<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Evan Ireland</title>
        <description>Windows, Microsoft 365, Intune, home lab builds, and documentation.</description>
        <link>https://evanireland.tech/</link>
        <atom:link href="https://evanireland.tech/feed.xml" rel="self" type="application/rss+xml"/>
        <pubDate>Thu, 01 Oct 2026 16:13:01 -0600</pubDate>
        <lastBuildDate>Thu, 01 Oct 2026 16:13:01 -0600</lastBuildDate>
        <generator>Jekyll v4.4.1</generator>
        
            <item>
                <title>My New Work Laptop Was Not Quite What It Said on the Box</title>
                <description>&lt;p&gt;Windows Autopilot device preparation is Microsoft’s newer way of setting up a work computer: you
unbox a Windows laptop, sign in with a work account, and the laptop configures itself - joins
the company’s identity system, enrolls in management, installs the company’s apps, turns on
encryption - without IT ever touching it. Microsoft’s documentation calls it “Autopilot device
preparation”; most of the internet calls it “Autopilot v2.”&lt;/p&gt;

&lt;p&gt;Documentation at &lt;a href=&quot;https://learn.microsoft.com/autopilot/device-preparation/overview&quot;&gt;Microsoft Learn&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Cards on the table before we start: this is my own business laptop, and I
used it as a lab. I could have turned it on, clicked through setup, and started working in twenty
minutes. Instead I set it up exactly the way I would set one up for a client, so I would have done
it once for real before anyone pays me to do it. That took two evenings instead of twenty minutes.
Worth it - and as you are about to see, the laptop made it worth it in ways I did not plan on originally.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;how-i-got-here&quot;&gt;How I got here&lt;/h2&gt;

&lt;p&gt;My own small-business tenant runs on Microsoft 365 Business Premium (with Copilot). That license includes Intune, which is Microsoft’s tool for managing company devices, and Entra ID, which is the identity system behind
every Microsoft 365 sign-in. I built the tenant a week earlier. What it did not have yet was a
single managed device in it - which is a strange state of affairs for someone who wants a job managing other people’s devices.&lt;/p&gt;

&lt;p&gt;So the new laptop had a job before it ever opened a spreadsheet: be the first managed endpoint,
built the client way, documented well enough to hand to the next person.&lt;/p&gt;

&lt;p&gt;The goals, in plain terms:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Join it to the business with &lt;strong&gt;Microsoft Entra join&lt;/strong&gt; - the cloud-only kind, no server in a
closet.&lt;/li&gt;
  &lt;li&gt;Have it set itself up with &lt;strong&gt;Autopilot device preparation&lt;/strong&gt;.&lt;/li&gt;
  &lt;li&gt;Strip out the consumer bloatware &lt;strong&gt;without&lt;/strong&gt; losing Copilot, which I am paying for.&lt;/li&gt;
  &lt;li&gt;Make sure I am &lt;strong&gt;not&lt;/strong&gt; an administrator on my own daily laptop, and prove that the emergency
admin account (Windows LAPS) works end to end - something my old homelab never quite achieved.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Real enthralling stuff I know. Let’s get into it, shall we?&lt;/p&gt;

&lt;h2 id=&quot;three-ways-to-join-a-windows-pc-explained-with-an-office-building&quot;&gt;Three ways to join a Windows PC, explained with an office building&lt;/h2&gt;

&lt;p&gt;If you have ever worked in an office, you have seen all three of these, you just did not know it.&lt;/p&gt;

&lt;p&gt;Picture the old way first. Your company owns the building. There is a front desk in the lobby,
and every computer in the building has to check in with that desk to let anyone sign in. That
front desk is a domain controller, and joining a computer to it is a &lt;strong&gt;domain join&lt;/strong&gt;. It works
beautifully - as long as you are inside the building. Take the laptop home and it is trying to
check in with a front desk it cannot see.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hybrid join&lt;/strong&gt; is what happens when that company also signs up for a cloud office. Now your
laptop has a badge for the building &lt;em&gt;and&lt;/em&gt; a badge for the cloud, and the two front desks keep
copying notes to each other. I built exactly that in my homelab. It works, and it is a lot of
moving parts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Entra join&lt;/strong&gt; gets rid of the building. There is no lobby and no front desk on site.
Your badge is issued by the cloud, checked by the cloud, and works the same at the office, at home,
or in a hotel. For a one-person business with no server room, it is the only one of the three
that makes any sense (I mean, for now anyways. I am someone who recreationally builds server clusters in their basement after all…).&lt;/p&gt;

&lt;p&gt;Simply put: domain join trusts a building, Entra join trusts the company.&lt;/p&gt;

&lt;p&gt;Back to the laptop…&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;the-prep-work-happens-before-the-laptop-is-ever-turned-on&quot;&gt;The prep work happens before the laptop is ever turned on&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;A note on names: real device and account names are swapped for placeholders below (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;ORG&amp;gt;&lt;/code&gt; is the business prefix), and identifiers in the screenshots are blacked out.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Most of this build happened in a web browser before the laptop came out of the box. Autopilot
device preparation needs the tenant ready for it, and the tenant preparation is the part that
transfers to every client.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Step&lt;/th&gt;
      &lt;th&gt;What was configured&lt;/th&gt;
      &lt;th&gt;Why&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;Entra device settings&lt;/td&gt;
      &lt;td&gt;Users may join devices; Entra LAPS &lt;strong&gt;on&lt;/strong&gt;; “registering user is local admin” &lt;strong&gt;None&lt;/strong&gt;; “Global administrator role is added as local administrator” &lt;strong&gt;No&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;The last one is the setting that stops the daily-driver account becoming an administrator on every device it joins&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Automatic enrollment&lt;/td&gt;
      &lt;td&gt;MDM user scope set&lt;/td&gt;
      &lt;td&gt;This is what turns “joined to Entra” into “managed by Intune”&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Two security groups&lt;/td&gt;
      &lt;td&gt;A &lt;strong&gt;user&lt;/strong&gt; group (who the setup policy targets) and a &lt;strong&gt;device&lt;/strong&gt; group (where new laptops land)&lt;/td&gt;
      &lt;td&gt;The device group is owned by Intune’s own provisioning service, so Intune can drop a new laptop into it mid-setup&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Required apps&lt;/td&gt;
      &lt;td&gt;Company Portal and Microsoft 365 Apps, to the device group&lt;/td&gt;
      &lt;td&gt;Only what has to exist before first sign-in&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Platform script&lt;/td&gt;
      &lt;td&gt;A logged, exact-name removal script for consumer apps, Copilot explicitly protected&lt;/td&gt;
      &lt;td&gt;Debloat as code, not a click-through tool&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Security policies&lt;/td&gt;
      &lt;td&gt;BitLocker (XTS-AES 256, key escrowed to Entra) and Windows LAPS (managed account &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;org&amp;gt;-lapsadmin&lt;/code&gt;, passphrase, reset 24 hours after use)&lt;/td&gt;
      &lt;td&gt;The laptop arrives encrypted with an emergency admin account already in place&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Setup policy&lt;/td&gt;
      &lt;td&gt;User-driven, Entra joined, &lt;strong&gt;standard user&lt;/strong&gt;, name template &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;ORG&amp;gt;-%SERIAL%&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;The policy that ties everything together&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/entra-device-settings.png&quot; alt=&quot;Entra local administrator settings with the Global administrator role toggle set to No and registering user set to None&quot; /&gt;
&lt;em&gt;Entra device settings - the Global Administrator role is not added as a local administrator, and Entra LAPS is on&lt;/em&gt;
&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/apdp-policy.png&quot; alt=&quot;Autopilot device preparation policy configuration showing user-driven, single user, Entra joined, standard user&quot; /&gt;
&lt;em&gt;The device preparation policy (support message, device name template and script name blacked out)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;One snag surfaced immediately. The device group has to be owned by a Microsoft service called the
&lt;strong&gt;Intune Provisioning Client&lt;/strong&gt;, and in a brand-new tenant that service did not exist yet. It was
created with one PowerShell command (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;New-MgServicePrincipal&lt;/code&gt; with Microsoft’s App ID), then added
as the owner. Every new client tenant will need the same step, which is exactly the kind of thing
I wanted to find on my own tenant first.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/provisioning-client-sp.png&quot; alt=&quot;PowerShell output of New-MgServicePrincipal creating the Intune Provisioning Client&quot; /&gt;
&lt;em&gt;Creating the missing service principal with Microsoft Graph PowerShell (object ID blacked out)&lt;/em&gt;&lt;/p&gt;

&lt;h3 id=&quot;why-not-a-pre-built-bloat-tool&quot;&gt;Why not a pre-built bloat tool&lt;/h3&gt;

&lt;p&gt;I have used the Chris Titus Tech utility on personal machines and I like it. On a managed business
device it is the wrong tool. Its tweaks change services and settings that the management platform
is also trying to control, and none of it is repeatable or auditable across ten clients. The skill
worth practicing is removing apps &lt;em&gt;through&lt;/em&gt; the management platform, so the same script runs the
same way on every device and leaves a log behind.&lt;/p&gt;

&lt;p&gt;Honest performance note, because someone will ask: on a Ryzen 7 with 32 GB of RAM, removing
Solitaire buys you approximately nothing you can measure. The real gain from this build is a clean
Windows install with no reseller software on it. Which brings us to the reseller.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;the-laptop&quot;&gt;The laptop&lt;/h2&gt;

&lt;p&gt;inb4: Do NOT automatically trust a PC you bought on Amazon just because you bought it on Amazon - especially if it’s not SOLD by Amazon. You can definitely see where this is going.&lt;/p&gt;

&lt;p&gt;Before wiping anything, the laptop was checked. A read-only PowerShell script was run from a USB
stick at the very first setup screen, offline, to record what the seller had actually shipped
before that evidence was erased by a clean install. Lenovo’s own warranty site was checked by
serial number at the same time.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Check&lt;/th&gt;
      &lt;th&gt;Expected from the listing&lt;/th&gt;
      &lt;th&gt;Found&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;Warranty&lt;/td&gt;
      &lt;td&gt;On-site, full term&lt;/td&gt;
      &lt;td&gt;&lt;strong&gt;Depot&lt;/strong&gt;, under six months left, registered ship-to location &lt;strong&gt;India&lt;/strong&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Windows license in firmware&lt;/td&gt;
      &lt;td&gt;A Pro key embedded by Lenovo&lt;/td&gt;
      &lt;td&gt;&lt;strong&gt;None&lt;/strong&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Windows activation&lt;/td&gt;
      &lt;td&gt;Retail or OEM Pro&lt;/td&gt;
      &lt;td&gt;&lt;strong&gt;Volume license (MAK) key&lt;/strong&gt; - a key issued to an organization, on a laptop sold to an individual&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Memory&lt;/td&gt;
      &lt;td&gt;32 GB as a matched pair&lt;/td&gt;
      &lt;td&gt;&lt;strong&gt;One&lt;/strong&gt; 32 GB stick from an unidentified manufacturer - so the memory runs single-channel&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Secure Boot&lt;/td&gt;
      &lt;td&gt;On&lt;/td&gt;
      &lt;td&gt;&lt;strong&gt;Off&lt;/strong&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Activation hacks / reseller software&lt;/td&gt;
      &lt;td&gt;None&lt;/td&gt;
      &lt;td&gt;None found&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/warranty.png&quot; alt=&quot;Lenovo warranty page showing depot support, under six months remaining and a ship-to location of India&quot; /&gt;
&lt;em&gt;Lenovo’s records: depot warranty ending March 2027, ship-to location India (serial, model suffix and QR code blacked out)&lt;/em&gt;
&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/bios-as-received.jpg&quot; alt=&quot;ThinkPad BIOS main page showing UEFI Secure Boot set to Off&quot; /&gt;
&lt;em&gt;The BIOS as received - Secure Boot off (serials, UUID and MAC address blacked out)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Nothing malicious turned up. That is not the same as clean, and a business laptop gets treated as
untrusted until it is proven otherwise.&lt;/p&gt;

&lt;p&gt;The part worth explaining is the license, because it fooled Windows itself. The installed copy
said “Licensed (activated).” Activated is not licensed. A volume key belongs to whatever
organization bought it; it does not legitimately ride along on a single laptop sold on Amazon. And
the Microsoft 365 Business Premium subscription does not fix that: its Windows rights are an
&lt;strong&gt;upgrade on top of&lt;/strong&gt; a legitimate Windows Pro license, not a license on their own.&lt;/p&gt;

&lt;p&gt;I had a choice: return it, or keep the hardware and fix everything else. With memory prices where
they are in 2026, I kept it. The decision was to scrub it, reinstall from Microsoft’s own media,
buy a retail Windows 11 Pro key, and replace the memory.&lt;/p&gt;

&lt;p&gt;I’m far too lazy to try and return something I bought online, so onwards we continue.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;scrub-wipe-reinstall&quot;&gt;Scrub, wipe, reinstall&lt;/h2&gt;

&lt;p&gt;The firmware was reset before anything else, in this order:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;The TPM security chip was cleared, removing any keys left by the previous builder.&lt;/li&gt;
  &lt;li&gt;BIOS defaults were loaded, then Secure Boot and AMD virtualization were turned back on.&lt;/li&gt;
  &lt;li&gt;A supervisor password was set - stored in the password manager first, because Lenovo
supervisor passwords cannot be recovered.&lt;/li&gt;
  &lt;li&gt;The SSD was erased with the BIOS Secure Wipe, which would not run without that supervisor
password.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The erase method was a single pass of zeros. I was tempted by the DoD multi-pass option, because
it sounds the most thorough. It is the wrong tool for an SSD: multi-pass overwriting was designed
for spinning disks, and an SSD’s controller remaps writes across its flash cells, so extra passes
add wear without reaching anything more. The drive’s own erase is the correct method.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/secure-wipe.jpg&quot; alt=&quot;Lenovo Secure Wipe confirming a single pass of zeros completed&quot; /&gt;
&lt;em&gt;Lenovo Secure Wipe complete - single pass of zeros&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Windows 11 Pro was then installed clean from Microsoft’s Media Creation Tool, and the laptop was
left sitting at the first setup screen.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;device-association-and-an-unplanned-trip-upstairs&quot;&gt;Device association, and an unplanned trip upstairs&lt;/h2&gt;

&lt;p&gt;Autopilot device preparation launched without the step the original Autopilot depended on - a
hardware ID registered by the manufacturer or reseller at purchase. A laptop bought from a
third-party seller never gets that registration. In August 2026 Microsoft added &lt;strong&gt;device
association&lt;/strong&gt;, which closes most of that gap: at the first setup screen, the laptop proves its
identity with its TPM chip and stores a marker for the company’s tenant in its firmware. That
marker is what lets the company name the device, mark it as corporate-owned, and skip most of
the setup screens.&lt;/p&gt;

&lt;p&gt;The mechanics:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;At the region screen, the Windows key was pressed five times to open the Autopilot menu.&lt;/li&gt;
  &lt;li&gt;The device information was exported to the USB stick as a CSV file.&lt;/li&gt;
  &lt;li&gt;The CSV was uploaded in Intune under Device association, and the setup policy was attached to
it.&lt;/li&gt;
  &lt;li&gt;Back on the laptop, association was completed.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The feature was one month old, so a rough edge was expected. The one that appeared: &lt;strong&gt;on Wi-Fi,
the association option refused to continue until the laptop was on Ethernet.&lt;/strong&gt; My workbench is in
the basement and the wired drop is not.&lt;/p&gt;

