# rollout (blogs) — RSS Amplifier

Recent posts from the 2 feeds in the RSS Amplifier directory that cover rollout.

Page: <https://rssamplifier.com/topics/rollout/blogs>  
Feed: <https://rssamplifier.com/topics/rollout/blogs.md>

---

## [Independent IT advice for good causes](https://emilebosch.com/2026/05/30/it-advice-for-good-causes/)

_2026-05-30 · Emile (ツ)_

Through Digitaalgoed.nl I&rsquo;m helping build an initiative that gives charities and non-profits independent IT advice, funded without reseller margins or vendor commitments. Charities often overpay for IT or sign restrictive contracts because they lack the budget and in-house expertise to evaluate the options. The advice covers software, infrastructure, and digital strategy, translating the…

## [Copilot vs Claude vs ChatGPT, without the hype](https://emilebosch.com/2026/05/28/copilot-vs-claude-vs-chatgpt/)

_2026-05-28 · Emile (ツ)_

I evaluated Copilot, Claude, and ChatGPT for Aan de Stegge (ASVB) and wrote a vendor-neutral report recommending which tool to use for which tasks. I scored each tool on quality, security, privacy, cost, and ease of use, testing them on real tasks from the organization&rsquo;s daily work. The report documents where each tool sends data, its compliance status, and its cost at full rollout. No…

## [Intune’s App Inventory Just Grew Up](https://joymalya.com/intune-enhanced-app-inventory/)

_2026-05-26 · Joymalya Basu Roy · MDM Tech Space_

Intune’s Enhanced App Inventory transforms application visibility from guesswork into a reliable security signal. By introducing richer metadata, user context, and freshness indicators, it closes long-standing audit and compliance gaps. Here’s what changed, how to enable it, and why it matters for Zero Trust operations. \[Read More\] The post Intune’s App Inventory Just Grew Up appeared first on MDM…

## [Teaching a construction company to actually use Copilot](https://emilebosch.com/2026/05/26/teaching-a-construction-company-copilot/)

_2026-05-26 · Emile (ツ)_

At Lithos I ran hands-on workshops that taught employees how to use Copilot and AI assistants on their own projects, including prompt design, output review, and model limitations. I assessed each role&rsquo;s workflows to find where AI could save time, then built a role-specific curriculum around those tasks. We also set guidelines for handling sensitive data, so employees know what not to paste…

## [Intune’s New Device View: Less Clicking, More Context (Finally)](https://joymalya.com/intunes-new-device-view-less-clicking-more-context/)

_2026-05-22 · Joymalya Basu Roy · MDM Tech Space_

Microsoft’s new Intune Device View isn’t about new features—it’s about better context. By consolidating device data, actions, compliance, and reporting into a single experience, it reduces admin friction and improves audit visibility. Here’s what changed, why it matters, and how it aligns with real-world endpoint operations. \[Read More\] The post Intune’s New Device View: Less Clicking, More…

## [When a fix at one company becomes a group-wide rollout](https://emilebosch.com/2026/05/19/fix-becomes-group-wide-rollout/)

_2026-05-19 · Emile (ツ)_

I&rsquo;m rolling out the tender process I built at Lithos across all the construction companies in the Aan de Stegge group (ASVB). Scaling the process means turning the Lithos workflow into a blueprint other companies can adopt while keeping their own local practices. The rollout standardizes the steps that improved results at Lithos and leaves company-specific details configurable. Most of the…

## [Untangling the tender process in construction](https://emilebosch.com/2026/05/12/untangling-the-tender-process/)

_2026-05-12 · Emile (ツ)_

At Lithos I mapped the tender process to find where the time and errors were concentrated. Much of the work repeated on every bid: documents spread across multiple folders, content copied from the previous bid, and stakeholders adding input at different stages. I standardized and automated the repeating work so the team produces a bid without reassembling the same documents each time. Removing the…

## [Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): Series Wrap‑Up](https://joymalya.com/secure-boot-certificate-update-rollout-series-wrap-up/)

_2026-03-30 · Joymalya Basu Roy · MDM Tech Space_

The Secure Boot 2023 CA transition was never just a certificate update. This epilogue looks back at what actually changed at enterprise scale—broken assumptions, firmware realities, and why proof matters more than deployment success. \[Read More\] The post Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): Series Wrap‑Up appeared first on MDM Tech Space .

