HomeNewsletterCommunityMVP FeedToolsArchiveBlogToday's NewsAboutServicesQuick Links★ Pro Subscribe free
Imran Awan — EndpointWeekly

Blog

Thoughts on Microsoft endpoint management, IT leadership and building a newsletter in public.

Live · Updated daily at 07:00 UTC
What's New Today — Official Vendor News
Today's announcements direct from Microsoft, OpenAI and Google. No community blogs — vendor sources only.
View today's news →
Copilot 25 September 2026
Copilot's New “Autopilot” Is Not Windows Autopilot: What the 25 September Relaunch Actually Ships
Microsoft relaunched Copilot around Home, Code, Autopilot and Office. Nothing is GA, the new Autopilot has nothing to do with Windows Autopilot, and the Auto-apply new services toggle is on by default.
IA
Imran Awan
👁 Read post →
Windows Server 25 September 2026
Windows Deployment Services Is Being Deprecated — Here Is What Actually Changes
Microsoft has deprecated the WDS server role starting with the next Windows Server release, pointing everyone at Configuration Manager. Here is how that connects to the CVE-2026-0386 hands-free deployment hardening from earlier in 2026, the exact registry key to check today, and how to inventory your own WDS dependency before you plan a migration.
IA
Imran Awan
👁 Read post →
Windows Update 25 September 2026
Windows 11 23H2 Enterprise End of Support: Build Your Intune Upgrade Plan for 25H2
Windows 11 23H2 Enterprise and Education get their last security update in November 2026. Here is how to inventory your remaining 23H2 devices, spot safeguard holds before they masquerade as deployment bugs, and build the Intune feature update policy and rollout rings to get everyone onto 25H2 before the deadline.
IA
Imran Awan
👁 Read post →
Intune 24 September 2026
Microsoft Intune Admin Tasks: The New Approval Queue, and the Source Microsoft Already Retired
Intune's new Admin tasks queue (GA, January 2026) consolidates EPM elevation requests, Defender security tasks, and Multi Admin Approval requests into one view at Tenant administration > Admin tasks. Here is the real RBAC model, the one source Microsoft's docs still list that no longer exists, and a read-only Graph API script for fleet visibility.
IA
Imran Awan
👁 Read post →
Entra ID 24 September 2026
Entra Permissions Management Is Retired. Your CIEM Coverage Might Still Have a Hole In It.
Microsoft Entra Permissions Management was fully retired on November 1, 2025, and its data deleted. The recommended replacement is a third-party product, not Defender for Cloud - and the native CIEM feature that survived is smaller, Azure-portal-only, and still changing in 2026.
IA
Imran Awan
👁 Read post →
Intune 24 September 2026
Endpoint Privilege Management Just Moved Into Your E5 License — Here's How to Actually Deploy It
From July 1 2026, Endpoint Privilege Management (EPM) is included in full Microsoft 365 E5 instead of costing extra. This is the deployment guide: what EPM actually elevates, the five elevation types, the console walkthrough for both policy types, why there's no GPO fallback, and a read-only Graph script to audit your rollout.
IA
Imran Awan
👁 Read post →
Security 24 September 2026
Microsoft Defender for Cloud Apps Retires Its Terminated-User Alert. Here Is What Replaces It.
Defender for Cloud Apps is replacing the legacy "Activity performed by terminated user" alert with a new dynamic detection, and unified RBAC now auto-enables for new customers. Here is what actually changed, how to verify your tenant, and a read-only script to catch the transition.
IA
Imran Awan
👁 Read post →
Intune 23 September 2026
Intune Deployment Plans Are Here: Build Native Ring-Based Rollouts for Apps and Policies
Intune's native ring-based rollouts are in public preview. The plan/deployment split, the exact wizard steps, the RBAC you actually need, and the two behaviours that will catch you out: final-ring replacement and assignment collisions.
IA
Imran Awan
👁 Read post →
Windows 11 23 September 2026
Windows 11 KB5124010 September Preview: Enterprise Deployment Guide — What's Fixed, What Isn't, and What to Test
KB5124010 is out as the final 24H2 optional preview. File History is fixed, but the AD domain-trust and USB Audio issues remain open. Here's the full enterprise deployment guide.
IA
Imran Awan
👁 Read post →
Intune 21 September 2026
Intune Is Moving Windows Health Attestation to Azure Attestation — Update Your Firewall Before Devices Become Noncompliant
In H1 2027, Intune will automatically migrate Windows 11 health attestation from DHA to Microsoft Azure Attestation. Devices with BitLocker, Secure Boot, or Code Integrity compliance policies can become noncompliant if the new MAA endpoints are blocked or SSL-inspected. Here's how to find affected policies, test connectivity from SYSTEM context, and fix it before the migration fires.
IA
Imran Awan
👁 Read post →
Windows 20 September 2026
KB5124008 Breaks File History: 'Reconnect Your Drive' Error Now Officially Confirmed
The September 2026 Patch Tuesday update KB5124008 causes File History to crash silently on Windows 11 24H2 and 25H2. Microsoft confirmed the issue on 19 September. Here's how to verify, detect fleet-wide, and protect your users while waiting for the fix.
IA
Imran Awan
👁 Read post →
Intune 20 September 2026
Microsoft Graph PowerShell v3 Drops Windows PowerShell 5.1 Support in Q4 2026
Microsoft started a 12-month retirement countdown for Windows PowerShell 5.1 support in Microsoft Graph PowerShell on September 16, 2026. v2.x keeps working with security fixes, but v3 - shipping Q4 2026 - runs on PowerShell 7.x only. Here is how to find and fix every admin script, scheduled task, Azure Automation runbook, and Intune script still on 5.1.
IA
Imran Awan
👁 Read post →
Security 18 September 2026
Microsoft Purview DLP: From Policy Tip Fatigue to Deterministic Data Protection
Most DLP programmes fail not because the technology is wrong but because policies enforce before anyone understands the data. This guide covers the six-stage maturity model, Exact Data Match, and the registry keys and diagnostic files that tell you why Endpoint DLP is silently not working.
IA
Imran Awan
👁 Read post →
Autopilot 18 September 2026
Moving from Classic Windows Autopilot to APDP — The IT Admin Migration Checklist
Microsoft now recommends Windows Autopilot Device Preparation for all new Windows 11 user-driven deployments. This step-by-step guide covers the exact prerequisites, group setup, deregistration order, and the one silent failure that blocks APDP even after you think you have migrated.
IA
Imran Awan
👁 Read post →
Windows 17 September 2026
Morocco Is Abolishing DST on 20 September 2026 — What Windows and IT Admins Need to Do
Morocco permanently moves to UTC+0 (GMT) on 20 September 2026. Windows devices set to Morocco Standard Time need the September Patch Tuesday update or the interim registry fix before Saturday.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 17 September 2026
Event ID 360: Every Prerequisite That Blocks Windows Hello for Business Provisioning
Event 360 in User Device Registration/Admin means WHfB provisioning will not launch. Decode every prerequisite line and get the specific fix for each one.
IA
Imran Awan
👁 Read post →
Windows 11 15 September 2026
KB5129195 Emergency Windows 11 Update: How Intune and Autopatch Admins Should Deploy It
KB5129195 fixes three September PT regressions (RDS, WSL, USB Audio) plus CVE-2026-62721. Updated 16 Sep: KB5129195 does NOT fix the domain trust regression on 25H2 + AD - see the dedicated section.
IA
Imran Awan
👁 Read post →
PowerShell 14 September 2026
slmgr.vbs Is Being Deprecated: Replace Windows Activation Scripts with the OSLicense PowerShell Module
VBScript is leaving Windows and slmgr.vbs goes with it. The OSLicense PowerShell module is the replacement, available from the September 2026 update. Here is the full migration playbook.
IA
Imran Awan
👁 Read post →
Security 11 September 2026
CVE-2026-81963: The September 2026 Windows Update Stack Vulnerability Already Being Exploited
CVE-2026-81963 is a Windows Update Stack elevation of privilege flaw rated 7.8 CVSS and confirmed exploited in the wild. A low-privilege user needs no interaction to reach SYSTEM. Here is what IT admins need to know and how to approach deployment.
IA
Imran Awan
👁 Read post →
Windows Server 11 September 2026
September 2026 Patch Tuesday Is Breaking Remote Desktop Services on Windows Server
September 2026 Patch Tuesday updates are causing Remote Desktop Services failures on Windows Server 2019, 2022, and 2025. Servers work initially then RDS hangs, dropping sessions and blocking new connections.
IA
Imran Awan
👁 Read post →
Windows 11 11 September 2026
KB5124008 Is Causing Black Screens in Citrix VDI — Explorer.exe Not Starting After Logon
September servicing (KB5120998 and KB5124008) is causing explorer.exe to fail to start in Citrix VDI environments, leaving users with a black screen after logon. Community workarounds and what to do now.
IA
Imran Awan
👁 Read post →
Windows 11 11 September 2026
KB5124008 Is Triggering Domain Logon Failures on Windows 11 24H2 and 25H2 — Machine Identity Isolation Explained
KB5124008 starts enforcing Machine Identity Isolation, a feature only supported with Windows Server 2025 DCs. If it was already enabled and your DCs are below WS2025 DFL, domain logons will fail.
IA
Imran Awan
👁 Read post →
Security 10 September 2026
ShieldCrash: What Admins Need to Know About the Microsoft Defender Patch-Bypass Claim
ShieldBreak (CVE-2026-69414) is patched in September 2026. ShieldCrash is a new researcher claim the fix is incomplete. Here is what is confirmed, what is not, and what to do right now.
IA
Imran Awan
👁 Read post →
Security 9 September 2026
September 2026 Patch Tuesday — Complete CVE Reference
All 633 CVEs from September 2026 Patch Tuesday — searchable, filterable, with plain-English IT admin notes on every vulnerability. Includes the actively exploited CVE-2026-81963 Windows Update Stack EoP used in ransomware pre-staging.
IA
Imran Awan
👁 Read post →
Windows 11 9 September 2026
Windows 11 KB5124008: September 2026 Patch Tuesday — Deploy and Verify
KB5124008 patches two actively exploited zero-days in the Windows Update Stack and ALPC. Deploy to pilot rings today — here is the full Intune runbook.
IA
Imran Awan
👁 Read post →
Security 7 September 2026
Windows Security Says Defender Antivirus Is Off. Microsoft Says It Is Not.
Microsoft confirmed a bug where Windows Security falsely reports Microsoft Defender Antivirus as turned off, even though real-time protection is still active. Here is how to verify the real status with Get-MpComputerStatus, Event Viewer, and the Intune or Defender for Endpoint portal before you escalate.
IA
Imran Awan
👁 Read post →
Windows 11 7 September 2026
Windows Blocks the inpoutx64 RGB Driver After KB5121003 - and September's Update Bakes It In For Everyone
Microsoft confirmed that RGB lighting and motherboard utility software installing a driver named inpoutx64 can make games freeze, crash, or restart the device after KB5121003. Microsoft's fix blocks the driver - and that block is being folded into the September 2026 security update for every managed device. Here is how to check if you have the driver before it changes under you, and why you should not mass-disable it.
IA
Imran Awan
👁 Read post →
Windows Update 6 September 2026
Windows Autopatch Now Controls Quality, .NET, and Quick Machine Recovery Updates — What Changes For Admins
Windows Autopatch is rolling out one governance surface for Windows quality updates, supported .NET Framework updates, and Quick Machine Recovery — with an approval-method setting Microsoft says cannot be edited once a policy is created.
IA
Imran Awan
👁 Read post →
Windows 11 5 September 2026
KB5120998 Is Silently Resetting Custom Mouse Cursors - But Only on Non-English Windows 11 Devices
KB5120998 resets custom mouse cursor schemes and animations back to Windows defaults, and reapplying them does not fix it - but Microsoft confirms this only happens on non-English Windows 11 installations. No fix yet; here's how to find who's actually exposed.
IA
Imran Awan
👁 Read post →
Windows 365 5 September 2026
Windows 365 Disaster Recovery Finally Has a Status API - Monitor Failover and Failback with Microsoft Graph
Microsoft Graph now exposes isDisasterRecoveryActive plus failoverInProgress/failbackInProgress on the Cloud PC object - real, queryable visibility into Windows 365 disaster recovery for the first time. Here's the exact API, the PowerShell, and a monitoring script.
IA
Imran Awan
👁 Read post →
Security 5 September 2026
Microsoft Edge 152 Got Two Security Updates in 48 Hours - Here's How to Prove Every Managed Device Actually Installed the Second One
Edge 152.0.4191.62 patched an actively-exploited CVE on September 2; 152.0.4191.66 followed two days later. Here's the real registry values, PowerShell, and Intune/GPO policy to prove every managed device actually installed it.
IA
Imran Awan
👁 Read post →
Windows 11 4 September 2026
Memory Integrity Shows “Off” in Windows 11 - Here's What That Actually Means
Memory integrity showing “Off” in Windows Security means two completely different things depending on the device. Here's how to tell which one you have in under a minute, the one-click fix for the easy case, and where to go for the driver-blocked case.
IA
Imran Awan
👁 Read post →
Windows 11 3 September 2026
Windows 11 26H2 Upgrade Failing? Here Are the Error Codes and What Causes Each One
0xC1900101, 0x80070070, 0xC1900208 — each 26H2 upgrade failure code points to a different root cause. Here's what triggers each one and the pre-upgrade checks that prevent them at fleet scale.
IA
Imran Awan
👁 Read post →
Windows 11 3 September 2026
Windows 11 KB5120998 Can Reset Desktop Backgrounds to Black — What IT Admins Need to Know
KB5120998 preview update (27 Aug 2026) causes some Windows 11 24H2 and 25H2 devices to lose desktop background settings, showing solid black. Manual restores don't work. Microsoft fix in progress.
