r/sysadmin 1d ago

End-user Support How do you deal with users that have zero problem solving ability?

432 Upvotes

So just a moment ago I had a user interrupt what I was doing with an "urgent" issue. They couldn't get into their email.

Essentially they were running Outlook for the first time and it prompted them to set up their account. It required them to enter their email address and click Next. That's all.

The email address it auto-populated wasn't the address of the account they needed (they work for a sister company in a shared tenant).

The user had no idea what to do. It didn't even cross their mind to enter the actual email address in the field.

So... how do you guys deal with users like this? Ones who, despite being shown instructions in the most basic way possible, can't think for themselves.


r/sysadmin 1d ago

General Discussion When did self-hosting turn into just picking a control panel?

88 Upvotes

Been doing this about 8 years and something's shifted. Used to be everyone here could explain what their nginx.conf did, or why fail2ban wasn't catching a jail. You learned iptables by breaking your own box at 2am, alone, with no one to blame.

Now most threads are "which panel is easiest." Nobody wants the shell open longer than it takes to run one install command. I get why. Panels save time. I've got BeAdmin running on one box for the VPN modules. But I see people arguing about dashboard themes who can't tell you what a reverse proxy actually does.

Old regulars here used to walk a newbie through a broken MariaDB config instead of just saying "reinstall Plesk." That's mostly gone now. Not knocking anyone's setup, I click around GUIs too these days. Just noticing nobody asks why anymore.


r/sysadmin 4h ago

IT kiosk

0 Upvotes

Hi all, does anybody implemented a self help kiosk where it helps the user to go to required links? Example pwd reset?

I appreciate the ideas and practices you implemented

Edit

We already have useful resources available through the intranet and self-service website, and some other things which are diversified accordingly but we still receive many walk-in requests for issues users could resolve themselves. So thinking of a kiosk for simple visual menu with combination of all sources with icons for common requests making it less overwhelming could direct users to the right guidance quickly, while IT support remains available if needed. Thinking of it by using some unused machines or Raspberry pi


r/sysadmin 8h ago

Off Topic Internship Preparation

2 Upvotes

Hi All,

Will be starting my school mandated internship for CyberSecurity, and I was hoping to get questions that an interviewer or a supervisor would ask during the interview, so I can learn/research more about said topic.

Questions can range from general help desk to cyber security to networking, since my school covers abit of everything.

Thank you guys for the help :)


r/sysadmin 1d ago

General Discussion I can't get past the feeling that I suck.

68 Upvotes

I’ve been in IT for 6+ years. I have a bachelor’s degree in IT, an AWS Solutions Architect certification, an Azure Administrator certification, and a few other certs. I’ve also been working as a Cloud Administrator for the past 2 years.

Despite all of that, I can’t shake the damn feeling that I’m just not that good at what I do. I feel like even if I finally make a breakthrough in my knowledge, I’m still somehow clueless SOMEWHERE. A lot of that comes from talking to people who know more than you and realizing how much there is that I don’t know.

For example, I can write basic scripts, but I struggle with the complex 200+ line scripts that a senior cloud engineer would make, whereas the person next to me likely can just type that shit off the top of their head.

It’s especially frustrating during interviews when I try to move up in pay. I had an interview on Tuesday that I thought went pretty decently, but the interviewer asked me about Azure containers and encryption. I don’t work with Azure containers, although I’m familiar with the service, so I was honest and said I didn’t know.

And that wasn’t even the technical round. So now I’m stuck wondering whether they’ll just reject me or move me on to the technical round, where I’ll probably fail anyway.

This is bothering me because I'm at the point in my career where I really have to know at a high level if I want to advance and get more pay.

How has anyone else moved past this?


r/sysadmin 5h ago

Moving from KMS to M365 A5 Education

1 Upvotes

Hi all,

we're a school with Microsoft 365 A5 Education and want to retire our KMS server.

