From 59ec1247ce4cd1a49c2de7604b582b2b8b86f97b Mon Sep 17 00:00:00 2001 From: weishen Date: Sat, 19 Sep 2026 12:33:03 +0800 Subject: [PATCH] course notes: IT Support and Service Desk Jobs crash course (37 videos) --- ...Support-Service-Desk-Crash-Course-Notes.md | 1059 +++++++++++++++++ 1 file changed, 1059 insertions(+) create mode 100644 knowledgebase/course-notes/IT-Support-Service-Desk-Crash-Course-Notes.md diff --git a/knowledgebase/course-notes/IT-Support-Service-Desk-Crash-Course-Notes.md b/knowledgebase/course-notes/IT-Support-Service-Desk-Crash-Course-Notes.md new file mode 100644 index 00000000..89d00758 --- /dev/null +++ b/knowledgebase/course-notes/IT-Support-Service-Desk-Crash-Course-Notes.md @@ -0,0 +1,1059 @@ +# IT Support and Service Desk Jobs — Crash Course for Beginners +# Course Notes (structured from transcripts) + +Source: /Users/weishen/mnt/volume2/knowledgebase/course/IT Support and Service Desk Jobs - Crash Course for Beginners +Generated: 2026-09-19 +Note: Chapter 10 (Final Quiz - Top 30 Technical Interview Questions) is an online Udemy quiz link only, no transcript content. 37 video transcripts across 10 chapters. + +--- + +## Chapter 1 — 1. Introduction + +**Core Insights** +- Instructor Marius (20+ years in IT: web developer, networking, Microsoft and Cisco exams, manager with degrees in HR and IT, consultant) built the course over ~4 months as a real-world journey into support/service desk engineering. +- Part 1 covers roughly 70–80% of what a support engineer needs to know — enough to start a job. Part 2 suits people with 5–6 months on the job: monitoring, virtualization, deeper troubleshooting, procedures, career advancement, web applications, interview questions, challenges and quizzes. +- The course simulates a real service desk with the industry-standard Jira Service Desk instead of theory/videos — you receive real tickets from a manager and an end user and click through resolving them. +- SLA is taught by watching a live ticket, not just a definition: e.g., 4 hours to reply, 8 hours to sort it out; you see the ticket status change as you work. + +**Detailed Notes** +- Approach: "not just talk" — real service desk application, simulated environment; hundreds/thousands of similar tools exist, but seeing everything in action transfers to your own device. +- Part 1 topic map: general skills, hardware, operating systems, networking, basic procedures, service desk tools. +- Viewer expectations: you have to memorize facts, read documentation, and play with the solutions yourself — the course shows the starting point, no boring lectures or long definitions. + +**Action Items** +- Practice inside a real service desk application alongside the lectures rather than just watching. +- After a few months in a support job, evaluate whether Part 2 (monitoring, virtualization, career path) is needed. + +**Key Terms/Concepts** +- **SLA (Service Level Agreement)**: the time window you must act within on a ticket — e.g., answer in 4 hours, resolve in 8. +- **Support/Service Desk Engineer**: entry-level IT role the course trains for. + +## Chapter 1 — 2. IT Support Roles + +**Core Insights** +- A service desk provides IT services under a contract between your company and the customer; your job is to sort out the problem, answer the question, or recommend a solution. +- First-line support is the first point of contact: phone, email, chat, ticket, or discussion board — supporting either internal users or external companies. +- Core workflow: figure out the problem → log it in a specialist (ticketing) system → give a quick fix, or escalate to second-line support (more knowledge, more tools); second line owns backends, application deployment, big upgrades and projects. +- It is possible to start knowing almost nothing (some adverts only require working English and the company trains you), but knowing basics makes it far less stressful. +- Soft skills are ~90% of hiring decisions — technical skills can be taught, attitude cannot. + +**Detailed Notes** +- Knowledge baseline: IT infrastructure (laptops, workstations, printers, phones), two operating systems (Windows, Linux), basic networking, web solutions, procedures and frameworks — the most popular framework is ITIL (which includes SLA). +- Prioritization: systems usually carry a priority value; P1 is the highest (everything down), e.g., a website down that sells online outweighs "John can't print but needs it next week." +- Certificates are not crucial at agent level — CompTIA, Microsoft MTA, Cisco CCNA for tech; PRINCE2/PMP to prove project knowledge; the company will train you. +- Interview tip: showing eagerness to learn and willingness to take extra steps gets you the job. + +**Action Items** +- Practice the log → quick-fix → escalate flow and judging ticket priority. +- Build basics: one Windows + one Linux OS, basic networking, ITIL/SLA concepts, web solutions. +- Prepare to demonstrate soft skills (politeness, helpfulness, punctuality, communication) since they dominate hiring decisions. + +**Key Terms/Concepts** +- **First-line support**: initial contact, triage, logging, quick fixes, escalation. +- **Second-line support**: backend infrastructure, deployments, upgrades, complex cases. +- **ITIL**: the most popular IT service-management framework/best practices. +- **P1**: highest-priority ticket (service totally down). + +## Chapter 1 — 3. Tools you Will Need Jira Service Desk, Support Tools, and Password Managers + +**Core Insights** +- Real support work uses four tool types: communication (email + messenger), a ticketing system, a remote-support tool, and a password manager. +- Ticketing system = Jira Service Desk (Atlassian): free for up to 3 agents in the cloud, nothing to install. +- End users raise tickets; agents work from a queue: assign the ticket, then drive status (To Do → In Progress → resolved). +- Remote support (TeamViewer as the example): a viewer on the agent's PC and an agent ("server") installed on every customer device — connect by picking the device. +- KeePass, an offline password manager: one master password, one entry per application/server, built-in password generator, and clipboard auto-clear (~12 s) for safety. + +**Detailed Notes** +- Communication: Microsoft Exchange (on-prem email server) or Exchange Online (cloud-hosted email); Outlook via web or Microsoft Office; Skype-style messengers. +- Getting Jira Service Desk: atlassian.com → Products → Jira Service Desk → "Try it free"; the Pricing page shows a free cloud option up to 3 agents — no install. +- Demo layout: General Service Desk (tickets from end users), Tasks (assignments from the manager), plus demo/old tickets. +- Example ticket: Kate Brown — "Cannot open doc1.docx"; the reporter immediately gets an email that someone will look at it. +- Agent view: the queue is a list of tasks; the case shows the reporter but is not yet assigned → assign it to an engineer or yourself; status "To Do" means nobody started. +- Remote support pattern: open the tool → see all connectable laptops/computers → select one → authenticate with username/password. +- KeePass usage: right-click to add entries in groups (e.g., Exchange mailbox username); generate passwords — 9 characters (uppercase, lowercase, digits) is acceptable for a local network, but internet-facing systems need stronger (e.g., 12 characters + special); copying a password clears the clipboard after 12 seconds so it can't be pasted elsewhere by accident. + +**Action Items** +- Create a free Jira Service Desk cloud account and click through queues, assignment, and status changes. +- Install and explore a password manager (e.g., KeePass): create entries, generate and copy passwords. +- Try a remote-support tool (TeamViewer) between two devices to learn the connect flow. + +**Key Terms/Concepts** +- **Queue**: the list of tickets/tasks awaiting an agent. +- **To Do**: ticket status meaning nobody has started work. +- **KeePass**: offline password manager with a single master password. +- **TeamViewer**: remote desktop/support tool (viewer + device agents). + +## Chapter 1 — 4. Let's Simulate Your First Days at Service Desk + +**Core Insights** +- Day 2 scenario: manager John emails three tickets; each names a device (e.g., T01) plus the task (check the Windows 10 edition on T01). +- Golden rule: the first thing after opening a ticket is to change its status (To Do → In Progress) before touching anything else — otherwise nobody knows you started working. +- SLA is tracked live: "time to first response" was green — 4 hours to assign the ticket to yourself; sometimes a status change alone counts as the first response, sometimes you must reply or add a note. +- Full resolution loop: acknowledge → connect remotely using credentials from the password manager → inspect → answer the ticket → set status Completed/Closed. + +**Detailed Notes** +- Ticket anatomy: device name (T01, a laptop) + action ("check the edition of Windows 10" — editions: Home, Professional, Enterprise). +- Two support apps: one keeps usernames/passwords (KeePass example), one connects remotely — support tool with a desktop shortcut listing all connectable machines (TeamViewer as example). +- Communication: internal "note" (only for you/team) vs "reply to customer"; being proactive ("Hi John, I am working on it") is good practice. +- Remote session: double-click T01 → username/password from KeePass → connected → right-click This PC → Properties → shows "Windows 10 Pro". +- Close the remote session, return to the ticketing system, reply "T01 has Windows 10 Pro installed" — put the key fact in bold so the manager spots it — then set status Completed, then Closed. + +**Action Items** +- Practice the golden loop: update ticket status immediately upon starting, then work — never leave a ticket in a stale state. +- Drill the flow on a lab machine: connect remotely, read OS/edition info, log the finding, close the ticket. +- Learn Windows editions (Home/Professional/Enterprise) and where to find them (System Properties). + +**Key Terms/Concepts** +- **In Progress / Completed / Closed**: ticket lifecycle states that drive SLA tracking. +- **Time to first response**: SLA metric — e.g., 4 hours to first action/assignment. +- **Assignment**: attaching the ticket to yourself or another engineer before work starts. + +--- + +## Chapter 2 — 1. Overview of Hardware + +**Core Insights** +- POST (Power On Self Test) runs on every device at boot to verify hardware is ready before the OS loads. +- BIOS is the low-level firmware that controls startup and displays key hardware info: product name, BIOS version, CPU, RAM, disks, and the OEM Windows product key. +- Knowing hardware details (CPU generation, RAM size, disk type) lets you estimate a device's age and capabilities. +- Hands-on practice on cheap test hardware is the recommended way to learn hardware. + +**Detailed Notes** +- POST: a set of startup procedures on laptops, desktops, and phones; checks the fan and power supply; if a critical issue is found, the boot process stops to protect the device. +- BIOS = Basic Input Output System — low-level software that controls basic functions and starts Windows, macOS, or Android. +- Accessing BIOS setup: no standard key — check the manual; commonly F1, F2, F10, F11 pressed at power-up; some devices (e.g. Lenovo Yoga) have a dedicated physical button. +- Lenovo