IA
Imran Awan
👁 Read post →
Windows 11 3 September 2026
Teams and New Outlook Won't Open on ARM Windows 11 PCs After the August Update — Microsoft Workaround
After KB5121003/KB5121000, Microsoft Teams and the new Outlook for Windows can fail to launch on ARM64 Windows 11 PCs such as Surface Pro 11 and Surface Laptop 7, especially freshly imaged ones. Microsoft's status is Mitigated, not Resolved: here is the exact workaround, an honest look at what causes it, and how to check and fix a fleet.
IA
Imran Awan
👁 Read post →
Windows 11 2 September 2026
Windows Will Auto-Enable Memory Integrity in October 2026 - Decide Now, or Windows Update Will Decide For You
From October 2026, Windows quality updates auto-enable Memory Integrity on devices with no explicit policy set. Make the decision yourself first - via Intune's HypervisorEnforcedCodeIntegrity setting - or Windows Update makes it for you.
IA
Imran Awan
👁 Read post →
Windows 11 2 September 2026
Devices Showing 'Not Applicable' in Your Secure Boot Report? Two Very Different Things Cause That
Not applicable in your Secure Boot report means Secure Boot is off, or the device isn't reporting data - and the report can't tell you which. A tested Lenovo BIOS remediation, step by step.
IA
Imran Awan
👁 Read post →
PowerShell 2 September 2026
PowerShell 7.4 LTS End of Support: Your "Upgrade" to 7.5 Did Not Buy You Any Time
PowerShell 7.4 LTS and 7.5 both reach end of support on the same day - November 11, 2026 - because they're built on different .NET versions with different clocks. Only 7.6 LTS has real runway.
IA
Imran Awan
👁 Read post →
Intune 1 September 2026
Moving Off Group Policy? Don't Lift and Shift - Here's the Tool Microsoft Actually Built for This
Copying every GPO into Intune one-for-one just moves your technical debt to the cloud. Group Policy Analytics tells you, setting by setting, what's actually worth migrating.
IA
Imran Awan
👁 Read post →
Intune 1 September 2026
What's Actually Changing in Intune and Windows for 2026 (No Jargon Required)
Licensing got simpler, Windows devices now have two ways to talk to the cloud, and new laptops can recognise your company before they're even turned on. The plain-English rundown.
IA
Imran Awan
👁 Read post →
Windows 11 1 September 2026
Windows 11 24H2 Home and Pro Stop Getting Updates on October 14, 2026 - A Year Before Enterprise
24H2 Home and Pro end of servicing is October 14, 2026 - a full year before Enterprise and Education hit the same wall. Same build, two very different clocks.
IA
Imran Awan
👁 Read post →
Windows Update 28 August 2026
Windows 11 26H2 Is Now in Release Preview: How to Test and Prepare Your Intune Environment Before GA
Microsoft moved Windows 11 26H2 into the Release Preview channel on 27 August 2026 as build 26300.9278, and explicitly invited commercial customers to validate before general availability. Here is the pilot plan: what changed, how the shared servicing branch delivers it, and how to test Intune policies, Defender, Autopilot and rollback before you widen the ring.
IA
Imran Awan
👁 Read post →
Intune 26 August 2026
You Turned On Windows Unattended Control in Remote Help. Your Help Desk Still Can't Use It.
A step-by-step setup guide for unattended Remote Help on Windows: licensing, prerequisites, RBAC permission, and the AVD-based deploy steps Microsoft's own docs split across five pages.
IA
Imran Awan
👁 Read post →
Windows 11 24 August 2026
WMIC Has Been Removed from Windows 11: Replace Your Legacy Scripts with PowerShell and CIM
The August 2026 preview update (KB5067470) removes wmic.exe from Windows 11 for good - no Feature on Demand fallback. WMI itself is untouched. Here is the full WMIC-to-PowerShell translation table, where legacy calls hide in the enterprise, and a read-only script that inventories every wmic dependency before the removal breaks it.
IA
Imran Awan
👁 Read post →
Windows 11 24 August 2026
Windows 11 26H2 with Intune: Readiness, Enablement Package and Autopatch Deployment Guide
Windows 11 26H2 has not reached General Availability - it is Insider-only as of this writing, and devices on 26H1 cannot update to it at all. Here is the verified enablement package mechanism, why 26H1 is excluded, and full Intune, Windows Autopatch, and WSUS walkthroughs to get ready now, plus a read-only fleet readiness reporter script.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
The Windows patching triage decision tree: which log, which key, which tool - and the five reflex fixes that destroy your evidence
Route each patching symptom to the one evidence source that answers it. Then learn the five documented "fixes" that delete the exact artefact Microsoft's own guidance tells you to read.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
One read-only PowerShell collector for Windows patching failures - and the six traps that make naive versions lie to you
Test-Path and value checks return confidently wrong patching verdicts on real devices. Six measured traps, and a read-only collector that handles every one of them.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Rolling back a bad cumulative update: what is actually uninstallable, and how /ResetBase quietly took the option away
A KB broke something and the instinct is to uninstall it. Here is what modern servicing will and will not let you remove, and why /ResetBase deletes the option before you need it.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Delivery Optimization says it is peering and your WAN link says otherwise: diagnosing DO before you blame the network
DO falls back to the CDN silently, with no error and no Event Viewer channel to read. Here is the read-only cmdlet path that proves whether peering happened, and why.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Your Autopatch report says Up to Date and the device disagrees: reconciling cloud update reporting against on-device truth
The portal shows Up to Date and the machine in front of you is missing a patch. Here is what the cloud report is really built from, and the on-device evidence that overrides it.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
The client is fine and your WSUS server is broken: the server-side diagnostic order to run before you touch another endpoint
A client reporting zero updates is usually telling the truth about what WSUS said. Here is the server-side order that finds the declined update, the bloated SUSDB and the recycling WsusPool first.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Proving a hotpatch actually applied: the build number is the wrong witness
In August 2026 the hotpatch put Windows 11 25H2 on build 26200.9106 and the LCU put it on 26200.9168. A rising build number proves nothing. Here is the evidence chain that does.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
A driver arrived from Windows Update and broke a fleet: how to prove which policy let it through
A driver landed that nobody approved, or the one you approved never came. Here is how to prove which delivery path installed it before you change a single policy.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Four sources disagree about your update history: which one can answer which question
Get-HotFix returned 4 rows, the WUA history 153 and the component store 415 on one device. None is wrong. Learn what each records, what it omits, and which question it answers.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Which Update Service Is This Device Actually Registered Against? Enumerate the Service IDs Before You Debug Anything Else
Before troubleshooting why a device gets the wrong updates, enumerate the registered update services. On a real 25H2 device the names and GUIDs do not match Microsoft's documentation.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
The KB installed fine and is still being offered: supersedence, and why 'applicable' is a separate field
One 25H2 device held 199 Superseded, 121 Installed and 95 Staged packages while Get-HotFix showed 4 rows. Here is how to tell installed from applicable before you reinstall anything.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Decoding WUfB deferrals: why your 7-day ring is really a 37-day ring
Your update ring says a 7-day quality deferral; the device is 37 days behind. Learn to compute a device's real patch position from four stacked clocks instead of trusting the portal.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Your Intune update ring says Succeeded: where the policy actually landed, and how to prove it
Intune reports delivery of policy, not effective configuration. MDM update settings land in PolicyManager, not the classic Policies hive - here is how to read the on-device truth.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Event 26 said "found 0 updates" 1,815 times: proving what the device is really missing with wsusscn2.cab
Windows Update reporting zero missing updates is not evidence of compliance. Microsoft's signed offline catalogue and the WUA API give you a real missing-updates list with no network in the loop.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
A clock 12 minutes out breaks Windows Update, and the error never mentions time
Windows Update authenticates over TLS and, in a domain, over Kerberos - both of which read the local clock. Measure the skew with w32tm before you touch the update stack.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Windows Update fails signature validation: diagnose catroot2 and the trusted root store before you delete anything
Only one of four trust-failure classes is a catroot2 problem, and Microsoft renames that folder rather than deleting it. Decode the code and ask the file before you stop a service.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Features on Demand and language packs vanish after a feature update: why servicing drops them and how to detect it first
After an in-place upgrade, RSAT tools and language features are simply gone, and nothing is corrupt. Here is why servicing drops optional content, and how to catch it before your users do.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
"Component Store Cleanup Recommended: Yes" - decide with evidence, and know what /ResetBase costs
DISM says cleanup is recommended and admins either ignore it for years or /ResetBase the whole fleet. Real measured data from one device shows why both are wrong.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Reserved storage: prove it is actually enabled before you blame it for a disk-space update failure
Reserved storage is set at deployment time, not toggled at will, and an unelevated DISM query returns Access is denied - not Disabled. Verify the real state before you blame disk space.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
"We couldn't complete the updates, undoing changes": reconstructing a rollback from what it leaves behind
The user sees a friendly message and the device reverts; the ticket arrives with no error code at all. Here is how to recover the code, the phase and the timeline from the rollback logs afterwards.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
SetupDiag already named your upgrade failure: reading the report Windows Setup left on the device
Windows Setup runs SetupDiag automatically when an upgrade fails, writing the matched rule name to disk and the registry. Read that before you touch anything - Disk Cleanup destroys it.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
0xC1900101 is not one error: the extend code after it names the phase that killed your feature update
0xC1900101 is a generic rollback code with nine documented causes. The extend code beside it decodes to a setup phase and operation, and that tells you which driver class to hunt.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
The folders that look like corruption: Panther, $WINDOWS.~BT and $WINDOWS.~WS after a failed feature update
A feature update fails and the evidence lands in hidden folders whose names read like disk corruption. Here is the real layout, which log lands where per phase, and how long you have to collect it.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
A feature update failed and setupact.log is 547 MB: read setuperr.log first
Windows Setup keeps its own logs, separate from CBS.log and the WU traces. On this device setupact.log is 547 MB and setuperr.log is 9 KB - and the 9 KB file names the failure.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Get-HotFix is lying to your patch report: it only sees CBS updates
Get-HotFix returned 4 rows on a device tracking 415 servicing packages. Microsoft documents it as CBS-only. Here is how to diagnose patch state properly.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
A WSUS device installed something WSUS never approved: diagnosing dual scan before you touch a policy
A device pointed at WSUS pulls updates straight from Microsoft, and nothing errors. Here is how to prove which service a scan actually used before you change a single policy value.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Your TargetReleaseVersion pin says 24H2 but the device is running 25H2
A real corporate device pinned to 24H2 is running 25H2. A pin caps what Windows Update offers - it never rolls back - and once overtaken it blocks every feature update.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Your Windows Update config reverted itself: WaaSMedicSvc, protected services, and the two other things that undo your changes
You disabled wuauserv and it came back; sc config on WaaSMedicSvc is denied even as admin. Learn which of three mechanisms actually reverted you, and the supported control plane instead.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
wuauclt /detectnow Does Nothing: Diagnosing Patching Through the Update Session Orchestrator
wuauclt /detectnow returns instantly and silently because it stopped working years ago. Learn what UsoSvc, MoUsoCoreWorker.exe and the UpdateOrchestrator tasks actually do, and how to prove a scan happened.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
The update stuck at 0% is a BITS job, not Windows Update: read the transfer queue first
A download stuck at 0% is a claim about a transfer queue nobody has read. Here is how to enumerate BITS jobs, decode their states and find the blocker before you restart a single service.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
0x8024402C and 0x8024401C: the proxy your browser uses is not the proxy Windows Update uses
0x8024402C is a name-resolution failure and 0x8024401C is an HTTP 408. Both usually mean the WinHTTP machine proxy is wrong, not your browser proxy. Prove which one before you change anything.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
0x80070002 and 0x8007000D: the same two Win32 codes mean five different things
Neither code is a Windows Update error code, which is why the advice for them contradicts itself. Localise the raise site in the logs first, then apply the one fix that matches.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Stop resetting SoftwareDistribution: diagnose datastore.edb first, because the reset deletes your evidence and your update history
Renaming SoftwareDistribution destroys datastore.edb, the local IDs that make WindowsUpdate.log readable, and your update history. Diagnose the real fault first - here is the read-only path.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
The update that installs at every boot and never finishes: reading pending.xml and the primitive operations queue
A device reboots, shows Working on updates, reverts, and repeats forever. Here is how to read pending.xml, poqexec.log and the Setup event log to find the stuck queue before you delete anything.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
TiWorker.exe at 100% CPU for an hour: how to tell whether it is hung, or doing exactly what it should
Helpdesk says kill TiWorker.exe. Usually it is mid-transaction and killing it corrupts servicing. Here is how to measure forward progress in CBS.log and tell busy from wedged before you touch it.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
"Pending reboot" has at least five sources and your tooling probably checks one
Windows has no single reboot-pending flag - it has five independent markers owned by different components. Read all of them, and learn why a stuck CBS flag blocks your next update.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Error 0x80073712: Prove the Component Store Is Really Corrupt Before You Rebuild Anything
0x80073712 means a CSI transaction refused to commit because component metadata failed validation. /CheckHealth does not scan, it reads a registry marker, so name the bad manifest before repairing.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
Error 0x800f081f is not a verdict: find the missing payload in CBS.log before you point DISM at a source
CBS_E_SOURCE_MISSING means servicing wanted a payload and could not find it - not that your store is corrupt. Identify the package and fault class first, then choose a source.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
WindowsUpdate.log is 276 bytes of pointer text: reading the real ETW traces with Get-WindowsUpdateLog
Windows Update stopped writing a text log in Windows 8.1; the evidence is now binary ETW .etl files. Here is how to prove the trace is running, decode it correctly, and read the result.