&lt;p&gt;Once again, I’m secretly lazy so carrying two laptops up two flights of stairs at 10:00 PM was not on my bingo card for the evening. However, I also wanted this to work so I gritted my teeth and headed upstairs to my router. I always keep a cable plugged into my managed switch so I can easily connect a laptop for circumstances like this but ya know…it’s like…all the way upstairs…&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/autopilot-menu.jpg&quot; alt=&quot;Windows setup screen offering Assign device association among its options&quot; /&gt;
&lt;em&gt;The Autopilot menu, reached with the Windows key pressed five times at the region screen&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Once wired, association completed at 22:09.&lt;/p&gt;

&lt;h2 id=&quot;nine-minutes&quot;&gt;Nine minutes&lt;/h2&gt;

&lt;p&gt;At 22:14 I signed in with my work account. The region, keyboard, license, privacy and “personal or
work?” screens never appeared - device association skipped them, as designed. The laptop showed a
percentage while it joined Entra, enrolled in Intune, landed in the device group, installed Company
Portal and Microsoft 365 Apps, and ran the removal script.&lt;/p&gt;

&lt;p&gt;At 22:23 I was at a desktop. The laptop had named itself &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;ORG&amp;gt;-XXXXXXXX&lt;/code&gt; from the template, was
marked corporate-owned in Intune, and had a managed local admin account waiting.&lt;/p&gt;

&lt;p&gt;Windows Hello was set up with a PIN only. I do not use fingerprint or face sign-in on anything, and
nothing about this build changes that.&lt;/p&gt;

&lt;p&gt;Then I went to bed. I learned on previous projects that pushing through tired is when I start
skipping steps and stop actually learning anything.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;the-green-checkmarks-lied-typical&quot;&gt;The green checkmarks lied (typical)&lt;/h2&gt;

&lt;p&gt;The next morning the BitLocker status was checked from the laptop itself rather than from the
Intune portal. The drive was encrypted with &lt;strong&gt;XTS-AES 128&lt;/strong&gt;. The policy said &lt;strong&gt;XTS-AES 256&lt;/strong&gt;. Intune
reported every BitLocker setting as “Succeeded.”&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/bitlocker-succeeded.png&quot; alt=&quot;Intune BitLocker policy settings report with every setting showing Succeeded&quot; /&gt;
&lt;em&gt;Intune reports every BitLocker setting as Succeeded (device and policy names blacked out)&lt;/em&gt;
&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/xts-aes-128.png&quot; alt=&quot;manage-bde output showing encryption method XTS-AES 128&quot; /&gt;
&lt;em&gt;The device itself says XTS-AES 128 (account name blacked out)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Diagnosis.&lt;/strong&gt; The policy values in the laptop’s registry were correct - the 256-bit setting had
arrived. The drive had simply been encrypted before it arrived: Windows automatic device
encryption started during setup, at its 128-bit default, and a cipher-strength setting does not
re-encrypt a drive that is already encrypted. “Succeeded” in Intune means the setting was
delivered. It does not mean the disk matches it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;First attempt - failed.&lt;/strong&gt; The drive was decrypted so the policy could re-encrypt it at 256-bit.
It never did. After fifteen minutes and two scheduled tasks meant to nudge it, the drive sat at
“Fully Decrypted, 0.0%.” The policy had already been processed on this device, and Intune has no
equivalent of on-premises Group Policy’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpupdate /force&lt;/code&gt; to replay it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Resolution.&lt;/strong&gt; The drive was encrypted by hand at the correct strength, and the new recovery key
was uploaded to Entra:&lt;/p&gt;

&lt;div class=&quot;language-powershell highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;n&quot;&gt;manage-bde&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-on&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;C:&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-UsedSpaceOnly&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-EncryptionMethod&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;xts_aes256&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-RecoveryPassword&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-SkipHardwareTest&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$rp&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;Get-BitLockerVolume&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-MountPoint&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;C:&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;KeyProtector&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;n&quot;&gt;Where-Object&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;KeyProtectorType&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;o&quot;&gt;-eq&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;&apos;RecoveryPassword&apos;&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;BackupToAAD-BitLockerKeyProtector&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-MountPoint&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;C:&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;-KeyProtectorId&lt;/span&gt;&lt;span class=&quot;w&quot;&gt; &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$rp&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nf&quot;&gt;KeyProtectorId&lt;/span&gt;&lt;span class=&quot;w&quot;&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Verified&lt;/strong&gt; with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;manage-bde -status C:&lt;/code&gt; (XTS-AES 256, protection on) and the new key showing in
Entra.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/re-encryption.png&quot; alt=&quot;manage-bde output showing encryption method XTS-AES 256 with protection on&quot; /&gt;
&lt;em&gt;After manual re-encryption: XTS-AES 256, protection on (account name blacked out)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The takeaway I will carry to every client: check the disk, not the report. A management portal
tells you what it sent. Only the device tells you what happened.&lt;/p&gt;

&lt;p&gt;The same morning the retail Windows 11 Pro key was bought from the Microsoft Store and activated,
and the BIOS was updated from 1.18 to 1.29 - with BitLocker suspended for one reboot first, so the
firmware change did not trigger a recovery-key prompt.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;installing-apps-without-being-an-administrator&quot;&gt;Installing apps without being an administrator&lt;/h2&gt;

&lt;p&gt;This is where the “not an admin on my own laptop” decision gets tested. Every app I wanted was
published in Intune as &lt;strong&gt;Available&lt;/strong&gt; to my user group, which puts it in the Company Portal app as a
self-service catalog. The Intune agent installs it as the system account, so a standard user never
needs an administrator password.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;App&lt;/th&gt;
      &lt;th&gt;How it was delivered&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;Bitwarden&lt;/td&gt;
      &lt;td&gt;Microsoft Store app (new)&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Visual Studio Code, Adobe Acrobat Reader, Signal&lt;/td&gt;
      &lt;td&gt;Microsoft Store app (new) - these come through as vendor installers hosted by the Store&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Google Chrome&lt;/td&gt;
      &lt;td&gt;Chrome Enterprise MSI, uploaded as a line-of-business app&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Gemini, Grok&lt;/td&gt;
      &lt;td&gt;Installed as web apps from the browser - no desktop package exists&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;Proton VPN, GitHub Desktop&lt;/td&gt;
      &lt;td&gt;Not in the Store catalog - deferred to a future project on packaging Win32 apps&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Two things were learned the slow way. First, a new “Available” app took about an hour to show up
in Company Portal the first time, and syncing the device does not speed it up, because the list
comes from the Intune service. Second, Bitwarden installed from Company Portal with &lt;strong&gt;no
administrator prompt at all&lt;/strong&gt; - which is the whole point.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/company-portal.png&quot; alt=&quot;Company Portal app catalog listing Adobe Acrobat Reader, Bitwarden, Google Chrome, Signal and Visual Studio Code&quot; /&gt;
&lt;em&gt;Company Portal as a self-service catalog (organization name blacked out)&lt;/em&gt;
&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/bitwarden-installed.png&quot; alt=&quot;Intune app overview for Bitwarden showing one device with a status of Installed&quot; /&gt;
&lt;em&gt;Bitwarden installed by the standard user with no elevation prompt; Intune reports one installed&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;And one honest gap. A standard user can still install software that only writes to their own
profile folder. Brave did exactly that, no prompt. Closing that requires Microsoft’s application
control features, which are a lot of overhead for a one-person shop. I am accepting the gap for now,
and saying so.&lt;/p&gt;

&lt;h2 id=&quot;proving-laps-end-to-end&quot;&gt;Proving LAPS end to end&lt;/h2&gt;

&lt;p&gt;“Verify LAPS end to end - actually retrieve a rotated password” has sat on my homelab to-do list
for a month. This time: the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;org&amp;gt;-lapsadmin&lt;/code&gt; password was retrieved from Intune, used to sign in
for the BitLocker fix, and then rotated with Intune’s “Rotate local admin password” remote action,
which reported Complete. The account exists, the password lives in Entra, and it changes on demand.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/entra-autopilot-intune-endpoint/laps-rotation.png&quot; alt=&quot;Intune device page with the Rotate local admin password remote action selected&quot; /&gt;
&lt;em&gt;Remote rotation of the managed local administrator password (device name, serial and model blacked out)&lt;/em&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;accounting&quot;&gt;Accounting&lt;/h2&gt;

&lt;p&gt;Cards on the table, again. Claude (Anthropic’s AI) was in this build from start to finish. It wrote
the runbook, the inspection script and the app-removal script, walked me through every step in a
chat, kept the build log, and drafted this post. I did every click and every command, and made
every decision - including several where I overruled it.&lt;/p&gt;

&lt;p&gt;It was also wrong, more than once, and it is worth listing exactly where, because these are the
same mistakes a person reading documentation would make:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;It said the Global Administrator role would be a local admin no matter what. There is a setting
for that.&lt;/li&gt;
  &lt;li&gt;It said a Microsoft change on 14 September had fixed the BitLocker timing problem. On this
laptop, it had not.&lt;/li&gt;
  &lt;li&gt;It expected the 25H2 installer. Microsoft was already shipping 26H2.&lt;/li&gt;
  &lt;li&gt;It expected device association to work on Wi-Fi.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every one of those was caught by doing the work on a real device rather than trusting a document.
That is the lesson I am taking from it, and it applies to my own notes as much as to an AI’s.&lt;/p&gt;

&lt;p&gt;It definitely pays to not just be a meat-proxy: pay attention to what the AI is saying, because pushback is necessary (cue: “You’re right to push back” meme).&lt;/p&gt;

&lt;h3 id=&quot;lab-compromises&quot;&gt;Lab compromises&lt;/h3&gt;

&lt;p&gt;So nobody has to ask:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;My account is still a Global Administrator for the tenant while also being my daily account. It
is no longer an administrator on the laptop, but the tenant-level risk stands. It is reversible
and on the list.&lt;/li&gt;
  &lt;li&gt;BitLocker unlocks with the TPM alone, no pre-boot PIN.&lt;/li&gt;
  &lt;li&gt;The memory is still the single stick until the replacement arrives.&lt;/li&gt;
  &lt;li&gt;There is no compliance policy or Conditional Access yet. Intune currently marks the laptop
“Compliant” only because the tenant default treats a device with no policy as compliant - which
is the first thing the next project changes.&lt;/li&gt;
&lt;/ul&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;what-is-next&quot;&gt;What is next&lt;/h2&gt;

&lt;p&gt;The work phone arrives today, and it gets the same treatment as its own project. After that, one
hardening project covers both devices at once: compliance policies, Conditional Access, update
rings, Defender for Business, and the decisions this laptop surfaced - application control and
stopping Windows from encrypting before the policy arrives.&lt;/p&gt;

&lt;p&gt;Most people just drink beer and play pickleball in their spare time. I apparently like to Entra Join laptops, deploy debloat scripts via Autopilot and Intune. I need new hobbies….&lt;/p&gt;

&lt;p&gt;Thanks for reading! - Evan&lt;/p&gt;

&lt;p&gt;The full technical record - tenant settings, design decisions, every issue and its fix - is in the project write-up: &lt;a href=&quot;/projects/entra-autopilot-intune-endpoint/&quot;&gt;Entra Join, Autopilot &amp;amp; Intune - Cloud-Native Windows Endpoint&lt;/a&gt;.&lt;/p&gt;
</description>
                <pubDate>Thu, 01 Oct 2026 12:30:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/autopilot-intune-work-laptop/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/autopilot-intune-work-laptop/</guid>
                
                <category>Intune</category>
                
                <category>Autopilot</category>
                
                <category>Entra ID</category>
                
                <category>BitLocker</category>
                
                <category>LAPS</category>
                
                <category>Hardware</category>
                
                <category>Troubleshooting</category>
                
                <category>MSP</category>
                
                
            </item>
        
            <item>
                <title>The IT Field Manual, version 1.4</title>
                <description>&lt;p&gt;The &lt;strong&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;IT Field Manual&lt;/a&gt;&lt;/strong&gt; is now at version 1.4. It runs
approximately 104,000 words across 36 sections, up from roughly 93,500 words and 31
sections in &lt;a href=&quot;/posts/it-field-manual-v1-3/&quot;&gt;version 1.3&lt;/a&gt; - about 10,300 more words.&lt;/p&gt;

&lt;p&gt;That is three separate pieces of work landing as one release, not three. Here is why,
what is actually new, and one placement call I made against my own staged source
material’s explicit advice.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt; &lt;/th&gt;
      &lt;th&gt; &lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Version&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;1.4, 19 September 2026&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Size&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;~104,000 words · 36 sections · ~493 headings&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;New since 1.3&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;§31 - §33 (A+ hardware/OS layer) · §34 - §35 (site survey and vendor due diligence)&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;New doctrine&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-13]&lt;/code&gt; - &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-15]&lt;/code&gt;, up from 12&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Corrections logged&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;74 in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[APX-C]&lt;/code&gt;, up from 54&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Read / download&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;Online&lt;/a&gt; · &lt;a href=&quot;/assets/docs/it-field-manual.md&quot;&gt;raw Markdown&lt;/a&gt;&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;h2 id=&quot;why-one-v14-not-three-version-bumps&quot;&gt;Why one v1.4, not three version bumps&lt;/h2&gt;

&lt;p&gt;By the time I sat down for this pass, three separate staged modules had piled up
against the vault master: a filtered A+ Study Guide, a vendor-assessment-and-site-survey
module, and a cloud-migration-economics-and-tooling module. Alongside them was one
still-open problem - a wording divergence I had found and partially fixed three weeks
earlier.&lt;/p&gt;

&lt;p&gt;Shipping each of those as its own version bump would have meant a v1.4 that was
superseded by a v1.5 within days, and a v1.5 superseded by a v1.6 not long after that.
Nobody reading a changelog gets anything out of that sequence except noise. So all four
went in as one release instead.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The wording divergence is worth explaining, since it is the least glamorous fix in this
release and the one that mattered most.&lt;/strong&gt; In early September I caught the phrase
“keeps it honest” sitting in several places in the manual - language my own voice
reference bans in favor of “legitimate,” “proper,” or “truthful.” I fixed it on the
published site immediately. I deliberately left the vault master - the actual source
file everything gets built from - unfixed, because a one-word patch outside a real
release is exactly the kind of silent drift this manual exists to prevent. For about
three weeks, the file I write from and the file the site serves were not the same
document. That is fixed now, as part of this release, not around it.&lt;/p&gt;

&lt;h2 id=&quot;new-the-parts-of-the-job-that-are-not-microsoft&quot;&gt;New: the parts of the job that are not Microsoft&lt;/h2&gt;

&lt;p&gt;The A+ Study Guide module was the biggest single source this round, and it got filtered
harder than its own “not exam-specific” bar - the standard was field relevance in 2026,
not “not literally a test question,” so roughly 60% of the source was discarded as
scaffolding or ground the manual already covered better.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;§&lt;/th&gt;
      &lt;th&gt;Section&lt;/th&gt;
      &lt;th&gt;What it is for&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;31&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Printers and imaging &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[PRN]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;The laser imaging process step by step, symptom-to-cause tables, and the one thing you never point at toner&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;32&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;macOS field reference &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[MAC]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;A Windows-to-Mac translation table for a technician who lives in Windows but supports mixed fleets&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;33&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Physical layer and connectors &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[CONN]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Cable standards and a connector-identification table rebuilt for what actually turns up in the field in 2026, not a 2015 study guide&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[PRN-06]&lt;/code&gt; is the one I would flag first if you only read one new entry: never
compressed air or a standard vacuum on toner. Compressed air aerosolizes a combustible
fine powder, and a standard vacuum’s motor brushes can ignite it. HEPA, ESD-safe toner
vacuum, nothing else.&lt;/p&gt;

