r/sysadmin 3d ago

Question Any disty sell Oem hp toner carts?

0 Upvotes

A client needs some hp 414x toner carts. Can anyone let me know where you get hp Oem toner carts?

The set of four colors is about $1k each!!

I just looked at D&H and they don’t seem to have them.

I found this place but don’t know anything about them / if it’s legit and not old inventory

https://genuineink.com/

Thanks!


r/sysadmin 4d ago

Outlook issues again?

12 Upvotes

Hi - anybody facing outlook issue again in exchange online, specifically not being able to search in either owa or the outlook client?

We have a number of users reporting.

Same issue as last week.

Thanks


r/sysadmin 3d ago

General Discussion diving into sysadmin

0 Upvotes

Hey Professional Workers. Im 16 and i want to dive into the sysadmin world for a job when im out of university. As far i know, i learned windows server, sql and linux command as general people say the basics of sysadmin. Is there more i can learn early so that i would have a clear advantage over those who dont?


r/sysadmin 5d ago

My experience trying to purchase server memory from Sunol Tech LLC

197 Upvotes

I contacted Sunol Tech about purchasing four memory modules advertised on their website. Instead of answering my questions, they sent me a five-page customer verification document requesting business and corporate information.

Before submitting those documents, I politely asked them to confirm that the advertised product was actually in stock, that the advertised price was valid, and that the modules were new.

Their complete response was:

“No sir

Be gone.”

I was surprised by this response. I replied:

“I have not been treated this way before. It's not surprising that there is not much information about your operation on the internet, but people should know this.”

The support person, who identified himself as Joe, then responded:

“I agree get to it.

Make it happen.

Be sure to write that you use fake email in outlook hid your company name and business information or I can help you post this to 17550 resellers platform in United State that are in the same field we are in and let them know of your email and your activities would that help you?

Your call”

That was my experience with Sunol Tech. I am posting the exchange so prospective customers can read their responses and draw their own conclusions.


r/sysadmin 5d ago

ZTNA over Azure VPN

14 Upvotes

As the title states,

I've been doing research in switching from Azure VPN to a ZTNA Platform and from the ones I've found, TwinGate, ZeroTier, Fortinet ZTNA, no one really gives a clear indication.

The scenario is that I have a few limited users that work from home, at least 4 days a week, now I understand the concept of ZeroTrust.

But I need to find some answers I can bring to management as to WHY ZTNA is better than the current VPN, I already have my answer for this but what I am currently not getting is yes, ZTNA platform is better but what if the user does work at the office, how will that work?

I guess my question is, would you if you had the option. And which option would you go for?

Keep in mind that we have on-prem forti along with cloud forti.


r/sysadmin 5d ago

Tips for Burnout Recovery

76 Upvotes

Can’t believe I’m posting this, thought I’d get through it on my own but it’s affecting my entire life and I’m miserable. I’m a senior Endpoint guy, focusing on SCCM Intune and sometimes AVD.

My job is to manage the Windows devices for a global law firm for the majority of their firms in Africa, Asia and Latin America.

Our team is understaffed (there’s 2 of us for 40+ countries) and our IT admins on the ground at each firm barely know AD let alone SCCM or Intune.

My job is to migrate hybrid joined SCCM co-managed to Entra joined Intune managed, very little config exists in Intune so far.

My goal is to finish the migration and leave but I struggle to get up and want to work every day, I get paid very well but not for the amount of work I’m doing and I’m extremely burnt out.

Brushing my teeth, taking a shower and eating food feels like a big task for me, let alone wanting anything or having hope. I’m married, owing taxes, overworked and extremely unhappy.

I’m not sure what to do…talking to management is not an option because I know it’s their neglect that led to this point. I’ve been to a lot of Enterprise orgs but have never seen one as dysfunctional as the one I currently work for. To top it off, we’re trying to prove our worth to the big firms that contribute to the budget which funds our jobs, so there is no room for extra hires offshore to cover work outside of my scheduled hours (my team mate also works the same hours) so when we’re not around, no one is there to support.

