From 62a4ad183ac4e35a9af57408a6402afe06d67599 Mon Sep 17 00:00:00 2001 From: Ivo Oskamp Date: Sat, 20 Jun 2026 19:25:57 +0200 Subject: [PATCH] Repository moved to Forgejo All content and history now live at https://forgejo.oskamp.info/ivooskamp/PWExpireNotification.git This Gitea copy is emptied and kept only as a redirect. --- .gitignore | 350 ------- Examples/SendMailMessage.ps1 | 47 - LICENSE | 21 - README.md | 96 +- docs/Get-PWADDSExpiringPassword.md | 101 -- docs/Get-PWApplicationToken.md | 113 --- docs/Send-PWExpiringMailMessage.md | 210 ---- docs/Set-PWEmailBody.md | 109 -- docs/Set-PWEmailMessagePayload.md | 111 --- docs/en-US/PWExpireNotification-help.xml | 930 ------------------ .../Functions/Get-PWADDSExpiringPassword.ps1 | 67 -- .../Functions/Get-PWApplicationToken.ps1 | 48 - .../1.0.1/Functions/New-PWEmailBody.ps1 | 29 - .../Functions/New-PWEmailMessagePayload.ps1 | 61 -- .../Functions/Send-PWExpiringMailMessage.ps1 | 107 -- .../1.0.1/PWExpireNotification-help.xml | 930 ------------------ .../1.0.1/PWExpireNotification.psd1 | 126 --- .../1.0.1/PWExpireNotification.psm1 | 23 - 18 files changed, 9 insertions(+), 3470 deletions(-) delete mode 100644 .gitignore delete mode 100644 Examples/SendMailMessage.ps1 delete mode 100644 LICENSE delete mode 100644 docs/Get-PWADDSExpiringPassword.md delete mode 100644 docs/Get-PWApplicationToken.md delete mode 100644 docs/Send-PWExpiringMailMessage.md delete mode 100644 docs/Set-PWEmailBody.md delete mode 100644 docs/Set-PWEmailMessagePayload.md delete mode 100644 docs/en-US/PWExpireNotification-help.xml delete mode 100644 src/PWExpireNotification/1.0.1/Functions/Get-PWADDSExpiringPassword.ps1 delete mode 100644 src/PWExpireNotification/1.0.1/Functions/Get-PWApplicationToken.ps1 delete mode 100644 src/PWExpireNotification/1.0.1/Functions/New-PWEmailBody.ps1 delete mode 100644 src/PWExpireNotification/1.0.1/Functions/New-PWEmailMessagePayload.ps1 delete mode 100644 src/PWExpireNotification/1.0.1/Functions/Send-PWExpiringMailMessage.ps1 delete mode 100644 src/PWExpireNotification/1.0.1/PWExpireNotification-help.xml delete mode 100644 src/PWExpireNotification/1.0.1/PWExpireNotification.psd1 delete mode 100644 src/PWExpireNotification/1.0.1/PWExpireNotification.psm1 diff --git a/.gitignore b/.gitignore deleted file mode 100644 index dfcfd56..0000000 --- a/.gitignore +++ /dev/null @@ -1,350 +0,0 @@ -## Ignore Visual Studio temporary files, build results, and -## files generated by popular Visual Studio add-ons. -## -## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore - -# User-specific files -*.rsuser -*.suo -*.user -*.userosscache -*.sln.docstates - -# User-specific files (MonoDevelop/Xamarin Studio) -*.userprefs - -# Mono auto generated files -mono_crash.* - -# Build results -[Dd]ebug/ -[Dd]ebugPublic/ -[Rr]elease/ -[Rr]eleases/ -x64/ -x86/ -[Aa][Rr][Mm]/ -[Aa][Rr][Mm]64/ -bld/ -[Bb]in/ -[Oo]bj/ -[Ll]og/ -[Ll]ogs/ - -# Visual Studio 2015/2017 cache/options directory -.vs/ -# Uncomment if you have tasks that create the project's static files in wwwroot -#wwwroot/ - -# Visual Studio 2017 auto generated files -Generated\ Files/ - -# MSTest test Results -[Tt]est[Rr]esult*/ -[Bb]uild[Ll]og.* - -# NUnit -*.VisualState.xml -TestResult.xml -nunit-*.xml - -# Build Results of an ATL Project -[Dd]ebugPS/ -[Rr]eleasePS/ -dlldata.c - -# Benchmark Results -BenchmarkDotNet.Artifacts/ - -# .NET Core -project.lock.json -project.fragment.lock.json -artifacts/ - -# StyleCop -StyleCopReport.xml - -# Files built by Visual Studio -*_i.c -*_p.c -*_h.h -*.ilk -*.meta -*.obj -*.iobj -*.pch -*.pdb -*.ipdb -*.pgc -*.pgd -*.rsp -*.sbr -*.tlb -*.tli -*.tlh -*.tmp -*.tmp_proj -*_wpftmp.csproj -*.log -*.vspscc -*.vssscc -.builds -*.pidb -*.svclog -*.scc - -# Chutzpah Test files -_Chutzpah* - -# Visual C++ cache files -ipch/ -*.aps -*.ncb -*.opendb -*.opensdf -*.sdf -*.cachefile -*.VC.db -*.VC.VC.opendb - -# Visual Studio profiler -*.psess -*.vsp -*.vspx -*.sap - -# Visual Studio Trace Files -*.e2e - -# TFS 2012 Local Workspace -$tf/ - -# Guidance Automation Toolkit -*.gpState - -# ReSharper is a .NET coding add-in -_ReSharper*/ -*.[Rr]e[Ss]harper -*.DotSettings.user - -# TeamCity is a build add-in -_TeamCity* - -# DotCover is a Code Coverage Tool -*.dotCover - -# AxoCover is a Code Coverage Tool -.axoCover/* -!.axoCover/settings.json - -# Visual Studio code coverage results -*.coverage -*.coveragexml - -# NCrunch -_NCrunch_* -.*crunch*.local.xml -nCrunchTemp_* - -# MightyMoose -*.mm.* -AutoTest.Net/ - -# Web workbench (sass) -.sass-cache/ - -# Installshield output folder -[Ee]xpress/ - -# DocProject is a documentation generator add-in -DocProject/buildhelp/ -DocProject/Help/*.HxT -DocProject/Help/*.HxC -DocProject/Help/*.hhc -DocProject/Help/*.hhk -DocProject/Help/*.hhp -DocProject/Help/Html2 -DocProject/Help/html - -# Click-Once directory -publish/ - -# Publish Web Output -*.[Pp]ublish.xml -*.azurePubxml -# Note: Comment the next line if you want to checkin your web deploy settings, -# but database connection strings (with potential passwords) will be unencrypted -*.pubxml -*.publishproj - -# Microsoft Azure Web App publish settings. Comment the next line if you want to -# checkin your Azure Web App publish settings, but sensitive information contained -# in these scripts will be unencrypted -PublishScripts/ - -# NuGet Packages -*.nupkg -# NuGet Symbol Packages -*.snupkg -# The packages folder can be ignored because of Package Restore -**/[Pp]ackages/* -# except build/, which is used as an MSBuild target. -!**/[Pp]ackages/build/ -# Uncomment if necessary however generally it will be regenerated when needed -#!**/[Pp]ackages/repositories.config -# NuGet v3's project.json files produces more ignorable files -*.nuget.props -*.nuget.targets - -# Microsoft Azure Build Output -csx/ -*.build.csdef - -# Microsoft Azure Emulator -ecf/ -rcf/ - -# Windows Store app package directories and files -AppPackages/ -BundleArtifacts/ -Package.StoreAssociation.xml -_pkginfo.txt -*.appx -*.appxbundle -*.appxupload - -# Visual Studio cache files -# files ending in .cache can be ignored -*.[Cc]ache -# but keep track of directories ending in .cache -!?*.[Cc]ache/ - -# Others -ClientBin/ -~$* -*~ -*.dbmdl -*.dbproj.schemaview -*.jfm -*.pfx -*.publishsettings -orleans.codegen.cs - -# Including strong name files can present a security risk -# (https://github.com/github/gitignore/pull/2483#issue-259490424) -#*.snk - -# Since there are multiple workflows, uncomment next line to ignore bower_components -# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622) -#bower_components/ - -# RIA/Silverlight projects -Generated_Code/ - -# Backup & report files from converting an old project file -# to a newer Visual Studio version. Backup files are not needed, -# because we have git ;-) -_UpgradeReport_Files/ -Backup*/ -UpgradeLog*.XML -UpgradeLog*.htm -ServiceFabricBackup/ -*.rptproj.bak - -# SQL Server files -*.mdf -*.ldf -*.ndf - -# Business Intelligence projects -*.rdl.data -*.bim.layout -*.bim_*.settings -*.rptproj.rsuser -*- [Bb]ackup.rdl -*- [Bb]ackup ([0-9]).rdl -*- [Bb]ackup ([0-9][0-9]).rdl - -# Microsoft Fakes -FakesAssemblies/ - -# GhostDoc plugin setting file -*.GhostDoc.xml - -# Node.js Tools for Visual Studio -.ntvs_analysis.dat -node_modules/ - -# Visual Studio 6 build log -*.plg - -# Visual Studio 6 workspace options file -*.opt - -# Visual Studio 6 auto-generated workspace file (contains which files were open etc.) -*.vbw - -# Visual Studio LightSwitch build output -**/*.HTMLClient/GeneratedArtifacts -**/*.DesktopClient/GeneratedArtifacts -**/*.DesktopClient/ModelManifest.xml -**/*.Server/GeneratedArtifacts -**/*.Server/ModelManifest.xml -_Pvt_Extensions - -# Paket dependency manager -.paket/paket.exe -paket-files/ - -# FAKE - F# Make -.fake/ - -# CodeRush personal settings -.cr/personal - -# Python Tools for Visual Studio (PTVS) -__pycache__/ -*.pyc - -# Cake - Uncomment if you are using it -# tools/** -# !tools/packages.config - -# Tabs Studio -*.tss - -# Telerik's JustMock configuration file -*.jmconfig - -# BizTalk build output -*.btp.cs -*.btm.cs -*.odx.cs -*.xsd.cs - -# OpenCover UI analysis results -OpenCover/ - -# Azure Stream Analytics local run output -ASALocalRun/ - -# MSBuild Binary and Structured Log -*.binlog - -# NVidia Nsight GPU debugger configuration file -*.nvuser - -# MFractors (Xamarin productivity tool) working folder -.mfractor/ - -# Local History for Visual Studio -.localhistory/ - -# BeatPulse healthcheck temp database -healthchecksdb - -# Backup folder for Package Reference Convert tool in Visual Studio 2017 -MigrationBackup/ - -# Ionide (cross platform F# VS Code tools) working folder -.ionide/ diff --git a/Examples/SendMailMessage.ps1 b/Examples/SendMailMessage.ps1 deleted file mode 100644 index bc2525b..0000000 --- a/Examples/SendMailMessage.ps1 +++ /dev/null @@ -1,47 +0,0 @@ -[cmdletbinding()] -param ( - $CredentialPath = '', - $clientID = '', - $resource = 'https://graph.microsoft.com', - $tenantName = '', - $SendEmailAccount = '', - $TestAddress = '', - $TextToAddToEmail = "To change your password on a PC press CTRL ALT Delete and choose Change Password", - $Signature = "Jolly B. Admin", - $Logging = $true, - $ExpireInDaysThreshold = 39 -) - -#Token -$sec = (Import-Clixml -Path $CredentialPath).GetNetworkCredential().Password - -$param = @{ - clientID = $clientID - clientSecret = $sec - resource = $resource - tenantName = $tenantName -} - -$token = Get-PWApplicationToken @param - -#Get all users - -if ($token) { - $ListOfUsers = Get-PWADDSExpiringPassword - Write-Verbose ("User Account: {0}, ExpiresOn: {1}, Days: {2} " -f $ListOfUsers[0].Name, $ListOfUsers[0].PasswordExpiresOn, $ListOfUsers[0].PasswordDaystoExpire) - foreach ($user in $ListOfUsers[0]) { - $params = @{ - Resource = $resource - SendEmailAccount = $SendEmailAccount - Token = $token - TestAddress = $TestAddress - ADAccount = $user - ExpireInDaysThreshold = $ExpireInDaysThreshold - TextToAdd = $TextToAddToEmail - Signature = $Signature - Logging = $true - - } - Send-PWExpiringMailMessage @params -Verbose - } -} \ No newline at end of file diff --git a/LICENSE b/LICENSE deleted file mode 100644 index d3426e0..0000000 --- a/LICENSE +++ /dev/null @@ -1,21 +0,0 @@ -MIT License - -Copyright (c) 2022 Daniel Carroll - -Permission is hereby granted, free of charge, to any person obtaining a copy -of this software and associated documentation files (the "Software"), to deal -in the Software without restriction, including without limitation the rights -to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -copies of the Software, and to permit persons to whom the Software is -furnished to do so, subject to the following conditions: - -The above copyright notice and this permission notice shall be included in all -copies or substantial portions of the Software. - -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -SOFTWARE. diff --git a/README.md b/README.md index d02c341..c4c889d 100644 --- a/README.md +++ b/README.md @@ -1,92 +1,14 @@ -# ADDSPasswordNotification +# PWExpireNotification — moved -Solution to send password expiring notifications to ADDS users using O365 Mailbox. It is suggested that you review the article located here: https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/microsoft-365-password-expiration-notification-email-solution/ba-p/2796353 +This repository has **moved to Forgejo** and is no longer maintained here. -## Getting Started +➡️ **New location:** https://forgejo.oskamp.info/ivooskamp/PWExpireNotification.git -1. First Save the below script into a directory. A suggested name would be PWExpireNotification.ps1 +Please update your remotes: - ```PowerShell - [cmdletbinding()] - param ( - $CredentialPath = '', - $clientID = '', - $resource = 'https://graph.microsoft.com', - $tenantName = '', - $SendEmailAccount = '', - $TestAddress = '', - $TextToAddToEmail = @" - To change your password on a PC press CTRL ALT Delete and choose Change Password - Line2 goes here - Line 3 goes here - "@, - $Signature = "Jolly B. Admin", - $Logging = $true, - $ExpireInDaysThreshold = 39 - ) +```bash +git remote set-url origin https://forgejo.oskamp.info/ivooskamp/PWExpireNotification.git +``` - #Token - $sec = (Import-Clixml -Path $CredentialPath).GetNetworkCredential().Password - - $param = @{ - clientID = $clientID - clientSecret = $sec - resource = $resource - tenantName = $tenantName - } - - $token = Get-PWApplicationToken @param - - #Get all users - - if ($token) { - $ListOfUsers = Get-PWADDSExpiringPassword - Write-Verbose ("User Account: {0}, ExpiresOn: {1}, Days: {2} " -f $ListOfUsers[0].Name, $ListOfUsers[0].PasswordExpiresOn, $ListOfUsers[0].PasswordDaystoExpire) - foreach ($user in $ListOfUsers) { - $params = @{ - Resource = $resource - SendEmailAccount = $SendEmailAccount - Token = $token - TestAddress = $TestAddress - ADAccount = $user - ExpireInDaysThreshold = $ExpireInDaysThreshold - TextToAdd = $TextToAddToEmail - Signature = $Signature - Logging = $true - - } - Send-PWExpiringMailMessage @params -Verbose - } - } - ``` - -2. Install the PWExpireNotification PowerShell module. You can do this by copying the module directly from GitHub into your local computer PowerShell module store, or running the following PowerShell command: - - ```PowerShell - Install-module PWExpireNotification, - ``` - -3. Create an application within AAD and provide it Mail.Send Graph permissions - -4. Create a client secret for the application. Do not forget to copy the secret to your clipboard or you will be forcet to recreate it. - -5. Create a shared mailbox within O365 - -6. Copy the clientID, tenantName, and shared mailbox name and place in the parameters at the top of the script -#The clientID is the Application ID created above. - - ```PowerShell - $clientID = 'ClientID GUID', - $tenantName = 'mytenant.onmicrosoft.com', - $SendEmailAccount = 'mysharedmailbox.mydomain.com', - ``` - -7. If testing enter in the test address that all emails will go to within the $TestAddress paramter - -8. Save the application secret to a PScredential file. - - ```PowerShell - $appsecret = 'secret' - $cred = [system.management.automation.pscredential]::new('application',(Convertto-SecureString $appsecret -asplaintext -force)) - $cred | Export-Clixml -path c:\temp\app.credential - ``` +The full history, branches, and files now live at the new location. This Gitea +copy has been emptied intentionally and is kept only as a redirect. diff --git a/docs/Get-PWADDSExpiringPassword.md b/docs/Get-PWADDSExpiringPassword.md deleted file mode 100644 index f7268ba..0000000 --- a/docs/Get-PWADDSExpiringPassword.md +++ /dev/null @@ -1,101 +0,0 @@ ---- -external help file: PWExpireNotification-help.xml -Module Name: PWExpireNotification -online version: -schema: 2.0.0 ---- - -# Get-PWADDSExpiringPassword - -## SYNOPSIS -This cmdlet obtains all users within the domain that have a password expiring at some point - -## SYNTAX - -``` -Get-PWADDSExpiringPassword [[-ExpireInDays] ] [[-ADFilter] ] [-IncludeAll] - [] -``` - -## DESCRIPTION -This cmdlet obtains all users within the domain that have a password expiring at some point -and omits those users that have an empty passwordlastset