Secure Active Directory Certificate Services: detect ESC1, ESC4, ESC6 and ESC8
Audit AD CS templates, ACLs, CA settings and IIS enrolment endpoints, then remediate ESC1, ESC4, ESC6 and ESC8 without disrupting critical certificates.
Read article→Technical blog · Field notes · Practical guides
Cybersecurity, Microsoft infrastructure, networking, backup, AI and residential technology explained with a practical approach.
Latest articles
Articles designed to help IT teams, decision makers and homeowners make better technical decisions.
Audit AD CS templates, ACLs, CA settings and IIS enrolment endpoints, then remediate ESC1, ESC4, ESC6 and ESC8 without disrupting critical certificates.
Read article→Inventory SMTP dependencies, choose OAuth, Microsoft Graph or a controlled relay, then remove Basic authentication without interrupting critical email.
Read article→Run cloudflared in Docker on Unraid, publish a service over HTTPS without port forwarding and protect it with Cloudflare Access.
Read article→Connect Home Assistant to UniFi Protect without exposing cameras: VLANs, local accounts, API access, notifications, retention, backups and secure remote access.
Read article→Recycle bins, versions and retention reduce risk but have finite windows. Build a tested Microsoft 365 backup and restore strategy.
Read article→SSID, channels, WPA2/WPA3, PMF, mDNS and VLANs: connect legacy IoT devices to modern Wi-Fi without weakening the network.
Read article→Find stale MDE devices with PowerShell and Active Directory. Separate inactivity, exclusion and offboarding, with review before any changes.
Read article→Plan your MDI v2-to-v3 migration: MDE prerequisites, patches, GPOs, action accounts, KQL validation and phased sensor cleanup.
Read article→A practical comparison of architectures, licensing, costs and trade-offs for choosing a replacement platform without weakening backup, storage or application operations.
Read article→A phased method to choose FIDO2 profiles, bootstrap with Temporary Access Pass, measure adoption and enforce phishing-resistant authentication without locking out accounts.
Read article→Audit signing, encryption, NTLM and guest access, then harden SMB in stages without disrupting legacy NAS devices and applications.
Read article→A Zero Trust architecture for controlling identities, tools, data, OAuth authorization, sensitive actions and audit trails for AI agents.
Read article→Ten practical KQL queries to monitor MDE sensors, ASR rules, logons, PowerShell, vulnerabilities and ransomware warning signs.
Read article→A practical method to detect RC4 dependencies, remediate service accounts and phase in AES after the 2026 Kerberos hardening changes.
Read article→A phased method to assess, deploy and monitor ASR rules with Intune or Group Policy before enabling Block mode.
Read article→A practical method to identify the most important Active Directory risks and build a realistic remediation plan.
Read article→Storage, cabling, PoE, privacy and remote access: the decisions to make before selecting and positioning cameras.
Read article→How to turn the 3-2-1 rule into a practical, testable strategy that withstands human error and ransomware.
Read article→