Files
nexus/knowledgebase/course-notes/IT-Support-Service-Desk-Crash-Course-Notes.md

88 KiB
Raw Permalink Blame History

IT Support and Service Desk Jobs — Crash Course for Beginners

Course Notes (structured from transcripts)

Source: /Users/weishen/mnt/volume2/knowledgebase/course/IT Support and Service Desk Jobs - Crash Course for Beginners Generated: 2026-09-19 Note: Chapter 10 (Final Quiz - Top 30 Technical Interview Questions) is an online Udemy quiz link only, no transcript content. 37 video transcripts across 10 chapters.


Chapter 1 — 1. Introduction

Core Insights

  • Instructor Marius (20+ years in IT: web developer, networking, Microsoft and Cisco exams, manager with degrees in HR and IT, consultant) built the course over ~4 months as a real-world journey into support/service desk engineering.
  • Part 1 covers roughly 70–80% of what a support engineer needs to know — enough to start a job. Part 2 suits people with 5–6 months on the job: monitoring, virtualization, deeper troubleshooting, procedures, career advancement, web applications, interview questions, challenges and quizzes.
  • The course simulates a real service desk with the industry-standard Jira Service Desk instead of theory/videos — you receive real tickets from a manager and an end user and click through resolving them.
  • SLA is taught by watching a live ticket, not just a definition: e.g., 4 hours to reply, 8 hours to sort it out; you see the ticket status change as you work.

Detailed Notes

  • Approach: "not just talk" — real service desk application, simulated environment; hundreds/thousands of similar tools exist, but seeing everything in action transfers to your own device.
  • Part 1 topic map: general skills, hardware, operating systems, networking, basic procedures, service desk tools.
  • Viewer expectations: you have to memorize facts, read documentation, and play with the solutions yourself — the course shows the starting point, no boring lectures or long definitions.

Action Items

  • Practice inside a real service desk application alongside the lectures rather than just watching.
  • After a few months in a support job, evaluate whether Part 2 (monitoring, virtualization, career path) is needed.

Key Terms/Concepts

  • SLA (Service Level Agreement): the time window you must act within on a ticket — e.g., answer in 4 hours, resolve in 8.
  • Support/Service Desk Engineer: entry-level IT role the course trains for.

Chapter 1 — 2. IT Support Roles

Core Insights

  • A service desk provides IT services under a contract between your company and the customer; your job is to sort out the problem, answer the question, or recommend a solution.
  • First-line support is the first point of contact: phone, email, chat, ticket, or discussion board — supporting either internal users or external companies.
  • Core workflow: figure out the problem → log it in a specialist (ticketing) system → give a quick fix, or escalate to second-line support (more knowledge, more tools); second line owns backends, application deployment, big upgrades and projects.
  • It is possible to start knowing almost nothing (some adverts only require working English and the company trains you), but knowing basics makes it far less stressful.
  • Soft skills are ~90% of hiring decisions — technical skills can be taught, attitude cannot.

Detailed Notes

  • Knowledge baseline: IT infrastructure (laptops, workstations, printers, phones), two operating systems (Windows, Linux), basic networking, web solutions, procedures and frameworks — the most popular framework is ITIL (which includes SLA).
  • Prioritization: systems usually carry a priority value; P1 is the highest (everything down), e.g., a website down that sells online outweighs "John can't print but needs it next week."
  • Certificates are not crucial at agent level — CompTIA, Microsoft MTA, Cisco CCNA for tech; PRINCE2/PMP to prove project knowledge; the company will train you.
  • Interview tip: showing eagerness to learn and willingness to take extra steps gets you the job.

Action Items

  • Practice the log → quick-fix → escalate flow and judging ticket priority.
  • Build basics: one Windows + one Linux OS, basic networking, ITIL/SLA concepts, web solutions.
  • Prepare to demonstrate soft skills (politeness, helpfulness, punctuality, communication) since they dominate hiring decisions.

Key Terms/Concepts

  • First-line support: initial contact, triage, logging, quick fixes, escalation.
  • Second-line support: backend infrastructure, deployments, upgrades, complex cases.
  • ITIL: the most popular IT service-management framework/best practices.
  • P1: highest-priority ticket (service totally down).

Chapter 1 — 3. Tools you Will Need Jira Service Desk, Support Tools, and Password Managers

Core Insights

  • Real support work uses four tool types: communication (email + messenger), a ticketing system, a remote-support tool, and a password manager.
  • Ticketing system = Jira Service Desk (Atlassian): free for up to 3 agents in the cloud, nothing to install.
  • End users raise tickets; agents work from a queue: assign the ticket, then drive status (To Do → In Progress → resolved).
  • Remote support (TeamViewer as the example): a viewer on the agent's PC and an agent ("server") installed on every customer device — connect by picking the device.
  • KeePass, an offline password manager: one master password, one entry per application/server, built-in password generator, and clipboard auto-clear (~12 s) for safety.

Detailed Notes

  • Communication: Microsoft Exchange (on-prem email server) or Exchange Online (cloud-hosted email); Outlook via web or Microsoft Office; Skype-style messengers.
  • Getting Jira Service Desk: atlassian.com → Products → Jira Service Desk → "Try it free"; the Pricing page shows a free cloud option up to 3 agents — no install.
  • Demo layout: General Service Desk (tickets from end users), Tasks (assignments from the manager), plus demo/old tickets.
  • Example ticket: Kate Brown — "Cannot open doc1.docx"; the reporter immediately gets an email that someone will look at it.
  • Agent view: the queue is a list of tasks; the case shows the reporter but is not yet assigned → assign it to an engineer or yourself; status "To Do" means nobody started.
  • Remote support pattern: open the tool → see all connectable laptops/computers → select one → authenticate with username/password.
  • KeePass usage: right-click to add entries in groups (e.g., Exchange mailbox username); generate passwords — 9 characters (uppercase, lowercase, digits) is acceptable for a local network, but internet-facing systems need stronger (e.g., 12 characters + special); copying a password clears the clipboard after 12 seconds so it can't be pasted elsewhere by accident.

Action Items

  • Create a free Jira Service Desk cloud account and click through queues, assignment, and status changes.
  • Install and explore a password manager (e.g., KeePass): create entries, generate and copy passwords.
  • Try a remote-support tool (TeamViewer) between two devices to learn the connect flow.

Key Terms/Concepts

  • Queue: the list of tickets/tasks awaiting an agent.
  • To Do: ticket status meaning nobody has started work.
  • KeePass: offline password manager with a single master password.
  • TeamViewer: remote desktop/support tool (viewer + device agents).

Chapter 1 — 4. Let's Simulate Your First Days at Service Desk

Core Insights

  • Day 2 scenario: manager John emails three tickets; each names a device (e.g., T01) plus the task (check the Windows 10 edition on T01).
  • Golden rule: the first thing after opening a ticket is to change its status (To Do → In Progress) before touching anything else — otherwise nobody knows you started working.
  • SLA is tracked live: "time to first response" was green — 4 hours to assign the ticket to yourself; sometimes a status change alone counts as the first response, sometimes you must reply or add a note.
  • Full resolution loop: acknowledge → connect remotely using credentials from the password manager → inspect → answer the ticket → set status Completed/Closed.

Detailed Notes

  • Ticket anatomy: device name (T01, a laptop) + action ("check the edition of Windows 10" — editions: Home, Professional, Enterprise).
  • Two support apps: one keeps usernames/passwords (KeePass example), one connects remotely — support tool with a desktop shortcut listing all connectable machines (TeamViewer as example).
  • Communication: internal "note" (only for you/team) vs "reply to customer"; being proactive ("Hi John, I am working on it") is good practice.
  • Remote session: double-click T01 → username/password from KeePass → connected → right-click This PC → Properties → shows "Windows 10 Pro".
  • Close the remote session, return to the ticketing system, reply "T01 has Windows 10 Pro installed" — put the key fact in bold so the manager spots it — then set status Completed, then Closed.

Action Items

  • Practice the golden loop: update ticket status immediately upon starting, then work — never leave a ticket in a stale state.
  • Drill the flow on a lab machine: connect remotely, read OS/edition info, log the finding, close the ticket.
  • Learn Windows editions (Home/Professional/Enterprise) and where to find them (System Properties).

Key Terms/Concepts

  • In Progress / Completed / Closed: ticket lifecycle states that drive SLA tracking.
  • Time to first response: SLA metric — e.g., 4 hours to first action/assignment.
  • Assignment: attaching the ticket to yourself or another engineer before work starts.

Chapter 2 — 1. Overview of Hardware

Core Insights

  • POST (Power On Self Test) runs on every device at boot to verify hardware is ready before the OS loads.
  • BIOS is the low-level firmware that controls startup and displays key hardware info: product name, BIOS version, CPU, RAM, disks, and the OEM Windows product key.
  • Knowing hardware details (CPU generation, RAM size, disk type) lets you estimate a device's age and capabilities.
  • Hands-on practice on cheap test hardware is the recommended way to learn hardware.

Detailed Notes

  • POST: a set of startup procedures on laptops, desktops, and phones; checks the fan and power supply; if a critical issue is found, the boot process stops to protect the device.
  • BIOS = Basic Input Output System — low-level software that controls basic functions and starts Windows, macOS, or Android.
  • Accessing BIOS setup: no standard key — check the manual; commonly F1, F2, F10, F11 pressed at power-up; some devices (e.g. Lenovo Yoga) have a dedicated physical button.
  • Lenovo Yoga example: BIOS screen shows product name and BIOS version; BIOS can be updated (e.g. for compatibility with a new hard disk or new CPU) but it is a dangerous low-level procedure — a failed update is very hard to recover from.
  • CPU: Intel model numbers indicate generation (e.g. i3-4xxx = 4th Gen, ~7-8 years old at recording; 8th/9th Gen were current then).
  • RAM: 8 GB (8192 MB) is enough for almost all applications and the standard today, except for gaming.
  • Storage: two drives — a standard HDD plus an SSD (solid state, flash-based, fast).
  • Licensing: Windows OEM license is coded into the BIOS/system board; after replacing a failed hard disk you can reinstall Windows with no product key.
  • Learning hardware: read reviews and magazines (graphics cards, power supplies, phones); download the system-board manual (screenshots + definitions); buy an old desktop PC (~$20) as a test device.

