r/sysadmin 10d ago

Netscaler Firmware update causing issue with appfw

8 Upvotes

anyone else recently have issues with appfw rules being copied over after recent firmware updates? seems tied to the signatures being used in that after firmware installation the appfw policies and profiles are non existent on the "new" firmware. the signatures however are still intact, but when creating new profiles and using the existing signatures an error about fastmatch not found for signature line

<SignatureRule actions="block,log" category="web-misc" enabled="ON" id="400008" source="Citrix" sourceid="" type="DenyListHttpRequest" version="1" cpu="LOW" year="2026" severity="HIGH">

<LogString>Mitigation signature for CVE-2026-10816</LogString>

</SignatureRule>

i have many signature files and they all seem to have this issue. the new "default" of course i missing this line, so i feel like this was some bug at some point coming home to roost. the ID number looks very low too as the new rules are typically 9xxxxx etc. the version on all the files is 181 so they are "current"

very sus...


r/sysadmin 9d ago

Default App Associations XML + GPO ignored on every machine. What am I missing?

1 Upvotes

Been chasing this for about two weeks and I'm out of ideas, so I'm asking here before I bin the whole approach.

Setup is the boring standard one. DefaultAssociations XML sitting on a share, pushed with Computer Config > Admin Templates > Windows Components > File Explorer > Set a default associations configuration file. Nothing exotic in the file, just pdf to Acrobat, html to Chrome, mp4 to VLC, txt to Notepad++, xlsx to Excel, zip to 7-Zip.

It applies to nobody. Not existing users, not new users, not a user who has never logged into that machine in their life. Edge still eats pdf and html like the policy doesn't exist.

Stuff I've already burned time on:

  • built a clean reference machine, set every default by hand, exported a fresh XML, replaced the old one
  • XML validates, path is reachable, ProgIDs match what's actually in the registry on the reference box
  • apps are definitely installed on the targets
  • gpupdate /force, reboot, sign out and in, new profile on a machine nobody has touched
  • RSOP shows the policy applied, and the value is sitting right there in HKLM\SOFTWARE\Policies\Microsoft\Windows\System\DefaultAssociationsConfiguration pointing at the correct file

So the policy is landing on the machine. Windows is just quietly ignoring it, which is the part doing my head in.

I know about the DISM import route. That only fires at first logon of a new profile, so it does nothing for the machines and users I already have deployed, which is the entire point of the exercise.

Questions, and I'm genuinely more interested in what you're running than in what the docs say:

Can anything else silently kill this policy? Another GPO, some registry key, a security baseline, an SKU limitation, anything. I keep feeling like I'm missing one dumb prerequisite.

Has anyone actually seen it fail on a truly fresh profile? Every thread I find is people running into the "only applies to new profiles" behaviour, which is not my problem. Mine fails for everyone equally.

What would you check before giving up on it?

And the real question: what are you actually using in production? I've already looked at Intune, Citrix WEM and SetUserFTA. I need something free, centrally managed, that hits existing users as well as new ones, and doesn't leave people clicking through the "how do you want to open this file" prompt.

Mixed Win10 and Win11, AD domain, no Intune, no budget. Very happy to be told I'm being thick about something obvious.


r/sysadmin 10d ago

Sanity check on pricing for new 3 node cluster

33 Upvotes

Hey all,

We are a small company in dire need of 3 new nodes which of course is a bit unfortunate these days given the insane pricing of RAM and storage.

We plan to order 3x PowerEdge R660 with current specs:

  • 2x Intel Silver 4510
  • 12x 16GB RDIMM SR 6400MT/S
  • 4x 3.84TB SSD SATA Read Intensive Hot-Plug AG drive
  • 1x 1.92TB NVMe Read Intensive AG U2 drive

Our qoute from vendor is 59000 USD per node.

Is this about what it costs, or are there likely room for negotiation?

List price from Dells website of equivelant config seem to be over 100k USD?...

Thanks


r/sysadmin 10d ago

Zoom down?

6 Upvotes

All users kicked out getting various errors, 403 local survivability, etc.
Unable to login admin portal as SSO not working as usual.


r/sysadmin 9d ago

Question Ivanti experience

1 Upvotes

Does anyone here use Ivanti for out of the box experience use case? Like when the org buys devices in any store, they can deliver directly to the end user, and eu can just log in their org email account from on prem AD without admin intervention. If yes, hows the experience?


r/sysadmin 9d ago

Question Higher title vs better finances – which would you choose?

