IT CHRONICLE
Home Home Il Progetto The Project Il Team The Team Strumenti di Rete Tool Kit Chiave PGP PGP Key Chi sono About Servizi Services EN
[ DOTT. FRANCESCO_RUSSO ]

ICT JOB DIARIESICT JOB DIARIES

List topics List topics
[ DOTT. FRANCESCO_RUSSO ]

Consulente ICT ICT Consultant

> Bridging Technology, Risk Management & Business

Il Profilo
Con oltre 25 anni di esperienza in reti, sistemi e IT risk management, mi occupo di amministrazione On-Premise e Cloud. Aiuto organizzazioni e imprese a garantire la conformità normativa (GDPR, ISO 27001, NIS 1 e 2) e offro servizi avanzati di Digital Forensics. Il mio obiettivo acquittal è consolidare il mio ruolo di esperto in Cybersecurity e Intelligenza Artificiale Generativa, operando a livello internazionale in modalità remote-first.

Esperienza sul Campo
Dal 2005 sono Programmatore Sistemista e Privacy Manager per il Consorzio per la Bonifica della Capitanata, ruolo a cui affianco una continua attività di consulenza per realtà sanitarie e studi legali (Gruppo Salatto, Studio Torlontano, ecc.). Gestisco operativamente attività di DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery e mitigazione dell'impatto dei rischi IT. In passato, ho coordinato team internazionali come IT Project Manager tra Amsterdam e Tallinn.

Visione Strategica e Competenze
Comprendere l'infrastruttura richiede anche una solida visione aziendale. Per questo ho integrato il mio background tecnico (Windows/Linux Server, reti TCP/IP, Firewall) con una Laurea Magistrale in Scienze Economiche conseguita con lode. Unisco l'approccio ingegneristico alle metodologie manageriali e Agile (ITIL v.3, Scrum, Six Sigma). Attualmente sto espandendo le mie competenze attraverso i percorsi ufficiali Google come Cybersecurity Expert e Generative AI Leader.

Oltre il codice
Lavoro correntemente in inglese (certificazione C2 Cambridge) e conosco altre tre lingue. Quando non sono alle prese con server o incident response, ricarico le energie a contatto con la natura, pilotando droni (UAS Open A1/A3), dedicandomi alla fotografia o sperimentando nuove tecniche ai fornelli.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Formazione Accademica

  • Master in Gestione delle imprese e delle società MA659 (30/30)
  • Laurea Magistrale in Scienze Economiche LM-56 (110/110 e Lode)
  • Laurea Triennale in Scienze dell'Economia e della Gestione Aziendale L-18 (94/110)

Certificazioni
Di seguito l'elenco completo delle certificazioni conseguite, dei corsi di specializzazione e dei badge ottenuti, a testimonianza del continuo aggiornamento tecnico e professionale:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)

The Profile
With over 25 years of experience in networks, systems, and IT risk management, I specialize in On-Premise and Cloud administration. I help organizations ensure regulatory compliance (GDPR, ISO 27001, NIS 1 and 2) and provide advanced Digital Forensics services. My current goal is to consolidate my expertise in Cybersecurity and Generative AI, collaborating internationally in a remote-first work environment.

Field Experience
Since 2005, I have served as the System Programmer and Privacy Manager for the Consorzio per la Bonifica della Capitanata, alongside continuous consulting work for healthcare facilities and law firms. I operationally manage DFIR (Digital Forensics and Incident Response), Business Continuity, Disaster Recovery, and IT risk mitigation. Previously, I coordinated international teams as an IT Project Manager between Amsterdam and Tallinn.

Strategic Vision & Skills
Understanding IT infrastructure also requires a solid business vision. That is why I integrated my technical background (Windows/Linux Servers, TCP/IP networks, Firewalls) with a Master's Degree in Economics (Summa Cum Laude). I combine an engineering approach with managerial and Agile methodologies (ITIL v.3, Scrum, Six Sigma). I am currently expanding my skill set through the official Google Cybersecurity Expert and Generative AI Leader paths.

Beyond the code
I am fluent in English (Cambridge C2 certification) and have knowledge of three other languages. When I am not dealing with servers or incident response, I recharge my energy by immersing myself in nature, flying drones (UAS Open A1/A3), practicing photography, or experimenting with new cooking techniques.