Action Items

  • Get any device, enter its BIOS, and identify product name, BIOS version, CPU, RAM, and disks.
  • Download the manual for your system board and study the BIOS settings.
  • Acquire a cheap old desktop (~$20), open it, and inspect the hardware and ports.

Key Terms/Concepts

  • POST: Power On Self Test, boot-time hardware self-check.
  • BIOS: Basic Input Output System, low-level firmware controlling device startup.
  • SSD: Solid State Drive, fast flash-based storage.
  • OEM product key: Windows license embedded in the BIOS/system board.

Chapter 2 — 2. Overview of Hardware - Part 2

Core Insights

  • Port identification is a core general skill; story: a web-support job applicant failed an interview by not knowing which port connects a laptop to a projector (HDMI).
  • USB color/size indicates speed: gray USB 2.0 vs colored USB 3.x vs small USB-C.
  • Video connectors differ: HDMI carries video + audio; DVI and VGA are video-only; DVI (digital) is better than VGA (analog).

Detailed Notes

  • Interview example: applicant for web support engineer at a hosting company was asked to connect a laptop to a projector and had no idea which port to use; the company refused to let him work with customers if he did not know HDMI.
  • Back panel overview: USB ports, Wi-Fi antenna connectors, USB 3.1 ports. Gray USB ports are usually USB 2.0 (old standard); yellow/red/blue USB ports are much faster (USB 3.x); USB-C is a small port, even faster and better.
  • Network Interface Card (NIC) port: connect a network cable for LAN/Internet access.
  • Audio ports: microphone, line in/out, speakers; an optical connection gives the highest quality audio.
  • Connector quick reference: USB → printers, mice, keyboards; HDMI/DVI/VGA → screens and graphics cards; HDMI → video AND audio; DVI and VGA → video only; DVI is better than VGA because it is digital while VGA is analog.
  • The lecture closes by introducing one more port type (Ethernet) as a preview.

Action Items

  • Identify every port on a real PC back panel and state its purpose.
  • Memorize which connectors carry audio (HDMI) vs video only (DVI, VGA).
  • Practice connecting a laptop to a projector or monitor.

Key Terms/Concepts

  • USB 2.0 vs 3.x: older vs faster USB standards, often told apart by color (gray vs blue/red/yellow).
  • HDMI: one cable carrying high-definition video and audio.
  • DVI/VGA: video-only display connectors; DVI digital, VGA analog.
  • NIC: Network Interface Card — the wired Ethernet (RJ-45) port.

Chapter 2 — 3. Basic IT Procedures

Core Insights

  • Support work means following documented procedures step by step, not inventing unique solutions.
  • Customer authorization comes first: verify the caller is entitled to open a ticket (PIN, serial number, prepaid contract).
  • Requests are classified (incident, request for change, task) and each type has its own procedure.
  • Do not memorize procedures — read them from the book/checklist so you never skip a step (pilot checklist analogy).

Detailed Notes

  • Templates: every ticket to a support company receives the same greeting template; templates are standard for external customers (informal greetings only OK for internal users in small companies).
  • Basic call procedure: receive client call → authorize the customer (PIN number, serial number, or proof of advanced payment) → verify they can open a ticket.
  • Wrong/invalid PIN: follow the separate document describing that case; be extremely polite, never dismissive.
  • Then classify: incident = something broken (cannot print, cannot send email, cannot open a website); request for change = planned modification (update the system, add memory); task = e.g. recommend a solution; many other options exist.
  • In practice you receive a book of procedures and just follow it; agents put callers on hold — 'May I put you on hold for a minute? I have to check something.'
  • Pilots are not allowed to run a checklist without a piece of paper or computer listing all steps, because you don't want to miss a step — same logic applies to support.
  • Even if a company asks you to memorize, you should know where to start.

Action Items

  • Practice classifying sample tickets as incident vs change vs task.
  • Always verify entitlement (PIN/serial) before working a ticket, politely.
  • When stuck, open the procedure document and follow it literally.

Key Terms/Concepts

  • Incident: an unplanned breakage ('I cannot print').
  • Request for Change: planned modification (update system, add memory).
  • Task: non-breakage work such as recommending a solution.
  • Authorization: proving a caller is entitled to support (PIN/serial).

Chapter 2 — 4. A User Needs Your Help!

Core Insights

  • First action on every ticket: change its status (to In progress), then acknowledge the user.
  • Answer the real question (which ports for a screen) with a clearly labeled screenshot, not bare text.
  • Annotate images and paste them directly into the ticketing system (Snipping Tool → Edit → Copy, no file save needed).
  • Close the loop: update status to resolved so everything is green and the customer is happy.

Detailed Notes

  • Scenario: Kate opens a ticket — she wants to buy a new system board and asks which port she can use to connect her screens.
  • Step 1: change ticket status to In progress; reply 'Hi Kate, I'm working on it'.
  • Open the board picture and analyze the ports: on the left two ports for mouse and keyboard (PS/2-style); VGA and DVI for a screen; USB; network card port; audio ports.
  • Prepare the answer: label all ports clearly so a non-expert understands, and keep the note neat.
  • Capture the annotated board with the Windows Snipping Tool; no need to save the image — Edit → Copy, then paste it straight into the ticket.
  • Send the final reply with the image and your signature; then change the status again to done — everything green, happy customer.
  • Expect follow-up questions: difference between VGA and DVI, whether both can be used at the same time, whether two screens can be connected.

Action Items

  • Practice the full ticket loop: status → acknowledge → investigate → annotated answer → resolve.
  • Learn to annotate screenshots and paste clipboard images into ticketing tools.
  • Prepare answers for common follow-ups (VGA vs DVI, dual monitors).

Key Terms/Concepts

  • Ticket status: lifecycle state (In progress → resolved), shown green when closed.
  • Snipping Tool: Windows screenshot utility; images can be copied to clipboard without saving.
  • PS/2 port: round connector for mouse/keyboard found on the board photo.

Chapter 2 — 5. Commands you Need to Know

Core Insights

  • Three core Windows commands for support: ipconfig, ping, shutdown — all run from cmd (Command Prompt).
  • ipconfig shows the device's IP address; an IP address identifies a device on a network, like an ID, and is used to send data between two points.
  • ping verifies a remote device is alive before starting a session; 8.8.8.8 (Google) is the classic test target.
  • shutdown can reboot, log off, or power off, with a time delay and a force flag — and can be aborted.

Detailed Notes

  • cmd: type cmd in Start to open Command Prompt; Properties lets you adjust font, layout, and colors (e.g. white background for readability).
  • ipconfig: display/verify IP configuration; IP address = device identifier on a network, like an ID; devices use IP addresses to communicate and exchange data.
  • ping : asks 'are you alive?' — check a device is up before starting a session to avoid failed transfers. Most popular target: 8.8.8.8 (Google, ~99.99% uptime); no reply → your internet is down. Windows sends 4 echo messages and reports 4 replies.
  • shutdown usage: shutdown /r /t 60 /f — /r = reboot, /t = delay in seconds (60), /f = force all applications to close; the system warns 'your PC will be rebooted in one minute'. Cancel the schedule with shutdown /a (restart cancelled).
  • shutdown supports reboot, logoff, or shutdown of a device from cmd; shutdown /? lists all available options.

Action Items

  • Open Command Prompt and run ipconfig to identify your IP address.
  • Ping 8.8.8.8 and an internal device to verify connectivity.
  • Try shutdown /r /t 60 /f and cancel it with shutdown /a; read shutdown /? for the full option list.
  • Customize cmd properties (font/layout/colors) for readability.

Key Terms/Concepts

  • cmd: Windows Command Prompt, the shell for executing commands.
  • IP address: unique identifier of a device on a network, used for routing data between endpoints.
  • ping: ICMP-based reachability test; replies confirm the host is alive.
  • 8.8.8.8: Google's public DNS server, 99.99% uptime, standard ping target.

Chapter 3 — 1. Task 1 - Benchmarking an SSD

Core Insights

  • The manager originally sent three tasks; only one was completed before, so two remained open — service desk work means you do not ignore your manager's tickets.
  • Task: connect to the remote machine T-01 and benchmark its SSD (solid state disk) with a dedicated disk-testing application — no option changes needed, just run the test.
  • The Knowledge Base (KB) is the primary self-service resource: a KB article explained what to do, which software to use, and provided the link to it.
  • Evidence is sent back through safe channels: a company network drive, or your own cloud (e.g., Microsoft OneDrive, iDrive) — never a customer's account.
  • Final verdict: not the fastest SSD out there, but a decent budget SSD — then the ticket is closed.

Detailed Notes

  • Setup: the laptop already has an SSD installed; the job is to measure how fast it reads and writes.
  • Workflow: ticket was pre-assigned → change its status → connect to T-01 → paste the KB link → open the application.
  • The benchmark app is simple: open it, run a test, do not change any options, press Start; it performs file/read-write operations to verify how fast the disk is.
  • First-time tool use is expected — someone will show you how; in most cases it is really simple.
  • Uploading the screenshot: use a dedicated network drive if available; otherwise your own cloud (OneDrive, iDrive) or whatever the company provides — do not use a customer's OneDrive or account.
  • Sharing the result: create a share link restricted to yourself, then copy/paste or drag-and-drop the screenshot into the chat message to the manager (John), save, done.
  • Close-out: answer the question (is it a fast SSD? — decent budget SSD, not the fastest) and close the ticket.