IA
Imran Awan
👁 Read post →
Windows Update 23 August 2026
CBS.log is 73,450 lines and one of them is your answer: how to read the servicing log before you run SFC
CBS.log is written by the servicing stack, not Windows Update, and SFC overwrites the evidence you needed. Here is how to find the first real error, measured on a live Windows 11 device.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Your Autopilot Device Came Back From Repair and Won't Enroll — Here's Why
A repaired laptop shows the generic Windows setup screen instead of your company's branded one, even though Intune still lists it. Here's why Autopilot's hardware hash treats a motherboard or TPM swap as a brand new device, and the exact steps to fix it.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot pre-provisioning: the reseal step is the part everyone gets wrong
The green success screen at the end of an Autopilot technician flow confirms enrollment, not completion. Here is the documented phase boundary between the technician flow and the user flow, what reseal actually does, and how to read the ESP tracking registry to tell which phase a device really finished.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
A browser test is not a network test: how proxies and TLS break-and-inspect kill Autopilot
The device has internet, the portal says the profile is assigned, and OOBE still fails. Here is the documented Autopilot endpoint set, why TLS break-and-inspect breaks device registration specifically, why an authenticated proxy has nobody to authenticate as during OOBE, and how to test each endpoint from the context that actually fails.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Which apps actually block the Enrollment Status Page (and why yours did not)
You set the ESP to block until your required apps install, it cleared in four minutes, and half the apps were missing. The ESP does not wait for your assignment list, it waits for a tracked set it computes once per phase. Here is exactly which apps make that set, which are silently ignored, and how to prove it from the device.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
You Deleted It From Intune and It Still Cannot Re-Enrol: Autopilot's Three-Object Problem
A retired Autopilot device is three separate records: the Autopilot registration, the Intune managed device, and the Entra ID device object. Deleting one does not delete the others. Here is the object model, the documented deletion order, and a read-only Graph script that audits all three for cross-object orphans.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The ZTDID: The One Attribute That Proves a Device Is Really Autopilot-Registered
A device enrols, reports compliant, and still never joins your all-Autopilot dynamic group. The reason is a marker called the ZTDID, stamped into physicalIds on an Entra device object you never created. Here is where it lives, why dsregcmd will never show it to you, the verbatim dynamic group rules that depend on it, and a read-only Graph script that finds every device missing it.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The Autopilot Conditional Access deadlock: requiring a compliant device can block the enrolment that makes devices compliant
A brand-new Autopilot device cannot be compliant before it is enrolled, so a Conditional Access policy that demands compliance during OOBE can block the very enrolment that would create it. Here is the exact token sequence, the documented app IDs, the four policy shapes that actually deadlock, the one shape Microsoft says is safe, and a read-only Graph script that audits your tenant for all of them.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
It attested last month: how a TPM firmware update breaks Autopilot self-deploying mode
Autopilot self-deploying mode and pre-provisioning authenticate the device with its TPM, and that needs a readable endorsement key certificate. Firmware TPMs fetch that certificate from the vendor on first use, so an OEM firmware update can break a device that worked yesterday. Here is what Microsoft documents about EK certificates, TPM clearing, PCR banks and the attestation error codes, plus a read-only script to baseline your fleet before the next firmware wave.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The ESP Hit Its Time Limit, The User Clicked Continue Anyway, And The Device Went Live Without Its Baseline
The Enrollment Status Page time limit is not a patience setting. It is the moment Windows hands the provisioning decision to your end user. Here is what each ESP failure-path setting really does, which documented bitmask draws the Reset, Try Again and Continue Anyway buttons, and how to detect afterwards that a device entered production despite a failed ESP.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Enrollment Configuration Priority: Why Your Second ESP Profile Never Applied
Device configuration profiles merge. Device enrollment configurations do not. Exactly one Enrollment Status Page profile, enrollment restriction or Windows Hello enrollment policy applies per device, chosen by the lowest priority number, and Intune never tells you which one lost. Here is the documented model, how to read the effective configuration from Graph and from the device registry, and a read-only script that flags profiles shadowed so completely they can never apply to anyone.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Assign User Does Not Lock the Device: What Autopilot AssignedUser Really Does
Assigning a user to an Autopilot device writes two strings to a cloud object and pre-fills a username. Microsoft documents enforcement in exactly one narrow case, and documents the ADFS exception in the same paragraph. Here is what AssignedUser actually does, why the Intune primary user can name somebody else entirely, and a read-only Graph script that finds every mismatch.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot Language, Region and Keyboard: The Profile Skips a Screen, It Does Not Install a Language
You set Language (Region) in the Autopilot profile, the OOBE screens disappear, and the device still boots in English with a US keyboard. That is not a bug. The OOBE language, the Windows display language, the system locale, the keyboard layout and the regional format are five separate settings with five separate mechanisms, and the profile only touches one of them. Here is exactly what the documented locale property and keyboardSelectionPageSkipped Boolean do, what needs a language pack or LXP instead, and a read-only script that reports every layer of the stack.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot silent BitLocker: the race between the ESP and your encryption policy
Silent BitLocker encryption during Autopilot is a race, not a switch. Windows encrypts the disk itself after OOBE with XTS-AES 128-bit, while Intune tries to deliver your disk encryption policy first. Here is the documented ordering, the full prerequisite list, the DeviceEncryptionStatus bitmask, and how to audit a fleet for Autopilot devices that never encrypted.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Troubleshooting Autopilot from inside OOBE: Shift+F10, the diagnostics page, and the policy that locks you out
A failed Autopilot device at OOBE has no desktop, no user session and no Event Viewer. Microsoft documents three interactive ways in and one that runs without you. Here is what each route produces, how to get logs off a device with no sign-in, and why the tag file that blocks Shift+F10 locks out the people who deployed it.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Enrolled Is Not Protected: Defender for Endpoint Onboarding During Autopilot
A device finishing Autopilot and appearing in Intune does not mean Microsoft Defender for Endpoint is onboarded. Onboarding is a separate policy-driven handshake that the sensor cannot complete until OOBE finishes. Here is the mechanism, the registry and event surface Microsoft documents, and a read-only script that tells you whether a device is onboarded, not onboarded, or onboarded but not reporting.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The Clock Is the First Dependency: How Time Skew Breaks Autopilot and Looks Like a Network Fault
Kerberos and OAuth both authenticate with timestamps, so a device with a dead CMOS battery or a factory clock set to the wrong year cannot authenticate at all. Microsoft documents the failure as TPM attestation errors and ESP timeouts, which sends admins chasing firmware and networks for hours. Here is why time gates token validation, the W32Time defaults that make a pre-join device worse rather than better, the documented event surface, and a read-only readiness script.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot device naming templates: the 15-character wall and the duplicate hostnames it silently creates
An Autopilot device name template has a 15-character budget, and Microsoft documents that an over-long %SERIAL% is truncated from the beginning of the sequence. Here is the exact arithmetic, why truncated serials from one vendor batch collide, what a duplicate hostname breaks in DNS and NetBIOS, and how to design a template that cannot collide - plus the hybrid-join naming path that supports no variables at all.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The Intune Connector Certificate Expires and Hybrid Autopilot Stops, With No Alert
Hybrid Autopilot depends on one on-premises service, and it authenticates to Intune with a machine credential Microsoft never documents the lifetime of. When that credential stops working the connector goes quiet, every domain join hangs, and nothing alerts you. Here is the documented health surface, the event channels, the Graph properties to poll, and a read-only script that gives you a verdict before deployment day does.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot into co-management: the ConfigMgr client handshake that has to happen in order
A co-managed Autopilot device needs three handshakes to land in order: Entra join and Intune enrollment, ConfigMgr client install AND registration from the cloud management gateway, then the workload authority map. Get the ordering wrong and you get a device that is enrolled, has a client, and obeys neither. Here is the documented sequence, the CCMSETUP properties that matter, and how to prove from the device which authority owns each workload.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Corporate or personal? How Autopilot devices get their ownership label, and what breaks when it is wrong
Intune stamps device ownership at enrolment time based purely on the enrolment route. Autopilot devices should land on corporate, but Entra-registered and Company Portal enrolments land on personal, and that single label decides what inventory Intune collects, whether Device query works, and which policies apply. Here is how ownership is determined, what the corporate identifiers feature really does on Windows, and how to audit and correct it.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot Device Preparation Needs an Assigned Group, Not a Dynamic One
Autopilot device preparation rejects the dynamic device groups classic Autopilot taught you to build, and it also needs the Intune Provisioning Client service principal as an owner of that group. Here is the exact group model, the permission grant nobody documents, and how to verify both with read-only Graph calls before deployment day.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Intune Platform Scripts Have No Guaranteed Order - and Autopilot Will Prove It
Microsoft documents that Intune platform scripts run before Win32 apps, and documents the phase order inside an Autopilot device preparation deployment. It documents no order at all between one platform script and another. Here is what is actually guaranteed, how to read the real order off a device, and the two design patterns that replace a script chain.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Autopilot device preparation leaves a different footprint - and your diagnostics scripts cannot read it
Your trusted Autopilot troubleshooting steps return blank values on a device preparation deployment that worked perfectly. Device preparation assigns a policy to a user group instead of a profile to a registered device, and it does not use the Enrollment Status Page - so the classic registry surfaces are legitimately absent. Here is exactly which surfaces are missing, why, and how to tell the two flows apart from the device.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The ESP device phase and user phase are two different machines: policy targeted at the wrong one never lands
The Enrollment Status Page runs its device preparation and device setup phases in device context, before any user exists, then runs account setup as the signed-in user. Anything assigned only to a user group cannot be enforced by either device phase. Here is the documented boundary, the CSP that proves it, and how to read from a device which phase did what.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Hybrid Autopilot Needs a Domain Controller in OOBE, and 802.1X, Wireless-Only Sites and VPN Branches All Break That
Microsoft documents that a hybrid Autopilot device must be on the internal network with access to a domain controller, resolve the domain DNS records, and talk to a domain controller to authenticate the user. Autopilot enforces part of that with a ping. The device holds no domain credential and no certificate at that moment, which is exactly why 802.1X ports, guest-only wireless and VPN-dependent branches fail. Here is the documented requirement, the honest options, and a read-only script that tests a provisioning network before deployment day does.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Four ways a device gets into Autopilot, and why they behave differently forever
OEM, reseller, manual CSV and automatic registration all produce identical-looking rows in the Windows Autopilot devices list, then behave differently for the rest of the device's life. Who can deregister, what survives in Entra ID, what happens after a motherboard swap, and why Microsoft Graph exposes no provenance property at all.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Who Owns the Device After Autopilot: Primary User, Device Affinity, and the Shared-Device Case Where Nobody Should
Intune sets a device primary user from whoever completed OOBE. That drives Company Portal, user-targeted apps, and self-service BitLocker key retrieval. On a shared or kiosk device it is actively wrong. Here is what Microsoft documents about primary user versus enrolled by versus device owner, what self-deploying mode and shared PC mode really change, and a read-only Graph script that finds every device where the recorded owner disagrees with reality.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Reading AutopilotConfigurationFile.json: Every Documented Field Mapped Back to the Intune Switch
Microsoft documents exactly nine properties for AutopilotConfigurationFile.json, and none of them share a name with the switch you flipped in the Intune blade. Here is the definitive mapping across all three surfaces - the offline JSON, the Microsoft Graph deployment profile and the Provisioning diagnostics registry key - plus the longer list of portal settings that never reach the JSON at all and where they actually live.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
The Autopilot PIN nobody can reset: Windows Hello recovery on day two
Autopilot enrols every new user into Windows Hello for Business and hands them a PIN, because provisioning is on by default. PIN recovery is off by default. Here is what that gap costs on day two, and how to close it before the first device ships.
IA
Imran Awan
👁 Read post →
Autopilot 21 August 2026
Your Update Deferral Policy And The Quality Update Autopilot Installs During OOBE Meet Inside The ESP
Windows OOBE now installs monthly security update releases during Autopilot, gated by the ESP setting Install Windows quality updates. Microsoft documents that your Update ring deferrals and pauses are honoured, and that the ESP does not exit until the ring has synced. Here is the documented sequence, the one setting that breaks it, the resolved-policy registry path that tells you what a freshly provisioned device actually got, and how to design rings that do not fight provisioning.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Attack Surface Reduction rules broke a line-of-business app: reading the audit events, finding the rule, and the exclusion that does not work the way you think
An ASR rule in Block mode kills an app and tells you nothing but a GUID. Here is the complete rule reference with every documented GUID, the five mode codes, how to read event 1121 and 1122 to attribute a block to one rule and one process, and why the three exclusion models are not interchangeable.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
SMB signing became mandatory and your NAS stopped working: signing, encryption, guest or SMB1?
