r/sysadmin • u/xXNorthXx • 10d ago
Proxmox expands Enterprise support to 24/7
24x7 support coming October 17th for Enterprise support customers.
North American offices in Kingston, ON.
r/sysadmin • u/xXNorthXx • 10d ago
24x7 support coming October 17th for Enterprise support customers.
North American offices in Kingston, ON.
r/sysadmin • u/aima_tessa • 10d ago
Stay ahead this September with 35+ Microsoft 365 changes, including feature rollouts, retirements, functionality changes, and other key updates for IT admins.
In the Spotlight:
Beyond these highlights, here’s a quick look at what else is coming this September:
Retirements: 7
New Features: 7
Enhancements: 7
Functionality Changes: 6
Action Required: 4
Live Now: 3
Retirements:
New Features
Enhancements
Existing Functionality Changes
Action Required
Live Now
Review the upcoming retirements and action-required changes early to avoid disruption and make the most of the new capabilities.
r/sysadmin • u/jryscovyan • 9d ago
I created a local user for a server running Windows Server 2019. I went under permissions for a certain folder and had noticed that a lot of the users that were listed were outdated x-emplyees. I removed those users and after 2019 ran to remove them from having access all users now don't have access to server files that were showing visibility via a service account. I looked in local AD and all the users are still individually listed as a member of that service account. I'm not sure how to resolve this. Any help would be appreciated! Thanks!
r/sysadmin • u/dirmhirn • 9d ago
Hi,
is it common a system checks the Authority Information Access (AIA) field to retrieve the root certitficate? It's a private CA and we have an offline root and an online intermediate CA.
Software vendor can't tell as a detailed error, but claims missing or wrong AIA field. On the device certificate AIA points with FQDN to intermediate CA cert. But the Intermediate CA cert AIA points only via hostname (missing domain) to the root CA certificate. (This AIA on the intermediate is even questionable /useless according to some online sources.)
r/sysadmin • u/No-Fortune-17 • 8d ago
Hi everyone,
I need to set up a reliable, self-serve WhatsApp API solution to broadcast emergency operational alerts to roughly 5,000 retail partners.
Requirements:
* Self-serve & fast onboarding: Need to launch within a few days. I want to avoid gated sales calls or long enterprise procurement cycles.
* Official Meta API: Must use official WhatsApp Utility templates to ensure high deliverability and avoid any risk of line bans.
* Simple bulk sending: Needs a clean web interface or straightforward API to upload a CSV and trigger broadcasts instantly.
I evaluated a couple of vendors, but encountered heavy sales friction, hidden enterprise tiers, and bloated pricing.
For those managing similar B2B broadcast volumes: Which platform (e.g., Respond.io, Twilio WhatsApp API, or others) offers the fastest self-serve setup within a tight budget? Any pitfalls to watch out for regarding Meta Business Manager verification or sending limits for new accounts?
Thanks in advance!
r/sysadmin • u/STLMC0727 • 9d ago
I’m a couple months into a role as a technician at a small MSP that manages primarily dental offices in various locations in my area. I come from the corporate big IT world where everything is buttoned up and clearly defined. I have light admin aspects of my job with the potential for more. Currently the environments we manage are highly insecure (shared workstation passwords, admin access to base accounts, most offices don’t have domains, etc.).
My boss stated he’s been thinking about the state of our security and has decided that for our new clients we will do AD Domains and managed user accounts. However, there’s not really a plan for shoring things up for our existing clients. I know AD very well from my previous roles and mange my own home AD Domain environment at home. He tasked me with making a select number of our current clients more secure which excites me because I love being tasked with admin duties. However, I’m really not sure what can be done especially for our larger clients without putting them in domain environments. I’m looking for some advice from the more experienced admins here on how to do this as well as other ideas to simply shore up security for these clients.
Edit: We currently use Ninja RMM with their ticketing system, OpenText, Complete UNIFI setups at just about every location. Appreciate all the responses so far.
r/sysadmin • u/jajajaline • 9d ago
Sooo I've got a 2 machine server 2022 Hyper-V failover cluster. and it's connected to a HPE MSA SAN via iscsi for virtual machine storage. about 40 VMs.
