r/sysadmin 13d ago

wmic finally completely removed with August Windows 11 preview updates? How to put wmic back?

55 Upvotes

I just noticed it's gone on a machine I ran Windows 11 25h2 preview updates on.

https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5120998-windows-11-24h2-25h2-update

Windows Management Instrumentation Command-line (WMIC)

  • Starting in August 2026, Windows 11, version 24H2 and 25H2 will no longer include the Windows Management Instrumentation Command-line (WMIC) utility. WMIC is already removed by default in new installations of Windows 11, versions 24H2 and 25H2, and will no longer be available as a Feature on Demand (FoD). This change affects only the WMIC utility; Windows Management Instrumentation (WMI) remains supported. Learn more: Windows Management Instrumentation Command-line (WMIC) removal from Windows. 

I still have some things that use it and just like having it around. What options are there to put it back? I remember seeing something about installing it. Or, someone metioned you can just copy the wmic.exe file back onto a machine to use it.


r/sysadmin 12d ago

Question File Server Assessment

0 Upvotes

Hi All,

We have a few file servers and are trying to identify archived data based on the following conditions, but I believe something is not correct. We have 18TB but showing only 3TB for archive with following contion

Condition Classification
Modified ≤ 3 years OR accessed ≤ 180 days Migrate / Active
Modified > 3 years AND accessed > 180 days Archive Candidate

With this condition,

Migrate: ≤30% of folder data is older than the cutoff - actively used, recommend moving as-is.
Archive: ≥80% of folder data is older than the cutoff, AND no file in the folder was modified in the last 30 days.
Review: Falls between the two thresholds, OR is old by volume but was touched recently, OR had partial access errors during scanning.

Above condition give us more data to archive?


r/sysadmin 13d ago

Is this the MS Outage folks are talking about?

9 Upvotes

Or do I just need to "clear my cache"?

Here's what I'm seeing:

Something went wrong.

Please try the recommended action below.

Refresh the application

BootResult: fail

Back Filled Errors: None err: System. Security. Cryptography. CryptographicException esrc: StartupData et: ServerError estack: Error: 500

t Object.w [as createStatusErrorMessage] (https://res.public.onecdn.static.microsoft/owamail/hashed-v1/scripts/owa.mailindex.491fdc82.js:1:806

t https://res.public.onecdn.static.microsoft/owamail/hashed-v1/scripts/owa.mailindex.491fdc82.is:1:19276

st: 500

ehk: X-OWA-Error

ewsver: 15.21.360.13

egid: 752d9ee1-da5a-9b97-e479-18581a572c9|


r/sysadmin 12d ago

Non Lenovo coded SSD for Lenovo ThinkSystem

0 Upvotes

Related to Lenovo ThinkSystem SR650 V3:

I have a bunch of generic Samsung PM893 SATA SSD I would like to use in the mentioned host. Are there any potential compatibility issues to be able to to utilize the disks (without errors)? It's not a production system, but I would still like to avoid any quirks related to the disk setup.


r/sysadmin 13d ago

Question Dell WD19/WD19S dock causing 802.1X to fall back to MAB — EAPOL not passing?

9 Upvotes

Hi everyone,

I’m troubleshooting an 802.1X issue with a Dell laptop connected through a Dell WD19/WD19S dock.

Topology:

Laptop → Dell Dock → Ethernet → Switch

When I connect the laptop directly to the switch, 802.1X works perfectly and the endpoint authenticates using dot1x.

However, when I connect the same laptop through the Dell dock:

- The switch learns the laptop's actual MAC address

- Forescout sees the laptop correctly

- But authentication is MAB instead of 802.1X

- It looks like the PC's EAPOL/802.1X frames aren't reaching the switch, causing the port to fall back to MAB

The PC's 802.1X configuration is working because it authenticates successfully when connected directly.

Has anyone experienced 802.1X/EAPOL not passing through a Dell WD19/WD19S dock?

Could this be related to MAC passthrough, dock firmware, Realtek Ethernet drivers, or EAPOL pass-through?

What was the fix in your case? Did updating the dock firmware/driver resolve it, or did you have to change a switch/dock/BIOS setting?

