Skip to content
  • Privacy Policy
AJ's Tech Chatter

AJ's Tech Chatter

Windows Endpoint Management with ConfigMgr, Intune, PowerShell, and more

  • Privacy Policy

Author: Anthony J. Fontanez

Windows Sysadmin, focused on ConfigMgr, Intune, PowerShell, AD/AAD, & Security. Admin team member for the WinAdmins Discord community - https://winadmins.io/
  • Home
  • Anthony J. Fontanez
  • Page 2
Active Directory PKI

Managing Two-Tier PKI in a Lab Environment

2022-02-032022-02-03 Anthony J. Fontanez

If you’re crazy like me, you go all out when running a homelab. Multiple domain controllers, role-based access, separate servers per role (for the most

Read More
Autopilot Intune

Hybrid Autopilot & ODJ Connector Permissions

2021-12-202025-02-27 Anthony J. Fontanez

2025-02-27 Update: This entire post is now irrelevant, see https://techcommunity.microsoft.com/blog/intunecustomersuccess/microsoft-intune-connector-for-active-directory-security-update/4386898 for more information. Disclaimer: I recommend utilizing pure-AAD join in 99% of use Autopilot use

Read More
ConfigMgr SQL WSUS

ConfigMgr, Multiple SUPs, Server 2022, and “The schema version of the database is from a newer version of WSUS”

2021-11-222024-12-11 Anthony J. Fontanez

UPDATE: 2024-12-11 This issue was resolved in the 2024-11 CU for Server 2022 (https://support.microsoft.com/en-us/topic/november-12-2024-kb5046616-os-build-20348-2849-817737a3-4027-485e-ba0d-e97ad4378047). If you made the change below in the past, you will

Read More
ConfigMgr

Configuring Kiosk Autologon with ConfigMgr

2021-10-292021-10-29 Anthony J. Fontanez

Kiosks can present an interesting challenge: how to keep the account credentials at least somewhat secure. In the past, we’ve typically utilized group policy to

Read More
ConfigMgr

Automating ConfigMgr Distribution Point Client Authentication Certificate Rotation

2021-10-202021-10-20 Anthony J. Fontanez

So, you’ve got your ConfigMgr site using HTTPS-only now (check out Migrating ConfigMgr to HTTPS-Only if you don’t!). All of your site system servers that

Read More
Active Directory

Group Policy Loopback Processing, Done Correctly

2021-10-112021-10-11 Anthony J. Fontanez

It’s 2021, why am I writing a post about Group Policy? Everyone has retired their AD infrastructure and is using Intune for everything now, right?

Read More
Active Directory Security

Windows Firewall: The Series

2021-09-162021-09-16 Anthony J. Fontanez

I’ve had an idea for a while now to write a series of posts covering configuration of the Windows Firewall, including topics such as: Basic

Read More
Misc

Windows Firewall Part 7: Final Thoughts

2021-09-162021-09-16 Anthony J. Fontanez

phew… If you made it here, congratulations. This series ended up being much longer and more detailed than I initially anticipated. It turns out that

Read More
Active Directory Azure AD Security

Windows Firewall Part 6: Azure AD Joined Clients

2021-09-162021-09-16 Anthony J. Fontanez

At this point, it’s now possible to make any/all services available from anywhere utilizing certificate authentication to Domain Controllers, obtaining computer and user Kerberos tickets,

Read More
Active Directory Security

Windows Firewall Part 5: Bootstrapping Kerberos via Certificate Authentication

2021-09-162021-09-16 Anthony J. Fontanez

Part 5 of this series will go over how to utilize certificate authentication to make services available from anywhere, without the need of a traditional

Read More

Posts pagination

Previous 1 2 3 Next

Recent Posts

  • Group SOA Conversion – From AD to Entra!
  • Internet-facing File Servers, with a dash of Entra Authentication!
  • Dealing With CVE-2023-24932, aka Remediating BlackLotus
  • Obsolete Security – Stop Setting These Policies!
  • Migrating an Online Issuing CA & OCSP

Contact

ajf8729
@ajf8729.com
ajf8729
ajf@anthonyfontanez.com
Mastodon

WinAdmins Community
WinAdmins
Windows-Admins
ajf@winadmins.io

WinAdmins Discord Community

Recent Comments

  • Michael on Windows Firewall Part 5: Bootstrapping Kerberos via Certificate Authentication
  • Christian on Internet-facing File Servers, with a dash of Entra Authentication!
  • Anthony J. Fontanez on Internet-facing File Servers, with a dash of Entra Authentication!
  • Steven McKenzie on Internet-facing File Servers, with a dash of Entra Authentication!
  • Louis on Dealing With CVE-2023-24932, aka Remediating BlackLotus

Archives

  • August 2025
  • July 2025
  • May 2025
  • April 2025
  • March 2024
  • December 2023
  • November 2022
  • October 2022
  • August 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • May 2021
  • August 2020

Tags

Active Directory (15) Autopilot (2) Azure AD (4) ConfigMgr (8) File Services (1) Intune (5) Misc (1) OSD (1) PKI (2) Printing (2) Security (15) SQL (2) WSUS (2)

Categories

  • Active Directory
  • Autopilot
  • Azure AD
  • ConfigMgr
  • File Services
  • Intune
  • Misc
  • OSD
  • PKI
  • Printing
  • Security
  • SQL
  • WSUS

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
DigitalOcean Referral Badge
All Rights Reserved 2026.
Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

AJ's Tech Chatter
Privacy Policy / Proudly powered by WordPress Theme: Fairy Dark.
AJ's Tech Chatter
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.