🛠️ PowerShell Administrative Scripts Collection
A comprehensive collection of PowerShell scripts for system administration, Microsoft Intune, Windows Updates, network diagnostics, user/group management, and remediation tasks in modern Windows enterprise environments.
🌟 Latest Features & Highlights
🖥️ Cross-Platform Support - Scripts work on Windows with PowerShell 5.1+ and PowerShell Core 7+
🔄 Comprehensive Intune Management - Complete suite for Intune management and troubleshooting
👥 User & Group Comparison - Compare AD and Intune user group memberships
🏥 Advanced Remediation Scripts - For Intune, Office, Windows Update, Dell Management
📊 Duplicate Device Detection - Find and manage duplicate Entra ID devices
🔧 WMI Repair Toolkit - Local and remote WMI repository repair capabilities
🚀 Remote Script Execution - Execute scripts on multiple servers simultaneously
# Clone repository
git clone https:// github.com / roalhelm/ PowershellScripts.git
cd PowershellScripts
# Repair Intune Management Extension
.\PSrepairIntuneManagementextention.ps1
# Fix Windows Update issues
.\REP_WindowsUpdate.ps1
# Compare user group memberships in AD
.\ADCompareUserGroups.ps1
# Compare Intune users
.\IntuneCompareUser\IntuneCompareUser.ps1
Requirement
Details
Usage
PowerShell
5.1 (Windows) or 7+ (Cross-Platform)
All scripts
Operating System
Windows 10/11, Server 2016+, macOS, Linux
Platform-specific features noted
Permissions
Administrator (Windows) / sudo (macOS/Linux)
System/Registry operations
Internet
Required
Cloud service tests, downloads
Required PowerShell Modules:
# Windows (PowerShell 5.1)
Install-Module PSWindowsUpdate, AzureAD, ActiveDirectory - Force - AllowClobber
# Cross-Platform (PowerShell 7+ on Windows, macOS, Linux)
Install-Module Microsoft.Graph - Force - AllowClobber
# For Graph API (Intune/Azure scripts)
Connect-MgGraph - Scopes " Device.Read.All" , " Group.ReadWrite.All"
🍎 macOS / 🐧 Linux Specific Requirements:
# Install PowerShell 7+ on macOS
brew install --cask powershell
# Install PowerShell 7+ on Linux (Ubuntu/Debian)
sudo apt-get update
sudo apt-get install -y powershell
# Launch PowerShell
pwsh
📦 Complete Script Overview
Script
Description
Purpose
Admin Rights
DetectRuntime6.ps1
.NET Desktop Runtime 6 Detection
Intune Detection Script
❌
DriverUpdate.ps1
System driver updates via Windows Update
BitLocker-aware driver updates
✅
REP_WindowsUpdate.ps1
Windows Update component reset
Repair for update issues
✅
UnblockFiles.ps1
File unblocking (security zones)
Security zone removal
❌
👥 User & Group Management
🔄 Graph API & Remote Operations
🏥 Remediation Scripts (Intune/SCCM/GPO Ready)
🛡️ Microsoft Defender Management
🏢 Dell Hardware Management
📋 Microsoft Office Management
📱 Intune Device Synchronization
📦 Intune Win32 App Management
🔄 Windows Update Repair (Multi-Stage Process)
🔍 Troubleshooting & Diagnostics
🪟 Windows 11 24H2 Specialized Tools
🎨 HTML Report Features (CheckMicrosoftEndpointsV2.ps1)
📈 Statistical Cards - Tested endpoints, success/failure rate, performance metrics
🎯 Color-Coded Indicators - Instant visual assessment (Green/Yellow/Red)
📱 Responsive Grid Layout - Perfect display on desktop, tablet, mobile
