#WindowsITPro
Personal Data Encryption folder protection now available: The new Personal Data Encryption known folder protection capability is now available on Windows 11, version 24H2 Enterprise and Education editions. This feature uses Windows Hello authentication to add… https://bit.ly/3ZNQi7I #WindowsITPro
December 19, 2024 at 5:04 PM
Join the Windows and Devices MVP community: The Microsoft Most Valuable Professional (MVP) Program recognizes exceptional IT professionals working with Microsoft products who demonstrate technical expertise, leadership, and a commitment to improvement. To become… https://bit.ly/3Em7f2i #WindowsITPro
February 5, 2025 at 5:05 PM
Windows at Microsoft Technical Takeoff 2025: I couldn't be more excited to share the full list of Windows sessions planned for our third edition of the Microsoft Technical Takeoff!

Our engineering PMs in Windows and Windows cloud experiences have been working… https://bit.ly/4k0jEJm #WindowsITPro
February 13, 2025 at 10:19 PM
Productive, secure, future-ready: Tackling Tech season 4 begins: What does Windows 365 deployment look like for organizations with high security standards? How does hotpatching improve on traditional update management? Where is the Windows Subsystem for Linux… https://bit.ly/4h6ygVb #WindowsITPro
February 20, 2025 at 3:04 PM
Frequently asked questions: Windows cloud security: In this week's episode of Windows in the Cloud, we took a closer look at ways you can better protect hybrid and remote users through the power of Windows 365 cloud security. If you're looking to invest in… https://bit.ly/4hvmLqM #WindowsITPro
January 28, 2025 at 1:56 AM
TPM 2.0 – a necessity for a secure and future-proof Windows 11: With Windows 10 end of support approaching, it’s important to revisit a key minimum system requirement for Windows 11: Trusted Platform Module (TPM) 2.0. Let’s discuss the role of TPM and its value… https://bit.ly/49ntWyA #WindowsITPro
December 3, 2024 at 5:00 PM
Skilling snack: Windows driver update management: How do you manage Windows driver updates? Whether you've been using Microsoft Intune or Windows Autopatch, today it's a cohesive unified experience. Learn about different ways to utilize our controls, such as… https://bit.ly/4h73uv8 #WindowsITPro
February 27, 2025 at 10:02 PM
Windows news you can use: December 2024: With so many Windows 11 innovations announced at Microsoft Ignite last month, where would you start? Check out practical tips and deeper dives, the December security update, and several preview opportunities.

New in… https://bit.ly/3BsDMmf #WindowsITPro
December 19, 2024 at 10:01 PM
Nese 7 and Nese Server 2008 R2 with SP1 will end of mainstream support after January 14, 2025

#NeseOS #Microsoft #Windows #Nese7 #NeseServer2008R2 #SP1 #news #BreakingNews‌ #ROBLOX #saveroblox #robloxacılsın #WindowsITPro #NeseServer #Nese #TrendingNow #Trending #Windows11 #USA!
December 20, 2024 at 1:27 PM
Hotpatch for client comes to Windows 11 Enterprise: Today we announce the public preview of hotpatch updates for Windows 11 Enterprise, version 24H2. With hotpatch updates, you can quickly take measures to help protect your organization from the evolving… https://bit.ly/3ZcYKhJ #WindowsITPro
November 19, 2024 at 1:34 PM
Unidirectional clipboard for Azure Virtual Desktop and Windows 365: Azure Virtual Desktop and Windows 365 have emerged as powerful solutions for enabling remote work and enhancing productivity. One crucial aspect is clipboard redirection, which allows users to… https://bit.ly/3Vwy7Cm #WindowsITPro
December 9, 2024 at 5:04 PM
Windows news you can use: November 2024: This month, we celebrate the general availability of Windows Server 2025 and the latest Windows innovations shared at our biggest annual event, Microsoft Ignite. Read on for more details on new features and capabilities… https://bit.ly/3Z9B9xq #WindowsITPro
November 26, 2024 at 6:03 PM
New end-user experiences for Windows in the cloud: December 2024: We have recent updates to share with you about end-user experiences, including news from Microsoft Ignite 2024 and Windows cloud announcements. The future of Windows is AI and the cloud for… https://bit.ly/4gjLCgK #WindowsITPro
December 5, 2024 at 3:02 PM
Administrator protection on Windows 11: In today's digital landscape, the importance of maintaining a robust security posture cannot be overstated. A critical aspect of achieving this is ensuring that users operate with the least privilege required. Users with… https://bit.ly/4eCcNSv #WindowsITPro
November 19, 2024 at 1:34 PM
Improved Copilot experiences for commercial organizations: Today, we're announcing that Microsoft Copilot experiences are evolving to better serve the needs of commercial organizations. These changes are designed to empower all users and organizations—no matter… https://bit.ly/40eIj3P #WindowsITPro
January 15, 2025 at 2:34 PM
Microsoft Connected Cache is now generally available: We are proud to announce the general availability of Microsoft Connected Cache on July 23, 2025, to Enterprise and Education organizations. We thank partners and customers who have participated in the preview program for their… #WindowsITPro
Microsoft Connected Cache is now generally available
