param([switch]$Elevated) function Check-Admin { $currentUser = New-Object Security.Principal.WindowsPrincipal $([Security.Principal.WindowsIdentity]::GetCurrent()) $currentUser.IsInRole([Security.Principal.WindowsBuiltinRole]::Administrator) } if ((Check-Admin) -eq $false)  { if ($elevated) { # could not elevate, quit }   else {   Start-Process powershell.exe -Verb RunAs -ArgumentList ('-noprofile -noexit -file "{0}" -elevated' -f ($myinvocation.MyCommand.Definition)) } exit } function Write-ProgressHelper { param ( [int]$StepNumber, [string]$Message ) Write-Progress -Activity 'PSC Update Readiness 2019' -Status $Message -PercentComplete (($StepNumber / $steps) * 100) } $script:steps = ([System.Management.Automation.PsParser]::Tokenize((gc "$PSScriptRoot\$($MyInvocation.MyCommand.Name)"), [ref]$null) | where { $_.Type -eq 'Command' -and $_.Content -eq 'Write-ProgressHelper' }).Count $stepCounter = 0 Write-ProgressHelper -Message 'Checking For Previous Run' -StepNumber ($stepCounter++) Start-Sleep -Seconds 2.5 $ErrorActionPreference="SilentlyContinue" $maxRepeat = 10 $Organisation = "PSC" $ThisPC = ($env:COMPUTERNAME + $env:username) $freespaceError = ("$env:COMPUTERNAME only has $spacegb GB Free and cannot continue 1903 install") $TeamViewerFileName = "c:\teamviewer_install\TeamviewerHost.msi" $InTuneLog = "c:\InTune_Log\$env:COMPUTERNAME.log" $InTuneFolder = "c:\InTune_Log\*.*" $InTune_Folder = "c:\InTune_Log\" $ts = New-TimeSpan -Hours 2 function not-exist { -not (Test-Path -Path $TeamViewerFileName) } #Set-Alias !exist not-exist -Option "Constant, AllScope" #Set-Alias exist Test-Path -Option "Constant, AllScope" Add-Type -AssemblyName System.Windows.Forms | Out-Null Stop-Transcript | out-null $ErrorActionPreference = "Continue" If (-not(Test-Path -Path $InTune_Folder)) { mkdir $InTune_Folder } filter timestamp {"$(Get-Date -Format G): $_"} if (Test-Path -Path $InTuneLog) { Remove-Item $InTuneLog -ErrorAction SilentlyContinue Remove-Item $InTune_Folder\$env:COMPUTERNAME.zip -Force -ErrorAction SilentlyContinue Remove-Item c:\InTune_Log\"$env:COMPUTERNAME"_Transcript.log -ErrorAction SilentlyContinue Remove-Item c:\InTune_Log\"$env:COMPUTERNAME".csv -ErrorAction SilentlyContinue Remove-Item c:\InTune_Log\$env:Computername-Bitlocker-Recovery-key.txt -ErrorAction SilentlyContinue Start-Sleep -Seconds 1.5} Else { # Move On } Start-Transcript -path c:\InTune_Log\"$env:COMPUTERNAME"_Transcript.log Write-ProgressHelper -Message 'Checking For Teamviewer' -StepNumber ($stepCounter++) Start-Sleep -Seconds 2.5 ############################################################################ # Teamviewer Start ############################################################################ #Get Teamviewer if (-not (Test-Path -Path $TeamViewerFileName)) { mkdir c:\teamviewer_install $url = "https://onedrive.live.com/download?cid=77FB0E4F642F10B7&resid=77FB0E4F642F10B7%21273176&authkey=AOouFE3GDGRSHIc" $output = "c:\teamviewer_install\TeamviewerHost.msi" $start_time = Get-Date $wc = New-Object System.Net.WebClient $wc.DownloadFile($url, $output) Write-Host "Temaviewer Downloaded" msiexec.exe /i "c:\teamviewer_install\TeamviewerHost.msi" /qn CUSTOMCONFIGID=6988pev APITOKEN=6581446-B1aEz7nIk9k92p4G7C1R ASSIGNMENTOPTIONS="--grant-easy-access" Write-Host "Teamviewer Installed" } Else { Write-Host "TeamViewer Already Installed" } ############################################################################# # Teamviewer End ############################################################################# Write-ProgressHelper -Message 'Checking Your PC Integrity - Integrity Is Important You Know' -StepNumber ($stepCounter++) Start-Sleep -Seconds 5 ############################################################################## # Computer