Emergency server help: get in touch

Windows

Windows Server guides and tools: Active Directory, Group Policy, RDS, WSUS, DHCP, DFS, Intune and PowerShell for Windows Server 2019–2025. Looking for Exchange Online, Entra ID or Microsoft 365 admin? See the Microsoft 365 guides.

Domain Controller Metadata Cleanup: Safely Demote or Remove a Dead DC

Demote a working domain controller with Uninstall-ADDSDomainController, or remove a failed one with forced removal, FSMO seizure and metadata cleanup in ADUC, Sites and Services or ntdsutil, then clean DNS and verify with dcdiag and repadmin.

September 30, 2026

Restore Domain Controller Backups: System State and DSRM Steps

Back up a Windows Server 2016 to 2025 domain controller with a system state backup, then run a non-authoritative or authoritative restore from DSRM with wbadmin and ntdsutil, including SYSVOL, deleted objects and a test restore plan.

September 30, 2026

AD Password Expiry Email: Reliable PowerShell Reminder Script in 6 Steps

Send HTML reminders before Active Directory passwords expire: read msDS-UserPasswordExpiryTimeComputed so fine-grained policies are respected, send through Microsoft Graph with a scoped app or through an SMTP relay with MailKit, log every message and run it daily as a gMSA scheduled task with a test mode.

September 30, 2026

Active Directory UPN Suffix: 4-Step Setup for Microsoft 365

Add a routable UPN suffix to an Active Directory forest with Domains and Trusts or Set-ADForest, change user UPNs in bulk with PowerShell, match the suffix to a verified Microsoft 365 domain, understand what Entra Connect does with the change, and roll back safely.

September 30, 2026

Delegate Password Reset in Active Directory: Secure 5-Step Helpdesk Setup

Give the helpdesk the right to reset passwords and unlock accounts on standard users only: Delegation of Control Wizard, the exact permissions it writes, dsacls and PowerShell equivalents, AdminSDHolder behaviour, auditing, testing and removal.

September 30, 2026

Find Inactive AD Users and Computers: PowerShell Cleanup in 5 Steps

Find stale Active Directory user and computer accounts with Search-ADAccount and Get-ADComputer, allow for lastLogonTimestamp replication lag, exclude service accounts, then disable, quarantine and delete them on a schedule with a full report and rollback.

September 30, 2026

Bulk Create AD Users from CSV: PowerShell Script in 7 Steps

A complete PowerShell workflow to create Active Directory users from a CSV file: a column template, input validation, unique sAMAccountName and UPN generation, OU placement, random initial passwords, group membership, logging, a -WhatIf dry run, updates with Set-ADUser and rollback.

September 30, 2026

Get-ADUser PowerShell Examples: 25 Queries for Active Directory

Twenty-five tested Get-ADUser queries for Windows Server 2016 to 2025: identity, filters, LDAP filters, OU scope, disabled, locked and expired accounts, last logon, password expiry, group membership, CSV reports and performance tips.

September 30, 2026

Disable NTLM Active Directory-Wide: 5 Safe Audit and Block Steps

A staged plan to reduce and block NTLM in an Active Directory domain: Restrict NTLM audit policies, NTLM Operational events 8001-8004, enhanced NTLM logging on Windows 11 24H2 and Server 2025, NTLMv1 detection, Kerberos fixes, blocking with exceptions and rollback.

September 30, 2026

SMB Signing Group Policy: Secure Setup and 3 Ways to Disable SMBv1

Require SMB signing with Group Policy on Windows 11 24H2 and Windows Server 2025, understand the new defaults, keep NAS and Samba shares working, handle insecure guest logons, audit and remove SMBv1 and add SMB encryption where it matters.

September 30, 2026

AppLocker Group Policy: Complete Audit-to-Enforce Guide in 6 Steps

Build an AppLocker allow-list with Group Policy on Windows 11 and Windows Server 2025: rule collections, default rules, publisher, path and hash rules, audit-only mode, event IDs 8003 and 8004, PowerShell testing, App Control for Business and a safe rollback.

September 30, 2026

Proxy Settings Group Policy: 6 Reliable Methods for Windows 11

Push a proxy server, bypass list or PAC file to Windows 11 and Windows Server with Group Policy Preferences, registry values, WinHTTP, Edge and Chrome policies and Intune, then stop users changing it and verify every layer.

September 30, 2026

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.