We are proud to announce the general availability of Microsoft Connected Cache on July 23, 2025, to Enterprise and Education organizations. We thank partners and customers who have participated in the preview program for their valuable feedback, which has helped us refine Connected Cache into a production-ready solution. Connected Cache helps organizations realize significant bandwidth savings when performing Windows 11 upgrades, Microsoft Intune provisioning, Intune application installations, Windows Autopilot software updates, and other monthly update deployments. As more organizations move to a cloud-native approach to device management, internet bandwidth consumption has become a major pain point. Without on-premises distribution points running Configuration Manager, customers have seen their network bandwidth consumption skyrocket as all their devices attempt to download updates directly from Windows Update over the internet. Microsoft Connected Cache for Enterprise and Education is available to all organizations with Windows Enterprise (E3, E5, and F3) or Windows Education (A3 and A5) entitlements, or a more comprehensive Microsoft 365 subscription. Eligible organizations can deploy Connected Cache nodes directly to host machines running Windows Server, Windows Desktop, and Linux [Ubuntu and Red Hat Enterprise Linux (RHEL)]. One of the standout benefits of Microsoft Connected Cache is its remarkable flexibility—it can be deployed on almost any platform within your existing infrastructure, including Windows Server, Windows Desktop, and popular Linux distributions like Ubuntu and Red Hat Enterprise Linux. This versatility ensures that organizations of all sizes and architectures can take advantage of its features without the need for significant hardware changes or investments. Connected Cache works efficiently by caching only the content specifically requested by devices on your organization's network, eliminating unnecessary storage use and reducing redundant downloads. As a result, bandwidth consumption is decreased, and users benefit from faster, more reliable access to updates and applications. Connected Cache and Delivery Optimization work together to save you bandwidth While Delivery Optimization is mostly known for being a peer-to-peer delivery solution, it is also the Windows downloader component that pulls Microsoft content from the cloud and provides enterprise and education users with tools to manage bandwidth traffic, throttling capabilities, and more. Connected Cache complements Delivery Optimization peer-to-peer as a dedicated software caching solution that can be deployed within your network. Once deployed to a host machine within your network, the Connected Cache node will transparently and dynamically cache the Microsoft-published content that your organization’s Windows devices need.  Using this solution, content requests from Delivery Optimization can be served by the locally deployed Connected Cache node instead of a content delivery network. This results in fast, bandwidth-efficient delivery across connected devices on your network. Connected Cache now uses a Windows installer for cache node deployment to Windows To better streamline the installation and update process for Windows-hosted cache nodes, Connected Cache now leverages a Windows installer application for deployment to Windows host machines. The Connected Cache installer is a command line application that offers easy deployment and updating of Windows-hosted cache nodes. It also lays the groundwork for future app capabilities such as new observability and troubleshooting tools. Connected Cache can be configured to support Intune and Teams content requests via HTTPS To meet evolving content delivery requirements from Microsoft content publishers, Connected Cache now supports both HTTP and HTTPS protocols. This enhancement ensures that Connected Cache can seamlessly cache and serve content regardless of the publisher’s delivery method. The added flexibility allows organizations to adapt to changing publisher requirements without compromising performance or efficiency. Notably, this update enables access to Teams content via Connected Cache for the first time—an important expansion of supported content types. As Intune transitions to requiring HTTPS content delivery, this feature ensures continued compatibility and uninterrupted caching benefits. To enable HTTPS support, IT administrators must deploy a certificate to Connected Cache. Configuration guidance is available in the public documentation. This update reinforces Microsoft Connected Cache’s role as a secure, adaptable, and enterprise-ready caching solution aligned with modern content delivery standards. Deploy Microsoft Connected Cache for Enterprise and Education Microsoft Connected Cache is a flexible caching solution that saves bandwidth and speeds up access to updates and applications without major hardware changes, helping you keep your organization’s devices productive and secure. It is free to use for organizations with eligible Windows Enterprise and Education entitlements. To get started, customers can use the Azure Marketplace to create “Microsoft Connected Cache for Enterprise and Education” Azure resources. Once the Connected Cache Azure resource has been created, organizations can create, configure, and deploy as many cache nodes as required to support their network topologies and content delivery needs. While access to Azure is required for usage and management, the Connected Cache Azure resource does not incur any Azure cost. Please see the Microsoft Connected Cache for Enterprise and Education documentation overview page for more details. Full details on the GA release can be found in the Release Notes public documentation. Start using Connected Cache today! --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
bit.ly
July 23, 2025 at 7:05 PM