&lt;p&gt;The connector table in §33 is not a straight copy of the source material either. USB-C
got added as its own row, Lightning got marked legacy rather than current, and the
mnemonics the study guide used to help you memorize the table got dropped entirely -
this is a lookup reference, not something you are studying for a test, so a device you
can Ctrl+F does the memorizing for you.&lt;/p&gt;

&lt;h2 id=&quot;new-reading-a-company-and-a-site-before-you-trust-either&quot;&gt;New: reading a company and a site before you trust either&lt;/h2&gt;

&lt;p&gt;The vendor-assessment-and-site-survey module added two full sections and two new
doctrine entries, and this is the part of the release aimed less at fixing something
broken and more at a skill I did not have a section for at all: judging whether an
inherited environment or an incumbent vendor is what it claims to be.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;§&lt;/th&gt;
      &lt;th&gt;Section&lt;/th&gt;
      &lt;th&gt;What it is for&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;34&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Site survey &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SITE]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;A shot list ordered by priority, evidence-handling rules, and the fact that a service tag is worth more than an estimate&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;35&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Vendor and platform due diligence &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[VEND]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Reading whether a product line is actually alive, and reading an incumbent’s invoices instead of its marketing&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-13]&lt;/code&gt; is the one I keep coming back to: &lt;strong&gt;a search that returns only
aggregators has told you the company is dead.&lt;/strong&gt; ZoomInfo, Manta, Dun &amp;amp; Bradstreet, and
similar directory sites never delete a listing - they are populated once from a public
filing and persist indefinitely, which means a defunct company can look extremely well
documented. Nine hits feels like evidence. It is nine copies of one filing. The fix is
requiring a live company website or a current state business-entity registry record
before you call anything active - the registry check takes about two minutes and settles
it outright.&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-14]&lt;/code&gt; is the physical-inspection companion to it: paper describes the part of
the world its author touched, and nothing else. A complete set of one vendor’s invoices
says nothing about a second vendor, a decommissioned appliance, or anything installed
before the first invoice in the set - not because the documents are wrong, but because
that is the definition of their scope. An hour walking a site with a written shot list
routinely finds what weeks of document review cannot.&lt;/p&gt;

&lt;h2 id=&quot;new-the-migration-pitch-split-into-the-two-numbers-it-actually-is&quot;&gt;New: the migration pitch, split into the two numbers it actually is&lt;/h2&gt;

&lt;p&gt;The cloud-migration-economics-and-tooling module was the smallest of the three by
section count - it landed as one doctrine entry and one extension, not a new section -
but &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-15]&lt;/code&gt; is doing real work: &lt;strong&gt;a cloud migration’s real saving for a small
organization is avoided capital spend, not a recurring discount.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The generic pitch - “the cloud saves you money on IT” - is not reliably true, and
treating it as automatic is a credibility risk in front of a technically literate buyer.
Recurring cost is usually close to even and depends entirely on what the organization
already owns; the real, defensible number is almost always on the capital side, where
aging on-premises hardware needs periodic replacement on a schedule that a cloud
migration can remove entirely. And administrative labor does not disappear - it changes
shape, from unplanned hardware-failure recovery to ongoing identity and policy
administration. Any total-cost argument that blends those two halves into one “savings”
figure is exactly where the misleading version of the pitch hides.&lt;/p&gt;

&lt;p&gt;The migration tooling itself - the file-share-to-SharePoint/OneDrive table - went into
a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[FILE-10]&lt;/code&gt;, which is the placement call from the intro.&lt;/p&gt;

&lt;h2 id=&quot;the-placement-call-i-made-against-my-own-source-material&quot;&gt;The placement call I made against my own source material&lt;/h2&gt;

&lt;p&gt;Both staged modules that added new sections came with their own integration
instructions, and I did not follow either one exactly as written.&lt;/p&gt;

&lt;p&gt;The vendor-assessment module’s own draft for §11 proposed a full second product-overlap
table for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[M365-21]&lt;/code&gt;. I wrote it short instead - a cross-reference to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[M365-13]&lt;/code&gt; and
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[M365-20]&lt;/code&gt;, which already cover that ground, plus only the material that was genuinely
new: checking for seat-by-seat license overlap, and the rule that “we already own an
equivalent” never extends to backup. Restating a table that already exists two sections
over is the kind of redundancy that makes a tagged, search-first document worse, not
more complete.&lt;/p&gt;

&lt;p&gt;The cloud-migration module’s own instructions named &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SPO]&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[AZ]&lt;/code&gt; as the candidate
home for the file-share migration tooling - it listed both as options. I put it in
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[FILE-10]&lt;/code&gt; instead. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SPO]&lt;/code&gt; is scoped tightly to sharing and guest access; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[FILE]&lt;/code&gt;
already carries the full lifecycle of on-premises file-share administration and reads
naturally as ending with “now retire it.” Cross-references went in from both &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SPO]&lt;/code&gt;’s
intro and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[AZ-07]&lt;/code&gt;’s Data Box entry, so the content stays reachable from every path
someone might search it from.&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[TRANSITION SLOT - he may want to make this a joke]&lt;/code&gt; Neither of those was the module’s
fault. A module is written against a snapshot of the manual that gets more stale the
longer it sits staged, and both of these had been sitting for a couple of weeks.&lt;/p&gt;

&lt;h2 id=&quot;the-correction-log-is-the-part-i-would-read&quot;&gt;The correction log is the part I would read&lt;/h2&gt;

&lt;p&gt;Appendix C is where every claim in my source material that turned out to be wrong gets
recorded, alongside the correction and where it was verified. Version 1.3 shipped with
54 entries. Version 1.4 has 74 - 20 in this release alone, which is the largest single
batch since the initial 16 that shipped with v1.0.&lt;/p&gt;

&lt;p&gt;A representative handful:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;SMB is not a Linux protocol.&lt;/strong&gt; It is Microsoft’s. Samba is the Linux/Unix
implementation of it - implementing a protocol does not make you its native platform.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Mixing RAM modules of different sizes and speeds does not waste capacity.&lt;/strong&gt; The
system uses the full combined capacity of every installed module, running at the speed
of the slowest one. The speed penalty is real; the capacity loss is not.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpedit.msc&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpmc.msc&lt;/code&gt; are not interchangeable&lt;/strong&gt;, and only one of them is
installed by default on a client OS. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpedit.msc&lt;/code&gt; is the Local Group Policy Editor.
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpmc.msc&lt;/code&gt; manages domain GPOs and their AD links, and it is an RSAT feature you have
to add.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Telnet does authenticate you&lt;/strong&gt; - with a username and password, in cleartext. No
encryption is not the same claim as no authentication, and conflating the two is a
worse mistake than either fact alone.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Azure Data Box does not have a flat 80 TB usable capacity anymore.&lt;/strong&gt; Current
Microsoft documentation shows a tiered lineup - roughly 35 TB, 120 TB, and 525 TB
usable, depending on the tier. I found this one myself while placing the
cloud-migration content, not from either staged module, which is exactly the kind of
catch this appendix exists for.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;what-is-actually-next-which-is-not-what-i-said-last-time&quot;&gt;What is actually next, which is not what I said last time&lt;/h2&gt;

&lt;p&gt;Version 1.3’s closing line said the next release would most likely be Linux and Samba.
It was not. A+ hardware content, vendor and site-survey due diligence, and cloud
migration economics came due first, and I would rather ship what was actually ready than
force a plan I made three weeks earlier onto a release it no longer describes.&lt;/p&gt;

&lt;p&gt;The Linux Field Manual is still a separate, not-yet-started document - a full bare-metal
Proxmox cluster build guide is staged and waiting for it, untouched, exactly where it was
last time. Section 25, “Personal additions,” is also still empty, on purpose, same as
every prior version.&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[TRANSITION SLOT - self-deprecation about predicting his own roadmap goes here]&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;That all being said, the manual stays public for the same reason it always has: a
document I know somebody might actually read is a document I write more carefully. If
you find something in it that is wrong or out of date, Appendix C is where it goes, and
it is the appendix I expect to keep growing fastest.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;Read the Field Manual →&lt;/a&gt;&lt;/strong&gt; ·
&lt;strong&gt;&lt;a href=&quot;/reference/&quot;&gt;Browse the Reference Library →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
</description>
                <pubDate>Sat, 19 Sep 2026 09:00:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/it-field-manual-v1-4/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/it-field-manual-v1-4/</guid>
                
                <category>Documentation</category>
                
                <category>Troubleshooting</category>
                
                <category>Hardware</category>
                
                <category>MSP</category>
                
                
            </item>
        
            <item>
                <title>I Put a Server Cluster in My Basement</title>
                <description>&lt;p&gt;Proxmox Virtual Environment is a free, open-source server platform that lets one physical
machine run many virtual machines and containers at once, managed through a web browser
instead of a command line. It is built on Debian Linux, it is used by everyone from home
labbers to actual businesses, and several machines running it can be joined into a
“cluster” so you administer all of them from one screen.&lt;/p&gt;

&lt;p&gt;Documentation and downloads at &lt;a href=&quot;https://www.proxmox.com/en/proxmox-virtual-environment/overview&quot;&gt;proxmox.com&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Cards on the table before we start: I had never used Proxmox before this build. Not once.
Everything below is a first-timer working through it in real time, which means you get the
mistakes too, and there were some good ones.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;how-i-got-here&quot;&gt;How I got here&lt;/h2&gt;

&lt;p&gt;My previous home lab was a Windows Server domain controller running on bare metal on an
old HP ProDesk, with a second controller virtualized on my main PC, pretending to be a
small business called HomeBiz. It worked. It taught me an enormous amount about Active
Directory, Group Policy, and hybrid identity. It also had a fairly serious problem, which
is that every time I wanted to build something new I had to destroy the thing that was
already there, and there was no backup of any of it anywhere.&lt;/p&gt;

&lt;p&gt;That is fine when the lab is only a lab. It stops being fine the moment you want the same
hardware to also run things your household actually depends on - DNS, file storage, connecting
the printer to the network because wi-fi prints suck,  ya know…stuff that gets noticed within 
about ninety seconds of going down.&lt;/p&gt;

&lt;p&gt;So the plan became: stop treating these three machines as three machines.&lt;/p&gt;

&lt;p&gt;The parts had been sitting around for a bit. Two used HP ProDesk business desktops that I
already owned, and a box of components for a new build I had not assembled yet. Then the
used CPU I had bought for that build turned out to be dead, which meant buying a brand new
one, which meant the whole thing slipped again.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/parts.jpg&quot; alt=&quot;Boxed components and the new AMD processor for the PX-03 build&quot; /&gt;
&lt;em&gt;Parts for the new node.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The new machine came together fine once the working CPU arrived. Bench tested it outside
the case first, which is one of those things that feels like an unnecessary extra step
right up until the moment it saves you from disassembling an entire build to find out
which part is bad.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/bench-test.jpg&quot; alt=&quot;PX-03 motherboard, CPU, and memory bench tested outside the case&quot; /&gt;
&lt;em&gt;Bench tested outside the case before assembly.&lt;/em&gt;
&lt;img src=&quot;/assets/projects/proxmox-cluster/px03-complete.jpg&quot; alt=&quot;The completed PX-03 build, case closed and cabled&quot; /&gt;
&lt;em&gt;The completed build.&lt;/em&gt;&lt;/p&gt;

&lt;h2 id=&quot;the-basement-problem&quot;&gt;The basement problem&lt;/h2&gt;

&lt;p&gt;Here is the constraint I could not engineer my way out of. The coax comes into the second
floor. The modem and the router live up there. The servers needed to live in the basement
utility room, because that is where it is cool, where there is space, and where my wife
does not have to look at them.&lt;/p&gt;

&lt;p&gt;Running actual ethernet between those two points is not something I can do in this
building. So the link between upstairs and downstairs is a powerline adapter pair, which
sends network traffic over the electrical wiring, and which gets me approximately 30
Mbit/s. That is not fast. On a gigabit home network that number looks genuinely bad.&lt;/p&gt;

&lt;p&gt;Here is the thing though, and this is the part I actually think is worth writing down: 30
Mbit/s being “bad” is meaningless until you say what it is carrying.&lt;/p&gt;

&lt;p&gt;I sat down and worked out what actually crosses that link. Cluster heartbeats - the
constant chatter the three servers use to confirm each other is still alive - do NOT cross
it, because all three machines sit on the same little switch in the basement. Backups do
not cross it either, same reason. What crosses it is me loading the web interface,
software updates, DNS queries, and eventually file transfers.&lt;/p&gt;

&lt;p&gt;Only that last one actually hurts. And the first one, the cluster heartbeats, is the one
that would have been genuinely dangerous, because that traffic is extremely sensitive to
delay and a flaky link carrying it would have made the whole cluster fall over
intermittently for reasons that would have looked like absolutely anything else.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;THE LINK LOOKED LIKE THE BIGGEST RISK IN THE ENTIRE BUILD AND IT TURNED OUT TO CARRY
ALMOST NONE OF THE TRAFFIC THAT MATTERS.&lt;/strong&gt; I would not have known that without writing out
the list.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/makeshift-rack.jpg&quot; alt=&quot;Three servers on a basement utility shelf with a terminal open&quot; /&gt;
&lt;em&gt;The rack. It is a shelf.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;That is my rack. It is a shelf. Anyways, moving on…&lt;/p&gt;

&lt;h2 id=&quot;building-the-thing&quot;&gt;Building the thing&lt;/h2&gt;

&lt;p&gt;The installs themselves were unremarkable, which is the correct outcome for an installer.
Three machines, three installations, roughly the same screens each time.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/first-login.png&quot; alt=&quot;Proxmox web interface login screen for PX-03&quot; /&gt;
&lt;em&gt;First login to the PX-03 web interface.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The first genuinely interesting decision came at the point of joining the three machines
into a cluster, and it went against the advice I had written down for myself weeks
earlier.&lt;/p&gt;

&lt;p&gt;The conventional wisdom is to wait. Get the layout settled first, then cluster, because
leaving a cluster later is much harder than joining one now. That is true and it is good
advice. It is also outweighed by a hard mechanical rule that I did not know about:&lt;/p&gt;

&lt;p&gt;/////BEGIN QUOTE/////
A Proxmox node that already holds any virtual machine or container CANNOT join a cluster.
The join command refuses. The node has to be emptied first.
/////END QUOTE/////&lt;/p&gt;

&lt;p&gt;Which flips the whole thing. Waiting does not defer the cost - it creates one, because
every VM I built in the meantime would have to be destroyed before its machine could join.
All three were empty right at that moment. That was the cheapest the operation was ever
going to be, so we did it right then.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/quorum.png&quot; alt=&quot;Proxmox cluster status showing three nodes and quorum&quot; /&gt;
&lt;em&gt;Three nodes, three votes, quorum of two.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Three nodes, three votes, quorum of two. Which means the lab machine can be powered off
whenever I want without anything else caring. That was the whole point of having three
boxes instead of one.&lt;/p&gt;

&lt;h2 id=&quot;and-then-dns-did-not-work-for-two-days&quot;&gt;And then DNS did not work for two days&lt;/h2&gt;

&lt;p&gt;I was building a DNS resolver. Not the filtering kind that blocks ads - the layer
underneath that, the part that actually goes out and finds the answer.&lt;/p&gt;