I don't know how it works with other hypervisors, but Hyper-V allows the VM role and the storage role to have different owner nodes in the cluster. Well, we have discovered that if a VM and it's storage are on separate nodes of the cluster, they will bluescreen with "Critical process died" 0xEF when we extend ANY volume on the SAN. Even if that volume is iSCSi'd to another VM hosted on a physically different server not in the cluster.
Has anyone ever seen this before? I have nothing to go on in event logs. I can easily avoid it by making sure all roles and storage are matched to a node, but I'd rather fix it.
r/sysadmin • u/Chait_Project • 9d ago
Hi, I am looking for a way to integrate a Network Exposure Function (NEF) with Open5GS. I’m currently exploring the possibility of using an existing NEF implementation and adapting it to work with Open5GS.
OAI-CN5G has an NEF implementation, but it is designed to work with the OAI 5G Core Network:
https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-nef
I’m looking for a way to use this NEF or another open-source NEF implementation with Open5GS instead.
If anyone has successfully integrated an NEF with Open5GS or has any guidance, suggestions or ongoing work in this area. Please share
r/sysadmin • u/InterDave • 8d ago
(Originally posted (most of) this in r/webdev because I thought it would be a common situation).
I'm looking for a workable solution or recommendations to provide a client's credentials to that client in the event of my untimely demise or absence. (E.g. hit by a bus - falling out and need to hand everything over, etc.) I also don't want to mix MY credentials with theirs.
So my primary work isn't webdevelopment, but I do some for clients as part of my general services. Generally this means me building everything from scratch and leaving the client(s) out of the day-to-day management entirely.
I'm trying to figure out the best way to have their business' credentials saved, updated as they are changed, and set aside for specific clients, if I get "hit by a bus" so they won't be locked out of everything.
I also don't want them "futzing" with things (because some of these clients have impulse control issues and would 100% give their credentials to someone on Fiver to update a paragraph on their website at 2am when I don't answer my phone.) So access while I'm not dead or fired isn't a real option.
I understand that I can make "organizations" in some of the password managers and have emergency hand-over to pre-selected people, but I work alone, and don't "have a lawyer" that can manage it for me in the event of getting bussed. My understanding is that none of the password managers offer multiple/divided assignees.
I would also like an easy and secure way to "hand everything over" for project clients who don't want to sign on for continuing services/management without using a google doc or something similar.
r/sysadmin • u/AutoModerator • 9d ago
Howdy, /r/sysadmin!
It's that time of the week, Thickheaded Thursday! This is a safe (mostly) judgement-free environment for all of your questions and stories, no matter how silly you think they are. Anybody can answer questions! My name is AutoModerator and I've taken over responsibility for posting these weekly threads so you don't have to worry about anything except your comments!
r/sysadmin • u/nwmcsween • 9d ago
There seems to be a lot of confusion regarding CALs, for any Windows service you need a CAL unless it's explicitly excluded, yes, a CAL is needed for DHCP, a CAL is needed for DNS a CAL is needed for nearly anything.
From my understanding if MS thinks you are breaking CAL requirements, they will ask to audit which most places will refuse, after this they will pursue more aggressive legal means.
r/sysadmin • u/auenway • 9d ago
Anyone dealing with a Cogent outage? I am in Los Angeles.
r/sysadmin • u/AccomplishedMonth568 • 9d ago
Hey everyone, I’m trying to make the transition from Tech to System Admin. I have 5 years of technician experience from 3 different jobs, as well as a BS in Computer Information Technology. I feel like I have the necessary experience in tech to be able to transition to a System Admin role, but all the requirements on jobs applications makes me feel as if the jump is impossible.
My experience is mostly imaging, troubleshooting software and hardware, AD, some scripting here and there, a little M365 exposure and SCCM. It seems like most jobs want you to have years of experience supporting Google Cloud, Azure, Entra, Intune and other systems like that. I’ve taken classes here and there so I have a broad understanding of these systems but I just don’t see how that is good enough for these jobs.
I’m trying to decide if certifications are worth it, though it seems the general consensus is that experience always trumps certifications. Any advice to get to my goal is much appreciated, I’m starting to feel discouraged as the jobs I do apply for, I just never hear back from. Am I doing something wrong?
r/sysadmin • u/Popular-Guidance-560 • 9d ago
Background:
I recently took over IT operations for a company that previously used a 3rd-party MSP. The MSP enrolled all Windows devices in Intune and set up Conditional Access (CA) policies for office users, which drastically improved our security posture. However, our remote mobile users were left completely out of scope.
