Skip to content

Removing %SystemRoot% mentions - #1391

Merged
DanPiazza-Netwrix merged 7 commits into
devfrom
origin/JBogalecki-Netwrix/ADO411519_remove_string
Aug 19, 2026
Merged

Removing %SystemRoot% mentions#1391
DanPiazza-Netwrix merged 7 commits into
devfrom
origin/JBogalecki-Netwrix/ADO411519_remove_string

Conversation

@JBogalecki-Netwrix

Copy link
Copy Markdown
Collaborator

@github-actions

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

47 issues fixed, 8 skipped across 2 files

CategoryFixes
Dale: idioms1
Dale: misplaced-modifiers2
Dale: passive-voice32
Dale: positional-references1
Dale: wordiness10
Dale: xy-slop1
Skipped (needs manual review)Reason
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:9 — Netwrix.FirstPersonFalse positive. The flagged 'I' is part of the proper name of the third-party service 'Have I Been Pwnd (HIBP)', not first-person usage. The rule matches '\bI\b' with no proper-noun exception. Removing or rewording the 'I' would misname the service or drop the required first-use expansion of the HIBP acronym. The same phrase appears in 30 files across passwordpolicyenforcer, threatprevention, and accessanalyzer, confirming it is established terminology.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:9 — Netwrix.FirstPersonFalse positive. Identical sentence to the 11.0 file: the flagged 'I' belongs to the service name 'Have I Been Pwnd (HIBP)'. No rewrite can remove it without misnaming the service or losing the acronym expansion.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:36 — Dale: xy-slop'only on the Network Share, not on each Domain Controller' states the positive first and the contrast is the substance of the point; rewriting would not improve it and risks losing the comparison
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:37 — Dale: misplaced-modifiers'a working network connection from the Domain Controllers to the Network Share with Read permissions' is genuinely ambiguous — 'with Read permissions' could attach to the connection, the account, or the share, and each reading changes the technical requirement
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:38 — Dale: wordinessSentence fragment continuing the colon on the previous line, spliced with an unrelated performance caveat; a confident rewrite requires knowing the intended structure of the bullet pair
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:38 — Dale: undefined-acronymsLSASS is a standard Windows OS component name that the sysadmin audience for this page would recognize
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:50 — Dale: wordiness'users' new and pending password (i.e. during a password reset)' — the parenthetical's scope is unclear, so condensing it could change which operation is being described
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:61 — Dale: wordiness'users' new and pending password (i.e. during a password reset)' — the parenthetical's scope is unclear, so condensing it could change which operation is being described

Ask @claude on this PR if you'd like an explanation of any fix.

@DanPiazza-Netwrix
DanPiazza-Netwrix marked this pull request as draft August 18, 2026 17:58
@github-actions

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

10 issues fixed, 12 skipped across 4 files

CategoryFixes
Dale: passive-voice4
Dale: wordiness6
Skipped (needs manual review)Reason
docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md:25 — Netwrix.FirstPersonFalse positive: the 'I' is part of the proper name of the third-party service 'Have I Been Pwnd (HIBP)'. Removing or rewriting it would make the reference factually wrong.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:9 — Netwrix.FirstPersonFalse positive: the 'I' is part of the proper name of the third-party service 'Have I Been Pwnd (HIBP)', spelled out on first use per the acronym rule. No rewrite preserves meaning.
docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md:25 — Netwrix.FirstPersonFalse positive: the 'I' is part of the proper name of the third-party service 'Have I Been Pwnd (HIBP)'. Removing or rewriting it would make the reference factually wrong.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:9 — Netwrix.FirstPersonFalse positive: the 'I' is part of the proper name of the third-party service 'Have I Been Pwnd (HIBP)', spelled out on first use per the acronym rule. No rewrite preserves meaning.
docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md:16 — Dale: wordinessSentence is truncated mid-clause: "The path can contain environment variables like" with no example following. This is a content gap left by the %SystemRoot% removal, not a style issue — the author must decide whether to supply a replacement example or delete the clause, so any fix would change meaning.
docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md:16 — Dale: wordinessSentence is truncated mid-clause: "The path can contain environment variables like" with no example following. This is a content gap left by the %SystemRoot% removal, not a style issue — the author must decide whether to supply a replacement example or delete the clause, so any fix would change meaning.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:50 — Dale: misplaced-modifiersThe parenthetical "(i.e. during a password reset)" is intended to qualify "pending" but sits after the whole noun phrase, and the phrase also has a subject-verb mismatch ("password ... matches"). Several valid restructurings exist with different emphasis, so a confident meaning-preserving fix isn't clear.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:61 — Dale: misplaced-modifiersThe parenthetical "(i.e. during a password reset)" is intended to qualify "pending" but sits after the whole noun phrase, and the phrase also has a subject-verb mismatch ("password ... matches"). Several valid restructurings exist with different emphasis, so a confident meaning-preserving fix isn't clear.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:37 — Dale: misplaced-modifiers"Requires a working network connection ... with Read permissions to check:" ends in a colon but the next bullet is a sibling rather than a child, and "with Read permissions" attaches ambiguously. Fixing the modifier requires restructuring the whole bullet list, which risks changing the technical meaning.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:38 — Dale: wordiness"The pending password candidate from Domain Controller against the HIBP Database stored on the Network Share, this could affect LSASS/Password Change performance..." is a comma-spliced fragment dependent on the broken list structure at line 37. Rewriting it in isolation would guess at the author's intended sentence boundaries.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:134 — Dale: wordiness"automate the tool to retrieve and/or prepare the HIBP dataset" is wordy, but the "and/or" carries a real technical distinction (retrieve, prepare, or both) that a concise rewrite would collapse.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:145 — Dale: wordiness"automate the tool to retrieve and/or prepare the HIBP dataset" is wordy, but the "and/or" carries a real technical distinction (retrieve, prepare, or both) that a concise rewrite would collapse.

