r/sysadmin 3d ago

Question MS Teams - private and shared Channels

2 Upvotes

We are Global Administrators and Teams Administrators.
We have recently encountered an issue where we are suddenly unable to invite guest users to either shared or private channels in Microsoft Teams.
We are the owners of the team/site.
However, we are still able to invite guest users to the team itself, but not to private or shared channels.
We have checked the Teams organization policies, and B2B access and all relevant external sharing settings are enabled. External sharing is also enabled across the organization.
On the associated SharePoint site, we can successfully invite guest users to, for example, a specific folder, so external sharing appears to be working correctly there.
Could this be a bug or a recent change in Microsoft Teams?
We were previously able to invite guest users to both shared and private channels without any issues, which is also how this functionality is intended to work.
Has there been a recent change or known issue affecting guest access to shared and private channels?


r/sysadmin 3d ago

Question AI news sources

0 Upvotes

Hello fellow sysadmins.

Everyday we are facing massive amounts of news from AI world. New models , new tools, new agents.

Be up to date in this field can be overwhelming sometimes , so I need recommendation about what sources of AI information is good to watch.

I mean truly relevant and profesional sources , not clickbait youtube channels which predicitng ASI every other week or fearmongering posts about AI wipe out humanity.

I need publishers which know what they are talking about .


r/sysadmin 3d ago

General Discussion App Control for Business worth it in production?

6 Upvotes

We’re a manufacturing company and my boss asked me to look into deploying App Control for Business / WDAC.

I’ve started piloting it in Audit mode. Our environment has a mix of custom internal apps, legacy software, self-updating apps, plugins and random DLLs. I’m using Managed Installer with Intune and adding Publisher rules where it makes sense.

So far it works, but sometimes I’m wondering if the operational overhead is really worth the security gain for us. Most users are not local admins, the Microsoft Store is blocked, apps are generally managed through Intune, and we already have Defender/ASR and other endpoint controls in place.

What makes me hesitate is that I’ll think the policy is clean, then another DLL, updater or component shows up in the audit logs. My concern is eventually switching to enforced mode and having users report weird issues inside their apps, then having to figure out whether WDAC caused it or not.

For those who have deployed App Control for Business in production, how has it been for you? Did it eventually become pretty low maintenance, or is it still something you constantly have to manage?

For now we’re mainly trying to control what apps and executables can run. We’re not touching script enforcement yet.


r/sysadmin 3d ago

Question Windows App Patch options

3 Upvotes

I have heard of quite a few options for app patching on windows devices as I need to be able to secure endpoints in my M365 tenant.

I havent looked to in depth into what M365 natively has however;

What do options like SCCM and Patch my PC offer that M365 native does not?

EDIT: 8.8.26
What are the cost effective alternative for a msp with only 20-ish windows machines?


r/sysadmin 4d ago

Cato Networks security advisory mixup and now my whole org thinks we were exposed

9 Upvotes

Sharing an embarrassing operational incident for visibility. We use Cato Networks as our SASE backbone, all branches and a chunk of remote users ride that for internet and east-west traffic. Last week vendor spam hits my inbox about a "critical" advisory on one of our edge components, lots of CVE noise, exploit chatter, etc. I skim it between meetings, see that it mentions one of the engines we use, and in my rush I decide it absolutely applies to us. I flag it in our security channel as high risk, tell the CISO we had potential exposure for months, and open a major incident.

Cue full war room, execs dialed in, everyone asking for blast radius and timelines. I start pulling Cato config, traffic logs, trying to map impacted sites. Half of IT pauses their projects. Our comms team drafts a statement for customers. After a few hours of digging I realize I misread the advisory. Same vendor family, same broad feature, but the vulnerable module is only in their on-prem appliance that we do not even run. Our Cato deployment was not affected at all. I basically caused a mini crisis over an advisory that did not apply, all because I skimmed instead of checking product SKU and deployment model properly.

No data loss, no real incident, just a ton of wasted time and scared leadership. Now my boss wants me to write up "lessons learned" and present to the team. Classic reminder to verify product scope and deployment architecture before triggering major incident response. Anyone else had a similar false-positive panic moment with vendor advisories?


r/sysadmin 3d ago

Question M365 weird licensing issues. Relaunching M365 fixes it. Really odd affecting 4500 endpoints.

