Skip to main content

PowerShell get local admins on remote PCs


How to list members of local administrators on a domain environment?

How to get localgroup administrator members on remote computers in an active directory domain?

Below is a piece of code using Powershell to list members of local administrator  groups on remote PCs.

Code should be run in an elevated mode which has proper access on remote computers.

It needs also WMI to be enable on remote computers being queried. Which is quite dangerous to enable all the time, after using WMI then it is good to disable the settings in order not to be exploited by other users, viruses or malwares.

If WMI is not enable on the remote PC then PowerShell will throw this error:

Connecting to remote server SERVER_NAME failed with the following error message : WinRM cannot complete the operation. Verify that the specified computer name is valid, that the computer is accessible over the network, and that a firewall exception for the WinRM service is
enabled and allows access from this computer. By default, the WinRM firewall exception for public profiles limits access to remote computers within the same local subnet.

Code below reads computers.txt file on drive d. Computers.txt has list of computer names that will be queried by PowerShell and if the script is successful it will write a text file with the remote computer name as its file name and the content will be the local admin members.

Change the script path accordingly where the computers.txt is readable.


Code snippet:
================

$computers = Get-content "D:\computers.txt"


ForEach ($Line In $computers)

{
  #write-host $Line
 Invoke-command -ComputerName $line -ScriptBlock { net localgroup administrators}  | out-file d:\$line.txt

 }


================



Cheers.. Hope it helps..

==================
Free Android Apps:

Click on links below to find out more:

https://play.google.com/store/apps/details?id=soulrefresh.beautiful.prayer


Catholic Rosary Guide  for Android:
Pray the Rosary every day, countless blessings will be showered upon your life if you recite the Rosary faithfully. 
https://play.google.com/store/apps/details?id=com.myrosaryapp

Comments

Popular posts from this blog

Notepad++ convert multiple lines to a single line and vice versa

Notepad++ is an awesome text editing tool, it can accept regex to process the text data. If the data is in a “.csv” format or comma separated values which is basically just a text file that can either be opened using a text editor, excel or even word. Notepad++ can process the contents of the file using regex. Example if the data has multiple rows or lines, and what is needed is to convert the whole lines of data into a single line. Notepad++ can easily do it using regex. However, if the data is on a single line and it needs to be converted into multiple lines or rows then regex can also be used for this case. Here’s an example on how to convert multiple rows or lines into a single line. Example data: Multiple rows, just a sample data. Press Ctrl+H, and  on "Find what" type: [\r\n]+ and on "Replace with" type with: , (white space) --white space is needed if need to have a space in between the data. See image below, "Regular Expression" must be se

WMIC get computer name

WMIC get computer model, manufacturer, computer name and  username. WMIC is a command-line tool and that can generate information about computer model, its manufacturer, its username and other informations depending on the parameters provided. Why would you need a command line tool if there’s a GUI to check? If you have 20 or 100 computers, or even more. It’s quite a big task just checking the GUI to check the computer model and username. If you have remote computers, you need to delegate someone in the remote office or location to check. Or you can just write a batch file or script to automate the task. Here’s the code below on how get computer model, manufacturer and the username. Open an elevated command prompt and type:     wmic computersystem get "Model","Manufacturer", "Name", "UserName" Just copy and paste the code above, the word “computersystem” does not need to be change to a computer name. A

How to check office version from command line

The are quite a few ways to check office version it can be done via registry, PowerShell or VBScript and of course, good old command line can also do it. Checking Windows office version whether it is Office 2010, Office, 2013, Office 2016 or other version is quite important to check compatibility of documents; or just a part of software inventory. For PowerShell this simple snippet can check the office version: $ol = New-Object -ComObject Excel.Application $ol . Version The command line option will tell you where’s the path located; the result will also tell whether office is 32-bit, 64-bit and of course the version of the office as well. Here’s the command that will check the office version and which program directory the file is located which will tell whether it’s 32-bit or 64-bit. Command to search for Excel.exe: DIR C:\ /s excel.exe | find   /i "Directory of"  Above command assumes that program files is on  C: drive. Sample Outpu