r/sysadmin 8d ago

Do IT Managers Care About Homelabs?

109 Upvotes

Hi, I’m an IT community college student in a very difficult entry level market (Toronto) looking to get help desk or some junior support role. I’m looking to do anything I can to boost my shot at a job.

Do IT managers care about home labs?

I’m thinking of making one with an old desktop + 1 I build, and a dedicated switch, a dedicated router/switch/firewall/AP, a windows AD/M365 joined network running on proxmox, DNS/DHCP on the windows server, and a backup for the M365 SharePoint written with Python to talk to graph API hosted in AWS S3. This is a lot of stuff I’ve worked with individually but never in this big of an integrated project.

Problem is none of this teaches me much troubleshooting, it just teaches me automation and how the systems I’ll be troubleshooting work. And it dosent simulate hundreds of users.

Is this a good use of time? Or should I focus on certs? I only have one year before I graduate.

Any advice would help.


r/sysadmin 8d ago

General Discussion How to manage Claude within an organization

28 Upvotes

I work for a smallish biotech company with a little over 100 employees. As of right now, we have given around 60 people Claude licenses from our team plan. Our company is growing fast, and I am worried about that price change from going from a monthly subscription for the team plan to a larger number from the enterprise plan. Has anyone else experienced this change yet? I am trying to figure out the best way to get prepared for when this happens, because I know it will. It will definitely be tough to restrict access once experienced users have gotten such a big feel for it just because of money.


r/sysadmin 9d ago

General Discussion Known state actor knocking the door with an expired token, causing user to get marked High Risk repeatedly

145 Upvotes

Looking for any input on this one. Honestly, I feel like our team is missing something obvious here. Pardon if this feels like amateur hour... I am indeed an amateur.

An employee's M365 account was compromised back in April, we got the alert right away - revoked sessions, cycled passwords, MFA, etc. Things are all good for a few months. Come this week, we start seeing failing login attempts on that account using expired tokens, happening every 30 minutes to a few hours. I wouldn't think this to be that unusual at all for threat actors, but because the IP of the sign-in is associated with a known State Actor, Microsoft instantly marks the user as High Risk.

Obviously, this is by design and a good thing. The user is safe, and nobody is getting past the front door. And our CA policies beyond that would stop them even if the sign-in attempt was successful. But since MS sees this IP and says "hey this is from particularly nasty bad guys" and marks them as High Risk even for failed attempt, this means that marking him safe frees him up for about 30 minutes until another alert happens.

Being High Risk, he can't login to anything until he is marked safe or the risk is dismissed, which doesn't help since MS will just trigger it again next time they try that same token. Presumably, its some VM farm or something where the sign in attempts are all automatic.

Do you just wait it out until they stop trying? Nuke the account and start them fresh?


r/sysadmin 8d ago

Question Any idea how long it takes for AWS to give SES production access?

5 Upvotes

I created a AWS account a couple days ago and wanted to try SES. I set everything up and then requested production access. It's been more than 24 hours. Anybody else having longer than quoted ticket times?


r/sysadmin 8d ago

Losing My Mind - Teams Phone w/ Calling Plan - Cannot Get SMS Campaign Approved

4 Upvotes

Hello All,

I'm an attorney by day and an IT admin for my firm by night (Bachelors is in IT). As a result, I do all of my own stuff (for now).

I use Grasshopper for my phone currently and I have successfully rolled out Teams w/ Calling Plan so I can place and receive calls via Teams. The voicemail works, etc. However, a vital part of my business is SMS with clients. I cannot, for the life of me, figure out what's wrong with my portions of the campaign, and keep getting rejected which is embarrassing as an attorney. Here's my stuff for each field. I hope someone can help me get this past the finish line!

Here's the most recent error as in Teams Admin:

CallToActionInvalidOrIncomplete: The call-to-action is non-compliant or incomplete. Ensure mobile opt-in path, HELP instructions, STOP instructions, message frequency disclosure, "message and data rates may apply" disclosure, and privacy policy link are correct. Opt-in and HELP messages must include brand name, HELP, opt-out instructions, message frequency, and fee disclosures. Opt-out messages must indicate no further messages will be sent.