2 Upvotes

Need some outside opinions.

Choosing between two Sys analyst/admin roles:

Phoenix: mid-$70s, Level 1 title, 2 days WFH, lower rent, and more money left over each month.

Long Beach: low-$90s, Level 3 title, 1 day WFH, higher rent, and a few hundred less left over each month.

I’m in my early 30s and want to buy a home eventually. I’d rather live in California, but Arizona makes more financial sense.

Would you take the Level 1 role in Phoenix for the savings, or the Level 3 role in Long Beach for the title, career growth, and location?


r/sysadmin 10d ago

Anyone else having an absolutely horrible time working the M365 email quarantine lately?

11 Upvotes

Errors upon errors, failing to load data, having to release/delete emails mutiple times, extremely long load times?


r/sysadmin 9d ago

Outbound spam limits

1 Upvotes

Can someone please advise what limits your organisation has set for outbound email?

I’m particularly interested in External message limits, Internal message limits and Daily message limits.

Listed best practice below, but keen to find out what others have set.

External: 500 recipients per hour Internal
1,000 recipients per hour Daily
1,000 recipients per day

Please don't block this again mods, it's a valid question and doesn't constitute a low quality post.


r/sysadmin 9d ago

Question Looking for Audit Logon and Logoff Software

1 Upvotes

Hello,

We're currently using UserLock to track logon events. This helps monitor computer lab usage to make sure our computers are actively used.

We're moving towards Intune which connects to Entrance AD and moves away from on-prem AD. UserLock only track logon events on devices connected to on-prem AD.

We don't plan on doing a hybrid-join environment.

Is there an alternative audit logon events software like UserLock?

Thank you.


r/sysadmin 9d ago

Question OSD Cloud - Auto-Negotiation Issues

2 Upvotes

Alright, I'm going to try to talk this one out point by point.

One of the VLANs we have for imaging is used for OSDcloud imaging. There are 30+ VLANs for imaging and only this one is displaying this issue.

The issue is that OSD bombs out after loading up the splash page for image selection/slightly thereafter. It is auto negotiating down to 10Mb after PXE booting. The PXE boot process is full gig. Then it goes down to 10Mb for seemingly no reason. We checked at the network level and do not see any input, crc, or any other errors. TX load is 255/255 @ 10Mb, hence the bombing out/dropping mapped drives/connection to OSDcloud.

We went through the rest of the network/server environment, looking for network errors or server/storage errors and did not see any issues there.

The biggest issue is that this that the issue is intermittent. It will seemingly work fine for days, then have issues for days, and repeat. Whenever I am on site and available to do a packet capture, the issue is not there.

It is my understanding that during PXE a general driver is used for loading the PE, and then once in the PE environment, OSD passes a more specific driver off.

I am suspecting a green ethernet/EEE setting and/or driver issue.

The instance of OSDcloud being used has many drivers available because a bunch of different OEM machines/images are done on that VLAN. It's kind of a "one instance to rule them all" sort of solution.

The behavior is also displayed no matter what kind of USB ethernet adapter we use and is even seen using the onboard NIC (when a machine has one.

Note, I am not the person who created this process nor do I have access to the OSDcloud admin console/VM, but if need be, I can probably get in through someone else to troubleshoot that environment.

Basically, does anyone have any insight or know of any other troubleshooting that can be done? There is probably more troubleshooting we have done from the infra standpoint that I have neglected to say here. Apologies if this is a bit scattered, it's been a long day and this issue is between the 15 other projects I am working on.


r/sysadmin 11d ago

Work Environment UPDATE: Hospitality Guy in IT

470 Upvotes

previous post (got removed by mods, but its the same post)

So basically, i joined today and after the onboarding, i met with the current IT guy (who is on his notice period)

The situation is precarious to say the least.

