Tip: Switch Windows Server from BIOS to UEFI Boot and Secure Boot

Today I had the requirement to convert a Windows server from Legacy BIOS to UEFI with Secure Boot. It was a virtual machine on an ESXi 8 server. However, the method described should also work with other hypervisors and also with physically installed Windows servers. If in the BIOS of the server or in the ... Read more

Windows certification authority: Changing the validity of the revocation list

The validity of certificates can be checked either via OCSP (Online Certificate Status Protocol) or classically via a revocation list (CRL). The basic revocation list of a Microsoft Windows certification authority is valid for 7 days by default. In some cases, this is too long, as a certificate may still be valid after revocation. Read more

Implement Exchange Health Checker recommendations via script

The Exchange Health Checker is an excellent tool to get a quick overview of the status of the Exchange Server. The PowerShell script provided by Microsoft is continuously updated and can generate a report in HTML format. For a fresh Exchange 2019 installation on a Windows Server 2022, the report looks like this, for example: ... Read more

Secure Windows Server 2022 (hardening)

In this article you will find my settings for hardening Windows Server 2022. These settings can be used for the template for VMs. New VMs based on these settings therefore already have a certain level of security. In my opinion, the settings are not too restrictive and should therefore be suitable for most applications/services. Read more

Windows updates from January 2022 cause problems

The Windows updates that Microsoft released on 11.01.2022 are causing some problems on Windows servers. In the meantime, there are increasing reports that domain controllers keep restarting after January CU has been installed. Some other problems seem to increasingly affect Windows Server 2012 R2. After installing the update, Hyper-V no longer starts and ReFS formatted ... Read more

Windows Server 2022: Channel error 36871

Schannel error messages are common and can have many different causes. Here is a rather specific error message that occurred on a Windows Server 2022 after the operating system underwent standard hardening. After disabling outdated cipher suites and SSL / TLS protocols, the following error message appeared very frequently in the system event log: Source: Schannel ... Read more

Windows Server 2022 is available!

Microsoft has released Windows Server 2022. The successor to Windows Server 2019 has the build number "20348.169, Version 21H2" and is available in the Standard and Datacenter editions. An additional edition with the name "Windows Server 2022 Datacenter: Azure Edition" is only available on Microsoft Azure. There are no Essentials with Windows Server 2022 ... Read more