Blog

Technical writing on SCCM, PowerShell, packaging, and enterprise IT.

RSS
Security / Patching

CVE-2026-50444 and the WSUS Servers Still on the Wire — Detection, Patch Order, and What ConfigMgr Shops Should Verify

On July 14, 2026, Microsoft published CVE-2026-50444 — a CVSS 8.8 elevation-of-privilege vulnerability in Windows Server Update Services, actively exploited in the wild and immediately added to the CISA Known Exploited Vulnerabilities catalogue. The initial fix proved incomplete. On July 18, out-of-band KB5121767 shipped as the authoritative remediation. Detection paths for an SCCM estate, the sanctioned patch order for Software Update Point hosts, and how this vulnerability makes the WSUS replacement conversation more urgent for shops that were still on the fence.

2026-07-19 13 min read
Endpoint Management

Enterprise App Catalog Auto-Update Went GA — Where It Fits Between Win32 Apps and Autopatch

With the June 2026 Intune service update (2606), auto-update for Enterprise App Catalog apps reached general availability. Microsoft Learn documentation was refreshed on June 24, 2026. The mechanism removes the manual supersedence chain that has governed third-party app updates in Intune since Enterprise App Management first shipped, but it does so under four hard constraints — no rollback, no ring-based rollout, no per-version reporting history, and a catalogue cache refresh window of up to one hour. Where EAM auto-update is defensible, where it is not, and why it is not a substitute for Autopatch.

2026-07-19 13 min read
Endpoint Management

PowerShell Script Installers for Intune Win32 Apps — What Changes for PSADT Wrappers and Where Multi-Admin Approval Bites

The PowerShell Script Installer for Intune Win32 Apps went generally available in January 2026 and has been in production use for six months. A Microsoft Learn documentation update on July 1, 2026 clarified the interaction between the Script Installer surface and Multi-Admin Approval, and named two further script properties that will fall under approval gating. A structural look at what the Script Installer changes for PSADT wrappers, three concrete deployment layouts with their tradeoffs, and the governance implication for MAA-enabled tenants.

2026-07-19 13 min read
Endpoint Management

WSUS Deprecation, Twenty-One Months On — Replacement Paths for ConfigMgr-Shop Admins

Windows Server Update Services was deprecated by Microsoft on September 20, 2024. Twenty-one months later, the role still ships in Windows Server 2025, still synchronises drivers, and still backs the Configuration Manager Software Update Point. What has accumulated in the interval — the driver-sync reversal, the September 2025 hardening pass, the October 2025 critical remote code execution vulnerability, the absence of any end-of-life date — is the story. Three sanctioned replacement paths, three concrete decision profiles for SCCM-shop admins.

2026-06-08 16 min read
Endpoint Management

Windows Autopatch Flips Hotpatch to Default — The May 2026 Pivot

On May 11, 2026, Windows Autopatch began enabling hotpatch security updates by default for every eligible Intune device that is not already governed by an explicit quality-update policy. KB5089466 was the first hotpatch delivered under the new default. The mechanism, the prerequisites, the opt-out path, and the consequences for ring-based estates.

2026-05-24 13 min read
SCCM / ConfigMgr

Configuration Manager 2603 — The Last Update Before Annual Cadence

Configuration Manager 2603 arrived in the Early Update Ring on May 5, 2026, and became globally available on May 27, 2026 — a security-focused release that closes the semi-annual era before Microsoft moves Configuration Manager to a yearly cadence with version 2609.

2026-05-23 14 min read
Security / Patching

Secure Boot certificates expiring in 2026 — an SCCM playbook

Microsoft's 2011 Secure Boot certificates expire from June 2026 onwards. The complete enterprise playbook — what expires when, what breaks, the AvailableUpdates registry mechanism, SCCM Configuration Baselines for detection and remediation, event-log signals, BitLocker and dual-boot edge cases, and guidance for disconnected environments.

2026-05-21 26 min read
Application Packaging

Creating a PSADT 4 Package — A 7-Zip Walkthrough

A complete walkthrough of building a PSADT 4 package from scratch, using 7-Zip as the example — from source acquisition and MSI inspection through wrapper authoring, local testing, code signing, and handoff to ConfigMgr.

2026-04-20 22 min read
SCCM / ConfigMgr

Operating System Deployment in SCCM — Foundations and Deployment Methods

A practical overview of Operating System Deployment in Configuration Manager — building blocks, the four deployment scenarios, task sequence anatomy, and log-driven troubleshooting. Not limited to bare metal.

2026-04-20 20 min read
SCCM / ConfigMgr

PSADT 4 Application Deployment in ConfigMgr

From PSADT 4 package to ConfigMgr Application — folder layout, deployment types, detection methods, install and uninstall commands, user experience settings, and log-driven verification. Focused on the ConfigMgr integration.

2026-04-20 19 min read
SCCM / ConfigMgr

Client Push Installation in SCCM — Setup, Flow, and Troubleshooting

A complete guide to SCCM Client Push: prerequisites, configuration, the three installation phases, log-driven troubleshooting, and why HTTPS-enabled environments frequently break at the certificate template.

2026-04-17 18 min read
SCCM / ConfigMgr

Building an SCCM Lab on Windows Server 2025

A step-by-step guide to a fully working SCCM lab on Windows Server 2025 — Domain Controller, SQL Server 2022, and Primary Site Server, with verified PowerShell scripts and the usual pitfalls.

2026-04-16 14 min read