Introducing the Windows 11 roadmap: We're thrilled to announce the launch of the Windows roadmap. At Microsoft, we've had the privilege to talk to thousands of IT professionals just like you, across the globe, about your experience managing Windows. Across those conversations, one… #WindowsITPro
Introducing the Windows 11 roadmap
We're thrilled to announce the launch of the Windows roadmap. At Microsoft, we've had the privilege to talk to thousands of IT professionals just like you, across the globe, about your experience managing Windows. Across those conversations, one thing rings loud and clear: the need for more transparency around what's shipping and when so that you can manage change for your estate. The Windows roadmap is a step forward in increasing transparency. On the roadmap, you can find information on Windows 11 improvements and features that: * Are currently available to validate in the Windows Insider Program. * Are gradually rolling out. * Are generally available (fully enabled in the monthly non-security update). Within the roadmap, you can also find instructions on how to access new features and improvements before they're enabled by default in your estate. The Windows roadmap site showing details for two features in preview, Recall and Click to Do. See what's coming to a specific version of Windows for the different release channels and device types (Copilot+ PC, Windows 11 PC), or check on the latest status of improvements and new features with intuitive filter controls. The Windows roadmap provides estimated release dates and descriptions for features being released. All information is subject to change. As a feature or product is canceled or postponed, information will be removed from this website. This is just the beginning! This roadmap is initially scoped to Windows client devices running Windows 11 as that is where we're adding the majority of improvements and new features at this time. As you start using this roadmap, we will be looking for your suggestions and feedback to improve how it works and what content is included so that we can better meet your needs. As we listen and learn, we'll consider expanding the roadmap to cover additional areas and device types. To that end, please leave us your feedback below or reach out to me directly here on the Tech Community, on X @ariaupdated, or on LinkedIn. In addition to the Windows roadmap, you can stay on top of newly released Windows 11 features, services, and enhancements through these official channels: * Windows release notes and release information * Windows release health dashboard * Windows Blog
bit.ly
March 27, 2025 at 7:33 PM
VBScript deprecation: Detection strategies for Windows: Start detecting Visual Basic Scripting Edition (VBScript) across your organization in preparation for the next deprecation phase.

At the current deprecation phase of VBScript, it's available as a feature on demand (FOD) and is… #WindowsITPro
VBScript deprecation: Detection strategies for Windows
Start detecting Visual Basic Scripting Edition (VBScript) across your organization in preparation for the next deprecation phase. At the current deprecation phase of VBScript, it's available as a feature on demand (FOD) and is enabled by default in Windows 11, version 24H2. Before VBScript is disabled by default on these and future OS versions, it's critical that you to identify where and how vbscript.dll is still being used within your enterprise environment. Take a look at four scalable, enterprise-ready mechanisms to detect usage and plan mitigation steps across all Windows platforms.  Strategy 1: Use Sysmon to monitor VBScript usage Use System Monitor (Sysmon) and load the tracking capability for its dynamic link libraries (.dll) to monitor enterprise-wide usage of VBScript. You can detect vbscript.dll loads by collecting and analyzing Sysmon logs across all Windows platforms. Important: Sysmon monitoring can cause performance and operational overhead, especially when deployed at scale. Before broad deployment, test on a small group of devices to evaluate performance impact. Configure .dll load tracking and deploy Sysmon Before deploying Sysmon, configure it with a minimal and focused rule set that targets .dll loads. Since Sysmon doesn't have a graphical user interface (GUI), you'll manage configurations via XML files and the command-line interface. Add a configuration to your Sysmon setup as illustrated in the following sample:         vbscript.dll    To apply this configuration: * Edit your Sysmon configuration file (typically, sysmon-config.xml). * Reload it using the Sysinternals Sysmon utility. * Open an elevated command prompt and run: Sysmon64.exe -c sysmon-config.xml * Verify the current configuration by running: Sysmon64.exe -c This configuration instructs Sysmon to generate Event ID 7 (image loaded) entries whenever any process loads vbscript.dll. The rule set sample above is sufficient to track VBScript. However, for more mature or modular configurations, consider adapting broader rule sets from these GitHub resources: * SwiftOnSecurity's baseline Sysmon config * Olaf Hartong's Sysmon Modular framework Now, you can deploy Sysmon using Microsoft Intune, Group Policy, Microsoft Configuration Manager, or scripts, depending on your organization's setup. Collect Sysmon logs of .dll loads After you configure and deploy Sysmon, collect the logs for Event ID 7. At this stage, you'll identify how many and which processes load vbscript.dll. * In the Event Viewer, go to Applications and Services Logs. * Locate Microsoft > Windows > Sysmon on the left navigation bar. * Select Operational. * In the Actions pane on the right, filter the log by Event ID 7, Sysmon. Screenshot of Event Viewer