M365SL.OrgMon.Serial.PA

M365SL.OrgMon.Serial.PA (ProbeActionModuleType)

Designed to leverage a Posh script PA for retrieving properties/metrics.

Element properties:

TypeProbeActionModuleType
IsolationAny
AccessibilityInternal
RunAsM365SL.RunAs.Profile
InputTypeSystem.BaseData
OutputTypeMicrosoft.Windows.SerializedObjectData

Member Modules:

ID Module Type TypeId RunAs 
POSH ProbeAction Microsoft.Windows.PowerShellProbe Default

Overrideable Parameters:

IDParameterTypeSelector
EventIDFilterstring$Config/EventIDFilter$
PoshLibraryPathstring$Config/PoshLibraryPath$
ProbeActionTimeoutSecondsint$Config/ProbeActionTimeoutSeconds$
WriteToEventLogbool$Config/WriteToEventLog$

Source Code:

<ProbeActionModuleType ID="M365SL.OrgMon.Serial.PA" Accessibility="Internal" Batching="false" PassThrough="false" RunAs="M365SL.RunAs.Profile">
<Configuration>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="ApiTokenScopeURL" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="ApiTokenURL" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="ApiURL" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="M365_AccountName" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="M365_AccountPassword" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="M365_ClientID" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="M365_ClientSecret" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="EventIDFilter" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="PoshLibraryPath" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="ProbeActionTimeoutSeconds" type="xsd:integer"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="TenantName" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="TLSVersion" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="WorkflowName" type="xsd:string"/>
<xsd:element xmlns:xsd="http://www.w3.org/2001/XMLSchema" minOccurs="1" name="WriteToEventLog" type="xsd:boolean"/>
</Configuration>
<OverrideableParameters>
<OverrideableParameter ID="EventIDFilter" Selector="$Config/EventIDFilter$" ParameterType="string"/>
<OverrideableParameter ID="PoshLibraryPath" Selector="$Config/PoshLibraryPath$" ParameterType="string"/>
<OverrideableParameter ID="ProbeActionTimeoutSeconds" Selector="$Config/ProbeActionTimeoutSeconds$" ParameterType="int"/>
<OverrideableParameter ID="WriteToEventLog" Selector="$Config/WriteToEventLog$" ParameterType="bool"/>
</OverrideableParameters>
<ModuleImplementation Isolation="Any">
<Composite>
<MemberModules>
<ProbeAction ID="POSH" TypeID="Windows!Microsoft.Windows.PowerShellProbe">
<ScriptName>M365SL.OrgMon.ps1</ScriptName>
<ScriptBody><Script>&lt;#
#===============================================================================================================================================================
Created by: Tyson Paul
Filename: M365SL.OrgMon.ps1
Description: This will calculate days until expiration for application secrets.

Version History:
2021.03.16.0938 - Cakeday! Added error handling to division operation: 'DirectoryPercentConsumed'
2020.12.08.2200 - Will immediately exit if unable to retrieve Token. No property bag.
2020.11.17.2224 - Added API Url params
2020.11.06.1720 - v1

Requirements: Must have an Azure application registered and have the following:
ClientID &amp; Application Secret

===============================================================================================================================================================
#&gt;

Param(
[string]$ApiTokenScopeURL,
[string]$ApiTokenURL,
[string]$ApiURL,

[string]$M365_AccountName,
[string]$M365_AccountPassword,

# Azure Application auth
[string]$M365_ClientID,
[string]$M365_ClientSecret,

# Comma-separated list of event IDs, script will only write to log for these EventIDs. This is a way to only write specific events. Only valid if $WriteToEventLog parameter is 'true'.
[string]$EventIDFilter,

# Comma-separated list of .ps1 files to load
[string]$PoshLibraryPath,

# This is a clever way to utilize the exact same script for both rule/mon and agent tasks.
[Parameter(Mandatory=$false,
ValueFromPipeline=$false,
ValueFromPipelineByPropertyName=$false,
ValueFromRemainingArguments=$false)]
[ValidateSet('PropertyBag', 'Serialized')]
[string]$ScriptOutputType = 'PropertyBag',

