Create a Dedicated Local Admin Account for Windows LAPS to Manage
Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
EXPLORE THE NOTEBOOK
Notes from the command line, the workbench, and the vintage computer shelf.
Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
Empty the Recycle Bin with no prompt, for one user or everyone on the machine, and optionally keep anything deleted recently.
Export your KACE device inventory to CSV and get a per-location (or per-label) device count, optionally just the machines added this week.
On Windows 10 and 11 there's no Windows Update logging to switch on. The trick is collecting it, and this script does that in one zip per machine.
A read-first WinRM check that tells you why remote PowerShell won't connect, fixes it only when you ask, and doubles as a ConfigMgr compliance script.
Clear the Windows DNS client cache locally or across a list of machines, and know when a flush will actually fix anything.
For the Entra-joined PC that never showed up in Intune. Check it's ready, kick off enrollment, and see why it failed if it does.
Getting devices into Intune · Note 3 ↗Load mobile numbers into Entra ID as an authentication method before users ever sign in, without stomping on numbers they've already registered.
How RADIUS VSAs work, how to add one in Windows NPS or FreeRADIUS to hand out DNS servers, and how to prove your VPN or NAS is actually using it.
A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Getting devices into Intune · Note 1 ↗The Settings app route into Intune, which of its three options to pick, and why the device might show up as personal when you didn't want it to.
Getting devices into Intune · Note 2 ↗A practical checklist for taking a device that gets its security policy through Defender for Endpoint and enrolling it in Intune without leaving a gap.