Sanity Check End ############################################################################## # Power Connect Check #Function Check-BatteryState { #param($Laptop=$env:computername) #$Bstatus = ((Get-WmiObject -Class Win32_Battery).BatteryStatus) #} $Bstatus = ((Get-WmiObject -Class Win32_Battery).BatteryStatus) if($Bstatus) { switch ($Bstatus) { 1 { "Battery is discharging" } 2 { "The system has access to AC so no battery is being discharged. However, the battery is not necessarily charging." } 3 { "Fully Charged" } 4 { "Low" } 5 { "Critical" } 6 { "Charging" } 7 { "Charging and High" } 8 { "Charging and Low" } 9 { "Charging and Critical " } 10 { "Unknown State" } 11 { "Partially Charged" } } } If ($BStatus -eq 2) { # Move On } Else { [System.Windows.Forms.MessageBox]::Show("You Need To Be Connected To The Power Adapter! Please re run from Software Center when power is avalable. Exiting...", $Organisation, [System.Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::ERROR) } # Power Connect Check End #---------------------------------------------------------------------------- Write-ProgressHelper -Message 'Checking Your Free Drive Space - You Should Be Saving Everything To The Cloud Anyway' -StepNumber ($stepCounter++) Start-Sleep -Seconds 5 #---------------------------------------------------------------------------- # Free Space Check Start $disk = Get-WMIObject Win32_Logicaldisk -filter "deviceid='$((Get-WMIObject Win32_OperatingSystem -computername $env:COMPUTERNAME).systemdrive)'" -ComputerName $env:COMPUTERNAME $freespace = ($disk.FreeSpace) $spacegb = [math]::Round($disk.Freespace/1GB,2) # Free Space Check End #---------------------------------------------------------------------------- Write-ProgressHelper -Message 'Checking Your PC Is Secure - Safety First!' -StepNumber ($stepCounter++) Start-Sleep -Seconds 5 #---------------------------------------------------------------------------- # Bitlocker Status Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force $blockerstatus = (Get-BitlockerVolume -MountPoint "C:") #---------------------------------------------------------------------------- Write-ProgressHelper -Message 'Checking For PSC Admin' -StepNumber ($stepCounter++) Start-Sleep -Seconds 5 #---------------------------------------------------------------------------- # PSC Admin User Check Start $UserPassword = ConvertTo-SecureString "Restore99!" -AsPlainText -Force $psclocaladmin = $null If ($psclocaladmin = Get-LocalUser pscadmin) { Add-LocalGroupMember -Group "Administrators" -Member "pscadmin" Enable-LocalUser -Name "pscadmin" } Else { # If (!$psclocaladmin) New-LocalUser "pscadmin" -Password $UserPassword -FullName "PSC Admin" -Description "PSC Admin Account" -AccountNeverExpires -PasswordNeverExpires Add-LocalGroupMember -Group "Administrators" -Member "pscadmin" Enable-LocalUser -Name "pscadmin" } # PSC Admin User Check End #---------------------------------------------------------------------------- Write-ProgressHelper -Message 'Creating Restore Point - We Like To Play It Safe!' -StepNumber ($stepCounter++) Start-Sleep -Seconds 10 #---------------------------------------------------------------------------- # System Restore Check Start Enable-ComputerRestore -Drive "C:\" Checkpoint-Computer -Description "New Intune Setup 2019" -RestorePointType MODIFY_SETTINGS # System Restore Check End #---------------------------------------------------------------------------- ############################################################################## # Computer Sanity Check End ############################################################################## Write-ProgressHelper -Message 'Checking For Errors - Its Windows 10, As If There Would Be Errors!?' -StepNumber ($stepCounter++) Start-Sleep -Seconds 5 # Errors If($freespace -lt 32212254720 ) { $freespaceError | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output } else { # No Error To See Here, Keep Moving! } If ($blockerstatus.protectionstatus -ne "On") { Enable-BitLocker -MountPoint C: -UsedSpaceOnly -SkipHardwareTest -RecoveryKeyPath "c:\InTune_Log\" -RecoveryKeyProtector manage-bde -protectors -get c: >> c:\InTune_Log\$env:Computername-Bitlocker-Recovery-key.txt ("BitLocker Was Off") | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output } Else { manage-bde -protectors -get c: >> c:\InTune_Log\$env:Computername-Bitlocker-Recovery-key.txt } Start-Sleep -Seconds 1.5 if ($BStatus -ne 2) { ("$env:username Did Not Plug In To Mains") | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output } # AutoPilot Hardware Hash Install-Script -Name Get-WindowsAutoPilotInfo -Force Start-Sleep -Seconds 3 Get-WindowsAutoPilotInfo.ps1 -append -OutputFile "c:\InTune_Log\$env:COMPUTERNAME.csv" Start-Sleep -Seconds 2.5 Stop-Transcript # Fail $LogsExist = (Test-Path $InTuneLog) Write-ProgressHelper -Message 'Sending Data To PSC IT' -StepNumber ($stepCounter++) Start-Sleep -Seconds 4 if (Test-Path $InTuneLog) { $psclocaladmin | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output ("BitLocker Was Off, It has now been switched on by InTune Script. Please try again in an hour") | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output Compress-Archive -Path $InTuneFolder -DestinationPath $InTune_Folder\$env:COMPUTERNAME.zip Start-Sleep -Seconds 5 Send-MailMessage -from "$env:username" -to "IT" -Subject "AAD Intune Upgrade Report Fail $env:computername" -Body "$env:COMPUTERNAME InTune Logs" -Attachments "$InTune_Folder\$env:COMPUTERNAME.zip" -SmtpServer "pscconsulting-com.mail.protection.outlook.com" curl "https://onedrive.live.com/download?cid=77FB0E4F642F10B7&resid=77FB0E4F642F10B7%21273301&authkey=AEReiJb0-g1gGqc" -o "$InTune_Folder\sendfile.ps1" Invoke-Expression (($InTune_Folder)+"\sendfile.ps1") Remove-Item $InTune_Folder\sendfile.ps1 -Force -ErrorAction SilentlyContinue [System.Windows.Forms.MessageBox]::Show("The PSC IT Update Readiness Tool Has Completed Its Task. All Details Have Been Sent To PSC IT.", $Organisation, [System.Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::INFORMATION) } Else { ("BitLocker Was Already On") | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output $psclocaladmin | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output ("$env:COMPUTERNAME has $spacegb GB Free") | Format-Table | Out-File -append "c:\InTune_Log\$env:COMPUTERNAME.log" | Write-Output Compress-Archive -Path $InTuneFolder -DestinationPath $InTune_Folder\$env:COMPUTERNAME.zip Start-Sleep -Seconds 5 Send-MailMessage -from "$env:username" -to "IT" -Subject "AAD Intune Upgrade Report Success $env:computername" -Body "$env:COMPUTERNAME InTune Logs" -Attachments "$InTune_Folder\$env:COMPUTERNAME.zip" -SmtpServer "pscconsulting-com.mail.protection.outlook.com" curl "https://onedrive.live.com/download?cid=77FB0E4F642F10B7&resid=77FB0E4F642F10B7%21273301&authkey=AEReiJb0-g1gGqc" -o "$InTune_Folder\sendfile.ps1" Invoke-Expression (($InTune_Folder)+"\sendfile.ps1") Remove-Item $InTune_Folder\sendfile.ps1 -Force -ErrorAction SilentlyContinue [System.Windows.Forms.MessageBox]::Show("The PSC IT Update Readiness Tool Has Completed Its Task. All Details Have Been Sent To PSC IT.", $Organisation, [System.Windows.Forms.MessageBoxButtons]::OK, [System.Windows.Forms.MessageBoxIcon]::INFORMATION) } Write-ProgressHelper -Message 'Checkup Complete - Thanks For Playing' -StepNumber ($stepCounter++) Start-Sleep -Seconds 3