit } } If ( ($HaltIfRunning -ne $null ) -and ($ForceClose) -and ( !(IsAdmin) ) ) { LogMsg "Cannot close dependent apps because this task does not have administrative privileges" ; Exit } If ( $HaltIfRunning ) { $Halt = $false LogMsg "Checking for running instances of the following dependent apps:" ForEach ( $name in $HaltIfRunning) { $RunningInstances = Get-Process | Where { $_.Name -like "${name}" } If ( $RunningInstances ) { If ( $ForceClose -eq $true ) { Try { $name | Stop-Process -Force } Catch { LogErr $_.Exception.Message ; Exit } Log " ""${name}"" (force closed)" -Name $LogName } Else { $Halt = $true ; LogMsg " ""${name}"" (running)" } } Else { LogMsg " ""${name}"" (not running)" } } If ( $Halt -eq $true ) { LogMsg "Dependent apps are currently in use and are preventing the specified script from running" ; Exit } } switch ($PSCmdlet.ParameterSetName) { 'live-ps' { LogMsg "Retrieving : ${LivePSScript}.ps1" Try { $Script = (New-Object Net.WebClient).DownloadString($URL) } Catch { LogErr $_.Exception.Message ; Exit } Try { $ScriptBlock = [Scriptblock]::Create($Script) } Catch { LogErr $_.Exception.Message ; Exit } LogMsg "Executing: ${LivePSScript}.ps1 ${Arguments}" Try { Invoke-Command -ScriptBlock $ScriptBlock -ArgumentList $Arguments } Catch { LogErr $_.Exception.Message ; Exit } } 'local' { LogMsg "Executing: ${Path} ${Arguments}" If ( $NoWait ) { Try { Start-Process "${Path}" -ArgumentList "{$Arguments}" } Catch { LogErr $_.Exception.Message } } Else { LogMsg " Waiting for script to finish..." Try { Start-Process "${Path}" -ArgumentList "{$Arguments}" -Wait } Catch { LogErr $_.Exception.Message } LogMsg " Finished" } } } } ## Return a Powershell version object from a string Function Get-Version { param([Parameter(Mandatory=$true)][string]$Version) [int]$Sets = 4 $VersionArray = $Version.Split('.') If ( $VersionArray.Count -le $Sets ) { $Sets = $VersionArray.Count } For ($i = 0; $i -le ($Sets - 1); $i++) { $Return = '{0}.{1}' -f $Return, $VersionArray[$i] } Return [version]$Return.Trim('.') } ## Determines whether a URL is valid Function IsURLValid { param([Parameter(Mandatory=$true,ValueFromPipeline=$true)][string]$URL) Try { $HTTPRequest = [System.Net.WebRequest]::Create($URL) $HTTPResponse = $HTTPRequest.GetResponse() $HTTPStatus = [int]$HTTPResponse.StatusCode $HTTPResponse.Close() } Catch {} If ($HTTPStatus -eq 200) { Return $true } Else { Return $false } } ## Downloads a file from a URL Function Download-File { param( [Parameter(Mandatory=$true,ValueFromPipeline=$true)][string]$URL, [Parameter(Mandatory=$false,ValueFromPipeline=$false)][string]$File ) If ( !($File) ) { $File = '{0}{1}' -f (GetTempPath), (Split-Path $URL -Leaf) } If ( IsURLValid $URL ) { If ( Test-Path $File ) { LogMsg "Deleting existing file: ""${File}""" Try { Remove-Item $File -Force } Catch { LogErr $_.Exception.Message } } LogMsg "Downloading ""${URL}"" to ""${File}""" Try { (New-Object System.Net.WebClient).DownloadFile($URL,$File) } Catch { LogErr $_.Exception.Message } If ( Test-Path "${File}" ) { Return "${File}" } Else { LogMsg "Downloaded file does not exist at ""${File}""" ; Return $false } } Else { LogMsg "URL is not valid or file cannot be reached: ${URL}" } } ## Install a program from a provided path Function Install-Program { param( [Parameter(Mandatory=$true)][string]$Path, [Parameter(Mandatory=$false)][string]$Arguments = '', [Parameter(Mandatory=$false)][switch]$Delete = $false ) If ( Test-Path "${Path}" ) { LogMsg "Running installer: ""${Path}"" ${Arguments}" Try { Start-Process "${Path}" -ArgumentList "${Arguments}" -Wait } Catch { LogErr $_.Exception.Message } LogMsg "Installer finished" If ( $Delete ) { LogMsg "Deleting installer: ""${Path}""" Try { Remove-Item -Path "${Path}" -Force } Catch { LogErr $_.Exception.Message } } } Else { LogMsg "The specified file could not be found: ""${Path}""" } } ## Function to compare current Windows version with a supplied version ## The value supplied must be a string and must include at least 1 decimal Function