Formazione in corso

  • Professional Cloud Architect (Google Cloud)

Academic Background

  • Postgraduate Master in Corporate and Business Management (MA659)
  • Master's Degree in Economics LM-56 (Summa Cum Laude)
  • Bachelor's Degree in Economics and Business Management L-18 (94/110)

Certifications
Below is the complete list of certifications, specialization courses, and badges achieved, demonstrating a continuous commitment to technical and professional development:

  • Cybersecurity Foundations Professional Certificate (ID: 51934206)
  • Microsoft Certified: Azure Fundamentals
  • Foundations of Operationalizing MITRE ATT&CK
  • Foundations of Purple Teaming
  • Autopsy Basics and Hands On – Digital Forensics (ID: YRXYSTQBK8)
  • GrassHopper Javascript – Coding Fundamentals, Coding Fundamentals II, Array Methods, Animations
  • Project Management Essentials Certified (ID: 55005870)
  • Scrum Foundation Certificate (SFPC) (ID: 43043593)
  • Six Sigma White Belt (ID: 55005099)
  • Six Sigma Yellow Belt (ID: 729673)
  • ITIL v.3 Foundation (ID: GR750562993FR)
  • Cybersecurity Essentials – Cisco Netacad
  • Introduction to Cybersecurity – Cisco Netacad
  • Introduction to Cisco Packet Tracer – Cisco Netacad
  • Introduction to Internet of Everything – Cisco Netacad
  • Google Analytics for Beginners
  • Google Digital Training (ID: R7ZXBVRRR)
  • The EU GDPR - An Introduction (ID: UC-0HROEMGN)
  • Eipass Progressive (ID: 8B77A028CB)
> author identified
Foto Francesco Russo

Pronto Soccorso IT - Ep. 15: Il secondo monitor fa i capricci ("Nessun Segnale")

 Lavorare con un solo schermo dopo aver provato la configurazione a doppio monitor è un po' come cercare di guidare guardando solo dallo specchietto retrovisore. Insopportabile. Quindi hai comprato un secondo monitor, l'hai collegato con fierezza, e... "Nessun segnale". Lo schermo rimane più nero dei tuoi fondi di caffè☕ 

Prima di dichiarare guerra ai cavi HDMI, assicurati che Windows sappia delle tue intenzioni espansionistiche.

Le regole d'ingaggio:
1. La mossa Win + P: Premi contemporaneamente il tasto Windows + P sulla tastiera. Si aprirà un pannello laterale.

Diplay


Se è impostato su "Solo schermo PC", ecco il tuo colpevole. Seleziona "Estendi" e guarda lo schermo prendere vita.
2. Forza il rilevamento: Tasto destro in un punto vuoto del desktop > "Impostazioni schermo". Scorri un po' verso il basso e cerca il pulsante "Rileva". A volte Windows ha solo bisogno di un incoraggiamento manuale.

Rileva schermo


3. Il controllo "Sei sicuro?": Sembra una banalità, ma verifica di aver inserito il cavo nella scheda video dedicata (se hai un PC fisso) e non nella porta disattivata della scheda madre. È l'errore più comune in assoluto, e nessuno vuole mai ammetterlo.


IT First Aid - Ep. 11 Windows 11 upgrade, with some troubles

Good morning everyone!

Here we are again, with a new problem, and obviously a new solution: the upgrade from Windows 10 to Windows 11.

About time, you might say! But a tiny clarification is needed here: as an IT technician, one of the things that has always bored me is spending my free time fixing my own devices. Because of this, my devices are always the last ones to be put on the waiting list.

Better late than never. At this point, however, you might wonder what's so special about this how-to compared to the hundreds available on the internet, especially for a procedure that requires no dark magic. Well, in my case, as Murphy's Law dictates, things got a bit more complicated. I had originally set up an MBR partition instead of GPT, a problem compounded by the fact that I hadn't enabled the BIOS in UEFI mode nor enabled Secure Boot.

In short, I unconsciously complicated things just to make the solution more interesting. Let's proceed and see how we managed to get out of this IT mess.

Phase 1: The illusions of the Microsoft tool (MBR2GPT)

On paper, Microsoft provides us with a command-line tool that should do the magic: MBR2GPT. The idea is that, by running it with administrator privileges, it converts the disk from MBR to GPT without touching the data, creating a ready-to-use EFI partition.

