Invoke-MtADManagementCommand
SYNOPSIS
Runs an allow-listed Active Directory management operation over WSMan/PSRP.
SYNTAX
Invoke-MtADManagementCommand [-Operation] <String> [[-ComputerName] <String>] [[-TimeoutSeconds] <Int32>]
[[-CancellationToken] <CancellationToken>] [-AllowNegotiateFallback] [-ProgressAction <ActionPreference>]
[<CommonParameters>]
DESCRIPTION
Creates a short-lived credentialed PSSession to the server resolved by the current Maester Active Directory connection. HTTPS with normal certificate validation is attempted first. An HTTP Negotiate fallback, which retains WSMan message encryption, is available only when explicitly enabled.
On non-Windows hosts, the optional PSWSMan module must be installed. The function invokes only fixed DNS inventory and SMB configuration scriptblocks, applies an operation timeout, honors cancellation at operation boundaries, and always removes a created PSSession.
EXAMPLES
EXAMPLE 1
Invoke-MtADManagementCommand -Operation SmbConfiguration
Retrieves the allow-listed SMB server configuration properties from the resolved domain controller over validated HTTPS.
EXAMPLE 2
Invoke-MtADManagementCommand -Operation DnsInventory -TimeoutSeconds 90 -AllowNegotiateFallback
Retrieves MicrosoftDNS WMI inventory and explicitly permits a Negotiate fallback if the validated HTTPS connection cannot be established.
PARAMETERS
-Operation
The fixed management operation to run. Supported values are DnsInventory and SmbConfiguration.
Type: String
Parameter Sets: (All)
Aliases:
Required: True
Position: 1
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-ComputerName
The server targeted by the management session. Defaults to the server resolved by the current Maester Active Directory connection.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: 2
Default value: [string]$__MtSession.ADConnection.ResolvedServer
Accept pipeline input: False
Accept wildcard characters: False
-TimeoutSeconds
The WSMan operation timeout in seconds. The value must be between 1 and 3600 seconds.
Type: Int32
Parameter Sets: (All)
Aliases:
Required: False
Position: 3
Default value: 60
Accept pipeline input: False
Accept wildcard characters: False
-CancellationToken
An optional cancellation token checked before connection, before remote invocation, and after the remote operation returns.
Type: CancellationToken
Parameter Sets: (All)
Aliases:
Required: False
Position: 4
Default value: [System.Threading.CancellationToken]::None
Accept pipeline input: False
Accept wildcard characters: False
-AllowNegotiateFallback
Allows fallback from validated HTTPS to HTTP with Negotiate authentication and WSMan message encryption. This function never changes TrustedHosts.
Type: SwitchParameter
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False
-ProgressAction
Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.
Type: ActionPreference
Parameter Sets: (All)
Aliases: proga
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.