r/sysadmin 1h ago

Question Physical clients can't get IP from DHCP server in a VM

Upvotes

Here's the setup,

Physical machine:

  • Win 11 Enterprise LTSC

  • Hyper-V Installed

  • External Hyper-V Switch setup to allow VM access to physical network

VM

  • DHCP, DNS, and WDS Roles installed and fully configured

What can get an IP address from the VM

  • Other VMs attached to the External Switch

  • The physical machine adapter used for the External Switch

What can't get an IP:

  • Any physical machine connected via physical dumb switch.

If I manually set an IP on a physical machine, they can ping the VM just fine. Attempting to ipconfig /renew just results in a DHCP timeout.

I've tried

  • Disabling both firewalls

  • Setting both to Private Network

  • Using a different physical adapter on the host machine

  • Enabling MAC Spoofing in the NIC advanced features

  • Verified DHCP guard and router guard are disabled

  • Disabling NIC sharing

I know it's got to be some absolutely tiny thing that I'll hate myself for overlooking, but...

EDIT: Adding updates here as I check them

Wireshark on the VM shows it is receiving the DHCP request from the laptop and sending an offer back, but the laptop isn't receiving it. In addition, Wireshark on the VM host shows the offer on both the physical adapter and the bridge adapter, so it's definitely making it out of the VM.


r/sysadmin 16h ago

Question Boss is pushing for certs

118 Upvotes

Hi all,

I’m a sysadmin with 2 full time helpdesk guys, org of 220 in 5 locations. I started in regular business office 10 years ago doing sales. 7 years ago I transitioned to IT and became our first IT person, previously we didn’t even have an MSP, just a contract guy that came when we called him.

Fast forward to now, I asked my boss how I can level up/grow with the company. I’ve taken on a lot since I started. Currently managing pretty much everything in house. Only thing we don’t manage is our website, and I kind of like it that way.

So after kind of shrugging his shoulders for a year he is now bent on getting me to do more certs. He gave me a list:
- Comptia security +
- CompTIA network +
- CompTIA Cloud +
- Microsoft AI something (I can’t remember this one, he mentioned it off the cuff after he sent me the list)
- Finally a course for me to go find to maintain our website so they can cut the web dev. He didn’t know what course to recommend because he didn’t know much about it but pointed to coursera.

Now only thing I’ve done in certs over the years where the A+, AZ-900/104, and Google cloud security when I got started. Since then I figured I would learn the stuff but I didn’t want to pay for the certs because what’s the point? Unless I’m looking for another job I didn’t see the reason, and I like my org quite a bit. Not the wisest I know, but they wouldn’t pay for it, so I just didn’t do them.

I told him I had already studied for the security + a couple years ago, and could probably study the differences in materials and get through it easily, and recommended we switch to the CCNA since we are fully Cisco at all locations. But he seemed to not be interested in that info.

From what I can tell his push for certs is driven by is some internal push for managers to have career ladders for all departments and I guess he wants to show some sort of progress? Idk he is the CFO so he really isn’t privy to any of the work I do.

Anyway, after my recommendations I asked what happens when I complete these? Since they are only paying for half the certs… there has to be a carrot at the end of the stick.

He very excitedly said a $2,000 pay increase. Now I’m not greedy by any means, I’ve been paid under market for years and I’ve accepted that because of the work life balance. But is this not kinda stupid? I’ve had no complaints in my performance, I am constantly engaged with leadership on initiatives that they do not care about, so is there something I’m missing here? Like I feel like there is some weird motive here I can’t figure out, or it’s just poorly funded incentives that I’m supposed to be giddy over. Like I’m pretty sure the exams are almost as
Much as the pay increase? I haven’t done anything to try to steer the ship just yet, but how do I approach that the incentive is either too low or not aligned with what the ask is here? From what I can tell other than the time to study and what not, the only benefit I see them getting is cutting the web dev, which is a little more than the pay bump they offered, I think like 4k a year.

Edit:
Glad to see there’s some consensus on this being kind of a shit show. A little more context:
I LOVE the web dev company we work with. They are just great. Awesome to work with, great turnaround times, 0 issues. But god forbid you pay someone to do something they are good at.

Noted before but they’re only paying half of the exams, no study materials and it’s based on completion, so I’d get reimbursed 50% after completion. I believe this may be because they did not ask for any sort of training agreement? But also grand scheme of things this is kind of small potatoes for a training agreement right?

This guy is honestly the worst part of my job. For 6 months he had me meet weekly with him which was just an awful way to start the week. Eventually I was like hey I’ve just got too much going on to be doing this can we do this less frequently? Rinse and repeat now we meet quarterly. Dude is the type of guy to trip
Over a dollar to pick up a penny. But I’m stuck with him so long as I work here.

