Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion AccessControlDsc.psd1
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@

@{
# Version number of this module.
ModuleVersion = '1.4.2'

ModuleVersion = '1.4.3'

# ID used to uniquely identify this module
GUID = 'a544c26f-3f96-4c1e-8351-1604867aafc5'
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,15 @@ function Resolve-Identity
if ($Identity -match '^S-\d-(\d+-){1,14}\d+$')
{
[System.Security.Principal.SecurityIdentifier]$Identity = $Identity

# Support for capability sids
if ($Identity.Value.StartsWith('S-1-15-3-'))
{
return [PSCustomObject]@{
Name = $Identity.Value
SID = $Identity.Value
}
}
}
else
{
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -400,7 +400,7 @@ Function Compare-ActiveDirectoryAccessRule
$_.InheritanceType -eq $referenceObject.InheritanceType -and
$_.InheritedObjectType -eq $referenceObject.InheritedObjectType -and
$_.ObjectType -eq $referenceObject.ObjectType -and
$_.IdentityReference -eq $referenceObject.IdentityReference
$_.IdentityReference.Value -eq $referenceObject.IdentityReference.Value
})
if($match.Count -ge 1)
{
Expand All @@ -426,7 +426,7 @@ Function Compare-ActiveDirectoryAccessRule
$_.InheritanceType -eq $referenceObject.InheritanceType -and
$_.InheritedObjectType -eq $referenceObject.InheritedObjectType -and
$_.ObjectType -eq $referenceObject.ObjectType -and
$_.IdentityReference -eq $referenceObject.IdentityReference
$_.IdentityReference.Value -eq $referenceObject.IdentityReference.Value
})
if($match.Count -gt 0)
{
Expand All @@ -444,7 +444,7 @@ Function Compare-ActiveDirectoryAccessRule
$_.InheritanceType -eq $referenceObject.InheritanceType -and
$_.InheritedObjectType -eq $referenceObject.InheritedObjectType -and
$_.ObjectType -eq $referenceObject.ObjectType -and
$_.IdentityReference -eq $referenceObject.IdentityReference
$_.IdentityReference.Value -eq $referenceObject.IdentityReference.Value
})
if($match.Count -eq 0)
{
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -498,7 +498,7 @@ function Test-ActiveDirectoryAuditRuleMatch
$_.ObjectType -eq $ReferenceRule.ObjectType -and
$_.InheritanceType -eq $ReferenceRule.InheritanceType -and
$_.InheritedObjectType -eq $ReferenceRule.InheritedObjectType -and
$_.IdentityReference -eq $ReferenceRule.IdentityReference
$_.IdentityReference.Value -eq $ReferenceRule.IdentityReference.Value
})
}
else
Expand All @@ -512,7 +512,7 @@ function Test-ActiveDirectoryAuditRuleMatch
$_.ObjectType -eq $ReferenceRule.ObjectType -and
$_.InheritanceType -eq $ReferenceRule.InheritanceType -and
$_.InheritedObjectType -eq $ReferenceRule.InheritedObjectType -and
$_.IdentityReference -eq $ReferenceRule.IdentityReference
$_.IdentityReference.Value -eq $ReferenceRule.IdentityReference.Value
})
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -518,7 +518,7 @@ function Test-FileSystemAuditRuleMatch
$_.AuditFlags -eq $ReferenceRule.AuditFlags -and
$_.InheritanceFlags -eq $ReferenceRule.InheritanceFlags -and
$_.PropagationFlags -eq $ReferenceRule.PropagationFlags -and
$_.IdentityReference -eq $ReferenceRule.IdentityReference
$_.IdentityReference.Value -eq $ReferenceRule.IdentityReference.Value
})
}
else
Expand All @@ -536,8 +536,7 @@ function Test-FileSystemAuditRuleMatch
(($_.PropagationFlags.value__ -eq 3 -and $ReferenceRule.PropagationFlags.value__ -in 1..3) -or
($_.PropagationFlags.value__ -in 1..3 -and $ReferenceRule.PropagationFlags.value__ -eq 0) -or
($_.PropagationFlags.value__ -eq $ReferenceRule.PropagationFlags.value__)) -and

$_.IdentityReference -eq $ReferenceRule.IdentityReference
$_.IdentityReference.Value -eq $ReferenceRule.IdentityReference.Value
})
}
}
Expand Down
4 changes: 2 additions & 2 deletions DscResources/NTFSAccessEntry/NTFSAccessEntry.psm1
Original file line number Diff line number Diff line change
Expand Up @@ -631,7 +631,7 @@ function Test-FileSystemAccessRuleMatch
$_.InheritanceFlags -eq $ReferenceRule.InheritanceFlags -and
$_.PropagationFlags -eq $ReferenceRule.PropagationFlags -and
$_.AccessControlType -eq $ReferenceRule.AccessControlType -and
$_.IdentityReference -eq $ReferenceRule.IdentityReference
$_.IdentityReference.Value -eq $ReferenceRule.IdentityReference.Value
})
}
else
Expand All @@ -646,7 +646,7 @@ function Test-FileSystemAccessRuleMatch
($_.PropagationFlags.value__ -in 1..3 -and $ReferenceRule.PropagationFlags.value__ -eq 0) -or
($_.PropagationFlags.value__ -eq $ReferenceRule.PropagationFlags.value__)) -and
$_.AccessControlType -eq $ReferenceRule.AccessControlType -and
$_.IdentityReference -eq $ReferenceRule.IdentityReference
$_.IdentityReference.Value -eq $ReferenceRule.IdentityReference.Value
})
}
}
Expand Down
6 changes: 3 additions & 3 deletions DscResources/RegistryAccessEntry/RegistryAccessEntry.psm1
Original file line number Diff line number Diff line change
Expand Up @@ -382,7 +382,7 @@ Function Compare-RegistryRule
$_.InheritanceFlags -eq $refrenceObject.InheritanceFlags -and
$_.PropagationFlags -eq $refrenceObject.PropagationFlags -and
$_.AccessControlType -eq $refrenceObject.AccessControlType -and
$_.IdentityReference -eq $refrenceObject.IdentityReference
$_.IdentityReference.Value -eq $refrenceObject.IdentityReference.Value
})
if ($match.Count -ge 1)
{
Expand All @@ -407,7 +407,7 @@ Function Compare-RegistryRule
$_.InheritanceFlags -eq $refrenceObject.InheritanceFlags -and
$_.PropagationFlags -eq $refrenceObject.PropagationFlags -and
$_.AccessControlType -eq $refrenceObject.AccessControlType -and
$_.IdentityReference -eq $refrenceObject.IdentityReference
$_.IdentityReference.Value -eq $refrenceObject.IdentityReference.Value
})
if($match.Count -eq 0)
{
Expand All @@ -424,7 +424,7 @@ Function Compare-RegistryRule
$_.InheritanceFlags -eq $refrenceObject.InheritanceFlags -and
$_.PropagationFlags -eq $refrenceObject.PropagationFlags -and
$_.AccessControlType -eq $refrenceObject.AccessControlType -and
$_.IdentityReference -eq $refrenceObject.IdentityReference
$_.IdentityReference.Value -eq $refrenceObject.IdentityReference.Value
})
if ($match.Count -gt 0)
{
Expand Down