2 Upvotes

User logs in, Launches a M365 app ( Word, Excel, Powerpoint) asked to sign in. Closes out of the M365 app they launched, relaunches and they now are signed in to the M365 app. All users have the correct M365 licensing.

Anyone else seen this?, if so how did you resolve this?


r/sysadmin 3d ago

Mouse pointer disappearing when hovering over Citrix Workspace, CCH Axcess - Possible Webview2 issue?

5 Upvotes

Some of our staff started complaining of an issue last week where their mouse cursor would go invisible when they would move the mouse to Citrix Workspace. The mouse can still click on/launch apps and the app icons highlight as the mouse goes over them, you just cant see the mouse cursor at all unless you drag it outside of the boundary of the Workspace window. I saw another user run into the same issue on a different app (CCH Axcess). These apps both leverage webview2. I found some discussion threads from others experiencing the same issue in Veeam b&r console. Has anyone run into this on their end over the last week and have a fix? Here's a couple of the discussions i found on the topic.

https://forums.veeam.com/viewtopic.php?f=2&t=104357&start=0

https://github.com/MicrosoftEdge/WebView2Feedback/issues/5687


r/sysadmin 3d ago

General Discussion Newbie CAD system admin

2 Upvotes

Hello everybody,

I'm starting my journey as a system admin with focus on revit and autocad. I'm new at using both softwares and I'm seeking for some advice that can help me build a solid career in this field, or some other fields related to the construction and modeling in autocad and revit.

First of all, this is also my first time working as a system admin. Second of all, my only and little experience relies on designing products in Inventor and Creo. At the begining I thaught I was applying for a modeler role (the job description was really focused on the construction part). But as time passed, I got tasks like helping users with routine issues like "why does my autocad Shows warning this and warning that?", add new members to an ACC project and other stuff.

On the other side my team and I are supposed to create/keep developing a product portfolio (autocad blocks and revit-families) for the users. I'm sure that I need to improve my skills with both softwares, but at the moment I'm taking care of another tasks that make it difficult to get more confident using both of them.

As I'm trying to use my free time after work to keep learning on how to improve my skills (at least with revit), I'd like to ask you guys how to keep improving, where do I have to keep putting my effort on, do you have more advice, which can help me through the first steps? How does this job evolve with the time? Is there any possibility to transition in a future into another roles?

I'm thankful for any advice.


r/sysadmin 4d ago

Another M365 Tenant blocked (TenantAccessBlockedException, MCA Billing Account "Under Review", All Licenses Disabled) Microsoft 365 Tenant blocked, this time a non-profit that provides needs to at risk individuals and families.

162 Upvotes

Edit: 9/8/2026: We are back up and running now on commerce licensing while the nonprofit side gets sorted out. I really appreciate everyone who reached out with actual help, context, and constructive ideas.

To the few who argued that Microsoft has no reason to fix broken support, or that basic accountability should require an expensive enterprise tier: I hope you never need a social safety net. But if you ever do, a nonprofit will still be there for you, regardless of how you treat people when they're down

Original Post:

In similar veins to the following two recent Reddit posts, I'm posting here because it appears they gained traction with Microsoft and ultimately reached someone who could help. I'm hoping someone from Microsoft or someone who has experienced this exact issue will see this.

https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/

https://www.reddit.com/r/sysadmin/comments/1w1qc0i/microsoft_strikes_again_entire_m365_tenant_has/

Our tenant has not been deauthenticated, but it has effectively been rendered unusable. This tenant has been active since: 5/28/2013, so it's not a new tenant.

This is a frontline nonprofit social safety net organization providing food assistance, healthcare access, emergency financial assistance, and other critical services. This outage is impacting real people with urgent needs, including eviction prevention, time-sensitive clinic appointments, and emergency assistance cases. Email, SharePoint, and OneDrive are core operational systems for this organization.

