Learn / Labs / Tools

Windows Operations

Windows Server and workstation operations, patching, baselines, build evidence, servicing, recovery, configuration, and troubleshooting.

4 guides0 labs11 tools2 capability mapsBrowse all topic paths

Capability Maps

How this path becomes useful work

Windows Patch Readiness and Maintenance Evidence

Know whether Windows servers are ready for patching and prove what changed after maintenance.

Free boundary
Read-only readiness checks, reboot detection, servicing evidence, and local reports for one environment.
Paid value later
Pre/post comparison, multi-host reporting, exception tracking, maintenance summaries, and reusable evidence packs.

Endpoint Management and SCCM-Style Reporting

Give endpoint and server owners useful compliance, inventory, deployment, and client-health reports without drowning them in raw console exports.

Free boundary
Read-only inventory and compliance starters, report design guidance, and small CSV/HTML outputs.
Paid value later
High-end report packs, query libraries, dashboards, deployment health summaries, and packaged documentation.
01

Learn

Understand Windows Operations

Technical guides that explain the concepts, architecture, decisions, and durable operator patterns.

02

Labs

Practice Windows Operations

Hands-on labs that turn the concepts into working systems and repeatable environments.

A hands-on lab has not been assigned to this path yet.

03

Tools

Operate Windows Operations

Free operator tools for checks, scripts, evidence, reporting, and practical infrastructure work.

Authenticated Users drive ACL scannerPowerShell scanner that checks fixed local drives on Windows servers for root ACL entries where Authenticated Users have broad access. Produces console and CSV evidence so admins can review exposure before any ACL changes.ScriptSecurity and Exposure ChecksRead-onlyCertificate expiration scannerA read-only certificate inventory that finds local-machine store certificates nearing expiration and captures certificates presented by known TLS endpoints for review.ScriptSecurity and Exposure ChecksRead-onlyDisk space cleanup candidate reportA read-only disk-pressure report that captures low-space context and returns targeted cleanup candidates from known folders without deleting, compressing, or moving anything.ScriptWindows Server HealthRead-onlyIIS site and binding inventoryA read-only IIS inventory that correlates sites, bindings, ports, host headers, app-pool identities, content paths, and certificate thumbprints for migration or renewal work.ScriptWindows Server HealthRead-onlyPending reboot detection across Windows serversA read-only pending reboot check for Windows servers before patching, application installs, or maintenance-window closure.ScriptPatch and Reboot ReadinessRead-onlyScheduled task inventory and failure reportA read-only scheduled task inventory that highlights failed runs, missed runs, disabled tasks, and ownership gaps.ScriptWindows Server HealthRead-onlyWindows firewall rule auditA read-only Windows Firewall audit that records enabled allow rules, ports, profiles, and address scopes.ScriptSecurity and Exposure ChecksRead-onlyWindows server health snapshotA read-only Windows Server health snapshot that returns one compact row per host for uptime, disk pressure, memory headroom, stopped automatic services, and recent system errors.ScriptWindows Server HealthRead-onlyWindows Server update failure evidence-first runbookA Windows Server-specific observe, compare, repair, validate workflow for one server that fails a monthly update while a peer succeeds, with proxy, update-source, servicing, applicability, CBS/DISM, and before/after evidence.ChecklistPatch and Reboot ReadinessChanges system stateWindows Update readiness and repair evidence packA patch readiness and repair evidence pack for reboot state, servicing health, update logs, and approved repair actions.ChecklistPatch and Reboot ReadinessChanges system stateWindows Update Repair ChecksA staged Windows Update troubleshooting path that starts read-only and escalates only when needed.ChecklistPatchingReview before running