In this article, I look at how to choose between a Windows Active Directory (AD) domain or workgroup. A Windows workgroup distributes identity and administration across individual computers, while an Active Directory domain centralizes them. That means the real choice is not how the PCs are grouped, but whether your organization can safely continue managing…
For too many service desks, identity verification still relies on asking the caller questions that only the real employee should be able to answer. Unfortunately, security questions don’t stand up particularly well against modern attacker techniques. Employee IDs, dates of birth, manager names, job titles and office locations can often be found through social media,…
Managing Active Directory groups at scale involves much more than adding and removing users. Enterprise organizations often need policy-based automation, self-service, access reviews, approval workflows, delegated administration, and auditable controls. Native tools such as Active Directory Users and Computers, PowerShell, and Remote Server Administration Tools are still important. However, purpose-built products can provide a more…
Last Update: Sep 29, 2026
Quick answer. To disable BitLocker in Windows 11: Sometimes, suspending BitLocker may be a better option. Disabling BitLocker causes the drive to be fully decrypted, while suspension temporarily unlocks access to the encryption keys. Do you need to disable BitLocker or suspend BitLocker? Although disabling BitLocker is an option, it might not always be the…
According to Neil Costa, Founder and CEO of HireClix, the most important challenge facing recruitment may no longer be efficiency. It may be trust. I sat down recently with Neil and we discussed the future of IT hiring. Artificial intelligence is transforming recruitment at a remarkable pace. Candidates are using AI tools to find jobs,…
I’ve been helping organizations harden Microsoft Entra ID for the last 5 years and given multiple talks on finding holes in Conditional Access. This month, I did some research into Device Platforms, testing a misconfiguration I find in almost every tenant. In my testing, a sign-in with an unclassified platform fell outside every Conditional Access…
PowerShell Restart-Computer allows you to restart local and remote computers by using the Restart-Computer command. This cmdlet can be entered directly at the command prompt, or it can be included in a PowerShell script. It initiates an immediate restart. It is worth noting however, that in order to use this command to remotely shut down…
Service accounts rarely attract much attention until a password change, server migration, or security issue breaks a workload. That’s why it’s worth choosing the right identity from the get-go because your decision affects not only security, but also the ongoing management of the service. Service Account vs User Account If you’re deciding which identity to…
Organizations are rushing to deploy Microsoft 365 Copilot, but in doing so, many are discovering that their biggest challenge isn’t AI adoption but years of unmanaged SharePoint content, inactive sites, and excessive permissions. SharePoint Advanced Management aims to solve those issues before they become Copilot problems. What is SharePoint Advanced Management? SharePoint Advanced Management (SAM)…
The patch window is collapsing, and that means the old services model for patching is collapsing with it. What’s been missing from that news is how you’re supposed to change your service model to deal with this reality. For years, patching followed a familiar ritual: Patch Tuesday arrives, IT reviews the updates, a pilot group…