About


Hi, I’m Zubair

I lead Imaging & OS Engineering on an enterprise endpoint-management engagement at HCLTech and work as an Intune MDM L3 resource. The estate I look after is roughly 50,000 Windows devices across global sites, including some isolated regional locations with heavy proxy restrictions — which is where most of the interesting problems come from.

What I work on

  • Imaging & OS deployment — Windows 11 image engineering with ADK/DISM, Autopilot, driver and BIOS management with HP CMSL
  • Microsoft Intune — Win32 app packaging (PSADT), Proactive Remediations, configuration and compliance policy, custom OMA-URI
  • SCCM / ConfigMgr and BigFix for co-managed and legacy estates
  • Security hardening — CIS benchmarks, BitLocker, Secure Boot, Windows Hello for Business
  • Automation — PowerShell everywhere, Nexthink Remote Actions, and some Python & Flask on the side

Why this blog

Most of what I post here started as a ticket, an escalation or a “why is this happening on 13,000 devices?” moment. Each post is the write-up I wish I’d found at the start.

Get in touch

The icons at the bottom of every page go to my email, GitHub and LinkedIn.

Everything here is my own work and opinion, not my employer’s or any client’s. Scripts are shared as-is — test in a pilot ring before you run anything fleet-wide.