Yoga example: BIOS screen shows product name and BIOS version; BIOS can be updated (e.g. for compatibility with a new hard disk or new CPU) but it is a dangerous low-level procedure — a failed update is very hard to recover from. +- CPU: Intel model numbers indicate generation (e.g. i3-4xxx = 4th Gen, ~7-8 years old at recording; 8th/9th Gen were current then). +- RAM: 8 GB (8192 MB) is enough for almost all applications and the standard today, except for gaming. +- Storage: two drives — a standard HDD plus an SSD (solid state, flash-based, fast). +- Licensing: Windows OEM license is coded into the BIOS/system board; after replacing a failed hard disk you can reinstall Windows with no product key. +- Learning hardware: read reviews and magazines (graphics cards, power supplies, phones); download the system-board manual (screenshots + definitions); buy an old desktop PC (~$20) as a test device. + +**Action Items** +- Get any device, enter its BIOS, and identify product name, BIOS version, CPU, RAM, and disks. +- Download the manual for your system board and study the BIOS settings. +- Acquire a cheap old desktop (~$20), open it, and inspect the hardware and ports. + +**Key Terms/Concepts** +- **POST**: Power On Self Test, boot-time hardware self-check. +- **BIOS**: Basic Input Output System, low-level firmware controlling device startup. +- **SSD**: Solid State Drive, fast flash-based storage. +- **OEM product key**: Windows license embedded in the BIOS/system board. + +## Chapter 2 — 2. Overview of Hardware - Part 2 + +**Core Insights** +- Port identification is a core general skill; story: a web-support job applicant failed an interview by not knowing which port connects a laptop to a projector (HDMI). +- USB color/size indicates speed: gray USB 2.0 vs colored USB 3.x vs small USB-C. +- Video connectors differ: HDMI carries video + audio; DVI and VGA are video-only; DVI (digital) is better than VGA (analog). + +**Detailed Notes** +- Interview example: applicant for web support engineer at a hosting company was asked to connect a laptop to a projector and had no idea which port to use; the company refused to let him work with customers if he did not know HDMI. +- Back panel overview: USB ports, Wi-Fi antenna connectors, USB 3.1 ports. Gray USB ports are usually USB 2.0 (old standard); yellow/red/blue USB ports are much faster (USB 3.x); USB-C is a small port, even faster and better. +- Network Interface Card (NIC) port: connect a network cable for LAN/Internet access. +- Audio ports: microphone, line in/out, speakers; an optical connection gives the highest quality audio. +- Connector quick reference: USB → printers, mice, keyboards; HDMI/DVI/VGA → screens and graphics cards; HDMI → video AND audio; DVI and VGA → video only; DVI is better than VGA because it is digital while VGA is analog. +- The lecture closes by introducing one more port type (Ethernet) as a preview. + +**Action Items** +- Identify every port on a real PC back panel and state its purpose. +- Memorize which connectors carry audio (HDMI) vs video only (DVI, VGA). +- Practice connecting a laptop to a projector or monitor. + +**Key Terms/Concepts** +- **USB 2.0 vs 3.x**: older vs faster USB standards, often told apart by color (gray vs blue/red/yellow). +- **HDMI**: one cable carrying high-definition video and audio. +- **DVI/VGA**: video-only display connectors; DVI digital, VGA analog. +- **NIC**: Network Interface Card — the wired Ethernet (RJ-45) port. + +## Chapter 2 — 3. Basic IT Procedures + +**Core Insights** +- Support work means following documented procedures step by step, not inventing unique solutions. +- Customer authorization comes first: verify the caller is entitled to open a ticket (PIN, serial number, prepaid contract). +- Requests are classified (incident, request for change, task) and each type has its own procedure. +- Do not memorize procedures — read them from the book/checklist so you never skip a step (pilot checklist analogy). + +**Detailed Notes** +- Templates: every ticket to a support company receives the same greeting template; templates are standard for external customers (informal greetings only OK for internal users in small companies). +- Basic call procedure: receive client call → authorize the customer (PIN number, serial number, or proof of advanced payment) → verify they can open a ticket. +- Wrong/invalid PIN: follow the separate document describing that case; be extremely polite, never dismissive. +- Then classify: incident = something broken (cannot print, cannot send email, cannot open a website); request for change = planned modification (update the system, add memory); task = e.g. recommend a solution; many other options exist. +- In practice you receive a book of procedures and just follow it; agents put callers on hold — 'May I put you on hold for a minute? I have to check something.' +- Pilots are not allowed to run a checklist without a piece of paper or computer listing all steps, because you don't want to miss a step — same logic applies to support. +- Even if a company asks you to memorize, you should know where to start. + +**Action Items** +- Practice classifying sample tickets as incident vs change vs task. +- Always verify entitlement (PIN/serial) before working a ticket, politely. +- When stuck, open the procedure document and follow it literally. + +**Key Terms/Concepts** +- **Incident**: an unplanned breakage ('I cannot print'). +- **Request for Change**: planned modification (update system, add memory). +- **Task**: non-breakage work such as recommending a solution. +- **Authorization**: proving a caller is entitled to support (PIN/serial). + +## Chapter 2 — 4. A User Needs Your Help! + +**Core Insights** +- First action on every ticket: change its status (to In progress), then acknowledge the user. +- Answer the real question (which ports for a screen) with a clearly labeled screenshot, not bare text. +- Annotate images and paste them directly into the ticketing system (Snipping Tool → Edit → Copy, no file save needed). +- Close the loop: update status to resolved so everything is green and the customer is happy. + +**Detailed Notes** +- Scenario: Kate opens a ticket — she wants to buy a new system board and asks which port she can use to connect her screens. +- Step 1: change ticket status to In progress; reply 'Hi Kate, I'm working on it'. +- Open the board picture and analyze the ports: on the left two ports for mouse and keyboard (PS/2-style); VGA and DVI for a screen; USB; network card port; audio ports. +- Prepare the answer: label all ports clearly so a non-expert understands, and keep the note neat. +- Capture the annotated board with the Windows Snipping Tool; no need to save the image — Edit → Copy, then paste it straight into the ticket. +- Send the final reply with the image and your signature; then change the status again to done — everything green, happy customer. +- Expect follow-up questions: difference between VGA and DVI, whether both can be used at the same time, whether two screens can be connected. + +**Action Items** +- Practice the full ticket loop: status → acknowledge → investigate → annotated answer → resolve. +- Learn to annotate screenshots and paste clipboard images into ticketing tools. +- Prepare answers for common follow-ups (VGA vs DVI, dual monitors). + +**Key Terms/Concepts** +- **Ticket status**: lifecycle state (In progress → resolved), shown green when closed. +- **Snipping Tool**: Windows screenshot utility; images can be copied to clipboard without saving. +- **PS/2 port**: round connector for mouse/keyboard found on the board photo. + +## Chapter 2 — 5. Commands you Need to Know + +**Core Insights** +- Three core Windows commands for support: ipconfig, ping, shutdown — all run from cmd (Command Prompt). +- ipconfig shows the device's IP address; an IP address identifies a device on a network, like an ID, and is used to send data between two points. +- ping verifies a remote device is alive before starting a session; 8.8.8.8 (Google) is the classic test target. +- shutdown can reboot, log off, or power off, with a time delay and a force flag — and can be aborted. + +**Detailed Notes** +- cmd: type cmd in Start to open Command Prompt; Properties lets you adjust font, layout, and colors (e.g. white background for readability). +- ipconfig: display/verify IP configuration; IP address = device identifier on a network, like an ID; devices use IP addresses to communicate and exchange data. +- ping : asks 'are you alive?' — check a device is up before starting a session to avoid failed transfers. Most popular target: 8.8.8.8 (Google, ~99.99% uptime); no reply → your internet is down. Windows sends 4 echo messages and reports 4 replies. +- shutdown usage: shutdown /r /t 60 /f — /r = reboot, /t = delay in seconds (60), /f = force all applications to close; the system warns 'your PC will be rebooted in one minute'. Cancel the schedule with shutdown /a (restart cancelled). +- shutdown supports reboot, logoff, or shutdown of a device from cmd; shutdown /? lists all available options. + +**Action Items** +- Open Command Prompt and run ipconfig to identify your IP address. +- Ping 8.8.8.8 and an internal device to verify connectivity. +- Try shutdown /r /t 60 /f and cancel it with shutdown /a; read shutdown /? for the full option list. +- Customize cmd properties (font/layout/colors) for readability. + +**Key Terms/Concepts** +- **cmd**: Windows Command Prompt, the shell for executing commands. +- **IP address**: unique identifier of a device on a network, used for routing data between endpoints. +- **ping**: ICMP-based reachability test; replies confirm the host is alive. +- **8.8.8.8**: Google's public DNS server, 99.99% uptime, standard ping target. + +--- + +## Chapter 3 — 1. Task 1 - Benchmarking an SSD + +**Core Insights** +- The manager originally sent three tasks; only one was completed before, so two remained open — service desk work means you do not ignore your manager's tickets. +- Task: connect to the remote machine T-01 and benchmark its SSD (solid state disk) with a dedicated disk-testing application — no option changes needed, just run the test. +- The Knowledge Base (KB) is the primary self-service resource: a KB article explained what to do, which software to use, and provided the link to it. +- Evidence is sent back through safe channels: a company network drive, or your own cloud (e.g., Microsoft OneDrive, iDrive) — never a customer's account. +- Final verdict: not the fastest SSD out there, but a decent budget SSD — then the ticket is closed. + +**Detailed Notes** +- Setup: the laptop already has an SSD installed; the job is to measure how fast it reads and writes. +- Workflow: ticket was pre-assigned → change its status → connect to T-01 → paste the KB link → open the application. +- The benchmark app is simple: open it, run a test, do not change any options, press Start; it performs file/read-write operations to verify how fast the disk is. +- First-time tool use is expected — someone will show you how; in most cases it is really simple. +- Uploading the screenshot: use a dedicated network drive if available; otherwise your own cloud (OneDrive, iDrive) or whatever the company provides — do not use a customer's OneDrive or account. +- Sharing the result: create a share link restricted to yourself, then copy/paste or