Initial situation In a small company (about 25 employees), over the past 2-3 months, problems with work PCs on Windows have become more frequent: slow logins, long launch times for office applications, periodic VPN interruptions and Explorer freezes. Symptoms do not manifest themselves in the same way for everyone; some users work remotely via the home Internet. Previously, targeted attempts were made to “clean up startup” and reinstall the VPN client, but the effect lasted for 1-2 weeks. Technical environment and limitations - Windows 10 22H2 and Windows 11 23H2, AD domain environment, roaming user profiles disabled - Microsoft 365 Apps, OneDrive, Teams, BitLocker enabled - Cisco AnyConnect VPN client (some users) and OpenVPN (another part) - you cannot change the VPN vendor - There is no centralized RMM, access is possible through Quick Assist/AnyDesk and locally 1-2 times a week - You cannot stop office work for more than 30 minutes per workstation; reinstalling the OS is allowed only as the last step and for a maximum of 2 PCs - User data cannot be touched - any changes must be reversible and documented What to do 1) Conduct a technical investigation into the causes of degradation - Collection of diagnostic data from at least 6 representative PCs (3 “problematic”, 3 “conditionally normal”) - Analysis of Windows Event Viewer logs (system, application, VPN), Reliability Monitor - Analysis of startup, services, scheduler tasks, drivers, network stack, influence of EDR/antivirus (if installed) - Performance measurements: login time, desktop appearance time, Excel/Outlook startup time, VPN interruption rate, DNS delays - Search for repeating patterns: driver conflicts, profile problems, GPO policies, DNS, MTU, split-tunnel, WFP filters, etc. 2) Prepare and implement a remediation plan in 2 stages - Quick adjustments with minimal risk (settings, services, network parameters, exceptions for VPN/OneDrive/Teams, correct clearing of caches/profiles, system integrity check) - In-depth adjustments if necessary (updating/rolling back drivers, changing VPN connection parameters within the current client, setting up GPOs, optimizing logon scripts, fixing problems with user profiles) - Implementation through an agreed checklist, with a work window and a rollback plan 3) Communicate the result and ensure reproducibility - Short instructions for the administrator “how to diagnose and prevent recurrence” - Final report with the root causes found, what exactly was changed, on which PCs, and why - A set of scripts/commands (PowerShell) for re-collecting diagnostics and basic checks (safely, without downloading personal data) Expected specific result - Reducing average user login time by at least 30% on problem PCs (compared to baseline measurement) - Reduced the number of VPN interruptions by at least 2 times on the same PCs within 5 working days after implementation - Elimination of recurring critical errors in Reliability Monitor related to Explorer/VPN/network stack (no more than 1 critical event per PC per 5 days is allowed) - A documented and reproducible fix plan that can be applied to other PCs without manual magic Acceptance criteria (measurable) - Initial measurements and final measurements for selected PCs are provided: login, application launch, VPN stability - List of changes accurate to parameters/keys/policies and rollback steps - Minimum 1 test run of the diagnostic script on 2 PCs with attached logs (without personal data) Notes Domain access/local admin rights will be issued for the duration of the work. It is important that the solutions are accurate: without “tweaks from the Internet”, disabling security and without installing dubious optimizers.