attribute - -## EXAMPLES - -### Example 1 -```powershell -PS C:\> Get-PWADDSExpiringPassword -``` - -Gets all users and their password expiration except if the user is disabled, -,the passwword is already expired, or the password is set to never expire. - -### Example 1 -```powershell -PS C:\> Get-PWADDSExpiringPassword -IncludeAll -``` - -Gets all users and their password expiration except if the -password less set is null. - -## PARAMETERS - -### -ADFilter -Allows the ability to scope query to a specific location or user attribute - -```yaml -Type: ScriptBlock -Parameter Sets: (All) -Aliases: - -Required: False -Position: 1 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -ExpireInDays -Filters the output to return only users with passwords that expire less than or equal to the day - -```yaml -Type: Object -Parameter Sets: (All) -Aliases: - -Required: False -Position: 0 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -IncludeAll -Enables the return of all users even if the the password never expires. - -```yaml -Type: SwitchParameter -Parameter Sets: (All) -Aliases: - -Required: False -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### CommonParameters -This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216). - -## INPUTS - -### None - -## OUTPUTS - -### System.Object -## NOTES - -## RELATED LINKS diff --git a/docs/Get-PWApplicationToken.md b/docs/Get-PWApplicationToken.md deleted file mode 100644 index 1200807..0000000 --- a/docs/Get-PWApplicationToken.md +++ /dev/null @@ -1,113 +0,0 @@ ---- -external help file: PWExpireNotification-help.xml -Module Name: PWExpireNotification -online version: -schema: 2.0.0 ---- - -# Get-PWApplicationToken - -## SYNOPSIS -Obtains an Application token using a client secret - -## SYNTAX - -``` -Get-PWApplicationToken [-clientID] [-clientSecret] [-Resource] - [-tenantName] [] -``` - -## DESCRIPTION -Intended to be used to obtain an token for an application that has Mail.Send permissions within Graph. - -## EXAMPLES - -### Example 1 -```powershell -PS C:\> $param = @{ - clientID = $clientID - clientSecret = $sec - resource = $resource - tenantName = $tenantName -} -$token = Get-PWApplicationToken @param -``` - -Providing the client ID, secret, graph resource, and tenantname, returns an OAuth token for the specified application - -## PARAMETERS - -### -Resource -Used to identify the graph resource where the token will be used. - -```yaml -Type: String -Parameter Sets: (All) -Aliases: -Accepted values: https://graph.microsoft.com, https://graph.microsoft.us, https://dod-graph.microsoft.us - -Required: True -Position: 2 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -clientID -Application ID of the AAD application - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: 0 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -clientSecret -Client secret of the application - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: 1 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -tenantName -Full TenantName such as mydomain.onmicrosoft.com - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: 3 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### CommonParameters -This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216). - -## INPUTS - -### None - -## OUTPUTS - -### System.Object -## NOTES - -## RELATED LINKS diff --git a/docs/Send-PWExpiringMailMessage.md b/docs/Send-PWExpiringMailMessage.md deleted file mode 100644 index 061da83..0000000 --- a/docs/Send-PWExpiringMailMessage.md +++ /dev/null @@ -1,210 +0,0 @@ ---- -external help file: PWExpireNotification-help.xml -Module Name: PWExpireNotification -online version: -schema: 2.0.0 ---- - -# Send-PWExpiringMailMessage - -## SYNOPSIS -Used to send password expiration notification of ADDS Users - -## SYNTAX - -``` -Send-PWExpiringMailMessage -Resource -SendEmailAccount -Token - [-TestAddress ] -ADAccount -Signature -TextToAdd - [-ExpireInDaysThreshold ] [-Logging] [-LogFile ] [] -``` - -## DESCRIPTION -Used to send password expiration notification of ADDS Users - -## EXAMPLES - -### Example 1 -```powershell -PS C:\>$params = @{ - Resource = $resource - SendEmailAccount = $SendEmailAccount - Token = $token - TestAddress = $TestAddress - ADAccount = $user - ExpireInDaysThreshold = $ExpireInDaysThreshold - TextToAdd = $TextToAddToEmail - Signature = $Signature - Logging = $true - - } - Send-PWExpiringMailMessage @params -Verbose -``` - -This command takes the input from the $params hashtable and then sends an email to the test address versus the configured user. This would be used in a test scenario. Prior to live implemenation. - -## PARAMETERS - -### -ADAccount -The ADUser account object - -```yaml -Type: PSObject -Parameter Sets: (All) -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -ExpireInDaysThreshold -The threshold for limiting at what time a user would be notified based on when their password expires. - -```yaml -Type: Int32 -Parameter Sets: (All) -Aliases: - -Required: False -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -LogFile -If you want to log each run of this function this will enable logging and display what users were notified placing the logfile in the specified path. - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: False -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Logging -Enable logging and output the logfile to the current working directory. - -```yaml -Type: SwitchParameter -Parameter Sets: (All) -Aliases: - -Required: False -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Resource -The graph resource that will be used - -```yaml -Type: String -Parameter Sets: (All) -Aliases: -Accepted values: https://graph.microsoft.com, https://graph.microsoft.us, https://dod-graph.microsoft.us - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -SendEmailAccount -The account that will be used to send the mail message. e.g. Shared O365 Mailbox - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Signature -The signature as a string that you would like within your email body. - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -TestAddress -Used for testing, all email messages will go to this address versus the end user. - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: False -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -TextToAdd -A free form string that will be within the email message body below the default line containing the number of days remaining before their password expires. - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Token -The token that will be used to send the message - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### CommonParameters -This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216). - -## INPUTS - -### None - -## OUTPUTS - -### System.Object -## NOTES - -## RELATED LINKS diff --git a/docs/Set-PWEmailBody.md b/docs/Set-PWEmailBody.md deleted file mode 100644 index eccf57e..0000000 --- a/docs/Set-PWEmailBody.