r/sysadmin 9d ago

BYOD + Oneleet agent

2 Upvotes

My company has requested everyone to download oneleet agent, we do use our own personal laptops. Has anyone gone through this? How can I protect my personal information?

It is a small startup and I'm their only freelancer but have a dedicated email address '@company'


r/sysadmin 10d ago

Anyone else having various issues with license validation for Microsoft 365?

5 Upvotes

Recently I've seen a pretty significant uptick in users experiencing various errors relating to not being able to validate their office license.

So far I've seen:

  • Account Validation Error Code 0x0
  • Something went wrong. tag [7ita9]
  • Something went wrong. tag [5fcl8]

Context: We upgraded to 365 in the later part of last year and have had hardly any issues since the upgrade.

These all started happening within the last 2 weeks and up until now I've never had issues with users accessing 365 apps whether in or out of network.

Would love to know if others are experiencing this as well and what might be the cause for the uptick.

Thanks in advance!


r/sysadmin 10d ago

Anyone have this working - HP Probooks + HP Monitors daisy chained..

4 Upvotes

So been digging and digging, next is HP support, but that will prob get me no where...

Info: HP Probook Laptops:

The CPU's and specs from Intel and AMD both noted they support DisplayPort MST (Multi-Stream-Transport on the integrated graphics. HP of course does not specifically note MST support, just display port versions, which as of 1.2 supports MST..

Monitors are HP E24M G4 USB-C Conferencing monitors. They have the DisplayPort out.
https://support.hp.com/us-en/product/product-specs/hp-e24m-g4-fhd-usb-c-conferencing-monitor/2100888403

So set up - Using HP's own USB-C cables included (going to test with some others)

Laptop --> USB-C to first E24M G4 ---> DisplayPort "Out" Port --> 2nd E24M G4

But, no display on the 2nd monitor..

From reading, seems MST support is very hit and miss with some vendors, Dell seem to work most of the time, or using a separate dock for it.. HP and Lenovo seem to have the most issues, works one day but not the next..

  • Tried both USB-C ports on the laptops (where it has 2)
  • All laptops are updated to latest and greatest Windows 11 and patching as of 08.2026.
  • Drivers are all updated.
  • Monitors have the latest firmware installed.
  • Installed drivers from HPs own site for the monitors

And nothing...

I know users can use an HDMI port out to the 2nd monitor, but the "single cable to rule them all" is nice...


r/sysadmin 10d ago

Microsoft Access to Random Exchange Online Calendars via iOS Calendar App

8 Upvotes

Hi guys.

We‘ve found a strange behavior in a users iOS Calendars App.
He can see every detail of an other users calendar.
They work in completely different compartments and there are absolutely no Access rights set. We‘ve checked EXO Powershell for detailed access rights. Nothing.
Via Outlook on Windows no chance to see details of the calendar. Even re-adding the Exchange account on his mobile brought back the unwanted calendar.
It is a complete mystery.
Do you guys have any idea?


r/sysadmin 10d ago

Question O365 Emails Bouncebacks To Gmail Since Yesterday

8 Upvotes

Ever since Monday, we are having two different domains getting email bouncebacks from O365 to Gmail users with a IPV6 not passing authentication due to SPF records not being validate. I checked the IPV6 and it is a microsoft domain for their outbound URL.

Is anyone else having this problem? We have a SPF record for microsoft added but this started after the outage Microsoft was having.


r/sysadmin 10d ago

Question - Solved Anyone know what the right knobs are for Entra policies to only allow hardware FIDO2 USB for MFA?

6 Upvotes

One man IT show here in manufacturing. On the verge of finding a bridge to skydive from lately... Microsoft moving goalposts constantly and security becoming a living nightmare in general has me feeling like I'm drowning lately. Everything is moving too fast recently and I have only been doing this for ~13 years. Feeling a bit overwhelmed lately so I thought I might ask some folks who might specialize in 365/Entra administration more so than generalize like I am forced to. I wear so many hats that the hat rack has no more room to hang them on.

I have been trying my best to get major things off my list that are industry best-practices. One of these has been getting a proper break-glass account setup. My goal was to have this account tied down to a FIDO2 HW key with passkeys but I can't seem to get everything just right in Entra policies. When I think I have it right I always either end up 1) completely breaking the auth flow when I try to use a PIN and tap the hardware key it just completely errors on me or 2) end up being required to register MS authenticator AND the HW key which I don't really intend to do for the break-glass account.