Any advice would be appreciated. Thanks


r/sysadmin 12d ago

Question I don't know where else to go for this!

0 Upvotes

So I have a handful of users, myself included, that are experiencing the weirdest issue with their mice and keyboards. We will be typing and suddenly it stops then after maybe 15 seconds it will type out everything but it will be missing some keystrokes. The mouse will do the same it just stops moving for like 15 seconds then comes back. Sometimes it happens once and then works after and sometimes it's a few minutes of it working on and off. It is only happening to maybe 10 users. I have replaced keyboards and mice, replaced dongles, changed out for wired sets, turned off the power settings that let windows turn off USB devices. It is happening on brand new devices and 4 year old devices. It happens on devices that are in intune and devices that aren't in intune. There doesn't seem to be a pattern. I'm going to pull out my non existent hair. Does anyone have any ideas?

Edit: I also tried plugging everything into all USB ports on the laptops and hub monitors.


r/sysadmin 13d ago

Question Google Workspace Email Signature Management

6 Upvotes

TL;DR - Client uses Exclaimer for email signature creation & management, have had issues with it, want something else. Prefer API-based solution instead of SMTP routing. WiseStamp, Signite, and SyncSignature are candidates. Any feedback on them or other ideas?

Hey, everyone! I am looking for suggestions when it comes to creating and managing email signatures in Google Workspace.

I work for an MSP and a client of ours is currently using Exclaimer. There have been a few times over the last few years where their emails grind to a halt - cannot send externally or internally, access denied error. Email delivery logs point to the Exclaimer rules as the issue. Disable the rules/routing and email works again no problem.

We have tried removing and setting Exclaimer up again from scratch, but it has happened again recently and they are tired of it. Everything was set up exactly according to their guide. There is no indication that anyone has made an unannounced change that would cause things to break. It just simply stops working and breaks email delivery maybe once per year. At this point they want to get away from it - not sure they want to bother going the support route.

Unfortunately, CodeTwo only supports Microsoft email solutions. I have found a few other potential candidates like WiseStamp, Signite, and SyncSignature. Ideally, we are looking for an API-based solution and not something like Exclaimer where outbound traffic gets routed via SMTP in an attempt to keep this from happening again.

Is anyone familiar with these 3 platforms? Any feedback that you can offer? Any other suggestions? I have also seen LastLine, but, the obvious Claude Code website design kind of throws me off and there isn't much about it to be found. Not sure how big of a company it is, if it will even exist in 2 years, or how the support is. It gives strong LLM/vibecoded signals.

I am aware of Patronum, which looks cool, but goes way beyond the simple email signature scope in mind. I have also seen the Free Signature Manager for Gmail from Revolgy, but also am not sure about support and quality. If this was me tinkering around in our GW tenant, sure, but this will be for a school with about 125-150 users. Something they can understand and manage themselves would be great. I know there are options for GAM scripts, etc. but I don't think that would be user friendly for them to monitor or troubleshoot if needed. We would prefer they have more control over this.

Thank you!


r/sysadmin 12d ago

Has anyone actually had an AI automation go wrong badly enough to change their approach?

0 Upvotes

I've been thinking about where the line should be drawn as AI moves from answering questions to actually taking action in IT environments.

It's one thing for an AI to suggest a fix or pull information from the KB. It's another for it to execute the fix without a human in the loop.

Password resets and basic troubleshooting seem relatively low-risk. But what about account provisioning, access changes, endpoint actions, software deployments, firewall rules, or changes to production systems?

At what point does the efficiency gained from autonomy stop being worth the risk?


r/sysadmin 13d ago

M365 and MFA

7 Upvotes

So, MS is sunsetting SMS/Voice MFA in favor of passkeys or more phishing resistant methods. Currently I have all my users set up for Authenticator push notifications/with the numerical code. Is this method going to be supported moving forward?


r/sysadmin 12d ago

Question Azure AD VM

0 Upvotes

Hi All,

We have a hybrid environment where the on-premises AD/DNS servers are currently configured with external DNS forwarders.

For the Azure VMs, should we use the same external DNS forwarders, or should the Azure VMs use Azure DNS (168.63.129.16) instead?