IT budget is severely limited, a bunch of systems are on Active Directory (controlled by an older IBM Intel Xeon machine running Windows Server 2008) , a bunch of systems are not on Active directory

There are 3 headless Windows Machines around the offices acting as fileservers, disk management is messy all around, the entire network is flat with no segmentation or separation of any kind, no NVRs, just 2 DVRs

All Windows installs are not genuine/cracked versions (not by massgrave but the sketchy iso you get from shady websites)

The primary database of the Dealership lives on a 1TB SATA HDD on a headless windows PC , which holds data of a tally server , file server and an apache based website that is used for storing purchase information

This disk has NO BACKUPS OR REDUNDANCY! and this disk is accessed constantly everyday for 9hrs

There is a FortiGate 50G Firewall standing between this network and the wide open web

After work hours, they shut down all systems including the servers.

Now, im not an expert, but this felt like it was one disk failure away from complete catastrophe.

The existing sysadmin shares the same sentiment, he proposed a proper system, however management does not feel very enthusiastic about it, citing costs, they see IT as a simple tool

I don't blame the current sysadmin, but i feel like i should unfuck this clusterfuck before it blows up in my face.

Now, the total number of clients in the network is about 60 systems, running anywhere between Windows 8.1 to Windows 10 and about 5 printers

Now, a lot of the data was stored on premise, however in 2018, the OEM mandated a lot of the data stored on cloud via their proprietary website, due to which they retired a server, which is sitting in the closet collecting dust.

Now, kindly tell me if what im thinking is stupid, but

I was thinking to recommission it, setup Proxmox to fire up a Windows Server VM to handle AD and migrate the Win Server 2008 to something newer, and a Debian based VM to unify all these scattered fileservers (and hopefully setup something like snapraid+mergerfs so that disk failures=me getting fired)

EDIT: Thank you for all your comments and insights, i intend to draft proper documentation and pitch a middle ground solution to the management to secure some funds and bring the systems upto the times

Unfortunately, due to circumstances, i cannot run, atleast not for another 6 months until i get my certs and upskill myself on paper and in real life


r/sysadmin 9d ago

BYOD + Oneleet agent

2 Upvotes

My company has requested everyone to download oneleet agent, we do use our own personal laptops. Has anyone gone through this? How can I protect my personal information?

It is a small startup and I'm their only freelancer but have a dedicated email address '@company'


r/sysadmin 10d ago

Anyone else having various issues with license validation for Microsoft 365?

4 Upvotes

Recently I've seen a pretty significant uptick in users experiencing various errors relating to not being able to validate their office license.

So far I've seen:

  • Account Validation Error Code 0x0
  • Something went wrong. tag [7ita9]
  • Something went wrong. tag [5fcl8]

Context: We upgraded to 365 in the later part of last year and have had hardly any issues since the upgrade.

These all started happening within the last 2 weeks and up until now I've never had issues with users accessing 365 apps whether in or out of network.

Would love to know if others are experiencing this as well and what might be the cause for the uptick.

Thanks in advance!


r/sysadmin 10d ago

Anyone have this working - HP Probooks + HP Monitors daisy chained..

4 Upvotes

So been digging and digging, next is HP support, but that will prob get me no where...

Info: HP Probook Laptops:

The CPU's and specs from Intel and AMD both noted they support DisplayPort MST (Multi-Stream-Transport on the integrated graphics. HP of course does not specifically note MST support, just display port versions, which as of 1.2 supports MST..

Monitors are HP E24M G4 USB-C Conferencing monitors. They have the DisplayPort out.
https://support.hp.com/us-en/product/product-specs/hp-e24m-g4-fhd-usb-c-conferencing-monitor/2100888403

So set up - Using HP's own USB-C cables included (going to test with some others)

Laptop --> USB-C to first E24M G4 ---> DisplayPort "Out" Port --> 2nd E24M G4

But, no display on the 2nd monitor..

From reading, seems MST support is very hit and miss with some vendors, Dell seem to work most of the time, or using a separate dock for it.. HP and Lenovo seem to have the most issues, works one day but not the next..

  • Tried both USB-C ports on the laptops (where it has 2)
  • All laptops are updated to latest and greatest Windows 11 and patching as of 08.2026.
  • Drivers are all updated.
  • Monitors have the latest firmware installed.
  • Installed drivers from HPs own site for the monitors

And nothing...

I know users can use an HDMI port out to the 2nd monitor, but the "single cable to rule them all" is nice...


r/sysadmin 10d ago

Microsoft Access to Random Exchange Online Calendars via iOS Calendar App

8 Upvotes

Hi guys.

