Windows LAPS and the migration from Microsoft LAPS

20230809 WindowsLAPS 08 Windows LAPS and the migration from Microsoft LAPS 1

In this era, the topic of IT security is becoming more and more important. A possible attack vector has always been the local admin passwords. In most cases, these were hard-wired into the installation image and had not been changed for years. Not only a risk from former employees. The lateral movement also poses a … Read more

List of different Group Policy Templates (Updated)

Gruppenrichtlinenkonsole mit Importierten Administrativen Vorlagen

Active Directory group policies, also called Group Policy Object (GPO), are one of my core topics. I have a lot to do with this in various projects and as a Microsoft trainer. As a result, I have accumulated a number of templates and links. This link collection should make your search a little easier. Only templates of the respective manufacturers or projects are listed here. I have deliberately avoided third-party guidelines.

Read more

Set Windows target release

Especially in test environments, you often need an older release of Windows 10, but how can you set Windows to a target release? Many companies are currently still using Windows 10 1909, and the Enterprise Edition is still supported until 11.05.2022. Unfortunately, I can only defer the feature upgrade in Windows 10 for 365 days. This means that a newly installed Windows 10 1909 updates to 20H2.

Read more

German Federal Office for Information Security (German BSI) security recommendations for Windows 10

20210511 Screenshot BSI German Federal Office for Information Security (German BSI) security recommendations for Windows 10 4

The German Federal Office for Information Security (BSI) has published new documents on Microsoft Windows 10 and how to secure it. I looked at the BSI security recommendations for Windows 10 before I wanted to report on them. The background to this is that in the past, publications in this direction were sometimes more than outdated when they were published or they were very superficial.

Read more

Device-specific administrative templates in Intune 2101

Intune Administrative Templates

Let’s first look at the comparative figures between the last article from October 2019 and now. The most changes have been made to Edge Bowser and Internet Explorer. There are also new settings for BitLocker. These were previously only configurable via their own policies in Intune.

Read more

Implement Microsoft Connected Cache with SCCM

Computergenerierter Alternativtext: M;cvosoff Del S evvice cDv u pdafe aunurg•

At Ignite 2019, Microsoft announced the Connected Cache (previously known as Delivery Optimization In-Network Cache (DOINC)). I’ll take a closer look at it now. But what do you really need it for?

Read more

Setting up Office 365 – Part 2

Setup Office 365 - Part 2

This article is part of my migration from my old Office 365 to my new Microsoft 365 Tenant. It is also about setting up Office 365, the other Microsoft 365 topics will follow later. I also have written this article intentionally so that it can also be used for setup outside of a migration scenario. Part 1 was about choosing the right edition, setting up the account and configuring the domains and DNS.

Read more

Microsoft Azure AD – what do you need it for?

Was ist Azure AD - Teil eins der Reihe - Artkelbild

I am often asked, what actually is this Azure-AD? I thought I could dedicate a blog series to this question, after all it is becoming more and more important. In this series, I will also write about authentication methods, types of identities and objects, licenses and compatible services. In short, everything about Azure Active Directory.

Read more