IT, digital assets, and finance reply guy 😁

Second #Solana Mobile phone with inbuilt TPM for crypto assets in 2025?! Let's give it a try, shall we? Referral for extra bonuses: solanamobile.com/refer/amate…
The Saga continues with @solanamobile...and the story is just beginning. #Chapter2 starts now. šŸ‘€šŸ‘‡
5
13
2,008
Andrea Matesi retweeted
Happy Birthday, Windows 11... It's an amazing operating system with massive power just below the surface. I would change and add many things, but there are many, many more I wouldn't. These are the hidden gems, pieces of Windows that people take for granted. Like the subsystem model. Win32 was never the operating system. It was a personality bolted onto NT, same as the old OS/2 and POSIX subsystems. That design decision from 1993 is why WSL exists at all. WSL1 ran Linux binaries as pico processes against a translation layer; WSL2 runs a real Linux kernel in a utility VM, and your distro still shows up as a normal Windows process tree you can attach a debugger to. People treat that as a feature. It is Dave Cutler's subsystem idea, still paying rent thirty years later. ACLs on every object, not just files. A process, a thread, a section, an event, a mutant, a token, a job — each one carries a security descriptor. The Object Manager doesn't special-case "files get security, everything else is a free-for-all." Open a handle and the Security Reference Monitor checks the ACL. That is why you can lock down a named pipe, a registry key, or another process with the same model, and why "run as" and restricted tokens actually mean something. The Object Manager itself. One namespace. \Device, \BaseNamedObjects, \Sessions, \Registry. Handles, reference counts, and a consistent lifetime model for almost everything the kernel exposes. Most of what you think of as "Windows APIs" is a user-mode wrapper over an object you opened by name or by inheritance. I/O completion ports and the I/O manager. Overlapped I/O is not a later bolt-on. IRPs, cancel routines, and a completion port that a thread pool can drain are how a service handles tens of thousands of sockets without a thread per connection. NTFS sits on the same path: journaling, the USN change journal, reparse points, sparse files, hard links, transactions when you want them. Cloud placeholders and symlinks are reparse points. They are not a hack layered on later. Job objects. A process is not the unit of resource control. A job is. CPU rate, memory, I/O, kill-on-close, nested jobs. Windows containers and a lot of sandboxing are just job objects with a nicer hat. ALPC for the cross-process calls you never see. Services, RPC, COM activation, the window manager talking to win32k — local procedure calls with security context carried along, not a pile of ad-hoc shared memory. And under it all, a type-1 hypervisor. The root partition is a guest. VBS, HVCI, Credential Guard, and the WSL2 VM are the same machinery. Memory integrity and isolated LSASS are not apps. They are partitions the kernel agreed to live beside. None of this shows up in a screenshot. It is why the thing still runs software from the 90s, a Linux toolchain, a GPU game, and a hypervisor-isolated credential store on the same box without each of those being a separate product. The shell can be argued with. The executive underneath it is the part I would keep. You could slap a new face on it tomorrow, and it would look entirely fresh while being incredibly stable thanks to 30+ years of dedicated engineering.
