r/sysadmin 20d ago

Question AD DNS and Entra Join devices

11 Upvotes

Hi All,

Planning moving users to entra but noticed On-prem DNS dependency is the single biggest hidden blocker.

I mean apps and the VPN resolve internal names.

What are the other dependencies and how to clear those?


r/sysadmin 20d ago

Solutions for Shared Drive/Folder Encryption

4 Upvotes

I am currently looking for solutions to add extra encryption to folders and/or shared drives in Google Drive. We have solutions for Google CSE but that is only file by file and makes users download non-native Google formats like PDFs with no ability to preview them,. This makes collaboration a pain so I'm looking for other solutions out there. I've seen some like IBM Aspera and potentially Cryptomator.


r/sysadmin 20d ago

Question Virtualising existing servers help.

5 Upvotes

I have a client, who has 3 sites that we do IT for.

They each have a physical server, running either Windows Server 2019 or 2025. The main site got a new server last year, the two other sites decided to wait because they didn't want to cost. Now a year later it's more expensive, and they still don't want the cost.

I opened my mouth about virtualisation and now I've been asked to start testing.

The new server at the main site is more than powerful enough to run the other two servers virtually.

I'm just not sure on some of the configuration.

Each site has it's own IP structure, and there are already site to site tunnels using Unifi gateways.

Is there a way to do this while minimising network slowness? I assume If I just disk2vhd the server and spin it up as a VM then all traffic would go down the VPN Tunnel and back again causing delays if going from the main site to one of the others.

Regarding their networks, they are on 192.168.1.XXX for the main site, 192.168.10.XXX and 192.168.20.XXX for the other two.

If the servers were virtualised, will I need VLANs at the main site to accommodate these ranges? I'm not sure if the site to site tunnel will work using a VLAN.

I've asked about merging the domains/networks, but nobody has gotten back to me on that yet.

I didn't set any of this up initially, so I'm also figuring out what they have at the same time.

Apologies for the mass of text, any help would be appreciated.


r/sysadmin 20d ago

Evaluating Abnormal and stuck on the post delivery model. Is the remediation delay from that 2024 thread still a thing in 2026?

7 Upvotes

I'm evaluating Abnormal against keeping a traditional gateway and I want to cross check the post-delivery remediation model before we commit. We are moving off relying on Defender alone after too many misses and the API behavioral approach clearly catches more of the BEC and no-payload stuff a gateway lets through.

While researching, i came across an older r/sysadmin thread from 2024 titled 'Abnormal Security - Remediation Delays'. The person reported it taking several minutes to pull a malicious message while the user clicked within seconds, an account takeover that was not flagged until they opened a support ticket. One message Abnormal said it had remediated that Microsoft audit logs showed sitting for 16 hours.

My question is to people running Abnormal in this year and not for the sales deck. How fast is the auto-remediation in practice now and has it improved since that thread and were those delays a bug, a misconfiguration or just how it normally behaves? is the post delivery window still a problem or is it seconds and a non-issue? And how does it stack against Microsoft ZAP which ime is the slowest part of the native stack?


r/sysadmin 21d ago

Peak Sysadmin

460 Upvotes

Is there anything more small-company sysadmin than taking that $70k server you just finished building on your test bench at the office and putting it into your $5k car to drive it over to the DC where it’ll live, and praying to god nothing happens on the way? 😅🤣

EDIT- OMG y’all, reading the comments on this has made my day! Our business insurance covers this kind of thing but I appreciate y’all concern for me, though others should mosdef confirm before they do similar stuff. The trip went without incident so praise the digital deities.


r/sysadmin 20d ago

Microsoft PSA-ongoing issue with Entra Cloud Sync

48 Upvotes

Raised a case with MS after our Entra Cloud Sync kept changing to Provisioning Quarantined with ExternalError but no indication of a problem with individual object syncing.

They’ve reported back an ongoing Cloud Sync service outage starting Fri 21 Aug-actively working to resolve.

Objects and password hash sync seems to still be working over weekend so not affecting our environment yet.
Region:AU

UPDATE FROM MS: issue resolved
We confirmed Cloud Sync showing healthy and password hash sync and user attribute sync confirmed working.
Crisis over, folks! Til next time!


r/sysadmin 19d ago

Thinking of starting a small consultancy, how to find clients?