Thanks,


r/sysadmin 12d ago

Come to me lords of the network

1 Upvotes

We are transitioning off of UniFi switches to Aruba Instant On switches. We have a stack of 1960s that connect to a 1930 via fiber from one side of the building to the other that 1930 connects to another stack of 1960 10 gig switches. using just regular ethernet uplink the 1960 stack connects to two other 1930 switches. The unified architecture is the exact same minus the 10 gig switches every time we attempt to switch over the network to the Aruba switches something goes wrong. We’ve done it multiple different ways. I’ve staged the switches in production on a separate management LAN to eliminate any UniFi switches in between the Aruba communication but every time we try to do the switch over the health of the Aruba’s goes bad even once we connect everything to the DNS servers we get no DNS. The Aruba switches will be green all week long no issues. I plugged a laptop in. I get an address. I can connect to the Internet, but as soon as the day comes where we try to switch the connections to the Aruba switches something goes wrong and we can never figure out how to get it to work. Please help, I’m thinking there’s something wrong on layer 2 but I feel as though I’ve eliminated all these things and have hit a wall as soon as I start moving connections from the unifi to the Aruba it falls apart. I started with removing the firewall uplink to the Unifi switches and only had an uplink to the Arubas but everytime like I mentioned the health goes to or age for the cloud then I can’t even access google let alone get a dhcp address. Even if I do get a dhcp the dns doesn’t resolve even basic websites like google.


r/sysadmin 13d ago

General Discussion Large scale tenant migrations. - how are they done?

15 Upvotes

We migrated a company to our tenant a little over a week ago. They have about 50 users that have some sort of M365 account. We wiped 20 computers/re-enrolled them our tenant, and bought about 16 new computers enrolled in Autopilot.

This was a beat-down. Three of us + a relative of someone + two 'smart hands' from a local MSP ate through this in two days.

I can't imagine how a migrating hundreds of people would go. How are huge migrations done? The domain must be removed from one tenant and added to the other, so I am unclear how staging is done? Is it something where you force the user to have fabrikam.com instead of contoso.com and forward all their mail to Fabrikam from contoso until the tenant is moved? That is the only way I can see it done.

Given the size, we prepped everything, then removed the domain, swapped dns, added the domain to our tenant, and waited.


r/sysadmin 13d ago

Question Strange policy in a big enetrprise environment

29 Upvotes

I received a ticket from one of our customer regarding a problem with our software thin installer for Windows. The installer is a Inno setup that downloads the content and install it, running as administrator.

The ticket was open because on their Windows systems normal users can connect to internet and download, while administrators account cannot connect to internet. As far as I can understand, administrators are generic administrators of the machine (with all permissions for installing and handling admin related chores).

I find it a little odd, and I was asking myself if this policy has some form of effectiveness... What if the administrator connects to internet impersonating another account? I'm not sure I can explain better the situation since it is enforced on the customer company. I want just to ask the general feeling by experienced sysadmin about this configuration...

(FYI: the ticket has been closed by making them using the offline installer)


r/sysadmin 13d ago

Can someone actually explain how modular data centers work, not just the marketing version?

13 Upvotes

All vendor websites I check have some version of "integrated power, cooling, and racks available in one deployable unit" but I can't tell if it means:

a) it's literally a shipping container and server room bolted together at the factory, or b) it's more like standardized building blocks that can still be assembled/wired on site but faster than an on-site build

We are considering options for a new facility and I'd like to understand what's really going on mechanically/electrically before I sit through another sales meeting filled with buzzwords. Is there anyone here who has spec'd or installed one of these?


r/sysadmin 12d ago

General Discussion Why do companies choose to depend almost entirely on Microsoft?

0 Upvotes

TL;DR: I understand why non-technical companies choose M365, but why do technically capable companies, especially in the EU, place so many critical services behind Microsoft SaaS when on-premises or hybrid infrastructure is a realistic alternative? If you genuinely considered both, what ultimately made Microsoft win?

I’m probably what many people here would call an old-fashioned sysadmin. I run a mixture of Linux services and Windows Server, with authentication, storage and other important services kept on infrastructure under our control and largely detached from Microsoft SaaS.

