Author Archives: ncbrady

Manage BitLocker policies and escrow recovery keys over a cloud management gateway (CMG)

Introduction Microsoft are continuously responding to feedback from UserVoice and one such new implementation in Technical Preview 2010.2 is the ability to manage BitLocker policies and escrow recovery keys over a cloud management gateway (CMG). For more details see here … Continue reading

Posted in 2010.2, 20H2, BitLocker Management via CMG | 1 Comment

Troubleshooting BitLocker Management in ConfigMgr – Part 2. Client side

Introduction Microsoft blogged about Bitlocker Management capabilities back in May, 2019. They detailed how that would impact and evolve on the following three platforms.     Cloud-based BitLocker management using Microsoft Intune     On-premises BitLocker management using System Center Configuration Manager … Continue reading

Posted in 2006, 20H2, BitLocker Management | 2 Comments

What’s new in Microsoft Endpoint Manager – part 2

Introduction These are my notes from a session @ Microsoft Ignite 2020, the session was hosted by Steve Dispensa (Director of Program Management at Microsoft Endpoint Manager) and Ramya Chitrakar (Director of Engineering at Microsoft Endpoint Manager). For the last … Continue reading

Posted in CMPivot | Leave a comment

New features in Configuration Manager Technical Preview 2010

Introduction On Friday, Microsoft released the latest Technical Preview release for Microsoft Endpoint Manager Configuration Manager, namely version 2010. As always, it contains a bunch of new features (based on uservoice feedback) and I’ll take a look at some of … Continue reading

Posted in 2010, Deploy task sequence to users, Scenario health, Show Status Messages, Syntax highlighting | Leave a comment

How can I dynamically install Windows 10 language packs and associated features on demand in an offline environment

Introduction Sometimes you need to install Windows features that normally need internet access (to install other components), language packs installed today are done in a modular and different format from previous years. In previous times you could simply install a … Continue reading

Posted in 2004, FOD, Language Pack, LTSC, offline, Windows 10 | Leave a comment

What’s new in Microsoft Endpoint Manager – part 1

Introduction These are my notes from a session shown today @ Microsoft Ignite 2020, the session was hosted by Steve Dispensa (Director of Program Management at Microsoft Endpoint Manager) and Ramya Chitrakar (Director of Engineering at Microsoft Endpoint Manager). For … Continue reading

Posted in Cloud Management, Microsoft Tunnel, tenant attach | Leave a comment

The right way to find logs from your CMG

Introduction To review logs real time on my CMG in Azure I assumed that using RDP to do so was a good idea, but that got some interesting reactions on Twitter, and I was informed that it was unsupported. I … Continue reading

Posted in 2009, CMG, logs | 1 Comment

OSD via boot media and CMG, available in TP2009

Introduction Microsoft have released Technical Preview 2009 and it contains a bunch of updates but one that’s very interesting is the ability to create bootable media to distribute to remote sites so that they can re-image via the CMG. This … Continue reading

Posted in 2009, bootable media over CMG | 3 Comments

Troubleshooting BitLocker Management in ConfigMgr – Part 1. Server side

Introduction Microsoft blogged about Bitlocker Management capabilities back in May, 2019. They detailed how that would impact and evolve on the following three platforms.     Cloud-based BitLocker management using Microsoft Intune     On-premises BitLocker management using System Center Configuration Manager … Continue reading

Posted in 1910, 2002, BitLocker Management, MBAM, pki, System Center Configuration Manager (Current Branch) | Leave a comment

Fixing an evaluation version of SSRS with “HTTP Error 503. The Service is unavailable”

Introduction I was writing a blog post about Troubleshooting BitLocker Management in ConfigMgr 2002 Current Branch and one of the things I was trying to do was install the web portals, but I was seeing errors shown below. Get-ReportServiceUri : … Continue reading

Posted in 2002, BitLocker Management, Reporting | Leave a comment

Running de-dup maintenance scripts after deleting hyper-v snapshots

Introduction I deleted several hyper-v snapshots to free up some space on my deduplicated nvme drive  on my Lenovo P1 hyper-v lab, as it was starting to get low. Below is roughly how much space was on the de-duplicated drive … Continue reading

Posted in deduplication, hyper-v, P1 Mobile workstation | Leave a comment

How can we utilize the Bitlocker Management feature during OSD with Endpoint Manager

Introduction I’ve had a lot of questions recently about people wanting to use the new BitLocker Management capabilities in Configuration Manager, and to make use of those abilities during OSD (Operating System Deployment). First things we need to keep in … Continue reading

Posted in 1910, 2002, 2006, BitLocker Management, Full Disk Encryption, MBAM, pki | Leave a comment

How can I replace an expired IIS certificate in a PKI enabled ConfigMgr environment

Introduction I was busy putting together another BitLocker Management OSD related blog post in one of my PKI enabled ConfigMgr labs (#11) when I noticed that PXE boot no longer worked. The virtual machine would attempt to PXE boot for … Continue reading

Posted in 2002, BitLocker, expired IIS cert, PKI, smspxe.log | 3 Comments

Cool new features in Technical Preview 2008

Introduction Microsoft released TP2008 yesterday, more details here, but I was busy building my deck so I didn’t blog anything, but I did the upgrade and waited until today to see what’s new. And as usual, it’s a list of … Continue reading

Posted in 2008, Collection Evaluation view, Collection query preview, delete aged collected diagnostic files, monitor scenario health, Setupdiag errors for feature updates, task sequence size | 1 Comment

Configuring the Registered Owner and Organization in Windows Autopilot delivered PCs

Introduction I received a brand new HP Laptop (HP EliteBook 830 G6) to verify our current Autopilot setup, and I went through OOBE. All seemed well and I was curious about the version of Windows shipped so I ran WinVer. … Continue reading

Posted in Intune, registered owner, Windows 10 AutoPilot | 2 Comments