Action Items

  • Practice the full ticket lifecycle: KB lookup → remote connect → run tool → capture screenshot → share evidence properly → report to manager → close ticket.
  • Learn to interpret SSD benchmark results (read/write speeds) to judge whether a drive is budget or high-end.
  • Set up a personal cloud share (OneDrive/iDrive) as an alternative when no network drive exists.

Key Terms/Concepts

  • SSD (Solid State Drive): fast storage with no moving parts; its read/write speed is measured by benchmark tools.
  • Knowledge Base (KB): internal documentation agents consult for steps, tools, and links on common tasks.
  • Ticket: a recorded, assignable service request with status (in progress → resolved); closes after the work is done and verified.
  • Network drive / cloud share: sanctioned storage for evidence screenshots; customer accounts must never be used.

Chapter 3 — 2. Task 2 - Installing an Agent

Core Insights

  • Big-company service desks support hundreds or thousands of users/devices, so physically visiting every machine is impractical.
  • Centralized management solves this: install one small agent per endpoint, then push any application (Microsoft Office, PDF viewer, daily-work apps) remotely with one click.
  • The demo platform (transcribed in the captions as 9-9 / 9-9 pro) is usable both in corporate environments and on your own PC.
  • The KB again drove the task: a short note said the agent installer would be waiting in the Downloads folder of T-01.
  • Verification is dashboard-driven: an installed agent reports back to a central server, and seeing the device discovered confirms it is up and running.

Detailed Notes

  • This is the final ticket of the chapter — task 3 of 3: an agent to be installed.
  • Why agents: users constantly request software (Microsoft Office, viewers, etc.); installing per-device on hundreds of machines is not viable.
  • Deployment model: install the lightweight agent on every device, then push any application you want from the console.
  • Steps: consult KB (agent found in Downloads) → set ticket status to In Progress → connect to T-01 → open Downloads → see the agent installer → provide the password → install completes.
  • Verification: open the platform dashboard (9-9 pro) — it shows one device has been discovered, meaning the agent is reporting to the server; the dashboard also exposes OS, domain name, users, IP addresses, and more for the laptop.
  • Business value: e.g., push a PDF viewer to 500 devices with one click instead of touching each machine.
  • Close-out: message the manager that the agent has been installed, mark the ticket completed — all three manager tasks are now done.

Action Items

  • Practice the agent install flow: KB → connect → locate installer → authenticate → install → confirm the device appears in the dashboard.
  • Explore an RMM/software-deployment tool (agent-based consoles like the one in this course, plus PDQ, Intune-style MDM, etc.) and push a test app to a lab machine.
  • Learn to read managed-device inventory (OS, domain, users, IP) from the dashboard for remote troubleshooting.

Key Terms/Concepts

  • Agent: small software installed on each endpoint that reports to a central server and enables remote software deployment/monitoring.
  • RMM dashboard / management console: central view of discovered devices with inventory details (OS, domain, user, IP).
  • Software push (remote deployment): installing an application to many endpoints at once from a central console via installed agents.
  • Knowledge Base (KB): internal documentation telling agents where installers live and how to perform tasks.

Chapter 4 — 1. Our User Needs Your Help Again!

Core Insights

  • The "Do I know this already?" question: on Windows 10, enable BitLocker for a user and check if the NIC has the latest drivers.
  • You don't need to understand a feature in depth to fix/enable it — knowing what a tool is for and where to find it is enough for first-line work; errors get escalated.
  • BitLocker is a full-disk encryption solution built into Windows, available on Windows Pro and above (not Windows 8/10 Home).
  • BitLocker encrypts the whole drive, not individual files; without the key/TPM, a stolen disk drive is unreadable.

Detailed Notes

  • Topic: operating systems — Windows, macOS, Linux, plus servers; the lecture series ends with a real ticket.
  • BitLocker normally requires a TPM (Trusted Platform Module) chip, which stores the encryption keys.
  • Enabling BitLocker without TPM is possible but not recommended and often against company policy — check policy first.
  • Scenario: user Kate needs BitLocker enabled on a test laptop; ticket flow — open case queue → assign ticket to yourself → reply to Kate ("I'm going to work on it now") → mark ticket in progress.

Action Items

  • Practice the ticket workflow: assign, reply to user, set status.
  • Locate and review BitLocker options in Windows Pro before attempting enablement.

Key Terms/Concepts

  • BitLocker: Windows full-disk encryption tool (Pro/Enterprise editions).
  • TPM (Trusted Platform Module): hardware chip that stores BitLocker encryption keys.
  • Ticket: tracked support request assigned to a technician, worked through statuses (open → in progress → closed).

Chapter 4 — 2. An Easy Job

Core Insights

  • BitLocker enablement, part 2: connect to test laptop TI-01 via RAdmin and turn on BitLocker; admin passwords live in KeePass.
  • If a laptop is about to sleep/go to sleep, do not attempt advanced operations (can break Windows) — call the user to plug in the power supply first.
  • BitLocker failed because the laptop has no TPM module; the error message asked to "allow BitLocker without a compatible TPM" — Windows requires enabling one extra feature.
  • When stuck: inform the customer of the delay, then escalate to manager/senior/2nd-3rd line, or re-assign the ticket — don't just Google.

Detailed Notes

  • Start menu → type "BitLocker" → "Turn on BitLocker". Kate is not a local administrator, so provide your own admin credentials (from KeePass).
  • Fix (senior-level, not first-line): run gpedit.msc (Local Group Policy Editor) as local admin → Computer Configuration → find "Allow BitLocker without a compatible TPM" → Enable → Apply/OK.
  • Push the policy to the device: gpupdate /force.
  • Reconnect and enable BitLocker: without TPM, a strong startup password is required (recommended ~20 characters; Windows rejects short ones).
  • Critical step: back up the Recovery Key (save to file or print to PDF) — if you lose both password and recovery key, there is no backdoor and the disk is unrecoverable; store the file in a secure place (it can recover the password).
  • Encryption options: encrypt used space only (device already in use); skip system check to avoid reboot.
  • Recovery file contains a BitLocker Recovery Key plus an identifier used to recover the disk.
  • Full encryption on an in-use laptop can take a few hours — can run in background, but better to leave it on and verify.

Action Items

  • Practice gpupdate /force and gpedit.msc policy navigation.
  • Always back up the recovery key and store it securely.

Key Terms/Concepts

  • gpedit.msc: Local Group Policy Editor — tweaks local OS policies.
  • gpupdate /force: refreshes/forces policy settings immediately.
  • Recovery Key: 48-digit key (with identifier) to unlock an encrypted disk when the password is lost.
  • Escalation: passing a ticket to a higher support line or senior technician.

Chapter 4 — 3. Overview of Microsoft Operating Systems - Windows 10

Core Insights

  • Legacy Windows (XP, Vista, 7) are end-of-life and should not exist in corporate environments; most companies standardized on Windows 10 (free upgrade years ago).
  • Windows 10 editions: Home, Pro, Enterprise; corporate environments run Pro and Enterprise, rarely Home.
  • For hundreds/thousands of devices, administration is centralized via Windows Server with Active Directory — e.g. one policy can enable BitLocker on all machines instead of configuring each.
  • Service-desk work: password resets, driver troubleshooting, using remote support tools.

Detailed Notes

  • Remote support tools: RAdmin (Radmin) and RealVNC require licenses (free trials); TightVNC is free but lacks features (e.g. no encryption/RealVNC extras). These tools require being on the same local network (and firewall rule changes, not recommended).
  • TeamViewer is a client-server solution: works across the internet (user in another country), no router/firewall changes; good for supporting dispersed users. Others: LogMeIn.
  • DHCP leases IP addresses automatically (no manual assignment for 500+ laptops); DNS translates names into IP addresses (e.g. facebook.com → IP).
  • Demo: ping facebook.com resolves via DNS; ipconfig (Windows) / ifconfig (Linux) shows your DNS server.
  • Admins don't create accounts via Settings → Accounts; instead right-click This PC → Manage → Local Users and Groups → Users → New User.
  • Device Manager shows all hardware; right-click device → Properties → Update Driver / Driver Details / Uninstall Driver. New hardware or misbehaving devices usually need a driver update; Windows can auto-search for the best driver.

Action Items

  • Try ipconfig and ping in CMD; open Device Manager and inspect drivers.
  • Compare a remote tool like TightVNC vs TeamViewer.

Key Terms/Concepts

  • Active Directory: central management of devices, users, permissions, and policies.
  • DHCP: automatically assigns IP addresses to devices.
  • DNS: translates hostnames (facebook.com) into IP addresses.
  • Device Manager: hardware inventory and driver management console.

Chapter 4 — 4. Let's Connect to MacBook Pro!

Core Insights

  • TeamViewer connects remotely to a MacBook Pro across the internet without touching routers/firewalls — unlike RAdmin, which works only on the local network.
  • TeamViewer is free for home users but requires a license for commercial/support use.
  • macOS security blocks remote control by default: the app must be allowed under System Preferences → Security & Privacy → Accessibility, or TeamViewer can't control mouse/keyboard.

Detailed Notes

  • The customer runs TeamViewer as a single file (no install); it shows an ID and a one-time password, or "unattended access" with a fixed password — provide both to connect.
  • Basic admin tasks: Users & Groups (unlock the padlock to make changes), account creation, wallpapers.
  • Bluetooth problems: usually fixed by turning Bluetooth off/on or disconnecting and reconnecting the device.
  • Printers can be added in Settings; backups use Time Machine (can exclude items).
  • Finder: Favorites, Locations, Tags (similar to Windows). End-user apps to know: Maps, Messages, Contacts, Calendars, Notes.
  • Networking: wireless settings, DHCP for IP assignment (don't assign static IPs to end users), view/connect/disconnect networks, change passwords.
  • Remote-session pitfall: never disconnect the wireless network while connected remotely — the session drops; keep a backup path (wired connection or second NIC) when testing wireless.
  • Activity Monitor ≈ Windows Task Manager; Terminal: ifconfig (like ipconfig), ping.
  • Recommendation: spend 30–45 minutes clicking around a MacBook Pro to learn it.