drag-and-drop the screenshot into the chat message to the manager (John), save, done. +- Close-out: answer the question (is it a fast SSD? — decent budget SSD, not the fastest) and close the ticket. + +**Action Items** +- Practice the full ticket lifecycle: KB lookup → remote connect → run tool → capture screenshot → share evidence properly → report to manager → close ticket. +- Learn to interpret SSD benchmark results (read/write speeds) to judge whether a drive is budget or high-end. +- Set up a personal cloud share (OneDrive/iDrive) as an alternative when no network drive exists. + +**Key Terms/Concepts** +- **SSD (Solid State Drive)**: fast storage with no moving parts; its read/write speed is measured by benchmark tools. +- **Knowledge Base (KB)**: internal documentation agents consult for steps, tools, and links on common tasks. +- **Ticket**: a recorded, assignable service request with status (in progress → resolved); closes after the work is done and verified. +- **Network drive / cloud share**: sanctioned storage for evidence screenshots; customer accounts must never be used. + +## Chapter 3 — 2. Task 2 - Installing an Agent + +**Core Insights** +- Big-company service desks support hundreds or thousands of users/devices, so physically visiting every machine is impractical. +- Centralized management solves this: install one small agent per endpoint, then push any application (Microsoft Office, PDF viewer, daily-work apps) remotely with one click. +- The demo platform (transcribed in the captions as 9-9 / 9-9 pro) is usable both in corporate environments and on your own PC. +- The KB again drove the task: a short note said the agent installer would be waiting in the Downloads folder of T-01. +- Verification is dashboard-driven: an installed agent reports back to a central server, and seeing the device discovered confirms it is up and running. + +**Detailed Notes** +- This is the final ticket of the chapter — task 3 of 3: an agent to be installed. +- Why agents: users constantly request software (Microsoft Office, viewers, etc.); installing per-device on hundreds of machines is not viable. +- Deployment model: install the lightweight agent on every device, then push any application you want from the console. +- Steps: consult KB (agent found in Downloads) → set ticket status to In Progress → connect to T-01 → open Downloads → see the agent installer → provide the password → install completes. +- Verification: open the platform dashboard (9-9 pro) — it shows one device has been discovered, meaning the agent is reporting to the server; the dashboard also exposes OS, domain name, users, IP addresses, and more for the laptop. +- Business value: e.g., push a PDF viewer to 500 devices with one click instead of touching each machine. +- Close-out: message the manager that the agent has been installed, mark the ticket completed — all three manager tasks are now done. + +**Action Items** +- Practice the agent install flow: KB → connect → locate installer → authenticate → install → confirm the device appears in the dashboard. +- Explore an RMM/software-deployment tool (agent-based consoles like the one in this course, plus PDQ, Intune-style MDM, etc.) and push a test app to a lab machine. +- Learn to read managed-device inventory (OS, domain, users, IP) from the dashboard for remote troubleshooting. + +**Key Terms/Concepts** +- **Agent**: small software installed on each endpoint that reports to a central server and enables remote software deployment/monitoring. +- **RMM dashboard / management console**: central view of discovered devices with inventory details (OS, domain, user, IP). +- **Software push (remote deployment)**: installing an application to many endpoints at once from a central console via installed agents. +- **Knowledge Base (KB)**: internal documentation telling agents where installers live and how to perform tasks. + +--- + +## Chapter 4 — 1. Our User Needs Your Help Again! + +**Core Insights** +- The "Do I know this already?" question: on Windows 10, enable BitLocker for a user and check if the NIC has the latest drivers. +- You don't need to understand a feature in depth to fix/enable it — knowing what a tool is for and where to find it is enough for first-line work; errors get escalated. +- BitLocker is a full-disk encryption solution built into Windows, available on Windows Pro and above (not Windows 8/10 Home). +- BitLocker encrypts the whole drive, not individual files; without the key/TPM, a stolen disk drive is unreadable. + +**Detailed Notes** +- Topic: operating systems — Windows, macOS, Linux, plus servers; the lecture series ends with a real ticket. +- BitLocker normally requires a TPM (Trusted Platform Module) chip, which stores the encryption keys. +- Enabling BitLocker without TPM is possible but not recommended and often against company policy — check policy first. +- Scenario: user Kate needs BitLocker enabled on a test laptop; ticket flow — open case queue → assign ticket to yourself → reply to Kate ("I'm going to work on it now") → mark ticket in progress. + +**Action Items** +- Practice the ticket workflow: assign, reply to user, set status. +- Locate and review BitLocker options in Windows Pro before attempting enablement. + +**Key Terms/Concepts** +- **BitLocker**: Windows full-disk encryption tool (Pro/Enterprise editions). +- **TPM (Trusted Platform Module)**: hardware chip that stores BitLocker encryption keys. +- **Ticket**: tracked support request assigned to a technician, worked through statuses (open → in progress → closed). + +## Chapter 4 — 2. An Easy Job + +**Core Insights** +- BitLocker enablement, part 2: connect to test laptop TI-01 via RAdmin and turn on BitLocker; admin passwords live in KeePass. +- If a laptop is about to sleep/go to sleep, do not attempt advanced operations (can break Windows) — call the user to plug in the power supply first. +- BitLocker failed because the laptop has no TPM module; the error message asked to "allow BitLocker without a compatible TPM" — Windows requires enabling one extra feature. +- When stuck: inform the customer of the delay, then escalate to manager/senior/2nd-3rd line, or re-assign the ticket — don't just Google. + +**Detailed Notes** +- Start menu → type "BitLocker" → "Turn on BitLocker". Kate is not a local administrator, so provide your own admin credentials (from KeePass). +- Fix (senior-level, not first-line): run gpedit.msc (Local Group Policy Editor) as local admin → Computer Configuration → find "Allow BitLocker without a compatible TPM" → Enable → Apply/OK. +- Push the policy to the device: `gpupdate /force`. +- Reconnect and enable BitLocker: without TPM, a strong startup password is required (recommended ~20 characters; Windows rejects short ones). +- Critical step: back up the Recovery Key (save to file or print to PDF) — if you lose both password and recovery key, there is no backdoor and the disk is unrecoverable; store the file in a secure place (it can recover the password). +- Encryption options: encrypt used space only (device already in use); skip system check to avoid reboot. +- Recovery file contains a BitLocker Recovery Key plus an identifier used to recover the disk. +- Full encryption on an in-use laptop can take a few hours — can run in background, but better to leave it on and verify. + +**Action Items** +- Practice gpupdate /force and gpedit.msc policy navigation. +- Always back up the recovery key and store it securely. + +**Key Terms/Concepts** +- **gpedit.msc**: Local Group Policy Editor — tweaks local OS policies. +- **gpupdate /force**: refreshes/forces policy settings immediately. +- **Recovery Key**: 48-digit key (with identifier) to unlock an encrypted disk when the password is lost. +- **Escalation**: passing a ticket to a higher support line or senior technician. + +## Chapter 4 — 3. Overview of Microsoft Operating Systems - Windows 10 + +**Core Insights** +- Legacy Windows (XP, Vista, 7) are end-of-life and should not exist in corporate environments; most companies standardized on Windows 10 (free upgrade years ago). +- Windows 10 editions: Home, Pro, Enterprise; corporate environments run Pro and Enterprise, rarely Home. +- For hundreds/thousands of devices, administration is centralized via Windows Server with Active Directory — e.g. one policy can enable BitLocker on all machines instead of configuring each. +- Service-desk work: password resets, driver troubleshooting, using remote support tools. + +**Detailed Notes** +- Remote support tools: RAdmin (Radmin) and RealVNC require licenses (free trials); TightVNC is free but lacks features (e.g. no encryption/RealVNC extras). These tools require being on the same local network (and firewall rule changes, not recommended). +- TeamViewer is a client-server solution: works across the internet (user in another country), no router/firewall changes; good for supporting dispersed users. Others: LogMeIn. +- DHCP leases IP addresses automatically (no manual assignment for 500+ laptops); DNS translates names into IP addresses (e.g. facebook.com → IP). +- Demo: `ping facebook.com` resolves via DNS; `ipconfig` (Windows) / `ifconfig` (Linux) shows your DNS server. +- Admins don't create accounts via Settings → Accounts; instead right-click This PC → Manage → Local Users and Groups → Users → New User. +- Device Manager shows all hardware; right-click device → Properties → Update Driver / Driver Details / Uninstall Driver. New hardware or misbehaving devices usually need a driver update; Windows can auto-search for the best driver. + +**Action Items** +- Try ipconfig and ping in CMD; open Device Manager and inspect drivers. +- Compare a remote tool like TightVNC vs TeamViewer. + +**Key Terms/Concepts** +- **Active Directory**: central management of devices, users, permissions, and policies. +- **DHCP**: automatically assigns IP addresses to devices. +- **DNS**: translates hostnames (facebook.com) into IP addresses. +- **Device Manager**: hardware inventory and driver management console. + +## Chapter 4 — 4. Let's Connect to MacBook Pro! + +**Core Insights** +- TeamViewer connects remotely to a MacBook Pro across the internet without touching routers/firewalls — unlike RAdmin, which works only on the local network. +- TeamViewer is free for home users but requires a license for commercial/support use. +- macOS security blocks remote control by default: the app must be allowed under System Preferences → Security & Privacy → Accessibility, or TeamViewer can't control mouse/keyboard. + +**Detailed Notes** +- The customer runs TeamViewer as a single file (no install); it shows an ID and a one-time password, or "unattended access" with a fixed password — provide both to connect. +- Basic admin tasks: Users & Groups (unlock the padlock to make changes), account creation, wallpapers. +- Bluetooth problems: usually fixed by turning Bluetooth off/on or disconnecting and reconnecting the device. +- Printers can be added in Settings; backups use Time Machine (can exclude items). +- Finder: Favorites, Locations, Tags (similar to Windows). End-user apps to know: Maps, Messages, Contacts, Calendars, Notes. +- Networking: wireless settings, DHCP for IP assignment (don't assign static IPs to end users), view/connect/disconnect networks, change passwords. +- Remote-session pitfall: never disconnect the wireless network while connected remotely — the