&lt;p&gt;Every single query came back SERVFAIL. Every one. Including the test that is specifically
designed to succeed.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/servfail.png&quot; alt=&quot;dig query returning SERVFAIL from the Unbound resolver&quot; /&gt;
&lt;em&gt;Every query came back SERVFAIL.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;And here is the trap I nearly walked into, which I think is the most useful thing in this
whole post. There is a standard pair of tests for checking that DNS security validation is
working. One name is supposed to come back fine, and one name is supposed to fail. Mine
failed. Correctly!&lt;/p&gt;

&lt;p&gt;Except the other one failed too. And so did everything else. &lt;strong&gt;A TEST THAT GIVES YOU THE
RIGHT ANSWER FOR THE WRONG REASON IS WORSE THAN A TEST THAT JUST FAILS&lt;/strong&gt;, because a failing
test makes you go look, and a falsely passing one makes you move on.&lt;/p&gt;

&lt;h3 id=&quot;what-a-resolver-actually-does&quot;&gt;What a resolver actually does&lt;/h3&gt;

&lt;p&gt;Worth a plain-language detour here, because the rest of this does not land without it.&lt;/p&gt;

&lt;p&gt;Think about how you would find a specific office in a large government building with no
directory in the lobby. You ask the security desk at the front, and they do not know where
that office is, but they know which floor handles that department. You go to that floor and
ask the desk there. They do not know either, but they know which wing. You ask at the
wing. Eventually somebody actually knows, and tells you the room number.&lt;/p&gt;

&lt;p&gt;That is recursion. Nobody in the chain knows the whole answer, and every one of them knows
who to ask next. A recursive resolver starts at the root servers - the front security desk
of the entire internet, and there are thirteen of them - and walks down until it reaches a
server that is actually authoritative for the name you asked about.&lt;/p&gt;

&lt;p&gt;The alternative, which is what most people’s computers do, is to ask one big public
resolver and take its word for it. That works fine. It also means that resolver sees every
single thing you look up.&lt;/p&gt;

&lt;p&gt;Simply put: recursion means finding out for yourself instead of asking somebody who will
remember that you asked.&lt;/p&gt;

&lt;h3 id=&quot;finding-it&quot;&gt;Finding it&lt;/h3&gt;

&lt;p&gt;Two commands solved this, and neither of them was a guess.&lt;/p&gt;

&lt;p&gt;The first one splits the problem in half. There is a flag you can send with a DNS query
that says “do the lookup, but skip the security validation step.” If the query works with
that flag and fails without it, your problem is validation. If it fails both ways, your
problem is the lookup itself.&lt;/p&gt;

&lt;p&gt;It failed both ways. So validation was innocent, and the actual lookup was broken. Half the
search space gone with one command.&lt;/p&gt;

&lt;p&gt;The second one asked a root server directly, with a flag telling it not to go asking anyone
else. And the answer that came back was wrong in three separate ways at once:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;It said &lt;strong&gt;REFUSED&lt;/strong&gt;. Serving that particular record is the one job a root server has. It
cannot refuse.&lt;/li&gt;
  &lt;li&gt;It came back in &lt;strong&gt;7 milliseconds.&lt;/strong&gt; From a basement, over a powerline adapter, to a root
server. My own queries to a machine sitting three feet away were taking 200 milliseconds.&lt;/li&gt;
  &lt;li&gt;It had the &lt;strong&gt;“recursion available” flag set.&lt;/strong&gt; Root servers do not do recursion. They
never set that flag. Not ever.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/root-server-query.png&quot; alt=&quot;Direct dig query to a root server returning REFUSED with the recursion-available flag set&quot; /&gt;
&lt;em&gt;A response that could not have come from a root server: REFUSED, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ra&lt;/code&gt; set, 7 ms.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;So whatever answered that query was not a root server. Something in between was grabbing
DNS traffic and answering it itself.&lt;/p&gt;

&lt;p&gt;It was my router. It has a feature that transparently intercepts DNS to cache and filter
it, which is a genuinely good feature for the devices in my house and an absolute
catastrophe for a machine whose entire job is going out and asking questions directly. My
resolver was getting its very first question answered by something that had no idea what
the root of the internet looked like, and it never got past step one.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The fix took about ninety seconds&lt;/strong&gt; once I knew what it was. The router lets you exempt
individual devices from that feature. One device exempted, nothing else on the network
touched.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/firewalla-services.png&quot; alt=&quot;Firewalla router DNS interception setting turned off for the server VLAN&quot; /&gt;
&lt;em&gt;DNS interception and DNS-over-HTTPS excluded for VLAN 30.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Two days. Ninety seconds. That is just how it be sometimes.&lt;/p&gt;

&lt;h3 id=&quot;the-part-i-got-wrong&quot;&gt;The part I got wrong&lt;/h3&gt;

&lt;p&gt;I want to be specific about my own mistake here rather than vague about it, because the
mistake is more instructive than the fix.&lt;/p&gt;

&lt;p&gt;I had written in my own notes, weeks ago, that this router feature would need to be turned
off before the ad-blocking layer would work. I had it filed as a client-side problem. Turn
it off before pointing the household at the new DNS server.&lt;/p&gt;

&lt;p&gt;That was incomplete, and the incompleteness is the whole lesson. &lt;strong&gt;A recursive resolver’s
own outbound questions are also DNS traffic.&lt;/strong&gt; Interception does not just stop clients from
reaching the resolver, it starves the resolver itself. So that step was not part of a later
cutover at all. It was a prerequisite for anything working, and I had it scheduled dead
last.&lt;/p&gt;

&lt;p&gt;Once the exemption was in place: cold query 294 milliseconds, same query again 1
millisecond from cache, security validation confirmed with the flag that only gets set when
the cryptographic chain actually checks out.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/dnssec-verified.png&quot; alt=&quot;dig output showing the AD flag confirming DNSSEC validation&quot; /&gt;
&lt;em&gt;The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ad&lt;/code&gt; flag: DNSSEC validation succeeded.&lt;/em&gt;&lt;/p&gt;

&lt;h2 id=&quot;backups-and-one-thing-worth-stealing&quot;&gt;Backups, and one thing worth stealing&lt;/h2&gt;

&lt;p&gt;I will not walk through the whole backup build, but there is one decision in it that I
think is genuinely worth copying regardless of what you run.&lt;/p&gt;

&lt;p&gt;The backup server has its own user accounts and its own permission roles. The obvious move
is to point the servers at it using an admin account, because that definitely works. What I
did instead was create an account with a role that can &lt;strong&gt;create and read backups but cannot
delete them.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The credentials sitting on my servers can add to backup history. They cannot destroy it.
Which matters because the way ransomware actually beats backups is not by being cleverer
than the encryption - it is by finding the credentials on the machine it just compromised
and using them to wipe the restore points before it starts.&lt;/p&gt;

&lt;p&gt;The trade-off is real and I had to configure around it: since that account cannot delete
anything, the cleanup schedule has to live on the backup server itself instead of being
driven by the servers. Which is fine. That is one setting.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/proxmox-cluster/backup-job.png&quot; alt=&quot;Backup job configured from PX-01 to the Proxmox Backup Server&quot; /&gt;
&lt;em&gt;Creating the backup job for PX-01.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;And then I ran the job manually and went and looked at the datastore to confirm a snapshot
actually landed in it. &lt;strong&gt;A BACKUP JOB THAT HAS NEVER BEEN RUN IS NOT A BACKUP, IT IS A
HOPE.&lt;/strong&gt; I have an untested restore sitting in my notes from a previous project that has
been quietly bothering me for weeks, and I did not want a second one.&lt;/p&gt;

&lt;h2 id=&quot;the-deliniation-of-work&quot;&gt;The Deliniation of Work&lt;/h2&gt;

&lt;p&gt;Cards on the table, because I think this matters and because the alternative is letting
people assume.&lt;/p&gt;

&lt;p&gt;I did not do this alone. I worked through the entire build in a live conversation with
Claude (Anthropic), and the division of labour was roughly this.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Claude did:&lt;/strong&gt; the architecture reasoning, most of the “here is why this option beats that
option” analysis, the exact commands and what every flag in them meant, the troubleshooting
methodology when DNS broke, and the documentation. It also caught things I would have
missed - it flagged that I was about to build a container with the wrong security setting,
it caught that I was about to buy a Windows license I did not need, and it noticed that I
had my own settled decision written down and was about to contradict it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I did:&lt;/strong&gt; every command, every physical action, every decision, and all the pushback. I
built the machine. I ran the tests. I made the calls on what to do and what to skip.&lt;/p&gt;

&lt;p&gt;And I want to be clear that the pushback was not decorative. Claude got things wrong, more
than once, and in ways that cost me time:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;It recommended a permission role that turned out to be structurally incapable of doing
the thing I needed, and I hit a 403 error because of it.&lt;/li&gt;
  &lt;li&gt;It sent me down a completely unnecessary SSH rabbit hole to solve a problem that had a
one-command answer sitting right there.&lt;/li&gt;
  &lt;li&gt;It told me to run a command without telling me which machine to run it on.&lt;/li&gt;
  &lt;li&gt;It handed me a config file reference and then never actually told me to create the file,
so I sat there wondering why nothing worked.&lt;/li&gt;
  &lt;li&gt;It predicted a default setting that turned out to be the opposite of what my system
actually had.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every one of those got corrected, most of them because I pushed back rather than because it
noticed. &lt;strong&gt;THAT IS THE ACTUAL SKILL HERE.&lt;/strong&gt; Not prompting. Reading the output, noticing when
it does not match what you were told to expect, and saying so.&lt;/p&gt;

&lt;p&gt;The documentation came out of the same conversation, and I want to name that plainly rather
than let it read as though I typed it all up afterwards. What I did do is decide what goes
in it, correct it where it was wrong, and refuse the parts I did not want.&lt;/p&gt;

&lt;h2 id=&quot;where-it-stands&quot;&gt;Where it stands&lt;/h2&gt;

&lt;p&gt;Three machines, one cluster, one screen. Always-on services on one node, backups on
another, a lab machine on the third that I can power off whenever I want without anything
else noticing.&lt;/p&gt;

&lt;p&gt;There are two things I deliberately did not do, and I wrote down the condition that would
make me change my mind rather than a date to reconsider:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;SSH root password login is still enabled.&lt;/strong&gt; It is only reachable from inside my own
network, and the moment I put any remote access in front of it - a VPN, a port forward,
anything - I close it. Not before.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;The lab’s isolated network does not exist yet.&lt;/strong&gt; Because building it now means guessing
at a design decision that belongs with the lab itself.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Next up is the ad-blocking layer, then network file storage, then rebuilding HomeBiz on top
of all of it - this time as something I can tear down and stand back up from code instead
of by hand.&lt;/p&gt;

&lt;p&gt;Onward and upward, I say.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;em&gt;The full technical writeup, with the architecture decisions and verification evidence, is
on the project page. The complete build procedure is
&lt;a href=&quot;/reference/playbooks/&quot;&gt;published separately as a runbook&lt;/a&gt;, for
anyone who wants to do this themselves - or for me, in a year, when I have forgotten all of
it.&lt;/em&gt;&lt;/p&gt;
</description>
                <pubDate>Sun, 30 Aug 2026 16:00:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/proxmox-cluster/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/proxmox-cluster/</guid>
                
                <category>Proxmox</category>
                
                <category>Homelab</category>
                
                <category>Linux</category>
                
                <category>DNS</category>
                
                <category>Networking</category>
                
                
            </item>
        
            <item>
                <title>Create a &quot;Second Brain&quot; using Claude</title>
                <description>&lt;p&gt;&lt;strong&gt;“An AI second brain is a personal knowledge system that captures your ideas, references, notes, and projects in one connected workspace, and is continuously read by an AI assistant that uses that context to answer questions, surface forgotten material, and generate new work. It is the AI-native evolution of the “second brain” concept popularized by Tiago Forte in 2022, where the AI does not replace your thinking, but reads everything you have captured before it responds.”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Definition from &lt;a href=&quot;https://storyflow.so/blog/what-is-ai-second-brain-complete-guide&quot;&gt;storyflow.so&lt;/a&gt;, author Justkay.&lt;/p&gt;

&lt;p&gt;Inb4: I’m into Claude-maxxing. Use your preferred frontier AI model for this, but my bias should be known upfront.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;how-i-got-here&quot;&gt;How I got here&lt;/h2&gt;

&lt;p&gt;I had first heard of this concept while briefly skimming YouTube videos as I lay rotting on my couch looking for something to watch. At first it didn’t really register and I didn’t click on it because (definitely with my algorithm) my feed is full of plenty - and arguably an unhealthy amount - of coding, AI, tech, and Cyberpunk 2077 videos with the occasional Japanese micro apartment tour video sprinkled in for good measure. Especially nowadays, I’m so hesitant to watch any video about AI from some random dude with a snapback hat with like 15K subscribers and has a folder on his desktop labeled “Chess Moves” where he keeps his “business strategy” files - basically reeks of internet guru slop and frankly I’m not about that.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/01-second-brain-video-recommendations.png&quot; alt=&quot;A YouTube homepage full of &amp;quot;AI second brain&amp;quot; video thumbnails and clickbait titles like The AI Second Brain Lie and Your Second Brain Doesn&apos;t Work&quot; /&gt;
&lt;em&gt;Yeah, these kinds of videos.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;However, the idea of using AI as a “second brain” did capture my attention conceptually for a moment as I’m all in on using frontier AI models to significantly increase productivity across multiple domains. Despite that, I did keep scrolling because my dinner was getting cold as I was trying hard to find something to watch while I eat and inevitably nap.&lt;/p&gt;

&lt;p&gt;A few weeks later my brother shot me a much more interesting video (admittedly I didn’t watch, see reasoning above), but my brother is a serious, tech-savvy guy who does insane work teaching himself programming, 3D printing, making a mobile app (makes homemade drones too, as one does) and that really sparked the thought into my head that hey maybe this is something worth looking into. My brother and I do have pretty good discussions regarding utilizing AI for personal things as well as work, and are in agreement that an individual’s ability to efficiently utilize AI frontier models will be a legitimate differentiating skill in the modern/future workplace.&lt;/p&gt;

&lt;p&gt;I like to think of AI as a tool - say, like a hammer: There are skilled tradesmen who use hammers in creating beautiful buildings, works of art, high quality furniture, and so on; and then there are people who can only use a hammer to throw a couple thumbtacks into the dry wall to hang “Live, Laugh, Love” signs in their dining rooms. Not throwing any shade to Target though - Target’s great, generic kitchen artwork aside.&lt;/p&gt;

&lt;p&gt;Enough about hammers - back to the Second Brain: After my conversation with my brother I naturally turned to Claude to try and understand what the concept actually is, how it can be useful, and is it even something worth trying to set up. I must admit I did also turn to some of the internet guru videos (tried to find some good ones - couldn’t), and I was able to gather the gist quickly enough to at least make a more informed prompt.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/02-asking-claude-to-explain-the-concept.png&quot; alt=&quot;A chat message asking Claude to explain the AI second brain concept and how best to use it&quot; /&gt;
&lt;em&gt;Asking Claude to explain the concept before building anything&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;To quote the esteemed author, Claude:&lt;/p&gt;

&lt;p&gt;/////BEGIN QUOTE/////&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where the idea came from&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;“Second brain” as a term is Tiago Forte’s, from his 2022 book &lt;em&gt;Building a Second Brain&lt;/em&gt;. But the concept is old and the book is mostly repackaging. The lineage runs back through David Allen’s &lt;em&gt;Getting Things Done&lt;/em&gt; (1999), Niklas Luhmann’s Zettelkasten (a German sociologist’s index-card system from the 1950s-90s, credited with letting him publish 70 books), and further back to commonplace books - the notebooks Renaissance scholars kept of quotes and observations, cross-indexed by theme.&lt;/p&gt;