Action Items

  • Practice a TeamViewer remote session and the Accessibility permission setup.
  • Explore System Preferences and Time Machine.

Key Terms/Concepts

  • TeamViewer: internet-based remote support tool (ID + password).
  • Accessibility permission: macOS gate that lets apps control the desktop.
  • Time Machine: macOS built-in backup tool.
  • Activity Monitor: macOS task/process manager.

Chapter 4 — 5. What to Expect From a Linux Device

Core Insights

  • Multiple OSes can run on one machine via virtualization — e.g. VirtualBox; the course's extra lecture (from the ethical hacking course) covers VirtualBox + Linux install step by step.
  • Demo uses Kali Linux, a security-focused Linux distribution with many pre-configured tools; with VirtualBox you can open one file and have Linux running within minutes.
  • Linux has a GUI for many tasks, but the terminal and commands are central; 80–90% of support jobs are Windows, so Linux support is niche but real.

Detailed Notes

  • GUI basics: change wireless/wired settings, view IP address, DHCP or static IP, turn the network card off/on; file manager shows Documents, Downloads, Desktop, Home, Other locations, Network.
  • Terminal commands: ifconfig — show IP address and network settings; ping — continues pinging until stopped with Ctrl+C; clear — clear the screen; ls — list folders and files; cd — change directory (e.g. cd Documents then ls); mkdir — create a directory.
  • Use Up/Down arrow keys to recall/reuse recent commands; list previously used commands (history).
  • Run man <command> to learn what a command does and see all its switches.

Action Items

  • Install VirtualBox + Kali Linux and click around the GUI.
  • Practice ls, cd, mkdir, ifconfig, ping, man in a terminal.

Key Terms/Concepts

  • Virtualization: running multiple operating systems on one device (VirtualBox).
  • Kali Linux: Linux distribution designed for security testing.
  • ifconfig / ls / cd / mkdir / man: core Linux terminal commands.

Chapter 4 — 6. Windows Server 2016

Core Insights

  • Only Windows Pro/Enterprise can be joined to a domain and managed by Windows Server — a key difference vs Home.
  • As a service desk agent you rarely connect to servers directly; when you do, it's via RDP (Remote Desktop Protocol), built into Windows, not RAdmin/TeamViewer.
  • RDP takes over the session: the logged-in user sees "someone else is using your computer" and can't watch — bad for user support, great for managing servers in a data center.
  • Active Directory Domain Services (AD DS) centralizes users, groups, permissions; the main service-desk tool is Active Directory Users and Computers.

Detailed Notes

  • Servers can be cloud-based, dedicated hardware, or a VirtualBox VM.
  • AD structure: a domain (e.g. test.local) is the logical container that devices join; folder-like items are Organizational Units (OUs), not folders.
  • Create user: right-click OU → New → User; naming follows company procedure/KB (e.g. M.Smith, MikeSmith, Mike.Smith) — check the knowledge base/manager, especially for external companies.
  • Password: set initial password; "user must change password at next logon" option enforces self-chosen passwords.
  • User properties → Account: Disable account when an employee leaves (don't delete immediately — they may have files/access); Reset Password (hand temp password, user changes it on login); Unlock account; Logon Hours — restrict when a user can log in (e.g. Tuesday until 3:30 PM).

Action Items

  • In AD Users and Computers, practice creating a user and toggling logon hours.
  • Learn your company's AD naming convention.

Key Terms/Concepts

  • RDP: Microsoft Remote Desktop Protocol for remote server/PC connection.
  • Domain: logical group of devices managed by Active Directory.
  • OU (Organizational Unit): AD container for users/computers/groups.
  • Logon Hours: time restrictions for user sign-in.

Chapter 4 — 7. Yet Another Ticket - Troubleshooting

Core Insights

  • When asked to verify whether a machine crashed recently, start with Event Viewer: Windows Logs → Application, Security, Setup, System — not all errors are critical.
  • Reliability History gives a graphical timeline; red entries mark critical problems (system crashes, RAM issues) and can be saved as a report.
  • The Microsoft Management Console (mmc) bundles all admin tools — Device Manager, Event Viewer, Disk Management, Services — in one console via snap-ins.
  • Services are small background applications; when a print job fails, restart the print server/spooler service.

Detailed Notes

  • Event Viewer: investigate specific events (e.g. event 99) — here it explained why the manager asked to check TI-01 (machine cannot talk to a server?).
  • Reliability History: filter/save as a report; used to answer "did this PC crash in the last couple of weeks?" — save the report and reply to the manager.
  • Open mmc via Win+R → type mmc (Microsoft Management Console) → File → Add/Remove Snap-ins → pick Device Manager, Event Viewer, Disk Management, Services — all in one place.
  • To manipulate services with admin rights: right-click CMD → Run as administrator, then run mmc so the whole console inherits admin rights, open Services, right-click the service → Restart.
  • Typical request flow: verify crash history → filter for critical errors → save a report → update/close ticket.

Action Items

  • Practice building an mmc console with Device Manager, Event Viewer, Services snap-ins.
  • Restart a service (e.g. print spooler) and check Event Viewer after.

Key Terms/Concepts

  • Event Viewer: Windows log viewer (Application/Security/Setup/System).
  • Reliability History: graphical crash/problem report tool.
  • mmc: Microsoft Management Console — hosts administrative snap-ins.
  • Service: background application managed via the Services console.

Chapter 4 — 8. Installing Malwarebytes using Ninite Pro

Core Insights

  • This task is a change (not an incident/issue): push Malwarebytes to TI-01 — the manager assumes you already know the toolchain (Ninite Pro, RAdmin, KeePass), so the ticket gives only the goal, not steps.
  • Ninite Pro silently deploys applications in the background — the user sees no prompts; a desktop icon simply appears after a few minutes.
  • Malwarebytes complements antivirus (works alongside Kaspersky, Bitdefender, etc.); it isn't sufficient as the only protection.

Detailed Notes

  • Workflow: open the request → assign to yourself → set status "implementing" → open Ninite Pro (laptop TI-01 listed) → Apps/Ops → select Malwarebytes → deploy/install to TI-01.
  • Connect to TI-01 via RAdmin to verify — no pop-ups or messages appear on the user's screen during silent install.
  • Ninite Pro also updates installed applications when new versions are released.
  • Malwarebytes licensing: 14-day trial; the free version does not run in the background — you can scan on demand but get no real-time protection.
  • Close the change: note the installed version (e.g. 4.0.4.49), describe everything in detail in the ticket, save — change complete.

Action Items

  • Practice a Ninite Pro silent install and verify via remote session.
  • Try Malwarebytes trial/free scan to see on-demand vs real-time modes.

Key Terms/Concepts

  • Change request: planned, approved modification (vs incident/issue).
  • Ninite Pro: centralized silent app installer/updater.
  • Malwarebytes: anti-malware scanner that complements traditional antivirus.

Chapter 5 — 1. Installing Office 365 Apps

Core Insights

  • Service desk work involves many Microsoft Office issues, often from non-technical users (real tickets: "What's PowerPoint?", "red icon on my desktop") — patience and plain-language explanations are core job skills.
  • Outlook is the most-supported Office app in business: it manages email, calendars, and contacts; managers depend on it, so Outlook tickets can be higher priority.
  • Office 365 licensing is complicated (Home vs Business, E1/E3/E5, Office 365 vs Microsoft 365); a service desk analyst must study the options to recommend the right solution.
  • Since Office 365, Office is subscription-based (pay monthly/yearly, never own it) — a shift from the old one-time purchase model.

Detailed Notes

  • Presenter's package: Office 365 Business. Two reasons chosen: (1) Outlook is NOT included in many Home packages; (2) Business allows commercial use — Home licenses don't.
  • License rules: Home = up to 6 family members; Business = 1 user but installable on up to 5 devices that the company owns.
  • Large companies (hundreds/thousands of users): Office 365 E3 or E5 — cheaper (~$8/month per user), more features.
  • Confusing lineup: Office 365 / Microsoft 365 / Home 365 / Office Business 365 / Office 365 E1-E5. When in doubt, a Microsoft partner can recommend the best fit.
  • Install: log in at office.com → download "Office 365 apps" → one click installs everything (no prompts asking which apps).
  • Older versions (e.g. Office 2010): download via Microsoft link, enter product key, verify, package downloads (presenter verified this works).
  • Cost comparison: Office 2010 bought once 11 years ago (£300-400); now ~$20-30/month with flexibility to pause/resume — no $500 upfront. Prediction: even Windows itself will become subscription-based.

Action Items

  • Practice explaining Office basics to non-technical users without jargon.
  • Study the current Office 365/Microsoft 365 license comparison (Home vs Business vs E3/E5) so you can recommend plans.
  • Walk through an Office install from office.com on a test machine.

Key Terms/Concepts

  • Office 365 / Microsoft 365: subscription plans for Office apps; names overlap confusingly.
  • Office 365 E3/E5: enterprise plans, cheaper per user at scale.
  • Product key: code needed to download/verify older, non-subscription Office versions.
  • Subscription model: pay periodically to use software; you never own the license.