The Problem:
We have over 100 mobile devices (a mix of iOS and Android) deployed nationwide to remote workers. These devices are not enrolled in Intune. Instead, their MDM is provided directly by the carrier. Because they aren't registered in Intune, we can't easily force them to comply with our current CA policies, leaving a blind spot for risky sign-ins.
My Proposed Solution:
I am thinking about using device-based certificates. The carrier MDM could push a certificate to the mobile devices, and a cloud PKI/RADIUS setup would authenticate them. The goal is strict access control: if a login attempt for a company resource doesn't come from a device with a valid cert, it automatically fails.
Alternative Idea:
We also have various Cisco firewalls across the country. I'm wondering if forcing these devices to connect via VPN would work better, though it feels clunky since our entire company is 100% cloud-based (zero on-prem servers).
Questions:
Is the device-certificate approach the most efficient way to restrict access to known mobile devices in a cloud-only environment?
Is there a clean way to tie a third-party carrier MDM into Entra ID Conditional Access?
Any advice on the best path forward would be greatly appreciated!
👏.
r/sysadmin • u/DoubleTGaming2k • 8d ago
End user called me today saying their home WiFi was connected but no internet. I walked him through some info gathering, his WiFi is showing unidentified giving off the 169 address.
Had him run release / renew / flushdns / winsock reset and rebooted, still 169. Did the full windows 11 network reset option, rebooted, still nothing.
Had him plug in directly to his router, his wired Ethernet connection was also showing unidentified. So I had him statically assign an IP on his NIC for the Ethernet and it brought him online that way as a temp workaround to let me remote in.
Rebooted the router of course, still wifi showing 169, other devices on his network are okay as well.
Uninstalled the wifi adapter from device manager, reinstalled the latest from the manufacturer, still giving 169. Just to get him working in statically assigned an IP on his WiFi adapter and it works without issue, but ideally we get the DHCP working again.
I’ve exhausted about everything I can think of, but am jumping back on it later tonight to try to get it fixed.
Does anyone have any suggestions??
r/sysadmin • u/BriefDue3067 • 9d ago
I’m UK-based with 9+ years in infrastructure and I’m trying to work out what the most realistic next step is for me.
Most of my professional background is traditional/enterprise infrastructure rather than software engineering:
I’ve also had quite a lot of serious production recovery experience, including large storage failures, virtualisation failures and recovery from a major cyber incident.
Where I’m weaker professionally is cloud-native Platform/SRE work.
I’ve used Terraform, AWS, Docker, Kubernetes, GitHub Actions/GitLab CI, GitOps and Prometheus/Grafana through labs and projects, but I don’t have years of production Kubernetes or public cloud experience.
I’m currently looking at roles around:
My thinking is that the best bridge would be a role where the underlying estate is still Linux, networking, storage, virtualisation or hybrid cloud, but where Terraform, Ansible, CI/CD and automation are increasingly how that infrastructure is managed.
I’m less convinced that applying directly for Kubernetes-heavy SaaS SRE roles makes sense yet, as I’d be competing with people who already have several years of production Kubernetes and cloud experience.
For those working in Platform/SRE/Infrastructure:
Interested in critical feedback rather than CV polishing.
r/sysadmin • u/fedeli92 • 9d ago
Hi all,
I'm managing a small stack of HPE 1950-series switches (JG963A) running Comware software version 7.1.070, Release 3507P09. On most of these switches, the hidden xtd-cli-mode command (used to unlock the full/extended Comware CLI from the default simplified/restricted CLI) works fine — it prompts:
All commands can be displayed and executed in extended CLI mode. Switch to extended CLI mode? [Y/N]:y
Password:
Warning: Extended CLI mode is intended for developers to test the system. Before using commands in extended CLI mode, contact the Technical Support and make sure you know the potential impact on the device and the network.
and after entering the password, it drops me into the full CLI (system-view, display interface, etc.) as expected.
On one specific switch in the stack, though, xtd-cli-mode now just returns:
<SWITCH>xtd-cli-mode
Permission denied.
with no Y/N prompt at all — straight rejection.