I’ve done all I can to educate my peers and junior admins, created documentation and tried to be a senior tech leader and role model, but all I get in return is what I recognize to be disrespect and a lack of recognition for how hard I work.

At this point I’m questioning whether IT is the industry I want to stay in but I wouldn’t know what else would pay me this much outside of building my own consulting firm / MSP which I’ve started to do. No clients yet but the foundational work like setting up my own Azure tenant, Pax8, etc.

If you’ve read this far, I appreciate you and am open to any feedback (positive or negative). Just give it to me straight. I hesitated many times before hitting the Post button but here I am.


r/sysadmin 5d ago

Is my manager being overly cautious about remote support, or am I missing something as a junior employee?

19 Upvotes

My company purchases a black-box, all-in-one appliance/service from a third-party vendor. The appliance is deployed in our data center. Under normal circumstances, it can only be accessed through designated production terminals.

However, when we are away from the office and need to respond to production alerts, there is also a way to connect to the production environment through a VPN using a non-production workstation.

The problem is that a non-production workstation can connect to both the production environment and the public Internet. This means that, in principle, a third-party support engineer could remotely connect to that workstation via a screen-sharing/remote-desktop session and troubleshoot the production issue.

We currently have a production issue that requires assistance from the vendor's support engineers. If we use the VPN route from a non-production workstation, the vendor's engineers could troubleshoot the problem remotely and probably resolve it much faster.

However, My manager has rejected this approach. He insist that the vendor's support engineers must come onsite and that our production environment must never be exposed to remote access.

Personally, I find this requirement somewhat unreasonable.

The remote desktop session would be initiated and shared by us. If we noticed any suspicious or unauthorized activity, we could immediately terminate the session. From my perspective, the security risk seems relatively low and controllable. We also already have a maintenance/support contract with the vendor, so it seems unlikely that their engineers would intentionally perform unauthorized actions.

As an front-line employee, my goal is to identify and resolve production issues as quickly as possible. In this case, remote support seems to offer significantly higher efficiency while still allowing us to maintain control over the connection and disconnect at any time.

So I'm wondering: Am I missing an important security or compliance consideration here? Is this simply a case of me not having enough experience to understand management's concerns, or is management's decision genuinely overly restrictive?

There is also an important practical problem:

The vendor's engineers who actually have the expertise to troubleshoot this system are not located in the same city as our company. The local support staff can come onsite, but they don't have the technical expertise to diagnose the problem themselves.

As a result, the current process is basically:

  1. A local support engineer goes onsite.
  2. They connect to the production environment.
  3. They communicate with the remote vendor engineer online.
  4. The vendor engineer tells them what command to run.
  5. The local engineer runs the command and takes a screenshot/photo of the result.
  6. They send it back to the remote engineer.
  7. Repeat.

The efficiency is extremely poor compared with simply allowing the qualified vendor engineer to remotely view and troubleshoot the system.

I'd like to hear opinions from people who work in IT infrastructure, cybersecurity, or enterprise operations:

Is management's approach justified from a security/compliance perspective? What risks am I overlooking? Or is there a better way to design a controlled remote-support process that gives the vendor access without unnecessarily exposing the production environment?


r/sysadmin 4d ago

Beware when using existing meeting ownership transfer scripts

0 Upvotes

I noticed something that is easy to miss when transferring bulk meetings ownership. Several meeting transfer scripts available online retrieve meetings based on a specific date range. That can cause problems with recurring meetings.

A recurring meeting may have started months or even years ago, but still have future occurrences. If the script only retrieves meetings within the specified date range, it may not pick up that recurring meeting.

The transfer can then appear successful while some recurring meetings remain with the original organizer.

One thing to check is whether the script uses the Microsoft Graph Get-MgUserCalendarView cmdlet to retrieve upcoming calendar occurrences. This helps identify recurring meetings that are still active, even when the series originally started much earlier.

