Topic Hub

Documents and Templates

Reusable documentation, reporting formats, handoff notes, worksheets, and evidence templates.

Use this hub as a cross-surface map: start with insights for this topic, then branch into supporting tools, drills, and implementation work as needed.

Related Items91
Best First StopInsights
How To Use This Hub
39 Insights39 Toolchest13 Labs

Start Here

Insights

Concepts, decision points, troubleshooting patterns, and operator-facing field notes.

Support Surface

Toolchest

Checklists, scripts, templates, and evidence packs you can use once the path is clear.

Support Surface

Labs

Hands-on build guides and validation environments for testing ideas end to end.

Insights

Insights that frame Documents and Templates

Insightschanges-system-state

Troubleshooting M365 Domain DNS Setup Issues

A Microsoft 365 domain DNS checklist for validating ownership, MX, Autodiscover, SPF, Teams/Skype records, propagation, and rollback before changing production mail flow.

Toolchest

Toolchest assets for Documents and Templates

ToolchestScriptActive Directory and IdentityRead-only

AD stale computer cleanup report

A read-only Active Directory stale computer report for last logon, OU, operating system, enabled state, and cleanup planning.

ToolchestScriptActive Directory and IdentityRead-only

All-DC lastLogon collector and stale-user evidence report

Collect non-replicated lastLogon values from every writable domain controller, calculate the newest observed logon per account, and export evidence suitable for stale-user or stale-computer cleanup decisions without relying on replicated lastLogonTimestamp alone.

ToolchestScriptSecurity and Exposure ChecksRead-only

Authenticated Users drive ACL scanner

PowerShell scanner that checks fixed local drives on Windows servers for root ACL entries where Authenticated Users have broad access. Produces console and CSV evidence so admins can review exposure before any ACL changes.

ToolchestTemplateHybrid Cloud OperationsRead-only

Azure Arc bulk onboarding CSV and logging starter

Reusable starter for Azure Arc onboarding waves using a host CSV, dry-run expectations, per-host logging, and repeatable result tracking suitable for tickets, change records, and post-wave reporting.

ToolchestChecklistHybrid Cloud OperationsRead-only

Azure Arc onboarding preflight checklist

Preflight checklist for onboarding Windows servers to Azure Arc. Confirms supported OS state, outbound connectivity, proxy/TLS behavior, local admin rights, target Azure placement, tagging, pilot scope, and rollback notes before any agent install.

ToolchestTemplateReporting and Evidence PacksRead-only

Azure Update Manager compliance workbook starter

Starter template for an Azure Workbook plus Resource Graph evidence pack that shows patch compliance, pending updates, unsupported coverage, and patch-group drift across Azure and Arc-enabled machines.

ToolchestTemplateHybrid Cloud OperationsRead-only

Azure Update Manager patch wave planning template

Operator-ready planning template for Azure Update Manager patch waves covering scope, maintenance windows, reboot tolerance, exclusions, soak periods, rollback contacts, and stop-go criteria before scheduled patching.

ToolchestTemplateBackup and RecoveryPlanning aid

Backup Restore Drill Evidence Checklist

A restore-drill evidence template for proving backups are usable, measuring recovery time, and turning failed assumptions into repair tasks before an outage.

ToolchestScriptSecurity and Exposure ChecksRead-only

Certificate expiration scanner

A read-only certificate inventory for finding expiring Windows certificate-store items and endpoint certificates before outages.

ToolchestScriptConnectivity and Network TriageRead-only

DHCP scope utilization report

A read-only DHCP scope report that surfaces high utilization, exhausted ranges, and cleanup candidates.

ToolchestScriptWindows Server HealthRead-only

Disk space cleanup candidate report

A read-only disk pressure report that finds likely cleanup candidates without deleting logs, caches, dumps, or user data.

ToolchestChecklistDNS and DHCPRead-only

DNS and DHCP Health Check

A diagnostic DNS and DHCP triage flow that captures evidence, follows decision branches, and explains what each result means before changing anything.

ToolchestScriptConnectivity and Network TriageRead-only

DNS resolution and reverse lookup audit

A read-only DNS audit that compares forward and reverse lookup results across host lists and expected DNS servers.

ToolchestScriptFile, Backup, and Storage OperationsRead-only

File share permission audit

A read-only file share audit that records SMB share permissions, NTFS access, and ownership evidence for review.

ToolchestRecommended toolFreeware Utilities Worth KeepingReview before running

Free network scanner and port inventory guide

A practical guide to free network scanning options for host discovery, port inventory, and safe scan scoping.