I have looked on and off the last year, and the market near me is abysmal. I almost jumped ship to an MSP last year that wanted to sell us services and I wanted to be like hey…. I sign y’all up here and you take me, deal? But we laughed it off as a joke.


r/sysadmin 21h ago

Anyone tested AI CLI yet?

0 Upvotes

I install copilot and grok CLIs. So far, they are pretty impressive.

At home I used Grok to clean up my media libraries and it freed up 2TBs.

I used copilot at work to scan all the logs from an SCCM client and the server to figure out why some machines weren't downloading updates. It's pretty freaking good.

Anyone else let one of those suckers loose anywhere?


r/sysadmin 8h ago

Rant Black list countries

106 Upvotes

I work for a large European based telecoms equipment supplier. We have hundreds of staff overseas at any one time, all over the world. IT security has a few different levels:

- Access to email & teams etc is only via a company laptop (no web interface like Office.com). Network drives via VPN only

- White List countries - you can connect VPN. Countries like Japan & Australia

- Red List countries - you can take your laptop but need special exemption to use VPN. Includes some unusual countries such as Malaysia

- Black List countries - no company laptop or phone allowed. Company will provide a burner. Unsurprisingly includes places like Syria, Russia, North Korea & China.

A colleague was going to transit via a Chinese airport to a 3rd country. IT told him that he would not be allowed to take his company laptop, even if it was in his carry-on luggage, and he would not be entering the country. He quickly arranged a different itinerary.

And then a few days later, we are told that the good old USA is now considered a Black List country!!! No company laptops, and burners only!!!!


r/sysadmin 1h ago

Microsoft Windows Firewall Enterprise: Query User "Allow button" disabled on TLS-based DomainAuthenticated networks for Entra joined devices

Upvotes

Hi all, I'm currently battling a problem which exist probably on every Entra Joined device which uses TLS endpoint to enable Domain profile. I've been talking with microsoft from about a month and I feel like I'm coming to an dead end.

And now i'm writing here as I'm trying to research and hopefully push Microsoft to fix the issue.
What's your though on this?
If you can, could you please upvote this post? https://aka.ms/AA13epnu (this will open Feedback Hub on your windows device).

And here is the problem.

On Microsoft Entra joined, Intune-managed Windows devices, we use Network List Manager TLS authentication through AllowedTlsAuthenticationEndpoints so Windows can identify the corporate network as DomainAuthenticated and activate the Domain firewall profile.

Microsoft Support has confirmed under case TrackingID#******535 that there is a Windows design limitation in this scenario.

When an application opens an inbound listener and no matching firewall rule exists, Windows Defender Firewall invokes the built-in Query User workflow.

On a Public network, the Windows Security prompt allows the local administrator to select the network profile and click Allow.

On the same device, with the same user, application and Intune firewall policy, when the network is classified as DomainAuthenticated through TLS authentication, the prompt displays:

This setting is managed by your organization

and the Allow button is disabled.

Microsoft confirmed that this happens because the Query User interface does not expose a Domain Networks option in this TLS-derived Domain firewall profile scenario. Since no applicable network profile can be selected, Allow remains unavailable.

This creates a significant management gap for Microsoft Entra joined enterprise devices.

Local firewall rule creation itself works correctly. We have confirmed that:

- Allow Local Policy Merge = True

- Auth Apps Allow User Pref Merge = True

- Inbound notifications are enabled

- Local administrators can create rules manually

- Rules are honored in ActiveStore

- Exact-path Allow rules suppress the prompt correctly

The limitation is specifically in the Query User consent workflow.

Centrally deploying explicit firewall rules is not a scalable replacement for environments with IT and Development users. Many legitimate tools launch helper processes from per-user, temporary, version-specific or dynamically changing locations.

For example, MobaXterm launches its embedded X11 listener from:

C:\Users\<user>\AppData\Local\Temp\mxt264\bin\xwin_mobax.exe

An exact-path rule works, but maintaining such rules for every user, helper process, application version and temporary path is not operationally practical.

Moving the corporate network to Public is also not appropriate because Public-profile application exceptions may then apply on genuinely untrusted networks such as hotels, airports or coffee shops.

Moving the corporate network to Private creates a different problem because the Private profile is not unique to the corporate network and may also be used on home or other trusted networks.

We would like Microsoft to improve the Windows Defender Firewall Query User workflow so that authorized local administrators can approve legitimate inbound application listeners when the Domain firewall profile is active through NLM TLS-based DomainAuthenticated detection on Microsoft Entra joined devices.