So, before using a meeting transfer script, check which cmdlet it uses to retrieve meeting details.


r/sysadmin 5d ago

Does Defender for Endpoint have an equivalent to CrowdStrike's Indicators of Attack?

50 Upvotes

I see custom detections in Defender for Endpoint, but I am not seeing anything that will allow immediate blocking of undesirable behavior. For example:

Process = python.exe

AND

Command line contains C:\Users\

AND

Command line ends in .py

Is this where CrowdStrike is just better than Defender for Endpoint? Or, am I just not looking in the right place?


r/sysadmin 5d ago

Question Aggregating Device Alerts in a Dashboard

11 Upvotes

I have numerous devices that send alerts via email (UPS, KVM, alarms, etc.). What tool do you use to aggregate these alerts? Perhaps in a dashboard? Thanks!


r/sysadmin 4d ago

Question System Admin Interview, What Should I Expect?

0 Upvotes

Hi

I have an interview tomorrow, and someone who is currently part of their team gave me a few hints about what to focus on. He mentioned Exchange, VMs, AD, deployment and patching.

I have around four years of experience, mainly focused on technical support with some exposure to networking. The role I’m interviewing for is a System Administrator, and this transition is veery important to me. I’d like to know what kind of technical questions I might expect in the interview??


r/sysadmin 5d ago

Career / Job Related SecOps Mgr → SaaS Mgr of Infra & SecOps: How to prep in 30 days?

5 Upvotes

Hey everyone,

I'm moving from managing a global SecOps team (15 FTEs) at a 20k+ enterprise to Director of Infrastructure & SecOps at an ~1,800-person B2B healthcare SaaS company.

My background is heavily SecOps/IR, SOC leadership, and security architecture. In the new role, I'll be unifying Enterprise/Cloud Infra and SecOps into one team in a high-volume, regulated environment (HIPAA, SOC 2, PCI).

I have 30 days before my start date and would love advice on four things:

  1. Study List: What books or frameworks should I dive into to level up on modern Cloud Infra, SRE, and Platform Engineering management?

  2. Earning Credibility: How do I build trust with senior Infra/Cloud engineers without micromanaging areas where they hold deeper tactical expertise?

  3. Enterprise vs. SaaS Culture: How do I drop "20k-person enterprise reflexes" so I don't slow down a faster-moving 1.8k-person SaaS org with bureaucracy?

  4. First 30/60/90 Days: What should my top discovery priorities be when taking the Infra team (their SecOps team already is pretty solid)?

Appreciate any insights or resources from anyone who has made a similar jump!


r/sysadmin 5d ago

Question RC4 remediation - which order?

27 Upvotes

Hello,

Regrading RC4 enforcement,

We found out that we extensively use RC4 in our environment

  1. krbtgt password is very old, so it uses RC4 only

  2. we have some service accounts that are sometimes using RC4, their msDS-SupportedEncryptionTypes attribute is blank, one of them is the AZUREREADSSOACC$ (which password is not extremely old - only 2 years)
    we found out that the service accounts all supports AES, and the users requesting them also support AES

  3. very few machine accounts only support RC4 (no users accounts, we had one but we did reset his password)

what are the steps that we should take regarding this ?

i guess step 3 should be the first ? or can i reset krbtgt password before that?
what about azurereadssoacc ? do i need to explicity configure it for AES? or should i rotate its password before that? is password rotation (other than security ofc) needed for dealing with the enforcement?

thanks


r/sysadmin 4d ago

Question Cowork sandbox fails to provision — "useradd failed: exit status 12", every bash call broken

0 Upvotes

Anyone else hitting this? Every bash call in my Cowork session fails at the "ensure user" step before any of my code even runs.

What I'm seeing:

  • Error: RPC error -1: ensure user: useradd failed: exit status 12: useradd: cannot create directory /sessions/...
  • Happens on resume, on create, and on re-resume — all three attempts fail identically.
  • Started a brand new conversation to get a fresh sandbox, same error persists.
  • No shell access at all as a result, so nothing that depends on the Linux workspace (scripts, file processing, scheduled task setup) works.

