Translate

Thursday, May 28, 2020

Windows10 - 2004 whats new

Windows10 - Version 2004 
Build 10.0.19041.264




Comprehensive but not full list of all updates known and available:

Cortana
  • Cortana has been redesigned with a conversation-based UI and support for light mode
  • The Cortana window can now be moved across the desktop
Search
  • Windows no longer indexes developer forlders like .git, .svn, .Nuget, .hg and more
  • Search can now better identify high usage and only index when enough resources are available.
Taskbar + Action center
  • Searching in Timeline when you didn't opt-in no longer requires you to tab past the opt-in text before you get to the search results
  • Action center will now show a direct link to Notification settings
  • You can now rename virtual desktops
File Explorer
  • Search is now powered by Microsoft Search
  • The Search bar in the File Explorer is now slightly longer by default
  • The context menu for .HEIC-files will now include options to Print or Set as Desktop Background
Settings
System
  • The App Volume and Device Preferences page has been redesigned
  • Storage Sense's group policies have been updated with better explanations for their functionality
  • You can now disable sounds for all notifications at once
  • You can now sort notifications senders
  • Under Notifications & actions, a setting has been added to disable the post-upgrade setup page
Devices
  • You can now manage the mouse cursor speed
  • When pairing with Swift Pair, the entire flow now happens within the notification with no need to open Settings
  • One less notification has to be shown for the full pairing experience over Bluetooth
  • You can now dismiss Swift Pair from the notification with the Dismiss-button
  • The device name and category are now shown in a Swift Pair notification
Network & Internet
  • The network Status page has been redesigned, showing the network usage for all active connections and integrating Data Usage
Apps
  • You can now select multiple features to be installed on your device
  • Features can now be searched through as well as sort them by Name, Size or Install date
  • Features will now shown when they were installed and any other dependencies they have
  • Latest actions has been added to Optional features and shows which installs, uninstalls and cancels you've performed
Accounts
  • "Make your device passwordless" has been added as a new option under Sign-in options
  • Your account picture will now sync faster through any Microsoft services
  • Ease of Access settings can no longer be set to sync between devices
  • The option "Automatically save my restartable apps when I sign out and restart them after I sign in." has been added on the Sign-in options page
Time & language
  • Language will now show an overview of various aspects of the system and to which language they are set, including Windows display, Apps & websites, Regional format, Keyboard and Speech, providing quick access to the various settings
  • The link to add a local experience pack has been removed
  • Opening a language's options will now show an updated language features overview
    • Required features are now listed below other features without a disabled checkmark
    • Features and settings that depend on other features and settings are now shown as a subitem of their parents
    • The various language feature will now show an icon on the right that will give the user a tooltip
Ease of Access
  • There is now a tooltip when hovering over the various color options for your cursor
Update & Security
  • You can now limit the bandwith usage by Delivery Optimization for both foreground and background
  • "Cloud download" has been added as a new recovery option
  • Windows Update will now list optional updates under "View optional updates"
  • All driver updates are now listed under "View optional updates", removing the need to check for drivers in the Device Manager
General
  • Improvements to the launch time when the Settings header is visible
Ink Workspace
  • The Ink Workspace flyout has been replaced with a small flyout menu
  • Sticky Notes are no longer accessible from the Ink Workspace
  • Sketchboard has been replaced with the Microsoft Whiteboard app

