Secure Boot is one of those foundational security features that most of us expect to “just work”. And for the most part, it does—until it doesn’t. With the upcoming Secure Boot certificate […]
Secure Boot is one of those foundational security features that most of us expect to “just work”. And for the most part, it does—until it doesn’t. With the upcoming Secure Boot certificate […]
Update! In my recent post, https://deploymentbunny.com/2026/04/07/secure-boot-2026-essential-updates-and-fixes/, I referenced the CheckSecureBoot script used to validate Secure Boot configuration during deployment. The purpose of the script is to be able to check the satus […]
Time synchronization is important Time synchronization is one of those areas that usually works without much attention, until it doesn’t. When it breaks, the symptoms are rarely obvious. Authentication issues, Kerberos problems, […]
I had the opportunity to present on Windows Operating System Hardening at MMS togather with Michael Niehaus , and if you attended, here is a recap of the session we did. This […]
In 2017 I published a small PowerShell script to deal with something that i needed, the ability to run DataDeduplication job as a commandline, so that turned into this post PowerShell is […]
The PK/KEK Reality Check and Fix! What is the issue? Secure Boot won’t ‘turn off’ in 2026. Most systems will keep booting, but devices that don’t transition from the 2011 trust anchors […]
LTSC is for Legacy workload and Infrastructure, SAC is for Apps When Windows Server 2016 was released Microsoft explained that the Desktop Edition and Core edition was about to be LTSC (released […]
There are many reason where it make sense to run Hyper-V in Hyper-V, one of them being to enable Credential Guard (VSM) in Windows Server 2016 TP 4 and later. For training, […]