A collection of scripts, templates, and tools for managing Windows endpoints at scale — covering Azure Virtual Desktop image builds, session host lifecycle, and day-to-day operational tasks.
avd/
├── bicep/ # Bicep templates for AVD session host deployment
│ ├── modules/ # Reusable modules (session hosts, image templates)
│ └── main-*.bicep
├── customizer/ # AIB / Packer customizer scripts (image-bake)
│ └── ConfigurationFiles/ # Bundled VDOT JSON (no runtime download required)
├── pipelines/ # Azure DevOps YAML pipelines
└── scripts/ # PowerShell scripts used by pipelines
devops/
└── aib-task-v2/ # Azure Image Builder DevOps task (v2)
intune/
├── bitlocker/ # BitLocker detection & remediation scripts for Intune
├── client-health/ # Single ConfigMgr baseline discovery for major Intune client issues
├── mdm-enrollment/ # Repair expired Intune MDM device cert (omadmclient high-CPU)
├── mdm-sync-service/ # Local MDM diagnostics, disabled-service repair, one-time sync and IME logs
└── onedrive-photos/ # Detect and remove shortcuts targeting OneDrive.App.exe
macos/
└── servicing/ # Developer-storage cleanup and reclaim helpers for macOS
tools/ # Standalone PowerShell/WPF utilities
windows/
├── applications/ # Generic MSI uninstaller by name pattern / publisher / GUID
├── configuration/ # Startup-app delay, Modern Standby power plans, processor boost settings
├── diagnostics/ # Read-only endpoint diagnostics — Location policy state, Defender/EDR coexistence, Delivery Optimization stats, power/standby evidence, audio artifact investigation, Microsoft service endpoint connectivity / proxy detection
├── dot3svc/ # Wired AutoConfig (dot3svc) migration reset
├── migration/ # Hybrid Join → Entra-only join in-place migration (EntraCutover)
├── print/ # Windows Protected Print (WPP) readiness — flag third-party v3/v4 drivers
├── rdp/ # Per-user RDP file signing (no admin required)
├── security/ # Hardware speculation mitigations, Secure Boot remediation
├── servicing/ # Pre-upgrade disk-space cleanup, WinRE partition resize, ESP free-space reporter
└── w365/ # Windows 365 Cloud PC utilities (disk resize, keyboard layout)
| Tool | Description |
|---|---|
| ADMXPolicyComparer | Compare ADMX policy baselines across Windows versions |
| AIBLogMonitor | Azure Image Builder log monitor |
| AvdAssessor | AVD environment assessment |
| AvdRewind | AVD session host rollback |
| AzChangeTracker | Azure resource change tracking |
| BaselineAssessor | Windows security baseline assessment (263 checks) |
| DeviceDecommissioner | Remove a device from AD, Entra ID, Intune, Autopilot, and SCCM in one guided workflow — pre-flight cards, BitLocker/LAPS warnings, dry-run, audit trail |
| PolicyPilot | Group Policy & MDM documentation — scans AD/Local/Intune, conflict detection, ADMX/CSP enrichment |
| W365Assessor | Windows 365 (Cloud PC) Enterprise & Frontline tenant assessment — 128 checks, 23 automated via Microsoft Graph |
| WinGetManifestManager | WinGet package manifest manager for private repos |
| Area | Description |
|---|---|
| avd/customizer/ | AIB / Packer image-bake customizers — AdminSysPrep, DisableAutoUpdates, InstallLanguagePacks, RemoveAppxPackages, RemoveUserApps, ResetAutoUpdateSettings, TimezoneRedirection, UpdateWinGet, WindowsOptimization (VDOT wrapper, JSON bundled in-repo) |
| avd/scripts/ | AVD pipeline helpers — host-pool drain, deployment telemetry, FSLogix repair, Get-StubAppPayloads / Install-AppxPayloads, hybrid activator, Remove-AvdHosts |
| avd/pipelines/ | Azure DevOps YAML pipelines for AVD activation, host-pool updates, image bakes |
| avd/bicep/ | Bicep templates for AVD session-host deployment (Entra ID + AD-joined variants) |
| intune/bitlocker/ | Intune Proactive Remediation pair — ensure BitLocker recovery key escrow to Entra ID; MBAM client uninstall |
| intune/client-health/ | Discover-IntuneClientMajorIssues.ps1 — self-contained ConfigMgr Compliance Baseline discovery for major service, enrollment, certificate and task faults. One String-equals-Passed rule; stopped services and routine log errors do not cause noncompliance. Includes WPN/IME checks and detailed local evidence; no sync or repair |
| intune/mdm-enrollment/ | Repair-IntuneMdmCert.ps1 — audit (read-only) or repair hosts whose expired Intune MDM device cert wedges omadmclient.exe at high CPU. Repair tears down the enrollment + re-enrolls via device credential. Built for cloned AVD fleets that expire together |
| intune/mdm-sync-service/ | Three standalone scripts: disabled dmwappushservice detection, startup repair plus one enrollment-specific PushLaunch request, and local MDM diagnostics with opt-in sync. Bounded task observation, JSON/object output and per-script IME logs. PowerShell 5.1/7; no Graph authentication or automatic re-enrollment |
| intune/onedrive-photos/ | Detection/remediation pair to remove Start Menu and Desktop shortcuts targeting OneDrive.App.exe. Shortcut-only cleanup; leaves the OneDrive client installed. Supports remediation preview with -WhatIf |
| macos/servicing/ | macos_dev_cleanup.sh — semi-interactive developer-storage cleanup (Xcode, VS Code/Cursor/Windsurf, .NET, Gradle, Android, Flutter, JetBrains, Homebrew, Docker, Time Machine) |
| windows/applications/ | Uninstall-MsiProduct.ps1 — generic MSI uninstaller by DisplayName / Publisher / Version / ProductCode wildcards. Registry-driven (no Win32_Product side effects); built for vendor agents whose GUID changes per release (e.g. Quest / KACE Agent) |