session drops; keep a backup path (wired connection or second NIC) when testing wireless. +- Activity Monitor ≈ Windows Task Manager; Terminal: `ifconfig` (like ipconfig), `ping`. +- Recommendation: spend 30–45 minutes clicking around a MacBook Pro to learn it. + +**Action Items** +- Practice a TeamViewer remote session and the Accessibility permission setup. +- Explore System Preferences and Time Machine. + +**Key Terms/Concepts** +- **TeamViewer**: internet-based remote support tool (ID + password). +- **Accessibility permission**: macOS gate that lets apps control the desktop. +- **Time Machine**: macOS built-in backup tool. +- **Activity Monitor**: macOS task/process manager. + +## Chapter 4 — 5. What to Expect From a Linux Device + +**Core Insights** +- Multiple OSes can run on one machine via virtualization — e.g. VirtualBox; the course's extra lecture (from the ethical hacking course) covers VirtualBox + Linux install step by step. +- Demo uses Kali Linux, a security-focused Linux distribution with many pre-configured tools; with VirtualBox you can open one file and have Linux running within minutes. +- Linux has a GUI for many tasks, but the terminal and commands are central; 80–90% of support jobs are Windows, so Linux support is niche but real. + +**Detailed Notes** +- GUI basics: change wireless/wired settings, view IP address, DHCP or static IP, turn the network card off/on; file manager shows Documents, Downloads, Desktop, Home, Other locations, Network. +- Terminal commands: `ifconfig` — show IP address and network settings; `ping` — continues pinging until stopped with Ctrl+C; `clear` — clear the screen; `ls` — list folders and files; `cd` — change directory (e.g. `cd Documents` then `ls`); `mkdir` — create a directory. +- Use Up/Down arrow keys to recall/reuse recent commands; list previously used commands (history). +- Run `man ` to learn what a command does and see all its switches. + +**Action Items** +- Install VirtualBox + Kali Linux and click around the GUI. +- Practice ls, cd, mkdir, ifconfig, ping, man in a terminal. + +**Key Terms/Concepts** +- **Virtualization**: running multiple operating systems on one device (VirtualBox). +- **Kali Linux**: Linux distribution designed for security testing. +- **ifconfig / ls / cd / mkdir / man**: core Linux terminal commands. + +## Chapter 4 — 6. Windows Server 2016 + +**Core Insights** +- Only Windows Pro/Enterprise can be joined to a domain and managed by Windows Server — a key difference vs Home. +- As a service desk agent you rarely connect to servers directly; when you do, it's via RDP (Remote Desktop Protocol), built into Windows, not RAdmin/TeamViewer. +- RDP takes over the session: the logged-in user sees "someone else is using your computer" and can't watch — bad for user support, great for managing servers in a data center. +- Active Directory Domain Services (AD DS) centralizes users, groups, permissions; the main service-desk tool is Active Directory Users and Computers. + +**Detailed Notes** +- Servers can be cloud-based, dedicated hardware, or a VirtualBox VM. +- AD structure: a domain (e.g. test.local) is the logical container that devices join; folder-like items are Organizational Units (OUs), not folders. +- Create user: right-click OU → New → User; naming follows company procedure/KB (e.g. M.Smith, MikeSmith, Mike.Smith) — check the knowledge base/manager, especially for external companies. +- Password: set initial password; "user must change password at next logon" option enforces self-chosen passwords. +- User properties → Account: Disable account when an employee leaves (don't delete immediately — they may have files/access); Reset Password (hand temp password, user changes it on login); Unlock account; Logon Hours — restrict when a user can log in (e.g. Tuesday until 3:30 PM). + +**Action Items** +- In AD Users and Computers, practice creating a user and toggling logon hours. +- Learn your company's AD naming convention. + +**Key Terms/Concepts** +- **RDP**: Microsoft Remote Desktop Protocol for remote server/PC connection. +- **Domain**: logical group of devices managed by Active Directory. +- **OU (Organizational Unit)**: AD container for users/computers/groups. +- **Logon Hours**: time restrictions for user sign-in. + +## Chapter 4 — 7. Yet Another Ticket - Troubleshooting + +**Core Insights** +- When asked to verify whether a machine crashed recently, start with Event Viewer: Windows Logs → Application, Security, Setup, System — not all errors are critical. +- Reliability History gives a graphical timeline; red entries mark critical problems (system crashes, RAM issues) and can be saved as a report. +- The Microsoft Management Console (mmc) bundles all admin tools — Device Manager, Event Viewer, Disk Management, Services — in one console via snap-ins. +- Services are small background applications; when a print job fails, restart the print server/spooler service. + +**Detailed Notes** +- Event Viewer: investigate specific events (e.g. event 99) — here it explained why the manager asked to check TI-01 (machine cannot talk to a server?). +- Reliability History: filter/save as a report; used to answer "did this PC crash in the last couple of weeks?" — save the report and reply to the manager. +- Open mmc via Win+R → type `mmc` (Microsoft Management Console) → File → Add/Remove Snap-ins → pick Device Manager, Event Viewer, Disk Management, Services — all in one place. +- To manipulate services with admin rights: right-click CMD → Run as administrator, then run `mmc` so the whole console inherits admin rights, open Services, right-click the service → Restart. +- Typical request flow: verify crash history → filter for critical errors → save a report → update/close ticket. + +**Action Items** +- Practice building an mmc console with Device Manager, Event Viewer, Services snap-ins. +- Restart a service (e.g. print spooler) and check Event Viewer after. + +**Key Terms/Concepts** +- **Event Viewer**: Windows log viewer (Application/Security/Setup/System). +- **Reliability History**: graphical crash/problem report tool. +- **mmc**: Microsoft Management Console — hosts administrative snap-ins. +- **Service**: background application managed via the Services console. + +## Chapter 4 — 8. Installing Malwarebytes using Ninite Pro + +**Core Insights** +- This task is a change (not an incident/issue): push Malwarebytes to TI-01 — the manager assumes you already know the toolchain (Ninite Pro, RAdmin, KeePass), so the ticket gives only the goal, not steps. +- Ninite Pro silently deploys applications in the background — the user sees no prompts; a desktop icon simply appears after a few minutes. +- Malwarebytes complements antivirus (works alongside Kaspersky, Bitdefender, etc.); it isn't sufficient as the only protection. + +**Detailed Notes** +- Workflow: open the request → assign to yourself → set status "implementing" → open Ninite Pro (laptop TI-01 listed) → Apps/Ops → select Malwarebytes → deploy/install to TI-01. +- Connect to TI-01 via RAdmin to verify — no pop-ups or messages appear on the user's screen during silent install. +- Ninite Pro also updates installed applications when new versions are released. +- Malwarebytes licensing: 14-day trial; the free version does not run in the background — you can scan on demand but get no real-time protection. +- Close the change: note the installed version (e.g. 4.0.4.49), describe everything in detail in the ticket, save — change complete. + +**Action Items** +- Practice a Ninite Pro silent install and verify via remote session. +- Try Malwarebytes trial/free scan to see on-demand vs real-time modes. + +**Key Terms/Concepts** +- **Change request**: planned, approved modification (vs incident/issue). +- **Ninite Pro**: centralized silent app installer/updater. +- **Malwarebytes**: anti-malware scanner that complements traditional antivirus. + +--- + +## Chapter 5 — 1. Installing Office 365 Apps + +**Core Insights** +- Service desk work involves many Microsoft Office issues, often from non-technical users (real tickets: "What's PowerPoint?", "red icon on my desktop") — patience and plain-language explanations are core job skills. +- Outlook is the most-supported Office app in business: it manages email, calendars, and contacts; managers depend on it, so Outlook tickets can be higher priority. +- Office 365 licensing is complicated (Home vs Business, E1/E3/E5, Office 365 vs Microsoft 365); a service desk analyst must study the options to recommend the right solution. +- Since Office 365, Office is subscription-based (pay monthly/yearly, never own it) — a shift from the old one-time purchase model. + +**Detailed Notes** +- Presenter's package: Office 365 Business. Two reasons chosen: (1) Outlook is NOT included in many Home packages; (2) Business allows commercial use — Home licenses don't. +- License rules: Home = up to 6 family members; Business = 1 user but installable on up to 5 devices that the company owns. +- Large companies (hundreds/thousands of users): Office 365 E3 or E5 — cheaper (~$8/month per user), more features. +- Confusing lineup: Office 365 / Microsoft 365 / Home 365 / Office Business 365 / Office 365 E1-E5. When in doubt, a Microsoft partner can recommend the best fit. +- Install: log in at office.com → download "Office 365 apps" → one click installs everything (no prompts asking which apps). +- Older versions (e.g. Office 2010): download via Microsoft link, enter product key, verify, package downloads (presenter verified this works). +- Cost comparison: Office 2010 bought once ~11 years ago (~£300-400); now ~$20-30/month with flexibility to pause/resume — no $500 upfront. Prediction: even Windows itself will become subscription-based. + +**Action Items** +- Practice explaining Office basics to non-technical users without jargon. +- Study the current Office 365/Microsoft 365 license comparison (Home vs Business vs E3/E5) so you can recommend plans. +- Walk through an Office install from office.com on a test machine. + +**Key Terms/Concepts** +- **Office 365 / Microsoft 365**: subscription plans for Office apps; names overlap confusingly. +- **Office 365 E3/E5**: enterprise plans, cheaper per user at scale. +- **Product key**: code needed to download/verify older, non-subscription Office versions. +- **Subscription model**: pay periodically to use software; you never own the license. + +## Chapter 5 — 2. Outlook and Emails + +**Core Insights** +- Outlook can be used as a web app (Outlook on the web/OWA) or as the desktop client; both work simultaneously and synchronize. +- Exchange-based accounts (Microsoft Exchange / Exchange Online — a paid Microsoft email server service) auto-configure in Outlook: just enter the email address, no server details needed. +- Non-Exchange accounts (Gmail, Yahoo, own server) require incoming/outgoing server settings — the most popular interview question at service desk hiring. +- Data file types: Exchange uses OST (syncs with server); POP3 accounts store mail in PST — backing up email = copying the PST file. + +**Detailed Notes** +- Demo account: Exchange Online address (onmicrosoft.com domain); you can later move to your own domain; presenter cancelled it after recording. +- Setup on a new PC: Outlook searches for accounts automatically; if already logged in with the same account, nothing to configure. +- Incoming server: POP3 