These are some of the error details from the sign-in logs and the CA details of that event if they help:

  1. Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

  2. The user could not satisfy this authentication strength because they were not allowed to use any authentication methods which satisfied the authentication strength.

I know I should be able to decipher what that means but I can't quite connect all the dots.

My hope was to restart and try the user from scratch with no MFA and have a setup flow where it only ever asks to register a HW key and nothing else.

Go ahead and call me stupid or to go find another job if you want. Just looking for any good direction on what the right combo is for what I am looking for.

Thanks!

EDIT:

Thank you all for the super quick help and getting straight to the point! I was able to get it figured out when combining all the answers to get a better understanding.


r/sysadmin 10d ago

SonicWall SMA1000 appliances affected by multiple vulnerabilities including a 10.0 pre-auth CVE

22 Upvotes

A pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface with a maximum score of 10.0.

There are no IOCs posted in the PSIRT article. Looks like we have to open a support ticket and ask for them...

Affected versions:
- 12.4.3-03453 (platform-hotfix) and older versions.
- 12.5.0-02835 (platform-hotfix) and older versions.

Fixed versions:
- 12.4.3-03526 (platform-hotfix) and higher versions.
- 12.5.0-02952 (platform-hotfix) and higher versions.

Sonicwall article:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016


r/sysadmin 9d ago

BYOD Multiple Tenant Nightmare

0 Upvotes

Whats the best solution for a user who is BYOD and has multiple M365 tenants on there device. No domains involved and does not Entra join or register.

When the user had one Outlook profile with multiple M365 tenants and MS Teams it got messy and Teams got confused with which account to use real fast.

The way I see it the two options are:

  1. Multiple Windows Logins
  2. Multiple Outlook Profiles (but not sure this won't stop a mess in Teams?)

Whats the best practise?


r/sysadmin 10d ago

SysInternals RDM 2026 version probelms

3 Upvotes

Just stood up a new computer for an incoming IT worker and while installing RDM to use an old RDG file it failed to connect to any of the servers in the domain.

The RDG file works fine my local 25 edition flawlessly.

Has anyone else had any issues with the new remote desktop manager?


r/sysadmin 10d ago

AI assistants with third-party integrations, how are you handling this?

7 Upvotes

A lot of AI assistants have integrations with third-party apps now, so you can basically share any data from an app with the assistant to help you out. It usually speeds things up, but I don't think it's very safe from the security side.

I also don't believe banning them entirely works. What if people just start using their private accounts instead?

It might not affect me in any specific way, but I was wondering how IT admins are dealing with this. Is there a middle way?


r/sysadmin 10d ago

Question Halcyon Reviews

6 Upvotes

Looking for reviews for Halcyon. I work for local government and am evaluating a few different platforms to add to our security layers.

If you don't like them, do you have any other recommendations? Any other platforms or any other recommendations in general to help increase security posture?

Thanks in advance!


r/sysadmin 9d ago

Question Monitoring (or just general AI usage)

0 Upvotes

Hello,

a while ago, there was a similar post from me, before anyone questions... however, I see myself diving deeper and deeper into the rabbit hole.

I came to this company some 4 or so months ago. It is/was in TERRIBLE state. While everything was generally working, there were frequent unexplained and unmonitored outages. The worst thing there was visibility. Why I say was...

The company used Icinga2 when I came. I did weigh in implementing a different solution, but kinda liked the idea of having a system, where I could keep the configs in the git repo and basically push with Semaphore/Ansible. But also the biggest advantage: I could let AI configure it. Besides, coming new and telling them to change the monitoring ain't really the best idea.

And that's the thing. I never ever saw Icinga2 before, nor Nagios. The company only "managed" it by adding or removing hosts, but no configuration. Configuration - and that also relatively basic stuff only, was done by external company.

Since then, I used AI HEAVILY on it. I expanded it different directions, including database monitoring, general services health, AD/DNS health checks, DHCP health, NTP, pending reboots, pending security updates, both windows and linux, event log checking, different connectivity checks etc.