Windows 11 24H2 and later require SMB signing, refuse insecure guest logons and ship without SMB1. Each control breaks a different class of NAS, scanner or legacy share, and none of the errors names the cause. Here is how to identify which control rejected a connection - registry, event IDs, drivers, GPO, Intune and PowerShell - and how to make an exception for exactly one of them.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The WinRE partition is too small: 0x80070643 and the recovery-partition resize you cannot avoid
A Windows Recovery Environment servicing update fails with 0x80070643 and admins chase Windows Update instead of disk geometry. Here is what WinRE is, why the update needs 250 MB free in the recovery partition, how to size the affected population across a fleet, and what the documented reagentc plus diskpart repair really does to a running machine.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Memory Integrity will not turn on: finding the incompatible driver, and what the vulnerable driver blocklist actually blocks
Memory Integrity (HVCI) is the highest-value hardening toggle in Windows 11, and it silently refuses to start when any loaded driver fails its requirements. Here is what HVCI actually enforces, the documented hardware prerequisites (including the TPM claim everyone gets wrong), how to find the blocking .sys by name and path from Win32_DeviceGuard, the registry, the CodeIntegrity event channel and setupact.log, and how the Microsoft vulnerable driver blocklist differs and how to prove it is on.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The component store is corrupt, so every update fails: what WinSxS actually is, and what DISM and SFC really do to it
WinSxS is not a folder of duplicate files, it is the Windows component store, and most of what Explorer counts there is hard links. Here is what the component store actually is, exactly what every DISM /Cleanup-Image switch does including the irreversible ones, what SFC does differently, the correct order to run them in according to Microsoft's own support article, and why /RestoreHealth fails when it cannot reach Windows Update.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Controlled folder access blocked your backup software: reading the block events and allowing one app without allowing everything
Microsoft Defender's controlled folder access blocks untrusted processes writing to protected folders, and it surfaces as a plain access-denied error with nothing pointing at Defender. Here is what it protects by default, how the trust decision is made, how to read event IDs 1123 and 1124 to get the exact process and target path, and how to allow one application without unprotecting a folder.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
DNS over HTTPS in Windows 11: encrypting resolution without blinding yourself
Windows 11 ships a DNS over HTTPS client that most estates have never configured. Here is exactly how it decides to encrypt, what it does to split-horizon DNS and domain-joined devices, every registry, event log, netsh, PowerShell, GPO and Intune surface involved, and a read-only script that reports the posture your devices really have.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Exploit Protection Mitigations: The Per-Process Hardening Nobody Configures, and the XML That Rewrites All of It
Exploit protection is the in-box successor to EMET, with twenty-two documented mitigations across two configuration levels. Almost nobody deploys it, and the single XML file that deploys it rewrites every executable it names and does not roll back when the policy is removed. Full reference: registry, event IDs, GPO, Intune, PowerShell, and a read-only audit script.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
LSA Protection, RunAsPPL and Credential Guard: Three Defences for One Target, and the Driver That Stops Them All
LSASS is the highest-value target on a Windows device, and Windows offers three overlapping protections for it. Admins enable LSA protection thinking they got Credential Guard, or set RunAsPPL and never notice a smartcard driver stopped it loading. Here is what each one actually stops, every registry, event, GPO and Intune surface involved, and how to prove from a device which are genuinely running rather than merely configured.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Print Spooler Hardening After PrintNightmare: The Settings That Actually Stopped It, and the Driver Installs They Broke
Microsoft flipped the Point and Print driver installation default on 10 August 2021 and a decade of "let the user add the printer" practice stopped working. Here is what the vulnerability class actually was, every documented hardening control and precisely what it blocks, the registry and Event Viewer surface, both Group Policy paths, the Intune Settings Catalog reality, and the supported ways to give users their printers back without reopening the hole.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Hardening Remote Desktop on Windows 11: NLA, encryption level, and the settings that still leave RDP exposed
Enabling RDP is one toggle. Hardening it is a dozen settings across the registry, Group Policy or Intune, and Windows Firewall. What Network Level Authentication actually does, what SecurityLayer and MinEncryptionLevel really control, the session timeouts and lockout interaction most guides skip, and how to verify what is genuinely in force on a device.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Servicing Stack Update Before Cumulative Update: Why the Order Matters and What a Combined SSU+LCU Package Really Is
The servicing stack is the code that installs Windows updates, so it has to be current before a cumulative update can apply. Here is what an SSU actually is, what a combined SSU+LCU package contains, why the SSU can never be uninstalled, the documented DISM ordering for offline image servicing, and how to read which servicing stack version a Windows 11 device is on.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Smart App Control: the Windows 11 security feature you cannot switch on, and why it is off on every managed device
Smart App Control blocks unsigned and unknown code using the same engine as App Control for Business, yet it turns itself off within 48 hours on enterprise-managed devices and no GPO, Intune or CSP setting can turn it back on. Here is the full surface - the CI registry key, CiTool, the CodeIntegrity event IDs, the shipped SmartAppControl.xml - and what to deploy instead.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The Built-In Scheduled Tasks Windows 11 Actually Depends On
Windows 11 ships 284 scheduled tasks under MicrosoftWindows, and 47 of them are Disabled on purpose. A reference for which ones matter, what each does, what observably breaks when a hardening baseline switches them off, and how to audit a fleet read-only - including why there is no modern GPO for this and why Intune exposes exactly one setting.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
WDAC or AppLocker: which application control to actually deploy, and why running both is a trap
Windows has two application control stacks with overlapping purpose and different futures. App Control for Business is enforced by ci.dll and needs no service; AppLocker needs appid.sys and the Application Identity service. Here is what each enforces, at which layer, where its policy lives, every Event ID for both, and what actually happens when both are active on the same device.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The machine bluescreened and there is no dump file: Windows Error Reporting, dump types, and the settings that quietly threw your evidence away
A memory dump only survives if five independent settings line up: the dump type, a page file big enough to back it, a writable destination, a retention rule that does not delete it, and - for application crashes - a WER LocalDumps key that Windows does not create for you. Here is the whole chain, the registry and event catalogue behind it, and a read-only script that tells you whether the next crash on a device will leave anything to debug.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Windows Event Forwarding: getting events off the endpoint without an agent, and the three things that silently stop it
Windows Event Forwarding ships in the box and moves selected events to a collector with no third-party agent. It also fails completely silently. Here is the full mechanism - registry, channels, services, binaries, GPO and the honest Intune position - plus a read-only script that tells you which of the three failure modes a client has.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Your firewall rule is deployed and the traffic is still blocked: profile scoping, rule merge, and the local rules you did not know were being ignored
Windows Defender Firewall has three profiles, several rule stores and a per-profile merge switch that decides whether local rules count at all. Deploy to the wrong profile, or turn local merge off without inventorying the rules your app installers created, and traffic dies with nothing obvious in the config. Here is how to read the effective rule set instead of the intended one, across registry, Event Viewer, pfirewall.log, GPO, Intune and PowerShell.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Windows Sandbox: the disposable VM in the box, and the .wsb settings that decide whether it is actually isolated
Windows Sandbox gives every Windows 11 Pro, Enterprise and Education device a throwaway hypervisor-isolated desktop. It launches with networking, clipboard sharing and vGPU all on, and a write-enabled mapped folder survives disposal. Here is every documented .wsb element, its security consequence, and the eight Group Policy and Intune settings that override the configuration file entirely.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Windows Search finds nothing, or eats the disk: the index, its database, and the rebuild you should almost never do blindly
The Windows Search index is a real database on disk, and most search failures are a crawl-scope or Group Policy problem rather than a corrupt catalog. Here is what the index actually is, where it lives, which Event IDs matter, and the ordered diagnostic path that avoids a blind multi-hour rebuild.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
A Safeguard Hold Is Blocking Your Feature Update: Finding Which One, and Why the Opt-Out Is Not a Fix
One device in the ring never gets the feature update, and Windows says nothing. That is a safeguard hold - Microsoft withholding the release from devices with a known-bad app, driver or hardware combination. Here is how the compatibility appraiser feeds it, where the eight-digit hold ID lives in the registry, why it all dies without diagnostic data, and why DisableWUfBSafeguards belongs in a validation ring and nowhere else.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Setting Default Apps and File Associations at Scale: the XML That Works, and the Per-User Hash That Defeats Scripting
Making Acrobat the default PDF handler across a fleet has no one-line answer. Windows guards every default with a per-user hash and reverts anything it did not write itself. Here is the full association model, the DISM export, and the difference between a one-time default and an enforced one.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Your branch office still saturates the WAN: how Delivery Optimization picks peers, and how to prove peering actually works
Delivery Optimization is on by default in LAN mode and almost nobody verifies it works, so a site with 200 devices downloads the same 4 GB update 200 times and nothing errors. Here is what the six download modes actually do, exactly how a peer group is formed from GroupID and GroupIDSource, why Windows 11 changed the LAN default, the honest answer about DO Event IDs, and the byte counters that prove whether peering works instead of assuming it does.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Dev Drive on Windows 11: a ReFS volume with a different antivirus model, and the security tradeoff nobody reads
Dev Drive is a ReFS volume where Filter Manager detaches every minifilter except antivirus, and Defender switches to an asynchronous performance mode. The build speed is real. So is the fact that you changed how a whole volume is protected. Here is exactly what changes, what the docs actually say, and every registry, GPO, Intune and fsutil surface that governs it.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The Enablement Package: How 24H2 Becomes 25H2 in a Reboot (and Why That Is Not a Real Upgrade)
Windows 11 24H2 and 25H2 share one servicing branch and one identical set of system files, so the version change is a tiny enablement package and a single restart - not a multi-gigabyte upgrade. Here is how to tell which path a device is on from its build number, where the eKB leaves evidence in the registry, Setup log, CBS log and component store, and why identical code still means two different end-of-support dates.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The firewall flipped to Public and broke everything: Network Location Awareness and the domain-detection race
Being domain-joined does not earn you the Domain firewall profile. Windows only grants the DomainAuthenticated category after a DNS SRV lookup finds a domain controller and an LDAP bind on TCP 389 succeeds. If the NIC wins that race, the network is classified Public and every Domain-scoped rule is inert. Here is the full chain, the registry and event evidence, and the mitigations Microsoft actually supports.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Storage Sense deleted the file a user needed: what it removes, when, and how to pin it centrally
Storage Sense empties the Recycle Bin at 30 days, deletes Downloads files by last-opened date, and turns cached OneDrive files back into placeholders. Here is exactly what each lever removes, the documented day thresholds, the low-free-space trigger, and the full policy surface for pinning it from Intune or Group Policy.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Virtualisation-based security will not start: the firmware, hypervisor and licensing prerequisites in the order Windows checks them
VBS is the foundation Credential Guard, Memory Integrity and Secure Launch sit on, and when it will not start the Settings UI tells you nothing. There is a definite prerequisite chain - firmware virtualisation, SLAT, Secure Boot, the platform security level, the hypervisor launch type - and it always fails at one identifiable link. Here is how to read which one, with every Win32_DeviceGuard enum translated.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The Windows 11 Context Menu: Where Your App's Right-Click Entries Went, and the Supported Way to Get Them Back
Windows 11 ships two context menus, and every legacy IContextMenu shell extension is demoted behind Show more options. Here is the documented model, the registry surface, why the widely-copied CLSID override is the wrong fleet answer, and what Microsoft actually supports.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Why this device cannot upgrade to Windows 11: reading the real hardware gate instead of guessing
"Not eligible for Windows 11" is one message hiding several independent checks: CPU model on the published supported list, TPM 2.0 present and enabled, UEFI firmware that is Secure Boot capable, memory, and system disk. Here is exactly what the compatibility appraiser writes when each one fails, where it writes it, how to read every gate directly with PowerShell, and the honest, documented position on registry bypasses.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Windows Protected Print: The Driverless Future, and What Stops Working the Day You Enable It
Windows protected print mode blocks every third-party print driver and prints only through the inbox IPP class driver. Here is exactly what it changes, what it uninstalls, and how to inventory a fleet's readiness before you commit.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
BitLocker asked for the recovery key after a firmware update: Measured Boot, the PCRs, and which change broke the seal
A BitLocker TPM protector seals the volume master key to a set of Measured Boot values held in Platform Configuration Registers. Change the firmware, Secure Boot state, the boot manager or a validated BCD setting and the seal stops validating, so the device asks for 48 digits. Here is what each PCR measures, the documented default validation profiles, which real change touches which register, and how to attribute a recovery prompt to a specific measurement using the BitLocker Management event channel and the measured boot log.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
File Explorer takes eight seconds to open a folder: finding the shell extension doing it
File Explorer loads third-party COM DLLs into its own process and calls them once per file. One handler that touches the network makes every folder open slow, and Windows publishes no event that names it. Here is every registration location, the documented 15-slot icon overlay limit, and a read-only way to find the culprit.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
The laptop was flat by morning: Modern Standby, the sleep state your fleet actually uses
Most modern laptops no longer use S3 sleep. They use Modern Standby, an S0 low-power idle state where Windows stays partially running and a single power request, wake timer or misbehaving driver can drain a battery behind a closed lid. Here is what Modern Standby actually is, how to tell which variant a device uses, and which built-in powercfg reports and Kernel-Power events name the exact offender.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Quick Assist vs Remote Help: the free one is a social-engineering vector, and the paid one is why
Quick Assist ships on every Windows 11 device and authorises a full remote-control session with a six-digit code read out over the phone - the exact opening move in documented tech-support scams and Black Basta ransomware intrusions. Remote Help is the licensed alternative with tenant-scoped Entra authentication, Intune RBAC, Conditional Access and session reporting. Here is how each one authenticates, what each one logs, and every documented way to remove or block the free one.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Windows Subscription Activation: When the Device Says Pro but You Licensed Enterprise
Modern Windows Enterprise activation has no product key and no KMS host. A device installs as Pro, a licensed user signs in with their Entra account, and Windows steps up to Enterprise. Here is the mechanism, the prerequisites in order, and how to diagnose a device stuck on Pro.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Reset this PC: cloud download versus local reinstall, and why the local one keeps failing
Reset this PC has two image sources: rebuild from the files already on the device, or download a fresh copy from Microsoft. Local reinstall is faster and works offline, but it rebuilds Windows from the component store that is already damaged on the devices you most need to reset. Here is the documented mechanism, what each option preserves, the WinRE and WinRE-networking dependencies, the log paths that actually explain a failure, and how to trigger either path centrally from Intune, a CSP or Graph.
IA
Imran Awan
👁 Read post →
Windows 11 21 August 2026
Reliability Monitor: the built-in view that answers "what changed before it broke"
Reliability Monitor puts crashes, bugchecks, driver installs and update installs on one timeline - and it is nothing more than a WMI client over two documented classes. Here is what it aggregates, where the data lives, every documented reason it appears empty, and how to run the same correlation across a fleet with PowerShell.
IA
Imran Awan
👁 Read post →
Windows 11 19 August 2026
Task Manager AI Workload Visibility: NPU Monitoring for IT Pros
Windows 11 Task Manager now shows NPU utilisation, AI workload types, and per-process AI usage on Copilot+ PCs. Every column, counter, and PowerShell query you need.
