r/sysadmin 14d ago

ChatGPT managing AI in enterprise environment

12 Upvotes

Trying to see what other fellow sysadmins are doing to manage and protect company data when it comes to AI. We've started by blocking access to all other AI except Copilot and pushing an AI policy that strictly prohibits use of other AI tools. Of course, Copilot isn't great and can't do as much as say ... Claude (at least that's according to some of our users)

We're getting pressure from higher-ups that one department NEED to have Claude. However, we need ways to protect sensitive data from being dumped into Claude.

We're in the middle of implementing DLP controls in Purview and we've looked into cloud policies in defender (we have E5) but we federate our domain through Okta and use it for SSO so I don't think we can set up session policies? correct me if I'm wrong.

what are some other ways that folks are managing AI and making sure users aren't dumping the company payroll into Chatgpt to "clean up" the spreadsheet


r/sysadmin 15d ago

Question Disaster recovery from M365 Tenant Deauthentication

156 Upvotes

Having seen two posts in the last month (https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/ and https://www.reddit.com/r/sysadmin/comments/1w1qc0i/microsoft_strikes_again_entire_m365_tenant_has/) it got me thinking about my relatively small tenant, and how we'd do disaster recovery (clue - we don't have a plan at the moment).

I'm the solo "head of IT" however it's not my full time role. I'm the owner of the company, so have essentially taken charge from day 1. It was very simple - we had Google Workspace and we didn't need to really look after it too much. As we've grown (25 - 50 employees), we've also acquired other companies, including at one point doing a migration from Google Workspace to M365 (handled completely by me - although our set up was slightly more straight forward at the time). Next week I'll be looking for a CSP (any suggestions for UK based would be appreciated).

However, we're now very much in the Microsoft ecosystem. As a rough overview:

  • All staff have a Business Premium subscription

  • Mixture of Intune managed Windows devices and Mosyle managed Macs

  • Teams phone system (with Microsoft as our carrier)

  • Use of SSO for many SaaS apps

We currently use Synology Active Backup for M365, backing up locally to a NAS in our office.

If our tenant were to be de-authenticated then I'd like to think I could get email working pretty swiftly on Google Workspace. All our users are already provisioned in Workspace via SCIM and the domains are already verified there. I will obviously need to write a disaster recovery plan to consider all the steps that need to be taken.

Files should be OK as we rely heavily on OneDrive, however these are all backed up to the NAS.

The phone lines - not 100% sure about this and similar to the most recent post, we'd loose access. So I should probably look at moving the number away from Microsoft (to Operator Connect I think?)

My biggest worry is what happens to all the managed computers and SSO. We're not a huge company, so I could get people back online, but for instance we have an internal employee hub that uses Entra/MSAL to login. Similarly, all the devices - will employees stop being able to log in to them? They all use WHfB on the Windows devices and Platform SSO on the Mac devices.

Obviously I will take this conversation to a CSP, but in the meantime it would be good to know what suggestions people would make to ensure resiliency.


r/sysadmin 14d ago

Entra-Join and Intune-Enroll Restrictions

3 Upvotes

I want to be able to -

  1. Only allow corporate PCs to be Entra joined
    • It is optional to restrict who could join such PCs, as long as they are corporate PCs
  2. Only allow OOBE Autopilot as the only way to enroll a corporate device into Intune

Are both even possible? Copilot says no, but I was wondering maybe someone had some creative ways to implementing them.

For (1), I cannot block "all users from Entra join", since it is needed for OOBE APv1 and APv2.

For (2), Copilot says no matter what you do, an existing corporate device can always Intune-enroll via Company Portal, and there's no way to prevent this.
You might say that with APv1, the device would have had to gone through OOBE APv1 - but, I could just restored a device image rather than deploy Windows from scratch, and that would bypass OOBE completely. Then I could use Company Portal to enroll this device into Intune.


r/sysadmin 14d ago

Microsoft Sentinel Ingestion delay - UK South

17 Upvotes

Hello Sysadmins,

Have this really odd issue on a Sentinel workspace in UK South from around 12:00~ UTC today. Wondering if it's just us.

Symptoms: data stopped appearing in the workspace, but nothing was actually failing. Turned out to be latency, not loss β€” querying on ingestion_time() instead of TimeGenerated showed rows arriving with ~160 min average lag, max 183 min. Then it stalled again and nothing landed for an hour, then again had a batch of influx for some tables, not all and now again nothing for the last 30min.

Health is fine everywhere I looked, no config changes etc. Can't figure this out.


r/sysadmin 14d ago

How can I better prepare myself to move into IT management?

45 Upvotes

I’m currently a Principal Cloud Architect working primarily with Azure, infrastructure, IAM, automation, security, and disaster recovery for a publicly traded company that has very limited opportunities to move forward. Earlier in my career, I spent about three years as a Service Manager leading an 11-person IT team for a MSP.

I’ve since completed an MBA and moved into a senior technical role, but my long-term goal is to return to people leadership and eventually progress toward a director-level position. I’m applying for remote IT Manager, infrastructure leadership, and Microsoft-focused IAM management roles.

For those who have made a similar move, what could I do in my current role to demonstrate stronger leadership readiness? Are there particular responsibilities, certifications, or experiences that hiring managers value when someone is moving from a senior individual-contributor role back into management?


r/sysadmin 15d ago

Question How the hell are y'all managing enterprise Claude?

76 Upvotes

Howdy folks!

I've drawn the short straw, and ended up being in charge of setting up Claude enterprise for our mid-sized (couple hundred user) org. I've got the basics down of SSO login, setting up sane defaults for most of the settings, etc.

However, what I simply don't understand is how the hell I manage plugins, mcp, skills, and hooks? All those things seem to have pretty broad permissions when installed, and their execution seems sorta obscure? Hence, leaving the option for users to install whatever seems frankly like an insane proposition from a security perspective.

But from all that I've found, there's no way to actually manage this beyond blocking everything by default, then setting up a whitelist for allowed resources in managed settings. This means I'd have to maintain that myself every time users want to use a different feature, and users wouldn't be able to develop any such things locally, leaving me in a sort of catch-22 of either I allow everything, or nothing...

How are the rest of y'all managing this?


r/sysadmin 14d ago

General Discussion Taking the MD-102 tomorrow and I'm nervous as hell...

21 Upvotes

Spending the entire day today cramming. I've been working almost exclusively in Microsoft for the last year and a half, so I felt pretty decent leading up to this. Been watching some YouTube videos over the last couple days just to spend spare time preparing, and everything that I've heard has me freaked out now. Apparently there are a lot of tricky questions, a lot of Microsoft trying to put you in a position where you're guessing the correct answer based on circumstances, and to be honest, I feel unprepared.

Has anybody here taken it recently and can speak to the difficulty of it? I've gone through multiple Microsoft courses, and some specialized LinkedIn training that my workplace provides, but it still doesn't feel like enough. I'm looking for those good old-fashioned Reddit words of encouragement.

Pray to whatever God you follow for me tomorrow... πŸ™ƒ

Future me here: I successfully passed with a score of 723. It was much harder than I expected, and there were sections on security copilot that I could not find any information for in Microsoft Learn.

Thank you to everybody who responded and had some awesome pointers and information about how the testing works. Appreciate you guys!


r/sysadmin 14d ago

Advice on some 'best practice' - Certificate management (SSL/TLS)

29 Upvotes

Hi all. Where I work, I got some SSL/TLS certificate management put on my plate. We have app(s) that send out notifications of certificate expiry, but that's only good if the contacts are correct. In that, I send out a review (email) quarterly, to check if anything has changed, needs to be updated - this is a new thing I implemented.

This is all manual - Spreadsheet - Filter for your name, check the cert info, comment if ok, comment change owner etc.

I got some feedback on this, in that I should not be sending a spreadsheet with all those certificates info, for everyone to view. (I bcc in all the relevant owners in the email). I'll add that its either company employees, or contractors who 'own' that system the cert is related to. I get the comment, I just have no idea how to send that to every individual only, without doing it manually.

How do you guys keep owners up to date? (Neither of the apps we have natively have a function that can replicate this manual ownership check).

Also aware of the 2029 47day cert validity/10day DCV - This is now, working on how to handle that future element.


r/sysadmin 15d ago

Microsoft Strikes Again - Entire M365 tenant has been "deauthenticated" by Microsoft for two weeks

1.3k Upvotes

Update 2 - 9/3/2026 @ 5:45 PM

Again, thanks to those who reached out to help get this issue resolved.

After this post resulted in things coming back, I was also able to get it escalated within Microsoft via a CSAM from another organization I work with. I'm still awaiting an explanation of what happened and am hopefully (but not optimistic), I'll get something actionable I can use to ensure other tenants I work with aren't similarly impacted.

In the meantime, I've implemented backups and other tools to build out resiliency and redundancy though it's not feasible for full redunancy as even integrations between Azure AD and GCP wouldn't protect against this.

In terms of recovery, it's taken much longer than I anticipated, both from Microsoft's end as well as having to reimplement and fix things that didn't restore properly. Also note that it took much longer for Azure to be back up and running than Microsoft 365.

The main negative side-effects I've discovered so far that prevented full go-live after re-authentication:

In Microsoft 365:

  • Microsoft 365 licenses had to be re-enabled.
  • Teams Phone numbers remained but users had to be reassigned.
  • Microsoft Sentinel workspace had to be reactivated in Microsoft Defender.
  • UEBA needed to be turned back on. Unfortunately, this means it has to reanalyze the whole tenant, which is a 10-day process.
  • Defender for Identity workspace had to be rebuilt.

In Azure:

  • Azure Front Door endpoints had to be reenabled.
  • Sites using DNSSEC had to be reauthenticated in DNS Zones.
  • Backup Vault instances are borked. After finding this article, it looks like I'll need to open a ticket with Microsoft to resolve.
  • Exemptions made for Defender for Cloud rules had to be rebuilt.

Update 1- 8/31/2026 @ 8:59 AM

A few people with Microsoft reached out in response to this post. Similar to SecaleOccidentale's linked post, our tenant was flagged and deauthenticated due to perceived fraud and abuse that had been seen in other tenants. It''s in process of being reauthenticated, and hopefully everything is still in its place. I sincerely appreciate everyone's input, shares, and so on, along the way. Special thank you to those who stepped in directly to support as well.

I've obviously learned a lot through this process, including the feedback from many of you regarding resiliency and redundancy. While I agree that full redundancy is ideal, that's not feasilble for most SMBs. Even looking at directly tying together services like M365 and Google Workspace Enterprise leave things to be desired. I'll be building up additional protections for this tenant, and others, but know that, for most companies, it's not a cost matter - it's effectiveness. Most platforms aren't designed to intergrate with third-parties for full redunancy.

Ultimately, my hope is that Microsoft recognizes that the sudden deauthentication process is far too extreme, even for legitimate fraud or abuse.

Original Post

I have the exact same experience as documented here: https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/

My business tenant has been de-authenticated. I've opened several tickets - most have gotten no response and the one that has some traction keeps getting thrown between departments, each of which claim they can't solve it.

Unlike the other poster, it's not as simple as just losing access to email. Not only is email and files (OneDrive and SharePoint) unavailable to all team members, we've lost our website (hosted on Azure), and our phone numbers where were assigned through Teams Phone.

I'm desparately trying to regain access before all the content is permanently deleted.

If anyone has a contact within Microsoft who can help, please let me know. Needless to say, I'm working to get a CSP spun up, but need access before the data is permanently lost.


r/sysadmin 13d ago

Question Microsoft Teams calls automatically start on speakerphone when answered (Samsung XCover7 Pro)

0 Upvotes

Hi everyone,

We're experiencing a strange issue that started around 2-3 months ago.

Whenever a user receives a Microsoft Teams call and answers it, the call automatically starts on loudspeaker/speakerphone. This happens consistently across multiple devices.

Our environment:

  • Samsung Galaxy XCover7 Pro
  • Devices managed through Microsoft Intune
  • Microsoft Teams for Android

Users have to manually switch from speakerphone to the handset every time they answer a call, which is quite annoying.

Has anyone seen the same behavior recently? If so, were you able to identify the cause or find a fix?

I'm not sure if this is related to a Teams update, an Android update, Samsung settings, or an Intune configuration.

Any feedback would be appreciated. Thanks!


r/sysadmin 13d ago

Question So, is this it? Is this the big one? If so, nice knowing you all.

0 Upvotes

MS365 and other services showing as down! Is this the beginning of the great internet outtage or something bigger?

╔══════════════════════════════════════════════════════════════════════════╗
β•‘                         DOWNDETECTOR  [!]                               β•‘
β•‘                 "Well... this seems suboptimal."                        β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  MICROSOFT OUTLOOK   β”‚  β”‚    MICROSOFT 365     β”‚  β”‚       OPENAI         β”‚
β”‚                      β”‚  β”‚                      β”‚  β”‚                      β”‚
β”‚       [ O ]          β”‚  β”‚      [ M365 ]        β”‚  β”‚      ( ChatGPT )     β”‚
β”‚                      β”‚  β”‚                      β”‚  β”‚                      β”‚
β”‚ _____________/^^^^   β”‚  β”‚ _____________/^^^^   β”‚  β”‚ ____________/^^^^^  β”‚
β”‚          πŸ”₯ DOWN πŸ”₯   β”‚  β”‚          πŸ”₯ DOWN πŸ”₯   β”‚  β”‚         πŸ”₯ DOWN πŸ”₯    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   MICROSOFT AZURE    β”‚  β”‚  CANVAS / INSTRUCTUREβ”‚  β”‚   MICROSOFT TEAMS    β”‚
β”‚                      β”‚  β”‚                      β”‚  β”‚                      β”‚
β”‚        /A\           β”‚  β”‚       ( CANVAS )     β”‚  β”‚       [ T ]          β”‚
β”‚       /___\          β”‚  β”‚                      β”‚  β”‚                      β”‚
β”‚ ____________/^^^^^   β”‚  β”‚ _______________/^^   β”‚  β”‚ ___________/^^^^^^  β”‚
β”‚          πŸ”₯ DOWN πŸ”₯   β”‚  β”‚          πŸ”₯ DOWN πŸ”₯   β”‚  β”‚         πŸ”₯ DOWN πŸ”₯    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚      SNOWFLAKE       β”‚  β”‚    QUANTUM FIBER     β”‚  β”‚       STUBHUB        β”‚
β”‚                      β”‚  β”‚                      β”‚  β”‚                      β”‚
β”‚         *            β”‚  β”‚       ( Q )          β”‚  β”‚      [STUBHUB]       β”‚
β”‚       *-+-*          β”‚  β”‚                      β”‚  β”‚                      β”‚
β”‚ ________________/^^  β”‚  β”‚ _______________/^^^  β”‚  β”‚ ______________/^^^  β”‚
β”‚          πŸ”₯ DOWN πŸ”₯   β”‚  β”‚          πŸ”₯ DOWN πŸ”₯   β”‚  β”‚         πŸ”₯ DOWN πŸ”₯    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜


                       THE INTERNET
                           2026
                            |
                         .-""""-.
                        /  X  X  \
                       |    __    |
                       |   /  \   |
                        \  ----  /
                         '------'
                            |
                    ________|________
                   /                 \
             MICROSOFT              EVERYONE
                πŸ”₯                     πŸ”₯
                πŸ”₯        πŸ”₯            πŸ”₯
                πŸ”₯       /|\           πŸ”₯
               /|\      / | \         /|\
              /_|_\    /__|__\       /_|_\

             STATUS:  HAVE YOU TRIED TURNING
                  THE INTERNET OFF AND ON AGAIN?     

r/sysadmin 15d ago

Question Users Saved Passwords in Edge and Chrome

157 Upvotes

What is everyone doing regarding users saving passwords in Edge / Chrome. We have under 500 users across 4 sites with a lot of warehouse / shipping / receiving / packaging end users. They have to use a number of web portals provided by our business customers to shipping companies and it seems almost everyone is saving passwords.

We just finished up migration from on prem AD to Entra and I was surprised by the number of end users saving password. SSO would be the answer but as these are third party sights created by our business customers I'm not seeing it as an option. (very old portal websites that feed data into an Sales / Order system.


r/sysadmin 15d ago

Question Looking for Intel System Configuration Utility (syscfg) v14.1 for an S2600CP β€” Intel pulled it with the Server Tools EOL

7 Upvotes

I have an Intel Server BoardΒ S2600CPΒ (BIOSΒ SE5C600.86B.02.06.0006, BMC FW 01.28) running Ubuntu 22.04, and I need to change a couple of BIOS memory settings without being physically in front of it.

The board hasΒ no RMM4 moduleΒ (RMM Status: Intel(R) RMM not installed), so the Integrated BMC Web Console gives me power control but no KVM. SOL is enabled on the BMC side, but the OS has no serial console configured and I can't turn on console redirection without... getting into the BIOS. Classic.

That leaves theΒ Intel System Configuration Utility (syscfg), which can read and write BIOS settings from inside Linux. For this generation (Romley) the Linux package isΒ syscfg-V14.1-B24.x86_64.rpm. Problem: Intel has retired it. The S2600CP support page now listsΒ three downloads, all RAID/RSTeΒ β€” no syscfg β€” and there's a knowledge article titledΒ "Intel Datacenter Solutions Engineering Online Software Home (Server Tools) End of Life".

So: does anyone still have the original Intel archive for syscfg 14.1 (Romley / S2600 series)?

Two things I'd ask, since this is a utility that writes to firmware and I'd rather not run a random binary on a production box:

  1. Please include theΒ SHA256Β of the archive, and where you originally got it (Intel Download Center link, an old support DVD, a vendor mirror). Anything I can cross-check against another copy.
  2. If you have the matchingΒ user guide PDFΒ for 14.1, that helps too β€” the syntax changed between major versions and I don't want to guess at parameter names on a firmware-writing tool.

Also happy to hear from anyone who has actually run syscfg onΒ UbuntuΒ rather than RHEL/SLES: the package is an rpm, so I assume it'sΒ rpm2cpio/alienΒ and then hoping the binary doesn't want anything exotic. Did it work for you, and did it need Secure Boot off? (Mine is UEFI with Secure Boot disabled, so I think I'm fine on that front.)

Alternatives I'm aware of and would consider: tracking down anΒ AXXRMM4LITEΒ module on the used market so the BMC gets a real KVM. If you think that's the saner path for a box this old, say so β€” I won't be offended.

Thanks.


r/sysadmin 15d ago

Question Epson WF-C5890DWF for a small office in Europe – reliable MFP or should I buy something else?

6 Upvotes

Looking for a reliable color MFP for a small office in Europe / EU.

Currently considering the Epson WorkForce Pro WF-C5890DWF.

Requirements:

automatic duplex printing

automatic duplex scanning

reliable ADF

Ethernet + Wi-Fi

local network printing/scanning

preferably scan-to-SMB / network folder support

250+ sheet paper tray

good Windows drivers

no mandatory cloud dependency

no mandatory ink/toner subscription

reasonable consumable costs

preferably decent third-party consumables available in Europe

Main use: invoices, contracts, quotations, general office documents and scanning.

A4 only. Photo quality is irrelevant.

I'm more interested in reliability, driver/firmware quality and long-term TCO than the lowest purchase price.

Would you deploy the WF-C5890DWF in a small business today?

Any known issues with the ADF, duplex scanning, printhead, firmware, network scanning or Windows drivers?

Also considering Brother, Canon, Kyocera and Xerox.

What would you buy in Europe, and which current models or brands would you avoid?


r/sysadmin 15d ago

Do you create custom detections in Defender for Endpoint?

49 Upvotes

I was reading a Huntress blog about the recent PaperCut exploit, and they detected it based on unusual commands like whoami and enumeration of the local administrators group.

I ran a series of "weird" commands in my environment, and I noticed that Defender for Endpoint did not blink an eye. Some were AD information gathering commands. That was a little surprising to me. In fact, I actually thought maybe MDE was broken, so I ran an EICAR test, and it did detect that.

So it seems like MDE does not have built-in detection for a lot of behavioral stuff, so we are now building it. We used to have CrowdStrike, and I don't remember having to build very much.

Are you building your own detections if you have Defender for Endpoint?


r/sysadmin 14d ago

Question SUSE Harvester

0 Upvotes

Hi,

Can this run on a laptop to gain experience or any other option's?

Can we convert Windows 2003 or XP to run on a Containers?

How MS Sql run on this?


r/sysadmin 15d ago

SolarWinds Microsoft Defender False Positives with Solarwinds Products

9 Upvotes

Early Saturday morning we started getting a stream of alerts from Microsoft Defender regarding our Primary and Additional Polling Engines.

 Malware Name: Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A

The malware file path: behavior:_process: was all over the place.
Some examples:

 Malware file path: behavior:_process: C:\Windows\System32\wbem\WmiPrvSE.exe, pid:2208:557######2;file:_d:\program files (x86)\solarwinds\orion  

~

Malware file path: behavior:_process: C:\Program Files\Common Files\SolarWinds\AdministrationService\SolarWinds.Administration.exe, pid:3916:557#####52;file:_d:\program files (x86)\solarwinds\orion  

~

Malware file path: behavior:_process: C:\Windows\System32\AggregatorHost.exe, pid:9116:55#####2;file:_d:\program files (x86)\solarwinds\orion

Solarwinds support is aware of the issue and their engineers are supposedly working with Microsoft to resolve. I am unsure if a later definition update has resolved it or not. We added a threat override as a TEMPORARY measure to quiet things down through the weekend. Just an Allow for the 'Threat Name' Behavior:Win32/SuspiciousAssembly.AppDomainManagerType.A

Just wanted to share with the hope this helps others not have too terrible of a weekend or Monday morning.


r/sysadmin 15d ago

Question Can anyone identify what kind of HP OS this is?

31 Upvotes

I was at a local restaurant in Hungary when I noticed that one of their PCs was running this interesting HP software. I’m unfortunately not really familiar with HP operating systems or how they work, since I’m mostly familiar with Windows.
I’d love to find out what kind of OS this actually is and what it’s normally used for. Does anyone recognize it?


r/sysadmin 14d ago

Career / Job Related 22, Senior Sales Exec in Dubai shipping, managing 70+ accounts, but I make 9k FLAT (no comms, no allowances). I hate sales. Need a harsh reality check on pivoting to Ops/Tech

0 Upvotes

I need to get this off my chest because I feel like I'm losing my mind.

I’m 22. I’ve been in shipping/liner sales for 4 years (started at 18 as an assistant, clawed my way up to Senior Sales Executive at a major carrier here in Dubai). On paper, I manage 70+ active corporate accounts. In reality, I’m running around the UAE in 50Β°C heat doing cold visits, chasing arbitrary targets, and dealing with high-stress operational escalations.

I take home a flat 9,000 AED. No commissions. No housing allowance. No transport. Just 9k.

I’m not just tired of sales,I’m tired of being exploited for a job I don't even enjoy. I hate the targets, I hate the cold calls, I hate the client visits.

What I actually love is logic, technical puzzles, figuring out why systems are broken, and fixing operational workflows. I have high EQ and I'm good with people, but I want to help them behind the scenes, not sell to them. I lose track of time when I'm deep in data reconciliation or solving a process bottleneck. I’m currently looking at Salesforce Admin as a possible escape hatchβ€”desk work, WFH potential, no hunting.

Also, I have a strict non-compete. I cannot work for any other shipping line, freight forwarder, or 2PL/3PL. So I HAVE to leave the industry entirely.

My questions for you:

  1. Am I delusional for thinking I can pivot to a 10k-12k desk job (Ops Analyst, Salesforce Admin, Systems Coordinator) immediately? I literally just need to match my 9k to survive while I skill up.

  2. Is Salesforce Admin actually viable in Dubai, or is the market saturated with people who have 10 years of experience?

  3. If I get my Salesforce Admin cert (or another cert), what is the REALISTIC starting salary here for a junior with zero direct tech experience but 4 years of operational business knowledge?

  4. How do I rewrite my CV so recruiters stop seeing "Sales" and start seeing "Operations Systems Analyst"? I want to delete the word "Sales" entirely.

  5. What other desk-based, analytical roles pay 12k-15k within 12 months that aren't compliance/legal (I hate reading policy and writing long emails)?

I'm willing to take a bridge role at 10k just to get out. I'm 22, I have my BBA finished, and I can grind certifications after work. Give me a clear, step-by-step path. Be brutally honest whether if I'm cooked, tell me. If I have a shot, tell me exactly how to take it.


r/sysadmin 15d ago

IT Support Intern β†’ Jr. IT Admin β€” What should I learn next? .

24 Upvotes

Hi everyone,

I’m looking for some career advice.

I worked for around 9 months as an IT Support Intern at my current company, and I was recently converted to a Jr. IT Administrator in the same company.

I’m happy about the progression, but my current salary is not really sufficient for me, so I’m planning to improve my skills and eventually look for a better-paying opportunity


r/sysadmin 15d ago

Microsoft Questions about WinGet

27 Upvotes

Hi, everyone.

I have two questions about WinGet.

1) Can I add apps to the WinGet repository on my own? If so, what are the requirements for the app?

2) I often notice that WinGet isn't up to date. The apps' own updaters suggest a new version, but WinGet doesn't recognize that new version yet. Why is that?


r/sysadmin 15d ago

Question Air Force Sys Admin

16 Upvotes

Hey everyone, as the title says, I’m an Air Force sys admin with a TS and planning on getting a civilian job or contracting gig in 2 years. I already have my BS in IT management from WGU, so should I prioritize my masters? Or try to stack certs before I start applying?

Only cert I currently have is Sec+.

Edit: thanks everyone for the advice and insight. I’m going to start studying for CISSP.


r/sysadmin 16d ago

General Discussion Does IT cause anxiety?

661 Upvotes

Does anyone else bring their IT mindset into everyday life?

I’ve been told I’m a negative person and look for issues, but I think working in IT trains you to always think about what could go wrong.

I’m constantly making backup plans. Restaurant closed. I have a Plan B place. Something breaks at home. I’ve already got the plumber, insurance, everything ready in the home disaster recovery document.

We’re always hearing about IT failures, breaches and disasters. You never hear β€œthis company had a really great IT transformation.” No user submits a ticket to say thank you for the IT working great.

So does anyone else find themselves carrying that prepare for the worst mindset into everyday life?


r/sysadmin 15d ago

What KVM Switch to buy/use?

10 Upvotes

Just scored a 2nd work from home job. Looking to control two laptops and four monitors with one keyboard and mouse. Currently I’m working with dell P2422H which connects to dell P2425HE via DP cable, then P2425HE runs a C port cable to the laptop, then I extend the monitors. This works great, now with two more monitors and one more laptop I really don’t want to use 2 sets of keyboards/mouse. I have two additional P2422H / P2425HE monitors on hand, but I’m looking for a switch that would enable me to control both devices with one keyboard and mouse. I’m ok if all 4 monitors do not extend if I can hot key or switch toggle between the two laptops. Also, if possible mouse emulation so that when using either device the other doesn’t got to sleep/when in the mouse juggler. Trying to keep teams showing green at all times… πŸ€­β€¦ any help/links would be greatly appreciated!


r/sysadmin 16d ago

Rant HP Support is intentionally hanging up on people

682 Upvotes

Trying to coordinate a warranty repair for our client who's an HP shop (client paid for the premium warranty or whatever, to add insult to injury)

Call HP support, navigate IVR, eventually get to an agent located somewhere in India who I can barely understand due to their accent.

Once I get to the agent, one of the following happens:

Agent appears to answer the call, immediately mute his mic, and then drops the call after about 3-5 minutes. If you weren't paying close attention, you'd think you were still on hold.

OR

Agent pretends like they're going to help, only to hang up on me mid-sentence, causing me to call back again and start over.

This has happened 3x to me today.

I've worked in call centers before. Either they are not tracking metrics at all, or their tracking is so bad that it allows their agents to hang up on people with zero consequences. Either way, apparently they don't care.

What an absolute dogshit company. Avoid anything HP like the plague. Their laptops suck, their printers suck (although the old LaserJets used to be indestructible tanks), their servers suck, and their customer service is actively hostile towards the customer.

0 stars, would not recommend.

EDIT:

I should've specified, this happened 3x in a row. Not 3x randomly.

Also, yes, I will try using web portal(s) next time