Let's verify that the partitions are ready using the Microsoft tool:

mbr2gpt /validate /disk:0 /allowFullOS

If the validation is successful, we execute the command. Unfortunately for me, the validation failed, and I had to rebuild the bootloader manually. Once the bootloader was rebuilt, I moved on to the actual conversion:

mbr2gpt /convert /disk:0 /allowFullOS
WARNING: TO CONVERT PARTITIONS WITH BITLOCKER, IT IS NECESSARY TO SUSPEND OR DISABLE BITLOCKER FIRST, OTHERWISE YOU WON'T BE ABLE TO REBOOT THE PC.

The tool creates the EFI and MSR partitions and updates the BCD without formatting. Do not unplug the PC during the operation.

At this point, we need to restart the PC in UEFI mode. Let's proceed from Windows:
Settings → System → Recovery → Advanced startup → Restart now → Troubleshoot → Advanced options → UEFI Firmware Settings → Restart.

UEFI boot


Upon reboot, we will have to enter the BIOS by pressing a key between F11 or F12 (depending on your PC manufacturer) before Windows boots. Once inside the BIOS, we will disable Legacy/CSM and set the boot mode strictly to UEFI. Save the settings and exit.

(Editor's note: If you have to use Diskpart to force a partition deletion like I did because of corrupt EFI volumes left behind, you might run into this beautiful Windows safety block: Virtual Disk Service error: Delete is not allowed on the current boot, system, pagefile, crashdump or hibernation volume. Just use the override parameter to bypass it. And when fixing the bootloader with bcdboot, wait for the majestic Boot files successfully created.)

At this point, Windows will boot up, and we can proceed with the upgrade to Windows 11 by going to the Windows Update tab and clicking to check for updates. If this doesn't show the option to switch to Windows 11, the reason you are not seeing the update yet is simply a matter of server timing. Microsoft handles the transition to Windows 11 with a staged rollout. Even if your PC is ready today, the Windows Update algorithm might put you in a "queue" and show you the banner weeks or even months from now. Obviously, there is no reason to wait for Microsoft's server timelines. There is an official and direct method to trigger the update immediately, keeping all your programs, files, and settings intact.

Here is how to force a clean upgrade:

The Windows 11 Installation Assistant

This is the official Microsoft tool designed specifically for those who have a compatible PC but don't want to wait for the Windows Update notification.

  1. Go to the official Microsoft download page by googling "Download Windows 11" (make sure the site is microsoft.com).
  2. The first option at the top will be the Windows 11 Installation Assistant.
  3. Click on Download Now.
  4. Run the downloaded file (Windows11InstallationAssistant.exe). Note: it might ask you to download and install the "PC Health Check" app for a final double-check; do it if prompted.
  5. Accept the license terms and click on Accept and install.

Note: If you run into TPM issues right after switching from Legacy to UEFI, you might see errors in Windows Security like Device health attestation isn't supported on this device and TPM storage is not available. Please clear your TPM. Simply click on Clear TPM in the UI and confirm upon reboot to reset the cryptographic keys.

At this point, the Assistant will do everything on its own. It will start the background download of Windows 11 (you can continue using the PC in the meantime), prepare the files, and, when ready, will ask you to restart. The reboot will take some time, similar to a large cumulative update, and upon completion, you will find yourself directly on the new Windows 11 desktop.

Pronto Soccorso IT - Ep. 11 Passaggio a Windows 11, con qualche problema

Buongiorno a tutti!

Eccoci di nuovo qui, per un nuovo problema, ed ovviamente una nuova soluzione: il passaggio da Windows 10 a Windows 11.

Alla buon'ora, direte voi! Però qui è necessaria una piccola, piccolissima precisazione: da tecnico informatico, una delle cose che mi ha sempre annoiato è impiegare il mio tempo libero per mettere a posto i miei dispositivi, motivo per cui nella lista d'attesa i miei dispositivi sono sempre gli ultimi ad essere serviti.

Meglio tardi che mai. Però a questo punto vi domanderete cosa ci sia di particolare in questo howto, rispetto alle centinaia disponibili su internet, e per di più per un procedimento che non ha nulla di alchemico: beh nel mio caso, come legge di Murphy impone, le cose si sono un po' più complicate, avendo creato in origine una partizione MBR e non GPT, problema al quale si è aggiunto il non avere abilitato il BIOS in modalità UEFI e l'avvio protetto.

Insomma, ho voluto un po' complicare le cose per rendere la soluzione più interessante. 

