internal/functions/get-domainuserdetails.ps1

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70

<#
    .SYNOPSIS
        Get details about the user
         
    .DESCRIPTION
        Extract the FQDM and Sid from the user account
         
    .PARAMETER Username
        User name with the domain name included, in either PRE-2000 or UPN style
         
    .EXAMPLE
        PS C:\> Get-DomainUserDetails -Username "Test@ACME.LOCAL"
         
        This will return the details from the user account "Test@ACME.LOCAL".
         
    .EXAMPLE
        PS C:\> Get-DomainUserDetails -Username "ACME.LOCAL\Test"
         
        This will return the details from the user account "ACME.LOCAL\Test".
         
    .EXAMPLE
        PS C:\> Get-DomainUserDetails -Username "ACME\Test"
         
        This will return the details from the user account "ACME\Test".
         
    .NOTES
        Author: Mötz Jensen (@Splaxi)
#>


function Get-DomainUserDetails {
    [Diagnostics.CodeAnalysis.SuppressMessageAttribute("PSUseSingularNouns", "")]
    [CmdletBinding()]
    param (
        [string] $Username
    )

    $res = [Ordered]@{}

    $domain = ""

    if ($Username -like "*@*") {
        $domain = $Username.Split("@")[1]
        $res.UserId = $Username.Split("@")[0]
    }
    else {
        $domain = $Username.Split("\")[0]
        $res.UserId = $Username.Split("\")[1]
    }

    $domains = Get-CimInstance Win32_NTDomain

    foreach ($item in $domains) {

        if ($item.DnsForestName -like "$($item.DomainName)*") {
            if (($item.DnsForestName -like "$domain" -or $item.DomainName -like "$domain")) {
                $res.Domain = $item.DnsForestName
                break
            }
        }
        elseIf ("$($item.DomainName).$($item.DnsForestName)".ToLower() -eq $domain.ToLower() -or $item.DomainName -like "$domain") {
            $res.Domain = "$($item.DomainName).$($item.DnsForestName)".ToLower()
            break
        }
    }

    $res.Sid = Get-Sid -Username $Username

    [PSCustomObject]$res
}