Microsoft Autopilot Pre-Provisioning troubleshooting – how to get the logs

get-AutopilotLogs.ps1

I work a lot with Microsoft Intune, Autopilot and also Pre-Provisioning. Especially with the latter, I often have to troubleshoot for my customers when things don’t work out. Michael Niehaus has written several articles on troubleshooting, including: Troubleshooting Windows Autopilot, a reference – Out of Office Hours (oofhours.com) Windows Autopilot diagnostics: Digging deeper – Out … Read more

Set Windows target release

Especially in test environments, you often need an older release of Windows 10, but how can you set Windows to a target release? Many companies are currently still using Windows 10 1909, and the Enterprise Edition is still supported until 11.05.2022. Unfortunately, I can only defer the feature upgrade in Windows 10 for 365 days. This means that a newly installed Windows 10 1909 updates to 20H2.

Read more

SSTP VPN with Let’s Encrypt certificates

SSTP requires an SSL certificate accepted by the client. If you have an internal certificate authority, you can use this. The only thing that must be ensured is that the client can also reach the blacklist on the Internet. Many fail with this requirement. So why not use another certificate, for example a free one from Let’s encrypt.

Read more

VPN Server with Windows Server 2022 (RAS)

In this article we will show you how to install and set up a VPN server with Windows Server 2022. We will go through the setup step by step.

This article is based on the article VPN Server with Windows Server 2019 (RAS) and has been updated for Windows Server 2022.

Read more

Windows 11 Installation – First Look

Windows 11 start page

In this article I show the manual Windows 11 installation and the first insights. The version used is from the Beta Channel, the Windows 11 Enterprise 21H2 (OS Build 22000.194) version. Since Windows 11 is already installed on my test hardware via in-place upgrade, I use a Hyper-V VM for this. It is absolutely necessary to use a VM of the 2nd generation. SecureBoot and the TPM must also be activated in the VM, otherwise the installation will fail.

Read more

Automatic Virtual Machine Activation (AVMA) with Windows Server Datacenter (Update)

AVMA2016 Automatic Virtual Machine Activation (AVMA) with Windows Server Datacenter (Update) 6

Behind the feature “Automatic Virtual Machine Activation” is a function in Microsoft Windows Server 2012R2 Datacenter, Microsoft Windows Server 2016 Datacenter and Microsoft Windows Server 2019 Datacenter for Hyper-V, but it works only with the Datacenter Edition activated. With this feature, all supported Windows Server operating systems since Microsoft Windows Server 2012R2 can be automatically activated by the Hyper-V host. But only up to the own version, which means that a Windows Server 2012 R2 Datacenter Hyper-V cannot activate Windows Server 2016. The limitation of this feature to the Datacenter Edition is due to the unlimited Virtual Windows Server Guests covered by the Datacenter License. The advantage is that it is now easier to assign the license to the corresponding datacenter license during a software audit on the AVMA license key.

Read more

German Federal Office for Information Security (German BSI) security recommendations for Windows 10

20210511 Screenshot BSI German Federal Office for Information Security (German BSI) security recommendations for Windows 10 8

The German Federal Office for Information Security (BSI) has published new documents on Microsoft Windows 10 and how to secure it. I looked at the BSI security recommendations for Windows 10 before I wanted to report on them. The background to this is that in the past, publications in this direction were sometimes more than outdated when they were published or they were very superficial.

Read more

Intune packaging made simple

Excerpt from the PowerShell execution of the command Invoke-Upload.ps1

I like to work with installation wrappers for packaging. It doesn’t matter whether it’s Microsoft System Center Configuration Manager (SCCM) or Microsoft Endpoint Configuration Manager (MECM) or the Microsoft Deploment Tollkit (MDT), I have also used them for Microsoft Intune packaging.

Read more