IsWindowsVersion { param( [Parameter(Mandatory=$true,ParameterSetName='gt')][string]$gt, [Parameter(Mandatory=$true,ParameterSetName='ge')][string]$ge, [Parameter(Mandatory=$true,ParameterSetName='lt')][string]$lt, [Parameter(Mandatory=$true,ParameterSetName='le')][string]$le, [Parameter(Mandatory=$true,ParameterSetName='eq')][string]$eq ) [version]$WindowsVersion = [System.Environment]::OSVersion.Version switch ($PSCmdlet.ParameterSetName) { 'gt' { If ( $WindowsVersion -gt (Get-Version $gt) ) { Return $true } Else { Return $false } } 'ge' { If ( $WindowsVersion -ge (Get-Version $ge) ) { Return $true } Else { Return $false } } 'lt' { If ( $WindowsVersion -lt (Get-Version $lt) ) { Return $true } Else { Return $false } } 'le' { If ( $WindowsVersion -le (Get-Version $le) ) { Return $true } Else { Return $false } } 'eq' { If ( $WindowsVersion -eq (Get-Version $eq) ) { Return $true } Else { Return $false } } } } ## Compare current Windows build with a supplied version ## The value supplied must be an int Function IsWindowsBuild { param( [Parameter(Mandatory=$true,ParameterSetName='gt')][int]$gt, [Parameter(Mandatory=$true,ParameterSetName='ge')][int]$ge, [Parameter(Mandatory=$true,ParameterSetName='lt')][int]$lt, [Parameter(Mandatory=$true,ParameterSetName='le')][int]$le, [Parameter(Mandatory=$true,ParameterSetName='eq')][int]$eq ) [int]$WindowsBuild = [System.Environment]::OSVersion.Version.Build switch ($PSCmdlet.ParameterSetName) { 'gt' { If ( $WindowsBuild -gt $gt ) { Return $true } Else { Return $false } } 'ge' { If ( $WindowsBuild -ge $ge ) { Return $true } Else { Return $false } } 'lt' { If ( $WindowsBuild -lt $lt ) { Return $true } Else { Return $false } } 'le' { If ( $WindowsBuild -le $le ) { Return $true } Else { Return $false } } 'eq' { If ( $WindowsBuild -eq $eq ) { Return $true } Else { Return $false } } } } ## Get the path to the TEMP folder (context dependant) Function GetTempPath { Return [System.IO.Path]::GetTempPath() } ## Determine if the system is 64-bit or not Function Is64bit { switch ( $(Get-CimInstance -ClassName Win32_OperatingSystem -Property OSArchitecture | Select-Object -ExpandProperty OSArchitecture) ) { '64-bit' { Return $true } '32-bit' { Return $false } } } ## Determine if the Powershell process is 64-bit or not Function Is64bitShell { If ( [System.Environment]::Is64BitProcess ) { Return $true } Else { Return $false } } ## Determine if a user is in a built-in role or specified group Function IsMemberOf { param( [Parameter(Mandatory=$false)] [switch]$Builtin=$false, [Parameter(Mandatory=$true,ValueFromPipeline=$true)] [string]$Group ) If ( $Builtin ) { Switch ( $Group ) { ("Administrator" -or "Administrators") { $Group = [System.Security.Principal.WindowsBuiltInRole]::Administrator ; break } ("Backup Operator" -or "Backup Operators" -or "BackupOperator" -or "BackupOperators") { $Group = [System.Security.Principal.WindowsBuiltInRole]::BackupOperator ; break } ("System Operator" -or "System Operators" -or "SystemOperator" -or "SystemOperators") { $Group = [System.Security.Principal.WindowsBuiltInRole]::SystemOperator ; break } ("Account Operator" -or "Account Operators" -or "AccountOperator" -or "AccountOperators") { $Group = [System.Security.Principal.WindowsBuiltInRole]::AccountOperator ; break } ("Print Operator" -or "Print Operators" -or "PrintOperator" -or "PrintOperators") { $Group = [System.Security.Principal.WindowsBuiltInRole]::PrintOperator ; break } ("Replicator" -or "Replicators") { $Group = [System.Security.Principal.WindowsBuiltInRole]::Replicator ; break } ("Power User" -or "Power Users" -or "PowerUser" -or "PowerUsers") { $Group = [System.Security.Principal.WindowsBuiltInRole]::PowerUser ; break } ("User" -or "Users") { $Group = [System.Security.Principal.WindowsBuiltInRole]::User ; break } ("Guest" -or "Guests") { $Group = [System.Security.Principal.WindowsBuiltInRole]::Guest ; break } default { ; break } } } Return ([Security.Principal.WindowsPrincipal][System.Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole($Group) }