Accessibility
  • Magnifier with larger pointers will now pan smoothly when as the pointer changes shape
  • "Change how capitalized text is read" has been removed from Narrator
  • Narrator now announced the toggle state of checkboxes in a Listview
  • Scan mode will now turn off to allow typing in the edit field of a spinner control
  • Narrator now has improved support for "invalid" and "required" properties on more controls
  • Narrator Braille can now reliably activate links by routing key
  • Narrator reliability has been improved from Chrome
  • Narrator now reads tables more efficiently by only reading the deltas when navigating.
  • Narrator + S now gives a webpage summary.
  • You can now keep the text cursor in the center of the screen when typing with Magnifier
  • Narrator can now say the title and url of a link
  • Narrator will now read the header first, followed by the cell data, followed by the row/column - position of a cell
  • When headers in data tables change, Narrator will now read them
  • Eye Control now supports drag-and-drop
  • Pausing Eye Control will now completely hide the launchpad
  • Buttons can now be clicked with switches on joysticks or device that emulate joysticks
  • Eye Control has been updated to provide more settings
  • Narrator now automatically starts reading web pages and emails
  • The Magnifier UI has been revamped with updated icon and moves the magnification in between the zoom buttons, it is no longer to change the view from the Magnifier window
  • Narrator will now turn on Scan Mode when reading Outlook or Windows Mail mails automatically
  • Each email will now be read with the status mentioned first in the list view
  • The text cursor can now be changed to any given color
  • Narrator will now start reading webpages from the top rather than from the main landmark on it
  • Narrator now supports the arria-haspopup property
  • You can now turn of Narrator input learning of by hitting Narrator + 1
  • Improved Magnifier performance when moving the mouse around the screen
  • Magnifier reading now support reading in more locations
  • Narrator's volume for link and scroll sounds has been bumped up
  • In Outlook, the "importance"-header is now always spoken by Narrator before the importance level
  • Magnifier can no longer be set to an UI that is visible in the viewport as a magnifying glass
Language and input
  • The on-screen keyboard now uses SwiftKey's Typing Intelligence on 39 new languages: Afrikaans (South Africa), Albanian (Albania), Arabic (Saudi Arabia), Armenian (Armenia), Azerbaijani (Azerbaijan), Basque (Spain), Bulgarian (Bulgaria), Catalan (Spain), Croatian (Croatia), Czech (Czech Republic), Danish (Denmark), Dutch (Netherlands), Estonian (Estonia), Finnish (Finland), Galician (Spain), Georgian (Georgia), Greek (Greece), Hausa (Nigeria), Hebrew (Israel), Hindi (India), Hungarian (Hungary), Indonesian (Indonesia), Kazakh (Kazakhstan), Latvian (Latvia), Lithuanian (Lithuania), Macedonian (Macedonia), Malay (Malaysia), Norwegian (Bokmal, Norway), Persian (Iran), Polish (Poland), Romanian (Romania), Serbian (Serbia), Serbian (Serbia), Slovak (Slovakia), Slovenian (Slovenia), Swedish (Sweden), Turkish (Turkey), Ukrainian (Ukraine), Uzbek (Uzbek)
  • Dictation support for English (Canada), English (UK), English (Australia), English (India), French (France), French (Canada), German (Germany), Italian (Italy), Spanish (Spain), Spanish (Mexico), Portuguese (Brazil), and Chinese (Simplified, China) has been added
  • A number of kaomoji have been added the to emoji picker.
Input Method Editor
  • The development version of the Japanese IME from build 18277 has been restored
  • Improved security and reliability in the revamped Chinese Simplified and Chinese Traditional IMEs, as well as a cleaner settings interface
  • The Chinese Pinyin IME now refers to "Default mode" instead of "Input mode"
  • A tip has been added to the Bopomofo IME settings that Ctrl + Space will toggle the conversation mode
  • The Japanese IME now has as default assinged value of Ctrl + Space to be "None"
  • Key assignment settings are now more discoverable in the Japanese IME
  • Improved performance for the Bopomofo, ChangJie, and Quick IMEs
  • You can now disable the Shift + Space keyboard shortcut in the Bopomofo IME as well as changing the candidate font size
  • You can now hide the IME toolbar from the toolbar menu
Apps