Procediamo quindi a descrivere come siamo riusciti a venire fuori da questo ginepraio informatico.

Fase 1: Le illusioni dello strumento Microsoft (MBR2GPT)

Sulla carta, Microsoft ci fornisce uno strumento a riga di comando che dovrebbe fare la magia: MBR2GPT. L'idea è che, avviandolo con i permessi di amministratore, converta il disco da MBR a GPT senza toccare i dati, creando una partizione EFI pronta all'uso.

Verifichiamo che le partizioni siano pronte utilizzando lo strumento di Microsoft:

mbr2gpt /validate /disk:0 /allowFullOS

Se la validazione ha successo eseguiamo il comando. Purtroppo per me la validazione non è andata a buon fine, ed ho dovuto ricostruire il bootloader. Una volta ricostruito il bootloader sono passato alla conversione vera e propria:

mbr2gpt /convert /disk:0 /allowFullOS
ATTENZIONE: PER CONVERTIRE PARTIZIONI CON BITLOCKER, È NECESSARIO PRIMA SOSPENDERE O DISATTIVARE BITLOCKER, ALTRIMENTI NON SAREMO IN GRADO DI RIAVVIARE IL PC.

Il tool crea le partizioni EFI e MSR e aggiorna il BCD senza formattare. Non scollegare il PC durante l’operazione.

A questo punto è necessario riavviare il pc in modalità UEFI, procediamo da Windows:
Impostazioni → Sistema → Ripristino → Avvio avanzato → Riavvia ora → Risoluzione problemi → Opzioni avanzate → Impostazioni firmware UEFI → Riavvia

Riavvio UEFI


Al riavvio dovremo entrare nel BIOS premendo un tasto fra F11 o F12 (a seconda del produttore del vostro pc) prima dell’avvio di Windows. Una volta entrati nel BIOS, disabiliteremo Legacy/CSM e imposteremo avvio solo UEFI, salviamo le impostazioni e usciamo.

A questo punto si avvierà Windows e potremo procedere all’aggiornamento a Windows 11 andando nella scheda aggiornamenti e cliccando per verificare la presenza di aggiornamenti. Se questo non dovesse mostrarci la possibilità di passare a Windows 11, il motivo per cui non vedi ancora l'aggiornamento su Windows Update è semplicemente una questione di tempistiche dei server. Microsoft gestisce il passaggio a Windows 11 con un rilascio scaglionato (staged rollout). Anche se il tuo PC è pronto oggi, l'algoritmo di Windows Update potrebbe mettersi in "coda" e proporti il banner tra settimane o addirittura mesi. Ovviamente, non c'è alcun motivo di aspettare i tempi tecnici dei server Microsoft. Esiste un metodo ufficiale e diretto per far partire l'aggiornamento immediatamente, mantenendo intatti tutti i tuoi programmi, i file e le impostazioni.

Ecco come forzare l'aggiornamento in modo pulito:


L'Assistente per l'installazione di Windows 11

Questo è il tool ufficiale di Microsoft pensato proprio per chi ha un PC compatibile ma non vuole aspettare la notifica di Windows Update.

  1. Vai sulla pagina ufficiale di download di Microsoft cercando su Google "Download Windows 11" (assicurati che il sito sia microsoft.com).
  2. La prima opzione in alto sarà Assistente per l'installazione di Windows 11.
  3. Clicca su Scarica ora.
  4. Avvia il file scaricato (Windows11InstallationAssistant.exe). Nota: potrebbe chiederti di scaricare e installare l'app "Controllo integrità PC" per un'ultima doppia verifica, fallo se te lo chiede.
  5. Accetta i termini di licenza e clicca su Accetta e installa.

A questo punto, l'Assistente farà tutto da solo. Inizierà il download in background di Windows 11 (puoi continuare a usare il PC nel frattempo), preparerà i file e, quando sarà pronto, ti chiederà di riavviare. Il riavvio richiederà un po' di tempo, simile a un grosso aggiornamento cumulativo, e al termine ti ritroverai direttamente sul nuovo desktop di Windows 11.

Happy Easter! The Sysadmin's Easter Egg: Unlocking "God Mode" in Windows 11

I have decided to give my readers a typical gift, a kind of present typical of the IT and video game world: Easter Eggs.