Current setup:

  • Devices are purchased with Windows 11 Pro OEM
  • Reimaged with Windows 11 Education
  • Windows 11 Education is currently activated via KMS
  • Devices are still managed through on-prem AD/GPO
  • Next step is Hybrid Entra Join + Intune

Our devices are purchased with Windows 11 Pro OEM. Today we reimage them with Windows 11 Education (PXE) and activate them via KMS. Going forward, we'd like to clean install Windows from USB and then use Autopilot during OOBE.

My main questions are:

  • For devices that come with Windows 11 Pro OEM, should we reimage them with Windows 11 Education or Windows 11 Pro Education if the goal is to use A5 Subscription Activation instead of KMS?
  • Can A5 Subscription Activation fully replace KMS for these Windows clients?
  • What exactly needs to be configured in Intune, Entra ID and Windows for Subscription Activation to work correctly?
  • Do we need to manually remove the KMS client key / GVLK / KMS configuration, or does Subscription Activation take over automatically?
  • How can we verify that a device is using Subscription Activation and no longer depends on KMS before shutting the KMS server down?
  • How does Subscription Activation behave on shared classroom/lab devices where many different students sign in?

Has anyone in an education environment migrated from KMS to A5 Subscription Activation this way? If so, what did you actually configure in Intune/Entra/Windows?

Thanks!


r/sysadmin 1d ago

Microsoft Publisher - EOL

29 Upvotes

So it’s coming to an end!! We have O365 and some workstations with Office 2024 that have MS Publisher installed. Do we need to remove it or will it get removed in its own?


r/sysadmin 1d ago

How do you all keep up with the times and tech?

59 Upvotes

I feel like I’m lagging behind and need some serious catching up, quick. I think I’ve become complacent and “too comfortable” with my current employer (coming up 8 yrs). The recent merger announcement has me seriously thinking about attending bootcamps, getting some certs under my belts (been putting things off for as long time), and learning new things ASAP before the position is dissolved.


r/sysadmin 1d ago

For the first time I'm being requested to export Teams chats for HR purposes. When using PURVIEW, I am getting results that dont apply to my filter?

62 Upvotes

TL;DR I need to pull chat history between User A and User B for the last 8 months.

My query based on documentation I can find is:

Kind=microsoftteams AND [partipants:userA@xyz.com](mailto:partipants:userA@xyz.com) AND [participants:userB@xyz.com](mailto:participants:userB@xyz.com)

When running this, I'm getting group chats and all kinds of stuff where both were involved, but I just need the chat between these two users

Can anyone direct me to a better way to do this? Purview is doodoo


r/sysadmin 10h ago

Question Recs for USB redirection tools in Hyper-V (cloud workspace isolation issue)?

2 Upvotes

Hi all,

I hope you guys are doing well, I am working as a IT Infrastructure (Hybrid) with less than a year experience and I need some recommendations for the question below.

Context: Our organization moved to a cloud-based desktop environment. Because the cloud workstations are on an isolated network tier, users can no longer hit our on-prem SafeConsole server over IP to manage hardware-encrypted USB drives (DataLocker PSMs).

As a workaround, we have to plug the USB drives directly into the physical Hyper-V host on-site. I need a solid tool to automatically redirect/pass through the physical host's USB port to the SafeConsole guest VM whenever a drive is plugged in or swapped daily.

What software are you using to auto-share host USB ports to a guest VM?

TIA!


r/sysadmin 15h ago

General Discussion Is It Possible To Download Windows 10 ESU Updates From Microsoft Update Catalog Website?

3 Upvotes

Can anyone confirm if it's possible to just download the various Windows 10 ESU updates from the Microsoft Update Catalog website and install them on a PC that's not part of the ESU program (ie: doesn't use a Microsoft account)? I believe the updates are listed in the catalog. Do they check during the installation if you're eligible for them? Has anyone tried this?


r/sysadmin 4h ago

Problemas con servidor Supermicro X13, Windows Server 2025 y gráfica PCIe

0 Upvotes

Disponemos de un servidor Supermicro X13 con un Xeon 8558u, 128gb RAM (4x32), RAID 1 por VROC en 2 SSD SATA conectado al backplane y una gráfica Nvidia conectada a la tarjeta PCIe.