Connect
  • Connect is now an optional feature downloadable in Settings
Notepad
  • Notepad can now restore unsaved content when Windows restarts for updates
Task Manager
  • The disk type will now be shown in Task Manager
  • Right clicking a process will now show "Provide Feedback" after "End task" and "End process tree" instead of between
  • The GPU temperature is now shown under Performance > GPU
Windows Sandbox
  • Support for capturing hotkeys in full screen has been added
  • A configuration file can now be set for Windows Sandboxes
  • Error dialogs will now show an error code and a link to Feedback Hub
  • You can now use a microphone in Windows Sandbox
  • The audio input device can now be set in the Sandbox config file
  • Shift + Alt + PrtScn now opens the ease of access dialog for high contrast mode
  • Ctrl + Alt + Break now toggles fullscreen mode
  • Windows Sandbox no longer requires the use of Admin privileges
Windows Subsystem for Linux
  • The file system of a Linux distro can now be accessed from File Explorer
  • Windows Subsystem for Linux version 2 has been added to Windows, including a full Linux kernel
  • Connections can now be made using localhost
  • Improved performance for directory listings in \wsI$
Other features
  • Tamper Protection will be set on by default again
  • You can now sign in with your Windows Hello PIN when in Safe Mode
And further
  • The "Windows Light" theme is now called "Windows (light)"
  • All Emoji 12.0 emojis now have keywords in the emoji picker
  • The OOBE will now show a lock icon with networks that are private
  • Windows Defender ATP is being renamed to Microsoft Defender
  • Windows will now periodically remind you to make backups if you do not have a backup solution installed
  • You're prefered defragmentation settings are now preserved after upgrading Windows
  • Support for Microsoft Bluetooth Mouse and Keyboard has been added to Swift Pair
  • Update the Windows version name to version 2004
Thanks to the Team of ChangeWindows!




Configuration and Deployment
As this is stuff IT Pros are focused here more explanations:

Delivery Optimization enhancements

  • Get-DeliveryOptimizationStatus -PeerInfo. Offers a real-time view behind-the-scenes of peer-to-peer activity (e.g. the peer IP Address, bytes received/sent).
  • Get-DeliveryOptimizationLogAnalysis. Get a summary of the activity in your Delivery Optimization log (e.g. the total number of downloads, downloads from peers, and overall peer efficiency). Use the -ListConnections flag to for in-depth look at peer-to-peer connections.
  • Enable-DeliveryOptimizationVerboseLogs. Offers a greater level of detail to assist in troubleshooting.
  • Enterprise network throttling. We've made enhancements to foreground vs. background throttling.
  • Automatic cloud-based congestion detection. Leverage the power of the Delivery Optimization cloud service to help identify download storms on your network. In short, the existing policy to delay background downloads from HTTP will indicate that the cloud service is allowed to dynamically back off downloading updates from the cloud for some devices while continuing to leverage local peer sources. Similarly, the same feature can help improve overall peer utilization by dynamically choosing which devices can download updates first. This feature is particularly useful to those of you who are deploying via rings and would like to avoid selecting individual devices in ring 0 (which can be cumbersome if you have thousands of sites). (Note: This client feature requires a cloud service support, which will be available in the near future, for full functionality.)

Servicing and deployment enhancements

  • Reduced offline time during feature updates. Beginning with Windows 10, version 1703, we've steadily reduced end user downtime during a feature update. With Windows 10, version 2004, offline time continues to decrease, from a median time of over 80 minutes in version 1703, to 16 minutes in version 2004, including only a single reboot for many users.
  • Improved controls for reserved storage. With the release of Windows 10, version 1903, we introduced reserved storage for newly manufactured PCs and clean Windows 10 installs. With Windows 10, version 2004, we've added a new set of Deployment Image Servicing and Management (DISM) commands and APIs so you can enable and disable reserved storage on demand, including reserved storage for Windows 10 devices that were not shipped with Windows 10, version 1903 and higher. For the full set of reserved storage command line options, see DISM Reserved Storage Command-line Options.
  • Improved controls and diagnostics for Windows Setup. For those using Windows Setup, Windows 10, version 2004 offers more control when upgrading to the latest update. For example:
  • Recover Windows 10 from the cloud. With this release we've added the option to recover Windows 10 by downloading the necessary files from the cloud, resulting in increased reliability and, depending on your internet speed, a faster recovery. For more details about the cloud-reset process, see Reset this PC option: Cloud download.
  • Windows Autopilot. Procure devices and have them delivered directly to the end user and provisioned from the cloud. Windows Autopilot has been available since Windows 10, version 1703 (with the 7D update) and with each new version of Windows 10 we add new, requested features. Today we're adding the ability to:
    • Configure user-driven Hybrid Azure AD Join with VPN support. This support has been backported to Windows 10, versions 1909 and 1903.
    • Configure language settings in the Windows Autopilot profile so that the out-of-box experience (OOBE) will skip the language, locale, and keyboard pages when the device is connected to ethernet.

