IntroductionI had a conversation with a customer recently: “We want better visibility into our Windows endpoints for security monitoring, but we don’t know where to start.” Honestly, that’s a fair place to be stuck. Windows can generate a huge number of security events, and if you try to collect everything on day one, you’ll drown in noise (and ingestion costs) before you find anything useful.So for this project, instead of trying to do everything at once, the team I worked with picked a small, high-value set of Windows Security events and started there — authentication, privileged access, process execution, registry…
Author: Eswar Koneti
Introduction During an SCCM Operating System Deployment (OSD), a client successfully obtained an IP address, downloaded WDSNBP, contacted the PXE-enabled Distribution Point, and then aborted PXE boot. The SMSPXE.log revealed that SCCM could not locate the required boot image for the PXE request. Symptoms – PXE boot starts successfully.- Client downloads WDSNBP.- ‘Configuration Manager is looking for policy’.- PXE boot aborts with abortpxe.com.- SMSPXE.log reports: ‘could not find boot image EK1005EE’. Observed PXE Error during the PXE boot. Distribution Point Configuration The PXE-enabled Distribution Point was correctly configured with:• Enable PXE support for clients• Allow this DP to respond to…
Introduction “One of the executives receiving Microsoft Authenticator prompts several times. Could someone be trying to access the account?” Whenever users report frequent MFA prompts, the first concern is usually security. Questions about compromised credentials, password spraying, token theft, or suspicious sign-in attempts quickly arise. When the affected user is a senior executive, these investigations become even more urgent because the impact on both security and productivity is much greater. However, through many customer engagements, I’ve learned that these investigations aren’t just about confirming whether an account has been compromised. Customers also want to understand why users are being prompted…
In enterprise environments, Configuration Manager (SCCM/MECM) servers are often shared by multiple administrators for day-to-day operations. While this centralized access improves efficiency, it can also introduce a common operational issue: inactive/disconnected RDP sessions consuming server resources. In this post, I’ll walk through a lightweight and effective solution I implemented at a customer site to automatically identify and log off disconnected sessions, helping to reclaim CPU and memory resources. At the customer environment, multiple administrators were logging into the SCCM server to perform their tasks. However, once done: The server monitoring team reported frequent performance alerts, and manual cleanup wasn’t sustainable.…
Introduction: Organizations enabling remote work with BYOD devices often rely on Azure Virtual Desktop (AVD) or Windows 365 Cloud PC. A common onboarding security practice is to create users in on‑premises Active Directory (AD) with the option “User must change password at next logon.” However, in hybrid identity setups, this setting can prevent new users from signing in remotely—causing confusion, helpdesk calls, and poor first‑day experience. This article explains why the issue occurs, the temporary workaround, and the correct Microsoft‑supported solution, including step‑by‑step configuration guidance. The Problem: Users created in on‑premises AD with “User must change password at next logon”…
One of our customers recently migrated from a third‑party MDM to Microsoft Intune (BYOD) using MAM-only app protection policies. Shortly after go‑live, user reported on iOS began seeing the following message in Microsoft Teams and other Intune-managed apps: Alert: Your organization will remove its data for this account (614).To access data for this account, you should restart this app and sign in to your work or school account. Troubleshooting Steps performed by the user: The user attempted the standard iOS device-side fixes: None of these steps stopped the 614 loop. Deeper Investigation — Reviewing Entra Sign‑In Logs To pinpoint the issue,…
Recently, I was setting up a new Configuration Manager (SCCM) environment as part of a side-by-side migration. One of the key configuration tasks was to replicate the Software Update Point (SUP) settings — particularly the Products selected for synchronization — to match the existing production environment. Before configuring the new SUP, I needed a list of all the products currently enabled on the old SCCM server for review and comparison. Available Options to Export the SUP Products List There are several ways to export the list of Software Update Point products from SCCM: Manual Method — Browse the console under…
Introduction: I was recently working on the rollout of a passwordless authentication solution in Microsoft Entra ID, which included Windows Hello for Business and Passkeys (FIDO2 security keys). As part of that rollout, one of the requirements was to identify all users and their registered authentication methods — things like MFA, Self-Service Password Reset (SSPR), and passwordless capability. While the Entra admin portal provides a view of this information under Authentication methods, however if you are looking for a way to export the data directly to a CSV file using PowerShell makes it much easier to process in Excel, Power…