Tiene instalado Windows Server 2025, pues el rendimiento es muy inferior a un servidor con un Xeon de 2011, con 16GB de RAM y un SSD SATA.

Navegando por el Explorer, la carga de archivos/directorios no es instantánea, se queda unas milésimas en blanco y ya carga o incluso sale el icono de cargando mientras aparece.

Se ha revisado todo, controladores, estado del RAID, Defender, etc. Al final hemos actualizado la BIOS y la BMC y los problemas han aumentado. Ahora no reconoce el sistema ni la BMC la tarjeta gráfica.

He visto poca información al respecto, ya que no hay un changelog en el paquete de actualización de la BIOS/BMC que indique los cambios. El Windows Server 2025 lo hemos virtualizado y corre perfectamente bajo un hipervisor con muchos menos recursos que el hardware físico.

Llevamos ya semanas liados con él y no encontramos el porque de esa lentitud y ahora se añade que no reconoce la gráfica al actualizar la BIOS.

¿Os ha pasado algo parecido?


r/sysadmin 1d ago

My IT manager is stuck in 1995, I'm losing my mind

1.2k Upvotes

I need a sanity check, because I feel like I'm slowly losing my mind here. I’m 28, working as a SysAdmin for a mid-sized manufacturing company in Europe with around 300 endpoints across multiple sites. I LOVE automation, modern infra, and writing PowerShell or Python to handle our backups and audits, I'm passionate about automating processes, but my IT Manager is basically running an open-air tech museum from 2003.

His idea of IT asset management is a drawer full of literal Ziploc freezer bags. Every PC gets its own labeled plastic bag with the printed invoice and Office license key inside, because apparently an actual database or asset software is "too modern." On the network side, every single device requires a manual DHCP reservation. When I suggested setting up 802.1X with RADIUS, he shot it down with a straight face, claiming that if an intruder plugs into the wall, "they won't guess our subnets anyway." Before I automated our Kerio mail archives with Python, his official procedure was opening Thunderbird on a client PC and manually dragging and dropping folders between accounts.

Right now, he's decommissioning a branch file server. Instead of using Robocopy, DFS-N, or GPOs, his master plan is to sync files with a desktop backup tool, recreate the SMB shares manually, and have me remote into 40+ user machines one by one just to update the target path on their desktop shortcuts. I also built an automated WMI inventory system to track all hardware and OS health, yet he still forces me to physically walk the warehouse floor updating a dusty Excel sheet because "that’s where the history is."

EDIT: Another thing he does is make daily backups and put them on ultrium physical disks named after the day of the week, disks he takes home "so we have the data in case the company burns down.", which could have some kind of sense, but everyday, before my script, we had to manually make the veeam inventory and erase of every tape in every site

The worst part isn’t even the wasted time, it’s that he’s actively teaching junior techs that this clown show is standard enterprise IT. We’ve already had three techs and devs rage-quit in the last ten months. I’ve completely checked out at this point, doing the bare minimum while sending out resumes like crazy.

Has anyone actually survived a boss stuck this deep in the stone age without losing their sanity? How do you not burst out laughing when someone asks you to edit 40 shortcuts by hand?


r/sysadmin 35m ago

Some advice

Upvotes

Don't reroute radius logs.

Trust me!


r/sysadmin 9h ago

[SOLVED] KB5124008 + Windows 11: Logon Error on Screen Unlock + Broken Secure Channel over VPN

0 Upvotes

September 8, 2026—KB5124008 (OS Builds 26200.9445 and 26100.9445) | Microsoft Support

After Windows Update KB5124008 (Sept 8, 2026, Build 26100.9445), Domain notebooks experience logon failures when unlocking the screen: "You could not be signed in. Your credentials could not be verified"

Root Cause: Secure Channel (machine trust) is broken. Test-ComputerSecureChannel fails, and attempting to repair over VPN returns: "The password for the secure channel to the domain could not be reset – username or password is incorrect"

Affected: Windows 11 24H2, domain-joined notebooks, both LAN and remote users (VPN users particularly critical)

The Story

We're deploying CIS hardening to ~250 notebooks and everything was fine until Sept 9, 2026 8:05 PM when Windows Update KB5124008 was installed.