## [Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field Guide for the Sleep‑Deprived IT Admin – Part 4](https://joymalya.com/intune-secure-boot-2023-certificate-update-rollout-part-4/)

_2026-03-29 · Joymalya Basu Roy · MDM Tech Space_

Secure Boot certificate updates won’t flip Secure Boot ON for you. This post shows how to safely enable Secure Boot at scale using Intune orchestration + PowerShell execution, with BitLocker readiness gates, and OEM-supported tooling for Lenovo and Dell. \[Read More\] The post Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field Guide for the Sleep‑Deprived IT Admin – Part 4…

## [WinCsFlags.exe and Secure Boot 2023 CA Updates &#8211; A Bridge Between Part 2 &#038; Part 3](https://joymalya.com/wincsflags-secure-boot-2023-updates-how-it-works/)

_2026-03-27 · Joymalya Basu Roy · MDM Tech Space_

WinCsFlags.exe doesn’t write Secure Boot certificates into firmware — it sets intent. This deep‑dive explains how WinCS works behind the scenes, how the Secure Boot 2023 CA update actually flows from Windows to UEFI firmware, why two reboots are expected, and how to validate success using UEFICA2023Status. A practical, engine‑room explanation bridging Part 2 (0x5944) and Part 3 (validation) of the…

## [Ship software peacefully (Sponsored)](https://crawlproof.com/a/V1YYohxaYsR3)

_2026-03-27 · **Sponsored**_

Connect your repo and deploy instantly — Railway handles config, scaling, and monitoring.

## [Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field Guide for the Sleep‑Deprived IT Admin – Part 3](https://joymalya.com/intune-secure-boot-2023-certificate-update-rollout-part-3/)

_2026-03-24 · Joymalya Basu Roy · MDM Tech Space_

Deploying the Secure Boot 2023 certificate update is the easy part. Proving it actually worked is where things get uncomfortable. In Part 3, the spotlight shifts from execution to evidence—where dashboards stop being trusted, reboots start to matter, and firmware finally gets a vote. This is the phase where Windows claims success, devices boot happily, and yet half your fleet may still be clinging…

## [Why Agentic AI Needs Guardrails: A Zero Trust Take on Microsoft Agent 365](https://joymalya.com/agentic-ai-zero-trust-governance-microsoft-agent-365/)

_2026-03-15 · Joymalya Basu Roy · MDM Tech Space_

The Claude / Terraform incident wasn’t AI going rogue—it was automation executing perfectly without governance. This post breaks down why agentic AI is a Zero Trust problem, not an intelligence one, and how Microsoft Agent 365 signals a shift toward scoped, observable, and approval‑gated agents designed to limit blast radius before damage happens. \[Read More\] The post Why Agentic AI Needs…

## [Intune Multi-Admin Approval: The Security Feature You Wish You&#8217;d Enabled Before Someone Pressed “Wipe All”!](https://joymalya.com/intune-multi-admin-approval/)

_2026-03-13 · Joymalya Basu Roy · MDM Tech Space_

There are some security lessons that arrive as a whitepaper, and then there are the ones that arrive like a brick through the server room window. This post explores why Intune Multi-Admin Approval is no longer just a nice governance feature, but a critical security control for preventing destructive remote actions like wipe, retire, and delete from being abused at scale. \[Read More\] The post…

## [Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field Guide for the Sleep‑Deprived IT Admin &#8211; Part 2](https://joymalya.com/intune-secure-boot-2023-certificate-update-rollout-part-2/)