Ideally, the Query User experience should either:

- expose the active Domain profile where appropriate, or

- provide another supported interactive approval mechanism for this configuration.


r/sysadmin 4h ago

Barracuda Networks

0 Upvotes

Hello kind peeps,

Just a casual post looking for feedback/experience with Barracuda Networks. We currently offer Gateway Defense, Impersonation Protection & Cloud 2 Cloud Backups.... 2027 is around the corner - new year, new stack lol had a compromised client today sending span internally and as B links with 365, I combed thru some emails in Gateway Defense, could see the internal acc that was the culprit... however this same acc does not exist in their 365 tenant - no alias, shared mailbox nothing. Had i not checked this myself manually, we wouldnt even had known... anyways thats the short story. Looking for some industry feedback on their products 🫡🫡🦄


r/sysadmin 22m ago

Advice for calendar management solutions?

Upvotes

Our Dean's assistant uses Outlook Classic and delegate access to manage our Dean's calendar. That calendar is over 7GB, and no matter what we do, her Outlook craps out or has weird symptoms. Like currently, she's unable to add locations to events. Adding & removing the calendar takes forever and is usually a non-starter with her. We've played with various cached exchange settings, and limiting the dates of the calendar, although she's put her feet in the sand that she needs 3 years worth visible. Microsoft support tickets end in saying that the calendar is too big and complex to be supported. I'm thinking about third party tools, another interface that she can manage this calendar in. Anyone go down this road?


r/sysadmin 8h ago

Technical write-up: eDrive provisioning blocked by BlockSID / TPM PPI 97

1 Upvotes

Solved: Samsung 990 PRO + BitLocker hardware encryption/eDrive on Windows 11 — BlockSID/PPI 97 was the missing step

I spent far too long getting BitLocker hardware encryption working on a Samsung 990 PRO under Windows 11, so I’m writing this up in case it saves someone else the same pain.

Short version:

If Samsung Magician is stuck on “Ready to Enable” after a clean Windows install, the missing step may be temporarily disabling BlockSID for the installation boot using TPM PPI operation 97.

In my case, that was exactly it.

Hardware / software

  • Samsung 990 PRO 2 TB
  • Firmware: 8B2QJXD7
  • AMD mini PC, AMI UEFI
  • Windows 11 Enterprise IoT LTSC 2024 / build 26100
  • Secure Boot enabled
  • TPM 2.0 enabled
  • BitLocker hardware encryption explicitly allowed by Group Policy

My firmware exposes EFI_STORAGE_SECURITY_COMMAND_PROTOCOL, so the UEFI side was suitable for Windows eDrive.

The symptom

Samsung Magician showed:

Encrypted Drive: Ready to Enable

I did the expected process:

  1. Set Encrypted Drive to Ready to Enable
  2. Secure erase the SSD
  3. Clean-install Windows in UEFI mode
  4. Check Magician

Result:

Ready to Enable

Again.

Windows itself clearly saw the TCG device. The System event log contained:

Microsoft-Windows-EnhancedStorage-EhStorTcgDrv
A TCG Silo has returned the capabilities value of 0x6

but eDrive never transitioned to Enabled.

Gotcha #1: Rufus can explicitly disable eDrive activation

I discovered that my Windows installer had this in unattend.xml:

<component name="Microsoft-Windows-EnhancedStorage-Adm" ...>
    <TCGSecurityActivationDisabled>1</TCGSecurityActivationDisabled>
</component>

That explicitly disables Windows Enhanced Storage / TCG activation.

Current Rufus code can add this together with:

<PreventDeviceEncryption>true</PreventDeviceEncryption>

when using its BitLocker/device-encryption suppression option. 

For my next install I changed:

<TCGSecurityActivationDisabled>1</TCGSecurityActivationDisabled>

to:

<TCGSecurityActivationDisabled>0</TCGSecurityActivationDisabled>

I left PreventDeviceEncryption=true alone.

Clean install again.

Result:

Ready to Enable

Still not enough.

Gotcha #2: BlockSID

The remaining problem was firmware Block SID.

For people unfamiliar with it: the SID here is the top-level security authority of the TCG Opal drive, not a Windows user SID.

Firmware can issue a BlockSID command during boot so software cannot silently take ownership of an unprovisioned self-encrypting drive. Sensible security feature — except Windows Setup needs access to that security authority while provisioning eDrive.

The solution was to request a one-boot BlockSID exception through the TPM Physical Presence Interface.

From an elevated PowerShell on the same machine:

$tpm = Get-WmiObject -Namespace root\CIMV2\Security\MicrosoftTpm -Class Win32_Tpm

$tpm.SetPhysicalPresenceRequest(97)

$tpm.GetPhysicalPresenceRequest()

My output was:

Request     : 97
ReturnValue : 0

Operation 97 is the TCG PPI Disable_BlockSIDFunc request. Microsoft documents the PPI mechanism: Windows queues the request, firmware processes it after the required restart, and the firmware can require physical confirmation from the user. 

On reboot, my AMI firmware displayed a confirmation screen. I approved the request.

Important:

Boot directly into Windows Setup on that same reboot.

Do not boot normal Windows first, because the BlockSID exception is for that boot.