87
57
687
19,693
Andrea Matesi retweeted
Todos los productos de Adobe reimplementados desde cero, gratuitos y de código abierto → getartcraft.com/apps
293
2,310
19,387
1,613,887
Andrea Matesi retweeted
Did you see the EPM docs got updated silently... without a real announcement? There’s now a new System settings policy in Endpoint Privilege Management. Instead of only elevating an EXE, EPM can now let a standard user change a specific Windows system setting. Think more along the lines of the kind of setting you would normally change through Windows Settings or the old Control Panel. The first documented example is Network Settings, which lets users change things like IPv4, IPv6, and DNS without giving them local admin rights. The Company Portal becomes the entry point, and behind the scenes EpmElevate.exe provides the dedicated elevated experience. I took a closer look at how the policy, the Company Portal, and EpmElevate.exe all fit together. And another System Settings scenario is also hiding in there that Microsoft still hasn’t documented yet... #Intune #MSIntune #Windows11 #EPM patchmypc.com/blog/manage-sy…
9
32
148
17,197
Andrea Matesi retweeted
LOTR might genuinely be one of the greatest things humans have ever put on a screen and I’m not even exaggerating. You can watch it as a kid and think it’s about hobbits and swords and this terrifying ring. Then you watch it as an adult and realize it’s basically about everything that actually matters. Power corrupts people and evil usually starts really small..Good people can be tempted and courage isn’t about being fearless. Friendship can literally carry you when you can’t carry yourself anymore. The smallest person in the room can change the course of history. You do the right thing not because you know you’re going to win, but because it’s the right thing to do. Honestly… I think it should be mandatory viewing for kids at some point. Not just ā€œwatch the movieā€ but actually dissect it. Why does Boromir fail? Why can Sam resist what other people can’t? Why does Frodo show Gollum mercy? Why is Aragorn a good leader when he spends half the story reluctant to have power? What happens when someone becomes consumed by resentment, fear, or the desire to control other people? Then make kids apply those questions to their own lives. Friendship, temptation, loyalty, courage, responsibility, choosing who you want to be when nobody is forcing you to choose correctly. There are probably more useful lessons about becoming a decent human being buried in those movies than in half the stuff we make kids memorize in school…and those are learnings and lessons that would stick and could carry you through all of life. My favorite part is that the heroes aren’t these invincible characters either. They’re tired, scared, tempted, and completely outmatched. Half the time they have no idea what they’re doing but they just keep going…. Then somehow Peter Jackson took ALL of THAT and made three epic movies at the same time, filled them with real sets, real landscapes, thousands of extras, incredible music,… and made something that still looks better than movies being made with $200M budgets 25 years later. I really don’t think we’ll ever get another thing like it.
The prologue of THE LORD OF THE RINGS: THE FELLOWSHIP OF THE RING (2001) packs more worldbuilding, scale, and spectacle into a few minutes than most fantasy films manage in an entire runtime.
163
1,186
9,519
369,004
Andrea Matesi retweeted
Do you think Intune is slow? When you put all the changes Microsoft has made next to each other, it starts to look like something much bigger than a few performance improvements. Intune is slowly moving away from waiting for timers and scheduled polling, toward push, local events and near real time actions. Policy delivery: The old roughly 30-minute notification throttle is being replaced by the Fast Lane model. Changes can trigger a new device check-in within minutes instead of sitting behind the old notification window. Remote actions :That annoying 5-minute queued delay after the first hours of enrollment? Gone on supported Windows versions. Remote actions can start the device check in immediately again. Device Sync: Sync used to mainly wake the Windows MDM world. Now one Sync can wake Windows MDM AND the Intune Management Extension. The IME side is delivered through IC3 and Trouter. Sync Status :It is no longer just ā€œpress Sync and hopeā€. The portal can now follow the progress of Policies, Applications, and Scripts. Win32 apps: A newly assigned Required Win32 app no longer necessarily has to wait for the normal 60-minute app check. Intune can push intent 2 over IC3 and bring the normal app check forward within minutes. Autopilot apps: When enrollment finishes, it can now trigger a fresh app check. That closes the gap where the desktop appeared, but the remaining Required apps could sit there waiting for the next app timer. Client-driven compliance: This one is even more interesting. The device can watch local signals such as Firewall, Defender, BitLocker, Secure Boot, and TPM. When something changes, it can proactively request a new compliance evaluation instead of waiting for the normal cycle. App Inventory: This used to be based around a 4-hour collection cycle. The newer Device Inventory Agent can react to an application change, validate it, and upload the delta on the next scheduler pass. In my testing, that was about 5 minutes. So... Do you still think Intune is slow? I think that question is becoming a lot harder to answer with a simple ā€œyesā€. #Intune #MSIntune #WindowsAutopilot