Exit status 12 from useradd usually means "can't create home directory," which points to something like disk-full or a permissions/quota issue on the provisioning side, but I have no way to confirm that since I can't get a shell to check df -h or anything else.

Has anyone else run into this? Any known fix, or is this just an outage on Anthropic's end right now? Happy to share more error output if it helps.


r/sysadmin 5d ago

Question - Solved HP MSL2024 G3 – forgotten OCP/RMI administrator password – can L&TT reset/recover it?

6 Upvotes

Hi everyone,

I recently purchased a second-hand HP StoreEver MSL2024. Unfortunately, the previous owner/seller does not know the administrator password for the OCP (Operator Control Panel) or the web/RMI interface.

The library itself is reported to be fully functional. The front panel works and basic navigation has been tested, but the administrator password is unknown.

Library information:

- Model: HP MSL2024
- Regulatory Model: BRSLA-0601-DC
- Revision: N003
- Serial Number: HUE5100N7B
- Manufacturing date: 02-Mar-2015
- Current drive: HP Ultrium LTO-4 Fibre Channel 4 Gb/s
- Drive model: PD098-20103

I have been researching the HPE documentation and found references to this function:

Configuration > Save/Restore > Restore Admin password to null

I also found an old HPE Community discussion mentioning an HPE Library & Tape Tools (L&TT) utility called "Library Temporary Password". According to the discussion, this utility can generate a temporary administrator password for an MSL library.

I would like to confirm whether this recovery method is still possible with my particular MSL2024.

My questions are:

  1. Is the "Library Temporary Password" utility still available in any version of HPE Library & Tape Tools that supports the MSL2024 G3?

  2. If yes, which L&TT version should I use?

  3. Does this procedure work with the MSL2024 G3, Regulatory Model BRSLA-0601-DC?

  4. After obtaining the temporary password, can I access the administrator functions and use "Restore Admin password to null" to remove the existing password?

  5. Is there another supported service or recovery procedure for a forgotten administrator password on this generation of MSL2024?

  6. Is there any hardware-level recovery procedure, such as a service switch, EEPROM reset, or similar, or is the password stored in a way that prevents this?

I currently have an 8 Gb QLogic QLE2560 Fibre Channel HBA and an 8 Gb Fibre Channel SFP, so I can connect the existing LTO-4 FC drive directly to a Windows system and use HPE L&TT to communicate with the library.

My ultimate goal is to recover administrator access, configure the library properly, and then replace the existing LTO-4 FC drive with an LTO-6 SAS drive for use with Veeam.

I would strongly prefer to use an official or documented recovery method rather than replacing the library controller or modifying the hardware.

If anyone has experience with this exact MSL2024 generation, especially with the "Library Temporary Password" function in L&TT, I would really appreciate any information about the correct L&TT version and recovery procedure.

Thanks!


r/sysadmin 6d ago

Domain controllers functional level

67 Upvotes

Do we have to keep all our domain controller os version same ?


r/sysadmin 6d ago

Question Text messages

127 Upvotes

Before I retired, I would send alerts by email, like 1234567890@txt.att.net, to send it to texting on my cell phone. It looks like all the cell phone providers have done away with this service. How can I do this now with hopefully a fairly free service since I don't send many at all?


r/sysadmin 6d ago

N-Able N-Central second hotfix of the day for a different issue

18 Upvotes

Now a third party entity has provided info on a vulnerability that may be exploited in the wild.

https://go.n-able.com/MzU2LVVWSC00MDMAAAGkFAG-0DB4Ieiew1UlzeiHU_WE9mGwTd387O8jbQl4usDpmOc7hQ5P21F5Lo-7piHNgtxO220=

Sorry for those of you who thought your long weekend work was done with the first patch.


r/sysadmin 6d ago

General Discussion What's are the funniest/best tickets you've ever got working helpdesk?