⏱️ Live Statistics - Test duration, timestamp, system information
📋 Detailed Service Analysis
🏢 Service Grouping - Clear organization by Microsoft services
✅ Status Badges - OK/FAILED with meaningful color coding
🌐 Network Details - IP addresses for troubleshooting and firewall configuration
⚡ Performance Metrics - Latency (ms) and speed data with automatic assessment
🚨 Impact Analysis & Troubleshooting
⚠️ Service Impact Warnings - What failures practically mean for business operations
🔧 Remediation Recommendations - Concrete action items for issues
📊 Performance Benchmarking - Automatic network quality assessment
💼 Practical Examples & Workflows
🌅 Daily IT Administration
# Quickly diagnose and fix Intune issues
.\Remediations\RepairIntuneWin32Apps\detectIntuneWin32Apps.ps1
if ($LASTEXITCODE -ne 0 ) {
.\Remediations\RepairIntuneWin32Apps\remediateIntuneWin32Apps.ps1
}
# Systematically fix Windows Update issues
.\REP_WindowsUpdate.ps1
.\Remediations\RepairWinUpdate\detection.ps1
# Compare user groups
.\ADCompareUserGroups.ps1
# Find duplicate devices
.\Get-DuplicateEntraDevices.ps1
🚀 Pre-Deployment Validation
# System readiness check
.\DetectRuntime6.ps1
.\DriverUpdate.ps1 - WhatIf
# Check Intune user assignments
.\IntuneCompareUser\IntuneCompareUser.ps1
📊 Compliance & Monitoring
# Automated remediation chain
.\Remediations\Intune- SyncDevice\Detection.ps1
.\Remediations\remediatOfficeUpdates\detectOfficeUpdates.ps1
.\Remediations\RepairWinUpdate\detection.ps1
# WMI health check
.\PSrepairWMI.ps1 - CheckOnly
🔧 Troubleshooting Workflows
# Comprehensive problem diagnosis
.\TroubleshootingGuide\Collect- Win11_24H2_Diagnostics.ps1
# Multi-stage Windows Update repair
.\Remediations\RepairWinUpdate\detectSTEP1.ps1
.\Remediations\RepairWinUpdate\remediationSTEP1.ps1
.\Remediations\RepairWinUpdate\detectSTEP2.ps1
.\Remediations\RepairWinUpdate\remediationSTEP2.ps1
🔧 Advanced Configuration & Best Practices
📁 Recommended Enterprise Directory Structure
C:\Scripts\PowershellScripts\
├── Core\
│ ├── PSrepairIntuneManagementextention.ps1
│ ├── REP_WindowsUpdate.ps1
│ └── PSrepairWMI.ps1
├── Reports\
│ ├── Remediation\
│ └── Diagnostics\
├── Logs\
│ ├── Remediation\
│ └── Diagnostics\
├── Config\
│ ├── DeviceGroups.csv
│ └── UserGroups.csv
└── Automation\
├── ScheduledTasks\
└── RemediationScripts\
🔒 Security & Permissions Matrix
Script Category
Windows Permission
Azure/Intune Permission
Network Access
Network Tests
Standard User
❌ Not required
✅ HTTPS (443)
System Repair
🔑 Administrator
❌ Not required
⚠️ Windows Update
Intune/Graph
Standard User
🔑 Graph API Scopes
✅ Graph Endpoints
Registry Ops
🔑 Administrator
❌ Not required
❌ Not required
WMI Repair
🔑 Administrator
❌ Not required
⚠️ Remote WMI (if remote)
📚 Documentation & Support
# Detailed help for each script
Get-Help .\PSrepairIntuneManagementextention.ps1 - Full
Get-Help .\REP_WindowsUpdate.ps1 - Examples
Get-Help .\Remediations\RepairIntuneWin32Apps\remediateIntuneWin32Apps.ps1 - Parameter All
# View script documentation
Get-Help .\ADCompareUserGroups.ps1 - Detailed
Get-Help .\Get-DuplicateEntraDevices.ps1 - Examples
🔍 Troubleshooting Resources
TroubleshootingGuide.md - Comprehensive problem-solving guide