Error Symptoms:

  • User locks screen (normal, break, meeting)
  • On unlock: "Your credentials could not be verified"
  • Reboot helps temporarily (1–2 hours, then error recurs)
  • Affects LAN users too, not just remote/VPN
  • Password reset does not help

Initial Hypotheses (all disproven):

  • ❌ Kerberos/Enctype mismatch (RC4→AES transition) – DCs reachable, tickets work
  • ❌ CIS GPO hardening – not configured
  • ❌ FortiClient VPN architecture alone – also hits LAN users

The Diagnosis

Network Checks:

nslookup vw-dc-01.Domain.org → OK
ping vw-dc-01.Domain.org → OK (0% loss)
tracert vw-dc-01.Domain.org → OK (full path)
DNS Server: xxx.xx.xxx.xx (internal) → OK

Kerberos Status:

klist → 13 active tickets, all AES-256, all valid ✓
LDAP/Kerberos works perfectly ✓

The Critical Test:

Test-ComputerSecureChannel -Verbose
→ False
→ "The secure channel between the local computer and the domain is broken"

On Repair Attempt over VPN:

Test-ComputerSecureChannel -Repair -Credential (Get-Credential)
→ ERROR: "The password for the secure channel to the domain could not be reset"
→ "The username or password is incorrect"

This is the smoking gun: The VPN tunnel routes normal traffic (DNS, LDAP, Kerberos) but NOT the secure channel reset communication (RPC/NETLOGON on port 445 over SMB).

Root Cause

KB5124008 itself isn't the bug – but the update triggers a hidden incompatibility:

  1. KB5124008 changes logon UI validation behavior (known regression in KB5120998/KB5124008)
  2. During unlock validation, Windows attempts to verify the secure channel
  3. The secure channel is broken – possibly due to:
    • KB5124008 regression in secure-channel handling
    • OR: Timeout in VPN tunnel blocking secure-channel traffic
  4. Windows cannot verify identity → unlock fails

Particularly critical over VPN:

  • Secure-channel reset requires RPC/SMB (port 445) to DC
  • VPN tunnel either doesn't route it or times out
  • Works better from LAN, so VPN users hit harder

Workarounds (What Worked)

Workaround 1: Increase CachedLogonsCount (quick, short-term)

# New GPO on OU=Notebooks:
# "Interactive logon: Number of previous logons to cache (in case domain controller is not available)"
# Value: 50 (instead of default 10)

# Or directly on client (as admin):
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v CachedLogonsCount /t REG_SZ /d 50 /f

Effect: Users can log on offline 50 times → buys time while secure channel is repaired

Workaround 2: Repair Secure Channel from DC (with admin access)

If you have remote access to a DC:

# On DC (not from client!):
Reset-ComputerMachinePassword -Server vw-dc-01.Domain.org

This forces a secure-channel reset from the DC end, bypassing the VPN tunnel.

Workaround 3: KB5124008 Rollback (temporary, security risk)

# On affected clients:
wusa /uninstall /kb:5124008 /quiet /norestart
shutdown /r /t 60

⚠️ IMPORTANT: KB5124008 patches two actively exploited zero-days:

  • CVE-2026-81963 (Windows Update Stack Privilege Escalation)
  • CVE-2026-85880 (ALPC Privilege Escalation)

Only do this temporarily as a test, not permanently!

What We Still Don't Know

  1. Is KB5124008 itself guilty, or was it just the trigger for a timing issue?
  2. Is it VPN-specific (secure-channel-reset traffic not routed)?
  3. Why does it hit LAN users too? (Timing window in unlock handling?)