protocol, port 110 (port = numeric identifier of a service); downloads email to the PC. +- Outgoing server: SMTP (Simple Mail Transfer Protocol), port 25. +- Encryption option: SSL/TLS — the same tech behind HTTPS in your browser (the "S" = secure); enforced by the email administrator. +- Adding Gmail: Outlook auto-detects the server; your own server/Yahoo requires filling in all mailbox fields manually. +- Exchange behavior: emails synchronize with the server (no copying needed) — unlike POP3 which downloads and stores locally. IMAP exists for other accounts (mentioned, out of scope). +- Common Excel ticket: spreadsheet prints across two pages → remove page view, switch to landscape, change size — everything fits one page. +- "Account error" in Office apps: Office uses the Windows login name (e.g. Mike), but the license belongs to another user (Marius) → click the correct licensed account. Recommendation: keep everything under one name per user to avoid this. + +**Action Items** +- Memorize port 110 (POP3 incoming) and port 25 (SMTP outgoing) — classic interview questions. +- Practice setting up Gmail vs Exchange accounts in Outlook on a test machine. +- Learn where OST/PST files live and how to back up by copying the PST. + +**Key Terms/Concepts** +- **POP3**: incoming email protocol, port 110, downloads mail to the client. +- **SMTP**: outgoing email protocol, port 25. +- **SSL/TLS**: encrypted connection protocol (same as HTTPS). +- **OST/PST**: local Outlook data files; Exchange uses OST, POP3 uses PST. +- **Exchange Online**: Microsoft's cloud email service (paid). + +## Chapter 5 — 3. Yet Another Ticket - Issues With Microsoft Word + +**Core Insights** +- Walkthrough of a real ticket: "How can I password-protect my doc?" — resolved by calling the user and guiding them through Word's settings. +- Word offers two separate passwords: one to OPEN the document, one to MODIFY it. +- There is NO official way to recover a password-protected Word document — no master password, no backdoor — even for IT. +- The only recovery path is a brute-force password-cracking tool, and only with manager + security team approval; never recommend it to end users. + +**Detailed Notes** +- Call-based resolution flow: confirm the user has the document ready → File → Save As (any location) → in the Save As dialog open Tools → General Options → set "password to open" and/or "password to modify" → save. +- Polishing the ticket: add a note to the ticket documenting the resolution. +- Bonus question scenario: user forgets the password → IT cannot open the file officially. +- Brute force attack: an application tries every possible combination one by one (aaa, aab, aac…). It's a guessing process, not password "recovery"; can take very long for strong passwords. +- Policy guidance: password-cracking is not a normal service desk task, and recommending tools to customers may be unauthorized; always escalate to your manager and security team first. + +**Action Items** +- Practice password-protecting a Word doc (open + modify passwords) and test both prompts. +- Know your company's policy on password recovery/cracking before handling such requests. + +**Key Terms/Concepts** +- **Password to open / password to modify**: two independent protections in Word (Tools → General Options in Save As). +- **Brute force attack**: trying all possible password combinations until one works. +- **Backdoor/master password**: does NOT exist for Office documents — a common user misconception. + +--- + +## Chapter 6 — 1. Basic Networking Terms + +**Core Insights** +- A network exists whenever at least two devices are connected and exchange data — it does not require a cable. +- Every device on a network has a MAC address: a unique, manufacturer-assigned physical hardware address that you do not configure yourself. +- Networks are classified by size: PAN (personal), LAN (local area) and WAN (wide area); a WAN connects two LANs via a router. +- You can find your own MAC address and default gateway on Windows with the `ipconfig` command. +- The best way to learn networking is to log in to a real router and explore its settings. + +**Detailed Notes** +- MAC address: + - Physical hardware address, unique per device, assigned by the manufacturer at the factory (e.g., to the wireless card inside a laptop) — you don't change it, you just use it. + - Used by devices inside a local area network for communication. + - View it on Windows: run `ipconfig`, find your network card, and read the *Physical Address* field (same thing as MAC address). +- Network components: + - Network Interface Card (NIC) plus a network cable (RJ45 connector) for wired connections; a wireless NIC is used for Wi-Fi instead — either works because the definition of a network is just two devices exchanging data. + - Example: a Bluetooth headset paired with a phone streaming Spotify is a valid network (a PAN — Personal Area Network). + - LAN: covers a limited area — one building, one office, one big site. + - WAN: covers a large area; e.g., connecting a LAN in New York to a LAN in Washington creates a WAN. + - Switch: the device used inside a LAN to connect many devices — printer, server, scanner, computers. (Pronunciation aside: router, not "router".) +- Default gateway: + - Shown in `ipconfig` output; it is the address of your router. + - At home, open a web browser and type your default gateway IP — ~99.99% of the time you can connect to the router's web interface. + - Login needs a username/password: often printed on a label on the router, sometimes sent by email from your company, or set by you when you first configure a new router you bought. +- Next lecture preview: a demo ASUS router at demo.ui.asus.com so you don't have to touch your own router if you're not comfortable. + +**Action Items** +- Run `ipconfig` on your PC and locate your Physical Address (MAC) and Default Gateway. +- Open a browser, type your default gateway IP, and log into your own router. + +**Key Terms/Concepts** +- **MAC address**: unique physical hardware address assigned by the manufacturer, used within a LAN. +- **NIC**: Network Interface Card — wired or wireless hardware enabling network connection. +- **RJ45**: standard connector for network (Ethernet) cables. +- **PAN / LAN / WAN**: personal / local / wide area network, scaling by geographic coverage. +- **Switch**: LAN device that lets many devices connect and communicate. +- **Router**: device that connects networks (e.g., LAN to WAN/Internet). +- **Default gateway**: the router's address on your local network; used to reach other networks. + +## Chapter 6 — 2. Let's Connect to a Router + +**Core Insights** +- Logging into a router shows a dashboard/network map: Internet status, number of connected devices, and how each device is connected. +- Better routers support more than one Internet uplink (e.g., broadband + 4G/LTE via USB dongle) and can use both at the same time. +- New routers often ship with an open (no-password) wireless network — you MUST secure it before use. +- Use WPA2 (or WPA3 if available) for wireless security; avoid WPA and WEP. +- The router's LAN settings show the DHCP server, which automatically assigns IP addresses to all devices on the network. + +**Detailed Notes** +- Demo used: an ASUS demo router (not a home router) — logging in reveals a dashboard with a live view of what is happening. +- Network map: similar to a dashboard; in the demo it shows 7 devices connected; clicking the device list shows how each one is connected. +- Multiple Internet links: + - Cheap routers: only one Internet connection option. + - More expensive routers: multiple options — e.g., a broadband connection plus a USB dongle with a 4G/LTE SIM as fallback. + - This is why routers have a WAN port and can use both connections simultaneously: broadband as the primary link and the secondary as backup. +- Wireless security checklist for a brand-new router: + - Out of the box many routers (e.g., ASUS) arrive as an open system — no wireless password; anyone could join your LAN. + - Before using it: go into wireless settings and enable WPA2 (choose WPA3 when possible). + - Avoid legacy protocols WPA and WEP — they are insecure. +- LAN tab: shows the DHCP server status — DHCP means the router automatically assigns IP addresses to all devices in the network. Also offers wireless configuration options. + +**Action Items** +- Log into your router (or use a vendor demo router) and read the network map/dashboard: how many devices are connected and how. +- Check your wireless security mode and change it to WPA2/WPA3 if it is WEP, WPA, or open. +- Identify your router's WAN/Internet options and understand primary vs. secondary (4G/LTE failover) connections. + +**Key Terms/Concepts** +- **Network map/dashboard**: router homepage showing connected devices and link status. +- **WAN port**: router port for the Internet/upstream connection. +- **USB dongle / 4G LTE**: alternative Internet uplink plugged into the router. +- **DHCP**: service on the router that auto-assigns IP addresses to LAN devices. +- **WPA2 / WPA3**: modern, secure Wi-Fi encryption standards. +- **WEP / WPA**: older, weak Wi-Fi security — avoid. + +## Chapter 6 — 3. GPO - Group Policy Object + +**Core Insights** +- GPO (Group Policy Object) lets IT control settings on many computers at once instead of configuring each device manually. +- Earlier lectures showed pushing applications and installing an agent centrally (e.g., no need to install or update a PDF viewer on every device individually). +- GPO is the answer to "what if I need to change something on 500 devices?" — you change it once, centrally. +- GPO enforces end-user restrictions: which desktop icons are allowed, wallpaper, network settings, and more. +- Policies are assigned per computer or per user account in Active Directory. + +**Detailed Notes** +- Motivation: walking to every device is not feasible; centralized management is required at scale (change a setting on 500 machines at once). +- Use cases: + - Control what end users are allowed to do with their company laptop (it is meant for work). + - Prevent users from changing network settings or changing their wallpaper. + - Enforce a corporate standard: define which icons appear on the desktop, force a specific wallpaper (e.g., a bank's logo on every screen — important when employees share screens with customers or clients accept policies on-screen). +- Scope: GPO can modify hundreds to thousands of Windows settings/options — going through all of them can keep an admin busy for weeks. +- Assignment: after configuring a policy, you assign it — to a computer object or to a user account. +- Context: GPO is an Active Directory feature — a powerful toolset for managing all devices in an organization. + +**Action Items** +- Explore the Group Policy Management console in a lab/Active Directory environment: create a sample GPO. +- Practice assigning a GPO to a computer (computer configuration) vs. a user (user configuration). +- Try small settings in a test environment (e.g., restrict desktop icons or force a wallpaper) before touching production. + +**Key Terms/Concepts** +- **GPO (Group Policy Object)**: central set of rules applied to users/computers in Active Directory. +- **Active Directory**: directory service that stores user/computer accounts and the target for GPO assignment. +- **Computer