showing search results for Event ID 7 in Sysmon. Forward these events to a central log store for analysis. Do this through Windows event forwarding, security information and event management (SIEM) agents, or manual exports. You can then use standard tools like Power BI, Microsoft Excel, or custom scripts to analyze these Sysmon logs. Analysis tip 1: Trace process ancestry in desktop and script usage Sysmon's Event ID 7 (image loaded) and Event ID 1 (process creation) can help identify which process loaded vbscript.dll and its immediate parent. This gives insights into process ancestry. Learn more about the types of events that Sysmon generates. To trace deeper process lineage (e.g., grandparent processes), use endpoint detection and response (EDR) or SIEM tools with visual process graphs. For more thorough analysis, consider using PowerShell scripts to: * Parse Event ID 7 to extract Process IDs (PIDs) of processes that loaded vbscript.dll. * Use Event ID 1 to find the parent process. This allows you to gain insight into what launched the script-capable process, such as wscript.exe, regsvr32.exe, or application binaries. If you're new to PowerShell, learn how to query and filter event logs. Analysis tip 2: Solve for noise in web-hosted environments Web-hosted environments are different. These include Internet Information Services (IIS) running VBScript for server-side scripting (e.g., classic Active Server Pages known as ASP). In such environments, vbscript.dll may be loaded passively during the initial page load, even before user interaction. This can generate noise in Sysmon logs, because Event ID 7 entries are logged regardless of whether VBScript is actively invoked. Furthermore, Sysmon events do not include web-layer context such as the URL or page name. To reduce noise and improve traceability, combine Sysmon logs with IIS logs. By correlating Sysmon timestamps with IIS request entries, you can identify which specific HTTP request triggered the vbscript.dll load, providing clearer context for web-based script execution. See Advanced logging for IIS – Log filtering if this is new to you. Strategy 2: Review VBScript dependencies In many enterprise environments, VBScript dependencies may be embedded in any of the following centrally managed locations: * Group Policy logon scripts * Group Policy logoff scripts * Group Policy startup scripts * Group Policy shutdown scripts * Scheduled tasks configured to launch legacy scripts * PowerShell scripts deployed via Intune that invoke .vbs scripts indirectly With this strategy, you'll identify these scripts in preparation for their remediation and VBScript removal.  Note: You can often perform these analyses from a single admin workstation or a domain controller (DC). That is because Group Policy objects (GPOs), scheduled tasks, and Intune scripts are centrally configured either via GPO or device-management platforms. Group Policy object scripts * Check \\\SYSVOL for .vbs files.  * Extract referenced scripts (e.g., using PowerShell).  * Look for any invocation of wscript.exe, cscript.exe, or .vbs files.  Brush up on using these scripts in Group Policy if needed. Scheduled tasks List scheduled tasks and inspect command lines (e.g., using PowerShell). Pay special attention to tasks under \Microsoft\Windows or custom organization-defined folders.  Microsoft Intune–deployed scripts (PowerShell) Although Intune doesn't natively run .vbs files, PowerShell scripts deployed via Intune can still invoke VBScript indirectly (e.g., via cscript.exe). Please review any PowerShell scripts deployed through Intune for embedded VBScript execution patterns. Strategy 3: Scan for .vbs files across the system  To complement other detection strategies for your enterprise, proactively search for .vbs script files on endpoints. This helps surface any legacy script usage not tied to scheduled tasks or GPOs.  Recursively look for .vbs files in common paths like:  * C:\Users\  * C:\ProgramData\  * C:\Program Files\  * C:\Program Files (x86)\ * C:\Scripts\  * C:\Windows\ (optional: might include noise)  Caution: Avoid scanning the entire C:\ blindly in production. It can cause performance issues or access errors. Focus on user- and script-relevant paths.  To scan relevant paths, adapt the following sample PowerShell script:  $pathsToScan = @("C:\Users", "C:\ProgramData", "C:\Scripts") $logPath = "C:\VBSScriptScan\VbsFiles_$(hostname).csv" $results = foreach ($path in $pathsToScan) {    if (Test-Path $path) {        Get-ChildItem -Path $path -Filter *.vbs -Recurse -ErrorAction SilentlyContinue |            Select-Object FullName, LastWriteTime, Length    } } $pathsToScan = @("C:\Users", "C:\ProgramData", "C:\Scripts") $logPath = "C:\VBSScriptScan\VbsFiles_$(hostname).csv" $results = foreach ($path in $pathsToScan) {    if (Test-Path $path) {        Get-ChildItem -Path $path -Filter *.vbs -Recurse -ErrorAction SilentlyContinue |            Select-Object FullName, LastWriteTime, Length    } } For large enterprise deployments, you can run this command via: * Microsoft Intune * Group Policy startup script  * Remote PowerShell (Invoke-Command)  * Microsoft Configuration Manager script deployments  Store results centrally (e.g., \\AdminPC\Scans\) or log them locally and collect them later.  