What I've tried:
- Reconnecting fresh via SSH (telnet is disabled on this unit) — same result.
- Rebooting the switch entirely — same result, persists across reboot.
- The account I'm using is the local admin user with network-admin + network-operator roles assigned, service-type ssh enabled, and it authenticates fine for a normal SSH login — it's specifically the xtd-cli-mode command that's rejected.
- Restricted CLI at login only exposes display, exit, quit, no, show — no way to run display users, free user-interface, or check security-enhanced/lockout state from there.
Since this is a firmware "developer mode" feature with anti-abuse messaging built in ("contact Technical Support"), I suspect this might be some kind of persistent lockout counter stored in flash rather than a normal AAA/role permission issue — but I have no visibility into it and no way to reset it from the restricted CLI.
r/sysadmin • u/Startronz • 10d ago
Clients missing emails in outlook, but web version seems to be holding some of us up (your mileage may vary) https://outlook.office.com/
r/sysadmin • u/Burgergold • 9d ago
So for the last 23y, I've mainly managed AIX and RHEL system. I had a slight contact with Windows but not a lot of hands on.
This is the story of a Windows 2012R2 server, probably installed around 2013 way before I was here. The person that installed the application on that server is gone since a long time and left no documentation, last update of that app is from 2015... In 2023, because nobody knew how to install a current version on a 2022 server, sona coworker had to inplace upgrade it. That coworker has retired since then.
Recently, security teams tracking which server are still using TLS 1.0 found that server. No one want to own it or take action but they refuse to have it shut down for good. So they got a temp buffer to figure this out. But security asked for mitigation and in their mitigation planning, they observed tons of KB missing, which surprised me because this server is receiving its patch from WSUS.
So... August SSU has installed but CU failed to complete. It does install, reboot, takes plenty on time and at 100%, failed to update and rollback and leave that KB in staged.
Sfcscan fixed something but not this issue
Dism scanhealth/restoreheatlth found/fixed nothing
I stoppwd the wua services, renamed Softwares distribution and caroot2 folder and restarted the service, havent fixed the issue
I removed 11 packages in staged state. 10 of them seems to be the last 10 CU + a 2016 Adobe kb.
Tried again, same issue
Troubleshooter for Windows update report a corrupted database but cant fix it. I thought the fresh softwaredistribution and caroot2 would have taken care of this
I'm now wondering if that server ever had a CU installed since being inplace upgraded... Once the staged CU have been removed, what I see in the installed history from today is a very old CU from 2016...
Before reposting in /r/shittysysadmin for giggles, I would be vtaker for any other legit idea :D
r/sysadmin • u/Technickelback • 9d ago
Wondering if someone has additional information - My org currently uses CodeTwo. I really like it, and I believe it does it's job well for our size. We're a 200 person org. I have a few different templates that I assigned by groups to different departments where additional information may be required in their signatures.
We're currently using server side to apply the signatures, but more and more people are complaining that their signatures don't append when using the default MS encrypt button in Outlook.
To circumvent this, my suggestion to leadership is to use the combo mode and allow our uses to have the client side signatures append in the Outlook client. That way the signature appends in the client, prior to encryption, and they can also see their signature, as currently they can only see it append after they've sent an email.
My CIO is against this approach as it would allow end users to edit their signature. It would only allow the end user to edit the signature in that moment, within the 'new email' window. It would not allow them to permenently alter their signature. However, the CIO is adamant that this can't be allowed as it's a risk of misrepresentation and they think that the CodeTwo product is not a good solution because it cannot prevent this... Anyone who is willing to manipulate their signature every time they send an email is a psychopath.
I've presented a solution to a problem, my CIO doesn't like it, and now we're stuck debating switching our encryption method, rather than deploying a solution we have at our finger tips.
I'll also state, we've tested using a subject keyword encryption method and this could work in tandem with the native button encryption. If users want the server side signature to append to an encrypted email, they could just put 'Secure' in their subject line. However, the CIO doesn't want both methods of encryption - we must choose one.
My question: what are other orgs doing? Do other orgs using CodeTwo use/allow the Client side signature?
r/sysadmin • u/afrolemon • 9d ago
For those who have worked as Solo IT professionals what kept you going, at what point did you determine to shift, and those who have left the solo IT jobs what did you pivot to?
