NAVANEM

Production-tested tutorials for IT admins

Step-by-step guides for sysadmins and infrastructure engineers, based on real deployments, with verification steps so you know the fix actually worked.

80guides

80 results

Illustration of Exchange Server OWA and ECP login pages protected by reCAPTCHA against automated brute force attacks.
medium5 steps · 6 min

Protect Exchange OWA from Brute Force Attacks with reCAPTCHA

Add Google reCAPTCHA v2 to Exchange OWA and ECP login pages to block brute force bots - free, no Azure AD Premium needed, works on Exchange 2013-2019.

jun 26, 2026 · start →
Illustration of an IT sysadmin migrating on-premises Exchange distribution groups to Exchange Online using PowerShell, with export, recreate, and finalization steps shown visually.
advanced8 steps · 6 min

Migrate Distribution Groups to Microsoft 365 with PowerShell

Migrate on-premises Exchange distribution groups to Microsoft 365 in 8 PowerShell steps - preserving members, owners, and moderation settings without downtime.

jun 26, 2026 · start →
Illustration of an IT sysadmin bulk-exporting OneDrive files for multiple Microsoft 365 users with PowerShell and Microsoft Graph, showing user accounts, folders, and automation flow.
medium4 steps · 6 min

Download OneDrive Files with PowerShell and Microsoft Graph

Bulk-export OneDrive files for multiple Microsoft 365 users using PowerShell and the Microsoft Graph API - no third-party tools required. Step-by-step for sysadmins.

jun 25, 2026 · start →
Illustration of Microsoft Intune controlling Windows Fast Startup through PowerShell scripts and registry edits across managed devices
medium5 steps · 6 min

Manage Windows Fast Startup via Intune: PowerShell Guide

Control Windows Fast Startup across your fleet by setting one registry DWORD via Intune PowerShell. Step-by-step guide for Windows 10/11 sysadmins.

jun 25, 2026 · start →
Illustration of a Group Policy Object blocking specific websites in Microsoft Edge across a Windows domain
medium6 steps · 5 min

GPO Block Websites in Microsoft Edge: Step-by-Step Guide

Block websites in Microsoft Edge via GPO across your Windows domain in under 30 minutes - no third-party tools needed. Full step-by-step guide with ADMX setup.

jun 25, 2026 · start →
Illustration of Microsoft Entra Connect being moved from an old Windows Server to a new one using a safe staged handoff
advanced7 steps · 6 min

Microsoft Entra Connect Migration: Move to a New Server

Move Microsoft Entra Connect V2 to Windows Server 2016, 2019, or 2022 in 7 steps - export config, enable TLS 1.2, and verify sync without downtime.

jun 25, 2026 · start →
Illustration of Microsoft Intune using a PowerShell script to set the Windows 11 taskbar left-aligned across managed devices
easy4 steps · 5 min

Align Windows 11 Taskbar Left via Intune: Step-by-Step

Use a 3-line PowerShell script in Microsoft Intune to enforce left-aligned taskbar on Windows 11 22H2+ - no GPO or third-party tools needed across your fleet.

jun 24, 2026 · start →
Illustration of Chrome ADMX templates imported into Intune to keep Google Chrome updated across managed Windows devices
medium6 steps · 6 min

Enforce Chrome Auto-Updates via Intune: Step-by-Step

Import Chrome ADMX templates into Intune and enforce auto-updates on Windows 10/11 devices in under 15 minutes. Works across all Intune-enrolled machines.

jun 24, 2026 · start →
Illustration of Exchange Server outbound mail flow being configured with a send connector through EAC and PowerShell
medium6 steps · 5 min

Exchange Server Send Connector: EAC + PowerShell Setup

Exchange Server send connector missing by default. Configure outbound mail via EAC or PowerShell in under 15 minutes with this step-by-step guide.

jun 24, 2026 · start →
Illustration of Windows 11 driver signature enforcement being disabled through advanced boot, Group Policy, and command-line troubleshooting
medium4 steps · 6 min

Disable Driver Signature Enforcement in Windows 11: 4 Methods

Disable driver signature enforcement in Windows 11 via 4 methods tested on 22H2: Startup Settings (session-only), bcdedit, Group Policy, and Advanced Boot Options for fleet deployments.