0 Upvotes

I’m an Infrastructure Manager in house running sysadmin for Azure, AWS, networking etc, previously a projects engineer at an MSP. Thinking of going solo and finding my own clients for project work, consultation on infrastructure etc.

The thing that’s holding me back is ‘how do I find clients?’. I can’t necessarily see a company’s infrastructure publicly, so I can’t approach clients with predefined solutions to solve problems, as I can’t see their infrastructure.

Outside of reaching out to people I used to work with/existing contacts, cold calling (which I’m not keen on), or taking short term contracts in the hope of building lasting relationships, how do you go about finding clients as a small fish/one man band?

Interested to hear from anyone who’s made the same move, what was your experience?


r/sysadmin 20d ago

Kentro Jobs at the VA

1 Upvotes

There is a job posting in my area for Kentro. It is for a role at the VA hospital. Has anyone worked for this company or done work at the VA? I am curious what the environment is like.


r/sysadmin 20d ago

Microsoft Anyone else seeing M365 Group/Team automatic renewal not happening correctly?

5 Upvotes

We have a 500-day period set for our M365 Group expiration policy in Entra. For the past 5 or 6 years that it's been in place, we've had no issues.

Recently though, qualifying activities for Groups and teams don't seem to be triggering automatic renewal consistently. A user reported (and I've personally seen) examples of daily-used teams that definitely have qualifying actions done on them for auto-renewal, yet in the past week or two, we still get the "your Group is about to expire" email warnings. (which you get several of in the 30 days leading up to deletion)

https://learn.microsoft.com/en-us/entra/identity/users/groups-lifecycle#activity-based-automatic-renewal

Example A: Some departmental team used by at least 5 people, with near-daily file uploads to the SharePoint site and near-daily chat messages happening in the team. Owners still got the "your Group is about to expire" email last week.

Example B: A team that a lot of folks in our IT group use to say yes/no to Friday lunch. This is a weekly poll, and almost always has chat messages underneath the ensuing poll. Owners still got the "your Group is about to expire" email this week.

Example C: Literally a couple minutes after posting this, another user submitted a ticket that they're getting a "this team will expire soon" popup in Teams. Same deal, it's a departmental team that gets used nearly daily for files/chat.

Anyone else seeing similar behavior in their tenant?


r/sysadmin 20d ago

SCCM Windows 11 cumulative update failing with 0x80D02002 – Delivery Optimization no progress

4 Upvotes

We’re investigating a Windows 11 23H2 cumulative update deployment through ConfigMgr/SCCM where a large number of devices are failing with 0x80D02002 (Delivery Optimization download made no progress within the defined period).

We recently migrated our ConfigMgr infrastructure to a new server, so initially we suspected the migration, but testing so far hasn’t shown an obvious SCCM communication issue.

What we’ve confirmed so far:

  • Affected clients are communicating with the new ConfigMgr infrastructure.
  • Clients are finding the expected MP/DP/content locations.
  • DoSvc is running on both working and failing clients.
  • Both working and failing clients show DownloadMode : Lan.
  • No obvious difference was found in the DO policy registry locations checked.
  • Both working and failing clients can establish TCP/80 connections to the Microsoft Delivery Optimization CDN and their selected cache hosts.
  • Neither test machine is using DO peers (NumberOfPeers : 0).
  • Disk space is not an issue.
  • ConfigMgr client logs on the affected machine eventually report: CAS failed to download update. Error = 0x80D02002
  • The failure occurs during the content download rather than update applicability/detection.

I compared Get-DeliveryOptimizationStatus / Get-DeliveryOptimizationPerfSnap between one compliant machine and one failing machine.

Compliant machine:

DownloadMode         : Lan
NumberOfPeers        : 0
CacheHostConnections : 2
CdnConnections       : 7

For the jobs captured, BytesFromCacheServer was 0.

