Running LAPS Around Desktop Security (Part 3 - GPOs and Testing)

The third post in a series on LAPS (Local Administrator Password Solution). This one covers the GPO configuration and testing.

Nathan Ziehnert

2 minute read

Now we reach the final stretch - the domain configuration is complete, we’ve installed the client side extensions on our workstations or servers, now they just need a policy that tells the CSE what to do!

Lenovo BIOS to UEFI Conversion During Task Sequence (SecureBoot and Virtualization Technology Too)

The first real utility of benefit that I wrote and have used in a major production way. You should consider using it as well if you have Lenovo equipment.

Nathan Ziehnert

2 minute read

As we plan for our migration from Windows 7 to Windows 10 as an organization we know that we want to take advantage of Credential Guard and Device Guard in our new OS. ConfigMgr, we also know that this requires us to make a few configuration changes to our workstation “BIOS” configuration - namely converting from BIOS to UEFI, enabling SecureBoot, and enabling the virtualization technologies. Our organization has about 2300 workstations, and at least 1800 of them are physical devices…

SCCM and "Failed" Drives

I had a little freak out session when a drive went bad. I spent the better part of a week fixing it so that you don't have to go through the same trouble.

Nathan Ziehnert

3 minute read

First a little disclaimer… you should be backing up your data. If you’re not, stop reading and go work out a backup strategy.