&lt;p&gt;The claim underneath all of them is the same: your brain is good at thinking and bad at storage, so stop asking it to store things. Offload retention to a system you trust, and free up working memory for the part machines can’t do.&lt;/p&gt;

&lt;p&gt;Forte’s framing is CODE: Capture, Organize, Distill, Express. Worth knowing because you’ll see it everywhere, but three of those four are filler. The one that matters is Distill. Everything else is logistics.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What AI actually changed&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the part worth being precise about, because the marketing overstates it badly.&lt;/p&gt;

&lt;p&gt;Before LLMs, the bottleneck in any note system was retrieval. You had to remember that you’d written a note, roughly what you called it, and roughly what words were in it. Keyword search only works if you can guess the keyword your past self used. This is why so many vaults die: people write notes and then can never find them again, so they stop trusting the system, so they stop writing.&lt;/p&gt;

&lt;p&gt;LLMs collapsed that bottleneck. You can now ask a fuzzy question - “didn’t I hit something like this before, where a thing looked fine locally but 404’d live?” - and get the right note back without knowing its name. That’s real, and it’s the whole delta.&lt;/p&gt;

&lt;p&gt;What AI did not change:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Capture still requires you. Claude doesn’t know what happened in your day.&lt;/li&gt;
  &lt;li&gt;Judgment still requires you. Claude can’t tell what mattered.&lt;/li&gt;
  &lt;li&gt;Understanding still requires you. A summary you didn’t write teaches you nothing.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So the accurate statement is: AI fixed the retrieval problem in note-taking, and note-taking still has all its other problems.&lt;/p&gt;

&lt;p&gt;/////END QUOTE/////&lt;/p&gt;

&lt;p&gt;I love that line: &lt;strong&gt;“Your brain is good at thinking and bad at storage, so stop asking it to store things.”&lt;/strong&gt; I think that made the concept click a lot faster for me than Chess Moves bro and his failed ecommerce drop-shipping business (maybe I’m just projecting here, I’m sure he’s a nice guy). This is definitely an area in my entire student and work career I’ve come incredibly short in: I’ll take plenty of notes in class, while doing a course, listening to a lecture, highlighting stuff in books I read, all of it - and then…I like, never go back and read them. Fortunately, I’ve been quite blessed with very good memory and I’m at least on the good end of the normal distribution curve of average IQ (total midwit though, I am what I am) so I’ve been a perpetual B+/A- student my entire life just by paying attention to the material presented. Where I’ve struggled though is having good, accessible, and more importantly usable reference material to draw from when I need it most. My memory is good but it’s not THAT good to be able to recall obscure data, quotes, niche concepts from economic literature, what I ate for breakfast, etc. All to say, utilizing the new hot tool in the modern world to solve a shortcoming of mine sounds like an excellent use of my time.&lt;/p&gt;

&lt;h2 id=&quot;turns-out-i-was-already-doing-this&quot;&gt;Turns out I was already doing this&lt;/h2&gt;

&lt;p&gt;In my dialogue with Claude, it turns out that I’ve been doing this informally, yet structurally for quite awhile already - case in point, the website this article is hosted on:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;The whole point of me creating evanireland.tech is to serve two goals:
    &lt;ul&gt;
      &lt;li&gt;Primarily as a portfolio to showcase my work, skills, and domain knowledge for potential employers/clients/colleagues.&lt;/li&gt;
      &lt;li&gt;Very close second is to be my own personal hub of reference material (the IT Field Manual, playbooks, runbooks, the to-be-published script repo, and so on) so I always have it available to me as long as I have an internet connection.&lt;/li&gt;
    &lt;/ul&gt;
  &lt;/li&gt;
  &lt;li&gt;I do the work firsthand (I do the projects, I save the reference material I find useful, I find the appropriate scripts and save them to VS Code), I take notes and screenshots as I go along, but then I utilize Claude to distill what I’ve done, clean up my digitally chicken-scratched, disheveled notes and documentation, turn it into a legible document, and integrate into the existing website files.&lt;/li&gt;
  &lt;li&gt;What I accomplish doing this way is a very efficient way to leverage what I’m good at, and what I could still do but could instead use an AI assistant to do much better and faster.&lt;/li&gt;
  &lt;li&gt;I do work, I learn skills, I find helpful resource material I would REALLY LIKE TO BE ABLE TO CONTINUE TO USE, I write it down, save it, and ask Claude to store it in a legible and accessible manner - and thanks to Claude I can do this veeerrryyy quickly and much better than if I were doing it by myself.&lt;/li&gt;
  &lt;li&gt;The IT Field Manual is the single best example I have of this: Cards on the table, do you think I wrote that start to finish? Helllll noooooo. What I did actually do is run through and find everything that’s listed there though, I tried out the scripts to make sure they worked, I did the troubleshooting steps to verify they were legit, but then Ol’ Buddy Claude distills the chaos into a very organized, singular reference complete with fancy hyperlinks, tags, tables, and so on. And it comes in handy to fill in gaps that I missed and/or didn’t properly articulate in my note taking process.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That’s really what is meant in Claude’s response: “the bottleneck in any note system was retrieval. You had to remember that you’d written a note, roughly what you called it, and roughly what words were in it. Keyword search only works if you can guess the keyword your past self used.”&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/03-it-field-manual-page.png&quot; alt=&quot;The IT Field Manual reference page on evanireland.tech&quot; /&gt;
&lt;em&gt;One of the reference pages this system is supposed to make easier to find again&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Another quite righteous example of a way I’m going to use this concept: This article. What I’m presently doing as I type is:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Writing the prose for the article, stream-of-conscious, thinking as I go along and making nice sounding words&lt;/li&gt;
  &lt;li&gt;I do the setup for the Second Brain utilizing Claude and the system it’s helping me develop&lt;/li&gt;
  &lt;li&gt;I take screenshots of the things I find interesting&lt;/li&gt;
  &lt;li&gt;Continue taking notes and refining&lt;/li&gt;
  &lt;li&gt;And when I’m done I’m going to drop all of this into the upcoming 00. Inbox folder to test the concept.&lt;/li&gt;
  &lt;li&gt;You’ll know I’ve been successful by reading the article.&lt;/li&gt;
  &lt;li&gt;And now I’ll have a reference to be shared with anyone who wants to set up their own second brain by yet another dude in his 30s wearing a snapback hat who has his own website. Oh God, what have I become…&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Also, for the sake of argument - yes I do indeed do my own writing (see below). Will I use Claude to help clean up my monkey brain writing and make it way prettier? You’re absolutely right.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/04-drafting-this-article.png&quot; alt=&quot;A draft of this article in a text editor, with screenshot placeholders still sitting in the text&quot; /&gt;
&lt;em&gt;Yes, this is a screenshot of the article you’re reading, mid-draft, placeholders and all&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Now let’s set this Bad Johnson up.&lt;/p&gt;

&lt;h2 id=&quot;setting-it-up&quot;&gt;Setting it up&lt;/h2&gt;

&lt;p&gt;So my big brain move after watching some videos on “How to Set Up Your Second Brain to Run Your Affiliate Marketing Site Slop” and listening to these guys with their convoluted setups was to… (I’m not even kidding, when I asked Grok to help come up with internet guru slop business ideas to make fun of, one of the examples was: “Notion Templates / Swipe Files / ‘Operating System’ - A second brain that is just folders. Sold as leverage.” That is so awesome)&lt;/p&gt;

&lt;p&gt;…just ask AI to help me set it up and show me how to use it. What a concept - off to a great start already!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/05-setup-prompt-to-claude.png&quot; alt=&quot;The initial prompt asking Claude to help set up a second brain, listing concerns about losing context across four existing Claude Projects&quot; /&gt;
&lt;em&gt;I forgot to tell him “Make no mistakes.” Dang it…&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;First step I did was to create a simple, blank folder on my desktop. I felt like eschewing Obsidian because it looks way too annoying to setup for this and like, it’s just an .md text editor anyways. I reserve the right to set it up on Obsidian in the future out of curiosity, but to learn this I opted for the path of least resistance.&lt;/p&gt;

&lt;p&gt;So a simple folder living on my desktop (backed up to OneDrive) it is. I felt like naming mine the Cogitator because 40K is cool, the Adeptus Mechanicus are cool (shouldn’t surprise anyone that a dude with a site like this is Ad Mech-down), and it gave me an excuse to create an Ad Mech icon to keep on my desktop.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/06-cogitator-desktop-icon.png&quot; alt=&quot;A desktop icon labeled Cogitator with a blue Adeptus Mechanicus-style skull icon, next to the Recycle Bin and OneDrive icons&quot; /&gt;
&lt;em&gt;The empty folder that started it all&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Anyways, when I submitted this prompt, I switched to Cowork mode and utilized the Opus 5 model set to High. I pointed Claude to the empty Cogitator folder and let it run.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/07-claude-response-three-decisions.png&quot; alt=&quot;Claude&apos;s response after being pointed at the empty folder, summarizing three architecture decisions before writing anything&quot; /&gt;
&lt;em&gt;Claude asking for three decisions before writing a single file&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/08-first-generated-layout-rejected.png&quot; alt=&quot;The first generated folder layout, with underscore-prefixed and numbered folders like 00-Inbox and 01-Projects&quot; /&gt;
&lt;em&gt;First pass at the architecture&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/09-explanation-of-generated-files.png&quot; alt=&quot;Claude summarizing what had been written to disk: 23 markdown files including a master context file and per-project briefs&quot; /&gt;
&lt;em&gt;And a rundown of what actually landed on disk&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Simple as that, no internet guru slop course required. Just use the AI model you’re guaranteed already paying for - or will end up paying for - if you’re going to set up a complicated storage system with it. Use the hammer for making useful things, not hanging “Live, Laugh, Love” signs in your kitchen, Madison.&lt;/p&gt;

&lt;h2 id=&quot;how-claude-actually-remembers-things&quot;&gt;How Claude actually remembers things&lt;/h2&gt;

&lt;p&gt;An important note here for understanding about how Claude/AI actually uses your saved context:&lt;/p&gt;

&lt;p&gt;Think of AI memory like writing on a physical whiteboard in a specific meeting room.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Conversations are like temporary room whiteboards.&lt;/strong&gt; Everything you discuss during a chat is written on that room’s whiteboard so the AI can read it and respond in real-time. But the moment you start a fresh chat, you walk into a brand-new, empty room. The AI can’t see the whiteboard in the old room.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Projects are like permanent notice boards in the hallway.&lt;/strong&gt; Files and instructions you explicitly upload to a Project act as permanent reference boards posted in the hallway. Whenever you start a new chat inside that Project, the AI reads the hallway notice board first, but it still cannot see what was written on the whiteboards of your previous chats.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Because an AI cannot automatically carry past chat notes to a new conversation, you have to summarize the important details from an existing chat and explicitly post them onto the Project’s notice board so future chats can read them.&lt;/p&gt;

&lt;p&gt;Simply put: A single chat is keeping track of what you’ve told it in a single chat, AI doesn’t necessarily know what you discussed in a different chat - even if they’re in the same Project umbrella. That is unless you have given the Project specific instructions and reference material to work with. Granted, Claude and some AI models do keep a persistent memory file about you generally, but it is very limited in what it’s going to keep track of.&lt;/p&gt;

&lt;p&gt;Which is the point of what we’re doing here - bridging the gap between these conversations by using the “Second Brain” file system which is going to comprise instructions and references. We’re basically building a library for Claude to refer to when we ask it questions. I only have to tell it my favorite TV show as a kid was Hey Arnold one time and save it into an instruction file - not relitigate it every time I ask it about peak television. The flipside of this being, should heaven forbid I forget what my favorite TV show was as a kid I can ask Claude who now has perpetual access to that information no matter when I ask it or what we’re discussing in the first place.&lt;/p&gt;

&lt;p&gt;There is one more piece worth knowing, and it’s the critical connecting piece: &lt;strong&gt;Cowork mode can read the folder directly.&lt;/strong&gt; A regular chat inside a Project only sees the hallway notice board. A Cowork session with your folder connected sees the notice board &lt;em&gt;and&lt;/em&gt; walks into your actual filing room. That is the difference between Claude knowing a summary of your projects and Claude reading the current state of them.&lt;/p&gt;

&lt;h2 id=&quot;the-first-layout-was-wrong-but-refinement-is-always-possible&quot;&gt;The first layout was wrong, but refinement is always possible&lt;/h2&gt;

&lt;p&gt;So, although Claude was able to write me the architecture directly into my folder - I didn’t quite like the way it had set it up. The structure felt a little off to me and I had to click through a bunch of confusing sub-folders, things were nested weird and weren’t where I as the user would expect them to be - all of that. However! You know what’s nice about using an AI agent for this in the first place??&lt;/p&gt;

&lt;p&gt;I can just ask it to redo it in a way that makes more sense to me…and then it does it…and it works.&lt;/p&gt;

&lt;p&gt;One important note for anyone who isn’t used to intelligently prompting AI models: You have to be specific. My go-to example is going to the barbershop: If you walk in and simply just ask for a haircut, you’re definitely going to get a haircut but it might not be the one you wanted - perhaps not even close to what you wanted. You HAVE to be specific - tell the barber exactly what you want or give him some references to work from. In this case - I have my OneDrive setup in a way that maps directly to how my brain likes folders/files set up. All I had to do to fix the Second Brain set up was point Claude at both my Cogitator folder and an offline copy of my OneDrive (with selected files deleted from it - I don’t want Claude to have access to specific things), and re-prompt “Make the Cogitator look more like this.” In short order I was able to have a file system in my Cogitator that is usable for both my brain and Claude programming. Simple as that.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/10-reorg-conversation.png&quot; alt=&quot;Claude describing the numbering and naming conventions it found in an existing OneDrive folder, in order to reproduce them in the vault&quot; /&gt;
&lt;em&gt;Pointing Claude at a folder I already navigate without thinking, and asking it to match that instead&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/projects/claude-second-brain/11-final-layout-result.png&quot; alt=&quot;The final Cogitator folder layout, numbered Title Case folders from 1. Ireland Capital through 9. Archive&quot; /&gt;
&lt;em&gt;Current layout, derived from existing OneDrive conventions&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The thing I want to flag here, because it is the actual lesson and not just a step: &lt;strong&gt;the layout does not have to be good for someone else, it has to be good for you.&lt;/strong&gt; Claude’s first attempt was a widely-recommended structure, and is the type of structure you’d pay dude bro to be able to take his affiliate marketing course. It was also one I would have probably stopped using in a month, because every time I went looking for something I would have had to think about where it lived. Mine is numbered folders in Title Case because that is what my OneDrive already looks like and my hands already know it. Yours should look like whatever you already navigate without thinking.&lt;/p&gt;

&lt;p&gt;The point is to build a tool YOU will use for YOUR work - you don’t have to take a cookie-cutter, boiler plate template; make the tool work for YOU.&lt;/p&gt;

&lt;h2 id=&quot;getting-your-existing-chats-out-of-their-silos&quot;&gt;Getting your existing chats out of their silos&lt;/h2&gt;

&lt;p&gt;So good - I have a file system architecture I like and organized the way that I want it. Next up is I need to get the relevant information to put in it. Personally, I have six Claude Project umbrellas I use:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Ireland Capital:&lt;/strong&gt; My personal finance and investing project&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;IT Skill Development:&lt;/strong&gt; Improving my IT domain knowledge skills&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;IT Cert Study Guides:&lt;/strong&gt; Self-explanatory&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Beginning Coding:&lt;/strong&gt; Also self-explanatory&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;IT Field Manual:&lt;/strong&gt; The project I use to distill the knowledge I find out in the wild and integrate into one cohesive study guide&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Branding:&lt;/strong&gt; For my resume, LinkedIn, social media posts, etc.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Here’s something I actually learned doing this and didn’t already know; worth internalizing before you try this: &lt;strong&gt;a new chat inside a Project cannot read your old chats in that same Project.&lt;/strong&gt; Not “struggles to.” It cannot. Back to the whiteboard - every conversation is its own room, and the door locks behind you.&lt;/p&gt;

&lt;p&gt;So you can’t open a fresh chat and say “summarize everything we’ve worked on.” It does not know. It will either tell you so, or - worse - it will do the very 2023-ish AI thing where it will very confidently make things up.&lt;/p&gt;

&lt;p&gt;What that means practically is that the distillation has to be run &lt;strong&gt;at the bottom of the existing chat&lt;/strong&gt;, while that conversation still remembers itself. You are not asking Claude to go retrieve something. You are asking it to write down what is currently in the room before you leave it.&lt;/p&gt;

&lt;p&gt;The prompt Claude gave me &lt;strong&gt;(pro-tip: ask the AI how to best use it)&lt;/strong&gt; looks like this:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;I am building a persistent knowledge system and I need to capture the state of this
work before this conversation&apos;s context is lost.