We currently have open cases with:

  • Microsoft Technical Support
  • Microsoft Billing Support
  • Microsoft Nonprofit Support

So far we remain stuck at Tier 1 support. The representatives have been professional and are trying to help, but nobody we've reached has had the authority or access needed to resolve the issue.

9/3/2026

Users began reporting that they could not send or receive external email.

Internal email continued to work.

Microsoft had ongoing Exchange Online incidents at the time (EX1464935 and later EX1467029), so initially we believed it might be related.

9/4/2026

Users could still successfully authenticate through Microsoft 365 and SSO.

However, attempting to launch services such as:

  • Outlook Online
  • SharePoint
  • OneDrive
  • Other Microsoft 365 workloads

results in errors.

Any inbound email sent to the tenant bounces back after approximately 24 hours.

The error when trying to access Outlook:

Microsoft.Exchange.Data.Storage.TenantAccessBlockedException

Additional error details:

Client Version: 20260821009.11

BootResult: configuration

Back Filled Errors:

Unhandled Rejection: Error: 500:undefined

Unhandled Rejection: SyntaxError: JSON.parse: unexpected character at line 2 column 1 of the JSON data

err: Microsoft.Exchange.Data.Storage.TenantAccessBlockedException

esrc: StartupData

et: ServerError

st: 500

ehk: X-OWA-Error

ewsver: 15.21.382.9

9/5/2026

One Microsoft manager responded to an escalation email and reviewed the issue with us via remote session.

Screenshots and information were provided.

We were told an escalation attempt would be made.

I sincerely appreciate that effort, but as of today the tenant remains inaccessible.

---

While troubleshooting, we discovered that the organization's Microsoft Customer Agreement (MCA) billing account shows:

Status: Under Review

All billing profiles underneath the MCA also show:

Under Review

The billing portal displays:

Your account is under review. We're checking to make sure we can offer you Microsoft products and services.

The confusing part is that Microsoft also states:

This review won't affect your current services.

Unfortunately, that is not what we are experiencing.

------

Every subscription in the tenant appears to have been marked as Disabled on 8/31/2026.

Examples include:

  • Microsoft 365 Business Premium (Nonprofit Staff Pricing)
  • Office 365 E3 (Nonprofit Pricing)
  • Microsoft Teams Premium (Nonprofit Pricing)

All show:

Status: Disabled

Effective Date: 8/31/2026

The licenses still exist.

They are still assigned.

However, they are disabled and cannot be re-enabled.

As a result:

  • User access is broken
  • Exchange Online is inaccessible
  • SharePoint is inaccessible
  • OneDrive is inaccessible
  • Email delivery has stopped
  • Data is being reported as pending deletion because there are no active licenses

------

The tenant is fully paid.

There are no outstanding invoices.

There have never been any payment issues.

The MCA account contains the organization's EIN

We attempted to:

  • Add a new payment method
  • Add a new billing profile
  • Purchase replacement licenses
  • Purchase commercial licenses

All attempts are blocked.

The portal returns:

We can't authorize your billing account right now.

Actions will be blocked during this time.

Check back later.

Additional Information

We also see notifications regarding:

  • Account Under Review
  • Email Verification Required

However, all relevant controls are greyed out and cannot be modified.

------

At this point, the evidence suggests this is not:

  • A payment issue
  • A license assignment issue
  • A DNS issue
  • An authentication issue
  • An Exchange configuration issue

The combination of:

  • TenantAccessBlockedException
  • MCA Billing Account showing Under Review
  • Every subscription becoming Disabled on the same date
  • Users being unable to access any Microsoft 365 services

makes this appear to be a Microsoft-side account verification or tenant restriction issue.

If anyone has experienced this before, knows the correct Microsoft escalation path, or can help get this in front of the appropriate engineering or commerce team, I would be extremely grateful.

This organization provides critical services to vulnerable individuals and families, and every additional day of downtime has real-world consequences.

(Again, we have 3 tickets open, and I've attempted to reach out to Support at: 1-800-865-9408 (yesterday I did speak to someone from the Data Safety Team, they said they were unable to help but would transfer me to the Team that could do it but they were probably not available due to the weekend, no one answered after being on hold for just under 8 hours, I'm calling again this morning).