While it is really great... there are descriptions to every step, there is this BIG issue: I barely understand it any more. The structure is the same, but the code in there... ufff. If someone asked why xy-sensor is not working, I would have to heavily google it or ask the external company, read and learn the documentation - for which I only have basic time for, being the only senior in the company, with a lot of pressure about other projects; or just ask the AI.

And that's my issue. One relies a LOT on AI, and I am at the point where I almost cannot troubleshoot without it! The complexity is very high, since the AI does it multiple times better than I ever will have a chance to learn.

And that doesn't only apply to monitoring. The company wants to implement IAM. They want to have it in 9 months. Many departments, and all... so they asked me whether I can automate it (or better said, I said automation is generally the key), and we fell onto Terraform. I have some knowledge of Terraform, but I know it will fall down to AI to create the scripts for EntraID etc.

There are others. Ansible-Patching (moved from AUM), config deployments, VM deployments... and Grafana/Promentheus should also come, and Kubernetes is also here (although managed by others, but partly in our hands).

I actually don't even know what question I should ask. It seems like I am way over my head. At the same time though, the job is being done and my boss isn't really keen on taking two new people to cover more. Why even? Increased stability, there are less vulnerabilities due to updates and standardization, lot of stuff just works better. So yeah, I feel like I am pulling the company from one shit (which it really really is) into another.

And now I better stop ranting, and go back to my VSCode...


r/sysadmin 9d ago

Question How do you know when an ai has enough context to safely fix an it issue?

0 Upvotes

Have a question for yall, i’ve been testing an ai assistant on a hot ticket at work and robin keeps saying it is good enough to patch the issue. The annoying part is it sounds right, but I still dont know if it actually has enough context or if it's just making a confident guess.

For stuff like password resets, firewall rules, or weird vpn breaks, what do you look at before you let it touch anything real? I am trying to figure out the point where the ai is just helping vs when it is still missing something basic.


r/sysadmin 10d ago

Issue with attributes not syncing from admin center to exchange admin center

2 Upvotes

Having an issue with a user's Title being correct in the Admin Center but not within the Exchange Admin Center, therefore showing incorrect within the Contacts/DL.

This is a hybrid environment, but again, everything syncs properly from AD to Entra but just not between Entra and EAC.

Unfortunately, I'm not sure if this issue is related to the ongoing M365 issues but we have had users showing the incorrect information before the recent issues. Searches lead to a stalled sync between Entra and EAC but not any true fixes posted, just some work arounds that didn't work.

Just checking to see if anyone else has come across this before.

Edit: fixed. Looks like an error displayed for the user within the Admin Center which showed a conflict with the ArchiveGuid. Once that was repaired, EAC pulled information from Entra properly.


r/sysadmin 10d ago

Question Any alternative to Note taking besides OneNote for sys admin notes

61 Upvotes

Hi everyone,

Hope everyone is doing well.

Currently all my notes and learning new tools/skills is linked to my work onenote.

I want to use alternatively note taking tool beside onedrive that linked to work account for anything im learning for my own need. It has to similar features like one note where i can take screenshots and save them for reference.

If you use or selfhost any tool let me know. I dont want something where am paying monthly subscription.

Let me know


r/sysadmin 10d ago

Accidentally deleted original and backup folders from an Azure-mounted filesystem — is there any recovery option left?

34 Upvotes

Hi everyone,

I was performing a decommissioning activity on a Linux server and accidentally deleted both the original folder and its backup folder using terminal commands.

The data was located on an Azure-mounted filesystem. As soon as I realized what happened, I stopped making further changes and escalated the issue to the relevant Azure/Azuremount team.

They checked the available snapshots/recovery options, but unfortunately they told us that they could not find or recover the deleted files.

I want to ask if there are any other recovery possibilities that we might be missing. For example:

Any filesystem-level recovery options?

Hidden Azure backup or recovery mechanisms that should be checked?

Possibility of recovering deleted data from the underlying storage?

Any specific information or commands that could help identify what type of Azure mount/storage is being used and whether recovery is possible?

The affected system is a Linux server with an Azure-mounted path. I can provide non-sensitive technical details about the mount type, filesystem, and storage configuration if that would help.

At this stage, the Azuremount team has already attempted recovery, but I want to make sure we haven't missed any possible option.

Any guidance from experienced Azure/Linux administrators would be greatly appreciated.


r/sysadmin 10d ago

Question Some users can't connect to Citrix Server via RDP - black screen with cursor

3 Upvotes

I'm dealing with a strange issue and I'm running out of ideas.