Strategy 4: Scan custom MSI packages for embedded VBScript Custom Microsoft Installer (MSI) packages may contain embedded VBScript through custom actions. This was a common packaging practice in older enterprise applications. These scripts are often silently executed during installation, repair, or uninstallation processes. Don't overlook them during your modernization efforts! With this strategy, you'll identify VBScript use in MSI files so you can flag legacy packages for remediation. Detect custom action * Use PowerShell to recursively scan .msi files across your software repositories. * Inspect the MSI CustomAction table for action types 6, 38, and 50. These correspond to VBScript entries. * Look for VBScript stored in binary streams, embedded inline, or referenced by path. Adapt the following PowerShell sample detection script: Get-ChildItem -Path "C:\MSIRepo" -Recurse -Filter *.msi | ForEach-Object {     $msiPath = $_.FullName     $sql = "SELECT * FROM CustomAction"     $installer = New-Object -ComObject WindowsInstaller.Installer     $database = $installer.GetType().InvokeMember("OpenDatabase", "InvokeMethod", $null, $installer, @($msiPath, 0))     $view = $database.OpenView($sql)     $view.Execute()     $record = $view.Fetch()     while ($record -ne $null) {         $actionName = $record.StringData(1)         $actionType = [int]$record.StringData(2)         if ($actionType -eq 6 -or $actionType -eq 38 -or $actionType -eq 50) {             Write-Output "⚠ VBScript Custom Action: $actionName in $msiPath"         }         $record = $view.Fetch()     } } Replace C:\MSIRepo with a local or network share that stores your MSI files (e.g., software deployment folders, Microsoft Configuration Manager package sources, or app archives). Scaling recommendations For better scaling experience, follow these recommendations: * Collect MSI files from known deployment shares (e.g., Intune or Configuration Manager package sources, network software shares). * Automate scanning using scheduled tasks or deployment tools (like Intune or Configuration Manager). * Export findings to a central log or reporting system for visibility and tracking. Avoid using Win32_Product for MSI enumeration. It can trigger a repair of all MSI-installed applications. Instead, rely on registry-based software inventory or trusted package management tools. To audit installed software, adapt the following PowerShell script. It lists installed applications from the Windows registry, showing each app's name, installation data, and publisher. Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* |    Where-Object { $_.DisplayName } |    Select-Object DisplayName, InstallDate, Publisher For reference on action types, see Microsoft official MSI documentation at CustomAction Table and Custom Action Types. Remediation options for MSI packages using VBScript You need to remediate MSI packages with VBScript custom actions. Your options depend on the source of the package: * Internally packaged MSIs: You may be able to repackage the installer using tools like Orca or Advanced Installer to remove or replace the VBScript custom actions. * Third-party/independent software vendor (ISV) software: Contact the vendor to request a supported version without VBScript usage. If unavailable, consider isolating or monitoring the app until migration is possible. VBScript is detected. What next? With these four detection methods, you gain a comprehensive view of VBScript dependencies across your current Windows platforms. This insight is key to planning effective remediation and aligning with future-proof technologies. Proactively migrate away from VBScript Once you identify scripts and processes that depend on VBScript, you're ready to migrate these dependencies away from VBScript. Please refer to the section “Next steps if my app or website has dependency on VBScript” in VBScript deprecation: Timelines and next steps. Remember: During the deprecation phase, you can continue using VBScript until it's completely retired in upcoming OS versions. The deprecation phase is designed to signal the upcoming change and give you time to research and migrate to alternatives. Proactively disable VBScript on Windows 11 Now that VBScript is enabled by default on Windows 11, version 24H2 and later, you can take additional steps to prepare. Once you confirm that VBScript is unused across these devices with the detection methods above, you should proactively disable it. Use the following Deployment Image Servicing and Management (DISM) command to do so: Dism /Online /Remove-Capability /CapabilityName:VBSCRIPT~~~~  Use Microsoft Intune, GPO Startup Scripts, or Microsoft Configuration Manager to deploy this command across your fleet.  Expect the following consequences of disabling VBScript: * All processes attempting to use VBScript (e.g., cscript.exe, wscript.exe, embedded Internet Explorer) are blocked.  * Scripts relying on VBScript fail silently or with errors.  Important: Please validate capability state and commands in a controlled test environment before wide-scale automation or rollout of this DISM command. The availability and behavior of the VBScript capability vary based on system configurations and different builds. This includes enabling or disabling VBScript via DISM or PowerShell. In summary, now is the time to start proactively migrating away from VBScript. We hope this guidance helps you detect and remediate usage before VBScript becomes disabled by default in the next deprecation phase. Read VBScript deprecation: Timelines and next steps for additional context and recommendations for more advanced scripting alternatives. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
bit.ly
May 16, 2025 at 5:02 PM
Optimize Windows Autopilot bandwidth use with Connected Cache: As organizations move from on-premises device management to cloud device management, the efficiency of internet bandwidth management and software deployment becomes increasingly important. Windows… https://bit.ly/4ioKzNx #WindowsITPro