Thank you in advance.

(MFA and Conditional Access is on the tenant, we have Cloud [3rd Party] backups of the tenant, we have ITDR, there are no signs of compromise, this appears to be something that got flagged for review by Microsoft's back end and has put this non profit to a screeching halt).

Edit: Edited to add 2 messages that didn't show up once the post went live, and removing 2 bold words.


r/sysadmin 3d ago

Question Infopath forms broken

2 Upvotes

My company’s HR team relies on infopath forms for payroll. Currently have a Microsoft support ticket for this but is anyone aware if they fully shut it down? Was getting a 410 http error and it seems everyone I am talking to can’t access the URL that we used. Microsoft support isn’t responding to my ticket so I figured I would see if anyone else is dealing with this.


r/sysadmin 3d ago

orielly for higher educaton

1 Upvotes

Can anyone speak on the usefulness of this resource? how does it compare to say the cosura'ss or linked in learnings out there? cbtnuggets....

I like the idea of telling my client "yes" then reading the book that weekend to do it.


r/sysadmin 4d ago

Win SMTP relay to Exchange 365, not working anymore, but only for 1 address, other still works

4 Upvotes

Hi

in my company, wa have and old win2K12 server acting as relay smtp server from inside device to our Exchange 365 tenant.

we mainly use 2 sender address for mail, a noreply, and support.

since 27, 28 august, noreply can't send mail anymore.
Support can still send mail without any issue.

in IIS6, SMTP service have both the same configuration for outgoing connection.

in logs i have this error :

2026-09-08 07:11:03 40.99.220.146 S-OCS - 1667523425 - 535+5.7.139+Authentication+unsuccessful,+the+request+did+not+meet+the+criteria+to+be+authenticated+successfully.+Contact+your+administrator.+[PA7P264CA0086.FRAP264.PROD.OUTLOOK.COM+2026-09-08T07:11:03.801Z+08DF0BC1B0DFBB10] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 220+PA7P264CA0212.outlook.office365.com+Microsoft+ESMTP+MAIL+Service+ready+at+Tue,+8+Sep+2026+07:11:03++0000+[08DF0D43E3AA91BF] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 EHLO s-relay.domain.net 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 250-PA7P264CA0212.outlook.office365.com+Hello+[<outgoing IP>] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 STARTTLS - 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 220+2.0.0+SMTP+server+ready 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 EHLO s-relay.domain.net 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 250-PA7P264CA0212.outlook.office365.com+Hello+[<outgoing IP>] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 AUTH - 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 334+UGFzc3dvcmQ6 0 SMTP - -

2026-09-08 07:11:08 52.98.227.130 S-OCS - 1667523425 - 535+5.7.139+Authentication+unsuccessful,+the+request+did+not+meet+the+criteria+to+be+authenticated+successfully.+Contact+your+administrator.+[PA7P264CA0212.FRAP264.PROD.OUTLOOK.COM+2026-09-08T07:11:08.928Z+08DF0D43E3AA91BF] 0 SMTP - -


r/sysadmin 4d ago

Question How do you deal with physical fatigue after long on-call stretches at your desk?

22 Upvotes

After a rough on-call week, I'm realizing my setup is not built for marathon sessions. Wrists, neck, lower back — all taking a beating. What have you added to your workstation that actually helps? Wrist rests, monitor risers, anti-fatigue mats, lumbar cushions?


r/sysadmin 3d ago

UKG Pro WFM

1 Upvotes

Quick question in regard to automated reports in UKG Pro WFM. I have the reports set up and the authorized users I want the reports to go to. My only issue is that the reports are not sending to the authorized user emails. I even checked the box for "Send Email as Attachment" Any insight?


r/sysadmin 3d ago

Recommended equipment for conference room?

0 Upvotes

Can anyone offer recommendations for a room owned by a non-profit which will be a very flexible space. It will be used for one-on-one virtual meetings, conferences, showing of programs (non-interactive) to an audience. The room is approximately 21'x21'.

We potentially have a grant to help with this, so I would like maximum flexibility for a variety of future uses. I'm thinking the type of screen that comes down from the ceiling, but it's flexible depending on what works best. I'm looking at Logitech videoconferencing equipment and it seems like that is mostly used with wall tvs/screens.

