Skip to content

Provisioning and Hardening

PowerShell scripts for building and securing Windows servers and domain controllers, and for bulk user creation. Source: scripts/provisioning/.

Why It Matters

Standing up and hardening servers by hand is slow and inconsistent. These scripts make common build and lockdown tasks repeatable, which is both faster and safer than clicking through them each time.

Test before production

The hardening and provisioning scripts change system and domain configuration. Review each one and run it in a test environment before using it against production.

Provisioning

Script Description
Add-2DomainControllers.ps1 Promote and configure a pair of domain controllers from variables at the top of the script
Domain-Join.ps1 Join a computer to the domain
Install-IIS.ps1 Install the IIS role if it is not already present
Run-ADSyncCycle.ps1 Trigger an Entra Connect / AD sync cycle

User Management

Script Description
Add-Users.ps1 Bulk-create Active Directory users
Add-Users-02.ps1 Bulk-create users from a comma-separated list of username, password, first and last name
AD-User-Export.ps1 Export Active Directory users to a report

Hardening

Script Description
Harden-DomainController.ps1 Enforce password complexity, enable advanced audit policy, and apply domain controller hardening
System-Hardening.ps1 Enable the Windows Firewall and apply baseline host hardening
Disable-Unneeded-Stuff.ps1 Disable Cortana, OneDrive, and other unneeded features and telemetry

Reporting

Script Description
Get-DomainInfo.ps1 Current domain and domain controller information
Get-PasswordExpiration.ps1 Password last-set and expiration dates
Get-LastBootTime.ps1 Last boot time of a host
Get-Storage.ps1 Storage and disk information