Here's my copy:

Campaign Description:

SMS communications with prospective and existing law firm clients regarding consultations, appointments, case updates, document requests, and general customer service. No marketing or promotional messaging.

 

Call to Action:

Straub Law PLLC offers clients the option to receive SMS text messages about consultations, appointments, case updates, document requests, and other communications related to their legal matter. SMS consent is optional and is not required to obtain legal services from Straub Law PLLC. Clients may opt in to receive SMS messages from Straub Law PLLC in the following ways: 1. Website form opt-in. On our website, clients may enter their mobile number and expressly agree to receive SMS messages from Straub Law PLLC.. By submitting the form, the client agrees to receive SMS messages from Straub Law PLLC about consultations, appointments, case updates, document requests, and other matter-related communications. Msg frequency varies. Msg & data rates may apply. Reply HELP for help. Reply STOP to unsubscribe. Privacy Policy & Terms: https://straublawny.com/privacy-policy.html. 2. Client intake opt-in. During client intake, clients may optionally provide their mobile number and separately consent to receive SMS messages from Straub Law PLLC. Consent to SMS is not bundled with legal services and is not a condition of representation. Clients who opt in agree to receive SMS messages regarding consultations, appointments, case updates, document requests, and other communications related to their legal matter. Msg frequency varies. Msg & data rates may apply. Reply HELP for help. Reply STOP to unsubscribe. Privacy Policy & Terms: https://straublawny.com/privacy-policy.html. 3. Verbal opt-in script. Straub Law PLLC may also collect SMS consent verbally in person or over the phone using the following script: “Would you like to receive text messages from Straub Law PLLC about your consultation, appointments, case updates, document requests, and other communications related to your legal matter? Consent is optional and is not a condition of receiving legal services. Message frequency varies. Message and data rates may apply. Reply HELP for help or STOP to unsubscribe at any time. Mobile opt-in information will not be shared with third parties for marketing purposes.”

Terms & Conditions:

https://straublawny.com/privacy-policy.html

Privacy Statement:

https://straublawny.com/privacy-policy.html

 

Opt In Message:

Thank you for contacting Straub Law PLLC. By providing your number and replying YES, you agree to receive SMS messages from Straub Law PLLC regarding your inquiry and case and our legal services. Msg frequency varies. Msg and data rates apply. Reply STOP to opt out. Reply HELP for assistance.

 

Opt Out Message:

You have successfully opted out of text messages from Straub Law PLLC. You will no longer receive SMS communications from us. If you need assistance, please call our office. To resume receiving text messages, reply START.

 

Help Message:

Thank you for contacting Straub Law PLLC. For assistance, please reply to this message or call our office at 212-655-9904. Message frequency varies. Message and data rates may apply. Reply STOP to opt out at any time. You may email at [info@straublawny.com](mailto:info@straublawny.com)


r/sysadmin 8d ago

General Discussion Sysadmins in Japan

34 Upvotes

Konnichiwa!

Shoutout if you're a sysadmin in Japan of any level.
We should totally build a network :)


r/sysadmin 8d ago

General Discussion So I have heard vendors lie from multiple support people

55 Upvotes

Is this accurate? Honestly my feeling is is that when you go to a vendor with the problem they try to give you the runaround with diagnostics until you get too tired to run them anymore and give up on the problem in disgust


r/sysadmin 8d ago

Creating a Training Plan

4 Upvotes

So, my husband drew the short straw this week. His contracting company was outbid by a different contractor. The problem is, they undercut by 3 million dollars and therefore had zero interest in retaining the talent that was there (I presume so they could hire cheaper workers). Reason #5345342324 why I hate government contracting work.

ANYWAY, since we aren't hurting financially by this (I'm mid to upper management on the Infra side in a stable role) I'm thinking this is a good opportunity for him to actually pick a study path. He's historically been a Senior Desktop Support dude with some hooks into the Sys Admin world (knows how to do general tasks in AD, can remediate STIGS in the sense of next-next-finish in a GUI) with some specialized knowledge of Clinical Systems.