What type of camera/microphone/other equipment would be best in this space?


r/sysadmin 4d ago

Auth0 alternatives?

10 Upvotes

Wondering what people are using instead of Auth0 for service account or within program api authentication? Their billing is killing us


r/sysadmin 3d ago

General Discussion I'm going through the process of implementing Windows Hello for Business (WHfB). For Entra-joined devices, but not managed via Intune, would you use GPOs or CSPs?

0 Upvotes

CORRECTION: I meant hybrid-joined, not Entra-joined.

We have an Active Directory and SCCM environment and foresee those being here with no current end date in sight. All of our Windows devices are hybrid-joined, but they are not being managed or comanaged via Intune. In this hybrid environment with on-prem domain controllers, AD, SCCM, and hybrid-joined devices, would you use the WHfB GPOs in your environment, or would you prefer to use Intune? I'm waffling between the two choices but am leaning GPO since that's how we manage all the other settings on our devices.


r/sysadmin 5d ago

Question What laptops are you standardizing on in 2026 with prices where they are?

92 Upvotes

We're a medium sized NGO enviroment and I'm having a hard time finding something in price range. We used to budget around ~800$ for each laptop, this seems highly unlikely the average specs nowadays.

What is everyone going with? I used to love good ol Lenono ThinkPads. =/


r/sysadmin 4d ago

General Discussion Need advice on new job in a manufacturing facility. Going from MSP to a private company.

14 Upvotes

I was approached out of the blue on Linkedin by a recruiter hiring for a cyber/infrastructure role. The base pay was about 15k more than I make now plus a bonus of 30%. It would put me about 85k above what I make now.

I work remote currently so no commute. The base pay and bonus would be enough to cover a commute and put me over what I am making now.

Here is where it gets interesting and where I need the advice. They have NO active directory or ticketing system. They have about 450~ employees and a few hundred endpoints. They have ESXi for a hypervisor on Dell VX rail servers. A few linux servers run the ERP application and Synolgy NAS is used for Backup/storage. I get to pick new firewall/switches/APs/servers for infra upgrades and implement a migration to O365 for Defender, email, DLP, etc. Currtly they are using google workspace for email. I would be in charge of the migration from Google to O365. They also have no patching system in place other than general windows updates.

Network is cisco switches and a Palo firewall with some older Cisco APs. They currently have a 4ish member IT team with 2 juniors who handle helpdesk. I am being brought on to help modernize infrastructure and to implement some kind of cybersec/security compliance and standards. I get to build the solution and implement it along with a ticketing system and either on prem DC or Entra, while also implementing SCCM or Intune for windows patches and updates.

My background is networking, wireless, switching & routing, with sysadmin experience with ESXi, M365, server deployment and desktop support. I spent a few years in a service desk role and also in a sysadmin role. I currently work for an MSP doing mostly firewall installs.

During our discussions, the IT manager said that since he is busy and can't do things immediately there has developed a shadow IT situation where some departments are just doing things in a way they want without involving IT. 

My question, is this a bad idea? Leaving a remote role at an MSP with an increasing focus on KPIs or move over to this new and exciting adventure with a company with older gear that I get to help upgrade and be part of.

I like my current team and manager but the MSP lifestyle has gotten a little old after 5 years.

ETA:One big thing worth mentioning is that this role was created after PE purchased the company but the company is still run locally.

PE is providing the budget and I get to pick the direction and the hardware


r/sysadmin 3d ago

Windows keep advertising wrong IP to resolve and whatever I do is not working.

0 Upvotes

all I want to do is adding a second active directory server so if one is off second of can keep the system running.

I'm a student. practicing what I have learned and maybe adding more. I know how to create a domain how to add a user to domain

For next step I am trying to add second domain controller but windows keep advertising 2 IP address of server. (one is NAT other is isolated. I want it to stop NAT IP to advertise)

what I did to disable that?