Windows Update for Business

  • Microsoft Intune console updates. The target version is now available in Intune, allowing you to specify to which Windows 10 OS version you want devices to move. This capability also enables you to keep devices on their current version until they reach end of service. Available now in the Intune console, you can also configure this as a Group Policy or Configuration Service Provider (CSP) policy.
  • Validation improvements. To ensure devices and end users stay productive and protected, Microsoft uses safeguard holds to block devices from updating when there are known issues that would impact that device. But we know this can interfere with validations. To better enable IT administrators to validate on the latest release, we have created a new policy to enable admins to opt devices out of the built-in safeguard holds.
  • Deferral policies. See FAQ below for a description of how deferral policies work in Windows Update for Business.
  • Documentation updates. We have improved our Windows Update for Business documentation to better communicate how to utilize Windows Update for Business to manage Windows Updates to keep devices secure and end users productive.

Windows Virtual Desktop

Windows Virtual Desktop continues to evolve and you can keep up with the latest enhancements by bookmarking the Windows Virtual Desktop community and staying tuned to the Windows IT Pro Blog. Most recently, we've published new PowerShell modules to PSGallery, including Remove-RdsRoleAssignment with the -AadTenantId parameter to remove role assignments of principals not associated to the Azure AD tenant, and Update-AzWvdHostPool -PersonalDesktopAssignmentType to automatically assign users to virtual machines. For more details, see the Windows Virtual Desktop PowerShell release notes.

Cortana enhancements

  • Productivity[1]. A chat-based UI gives you the ability to interact with Cortana using typed or spoken natural language queries to easily get information across Microsoft 365 and stay on track. In the coming months, with regular app updates through the Microsoft Store, we'll enhance this experience to support wake word invocation and enable listening when you say “Cortana,” offer more productivity capabilities (such as surfacing relevant emails and documents to help you prepare for meetings), and expand supported capabilities for international users.
  • Security. You now must be securely logged in with your work or school account or your Microsoft account before using Cortana. Because of this tighter access, some skills including music, connected home, and third-party skills will no longer be available. Additionally, users get cloud-based assistance services that meet Office 365's enterprise-level privacy, security, and compliance promises as set out in the Online Services Terms.
  • Move the Cortana window. With Windows 10, version 2004, you can drag the Cortana window to a more convenient location on your desktop.

Thursday, April 23, 2020

M365 wrong licensing impacts performance

Tenant level security & compliance features may have performance issues when licensed wrong!





Good example is the use of Office 365 ATP e.g. detonation chamber for attachements. Behind this feature there are VMs spinned up for processing the attachments. The number of licensed users control in the background the ammount of VMs used for this. Some customers belief its a good Idea to have 1 x E5 license and then they are able to use the features as they are tenant wide activated then.
But they fail in:
1. doing a license violation
2. having not enough ressources allocated to do the work. Physical result is a strongly delayed delivery of mails with attachments or with dynamic delivery option enabled also a strong delay in delivering the final attachment. This is caused by a tremendous queue of attachments waiting to be checked as there are not enough ressources allocated in the background.
For this and more impacts please refer also to this article. It also covers the topic how to limit the services correctly to the targeted users. https://docs.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-365-security-compliance-licensing-guidance

Friday, March 27, 2020

SCCM ConfigMgr Client Health

When you operate your client in an enterprise environment, then you may find from time to time clients in an unhealty condition. E.g. SCCM reporting does not work anymore or other issues around WMI originating from a corrupt WMI repository and much more.