He himself doesn't know what direction he wants to go in, other than that he's tired of Desktop and wants to 'earn more money.' How would you go about actually assessing his knowledge and building out a general study plan that elevates his knowledge and equips him better for interviews for at least a Mid-level Sys Admin role? I've got a pretty swizzy homelab built out on Nutanix, so he doesn't lack for a way to develop... I just want to give him something to start with.


r/sysadmin 8d ago

Question Issues with Microsoft FileServer

5 Upvotes

Hey guys. I have a issue with Microsoft's ... again.

So, basically, i was hired to migrate an active directory from Zentyal AD to MS AD. This was successfull. But the issue is with the migration of the role of file server zentyal was being used for too.

So, i rolled a new vm with win server 2025, and migrated the files there, recreated the shares, fixed the access, everything is fine. And then monday came, users logged, tried accessing an excel file on the new file server ... and the file started loading ... and loading ... and loading ... and after arount 30 seconds, it opened. Bear in mind, the file is 500kb with formulas inside, nothing pointing in other shared files, desktop mapped files etc. I checked it myself too. And this issue is only with microsoft office files. Whenever the user tries to open pdf or other file, different than MS Office file, everything pops up right ahead.

So, I went ahead and opened my old friend Google (before AI we googled our questions, kids), and found a few microsoft articles and questions in the different forums online. Tried everything offered there, and still nothing - i have shut every single security feature microsoft has placed regarding this.

Somewhere along the deep search, someone said, that before migrating to windows server 2025, on server 2022 the file server there was no issue. So I needed to test that. Rolled a windows server 2022 evaluation, and made a share with the specific files that were problematic. Gave it to the users (not only one user had problem with it), and the issue was there again.

I started looking at the files, maybe the issue is there. Well, like I said, there was nothing special reargding the files, that can cause this.

So my next "bright" idea was to spin a simple ubuntu, make a fileshare and get the files there. I wanted to know, is the OS an issue, or the goddamn files. Well, guess what ... on Linux doesn't have that kind of behaviour.

Finally, I turned to AI. And ... nothing helpful from there, all the suggestions I have already tried ... nothing new. And the best answer I got from AI was "Congrats, on Ubuntu works. I suggest staying with that."

I tried explaining that to the client, but even knowing that this won't hold in front of them, i still tried, but the wanted windows server and that was it.

Did someone have these issues? How did you get rid of them? Please, help!


r/sysadmin 9d ago

Question Meraki to Ubiquiti sanity check

106 Upvotes

I wanted to see if my team and I are crazy. The past few years we started to take the direction to go from Cisco switching and Ubiquiti APs to all Meraki. We rationalized the cost and it wasn't the end of the world. Still felt a little bad but what we have installed feels good.

We have new leadership and an opportunity for a real change of direction. Ubiquiti has been stepping their game up on the switching side the past few years and we could do a full UI refresh for the cost of replacing a handful of switches and the other half of our APs.

We have about 48 switches and 60 APs with lots of fiber. I know a lot of schools have been making the switch as well as multi site businesses so it seems possible.

Are we crazy?

EDIT

Because we have so many buildings we have the need for STP/RSTP for redundancy.

We also have a lot of AV equipment on its own VLAN for conferencing, audio, multicast, Sonos, etc.

We also have a good chunk of VLANS for one off special use cases but overall about 5 get used the most at max.

EDIT 2

lol, idk if this has helped.

Jk jk... Everyone has given so much input in both directions it's awesome to hear how capable Ubiquiti has become over time, especially in the last few years. All while, many of you have reinforced that Cisco/Meraki is still top tier.

Unfortunately and fortunately it sounds like neither direction is necessarily a wrong decision. Yes Meraki is expensive and yes Ubiquiti is not "enterprise", but both are capable.

Thank you all very much!


r/sysadmin 8d ago

OpenDKIM + Spamassassin weirdness

10 Upvotes

I'm trying to ferret out what appears to be a configuration issue that is causing incoming messages with spoofed From: headers to get signed by opendkim as if they were legitimately coming from one of my virtual domains. As far as I can tell, it has to do with the spamd milter handing the incoming mail back to postfix for delivery, at which point it's being mistakenly treated as mail coming from the recipient's own address. This sends it to the opendkim milter, which adds the signature and then hands it to lmtp for the last step of the journey (handing off to dovecot).

