Email
Deploy MTA-STS and SMTP TLS Reporting without disrupting mail reception by auditing MX and STARTTLS, publishing the HTTPS policy in testing mode, adding DNS records, reviewing TLS-RPT reports, and moving to enforce gradually.
View →
Email
Move DMARC safely to p=reject by inventorying sending sources, aligning SPF and DKIM, collecting aggregate reports, starting with p=none, validating indirect mail flows, then progressing through quarantine to enforcement.
View →
Microsoft 365
Deploy a Windows compliance policy in Microsoft Intune with measurable requirements, appropriate noncompliance actions, pilot monitoring, and controlled use of compliance state in Conditional Access.
View →
Windows & Security
Enable Secure Boot across a Windows fleet without making devices unbootable by inventorying UEFI and GPT readiness, preserving BitLocker recovery keys, piloting by hardware model, converting MBR to GPT only when required, and validating after restart.
View →
Windows & Security
Deploy BitLocker across Windows devices only after recovery information is centrally backed up to Active Directory or Microsoft Entra ID, using a pilot group and validating recovery before wider encryption.
View →
Virtualization
Create an external Hyper-V vSwitch without losing management access by selecting the correct physical adapter, preparing VLAN settings, preserving the Management OS path, and validating host and VM connectivity.
View →
Virtualization
Create, validate, apply, and remove a Hyper-V checkpoint safely without treating it as a backup, preferring production checkpoints and verifying AVHDX merge completion afterward.
View →
Virtualization
Add a Proxmox VE node to an existing cluster by preparing DNS and hosts resolution, matching versions, validating Corosync networking and quorum, checking storage compatibility, joining the cluster, and validating pmxcfs and migrations.
View →
Storage
Present an iSCSI LUN to Windows Server with MPIO by separating storage paths, enabling the Microsoft DSM, creating multiple persistent sessions, configuring multipath policy, and testing the loss of one path.
View →
Microsoft 365
Deploy Windows Autopilot for cloud-driven Windows provisioning by registering devices correctly, assigning an OOBE profile to a pilot group, validating Entra join and Intune enrollment, checking required apps and policies, and expanding gradually.
View →