Emergency server help: get in touch

Active Directory

Active Directory guides: install and promote domain controllers, FSMO roles, replication, account lockouts, gMSA, LAPS and PowerShell scripts.

RDS Farm Windows Server 2025: Complete Deployment in 9 Steps

Build a session-based Remote Desktop Services farm on Windows Server 2025 with Server Manager or PowerShell: role placement, collections, profiles, certificates, RD Gateway, RemoteApps and a highly available Connection Broker.

September 30, 2026

Install RSAT on Windows 11: 5 Methods, Including Offline

Add Active Directory, Group Policy, DNS, DHCP and other Remote Server Administration Tools to Windows 11 through Settings, PowerShell or DISM, fix the WSUS 0x800f0954 error, install offline and use the Windows Server equivalents.

September 30, 2026

Convert Evaluation Edition to Full Windows Server: DISM Steps for 2025

Turn a Windows Server 2016 to 2025 evaluation install into a licensed Standard or Datacenter edition with DISM, move Standard to Datacenter, switch between retail, MAK and KMS keys with slmgr, and handle the domain controller limitation and activation errors.

September 30, 2026

Windows Server 2025 In-Place Upgrade from 2019, 2022 and Older

Upgrade Windows Server 2012 R2, 2016, 2019 or 2022 directly to Windows Server 2025 with setup.exe or the Windows Update feature update: supported paths, prerequisites, a compatibility scan, unattended switches, domain controller rules and post-upgrade checks.

September 30, 2026

Active Directory Audit Policy: DC Settings and 35 Key Event IDs

Configure Advanced Audit Policy on Windows Server 2016 to 2025 domain controllers, enforce subcategories, pick the right Success and Failure settings, size the Security log, and query the event IDs that matter for logons, lockouts, account and group changes.

September 30, 2026

Group Managed Service Accounts (gMSA): Complete Windows Server 2025 Guide

Replace service account passwords with group managed service accounts: create the KDS root key, create and install a gMSA, run Windows services, scheduled tasks, IIS application pools and SQL Server under it, and understand the new Windows Server 2025 delegated MSA.

September 30, 2026

Domain Controller Metadata Cleanup: Safely Demote or Remove a Dead DC

Demote a working domain controller with Uninstall-ADDSDomainController, or remove a failed one with forced removal, FSMO seizure and metadata cleanup in ADUC, Sites and Services or ntdsutil, then clean DNS and verify with dcdiag and repadmin.

September 30, 2026

Restore Domain Controller Backups: System State and DSRM Steps

Back up a Windows Server 2016 to 2025 domain controller with a system state backup, then run a non-authoritative or authoritative restore from DSRM with wbadmin and ntdsutil, including SYSVOL, deleted objects and a test restore plan.

September 30, 2026

AD Password Expiry Email: Reliable PowerShell Reminder Script in 6 Steps

Send HTML reminders before Active Directory passwords expire: read msDS-UserPasswordExpiryTimeComputed so fine-grained policies are respected, send through Microsoft Graph with a scoped app or through an SMTP relay with MailKit, log every message and run it daily as a gMSA scheduled task with a test mode.

September 30, 2026

Active Directory UPN Suffix: 4-Step Setup for Microsoft 365

Add a routable UPN suffix to an Active Directory forest with Domains and Trusts or Set-ADForest, change user UPNs in bulk with PowerShell, match the suffix to a verified Microsoft 365 domain, understand what Entra Connect does with the change, and roll back safely.

September 30, 2026

Delegate Password Reset in Active Directory: Secure 5-Step Helpdesk Setup

Give the helpdesk the right to reset passwords and unlock accounts on standard users only: Delegation of Control Wizard, the exact permissions it writes, dsacls and PowerShell equivalents, AdminSDHolder behaviour, auditing, testing and removal.

September 30, 2026

Find Inactive AD Users and Computers: PowerShell Cleanup in 5 Steps

Find stale Active Directory user and computer accounts with Search-ADAccount and Get-ADComputer, allow for lastLogonTimestamp replication lag, exclude service accounts, then disable, quarantine and delete them on a schedule with a full report and rollback.

September 30, 2026

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.