Chapter 5 — 2. Outlook and Emails

Core Insights

  • Outlook can be used as a web app (Outlook on the web/OWA) or as the desktop client; both work simultaneously and synchronize.
  • Exchange-based accounts (Microsoft Exchange / Exchange Online — a paid Microsoft email server service) auto-configure in Outlook: just enter the email address, no server details needed.
  • Non-Exchange accounts (Gmail, Yahoo, own server) require incoming/outgoing server settings — the most popular interview question at service desk hiring.
  • Data file types: Exchange uses OST (syncs with server); POP3 accounts store mail in PST — backing up email = copying the PST file.

Detailed Notes

  • Demo account: Exchange Online address (onmicrosoft.com domain); you can later move to your own domain; presenter cancelled it after recording.
  • Setup on a new PC: Outlook searches for accounts automatically; if already logged in with the same account, nothing to configure.
  • Incoming server: POP3 protocol, port 110 (port = numeric identifier of a service); downloads email to the PC.
  • Outgoing server: SMTP (Simple Mail Transfer Protocol), port 25.
  • Encryption option: SSL/TLS — the same tech behind HTTPS in your browser (the "S" = secure); enforced by the email administrator.
  • Adding Gmail: Outlook auto-detects the server; your own server/Yahoo requires filling in all mailbox fields manually.
  • Exchange behavior: emails synchronize with the server (no copying needed) — unlike POP3 which downloads and stores locally. IMAP exists for other accounts (mentioned, out of scope).
  • Common Excel ticket: spreadsheet prints across two pages → remove page view, switch to landscape, change size — everything fits one page.
  • "Account error" in Office apps: Office uses the Windows login name (e.g. Mike), but the license belongs to another user (Marius) → click the correct licensed account. Recommendation: keep everything under one name per user to avoid this.

Action Items

  • Memorize port 110 (POP3 incoming) and port 25 (SMTP outgoing) — classic interview questions.
  • Practice setting up Gmail vs Exchange accounts in Outlook on a test machine.
  • Learn where OST/PST files live and how to back up by copying the PST.

Key Terms/Concepts

  • POP3: incoming email protocol, port 110, downloads mail to the client.
  • SMTP: outgoing email protocol, port 25.
  • SSL/TLS: encrypted connection protocol (same as HTTPS).
  • OST/PST: local Outlook data files; Exchange uses OST, POP3 uses PST.
  • Exchange Online: Microsoft's cloud email service (paid).

Chapter 5 — 3. Yet Another Ticket - Issues With Microsoft Word

Core Insights

  • Walkthrough of a real ticket: "How can I password-protect my doc?" — resolved by calling the user and guiding them through Word's settings.
  • Word offers two separate passwords: one to OPEN the document, one to MODIFY it.
  • There is NO official way to recover a password-protected Word document — no master password, no backdoor — even for IT.
  • The only recovery path is a brute-force password-cracking tool, and only with manager + security team approval; never recommend it to end users.

Detailed Notes

  • Call-based resolution flow: confirm the user has the document ready → File → Save As (any location) → in the Save As dialog open Tools → General Options → set "password to open" and/or "password to modify" → save.
  • Polishing the ticket: add a note to the ticket documenting the resolution.
  • Bonus question scenario: user forgets the password → IT cannot open the file officially.
  • Brute force attack: an application tries every possible combination one by one (aaa, aab, aac…). It's a guessing process, not password "recovery"; can take very long for strong passwords.
  • Policy guidance: password-cracking is not a normal service desk task, and recommending tools to customers may be unauthorized; always escalate to your manager and security team first.

Action Items

  • Practice password-protecting a Word doc (open + modify passwords) and test both prompts.
  • Know your company's policy on password recovery/cracking before handling such requests.

Key Terms/Concepts

  • Password to open / password to modify: two independent protections in Word (Tools → General Options in Save As).
  • Brute force attack: trying all possible password combinations until one works.
  • Backdoor/master password: does NOT exist for Office documents — a common user misconception.

Chapter 6 — 1. Basic Networking Terms

Core Insights

  • A network exists whenever at least two devices are connected and exchange data — it does not require a cable.
  • Every device on a network has a MAC address: a unique, manufacturer-assigned physical hardware address that you do not configure yourself.
  • Networks are classified by size: PAN (personal), LAN (local area) and WAN (wide area); a WAN connects two LANs via a router.
  • You can find your own MAC address and default gateway on Windows with the ipconfig command.
  • The best way to learn networking is to log in to a real router and explore its settings.

Detailed Notes

  • MAC address:
    • Physical hardware address, unique per device, assigned by the manufacturer at the factory (e.g., to the wireless card inside a laptop) — you don't change it, you just use it.
    • Used by devices inside a local area network for communication.
    • View it on Windows: run ipconfig, find your network card, and read the Physical Address field (same thing as MAC address).
  • Network components:
    • Network Interface Card (NIC) plus a network cable (RJ45 connector) for wired connections; a wireless NIC is used for Wi-Fi instead — either works because the definition of a network is just two devices exchanging data.
    • Example: a Bluetooth headset paired with a phone streaming Spotify is a valid network (a PAN — Personal Area Network).
    • LAN: covers a limited area — one building, one office, one big site.
    • WAN: covers a large area; e.g., connecting a LAN in New York to a LAN in Washington creates a WAN.
    • Switch: the device used inside a LAN to connect many devices — printer, server, scanner, computers. (Pronunciation aside: router, not "router".)
  • Default gateway:
    • Shown in ipconfig output; it is the address of your router.
    • At home, open a web browser and type your default gateway IP — ~99.99% of the time you can connect to the router's web interface.
    • Login needs a username/password: often printed on a label on the router, sometimes sent by email from your company, or set by you when you first configure a new router you bought.
  • Next lecture preview: a demo ASUS router at demo.ui.asus.com so you don't have to touch your own router if you're not comfortable.

Action Items

  • Run ipconfig on your PC and locate your Physical Address (MAC) and Default Gateway.
  • Open a browser, type your default gateway IP, and log into your own router.

Key Terms/Concepts

  • MAC address: unique physical hardware address assigned by the manufacturer, used within a LAN.
  • NIC: Network Interface Card — wired or wireless hardware enabling network connection.
  • RJ45: standard connector for network (Ethernet) cables.
  • PAN / LAN / WAN: personal / local / wide area network, scaling by geographic coverage.
  • Switch: LAN device that lets many devices connect and communicate.
  • Router: device that connects networks (e.g., LAN to WAN/Internet).
  • Default gateway: the router's address on your local network; used to reach other networks.

Chapter 6 — 2. Let's Connect to a Router

Core Insights

  • Logging into a router shows a dashboard/network map: Internet status, number of connected devices, and how each device is connected.
  • Better routers support more than one Internet uplink (e.g., broadband + 4G/LTE via USB dongle) and can use both at the same time.
  • New routers often ship with an open (no-password) wireless network — you MUST secure it before use.
  • Use WPA2 (or WPA3 if available) for wireless security; avoid WPA and WEP.
  • The router's LAN settings show the DHCP server, which automatically assigns IP addresses to all devices on the network.

Detailed Notes

  • Demo used: an ASUS demo router (not a home router) — logging in reveals a dashboard with a live view of what is happening.
  • Network map: similar to a dashboard; in the demo it shows 7 devices connected; clicking the device list shows how each one is connected.
  • Multiple Internet links:
    • Cheap routers: only one Internet connection option.
    • More expensive routers: multiple options — e.g., a broadband connection plus a USB dongle with a 4G/LTE SIM as fallback.
    • This is why routers have a WAN port and can use both connections simultaneously: broadband as the primary link and the secondary as backup.
  • Wireless security checklist for a brand-new router:
    • Out of the box many routers (e.g., ASUS) arrive as an open system — no wireless password; anyone could join your LAN.
    • Before using it: go into wireless settings and enable WPA2 (choose WPA3 when possible).
    • Avoid legacy protocols WPA and WEP — they are insecure.
  • LAN tab: shows the DHCP server status — DHCP means the router automatically assigns IP addresses to all devices in the network. Also offers wireless configuration options.

Action Items

  • Log into your router (or use a vendor demo router) and read the network map/dashboard: how many devices are connected and how.
  • Check your wireless security mode and change it to WPA2/WPA3 if it is WEP, WPA, or open.
  • Identify your router's WAN/Internet options and understand primary vs. secondary (4G/LTE failover) connections.

Key Terms/Concepts

  • Network map/dashboard: router homepage showing connected devices and link status.
  • WAN port: router port for the Internet/upstream connection.
  • USB dongle / 4G LTE: alternative Internet uplink plugged into the router.
  • DHCP: service on the router that auto-assigns IP addresses to LAN devices.
  • WPA2 / WPA3: modern, secure Wi-Fi encryption standards.
  • WEP / WPA: older, weak Wi-Fi security — avoid.

Chapter 6 — 3. GPO - Group Policy Object

Core Insights

  • GPO (Group Policy Object) lets IT control settings on many computers at once instead of configuring each device manually.
  • Earlier lectures showed pushing applications and installing an agent centrally (e.g., no need to install or update a PDF viewer on every device individually).
  • GPO is the answer to "what if I need to change something on 500 devices?" — you change it once, centrally.
  • GPO enforces end-user restrictions: which desktop icons are allowed, wallpaper, network settings, and more.
  • Policies are assigned per computer or per user account in Active Directory.

Detailed Notes

  • Motivation: walking to every device is not feasible; centralized management is required at scale (change a setting on 500 machines at once).
  • Use cases:
    • Control what end users are allowed to do with their company laptop (it is meant for work).
    • Prevent users from changing network settings or changing their wallpaper.
    • Enforce a corporate standard: define which icons appear on the desktop, force a specific wallpaper (e.g., a bank's logo on every screen — important when employees share screens with customers or clients accept policies on-screen).
  • Scope: GPO can modify hundreds to thousands of Windows settings/options — going through all of them can keep an admin busy for weeks.
  • Assignment: after configuring a policy, you assign it — to a computer object or to a user account.
  • Context: GPO is an Active Directory feature — a powerful toolset for managing all devices in an organization.