Write me a single markdown document that a future version of you - one with **zero**
memory of this conversation - could read cold and immediately be as useful as you
are right now. Assume that reader knows nothing except what you write.

Use exactly these headings:

## Purpose
What this project is for, in two or three sentences. Why it exists, not just what
it is.

## Current state (as of &amp;lt;today&apos;s date&amp;gt;)
Where things actually stand. What is built, what works, what is half-finished, what
is broken. Be concrete. &quot;The deploy script works&quot; is useless; &quot;deploy.ps1 pushes to
the gh-pages branch, but does not handle the custom domain CNAME&quot; is useful.

## Key decisions and why
Every real decision we made, with the reasoning. This is the most valuable section -
it stops a future conversation from talking me back out of a decision I already made
for good reasons. Format each as: decision, then the reason in one line.

## Dead ends - do not try these again
Approaches we tried that failed, and why they failed. Be specific about the failure
mode. This section saves me the most time and it is the one people forget to write.

## Conventions and vocabulary
Naming schemes, file layouts, terms we use in a specific way, formatting rules,
anything where &quot;how we do it here&quot; differs from the generic default.

## Open threads
Unfinished work and unanswered questions, ordered most-important first. For each,
say what the actual next action is - a verb, not a topic.

## What Claude should know about working with me on this
Anything about my skill level in this area, my preferences, or how I like this
particular kind of work handled.

Rules for writing it:

- **Do not flatter the work and do not inflate progress.** If something is barely
  started, say barely started. An over-optimistic brief is worse than no brief,
  because I will act on it.
- **Do not include anything you are not confident actually happened** in this
  conversation. If you are unsure, mark it `[uncertain]` rather than smoothing it
  over.
- Prefer specifics over summary. File names, commands, versions, exact errors.
- If a section genuinely has nothing in it, write &quot;None yet.&quot; Do not pad it.
- Output raw markdown in a single code block so I can copy it cleanly.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Two things about that prompt are doing most of the work, and they are not the obvious ones.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Dead ends - do not try these again”&lt;/strong&gt; is the section nobody writes and the one that pays for the whole exercise. Every project has three or four approaches you tried that failed for a specific reason, and six months later that reason is completely gone from your head. Mine has entries like “Jekyll silently drops future-dated posts, with no build error” - which cost me a genuinely annoying afternoon once and will now never cost me one again. Nice try!&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Do not flatter the work and do not inflate progress”&lt;/strong&gt; exists because the default failure mode of an AI summary is optimism. A brief that says a thing is “largely complete” when it is half-built is worse than having no brief at all, because you will plan against it.&lt;/p&gt;

&lt;p&gt;I ran that prompt on the two or three load-bearing chats inside each Project - not every chat, just the ones actually carrying the work - and ended up with eleven documents. Then I saved all eleven into the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;00. Inbox&lt;/code&gt; folder and did not sort a single one of them.&lt;/p&gt;

&lt;p&gt;And then we get to the part that still feels slightly illegal. I opened a Cowork session, pointed it at the Inbox, and said “file these where they go.” It read all eleven, worked out which Project each belonged to, merged the three-per-project ones into single briefs, and put them away. It also caught two things I would not have: one of my distillations described the website as being on a theme I had migrated away from days earlier (the “as of” date on a distillation is the date you &lt;em&gt;ran&lt;/em&gt; it, not the date the work happened), and two different briefs described my own skill level in flatly contradictory ways.&lt;/p&gt;

&lt;p&gt;While I’ll be a son of a gun… Also worth doing: Make Claude audit your folder through multiple iterations; make it catch these inconsistencies early and often. AI is good but it’s not perfect, feel me?&lt;/p&gt;

&lt;h2 id=&quot;what-is-actually-in-the-folder-and-what-each-piece-does&quot;&gt;What is actually in the folder, and what each piece does&lt;/h2&gt;

&lt;p&gt;This is the part I wanted to lay out plainly, because “second brain” gets used to describe everything from a Notion template to a paid course, and in practice mine is about five ideas.&lt;/p&gt;

&lt;p&gt;Here is the whole thing:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;Cogitator/
├── 0. About Evan.md          &amp;lt;- who I am. the one file Claude always gets.
├── 0. START HERE.md          &amp;lt;- how the system works. rules and conventions.
├── 00. Inbox/                &amp;lt;- dump zone. no rules. emptied weekly.
├── 1. Ireland Capital/       ┐
├── 2. IT Skill Development/  │
├── 3. IT Cert Study Guides/  │  one folder per Claude Project.
├── 4. Beginning Coding/      │  the number matches the project.
├── 5. IT Field Manual/       │
├── 6. Branding/              ┘
├── 7. Resources/             &amp;lt;- stuff that serves more than one project
├── 8. Logs/                  &amp;lt;- learning log, weekly reviews
└── 9. Archive/               &amp;lt;- finished or superseded, kept anyway
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;And every one of those six project folders is identical inside:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;2. IT Skill Development/
├── 0. Brief.md      &amp;lt;- the state of this project
├── 1. Working/      &amp;lt;- what I&apos;m actively doing
├── 2. Reference/    &amp;lt;- finished stuff I&apos;ll look up later
└── 9. Archive/      &amp;lt;- superseded, kept
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;That sameness is deliberate and systematic - which when building a “system” is kind of the point, yeah? Claude can open any project folder and already know where things are without hunting, and more importantly &lt;em&gt;I&lt;/em&gt; never have to decide where something goes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. About Evan.md&lt;/code&gt;&lt;/strong&gt; is the master context file - who I am, my background, what I’m working toward, my certs, how I want Claude to talk to me (bluntly, explain the mechanism behind commands, don’t inflate progress), and what I’m currently focused on. This is the &lt;strong&gt;only&lt;/strong&gt; file I upload into a Claude Project’s knowledge base, so even a plain chat on my phone knows who it’s talking to. It changes maybe monthly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. START HERE.md&lt;/code&gt;&lt;/strong&gt; is the operating manual - the naming conventions, the map of the folders, how the projects feed each other, and a list of things that are already decided so a fresh Claude doesn’t spend three paragraphs re-raising them. This one stays on disk. Cowork reads it live.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;N. &amp;lt;Project&amp;gt;/0. Brief.md&lt;/code&gt;&lt;/strong&gt; is the per-project state file, and it is the workhorse. It carries the seven sections from that distillation prompt - purpose, current state, decisions and why, dead ends, conventions, open threads, and how to work with me on this specific thing. When I finish a session, this is the file that gets updated. When I start a session, this is the file that gets read.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;00. Inbox&lt;/code&gt;&lt;/strong&gt; is a dump zone with zero rules. Screenshots, half-thoughts, exports, files I pulled off OneDrive, whatever. The rule is that capture has to be frictionless or you stop capturing, and deciding where a thing belongs is a completely separate job from writing it down. I empty it about once a week by pointing Claude at it and saying “file these.”&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;7. Resources&lt;/code&gt;&lt;/strong&gt; holds anything serving more than one project - my writing style reference, reusable prompts, and a running “field lessons” file that is every “dead ends” section from every brief pulled into one searchable place. That last one gets used more than I expected, because a dead end is a fact about a &lt;em&gt;tool&lt;/em&gt;, not about a project, and I go looking for it by symptom.&lt;/p&gt;

&lt;p&gt;The one rule that keeps this from rotting: &lt;strong&gt;the folder is the source of truth, and only &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. About Evan.md&lt;/code&gt; gets uploaded into Claude’s project knowledge.&lt;/strong&gt; Briefs stay on disk and get read live. If you upload a copy of a brief and then edit the original, you now have two versions and Claude will confidently use the stale one. Ask me how I know.&lt;/p&gt;

&lt;h2 id=&quot;dumping-in-everything-else&quot;&gt;Dumping in everything else&lt;/h2&gt;

&lt;p&gt;And you can extrapolate from there and drop in other information you need organized. For example, before I was doing this I had files saved on my OneDrive or otherwise on my PC locally. Previously I would drag and drop these into the chats/Projects manually and instruct Claude from there. As previously alluded to: This can become quite cumbersome and I’m storing data/information/documents across multiple streams with varying degrees of uniformity - another issue that the Second Brain concept aims to solve. To bring the quote up again: “Your brain is good at thinking and bad at storage, so stop asking it to store things.”&lt;/p&gt;

&lt;p&gt;With this in mind, I more or less grabbed every file I could find that I would want ingested and integrated into this data borg - spreadsheets from my OneDrive, odd Word documents with notes, other study guides, reference material, etc; basically anything I wanted organized by Claude, analyzed, stored for future reference while still providing easy enough access for me to update things manually (e.g. a financial spreadsheet I make manual updates to, but save directly in the Cogitator for Claude to access and store). Drop all of that in your inbox and re-prompt “Analyze and store these documents into the proper projects.”&lt;/p&gt;

&lt;p&gt;That run was 157 files and about 71 MB - screenshots, playbooks, study guide PDFs, four versions of my IT Field Manual, a pile of resume drafts going back to March. A few things worth knowing about how that actually went, because it was not purely magic:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;It sorted everything by project and put active work in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;1. Working/&lt;/code&gt; and finished material in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;2. Reference/&lt;/code&gt;, which is the split I would have made by hand and did not have to.&lt;/li&gt;
  &lt;li&gt;It found 28 groups of &lt;strong&gt;exact&lt;/strong&gt; duplicates by checksum - the same AZ-900 study guide saved in two places, and 26 screenshots that existed twice under different filenames because I had renamed them for the website. It kept one copy of each and wrote a small mapping file so the rename is still reproducible. That is roughly 9 MB of my own mess that I did not know I had.&lt;/li&gt;
  &lt;li&gt;It did &lt;strong&gt;not&lt;/strong&gt; delete anything. Everything it pulled out went into a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_to_delete/&lt;/code&gt; folder for me to review and empty myself, which is the correct behavior and I would be suspicious of a setup that did otherwise.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Then the actual payoff. An example:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Previously I had been using Grok for resume writing and help, storing all of my resume related documents in my OneDrive.&lt;/li&gt;
  &lt;li&gt;I created the Branding Project in Claude for the explicit purpose of helping me build a cohesive “brand” for myself - a resume being a part of this line of effort.&lt;/li&gt;
  &lt;li&gt;Up until I created this project, Claude had zero reference to work from other than what I’ve manually edited in its Memory or stored in a project context/instructions.&lt;/li&gt;
  &lt;li&gt;With this Second Brain, I simply dragged and dropped all of my previous resume stuff (master resume, tailored resumes, bulleted lists of notes, and so on) into the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;00. Inbox&lt;/code&gt;, pointed a Claude instance under the Branding umbrella, said organize/ingest these files, analyze them, and update my master resume based on the information you’re able to find in the Cogitator folder. For example, my new Microsoft certifications hadn’t been reflected anywhere in my OneDrive resume folder. But Claude knows that I passed/acquired these certifications from another Project. Since all the information canonically lives in one place, Claude is able to pull information together from different projects to enable its task under a single project.&lt;/li&gt;
  &lt;li&gt;And in a matter of minutes I had a brand new, updated, revised resume.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last bullet is the whole “thesis” in one example, so I want to be precise about what happened. The resume lives in the Branding project. The certifications live in the Cert Study Guides project. The homelab build that supplies half the resume’s technical bullets lives in IT Skill Development. Those are three separate Claude Projects that cannot see each other - &lt;strong&gt;but they are three folders in one vault, and a Cowork session reads all of it.&lt;/strong&gt; The Project boundary stops mattering the moment the material is on disk.&lt;/p&gt;

&lt;h2 id=&quot;things-that-broke-because-they-will-break-for-you-too&quot;&gt;Things that broke, because they will break for you too&lt;/h2&gt;

&lt;p&gt;I am not going to pretend this was clean nor quite as straightforward as I’ve alluded to - which is also a big point of writing this all down in article-form. Three things went wrong, all of them mine, and all three are the kind of thing you will hit if you build one of these.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. I renamed a file and broke the system’s own start-up prompt.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Early on, the master context file was called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CONTEXT.md&lt;/code&gt;. Two rounds of reorganizing later it was called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. About Evan.md&lt;/code&gt; - but the “start of session” prompt I had saved still told Claude to go read &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CONTEXT.md&lt;/code&gt;. So I opened a fresh chat, pasted my own prompt, and the first thing that happened was Claude telling me the file I had asked for did not exist.&lt;/p&gt;

&lt;p&gt;The fix is boring and it is the actual lesson: &lt;strong&gt;when you rename something, grep the whole vault for the old name.&lt;/strong&gt; Instructions that point at files rot the instant you move the files, and you will not notice because &lt;em&gt;you&lt;/em&gt; know where everything is.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. My instructions told Claude to upload files, so it did.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Every project brief had a line at the top saying “upload this file to that Project’s knowledge base.” That was written as a note to &lt;em&gt;me&lt;/em&gt;. A Cowork session with folder access read it as an instruction to &lt;em&gt;itself&lt;/em&gt;, and helpfully uploaded three files into my Branding project - creating exactly the duplicate-copies-that-drift problem I had spent an hour building rules to prevent.&lt;/p&gt;

&lt;p&gt;It did the reasonable thing. The instruction was just written for the wrong reader. &lt;strong&gt;If your notes-to-self live in a file an AI reads, they are not notes to self - they are instructions.&lt;/strong&gt; Write them accordingly, and be explicit about what the AI should never do on its own.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. I let a priority list turn into a gate.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;My context file has a “current focus” section so answers land in the right frame. I had let it end with the line “Everything else waits. This is the honest priority order, not the interesting one.”&lt;/p&gt;

&lt;p&gt;Read that as a human and it is a note about my own scheduling. Read it as an AI and it is a rule, so a fresh Claude opened by informing me that the thing I had just asked about was supposed to be waiting behind my A+ prep. Which - no. It is my vault and they are my questions.&lt;/p&gt;

&lt;p&gt;That one is now explicit: priorities are context, never gates. It can flag that something is outside my stated focus in one line, and then it does the work anyway. &lt;strong&gt;Be careful about writing anything into your context files that an AI could enforce against you.&lt;/strong&gt; You are building a reference, not a supervisor.&lt;/p&gt;