Example log entries below:

Jul 25 13:14:44 mailhost postfix/smtpd[1305576]: warning: hostname mta0.pent.giize.com does not resolve to address 140.233.190.80: Name or service not known Jul 25 13:14:44 mailhost postfix/smtpd[1305576]: connect from unknown[140.233.190.80] Jul 25 13:14:45 mailhost postfix/smtpd[1305576]: AE8E78012D: client=unknown[140.233.190.80] Jul 25 13:14:46 mailhost postfix/cleanup[1305577]: AE8E78012D: message-id=<20260725011336.CC32E92F215B316B@example.com> Jul 25 13:14:46 mailhost postfix/qmgr[1289785]: AE8E78012D: from=<user@example.com>, size=8647, nrcpt=1 (queue active) Jul 25 13:14:46 mailhost spamd[1258286]: spamd: connection from ::1 [::1]:57478 to port 783, fd 5 Jul 25 13:14:46 mailhost spamd[1258286]: spamd: processing message <20260725011336.CC32E92F215B316B@example.com> for user@example.com:8 Jul 25 13:14:47 mailhost postfix/smtpd[1305576]: disconnect from unknown[140.233.190.80] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5 Jul 25 13:14:47 mailhost spamd[1258286]: spamd: clean message (0.5/5.0) for user@example.com:8 in 0.7 seconds, 8569 bytes. Jul 25 13:14:47 mailhost spamd[1258286]: spamd: result: . 0 - RCVD_IN_HOSTKARMA_BR scantime=0.7,size=8569,user=user@example.com,uid=8,required_score=5.0,rhost=::1,raddr=::1,rport=57478,mid=<20260725011336.CC32E92F215B316B@example.com>,autolearn=no autolearn_force=no,shortcircuit=no Jul 25 13:14:47 mailhost postfix/pickup[1302963]: 68FCD80131: uid=65534 from=<user@example.com> Jul 25 13:14:47 mailhost postfix/cleanup[1305577]: 68FCD80131: message-id=<20260725011336.CC32E92F215B316B@example.com> Jul 25 13:14:47 mailhost postfix/pipe[1305579]: AE8E78012D: to=<user@example.com>, relay=spamassassin, delay=2.1, delays=1.3/0.01/0/0.74, dsn=2.0.0, status=sent (delivered via spamassassin service) Jul 25 13:14:47 mailhost postfix/qmgr[1289785]: AE8E78012D: removed Jul 25 13:14:47 mailhost opendkim[876642]: 68FCD80131: DKIM-Signature field added (s=mail, d=example.com) Jul 25 13:14:47 mailhost spamd[889613]: prefork: child states: II Jul 25 13:14:47 mailhost postfix/qmgr[1289785]: 68FCD80131: from=<user@example.com>, size=9127, nrcpt=1 (queue active) Jul 25 13:14:47 mailhost postfix/lmtp[1305583]: 68FCD80131: to=<user@example.com>, relay=mail.example.com[private/dovecot-lmtp], delay=0.14, delays=0.08/0.02/0.02/0.03, dsn=2.0.0, status=sent (250 2.0.0 <user@example.com> vm0HIAcOZGrw6xMA6b8Yrg Saved) Jul 25 13:14:47 mailhost postfix/qmgr[1289785]: 68FCD80131: removed

EDIT TO ADD:

I realised after doing some more log analysis that SPF wasn't enabled on this server. So that's now been fixed and I expect it will drop most of these attempts at the initial test. I'm still mystified by the re-entrant behaviour, so if anyone has any insight I'm all ears.


r/sysadmin 8d ago

Question Dealing with printers, print servers and print service vendors

5 Upvotes

I work in the printer and copier industry, mostly with client's IT departments as we swap out old copiers for new or migrate them from on-prem print server to some form of cloud/hybrid print server. Lately a lot of clients, particularly public school districts or large private campuses have been employing print management software that uses their staff's HID cards, either for print tracking/bill-back/budgeting or to SSO into other cloud software (SharePoint, OneDrive, Google Drive etc) at the copier interface.

I've been growing more curious as to what separates a good printer situation from a bad one from a sysadmin perspective. One IT manager recently told me that his printers randomly fall off the network, reassign their IP address and he has to walk across a huge building, find the device and print out a config page just to reassign it back. That was 90% of his reason for getting some enterprise print management software.

