Repository navigation
Expand file tree
/
Copy pathLocalAdminCleanup.ps1
More file actions
99 lines (82 loc) · 3.38 KB
/
Copy pathLocalAdminCleanup.ps1
File metadata and controls
99 lines (82 loc) · 3.38 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
<#
.AUTHOR
Outside Open - 2022
https://outsideopen.com/
.SYNOPSIS
Disables the built-in Administrator account and remove local admin from all users except the defined excludedUserName user.
.DESCRIPTION
This PowerShell script disables the built-in Administrator account, removes all other users from the Administrators group except for a specified user, and logs actions. It verifies that the excluded user exists and is an administrator before proceeding.
.PREREQUISITES
- Execution Policy must be set to RemoteSigned.
- Requires administrative privileges.
.WARRANTY
Provided "as is", with no warranties implied. Review and test in a non-production environment before deployment.
.EXAMPLE
Run the script in an administrative PowerShell session:
.\LocalAdminCleanup.ps1
#>
# Configuration
$excludedUserName = "JohnSmith" # Username to retain administrative privileges. Adjust as needed.
$logPath = "C:\ISSO\Audits\Logs"
$logFileName = "Admin-Rights-Log-" + (Get-Date -Format "yyyy-MM-dd-HHmmss") + ".txt"
$logFile = Join-Path -Path $logPath -ChildPath $logFileName
# Ensure the log directory exists
if (-not (Test-Path -Path $logPath)) {
New-Item -Path $logPath -ItemType Directory | Out-Null
}
# Function to log messages and display in color
function Log-Message {
param (
[string]$Message,
[string]$Color = "White" # Default color
)
$timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss"
$logMessage = "$timestamp - $Message"
$logMessage | Out-File -FilePath $logFile -Append
Write-Host $Message -ForegroundColor $Color
}
# Verify the excluded account exists
$excludedUser = Get-LocalUser -Name $excludedUserName -ErrorAction SilentlyContinue
if (-not $excludedUser) {
Log-Message "The specified account to exclude ($excludedUserName) does not exist." "Red"
exit
}
# Check if the excluded account is an administrator by comparing SIDs
$isAdmin = $false
$adminMembers = Get-LocalGroupMember -Group "Administrators"
foreach ($member in $adminMembers) {
if ($member.Sid -eq $excludedUser.Sid) {
$isAdmin = $true
break
}
}
if (-not $isAdmin) {
Log-Message "The specified account to exclude ($excludedUserName) is not an administrator." "Red"
exit
}
# Always disable the built-in Administrator account
try {
$adminAccount = Get-LocalUser -Name "Administrator"
if ($adminAccount.Enabled) {
Disable-LocalUser -Name "Administrator"
Log-Message "The built-in Administrator account has been disabled." "Green"
} else {
Log-Message "The built-in Administrator account is already disabled." "Yellow"
}
} catch {
Log-Message "Failed to disable the built-in Administrator account: $_" "Red"
}
# Adjust membership of the Administrators group
$adminGroup = Get-LocalGroup -Name "Administrators"
$adminMembers = Get-LocalGroupMember -Group $adminGroup.Name
foreach ($member in $adminMembers) {
if ($member.Sid -ne $excludedUser.Sid -and $member.Name -ne "Administrator") {
try {
Remove-LocalGroupMember -Group $adminGroup.Name -Member $member.Name -ErrorAction Stop
Log-Message "Removed $($member.Name) from the Administrators group." "Green"
} catch {
Log-Message "Failed to remove $($member.Name) from the Administrators group: $_" "Yellow"
}
}
}
Log-Message "Script execution completed. Specified adjustments have been made to the Administrators group." "Green"