Security Headers on a Static Site When Your Host Won't Set Them
My brand-new blog got an F on a security header scan. Here's why, what actually matters for a static site, and the fixes that work on DigitalOcean App Platform.
Across the notebook
Entries sharing this tag, wherever they're filed.
My brand-new blog got an F on a security header scan. Here's why, what actually matters for a static site, and the fixes that work on DigitalOcean App Platform.
One script that locks a departing user out, cleans up their groups and licenses, and keeps their mail, with a CSV record of every step.
Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
Find the updates the most machines are actually missing, bundle them into a group, and deploy them to a pilot collection, with a WhatIf preview first.
A quick, safe software inventory from the registry, local or remote, that returns objects you can filter and export instead of a wall of colored text.
When Windows Update is greyed out or just won't run, check all the policy values and services that can block it, and put them back the way Windows shipped.
A one-off local admin account done properly, with a hidden password prompt, a language-proof group lookup, and an expiry date for the temporary ones.
Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
Load mobile numbers into Entra ID as an authentication method before users ever sign in, without stomping on numbers they've already registered.
How RADIUS VSAs work, how to add one in Windows NPS or FreeRADIUS to hand out DNS servers, and how to prove your VPN or NAS is actually using it.
A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗A practical checklist for taking a device that gets its security policy through Defender for Endpoint and enrolling it in Intune without leaving a gap.
Audit who still talks SMBv1 to your machines, then switch it off for good, with one script and three modes.
Turn on Dell's Password Bypass so patch reboots don't sit at a power-on password prompt all night, then turn it back off when you're done.
How I think about patch risk now. Sort updates by blast radius, roll them out in rings, decide what "bad" looks like up front, and know your way back before you need it.
Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.
Compare files, whole folder trees, or a download against its published checksum with Get-FileHash, and get back a clear Match or Different for every file.
How to build a configuration profile in Intune, roll it out to machines that are already in people's hands, and confirm it actually landed.
One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.
Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.
Put a BIOS admin password on new Dells, or change the old one across the fleet, with both passwords handed over at runtime.
Clear the BIOS setup password on Dell PCs and see exactly what changed, with the password supplied at runtime instead of sitting in a package.
Find out which Chrome version a machine is really running, whether an update is stuck waiting on a restart, and kick Google's updater into checking now.
Remove the internal drive password from Dell PCs with Dell's PowerShell provider, without ever writing the password into a script or package.
Onboarding to Defender for Endpoint and enrolling in Intune are two different things, and you almost never have to offboard one to get the other.
Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.