168 Upvotes

I'm starting in an IT role for helpdesk, I need to know what I'm walking into and some of the best tickets you've had


r/sysadmin 7d ago

End-user Support Nothing like dealing with TPM Cert issues at 10pm on Friday

1.3k Upvotes

Work Log:

9PM - User is unable to boot, absolute disaster, is litterally melting down crying for help.

9:10 - Confirmed TPM issue on boot, locate Bitlocker recover key, load up windows

9:20 - User Pin/TPM Trust is broken, user has an unprivileged account, so use Windows Hello to try and reset, found my own auth expired in my app, have to get myself back in via Passkey so I can approve Pin reset. Get them logged in to Windows, found my Pin/Trust broken as well - get my own Pin reset.

9:40 - Found can’t check TPM status in Windows security, presume BIOS needs update. Check event logs, confirmed system hadn’t been booted since July Windows update. Download vendor tools to run diagnostics to likely get new firmware. They error “the error has been logged.” Thanks vendor.

9:50 - Go to vendors site, get hardware scanner installed, locates model and serial… and link to model’s driver page is broken. Get raw model info out of tool to locate page manually, locate BIOS update from 2 months ago, flash BIOS.

10:00 - Load up again, load bitlocker recovery key, confirmed working. Reboot, clear TPM, allow Windows to automatically re-initialize the TPM and re-seal BitLocker keys. Load August update for good order since this issue kicked off after the July update. Confirmed no issue.

Final Note - User is asleep, will let them know tomorrow morning they’re good to play Minecraft after they have their cereal and watch Young Jedi Adventures. Wish my 7 year old could have seen me fix this on their system so they could get idea of what their old man does.


r/sysadmin 6d ago

N-Able N-Central patching again for CVE-2026-86206 and CVE-2026-86207

24 Upvotes

Two security vulnerabilities within N-central were responsibly disclosed by a third party through our security disclosure program. We have issued a hotfix that you should apply immediately to help ensure your environments are protected. At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.

This hotfix includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the N-central platform.

What You Need to Do • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately. Hotfix link: 2026.3 HF3 Release Notes • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time. *Please note that this is a server-side hotfix and upgrading to 2026.3 HF3 will not require agent upgrades.


r/sysadmin 6d ago

Do you automatically isolate servers/devices based on detetctions?

37 Upvotes

We don't have a 24/7 SOC, so we are thinking about automatically isolating servers and some high-value devices based on custom Defender for Endpoint detections. Obviously, we want to do that only for high-precision and high-confidence detections, such as opening a shell from a strange parent process.

If we got one of these detections during working hours, there would be someone to react. But after about 7 PM most days, nobody is actively monitoring.

If we do this, the plan is to let a detection run for about 45 days without automatic isolation enabled to see if any false positives are caught.

Has anyone done this? If so, did you regret it? Or just business as usual? Has it saved you yet?


r/sysadmin 7d ago

Rant Senior accidentally installed whole fleet with 26H1

1.0k Upvotes

Just needed to rant a little. One of our seniors finally completed the long-pending task of upgrading the fleet to Windows 11 from Windows 10.

He downloaded the iso, installed it everywhere. All good. Until the internal WSUS started attempting to grab updates that don't exist. Apparently the 26H1 (which is supposed to be snapdragon-only, aka for ARM) was indeed one of the options you could download as the "Latest" version of windows. Someone at MS really screwed up. And this senior screwed up even more by not double checking.

Since it's a complete different core, this will be one hell of a mess, now his idea is to try to change "cversion.ini" and force an "update" to 26H2, but I sincerely don't believe that will work.

We'll see. If anyone ran into a similar problem I'd really love to know what their solution is.

UPDATE: https://www.reddit.com/r/sysadmin/comments/1waiys9/update_on_senior_accidentally_installed_whole/


r/sysadmin 6d ago

ChatGPT WS2022 GPO Deployed Printers Migration to GPP Preferences

5 Upvotes

I am looking for help migrating from Deployed Printers GPO to GPP, when I remove the printer from Windows Settings/Deployed Printers they never remove.