# Azure tenant
[string]$TenantName,

[string]$TLSVersion,

# Typically this is the name of the workflow calling this script. Should be set to the name of the probe/WA if being used by both rules/mons so as not to break cookdown.
# Keep in mind that datasource params need to be identical for cookdown to work.
[string]$WorkflowName,

# type:string. SCOM bool params are different than Posh bool. Will get converted to Posh bool below.
[string]$WriteToEventLog = 'false'
)

# Set defaults for event filters. Apparently setting this in the Params declaration did not work.
If (-NOT $EventIDFilter) {
$EventIDFilter = "9990,9991,9992,9995,9996,9997,9998,9999"
}

$ScriptName = 'M365SL.OrgMon.ps1'
$NameSpace = 'Library'
[bool]$WriteToEventLog = [System.Convert]::ToBoolean($WriteToEventLog)
$Testing = $false

######################### FUNCTIONS ############################
################################################################
Function Load-Library {
Param (
[string]$PoshLibraryPath
)
$ErrorActionPreference = 'STOP'
If (-NOT $NameSpace.Length) {
$NameSpace = $ScriptName
}
$EventSource = "M365 Supplemental"
$EventLogName = "Application"
$objEvent = New-Object System.Diagnostics.EventLog
$objEvent.Source = $EventSource
$objEvent.Log = $EventLogName
$EventID_Normal = 9992
$EventID_Anomaly = 9996
[Int]$info=4 #System.Diagnostics.EventInstance
[Int]$critical=1
[Int]$warn=2

If ($PoshLibraryPath ){
Start-Sleep -Seconds 5 #Allow time for Library to be deployed
ForEach ($Path in $PoshLibraryPath.Split(',') ){
Try {
If (($Path.Length) -AND ($Path -notmatch '^-1$')) {
. $Path
If ([bool]$WriteToEventLog -eq $true) {
$msg = "Line [$($MyInvocation.ScriptLineNumber)], $($MyInvocation.PSCommandPath): Success loading library file: [$($Path)]"
$logData = "$($Msg)^$($Msg)^$($ScriptName)^$($TenantName)^$($NameSpace)"
[array]$arrMessage = @($logData.Split('^'))
$objEventID = New-Object System.Diagnostics.EventInstance($EventID_Normal,1,$info)
$objEvent.WriteEvent($objEventID, @($arrMessage))
}
}
} Catch {
[bool]$LibExists =$false
Try {
# It's possible the libfile exists (as it should) but cannot be loaded for some reason.
[bool]$LibExists = [bool](Test-Path -Path $Path -PathType Leaf)
} Catch {
#File does not exist. LibExists = $false already by default
}
$msg = "Line [$($MyInvocation.ScriptLineNumber )]: Error loading PoshLibrary at path:[$($Path)]. Library file exists? [$($LibExists)]. This is likely to cause many other dependent functions to fail. `n`nError data: $($_)`n`n"
$logData = "$($Msg)^$($Msg)^$($ScriptName)^$($TenantName)^$($NameSpace)"
[array]$arrMessage = @($logData.Split('^'))
$objEventID = New-Object System.Diagnostics.EventInstance($EventID_Anomaly,1,$warn)
$objEvent.WriteEvent($objEventID, @($arrMessage))
}
}
}
$ErrorActionPreference = 'CONTINUE'
}
################################################################

############## TESTING ##############
&lt;# #Run this as needed when testing

Function Testing {
$Testing = $true
Get-Item Alias:\_LINE_ -ErrorAction Ignore | Remove-Item -ErrorAction Ignore
$testParamsFile = (Join-path $TestFolder ("PARAMS_$($ScriptName)"))
#Write-Host "$(Test-Path $testParamsFile):$($testParamsFile)" -F Yellow -B Green
. $testParamsFile
. Load-Library -PoshLibraryPath $PoshLibraryPath

# Encode user data/passwords in current test user context
$M365_ClientSecret = Encode-UserData $M365_ClientSecret_PLAINTEXT
$M365_AccountPassword = Encode-UserData $M365_AccountPassword_PLAINTEXT
$error.Clear()
}

$TestFolder = "C:\Test\M365SMP_Dev\$($NameSpace)\TestSetup"
If (Test-Path -Path $TestFolder) {
. Testing
}