vs. User configuration**: a GPO can target either the machine or the logged-in account. +- **Agent/central deployment**: pushing software (e.g., PDF viewer) centrally rather than installing per device. + +--- + +## Chapter 7 — 1. ITIL in a Nutshell + +**Core Insights** +- ITIL is the framework behind most service desk procedures; a full official course lasts ~3 days (8 hours/day), but a service desk agent only needs a handful of everyday terms. +- ITIL 4's service value chain is a chain of activities: Plan, Improve, Engage, Design & Transition, Obtain/Build, Deliver & Support. +- The four dimensions of service management: organization and people, value streams and processes, partners and suppliers, information and technology — useful to impress managers, but not used daily. +- Terms you will be assumed to know on the job: SLA, OLA, CAB, ECAB (emergency CAB), and change freezes. +- Everything is aimed at delivering the best value and best service to customers. + +**Detailed Notes** +- **SLA** (Service Level Agreement): agreed service targets — e.g., "4 hours to reply to my customer, 16 hours to close the ticket." It is the agent's responsibility. Data centers quote SLA uptime, e.g., 99.9%. +- **OLA** (Operational Level Agreement): an agreement between an IT service provider and another part of the same company (department-to-department, e.g., one department and another). +- **CAB** (Change Advisory Board): approves changes. Example: deploying a cloud-based antivirus solution on 500 devices is a big change that needs approval — unlike fixing a ticket about password-protecting a Word document. + - Process: submit a special document → get invited to a CAB conference call → present the change so both technical staff and managers understand what you want to achieve → include a backup plan (what you'll do if something goes wrong) → show how you will measure everything. You fill in a template with several fields. +- New service desk agents are rarely asked to raise changes as a first task; changes are often handled by a different department or second-line staff. +- **ECAB** (Emergency CAB): for urgent changes. Example: Cisco announces a critical firewall bug; the fix requires a firmware update and reboot — that is still a change, but a normal CAB meeting (weekly/monthly) is too slow; you must act within hours, so you go to an emergency CAB and justify why it cannot wait. +- **Change freeze**: e.g., at Christmas, no changes are introduced because something can go wrong; any change must be justified as an emergency. Change calendars in your applications flag freeze periods and warn you. + +**Action Items** +- Memorize SLA / OLA / CAB / ECAB definitions and the service value chain activities before interviews — most applicants can't even define SLA. +- Practice the classification test: is this a routine fix, or a change that needs CAB/ECAB approval (scale = number of devices affected)? + +**Key Terms/Concepts** +- **SLA**: Service Level Agreement — agreed response/closure targets (e.g., reply in 4h, close in 16h). +- **OLA**: Operational Level Agreement — service agreement between parts of the same company. +- **CAB**: Change Advisory Board — approves non-urgent changes with documented plans. +- **ECAB**: Emergency Change Advisory Board — fast-track approval for changes that can't wait days. +- **Change freeze**: period (e.g., holidays) when changes are forbidden unless justified as emergencies. +- **Service value chain**: ITIL 4's chain of value-adding activities. + +## Chapter 7 — 2. ITIL in a Nutshell - Part 2 + +**Core Insights** +- Service operations run on three ticket types: incidents (something broken), problems (root cause of many related incidents), and service requests (a user asking for something to change). +- Escalation is two-way: you escalate what you can't solve, and unsatisfied users can escalate you to your manager behind your back. +- Continual Service Improvement (CSI) — analyzing, reviewing, and recommending improvements — is part of the job, including flagging security issues. +- Documentation discipline matters: notes must let the next person understand what happened; configuration items must be updated whenever details change. +- Mistakes are inevitable; the goal is to learn and progress from first line toward second/third line. + +**Detailed Notes** +- **Incident**: something broken that you fix — user "can't print," "can't connect to the Internet," "can't log in." +- **Problem**: when many incidents share one cause — e.g., 15 calls about an Exchange server / "I can't download my emails" — it is not just an incident; it affects many users and must be raised and fixed. +- **Service request**: user wants something changed. Sometimes you can't finish a task yourself — e.g., an earlier task where there was no TPM module and someone had to enable a security policy (BitLocker); you escalate: "I don't know how to do it, can you help me please." +- **Customer escalation**: in most ticketing systems the user has an escalation option; if unhappy, they can escalate to your leader/manager without you knowing — you find out days later when your manager calls a meeting to understand what went wrong. In a good company it is treated as a learning exercise; sometimes it is just an upset user. +- **CSI**: analyze, review, make recommendations to improve services; tell your manager or a senior person — a really small thing can make a huge difference. +- **Security reporting**: if you notice a customer saved a document with a password in clear text, don't lecture the user; discuss it with your manager, who takes it from there. +- **Monitoring**: systems send alerts, events, and incidents; your job is to sort them out. +- **Documentation**: keep knowledge base pages and notes up to date — e.g., if you change a server's IP address, modify the document straight away: go to assets and update the configuration item. Someone will use that information within hours; when you go home, a colleague must be able to read your notes and reconstruct what happened. Same applies to tickets, incidents, and changes: describe what the problem was. +- **Handover**: many places have a page to monitor/update what happened in the last 8/16/24 hours — especially important before escalation, because the person you escalate to knows more than you and will challenge obvious mistakes. +- **Cautionary example**: first-line network agent, customer says "my internet is down"; agent asks "can you see the lights on your router?" — customer says no → agent escalates with "your router is broken." A field engineer was sent on-site to replace the router when the real fix was simply pushing the power cord back in. Verify a bit more before escalating. +- Expect to make mistakes — it's not a question of if but when; learn from them and you'll become a second/third line guy in a few years. + +**Action Items** +- Practice classifying tickets as incident / problem / service request and deciding when to escalate vs. fix yourself. +- Build the habit of writing notes a colleague could act on without talking to you; keep CMDB/configuration items current when anything changes. + +**Key Terms/Concepts** +- **Incident**: unplanned interruption (e.g., can't print) that must be restored. +- **Problem**: underlying cause of multiple related incidents affecting many users. +- **Service request**: user-initiated request to change or provide something. +- **Escalation**: raising a ticket to higher/specialist support; also customer complaints rising to management. +- **CSI**: Continual Service Improvement — analyzing and recommending service improvements. +- **Configuration item (CI)**: a tracked asset (e.g., a server and its IP address) that must stay accurate. +- **TPM/BitLocker**: example from earlier tasks — a missing TPM module required enabling a security policy. + +--- + +## Chapter 8 — 1. An Interview Process + +**Core Insights** +- Job hunting follows a standard pipeline: advert → application (CV + cover letter) → screening call → interview → offer; expect each step to take time. +- No single job site lists everything — apply directly on company career pages; many firms only advertise on their own website. +- Recruiters may spend only ~5–6 seconds on a CV when there are hundreds of applications, so yours must be flawless and instantly scannable. +- Even HR screeners can throw basic technical questions (e.g., "what port is SMTP on?" — port 25), so review fundamentals before the first call. + +**Detailed Notes** +- Job sources: online adverts, direct applications to companies, and recruitment agencies working on behalf of firms; never rely on one website/engine as the only source — many big companies post jobs only on their own site. +- Application materials: a polished CV using a clean template, plus a cover letter; if English is not your native language, have a native speaker check it — small mistakes look terrible against hundreds of applicants; keep a professional LinkedIn profile. +- Patience: it can take a few weeks before anyone even opens your application. +- Screening phone call (agency or HR): typical questions — availability, salary expectation, experience, "tell me about yourself", why you want this job, why you applied, why you want to change jobs, availability for an on-site interview, what you want to achieve in the next five years. +- Technical screening: HR staff can ask technical questions from a prepared list; example given: SMTP port number (port 25 — "you know it or you don't"). Review the course's final quiz — a Top 50 interview questions list. +- Interview: on-site or remote (Skype or the company's own platform); a short meeting with a manager and an engineer; many companies give a technical test (often pure memorization), while conversational interviews let you show real understanding. Find a quiet place, stay relaxed, project that you're the best candidate. +- Offer stage: an e-mail saying "we can hire you — here is what we can offer." + +**Action Items** +- Apply directly on big local companies' career sites, not only job portals. +- Get CV/cover letter proofread; polish your LinkedIn profile. +- Prepare answers to the standard screening questions; review the Top 50 interview questions quiz. +- Drill basic protocol/port facts (SMTP = 25) in case HR tests you. + +**Key Terms/Concepts** +- **SMTP**: email-sending protocol; its well-known port is 25. +- **Agency**: a third party recruiting on a company's behalf. +- **Cover letter**: short letter accompanying the CV that tailors you to the role. + +## Chapter 8 — 2. Tips for you + +**Core Insights** +- You will land an IT job if you are patient, competent, and visibly willing to learn — but it takes time. +- A CV with zero experience must still show proof of effort: completed courses, home labs, tools actually touched. +- You can manufacture experience: freelance small jobs, be active on discussion boards, stay current on hardware/software. +- Lying on a CV backfires — managers are often technical and will probe claims with questions. + +**Detailed Notes** +- Don't send a CV saying "I know nothing about IT": show something — completed online courses (not a Microsoft certificate, but still evidence), e.g. "I completed 15 courses, I created a few labs." +- Sample CV line for no experience: "I built a big lab at home — installed Active Directory, Windows Server, Windows 10; used