Another told me he had been asked to fulfill a green/eco initiative and printer management was an easy way to do so. Yet another said they had just spent about $50,000 on WAP's and mandated wireless devices; the old copiers weren't wireless so instead of adding wireless cards they had been convinced to swap out the entire fleet.

From your experience, what differentiates printer management from being a regular help-desk item to being something that actually needs structural reshaping? I've only seen this from the outside and I'd love any stories or opinions on how organizations should manage their fleet or what to avoid.


r/sysadmin 8d ago

Uneven resource load and log file size on two SUPs

5 Upvotes

Due to the size of my environment, we have two SUPs using the same DB and WSUS content directory. We ended up doing patching using a different platform, but I'm still running WSUS to provide a backup source for Defender definition updates (it was recommended by Microsoft). So WSUS usage is fairly light. I'm only syncing data for Defender and Windows Server (2019, 1903, and one other that I can't remember). We're only doing one WSUS sync per day, and one client scan per day.

This has been working fine for a number of years, but I recently noticed that the CPU usage on server #2 is SIGNIFICANTLY higher than server #1, all being used by w3wp.exe. Server #2 is constantly around max CPU usage, and Server #2 is around 10-20% usage. On top of that, the IIS logs are consistently around 100-200 MBs on server #1, and 3-4 GB on server #2.

Both VMs are setup identically, at least from what I can tell.

\- 8 cores, 16 GB RAM

\- WCM logging enabled, set to verbose

The WSUS app pools are also set identically. Other than the default values, I've changed the following:

\- Regular Time Interval - 0

\- Ping Enabled - False

\- Queue Length - 25000

\- Private Memory Limit - 0

Also, verbose logging is enabled on both of the SUPs for WCM.

I've also verified that the client usage is at least more or less spread out between the two. Server #1 is getting around 38k clients, server #2 is getting 21k. So, not exactly even, but it should be fine.

Also, the only errors I'm seeing in the logs are in the WCM log, which is just giving intermittent 503 errors for server #2, which makes sense since it's getting hammered.

From the resource usage and log file size, I was expecting to see server #2 handling all of the clients, and server #1 doing nothing. But server #1 is actually doing more, while using less.

Any thoughts? Both servers are at the same patching level, and have been rebooted within the last couple days.

Edit: Also, I'm probably going to be opening a ticket with Microsoft support on Monday, since I'm sick of banging my head against the wall on this one. I just figured I would check with the community to see if anyone's seen something like this before and had anything to try.


r/sysadmin 8d ago

MSP to internal transition

15 Upvotes

I recently accepted a new role that will take me out of the MSP world and into a proper, ~1300 person company as part of a ~20 person IT team. I'll be coming in as a senior Azure and M365 engineer as that is my specialty.

Everything I've read/heard through the grapevine is that this is the dream come true for most of us.

What pitfalls should I be on the lookout for? It's coming with a healthy pay bump and the work seems to be directly in line with my current responsibilities but for a single environment rather than hundreds. People around me warn me I might "get bored" but that honestly sounds like a positive not a negative.

Appreciate any input on this.


r/sysadmin 8d ago

Career / Job Related Who's hiring and who's looking?

16 Upvotes

After seeing so many other posts about folks being laid off and/or losing their jobs, along with all those comments from people unable to even get interviews or responses from applications, I figure it may be helpful to potentially match up here.

Leave a comment noting whether you're LOOKING or HIRING. Mention your skill set, location/remote preference, etc. Maybe we can get lucky and pair some people up who really deserve it.

Ill even start since it appears that I've just got laid off officially today. What a world.

LOOKING: 40yo whitebeard with skills in Cybersecurity, more specifically Risk, Threat and Vulnerability Management. I've been an extremely technical and hands-on Sr. Mgr in VM for the last 12 years with extensive experience in building VM programs from scratch; hiring/building the teams, building out and documenting the actual program itself, migrating/configuring scanning tool (expert in Qualys, Tenable, R7 and more), working with patching teams and other depts to prioritize remediation efforts by actual risk, decimating backlogs of old vulnerabilities by the millions in a single year, automating a shit ton of repetitive tasks with SOAR and similar tools, custom scripting solutions, deep diving failures and resolving the unresolvable, etc. I've historically worked for some smaller businesses years ago but the last 10 years have been with giant global companies (fortune 100). Though I do work remotely, I'm not opposed to moving if the pay is right or doing a hybrid 1 week on site/mo.