ToolchestTemplateReporting and Evidence PacksPlanning aid

HTML operations email reporting starter

Reusable template for infrastructure scripts that produce an HTML email report with summary tiles, per-host results, failure sections, runtime metadata, operator notes, and a plain log. Designed to give admins a repeatable evidence format for tickets, maintenance summaries, and validation drills without embedding unsafe credential handling.

ToolchestScriptWindows Server HealthRead-only

IIS site and binding inventory

A read-only IIS inventory for sites, app pools, bindings, host headers, ports, certificate thumbprints, and content paths.

ToolchestChecklistActive Directory and IdentityRead-only

Inactive AD user disable review workflow

Two-phase review checklist for identifying inactive AD user accounts, validating inactivity evidence, applying exclusions, capturing approval, and preparing rollback details before any disable action.

ToolchestTemplateOperations TemplatesPlanning aid

Incident Note Template

A compact operator note format for capturing symptoms, checks, decisions, and follow-up while the issue is fresh.

ToolchestChecklistApplication HostingRead-only

Internal IIS site rollout checklist

Operator checklist for launching an internal IIS-hosted site with evidence capture for IIS role presence, site folder layout, bindings, app pool identity, DNS readiness, browser validation, and rollback notes.

ToolchestScriptConnectivity and Network TriageRead-only

PowerShell server connectivity quick check

A read-only connectivity triage script that separates DNS, ping, RDP, WinRM, and application-port failures before escalation.

ToolchestScriptInventoryRead-only

RADIUS and NPS server detection report

Read-only PowerShell reporting script pattern to identify likely Microsoft NPS or other RADIUS-capable Windows servers using multiple evidence sources: NPS service presence, NPAS role/feature state, IAS/NPS event log activity, UDP 1812/1813 listener evidence, and registry indicators. Designed for migration discovery, audit support, and authentication troubleshooting.

ToolchestChecklistRemote AccessRead-only

RDP Connectivity Checklist

A structured check for RDP failures before changing firewall rules, user rights, or server policy.

ToolchestScriptConnectivity and Network TriageRead-only

RDP failure triage script

A read-only RDP triage script pattern for DNS, TCP 3389, listener state, firewall evidence, sessions, and event logs.

ToolchestTemplateFile ServicesChanges system state

Robocopy Job Template

A safer starting point for repeatable Windows file copy jobs with logging and dry-run review.

ToolchestTemplateFile, Backup, and Storage OperationsChanges system state

Robocopy job template and log parser

A safer Robocopy job template with dry-run review, log capture, exit-code interpretation, and migration evidence.

ToolchestChecklistMigration and CutoverChanges system state

Robocopy migration cutover checklist and evidence pack

Operator checklist and evidence structure for file migration cutovers using Robocopy. Covers pre-copy checks, dry-run evidence, final sync readiness, exclusion review, validation samples, rollback details, and signoff artifacts suitable for tickets and change records.

ToolchestScriptActive Directory and IdentityRead-only

Service account usage finder

A read-only service account discovery pass for Windows services, scheduled tasks, and IIS application pools.

ToolchestRecommended toolFreeware Utilities Worth KeepingRead-only

Sysinternals first-response kit guide

A practical Sysinternals first-response map for process, file handle, startup, network, login, and registry symptoms.

ToolchestRecommended toolMonitoringPlanning aid

Uptime Kuma Monitoring Starter

A simple monitoring starter for internal services, homelab systems, and small-office status checks.

ToolchestScriptSecurity and Exposure ChecksRead-only

Windows firewall rule audit

A read-only Windows Firewall audit that records enabled allow rules, ports, profiles, and address scopes.

ToolchestScriptWindows Server HealthRead-only

Windows server health snapshot

A read-only Windows Server snapshot for uptime, disk pressure, memory, stopped automatic services, and recent critical events.

ToolchestChecklistPatchingChanges system state

Windows Update Repair Checks

A staged Windows Update troubleshooting path that starts read-only and escalates only when needed.

ToolchestRecommended toolConnectivity and Network TriageReview before running

Wireshark packet capture triage guide

A packet-capture triage guide for DNS, TLS, DHCP, SMB, RDP, retransmissions, and sensitive-data handling.

Labs

Labs and build work for Documents and Templates

LabsPowerShell and Admin AutomationReporting and AuditsIntermediate

Build a Safe File Server Permission Audit with PowerShell

Build a read-only PowerShell permission audit for Windows file shares, export remediation candidates, and preserve evidence for an access review without changing ACLs.

LabsStorage and BackupBackup PlatformsIntermediate

Family NAS Backup Plan with Snapshots and Offsite Sync

Create a family NAS backup plan with snapshot retention, offsite copy targets, restore notes, and a small proof restore so backup success is based on evidence instead of hope.