Anthony J. Fontanez
@ajf8729.com
250 followers 250 following 73 posts
Lead Customer Engineer (Intune/ConfigMgr) Endpoint Management Enthusiast Admin: WinAdmins Community (@winadmins.io) About Me: https://ajf.one/me Blog: https://ajf.one/blog All views are my own.
Posts Media Videos Starter Packs
RIP Windows 10 tomorrow, can still remember running the initial insider builds!
Woohoo, #Autopatch can use a Win32 app instead of a platform script for the broker now! Go to intune.microsoft.com#view/Microso... and hit that Migrate button right meow! In case you missed the MC notification about this, it's here admin.cloud.microsoft#/MessageCent... #Intune
TIL that you need DA to view RODC password replication policy results (was testing/verifying for AzureADKerberos). @josephryanries.bsky.social maybe you know why, seems odd, thought that would fall under typical RO directory data for domain users.
Reminder! - "The option to move back to Compatibility mode will remain until September 2025. After this date, the StrongCertificateBindingEnforcement registry key will no longer be supported" - support.microsoft.com/en-us/topic/... #ADCS #InfoSec
KB5014754: Certificate-based authentication changes on Windows domain controllers - Microsoft Support
support.microsoft.com
Reposted by Anthony J. Fontanez
I scored 11/21 on e-mail.wtf and all I got was this lousy text to share on social media.
Email is Easy
Everyone knows what an email address is, right?
e-mail.wtf
It might just load it into memory, which is what I would imagine happens when passing a UNC path.
Not quite sure, don't see it in C:\Windows\Temp, and can't tell from a quick procmon glance.
TIL you can pass an HTTP(S) URL directly to msiexec.exe and it will totally work. I had no idea!
ICYMI - #PowerShell 2.0 removal coming soon! learn.microsoft.com/en-us/window... - "Windows PowerShell 2.0 is removed from Windows 11, version 24H2 starting with the August 2025 non-security update. It’s also removed from Windows Server 2025 starting with the September 2025 security update."
Windows message center
Windows message center
learn.microsoft.com
Reposted by Anthony J. Fontanez
Folks, bookmark this 👇

Did you know I curate a list of all the awesome Entra related links all in one place?

Here's a quick peak into this list
I ended up writing a post about the new feature to change group SOA from AD to #Entra. Big big thanks to @intune.best for all of the assistance he provided and initial testing he did in #WinAdmins Discord voice yesterday!

ajf.one/group-soa
Aye, this new #Entra feature is pretty neat once you work out the missing bits! After you set isCloudManaged=true, add the group to the Cloud Sync Entra->AD config, trigger provisioning, and watch the group get relocated/renamed! SOA reversal with the SID maintained! See before and after images:
Reposted by Anthony J. Fontanez
It has been almost 3 years since my last blog post, but I am excited to share my first Microsoft Tech Community post!

Want deeper Intune reporting? I walk through building a Windows 365 dashboard using Power BI + Log Analytics.

Check it out!
#Intune #Windows365 #TechCommunity
Creating Custom Intune Reports with Microsoft Graph API | Microsoft Community Hub
  Systems administrators often need to be able to report on data that is not available in the native reports in the Intune console. In many cases this...
techcommunity.microsoft.com
If you were to trust their root CA as instructed, anything it issues would be inherently trusted by your device.
This is actually hilarious and no, you shouldn't blindly trust some root CA like this. This defeats the purpose of how PKI works. Public CAs are heavily regulated in terms of auditing and security.
Notepad++'s code signing cert expired, couldn't get a new one under the "Notepad++" name, so instead of getting one under their name (what the WinSCP developer does), they instead created their own root CA, issued a code signing cert, and want you to trust it notepad-plus-plus.org/news/v883-se...
Notepad++ v8.8.3 - Self-signed Certificate: Certified by Code, Not Corporations | Notepad++
notepad-plus-plus.org
And it's a super easy setup/upgrade, go do it now! #Entra
Reposted by Anthony J. Fontanez
Happy Memorial Day Weekend Everyone! Indy 500 tomorrow, Game 3 between the Pacers and Knicks. What better way to celebrate the weekend than a new post about converting SCCM Configuration Items to Intune Remediation Scripts?

joeloveless.com/2025/05/conf...

#sccm #intune #mecm #powershell
Converting Registry Based SCCM Configuration Items to Intune Remediation Scripts
Script walkthrough on converting SCCM Configuration Items to Intune Remediation Scripts.
joeloveless.com
My take on remediating #BlackLotus via #Intune Remediations & #ConfigMgr CIs. It sure was fun to code up and test as much as I was able to. Please let me know if you have any feedback or run into any issues if you try the scripts out!

ajf.one/blacklotus
Dealing With CVE-2023-24932, aka Remediating BlackLotus
CVE-2023-24932. 2023 feels like so long ago, and yet, this is still an issue. Why? Because it’s quite frankly a mess to deal with and has multiple moving parts. I highly recommend reading tho…
ajf.one