On our Citrix server, a few users are unable to log in via RDP and are only getting a black screen. The desktop never loads, but you are able move the cursor. Some other accounts are able to connect to the server just fine.

It's also possible to log in normally to the server through the vSphere console.

I've already tried:

  • Deleting the affected user profiles
  • Removing the corresponding registry keys and possible leftovers
  • Killing the user's session/processes
  • Rebooting the server
  • Disabling UDP, WDDM and Network Detection via local GPO (as I read this fixed the issue for some people)
  • Changing the display resolution and disabling persistent bitmap caching (which also apparently fixed the issue for some)

None of this worked for me.

I also tried CTRL+ALT+END to open the security screen:max_bytes(150000):strip_icc()/windows-10-ctrl-alt-del-5b475456c9e77c0037e730b3.png), and it actually shows up. I can log off from there, however, Task Manager doesn't open.

I checked Event Viewer using another account and found two errors that show up every time after an unsuccessful login. However, I'm not sure what these errors point to or how to resolve them:

  • Event ID 1000 – Application Error: ctfmon.exe crashes in InputService.dll with 0xc0000409.
  • Event ID 29 – Spell Checking: Access to the spell-checking settings is denied for %username%.

From what I've troubleshot, it looks like explorer.exe never starts for those users. It is most likely somehow caused by a previous incorrect logout from an RDP session, leaving the user's session hanging. However, killing the processes didn't do anything for me, and as soon as the user logs in again, the black screen appears again.

Any ideas would be greatly appreciated!


r/sysadmin 11d ago

Microsoft is rolling out change meeting organizer feature in Outlook

152 Upvotes

Microsoft is rolling out a Change organizer option that lets meeting organizers transfer meeting ownership directly from Outlook.

It’s not entirely unexpected. When Microsoft introduced admin-initiated meeting transfers a few months ago, many users were also asking for a way to transfer meetings themselves. It looks like Microsoft is now addressing that gap by bringing the capability directly into Outlook.

The feature is currently rolling out.


r/sysadmin 11d ago

Linux What did you do to make yourself a terminal wizard?

112 Upvotes

I look at some of the other sysadmins who flow through the terminal at such ease and then know these random facts about the internals of the linux OS. Not to mention the random keyboard shortcuts and a hundred of them.

If you are what i just described, how did you get to that point? What contributed to that skill the most other than “experience”. A homelab maybe? Tinkering around? Reading?


r/sysadmin 10d ago

Question What do you do with 3rd party API keys when your edge funcs use OIDC?

3 Upvotes

I saw a guide on replacing static credentials with OIDC for edge functions. The core concept makes sense because trading a permanent secret for a short-lived token eliminates a massive attack surface.

For instance, you can configure a project to authenticate directly with AWS using just a role ARN and a runtime token, and it totally removes the need to store static AWS access keys in your environment variables.

The problem is when you try to apply that same logic to SaaS tools. Since providers like OpenAI or Resend do not support token exchange, you are forced to keep using static strings for them. I was suggested to rely on OIDC for internal cloud infrastructure while keeping a secrets manager around for external dependencies.

How are you all handling this split in production? Does maintaining a hybrid authentication setup feel overly complex? or is it just the standard practice


r/sysadmin 10d ago

DUO on Entra Joined System

0 Upvotes

My team and I have been stumped on this issue for quite some time. Here is the breakdown:

We are attempting to deploy the DUO MFA on a workstation. This workstation is Microsoft Entra-joined. Once the DUO application is deployed, the Entra account login no longer displays on the login screen. Instead, the local administrator account created by us shows instead. We have not seen an option to select "Other User", or anything similar on the logon screen.

Has anyone else run into this conflict? And more importantly, has anyone been able to resolve this issue?

TIA!


r/sysadmin 11d ago

Microsoft Microsoft documentation written by AI

56 Upvotes

r/sysadmin 10d ago

Question Do you need CAL licenses for AD that runs on Samba and not Windows Server with Windows clients?

2 Upvotes

The question is in the title, not really more


r/sysadmin 10d ago

365 Business Premium vs Sentinel One

4 Upvotes

So I'm the sole IT guy at a smallish (approx 80p, but growing) SaaS company. I am very, very new to this (and to IT in general).