PRTG for monitoring; used a software-deployment/RMM tool to push software to my end devices; played with Kaspersky Cloud/Endpoint Protection." +- Freelancing as a starting point: post an ad ("I can fix your wireless issues"); a client calls, you pop in and fix it. +- Stay active online: join discussion boards to ask and answer questions; read tech magazines; keep up to date on hardware/software — e.g., be able to recommend a NAS (network-attached storage) device on request. +- Career reality: IT is not a 9-to-5 job — continuous learning, labs, and exams; the payoff is helping people, good pay, job security after a few years, and specializations (networking, cloud, Microsoft, Cisco). +- Don't lie: never claim "I installed 500 servers in the last five years" if you installed a couple in a virtual machine; as a technical manager he routinely asks a few technical questions, surprising candidates. +- Mindset: stay patient, hope someone gives you a chance — it will happen. + +**Action Items** +- Build a home lab (Active Directory, Windows Server, monitoring, deployment tool) and list it on your CV. +- Take small freelance IT jobs (e.g., fixing home Wi-Fi). +- Join discussion boards; read tech news/magazines weekly. +- Keep every CV claim honest — expect technical verification in interviews. + +**Key Terms/Concepts** +- **NAS (Network-Attached Storage)**: dedicated file-storage device on the LAN. +- **Active Directory**: Microsoft directory service managing domain users/computers. +- **PRTG**: network and IT infrastructure monitoring tool. + +## Chapter 8 — 3. A Chat with an HR Specialist + +**Core Insights** +- The #1 first-interview mistake is criticizing your previous employer — the interviewer assumes you'll do the same to them after you leave. +- Timing matters: arriving late reads as chronically late to work; arriving far too early forces a rushed, non-relaxed start; no-shows mean you'll likely never be interviewed there again. +- Never bring family (parents, children, partner/spouse) — it signals home difficulties and that you may get called away from work. +- Skills claims without proof read as lies: any stated skill needs a concrete example or you're immediately disqualified. + +**Detailed Notes** +- Dress professionally even if the workplace is casual: be clean, pressed, and ready; don't assume casual wear is acceptable — the HR specialist recounts candidates arriving in pajamas and slippers. +- Preparation: practice interviewing with someone; read the company website; understand what the company does and who its clients are; bring that research to the interview to show you've done your homework. +- Social media: recruiters look up your name and view your pages; unflattering pictures or content are another automatic disqualifier. +- Compiled with colleagues into a short list of the most important mistakes — these apply to first interviews generally. + +**Action Items** +- Never bad-mouth former employers in an interview. +- Arrive on time (not late, not excessively early); never be a no-show. +- Attend alone, professionally groomed and dressed. +- Prepare 1–2 concrete examples per claimed skill; practice interviewing with someone. +- Audit and clean social media profiles before applying. + +**Key Terms/Concepts** +- **No-show**: failing to attend an arranged interview; never acceptable, burns the bridge. +- **Recruiter**: person screening/placing candidates (agency or company HR). + +## Chapter 8 — 4. An Interview With an IT Analyst + +**Core Insights** +- Believe in yourself and do your homework: understand the service desk concept and the ITIL framework — don't just follow it, understand the standard. +- SLA ≠ resolution deadline: it's the time to acknowledge/respond to the ticket (a 20-minute SLA means acknowledge within 20 minutes, not resolve), then keep updating the ticket as you work. +- Attitude beats experience: he accepted a sys admin offer with zero sys admin background by saying "I'm willing to take this job 100% if given the opportunity" — the manager invested in him. +- Always ask about career prospects in interviews, and read the whole job description so you know exactly what products/expertise the company wants. + +**Detailed Notes** +- Guest's path: 10+ years in service desk roles, then team lead, then system admin; current interest leaning toward security. +- Interview prep: follow and understand ITIL (the ideal framework for service desk work); people get scared of SLA — clarify the acknowledge-vs-resolve distinction; e.g., 20-minute SLA = acknowledge the ticket in 20 minutes ("we are working on it, it will take some time") and post updates on the ticket for that user. +- Learning: Udemy courses at good prices are worthwhile refreshers (he used them himself); get certifications and relevant education; update yourself daily — "if you're out for a while, you're outdated." +- Job expectations: service desk work requires understanding how IT/business functions work and basic troubleshooting; people already do IT themselves (smart TV example: unplug the cable, switch input, restart, update) — service desk scales that up. +- Job description: nowadays it lists the products they need expertise in — read it thoroughly and understand the requirements before applying. +- Most important interview question: "What is my career prospect down the road if I join the company?" + +**Action Items** +- Learn the ITIL framework; practice explaining SLA as acknowledgment time vs. resolution time. +- Adopt a "willing to learn, give me the opportunity" attitude when offered stretch roles. +- Ask about career progression in every interview; study the full job description first. + +**Key Terms/Concepts** +- **SLA (Service-Level Agreement)**: agreed response (acknowledgement) time for tickets, not necessarily resolution time. +- **ITIL**: IT service-management framework/standard (incident, problem, change processes). +- **Service desk vs. sys admin**: front-line ticket handling vs. server/domain administration — adjacent but different skill sets. + +--- + +## Chapter 9 — 1. AV in the Cloud - We all Have to Keep Learning! + +**Core Insights** +- It is OK (and professional) to say "I don't know" or "I've never used this tool before" — even senior IT people must learn new tools every day. +- Cloud-based antivirus management (Kaspersky Endpoint Security Cloud / Cloud and Point Protection) centralizes all AV admin in one web console: deploy agents, see infections, modify policies. +- Before deploying to a paying client, the presenter tested the solution hands-on in a trial tenant — the lesson is to always test unfamiliar software first. +- Deploying AV via admin-controlled packages is preferred over asking end users to install it themselves. + +**Detailed Notes** +- Kaspersky Endpoint Security Cloud: one console/website/dashboard to manage all antivirus applications. +- Trial: registration with company name, 30 days to test, license covers up to 100 devices — enough for testing. +- Windows Defender note: a "something is broken / not enabled" warning is not always critical — real-time protection was enabled; only one optional feature was off, so no need to panic. +- Client wanted "something better with more features" → requested Kaspersky Cloud and Point Protection. +- Deployment options found in the console: **manual installation** (download a package), **Active Directory Group Policy** (GPO software push), **distribution packages** (create package, push any way you want), run installation on the user's behalf, or write your own script. +- End-user self-install is not recommended — most users won't follow the instructions. +- Package flow: accept/read licenses → package creation takes a moment → package was run/installed silently on a connected test machine (TS01); silent installs ask no questions because IT defines policy (e.g., an HR user shouldn't decide firewall settings). +- Security profiles/options in console: enable/disable/modify features (firewall, web control, host intrusion prevention); presenter disabled the firewall because a VPN in use could be blocked; changes apply automatically to all managed end devices. +- License must be activated after install; "policy has been applied" + device showing up-and-running confirms success. +- Same procedure on servers (test Windows Server 2016): download package, install, activate license. +- Dashboard status: a removed/uninstalled device shows as down (fine); managed device listed in **green = good / up to date / up and running**. + +**Action Items** +- Practice: create a trial account in a cloud security console, deploy the agent to a test machine, and push a policy change. +- Try any AV (Kaspersky, Norton, Defender, etc.) on a **test device or VM, never your main laptop** — these apps integrate deeply into the OS. +- Practice troubleshooting a Defender-style warning by reading which component is actually disabled before escalating. + +**Key Terms/Concepts** +- **Cloud AV console**: centralized web dashboard to deploy agents, view infections, and manage security policies across devices. +- **Distribution package**: pre-built installer pushed silently to endpoints by IT instead of manual user install. +- **Group Policy (GPO)**: Active Directory mechanism to push software/settings to domain machines. +- **Policy applied**: console indicator that the pushed security configuration reached and activated on the endpoint. + +## Chapter 9 — 2. Using a Monitoring System + +**Core Insights** +- Monitoring exists to be **proactive**: detect problems before the customer calls — they pay you to look after the systems. +- PRTG is an easy-to-use monitoring system that is **free** (even after trial expiry) for up to 100 devices — great for self-learning on a test machine. +- A monitor uses sensors/probes that regularly query devices (e.g., "how many free gigabytes on the disk?") and flip status red/green. +- The monitoring-tool market is huge and fragmented — at least 100 products in the US alone, and enterprises often use custom-coded solutions. + +**Detailed Notes** +- PRTG should be run on a test device because it gets deep into system settings. +- What to monitor: servers, routers, switches, access points, printers — e.g., a file server where users store important documents needs disk-space monitoring so it never fills up. +- On first connection, one item already shows **red** (something down); when a service stops it goes red, and **green** when it works again. +- Green doesn't mean ignore it: go back and review what happened minutes ago (history/incident timeline). +- On install, basic sensors run automatically out of the box: Ping, DNS, HTTP, plus a free-space sensor on the C: drive. +- Sensor thresholds are configurable: trigger an alert when, e.g., only 10% or 50% of disk space remains — thresholds depend on company policy. +- **Warning vs alert**: a warning means "not down, not critical, but look at it" — it doesn't demand a 7 a.m. Sunday response, but it can escalate into a critical issue if ignored. +- It is not the entry-level support person's job to tune all sensor settings, but experimenting with them is valuable. + +**Action Items** +- Install PRTG on a VM/test device and watch the default sensors (Ping, DNS, HTTP, disk space) come up. +- Change one sensor threshold and verify you receive the corresponding warning. +- Deliberately stop a service (e.g., a web server) and observe the red/green status flip and the alert history. +- Inventory your own devices and list which services (disk, uptime, DNS, HTTP) you would monitor for each. + +**Key Terms/Concepts** +- **Monitoring system (PRTG)**: software that continuously checks devices/services and alerts on failures or threshold breaches. +- **Sensor/probe**: a component that performs a single check (disk space, ping, HTTP response, DNS lookup) against a monitored device. +- **Proactive vs reactive support**: finding problems via monitoring before users report them versus fixing after complaints. +- **Warning state**: a non-critical, non-down condition that should be reviewed, not ignored. + +--- + +## Chapter 11 — 1. Policies - GPO in action + +**Core Insights** +- GPO (Group Policy Object) = a collection of policy settings that controls an operating system; lets an admin manage thousands of settings across hundreds of devices from one central place. +- In corporate environments, end users should NOT be local administrators — GPO is how you centrally lock down devices instead of touching each one. +- A GPO must be created AND linked to an OU (Organizational Unit) before it takes effect; linking determines which users/computers it applies to. +- Computer Configuration settings apply to the machine regardless of who logs on; User Configuration settings apply to a specific user. +- "Enabled" does not always mean "allowing" — it can also block something (e.g., "Remove Recycle Bin icon" vs "Enable Active Desktop"); always read the policy description. + +**Detailed Notes** +- Demo setup: server + test device logged in as user "Mike"; created OU "WTA" in Active Directory Users and Computers and moved Mike into it; created policy "Test GPO 1" via Tools → Group Policy Management. +- Right-click the OU → "Create a GPO in this domain and link it here" (combines create + link; you can also create a GPO first and link it later). +- Example policy applied: User Configuration → Administrative Templates → Desktop → "Remove Recycle Bin icon from desktop" → Enabled; each policy shows a description, supported operating systems, and Details/Delegation tabs (delegation lets you scope/lock down who edits it). +- Policy refresh options: reboot the PC (recommended, easiest), or run `gpupdate /force` (refreshes without reboot; some settings still require a reboot — Microsoft states this in the policy). +- Reboot from command line: `shutdown /r /f /t 5` — /r = reboot, /f = force close background apps, /t 5 = do it in 5 seconds. +- Verify applied policies: `gpresult /r` (summary data) — confirms e.g. "Test GPO has been applied". +- Additional options shown: Prohibit access to Control Panel (blocks Control Panel and PC Settings); Windows Settings can control applications, drive maps, environment, files/folders, registry, shortcuts; Network Settings restrict what is allowed for LAN connections/network settings. + +**Action Items** +- Build a small lab: create a test OU and user, apply a simple GPO, and observe the effect after reboot or gpupdate. +- Practice gpupdate /force, gpresult /r, and shutdown /r /f /t 5 until fluent. +- Read policy descriptions carefully before setting "Enabled" — determine whether it allows or blocks. + +**Key Terms/Concepts** +- **GPO (Group Policy Object)**: collection of policy settings controlling OS behavior, applied via AD. +- **OU (Organizational Unit)**: AD container used to scope GPO application to users/computers. +- **gpupdate /force**: command to refresh Group Policy immediately. +- **gpresult /r**: reports applied GPOs (summary data) for troubleshooting. + +## Chapter 11 — 2. Shares + +**Core Insights** +- Two permission systems work together for shared folders: Share permissions (Read / Change / Full Control) and NTFS permissions (full control, modify, read/write, etc.) on the Security tab. +- When both apply, the most restrictive permission wins — the standard practice is Full Control on the share, then lock down with NTFS. +- Never give end users NTFS Full Control: it lets them take ownership of items and change permissions themselves. +- In enterprises, folder access is a process, not a courtesy: users raise a ticket/change request and someone approves it before the IT admin grants access. +- The engineer's two main daily tasks: managing users in Active Directory and assigning permissions to files and shares. + +**Detailed Notes** +- File systems: legacy FAT/FAT32 not covered; focus on NTFS; ReFS (Resilient File System) is not a replacement for NTFS — it was designed for data stores / data centers on big networks. +- NTFS capabilities: compression, encryption via EFS (Encrypted File System), disk quotas (e.g., give Mike 5 GB of space), and granular security per user. +- Lab flow: create folder "test 1" → Properties shows the two relevant tabs — Sharing (share the folder onward) and Security (NTFS permissions). +- Share permissions = 3 options: Read, Change, Full Control. NTFS permissions = many options; Full Control should be avoided for end users (though sometimes justified). +- Sharing tab → Advanced Sharing → Permissions shows Full Control/Change/Read; Security tab shows Full Control, Modify, etc. +- Effective Permissions: when combinations get confusing (e.g., Full Control + Modify), Windows' advanced security "Effective Permissions" view computes exactly what a user (e.g., Mike) can access — good troubleshooting tool. +- Goal of the upcoming lab: share a folder and map a drive so Mike can access it with a single desktop double-click. + +**Action Items** +- Practice creating a shared folder on any Windows 7/8/10 machine — a server is NOT required to experiment with shares. +- Memorize the difference between Share permissions (Read/Change/Full Control) and NTFS permissions, and the "most restrictive wins" rule. +- Test the Effective Permissions feature with overlapping share + NTFS settings. + +**Key Terms/Concepts** +- **NTFS**: New Technology File System; supports compression, encryption (EFS), quotas, granular permissions. +- **Share permissions**: Read / Change / Full Control, applied to the network share. +- **EFS**: Encrypted File System — NTFS-level file encryption. +- **ReFS**: Resilient File System for data stores/data centers; not an NTFS replacement. +- **Effective Permissions**: Windows calculation showing a user's actual combined access. + +## Chapter 11 — 3. Installing Linux Using VirtualBox + +**Core Insights** +- Virtualization prerequisites: the CPU must support virtualization (Intel VT-x / AMD-V) AND the feature must be enabled in BIOS — check your exact laptop/desktop model with Google (e.g., "HP 250 enable VT-x"). +- A VM behaves like a real PC: it needs CPU, RAM, and disk space — plan hardware accordingly (decent i5/i7, lots of RAM, SSD). +- VirtualBox is free (paid license unlocks extra features); commercial alternates are VMware and Hyper-V (built into many Windows platforms); VMware Player is free but limited. +- A dynamically allocated virtual disk only consumes space as the guest OS grows, so you can run many VMs on one machine. + +**Detailed Notes** +- RAM planning: a Windows 10 VM should get ~2 GB of RAM — five or six VMs can quickly exceed 16 GB of total RAM. +- SSD strongly recommended: it speeds up every VM operation; booting a Windows 10 VM can go from minutes to seconds. +- VirtualBox install itself is trivial: Next, Next, accept everything, allow the special driver to be installed. +- Creating a VM: give it a name — VirtualBox recognizes known OS names (e.g., "Linux") and auto-suggests/customizes the type; specify RAM; create a new hard disk or use an existing one. +- Hard disk file type options matter mainly when moving VMs between platforms — skip them when starting from scratch. +- Sizing: e.g., specify 50 GB; choose the dynamic option so the disk grows as needed instead of reserving 50 GB immediately. +- First boot fails until you attach an OS image (ISO): Windows 10 needs a full install wizard; Kali Linux is pre-configured — no wizard, usable straight away (shown in the next lecture). + +**Action Items** +- Verify your CPU supports VT-x/AMD-V and check it is enabled in BIOS before installing any hypervisor. +- Download a Linux ISO (e.g., Kali) and complete a full VirtualBox VM creation walkthrough. + +**Key Terms/Concepts** +- **Virtualization**: running a complete OS in software as a VM on a host machine. +- **VT-x / AMD-V**: CPU instruction sets that enable hardware-assisted virtualization. +- **Hyper-V**: Microsoft's hypervisor, available on many Windows editions. +- **VMware / VirtualBox**: virtualization platforms; VirtualBox is free, VMware Player is free but limited. +- **Dynamic disk**: virtual disk that grows with usage rather than pre-allocating full space. + +## Chapter 11 — 4. Overview of Windows 10 + +**Core Insights** +- Windows editions and system requirements are a guaranteed exam topic — memorize which editions exist and what each one can do. +- Two main editions: Home (ships with most laptops/desktops, for home users) and Pro (for corporate networks — the key feature is joining a domain, i.e., being managed by a Windows Server). +- Home cannot join a domain and cannot host Remote Desktop (RDP) connections; Pro can do both. +- Enterprise, Mobile, and Education are volume-license editions: large organizations license them per number of users (e.g., 10,000) instead of buying thousands of individual Pro copies. +- BitLocker full-disk encryption is built into Windows but only available in Pro, not Home. + +**Detailed Notes** +- RDP: Settings → Remote allows enabling Remote Desktop on the Enterprise edition in the demo; the Home edition has no RDP role — you cannot RDP into a Home client. +- "S" edition: a limited version designed for Microsoft Surface-type devices; can be upgraded from S to Home or Pro. +- Pro vs Home comparison: user experience and security basics are the same; differences are in business features such as Group Policy (domain join + server-applied policies require Pro — Home has no Group Policy Objects), Remote Desktop, and Hyper-V (virtualization, covered later). +- BitLocker: available in Windows 10 Pro (it was NOT available in Windows 7 Pro) but not in Windows 10 Home — Home users cannot encrypt their hard disk with BitLocker. +- Licensing model: to equip a company (e.g., 10,000 users) you negotiate an Enterprise license covering X users; same model applies to Mobile and Education editions. +- Resources: the lecture shows links to a comparison table / Wikipedia table listing every edition and its features — worth visiting. + +**Action Items** +- Memorize the Windows 10 edition list (Home, Pro, S, Enterprise, Mobile, Education) and the features unique to Pro (domain join, BitLocker, GPO, RDP host, Hyper-V). +- Check the Wikipedia edition-comparison table and the official Microsoft comparison page. + +**Key Terms/Concepts** +- **Domain join**: connecting a PC to an AD domain so a server manages it via Group Policy — Pro feature only. +- **RDP (Remote Desktop Protocol)**: remote desktop access; hosting it requires Pro/Enterprise, Home cannot receive RDP. +- **BitLocker**: built-in Windows full-disk encryption; Pro only. +- **Group Policy**: server-applied policies for managed clients; Home cannot receive GPOs. +- **Volume licensing**: bulk/enterprise licensing for many users (Enterprise, Mobile, Education).