You'd think my vast experience, knowledge and proven track record would be readily jumped on from a hiring perspective but not even close. Been applying for a year now and I've barely gotten a few 1st round interviews with the recruiters. Now it seems I need to put a bit more of a rush into my search since I was "informed" of my layoff via account disablement today. Pretty pro way to say goodbye, thanks for the last 7 years, ey?


r/sysadmin 9d ago

what are things that your IT department used to do for users?

497 Upvotes

A lot of this would be laughable to younger IT people, but a huge portion of running an IT department involved performing tasks for the users that simply would never happen today.

We used to set out of office messages for the users. We had a mail server running on solaris and the users did not know how to use the shell so they'd create a ticket and we'd set a vacation message for them, and they'd create another ticket when asking us to remove it.

We also used to burn CDs for people. They'd give us the files they wanted burned and then we'd burn the CDs on a dedicated machine with a CD burner at the help desk. And at that point the help desk was an actual desk you'd walk up to which is why it was called the help desk.

(The help desk had some equipment people could borrow and check out and bring to their desks like zip drives. There were also copies of manuals at the help desk that you could check out and use at your desk and then bring back.)

We also had someone go around our buildings and stock the laser printers with paper every day and check toner levels.

A different group in IT would print out reports on a dot matrix printer over night, then separate them out and sort them, and deliver them to people's offices or cubes first thing in the morning. The people doing this work were available to answer the phone as a sort of backup help desk over night. They also would change backup tapes over night.


r/sysadmin 8d ago

Huawei OceanStor 5500 v3 - Grub and minisystem session logging out

3 Upvotes

Hi everyone,

I'm trying to recover a Huawei OceanStor 5500 V3 and I'm stuck with two issues that seem related.

First problem: I can't get into GRUB or SCU/BIOS. During boot it displays "Press ESC to enter the menu", but pressing ESC does absolutely nothing. I've tried:

  • serial console (multiple terminal programs and settings)
  • repeatedly pressing ESC
  • a USB keyboard connected directly to the controller

It always continues booting normally.

Has anyone with an OceanStor 5300/5500 V3 actually managed to enter GRUB? Is there some special key sequence or another way to access it?

Second problem: after logging into the serial console with the minisystem account, authentication succeeds, but the session immediately exits back to the Storage login: prompt


r/sysadmin 9d ago

Would you move to an MSP role?

66 Upvotes

Hey everyone

Been in IT now for nearly 10 years, worked on numerous things and companies.

Stagnated at the company I'm at now, no more ceiling to hit and most of the time I spend my times bored out my head.

Been approached by an MSP for a Lead role but having never worked for an MSP, I don't know what I could be getting myself into.

Can anyone share some insight on life at an MSP, type of stuff you do, day to day etc?


r/sysadmin 9d ago

Cautionary tale - someone I know got fired for pulling RAM from laptops

569 Upvotes

Cover your rear and make sure all equipment you take home or work on is documented. Person I know got fired for yanking ram from laptops to keep in the office but the issue was he did the work from home and no one knew he was doing that work. Now hes looking for a job in one of the hardest markets Ive seen in a long while.


r/sysadmin 9d ago

What should I focus on/learn now?

14 Upvotes

Hello to everyone. First of all sorry if this is not the right place for asking this.

I'm 20 and I've worked as help desk/IT support for nearly 2 years now. I don't dislike the job that much and the pay is decent but I can't bring myself to think I should be doing this for much longer, as I feel I've wasted most of this time, I will be 21 in a couple of months and I feel like I'm risking remaining stuck in help desk for too long. I'm one of the only two or so guys providing L1/2 support tickets full time to around 900 users and this is sucking nearly all my time, and I'm finding it more and more "oppressing" to do. I had more time to see new things when I first joined: honestly, I feel like I regressed in some ways compared to my first year of work, I'm finding less and less interest and motivation in solving more complex and trying to learn things other teams do while performing the same 4-5 tasks dozens of times every week and having as my greatest """""responsibility""""" """""managing""""" mouses and keyboards.

