Flatten a Messy Media Library into A-Z Bucket Folders
A PowerShell script that sorts every show and movie in a folder into flat A-Z buckets, skips anything that would collide, and dry-runs honestly.
Across the notebook
Entries sharing this tag, wherever they're filed.
A PowerShell script that sorts every show and movie in a folder into flat A-Z buckets, skips anything that would collide, and dry-runs honestly.
Use PowerShell's own parser to catch typos and broken brackets in a whole folder of scripts, before anything runs.
A dry run that quietly lies to you. Why ForEach-Object's property shorthand returns nothing under -WhatIf, and the one-line fix.
Find out which resource groups are eating your Azure budget, straight from PowerShell, no portal clicking required.
One script that locks a departing user out, cleans up their groups and licenses, and keeps their mail, with a CSV record of every step.
Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
One object per update deployment with targeted, compliant, failed and unknown counts, so you can spot the deployments that need you.
Find the updates the most machines are actually missing, bundle them into a group, and deploy them to a pilot collection, with a WhatIf preview first.
Install a product key, activate it and confirm the edition actually changed, without the key ever landing in a script file or a log.
Turn "wrap this script in a package and push it to the DPs" into one command, with a dry run before anything gets created.
When Graph cmdlets start throwing assembly errors, it's almost always mixed module versions. This removes every copy and puts back one matching set.
Before you rename, rescope or delete a group, find out what it's wired to. Members, owners, licenses, apps and Intune policies, in one report.
A computer inventory straight out of AD, with OS build, last logon, password age and OU in one tidy CSV, ready for audits or a stale-machine cleanup.
Turn a folder of CBR comics into CBZ with 7-Zip, and optionally shrink the pages to WebP with cwebp or ImageMagick, testing every file before anything is replaced.
Thread: Archive conversion workshop ↗The folder layout and naming rules I use for a pile of old Mac software, and the small PowerShell script that does the renaming without losing the original names.
Repack .7z files as plain Deflate ZIPs with UTF-8 file names, including password-protected ones, and test every result before the original goes anywhere.
Thread: Archive conversion workshop ↗A quick, safe software inventory from the registry, local or remote, that returns objects you can filter and export instead of a wall of colored text.
Clean old user profiles off shared PCs and servers through Win32_UserProfile, so the folder and the registry entry go together and nobody gets a TEMP profile.
Find the old Outlook .ost files nobody is using any more and reclaim the space, without touching the ones Outlook has open.
Clear old temp files from the usual suspects and run Disk Cleanup unattended, with an age threshold and a -WhatIf that shows how much you'd get back.
When Windows Update is greyed out or just won't run, check all the policy values and services that can block it, and put them back the way Windows shipped.
Hand a list of folders from several drives to robocopy in one go, keep their structure on the new drive, catch name collisions before anything moves, and get a log per folder.
Pull shutdown, startup and crash events from the System log so you can tell a planned restart from a power cut, and see who or what asked for it.
A one-off local admin account done properly, with a hidden password prompt, a language-proof group lookup, and an expiry date for the temporary ones.
Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
Empty the Recycle Bin with no prompt, for one user or everyone on the machine, and optionally keep anything deleted recently.
Export your KACE device inventory to CSV and get a per-location (or per-label) device count, optionally just the machines added this week.
On Windows 10 and 11 there's no Windows Update logging to switch on. The trick is collecting it, and this script does that in one zip per machine.
A read-first WinRM check that tells you why remote PowerShell won't connect, fixes it only when you ask, and doubles as a ConfigMgr compliance script.
Clear the Windows DNS client cache locally or across a list of machines, and know when a flush will actually fix anything.
For the Entra-joined PC that never showed up in Intune. Check it's ready, kick off enrollment, and see why it failed if it does.
Thread: Getting devices into Intune ↗Load mobile numbers into Entra ID as an authentication method before users ever sign in, without stomping on numbers they've already registered.
Point each domain controller at a partner DC first and itself (127.0.0.1) last, the way Microsoft recommends, across all your DCs in one pass.
Audit who still talks SMBv1 to your machines, then switch it off for good, with one script and three modes.
Turn on Dell's Password Bypass so patch reboots don't sit at a power-on password prompt all night, then turn it back off when you're done.
List the preview handlers installed on a PC, see which one each file type uses, and point extensions like .log, .ps1 or .json at the handler you want.
Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.
Dump every OU in the domain to a spreadsheet, with a readable path, depth, GPO link count and, if you want, how many objects live in each one.
A width check that works in a real console, in VS Code, and in scheduled tasks and CI runners where there's no window to measure.
One script that reads the WSUS, scan-source and Windows Update for Business settings on a device and tells you where it's really getting updates from, with a safe reset for leftovers.
Compare files, whole folder trees, or a download against its published checksum with Get-FileHash, and get back a clear Match or Different for every file.
Register the Microsoft Update service through the Windows Update Agent's own COM API, so devices pick up Office and other Microsoft product updates, not just Windows.
One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.
Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.
Put a BIOS admin password on new Dells, or change the old one across the fleet, with both passwords handed over at runtime.
Repack ZIPs as 7z, see exactly how much space each one saved, and keep the ZIP when the 7z wouldn't be any smaller.
Thread: Archive conversion workshop ↗Find project folders that haven't changed in N days, zip each one to an archive location with the date of its last change, verify it, and optionally clear out the original.
Switch workstations to High Performance (or Ultimate Performance) by GUID, restore the plan if the image hid it, and don't end up with five copies of it.
Integrity-test every ZIP, 7z, RAR and TAR in a folder, then optionally repack the good ones into a single format. Broken archives never get touched.
Thread: Archive conversion workshop ↗Clear the BIOS setup password on Dell PCs and see exactly what changed, with the password supplied at runtime instead of sitting in a package.
One uninstall script for every retired app. Give it a display name and it finds the right uninstall command, MSI or not, and runs it quietly.
Find out which Chrome version a machine is really running, whether an update is stuck waiting on a restart, and kick Google's updater into checking now.
Stop the spooler, clear out the wedged job files, and bring it back up, with -WhatIf and an option to leave recent jobs alone.
Remove the internal drive password from Dell PCs with Dell's PowerShell provider, without ever writing the password into a script or package.
Write extensionAttribute1-15 on cloud-only Entra ID users from a CSV, with a clear note for every synced account it can't touch.
Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
A gpupdate wrapper that checks the domain trust first, never bounces anyone's session, and reports a real success or failure back to ConfigMgr.
Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.
Feed it a list of computers and a service name, get back one row per machine saying whether it's installed, running, and how it starts.
The hardware hash script behind Windows Autopilot, explained. Upload straight to Intune with -Online, or export a CSV when the device can't reach the tenant.
Thread: Getting devices into Intune ↗