Action Items

  • Explore the Group Policy Management console in a lab/Active Directory environment: create a sample GPO.
  • Practice assigning a GPO to a computer (computer configuration) vs. a user (user configuration).
  • Try small settings in a test environment (e.g., restrict desktop icons or force a wallpaper) before touching production.

Key Terms/Concepts

  • GPO (Group Policy Object): central set of rules applied to users/computers in Active Directory.
  • Active Directory: directory service that stores user/computer accounts and the target for GPO assignment.
  • Computer vs. User configuration: a GPO can target either the machine or the logged-in account.
  • Agent/central deployment: pushing software (e.g., PDF viewer) centrally rather than installing per device.

Chapter 7 — 1. ITIL in a Nutshell

Core Insights

  • ITIL is the framework behind most service desk procedures; a full official course lasts ~3 days (8 hours/day), but a service desk agent only needs a handful of everyday terms.
  • ITIL 4's service value chain is a chain of activities: Plan, Improve, Engage, Design & Transition, Obtain/Build, Deliver & Support.
  • The four dimensions of service management: organization and people, value streams and processes, partners and suppliers, information and technology — useful to impress managers, but not used daily.
  • Terms you will be assumed to know on the job: SLA, OLA, CAB, ECAB (emergency CAB), and change freezes.
  • Everything is aimed at delivering the best value and best service to customers.

Detailed Notes

  • SLA (Service Level Agreement): agreed service targets — e.g., "4 hours to reply to my customer, 16 hours to close the ticket." It is the agent's responsibility. Data centers quote SLA uptime, e.g., 99.9%.
  • OLA (Operational Level Agreement): an agreement between an IT service provider and another part of the same company (department-to-department, e.g., one department and another).
  • CAB (Change Advisory Board): approves changes. Example: deploying a cloud-based antivirus solution on 500 devices is a big change that needs approval — unlike fixing a ticket about password-protecting a Word document.
    • Process: submit a special document → get invited to a CAB conference call → present the change so both technical staff and managers understand what you want to achieve → include a backup plan (what you'll do if something goes wrong) → show how you will measure everything. You fill in a template with several fields.
  • New service desk agents are rarely asked to raise changes as a first task; changes are often handled by a different department or second-line staff.
  • ECAB (Emergency CAB): for urgent changes. Example: Cisco announces a critical firewall bug; the fix requires a firmware update and reboot — that is still a change, but a normal CAB meeting (weekly/monthly) is too slow; you must act within hours, so you go to an emergency CAB and justify why it cannot wait.
  • Change freeze: e.g., at Christmas, no changes are introduced because something can go wrong; any change must be justified as an emergency. Change calendars in your applications flag freeze periods and warn you.

Action Items

  • Memorize SLA / OLA / CAB / ECAB definitions and the service value chain activities before interviews — most applicants can't even define SLA.
  • Practice the classification test: is this a routine fix, or a change that needs CAB/ECAB approval (scale = number of devices affected)?

Key Terms/Concepts

  • SLA: Service Level Agreement — agreed response/closure targets (e.g., reply in 4h, close in 16h).
  • OLA: Operational Level Agreement — service agreement between parts of the same company.
  • CAB: Change Advisory Board — approves non-urgent changes with documented plans.
  • ECAB: Emergency Change Advisory Board — fast-track approval for changes that can't wait days.
  • Change freeze: period (e.g., holidays) when changes are forbidden unless justified as emergencies.
  • Service value chain: ITIL 4's chain of value-adding activities.

Chapter 7 — 2. ITIL in a Nutshell - Part 2

Core Insights

  • Service operations run on three ticket types: incidents (something broken), problems (root cause of many related incidents), and service requests (a user asking for something to change).
  • Escalation is two-way: you escalate what you can't solve, and unsatisfied users can escalate you to your manager behind your back.
  • Continual Service Improvement (CSI) — analyzing, reviewing, and recommending improvements — is part of the job, including flagging security issues.
  • Documentation discipline matters: notes must let the next person understand what happened; configuration items must be updated whenever details change.
  • Mistakes are inevitable; the goal is to learn and progress from first line toward second/third line.

Detailed Notes

  • Incident: something broken that you fix — user "can't print," "can't connect to the Internet," "can't log in."
  • Problem: when many incidents share one cause — e.g., 15 calls about an Exchange server / "I can't download my emails" — it is not just an incident; it affects many users and must be raised and fixed.
  • Service request: user wants something changed. Sometimes you can't finish a task yourself — e.g., an earlier task where there was no TPM module and someone had to enable a security policy (BitLocker); you escalate: "I don't know how to do it, can you help me please."
  • Customer escalation: in most ticketing systems the user has an escalation option; if unhappy, they can escalate to your leader/manager without you knowing — you find out days later when your manager calls a meeting to understand what went wrong. In a good company it is treated as a learning exercise; sometimes it is just an upset user.
  • CSI: analyze, review, make recommendations to improve services; tell your manager or a senior person — a really small thing can make a huge difference.
  • Security reporting: if you notice a customer saved a document with a password in clear text, don't lecture the user; discuss it with your manager, who takes it from there.
  • Monitoring: systems send alerts, events, and incidents; your job is to sort them out.
  • Documentation: keep knowledge base pages and notes up to date — e.g., if you change a server's IP address, modify the document straight away: go to assets and update the configuration item. Someone will use that information within hours; when you go home, a colleague must be able to read your notes and reconstruct what happened. Same applies to tickets, incidents, and changes: describe what the problem was.
  • Handover: many places have a page to monitor/update what happened in the last 8/16/24 hours — especially important before escalation, because the person you escalate to knows more than you and will challenge obvious mistakes.
  • Cautionary example: first-line network agent, customer says "my internet is down"; agent asks "can you see the lights on your router?" — customer says no → agent escalates with "your router is broken." A field engineer was sent on-site to replace the router when the real fix was simply pushing the power cord back in. Verify a bit more before escalating.
  • Expect to make mistakes — it's not a question of if but when; learn from them and you'll become a second/third line guy in a few years.

Action Items

  • Practice classifying tickets as incident / problem / service request and deciding when to escalate vs. fix yourself.
  • Build the habit of writing notes a colleague could act on without talking to you; keep CMDB/configuration items current when anything changes.

Key Terms/Concepts

  • Incident: unplanned interruption (e.g., can't print) that must be restored.
  • Problem: underlying cause of multiple related incidents affecting many users.
  • Service request: user-initiated request to change or provide something.
  • Escalation: raising a ticket to higher/specialist support; also customer complaints rising to management.
  • CSI: Continual Service Improvement — analyzing and recommending service improvements.
  • Configuration item (CI): a tracked asset (e.g., a server and its IP address) that must stay accurate.
  • TPM/BitLocker: example from earlier tasks — a missing TPM module required enabling a security policy.

Chapter 8 — 1. An Interview Process

Core Insights

  • Job hunting follows a standard pipeline: advert → application (CV + cover letter) → screening call → interview → offer; expect each step to take time.
  • No single job site lists everything — apply directly on company career pages; many firms only advertise on their own website.
  • Recruiters may spend only ~5–6 seconds on a CV when there are hundreds of applications, so yours must be flawless and instantly scannable.
  • Even HR screeners can throw basic technical questions (e.g., "what port is SMTP on?" — port 25), so review fundamentals before the first call.

Detailed Notes

  • Job sources: online adverts, direct applications to companies, and recruitment agencies working on behalf of firms; never rely on one website/engine as the only source — many big companies post jobs only on their own site.
  • Application materials: a polished CV using a clean template, plus a cover letter; if English is not your native language, have a native speaker check it — small mistakes look terrible against hundreds of applicants; keep a professional LinkedIn profile.
  • Patience: it can take a few weeks before anyone even opens your application.
  • Screening phone call (agency or HR): typical questions — availability, salary expectation, experience, "tell me about yourself", why you want this job, why you applied, why you want to change jobs, availability for an on-site interview, what you want to achieve in the next five years.
  • Technical screening: HR staff can ask technical questions from a prepared list; example given: SMTP port number (port 25 — "you know it or you don't"). Review the course's final quiz — a Top 50 interview questions list.
  • Interview: on-site or remote (Skype or the company's own platform); a short meeting with a manager and an engineer; many companies give a technical test (often pure memorization), while conversational interviews let you show real understanding. Find a quiet place, stay relaxed, project that you're the best candidate.
  • Offer stage: an e-mail saying "we can hire you — here is what we can offer."

Action Items

  • Apply directly on big local companies' career sites, not only job portals.
  • Get CV/cover letter proofread; polish your LinkedIn profile.
  • Prepare answers to the standard screening questions; review the Top 50 interview questions quiz.
  • Drill basic protocol/port facts (SMTP = 25) in case HR tests you.

Key Terms/Concepts

  • SMTP: email-sending protocol; its well-known port is 25.
  • Agency: a third party recruiting on a company's behalf.
  • Cover letter: short letter accompanying the CV that tailors you to the role.

Chapter 8 — 2. Tips for you

Core Insights

  • You will land an IT job if you are patient, competent, and visibly willing to learn — but it takes time.
  • A CV with zero experience must still show proof of effort: completed courses, home labs, tools actually touched.
  • You can manufacture experience: freelance small jobs, be active on discussion boards, stay current on hardware/software.
  • Lying on a CV backfires — managers are often technical and will probe claims with questions.