&lt;h2 id=&quot;the-actual-step-by-step&quot;&gt;The actual step-by-step&lt;/h2&gt;

&lt;p&gt;Here is the whole thing with the storytelling stripped out. This is genuinely all of it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Make an empty folder.&lt;/strong&gt; Anywhere you will actually see it. Mine is on my desktop, synced to OneDrive so it’s backed up. Name it whatever your heart desires.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Open a Cowork session and connect that folder.&lt;/strong&gt; In the Claude desktop app, add the folder as a connected folder. This is the step that lets Claude read and write files directly instead of you pasting things back and forth.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Ask Claude to build the structure - and tell it about you.&lt;/strong&gt; Not “make me a second brain.” Tell it what you do, what you’re trying to get out of it, what your existing projects are, and what you’re worried about losing. My opening prompt was five sentences of context and two bullet points of concerns, and that was enough.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Look at what it made and reject it if it’s wrong.&lt;/strong&gt; Seriously, I can’t stress this enough. The first layout it gives you will be reasonable and generic. If clicking through it feels annoying, say so. Better: point it at a folder you already navigate comfortably and say “make it look more like this.” Being specific is the entire skill.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Create one folder per Claude Project you already use&lt;/strong&gt;, with the same four things inside each: a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. Brief.md&lt;/code&gt;, a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;1. Working/&lt;/code&gt;, a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;2. Reference/&lt;/code&gt;, and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;9. Archive/&lt;/code&gt;. Add an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;00. Inbox/&lt;/code&gt; at the top level for dumping, and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Resources&lt;/code&gt; folder for anything that serves more than one project.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;6. Write the two files that make it work:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. About Evan.md&lt;/code&gt; (yours will have your name on it) - who you are, what you’re working on, how you want Claude to talk to you. This is the only file you upload into your Claude Projects.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. START HERE.md&lt;/code&gt; - your naming conventions, what lives where, and any rules you want a fresh Claude to follow.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;7. Distill your existing chats.&lt;/strong&gt; For each Project, find the two or three conversations actually carrying the work. Scroll to the bottom of each one, paste the distillation prompt from earlier in this article, and save the output. Drop them all in the Inbox.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;8. Point Claude at the Inbox and tell it to file everything.&lt;/strong&gt; Then keep doing that. Every time you have a pile of stuff - screenshots, exports, old documents, whatever - it goes in the Inbox and gets sorted later.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;9. End sessions by writing back.&lt;/strong&gt; This is the habit the whole thing depends on and the one people skip (I would also skip it if this was any harder/more complicated - hence Step 4). When you finish a conversation that produced something, tell Claude to update that project’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0. Brief.md&lt;/code&gt; before you close it. Ninety seconds. If you skip this step, you are just building a folder of files you stopped updating.&lt;/p&gt;

&lt;p&gt;That’s it. There is no step ten, there is no template to buy, and there is no course.&lt;/p&gt;

&lt;h2 id=&quot;wrapping-up&quot;&gt;Wrapping up&lt;/h2&gt;

&lt;p&gt;This is but a small example of how simple and streamlined this can be. I don’t have to hunt for documents anymore, I don’t have to remember what I did and did not take notes on, when I want to work on something with multiple inputs I don’t have to scramble across multiple systems to get my required data. None of it. Drag, drop, prompt, read, refine, repeat.&lt;/p&gt;

&lt;p&gt;The one honest caveat I’ll leave you with: the system is only as good as the writing-back habit. Everything above is logistics - the folders, the numbering, the conventions. The part that actually determines whether this is still useful to you in six months is whether you spend the ninety seconds at the end of a session telling it what happened. Forte’s CODE framing had four letters and Claude was right that only Distill matters. That is the one you have to do, and it’s the one no amount of tooling will do for you.&lt;/p&gt;

&lt;p&gt;That’s all there is to it. Nothing complicated, you don’t need to waste an hour watching dude-bro YouTube videos, and you sure as heck don’t need to pay money for someone else’s template (granted you need to pay for Claude/your AI model of choice, but come on you know what I mean). You already have the one tool you need to accomplish this - use it to your advantage and reap the rewards. And once you’ve set it up the way you want with your AI agent’s help - feel free to pick up some nice signs from Target to hang in your dining room; your friends think you’re super clever I promise.&lt;/p&gt;

&lt;p&gt;If you want the technical version of all this - the architecture, the migration numbers, and the three failure modes written up like an actual incident report instead of a guy talking about hammers - that’s here: &lt;strong&gt;&lt;a href=&quot;/projects/claude-second-brain/&quot;&gt;Claude Second Brain - Personal Knowledge System →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Now if you’d like a link to my affiliate marketing course, please see the link at… (kidding)&lt;/p&gt;
</description>
                <pubDate>Sat, 29 Aug 2026 09:30:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/claude-second-brain/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/claude-second-brain/</guid>
                
                <category>Claude</category>
                
                <category>Cowork</category>
                
                <category>Productivity</category>
                
                <category>Personal Knowledge Management</category>
                
                
            </item>
        
            <item>
                <title>The IT Field Manual, version 1.3</title>
                <description>&lt;p&gt;The &lt;strong&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;IT Field Manual&lt;/a&gt;&lt;/strong&gt; is now at version 1.3.
&lt;a href=&quot;/posts/it-field-manual-v1/&quot;&gt;Version 1.0&lt;/a&gt; went up five days ago at approximately
37,000 words across 23 sections. It now runs approximately 93,000 words across
31.&lt;/p&gt;

&lt;p&gt;This was not a rewrite. Sections 00 through 21 are unchanged and every tag from
version 1.0 still resolves, which was the whole point of tagging blocks instead
of numbering them. Three versions landed in five days because three different
piles of material came due at once: a set of course notes I had never filed, a
study guide I was working through, and the &lt;a href=&quot;/projects/m365-administration/&quot;&gt;Microsoft 365
project&lt;/a&gt; I finished over the weekend.&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt; &lt;/th&gt;
      &lt;th&gt; &lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Version&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;1.3, 23 August 2026&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Size&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;~93,000 words · 31 sections · ~440 headings&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;New since 1.0&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;§22 – §24 fundamentals · §26 – §30 cloud administration&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Corrections logged&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;54 in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[APX-C]&lt;/code&gt;, up from 16&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;Read / download&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;Online&lt;/a&gt; · &lt;a href=&quot;/assets/docs/it-field-manual.md&quot;&gt;raw Markdown&lt;/a&gt;&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;h2 id=&quot;11--the-layer-that-was-missing-underneath&quot;&gt;1.1 – the layer that was missing underneath&lt;/h2&gt;

&lt;p&gt;Version 1.0 had a real gap and I didn’t see it until I tried to explain
something out of it. The manual could tell me the command to run, the order to
run it in, and what the output should look like. It could not tell me &lt;em&gt;why&lt;/em&gt;
that was the right command, because there was no protocol or security layer
sitting under the operational one.&lt;/p&gt;

&lt;p&gt;Concretely: there was nothing on the OSI model, CIDR and subnet math, DNS
record types, the DHCP DORA sequence, TCP handshake semantics, cryptography,
AAA, or the Kerberos ticket flow. Those are the things a client and/or a senior
engineer asks about after the ticket is closed, and “the runbook said so” isn’t
an answer either of them accepts.&lt;/p&gt;

&lt;p&gt;Sections 22, 23, and 24 close it. The tag prefixes are deliberately split rather
than merged:&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;Prefix&lt;/th&gt;
      &lt;th&gt;What it holds&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[NET]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Network diagnostics – the commands you run&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[NETF]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Networking fundamentals – the reasoning underneath them&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SEC]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Security procedures – least privilege, incident response&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SECF]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Security fundamentals – crypto, AAA, threat taxonomy&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[SYSF]&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Systems and directory concepts – MBR/GPT, LDAP bind, SAM&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;When something is on fire I want the first one. When somebody asks me to justify
it, I want the second. Keeping the two apart means neither search has to wade
through the other, and it costs nothing but a naming convention.&lt;/p&gt;

&lt;h2 id=&quot;12-and-13--the-half-of-the-job-that-is-not-on-premises&quot;&gt;1.2 and 1.3 – the half of the job that is not on-premises&lt;/h2&gt;

&lt;p&gt;Version 1.0 was straightforward about where it came from. It came out of building a
hybrid environment on hardware, so it was strongest on Active Directory, Group
Policy, file services, and the sync bridge into the cloud. Actual cloud
administration was one thin section.&lt;/p&gt;

&lt;p&gt;Five sections now cover it:&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;§&lt;/th&gt;
      &lt;th&gt;Section&lt;/th&gt;
      &lt;th&gt;What it is for&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;26&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Microsoft Purview and data governance&lt;/td&gt;
      &lt;td&gt;Sensitivity labels, DLP, retention, eDiscovery, and the simulation-mode trap&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;27&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Copilot and agent administration&lt;/td&gt;
      &lt;td&gt;Oversharing readiness, licensing, RCD vs RSS vs RAC, agent governance&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;28&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Public DNS for mail&lt;/td&gt;
      &lt;td&gt;MX, autodiscover, SPF, DKIM, DMARC, DNSSEC, and wildcard records&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;29&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;Exchange Online administration&lt;/td&gt;
      &lt;td&gt;Message trace, quarantine, shared mailboxes, delegation, proxy addresses&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;strong&gt;30&lt;/strong&gt;&lt;/td&gt;
      &lt;td&gt;SharePoint Online and OneDrive&lt;/td&gt;
      &lt;td&gt;External sharing, guest access, and the people picker&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Sections 28, 29, and 30 are the M365 project written back into reference form,
with the lab’s hosts, domains, and tenant names stripped at the moment of
writing rather than later. Sections 26 and 27 came out of the Copilot and Agent
Administration Fundamentals material I am studying, with the exam scaffolding
removed – the passing score and the domain weighting do not transfer to a job,
and the product behavior does.&lt;/p&gt;

&lt;h2 id=&quot;two-new-rules-in-the-doctrine-section&quot;&gt;Two new rules in the doctrine section&lt;/h2&gt;

&lt;p&gt;Section 01 is ten rules that apply regardless of which technology is broken. It
hadn’t changed since version 1.0. It now has twelve.&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-11]&lt;/code&gt; – &lt;strong&gt;an override makes your diagnostics lie.&lt;/strong&gt; A wildcard DNS
record, an allowed-sender entry, and a DLP policy left in simulation mode are
three unrelated products doing the same thing: the test still runs, still
returns a result, and the result still looks like an answer. I wrote about
&lt;a href=&quot;/posts/when-the-system-says-it-worked/&quot;&gt;all three in more detail&lt;/a&gt; last week.&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[DOCTRINE-12]&lt;/code&gt; – &lt;strong&gt;read the screen before you diagnose.&lt;/strong&gt; Three separate
incidents on one project were answered by information already rendered on the
monitor in front of me. The most expensive was a DNS delegation I waited on for
forty-five minutes while the admin center displayed a banner saying DNSSEC was
enabled and Microsoft 365 DNS hosting doesn’t support it.&lt;/p&gt;

&lt;p&gt;That one is the image at the top of this post. It seemed only fair to leave it
there.&lt;/p&gt;

&lt;h2 id=&quot;the-correction-log-is-the-part-i-would-read&quot;&gt;The correction log is the part I would read&lt;/h2&gt;

&lt;p&gt;Appendix C records every claim in my own source material that turned out to be
wrong, alongside the correction and where it was verified. Version 1.0 shipped
with 16 entries. Version 1.3 has 54.&lt;/p&gt;

&lt;p&gt;A representative handful:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;The DKIM selector CNAME format changed in May 2025&lt;/strong&gt; and now includes a
dynamically assigned partition character. The target ends &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.dkim.mail.microsoft.com&lt;/code&gt;,
and truncated examples missing the trailing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.com&lt;/code&gt; are still circulating,
which leaves the record stuck on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CnameMissing&lt;/code&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Message trace is interactive out to 10 days, not 7.&lt;/strong&gt; Original client IP is
retained for 10 days and appears only in the downloadable reports.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;The quarantine retention default depends on where the policy was created.&lt;/strong&gt;
Thirty days in the Defender portal, 15 in PowerShell. The correct move is to
read it off the policy rather than quoting a number from memory.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Business Premium sensitivity labels can apply encryption&lt;/strong&gt;, which I had
filed as an E3 feature. What Business Premium actually lacks is automatic and
recommended labeling.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Sensitivity labels as a DLP condition are E5-tier.&lt;/strong&gt; On Business Premium the
policy saves without complaint and then silently never matches, which is a
worse failure than an error message.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Two entries are flagged as unverified rather than quietly dropped, because I
could not confirm them against Microsoft Learn, and a labeled maybe is worth
more than a confident wrong answer.&lt;/p&gt;

&lt;h2 id=&quot;the-instruction-i-did-not-follow&quot;&gt;The instruction I did not follow&lt;/h2&gt;

&lt;p&gt;The M365 project produced a tagged module written to be pasted straight into the
manual. Its own integration instructions said to add it as sections 23 through
26 under a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[PUR]&lt;/code&gt; tag prefix.&lt;/p&gt;

&lt;p&gt;Both were wrong by the time it was written. Sections 23 through 26 were already
occupied by the fundamentals layer added in 1.1, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[PUR]&lt;/code&gt; collides with the
existing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[PURV]&lt;/code&gt; prefix badly enough that a search for one returns both. So the
Purview material got merged into the existing §26 instead of standing up a
second Purview section, and the new material landed at 28 through 30.&lt;/p&gt;

&lt;p&gt;I’m noting this because it’s the failure mode of any generated documentation,
including the kind I produce with an assistant. &lt;strong&gt;The instructions were written
against a snapshot of the manual that was already four days stale.&lt;/strong&gt; Pasting
them in as written would have produced two Purview sections, a colliding tag,
and a contents table that lied about both. Documentation that arrives with
integration steps still has to be integrated by somebody holding the current
version.&lt;/p&gt;

&lt;h2 id=&quot;what-is-next&quot;&gt;What is next&lt;/h2&gt;

&lt;p&gt;Section 25, “Personal additions,” is still empty, and that’s still deliberate.
It is the landing zone for entries that have not earned a home yet, and an empty
section is a standing invitation to fill it.&lt;/p&gt;

&lt;p&gt;Moving forward: an Ubuntu Server file/print services build, which is the next
thing the manual has no coverage of at all, and converting the inline scripts
into a real &lt;a href=&quot;/reference/scripts/&quot;&gt;parameterized toolkit&lt;/a&gt;. Version 1.4 will most
likely be Linux and Samba.&lt;/p&gt;

&lt;p&gt;That all being said, the manual is public because a document I know somebody
might read is a document I write more carefully. If you spot something in it
that is wrong and/or out of date, I would be more than happy to hear about it –
that is what Appendix C is for, and it is the appendix I expect to keep
growing!&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;Read the Field Manual →&lt;/a&gt;&lt;/strong&gt; ·
&lt;strong&gt;&lt;a href=&quot;/reference/&quot;&gt;Browse the Reference Library →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
</description>
                <pubDate>Mon, 24 Aug 2026 09:00:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/it-field-manual-v1-3/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/it-field-manual-v1-3/</guid>
                