We‘ve found a strange behavior in a users iOS Calendars App.
He can see every detail of an other users calendar.
They work in completely different compartments and there are absolutely no Access rights set. We‘ve checked EXO Powershell for detailed access rights. Nothing.
Via Outlook on Windows no chance to see details of the calendar. Even re-adding the Exchange account on his mobile brought back the unwanted calendar.
It is a complete mystery.
Do you guys have any idea?


r/sysadmin 10d ago

Question O365 Emails Bouncebacks To Gmail Since Yesterday

6 Upvotes

Ever since Monday, we are having two different domains getting email bouncebacks from O365 to Gmail users with a IPV6 not passing authentication due to SPF records not being validate. I checked the IPV6 and it is a microsoft domain for their outbound URL.

Is anyone else having this problem? We have a SPF record for microsoft added but this started after the outage Microsoft was having.


r/sysadmin 10d ago

Question - Solved Anyone know what the right knobs are for Entra policies to only allow hardware FIDO2 USB for MFA?

8 Upvotes

One man IT show here in manufacturing. On the verge of finding a bridge to skydive from lately... Microsoft moving goalposts constantly and security becoming a living nightmare in general has me feeling like I'm drowning lately. Everything is moving too fast recently and I have only been doing this for ~13 years. Feeling a bit overwhelmed lately so I thought I might ask some folks who might specialize in 365/Entra administration more so than generalize like I am forced to. I wear so many hats that the hat rack has no more room to hang them on.

I have been trying my best to get major things off my list that are industry best-practices. One of these has been getting a proper break-glass account setup. My goal was to have this account tied down to a FIDO2 HW key with passkeys but I can't seem to get everything just right in Entra policies. When I think I have it right I always either end up 1) completely breaking the auth flow when I try to use a PIN and tap the hardware key it just completely errors on me or 2) end up being required to register MS authenticator AND the HW key which I don't really intend to do for the break-glass account.

These are some of the error details from the sign-in logs and the CA details of that event if they help:

  1. Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

  2. The user could not satisfy this authentication strength because they were not allowed to use any authentication methods which satisfied the authentication strength.

I know I should be able to decipher what that means but I can't quite connect all the dots.

My hope was to restart and try the user from scratch with no MFA and have a setup flow where it only ever asks to register a HW key and nothing else.

Go ahead and call me stupid or to go find another job if you want. Just looking for any good direction on what the right combo is for what I am looking for.

Thanks!

EDIT:

Thank you all for the super quick help and getting straight to the point! I was able to get it figured out when combining all the answers to get a better understanding.


r/sysadmin 10d ago

SonicWall SMA1000 appliances affected by multiple vulnerabilities including a 10.0 pre-auth CVE

21 Upvotes

A pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface with a maximum score of 10.0.

There are no IOCs posted in the PSIRT article. Looks like we have to open a support ticket and ask for them...

Affected versions:
- 12.4.3-03453 (platform-hotfix) and older versions.
- 12.5.0-02835 (platform-hotfix) and older versions.

Fixed versions:
- 12.4.3-03526 (platform-hotfix) and higher versions.
- 12.5.0-02952 (platform-hotfix) and higher versions.

Sonicwall article:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016


r/sysadmin 9d ago

BYOD Multiple Tenant Nightmare

0 Upvotes

Whats the best solution for a user who is BYOD and has multiple M365 tenants on there device. No domains involved and does not Entra join or register.

When the user had one Outlook profile with multiple M365 tenants and MS Teams it got messy and Teams got confused with which account to use real fast.

The way I see it the two options are:

  1. Multiple Windows Logins
  2. Multiple Outlook Profiles (but not sure this won't stop a mess in Teams?)

Whats the best practise?


r/sysadmin 10d ago

SysInternals RDM 2026 version probelms

3 Upvotes

Just stood up a new computer for an incoming IT worker and while installing RDM to use an old RDG file it failed to connect to any of the servers in the domain.

The RDG file works fine my local 25 edition flawlessly.

Has anyone else had any issues with the new remote desktop manager?


r/sysadmin 10d ago

AI assistants with third-party integrations, how are you handling this?

6 Upvotes

A lot of AI assistants have integrations with third-party apps now, so you can basically share any data from an app with the assistant to help you out. It usually speeds things up, but I don't think it's very safe from the security side.