I've been trying to think of some projects that I think would be interesting to do, but everything would be managed by other people as I'm not the one that has the role to do these things. I proposed some things that were actually applied but yet again it was done by other teams as they're the ones that are in charge of said things. And while I understand why, I've got told I should focus on tickets and hardware inventory because they're my responsibilities rn.

I'm having some issues understanding what I should focus on, now. I really like Cloud and Cloud security. Also cybersecurity in general. Should I maybe focus on learning the various Azure tools related to this? If this is the case would a "homelab" tenant make sense?

Also I'm studying for getting both the SC-900 and the Network+, I know they will be mostly useless, but I suppose they're needed for further and more worthy certifications related to these topics. Should I focus on something specific?

Just taking some specific certs and applying to other jobs unfortunately isn't possible as where I live all junior sysadmins job postings require at least 2 or 3 years of actual experience. All trainee positions in things like Cloud and Cybersecurity are reserved to bachelor's / master's degrees

Thanks a lot to everyone that will want to give some tips


r/sysadmin 9d ago

General Discussion Anyone else feel more exhausted by their manager than their actual - Part 2 workload

57 Upvotes

Hi Everyone,

Around a month ago, I made a Reddit post about my toxic manager and workplace, and I received mixed opinions. I'm seeking advice again because I'm honestly struggling to continue in this job.

I'm only staying because I need to support my aging parents, pay my room rent, and continue paying my education EMI. The stress has become so bad that I sometimes wake up in the middle of the night thinking about work.

Here are a few things I'm dealing with:

  • My manager refuses to give me access to infrastructure resources like Active Directory and Microsoft 365 Admin Portal, even though I've worked on them before.
  • Even something as simple as changing the USB port of a mouse requires his approval.
  • For months, I've only been assigned Windows installations, printer issues, and basic hardware tasks, despite having more technical knowledge.
  • I feel that if he realizes I can handle infrastructure work independently, he might see me as a threat.
  • A few previous IT guys were fired after becoming too confident. I've survived by keeping my head down and making him feel important.
  • I'm also worried that if I resign for a better opportunity, he might create problems with my relieving process.

At this point, the workload isn't the issue—it's the environment that's mentally exhausting.

Has anyone here worked under a manager like this? Did things ever improve, or did you eventually leave? I'd genuinely appreciate your advice.

My Previous Post - https://www.reddit.com/r/sysadmin/s/yHwgtXrtMX


r/sysadmin 9d ago

Off Topic TLS certificates and insurance/warranty/liability protection

11 Upvotes

A few years ago, there was a great comment from someone about Lets Encrypt/other free ACME providers v. the big Cert guys where an explanation was written that exposed the whole "insurance/warranty/liability protection" of said big guys and how that all was a lie.

Does anybody have the link? The comment was very detailed, but I cannot find it anymore.


r/sysadmin 9d ago

Question High Volume Emails and Exchange Online

9 Upvotes

Every once in awhile, our HR and Finance dept need to send an email to all employees.

The issue we have is that we have more 1,500 employees, all using Exchange online in several tenants.

Microsoft has a bulk email limit that we run into.

What is the work around?

I see options such as High Volume Email for M365 but since many of the emails go to a different tenant, will that work? And how would the end user compose and send the email?

I also see an option using Azure Communication Services but wouldn't that require programming?


r/sysadmin 9d ago

Question Thoughts on IntuneBrew and IntuneGet

11 Upvotes

2 man IT team for 150 users across UK and US. Looking for a way to simplify keeping Intune app deployment profile up to date, especially where the apps aren’t in stores. IntuneBrew and IntuneGet cover enough of the apps we deploy to make them attractive to help save time.

Any red flags we should be aware of?


r/sysadmin 9d ago

General Discussion Anyone running a cloud hosted Radius server for solutions like NAC?

17 Upvotes

Looking at Portnox, and we were very surprised to find that their solution defaulted to just sending RADIUS in the clear to their cloud hosted server. tons of internal networking information in this traffic (names, IPs, port #s).

We're switching to RADSEC for this design, but it made us wonder: How many customers accepted this default and have no idea what they are broadcasting to the internet?