#&gt;
############## TESTING ##############


. Load-Library -PoshLibraryPath $PoshLibraryPath
LogIt -EventID 9990 -Type $info -Msg "Begin script..." -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()

# Set up BasicBag with defaults
$bag = New-Object -TypeName BasicBag
$bag.AddValue('Category',"OrgData")
$bag.AddValue('Message',"")
$bag.AddValue('Result',"FAILURE") #default, unless the tests succeed

$bag.AddValue('ThisScriptInstanceGUID',"$ThisScriptInstanceGUID")
$bag.AddValue('Whoami',"$whoami")
$bag.AddValue('M365_ClientID',"$M365_ClientID")
$bag.AddValue('M365_AccountName',"$M365_AccountName")
$bag.AddValue('TenantName',"$TenantName")
$bag.AddValue('DisplayName',"")
$bag.AddValue('OrgID',"")
$bag.AddValue('tenantType',"")

$bag.AddValue('DirectoryUsedMB',[int]0)
$bag.AddValue('DirectoryQuotaMB',[int]0)
$bag.AddValue('DirectoryFreeMB',[int]0)
$bag.AddValue('DirectoryPercentConsumed',[int]0)
$bag.AddValue('DirectoryPercentFree',[int]0)

$bag.AddValue('AuthenticationDurationMS',[double]0)
$bag.AddValue('AuthenticationDurationSeconds',[double]0)


LogIt -EventID 9992 -Type $info -msg "Setting TLS for session, Version: [$($TLSVersion)]." -Proceed $WriteToEventLog -Line $(_LINE_); $Error.Clear();
#Set Default TLS
. Set-TLS -TLSVersion $TLSVersion

# Decode Account Password
$Message = "Decode password for [$($NameSpace)]."
LogIt -EventID 9992 -Type $info -Msg $Message -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
Try {
$M365_AccountPassword_DECRYPTED = Decode-UserData -Data $M365_AccountPassword
} Catch {
$Message += "Unable to $($Message). See error data."
LogIt -EventID 9995 -Type $warn -Msg $Message -Proceed $true -LINE $(_LINE_); $Error.Clear()
$bag.Message += " $Message"
}

# Decode Client Secret
$Message = "Decode client secret for [$($NameSpace)]."
LogIt -EventID 9992 -Type $info -Msg $Message -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
Try {
$M365_ClientSecret_DECRYPTED = Decode-UserData -Data $M365_ClientSecret
} Catch {
$Message += "Unable to $($Message). See error data."
LogIt -EventID 9995 -Type $warn -Msg $Message -Proceed $true -LINE $(_LINE_); $Error.Clear()
$bag.Message += " $Message"
}

$StopWatch = [System.Diagnostics.Stopwatch]::StartNew() #Intention is to track the duration of this activity, regardless of success/failure.
# Get Access Token
$Message = "Get Access Token for [$($NameSpace)]."
LogIt -EventID 9992 -Type $info -Msg $Message -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
Try {
$TokenResponse = Get-AccessToken -Delegated -User $M365_AccountName -Pass $M365_AccountPassword_DECRYPTED -ClientID $M365_ClientID -ClientSecret $M365_ClientSecret_DECRYPTED -TenantName $TenantName -ApiTokenUrl $ApiTokenURL -ApiTokenScopeURL $ApiTokenScopeURL
$AuthenticationDurationSeconds = [double](Format-Number $StopWatch.Elapsed.TotalSeconds -DecimalPlaces 3)
$AuthenticationDurationMS = [double](Format-Number $StopWatch.Elapsed.TotalMilliseconds -DecimalPlaces 0)
} Catch {
$Message = "Unable to $($Message). See error data. Exiting."
LogIt -EventID 9997 -Type $warn -Msg $Message -Proceed $true -LINE $(_LINE_); $Error.Clear()
If ($ScriptOutputType -eq 'Serialized') {
Write-Output $Message
}
Exit
}
$StopWatch.Stop()

$Activity = "attempt to get org data from tenant [$($TenantName)]."
LogIt -EventID 9992 -Type $info -Msg $Activity -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
Try {
$URL = "$($ApiURL)/v1.0/organization"
$Results = Invoke-RestMethod -Headers @{Authorization = "Bearer $($Tokenresponse.access_token)"} -Uri $URL -Method Get -ContentType 'application/json' -ErrorAction Stop
$Message = "Successful $Activity."
LogIt -EventID 9992 -Type $info -Msg $Message -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
} Catch {
$Message = "Failed $Activity. See error data."
LogIt -EventID 9992 -Type $info -Msg $Message -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
}
$bag.Message = $Message