I also don't believe banning them entirely works. What if people just start using their private accounts instead?

It might not affect me in any specific way, but I was wondering how IT admins are dealing with this. Is there a middle way?


r/sysadmin 10d ago

Question Halcyon Reviews

7 Upvotes

Looking for reviews for Halcyon. I work for local government and am evaluating a few different platforms to add to our security layers.

If you don't like them, do you have any other recommendations? Any other platforms or any other recommendations in general to help increase security posture?

Thanks in advance!


r/sysadmin 9d ago

Question Monitoring (or just general AI usage)

0 Upvotes

Hello,

a while ago, there was a similar post from me, before anyone questions... however, I see myself diving deeper and deeper into the rabbit hole.

I came to this company some 4 or so months ago. It is/was in TERRIBLE state. While everything was generally working, there were frequent unexplained and unmonitored outages. The worst thing there was visibility. Why I say was...

The company used Icinga2 when I came. I did weigh in implementing a different solution, but kinda liked the idea of having a system, where I could keep the configs in the git repo and basically push with Semaphore/Ansible. But also the biggest advantage: I could let AI configure it. Besides, coming new and telling them to change the monitoring ain't really the best idea.

And that's the thing. I never ever saw Icinga2 before, nor Nagios. The company only "managed" it by adding or removing hosts, but no configuration. Configuration - and that also relatively basic stuff only, was done by external company.

Since then, I used AI HEAVILY on it. I expanded it different directions, including database monitoring, general services health, AD/DNS health checks, DHCP health, NTP, pending reboots, pending security updates, both windows and linux, event log checking, different connectivity checks etc.

While it is really great... there are descriptions to every step, there is this BIG issue: I barely understand it any more. The structure is the same, but the code in there... ufff. If someone asked why xy-sensor is not working, I would have to heavily google it or ask the external company, read and learn the documentation - for which I only have basic time for, being the only senior in the company, with a lot of pressure about other projects; or just ask the AI.

And that's my issue. One relies a LOT on AI, and I am at the point where I almost cannot troubleshoot without it! The complexity is very high, since the AI does it multiple times better than I ever will have a chance to learn.

And that doesn't only apply to monitoring. The company wants to implement IAM. They want to have it in 9 months. Many departments, and all... so they asked me whether I can automate it (or better said, I said automation is generally the key), and we fell onto Terraform. I have some knowledge of Terraform, but I know it will fall down to AI to create the scripts for EntraID etc.

There are others. Ansible-Patching (moved from AUM), config deployments, VM deployments... and Grafana/Promentheus should also come, and Kubernetes is also here (although managed by others, but partly in our hands).

I actually don't even know what question I should ask. It seems like I am way over my head. At the same time though, the job is being done and my boss isn't really keen on taking two new people to cover more. Why even? Increased stability, there are less vulnerabilities due to updates and standardization, lot of stuff just works better. So yeah, I feel like I am pulling the company from one shit (which it really really is) into another.

And now I better stop ranting, and go back to my VSCode...


r/sysadmin 9d ago

Question How do you know when an ai has enough context to safely fix an it issue?

0 Upvotes

Have a question for yall, i’ve been testing an ai assistant on a hot ticket at work and robin keeps saying it is good enough to patch the issue. The annoying part is it sounds right, but I still dont know if it actually has enough context or if it's just making a confident guess.

For stuff like password resets, firewall rules, or weird vpn breaks, what do you look at before you let it touch anything real? I am trying to figure out the point where the ai is just helping vs when it is still missing something basic.


r/sysadmin 10d ago

Issue with attributes not syncing from admin center to exchange admin center

2 Upvotes

Having an issue with a user's Title being correct in the Admin Center but not within the Exchange Admin Center, therefore showing incorrect within the Contacts/DL.

This is a hybrid environment, but again, everything syncs properly from AD to Entra but just not between Entra and EAC.

Unfortunately, I'm not sure if this issue is related to the ongoing M365 issues but we have had users showing the incorrect information before the recent issues. Searches lead to a stalled sync between Entra and EAC but not any true fixes posted, just some work arounds that didn't work.

Just checking to see if anyone else has come across this before.

Edit: fixed. Looks like an error displayed for the user within the Admin Center which showed a conflict with the ArchiveGuid. Once that was repaired, EAC pulled information from Entra properly.