IA
Imran Awan
👁 Read post →
Autopilot 17 August 2026
You Changed the Group Tag and Nothing Happened: The OrderID Assignment Chain
A group tag is not a device setting. It is written to the Entra device object as OrderID, matched by a dynamic group rule, which then drives profile assignment - three stages, each with its own delay. Plus the flag that means group tag changes will never redirect a device at all.
IA
Imran Awan
👁 Read post →
Autopilot 17 August 2026
Autopilot Reset, Wipe, or Fresh Start: Which One Actually Does What You Want
Three device actions that all sound like 'reset it', with genuinely different outcomes - and one hard limitation nobody expects: Autopilot Reset does not support Entra hybrid joined devices at all. What each action preserves, the WinRE prerequisite that fails with 0x80070032, and why local and remote reset treat the primary user differently.
IA
Imran Awan
👁 Read post →
Autopilot 17 August 2026
Stuck on "Securing Your Hardware": TPM Attestation and Error 0x800705B4
Self-deploying and pre-provisioning modes authenticate the device itself using TPM 2.0 attestation. When that fails you get 0x800705B4 - a timeout, not an explanation. Here are the four prerequisites attestation actually needs, why virtual machines can never pass, and a tested script that checks all of them.
IA
Imran Awan
👁 Read post →
Autopilot 16 August 2026
Hybrid Autopilot Fails Silently If Your ODJ Connector Is Below 6.2501.2000.5
Intune Connector for Active Directory builds older than 6.2501.2000.5 can no longer process enrollment requests. Hybrid Autopilot does not tell you that - it fails with an offline domain join timeout instead. How to check the connector, what the join method registry value proves, and why skipping the DC connectivity check moves the failure later.
IA
Imran Awan
👁 Read post →
Autopilot 16 August 2026
Where ESP Progress Actually Lives: The Category-Status JSON in the Registry
The Enrollment Status Page writes its own progress to the registry as three JSON blobs - one per phase, with a state and the exact on-screen text for every subcategory. That means you can determine precisely which step an ESP hung on after the fact, without trawling MDM diagnostic logs.
IA
Imran Awan
👁 Read post →
Autopilot 16 August 2026
CloudAssignedOobeConfig Decoded: Which OOBE Screens Your Profile Actually Skipped
One REG_DWORD on every Autopilot device encodes which OOBE screens your deployment profile suppressed. Here is how to decode the documented bits, a tested script that does it for you, and an honest warning about the bits Microsoft has never published - including the two that were set on a real device.
IA
Imran Awan
👁 Read post →
Autopilot 16 August 2026
Your Autopilot Profile Edit Didn't Apply: The Cache Nobody Checks
You edited the Autopilot deployment profile, synced the device, and nothing changed. That is because the profile is downloaded exactly once, at provisioning, and cached in two places - the registry and a JSON file on disk. Here is where it lives, how to read the download date, and why the hardware hash is cached there too.
IA
Imran Awan
👁 Read post →
AI 16 August 2026
AI-Powered Phishing Doesn't Need to Beat MFA - It Just Needs Your Conditional Access Policy to Say "MFA" Instead of "Phishing-Resistant"
AI-generated pretexting makes AiTM reverse-proxy phishing kits far more convincing, but the reason they still succeed is a Conditional Access setting: policies that require generic "MFA" instead of a phishing-resistant authentication strength. Here is a Graph-based script that audits every policy in your tenant for the gap.
IA
Imran Awan
👁 Read post →
Career 16 August 2026
The Cybersecurity Certification Path for Intune Admins in 2026 (SC-900, SC-300, SC-500, SC-200)
A practical, no-fluff certification order for Intune/Entra admins who want to move into identity and security work — which exams matter, which to skip, and why AZ-500 retiring changes the plan.
IA
Imran Awan
👁 Read post →
Security 16 August 2026
Your RMM Tool Has a Service Principal in Your Tenant. Does It Have Intune Admin Rights?
DragonForce ransomware breached an MSP through its RMM platform and pivoted into downstream client networks. Here is a PowerShell audit that finds every service principal in your tenant holding Intune- or Entra-admin-equivalent Graph permissions before an upstream compromise becomes your incident.
IA
Imran Awan
👁 Read post →
Security 16 August 2026
Intune, Defender, and Entra ID in 2026: What Is Actually Unified vs Still Fragmented
A practitioner audit of what genuinely works as one system across Intune, Defender, and Entra ID today, and what is still three portals wearing one licensing bundle.
IA
Imran Awan
👁 Read post →
Entra ID 16 August 2026
Your Conditional Access "Compliant Device" Check Is Trusting a Signal That Could Be Weeks Old
Require device to be marked as compliant reads a stored flag, not a live device check - and Intune gives silent devices up to 30 days before that flag is questioned. Here is how to measure the gap with Microsoft Graph and a read-only PowerShell script.
IA
Imran Awan
👁 Read post →
Security 15 August 2026
Pass-the-Passkey: How a Windows Event Log Let Attackers Replay Your Entra Sign-In (CVE-2026-34348)
For several minutes, a genuine passkey sign-in to Entra ID could be replayed by anyone who could read the local Windows event log - no phishing, no stolen private key, no password. From Michael Grafnetter's Pass-the-Passkey research at Black Hat USA 2026: what got logged, why Entra didn't catch the replay, and how to verify your fleet is patched (CVE-2026-34348) without ever touching the log's sensitive content.
IA
Imran Awan
👁 Read post →
Security 13 August 2026
BlackLotus Isn't Fixed When the Certificate Updates: Tracking All Four Secure Boot Mitigations
Your Secure Boot report shows the 2023 certificate installed - but CVE-2023-24932 (BlackLotus) needs four sequential mitigations to actually close, and a cert-only check misses the other three. What each mitigation does, the registry bitmask that tracks them, and a ConfigMgr hardware inventory technique for fleet-wide tracking that Intune's own report doesn't cover.
IA
Imran Awan
👁 Read post →
Windows Update 12 August 2026
KB5121003 and KB5120240: What's Actually New in August 2026's Patch Tuesday
KB5121003 (24H2/25H2, builds 26200.9168 / 26100.9168) and KB5120240 (23H2, build 22631.7517) landed 11 August 2026 with no known issues - but File Explorer, Search and Windows Hello ESS changes roll out gradually via Controlled Feature Rollout. What's actually in it, why some devices won't show it yet, and a script to confirm your fleet landed on the right build.
IA
Imran Awan
👁 Read post →
Microsoft Entra ID 11 August 2026
SMS and Voice MFA Are Being Retired in Entra ID: A Scenario-Based Guide to What Replaces Them
Passkeys become the Entra ID default on 1 September 2026 and SMS/voice MFA retires on 1 February 2027 - but one blanket replacement for everyone is the wrong call. A scenario-based framework for office users, admins, frontline shared devices, and onboarding/recovery, with a read-only readiness audit script.
IA
Imran Awan
👁 Read post →
Security 9 August 2026
Microsoft Edge Now Lets Users Sign In With Google — Here's What Enterprise Admins Need to Do
Edge now shows a Google sign-in option for browser profiles. On managed endpoints, that means corporate passwords and history can sync to a personal Google account.
IA
Imran Awan
👁 Read post →
Security 9 August 2026
Device Code Phishing: How Attackers Steal Microsoft 365 Sessions Without a Password
A user visits the real microsoft.com/devicelogin page, enters a real code, and hands an attacker a valid OAuth token - no password stolen, no MFA bypassed. How the flow is abused, how to spot it in Entra sign-in logs, and how to block it with Conditional Access.
IA
Imran Awan
👁 Read post →
Autopilot 7 August 2026
Windows Autopilot MDM Log Collection: Complete Troubleshooting Reference
Every command, registry key, event ID, and error code for diagnosing Windows Autopilot enrollment failures. Covers MdmDiagnosticsTool.exe, Get-AutopilotDiagnostics, ESP registry analysis, ODJ Connector logs, and hardware hash collection.
IA
Imran Awan
👁 Read post →
Security 7 August 2026
Windows August 2026 Patch Tuesday: SharePoint Unauthenticated RCE, Kernel Privesc, and What’s Actually Good in KB5101684
A no-auth SharePoint RCE chain, a Windows kernel privesc, and 200-300+ CVEs land on 12 August. Here is what to patch first and what to enable in KB5101684.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 4 August 2026
Windows Hello for Business Not Working on a Hybrid-Joined Device — Step-by-Step Diagnostic Walkthrough
WHfB signs in with a PIN but Event 360 keeps firing? This walkthrough traces the real command sequence — dsregcmd, AAD event logs, VPN PRT refresh — and finds the root cause: a domain controller you cannot reach.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
dsregcmd /status Decoded: The Complete Field Reference for WHfB and PRT
One command answers more WHfB questions than any portal - and its forty-plus fields come with almost no explanation. This is the field-by-field reference: every dsregcmd /status section, what each line means, and which values are good, so you read the whole picture instead of the three lines you recognise.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
The Complete Windows Hello for Business Event ID Catalog (Across All Three Logs)
WHfB logs to three different places with cryptic IDs and no index. This catalog maps which log holds what - User Device Registration (358/360/362/363), HelloForBusiness Device Unlock (3520-8520), and AAD - and what each event is telling you, so you stop guessing which log to open.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Force Phishing-Resistant Sign-In: Requiring WHfB With Conditional Access Authentication Strength
Enabling WHfB makes it available - it does not make it mandatory. A Conditional Access authentication strength does. WHfB is one of three methods that satisfy the built-in Phishing-resistant MFA strength; here is how to require it on sensitive resources, and the primary-auth trap that generates lockout tickets.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows as a Passkey Provider: Where WHfB Ends and Passkeys Begin (24H2)
Windows Hello is already a passkey provider - it can create, store and unlock passkeys for the whole web with the same PIN or biometric your users have for WHfB. This closing post in the series maps where WHfB ends and passkeys begin, and the 24H2 privacy-consent controls enterprises need to govern them.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello Signs In Fine but File Shares Prompt: Fixing On-Premises SSO
The user signs in with their PIN and cloud apps work, but a file share throws a credential prompt. Hello is fine - the hand-off to an on-premises Kerberos ticket broke. This walks the PRT to partial-TGT to full-TGT chain and shows how to find the exact broken link with dsregcmd, klist and nltest.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello Survives a Password Change - Your Saved Credentials Might Not (DPAPI)
Changing a password does not break WHfB sign-in - it uses a key, not the password. But a password RESET can orphan the DPAPI master key, and suddenly saved Wi-Fi drops and Credential Manager throws 0x80090345. Here is why the two are independent, and how to stop the DPAPI casualties.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Deploying FIDO2 Security Keys Alongside Windows Hello - and Locking Them Down by AAGUID
A FIDO2 key is the portable companion to a device-bound WHfB credential - but enabling FIDO2 without restrictions lets users register any key from a drawer. This covers passkey profiles, enforcing attestation, and restricting registration to the exact key models you trust by their AAGUID.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
TPM and Windows Hello for Business: Require It, Diagnose It, and the Firmware-TPM Traps
The TPM is what makes a WHfB key unexportable - but without RequireSecurityDevice, some of your fleet may be running Hello on software keys with no hardware guarantee. This covers requiring the TPM properly, diagnosing lockout with Get-Tpm, and the fTPM/PTT firmware traps that wipe credentials.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
How to Cleanly Disable or Remove Windows Hello for Business (Without Leaving Orphaned Keys)
WHfB is enabled by default on every Entra joined device - Autopilot turned it on, not you. Disabling it cleanly is a three-part job across the tenant policy, device policy and the credential cleanup. Here is how to do it at the right layer without scattering orphaned keys across your directory.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello for Business During Autopilot: Why It Provisions When You Did Not Expect It
A new Autopilot device pops a 'set up a PIN' prompt nobody configured - or fails provisioning on a hybrid device at first boot. WHfB is enabled by default on Entra joined devices and the tenant policy fires at enrolment. Here is how to control exactly when, and whether, Hello provisions.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello for Business PIN Complexity: Every Setting, CSP and GPO (and the 24H2 Trap)
The WHfB PIN complexity Group Policy is not where you would look, and PIN expiration silently stopped working on Windows 11 24H2 with VBS. This documents every PIN setting in CSP and GPO, and the two traps that make admins think their policy is broken when it is working as designed.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello for Business Dual Enrollment: A Privileged PIN for Admins (Cert-Trust Only)
Dual enrollment lets an admin enrol both their standard and privileged accounts for Hello on one device and elevate with a PIN instead of a password. It is powerful and narrow - certificate trust only, GPO only, and not a PAW replacement. Here is the full setup including the AdminSDHolder step.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Shadow Credentials: Detecting the msDS-KeyCredentialLink Attack Hiding in Your WHfB Deployment
The same attribute that stores WHfB keys - msDS-KeyCredentialLink - is one of Active Directory's most abused escalation primitives. This defender's guide covers how the Shadow Credentials attack works, how to catch it with Event 5136 auditing, and how to cut the write paths that enable it.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Inside the NGC Container: Why 'Just Delete the Ngc Folder' Is Terrible Windows Hello Advice
The NGC container is where your WHfB private key lives - and 'just delete the Ngc folder' is the internet's most destructive fix for it. Here are the real PassportForWork registry keys, the Event ID catalog, the supported certutil reset, and a Proactive Remediation pair - not another folder-delete guide.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello PIN Reset Done Right: Destructive vs Non-Destructive (and the Free Service Nobody Enables)
The default WHfB PIN reset throws away the credential and re-enrols - which can lock out hybrid key-trust users above the lock screen. Non-destructive PIN reset fixes that, is free, and almost nobody turns it on. Here is how to deploy it and prove it is live with dsregcmd CanReset.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello Multifactor Device Unlock: Require a Trusted Signal, Not Just a PIN
Trusted signal unlock makes a device open only when the user proves themselves AND the machine sees a trusted signal - a known Wi-Fi network or a paired phone. This guide covers the exact credential-provider GUIDs, the signal-rule XML, and the Device Unlock event IDs to verify it.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Where Windows Hello for Business Keys Really Live: The msDS-KeyCredentialLink Deep Dive
The WHfB public key lives in one AD attribute - msDS-KeyCredentialLink - and almost nobody looks inside it. This deep dive decodes the key credential structure, shows how to enumerate and audit it with PowerShell, and explains how to find and clean up orphaned keys safely.