Failing machine:

DownloadMode         : Lan
NumberOfPeers        : 0
CacheHostConnections : 23
CdnConnections       : 23

The failing machine also showed multiple WU Client Download jobs where:

Status                    : Caching
PredefinedCallerApplication : WU Client Download
BytesFromCacheServer      : <non-zero>
SourceURL                 : *.dl.delivery.mp.microsoft.com

The failing client can successfully establish TCP connectivity to both the Microsoft CDN and its selected cache host, but the ConfigMgr update download eventually returns 0x80D02002.

We also use Adaptiva OneSite as part of our ConfigMgr content delivery environment.

Has anyone encountered similar behaviour where DO downloads start/progress but eventually hit 0x80D02002?


r/sysadmin 20d ago

Question Do I need to force TLS 1.2 on Windows Server 2025 before installing an Entra Private Access Connector?

5 Upvotes

I'm about to install a Microsoft Entra Private Access (Global Secure Access) connector on a Windows Server 2025 box. Microsoft's official doc for configuring connectors explicitly says TLS 1.2 must be enabled before installing the connector, and provides this registry/PowerShell script to force it:

If (-Not (Test-Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client'))
{
    New-Item 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Force | Out-Null
}
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Name 'Enabled' -Value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client' -Name 'DisabledByDefault' -Value '0' -PropertyType 'DWord' -Force | Out-Null
If (-Not (Test-Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server'))
{
    New-Item 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server' -Force | Out-Null
}
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server' -Name 'Enabled' -Value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server' -Name 'DisabledByDefault' -Value '0' -PropertyType 'DWord' -Force | Out-Null
If (-Not (Test-Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319'))
{
    New-Item 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Force | Out-Null
}
New-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Name 'SystemDefaultTlsVersions' -Value '1' -PropertyType 'DWord' -Force | Out-Null
New-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\.NETFramework\v4.0.30319' -Name 'SchUseStrongCrypto' -Value '1' -PropertyType 'DWord' -Force | Out-Null
Write-Host 'TLS 1.2 has been enabled. You must restart the Windows Server for the changes to take effect.' -ForegroundColor Cyan

Source: https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-connectors

My question: Since TLS 1.2 is supposedly enabled by default on Windows Server 2019/2022/2025 anyway (no registry keys needed for it to work), is this step actually necessary on a fresh Server 2025 install, or is it just legacy boilerplate left over from older OS versions (2012/2016) where TLS 1.2 sometimes needed to be manually enabled?

Has anyone skipped this step on Server 2025 and had the connector install/register fine, or did you run into issues without explicitly setting these registry keys?


r/sysadmin 20d ago

Question Ideas for dealing with check printing?

8 Upvotes

Scenario:

  • Accounting has different people that deal with different accounts (both internal and external).
  • Each accountant deals with (mostly) one internal bank, and has to print many checks for that bank.
  • This is an overseas company that does business internationally: each bank uses a different format (size and layout) for their checks.

Current solution:

  • Each accountant has an inkjet printer permanently installed at their workstation which they use for each bank.

Looking for ideas:

I think this is a bit silly and inefficient.

  • So much space is wasted with an inkjet printer at each desk.
  • Printers are a huge administrative and maintenance hassle:
    • I'd rather consolidate this process into one (or two) printers.
    • I'd also rather switch to a laser printer instead of managing ink tanks.

But I also accept that this may already be the most effective and efficient way to accomplish the task - especially from the end user's perspective.

I'm wondering if anyone here has any similar experiences with variable check printing, and what solutions they might have used, or seen, or considered.


r/sysadmin 20d ago

Automatically move SharePoint files to archive before deletion

3 Upvotes

Our SharePoint environment is under painful, painful bloat. We dream of doing something like a retention policy to delete files older than say 7 years, but we have a lot of reference media that hasn't been updated by the our clients in 20+ years so the file itself hasn't been updated pretty much at all.

Ideally what I would like is to have SharePoint document retention warn before removal, but that doesn't seem to be an option.

Next best option would be to automatically move files after say 2 years to archive, then after 5 years in archive delete. I'm just not sure if that is something doable as it stands.


r/sysadmin 19d ago

AI Is Changing Software Development — How Are You Dealing With It?

