Microsoft 365
Prepare a OneDrive to SharePoint migration by reviewing ownership, volume, path lengths, permissions, versions, links, target information architecture, a pilot move, cutover method, and post-migration validation.
View →
Microsoft 365
Offboard an Intune-managed device by choosing Retire, Delete, Wipe, or another action according to ownership and scenario, preserving recovery information, removing corporate access, and validating the final device state.
View →
Active Directory
Deploy Windows LAPS in Active Directory by choosing the backup directory, delegating read and rotation permissions precisely, applying policy to a pilot group, validating password rotation and retrieval, and expanding in stages.
View →
Windows Server
Enforce SMB Signing progressively on Windows clients and servers to reduce tampering and relay risks while identifying incompatible NAS devices, printers, and applications before broad enforcement.
View →
Active Directory
Create an Active Directory site that represents a real network location, associate its IP subnets, connect it to the replication topology, and verify that clients and domain controllers select the expected site.
View →
Active Directory
Create a group Managed Service Account for a Windows service, restrict which hosts can retrieve its managed password, install and test the account on a pilot server, and migrate the service with a rollback path.
View →
Networking & Security
Integrate a VPN with RADIUS or NPS using a defined RADIUS client, shared secret, Network Policy, dedicated access group, pilot users, and logs, without granting VPN access to every valid directory account.
View →
Networking & Wi-Fi
Migrate a Wi-Fi SSID from WPA2 to WPA3 progressively by inventorying client capabilities, using transition mode where necessary, enabling PMF, piloting representative devices, measuring incompatibilities, and removing WPA2 fallback deliberately.
View →
Networking & Security
Enable DHCP Snooping progressively by identifying legitimate DHCP paths, trusting only uplinks or server-facing ports, rate-limiting client ports where appropriate, validating the binding table, and monitoring for blocked offers.
View →
Microsoft 365
Create a Microsoft Entra Conditional Access policy in report-only mode, exclude emergency accounts, target a pilot group, analyze sign-in results, and enable enforcement progressively without locking out administrators.
View →