Check MECM Software Update Deployment Status with PowerShell
One object per update deployment with targeted, compliant, failed and unknown counts, so you can spot the deployments that need you.
Thread: Windows Update, untangled ↗Tagged · 26 notes
Everything tagged SCCM, wherever it's filed, newest first.
One object per update deployment with targeted, compliant, failed and unknown counts, so you can spot the deployments that need you.
Thread: Windows Update, untangled ↗Find the updates the most machines are actually missing, bundle them into a group, and deploy them to a pilot collection, with a WhatIf preview first.
Thread: Windows Update, untangled ↗Install a product key, activate it and confirm the edition actually changed, without the key ever landing in a script file or a log.
Thread: Packaging with ConfigMgr ↗Turn "wrap this script in a package and push it to the DPs" into one command, with a dry run before anything gets created.
Thread: Packaging with ConfigMgr ↗When Windows Update is greyed out or just won't run, check all the policy values and services that can block it, and put them back the way Windows shipped.
Thread: Windows Update, untangled ↗A one-off local admin account done properly, with a hidden password prompt, a language-proof group lookup, and an expiry date for the temporary ones.
Thread: Local admin, done right ↗Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
Thread: Local admin, done right ↗Export your KACE device inventory to CSV and get a per-location (or per-label) device count, optionally just the machines added this week.
Thread: Packaging with ConfigMgr ↗On Windows 10 and 11 there's no Windows Update logging to switch on. The trick is collecting it, and this script does that in one zip per machine.
Thread: Windows Update, untangled ↗A read-first WinRM check that tells you why remote PowerShell won't connect, fixes it only when you ask, and doubles as a ConfigMgr compliance script.
Thread: Windows Update, untangled ↗A decade-plus of Windows migrations, endpoint security, and infrastructure work, boiled down to what I did and how big it was.
A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗Audit who still talks SMBv1 to your machines, then switch it off for good, with one script and three modes.
Thread: PowerShell craft ↗Turn on Dell's Password Bypass so patch reboots don't sit at a power-on password prompt all night, then turn it back off when you're done.
Thread: Dell BIOS passwords, without the pain ↗How I think about patch risk now. Sort updates by blast radius, roll them out in rings, decide what "bad" looks like up front, and know your way back before you need it.
Thread: Windows Update, untangled ↗One script that reads the WSUS, scan-source and Windows Update for Business settings on a device and tells you where it's really getting updates from, with a safe reset for leftovers.
Thread: Windows Update, untangled ↗Register the Microsoft Update service through the Windows Update Agent's own COM API, so devices pick up Office and other Microsoft product updates, not just Windows.
Thread: Windows Update, untangled ↗Put a BIOS admin password on new Dells, or change the old one across the fleet, with both passwords handed over at runtime.
Thread: Dell BIOS passwords, without the pain ↗Switch workstations to High Performance (or Ultimate Performance) by GUID, restore the plan if the image hid it, and don't end up with five copies of it.
Thread: Packaging with ConfigMgr ↗Clear the BIOS setup password on Dell PCs and see exactly what changed, with the password supplied at runtime instead of sitting in a package.
Thread: Dell BIOS passwords, without the pain ↗One uninstall script for every retired app. Give it a display name and it finds the right uninstall command, MSI or not, and runs it quietly.
Thread: Packaging with ConfigMgr ↗Stop the spooler, clear out the wedged job files, and bring it back up, with -WhatIf and an option to leave recent jobs alone.
Thread: Spring cleaning for Windows PCs ↗Remove the internal drive password from Dell PCs with Dell's PowerShell provider, without ever writing the password into a script or package.
Thread: Dell BIOS passwords, without the pain ↗Onboarding to Defender for Endpoint and enrolling in Intune are two different things, and you almost never have to offboard one to get the other.
Thread: Getting devices into Intune ↗Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
Thread: Local admin, done right ↗A gpupdate wrapper that checks the domain trust first, never bounces anyone's session, and reports a real success or failure back to ConfigMgr.
Thread: Packaging with ConfigMgr ↗