In software development jargon, an Easter Egg is a hidden feature, message, or inside joke intentionally inserted by programmers into an operating system or application, or very often a hidden level or room in a video game. To find them, you need to know exactly where to look or what specific "ritual" of keys to execute.

Today, in keeping with the holiday theme, we are going to "unwrap" the ultimate Easter egg of Microsoft systems: Windows 11 God Mode.


What is "God Mode"?

The term "God Mode" originates from video games, indicating a cheat that makes the player invincible. On Windows, its actual technical name is the Windows Master Control Panel shortcut.

It is a special hidden folder that, once unlocked, acts as a centralized hub providing direct access to over 200 advanced system administration and configuration tools, bypassing the modern (and sometimes fragmented) Windows 11 Settings interface.

For a Systems Programmer or an IT Security Manager, it's an incredibly useful tool to have everything under control in a single window, from disk partitioning to advanced network management and local security policies.


How to unlock the secret menu (Tutorial)

The activation process is straightforward and does not require any dangerous Registry edits. You simply need to create a folder and assign it a specific Windows Globally Unique Identifier (GUID).

Here are the steps:

  1. Right-click on an empty spot on your Desktop (or any other directory where you want to place the menu).
  2. Select New > Folder.
  3. Now, select the newly created folder and press F2 to rename it.
  4. Copy and paste exactly the following string as the folder name:
GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}

Sysadmin note: the word "GodMode" before the dot can be replaced with any name you prefer (e.g., AdminTools.{ED7BA...}), but the alphanumeric string inside the curly brackets must remain intact.


The Result

As soon as you press Enter, you will see the folder icon change instantly: it will become identical to the legacy Control Panel icon, losing the text name you assigned to it.

Double-clicking on this new icon will open a window containing a massive list of shortcuts divided by category: Windows Tools, Credential Manager, Network and Sharing Center, BitLocker, Troubleshooting, and much more.

In an era where Microsoft is progressively hiding advanced settings in favor of a more "user-friendly" interface (which can be frustrating for power users), this Easter Egg remains an essential escape route for IT professionals.

Happy Easter and happy system hacking!

Buona Pasqua! L'Uovo di Pasqua dei Sistemisti: Sbloccare il "God Mode" su Windows 11

Ho deciso di fare ai miei lettori, un regalo tipico, un tipo di dono tipico dell'informatica e del mondo dei videogame: gli Easter Egg.

Nel gergo dello sviluppo software, un Easter Egg è una funzione nascosta, un messaggio o uno scherzo inserito intenzionalmente dai programmatori all'interno di un sistema operativo o di un'applicazione, o molto spesso un quadro o una stanza nascosta in un videogame. Per trovarli, bisogna sapere esattamente dove cercare o quale "rituale" di tasti eseguire.

Oggi, in tema con le festività, andiamo a "scartare" l'uovo di Pasqua per eccellenza dei sistemi Microsoft: il God Mode di Windows 11.


Cos'è il "God Mode"?

Il termine "God Mode" (Modalità Dio) deriva dal mondo dei videogiochi, dove indica un trucco che rende il giocatore invincibile. Su Windows, il suo vero nome tecnico è Windows Master Control Panel shortcut.

Si tratta di una speciale cartella nascosta che, una volta sbloccata, funge da hub centralizzato fornendo l'accesso diretto a oltre 200 strumenti di amministrazione e configurazione avanzata del sistema, bypassando le moderne (e a volte dispersive) interfacce delle Impostazioni di Windows 11.

Per un Programmatore Sistemista o un IT Security Manager, è uno strumento utilissimo per avere tutto sotto controllo in una singola finestra, dal partizionamento dei dischi alla gestione avanzata delle reti, fino alle policy di sicurezza locale.


Come sbloccare il menu segreto (Tutorial)

Il processo per attivarlo è semplicissimo e non richiede modifiche pericolose al Registro di Sistema. È sufficiente creare una cartella e assegnarle un codice identificativo univoco (GUID) specifico di Windows.

Ecco i passaggi:

  1. Fai clic col tasto destro in un punto vuoto del tuo Desktop (o in qualsiasi altra directory in cui desideri posizionare il menu).
  2. Seleziona Nuovo > Cartella.
  3. Ora, seleziona la cartella appena creata e premi F2 per rinominarla.
  4. Copia e incolla esattamente la seguente stringa come nome della cartella:
GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}

Nota sistemistica: la parola "GodMode" prima del punto può essere sostituita con qualsiasi nome tu preferisca (es. AdminTools.{ED7BA...}), ma la stringa alfanumerica tra parentesi graffe deve rimanere intatta.