March 5, 2025 at 5:45 PM
Get started with quick machine recovery in Windows: Quick machine recovery—a powerful feature that automatically detects, diagnoses, and resolves critical issues on your device—is now available in the Windows Insider Preview Beta Channel for Windows 11, version 24H2. First announced… #WindowsITPro
Get started with quick machine recovery in Windows
Quick machine recovery—a powerful feature that automatically detects, diagnoses, and resolves critical issues on your device—is now available in the Windows Insider Preview Beta Channel for Windows 11, version 24H2. First announced by Microsoft CEO Satya Nadella at Microsoft Ignite 2024 as part of the Windows Resiliency Initiative, this feature is a game-changer for Windows 11 devices facing boot issues. Reducing the burden on IT administrators With system failures, devices can sometimes get stuck in the Windows Recovery Environment (Windows RE), severely impacting productivity and often requiring IT teams to spend significant time troubleshooting and restoring affected machines. With quick machine recovery, when a widespread outage affects devices from starting properly, Microsoft can broadly deploy targeted remediations to affected devices via Windows RE—automating fixes and quickly getting users to a productive state without requiring complex manual intervention. What's included in the preview Currently available in preview for Windows Insiders in the Beta Channel, quick machine recovery supports Windows 11, version 24H2 devices with an up-to-date version of Windows RE. This feature will eventually be enabled by default for Windows 11 Home devices. For devices running Windows 11 Pro and Enterprise, local and IT admins will be in full control and can enable or customize the feature for the devices in their organizations. Quick machine recovery is shown in the Advanced options menu for Windows RE The following capabilities are available with this initial release: * Enable/disable: IT admins can enable or disable quick machine recovery via the RemoteRemedation CSP or directly on the device via reagentc.exe in an administrative command prompt. * Preconfigure experience: IT admins can prepopulate network credentials to ensure seamless delivery of automatic remediations. They can also configure the scanning interval, which checks for remediations (recommended: every 30 minutes), and the timeout, which determines when the device will restart (recommended: 72 hours, to optimize the remediation process). * Test: Simulate the quick machine recovery process through test mode to ensure readiness before deployment. Keep an eye out for a test remediation package coming your way in the next few days, allowing you to experience the quick machine recovery feature in action. How it works Quick machine recovery strengthens system resilience by detecting failures and automating remediation to minimize downtime. During a widespread outage, assuming the system has quick machine recovery and automatic remediation enabled, the process would look like this: * Device enters recovery mode: If a Windows 11, version 24H2 device encounters a critical failure preventing normal boot, it enters Windows RE. * Network connection established: Windows RE connects to the network using ethernet or Wi-Fi protected access (WPA), ensuring the device can communicate with Microsoft's recovery services. Future updates will introduce additional networking configurations for broader support. * Incident analysis: Microsoft analyzes crash data from affected devices to identify patterns and pinpoint the root cause. If a widespread outage is detected, an internal response team is activated to develop, validate, and prepare a targeted remediation. * Remediation rollout: In this initial release, Microsoft will deliver the remediation via Windows Update, adhering to the update policies configured on the device. Microsoft will safely rollout the remediation. Get started today Windows Insiders can start testing quick machine recovery by installing the latest Windows Insider Preview build in the Beta Channel for Windows 11, version 24H2. We encourage you to explore the capabilities and provide feedback via Feedback Hub (file under Recovery and Uninstall > Quick Machine Recovery) to help us refine and optimize this feature. You can learn more about quick machine recovery by reading today's announcement on the Windows Insider Blog. Stay tuned for future enhancements as we continue to strengthen Windows resilience and support IT admins in maintaining seamless business operations. To learn more about the Windows Resiliency Initiative, see Windows security and resiliency: Protecting your business. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
bit.ly
March 28, 2025 at 5:02 PM
Understanding the Microsoft Pluton security processor: Earlier this year, we announced that the Microsoft Pluton security processor (Pluton) will be enabled by default on all Copilot+ PCs. With new Pluton devices manufactured by our rich ecosystem of PC… https://bit.ly/4aAhdJr #WindowsITPro
January 30, 2025 at 3:01 PM
Attestation readiness verifier for TPM reliability: The attestation readiness verifier tool is here to help you enhance Trusted Platform Module (TPM) reliability! It simulates verification of Measured Boot logs and proactively identifies security and reliability… https://bit.ly/4bLzhkf #WindowsITPro
March 19, 2025 at 4:03 PM
Act now: Secure Boot certificates expire in June 2026: Prepare for the first global large-scale certificate update to Secure Boot.