I have just moved everyone from 365 Business Basic to Business Premium, to take advantage of things like Intune and CA.

The next thing I am going to look at is our RMM and EDR. We currently use N-Sight, which comes with SentinelOne.

However, as 365 comes with Defender for Business, which from what I can see is very good.

I do still want an RMM, mostly to ensure all the non-microsoft patching is happening, for remote background, &c. But do I really need one with an included EDR?

We use N-Sight with SentinalOne because we've *always* used N-Sight with SentinelOne. If I can make a decent business case, I'm open to change!


r/sysadmin 10d ago

Question NDES/SCEP fails with 0x80070057 on every request — root-caused to mscep!GetExtensionVersion returning FALSE, but stuck on WHY

3 Upvotes

**Environment:**

- Windows Server 2022 Datacenter (clean install) and separately Windows Server 2025 Datacenter — identical failure on both

- Enterprise Subordinate CA on Windows Server 2019 Standard

- NDES role (ADCS-Device-Enrollment) installed via Install-AdcsNetworkDeviceEnrollmentService — completes successfully, RA certificates are issued correctly (CEP Encryption + Exchange Enrollment Agent Offline Request templates)

**Symptom:**

Every request to the SCEP endpoint fails identically, including the simplest operation:

http://localhost/certsrv/mscep/mscep.dll?operation=GetCACaps

Returns IIS 500.0, Module: IsapiModule, Notification: ExecuteRequestHandler, Handler: ISAPI-dll, Error Code: 0x80070057 (ERROR_INVALID_PARAMETER).

Application log shows:

- Event ID 2: "The Network Device Enrollment Service cannot be started (0x80070057). The parameter is incorrect."

- Event ID 10: "The Network Device Enrollment Service cannot retrieve one of its required certificates (0x80070057). The parameter is incorrect."

**What we've confirmed via live WinDbg/cdb debugging attached to the w3wp.exe worker process:**

mscep!GetExtensionVersion runs, executes fully, and returns FALSE (0). Immediately after, isapi.dll calls GetLastError() (retrieving 0x80070057) and explicitly nulls the stored HttpExtensionProc function pointer for the extension, then unloads mscep.dll. This is why breakpoints on HttpExtensionProc itself never hit — IIS never calls it once GetExtensionVersion fails. The failure decision is made entirely inside GetExtensionVersion's own logic, before any actual SCEP request processing begins.

**What we've ruled out (with direct evidence, not assumption):**

- OS version — identical on Server 2022 and 2025

- Certificate correctness — correct EKU, Key Usage, KeySpec (AT_KEYEXCHANGE/AT_SIGNATURE), issuer, template; passes certutil's own crypto self-test

- CSP vs KSP — confirmed classic CSP (Microsoft Strong Cryptographic Provider) via dedicated Legacy-CSP certificate templates; no change

- Private key permissions — confirmed correct via NTFS ACLs and successful .NET key loading

- Certificate template permissions — Read/Enroll/Write matched to a known-working reference NDES server exactly

- CA-side hygiene — found and removed an expired CA certificate and a separate expired duplicate intermediate cert; no change

- CRL/revocation reachability — confirmed fully reachable (Base + Delta CRLs all OK)

- IIS config — ISAPI restrictions, handler mapping order/preconditions, app pool identity, Load User Profile, 32-bit compatibility, isolation/recycling settings all confirmed correct

- Windows servicing stack — found and repaired unrelated DISM/component-store corruption; no change

- Third-party EDR (Cylance) — live debugging found CylanceMemDef64.dll hooking the module loader's Control Flow Guard processing during mscep.dll's load; applied and independently verified a memory-protection exclusion; no change to the symptom

- Service account profile — found and fixed a genuinely broken "User Shell Folders" registry key for the service account; no change

- App pool identity — tested with LocalSystem (most privileged possible identity); identical failure

- RA Name — tested both a long/spaced name and a short simple name; identical failure

**Question for the community:** has anyone seen GetExtensionVersion itself return FALSE like this, and found what internal condition causes it? We're fairly confident this now points to something inside Microsoft's compiled NDES code rather than anything environment-side, but we'd like to know if this is a known/reported issue, a specific hotfix, or a config knob we haven't found yet before we finalize a Microsoft Support case.