If ($Results) {
$bag.Result = 'SUCCESS'
$bag.OrgID = $Results.Value.Id
$bag.DisplayName = $Results.value.displayname
$bag.tenantType = $Results.value.tenantType
$bag.DirectoryUsedMB = $Results.Value.directorySizeQuota.used
$bag.DirectoryQuotaMB = $Results.Value.directorySizeQuota.total
$bag.DirectoryFreeMB = (($Results.Value.directorySizeQuota.total) - ($Results.Value.directorySizeQuota.used))
Try {
$bag.DirectoryPercentConsumed = ([double]("{0:N3}" -f ($Results.Value.directorySizeQuota.used / $Results.Value.directorySizeQuota.total)))
} Catch {
$Message = "Failed to calculate 'DirectoryPercentConsumed'. See error data."
LogIt -EventID 9996 -Type $info -Msg $Message -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()
$bag.DirectoryPercentConsumed = [double]0
}
$bag.DirectoryPercentFree = ([double]("{0:N3}" -f (100 - $bag.DirectoryPercentConsumed)))

$bag.AuthenticationDurationMS = $AuthenticationDurationMS
$bag.AuthenticationDurationSeconds = $AuthenticationDurationSeconds
}

Output $bag
LogIt -EventID 9991 -Type $info -Msg "End script." -Proceed $WriteToEventLog -LINE $(_LINE_); $Error.Clear()</Script></ScriptBody>
<Parameters>
<Parameter>
<Name>ApiTokenScopeURL</Name>
<Value>$Config/ApiTokenScopeURL$</Value>
</Parameter>
<Parameter>
<Name>ApiTokenURL</Name>
<Value>$Config/ApiTokenURL$</Value>
</Parameter>
<Parameter>
<Name>ApiURL</Name>
<Value>$Config/ApiURL$</Value>
</Parameter>
<Parameter>
<Name>M365_AccountName</Name>
<Value>$Config/M365_AccountName$</Value>
</Parameter>
<Parameter>
<Name>M365_AccountPassword</Name>
<Value>$Config/M365_AccountPassword$</Value>
</Parameter>
<Parameter>
<Name>M365_ClientID</Name>
<Value>$Config/M365_ClientID$</Value>
</Parameter>
<Parameter>
<Name>M365_ClientSecret</Name>
<Value>$Config/M365_ClientSecret$</Value>
</Parameter>
<Parameter>
<Name>EventIDFilter</Name>
<Value>$Config/EventIDFilter$</Value>
</Parameter>
<Parameter>
<Name>PoshLibraryPath</Name>
<Value>$FileResource[Name='Res.M365SL.M365Library.ps1.Resource']/Path$,$Config/PoshLibraryPath$</Value>
</Parameter>
<Parameter>
<Name>ScriptOutputType</Name>
<Value>Serialized</Value>
</Parameter>
<Parameter>
<Name>TenantName</Name>
<Value>$Config/TenantName$</Value>
</Parameter>
<Parameter>
<Name>TLSVersion</Name>
<Value>$Config/TLSVersion$</Value>
</Parameter>
<Parameter>
<Name>WorkflowName</Name>
<Value>M365SL.OrgMon.Serial.PA_($Config/WorkflowName$)</Value>
</Parameter>
<Parameter>
<Name>WriteToEventLog</Name>
<Value>$Config/WriteToEventLog$</Value>
</Parameter>
</Parameters>
<TimeoutSeconds>$Config/ProbeActionTimeoutSeconds$</TimeoutSeconds>
</ProbeAction>
</MemberModules>
<Composition>
<Node ID="POSH"/>
</Composition>
</Composite>
</ModuleImplementation>
<!--<OutputType>System!System.PropertyBagData</OutputType>-->
<OutputType>Windows!Microsoft.Windows.SerializedObjectData</OutputType>
<InputType>System!System.BaseData</InputType>
</ProbeActionModuleType>