Detailed Notes

  • Don't send a CV saying "I know nothing about IT": show something — completed online courses (not a Microsoft certificate, but still evidence), e.g. "I completed 15 courses, I created a few labs."
  • Sample CV line for no experience: "I built a big lab at home — installed Active Directory, Windows Server, Windows 10; used PRTG for monitoring; used a software-deployment/RMM tool to push software to my end devices; played with Kaspersky Cloud/Endpoint Protection."
  • Freelancing as a starting point: post an ad ("I can fix your wireless issues"); a client calls, you pop in and fix it.
  • Stay active online: join discussion boards to ask and answer questions; read tech magazines; keep up to date on hardware/software — e.g., be able to recommend a NAS (network-attached storage) device on request.
  • Career reality: IT is not a 9-to-5 job — continuous learning, labs, and exams; the payoff is helping people, good pay, job security after a few years, and specializations (networking, cloud, Microsoft, Cisco).
  • Don't lie: never claim "I installed 500 servers in the last five years" if you installed a couple in a virtual machine; as a technical manager he routinely asks a few technical questions, surprising candidates.
  • Mindset: stay patient, hope someone gives you a chance — it will happen.

Action Items

  • Build a home lab (Active Directory, Windows Server, monitoring, deployment tool) and list it on your CV.
  • Take small freelance IT jobs (e.g., fixing home Wi-Fi).
  • Join discussion boards; read tech news/magazines weekly.
  • Keep every CV claim honest — expect technical verification in interviews.

Key Terms/Concepts

  • NAS (Network-Attached Storage): dedicated file-storage device on the LAN.
  • Active Directory: Microsoft directory service managing domain users/computers.
  • PRTG: network and IT infrastructure monitoring tool.

Chapter 8 — 3. A Chat with an HR Specialist

Core Insights

  • The #1 first-interview mistake is criticizing your previous employer — the interviewer assumes you'll do the same to them after you leave.
  • Timing matters: arriving late reads as chronically late to work; arriving far too early forces a rushed, non-relaxed start; no-shows mean you'll likely never be interviewed there again.
  • Never bring family (parents, children, partner/spouse) — it signals home difficulties and that you may get called away from work.
  • Skills claims without proof read as lies: any stated skill needs a concrete example or you're immediately disqualified.

Detailed Notes

  • Dress professionally even if the workplace is casual: be clean, pressed, and ready; don't assume casual wear is acceptable — the HR specialist recounts candidates arriving in pajamas and slippers.
  • Preparation: practice interviewing with someone; read the company website; understand what the company does and who its clients are; bring that research to the interview to show you've done your homework.
  • Social media: recruiters look up your name and view your pages; unflattering pictures or content are another automatic disqualifier.
  • Compiled with colleagues into a short list of the most important mistakes — these apply to first interviews generally.

Action Items

  • Never bad-mouth former employers in an interview.
  • Arrive on time (not late, not excessively early); never be a no-show.
  • Attend alone, professionally groomed and dressed.
  • Prepare 1–2 concrete examples per claimed skill; practice interviewing with someone.
  • Audit and clean social media profiles before applying.

Key Terms/Concepts

  • No-show: failing to attend an arranged interview; never acceptable, burns the bridge.
  • Recruiter: person screening/placing candidates (agency or company HR).

Chapter 8 — 4. An Interview With an IT Analyst

Core Insights

  • Believe in yourself and do your homework: understand the service desk concept and the ITIL framework — don't just follow it, understand the standard.
  • SLA ≠ resolution deadline: it's the time to acknowledge/respond to the ticket (a 20-minute SLA means acknowledge within 20 minutes, not resolve), then keep updating the ticket as you work.
  • Attitude beats experience: he accepted a sys admin offer with zero sys admin background by saying "I'm willing to take this job 100% if given the opportunity" — the manager invested in him.
  • Always ask about career prospects in interviews, and read the whole job description so you know exactly what products/expertise the company wants.

Detailed Notes

  • Guest's path: 10+ years in service desk roles, then team lead, then system admin; current interest leaning toward security.
  • Interview prep: follow and understand ITIL (the ideal framework for service desk work); people get scared of SLA — clarify the acknowledge-vs-resolve distinction; e.g., 20-minute SLA = acknowledge the ticket in 20 minutes ("we are working on it, it will take some time") and post updates on the ticket for that user.
  • Learning: Udemy courses at good prices are worthwhile refreshers (he used them himself); get certifications and relevant education; update yourself daily — "if you're out for a while, you're outdated."
  • Job expectations: service desk work requires understanding how IT/business functions work and basic troubleshooting; people already do IT themselves (smart TV example: unplug the cable, switch input, restart, update) — service desk scales that up.
  • Job description: nowadays it lists the products they need expertise in — read it thoroughly and understand the requirements before applying.
  • Most important interview question: "What is my career prospect down the road if I join the company?"

Action Items

  • Learn the ITIL framework; practice explaining SLA as acknowledgment time vs. resolution time.
  • Adopt a "willing to learn, give me the opportunity" attitude when offered stretch roles.
  • Ask about career progression in every interview; study the full job description first.

Key Terms/Concepts

  • SLA (Service-Level Agreement): agreed response (acknowledgement) time for tickets, not necessarily resolution time.
  • ITIL: IT service-management framework/standard (incident, problem, change processes).
  • Service desk vs. sys admin: front-line ticket handling vs. server/domain administration — adjacent but different skill sets.

Chapter 9 — 1. AV in the Cloud - We all Have to Keep Learning!

Core Insights

  • It is OK (and professional) to say "I don't know" or "I've never used this tool before" — even senior IT people must learn new tools every day.
  • Cloud-based antivirus management (Kaspersky Endpoint Security Cloud / Cloud and Point Protection) centralizes all AV admin in one web console: deploy agents, see infections, modify policies.
  • Before deploying to a paying client, the presenter tested the solution hands-on in a trial tenant — the lesson is to always test unfamiliar software first.
  • Deploying AV via admin-controlled packages is preferred over asking end users to install it themselves.

Detailed Notes

  • Kaspersky Endpoint Security Cloud: one console/website/dashboard to manage all antivirus applications.
  • Trial: registration with company name, 30 days to test, license covers up to 100 devices — enough for testing.
  • Windows Defender note: a "something is broken / not enabled" warning is not always critical — real-time protection was enabled; only one optional feature was off, so no need to panic.
  • Client wanted "something better with more features" → requested Kaspersky Cloud and Point Protection.
  • Deployment options found in the console: manual installation (download a package), Active Directory Group Policy (GPO software push), distribution packages (create package, push any way you want), run installation on the user's behalf, or write your own script.
  • End-user self-install is not recommended — most users won't follow the instructions.
  • Package flow: accept/read licenses → package creation takes a moment → package was run/installed silently on a connected test machine (TS01); silent installs ask no questions because IT defines policy (e.g., an HR user shouldn't decide firewall settings).
  • Security profiles/options in console: enable/disable/modify features (firewall, web control, host intrusion prevention); presenter disabled the firewall because a VPN in use could be blocked; changes apply automatically to all managed end devices.
  • License must be activated after install; "policy has been applied" + device showing up-and-running confirms success.
  • Same procedure on servers (test Windows Server 2016): download package, install, activate license.
  • Dashboard status: a removed/uninstalled device shows as down (fine); managed device listed in green = good / up to date / up and running.

Action Items

  • Practice: create a trial account in a cloud security console, deploy the agent to a test machine, and push a policy change.
  • Try any AV (Kaspersky, Norton, Defender, etc.) on a test device or VM, never your main laptop — these apps integrate deeply into the OS.
  • Practice troubleshooting a Defender-style warning by reading which component is actually disabled before escalating.

Key Terms/Concepts

  • Cloud AV console: centralized web dashboard to deploy agents, view infections, and manage security policies across devices.
  • Distribution package: pre-built installer pushed silently to endpoints by IT instead of manual user install.
  • Group Policy (GPO): Active Directory mechanism to push software/settings to domain machines.
  • Policy applied: console indicator that the pushed security configuration reached and activated on the endpoint.

Chapter 9 — 2. Using a Monitoring System

Core Insights

  • Monitoring exists to be proactive: detect problems before the customer calls — they pay you to look after the systems.
  • PRTG is an easy-to-use monitoring system that is free (even after trial expiry) for up to 100 devices — great for self-learning on a test machine.
  • A monitor uses sensors/probes that regularly query devices (e.g., "how many free gigabytes on the disk?") and flip status red/green.
  • The monitoring-tool market is huge and fragmented — at least 100 products in the US alone, and enterprises often use custom-coded solutions.

Detailed Notes

  • PRTG should be run on a test device because it gets deep into system settings.
  • What to monitor: servers, routers, switches, access points, printers — e.g., a file server where users store important documents needs disk-space monitoring so it never fills up.
  • On first connection, one item already shows red (something down); when a service stops it goes red, and green when it works again.
  • Green doesn't mean ignore it: go back and review what happened minutes ago (history/incident timeline).
  • On install, basic sensors run automatically out of the box: Ping, DNS, HTTP, plus a free-space sensor on the C: drive.
  • Sensor thresholds are configurable: trigger an alert when, e.g., only 10% or 50% of disk space remains — thresholds depend on company policy.
  • Warning vs alert: a warning means "not down, not critical, but look at it" — it doesn't demand a 7 a.m. Sunday response, but it can escalate into a critical issue if ignored.
  • It is not the entry-level support person's job to tune all sensor settings, but experimenting with them is valuable.

Action Items

  • Install PRTG on a VM/test device and watch the default sensors (Ping, DNS, HTTP, disk space) come up.
  • Change one sensor threshold and verify you receive the corresponding warning.
  • Deliberately stop a service (e.g., a web server) and observe the red/green status flip and the alert history.
  • Inventory your own devices and list which services (disk, uptime, DNS, HTTP) you would monitor for each.

Key Terms/Concepts

  • Monitoring system (PRTG): software that continuously checks devices/services and alerts on failures or threshold breaches.
  • Sensor/probe: a component that performs a single check (disk space, ping, HTTP response, DNS lookup) against a monitored device.
  • Proactive vs reactive support: finding problems via monitoring before users report them versus fixing after complaints.
  • Warning state: a non-critical, non-down condition that should be reviewed, not ignored.

