Pages

Thursday, December 29, 2022

Bulk Create Distribution Lists (DL) in Microsoft O365 With Powershell

Recently due to an O365 tenant to tenant migration, we wanted to create distribution lists that were on tenant A, on tenant B. Creating a single distribution list with number of users in M365 admin center alone is a cumbersome task. As per our requirement, DL count is more than 100 with some have more than 50 users as members.

In a scenario like this, Powershell and Excel are your friends. I will explain how I achieved the goal.

Monday, May 10, 2021

Generate HPE Array Diagnostic Utility (ADU) Report on VMware ESXi – Step-by-Step

You can follow below steps to generate ADU report on a production ESXi host without rebooting the server to access Array Configuration Utility. I have tested this on a HPE DL360 Gen9 server with VMware ESXi 6 installed. If you have used a customized ESXi version from the HPE site to install ESXi, it contains drivers and packages/tools/utilities to manage and monitor the hardware.

If you have not used an ESXi version customized for HPE servers, to install Smart Storage Administrator follow steps listed later in the document.

Monday, December 14, 2020

Simple PowerShell Script to Get the Latest Installed Hotfix and Installed Date

One of our customers had a requirement to get the last installed Windows update and the installed date on several machines through MECM. Since MECM does not offer readily available report for this type of scenario, I used PowerShell instead to query machines and get details.

Below is the script.

Tuesday, June 9, 2020

Create Azure P2S VPN with Azure AD Authentication

You can use Azure Point-to-Site (P2S) VPN to connect to your Azure Virtual Network from an individual device. This helps remote workers to access resources inside the VNet. You can use certificates, RADIUS or Azure AD for user authentication.

Azure AD authentication is the most recent and easiest method to configure. With AAD authentication you can leverage additional security features like MFA and Conditional Access. It uses OpenVPN protocol for tunneling. Below is the method to configure P2S VPN using Azure AD.

Friday, May 15, 2020

Microsoft Endpoint Configuration Manager Firewall Ports

This is a downloadable spreadsheet which consists of all default firewall ports related to MECM infrastructure. Primary purpose of this document is to give MECM Admins a simple overview of firewall ports required for MECM.

Thursday, May 14, 2020

MECM Client Windows Updates Scan Failed with Error = 0x80244022

Today, I was informed by a customer regarding an MECM (Microsoft Endpoint Configuration Manager) updates deployment issue. Some machines haven't downloaded updates for months. 

To troubleshoot the issue I examined logs related to software updates in client.

Tuesday, May 12, 2020

Configure Azure Bastion to Connect to Virtual Machines

Azure Bastion is a service (PaaS) which provides the ability to connect (RDP/SSH) to Azure virtual machines directly over TLS. With Azure Bastion, you don’t need to configure a public IP address on the VM to connect through RDP or SSH. Also, you don’t need any additional agent or software installed on your machine or inside Azure VM since you connect to VM directly from the Azure portal. Only an HTML5 capable browser is sufficient.

Azure Bastion deployment is per virtual network. Therefore, once you deployed it to a virtual network, you can connect to any VM inside that virtual network.

Tuesday, October 9, 2018

LEDBAT Not Correctly Configured in Windows Server 2016

LEDBAT or Low Extra Delay Background Transfer is a TCP Congestion control mechanism available in Windows Server 2016 and Windows Server 2019. LEDBAT helps to utilize the entire bandwidth (e.g. for SCCM packages or Windows Updates) when the network is free and if some other task (e.g. Application) requires bandwidth, it will give priority for that task.

Today I tried to configure LEDBAT in my SCCM environment. It's just a simple task as ticking a checkbox in Distribution Point properties. But in the background it does not get configured correctly due to incorrect TCP Templates.

Monday, October 8, 2018

WSUS: EULA Download in Pending State

Recently at a customer site I encountered below issue, some updates (specifically updates under Update Rollups classification) not syncing because End User License Agreements cannot be downloaded into WSUS.

In Wsyncmgr log there was this error.







Thursday, September 27, 2018

Post-Installation Configuration Failed When Re-Installing WSUS on Server 2016

I came across this issue today when I try to remove and re-install SUP and WSUS role from a ConfigMgr (CB) Server running on Widows Server 2016.

As usual I,

Sunday, July 8, 2018

Bring Deleted/Declined Windows Update Back to SCCM


Maintaining WSUS and SCCM SUP correctly is an essential task in every SCCM environment. There are great guides on declining superseded updates, maintaining SUP, re-indexing SUSDB out there on web.

There could be scenarios where you need to bring back declined/deleted update/s back to SCCM and deploy. Below are the steps that you need to follow in such a scenario.

Monday, April 9, 2018

Powershell Script to Create SCCM Collections Based on Device Models

In an environment that SysAdmins doesn't have any idea about how many number of device models exists, managing device drivers will be a cumbersome task.