IA
Imran Awan
👁 Read post →
Entra ID 31 July 2026
Zero Reviewers Responded, So Entra Auto-Approved a Departed Admin
An Entra access review whose deadline passes with no responses can auto-apply a default decision of Approve, so a stale or departed user silently keeps a privileged role. Here's the exact setting combination, how to check it, and a read-only PowerShell audit.
IA
Imran Awan
👁 Read post →
Entra ID 31 July 2026
Your Classic Entra Connect Sync Server Stopped Exporting — and Cloud Sync Monitoring Won't Catch It
You monitor modern Entra Cloud Sync, but a second domain still syncs through classic Entra Connect Sync on an ageing server. Its scheduler drifted or it slipped into staging mode, exports stopped, and objects silently went stale. Here's how to audit Connect Sync health with the ADSync module and a read-only PowerShell script.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
Entra Says "No Risky Users" — But a Real Detection Just Auto-Dismissed Itself
A risky sign-in fires a real detection, the user passes MFA under a risk-based policy, the riskState flips to remediated, and they vanish from the risky users report. Here's how to resurface every dismissed and auto-remediated detection with Microsoft Graph.
IA
Imran Awan
👁 Read post →
Intune 31 July 2026
Your Intune Filter Matches Zero Devices and the Portal Won't Tell You
An include assignment filter with a subtly wrong rule can match zero devices, so a policy assigned to All Devices silently lands on nobody - with no error. Here's why it happens and a read-only PowerShell script that flags the traps.
IA
Imran Awan
👁 Read post →
Entra ID 31 July 2026
Group-Based Licensing Fails Silently for Some Users — Here's How to Find Them
Assign Microsoft 365 licences to a security group and for some members the assignment silently fails - a service-plan conflict, too few licences, or a missing usage location. The group looks fine; the error only lives in each user's licenseAssignmentStates. Here's how to audit it with Microsoft Graph.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
Windows LAPS vs Legacy LAPS: The Migration Drift Where Two Managers Fight Over One Password
You migrated from legacy Microsoft LAPS to Windows LAPS and the portal looks clean. But if the old client and GPO are still applying, two managers fight over the local admin password and only one actually rotates. Here's a device-side drift audit.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
A Revoked Certificate That Still Signs In: The Entra CBA Revocation Gap
You enable phishing-resistant certificate-based auth, issue smart-card certs, then revoke one when someone leaves. But if the CA's CRL distribution point is missing from your Entra CBA trust store, Entra never checks revocation and the revoked cert keeps signing in. Here's why, and a read-only PowerShell audit that catches it.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
Global Secure Access Is On, But Your Internet Traffic Never Entered the Tunnel
You rolled out Global Secure Access and assumed traffic was now tunnelled and inspected. By default only the Microsoft 365 profile is enabled - Internet and Private access ship disabled. Here's how to audit GSA traffic forwarding profile coverage with Microsoft Graph before a Conditional Access assumption breaks.
IA
Imran Awan
👁 Read post →
Intune 31 July 2026
You Scoped That Admin to One Scope Tag. They Can Still See Every Untagged Object.
Intune scope tags are an allow-list of what a scoped admin CAN see, not a wall around what they can't. Any policy, profile or app you forget to tag silently gets the Default scope tag and stays visible. Here's the mechanism and a read-only PowerShell script to find every leaky object.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
A Partner Tenant Can Satisfy Your MFA Requirement For You
Your Conditional Access requires MFA, yet a guest from a partner tenant signs in without ever being challenged. An inbound trust setting is accepting MFA already satisfied in their tenant. Here's how to audit every cross-tenant inbound trust with Microsoft Graph.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 30 July 2026
Key Trust vs Certificate Trust vs Cloud Kerberos Trust: Which One Is Your Device Actually Using?
Three trust models, and most admins cannot say for certain which one a given device is running. This guide decodes the difference, then shows the exact commands and registry values that prove - not guess - whether a device is on key trust, certificate trust or cloud Kerberos trust.
IA
Imran Awan
👁 Read post →
Windows 30 July 2026
Windows Hello for Business Doesn't Work Over RDP — Here's What Actually Does
A user signs into their laptop with a fingerprint, then RDPs to a server and gets thrown back to a password prompt. WHfB credentials are TPM-bound to the local device and can't be used on a remote session. Here are the two real supported fixes, and a script that checks which one your device is ready for.
IA
Imran Awan
👁 Read post →
Entra ID 30 July 2026
Temporary Access Pass: The Passwordless Bootstrap Nobody Talks About
A new hire needs Windows Hello for Business set up on day one with no password yet. A user loses their only passwordless method and support has no way back in. A Temporary Access Pass solves both - here's exactly how the lifetime settings work, the two-TAP gotcha, and an audit script.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 29 July 2026
Migrating Windows Hello for Business From Certificate Trust to Cloud Kerberos Trust (and Retiring NDES)
There is no in-place migration from certificate trust to cloud Kerberos trust - the Windows Hello container must be deleted first. Here is the safe phased cut-over, the certutil -deletehellocontainer step, and how to decommission NDES without breaking your Wi-Fi and VPN certificates.
IA
Imran Awan
👁 Read post →
Intune 29 July 2026
Your Intune Portal Shows What Was Assigned. This Script Shows What Actually Landed.
The Intune admin center reports what a policy was assigned to. It doesn't tell you what actually landed in the registry on that device. Here's a script that reads all six real local sources of truth and builds one readable report - no Graph, no internet required.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 28 July 2026
Windows Hello for Business Cloud Kerberos Trust: The Complete Deployment Guide
Cloud Kerberos trust deploys Windows Hello for Business with no PKI and no AD FS. This end-to-end guide covers the partial-TGT mechanism, Entra Kerberos setup with Set-AzureADKerberosServer, the exact Intune, CSP and GPO settings, and how to prove it works.
IA
Imran Awan
👁 Read post →
Entra ID 28 July 2026
A Lapsed Entra ID P2 License Doesn't Pause PIM — It Deletes Every Eligible Assignment
When your Entra ID P2 or Governance license lapses, Conditional Access policies freeze in place - but PIM eligible role assignments are deleted outright, while standing admin access survives untouched. Here's the exact behaviour, and a script to check your exposure first.
IA
Imran Awan
👁 Read post →
Security 23 July 2026
Your BitLocker Escrow Report Says 100%. When Did Anyone Last Prove One of Those Keys Still Matches the Drive?
A recovery key escrowed to Entra ID or AD is tied to a specific KeyProtectorId - one protector, one point in time. Re-image a drive or rotate a protector, and the escrowed record can quietly go stale while your audit still reports GREEN.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Windows Autopilot Deployment Modes Explained: User-Driven, Self-Deploying, and White Glove
User-driven, self-deploying, and pre-provisioning look interchangeable in the Intune dropdown. They aren't — pick the wrong one or leave a stale device record behind, and the device drops straight to standard, unbranded OOBE.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Autopilot-Capable Isn’t Autopilot-Registered: The Hardware Gap That Breaks Deployment
A laptop can meet every Windows Autopilot hardware requirement on paper and still fail hardware hash capture or profile assignment. Here's the exact SMBIOS and hash-capture gap that causes it, and how to check for it before deployment day.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
The Enrollment Status Page Isn't Blocking What You Think It's Blocking
ESP shows progress for a lot more than it actually blocks on, and the gap between 'tracked' and 'blocking' is exactly why an app can show failed while it's sitting there installed and working. Here's what ESP really enforces and how to configure a timeout policy that doesn't trap users forever.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Flip a Co-Management Workload to Intune Too Early and the Policy Gap Is Invisible
Co-management splits management authority per workload between ConfigMgr and Intune — but switch a workload before the equivalent Intune policy exists, and devices lose settings silently, with no error anywhere.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Cloud Management Gateway: Why "Not Connected to CMG" Almost Always Means a Certificate, Not a Server
A device shows healthy CMG deployment on the console, yet the client says it can't reach it. Here's what CMG actually does and why cert trust or CRL/OCSP reachability — not the gateway itself — is usually the real cause.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Intune Management Extension: Why Your Win32 App Is Stuck at "Processing"
A required Win32 app stuck at 'Processing' for days isn't an Intune problem — it's the Intune Management Extension agent on the device. Here's what it does, how it installs, and the real fix.
IA
Imran Awan
👁 Read post →
Entra ID 23 July 2026
An Entra Registered Device Isn’t a Security Gap — It’s a Different Job Entirely
An admin sees 'Microsoft Entra registered' and assumes it's the weak, unmanaged category — then tries to force BYOD devices into full join and breaks access for a whole team. Here's what actually separates joined, hybrid joined, and registered.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Switching Co-Management Workloads to Intune: Pilot Collection First, Never All Seven at Once
Switching all seven co-management workloads to Intune at once for your whole estate is how organisations silently lose GPO and baseline settings enforcement overnight. Here's the staged, pilot-first rollout Microsoft actually documents.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Windows Autopilot Fails During OOBE: The Errors, Event IDs, and Fixes That Actually Matter
Devices stuck on 'Just a moment', ESP timeouts, and Something went wrong pages during Autopilot deployment — here are the real Event IDs, error codes, and root causes behind them, plus a read-only script.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Deregister an Autopilot Device Out of Order and You Can Orphan It Permanently
Windows Autopilot registration is a two-part process, and deregistering a device the wrong way — or deleting the Entra device object manually — can leave it permanently stuck. Here's the exact correct order across Intune, Autopilot, and Entra ID, plus a read-only PowerShell script to check status before and after.
IA
Imran Awan
👁 Read post →
Security 22 July 2026
How Many People Are Still in Your Local Administrators Group From a Request Six Months Ago?
LAPS proves your local admin password rotates. It doesn't prove nobody's quietly accumulated permanent access. Here's a device-side detection script for Intune Proactive Remediations that catches local admin group drift.
IA
Imran Awan
👁 Read post →
Entra ID 22 July 2026
Your Entra Cloud Sync Job Has Been Failing Quietly for Three Weeks — Here's How to Catch It
Hybrid sync errors pile up silently until a helpdesk ticket arrives weeks later. Here's how Entra Cloud Sync job health actually works via Microsoft Graph, the gotcha with CountSuccessiveCompleteFailures, and a PowerShell script that catches it early.
IA
Imran Awan
👁 Read post →
Security 22 July 2026
How Many of Your BitLocker Devices Actually Have a Recovery Key Escrowed Anywhere?
If it's not 100%, some of your encrypted devices are one recovery prompt away from permanent data loss. Here's why Entra-escrowed and AD-escrowed keys need two different audits, and a PowerShell script for the one Graph can actually see.
IA
Imran Awan
👁 Read post →
Security 22 July 2026
How Many of Your App Registrations Have a Secret Expiring This Week?
App registration client secrets and certificates expire silently, and nobody tracks the date until an integration breaks with AADSTS7000215. Here's a PowerShell audit that flags every expiring credential in your tenant before it does.
IA
Imran Awan
👁 Read post →
Windows 21 July 2026
Windows 11 LTSC 2024: The 5-Year vs 10-Year Lifecycle Trap
Windows 11 Enterprise LTSC 2024 has a 5-year lifecycle. Windows 11 IoT Enterprise LTSC 2024 has a 10-year lifecycle. Same feature set, same version — buying the wrong SKU for a long-life device is an expensive mistake.
IA
Imran Awan
👁 Read post →
Entra ID 21 July 2026
Find Every Privileged Role, Permission & Assignment in Entra ID
Microsoft's new PRIVILEGED label (preview) finally flags every Entra role, permission, and assignment that can lead to elevation of privilege. Here's how to find them all with PowerShell and Graph, read the escalation chains, and cut your privileged assignments down to size.
IA
Imran Awan
👁 Read post →
Security 16 July 2026
That AI Tool You Just Gave 'Read/Write All' to Entra and Intune — Would You Even Notice?
A newly adopted AI ITSM platform just asked for Directory.ReadWrite.All. Most tenants never revisit an OAuth consent grant once it's approved. Here's a PowerShell audit that flags every risky enterprise app permission in your tenant.
IA
Imran Awan
👁 Read post →
Security 16 July 2026
Is Your LAPS Password Actually Rotating — Or Just Configured? Here's How to Tell the Difference
Windows LAPS can look compliant in Intune and still have a local admin password that hasn't rotated in months. Here's why the CSP and GPO paths conflict, and a PowerShell script that tells you which devices are actually stale.
IA
Imran Awan
👁 Read post →
Entra ID 16 July 2026
How Many of Your Global Admins Are PERMANENTLY Global Admins? Here's How to Find Out
Standing privileged access is the top finding in every security review — and turning on PIM doesn't retroactively convert old active assignments to eligible. Here's a script that finds every permanent admin role in your tenant.
IA
Imran Awan
👁 Read post →
Entra ID 16 July 2026
Do You Know Which Users Have ZERO Conditional Access Policy Applied? Here's How to Check
Conditional Access targets groups and apps, not "all users" by default. Gaps open silently as your tenant grows. Here's a PowerShell script that computes real effective coverage per user and workload identity — and finds every hole.
IA
Imran Awan
👁 Read post →
Microsoft 365 15 July 2026
Building Agents for Microsoft Teams: SDK, MCP, and What IT Admins Need to Know
Microsoft's Teams SDK now lets you build native AI agents in TypeScript, C#, and Python. Here's how authentication, MCP, and governance work — and what IT admins must audit before agents go live.