The tech fellow Anders Rodland created a fantastic PowerShell based framework to diagnose and heal your (sccm) clients automatically.


Features

ConfigMgr Client Health detects and fixes following errors:

  • ConfigMgr client is not installed.
  • ConfigMgr client is assigned the correct site code.
  • ConfigMgr client is upgraded to current version if not at specified minimum version.
  • ConfigMgr client not able to forward state messages to management point.
  • ConfigMgr client stuck in provisioning mode.
  • ConfigMgr client maximum log file size.
  • ConfigMgr client cache size. Fixed size (MB) or percentage of disk space.
  • ConfigMgr client certificate error.
  • ConfigMgr client hardware inventory not running.
  • ConfigMgr client CcmSQLCE.log exists and client is not in debug mode.
  • Corrupt WMI.
  • DNS server record matches local IP’s
  • Drivers – Reports faulty or missing drivers on client.
  • Logging to SQL database and / or file share
  • Pending reboot check
  • User-friendly reboot of computer with 3rd party reboot app when in pending reboot or computer uptime is more than specified in config.
  • Services for ConfigMgr client is not running or disabled.
  • Other services can be specified to start and run and specific state.
  • Windows Update Agent not working correctly, causing client not to receive patches.
  • Windows Update Agent missing patches that fixes known bugs.
  • PLUS additional ones in the latest version (check it out!)

More Information's can be found here:
https://www.andersrodland.com/configmgr-client-health/

And the latest "ConfigMgrClient Health" can be found on Github:
https://github.com/AndersRodland/ConfigMgrClientHealth

Monday, March 23, 2020

Autopilot with non-signature devices (CSP admins only)

Recently I had a customer they acquired Dell devices regularly without the Signature Edition so they would not receive the Autopilot hashes automatically in their tenant.


There is still a way to make it work. But this cant be done by a regular tenant admin. This need to be done by the CSP admin so you need to contact your Cloud Solution Provider (CSP) as they have a special chain of trust with Microsoft. You need to trust this CSP and allow him to be your CSP administrator in your tenant. This prevents any abuse of this process.

Therefore you need also to provide a CSV list to your CSP.

The format must be:

So you need the Device Serial Number, the Manufacturer Name and the Device model. 

(Device serial number,Windows product ID,Hardware hash,Manufacturer name,Device model) for copy&paste in your Excel table.

Manufacturer and Device model are very critical. So you can not write what you think of. It need to be the output of this Powershell command:

Get-CimInstance -ClassName Win32_ComputerSystem -property Manufacturer, Model | Select-Object Manufacturer, Model

Manufacturer          Model
------------          -----
Microsoft Corporation Surface Pro 6

You compile the table above with the serial number and these make and model information's (to be very exact is crucial!). The Windows product ID and the Hardwarehash need to be empty! 

Then you need to export this as CSV file and hand it over to your CSP for uploading it. This allows you also to on-board machines you have not yet bought as Autopilot machines (with Autopilot hardware vendor SKU and/or Signature Edition)

Additional drawback when not using the signature editon:
You still may have plenty bloatware installations in your image. You may want to remove them manually which might be tricky in some cases.


More information's about Autopilot can be found here:
https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-autopilot


More information's about the signature edition can be found here:
https://www.microsoft.com/en-gd/store/b/signaturepcs

(dont be shocked. This is only available in Granada English! :-))

Monday, January 27, 2020

What does this 0xC00000... errorcodes mean

Sometimes you get in Windows some strange error codes without any meaning behind.

