Series
Guides that build on each other, in order.
Intune from Zero
11 chapters- 00 Microsoft Intune from Zero: the complete series From an empty tenant to a Windows 11 device that provisions itself, encrypts itself and can be reached remotely. Ten chapters, with the errors included.
- 01 Preparing a Microsoft 365 tenant for Intune Licensing that actually matters, two accounts to create before anything else, and the automatic enrolment setting that almost no guide bothers to mention.
- 02 Autopilot: dynamic groups, branding and deployment profiles The profile decides whether a device joins Entra or the domain — not the import script. Groups by ZTDId, a 10 KB logo limit, names truncated at 15.
- 03 Importing the Autopilot hardware hash: the errors nobody documents PowerShell that exits with no output, AADSTS530035, and a VM with no serial number. Three real failures importing the hash, and how to make it non-interactive.
- 04 Deploying apps and OneDrive with Intune Required apps that install during OOBE, Chrome as a line-of-business MSI, and the OneDrive setting that fails in silence if the Tenant ID is wrong.
- 05 Securing an Autopilot device: compliance, BitLocker and LAPS A BitLocker policy that silently never applies, a TPM error that lies, and LAPS done properly. What really happens when you harden an Entra-joined device.
- 06 Windows Update with Intune: rings, deadlines and active hours Without deadlines the patches are downloaded and never active. Rings, quality tight and feature loose, and why pre-release builds stay switched off.
- 07 Defender in Intune: dedicated policies instead of a baseline A security baseline caused a silent conflict that took deleting it to resolve. Three explicit policies instead, and why ASR rules always start in Audit.
- 08 Remote Desktop on Entra-joined devices, managed by Intune Enabling RDP by policy does not open the firewall, net localgroup hides Entra members, and AADSTS293004 means the name you typed is not the device name.
- 09 Conditional Access: MFA yes, compliant device not yet Two policies instead of one, a break-glass account excluded by name, and why requiring a compliant device tenant-wide locks you out of your own tenant.
- 10 Italian keyboard on an en-US image: what Autopilot cannot do The Autopilot profile requests a language, it does not install one. A script for keyboard and formats, and why the interface deliberately stays English.
Hybrid Windows Server
6 chapters- 01 Windows Server 2022 on Proxmox: UEFI, VirtIO and the missing disk The installer shows no disks because Windows has no VirtIO driver. Machine type, firmware, and the snapshot to take before anything else happens.
- 02 Why your AD domain should not be your public domain Naming the internal directory after the public domain creates split-brain DNS, and you pay for it for years. A subdomain costs nothing and avoids it.
- 03 Verifying a domain in Microsoft 365 without touching your mail Verification is one TXT record and changes nothing. The wizard then offers to configure mail, and that is the step that moves it. Decline it.
- 04 Entra Connect: password hash sync, SSO and OU filtering It is no longer on the Download Center, the wizard's embedded browser cannot register MFA, and OU filtering is the setting to get right first time.
- 05 Migrating a mailbox from Aruba to Exchange Online, licence-free A shared mailbox costs nothing up to 50 GB. The DKIM value the portal suggests is the wrong one, and IMAP migrations have no Complete button.
- 06 Secure RDP to a domain controller, reachable only over VPN The listener does not come up until you reboot, and the service refuses to restart by hand. Then a firewall rule that only lets the VPN through.