IA
Imran Awan
👁 Read post →
Entra ID 14 July 2026
Passkeys Are Now the Default in Entra ID: What You Need to Do Before February 2027
Microsoft is ending SMS and voice MFA by 1 February 2027 and making passkeys the default in Entra ID. Here's the full timeline, how to find at-risk users with PowerShell, and how to run a registration campaign before the deadline.
IA
Imran Awan
👁 Read post →
Windows 11 14 July 2026
Windows June 2026: Kerberos RC4 Enforcement, Windows Ready Print, and What IT Admins Need to Do Now
June 2026 brought one of the most urgent Windows security changes in years: Kerberos RC4 Audit mode is gone. Plus Intune Compliance policy deep-dive, Defender for Endpoint via Intune, security baselines update, and Intune Suite now free in M365 E3/E5.
IA
Imran Awan
👁 Read post →
Entra ID 12 July 2026
How to Enable Passkeys with Microsoft Authenticator in Microsoft 365
Passkeys in Microsoft Authenticator give your users phishing-resistant authentication without hardware keys. Here is how to enable them in Entra ID, deploy via Intune, and verify adoption with PowerShell.
IA
Imran Awan
👁 Read post →
Windows 11 12 July 2026
Windows Monthly Updates Explained: LCU, SSU, Patch Tuesday and What Actually Gets Installed
Every month Windows ships updates and most admins do not know the difference between an LCU and a preview release. Here is the complete guide to the Windows update cadence, update types, and how to control them in Intune.
IA
Imran Awan
👁 Read post →
Microsoft 365 12 July 2026
Copilot in Excel for Finance: Skills, Data Connectors, and Plan with Copilot Explained
Microsoft has rebuilt Copilot in Excel around how finance teams actually work — with custom Skills, six new financial data connectors, and a Plan with Copilot feature that shows every step before executing.
IA
Imran Awan
👁 Read post →
Guides 12 July 2026
Active Directory Domain Controller Hardening for Hybrid Environments
Domain Controllers are the highest-value target in your environment. This post covers DCSync audit, Protected Users, Credential Guard via Intune, Kerberoasting detection, and Entra Connect hardening for hybrid AD deployments.
IA
Imran Awan
👁 Read post →
Guides 12 July 2026
Windows 365 for Agents: A Secured Cloud PC Execution Environment for AI
AI agents running on user workstations create unacceptable blast radius and auditability problems. Windows 365 for Agents gives each agent its own isolated, Intune-managed Cloud PC with network isolation and full audit logs.
IA
Imran Awan
👁 Read post →
Intune 12 July 2026
How to Look Up a Windows Autopilot Device by Serial Number Using PowerShell
The exact Graph PowerShell filter syntax to look up any Autopilot device by serial number — single device, bulk CSV, Group Tag updates, and what to do when the filter returns nothing.
IA
Imran Awan
👁 Read post →
Active Directory 12 July 2026
10 Essential PowerShell Commands Every Active Directory Administrator Should Know
The 10 PowerShell commands every AD administrator needs: DC enumeration, replication status, FSMO roles, stale account cleanup, lockout detection, password policy review, and DC port connectivity testing.
IA
Imran Awan
👁 Read post →
Guides 11 July 2026
MD-102 Exam Guide: How to Pass the Microsoft Endpoint Administrator Certification
The complete guide to passing MD-102: Endpoint Administrator. Covers all five exam domains with official skill percentages, real Intune scenarios, PowerShell examples, and exam-day tips — built entirely from Microsoft Learn.
IA
Imran Awan
👁 Read post →
Intune 11 July 2026
Windows 11 Start Menu Policy Settings: The Complete Intune & CSP Reference
Every Windows 11 Start menu policy setting explained — CSP paths, GPO equivalents, and exactly how to deploy them via Intune custom OMA-URI profiles. Pin layouts, power buttons, account options, and pinned folders all covered.
IA
Imran Awan
👁 Read post →
Windows 11 10 July 2026
Microsoft's AI Is Hunting Windows Vulnerabilities Before Attackers Do — What MDASH Means for Your Fleet
Microsoft's MDASH — a multi-model AI scanning harness — is now hunting Windows vulnerabilities before attackers find them. Expect more patches, faster. Here is what MDASH actually does, why you should expect higher patch volume, and how to configure Windows Autopatch and hotpatch to absorb it without breaking your fleet.
IA
Imran Awan
👁 Read post →
Azure 9 July 2026
Azure Files Kerberos Auth With Hybrid Identities — No More Storage Account Keys for Domain Users
Storage account keys give everyone root-level access with no per-user permissions and no SSO. Microsoft Entra Kerberos authentication fixes this — hybrid domain users access Azure Files with their Windows credentials, proper NTFS ACLs, and silent SSO at logon. Here is the complete Intune setup from storage account through to client policy and proof it is working.
IA
Imran Awan
👁 Read post →
Windows 11 9 July 2026
Windows Settings Backup Is On by Default From 26H2 — What You Need to Do Before It Hits Your Fleet
Starting with Windows 11 26H2, eligible devices will have settings backup on by default. If your backup policy is Not Configured right now, backup will start running automatically when 26H2 lands. Here is what changes, what does not, and the three decisions every admin needs to make before it reaches their fleet.
IA
Imran Awan
👁 Read post →
Intune 8 July 2026
Get a PRT Fleet Health Report in 5 Minutes Using Graph Explorer
You have deployed the PRT detection script to Intune. Now how do you see the results across your whole fleet? Two Graph Explorer queries, one JSON export, and 30 seconds in Excel gives you a complete PRT health snapshot with hostnames, UPNs, and which devices need manual intervention.
IA
Imran Awan
👁 Read post →
Entra ID 7 July 2026
The Primary Refresh Token (PRT): How Entra ID SSO Actually Works Under the Hood
The PRT is the token that powers silent SSO across every Microsoft 365 app on your Windows devices. Most admins treat it as a black box. Here is what is actually inside it, how the TPM protects it, and what breaks when it goes wrong.
IA
Imran Awan
👁 Read post →
Scripts & Tools 6 July 2026
Deploy Free WHfB Health Scripts to Intune: Six Checks, Five Auto-Repairs, Zero Helpdesk Calls
WHfB breaks silently — PRT expires, NGC keys corrupt, services stop. Here is a Proactive Remediation pair that detects all six failure modes and repairs them automatically, including the trick for running dsregcmd /refreshprt from SYSTEM context.
IA
Imran Awan
👁 Read post →
Guides 1 July 2026
Microsoft Intune Complete Roadmap: Beginner to Advanced (All 12 Chapters)
A structured 12-chapter roadmap covering everything in Microsoft Intune — from architecture and enrolment to Autopilot, compliance, Win32 apps, Defender, and troubleshooting. The learning path for MD-102 and real-world endpoint engineering.
IA
Imran Awan
👁 Read post →
Intune 1 July 2026
Intune Certificate Profiles: SCEP, PKCS, NDES and the Full Architecture
Certificate-based authentication in Intune — the full architecture from Root CA through NDES and the Certificate Connector to device and user profiles. Covers SCEP vs PKCS, lifecycle management, troubleshooting connector errors, and best practices.
IA
Imran Awan
👁 Read post →
Entra ID 1 July 2026
Microsoft Entra ID Complete Overview: Identity, SSO, Conditional Access and Licensing (Part 1)
The complete foundational guide to Microsoft Entra ID — what it is, how authentication works, core components (users, groups, devices, apps), identity types, SSO protocols, Conditional Access, licensing tiers, and Azure AD Connect hybrid identity.
IA
Imran Awan
👁 Read post →
Intune 1 July 2026
Windows Autopilot Complete Overview: Deployment Types, Components and Registration (Part 1)
The complete Windows Autopilot fundamentals guide: what it is, how it works, User-Driven vs Self-Deploying vs Hybrid deployment, required components, Autopilot profiles, device registration methods, prerequisites, and the firewall URLs you must allow.
IA
Imran Awan
👁 Read post →
Intune 1 July 2026
Intune Win32 App Deployment: Complete Guide from Packaging to Monitoring
The complete Win32 app deployment guide: packaging with IntuneWinAppUtil, install and uninstall commands, detection rules (file, registry, MSI, script), assignment types, the IME installation pipeline, monitoring, common error codes, and best practices.
IA
Imran Awan
👁 Read post →
Guides 1 July 2026
Top 20 PowerShell Commands Every Intune & Azure Engineer Needs
PowerShell is not optional for Intune and Azure engineers. Here are the 20 commands you need daily — with real-world examples from device management, identity, and automation workflows.
IA
Imran Awan
👁 Read post →
Intune 30 June 2026
Microsoft Store Apps in Intune — Deployment & Troubleshooting, End to End
Store for Business is gone — modern Intune Store apps are winget-backed. The full deployment flow, what the IME leaves on the device (registry, logs, services), the PFN vs Package ID, the error codes everyone hits, and a free read-only status script.
IA
Imran Awan
👁 Read post →
Intune 30 June 2026
Windows Autopatch — What It Actually Is, and What It Changes on Your Devices
Microsoft-managed updates sound great — but what does Autopatch actually do? The cloud back end, the registration flow, the deployment rings, and the exact registry keys, agents, tasks, services and events it leaves on a device — verified live.
IA
Imran Awan
👁 Read post →
Security 29 June 2026
Secure Boot Certificate Update 2026: Fix Non-Compliant Devices with Intune
3,052 devices showing 'Not Up to Date' in your Secure Boot Status Report? Here is the complete guide — what Secure Boot is, why the 2026 deadline matters, and how to fix both failure states with Intune Proactive Remediations and PowerShell scripts.
IA
Imran Awan
👁 Read post →
Security 29 June 2026
Which Windows Hello Gesture Did They Actually Use? Face, Fingerprint, PIN or Password
Entra only ever says "Windows Hello for Business" — never whether someone used face, fingerprint, PIN or password. Here is how I reverse-engineered the Windows event logs to build the report Microsoft does not ship.
IA
Imran Awan
👁 Read post →
Intune 28 June 2026
Microsoft Intune: Win32 vs. Store App Deployment — Complete Guide
Win32 or Store? Complete breakdown of both Intune app deployment methods — packaging, IME internals, detection rules, Autopilot ingestion order, and PowerShell scripts for every scenario.
IA
Imran Awan
👁 Read post →
Autopilot 28 June 2026
Windows Autopilot: Complete Device Lifecycle Management Guide
Zero-touch provisioning from factory to fully managed desktop. Complete guide to Autopilot deployment modes, ESP configuration, hardware hash harvesting, profile assignment, and troubleshooting the 5 most common failures.
IA
Imran Awan
👁 Read post →
Microsoft 365 27 June 2026
Agent 365 Now Requires M365 E5 — Licensing Impact and Your Options
From June 1 2026, new Agent 365 purchases require M365 E5. Existing customers are grandfathered, but E3 organisations wanting new deployments must upgrade. Full breakdown of what E5 adds, the cost comparison, and your three options.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Security Copilot for Intune — 4 AI Agents Deep Dive (Policy, Change, Offboarding, Vuln)
Microsoft Security Copilot now has four dedicated Intune agents: Policy Configuration, Change Review, Device Offboarding, and Vulnerability Remediation. E5 tenants get free SCU capacity through June 30. Complete technical guide with PowerShell scripts.
IA
Imran Awan
👁 Read post →
Copilot 27 June 2026
Copilot Cowork Is Now GA — Metered Billing, Spending Limits & IT Governance
Copilot Cowork went GA on June 16 2026 with usage-based billing — enterprises now pay per task on top of M365 Copilot licences. Off by default. This guide covers spending limits, compliance controls, and how to enable it safely for your organisation.
IA
Imran Awan
👁 Read post →
Copilot 27 June 2026
Microsoft Scout — The Always-On Autopilot Agent for M365 (Build 2026)
Announced at Build 2026, Microsoft Scout is Microsoft's first always-on Autopilot agent — it runs in the background under its own Entra identity, monitoring Teams, Outlook, and SharePoint and taking action without prompting. IT governance guide for endpoint admins.
IA
Imran Awan
👁 Read post →
Microsoft 365 27 June 2026
Microsoft 365 Copilot Auto-Install Block Guide — IT Admin Opt-Out (June–July 2026)
Microsoft is pushing the M365 Copilot app to all enterprise Windows devices June 15–July 20, even without a Copilot licence. Act before your channel window closes — here are the three methods to block it and the PowerShell to remove it if it already installed.
IA
Imran Awan
👁 Read post →
Windows 27 June 2026
Windows Hello for Business Provisioning Failure — Complete Fix
WHfB provisioning prompt never appears, or disappears silently? Event IDs 360, 362, and 363 in User Device Registration log tell you exactly why. This guide covers every cause — TPM lockout, missing PRT, policy conflicts — and the fix for each.
IA
Imran Awan
👁 Read post →
Entra ID 27 June 2026
PRT Not Working + Local Admin Missing on Entra Joined Device
Primary Refresh Token broken means no SSO to Microsoft 365. Local admin not applying means the Entra role claim hasn't refreshed. Both fixed with dsregcmd /refreshprt and a full sign-out — here's the complete guide.
IA
Imran Awan
👁 Read post →
Entra ID 27 June 2026
Entra Hybrid Join Stuck in Pending State — Complete Fix Guide
Devices stuck in Pending in the Entra portal won't receive Intune policies. This guide covers every root cause — stale certs, OU moves, AD sync gaps — with dsregcmd commands and a bulk GPO fix script.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Intune Enrollment Error Codes: Complete Troubleshooting Guide
Intune enrollment failing with a hex error code? This complete reference covers every common enrollment error — 0x80180026, 0x80070774, 80180018, 801c0003, 0x80090016 — with the exact cause and fix for each.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Intune and Apple WWDC 2026 — What IT Admins Need to Know
Apple WWDC 2026 brought major changes to MDM management — new declarative device management APIs, iOS 26 supervised mode changes, and macOS 26 privacy controls that affect Intune enrollment. Full breakdown for IT admins.