The Microsoft certificates used in Secure Boot are the basis of trust for operating system security, and all will be expiring beginning June 2026. The… #WindowsITPro
Act now: Secure Boot certificates expire in June 2026
Prepare for the first global large-scale certificate update to Secure Boot. The Microsoft certificates used in Secure Boot are the basis of trust for operating system security, and all will be expiring beginning June 2026. The way to automatically get timely updates to new certificates for supported Windows systems is to let Microsoft manage your Windows updates, which include Secure Boot. A close collaboration with original equipment manufacturers (OEMs) who provide Secure Boot firmware updates is also essential. If you haven't yet, begin evaluating options and start preparing for the rollout of updated certificates across your organization in the coming months. Learn about this effort, its impact, and what you as an IT admin should do to help ensure that your Windows devices can receive updates after June 2026 without compromising system security. Important: While platforms beyond Windows are affected, this article focuses on the solution for Windows systems. Be sure to monitor the Secure Boot certificate rollout landing page for status and guidance updates. Recap: Why Secure Boot requires updating Secure Boot helps to prevent malware from running early in the startup sequence of a Windows device. Coupled with the Unified Extensible Firmware Interface (UEFI) firmware signing process, Secure Boot uses cryptographic keys, known as certificate authorities (CAs), to validate that firmware modules come from a trusted source. After 15 years, the Secure Boot certificates that are part of Windows systems will start expiring in June 2026. Windows devices will need new certificates to maintain continuity and protection. * Affected: Physical and virtual machines (VMs) on supported versions of Windows 10, Windows 11, Windows Server 2025, Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012, Windows Server 2012 R2—the systems released since 2012, including the long-term servicing channel (LTSC) * Not affected: Copilot+ PCs released in 2025 Note: Affected third-party OS includes MacOS. However, it's outside the scope of Microsoft support. For Linux systems dual booting with Windows, Windows will update the certificates that Linux relies on. Secure Boot uses certificate-based trust hierarchy to ensure that only authorized software runs during system startup. At the top of this hierarchy is the Platform Key (PK), typically managed by the OEM or a delegate, which acts as the root of trust. The PK authorizes updates to the Key Enrollment Key (KEK) database, which in turn authorizes updates to two critical signature databases: the Allowed Signature Database (DB) and the Forbidden Signature Database (DBX). This layered structure ensures that only validated updates can modify the system's boot policy, maintaining a secure boot environment. See how it works in Updating Secure Boot keys. The change: Expiring certificates Windows systems released since 2012 might have expiring versions of the certificates listed below. The UEFI Secure Boot DB and KEK need to be updated with the corresponding new certificate versions. See what new certificates will be available in the coming months to maintain UEFI Secure Boot continuity. Expiration date Expiring certificate Updated certificate What it does Storing location June 2026 Microsoft Corporation KEK CA 2011 Microsoft Corporation KEK 2K CA 2023 Signs updates to DB and DBX KEK June 2026 Microsoft Corporation UEFI CA 2011 (or third-party UEFI CA)* a) Microsoft Corporation UEFI CA 2023 b) Microsoft Option ROM UEFI CA 2023   a) Signs third-party OS and hardware driver components b) Signs third-party option ROMs   DB Oct 2026 Microsoft Windows Production PCA 2011 Windows UEFI CA 2023 Signs the Windows bootloader and boot components DB *You need two new certificates for Microsoft Corporation UEFI CA 2011, which together allow for more granular control. Microsoft and partner OEMs will be rolling out certificates to add trust for the new DB and KEK certificates in the coming months.  The impact and implications The CAs ensure the integrity of the device startup sequence. When these CAs expire, the systems will stop receiving security fixes for the Windows Boot Manager and the Secure Boot components. Compromised security at startup threatens the overall security of affected Windows devices, especially due to bootkit malware. Bootkit malware can be difficult or impossible to detect with standard antivirus software. For example, even today, the unsecured boot path can be used as a cyberattack vector by the BlackLotus UEFI bootkit (CVE-2023-24932). Every Windows system with Secure Boot enabled includes the same three certificates in support of third-party hardware and Windows ecosystem. Unless prepared, physical devices and VMs will: * Lose the ability to install Secure Boot security updates after June 2026. * Not trust third-party software signed with new certificates after June 2026. * Not receive security fixes for Windows Boot Manager by October 2026. To prevent this, you'll need to update your organization's entire Windows ecosystem with certificates dated 2023 or newer. This will also help you apply mitigations needed to help secure your systems against the BlackLotus and similar boot-level cyberattacks today. Take action today To begin, bookmark the Secure Boot certificate rollout landing page and take our readiness survey! Important: Check with your OEMs on the latest available OEM firmware. Apply any available firmware updates to your Windows systems before applying the new certificates. In the Secure Boot flow, firmware updates from OEMs are the foundation for Windows Secure Boot updates to apply correctly. Microsoft support is only available for supported client versions of Windows 11 and Windows 10. Once Windows 10 reaches end of support in October 2025, consider getting Extended Security Updates (ESU) for Windows 10, version 22H2 if you're not ready to upgrade. In the coming months, we expect to update the Secure Boot certificates as part of our latest cumulative update cycle. The solution that requires the least effort is letting Microsoft manage your Windows device updates, including Secure Boot updates. However, you might need to adopt multiple solutions. Your specific next step depends on the Windows systems and how you manage them. Enterprise IT-managed systems that