Like 0xC0000005 or many other ones.


There is a simple Microsoft command line tool available to reveal the meaning of them. This tool was recently updated to the latest version. You find it here: https://www.microsoft.com/en-us/download/details.aspx?id=100432

Compared to the older version there are know approx. 8000 new return codes from more resources added. So its worth to download the latest version.

When you download it simply execute the executable followed
by the error code: e.g.  err 0xC0000005


The error code may be used on more than on place in the OS. So you need to figure out the source (or OS area) where the issue happend.

winerror.h, ntstatus.h and bugcodes.h are handled typically by the OS kernel and relate to core os functions like file access etc.



USAGE: err [opt] {value} [value] [value] ...
 where <value> must be of one of the following forms:
   1. decorated hex (0x54f)
   2. implicit hex  (54f)
   3. ambiguous     (1359)
   4. exact string  (=ERROR_INTERNAL_ERROR)
   5. substring     (:INTERNAL_ERROR)
...and <opt> may be one of:
   /:xml         - causes the output to be in XML-parseable form.
                   To understand the output, try it.  It's pretty obvious.
   /:listTables  - lists all the tables below in XML format.
                   Again, the format is pretty straightforward.
   /:outputtoCSV - lists all the tables below in CSV format.
   /:outputtoJS  - lists all the tables below for use in JS.
   /:outputtoCPP - lists all the tables below for a C++ header.
   /:hresultfromwin32 - prints HRESULT_FROM_WIN32 errors for a C++ header.

All values on the command line will be looked up in our internal
tables and presented to you.  If available, informational data
associated with the value(s) will also be shown (see below).
All tables are searched by default, but you can restrict the
output to those tables you deem appropriate by adding
"/<tablename>" to the beginning of the commandline.

Example:

> err /winerror.h /ntstatus.h 0
# winerror.h selected.
# ntstatus.h selected.
# for hex 0x0 / decimal 0 :
  STATUS_WAIT_0                                             ntstatus.h
  ERROR_SUCCESS                                             winerror.h
# The operation completed successfully.
  NO_ERROR                                                  winerror.h
  SEC_E_OK                                                  winerror.h
  S_OK                                                      winerror.h
# 5 matches found for "0"

This app has support derived from the following headers and privates:

  activprof.h             activscp.h             adoint.h               adserr.h
  asferr.h                audioclient.h          audioenginebaseapo.h   bitsmsg.h
  bthdef.h                bugcodes.h             cderr.h                cdosyserr.h
  cfgmgr32.h              cierror.h              corerror.h             corsym.h
  ctffunc.h               d3d.h                  d3d9.h                 d3d9helper.h
  d3dx10.h                d3dx10core.h           d3dx9.h                d3dx9xof.h
  daogetrw.h              dbdaoerr.h             dciddi.h               ddeml.h
  ddraw.h                 dhcpssdk.h             difxapi.h              dinput.h
  dinputd.h               dlnaerror.h            dmerror.h              drt.h
  dsound.h                dxfile.h               eaphosterror.h         ehstormsg.h
  esent.h                 fherrors.h             filterr.h              fltdefs.h
  hidpi.h                 iiscnfg.h              imapi2error.h          imapi2fserror.h
  imapierror.h            ime.h                  intshcut.h             ipexport.h
  iscsierr.h              iscsilog.h             jscript9diag.h         legacyErrorCodes.h
  lmerr.h                 lmerrlog.h             lmsvc.h                lpmapi.h
  lzexpand.h              mciavi.h               mdmregistration.h      mdmsg.h
  mediaerr.h              mferror.h              mmstream.h             mobsync.h
  mpeg2error.h            mprerror.h             mq.h                   mqoai.h
  msctf.h                 msdrmerror.h           msime.h                msiquery.h
  msopc.h                 mswmdm.h               msxml2.h               nb30.h
  ndattrib.h              netcfgx.h              netevent.h             netmon.h
  netsh.h                 nserror.h              ntdddisk.h             ntdsapi.h
  ntdsbmsg.h              ntiologc.h             ntstatus.h             odbcinst.h
  ole.h                   olectl.h               oledberr.h             oledlg.h
  p2p.h                   patchapi.h             patchwiz.h             pbdaerrors.h
  pdhmsg.h                photoacquire.h         portabledevice.h       qossp.h
  raserror.h              rdcentraldb.h          reconcil.h             routprot.h
  rtcerr.h                sberrors.h             scesvc.h               schannel.h
  setupapi.h              shellapi.h             sherrors.h             shimgdata.h
  shobjidl_core.h         slerror.h              snmp.h                 spatialaudioclient.h
  spatialaudiometadata.h  sperror.h              stierr.h               synchronizationerrors.h
  tapi.h                  tapi3err.h             tcerror.h              textserv.h
  textstor.h              thumbcache.h           tpcerror.h             txdtc.h
  upnp.h                  upnphost.h             urlmon.h               usb.h
  usp10.h                 vdserr.h               vfw.h                  vfwmsgs.h
  vsserror.h              wbemcli.h              wcmerrors.h            wcntypes.h
  wdfstatus.h             wdscpmsg.h             wdsmcerr.h             wdstptmgmtmsg.h
  werapi.h                wiadef.h               winbio_err.h           wincrypt.h
  windowsplayready.h      windowssearcherrors.h  winerror.h             winfax.h
  winhttp.h               wininet.h              winioctl.h             winldap.h
  winsnmp.h               winsock2.h             winspool.h             wpc.h
  wsbapperror.h           wsmerror.h             wuerror.h              xapo.h
  xaudio2.h               xmllite.h              xpsdigitalsignature.h  xpsobjectmodel.h
  xpsobjectmodel_1.h
There are currently 25259 return codes registered from 173 sources.


Friday, January 17, 2020

Powershell - replace files in use

UPDATED - 02/08/2020

If you want to replace a file in use you need to handle a very strange registry key called "PendingFileRenameOperations" with a REG_MULTI_SZ type.

If you handle this manually you will absolutely run in trouble. As this key is rarely empty. So you would have to read, append and write again. The chance that you corrupt this thing is very high.

Better to use the builtin function for this. The API is called: MoveFileEx 
More Infos about this API you will find here:https://docs.microsoft.com/en-gb/windows/win32/api/winbase/nf-winbase-movefileexa



The file will be replaced during a reboot. This is especially handy when files are locked during regular OS operation. You can even delete a locked file (check API documentation for this).

As this is an unmanaged code API (The real Win32 world without .Net extensions) you need a little bit more code to make it work like a .Net API class. So pure [.NETAPI CALL]::APINameAndOptions does not work alone!

To get a clue how to use it in PowerShell you find here an example:

# Function definition for the API MoveFileEx in PowerShell

Add-Type -TypeDefinition @'
using System;
using System.Runtime.InteropServices; 

    [Flags]
    public enum MoveFileFlags
    {
        MOVEFILE_REPLACE_EXISTING = 0x00000001,
        MOVEFILE_COPY_ALLOWED = 0x00000002,
        MOVEFILE_DELAY_UNTIL_REBOOT = 0x00000004,
        MOVEFILE_WRITE_THROUGH = 0x00000008,
        MOVEFILE_CREATE_HARDLINK = 0x00000010,
        MOVEFILE_FAIL_IF_NOT_TRACKABLE = 0x00000020
    }

public static class Kernel32
    {
        [DllImport("kernel32.dll", SetLastError = true, CharSet = CharSet.Unicode)]
        public static extern bool MoveFileEx(string lpExistingFileName, string lpNewFileName,MoveFileFlags dwFlags);
    }
'@