Ask @claude on this PR if you'd like an explanation of any fix.

@github-actions

Copy link
Copy Markdown
Contributor

Documentation PR Review

Editorial Review

docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md

  • Completeness — Line 16: The rewrite dropped the environment variable example. The original sentence ended with "The path can contain environment variables like" and the example %SystemRoot% was stranded in the warning block below. Removing the stranded text also removed the only example, so the reader now has no model for what a valid path looks like. The 11.2 version of this page keeps an example (%ProgramFiles%). Suggested fix: "The path can contain any standard Windows environment variable, such as %SystemRoot% or %ProgramFiles%."
  • Clarity — Line 24: "Have I Been Pwnd (HIBP)" misspells the service name. The service is Have I Been Pwned, and the 11.2 pages already use the correct spelling. Suggested fix: "the Have I Been Pwned (HIBP) database."

docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md

  • Completeness — Line 23: "consider the pros and cons of each deployment location" promises a comparison, but the two bullets that follow describe only a local copy — no alternative location is presented, so "each" has nothing to refer to. The 11.1 version of this page has the full local-vs-network-share comparison. Suggested fix: port the two-scenario comparison from 11.1, or reword to match the content actually present: "Before deploying the HIBP database, consider the following."
  • Clarity — Line 9: "Have I Been Pwnd (HIBP)" misspells the service name. Suggested fix: "Have I Been Pwned (HIBP)."
  • Clarity — Line 63: "this download consumes significant CPU and time" reads awkwardly and loses the original meaning, which was download time specifically. Suggested fix: "this download consumes significant CPU resources and takes a long time to complete."

docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md

  • Completeness — Line 16: Same as 11.0 — the environment variable example was removed along with the stranded %SystemRoot% text, leaving the reader with no example of a valid path. Suggested fix: "The path can contain any standard Windows environment variable, such as %SystemRoot% or %ProgramFiles%."
  • Clarity — Line 24: "Have I Been Pwnd (HIBP)" misspells the service name. Suggested fix: "the Have I Been Pwned (HIBP) database."

docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md

  • Clarity — Line 27: "(Aproximetly 13GB but subject to change)" carries two typos into a rewritten line — "Aproximetly" and the missing space in "13GB". The same bullet in the 11.0 file was corrected in this PR, so the two versions now disagree. Suggested fix: "The HIBP database takes up additional space on the machine where you copy it (approximately 13 GB, but subject to change)."
  • Clarity — Line 28: "in the location that the Rule specifies" leaves the reader guessing which rule, and the capitalized "Rule" isn't a defined term on this page. Suggested fix: "For a local deployment, the database must be on every domain controller, in the location specified by the Compromised rule."
  • Clarity — Line 38: "The HIBP database requires space on one Network Location instead of on each domain controller" restates the first bullet in the same list ("The database takes up space only on the Network Share, not on each Domain Controller"). Two bullets making the same point in a pros-and-cons list makes the trade-off harder to scan. Suggested fix: delete this bullet.
  • Clarity — Line 39: "the Domain Controller must assume the hash is okay" is vague about the actual behavior — the reader can't tell whether the password is accepted, rejected, or queued. Suggested fix: "During a password change, if the Network Share isn't available, the domain controller can't check the hash and accepts the password, which could allow a known compromised password."
  • Clarity — Line 9: "Have I Been Pwnd (HIBP)" misspells the service name. Suggested fix: "Have I Been Pwned (HIBP)."
  • Clarity — Line 74: "this download consumes significant CPU and time" reads awkwardly and loses the original meaning of download time. Suggested fix: "this download consumes significant CPU resources and takes a long time to complete."

Summary

13 editorial suggestions across 4 files. Vale and Dale issues are auto-fixed separately.

Two themes worth a look before merge: the environment variable example was lost from both compromised_rule.md files when the stranded %SystemRoot% text was cleaned up, and the two versions of hibpupdater.md have drifted apart — 11.0 promises a comparison of deployment locations it doesn't contain, while 11.1 has the comparison but kept typos that were fixed in 11.0.


What to do next:

Comment @claude on this PR followed by your instructions to get help:

  • @claude fix all issues — fix all editorial issues
  • @claude help improve the flow of this document — get writing assistance
  • @claude explain the voice issues — understand why something was flagged

You can ask Claude anything about the review or about Netwrix writing standards.

Automated fixes are only available for branches in this repository, not forks.

@github-actions

Copy link
Copy Markdown
Contributor

Auto-Fix Summary

10 issues fixed, 12 skipped across 4 files

CategoryFixes
Dale: misplaced-modifiers2
Dale: passive-voice2
Dale: undefined-acronyms1
Dale: wordiness5
Skipped (needs manual review)Reason
docs/passwordpolicyenforcer/11.0/admin/manage-policies/rules/compromised_rule.md:24 — Netwrix.FirstPersonFalse positive: the 'I' is part of the third-party service name 'Have I Been Pwnd (HIBP)', not first-person voice. Any rewrite would corrupt the proper noun.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:9 — Netwrix.FirstPersonFalse positive: the 'I' is part of the third-party service name 'Have I Been Pwnd (HIBP)', not first-person voice. Any rewrite would corrupt the proper noun.
docs/passwordpolicyenforcer/11.1/admin/manage-policies/rules/compromised_rule.md:24 — Netwrix.FirstPersonFalse positive: the 'I' is part of the third-party service name 'Have I Been Pwnd (HIBP)', not first-person voice. Any rewrite would corrupt the proper noun.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:9 — Netwrix.FirstPersonFalse positive: the 'I' is part of the third-party service name 'Have I Been Pwnd (HIBP)', not first-person voice. Any rewrite would corrupt the proper noun.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:23 — Dale: idioms'pros and cons' is standard business English rather than a culturally specific idiom; rewriting to 'advantages and disadvantages' adds length without improving clarity.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:109 — Dale: xy-slop'Password Policy Enforcer doesn't distribute hash file updates to other computers, but you can use the Windows Distributed File System...' is a factual limitation plus a workaround with a different subject, not the 'x is not y, x is z' rhetorical pattern.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:105 — Dale: wordiness'the local copy of the (manually obtained) database' is awkward, but the parenthetical carries meaning about how the file was sourced and multiple rewrites are equally valid.
docs/passwordpolicyenforcer/11.0/installation/hibpupdater.md:49 — Dale: wordinessThe Passwords Hash database sentence is long and has a number-agreement problem, but tightening it risks changing the technical claim about which password (new versus pending) is checked.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:23 — Dale: idioms'pros and cons' is standard business English rather than a culturally specific idiom.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:38 — Dale: wordiness'The HIBP database requires space on one Network Location instead of on each domain controller' duplicates the first bullet in the same list, but removing a whole bullet is a content decision for the author, not a style fix.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:39 — Dale: wordiness'must assume the hash is okay' is informally worded, but any replacement ('assumes the password is not compromised') asserts specific fallback behavior that isn't stated elsewhere.
docs/passwordpolicyenforcer/11.1/installation/hibpupdater.md:60 — Dale: wordinessThe Passwords Hash database sentence is long and has a number-agreement problem, but tightening it risks changing the technical claim about which password is checked.