Script Comments - Detailed inline documentation in each script
Error Handling - Detailed error messages with concrete solution suggestions
Exit Codes - Standardized return values for automation
# Example: Show all available scripts
Get-ChildItem - Path . - Filter " *.ps1" - Recurse | Select-Object Name, Length, LastWriteTime
# Example: Check script dependencies
$RequiredModules = @ (' PSWindowsUpdate' , ' Microsoft.Graph' , ' ActiveDirectory' )
$RequiredModules | ForEach-Object {
if (Get-Module - ListAvailable - Name $_ ) {
" ✅ $_ available"
} else {
" ❌ $_ missing - Install-Module $_ -Force"
}
}
📈 Version History & Roadmap
🔮 Roadmap & Planned Features
🤖 Enhanced Remediation Automation - Intelligent troubleshooting workflows
🔄 Integration APIs - REST API for SIEM/monitoring systems
📧 Email Notifications - Automatic alert delivery
🌍 Multi-Language Support - International localization
🍎 Enhanced macOS/Linux Support - More cross-platform scripts
📊 Advanced Reporting - Enhanced diagnostic reports
🖥️ Cross-Platform Compatibility Guide
✅ Fully Compatible Scripts (Windows with PowerShell 5.1+)
Script
PowerShell 5.1+
PowerShell Core 7+
Notes
GraphApiOdataNextLink.ps1
✅
✅
Pure Graph API
IntuneCompareUser.ps1
✅
✅
Pure Graph API
Get-DuplicateEntraDevices.ps1
✅
✅
Pure Graph API
Script
Reason
Alternative
PSrepairIntuneManagementextention.ps1
Windows-specific services
N/A
REP_WindowsUpdate.ps1
Windows Update components
N/A
PSrepairWMI.ps1
WMI (Windows-specific)
N/A
DriverUpdate.ps1
Windows drivers and BitLocker
N/A
🔧 Platform Detection Example
# How scripts detect platform and choose appropriate module
$isPwshCore = $PSVersionTable.PSEdition -eq ' Core'
if ($isPwshCore ) {
# PowerShell Core 7+ (Windows/macOS/Linux)
Import-Module Microsoft.Graph
Connect-MgGraph - Scopes " Device.Read.All" , " Group.ReadWrite.All"
} else {
# Windows PowerShell 5.1
Import-Module AzureAD
Connect-AzureAD
}
🛠️ Installation & Setup Guide
1️⃣ Initial Repository Setup
# Step 1: Clone repository and setup
git clone https:// github.com / roalhelm/ PowershellScripts.git
cd PowershellScripts
# Step 2: Adjust execution policy (if required)
Set-ExecutionPolicy - ExecutionPolicy RemoteSigned - Scope CurrentUser - Force
# Step 3: Add directory to PATH (optional)
$currentPath = [Environment ]::GetEnvironmentVariable(" PATH" , " User" )
$scriptPath = (Get-Location ).Path
if ($currentPath -notlike " *$scriptPath *" ) {
[Environment ]::SetEnvironmentVariable(" PATH" , " $currentPath ;$scriptPath " , " User" )
}
2️⃣ Dependencies & Prerequisites
# === Windows PowerShell 5.1 ===
$WindowsModules = @ (' PSWindowsUpdate' , ' AzureAD' , ' ActiveDirectory' )
$WindowsModules | ForEach-Object {
Install-Module $_ - Force - AllowClobber - Scope CurrentUser
Import-Module $_ - Force
}
# === PowerShell Core 7+ (Windows/macOS/Linux) ===
$CrossPlatformModules = @ (' Microsoft.Graph' )
$CrossPlatformModules | ForEach-Object {
Install-Module $_ - Force - AllowClobber - Scope CurrentUser
Import-Module $_ - Force
}
# Graph API authentication (for Intune/Azure scripts on all platforms)
Connect-MgGraph - Scopes @ (
" Device.Read.All" ,
" Group.ReadWrite.All" ,
" User.Read.All" ,
" Directory.AccessAsUser.All"
)
