Category: Endpoint
-
I’m Surrounded by a Bunch of Device Objects: Cleaning House in the Cloud Without Burning Everything Down
It’s 4:30 PM on a Friday. You’re trying to deploy a critical new Device config policy to a specific laptop, but when you type the hostname into the search bar to add the device to an Entra ID group, Microsoft Entra ID spits back three identical objects. Two are stale, one is active, and they…
-
The Dark Art of Intune Remediation: Hidden Tips, Tricks and Hacks
Intune Remediations always get introduced with the same corporate line: “A detection script finds the issue, and a remediation script fixes it.” Sure. That’s technically true. It’s also the kind of thing you say when you’ve never actually had to run this stuff across tens of thousands of endpoints. Anyone who has knows Remediations behave…
-
Your Brand-New Entra ID Joined Devices Hate Your Corporate LAN — Here’s How to Fix It
TL;DR: When you move to pure Entra ID–joined devices, they lose the ability to see traditional Active Directory Domain Controllers. Because Windows Network Location Awareness can’t complete its legacy LDAP domain-authentication handshake, it defaults to the Public firewall profile — blocking inbound management traffic like Ping, RPC, and WMI on your own LAN. The fix…
-
Windows 11 Hotpatching: Because Your Users Will Never Reboot on Purpose
TL;DR Windows 11 Hotpatching is great—if your environment is modern, standardized, and already running clean. It delivers two months of security updates with zero reboots, but it also removes the accidental stability you got from monthly forced restarts. You’ll need Windows 11 24H2, VBS, Secure Boot, TPM 2.0, Entra ID join, Intune, and Autopatch/WUfB before…
-
Preparing Your Virtual Environment for Windows 11: Tackling EFI, Secure Boot, and TPM Part – 3 Upgrading Hardware and adding TPM
The last piece of the puzzle is often upgrading the VM. Before you can add a vTPM, your environment needs to meet a few prerequisites: For the purpose of this guide, we’ll assume that you already have vCenter Server 6.7+ deployed and that virtual machine encryption and KMS are configured in your environment. These initial…
-
Preparing Your Virtual Environment for Windows 11: Tackling EFI, Secure Boot, and TPM Part – 2 Converting to GPT/EFI
So, you made it past part 1, thank you. I thought I lost you there. As I mentioned before, in the virtual environment, many IT admins didn’t update the disk configuration in the template when we transitioned from Windows 7 to Windows 10. GPT/EFI is the starting point to get us where we need to…
-
Preparing Your Virtual Environment for Windows 11: Tackling EFI, Secure Boot, and TPM – Part – 1
The clock is ticking! October 14, 2025, marks the official End of Life (EOL) for Windows 10 Enterprise. After this date, Windows 10 will no longer receive patches or security updates from Microsoft, essentially becoming unsupported. While it might continue to function, running an unsupported OS poses significant security risks. If you work in the…