{"id":571,"date":"2017-09-06T08:57:07","date_gmt":"2017-09-06T07:57:07","guid":{"rendered":"http:\/\/snakenet.eu\/blog\/?p=571"},"modified":"2017-09-06T08:57:07","modified_gmt":"2017-09-06T07:57:07","slug":"lister-les-erreurs-dauthentification-radius-nps-via-powershell","status":"publish","type":"post","link":"https:\/\/snakenet.eu\/blog\/lister-les-erreurs-dauthentification-radius-nps-via-powershell\/571\/","title":{"rendered":"Lister les erreurs d&rsquo;authentification Radius (NPS) via PowerShell"},"content":{"rendered":"<p>Avec \u00e7a, vous aurez les derni\u00e8res erreurs et leurs causes possibles.<\/p>\n<p>&nbsp;<\/p>\n<pre>$NpsServers=('DC01','DC02')\r\n$ReturnArray=@()\r\n\r\n$NPS_Filter=\"&lt;QueryList&gt;\r\n &lt;Query Id=`\"0`\" Path=`\"System`\"&gt;\r\n &lt;Select Path=`\"System`\"&gt;*[System[Provider[@Name='NPS']]]&lt;\/Select&gt;\r\n &lt;Select Path=`\"System`\"&gt;*[System[Provider[@Name='HRA']]]&lt;\/Select&gt;\r\n &lt;Select Path=`\"System`\"&gt;*[System[Provider[@Name='Microsoft-Windows-HCAP']]]&lt;\/Select&gt;\r\n &lt;Select Path=`\"Security`\"&gt;*[System[Provider[@Name='Microsoft-Windows-Security-Auditing'] and Task = 12552]]&lt;\/Select&gt;\r\n &lt;\/Query&gt;\r\n&lt;\/QueryList&gt;\"\r\n\r\nforeach ( $NpsServer in $NpsServers ) {\r\n foreach ( $Event in (Get-WinEvent -MaxEvents 800 -ComputerName $NpsServer -FilterXml ([xml]$NPS_Filter) | where {$_.message -like \"*denied*\"} ) ){\r\n $Message=$Event.Message.Split(\"`n\")\r\n\r\n$Retour = [PSCustomObject]@{\r\n TimeCreated =$Event.TimeCreated\r\n MachineName =$Event.MachineName\r\n AccountName =((($Message |Select-String -Pattern \"Account Name\" -CaseSensitive)[0]).ToString().split(':')[1]).trim()\r\n AuthType =((($Message |Select-String -Pattern \"Authentication Type\" -CaseSensitive)[0]).ToString().split(':')[1]).trim()\r\n Reason =''\r\n }\r\n if ($Message |Select-String -Pattern \"Reason\" ){\r\n $Retour.Reason =((($Message |Select-String -Pattern \"Reason:\" -CaseSensitive)[0]).ToString().split(':')[1]).trim()\r\n }\r\n\r\n$ReturnArray+=$Retour\r\n }\r\n}\r\n$ReturnArray| ft -autosize<\/pre>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Avec \u00e7a, vous aurez les derni\u00e8res erreurs et leurs causes possibles. &nbsp; $NpsServers=(&lsquo;DC01&prime;,&rsquo;DC02&prime;) $ReturnArray=@() $NPS_Filter=\u00a0\u00bb&lt;QueryList&gt; &lt;Query Id=`\u00a0\u00bb0`\u00a0\u00bb Path=`\u00a0\u00bbSystem`\u00a0\u00bb&gt; &lt;Select Path=`\u00a0\u00bbSystem`\u00a0\u00bb&gt;*[System[Provider[@Name=&rsquo;NPS&rsquo;]]]&lt;\/Select&gt; &lt;Select Path=`\u00a0\u00bbSystem`\u00a0\u00bb&gt;*[System[Provider[@Name=&rsquo;HRA&rsquo;]]]&lt;\/Select&gt; &lt;Select Path=`\u00a0\u00bbSystem`\u00a0\u00bb&gt;*[System[Provider[@Name=&rsquo;Microsoft-Windows-HCAP&rsquo;]]]&lt;\/Select&gt; &lt;Select Path=`\u00a0\u00bbSecurity`\u00a0\u00bb&gt;*[System[Provider[@Name=&rsquo;Microsoft-Windows-Security-Auditing&rsquo;] and Task = 12552]]&lt;\/Select&gt; &lt;\/Query&gt; &lt;\/QueryList&gt;\u00a0\u00bb foreach ( $NpsServer in $NpsServers ) { foreach ( $Event in (Get-WinEvent -MaxEvents 800 -ComputerName $NpsServer -FilterXml ([xml]$NPS_Filter) | where {$_.message -like \u00ab\u00a0*denied*\u00a0\u00bb} [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58,4,63],"tags":[],"class_list":["post-571","post","type-post","status-publish","format-standard","hentry","category-powershell","category-wifi","category-windows"],"_links":{"self":[{"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/posts\/571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/comments?post=571"}],"version-history":[{"count":1,"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/posts\/571\/revisions"}],"predecessor-version":[{"id":572,"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/posts\/571\/revisions\/572"}],"wp:attachment":[{"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/media?parent=571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/categories?post=571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/snakenet.eu\/blog\/wp-json\/wp\/v2\/tags?post=571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}