Ask @claude on this PR if you'd like an explanation of any fix.

@JBogalecki-Netwrix
JBogalecki-Netwrix marked this pull request as ready for review August 19, 2026 12:47
@DanPiazza-Netwrix
DanPiazza-Netwrix merged commit ffb517d into devAug 19, 2026
10 checks passed
@DanPiazza-Netwrix
DanPiazza-Netwrix deleted the origin/JBogalecki-Netwrix/ADO411519_remove_string branch August 19, 2026 13:17
JBogalecki-Netwrix pushed a commit that referenced this pull request Sep 4, 2026
Port the fix from PR #1391 (netwrix/docs) to v12.0. That PR cleaned up
a dangling "%SystemRoot%." fragment left in a warning callout in
11.0/11.1's hibpupdater.md; 11.2 (and the v12.0 scaffold copied from
it) went through a separate rewrite that missed this one instance.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
JBogalecki-Netwrix pushed a commit that referenced this pull request Sep 4, 2026
11.2 is still fully built and directly reachable even though it's now
hidden from navigation, so the same stray "%SystemRoot%." fragment
fixed in 12.0 was still live there. Apply the same one-line fix from
PR #1391.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
hilram7 pushed a commit that referenced this pull request Sep 4, 2026
* docs(ppe): scaffold Password Policy Enforcer v12.0
Copy the 11.2 docs and sidebar as the v12.0 baseline, register the new
version in products.js as latest/default, and repoint internal
cross-links within the new version to 12.0. Screenshots and installer
build numbers still reference 11.2 pending real v12.0 assets/builds.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
* docs(ppe): update v12.0 build numbers and use dedicated v12.0 images
Replace the inherited 11.2.0.148 build number with 12.0.0.78 in
installer filenames, msiexec examples, and cmdlet version output.
Copy static/images/passwordpolicyenforcer/11.2/ to a new 12.0/ folder
and repoint all image references in the v12.0 docs to it, so the new
version no longer depends on the 11.2 image set.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
* docs(ppe): remove placeholder images from v12.0 scaffold
The v12.0 copy carried over 11.2's screenshots verbatim, which
misrepresented an unreleased version's UI. Remove all 123 image
embeds and the copied static/images/passwordpolicyenforcer/12.0/
folder (170 files), and reword the two passages that referenced a
screenshot directly in prose (complexity_rule.md, history_rule.md)
so they stand on their own without an image.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
* docs(ppe): remove stray %SystemRoot% mention in v12.0 hibpupdater.md
Port the fix from PR #1391 (netwrix/docs) to v12.0. That PR cleaned up
a dangling "%SystemRoot%." fragment left in a warning callout in
11.0/11.1's hibpupdater.md; 11.2 (and the v12.0 scaffold copied from
it) went through a separate rewrite that missed this one instance.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
* fix(vale): auto-fix style issues (Vale + Dale)
* docs(ppe): fix orphaned image-caption regressions and stale version references
Address review findings from PR #1478:
- testpolicy.md: reword the fail/pass example paragraphs left orphaned
by the screenshot removal
- usersgroups.md: replace the empty "Policy selection flowchart"
section with a Mermaid diagram reproducing the removed screenshot
(managing_policies.webp) exactly
- character_rules.md, configuring_the_password_policy_client.md:
fix sentences left trailing into a removed screenshot
- testing_the_password_policy.md: replace the orphaned "mypassword
fails two requirements" reference with the actual failing rules
- CLAUDE.md: add the missing 12.0 row, correct 11.2's status to
Hidden, and make the Cmdlets/Rules convention sections reference
"the current latest version" instead of hardcoding 11.2 so they
don't go stale on the next version bump
- Two KB source files: drop the hardcoded 11_2 version segment from
5 links so they resolve through the evergreen version-less redirect
instead of pointing at the now-hidden 11.2 docs
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
* fix(vale): auto-fix style issues (Vale + Dale)
* docs(ppe): backport %SystemRoot% fix to 11.2
11.2 is still fully built and directly reachable even though it's now
hidden from navigation, so the same stray "%SystemRoot%." fragment
fixed in 12.0 was still live there. Apply the same one-line fix from
PR #1391.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X5R4A6vzRHbgT2b1S7hguR
* fix(vale): auto-fix style issues (Vale + Dale)
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@JBogalecki-Netwrix@DanPiazza-Netwrix@jth-nw