send diagnostic data No action is required if Windows systems at your organization receive Windows updates from Microsoft and send diagnostic data back to Microsoft. This includes devices that receive updates through Windows Autopatch, Microsoft Configuration Manager, or third-party solutions. Note: Check that your firewall doesn't block diagnostic data. If it does, please take action to help diagnostic data reach Microsoft. Windows diagnostic data and OEM feedback will help us group devices with similar hardware and firmware profiles to gradually release Secure Boot updates to you. This allows us to intelligently monitor the rollout process, proactively pausing, addressing any issues, and continuing as needed. Just keep your devices updated with the latest Windows updates! Enterprise IT-managed systems that don't send diagnostic data Enable Windows diagnostic data and let Microsoft manage your updates by taking the following steps: * Configure your organizational policies to allow at least the “required” level of diagnostic data. You can use Group Policy or mobile device management (MDM) to do this. See how to do this in Group Policy Management Editor for Windows 11 and Windows 10. * Allow Microsoft to manage Secure Boot-related updates for your devices by setting the following registry key: o   Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot o   Key name: MicrosoftUpdateManagedOptIn o   Type: DWORD o   DWORD value: 0x5944 (opt in to Windows Secure Boot updates) We recommend setting this key to 0x5944. It indicates that all certificates should be updated in a manner that preserves the security profile of the existing device. It also updates the boot manager to the one signed by the Windows UEFI CA 2023 certificate. Note: If the DWORD value is 0 or the key doesn't exist, Windows diagnostic data is disabled. If you prefer not to enable diagnostic data, please take this anonymous readiness survey. Help us assess the needs of environments like yours to create future guidance on managing the update process independently. You'll remain fully in control and responsible to execute and monitor these updates. Air-gapped devices, such as in government scenarios or manufacturing, are a special case. Because Microsoft cannot manage these updates, we can only offer the following limited support: * Recommend known steps or methods for deploying these updates * Share data gathered from our rollout stream When available, look for these resources on the Secure Boot certificate rollout landing page. Systems with Secure Boot disabled Windows cannot update the active variables of the Secure Boot certificates if Secure Boot is disabled. Important: Toggling Secure Boot on or off might erase the updated certificates. If Secure Boot is on, leave it enabled. Turning it off can reset the settings with defaults, which is not desirable. Share these recommendations with individual users: * Press Windows key + R, type msinfo32, and then press Enter. * In the System Informationwindow, look for Secure Boot State. * If it says On, you're good to go! If Secure Boot is off or unsupported, the device may not receive the new CAs. For these devices, you may choose to enable Secure Boot with this guidance: Windows 11 and Secure Boot.  Change management considerations Don't wait until June 2026! Updating DB and KEK with new 2023 certificates will help prevent your systems from boot-level security vulnerabilities today. Get the latest OEM firmware updates and let Microsoft manage your Windows updates to receive Secure Boot updates automatically. Otherwise, help us understand your special case by completing this anonymous readiness survey. Watch the release notes for Windows 11, version 24H2, version 23H2, and Windows 10 in the coming months to know when these updates are available to you. Stay tuned for additional guidance for the LTSC as needed. Bookmark these additional resources: * Secure Boot certificate rollout landing page * Windows devices for businesses and organizations with IT-managed updates * Windows devices for home users, businesses, and schools with Microsoft-managed updates * Windows 11 and Secure Boot * Secure Boot * Updating Secure Boot keys * Enterprise deployment guidance for CVE-2023-24932 * How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932   --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
bit.ly
June 26, 2025 at 5:03 PM
New enhancements for Windows App on web: A set of new enhancements for Windows App on web, including the Remote App Launcher and new printing capabilities, improve your experience and ease of use.

Remote App Launcher

Located directly on the toolbar inside the web client itself,… #WindowsITPro
New enhancements for Windows App on web
A set of new enhancements for Windows App on web, including the Remote App Launcher and new printing capabilities, improve your experience and ease of use. Remote App Launcher Located directly on the toolbar inside the web client itself, you can now use Remote App Launcher to launch additional apps without leaving the web window. With Remote App Launcher, you can discover and launch apps easily, without having to switch back and forth between tabs. Screenshot of the Remote App Launcher dropdown menu from the toolbar in Windows App on web. Improved printing capabilities In addition to the Remote App Launcher, there are improved printing capabilities for Windows App on web. You can now effortlessly print documents directly to your locally attached printers. This enhancement streamlines the printing experience, eliminating the need for additional steps between viewing and printing documents. Access remote sessions natively You can now utilize the Windows App on web to access Windows App and Azure Virtual Desktop remote sessions natively. By simply selecting the "Connect in desktop app" option from the dropdown menu, you can open the desktop version of the Windows App. Print Screenshot of a Cloud PC in Windows App with dropdown-menu options. Connect to Windows App on web or review Windows App documentation to learn more about Windows App across all devices. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
bit.ly
May 5, 2025 at 3:00 PM
Windows news you can use: January 2025: Learn more about what's new in Windows 11 this month. Explore updates and innovations for device management, security, productivity and collaboration, Copilot+ PCs, and more. Don't miss lifecycle news and previews rolling… https://bit.ly/40HCH2g #WindowsITPro
January 31, 2025 at 7:11 PM