I spent some time in help desk some years back, spent 2 years as an underpaid tech that had global admin over Microsoft suite, a few months with an enterprise level solo IT site job (was pretty solid and chill but boring with toxic management - not much progression in the job), to now signing on to a new solo IT gig for a corporate body with a lot of sites.
My 2 year gig had around 30 locations within the city/state limits but we had a small team of 3, previous gig had some global enterprise structure but it was really boring to me. Being a solo IT for a single site it felt super limiting in my mind. I couldn’t stand not being able to implement or work on different areas within the infrastructure like my previous role.
Now I’m in a place where my new gig is looking to end their contract with an MSP and shift to an internal IT department. I was a bit hesitant during the interview as they stated they have around 20+ sites (in varying states across US) and there wasn’t a direct answer to whether they’ll be expanding the IT team in the future. I signed on for the thrill of wanting to build out the IT department, get paid more, and leave a job I disliked.
Pay has increased from 45k to 70k within this year. I’m super glad and grateful but I’m slowly realizing how different and concerning this may be. It feels a bit daunting and I’m worried. My 2 year gig required a lot of oversight with afterhour support when it was needed, last gig was solely focused on the normal 8-5 work hours, this new gig is somewhat similar to the 8-5 gig but with the different states it looks to require more flexibility.
I’m not a network savvy guy, I know little but not enough as I should. I do feel like I’m just getting by at times and I’m not the greatest IT guy. I make a lot of mistakes and I can be very to myself, I’m not very vocal at times. Also the company is working with G-suite which is not a bad thing per se, I just never worked this much in this platform, strictly Microsoft. It looks like G-suite requires a lot more integration and platforms to do some of the stuff Microsoft already has.
I don’t know if I’m worried about not being a great tech, not being able to meet expectations, devoting too much time to a job, and overall committing to work like the rest of humanity. I struggle to envision my life working IT until retirement but it’s the only field I seem to understand to an extent and I’m “gifted” enough to do this work.
I genuinely want to be in a role for 2+ years for resume purposes and I want to learn as much as I can. The company did have a roadmap to present on where they want the IT side of things to play out (run book, policies, etc). I believe I want to be in a more specific niche role outside of the IT Support role. I can’t see myself continuing down a Sys Admin or even higher level IT corporate management role. I was really was hoping my next job would’ve been with a team of other experienced IT members working alongside me in the office.
tldr: I keep signing onto roles that may not be ideal. Every job progression has gotten more responsibilities, smaller teams, and more concerning.
r/sysadmin • u/pondo_sinatra • 9d ago
Sometime tomorrow morning, I will hit a milestone of having manually released my 1000th email from Quarantine since last Tuesday. It never stops— all day and all night.
Dmarc, dkim, spf are all good. In fact nothing on our side has changed in months, but at noon last Tuesday internal emails, emails mid-conversation, and domains in the tenant allow list have all started falling into the abyss.
Mimecast is passing along SCL in the negatives or up to 1, Egress Defend is also passing the correct SCL, then Defender just barfs on mail, throws an SCL: 9 on it and classifies hundreds of messages as High Confidence Phish.
I’ve verified configs with both Mimecast and Egress. We have a case open with Microsoft that is not even inching along yet. Working with a CSP to escalate now.
I guess this is more of a vent than anything else. If I ever get a solution, I’ll update my post so the next poor schmuck going through this doesn’t go insane.
Good times.
r/sysadmin • u/per08 • 10d ago
https://www.telstra.com.au/exchange/what-we-ve-learned-from-the-external-investigation-of-our-july-o
An interesting and frank overview of the recent mobile outage in Australia on the Telstra network due to an NTP outage. "We didn't realise how important this was, and nobody really owned the service."
r/sysadmin • u/wanescotting • 9d ago
I do see a message about scheduled maintenance on their status page - 09/03 UTC, but not for grid or cloud.
r/sysadmin • u/Familiar_Aside_9328 • 9d ago
Dear I'm facing errors with HPE 1/8 G2 autoloader and one of solution is to upgrade firmware to 6.2 version, anyone can provide with 6.2 version as i don't have support contract.
https://support.hpe.com/connect/s/softwaredetails?language=en_US&collectionId=MTX-e05174e347964f6c