Supported Tasks
With proper privileged access (permanent Domain Admin OR modern JIT/ZSP setup), the agent can autonomously complete 95%+ of standard Tier-1 and Tier-2 tickets without human intervention.
Tier 1 – User & Workstation Support (100% autonomous today)
✔ Reset user passwords (AD & Entra ID/Azure AD)
✔ Unlock user accounts
✔ Enable/disable accounts
✔ Add/remove users from security groups
✔ Create new AD user accounts (onboarding)
✔ Manage Microsoft 365 licenses (assign/remove)
✔ Rotate or retrieve BitLocker recovery keys
✔ Retrieve or rotate Windows LAPS passwords
✔ Reboot workstations/servers remotely
✔ Force Group Policy update (gpupdate)
✔ Clear print spooler on workstations & print servers
✔ Install/uninstall software via Intune or PSEXEC
✔ Run remote PowerShell scripts on endpoints
✔ Join/re-join computers to domain
✔ Rename computers
✔ Move computers between OUs
Tier 2 – Server & Infrastructure Tasks (90–95% autonomous today)
✔ Restart Windows services on servers
✔ Check and clear disk space (including pagefile, logs, shadow copies)
✔ Extend or shrink volumes (online)
✔ Manage IIS application pools (recycle, start, stop)
✔ Check and restart failed Windows updates
✔ Retrieve and upload CBS/DISM logs for analysis
✔ Manage scheduled tasks (create/modify/delete)
✔ Add/remove server roles & features (with reboot scheduling)
✔ Manage DNS record management (A, CNAME, PTR, MX)
✔ DHCP scope management and reservation creation
✔ Manage local administrators on servers/workstations
✔ Patch management status checks and forced scans
✔ SCCM/Intune client repair and reinstall
Active Directory & Entra ID Hygiene
✔ Find and disable stale user/computer accounts
✔ Find and clean up orphaned objects
✔ Manage group membership at scale
✔ Generate compliance reports (privileged groups, password age, etc.)
Security & Incident Response (with proper tooling)
✔ Isolate compromised workstation (disable NIC, move to quarantine VLAN)
✔ Kill malicious processes remotely
✔ Run Sysmon/EVTX queries across fleet
✔ Retrieve and rotate service account passwords
✔ Emergency account lockout and privilege revocation
Tasks that still require human review or break-glass (2025)
✘ Domain controller promotion/demotion
✘ Schema updates
✘ Full forest recovery
✘ Certificate Authority management
✘ GPO creation/modification that affects Domain Admins/Enterprise Admins
Tasks that still require human review or break-glass (2025)
✘ Domain controller promotion/demotion
✘ Schema updates
✘ Full forest recovery
✘ Certificate Authority management
✘ GPO creation/modification that affects Domain Admins/Enterprise Admins