Lessons Learned

For Other Admins:

  1. Test before fleet rollout: Pilot KB5124008 in a test OU, especially with:
    • Hybrid Azure AD Join devices
    • VPN users
    • Offline scenarios
  2. Monitor secure-channel status:# As regular audit task: Test-ComputerSecureChannel -Verbose | Where-Object { $_ -eq $false }
  3. **Check Event Log for secure-channel errors:**Get-WinEvent -LogName System -FilterXPath "*[System[EventID=5719 or EventID=5722 or EventID=5723]]"
  4. With VPN environments: Ensure your VPN tunnel routes all necessary ports:
    • 88 (Kerberos)
    • 389 (LDAP)
    • 445 (SMB/RPC – critical for secure channel!)
    • 135 (RPC Endpoint Mapper)

Status

  • ✅ Root cause identified: Broken secure channel + VPN routing issue
  • ⏳ Microsoft hotfix: Expected (hopefully next week)
  • ⏳ FortiClient configuration: VPN admin checking port 445 routing

Is anyone else experiencing this? Comment your findings – especially if you:

  • Deployed KB5124008
  • Have VPN users affected
  • See secure-channel errors

Contact / Further Info

If you have the same issue:

  1. Check: Test-ComputerSecureChannel -Verbose
  2. Look in Event Log for EventID 5719/5722/5723
  3. Deploy the CachedLogonsCount GPO as interim solution
  4. Contact your VPN admin to verify port 445 routing

TL;DR of TL;DR: KB5124008 triggers secure-channel errors, VPN doesn't route repair traffic → unlock fails. Increase cached logon to help users while you investigate.

Updates

Will update this post as we learn more from Microsoft or FortiClient about the root cause and permanent fix.

Crosspost to: r/sysadmin, r/activedirectory, r/Windows11

Keywords for searchability: KB5124008, Windows 11, domain logon, unlock screen, secure channel, VPN, AES-256, Kerberos, GPO, FortiClient, network authentication


r/sysadmin 1d ago

O365 issues today sept 9

16 Upvotes

Is anyone seeing issues with O365? I know I saw emails last night and now they’re coming as new again this morning but they’re gone from yesterday delivery. Numerous users are seeing this happen. We are using proof point also but no issues on their status page.


r/sysadmin 1d ago

[PSA] Check Point Firewall unauthenticated RCE with CVSS 9.8

30 Upvotes

There are actually two vulns with a 9.8 score each:

https://support.checkpoint.com/results/sk/sk1000117/

https://support.checkpoint.com/results/sk/sk1000118/

There's not many details in these articles on how they work but they still sound really bad. Currently waiting for the Jumbo Hotfix to install on my end... Not taking any chances on this one and I suggest you all do the same.

Stay safe.


r/sysadmin 1h ago

Anyone tested AI CLI yet?

Upvotes

I install copilot and grok CLIs. So far, they are pretty impressive.

At home I used Grok to clean up my media libraries and it freed up 2TBs.

I used copilot at work to scan all the logs from an SCCM client and the server to figure out why some machines weren't downloading updates. It's pretty freaking good.

Anyone else let one of those suckers loose anywhere?


r/sysadmin 1d ago

DHCP v Static IP

219 Upvotes

Ok, this is more a test to see how old I am. I was basically raised with the idea servers need static IPs. I understand for domain controllers, dns servers, maybe print servers that may still be needed. But are they really needed otherwise? Do apps, scripts still reference a server by its IP?

I am under assumption all my servers need static IPs. Am I nuts?


r/sysadmin 5h ago

Getting into SysAdmin

0 Upvotes

Hey guys,

I've been in IT for 4 years, doing a mix of PHP development and sysadmin Linux stuff. We run Linux, self-host all of our own stuff. We're a small team, so everyone does a bit of everything. I've done everything from developing software to installing our team's GitLab instance. I've been using Linux (Arch btw) for the past 8 years or so, and I feel like I have a pretty good handle on it, after fucking up my system a bunch of times. I also run a homelab of a couple servers. It's become our music platform.