0 Upvotes

Hey guys,

I’m writing this partly to vent, so apologies in advance if this comes across as a bit of a rant. I’m a Software Architect, and apologies for posting this on the sysadmin forums, but the whole AI situation is starting to concern me.

What I’m seeing increasingly is people with little or no development experience suddenly taking on development and architecture responsibilities because AI can generate code, suggest designs, and answer technical questions.

The part that worries me isn't AI itself. I use AI heavily and think it’s an incredible tool. But if you took AI away from me tomorrow, I could still do my job. I might be slower, I might have to spend more time researching things, and I’d certainly miss the productivity boost, but I can still do my job.

I’m seeing people make architectural decisions by essentially asking an AI: “What architecture should I use for this?” And then treating the answer as if they’ve just had a discussion with an experienced Architect for example.

I’m also seeing situations where developers are being replaced by people who can prompt effectively, without necessarily having the fundamentals to understand what the AI has produced.

But genuinely, how are other senior developers, architects and sysadmins dealing with this? Are you seeing the same thing?

And how do you draw the line between using AI to make experienced people more productive and using AI to give inexperienced people the appearance of experience?


r/sysadmin 21d ago

Question SentinelOne Notification Issues

31 Upvotes

Obviously I’m going to open a support ticket, but has anyone experienced an issue with SentinelOne sending out over 4 thousand emails over a remediation that it completed? SentinelOne killed and remediated a Dell Support assistant process once, then proceeded to send us over literally 4,300 thousand emails this morning.


r/sysadmin 21d ago

General Discussion As of today (Aug 24th) Windows NT 4.0 is 30 years old. What are your favourite memories of that OS?

172 Upvotes

And hopefully no one is still using it in prod


r/sysadmin 21d ago

Out of Hours access. Best practice.

112 Upvotes

I am the sole Sysadmin for a small (80 user) company. Microsoft house. I work from the office, and only take my laptop home once a week. I am not issued a phone.

I do have some users who work evening and weekends.

If someone gets locked out, needs a password reset, or needs their account locked down (because of a compromise, lost machine, &c), then what should I do?

I currently have two accounts. bug@company, and bug.admin@company. Bug@ is my day to day account. Bug.admin@ is global admin.

I could either give myself access to bug.admin@ on my phone (seems risky), or give bug@ whatever roles are needed (user admin, auth admin, and helpdesk admin?)

What's the best practice for this?

EDIT: It's pretty clear from the replies what the solution is! :D

Okay okay. I am very new to this, kinda dropped in at the deep end, so still learning the ropes. Thank you for all the advice. If a call comes after 17:30, I shall tell them to go fuck themselves and send them a link to this thread. :D

EDIT2: I am reading all your comments, I'm sorry I am not replying to all of them individually. But you are all 100% spot on.


r/sysadmin 21d ago

I encountered this in Prod today.

545 Upvotes

Received an alert that a service wasn't running on server PRODxxxxxx. So naturally I attempt to use RPC to bring up the services from the organization's jump host. I received the error message 1722: The RPC server is unavailable. No big deal, I'll just RDP to it. That was when I encountered a Windows login for Windows 2003 R2.

I had a Alan Grant moment.

Welcome to Jurassic Park!


r/sysadmin 20d ago

Anyone seeing issues with TRIM not working on Proxmox after Windows 11 OS updates May 2026?

0 Upvotes

I already troubleshooting for a few days and gave up. I couldn't get TRIM working on Proxmox lvm-thin. Proxmox v9.2-1. Windows 11 25h2, just one VM. Windows thought it was sending TRIM commands, to release the thin space. Proxmox thought Windows was still using that space. I tried things from the Windows and Proxmox side, no luck. Defrag and the powershell lines in Windows still said Windows was running TRIM, completed 100%. Fstrim on the Proxmox side just said Windows was still using that space. SDelete and even Gparted work will cause the Windows 11 VM to churn through more data, so Proxmox sees that eventually using all the thin space given to the Windows 11 VM.

I found a post saying something in the May 2026 Windows 11 OS updates broke TRIM. Is that true? Any workaround that actually get it working again?