# Calling the function in Powershell with an example
# [kernel32]::MoveFileEx(OLDFILE,NEWFILE,"MOVEFILE_DELAY_UNTIL_REBOOT")
# Parameter Options: 
#   1. Option 1 is new fullpath filename and should have a temporary name.
#   2. Option 2 is for file in use (when API-NULL is given for option 2 then file from option 1 will be deleted)
#      IMPORTANT:  Use [NullString]::Value     the Powershell version of $Null does not get passed to the API properly!
#   3. Parameter which will tell the replacement (or even delete) of locked file during reboot!
#   4. For proper replacement you need 2 calls. 1st call with API specific NULL value will delete the original file. The 2nd call will rename the new file with temp name to the original file
#   5. To retrieve the API extended error properties in case of a failure the command is extended by $Lasterror with capturing the component model exception

# 1st Call to delete the old original file first! 
[kernel32]::MoveFileEx("C:\temp\Test1.txt",[NullString]::Value,"MOVEFILE_DELAY_UNTIL_REBOOT");$LastError = [ComponentModel.Win32Exception][Runtime.InteropServices.Marshal]::GetLastWin32Error()

# 2nd Call to rename the new temporary file with the old originial file name. Which now has new content!
[kernel32]::MoveFileEx("C:\temp\Test2.txt","C:\temp\Test1.txt", "MOVEFILE_DELAY_UNTIL_REBOOT");$LastError = [ComponentModel.Win32Exception][Runtime.InteropServices.Marshal]::GetLastWin32Error()


TROUBLESHOOTING:
1. Use Sysinternals "PendMoves.exe" to check the status and valid entries of registry key for "PendingFileRenameOperations"
2. Registrykey "PendingFileRenameOperations" can be checked also manually at: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
 a. When the key does not exist - no further rename operations exist
 b. When an operation fails during the reboot the key will be deleted also. So nothing is kept!
 c. DO NEVER EVER edit this key manually! Its a binary stored Multi_REG_SZ. Whatever you do it will just be worse!
3. For more log information's check also C:\Windows\PFRO.log




0xc0000035 indicates that you missed the delete the original file first!
0xc0000034 indicates that the file is already deleted. So you can ignore it!

Wednesday, January 15, 2020

Tune up your old SurfacePro4

I have a Surface Pro4 for a while. And it got every half year its nice fine upgrade. 

Since beginning the Surface Pro4 supported 2 external full HD monitors via the dock but then the internal screen was blacking out. Checked the specs and it was as it was by design. The gaphic adapter did not support 3 monitors (while external are full HD 1080 and the internal was in native 2k mode)

In October I realized that after a certain update (could not found which one) the WLAN becomes also very clunky (bad WLAN performance). Sometimes packet loss or ping roundtrip times in the 900ms or more milliseconds. Did here also some research and all hints just improved from time to time so no real solution.

So what is the best advice when in trouble?


  1. Reboot
  2. Reinstall
  3. Rebuy newer hardware


Then I thought ok its now worth to reinstall my machine completely fresh from ground. (2. Reinstall option). Due to Onedrive not really a big data loss. Just the hazzle of reinstalling latest version of my software suites.



And it turned out it was a refreshing living cell injection for my PC!

After processing all the updates the machine is supporting things out of the box I had never before automatically.


  1. It now supports 2 external screens while still having native resolution shown on the internal screen (= 1 screen more!)
  2. The bad WLAN performance was gone
  3. It supports now out of the box space reservation for upgrades (fresh installed systems since 1903 (afaik) will create a extra free space reserved for future upgrades. So no showblocker for upgrades anymore with HDDs full of data. This only works with fresh installed machines beginning with 1903. So migrations from 1507 over and over again do not support this)
  4. My important user profile documents are automatically migrated to Onedrive out of the box! So everything you store them will integrate automatically to Onedrive. Just be aware of your picture archive. It automatically syncs down and blows your HDD. So you should keep it "cloud only" with the Files On Demand feature!!!)


All over my advice is from time to time it is still worth to take a fresh restart! (Ensuring that all your precious data is stored in OneDrive)