_2026-03-10 · Joymalya Basu Roy · MDM Tech Space_

Part 2 of the Secure Boot 2023 CA Update series dives into the actual rollout: how Windows applies the new KEK/DB certificates, why automatic updates aren’t guaranteed, and how Intune admins can safely trigger and manage the update workflow using registry‑based signals and proactive remediations. \[Read More\] The post Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field…

## [Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field Guide for the Sleep‑Deprived IT Admin &#8211; Part 1](https://joymalya.com/intune-secure-boot-2023-certificate-update-rollout-part-1/)

_2026-03-08 · Joymalya Basu Roy · MDM Tech Space_

Before you roll out the Secure Boot 2023 certificates, map your fleet. This guide shows how to inventory posture with Intune—reports, proactive remediations, JSON outputs, and OEM gotchas. \[Read More\] The post Secure Boot Certificate Update Rollout at 50,000 Feet (and Devices): A Field Guide for the Sleep‑Deprived IT Admin Part 1 appeared first on MDM Tech Space .

## [Running OCI/Docker images on Sprite.dev](https://emilebosch.com/2026/03/01/oci-docker-images-on-sprite-dev/)

_2026-03-01 · Emile (ツ)_

Sometimes you want to run your existing docker images in Sprite&rsquo;s firecracker vms. You&rsquo;ll quickly come to the conclusion that it&rsquo;s a pretty stripped kernel and Docker will complain a lot. Since Sprite is sandboxed I don&rsquo;t need any of the Docker features in terms of isolation, it&rsquo;s just one sprite per role. But i do want the docker images i&rsquo;ve created before. You…

## [Deepseeks 3FS' FUSE hackery is super interesting](https://emilebosch.com/2026/02/14/deepseeks-3fs-fuse-hack-is-super-smart/)

_2026-02-14 · Emile (ツ)_

Deepseek released 3FS some time ago, a filesystem to blast tons of data to your GPU cluster for efficient training since GPU&rsquo;s needs to go BRRRRR and not wait on IO. I was checking out their paper and docs and went found this cool hack for FUSE that they employ. FUSE makes it possible to have a Filesystem in UsErspace so that us mere mortals don&rsquo;t have to hack the kernel too much in…

## [StarGZ fast docker snapshotter is low-key magic](https://emilebosch.com/2026/02/13/stargz-is-a-sexy-piece-of-tech/)

_2026-02-13 · Emile (ツ)_

Sometimes you run into tech that makes you go “Heh?”, which is the positive variant of its cousin, “Wtf?”. My newest addition, Stargz snapshotter , is exactly that kind of tech. Without immediately spoiling how the magic works: Stargz snapshotter is something you install on your Docker host that causes the daemon to download only the files your workload actually uses, just in time . Heh? I know…

## [On mourning the craft](https://emilebosch.com/2026/02/07/i-also-mourned-our-craft/)

_2026-02-07 · Emile (ツ)_

I recently read We mourn our craft and it resonates for me. It does more than that actually. I think it&rsquo;s normal to feel grief and emotions like mourning for something you&rsquo;ve worked so passionately hard to obtain, becoming so easily accessible and reproducible for others. I don&rsquo;t hate AI, I am actually very productive with it and I can do more than ever. However, I do grieve.…

## [One OS for your AI workforce (Sponsored)](https://crawlproof.com/a/b6CkPD2IQcXV)

_2026-02-07 · **Sponsored**_

Build, direct, and supervise an AI workforce from a single operating workspace.

## [Gow - Simple compile on save, live reload for go web applications](https://emilebosch.com/2026/02/01/gow-filewatcher-livereload/)

_2026-02-01 · Emile (ツ)_

When building Go web applications, fast feedback matters. The usual loop, compile, run, open the browser, refresh, adds friction, especially when you also want to test on your phone. That’s the problem gow is built to solve. Faster loops with Gow I&rsquo;ve decided to fix this with a unified tool. Gow combines: Automatic compilation Live browser reloading Easy phone access via QR codes Whenever…