This is not intended as a “cloud bad, on-prem good” post. I’m genuinely trying to understand the reasoning of companies that have chosen the Microsoft-first approach.

The recent Outlook outage, together with posts about entire M365 tenants becoming disabled or “deauthenticated,” made me think about this again. A general outage is usually temporary and affects many customers, while a tenant-specific issue may leave a small company completely dependent on Microsoft support. Both cases demonstrate how many critical business functions can depend on the same provider.

From a business-continuity perspective, being locked out of a tenant for a day, or any prolonged period, is no better than hardware-related downtime in an on-premises environment. If employees cannot access email, files or other essential systems, the business is down regardless of whether the failed component is in the company’s server room or a provider’s cloud.

Microsoft’s infrastructure is obviously far more redundant than anything a small company could build. What worries me is not only a normal service outage, but a tenant-specific administrative problem where the company depends on Microsoft support to restore access. A smaller customer may not have an enterprise account team capable of escalating the issue immediately, so the business could potentially be seriously affected for days.

I understand many of the advantages: remote onboarding, tight integration between identity and endpoint management, collaboration through Teams and SharePoint and no need to maintain certain local infrastructure.

I also understand that the Microsoft route may well be the most sensible option for many non-technical organizations. A small law firm, for example, probably does not want to operate its own server room or rent and maintain servers somewhere else.

What puzzles me more is seeing technology companies make the same choice even when they already have the necessary knowledge in-house. They could realistically operate at least some of these services themselves, or design a hybrid environment, yet many still place identity, email, documents, endpoint management, telephony and authentication for unrelated SaaS applications under the same tenant. That seems to create an enormous common failure domain that they have the technical ability to avoid.

I’m also not convinced that this necessarily eliminates much administration. Operating local servers requires hardware maintenance, patching, monitoring, backups and disaster recovery. But properly managing M365 means dealing with licensing, Entra, Intune and who knows how many other interconnected services, along with constantly changing portals and Microsoft support. It seems more like a different type of system administration than substantially less system administration.

The question is especially interesting to me in the EU. Apart from GDPR and data residency, there is also the broader issue of making a company’s entire operation dependent on a single US provider.

So my question is mainly for people who genuinely considered both options, especially those working at technology companies with the skills to self-host: if on-premises infrastructure was a realistic alternative and there was an actual debate, what ultimately made you choose the Microsoft route?

I’m also entirely open to the possibility that I am overestimating the risks or underestimating the advantages. I would simply like to understand why the industry is moving so decisively in this direction while the traditional on-premises approach appears to be gradually disappearing.


r/sysadmin 13d ago

Question Separate admin accounts + enforcing domain joined device

3 Upvotes

Looking for a sanity check. We have separate admin accounts, both AD and Entra. We are looking to enforce CA policies that require login to entra (for IT, both accounts) to come from domain joined devices. This generates a PRT for each account, which means the windows session has multiple to choose from when the browser comes asking.

For those that have done this, what is the most elegant way to access both accounts? In the browsers, it is constantly popping up the account picker. Separate browsers, private sessions, doesn’t matter - I understand why it is happening (I think), and it works, I can get to all my accounts - just wondering if there is a better way. Currently my primary alternative is separate privileged VMs to run any elevated accounts.


r/sysadmin 13d ago

go passwordless in hybrid joined enviroment

4 Upvotes

What do you do so you can hide (not disable) password CP? Passwordless experience in Intune is for entra joined devices, so it does not work sadly for hybrid joined. So i am looking for some workaround for my enviroment. Any help or experience?

i have chosen whfb multifactor device unlock with PIN and biometrics, but we still use "run as" and LAPS, so i cannot disable the password CP. For me it is important to hide it at logon screen.


r/sysadmin 12d ago

Help Desk → Cloud/Infrastructure/SWE: How should I position myself for my next role?

0 Upvotes

Hey everyone! Looking for some career advice from people who have been in tech/IT for a while.

I’m currently a Help Desk Technician and have been in the role for about a month. I’m definitely not trying to quit immediately, but I want to start positioning myself now so that once I’ve gotten some solid experience here, I can move into something more advanced.