3️⃣ First Run & Validation
# Step 1: Test remediation scripts (with caution!)
.\DetectRuntime6.ps1
.\Remediations\Intune- SyncDevice\Detection.ps1
# Step 2: Check user groups
.\ADCompareUserGroups.ps1
# Step 3: Find duplicate devices
.\Get-DuplicateEntraDevices.ps1
# Step 4: Test WMI health
.\PSrepairWMI.ps1 - CheckOnly
🔒 Security, Compliance & Best Practices
🛡️ Enterprise Security Guidelines
Security Aspect
Recommendation
Implementation
Compliance
Execution Policy
RemoteSigned minimum
Set-ExecutionPolicy RemoteSigned -Scope CurrentUser
✅ Corporate Policy
Script Signing
Recommended for production
Use code signing certificate
✅ Enterprise Standard
Credential Management
Secure Store/Key Vault
$cred = Get-Credential instead of hardcoding
🔒 Security Baseline
Audit Logging
All critical operations
Windows Event Log + Custom Logs
📋 Compliance Ready
Network Monitoring
Enable firewall logs
Monitor outbound connections
🔍 Network Security
🔐 Recommended Deployment Strategy
# 1. Test Environment Validation
$TestEnvironments = @ (" DEV" , " TEST" , " UAT" )
$TestEnvironments | ForEach-Object {
Write-Host " Testing in $_ environment..." - ForegroundColor Cyan
# Run remediation tests
.\Remediations\RepairWinUpdate\detection.ps1
}
# 2. Staged Rollout
$ProductionGroups = @ (" Pilot-Users" , " IT-Department" , " All-Users" )
# Implementation according to company policy
# 3. Monitoring & Feedback Loop
# Scheduled tasks for regular health checks
# Integration with existing monitoring (SCOM, PRTG, etc.)
🤝 Community & Contributing
🍴 Fork the repository on GitHub
🌿 Feature Branch create: git checkout -b feature/amazing-new-feature
💾 Commit your changes: git commit -am 'Add amazing new feature'
📤 Push to branch: git push origin feature/amazing-new-feature
🔄 Pull Request create with detailed description
📝 Code Style : PowerShell Best Practices and PSScriptAnalyzer compliance
📚 Documentation : Complete comment-based help for all functions
🧪 Testing : Validation in at least 2 different environments
🔄 Backwards Compatibility : Compatibility with PowerShell 5.1+
🔒 Security : No hardcoded credentials or unsafe practices
🐛 Issue Reporting & Support
Use GitHub Issues for:
Issue Type
Label
Template
Response Time
🐛 Bug Reports
bug
Bug Report Template
24-48h
💡 Feature Requests
enhancement
Feature Request Template
1 week
📖 Documentation
documentation
Documentation Template
48h
❓ Questions
question
Question Template
24h
🚨 Security Issues
security
Private Disclosure
Immediate
📈 Repository Statistics & Metrics
Category
Script Count
Lines of Code
Last Updated
Platform Support
System & Updates
4
800+
December 2025
Windows Only
Intune & MDM
2
400+
December 2025
Windows Only
User & Group Management
3
600+
December 2025
Windows ⭐
Remediation Scripts
15+
1,000+
December 2025
Windows Only
Troubleshooting Tools
2
300+
December 2025
Windows Only
Graph API & Remote
3
500+
December 2025
Windows
Total
15+
3,600+
Actively maintained
Windows
📄 License & Legal Information
This project is licensed under the GNU General Public License v3.0
Key License Points:
✅ Commercial Use allowed
✅ Modification and Distribution allowed
✅ Patent Use protected
⚠️ Source Code Disclosure required for distribution
⚠️ Same License required for derivative works
Ronny Alhelm
🌐 GitHub : @roalhelm
📧 Contact : Via GitHub Issues (preferred)
💼 Professional : Enterprise PowerShell Solutions
🙏 Acknowledgments & Credits
Microsoft Documentation Team - For comprehensive API documentation
PowerShell Community - For best practices and code reviews
Enterprise IT Feedback - For real-world requirements and use cases
Open Source Contributors - For testing, bug reports, and feature suggestions