Il Risultato

Appena premerai Invio, vedrai l'icona della cartella cambiare istantaneamente: diventerà identica a quella dello storico Pannello di Controllo, perdendo il nome testuale che le avevi assegnato.

Facendo doppio clic su questa nuova icona, ti si aprirà una finestra contenente un lunghissimo elenco di scorciatoie suddivise per categoria: Strumenti di Windows, Gestione credenziali, Centro connessioni di rete, BitLocker, Risoluzione dei problemi e molto altro.

In un'epoca in cui Microsoft sta progressivamente nascondendo le impostazioni avanzate a favore di un'interfaccia più "user-friendly" (spesso frustrante per i power user), questo Easter Egg rimane una via di fuga essenziale per noi professionisti IT.

Buona Pasqua e buon "hacking" dei sistemi!

Automation - PowerShell Script to Check Windows 11 Readiness (TPM 2.0 and Secure Boot)

When managing an IT infrastructure, relying on consumer GUI tools like Microsoft's PC Health Check app to verify Windows 11 compatibility isn't scalable. As sysadmins, we need automated, fast tools that provide clear text output to integrate into broader deployment scripts.

The two most critical (and often blocking) requirements for upgrading from Windows 10 to Windows 11 concern hardware security: the presence of TPM 2.0 (Trusted Platform Module) and the enablement of Secure Boot at the UEFI level.

Powershell Automation


I wrote a quick PowerShell script that queries the operating system directly to extract this information without needing to reboot the machine or enter the BIOS/UEFI.

The Script

You can run this code block by opening PowerShell with Administrator privileges. The script checks the TPM status and Secure Boot configuration, returning immediate color-coded feedback.


<#
.SYNOPSIS
    Verifies system readiness for the Windows 11 upgrade (Focus on TPM and Secure Boot).
.DESCRIPTION
    The script checks if the TPM module is present, ready, and version 2.0.
    It also verifies whether Secure Boot is enabled in the UEFI firmware.
#>

Write-Host "=========================================" -ForegroundColor Cyan
Write-Host "  Windows 11 Requirements Check          " -ForegroundColor Cyan
Write-Host "=========================================`n" -ForegroundColor Cyan

# 1. Check TPM
Write-Host "[*] Checking TPM module..."
try {
    $tpm = Get-Tpm
    if ($tpm.TpmPresent) {
        # The TpmReady property indicates if it is ready for use
        if ($tpm.TpmReady) {
            Write-Host "    [OK] TPM detected and ready for use." -ForegroundColor Green
        } else {
            Write-Host "    [WARNING] TPM present but not initialized." -ForegroundColor Yellow
        }
    } else {
        Write-Host "    [ERROR] No TPM module detected on the motherboard." -ForegroundColor Red
    }
} catch {
    Write-Host "    [ERROR] Cannot query TPM. Ensure you are running as Administrator." -ForegroundColor Red
}

# 2. Check Secure Boot
Write-Host "`n[*] Checking Secure Boot..."
try {
    $secureBoot = Confirm-SecureBootUEFI
    if ($secureBoot) {
        Write-Host "    [OK] Secure Boot enabled in UEFI firmware." -ForegroundColor Green
    } else {
        Write-Host "    [ERROR] Secure Boot is disabled. You need to enable it in BIOS/UEFI." -ForegroundColor Red
    }
} catch {
    Write-Host "    [ERROR] Cmdlet not supported or system in Legacy BIOS mode (non-UEFI)." -ForegroundColor Red
}

Write-Host "`n=========================================" -ForegroundColor Cyan
Write-Host "Check complete." -ForegroundColor Cyan

How does it work under the hood?

Get-Tpm: This is a native Windows cmdlet that returns an object containing the details of the Trusted Platform Module. We check TpmPresent and TpmReady to ensure not only that the chip exists, but that it has been properly activated at the OS level.

Confirm-SecureBootUEFI: This cmdlet directly queries the firmware variables. If it returns True, Secure Boot is active. If the script falls into the catch block, it is highly likely that the system drive is MBR-partitioned and booting in Legacy BIOS mode (which prevents the installation of Windows 11).

