Guides
The real path, with the errors you actually hit.
On a GL.iNet the token is enough and the router does the rest. Everywhere else the private key must be pulled from the account API: how, and from which machine.
Install MeshCentral on a Linux VPS: dedicated user, systemd service, firewall, 2FA and your first agent. Every command explained, field-tested.
Three components claim the same field: the email address policy, the command you are running, and Entra. They win in that order, and none of them says so.
The receive connector was configured correctly and the relay right was granted. Exchange refused anyway, because the connection never reached that connector.
Nine phases, the order that binds them, what you need before you start, and the six traps that cost an evening. With the step-by-step build manual.
Entra Connect stopped on an expired certificate. Two timestamps in the same event told a different story: the VM time zone, Proxmox, and nine exact hours.
A script that has run for years can depend on conditions nobody wrote down. You only find them by running it in an environment rebuilt from scratch.
It is no longer on the Download Center, the wizard's embedded browser cannot register MFA, and OU filtering is the setting to get right first time.
A shared mailbox costs nothing up to 50 GB. The DKIM value the portal suggests is the wrong one, and IMAP migrations have no Complete button.
Verification is one TXT record and changes nothing. The wizard then offers to configure mail, and that is the step that moves it. Decline it.
GTUBE produced no SCL header, and the filter was right. Two identical sends with opposite outcomes, and a missing log line that proved the interception.
A cmdlet parameter removed for security, a certificate for a machine outside the domain, and an IIS error whose real cause was NTFS permissions.
The listener does not come up until you reboot, and the service refuses to restart by hand. Then a firewall rule that only lets the VPN through.
Naming the internal directory after the public domain creates split-brain DNS, and you pay for it for years. A subdomain costs nothing and avoids it.
The installer shows no disks because Windows has no VirtIO driver. Machine type, firmware, and the snapshot to take before anything else happens.
Real errors from an Autopilot deployment, each with the cause hiding behind a misleading message. For people pasting an error message into a search box.
The profile decides whether a device joins Entra or the domain — not the import script. Groups by ZTDId, a 10 KB logo limit, names truncated at 15.
Two policies instead of one, a break-glass account excluded by name, and why requiring a compliant device tenant-wide locks you out of your own tenant.
A security baseline caused a silent conflict that took deleting it to resolve. Three explicit policies instead, and why ASR rules always start in Audit.
Required apps that install during OOBE, Chrome as a line-of-business MSI, and the OneDrive setting that fails in silence if the Tenant ID is wrong.
PowerShell that exits with no output, AADSTS530035, and a VM with no serial number. Three real failures importing the hash, and how to make it non-interactive.
The Autopilot profile requests a language, it does not install one. A script for keyboard and formats, and why the interface deliberately stays English.
From an empty tenant to a Windows 11 device that provisions itself, encrypts itself and can be reached remotely. Ten chapters, with the errors included.
Licensing that actually matters, two accounts to create before anything else, and the automatic enrolment setting that almost no guide bothers to mention.
Enabling RDP by policy does not open the firewall, net localgroup hides Entra members, and AADSTS293004 means the name you typed is not the device name.
A BitLocker policy that silently never applies, a TPM error that lies, and LAPS done properly. What really happens when you harden an Entra-joined device.
Without deadlines the patches are downloaded and never active. Rings, quality tight and feature loose, and why pre-release builds stay switched off.
Two network cards and it worked: mail flowed, Edge was reachable. Every functional test would pass. Only an architectural question exposed the gap.
No tenant meant no cloud mail filtering. Rebuilding it locally taught more: activating a service shows where the switch is, rebuilding it shows what it does.
The subscription file expires in a day, -FileName and -FileData are not interchangeable, and mail bypassed Edge because of a connector created days before.
Six recurring patterns from eleven diagnosed faults: the sophisticated hypothesis is usually wrong, and a system that refuses is often right to refuse.
Fully managed, work profile and dedicated devices: which enrollment mode fits which case, and how to connect the Managed Google Play account.
Free, P1 and P2 licences, users and dynamic groups, MFA and Conditional Access. What you actually need and what can wait, with concrete examples.