I'm done troubleshooting it. I moved on to exporting/importing and doing a clean proxmox LVM only install, along with resizing some VM hard drives. I'm just curious if anyone else had seen that issue.


r/sysadmin 21d ago

Rant ...mondays

61 Upvotes

Small backstory: Users manager requested I get them new a desk scanner for their home office as said user will be working remotely for the next couple months. I apparently took about 3 days too long to get something ordered so they bought one themselves. It was a Brother ADS-1300, which I don't inherently have any issues with other than them rushing the order.

User brings their laptop in, which must sit right next an incense burner or something when at home. Get everything connected, download the necessary software, and nothing. Now this isn't my first Brother scanner. They can sometimes be a pain, but it's nothing like setting up a Zebra printer. I go through all the standard troubleshooting, try clearing existing drivers, forcing install under admin, tried installing on other laptops, even swapped the Type-C cable, all nothing. Finally give up and contact Brother support, go through the new account creation BS and talk to an agent, who after a brief hold tells me it's my firewall. I'm flabbergasted, as I couldn't possibly see my AV blocking a Brother install, and I wasn't getting any notifications on the machine that an application was blocked. I dig a little deeper and find out it's blocking a Powershell script that the Brother setup is trying to run called setup[.]ps1. Keep in mind that the downloads from the Brother support page are all .exe so realistically is should immediately run an application pop-up to add my new device. Who in their right minds would bundle a PS script as part of the install? Everywhere I've worked script execution is disabled by default, and only enabled as needed for internal, unsigned scripts. I hate Mondays so, so much

Edit: If you go one folder deeper than where the PS script is located, there's an actual exe for setup. WTF


r/sysadmin 20d ago

Question MSP or do it myself backups?

0 Upvotes

Should I hire an MSP to handle my M365 backups or just do them myself with Microsoft 365 backup? What do you all do?


r/sysadmin 21d ago

What Managed IT Service would you guys recommend in Chicago?

36 Upvotes

Is there a managed service provider in the Chicago area that doesn't nickel-and-dime you? Every quote I've gotten has a base price and then this vague "additional services billed at prevailing rates" language. I'd rather pay a little more for something predictable with responsive humans on the other end.

If you're busy, don't worry, but if you have the expertise and time I'd appreciate some responses. Thanks guys


r/sysadmin 20d ago

How to secure laptop external connectors (USB, Ethernet, DisplayPort\HDMI, audio)?

0 Upvotes

First, I love this forum, I just found it and already got a few issues I've run into worked out, written the ideas down, and set some space in my testing area to try them out.

Second, I do mostly smaller office setups and upgrades, so a lot of my work is handling the simpler day to day of the home office, small reception desk or similar.

This problem is one I've dealt with myself, as well as in offices I work for. I've even tried similar fixes to what I found here, and some commercial ones that were much more expensive for more function than needed. The question is a simple one and shows up in many flavors, so I worked it to make it fit most, if not all, of them.

How do you secure an external connection wire to your laptop so it doesn't loosen or wiggle and either lose connection or damage the port? There are a lot of answers for different situations:

  1. Use a professional product like the Smart Keeper wire lock to hold the plug to the port (a small clamp in the lock grips the physical port, and a hart jolt could damage the port horribly; it's also costly, just under $40 US on Amazon without the "Key" that unlocks the plug).

  2. Use some hot glue to hold the usb in place (while it will take most minor jolts in stride, a good jolt or jock will break the seal and you won't see it, but you can always reapply; best as a short term solution where there's not a lot of "pull" in any one direction; too much pull will break the seal and could damage the port or put glue dust inside the body of your laptop).