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -external help file: PWExpireNotification-help.xml -Module Name: PWExpireNotification -online version: -schema: 2.0.0 ---- - -# Set-PWEmailBody - -## SYNOPSIS -This cmdlet is used to configure the email message body in JSON format for configuring the JSON payload to graph - -## SYNTAX - -``` -Set-PWEmailBody [[-Subject] ] [[-Importance] ] [[-Message] ] [[-EmailAddress] ] - [] -``` - -## DESCRIPTION -This cmdlet is used to configure the email message body in JSON format for configuring the JSON payload to graph - -## EXAMPLES - -### Example 1 -```powershell -PS C:\> Set-PWEmailBody -Subject "Your Password is Expiring in 10 Days" ` - -Importance "High" ` - -Message "Please change soon" ` - -EmailAddress "olduser@mycompany.com" -``` - -Prepares the message section of the JSON payload to be submitted to Graph for sending the email message - -## PARAMETERS - -### -EmailAddress -Email address to receive the email - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: False -Position: 3 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Importance -Set the Importance of the email: High or Low - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: False -Position: 1 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Message -The message body - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: False -Position: 2 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Subject -Subject line of the email - -```yaml -Type: String -Parameter Sets: (All) -Aliases: - -Required: False -Position: 0 -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### CommonParameters -This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216). - -## INPUTS - -### None - -## OUTPUTS - -### System.Object -## NOTES - -## RELATED LINKS diff --git a/docs/Set-PWEmailMessagePayload.md b/docs/Set-PWEmailMessagePayload.md deleted file mode 100644 index 2607fa2..0000000 --- a/docs/Set-PWEmailMessagePayload.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -external help file: PWExpireNotification-help.xml -Module Name: PWExpireNotification -online version: -schema: 2.0.0 ---- - -# Set-PWEmailMessagePayload - -## SYNOPSIS -Creates the full message paylod of to send to Graph API - -## SYNTAX - -### Message -``` -Set-PWEmailMessagePayload -TextToAdd -ADAccount -Signature [] -``` - -### Subject -``` -Set-PWEmailMessagePayload -ADAccount -Subject [] -``` - -## DESCRIPTION -Creates the full message paylod of to send to Graph API - -## EXAMPLES - -### Example 1 -```powershell -PS C:\> Set-PWEmailMessagePayload -TextToAdd $TextToAdd -ADAccount $ADAccount -Signature $Signature -``` - -Prepares the json payload for graph - -## PARAMETERS - -### -ADAccount -The account that is expiring - -```yaml -Type: PSObject -Parameter Sets: (All) -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Signature -Signature to be used within the email - -```yaml -Type: PSObject -Parameter Sets: Message -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -Subject -The email subject - -```yaml -Type: String -Parameter Sets: Subject -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### -TextToAdd -Any additional text to add to the email body - -```yaml -Type: String -Parameter Sets: Message -Aliases: - -Required: True -Position: Named -Default value: None -Accept pipeline input: False -Accept wildcard characters: False -``` - -### CommonParameters -This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see [about_CommonParameters](http://go.microsoft.com/fwlink/?LinkID=113216). - -## INPUTS - -### None - -## OUTPUTS - -### System.Object -## NOTES - -## RELATED LINKS diff --git a/docs/en-US/PWExpireNotification-help.xml b/docs/en-US/PWExpireNotification-help.xml deleted file mode 100644 index f459155..0000000 --- a/docs/en-US/PWExpireNotification-help.xml +++ /dev/null @@ -1,930 +0,0 @@ - - - - - Get-PWADDSExpiringPassword - Get - PWADDSExpiringPassword - - This cmdlet obtains all users within the domain that have a password expiring at some point - - - - This cmdlet obtains all users within the domain that have a password expiring at some point and omits those users that have an empty passwordlastset attribute - - - - Get-PWADDSExpiringPassword - - ExpireInDays - - Filters the output to return only users with passwords that expire less than or equal to the day - - Object - - Object - - - None - - - ADFilter - - Allows the ability to scope query to a specific location or user attribute - - ScriptBlock - - ScriptBlock - - - None - - - IncludeAll - - Enables the return of all users even if the the password never expires. - - - SwitchParameter - - - False - - - - - - ADFilter - - Allows the ability to scope query to a specific location or user attribute - - ScriptBlock - - ScriptBlock - - - None - - - ExpireInDays - - Filters the output to return only users with passwords that expire less than or equal to the day - - Object - - Object - - - None - - - IncludeAll - - Enables the return of all users even if the the password never expires. - - SwitchParameter - - SwitchParameter - - - False - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> Get-PWADDSExpiringPassword - - Gets all users and their password expiration except if the user is disabled, ,the passwword is already expired, or the password is set to never expire. - - - - -------------------------- Example 1 -------------------------- - PS C:\> Get-PWADDSExpiringPassword -IncludeAll - - Gets all users and their password expiration except if the password less set is null. - - - - - - - - - Get-PWApplicationToken - Get - PWApplicationToken - - Obtains an Application token using a client secret - - - - Intended to be used to obtain an token for an application that has Mail.Send permissions within Graph. - - - - Get-PWApplicationToken - - clientID - - Application ID of the AAD application - - String - - String - - - None - - - clientSecret - - Client secret of the application - - String - - String - - - None - - - Resource - - Used to identify the graph resource where the token will be used. - - - https://graph.microsoft.com - https://graph.microsoft.us - https://dod-graph.microsoft.us - - String - - String - - - None - - - tenantName - - Full TenantName such as mydomain.onmicrosoft.com - - String - - String - - - None - - - - - - Resource - - Used to identify the graph resource where the token will be used. - - String - - String - - - None - - - clientID - - Application ID of the AAD application - - String - - String - - - None - - - clientSecret - - Client secret of the application - - String - - String - - - None - - - tenantName - - Full TenantName such as mydomain.onmicrosoft.com - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> $param = @{ - clientID = $clientID - clientSecret = $sec - resource = $resource - tenantName = $tenantName -} -$token = Get-PWApplicationToken @param - - Providing the client ID, secret, graph resource, and tenantname, returns an OAuth token for the specified application - - - - - - - - Send-PWExpiringMailMessage - Send - PWExpiringMailMessage - - Used to send password expiration notification of ADDS Users - - - - Used to send password expiration notification of ADDS Users - - - - Send-PWExpiringMailMessage - - ADAccount - - The ADUser account object - - PSObject - - PSObject - - - None - - - ExpireInDaysThreshold - - The threshold for limiting at what time a user would be notified based on when their password expires. - - Int32 - - Int32 - - - None - - - LogFile - - If you want to log each run of this function this will enable logging and display what users were notified placing the logfile in the specified path. - - String - - String - - - None - - - Logging - - Enable logging and output the logfile to the current working directory. - - - SwitchParameter - - - False - - - Resource - - The graph resource that will be used - - - https://graph.microsoft.com - https://graph.microsoft.us - https://dod-graph.microsoft.us - - String - - String - - - None - - - SendEmailAccount - - The account that will be used to send the mail message. e.g. Shared O365 Mailbox - - String - - String - - - None - - - Signature - - The signature as a string that you would like within your email body. - - String - - String - - - None - - - TestAddress - - Used for testing, all email messages will go to this address versus the end user. - - String - - String - - - None - - - TextToAdd - - A free form string that will be within the email message body below the default line containing the number of days remaining before their password expires. - - String - - String - - - None - - - Token - - The token that will be used to send the message - - String - - String - - - None - - - - - - ADAccount - - The ADUser account object - - PSObject - - PSObject - - - None - - - ExpireInDaysThreshold - - The threshold for limiting at what time a user would be notified based on when their password expires. - - Int32 - - Int32 - - - None - - - LogFile - - If you want to log each run of this function this will enable logging and display what users were notified placing the logfile in the specified path. - - String - - String - - - None - - - Logging - - Enable logging and output the logfile to the current working directory. - - SwitchParameter - - SwitchParameter - - - False - - - Resource - - The graph resource that will be used - - String - - String - - - None - - - SendEmailAccount - - The account that will be used to send the mail message. e.g. Shared O365 Mailbox - - String - - String - - - None - - - Signature - - The signature as a string that you would like within your email body. - - String - - String - - - None - - - TestAddress - - Used for testing, all email messages will go to this address versus the end user. - - String - - String - - - None - - - TextToAdd - - A free form string that will be within the email message body below the default line containing the number of days remaining before their password expires. - - String - - String - - - None - - - Token - - The token that will be used to send the message - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\>$params = @{ - Resource = $resource - SendEmailAccount = $SendEmailAccount - Token = $token - TestAddress = $TestAddress - ADAccount = $user - ExpireInDaysThreshold = $ExpireInDaysThreshold - TextToAdd = $TextToAddToEmail - Signature = $Signature - Logging = $true - - } - Send-PWExpiringMailMessage @params -Verbose - - This command takes the input from the $params hashtable and then sends an email to the test address versus the configured user. This would be used in a test scenario. Prior to live implemenation. - - - - - - - - Set-PWEmailBody - Set - PWEmailBody - - This cmdlet is used to configure the email message body in JSON format for configuring the JSON payload to graph - - - - This cmdlet is used to configure the email message body in JSON format for configuring the JSON payload to graph - - - - Set-PWEmailBody - - Subject - - Subject line of the email - - String - - String - - - None - - - Importance - - Set the Importance of the email: High or Low - - String - - String - - - None - - - Message - - The message body - - String - - String - - - None - - - EmailAddress - - Email address to receive the email - - String - - String - - - None - - - - - - EmailAddress - - Email address to receive the email - - String - - String - - - None - - - Importance - - Set the Importance of the email: High or Low - - String - - String - - - None - - - Message - - The message body - - String - - String - - - None - - - Subject - - Subject line of the email - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> Set-PWEmailBody -Subject "Your Password is Expiring in 10 Days" ` - -Importance "High" ` - -Message "Please change soon" ` - -EmailAddress "olduser@mycompany.com" - - Prepares the message section of the JSON payload to be submitted to Graph for sending the email message - - - - - - - - Set-PWEmailMessagePayload - Set - PWEmailMessagePayload - - Creates the full message paylod of to send to Graph API - - - - Creates the full message paylod of to send to Graph API - - - - Set-PWEmailMessagePayload - - ADAccount - - The account that is expiring - - PSObject - - PSObject - - - None - - - Signature - - Signature to be used within the email - - PSObject - - PSObject - - - None - - - TextToAdd - - Any additional text to add to the email body - - String - - String - - - None - - - - Set-PWEmailMessagePayload - - ADAccount - - The account that is expiring - - PSObject - - PSObject - - - None - - - Subject - - The email subject - - String - - String - - - None - - - - - - ADAccount - - The account that is expiring - - PSObject - - PSObject - - - None - - - Signature - - Signature to be used within the email - - PSObject - - PSObject - - - None - - - Subject - - The email subject - - String - - String - - - None - - - TextToAdd - - Any additional text to add to the email body - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> Set-PWEmailMessagePayload -TextToAdd $TextToAdd -ADAccount $ADAccount -Signature $Signature - - Prepares the json payload for graph - - - - - - \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/Functions/Get-PWADDSExpiringPassword.ps1 b/src/PWExpireNotification/1.0.1/Functions/Get-PWADDSExpiringPassword.ps1 deleted file mode 100644 index 5755831..0000000 --- a/src/PWExpireNotification/1.0.1/Functions/Get-PWADDSExpiringPassword.ps1 +++ /dev/null @@ -1,67 +0,0 @@ -Function Get-PWADDSExpiringPassword { - [cmdletbinding()] - - [OutputType([System.Collections.Generic.List[PSCustomObject]])] - - param ( - [int]$ExpireInDays = 30, - - [scriptblock]$ADFilter, - - [switch]$IncludeAll - ) - begin { - #ToDO - # Email Attribute selection vs. current single attribute. Mail, custom attribute - # Still needs logging - } - Process { - # System Settings - $Today = Get-Date - # End System Settings - if ($PSBoundParameters.ContainsKey('ADFilter' )) { - $users = get-aduser -filter $ADFilter -Properties Name, PasswordNeverExpires, PasswordExpired, PasswordLastSet, EmailAddress - if ($PSBoundParameters.ContainsKey('IncludeAll')) { - $users = $users | Where-Object {$null -ne $PSItem.PasswordLastSet} - } - else { - $users = $users | Where-Object { ($PSItem.Enabled -eq $true) -and ($PSItem.PasswordNeverExpires -eq $false) -and ($PSItem.PasswordExpired -eq $false) } - } - } - else { - $users = Get-ADUser -filter * -Properties Name, PasswordNeverExpires, PasswordExpired, PasswordLastSet, EmailAddress - if ($PSBoundParameters.ContainsKey('IncludeAll')) { - $users = $users | Where-Object {$null -ne $PSItem.PasswordLastSet} - } - else { - $users = $users | Where-Object { ($PSItem.Enabled -eq $true) -and ($PSItem.PasswordNeverExpires -eq $false) -and ($PSItem.PasswordExpired -eq $false) } - } - } - $DefaultmaxPasswordAge = (Get-ADDefaultDomainPasswordPolicy).MaxPasswordAge - - $UserCollection = [System.Collections.Generic.List[pscustomobject]]::new() - - foreach ($user in $users) { - Write-Verbose "$($user.Name)" - $PasswordPol = (Get-AduserResultantPasswordPolicy $user) - # Check for Fine Grained Password - if ($PasswordPol) { - $maxPasswordAge = ($PasswordPol).MaxPasswordAge - } - else{ - # No FGP set to Domain Default - $maxPasswordAge = $DefaultmaxPasswordAge - } - $UserCollection.Add( - [pscustomobject]@{ - Name = $user.Name - EmailAddress = $user.EmailAddress - PasswordExpiresOn = $user.PasswordLastSet + $maxPasswordAge - PasswordDaystoExpire = (New-TimeSpan -Start $Today -End ($user.PasswordLastSet + $maxPasswordAge)).Days - } - ) - } - return $UserCollection - } - end {} -} \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/Functions/Get-PWApplicationToken.ps1 b/src/PWExpireNotification/1.0.1/Functions/Get-PWApplicationToken.ps1 deleted file mode 100644 index 6ad8fe2..0000000 --- a/src/PWExpireNotification/1.0.1/Functions/Get-PWApplicationToken.ps1 +++ /dev/null @@ -1,48 +0,0 @@ -function Get-PWApplicationToken { - [cmdletbinding()] - param ( - [parameter(Mandatory = $true)] - [string]$clientID, - - [parameter(Mandatory = $true)] - [string]$clientSecret, - - [parameter(Mandatory = $true)] - [ValidateSet( - 'https://graph.microsoft.com','https://graph.microsoft.us','https://dod-graph.microsoft.us' - )] - [string]$Resource, - - [parameter(Mandatory = $true)] - [string]$tenantName - ) - - - begin{ - if ($Resource -eq 'https://graph.microsoft.com') { $AADLoginURI = 'https://login.microsoftonline.com' } - elseif ($Resource -eq 'https://graph.microsoft.us') { $AADLoginURI = 'https://login.microsoftonline.us' } - elseif ($Resource -eq 'https://dod-graph.microsoft.us') { $AADLoginURI = 'https://login.microsoftonline.us' } - } - process{ - Try { - $params = @{ - Uri = "$AADLoginURI/$TenantName/oauth2/v2.0/token" - Method = "POST" - ErrorAction = "Stop" - } - $ReqTokenBody = @{ - Grant_Type = "client_credentials" - Scope = "$($Resource)/.default" - client_Id = $clientID - Client_Secret = $clientSecret - } - $TokenResponse = Invoke-RestMethod @params -Body $ReqTokenBody - return $TokenResponse.access_token - } - catch { - $_ - #[System.ApplicationException]::new("Failed to aquire token") - } - } - end{} -} \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/Functions/New-PWEmailBody.ps1 b/src/PWExpireNotification/1.0.1/Functions/New-PWEmailBody.ps1 deleted file mode 100644 index 3cea58c..0000000 --- a/src/PWExpireNotification/1.0.1/Functions/New-PWEmailBody.ps1 +++ /dev/null @@ -1,29 +0,0 @@ -function New-PWEmailBody { - [cmdletbinding(SupportsShouldProcess=$true)] - param ( - [string]$Subject, - [string]$Importance, - [String]$Message, - [string]$EmailAddress - ) - if ($PSCmdlet.ShouldProcess(("Subject:{0}; Message: {1}; Recipient(s):{2}" -f $Subject,$Message,$EmailAddress))) { - $body = [pscustomobject]@{ - Message = [pscustomobject]@{ - Subject = $subject - importance = $importance - Body = [pscustomobject]@{ - ContentType = "Text" - Content = $Message - } - ToRecipients = [array][pscustomobject]@{ - EmailAddress = [pscustomobject]@{ - Address = $emailaddress - } - } - } - SaveToSentItems = $false - isDraft = $false - } - return $body - } -} \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/Functions/New-PWEmailMessagePayload.ps1 b/src/PWExpireNotification/1.0.1/Functions/New-PWEmailMessagePayload.ps1 deleted file mode 100644 index 29e8901..0000000 --- a/src/PWExpireNotification/1.0.1/Functions/New-PWEmailMessagePayload.ps1 +++ /dev/null @@ -1,61 +0,0 @@ -Function New-PWEmailMessagePayload { - [cmdletbinding(SupportsShouldProcess=$true)] - param ( - [parameter( - Mandatory=$true, - ParameterSetName = 'Message' - )] - [string]$TextToAdd, - - [parameter( - Mandatory=$true, - ParameterSetName = 'Message' - )] - [parameter( - Mandatory=$true, - ParameterSetName = 'Subject' - )] - [pscustomobject]$ADAccount, - - [parameter( - Mandatory=$true, - ParameterSetName = 'Message' - )] - [pscustomobject]$Signature, - - [parameter( - Mandatory=$true, - ParameterSetName = 'Subject' - )] - [String]$Subject - ) - $text = @" -Dear {0}, - -Your Password will expire {1} - -$TextToAdd - -Thanks, - -$Signature -"@ - - if ($PSCmdlet.ShouldProcess("Creating new {0}" -f $PSCmdlet.ParameterSetName)) { - - if (($ADAccount.PasswordDaystoExpire) -gt "1") { - $messageDays = "in " + "$($ADAccount.PasswordDaystoExpire)" + " days." - } - else { - $messageDays = "today." - } - if ($PSBoundParameters.ContainsKey('Signature')) { - - $outtext = ($text -f $ADAccount.Name, $messageDays) - } - elseif ($PSBoundParameters.ContainsKey('Subject')) { - $outtext = ($Subject -f $messageDays) - } - return $outtext - } -} \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/Functions/Send-PWExpiringMailMessage.ps1 b/src/PWExpireNotification/1.0.1/Functions/Send-PWExpiringMailMessage.ps1 deleted file mode 100644 index 08b302c..0000000 --- a/src/PWExpireNotification/1.0.1/Functions/Send-PWExpiringMailMessage.ps1 +++ /dev/null @@ -1,107 +0,0 @@ -function Send-PWExpiringMailMessage { - [cmdletbinding()] - param( - [parameter(Mandatory = $true)] - [ValidateSet( - 'https://graph.microsoft.com','https://graph.microsoft.us','https://dod-graph.microsoft.us' - )] - [string]$Resource, - - [parameter(Mandatory = $true)] - [string]$SendEmailAccount, - - [parameter(Mandatory = $True)] - [string]$Token, - - [parameter(Mandatory = $false)] - [string]$TestAddress, - - [parameter(Mandatory = $true)] - [PSCustomObject]$ADAccount, - - [parameter(Mandatory = $true)] - [string]$Signature, - - [parameter(Mandatory = $true)] - [string]$TextToAdd, - - [int]$ExpireInDaysThreshold = 30, - - [Parameter( - ParameterSetName = 'Log' - )] - [switch]$Logging, - - [Parameter( - ParameterSetName = 'Log' - )] - [string]$LogFile = "$($PWD.Path)\Expiring.csv" # ie. c:\mylog.csv - ) - begin{ - <#TODO - Update handling of logging for Notified - #> - if (!$token) { - Write-Error "No Token. Please provide a valide token" - Break - } - } - - process{ - if ($PSBoundParameters.ContainsKey('Logging')) { - # Test Log File Path - $logfilePath = (Test-Path $logFile) - if (($logFilePath) -ne "True") { - # Create CSV File and Headers - $null = New-Item $logfile -ItemType File - Add-Content $logfile "Date,Name,EmailAddress,DaystoExpire,ExpiresOn,Notified" - } - } - # If Testing Is Enabled - Email Administrator - Write-Verbose ("User Account: {0}, ExpiresOn: {1}, Days: {2} " -f $ADAccount.Name, $ADAccount.PasswordExpiresOn, $ADAccount.PasswordDaystoExpire) - if ($TestAddress) { - $emailAddress = $TestAddress - } - - # If a user has no email address listed - elseif (!($ADAccount.EmailAddress)) { - $emailAddress = $TestAddress - if (!($emailAddress)) {throw "No email address"} - } - else { $emailAddress = $ADAccount.EmailAddress } - Write-Verbose ("EmailAddress to recieve email: {0}" -f $emailAddress) - # Email Subject Set Here - $subject= New-PWEmailMessagePayload -ADAccount $ADAccount -Subject "Your password will expire {0}" - $Message = New-PWEmailMessagePayload -TextToAdd $TextToAdd -ADAccount $ADAccount -Signature $Signature - $body = New-PWEmailBody -Subject $subject -Importance 'High' -Message $Message -EmailAddress $emailAddress - - #Send the email message - if (($ADAccount.PasswordDaystoExpire -ge "0") -and ($ADAccount.PasswordDaystoExpire -le $ExpireInDaysThreshold)) { - $sent = "Yes" - # If Logging is Enabled Log Details - if ($PSBoundParameters.ContainsKey('Logging')) { - Add-Content $logfile "$([datetime]::Today.ToShortDateString()),$($ADAccount.Name),$emailaddress,$($ADAccount.PasswordDaystoExpire),$($ADAccount.PasswordExpiresOn),$sent" - } - Try { - $apiUrl = "$resource/v1.0/users/$SendEmailAccount/sendMail" - Write-Verbose $apiUrl - Write-Verbose ("Using Token: {0}" -f $Token) - $bodyson = $body | ConvertTo-Json -Depth 20 -Compress - Write-Verbose ("Payload: {0}" -f $bodyson) - Invoke-RestMethod -Headers @{Authorization = "Bearer $($token)"} -Uri $apiUrl -Body $bodyson -Method Post -ContentType 'application/json' - } - Catch { - $_ - } - } - else{ - $sent = "No" - # If Logging is Enabled Log Details - if ($PSBoundParameters.ContainsKey('Logging')) { - Add-Content $logfile "$([datetime]::Today.ToShortDateString()),$($ADAccount.Name),$emailaddress,$($ADAccount.PasswordDaystoExpire),$($ADAccount.PasswordExpiresOn),$sent" - } - } - } - - end{} -} \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/PWExpireNotification-help.xml b/src/PWExpireNotification/1.0.1/PWExpireNotification-help.xml deleted file mode 100644 index f459155..0000000 --- a/src/PWExpireNotification/1.0.1/PWExpireNotification-help.xml +++ /dev/null @@ -1,930 +0,0 @@ - - - - - Get-PWADDSExpiringPassword - Get - PWADDSExpiringPassword - - This cmdlet obtains all users within the domain that have a password expiring at some point - - - - This cmdlet obtains all users within the domain that have a password expiring at some point and omits those users that have an empty passwordlastset attribute - - - - Get-PWADDSExpiringPassword - - ExpireInDays - - Filters the output to return only users with passwords that expire less than or equal to the day - - Object - - Object - - - None - - - ADFilter - - Allows the ability to scope query to a specific location or user attribute - - ScriptBlock - - ScriptBlock - - - None - - - IncludeAll - - Enables the return of all users even if the the password never expires. - - - SwitchParameter - - - False - - - - - - ADFilter - - Allows the ability to scope query to a specific location or user attribute - - ScriptBlock - - ScriptBlock - - - None - - - ExpireInDays - - Filters the output to return only users with passwords that expire less than or equal to the day - - Object - - Object - - - None - - - IncludeAll - - Enables the return of all users even if the the password never expires. - - SwitchParameter - - SwitchParameter - - - False - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> Get-PWADDSExpiringPassword - - Gets all users and their password expiration except if the user is disabled, ,the passwword is already expired, or the password is set to never expire. - - - - -------------------------- Example 1 -------------------------- - PS C:\> Get-PWADDSExpiringPassword -IncludeAll - - Gets all users and their password expiration except if the password less set is null. - - - - - - - - - Get-PWApplicationToken - Get - PWApplicationToken - - Obtains an Application token using a client secret - - - - Intended to be used to obtain an token for an application that has Mail.Send permissions within Graph. - - - - Get-PWApplicationToken - - clientID - - Application ID of the AAD application - - String - - String - - - None - - - clientSecret - - Client secret of the application - - String - - String - - - None - - - Resource - - Used to identify the graph resource where the token will be used. - - - https://graph.microsoft.com - https://graph.microsoft.us - https://dod-graph.microsoft.us - - String - - String - - - None - - - tenantName - - Full TenantName such as mydomain.onmicrosoft.com - - String - - String - - - None - - - - - - Resource - - Used to identify the graph resource where the token will be used. - - String - - String - - - None - - - clientID - - Application ID of the AAD application - - String - - String - - - None - - - clientSecret - - Client secret of the application - - String - - String - - - None - - - tenantName - - Full TenantName such as mydomain.onmicrosoft.com - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> $param = @{ - clientID = $clientID - clientSecret = $sec - resource = $resource - tenantName = $tenantName -} -$token = Get-PWApplicationToken @param - - Providing the client ID, secret, graph resource, and tenantname, returns an OAuth token for the specified application - - - - - - - - Send-PWExpiringMailMessage - Send - PWExpiringMailMessage - - Used to send password expiration notification of ADDS Users - - - - Used to send password expiration notification of ADDS Users - - - - Send-PWExpiringMailMessage - - ADAccount - - The ADUser account object - - PSObject - - PSObject - - - None - - - ExpireInDaysThreshold - - The threshold for limiting at what time a user would be notified based on when their password expires. - - Int32 - - Int32 - - - None - - - LogFile - - If you want to log each run of this function this will enable logging and display what users were notified placing the logfile in the specified path. - - String - - String - - - None - - - Logging - - Enable logging and output the logfile to the current working directory. - - - SwitchParameter - - - False - - - Resource - - The graph resource that will be used - - - https://graph.microsoft.com - https://graph.microsoft.us - https://dod-graph.microsoft.us - - String - - String - - - None - - - SendEmailAccount - - The account that will be used to send the mail message. e.g. Shared O365 Mailbox - - String - - String - - - None - - - Signature - - The signature as a string that you would like within your email body. - - String - - String - - - None - - - TestAddress - - Used for testing, all email messages will go to this address versus the end user. - - String - - String - - - None - - - TextToAdd - - A free form string that will be within the email message body below the default line containing the number of days remaining before their password expires. - - String - - String - - - None - - - Token - - The token that will be used to send the message - - String - - String - - - None - - - - - - ADAccount - - The ADUser account object - - PSObject - - PSObject - - - None - - - ExpireInDaysThreshold - - The threshold for limiting at what time a user would be notified based on when their password expires. - - Int32 - - Int32 - - - None - - - LogFile - - If you want to log each run of this function this will enable logging and display what users were notified placing the logfile in the specified path. - - String - - String - - - None - - - Logging - - Enable logging and output the logfile to the current working directory. - - SwitchParameter - - SwitchParameter - - - False - - - Resource - - The graph resource that will be used - - String - - String - - - None - - - SendEmailAccount - - The account that will be used to send the mail message. e.g. Shared O365 Mailbox - - String - - String - - - None - - - Signature - - The signature as a string that you would like within your email body. - - String - - String - - - None - - - TestAddress - - Used for testing, all email messages will go to this address versus the end user. - - String - - String - - - None - - - TextToAdd - - A free form string that will be within the email message body below the default line containing the number of days remaining before their password expires. - - String - - String - - - None - - - Token - - The token that will be used to send the message - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\>$params = @{ - Resource = $resource - SendEmailAccount = $SendEmailAccount - Token = $token - TestAddress = $TestAddress - ADAccount = $user - ExpireInDaysThreshold = $ExpireInDaysThreshold - TextToAdd = $TextToAddToEmail - Signature = $Signature - Logging = $true - - } - Send-PWExpiringMailMessage @params -Verbose - - This command takes the input from the $params hashtable and then sends an email to the test address versus the configured user. This would be used in a test scenario. Prior to live implemenation. - - - - - - - - Set-PWEmailBody - Set - PWEmailBody - - This cmdlet is used to configure the email message body in JSON format for configuring the JSON payload to graph - - - - This cmdlet is used to configure the email message body in JSON format for configuring the JSON payload to graph - - - - Set-PWEmailBody - - Subject - - Subject line of the email - - String - - String - - - None - - - Importance - - Set the Importance of the email: High or Low - - String - - String - - - None - - - Message - - The message body - - String - - String - - - None - - - EmailAddress - - Email address to receive the email - - String - - String - - - None - - - - - - EmailAddress - - Email address to receive the email - - String - - String - - - None - - - Importance - - Set the Importance of the email: High or Low - - String - - String - - - None - - - Message - - The message body - - String - - String - - - None - - - Subject - - Subject line of the email - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> Set-PWEmailBody -Subject "Your Password is Expiring in 10 Days" ` - -Importance "High" ` - -Message "Please change soon" ` - -EmailAddress "olduser@mycompany.com" - - Prepares the message section of the JSON payload to be submitted to Graph for sending the email message - - - - - - - - Set-PWEmailMessagePayload - Set - PWEmailMessagePayload - - Creates the full message paylod of to send to Graph API - - - - Creates the full message paylod of to send to Graph API - - - - Set-PWEmailMessagePayload - - ADAccount - - The account that is expiring - - PSObject - - PSObject - - - None - - - Signature - - Signature to be used within the email - - PSObject - - PSObject - - - None - - - TextToAdd - - Any additional text to add to the email body - - String - - String - - - None - - - - Set-PWEmailMessagePayload - - ADAccount - - The account that is expiring - - PSObject - - PSObject - - - None - - - Subject - - The email subject - - String - - String - - - None - - - - - - ADAccount - - The account that is expiring - - PSObject - - PSObject - - - None - - - Signature - - Signature to be used within the email - - PSObject - - PSObject - - - None - - - Subject - - The email subject - - String - - String - - - None - - - TextToAdd - - Any additional text to add to the email body - - String - - String - - - None - - - - - - None - - - - - - - - - - System.Object - - - - - - - - - - - - - - -------------------------- Example 1 -------------------------- - PS C:\> Set-PWEmailMessagePayload -TextToAdd $TextToAdd -ADAccount $ADAccount -Signature $Signature - - Prepares the json payload for graph - - - - - - \ No newline at end of file diff --git a/src/PWExpireNotification/1.0.1/PWExpireNotification.psd1 b/src/PWExpireNotification/1.0.1/PWExpireNotification.psd1 deleted file mode 100644 index fb3bea7..0000000 --- a/src/PWExpireNotification/1.0.1/PWExpireNotification.psd1 +++ /dev/null @@ -1,126 +0,0 @@ -# -# Module manifest for module 'PSGet_ADDSPasswordNotification' -# -# Generated by: Daniel Carroll -# -# Generated on: 3/6/2022 -# - -@{ - -# Script module or binary module file associated with this manifest. -RootModule = 'PWExpireNotification.psm1' - -# Version number of this module. -ModuleVersion = '1.0.1' - -# Supported PSEditions -# CompatiblePSEditions = @() - -# ID used to uniquely identify this module -GUID = '626c48e4-dcf8-4364-b5ab-135429452403' - -# Author of this module -Author = 'Daniel Carroll' - -# Company or vendor of this module -CompanyName = 'Carroll Solutions' - -# Copyright statement for this module -Copyright = 'This work is licensed under the Creative Commons Attribution 4.0 International License. To view a copy of this license, visit http://creativecommons.org/licenses/by/4.0/ or send a letter to Creative Commons, PO Box 1866, Mountain View, CA 94042, USA.' - -# Description of the functionality provided by this module -Description = 'PowerShell module for sending notifications to end users when their password is expiring using an O365 mailbox' - -# Minimum version of the Windows PowerShell engine required by this module -PowerShellVersion = '5.1' - -# Name of the Windows PowerShell host required by this module -# PowerShellHostName = '' - -# Minimum version of the Windows PowerShell host required by this module -# PowerShellHostVersion = '' - -# Minimum version of Microsoft .NET Framework required by this module. This prerequisite is valid for the PowerShell Desktop edition only. -# DotNetFrameworkVersion = '' - -# Minimum version of the common language runtime (CLR) required by this module. This prerequisite is valid for the PowerShell Desktop edition only. -# CLRVersion = '' - -# Processor architecture (None, X86, Amd64) required by this module -# ProcessorArchitecture = '' - -# Modules that must be imported into the global environment prior to importing this module -#RequiredModules = @('ActiveDirectory') - -# Assemblies that must be loaded prior to importing this module -# RequiredAssemblies = @() - -# Script files (.ps1) that are run in the caller's environment prior to importing this module. -# ScriptsToProcess = @() - -# Type files (.ps1xml) to be loaded when importing this module -# TypesToProcess = @() - -# Format files (.ps1xml) to be loaded when importing this module -# FormatsToProcess = @() - -# Modules to import as nested modules of the module specified in RootModule/ModuleToProcess -# NestedModules = @() - -# Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export. -FunctionsToExport = @('New-PWEmailBody','Get-PWApplicationToken','Get-PWADDSExpiringPassword','Send-PWExpiringMailMessage','New-PWEmailMessagePayload') - -# Cmdlets to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no cmdlets to export. -CmdletsToExport = @() - -# Variables to export from this module -# VariablesToExport = @() - -# Aliases to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no aliases to export. -AliasesToExport = @() - -# DSC resources to export from this module -# DscResourcesToExport = @() - -# List of all modules packaged with this module -# ModuleList = @() - -# List of all files packaged with this module -# FileList = @() - -# Private data to pass to the module specified in RootModule/ModuleToProcess. This may also contain a PSData hashtable with additional module metadata used by PowerShell. -PrivateData = @{ - - PSData = @{ - - # Tags applied to this module. These help with module discovery in online galleries. - Tags = @('ActiveDirectory','PasswordExpiration','EmailNotification','O365MailNotification','MicrosoftGraph','SendMail') - - # A URL to the license for this module. - LicenseUri = 'https://raw.githubusercontent.com/dacarroll/PWExpireNotification/main/LICENSE' - - # A URL to the main website for this project. - ProjectUri = 'https://github.com/dacarroll/PWExpireNotification' - - # A URL to an icon representing this module. - # IconUri = '' - - # ReleaseNotes of this module - ReleaseNotes = 'Minor fix for New-PWEmailBody' - - # External dependent modules of this module - ExternalModuleDependencies = 'ActiveDirectory' - - } # End of PSData hashtable - -} # End of PrivateData hashtable - -# HelpInfo URI of this module - HelpInfoURI = 'https://github.com/dacarroll/PWExpireNotification/docs' - -# Default prefix for commands exported from this module. Override the default prefix using Import-Module -Prefix. -# DefaultCommandPrefix = '' - -} - diff --git a/src/PWExpireNotification/1.0.1/PWExpireNotification.psm1 b/src/PWExpireNotification/1.0.1/PWExpireNotification.psm1 deleted file mode 100644 index 77f202a..0000000 --- a/src/PWExpireNotification/1.0.1/PWExpireNotification.psm1 +++ /dev/null @@ -1,23 +0,0 @@ -# .ExternalHelp PWExpireNotifictaion-help.xml -[cmdletbinding()] -param() -Write-Verbose $PSScriptRoot - -Write-Verbose 'Import everything in sub folders public, private folder' -$functionFolders = @('Functions', 'Internal') -ForEach ($folder in $functionFolders) { - $folderPath = Join-Path -Path $PSScriptRoot -ChildPath $folder - If (Test-Path -Path $folderPath) { - Write-Verbose -Message "Importing from $folder" - $functions = Get-ChildItem -Path $folderPath -Filter '*.ps1' - ForEach ($function in $functions) { - Write-Verbose -Message " Importing $($function.BaseName)" - try { - . $($function.FullName) - } - catch { - Write-Verbose ('Failed to import "{0}". Reason: "{1}"' -f $function.FullName, $_.Exception.Message) - } - } - } -} \ No newline at end of file