Conclusion and Future Developments

This script is a great starting point for a security baseline. In Enterprise environments, these checks can be integrated into a larger PowerShell module, perhaps executed via GPO or RMM, to generate a CSV report of all machines in the corporate fleet that are ready (or not) for the new OS rollout.

You can find this and other automation scripts on my GitHub.

Automazione - Script PowerShell per la verifica dei requisiti di Windows 11 (TPM 2.0 e Secure Boot)

Quando si gestisce un'infrastruttura IT, affidarsi a tool grafici "consumer" come l'app Controllo integrità PC di Microsoft per verificare la compatibilità a Windows 11 non è scalabile. Come sistemisti, abbiamo bisogno di strumenti automatizzabili, rapidi e che forniscano output testuali chiari da poter integrare in script di deploy più ampi.

I due requisiti più critici (e spesso bloccanti) per l'upgrade da Windows 10 a Windows 11 riguardano la sicurezza hardware: la presenza del TPM 2.0 (Trusted Platform Module) e l'abilitazione del Secure Boot a livello UEFI.

Powershell Automation


Ho scritto un rapido script in PowerShell che interroga direttamente il sistema operativo per estrarre queste informazioni senza dover riavviare la macchina o entrare nel BIOS/UEFI.


<#
.SYNOPSIS
    Verifica la prontezza del sistema per l'upgrade a Windows 11 (Focus su TPM e Secure Boot).
.DESCRIPTION
    Lo script controlla se il modulo TPM è presente, pronto e in versione 2.0.
    Verifica inoltre se il Secure Boot è abilitato nel firmware UEFI.
#>

Write-Host "=========================================" -ForegroundColor Cyan
Write-Host "  Verifica Requisiti Windows 11          " -ForegroundColor Cyan
Write-Host "=========================================`n" -ForegroundColor Cyan

# 1. Verifica TPM
Write-Host "[*] Controllo modulo TPM..."
try {
    $tpm = Get-Tpm
    if ($tpm.TpmPresent) {
        # La proprietà TpmReady indica se è pronto all'uso
        if ($tpm.TpmReady) {
            Write-Host "    [OK] TPM rilevato e pronto all'uso." -ForegroundColor Green
        } else {
            Write-Host "    [WARNING] TPM presente ma non inizializzato." -ForegroundColor Yellow
        }
    } else {
        Write-Host "    [ERRORE] Nessun modulo TPM rilevato sulla scheda madre." -ForegroundColor Red
    }
} catch {
    Write-Host "    [ERRORE] Impossibile interrogare il TPM. Assicurati di eseguire come Amministratore." -ForegroundColor Red
}

# 2. Verifica Secure Boot
Write-Host "`n[*] Controllo Secure Boot..."
try {
    $secureBoot = Confirm-SecureBootUEFI
    if ($secureBoot) {
        Write-Host "    [OK] Secure Boot abilitato nel firmware UEFI." -ForegroundColor Green
    } else {
        Write-Host "    [ERRORE] Secure Boot disabilitato. È necessario attivarlo nel BIOS/UEFI." -ForegroundColor Red
    }
} catch {
    Write-Host "    [ERRORE] Cmdlet non supportata o sistema in modalità BIOS Legacy (non UEFI)." -ForegroundColor Red
}

Write-Host "`n=========================================" -ForegroundColor Cyan
Write-Host "Controllo terminato." -ForegroundColor Cyan

Come funziona sotto il cofano?

Get-Tpm: È una cmdlet nativa di Windows che restituisce un oggetto contenente i dettagli del Trusted Platform Module. Verifichiamo TpmPresent e TpmReady per assicurarci non solo che il chip esista, ma che sia stato attivato correttamente a livello di sistema operativo.

Confirm-SecureBootUEFI: Questa cmdlet interroga direttamente le variabili firmware. Se restituisce True, il Secure Boot è attivo. Se lo script finisce nel blocco catch, è altamente probabile che il disco di sistema sia partizionato in MBR e avvii in modalità Legacy BIOS (che impedisce l'installazione di Windows 11).

Conclusioni e Sviluppi Futuri

Questo script è un ottimo punto di partenza per una baseline di sicurezza. In ambienti Enterprise, questi controlli possono essere integrati in un modulo PowerShell più grande, magari eseguito tramite GPO o RMM, per generare un report CSV di tutte le macchine del parco aziendale pronte (o meno) per il rollout del nuovo OS.

Trovate questo e altri script di automazione sul mio GitHub.