Retrieve Local Admins via Powershell

Hey guys, i'd like a script to run to retrieve the list of local Administrators of a group of servers but only match certain users.

So something like

(Get-WMIObject Win32_Group | Where-Object { $_.Name –eq ‘Administrators’ }).GetRelated() | Where-Object { $_.__CLASS –eq “Win32_UserAccount” –or $_.__CLASS –eq “Win32_Group” } | Select-Object __CLASS,Caption,SID


But have a where-object that includes a certain user (just so we can identify if a user has local admin to any server.

Thanks for your help :)
TerellionAsked:
Who is Participating?
 
SubsunConnect With a Mentor Commented:
Function usage is same as shown in above comment..
Function Get-localadmin ($Comp,$User){
$group =[ADSI]"WinNT://$Comp/Administrators"
$Member = @($group.psbase.Invoke("Members")) | % {
	 $_.GetType().InvokeMember("Name", 'GetProperty', $null, $_, $null)
	} |?{$_ -eq $User}
 If ($Member){
	  New-Object PSObject -Property @{
	  Server = $Comp
	  Member = "Yes"
	  }
  }
 }

Open in new window

0
 
Tej Pratap Shukla ~DexterServer AdministratorCommented:
Hi..

Follow the link for script to retrive local admins

http://andrewmorgan.ie/2011/06/retrieve-a-list-of-local-administrators-using-powershell/

Thanks
Dexter
0
 
TerellionAuthor Commented:
Hi there, thanks for that. Do you know how to filter this down though so it only shows certain users?
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
Tej Pratap Shukla ~DexterServer AdministratorCommented:
0
 
SubsunConnect With a Mentor Commented:
To find whether a user is member of a local admin group you can use following function..
Function Get-localadmin ($Comp,$User){
$group =[ADSI]"WinNT://$Comp/Administrators"
$Member = @($group.psbase.Invoke("Members")) | % {
	 $_.GetType().InvokeMember("Name", 'GetProperty', $null, $_, $null)
	} |?{$_ -eq $User}
 If ($Member){
	  New-Object PSObject -Property @{
	  Server = $Comp
	  Member = "Yes"
	  }
  }Else{
  New-Object PSObject -Property @{
  Server = $Comp
  Member = "No"
  }
  }
 }

Open in new window

So to check against single server
Get-localadmin -Comp ServerA -User UserA 

Open in new window

To check against a list of servers..
GC Server.txt | %{
Get-localadmin -Comp $_ -User UserA
}

Open in new window

0
 
TerellionAuthor Commented:
Hi Subsun, thats brilliant! Is there a way to only show the ones that say Member - Yes? Thanks!
0
 
TerellionAuthor Commented:
That is absolutely superb, works a treat THANK YOU! :)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.