Chapter 11 — 1. Policies - GPO in action

Core Insights

  • GPO (Group Policy Object) = a collection of policy settings that controls an operating system; lets an admin manage thousands of settings across hundreds of devices from one central place.
  • In corporate environments, end users should NOT be local administrators — GPO is how you centrally lock down devices instead of touching each one.
  • A GPO must be created AND linked to an OU (Organizational Unit) before it takes effect; linking determines which users/computers it applies to.
  • Computer Configuration settings apply to the machine regardless of who logs on; User Configuration settings apply to a specific user.
  • "Enabled" does not always mean "allowing" — it can also block something (e.g., "Remove Recycle Bin icon" vs "Enable Active Desktop"); always read the policy description.

Detailed Notes

  • Demo setup: server + test device logged in as user "Mike"; created OU "WTA" in Active Directory Users and Computers and moved Mike into it; created policy "Test GPO 1" via Tools → Group Policy Management.
  • Right-click the OU → "Create a GPO in this domain and link it here" (combines create + link; you can also create a GPO first and link it later).
  • Example policy applied: User Configuration → Administrative Templates → Desktop → "Remove Recycle Bin icon from desktop" → Enabled; each policy shows a description, supported operating systems, and Details/Delegation tabs (delegation lets you scope/lock down who edits it).
  • Policy refresh options: reboot the PC (recommended, easiest), or run gpupdate /force (refreshes without reboot; some settings still require a reboot — Microsoft states this in the policy).
  • Reboot from command line: shutdown /r /f /t 5 — /r = reboot, /f = force close background apps, /t 5 = do it in 5 seconds.
  • Verify applied policies: gpresult /r (summary data) — confirms e.g. "Test GPO has been applied".
  • Additional options shown: Prohibit access to Control Panel (blocks Control Panel and PC Settings); Windows Settings can control applications, drive maps, environment, files/folders, registry, shortcuts; Network Settings restrict what is allowed for LAN connections/network settings.

Action Items

  • Build a small lab: create a test OU and user, apply a simple GPO, and observe the effect after reboot or gpupdate.
  • Practice gpupdate /force, gpresult /r, and shutdown /r /f /t 5 until fluent.
  • Read policy descriptions carefully before setting "Enabled" — determine whether it allows or blocks.

Key Terms/Concepts

  • GPO (Group Policy Object): collection of policy settings controlling OS behavior, applied via AD.
  • OU (Organizational Unit): AD container used to scope GPO application to users/computers.
  • gpupdate /force: command to refresh Group Policy immediately.
  • gpresult /r: reports applied GPOs (summary data) for troubleshooting.

Chapter 11 — 2. Shares

Core Insights

  • Two permission systems work together for shared folders: Share permissions (Read / Change / Full Control) and NTFS permissions (full control, modify, read/write, etc.) on the Security tab.
  • When both apply, the most restrictive permission wins — the standard practice is Full Control on the share, then lock down with NTFS.
  • Never give end users NTFS Full Control: it lets them take ownership of items and change permissions themselves.
  • In enterprises, folder access is a process, not a courtesy: users raise a ticket/change request and someone approves it before the IT admin grants access.
  • The engineer's two main daily tasks: managing users in Active Directory and assigning permissions to files and shares.

Detailed Notes

  • File systems: legacy FAT/FAT32 not covered; focus on NTFS; ReFS (Resilient File System) is not a replacement for NTFS — it was designed for data stores / data centers on big networks.
  • NTFS capabilities: compression, encryption via EFS (Encrypted File System), disk quotas (e.g., give Mike 5 GB of space), and granular security per user.
  • Lab flow: create folder "test 1" → Properties shows the two relevant tabs — Sharing (share the folder onward) and Security (NTFS permissions).
  • Share permissions = 3 options: Read, Change, Full Control. NTFS permissions = many options; Full Control should be avoided for end users (though sometimes justified).
  • Sharing tab → Advanced Sharing → Permissions shows Full Control/Change/Read; Security tab shows Full Control, Modify, etc.
  • Effective Permissions: when combinations get confusing (e.g., Full Control + Modify), Windows' advanced security "Effective Permissions" view computes exactly what a user (e.g., Mike) can access — good troubleshooting tool.
  • Goal of the upcoming lab: share a folder and map a drive so Mike can access it with a single desktop double-click.

Action Items

  • Practice creating a shared folder on any Windows 7/8/10 machine — a server is NOT required to experiment with shares.
  • Memorize the difference between Share permissions (Read/Change/Full Control) and NTFS permissions, and the "most restrictive wins" rule.
  • Test the Effective Permissions feature with overlapping share + NTFS settings.

Key Terms/Concepts

  • NTFS: New Technology File System; supports compression, encryption (EFS), quotas, granular permissions.
  • Share permissions: Read / Change / Full Control, applied to the network share.
  • EFS: Encrypted File System — NTFS-level file encryption.
  • ReFS: Resilient File System for data stores/data centers; not an NTFS replacement.
  • Effective Permissions: Windows calculation showing a user's actual combined access.

Chapter 11 — 3. Installing Linux Using VirtualBox

Core Insights

  • Virtualization prerequisites: the CPU must support virtualization (Intel VT-x / AMD-V) AND the feature must be enabled in BIOS — check your exact laptop/desktop model with Google (e.g., "HP 250 enable VT-x").
  • A VM behaves like a real PC: it needs CPU, RAM, and disk space — plan hardware accordingly (decent i5/i7, lots of RAM, SSD).
  • VirtualBox is free (paid license unlocks extra features); commercial alternates are VMware and Hyper-V (built into many Windows platforms); VMware Player is free but limited.
  • A dynamically allocated virtual disk only consumes space as the guest OS grows, so you can run many VMs on one machine.

Detailed Notes

  • RAM planning: a Windows 10 VM should get ~2 GB of RAM — five or six VMs can quickly exceed 16 GB of total RAM.
  • SSD strongly recommended: it speeds up every VM operation; booting a Windows 10 VM can go from minutes to seconds.
  • VirtualBox install itself is trivial: Next, Next, accept everything, allow the special driver to be installed.
  • Creating a VM: give it a name — VirtualBox recognizes known OS names (e.g., "Linux") and auto-suggests/customizes the type; specify RAM; create a new hard disk or use an existing one.
  • Hard disk file type options matter mainly when moving VMs between platforms — skip them when starting from scratch.
  • Sizing: e.g., specify 50 GB; choose the dynamic option so the disk grows as needed instead of reserving 50 GB immediately.
  • First boot fails until you attach an OS image (ISO): Windows 10 needs a full install wizard; Kali Linux is pre-configured — no wizard, usable straight away (shown in the next lecture).

Action Items

  • Verify your CPU supports VT-x/AMD-V and check it is enabled in BIOS before installing any hypervisor.
  • Download a Linux ISO (e.g., Kali) and complete a full VirtualBox VM creation walkthrough.

Key Terms/Concepts

  • Virtualization: running a complete OS in software as a VM on a host machine.
  • VT-x / AMD-V: CPU instruction sets that enable hardware-assisted virtualization.
  • Hyper-V: Microsoft's hypervisor, available on many Windows editions.
  • VMware / VirtualBox: virtualization platforms; VirtualBox is free, VMware Player is free but limited.
  • Dynamic disk: virtual disk that grows with usage rather than pre-allocating full space.

Chapter 11 — 4. Overview of Windows 10

Core Insights

  • Windows editions and system requirements are a guaranteed exam topic — memorize which editions exist and what each one can do.
  • Two main editions: Home (ships with most laptops/desktops, for home users) and Pro (for corporate networks — the key feature is joining a domain, i.e., being managed by a Windows Server).
  • Home cannot join a domain and cannot host Remote Desktop (RDP) connections; Pro can do both.
  • Enterprise, Mobile, and Education are volume-license editions: large organizations license them per number of users (e.g., 10,000) instead of buying thousands of individual Pro copies.
  • BitLocker full-disk encryption is built into Windows but only available in Pro, not Home.

Detailed Notes

  • RDP: Settings → Remote allows enabling Remote Desktop on the Enterprise edition in the demo; the Home edition has no RDP role — you cannot RDP into a Home client.
  • "S" edition: a limited version designed for Microsoft Surface-type devices; can be upgraded from S to Home or Pro.
  • Pro vs Home comparison: user experience and security basics are the same; differences are in business features such as Group Policy (domain join + server-applied policies require Pro — Home has no Group Policy Objects), Remote Desktop, and Hyper-V (virtualization, covered later).
  • BitLocker: available in Windows 10 Pro (it was NOT available in Windows 7 Pro) but not in Windows 10 Home — Home users cannot encrypt their hard disk with BitLocker.
  • Licensing model: to equip a company (e.g., 10,000 users) you negotiate an Enterprise license covering X users; same model applies to Mobile and Education editions.
  • Resources: the lecture shows links to a comparison table / Wikipedia table listing every edition and its features — worth visiting.

Action Items

  • Memorize the Windows 10 edition list (Home, Pro, S, Enterprise, Mobile, Education) and the features unique to Pro (domain join, BitLocker, GPO, RDP host, Hyper-V).
  • Check the Wikipedia edition-comparison table and the official Microsoft comparison page.

Key Terms/Concepts

  • Domain join: connecting a PC to an AD domain so a server manages it via Group Policy — Pro feature only.
  • RDP (Remote Desktop Protocol): remote desktop access; hosting it requires Pro/Enterprise, Home cannot receive RDP.
  • BitLocker: built-in Windows full-disk encryption; Pro only.
  • Group Policy: server-applied policies for managed clients; Home cannot receive GPOs.
  • Volume licensing: bulk/enterprise licensing for many users (Enterprise, Mobile, Education).