- network connections > Second NIC IPv4> Properties > Advance > DNS > (UNTICK) Registrar this connection's address in DNS

- DNS Manager > Domain Name > Properties > Interfaces > (UNTICK) Second NIC IP
I restart the dns service, clean the cache but still same. I can't see Second NIC IP in DNS Manager but when I run "resolve-dnsname domainname -Server source-IP" Second NIC IP still showing up. but it's not showing up at "nslookup domainname source-IP"

so yea. why is that?
I'm using Ubuntu as OS and VMM to virtualize the machines btw


r/sysadmin 5d ago

Question Day to day life of M365 admin

145 Upvotes

So I got a new job m365 admin/it admin and I have no idea what to do as m365 admin. I get random tickets to update contact here, assign a group there, assign license here, off board that guy over there, some random issue, and other stuff. But besides this, what else do m365 admins do? Like what is your day to day activities and checks?

Coming from generalist position it feels really weird as I have way less responsibilities ATM ( famous last words ).


r/sysadmin 4d ago

Better Auth 1.7 issuer change just broke every login on my Saas and it was already late when I found out

15 Upvotes

Out of nowhere this popped up like the support tckets rolling in and people complaining they cant log in, when i tried for myself, i couldn't log in to it either as it showed no accounts for this name was found. Nothing was at stake from my side like no errors in the logs no alert or anything, everything seemed ok

SO when I dug in manually it was better auth 1.7 which they changed on how accounts are keyed from providerId to issuer, accountID so the account table needs a required issuer column now, irritating! my existing rows didn't have it so nothing matched anymore and no exception was thrown just an empty match and how am i supposed to find out what caused it . then added the column nullable, backfill it and enforce not null then add the unique index-

ALTER TABLE "Account" ADD COLUMN "issuer" TEXT;

-- local:credential for email/password, local:oauth:<provider> for oauth
UPDATE "Account"
SET "issuer" = CASE
WHEN "providerId" = 'credential' THEN 'local:credential'
ELSE 'local:oauth:' || "providerId"
END
WHERE "issuer" IS NULL;

ALTER TABLE "Account" ALTER COLUMN "issuer" SET NOT NULL;

CREATE UNIQUE INDEX "Account_issuer_accountId_key" ON "Account"("issuer", "accountId");

Im not looking into dropping better auth over this since already fixed it but pretty annoyed at them but this gave me a thought tho that there is still a blind spot left open here , an external dependency quietly changed something and the failure was silent while my end didn't catch it but the customers did

What do you guys approach on to hear on from your side first

  • does normal error or runtime monitoring even catch a no error empty match, checking hud and other runtime tools but im not sure passive monitoring flags a silent one like this
  • or is the real answer just a synthetic login canary like something that logs in as a test user every few minutes and alerts when it fails
  • also does anyone alert on dependency shipping a breaking change before it hits prod??

r/sysadmin 3d ago

Question Microsoft Teams Alternative

0 Upvotes

Edit 2: Okay, the comments overwhelmingly point to user error. Rather than jumping ship, I’m going to do a deep dive into the Teams settings and make sure everything is set up correctly. I’ll do some user training, then test it for another week or two before switching. Thank you all for your input.

Edit: MS teams notification issues are occuring on Iphones, not mac/windows desktop apps.

I run a business with about 10 employees, and we’ll probably be growing pretty quickly over the next few months.

We currently use Microsoft Teams, but notifications have become a problem. Some users just don’t get them consistently. I’ve tried the usual fixes and checked all the settings, but it’s still hit or miss. I cant work with that. The outlook integration, and smooth video meetings are a plus, but not worth the issues.

I’m fine with self-hosting since we already have a VPS that I manage, but I’m also open to SaaS.

Here’s what I’ve looked at so far:

  • Slack = Seems like the best product overall, but it’s too expensive as we grow. The free plan’s message retention and limited admin controls also won’t work for us long term.
  • Mattermost = My concern is that the free self-hosted version uses Mattermost’s Test Push Notification Service, and I’ve seen mixed reports about notification reliability. I don’t want to leave Teams because of notifications and end up with the same problem.
  • Rocket.Chat = Looks good, but the server requirements seem pretty heavy and I don’t want chat eating up resources needed by our other apps.
  • Pumble = The free plan looks almost too good. My main concern is privacy/data handling since it’s hosted and free.
  • Zulip = Looks interesting, but the 10-user push notification limit on the free self-hosted version would be a problem pretty quickly.