                <category>Documentation</category>
                
                <category>Microsoft 365</category>
                
                <category>DNS</category>
                
                <category>Purview</category>
                
                <category>Troubleshooting</category>
                
                
            </item>
        
            <item>
                <title>Three times in two days, a system told me it worked when it hadn&apos;t</title>
                <description>&lt;p&gt;I spent two days last week doing the unglamorous half of Microsoft 365 –
mail flow, shared mailboxes, distribution lists, SharePoint sharing, and a
DLP policy. The full write-up is up now:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/projects/m365-administration/&quot;&gt;Microsoft 365 Administration – Mail Flow, Collaboration &amp;amp; Data Governance →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;/projects/hybrid-ad-smb/&quot;&gt;last project&lt;/a&gt; built a hybrid environment from
bare metal, which answered &lt;em&gt;how do you stand this up&lt;/em&gt; and never once touched
&lt;em&gt;what do you do on Tuesday&lt;/em&gt; – and at a small business, Tuesday is almost
entirely email. Shared mailboxes, “where did my message go,” “why is this in
quarantine,” “can you give Sarah access to the sales inbox.” I had zero
hands-on with any of that, so it is what I went after this time.&lt;/p&gt;

&lt;p&gt;Nine root-cause findings came out of it. Three of them turned out to be the
same finding wearing different clothes, and that one is the reason this is a
post and not just a link to the case study.&lt;/p&gt;

&lt;h2 id=&quot;the-pattern&quot;&gt;The pattern&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;A wildcard DNS record.&lt;/strong&gt; I ran an inventory script expecting five
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DNS name does not exist&lt;/code&gt; answers for five missing records, and what came back
instead was five perfectly valid answers. The registrar’s default &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;*&lt;/code&gt; parking
CNAME was quietly answering for every subdomain that had no explicit record of
its own. Every “does this record exist?” check came back yes, and not one of
the five records existed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;An allow-list entry.&lt;/strong&gt; I had modified an anti-spam policy for a quarantine
test and then never reverted it, which contaminated the next task. So I added
an allowed-sender entry to stop the interference – which meant my subsequent
“is it reverted yet?” test would deliver successfully &lt;em&gt;whether or not the
revert had taken&lt;/em&gt;. I had destroyed my own ability to tell the two states apart,
and I had done it with a fix.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A DLP policy in simulation mode.&lt;/strong&gt; This is the one that actually bothers me.
Outlook showed the policy tip before send, message trace logged three DLP rule
evaluations, and I received a notification telling me I had shared content
containing a credit card number outside the organization. Every surface a
reasonable person would think to check said the policy was working.&lt;/p&gt;

&lt;p&gt;The card number arrived at the external recipient in plain text.&lt;/p&gt;

&lt;p&gt;I flipped the policy to enforcement and ran the identical test half an hour
later, and &lt;strong&gt;the message trace came back effectively identical&lt;/strong&gt; – same events,
same rule evaluations, same policy tip, same user notification. The only
difference anywhere in the chain was at the far end, where the recipient this
time received an encrypted &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.rpmsg&lt;/code&gt; wrapper instead of a readable card
number.&lt;/p&gt;

&lt;h2 id=&quot;why-this-is-worth-a-post&quot;&gt;Why this is worth a post&lt;/h2&gt;

&lt;p&gt;An override does not only change behavior; it changes what your tests
&lt;em&gt;report&lt;/em&gt;, and it does that silently. The test still runs, it still returns a
result, and the result still looks exactly like an answer.&lt;/p&gt;

&lt;p&gt;Had I deployed that DLP policy for a client and walked away, I would have told
them their data was protected. It was not. Nothing on the admin side would ever
have contradicted me.&lt;/p&gt;

&lt;p&gt;Four rules I am keeping:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;&lt;strong&gt;Remove overrides before testing, not after.&lt;/strong&gt; A revert verified while an
override is still active is not verified.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Verify at the far end.&lt;/strong&gt; DNS answering is not mail flowing. A policy tip
is not enforcement. Check what the recipient actually received.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;When a result matches what you expected, ask what the test could not have
told you.&lt;/strong&gt; Agreement is not confirmation.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;In an inherited environment, inventory the overrides before you trust any
diagnostic.&lt;/strong&gt; Wildcard DNS records, allow lists, disabled policies,
simulation-mode policies – all invisible until you go looking for them
specifically.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2 id=&quot;the-other-one-i-earned-the-hard-way&quot;&gt;The other one I earned the hard way&lt;/h2&gt;

&lt;p&gt;Separately, and more embarrassingly: I burned approximately forty-five minutes
waiting on a DNS delegation to Microsoft that was never going to work, because
DNSSEC was enabled on the domain and Microsoft-hosted DNS does not support it.&lt;/p&gt;

&lt;p&gt;The admin center had a banner saying exactly that. On screen. The whole time.&lt;/p&gt;

&lt;p&gt;Two more of the same shape are in the write-up – a SharePoint share that
“never arrived” where the confirmation dialog had named the actual recipient,
and an unexplained &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Drop&lt;/code&gt; in a message trace whose detail line carried an SMTP
&lt;em&gt;success&lt;/em&gt; code. In all three cases the answer was already rendered on the screen
I was staring at, well before I started building a theory about what might have
gone wrong.&lt;/p&gt;

&lt;p&gt;Reading the banners and/or the confirmation dialogs is a cheaper habit than the
alternative.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;/projects/m365-administration/&quot;&gt;Read the full case study →&lt;/a&gt;&lt;/p&gt;
</description>
                <pubDate>Sun, 23 Aug 2026 18:00:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/when-the-system-says-it-worked/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/when-the-system-says-it-worked/</guid>
                
                <category>Microsoft 365</category>
                
                <category>Exchange Online</category>
                
                <category>DNS</category>
                
                <category>Purview</category>
                
                <category>Troubleshooting</category>
                
                
            </item>
        
            <item>
                <title>The IT Field Manual, version 1.0</title>
                <description>&lt;blockquote&gt;
  &lt;p&gt;&lt;strong&gt;Update, 24 August 2026.&lt;/strong&gt; The manual is now at &lt;strong&gt;version 1.3&lt;/strong&gt; – roughly
93,000 words across 31 sections, with a fundamentals layer and five new cloud
administration sections. Everything below still holds, with one exception:
“Personal additions” moved from §22 to &lt;strong&gt;§25&lt;/strong&gt; when the fundamentals sections
were added. See &lt;strong&gt;&lt;a href=&quot;/posts/it-field-manual-v1-3/&quot;&gt;what changed in v1.3&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I have published the &lt;strong&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;IT Field Manual&lt;/a&gt;&lt;/strong&gt; – the
single document I work out of. It sits at the top of a new
&lt;strong&gt;&lt;a href=&quot;/reference/&quot;&gt;Reference Library&lt;/a&gt;&lt;/strong&gt; alongside the build playbooks and, before
long, a script toolkit.&lt;/p&gt;

&lt;p&gt;It is version 1.0 of a living document rather than a finished one, and it is
going to stay that way.&lt;/p&gt;

&lt;h2 id=&quot;the-problem-it-solves&quot;&gt;The problem it solves&lt;/h2&gt;

&lt;p&gt;For the first few months of building things I took notes the way most people
take notes: a file per topic, named after whatever I was doing that day.
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ad-notes.md&lt;/code&gt;. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;intune-stuff.md&lt;/code&gt;. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;powershell-things.md&lt;/code&gt;. A folder of them.&lt;/p&gt;

&lt;p&gt;The failure mode showed up the first time I hit a problem I had already solved.
I knew I had written down the fix for Folder Redirection failing with Event ID&lt;/p&gt;
&lt;ol&gt;
  &lt;li&gt;What I could not remember was which file it lived in, whether I had filed
it under Group Policy and/or file permissions, or what I had named it. Finding
it again took longer than solving the thing from scratch would have taken.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Notes scattered across a dozen files are not a reference – they are a search
problem you built for yourself, and the bill comes due at the worst moment.&lt;/p&gt;

&lt;h2 id=&quot;what-actually-changed&quot;&gt;What actually changed&lt;/h2&gt;

&lt;p&gt;One file. Thirty-seven thousand words. And one rule that makes it work:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Every block carries a bracketed tag. Search the tag, not the prose.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A note about domain join failures is tagged &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[AD-JOIN-FAIL]&lt;/code&gt;, Group Policy
triage is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[GPO-TRIAGE]&lt;/code&gt;, and the Service Connection Point trap that cost me an
afternoon is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[HYB-SCP]&lt;/code&gt;. When I write a new entry that relates to an older one
I reference the tag rather than the section, and that reference still resolves
after I have reorganized the document twice, because the tags stay stable even
when the section numbers do not.&lt;/p&gt;

&lt;p&gt;The practical effect: Ctrl+F, type the tag, land on the answer. No folder
structure to remember, no naming convention to be consistent about, no decision
about where something belongs.&lt;/p&gt;

&lt;h2 id=&quot;what-is-in-it&quot;&gt;What is in it&lt;/h2&gt;

&lt;p&gt;Twenty-three sections. The ones I open most:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;§18 – Error → cause → fix index.&lt;/strong&gt; The error text goes in exactly as it
appears on screen, and the index does the rest. This is the front door most
days.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;§01 – Troubleshooting doctrine.&lt;/strong&gt; Ten rules that transfer between every
technology in the rest of the manual. &lt;em&gt;“The error message describes the
symptom, not the cause.”&lt;/em&gt; &lt;em&gt;“A backup you have never restored from is a
hypothesis.”&lt;/em&gt;&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;§06 – Greenfield build order.&lt;/strong&gt; Fifteen phases, in the order the work should
be done rather than the order you learn it in.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;§15 – Standard operating procedures.&lt;/strong&gt; Onboarding, offboarding, workstation
deployment, monthly maintenance, FSMO seizure, compromised account response.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;§16 – Assessing an inherited network.&lt;/strong&gt; A discovery block to run before
touching anything, and triage trees for what you will find.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Plus PowerShell fundamentals, network diagnostics, AD operations, Group Policy,
file services and permissions, hybrid identity, Intune, Microsoft 365, Azure,
Windows client builds, storage, decommissioning, a script toolkit pattern, and
documentation templates.&lt;/p&gt;

&lt;h2 id=&quot;the-rules&quot;&gt;The rules&lt;/h2&gt;

&lt;p&gt;Three, written into the manual’s own maintenance protocol:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Strip the client.&lt;/strong&gt; No real hostname, IP, username, or domain ever goes in –
the placeholder gets substituted at the moment of writing rather than later. A
manual full of real client detail is a manual nobody can ever be handed, and the
retroactive cleanup never actually happens.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Record the fix, not the workaround – and a workaround that had to be used
gets labeled as one.&lt;/strong&gt; A workaround is a modification to the environment, and
the environment remembers it long after the person who made it has forgotten.
Unlabeled workarounds are the most expensive category of self-inflicted
troubleshooting there is.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Date anything Microsoft can change.&lt;/strong&gt; Portal click-paths, product names, and
CLI switches rot on their own schedule, while facts about protocols – Kerberos
clock skew, DNS SRV records, NTFS evaluation order – do not rot at all. The
first kind carries a date; the second kind does not need one.&lt;/p&gt;

&lt;h2 id=&quot;why-publish-it&quot;&gt;Why publish it&lt;/h2&gt;

&lt;p&gt;Two reasons, and only one of them has anything to do with other people.&lt;/p&gt;

&lt;p&gt;The honest one first: a document I know is public is a document I write more
carefully. Vague notes survive in private. They do not survive being read.&lt;/p&gt;

&lt;p&gt;The other is that this is the artifact that actually represents the work. The
&lt;a href=&quot;/projects/hybrid-ad-smb/&quot;&gt;hybrid AD case study&lt;/a&gt; describes an environment I
built and then deliberately destroyed, so the network itself is gone and what
is left of it is the documentation. The only question worth asking about that
documentation is whether it was good enough to rebuild from, and that one got
answered when I rebuilt the environment out of my own playbook in 5 hours 58
minutes with no rework.&lt;/p&gt;

&lt;p&gt;The manual is the same bet, made larger.&lt;/p&gt;

&lt;h2 id=&quot;what-is-next&quot;&gt;What is next&lt;/h2&gt;

&lt;p&gt;Section 22 is titled “Personal additions” and is currently empty. That is
deliberate – it is where entries land before they get filed properly, and an
empty section is a standing invitation to fill it.&lt;/p&gt;

&lt;p&gt;Moving forward: converting the inline scripts into a real
&lt;a href=&quot;/reference/scripts/&quot;&gt;parameterized toolkit&lt;/a&gt;, and a second playbook once the
Ubuntu file and print services build is finished.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/reference/field-manual/&quot;&gt;Read the Field Manual →&lt;/a&gt;&lt;/strong&gt; ·
&lt;strong&gt;&lt;a href=&quot;/reference/&quot;&gt;Browse the Reference Library →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
</description>
                <pubDate>Wed, 19 Aug 2026 20:00:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/it-field-manual-v1/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/it-field-manual-v1/</guid>
                
                <category>Documentation</category>
                
                <category>PowerShell</category>
                
                <category>Active Directory</category>
                
                
            </item>
        
            <item>
                <title>I built a hybrid AD environment, tore it down, and built it again</title>
                <description>&lt;p&gt;I have been building a simulated small-business network in my basement – a
hybrid Active Directory and Microsoft 365 environment of the kind a 5–50 seat
company actually runs. The full case study is up now:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;/projects/hybrid-ad-smb/&quot;&gt;Hybrid Active Directory &amp;amp; Microsoft 365 Environment – SMB Simulation →&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The part I think matters most, and this is just my own read on it, is that I
built the whole thing twice.&lt;/p&gt;

&lt;p&gt;Round 1 was tutorial-led and out of order, and what it produced wasn’t a
network so much as a list of failures. A &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.local&lt;/code&gt; domain name that forced me to
rewrite every UPN later. Group Policy linked to an OU that held no computer
objects, so it never applied to anything. Two separate administrative lockouts
from permissions I set incorrectly. Every one of those got traced back to a
root cause instead of worked around, and every one became a section of a
playbook I wrote for myself.&lt;/p&gt;

&lt;p&gt;Round 2 was the real test: rebuild the environment from that playbook, treat
the playbook as a checklist, and find out whether the documentation held up
under somebody using it. It held up. Five hours and fifty-eight minutes, bare
metal to a hybrid-joined client with Intune-deployed apps and a replicating
second domain controller, with no rework.&lt;/p&gt;

&lt;p&gt;Three problems from the build are written up in full in the case study, with
symptom, diagnosis, and resolution:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;A domain join failing against a domain controller that answered &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ping&lt;/code&gt;
without complaint – the cause was Kerberos clock skew, not DNS.&lt;/li&gt;
  &lt;li&gt;Hybrid Entra join failing after the users had synchronized perfectly – the
Service Connection Point had never been written, because that step sits
outside the linear Entra Connect wizard.&lt;/li&gt;
  &lt;li&gt;Intune enrollment failing completely silently – a group-based licensing group
that had been created and assigned a SKU and then never given any members.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last one threw no error and/or warning in any console, which is the sort
of thing you don’t learn until you walk into it.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;/projects/hybrid-ad-smb/&quot;&gt;Read the full case study →&lt;/a&gt;&lt;/p&gt;
</description>
                <pubDate>Wed, 19 Aug 2026 12:00:00 -0600</pubDate>
                <link>https://evanireland.tech/posts/hybrid-ad-smb-round-2/</link>
                <guid isPermaLink="true">https://evanireland.tech/posts/hybrid-ad-smb-round-2/</guid>
                
                <category>Active Directory</category>
                
                <category>Entra ID</category>
                
                <category>Documentation</category>
                
                
            </item>
        
    </channel>
</rss>