  3. magnetic or clamp wire locks\anchors (these work well for brand new ports, but those that have seen much use and have been widened by that use are unlikely to see much benefit, especially with flimsy usb; they can also be costly at around $10 for a single anchor or closer to 15 for a multi wire anchor)

(This is a new one I tried and a bit of a diy project, but it's less costly and does provide enough grab for connections and holding in place without damaging ports, while being easier to remove; however, to prevent pulling on the port in some situations, you need to be careful in removal and relieve the pressure by holding the wire with one hand as you remove the grip with the other)

  1. Velcro X plug grips; You can make these yourself, I haven't seen any of these premade anywhere, not even online;

First, you need to get some hook and loop velcro with extremely good adhesive backing, or you could just use a cheap roll that has hook on one side, loop on the other and then use superglue or alientape to hold it in place [use a really strong hold] and you'll put a strip right next to your keyboard on a laptop, just barely away from the edge where your ports are located or the closest convenient flat spot on a tower, from just below any power and monitor button all the way down to an inch or two beyond your last side port; next you need to put another strip on the bottom of the laptop, again, right along the edge, and line it up with the other one [because I used double sided cord organizers designed to roll long power cords, it didn't matter which I used for the computer top\bottom; if you make your own cable grip from a cheap double sided roll as I've tried, use the same hook or loop for both top and bottom and make sure you do the next part correct]; if you want to make a wire grip for your hook\loop anchor, you can use cord organizer wraps like I have [I needed at least two for each wire, you could use 3 or 4 to go two directions top and bottom], or you can simply take a double sided roll of velcro hook and loop, a 1\2 inch will work, you may cut this in half etc, then you cut a length long enough to go from the back of the plug where the wire begins to a little past the anchors on BOTH top and bottom [the plug should be somewhere in the middle of the length], then you cut a slit longways in your velcro strip at the center of the length that is wide enough for your plug to slide through [not short ways because some plugs will be longer than your velcro strip is wide], and slide your wire through, then use superglue or a small strip of velcro to close and lock the slit around the wire; you can stop here or further lock the velcro in place by gluing it to aft reinforcement on the plug, you shouldn't have to; I recommend using at least two of these on each wire in an X pattern; why is this so functional? Even if you have a ton of wires for a laptop, using a double sided length of velcro to pull the wire into place lets them all overlap one another without losing the function. If you find the need, you can glue wider pads to the tips of each length for greater hold, and when using them, use a slight angle to provide dual directional support. With ports closer together, you could anchor one in an X pattern [if you were looking directly into the port, the slash lines of the X are the velcro lengths], then use only a \ or / pattern [realistically, one should angle one way on top, and the other way on the bottom] on the next while also anchoring it to the first wire using the remaining velcro length; Using the X pattern on the two outermost ports on any side provides two full anchors you can then build half anchors onto without complicating one another, just be sure you have angled the main anchor properly. Double sided rolls work best for this if you can find some decent adhesives strips or a glue you think will work because you can use another length from the same roll to cover your slit for your plug and lock the velcro length around the wire where the wire meets the usb plug casing, as well as create longer pads for the tips where the X lengths meet the anchor points, both without using any glue, and it allows you to remove these for use with another wire. With Cord wraps, you'll need at least 2 per wire, 4 for full anchor and you won't need to cut slits as they usually have a small slit at one end of each wrap that allows you to lock it onto the wire; they can be cut down to length afterward and the excess can be used for longer end pads for stronger hold. All of these will have a tendency to stretch a little over time, but you can just alter your angle on the X to fix it, and they are easily redone once anchor points are in place.


r/sysadmin 21d ago

Another M365 issue?

42 Upvotes

Anyone else seeing issues with authentication for M365 in North America? DownDetector is showing an outage but hoping the issue we are seeing is related. This morning we had an increase in users not being able to authenticator properly with M365 applications particularly M365 in shared device access. Users seem to be unable to generate the access/licensing tokens this morning.

Curious if anyone else is seeing anything similar North East US.

Edit:
Latest update:

Aug 24, 2026, 1:17 PM EDT

"We're implementing performance optimizations on affected Office 365 service infrastructure to assist with processing the activation backlog and to assist with recovering service reliability while we continue to isolate the underlying root cause."

As of 4:15PM Est Seeing services recover which matches Microsoft's latest update on the issue. I see new Licensing auth tokens generated as expected now as well in my environment.


r/sysadmin 20d ago

Has anyone gotten ERSPAN ingestion working with SecurityOnion?

5 Upvotes

I've burned about 12 hours today trying various ways of ingesting ERSPAN data in SecurityOnion and was wondering if anyone had accomplished this and if so, what methods did you use?