AD Password Expiry Email: Reliable PowerShell Reminder Script in 6 Steps
Send HTML reminders before Active Directory passwords expire: read msDS-UserPasswordExpiryTimeComputed so fine-grained policies are respected, send through Microsoft Graph with a scoped app or through an SMTP relay with MailKit, log every message and run it daily as a gMSA scheduled task with a test mode.
September 30, 2026
Active Directory UPN Suffix: 4-Step Setup for Microsoft 365
Add a routable UPN suffix to an Active Directory forest with Domains and Trusts or Set-ADForest, change user UPNs in bulk with PowerShell, match the suffix to a verified Microsoft 365 domain, understand what Entra Connect does with the change, and roll back safely.
September 30, 2026
Delegate Password Reset in Active Directory: Secure 5-Step Helpdesk Setup
Give the helpdesk the right to reset passwords and unlock accounts on standard users only: Delegation of Control Wizard, the exact permissions it writes, dsacls and PowerShell equivalents, AdminSDHolder behaviour, auditing, testing and removal.
September 30, 2026
Find Inactive AD Users and Computers: PowerShell Cleanup in 5 Steps
Find stale Active Directory user and computer accounts with Search-ADAccount and Get-ADComputer, allow for lastLogonTimestamp replication lag, exclude service accounts, then disable, quarantine and delete them on a schedule with a full report and rollback.
September 30, 2026
Bulk Create AD Users from CSV: PowerShell Script in 7 Steps
A complete PowerShell workflow to create Active Directory users from a CSV file: a column template, input validation, unique sAMAccountName and UPN generation, OU placement, random initial passwords, group membership, logging, a -WhatIf dry run, updates with Set-ADUser and rollback.
September 30, 2026
Get-ADUser PowerShell Examples: 25 Queries for Active Directory
Twenty-five tested Get-ADUser queries for Windows Server 2016 to 2025: identity, filters, LDAP filters, OU scope, disabled, locked and expired accounts, last logon, password expiry, group membership, CSV reports and performance tips.
September 30, 2026
Disable NTLM Active Directory-Wide: 5 Safe Audit and Block Steps
A staged plan to reduce and block NTLM in an Active Directory domain: Restrict NTLM audit policies, NTLM Operational events 8001-8004, enhanced NTLM logging on Windows 11 24H2 and Server 2025, NTLMv1 detection, Kerberos fixes, blocking with exceptions and rollback.
September 30, 2026
SMB Signing Group Policy: Secure Setup and 3 Ways to Disable SMBv1
Require SMB signing with Group Policy on Windows 11 24H2 and Windows Server 2025, understand the new defaults, keep NAS and Samba shares working, handle insecure guest logons, audit and remove SMBv1 and add SMB encryption where it matters.
September 30, 2026
AppLocker Group Policy: Complete Audit-to-Enforce Guide in 6 Steps
Build an AppLocker allow-list with Group Policy on Windows 11 and Windows Server 2025: rule collections, default rules, publisher, path and hash rules, audit-only mode, event IDs 8003 and 8004, PowerShell testing, App Control for Business and a safe rollback.
September 30, 2026
Proxy Settings Group Policy: 6 Reliable Methods for Windows 11
Push a proxy server, bypass list or PAC file to Windows 11 and Windows Server with Group Policy Preferences, registry values, WinHTTP, Edge and Chrome policies and Intune, then stop users changing it and verify every layer.
September 30, 2026
Windows Update Group Policy: 7 Settings for Windows 11
Configure Windows 11 24H2/25H2 and Windows Server update behaviour with Group Policy: WSUS location and client-side targeting, Configure Automatic Updates, deadlines, active hours, deferrals, target feature version, Intune update rings and verification.
September 30, 2026
Backup Restore GPO PowerShell: 7 Steps for Safe Recovery
Back up every GPO on a schedule with Backup-GPO, save the links and WMI filters that backups leave out, roll GPOs back with Restore-GPO or GPMC, move settings to another domain with Import-GPO and a migration table, and handle local policy with LGPO.exe.
September 30, 2026