jun 24, 2026 · start →
Illustration of WSReset.exe clearing Microsoft Store cache to fix download errors and crashes on Windows 10 and 11
easy5 steps · 5 min

WSReset.exe: Clear Microsoft Store Cache Step by Step

Run WSReset.exe on Windows 10 and 11 to clear the Microsoft Store cache and fix download errors in under 60 seconds - no restart needed.

jun 24, 2026 · start →
Illustration of Microsoft Intune Unattended Remote Help securely connecting an admin to Windows devices without user involvement
medium6 steps · 5 min

Intune Unattended Remote Help: Access Windows Devices Without User Interaction

Configure Intune Unattended Remote Help (GA July 2026, requires Intune Suite) to remotely access Windows devices with no end-user prompt. Full setup guide.

jun 23, 2026 · start →
Illustration of Microsoft Intune pushing a Settings Catalog policy that prevents WinRM from storing RunAs credentials on Windows devices
medium6 steps · 5 min

Disable WinRM Basic Authentication via Intune: Step-by-Step

Block plain-text credential exposure over WinRM with an Intune Settings Catalog policy. Applies to Windows 10 1709+ (build 16299) and later. Deploy in minutes.

jun 23, 2026 · start →
Illustration of a PDC Emulator syncing with an external NTP source while VM guest time synchronization is disabled and domain time stays accurate
medium9 steps · 6 min

Configure NTP Time Source on a Windows Domain Controller

Configure an external NTP source on your PDC Emulator to keep Kerberos clock skew under the 5-minute limit - with PowerShell commands and verification steps.

jun 23, 2026 · start →
Illustration of Intune and a PowerShell remediation script restricting Windows local logon so only the assigned user can sign in on each device and other credential reuse attempts are blocked
medium6 steps · 6 min

Intune Remediation: Lock Windows Logon to Current User

Use an Intune Remediation PowerShell script to restrict Allow logon locally to one assigned user, cutting lateral movement risk per CISA guidance. Setup takes under 30 minutes.

jun 22, 2026 · start →
Illustration of an admin using PowerShell and Microsoft Intune to deploy and centrally configure uBlock Origin Lite on many Windows browsers to block malvertising
medium6 steps · 6 min

Deploy uBlock Origin Lite via Intune: Enterprise Guide

Deploy uBlock Origin Lite across managed Windows devices with PowerShell and Intune, blocking malvertising at scale across Windows 10/11 in under 30 minutes.

jun 21, 2026 · start →
Illustration of an admin using PowerShell and Intune to push standardized Outlook classic default fonts to multiple Windows devices
medium6 steps · 6 min

PowerShell Intune Remediations: Set Outlook Default Font

Deploy a PowerShell Intune Remediations package that writes Outlook classic default font registry values to every targeted Windows device - no Group Policy needed.

jun 21, 2026 · start →
Diagram of a sysadmin exporting an Enterprise CA root certificate as a .cer file, creating a Trusted certificate profile in the Intune admin center with that .cer and targeting Windows devices so the CA is installed in their Trusted Root Certification Authorities store
medium5 steps · 6 min

Deploy a Trusted Root Certificate with Intune: Step-by-Step

Export your Enterprise CA root certificate and push it to Windows devices using an Intune Trusted Certificate profile. Full walkthrough for sysadmins.

jun 21, 2026 · start →
Illustration of an Intune admin using a Windows Settings Catalog profile to enable the Hide Update Notifications policy under Microsoft 365 Apps update settings and assign it to Windows devices so Office update prompts no longer appear to end users
easy6 steps · 5 min

Disable Office Update Notifications in Intune: Step-by-Step

Use Intune Settings Catalog to push the Hide Update Notifications policy to Windows 10/11 devices and silence Microsoft 365 update prompts in under 10 minutes.

jun 21, 2026 · start →
Diagram of the Microsoft Intune admin center showing an admin creating scope tags, linking them to RBAC role assignments for specific admin groups, and using those scope tags to restrict which devices, apps and policies are visible to admins based on department or region
medium6 steps · 6 min

Intune Scope Tags: Step-by-Step Setup for Sysadmins

Learn how to create Intune scope tags in 6 steps, assign them to RBAC roles, and isolate admin visibility by department or region in Microsoft Intune.

jun 21, 2026 · start →
show