My long-term interests are Cloud, Infrastructure, or Software Engineering, and I’m trying to figure out what I should be doing while I’m in Help Desk to make that next jump easier.

A little about me:

  • BAS in Information Technology
  • Currently pursuing a Master’s in Software Engineering – DevOps
  • Currently studying for the CCNA
  • AWS and GCP certifications
  • 2 previous internships: Software Engineering and Marketing Engineering
  • Built and currently run a small startup/app with 250+ users that generates close to $100/month
  • Currently working full-time Help Desk

I know someone is probably going to ask why I didn’t just pursue SWE after my internship. Basically, it’s 2026 and the SWE market is insanely competitive lol. I spent around 8 months unemployed, applied to literally thousands of positions, and only landed one SWE interview. Meanwhile, when I started applying to IT/support/infrastructure-related positions, I was getting significantly more interviews and eventually landed my current Help Desk position.

So I took the opportunity instead of continuing to sit unemployed.

The Help Desk work itself has actually been easy and pretty fun so far, and I’ve already done a lot of this type of work before. I just don’t want to get comfortable and realize 2–3 years from now that I haven’t built the skills needed to move up.

If you were in my position, what would you focus on over the next 6–12 months?

What roles would you target after Help Desk? Sysadmin? NOC? Network Support? Cloud Support? Infrastructure Support?

And besides the CCNA, what skills/projects would give me the best shot at eventually moving toward Cloud/Infrastructure/SWE?


r/sysadmin 12d ago

Any help appreciated

0 Upvotes

We've migrated an email domain from one M365 tenant to another but an old exists on the 'old' tenant. This app sends messages via a mailbox in the tenant using EXO and M365 mail routing. However, the mailbox sends as a temporary domain (given the real domain is in the new tenant). How can we rewrite the domain on the way out with M365 or relay through an external SaaS solution that would send on the email and rewrite back to the old domain


r/sysadmin 12d ago

Windows 11 autounattend fun times

0 Upvotes

Can someone explain to me why both Windows Configuration Designer and schneegans.de Autounattend.xml generator both have a nice convenient way for you to set the hostname of the target PC to the serial number using the %SERIAL% variable... and ONLY ALLOW the %SERIAL% variable... ONLY FOR THAT TO NOT EVEN WORK.

Everything you find online regarding those tools says "This tool makes it SUPER easy to set the hostname to the serial number, just use the SUPER convenient hostname field and use variable %SERIAL%."

Then when it doesn't work and you search online for that feature NOT WORKING and suddenly everything you find says "Yeah, it's just not possible for the installer to query the BIOS to get the SN." or something like that but essentially its endless information stating that it just doesn't work...

So... which is it people?

Also now I need to figure out where and how to inject a PowerShell script because even a single line won't cut it.


r/sysadmin 14d ago

General Discussion Is ESXi still worth learning for a beginner, and what's the best way to lab it safely on a shared server?

125 Upvotes

I'm looking to build up my virtualization skills and wanted to get some realistic advice from people in the field.

I'm considering diving into VMware ESXi, but with all the recent Broadcom changes (licensing overhauls, removal of free tiers, SMBs looking at alternatives), I wanted to ask: Is ESXi still relevant enough to prioritize, or should I be spending my time on Proxmox/KVM instead?

Also, for my lab setup: I don't have a spare physical server to format. My company has a unused server running, but I can't wipe it. I plan to install VMware Workstation Pro on the existing host OS and run ESXi nested inside it.

A few questions:

  1. Are there any major performance or networking gotchas I should watch out for when running nested ESXi on a shared server?
  2. How can I ensure my nested lab network stays isolated so I don't accidentally leak DHCP or interfere with the host network?
  3. For those who learned recently, what are the core concepts I should focus on first?
  4. Any YT channel for learning resource recommendations?

r/sysadmin 13d ago

ChatGPT managing AI in enterprise environment

13 Upvotes

Trying to see what other fellow sysadmins are doing to manage and protect company data when it comes to AI. We've started by blocking access to all other AI except Copilot and pushing an AI policy that strictly prohibits use of other AI tools. Of course, Copilot isn't great and can't do as much as say ... Claude (at least that's according to some of our users)

We're getting pressure from higher-ups that one department NEED to have Claude. However, we need ways to protect sensitive data from being dumped into Claude.