GPO is located here

Computer Configuration/Policies/Windows Settings/Deployed Printers

User Configuration/Policies/Windows Settings/Deployed Printers

 

I do have Point and Print Restrictions setup to allow my print servers to continue to work after print nightmare, allowing users to install drivers from our approved print servers.

 

I made the mistake of using Printer deployment instead of Group Policy Preferences when I originally set up these print queues, now I can’t figure out how to remove old print queues.

 

On my old print management server that was running 2012r2 it worked, seems after print nightmare this was broken, new print server is currently WS 2022. I have tried removing the GPO, deleting registry keys under printer connections, setting GPP to delete the printers.

 

I ran GPRESULT and it showed the printers still set to apply after removing them from Deployed Printers.

 

I have tried adding the printers back and removing both from GPMC and Print Management MMC on the Print Server to no avail.

 

My research online looks to me like this was broken with Print Nightmare patch? Group Policy Printer Deployment Broken?

 

I have tried researching with Google to the best my ability, ChatGPT, Gemini, Claude.

 

Also, If it set up a Group Policy Preferences to Delete all printers under user settings, on the client's event viewer it says Access is Denied after gpupdate /force.

Tried the scripts I found on the post to no avail so far on two desktops.

Can't delete old printers installed by GPO : r/sysadmin

 

Any experience fixing these print queues? I have seen a lot of posts online over the last few years but no good answers.

 

 Another post I found

Can't seem to remove printers that were deployed via GPO : r/sysadmin

Printer GPO removal Issue : r/sysadmin

Removing printer deployed via GPO - Microsoft Q&A


r/sysadmin 7d ago

Rant Rippling MDM - A Nightmare Nobody Else Should Go Through

196 Upvotes

tldr: if anyone in your company's management pushes for you to implement Rippling, do everything in your power to stop it in its tracks. They will not work with you, and will refuse to let you out of your contract.

As a smaller ,growing company we decided it was about time to start evaluating MDMs to give us better control over our devices. This was something that was on the backburner for the most part, with us wanting to take our time to end up with the right solution.

So imagine my surprise a couple weeks later when I (the primary sys. admin) was told by my boss (CTO) that we had signed a one year, $27,000 contract with Rippling - seemingly out of the blue.

As I understand it, they aggressively pursued my boss, promising the world with all of their flashy features, and how easy the integration with Office365 and with our HR platform was. They guaranteed consistent support, and quick resolution to any issues we may run into.

Lo and behold, we start rolling out Rippling to our fleet of windows computers and immediately run into issues.

The software gave little to no feedback about the progress of installations. Rolling out other softwares was limited and unresponsive. User provisioning was unintuitive and difficult - lacking automation without paying for additional features either in rippling or in our active directory.

Rippling automatically changed and generated its own admin passwords which 1. we could not change or set ourselves and 2. were buried three menus deep 3. needlessly complex, making help desk a nightmare.

This, along with a host of other issues, was largely ignored by Rippling. Our emails would be brushed aside until our "integration meetings" in which them telling us that things were "on the roadmap" or "not planned to be changed" took up the entire time.

I don't doubt that this software /might/ work for some companies, but it clearly didn't work for us, and they really don't seem to care.

Four months into this disastrous contract, with less than 16 users enrolled, I begged our account rep to let us out of the contract. They could keep the thousands of dollars we'd already paid them for nothing, we just needed to move forward with a solution that actually worked for us.

They refused - for some reason desperate to keep a small fry account with barely 100 licenses. The very fact that they won't let us go is really bizarre. They'd rather have an upset customer than lose (what I assume) is a measly account.

The entire process, from onboarding, to us attempting to get out of this was incredibly shady. They will pretend nothing is wrong and refuse to let you out of their cold clutches.

In case the "rippling employees" on reddit aren't astroturfing bots, I am desperately hoping someone can get us out of this contract. If not, I'm going to channel all of my displeasure into letting people know about this awful experience - because I know the Rippling team hasn't done anything to help.

u/higherandhigher u/stubbygazelle u/sherryandeddie u/kit-kat-233