| windows/configuration/ | Startup-app delay and Modern Standby power-plan configuration. Configure-ProcessorBoost.ps1 queries the active plan by default; -Disable, -Enable, or -Configure 0-6 sets processor boost for both AC and battery power. Changes require elevation. |
| windows/diagnostics/ | LocationPolicyState/Get-LocationPolicyState.ps1 — report the effective Windows Location policy state and every author that can force/lock the toggle. MdeCoexistenceState/Get-MdeCoexistenceState.ps1 — effective Defender AV / Defender for Endpoint state, detection of third-party AV/EDR sharing the endpoint (minifilters by altitude band, services, Security Center), sensor health from the SENSE log, and an automated exclusion-hygiene review that catches %USERPROFILE%-style rules that silently match nothing under LocalSystem. Read-only, JSON output, Intune exit codes. DeliveryOptimizationStatistics/Get-DeliveryOptimizationStatistics.ps1 — local Delivery Optimization configuration, month-to-date traffic split by source (direct CDN, Connected Cache, LAN / Group / Internet / Link-Local peers), bandwidth-savings and P2P efficiency, cache size, peer count and active jobs. Reads the root/Microsoft/Windows/DeliveryOptimization CIM provider directly to recover MonthlyGroupBytes and MonthlyLinkLocalBytes, which the in-box PowerShell wrapper silently drops, and derives direct-CDN bytes before applying the mutually exclusive WUfB source formulas. Read-only; console table, PSCustomObject, or single-line JSON for Grafana / Loki / Telegraf ingestion. PowerEvidence/Get-PowerEvidence.ps1 — one-pass power / standby / screen-on evidence collector (powercfg /a, battery report, SleepStudy, System Power, wake diagnostics, Kernel power/boot events, Fast Startup / Hibernate config) that auto-zips a bundle for return. Runs unelevated; elevation adds SleepStudy / System Power / active requests. AudioArtifactHunter/ — evidence-collection suite for intermittent audio artifacts (unexpected loud transients, self-changing volume, mute that will not stick). Separates signal-level from gain-level causes by running a rolling WASAPI loopback capture (peak/true-RMS levels, discontinuity flags, auto-trigger + user-dropped incident markers) alongside a no-audio endpoint-state monitor (volume scalar, mute, device identity, per-app sessions). Adds a controlled stimulus runner with a silent-toast control case, an audio-stack inventory with baseline diff, EVTX/ZIP retention profiling and incident correlation, a run-review pass that ranks incident candidates so an unattended capture can be triaged without listening to it, and a reversible notification-sound silencer. Loopback capture is privacy-gated behind a mandatory acknowledgement. WindowsServiceEndpoints/Test-WindowsServiceEndpoints.ps1 — connectivity check for the Microsoft endpoints Windows 11 services depend on (Windows Update, Delivery Optimization, Store, Defender, certificate trust, activation, diagnostics, NCSI, WNS, Edge update): DNS, direct TCP, HTTP and TLS through the proxy Windows would use. Detects a proxy in the middle — explicit/PAC/WPAD proxy, TLS inspection (chain root), proxy headers, 407, refused tunnels, block pages served as HTTP 200, redirects to proxy portals, Microsoft-signed trust-list integrity over plain HTTP, Zscaler path and steering agents. Colour-coded report, CSV export, exit codes 0/1/2. Read-only |
| windows/dot3svc/ | Reset 802.1X / wired-AutoConfig profiles after migration |
| windows/migration/ | EntraCutover — experimental, not supported by Microsoft. In-place Hybrid Join → Entra-only join migration (no reinstall). Resumable 5-phase state machine (Assess/Prepare/Teardown/Join/Finalize), Intune enrollment + stale-GPO cleanup, fresh-profile + OneDrive KFM, BitLocker re-escrow to the new device object, break-glass admin + djoin offline-rejoin rollback. CLI, CMTrace logging |
| windows/print/ | Get-PrintDriverWppReadiness.ps1 — flag machines with third-party v3/v4 print drivers (not yet Windows Protected Print ready) ahead of WPP enforcement. Intune Proactive Remediation detection script (exit 0/1) + standalone CSV/JSON fleet inventory; maps drivers to printers actually using them. Read-only |
| windows/rdp/ | Sign .rdp files in user context (no admin required) |
| windows/diagnostics/NtlmUsageDetection/ | Read-only NTLM usage evidence detector for Ivanti: four-line output, collection diagnostics, optional JSON and offline tests |
| windows/security/ | Hardware speculation mitigations + Secure Boot UEFI CA 2023 remediation (Intune PR pair) |
| windows/servicing/ | Invoke-PreUpgradeCleanup.ps1 — reclaim disk space via cleanmgr + DISM before a feature update or after image bake. Resize-RecoveryPartition.ps1 — resize the WinRE recovery partition (KB5034441 / CVE-2024-20666 remediation). Get-EspPartitionStatus.ps1 — EFI System Partition size/free reporter as JSON for Grafana/Loki/Telegraf (KB5089549 / 0x800f0922 monitoring) |
| windows/w365/ | Windows 365 Cloud PC utilities — disk resize, keyboard layout configuration |
Most pipeline files use <YOURVALUE> placeholders — search for <YOUR and replace with your environment-specific values before use.
- PowerShell 5.1+
- Azure CLI / Az PowerShell modules (for AVD scripts and pipelines)
- Windows 11 (for WPF-based tools)
MIT