Following is a Powershell script to create collections based on device models that already inventoried by SCCM.

Saturday, April 7, 2018

Resolve "Client certificate: None" Issue in a SCCM Client

Few days ago in a project that I involve in to replace a customer's existing SCCM CB infrastructure with a completely new one, I faced this "Client certificate: None" issue in a couple of computers. In their environment there are 2 Stand Alone Primary Site Servers with different site codes; existing and new one. Site is configured to use HTTP or HTTPS.

I was using a script to change the clients' site code and management point from existing to new one. While most clients that I tested changed its site assignment without issue, couple of Windows 10 version 1607 clients had this issue.


Thursday, March 1, 2018

Reset Expired Domain Administrator Password in Azure DC

Today I had to face this issue of expired Domain Administrator password in a DC hosted in Azure IaaS. This is my SCCM lab environment which has a single DC and completely resides in Azure. The worst thing happened to me was, expired passwords of;

1. Local Admin account which I created at the time of creating the DC VM and also the Domain Admin.
2. Other only Domain Admin account.
3. SCCM Administrator account.

at the same time.

Sunday, October 29, 2017

Enable Multifactor Logon Policy with Windows Hello

Windows Hello came as a technology to replace password based authentication with biometrics and PIN. Even though initially Microsoft said that this satisfies the multi factor authentication requirements, it was doubtful. They initially stated that PIN or biometrics is local to the specific device. So as per Microsoft, 1st authentication factor is the device, 2nd authentication factor is PIN or fingerprint or facial recognition. And there was no capability to use both PIN and fingerprint or PIN and facial recognition.

Now, with Windows 10 Fall Creators Update (version 1709) it is possible to do above.

Wednesday, August 30, 2017

Configure BitLocker on Intune Enrolled Windows 10 Devices

BitLocker can be managed in several ways in the enterprise. GPOs, MBAM, ConfigMgr are the most common methods. But what if you don't have Microsoft EA to bring in MBAM or you have Windows 10 Professional devices? And you have mobile Windows 10 devices that does not joined to ADDS. To overcome above issues, there's a possibility to manage BitLocker through Microsoft Intune and Azure AD. But to keep in mind this method does not provide funtionality as MBAM. In the end of this post I will describe limitations of this method.

Following are the steps to configure BitLocker through Intune and AAD. I have tested this on a Azure AD joined Windows 10 (1703) machine that directly enrolled in Intune as MDM.


Thursday, August 17, 2017

Block Apps on Intune Enrolled Samsung Devices through OMA-URI Settings

Recently one of our customers had a requirement to use Samsung Galaxy Tabs as Kiosk devices. These devices are shared devices that have enrolled to Intune using a Device Enrollment Manager (DEM) account which only used to run a specific LOB application.

The issue that we faced was this specific tab model, Samsung Galaxy Tab E 9.6 (SM-T561) does not have full KNOX capability baked into the OS. Simply there's no KNOX version information in Settings > About device. Because of this, none of the KNOX required policies didn't work on the device because Intune requires Samsung KNOX capable devices.

Since "Kiosk policy" didn't work on this device, the only method to achieve this was block apps from running through OMA-URI settings.

Wednesday, July 12, 2017

Deploy ADMX-Backed Policies to Intune Managed Windows 10 Device

In the past, Intune was only able to deploy a given set of device configuration policies. So, if the company has Intune managed Windows devices, they missed the good old Group Policy functionality. Fortunately starting with Windows 10 version 1703 (= Creators Update) and the new MDM capabilities, now it is possible to deploy certain ADMX based group policies (ADMX-backed policies) to Intune managed devices with the aid of Policy CSP.

Sunday, June 11, 2017

Protect Corporate Apps & Data on devices with Intune Mobile Application Management (MAM) – Using Intune in Azure Portal

Mobile Application Management or simply MAM is a great feature that comes with Enterprise Mobility + Security suite. It helps to protect corporate apps and data by enforcing configurable policies. MAM policies can be deployed to employee-owned unmanaged devices, devices that are enrolled in Intune and devices managed by a third-party mobile device management (MDM) solution.
This article describes how to configure MAM policies on Android devices that are enrolled in Intune.

For this guide I am using a device which is enrolled in Intune.


Tuesday, April 25, 2017

Upgrade to Internet Explorer 11 using System Center Configuration Manager - An Alternative Way

Recently one of our customer wanted to upgrade their Internet Explorer version to 11 in Windows 7 machines since Microsoft already stopped support for versions below Internet Explorer 11 long time back.

For the upgrade, most used methods are:

1. Task Sequence.
2. IEAK - Internet Explorer Administration Kit.

From above two, task sequence was the preferred method because, in that, it is possible to deploy prerequisites first and then deploy Internet Explorer 11 and also it can control restarts.

IEAK does not have many success rates.

But for me both of the above methods didn't work as it should. Task sequence gave errors.

So I used this method: