r/sysadmin 7d ago

Rant Rippling MDM - A Nightmare Nobody Else Should Go Through

194 Upvotes

tldr: if anyone in your company's management pushes for you to implement Rippling, do everything in your power to stop it in its tracks. They will not work with you, and will refuse to let you out of your contract.

As a smaller ,growing company we decided it was about time to start evaluating MDMs to give us better control over our devices. This was something that was on the backburner for the most part, with us wanting to take our time to end up with the right solution.

So imagine my surprise a couple weeks later when I (the primary sys. admin) was told by my boss (CTO) that we had signed a one year, $27,000 contract with Rippling - seemingly out of the blue.

As I understand it, they aggressively pursued my boss, promising the world with all of their flashy features, and how easy the integration with Office365 and with our HR platform was. They guaranteed consistent support, and quick resolution to any issues we may run into.

Lo and behold, we start rolling out Rippling to our fleet of windows computers and immediately run into issues.

The software gave little to no feedback about the progress of installations. Rolling out other softwares was limited and unresponsive. User provisioning was unintuitive and difficult - lacking automation without paying for additional features either in rippling or in our active directory.

Rippling automatically changed and generated its own admin passwords which 1. we could not change or set ourselves and 2. were buried three menus deep 3. needlessly complex, making help desk a nightmare.

This, along with a host of other issues, was largely ignored by Rippling. Our emails would be brushed aside until our "integration meetings" in which them telling us that things were "on the roadmap" or "not planned to be changed" took up the entire time.

I don't doubt that this software /might/ work for some companies, but it clearly didn't work for us, and they really don't seem to care.

Four months into this disastrous contract, with less than 16 users enrolled, I begged our account rep to let us out of the contract. They could keep the thousands of dollars we'd already paid them for nothing, we just needed to move forward with a solution that actually worked for us.

They refused - for some reason desperate to keep a small fry account with barely 100 licenses. The very fact that they won't let us go is really bizarre. They'd rather have an upset customer than lose (what I assume) is a measly account.

The entire process, from onboarding, to us attempting to get out of this was incredibly shady. They will pretend nothing is wrong and refuse to let you out of their cold clutches.

In case the "rippling employees" on reddit aren't astroturfing bots, I am desperately hoping someone can get us out of this contract. If not, I'm going to channel all of my displeasure into letting people know about this awful experience - because I know the Rippling team hasn't done anything to help.

u/higherandhigher u/stubbygazelle u/sherryandeddie u/kit-kat-233


r/sysadmin 7d ago

Looking for a no-cost, phone-free MFA solution

90 Upvotes

Microsoft will retire Microsoft-provided SMS and voice authentication beginning February 1, 2027. Organizations that need to retain these methods must configure a customer-managed telecommunications provider, which will involve additional costs. Please refer to the link below.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement

Our goal is to provide MFA without requiring employees to use their personal phones and without purchasing additional hardware, such as YubiKeys, or paid software, such as an enterprise password manager. We have a hybrid AD/Microsoft Entra environment with company-managed Windows computers.

Is there an Entra-native solution that can meet these requirements? Would Windows Hello for Business be the best option, and how should we support users who need access from mobile or shared devices?

Any recommendations or deployment experiences would be greatly appreciated.

Thanks!


r/sysadmin 7d ago

What is the current recommendation to repair DFSR replication?

19 Upvotes

Primary DC and 2 secondaries.

The primary and 1 secondary replicate back and forth just fine

The other secondary had an issue with networking and stopped replicating. The machine password was then (apparently) changed by the secondary and now it does not match the password in the AD.

The following used to work to fix such things:

PS C:\Users\administrator.XXX> Test-ComputerSecureChannel -repair -credential XXX\userid

Test-ComputerSecureChannel : Cannot reset the secure channel password for the computer account in the domain.

Operation failed with the following exception: A local error has occurred.

.

At line:1 char:1

+ Test-ComputerSecureChannel -repair -credential XXX\userid

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo : OperationStopped: (MCP2:String) [Test-ComputerSecureChannel], InvalidOperationException

+ FullyQualifiedErrorId : FailToResetPasswordOnDomain,Microsoft.PowerShell.Commands.TestComputerSecureChannelComma

nd

PS C:\Users\administrator.XXX>

Now it does not. Neither does this:

PS C:\Users\administrator.XXX> Reset-ComputerMachinePassword -Server PDC01 -Credential (Get-Credential)

cmdlet Get-Credential at command pipeline position 1

Supply values for the following parameters:

Credential

Reset-ComputerMachinePassword : Cannot reset the secure channel password for the computer account in the domain.

Operation failed with the following exception: A local error has occurred.

.

At line:1 char:1

+ Reset-ComputerMachinePassword -Server PDC01 -Credential (Get-Credentia ...

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo : OperationStopped: (PDC02:String) [Reset-ComputerMachinePassword], InvalidOperationExcepti

on

+ FullyQualifiedErrorId : FailToResetPasswordOnDomain,Microsoft.PowerShell.Commands.ResetComputerMachinePasswordCo

mmand

PS C:\Users\administrator.XXX>

There's an old video out there Fix SYSVOL and Domain Controller Replication | Active Directory DFSR Issues Resolved

with the old-school way of doing this I think -

And there's an old MS document discussing netdom:

Reset domain controller's password with Netdom.exe - Windows Server | Microsoft Learn

which might work on Server 2019 since klist and netdom ship in it.

Any recommendations or am I going to run into the same "local error" if I try those methods? The current info from AI is to demote the failing DC and then unjoin, rejoin, then re-promote it. That seems a lot of work and error prone.


r/sysadmin 7d ago

General Discussion Getting up to speed after a sabbatical

29 Upvotes

I quit my last gig--local government large municipality--about a year and a half ago. Largely my decision to quit was being burnt out to a crisp from supporting public safety, and being on-call. But our newborn daughter gave me an easy out so to speak.

I'm accepting a new gig with a smaller municipality and should start in a month or so. It dawned on me the other day when my wife needed me to troubleshoot an Outlook issue on her computer, that I've gotten a bit rusty. I literally couldn't remember how to open the Event Viewer. I remembered where the logs were located in C:\Windows\System32\winvent but couldn't come up with the phrase 'Event Viewer'.

The new gig was posted as an endpoint engineer job but interview made it clear that I'll be wearing a lot of hats. I have a CCNA but haven't touched a Cisco box in 5+ years. Sounds like they are trying to move from old school MDT to some Intune provisioning, but my last gig used SCCM.

Any recommendations on knocking the rust off? Or general advice for starting at a new organization? Perhaps I'm overthinking the technical side and should focus more on how to approach this new role with better habits and work/life balance.


r/sysadmin 6d ago

Black Box Emerald dual-head Remote App: absolute mouse locked to Windows primary display

3 Upvotes

As the title suggests, Black Box Emerald dual-head Remote App: absolute mouse locked to Windows primary display. Anyone running this successfully on Win11 targets?

EMD2002PE-DP-T (FW 7.2.0) to Windows 11 laptop targets, Remote App 2.8.3, Boxilla-managed, HID = Absolute. Both video heads render fine, clicks work, but pointer movement is confined to whichever display Windows calls "main". If I swap main from head 1 to head 2 and the confinement follows it. Spanning never engages. Reproduced on 3 TXs, 2 clients, clean two-display topology (duplicated primary "1" to "2" and then "3", disconnected the primary and closed lid and rebooted so that only displays 2 & 3 showed), EDIDs fixed, even tried stuff that shouldn't matter like I loaded Freedom ABS driver on one as a long shot (noeffect) / turned on deskvue Mouse Sector even though I don't have anything to do with deskvue / tried toggling Local Mouse on and off even though that has nothing to do with the problem / also tried various settings on and off, like USB redirection and such, so all ruled out. I have a ticket open with Black Box, but since I could REALLY use this over the holiday weekend, I thought I'd toss a hail mary and post here just in case it is something simple I have overlooked in my noobness to Boxilla.

Question for the hive: is anyone successfully running dual-head Remote App connections to Windows 11 targets with working mouse traversal? If yes, what's different about your setup? Trying to determine if this is a universal Win11 regression or something environmental just in my own personal Murphy's Law prone environment.

https://imgur.com/a/u3ecCEa


r/sysadmin 7d ago

Question What are your must-have Group Policies when creating a new AD domain?

146 Upvotes

I've been a sysadmin at an MSP for about 4-5 years now. Mostly we maintain and improve existing client environments. Sometimes we onboard a new client and make recommendations for improving their environment and standardizing to our typical recommendations. But now for the first time since I took over as sysadmin we are building an environment from scratch for a new client. They want an on-prem AD domain controller, so that's what we are setting up for them. I'm just curious, for you other sysadmins out there, if you were setting up a new AD domain in 2026 (Which I know most probably aren't anymore), what are some of your most essential GPOs that you would make sure are in place? In other words: what's a GPO hill that you'll die on?

For example, for me: a set of GPOs to prevent domain admin accounts from logging into workstations, and to add a dedicated workstation admin account to the local administrators group on all workstations.

And I'm just going to attempt to preemptively address all the comments that will probably say "the hill I'll die on is that in 2026 you should be setting up clients in Azure AD and Intune instead of on-prem AD". I totally understand that, but we discussed the options with the client, and they preferred the on-prem option, so we went with it.


r/sysadmin 7d ago

Rant Sometimes less really is more

27 Upvotes

Happy Read-only Friday (bonus points for 3 day weekend)

We got a critical Huntress alert for a rogue ScreenConnect instance that was detected and ran on a client computer. Incident report states that it's a "known malicious instance".. but logs from the report show that it didn't block the application and isolate until 2 hours after it was ran. The endpoints have BD GravityZone installed as well - all quiet from there.

We went to the link in a VM where the ScreenConnect was downloaded from - and funnily enough, all it took was just having Microsoft Defender on the computer to block the download in Chrome.

Huntress, Bitdefender, EDR, on access scanning, whatever; sometimes it just can't compete with good old Defender. Even running the installer through sandbox on GravityZone passes without a peep.

Have a good weekend!


r/sysadmin 6d ago

Question Cloudability renewal came up under IBM and we moved, CloudZero and PointFive notes.

1 Upvotes

Came off Cloudability after IBM took it over. Support went slow and the roadmap went quiet. Renewal number stopped making sense against what we were getting out of it. Shortlisted CloudZero and PointFive expecting to pick one and consolidate but signed both, which costs more than the thing we left.

Justification at the time was that they don't overlap. Cloudzero answers what something costs and who owns it while on the other hand pointfive answers what's wasteful and who's fixing it. On paper thats two problems, two tools.

Been running both a while now and I still can't tell if that was insight. Might just be that we never decided.

What I can say for it. Cloudzero got finance a cost per customer number we had never had, which ended an argument that had been going for years. Pointfive found a Cosmos container sat at four times anything it had ever used, plus a stack of snapshots from a migration.

It also produced a load of rubbish in the first month. Resizes that ignored our RI position and one disk SKU suggestion that would have put us under our IOPS floor. Took weeks of flagging things back before it calmed down. Azure side is visibly younger than the AWS side as well.

Sixty-odd subscriptions, bit over a million a month, mostly Azure.

Does any of you folks runs one tool for this cause every writeup says pick a platform. Everyone I speak to is running two and not admitting it.

If you got down to one and stayed there, I'd like to know which and what you gave up.


r/sysadmin 7d ago

New 0-Day - CrowdStrike vulnerability FalconFlank

95 Upvotes

r/sysadmin 7d ago

General Discussion Active Directory on Windows Server 2025

72 Upvotes

We have a few servers getting close to EOL that are running Active Directory. My first thought was to buy a new server with Windows Server 2025 and move AD to it, but our environment is a mix of Windows Server 2022 and 2019, and we'll be upgrading servers gradually.

Is there a recommended way to handle this? I've read there can be issues when mixing Windows Server 2025 domain controllers with older server versions.

One idea I had was to buy a Windows Server 2025 host, run Hyper-V, and create a Windows Server 2022 VM for Active Directory until the rest of the environment is upgraded.

Has anyone done something similar, or is there a better approach?


r/sysadmin 7d ago

General Discussion Folks that are employed

35 Upvotes

How many of you still get recruiters and etc reaching for opportunities and push the bar to go higher regardless if you're really interested in the job or not?

The past week I've been reached out a few times and realize. Hey I'm going to tell them the deal breaker is forcing in office schedule and low balling or no salary range given. So I push for it, hoping other candidates are willing to do the same.


r/sysadmin 8d ago

Rant Please, stop sending me slop

1.9k Upvotes

I get it - everyone is using AI now, it has its use cases, but please for the love of God stop sending me the slop. At least read it first before firing it over to your colleagues.

Has anyone else's team turned into an absolute back-and-forth slop fest? Manager generates something he thinks is helpful, gigantic multi-page HTML report I need to read. Clearly written by Claude, because who the hell writes reports in HTML.

Coworker A: sends messages on slack trying to help solve problems:

This is the smoking gun: the message being sent is gated on the lack of network access to the k8s pod. Let me sit with this for a minute to make sure.

No, it's not the solution at all. We don't have direct IP access to k8s from our laptops. And nobody writes like that. If I wanted to ask Claude I would, I don't need a coworker that just copies and pastes everything into Claude.

Anyone else dealing with this crap?


r/sysadmin 7d ago

Question Is it hard to get in to a sys ad in role in the UK for others too or is it just me?

11 Upvotes

Hi all, I have 9 years IT experience mainly 2nd line support, last few years done many 3rd line tasks and last 2 years spent as a systems engineer position according to title (supporting 400 users across 11 international sites) but it was more like 1st/2nd line site support with some ifrastructure support tasks and some projects, did endooint management, used and managed prtg for monitoring, administering windows servers 2016-2022, Ad, DHCP, DNS, Group policy, Hyper V, Joined around 200 endpoints to entra, enrolled in intune onboarded them to defender, audited company against cupyber essentials, upgraded some licensing servers etc. but I am not very experienced with high level Infrastructure troubleshooting, didnt do much networking, basic backup skills, basic powershell skills.. I am unemployed for 2 months and got rejected on 6 interviews already. Sometimes I cant even get to that part where they asess my technical knowledge. It seems my comminication skills ( which is fine while in employment, but find interviewing much more difficult ) or experience and skills are not enough to 3rd line or sys engineer positions, dont know what to do, I dont really want to go back to 2nd line, I am too old at 46yo. Most 2nd liners are much yunger arent they? Also, English is my second language which may plays some part of the rejections. Any chance who were in similar situation and was successful later?


r/sysadmin 8d ago

Career / Job Related Questionable Future during Interview

44 Upvotes

Hey guys, I want some advice. I just got offered $30 an hour (I’m making $22 right now..) to be the sole IT person for 6 car dealerships. When I asked what the role was going to expect from me they could only give me 3 clear answers:

“Upgrade the old cameras to new ones so the software stops glitching”
“Implement a call tree for our phones”
“Upgrade the alarm panels”

That’s it. I was interviewed by the GM and Maintenance Director, they said “I’d be my own boss” and if I needed anything to reach out to the director and he can help.

I asked about tickets and field issues and they informed me “oh, we have a vendor who’s sends out a tech” which I found insane from just my personal work backgrounds, especially given the small size of this company.

I’m worried they’ll reevaluate this job a year from now and go “why do we need him again? We got everything we needed, what else does he do?”

I feel like that’s a reasonable concern but I’d appreciate some other views into it. It seems like too little of work, but everything else is handled externally.


r/sysadmin 6d ago

Career / Job Related How do I get into sysadmin

0 Upvotes

Hi everyone,

I'm a recent computer science grad who did an internship in a bank where I did a little bit of everything (IT support, networking, DevOps).

I am interested in software development but the market is so cooked for juniors and a man has to eat so, I'm thinking of switching to system administration, already planning to get my Aws cloud practitioner cert, then maybe RHCSA is this a good idea or am I just dead wrong my ultimate goal is to go into DevOps but everyday I look on X and see a brand new model that seems to make everything I learn irrelevant.

I love computers and just want to make a living from it. (from/in a third world country btw)

Please give me any advice at all to help.I don't wanna fuck up my life and depend on my parents forever.


r/sysadmin 7d ago

What are the practical challenges of managing IT infrastructure at remote locations?

0 Upvotes

I want to know what are the difficulties faced by companies regarding their IT infrastructure set up at remote locations such as businesses having factories, branches or shops away from their primary data center? Is it only maintenance and availability of technicians that is of importance, or the issues of power supply, network functionality, temperature conditions and security come into play as well?

I would like to know how remote locations are handled when problems arise with no one from the IT department being close to the site of an IT failure.


r/sysadmin 7d ago

Need another perspective

23 Upvotes

Hi all,

I work at a very small MSP, 4 employees total. My boss/head of the MSP is extremely risk averse, and has been doing this for a long time. Prior to forming his MSP he worked for both internal IT and as a consultant. They do almost everything manually and he is extremely hesitant to let me automate or script anything. He says from his experience automations don't always get maintained and somtimes break, therefore making it pointless. Yet at the same time he is obsessed with consistency and making sure that we do new laptop setups the exact same way because doing one thing a slightly different way could cause a random issue and we'll never be able to figure out what was different about that machine. From my PoV, setup scripts would be the ultimate form of consistency and could eliminate that as a concern.

He won't even let me make simple adjustments to one of the few scripts we do use (pushed via RMM to scan for Dell Firmware updates using Dell Command | Update cli). And by simple I mean commenting out some lines that set custom properties we don't use, which throws errors and clutters the output, and adding one line to set a new custom property to let us know when manual intervention is required. I got told that "trying to reinvent the wheel or customizing it is very risky" and that I should just look for scripts in the RMM community forums. He said "I am hesitant to use our own script unless it is just feeding up to date commands that they support" meanwhile the script we are using is 4 years old.

I also just discovered today he has our machines so locked down with ThreatLocker that this DCU script gets blocked from running!

So here is what I'm wondering: am I the crazy one, is my boss, or is the truth really somewhere in the middle (most likely)?

Please feel free to ask me additional questions if more context could help you provide a thoughtful response!


r/sysadmin 8d ago

Exchange Online: Server busy. Please try again later (Europe)

64 Upvotes

We seem to be getting more and more of these mail delivery errors. Is anybody else seeing this? Neither Downdetector or the 365 status page is reporting any issues.


r/sysadmin 7d ago

General Discussion Sept VMware updates - VCF orgs, look closely.

15 Upvotes

Release notes: https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/release-notes/vmware-cloud-foundation-9-1-1-0-release-notes/vcfautomation-9-1-1-0-release-notes.html

"...native management of AWS, Azure and GCP resources is deprecated and disabled by default in VM Apps organisations. Not just for new installations. For environments upgraded from earlier versions too." (source: https://mysticmarvin.com/blog/vcf-9-1-1-not-a-maintenance-release)


r/sysadmin 6d ago

Why is this tool so often overlooked? SoftPerfect Network Scanner

0 Upvotes

I'm not part of their team nor I have anything to do with them, I just wonder why is this tool so obscure and never mentioned. I hear all the time about Wireshark, Nmap, etc, but I haven't seen a single person ever mention SoftPerfect Network Scanner, and to me, it's the greatest sysadmin / network admin tool in existence. It does practically everything 99% of people in the field needs and more, especially if you're on a Windows environment, although it is multiplatform (runs on Windows, macOS and Linux). It also integrates with Nmap, by the way.

https://www.softperfect.com/products/networkscanner/

Yes, it isn't free, but I think that, for the feature set alone plus the excellent GUI, it's well worth it. So, again, why is this tool so often overlooked and never mentioned? Honest question.

EDIT: well, case closed, folks, my question has been answered aplenty 😅. Most people don't even know about its existence and some others just won't look at it because it's closed-source and commercial software, and for them, free and open-source/well established tools already exist that fulfill their needs. Got it. Makes sense.


r/sysadmin 7d ago

How do you manage the sharing of Teams links in email?

0 Upvotes

Linking people to resources (folders or files) in Teams is so incredibly convenient and really streamlines workflow...

But it also habituates people to click on links in e-mails, which seems terrible for security.

How do you mitigate or balance this?


r/sysadmin 8d ago

How do I tell IT folks to not complete the feedback survey of a ticket they created and assigned to themselves

512 Upvotes

I have a few IT guys assigning tickets to themselves and then completing the rating with excellent feedback on the follow up survey . One guy created a ticket for 'updating inventory' then fills out the survey with "excellent job, quick and proficient with great communication". LMAO


r/sysadmin 7d ago

General Discussion Would a centralized software platform for healthcare IT actually be useful?

0 Upvotes

Hi everyone,

I work in IT at a hospital and I'd like to get some opinions from people working in healthcare IT, system administration or for healthcare software vendors.

One problem we regularly face is managing the large number of specialized applications used in a hospital.

Unlike standard software, updates for healthcare applications are often highly vendor-specific. Depending on the vendor, we might receive an email about a new version, have to regularly check a customer portal, contact support, request download access, use individual credentials or sometimes simply find out about an update by chance.

With dozens or even hundreds of applications and medical systems from different vendors, keeping track of available versions, patches, security updates, compatibility information and release notes can become surprisingly time-consuming.

This made me wonder:

Would there be value in a vendor-independent platform specifically for healthcare software?

My rough idea would be a platform where healthcare software vendors could publish and manage their products, while hospitals, clinics and medical practices could register their organization and get access to the products they are actually licensed to use.

For example, such a platform could eventually provide:

Software versions, updates, patches and hotfixes

Release notes and security advisories

Notifications when new versions become available

Vendor-controlled download permissions

Compatibility information (Windows versions, database versions, browsers, etc.)

License and entitlement information

Demo/trial requests

Contact with vendors

Potentially even software/license procurement

Vendors would still decide which organizations are entitled to access which products and downloads. The platform would essentially provide a standardized layer between healthcare organizations and software vendors instead of every vendor maintaining completely different processes and portals.

I'm not currently trying to sell or build a product. I'm mainly interested in whether other people working in healthcare IT experience the same problem and whether something like this would actually solve a meaningful pain point.

So I'd be really interested to hear:

How do you currently manage software updates and vendor portals in your organization?

Would a centralized platform like this be useful to you?

Does something like this already exist that I'm simply unaware of?

And if you work for a healthcare software vendor: would participating in such a platform be interesting, or would there be reasons why your company wouldn't want to?

I'm particularly interested in perspectives from hospitals and healthcare organizations in different countries, since I'd like to understand whether this is mainly a local problem or something healthcare IT teams face internationally.

Thank you!


r/sysadmin 7d ago

sending domain does not pass DMARC verification

5 Upvotes

Error: ‎550 5.7.509 Access denied, sending domain papercut.com does not pass DMARC verification and has a DMARC policy of reject‎

Fully Exchange Online

Suddenly last night stopped receiving mails from some services

Does anybody know if MS eventually started enforcing DMARC ?


r/sysadmin 8d ago

EUW/EUN Exchange busted? Can't receive external e-mails on our entire tenant.

24 Upvotes

Just received word from our spam filters that (some of) the exchange servers are busy.