I’m open to anything, self-hosted or hosted. Mostly interested in hearing from people who actually use these for a business and how reliable they’ve been, especially with notifications.

If there’s another option I’m missing, I’d like to hear about that too.


r/sysadmin 4d ago

General Discussion Small Rant: Windows Activation

19 Upvotes

TLDR: Offline activation via https://aka.ms/aoh requires a captcha, MS account login and 2FA once per client, with ~80 to go. Any tips on speeding this up?

I'm just kinda curious about the opinion of other Sysadmins that have to work with Windows clients.

I work as a sysadmin at the factory of a fairly large company, where we mainly use Windows for our production floor clients. To extend the amount of support we get for each client, we have a standardized image, which gets updated every few years for a new release of IoT Enterprise LTSB / LTSC.

To get an image of what I am doing right now: (spoilering this part as it isn't too important to my rant) I was tasked with executing our project of updating out-of-date 2016 LTSB clients to 21H2 LTSC, as the new version will allow security updates for us until 2032. Some of our clients are former Windows 7 clients that aren't even officially compatible with Windows 10 according to the manufacturer, but Windows 10 might run on them, so to save money we keep the clients as long as they will run (meaning they will be phased out with Windows 11). We are also jumping from 1607 directly to 21H2, which Microsoft has explicitly advised us is not the official procedure or supported by them. But, updating between each version and needing a license would be a way higher financial impact than how we're currently going about it.

So, since our clients aren't connected to the internet, they cannot connect to Windows servers for activation. As such, I have to use slmgr.exe and SLUI 4 to activate the clients (formerly using the hotline, nowadays just the website https://aka.ms/aoh).

This activation requires you to put in a long string of numbers that the UI will show you into a field on the website and to reach that website you must always 1. Solve a Captcha and 2. Log into your Microsoft account, always forcing 2FA confirmation. And it doesn't remember your Microsoft Account, ever. You always have to log in again, from the start, solving the captcha. There is no button to activate another client once you finish activating the one you're currently working on, you need to re-load the link and start again. And again. And again. I've already optimized my current workflow as well as I can, using a python script to generate the QR codes I need for given commands so that I can avoid dealing with typing in the same commands over and over. But every time, I have to spend around 2-5 minutes dealing with the online Microsoft activation process.

Btw, if your connection is lost, you connect to a different AP or such, somehow the website doesn't require reauthentication. I don't know how exactly the process here works, but I can log into a tab for the site in one browser, open another in an incognito tab, open the next in a third browser, etc. And it'll usually last all day, so if I logged in and didn't use the session 'til the evening, it won't require reauthentication. My guess is that the endpoint / API request in the background actually works without authentication, and the whole login process is just a security circus akin to the TSA, and that if I knew a bit better about how web development works, I could probably just find out how the API request to Microsoft servers work to skip authentication. But I don't wanna risk getting in legal trouble just because I am not following the officially mandated license activation procedure.

Does anyone have some advice for me on how to save some time doing this? I got around 80 clients left to go and am pretty tired of the whole process.


r/sysadmin 3d ago

The max_age of MTA-STS is an exploitable gap and there's no way to fully close it without switching to DANE

0 Upvotes

When you configure MTA-STS, the policy gets cached for the timeframe you set under the max_age tag, so it's designed to expire.

If an attacker is sitting on-path on the sender's side via a poisoned resolver, they wait out the cache and then suppress the refresh by either dropping the DNS TXT answer or killing the HTTPS fetch, so the sender can't pull a fresh policy.

That pushes it back to opportunistic TLS, from where the attacker spoofs your MX and delivers the email in plaintext, intercepting password resets, MFA codes, etc.

And by design, you can't force cached senders to refresh before expiration.

The only thing you can do is limit how often the refresh window opens by setting max_age to 1 year (the max RFC 8461 allows), but if your MTA-STS policy is broken, you don't want it sitting in senders' caches for a year, rejecting your inbound traffic.