IA
Imran Awan
👁 Read post →
Windows 27 June 2026
KB5094126 Sign-in Failure Fix — Windows 11 24H2
KB5094126 is causing sign-in failures on some Windows 11 24H2 devices after installation. This post covers the symptoms, affected configurations, and both the official Microsoft workaround and the permanent fix.
IA
Imran Awan
👁 Read post →
Entra ID 27 June 2026
Entra Conditional Access: WHfB Enforcement Deadline July 2026
Microsoft's July 2026 deadline for phishing-resistant MFA enforcement is approaching. Here's what Conditional Access changes you need to make now to avoid access disruptions when the WHfB enforcement goes live.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
What's New in Microsoft Intune — June 2026
Microsoft Intune June 2026 release — new Autopilot device preparation updates, Copilot integration in Intune admin centre, and the latest policy improvements for Windows, iOS, and Android.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Top 10 Intune PowerShell Commands Every Admin Should Know
These 10 Microsoft Graph PowerShell commands are the foundation every IT admin and EUC engineer needs before moving to advanced Intune automation — covering device inventory, compliance reporting, remote actions, and bulk cleanup.
IA
Imran Awan
👁 Read post →
Scripts 27 June 2026
Export and Filter Group Policy Objects to CSV with PowerShell
A simple PowerShell script that lets you search your entire GPO estate by keyword and export the results to CSV — no manual browsing in GPMC required.
IA
Imran Awan
👁 Read post →
Autopilot 27 June 2026
Windows Autopilot Enrollment Failures: A Structured Troubleshooting Guide
A step-by-step guide for troubleshooting Windows Autopilot enrollment failures — covering hardware hash, profile assignment, network requirements, logs, and common error codes.
IA
Imran Awan
👁 Read post →
Windows 26 June 2026
Windows Update Stuck? The Complete Fix Guide (Every Verified Method)
Windows Update stuck at 0%, failing with an error code, or frozen at boot? This complete guide covers every verified fix — from the built-in troubleshooter and DISM/SFC repairs to the full component reset script — with real command outputs and community-validated methods used by thousands of IT professionals.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Autopatch Is Alerting on Expiring Secure Boot Certificates — Here's What to Do
Windows Autopatch has added a new alert: 'Secure Boot — certificate update required'. Devices using the older Microsoft Secure Boot certificates are flagged because those certificates expire in 2026. Here is what the alert means, which devices are affected, and how to get them onto the 2023 UEFI certificates.
IA
Imran Awan
👁 Read post →
Technical Guide 26 June 2026
Hotpatch for Windows 11 — June and July Are Baseline Months. Here's the Full 2026 Schedule
If your Windows 11 devices didn't hotpatch in June — that's expected. June 2026 is a baseline month, which means a full cumulative update and a restart. So is July. Hotpatch doesn't resume until August. Here is the complete 2026 schedule, what prerequisites you need, and what to check if your devices aren't hotpatching when they should be.
IA
Imran Awan
👁 Read post →
Intune 26 June 2026
Windows Autopilot Device Preparation Roadmap: What Is Coming and When to Migrate
Pre-provisioning and self-deploying modes are planned for Autopilot Device Preparation but not yet available. Both classic Autopilot and Device Preparation run in parallel — no forced migration.
IA
EndpointWeekly Team
👁 Read post →
Intune 26 June 2026
Autopilot Device Preparation: App Limit Now 25, Managed Installer Fixed, Enterprise App Catalog Added
Three key improvements: app limit raised to 25, managed installer fix (April 2026), Enterprise App Catalog support from Intune 2506.
IA
EndpointWeekly Team
👁 Read post →
Windows 26 June 2026
Windows Autopilot Now Installs Monthly Security Updates During OOBE — What IT Admins Must Check
From January 2026, devices going through Windows Autopilot automatically receive the latest monthly security update during OOBE. Adds 20-40 min to provisioning.
IA
EndpointWeekly Team
👁 Read post →
Intune 26 June 2026
Windows Autopilot Device Preparation + Windows 365: Now Generally Available
From May 11 2026, Autopilot Device Preparation GA for Windows 365 Enterprise, Flex Dedicated, Flex Shared, and Cloud Apps.
IA
EndpointWeekly Team
👁 Read post →
AI 26 June 2026
Copilot Notebooks Now Available to Copilot Chat Users: What Is New in June 2026
Microsoft is expanding Copilot Notebooks to Copilot Chat users for the first time, rolling out in June 2026. Chat users get access via OneNote on web with standard sources and mind maps. At the same time, M365 Copilot users gain Teams meetings as a knowledge source, an Excel agent that generates spreadsheets from notebook content, auto-generated infographics, and a redesigned UI.
IA
EndpointWeekly Team
👁 Read post →
AI 26 June 2026
Microsoft Agent 365: The IT Admin Guide to Governing AI Agents Across Your Organisation
Microsoft Agent 365 is generally available as of May 1, 2026 — a purpose-built control plane for observing, governing, and securing every AI agent in your organisation. GA brings the Agent Registry backed by Entra Agent IDs, Registry Sync with AWS, Google Cloud, Salesforce and Databricks, a Shadow AI page for local endpoint agents, and deployment controls for approved agents. Here's what IT admins need to know.
IA
EndpointWeekly Team
👁 Read post →
Windows 26 June 2026
Windows 365 Developer Image: A Pre-Configured Cloud PC for Dev Teams (Build 2026)
Microsoft announced a Windows 11 developer configuration image for Windows 365 at Build 2026, now in public preview. It comes pre-installed with VS Code, Git, GitHub CLI, Python, Node.js, and WSL with Ubuntu. Here's what IT admins need to know about availability, requirements, and preview limitations.
IA
EndpointWeekly Team
👁 Read post →
AI 26 June 2026
Claude Opus 4.8 Is Now Inside Microsoft 365 Copilot: What IT Admins Need to Know
Anthropic Claude Opus 4.8 is now available directly inside Microsoft 365 Copilot alongside OpenAI GPT models. Users can choose their model, run side-by-side comparisons with Model Council, or let Auto mode pick the best option. Here is what IT admins need to know about EU Data Boundary restrictions, government cloud limitations, and how to brief your users.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Microsoft Purview DLP Now Scans Copilot Prompts in Real Time: How to Turn It On
Microsoft Purview DLP can now block Copilot from processing prompts that contain sensitive data — credit card numbers, national IDs, or custom sensitive information types your organisation defines. A default policy already exists in your tenant, but it is in simulation mode and not blocking anything yet.
IA
EndpointWeekly Team
👁 Read post →
Licensing 26 June 2026
Microsoft 365 Copilot SMB Pricing Changes July 1, 2026: What You Need to Know Before the Deadline
From July 1, Microsoft 365 Business Standard with Copilot and Business Premium with Copilot become permanent SKUs with updated list prices. If you manage licensing for a business under 300 seats, here is exactly what changes, what promos are still running, and whether to buy before June 30.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Entra ID SSPR Change: Unregistered Phone Numbers Stop Working September 7, 2026
From September 7 2026, Microsoft Entra self-service password reset will only accept methods users have explicitly registered. Directory-sourced phone numbers and emails that were never formally registered will stop working. Here is what to audit and fix before the deadline.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Microsoft Entra Custom Controls Are Being Retired: How to Migrate to External MFA Before September 2026
Custom Controls in Microsoft Entra Conditional Access stop accepting changes in September 2026 and reach end of life in May 2027. If you use Duo, Okta, or any third-party MFA provider through Custom Controls, here is your step-by-step migration guide to External MFA before the deadline.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Windows 11 June 2026 Security Alert: Secure Boot Certificate Update and BitLocker Bypass Fix
KB5094126 delivers two urgent security items: automatic migration from expiring 2011 Secure Boot certificates to 2023 certs, and a patch for CVE-2026-45585 — a BitLocker bypass that allows physical attackers to decrypt protected drives via the Windows Recovery Environment.
IA
EndpointWeekly Team
👁 Read post →
Windows 26 June 2026
Get Ready for Windows 11 26H2: What IT Teams Need to Do Now
Windows 11 version 26H2 is confirmed for Fall 2026 and is already in the Experimental Insider channel. Here is everything enterprise IT teams need to know to start testing and plan their rollout — including the critical 26H1 device upgrade dead-end.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
The Windows 11 25H2 Security Baseline Is in Intune — Here Is What Changed and How to Migrate
The Windows 11 25H2 security baseline is now in Intune. Your existing profiles will not auto-update. Here is what changed, how to handle the IE11 COM known issue, and how to migrate cleanly.
IA
Imran Awan
👁 Read post →
Windows Update 26 June 2026
Windows Autopatch Just Turned Hotpatch On By Default — Act Before It Hits Your Estate
From May 2026, hotpatch updates are enabled by default for all eligible devices in Windows Autopatch. No restart required for most months — but if your estate is not ready, you need to opt out now.
IA
Imran Awan
👁 Read post →
Licensing 26 June 2026
Intune Suite Is Now Included in M365 E3 and E5 — What Changes on July 1
From July 1 2026, Endpoint Privilege Management, Enterprise App Management, and Cloud PKI land in M365 E5 at no extra cost. M365 E3 gets Advanced Analytics, Remote Help, and Tunnel for MAM. No action needed — tenants are auto-provisioned.
IA
Imran Awan
👁 Read post →
AI 26 June 2026
ChatGPT Is Now Inside Microsoft Teams — What Every IT Admin Needs to Know
OpenAI has shipped admin-managed Teams sync for ChatGPT Enterprise. One Entra admin consent and ChatGPT can index your entire organisation Teams content. Here is what IT admins need to know before enabling it.
IA
Imran Awan
👁 Read post →
Scripts 26 June 2026
Get the Primary User and Last Sync Time for Any Intune Device — Bulk via PowerShell
You export a list of devices and all you get is hostnames. This script feeds that CSV into Microsoft Graph and gives you back the primary user, last sync time, and device status for every device in one run.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Microsoft Defender EDR Updates Now Ship via Microsoft Update — What Changes for Endpoint Admins
Microsoft now distributes Defender for Endpoint EDR component updates through Microsoft Update independently of the monthly Windows OS rollup. If you rely on manual deployment packages, you need to add the new Defender update package to your update process now.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Microsoft Defender Can Now Automatically Isolate Compromised Endpoints — Here's How It Works
Microsoft Defender for Endpoint now has a preview capability that automatically severs a compromised device from your corporate network the moment suspicious activity is detected — while keeping a secure channel open so your security team can still investigate remotely.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Defender Now Discovers and Protects Local AI Agents on Windows Endpoints
A new preview capability in Microsoft Defender for Endpoint automatically discovers local AI agents running on onboarded Windows devices — coding agents, IDE extensions like GitHub Copilot, desktop AI assistants — and provides runtime protection that can block prompt injection before it executes.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
CVE-2026-41091: Microsoft Defender Elevation of Privilege Vulnerability Exploited in the Wild — Patch Now
CVE-2026-41091 is a CVSS 7.8 elevation of privilege vulnerability in Microsoft Defender that has already been exploited in the wild. Fixed in June 2026 Patch Tuesday alongside two additional Defender CVEs. Check your Defender engine version now — it should be 1.1.26050.11 or later.
IA
Imran Awan
👁 Read post →
Technical Guide 25 June 2026
Silently Fix a Missing Primary Refresh Token with Intune Proactive Remediations
No PRT means no passwordless. The device looks healthy in Intune, compliance shows green, but WHfB provisioning silently fails. Here is the 6-step automated remediation that detects and fixes it without touching a healthy device.
IA
Imran Awan
👁 Read post →
AI Engineering 25 June 2026
AI Loops: What the Best Engineers Are Actually Building Right Now
Most people still use AI the slowest way — one prompt, one answer, repeat by hand. The engineers pulling ahead are building loops. Here is what a loop actually is, how it works, when to build one, and two copy-paste templates you can run in Claude or ChatGPT right now.
IA
Imran Awan
👁 Read post →
Technical Guide 25 June 2026
Silently Fix Broken Windows Hello for Business with Intune Proactive Remediations
NgcSet = NO on a device that looks perfectly healthy is one of the most common WHfB failure patterns. Here is the two-script Intune Proactive Remediation that detects and silently fixes it — without touching a healthy device.
IA
Imran Awan
👁 Read post →
Community Recap 24 June 2026
10 Key Takeaways from Microsoft's Windows Autopilot AMA
Microsoft's product team hosted a live AMA on Windows Autopilot deployment — Maggie D'Acuba (Product Manager, Windows Autopilot) and Perla Morales answered real questions from IT admins. Here are the 10 things that stood out.
IA
Imran Awan
👁 Read post →
Story 20 June 2026
Why I Started EndpointWeekly
Every Friday I found myself manually searching through dozens of blogs, social feeds and Microsoft docs just to stay current. I built EndpointWeekly to fix that — for myself, and for every engineer who feels the same.
IA
Imran Awan
👁 Read post →
Tips 10 June 2026
5 Intune Tips Every Admin Should Know in 2026
After years of managing Intune environments, these are the five settings, workflows and techniques that consistently save time and prevent headaches.
IA
Imran Awan
👁 Read post →
Technical Guide 11 May 2026
Automating Windows Hello for Business Enrollment with PowerShell and Intune
Devices can be Azure AD joined with a valid PRT and still have Windows Hello completely unprovisioned. Here's how I built a three-script solution to detect, remediate and automate the entire enrollment flow — silently, in user context, via Intune.
IA
Imran Awan
👁 Read post →
🔍
No posts found
Try a different search term or filter