10
42
167
9,896
Andrea Matesi retweeted
A new national front door to the federal government. One trusted place to help people find answers. Whatever you need from government, start here: AMERICA.GOV
1,080
4,090
18,538
1,121,464
Andrea Matesi retweeted
Water droplets filmed at 20 000 frames a second with a macro lens to capture non-coalescence [šŸ“¹ The Slow Mo Guys]
curious side of š•
93
1,326
9,223
279,574
Andrea Matesi retweeted
By far the best genre of slop so far 🤣
282
1,987
20,989
2,971,841
Andrea Matesi retweeted
My god this is such a good speech that every SWE needs to hear. You know what? Every person should hear it Keep the happy memories, eyes on the reality, be excited about the future. That’s the best that anyone can do
378
2,072
15,863
3,672,489
Andrea Matesi retweeted
holy shit i asked claude to make a video on western civiization
2,747
10,562
61,418
15,025,917
Andrea Matesi retweeted
Recovery Remote Management lets IT fix broken Windows devices remotely even when they can’t boot. WinRE runs the plug‑ins, handles the repair and gets the device back online. learn.microsoft.com/en-us/wi…
1
16
66
6,402
Andrea Matesi retweeted
Prefer video? I walk through the whole migration on YouTube. ā–¶ļø youtube.com/watch?v=toptT2YB… #PowerShell #Intune Every claim (Sept 16 2026 date, the exact Microsoft quote on v3, the Nov 11 2026 7.4/7.5 EOL date, the 7.6-into-2028 runway
1
2
412
šŸš€ Staged rollouts in Microsoft Intune just got released in public preview! If you've ever had to manage multi-phase app or policy deployments by manually swapping Entra groups or building custom PowerShell automation, Deployment Plans in Microsoft Intune is a massive quality-of-life upgrade. Instead of all-or-nothing rollouts or manual babysitting, Intune now gives us built-in orchestration to roll out payloads (apps & configuration policies) across staged rings. Here are 3 reasons why this new feature is a game-changer: 1ļøāƒ£ Standardized, Reusable Rollout Templates No more reinventing the wheel for every application or policy update. With Deployment Plans, you can define your organization's approved rollout pattern once (e.g., Pilot → Early Adopters → Broad → All Devices) with preset deferral intervals (hours/days). When you're ready to deploy, you just attach the payload to your plan. 2ļøāƒ£ Cumulative Phased Rings (With Virtual Group Smarts) Each ring safely expands targeting cumulatively over time. Even better: if your final ring targets virtual groups like All Devices or All Users, Intune automatically handles the transition—clearing previous staging assignments and rolling up the deployment cleanly into a broad assignment. 3ļøāƒ£ Full Control with Pause, Resume & Collision Detection Things don’t always go according to plan, and safety nets are essential. Active deployments can be paused, resumed, or cancelled on the fly. Plus, built-in assignment collision detection prevents conflicts before a ring activates, protecting production environments from accidental dual-targeting or configuration drift. Native ring-based deployments have been on the community wishlist for a long time, and bringing this directly into the Intune Admin Center is a huge step forward for safer change management. šŸ”— Read the full documentation: learn.microsoft.com/en-us/in… Have you tested this out in preview yet? How are you handling staged rollouts today? šŸ‘‡ #MicrosoftIntune #EndpointManagement #SysAdmin #ModernWorkplace #CloudManagement #MSIntune
1
28
97
7,032
Andrea Matesi retweeted
Even better news - Server 2016 reaches end of support in January 2027!

ALT Lets Go Hurry GIF

5
5
32
4,021
Andrea Matesi retweeted
OK, so this is actually a pretty big deal 🄳 Microsoft removed the Entra P1 license requirement to export logs from Entra to Azure Storage or Event Hub Even better, Azure Data Explorer offers up to 100GB free data ingestion from these - a huge win for small/low resource orgs
Entra ID sign-in logs are not accessible via the Graph API in free-tier tenants, but they can still be collected live using diagnostic settings to send them to event hub. The former is documented but not the latter. Is it known or intended?
4
54
291
26,798
Andrea Matesi retweeted
Every Windows admin has typed cscript slmgr.vbs /ato at least once. It feels permanent. It isn't. VBScript is being removed from Windows entirely, and slmgr.vbs goes with it. Here's the replacement, and why it'll fail silently if you don't migrate. 🧵 #PowerShell #Windows11
4
17
81
13,864
Andrea Matesi retweeted
We’re sharing a solution to the Navier-Stokes Millennium Prize Problem, one of the deepest problems at the frontier of mathematics. The proof was produced by a group of agents, using an OpenAI next-generation model significantly more capable than GPT-6 Astra. The problem concerns whether the description of smooth three-dimensional fluid motion modeled by the Navier-Stokes equations can break down. It has remained unresolved for roughly 90 years.
5,704
20,138
120,427
75,097,682