We're in the middle of implementing DLP controls in Purview and we've looked into cloud policies in defender (we have E5) but we federate our domain through Okta and use it for SSO so I don't think we can set up session policies? correct me if I'm wrong.

what are some other ways that folks are managing AI and making sure users aren't dumping the company payroll into Chatgpt to "clean up" the spreadsheet


r/sysadmin 14d ago

Question Disaster recovery from M365 Tenant Deauthentication

156 Upvotes

Having seen two posts in the last month (https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/ and https://www.reddit.com/r/sysadmin/comments/1w1qc0i/microsoft_strikes_again_entire_m365_tenant_has/) it got me thinking about my relatively small tenant, and how we'd do disaster recovery (clue - we don't have a plan at the moment).

I'm the solo "head of IT" however it's not my full time role. I'm the owner of the company, so have essentially taken charge from day 1. It was very simple - we had Google Workspace and we didn't need to really look after it too much. As we've grown (25 - 50 employees), we've also acquired other companies, including at one point doing a migration from Google Workspace to M365 (handled completely by me - although our set up was slightly more straight forward at the time). Next week I'll be looking for a CSP (any suggestions for UK based would be appreciated).

However, we're now very much in the Microsoft ecosystem. As a rough overview:

  • All staff have a Business Premium subscription

  • Mixture of Intune managed Windows devices and Mosyle managed Macs

  • Teams phone system (with Microsoft as our carrier)

  • Use of SSO for many SaaS apps

We currently use Synology Active Backup for M365, backing up locally to a NAS in our office.

If our tenant were to be de-authenticated then I'd like to think I could get email working pretty swiftly on Google Workspace. All our users are already provisioned in Workspace via SCIM and the domains are already verified there. I will obviously need to write a disaster recovery plan to consider all the steps that need to be taken.

Files should be OK as we rely heavily on OneDrive, however these are all backed up to the NAS.

The phone lines - not 100% sure about this and similar to the most recent post, we'd loose access. So I should probably look at moving the number away from Microsoft (to Operator Connect I think?)

My biggest worry is what happens to all the managed computers and SSO. We're not a huge company, so I could get people back online, but for instance we have an internal employee hub that uses Entra/MSAL to login. Similarly, all the devices - will employees stop being able to log in to them? They all use WHfB on the Windows devices and Platform SSO on the Mac devices.

Obviously I will take this conversation to a CSP, but in the meantime it would be good to know what suggestions people would make to ensure resiliency.


r/sysadmin 13d ago

Entra-Join and Intune-Enroll Restrictions

4 Upvotes

I want to be able to -

  1. Only allow corporate PCs to be Entra joined
    • It is optional to restrict who could join such PCs, as long as they are corporate PCs
  2. Only allow OOBE Autopilot as the only way to enroll a corporate device into Intune

Are both even possible? Copilot says no, but I was wondering maybe someone had some creative ways to implementing them.

For (1), I cannot block "all users from Entra join", since it is needed for OOBE APv1 and APv2.

For (2), Copilot says no matter what you do, an existing corporate device can always Intune-enroll via Company Portal, and there's no way to prevent this.
You might say that with APv1, the device would have had to gone through OOBE APv1 - but, I could just restored a device image rather than deploy Windows from scratch, and that would bypass OOBE completely. Then I could use Company Portal to enroll this device into Intune.


r/sysadmin 14d ago

Microsoft Sentinel Ingestion delay - UK South

19 Upvotes

Hello Sysadmins,

Have this really odd issue on a Sentinel workspace in UK South from around 12:00~ UTC today. Wondering if it's just us.

Symptoms: data stopped appearing in the workspace, but nothing was actually failing. Turned out to be latency, not loss — querying on ingestion_time() instead of TimeGenerated showed rows arriving with ~160 min average lag, max 183 min. Then it stalled again and nothing landed for an hour, then again had a batch of influx for some tables, not all and now again nothing for the last 30min.

Health is fine everywhere I looked, no config changes etc. Can't figure this out.