File Share Auditing: Find Who Deleted a File in 5 Steps
Turn on file share auditing on a Windows Server 2025 file server so you can answer "who deleted this file?": audit policy, SACLs in the GUI and PowerShell, events 4663 with the DELETE access mask, 4660 and 5145, a search script, log sizing and restoring from Previous Versions.
September 30, 2026
NTFS Permissions and Share Permissions: 7 Secure File Server Rules
Set up a Windows Server 2025 file share the maintainable way: simple share permissions, NTFS permissions granted to domain local groups (AGDLP), icacls and PowerShell commands, controlled inheritance, access-based enumeration and effective access checks.
September 30, 2026
RDP Connection Logs: 14 Event IDs to Track Who Connected and From Where
Find out who connected over Remote Desktop, from which IP address and for how long, using the RemoteConnectionManager, LocalSessionManager and Security event logs, with the audit policies they need, a PowerShell report and brute-force detection.
September 30, 2026
Active Directory Audit Policy: DC Settings and 35 Key Event IDs
Configure Advanced Audit Policy on Windows Server 2016 to 2025 domain controllers, enforce subcategories, pick the right Success and Failure settings, size the Security log, and query the event IDs that matter for logons, lockouts, account and group changes.
September 30, 2026
Group Managed Service Accounts (gMSA): Complete Windows Server 2025 Guide
Replace service account passwords with group managed service accounts: create the KDS root key, create and install a gMSA, run Windows services, scheduled tasks, IIS application pools and SQL Server under it, and understand the new Windows Server 2025 delegated MSA.
September 30, 2026
Delegate Password Reset in Active Directory: Secure 5-Step Helpdesk Setup
Give the helpdesk the right to reset passwords and unlock accounts on standard users only: Delegation of Control Wizard, the exact permissions it writes, dsacls and PowerShell equivalents, AdminSDHolder behaviour, auditing, testing and removal.
September 30, 2026
Disable NTLM Active Directory-Wide: 5 Safe Audit and Block Steps
A staged plan to reduce and block NTLM in an Active Directory domain: Restrict NTLM audit policies, NTLM Operational events 8001-8004, enhanced NTLM logging on Windows 11 24H2 and Server 2025, NTLMv1 detection, Kerberos fixes, blocking with exceptions and rollback.
September 30, 2026
SMB Signing Group Policy: Secure Setup and 3 Ways to Disable SMBv1
Require SMB signing with Group Policy on Windows 11 24H2 and Windows Server 2025, understand the new defaults, keep NAS and Samba shares working, handle insecure guest logons, audit and remove SMBv1 and add SMB encryption where it matters.
September 30, 2026
AppLocker Group Policy: Complete Audit-to-Enforce Guide in 6 Steps
Build an AppLocker allow-list with Group Policy on Windows 11 and Windows Server 2025: rule collections, default rules, publisher, path and hash rules, audit-only mode, event IDs 8003 and 8004, PowerShell testing, App Control for Business and a safe rollback.
September 30, 2026
Windows Firewall Group Policy: 5 Steps to Deploy Secure Rules
Manage Windows Defender Firewall on Windows 11 and Windows Server 2025 from a GPO: profile defaults, inbound rules for RDP, WinRM, ICMP and SMB, rule merging, logging, PowerShell GPO sessions, Intune and verification.
September 30, 2026
Local Administrators Group Policy: 4 Ways to Control Admin Rights
Control who is in the local Administrators group on Windows 11 and Windows Server 2025 with Restricted Groups, Group Policy Preferences, per-computer admin groups and Intune, then verify the result and roll back safely.
September 30, 2026
Screen Lock Group Policy: Lock Windows 11 After Inactivity the Right Way
Lock idle Windows 11 and Windows Server sessions automatically with the machine inactivity limit, password-protected screen saver, power and wake settings, dynamic lock or Intune, and keep meeting rooms and kiosks as controlled exceptions.
September 30, 2026