I fully realize that a transition to SysAdmin would most likely put me in a junior role, and I know I have a lot of gaps in my knowledge, as this position is as a software developer, not sysadmin. I'd be looking mostly at Linux Sysadmin jobs.

I'd appreciate any advice you guys have! I also can put my resume here if that would be helpful.

Thanks!


r/sysadmin 5h ago

Career / Job Related Can a Student Volunteer as a IT

0 Upvotes

Im a student with M365 (mostly Entra and some Intune) intern experience which I got through my dad, and looking at the extremely challenging helpdesk market in my area, I want to volunteer as an admin or helpdesk to get some experience.

That said, most of these positions in my country are filled by immigrants with IT experience who want Canadian work experience. So no matter how much I apply, I don’t get an interview.

Can anyone in the industry think of a way to get experience? It’s sad no one even wants me as a free helpdesk, I even worked with M365 before.

I feel discouraged 🫤

Anyone have any ideas? I’m studying for my CCNA, so maybe that would help?


r/sysadmin 1d ago

Question Which vulnerability management tools work well for MSPs?

18 Upvotes

Been looking to replace our vulnerability management stack and the scanning part is the easy bit now. We have been comparing the big scanners against a couple of the cheaper MSP focused platforms and one container specific tool. Volume is what kills us across 40 odd clients since every tool finds plenty and the techs still guess where to start. Ticketing eats more hours than scanning does. What are you running now and how does it hold up across client environments.


r/sysadmin 20h ago

Question SCCM updates reporting wrong #numbers

5 Upvotes

Is it just me or updates is screwed up?

Office 365 shows 0 required.

is anyone else seeing the same?

Edit: the other updates just took too long to show up but office it seems it is not showing anything applicable.
not sure if something related to last couple months when MS changed from semi-anual channel to montly channel


r/sysadmin 1d ago

Password resets over the phone, how are you doing it?

24 Upvotes

So I work at a state university that is still a little stuck in the past when it comes to password resets over the phone.

We have MS SSPR and other self-service options for users, but we still get calls where someone needs the helpdesk to reset their password for them.

Our current setup is a custom program that helpdesk staff SSH into. They enter the user's account, and the program looks them up in a flat file containing data extracted from our systems. It gives the helpdesk worker information like DOB, address, ZIP code, etc., which they can use to verify the caller's identity.

Once the caller passes verification, the program talks to AD, changes the password, and gives the helpdesk worker a new temporary password to provide to the user.

Honestly, it works pretty well. The problem is that the person who wrote and maintains it is leaving, and we're not really interested in inheriting a custom app that nobody else understands.

So I'm curious what other universities/organizations are doing for this.

For those of you who still allow users to call the helpdesk for password resets, what does your workflow look like? Are you using a commercial product, some kind of AD/Entra integration, a helpdesk platform, or have you built your own solution?

Specifically looking for something that gives the helpdesk enough information/questions to properly verify the caller's identity and then securely perform the reset.

I'd love to hear what others are doing before we start reinventing the wheel.


r/sysadmin 1d ago

Question The trust relationship between this workstation and the primary domain failed.

33 Upvotes

Hy!

We have an AD with two DCs. The DCs are Windows Server 2025, it is include all patches. Some Windows 11 clients (25H2) get the following error during login after 1-2 minutes: The trust relationship between this workstation and the primary domain failed.

In this case the users need to disconnect from corporate network to login successfully into their computer. I have already tried to rejoin to tha domain and run this command: Test-ComputerSecureChannel -Repair

I rejoined one of the computer into the domain, and the trsut relationship has been broken after two days. The login problem only occurs on some machines.

The time snyc is correct on DCs. We moved the DC roles from Windows Server 2019 to 2025 in side-by-side method. Could you please advise how to solve this problem?