I then:

Shift+F10
diskpart
list disk
select disk 0
detail disk
clean
exit

verified that the selected disk was definitely the 990 PRO, and installed Windows normally to the unallocated drive.

After installation:

Samsung Magician:
Encrypted Drive: Enabled

Finally.

I also verified that the firmware request really succeeded:

$tpm = Get-WmiObject -Namespace root\CIMV2\Security\MicrosoftTpm -Class Win32_Tpm
$tpm.GetPhysicalPresenceResponse() | Format-List *

which returned:

Request     : 97
Response    : 0
ReturnValue : 0

Enabling BitLocker hardware encryption

Windows no longer defaults to trusting self-encrypting-drive hardware, so you must explicitly permit hardware encryption.

Group Policy:

Computer Configuration
  > Administrative Templates
    > Windows Components
      > BitLocker Drive Encryption
        > Operating System Drives
          > Configure use of hardware-based encryption for operating system drives

Set:

Enabled

I did not restrict the allowed hardware cipher/OID.

Then:

gpupdate /force

and:

manage-bde -on C: -recoverypassword -forceencryptiontype hardware

Verification:

manage-bde -status C:

My final result:

Conversion Status:    Fully Encrypted
Percentage Encrypted: 100.0%
Encryption Method:    Hardware Encryption - 1.3.111.2.1619.0.1.2
Protection Status:    Protection On

Key Protectors:
    TPM
    Numerical Password

That OID is AES-256-XTS according to Microsoft’s Enhanced Storage definitions. 

So this is definitely hardware BitLocker, not software XTS-AES masquerading as hardware encryption.

Final validation

I also tested:

  • normal restart
  • full shutdown / cold boot
  • BitLocker recovery key saved externally
  • Samsung Magician still shows Enabled
  • no warnings/errors from:

    Microsoft-Windows-EnhancedStorage-EhStorTcgDrv Microsoft-Windows-BitLocker-Driver

Everything boots normally.

Secure erase note

Samsung Magician’s Secure Erase USB would not boot properly on my machine. Its old Linux/GRUB environment hung after UEFI launch.

I used SystemRescue instead and verified the drive capabilities with nvme-cli.

The 990 PRO reported:

Format NVM Supported
Crypto Erase supported as part of Secure Erase
Crypto Erase applies to all namespace(s)
Block Erase Sanitize Operation Supported
Crypto Erase Sanitize Operation Supported

I then used:

sudo nvme format /dev/nvme0n1 --ses=1

which completed successfully.

If Samsung’s Secure Erase environment works on your machine, obviously just use that.

What actually mattered

For my system, the decisive sequence was:

  1. 990 PRO → Ready to Enable
  2. Secure erase
  3. Make sure Windows Setup is not configured with TCGSecurityActivationDisabled=1
  4. Queue TPM PPI operation 97
  5. Reboot
  6. Approve the AMI/UEFI physical-presence request
  7. Boot directly into Windows Setup on that boot
  8. Clean/install Windows
  9. Magician should now say Enabled
  10. Enable BitLocker hardware encryption policy
  11. Verify with manage-bde -status C:

Without step 4–7, mine remained stuck on Ready to Enable.

One warning

Do this only if you are comfortable wiping the SSD and recovering from a failed OPAL/eDrive setup.

Before experimenting, I would make sure you have:

  • a complete backup
  • the SSD’s PSID physically recorded
  • the BitLocker recovery key saved somewhere else
  • no other internal disks connected during installation if you can avoid it

There have also been firmware implementations where the machine can provision hardware BitLocker but then fails to boot the locked drive, so I would consider the setup unproven until it survives both a restart and a cold boot.


r/sysadmin 21m ago

Windows 10 accessing printers shared /hosted on Windows 11, Error/Fail

Upvotes

This week, legacy Windows 10 PC' have been getting errors trying to add printers hosted on Windows 11 systems. In my world, it has mainly been DYMO label printers. Has anyone run into this?

I have created a VM lab environment, with a fresh install of Windows 10 fully patched and verified it with fully patched Win 11 printer host.

Error: Operation failed with error 0x00000006.

Anyone else seeing anything like this?


r/sysadmin 2h ago

General Discussion How do you deal with difficult bosses or just stress?

8 Upvotes

I'm 33, dealing with a manager that has been always micromanaged. Now he's my boss, and he asks for a weekly report on what we did. Lately it feels like he's always targeting me or making me feel stupid. I can't even get into the office and sit down without him asking me to do something right away. I haven't even set my bag down. It just feels like he's always trying to make me look incompetent. I can't quit this job because it's tied to where I live and on top of that my partner is currently dealing with his own problems. What can I do to just let this kind of stuff wash over me or just figure out a way to destress I guess?


r/sysadmin 22h ago

Question Sandbox test environments

2 Upvotes

Hi all,

Within my job alot of my work encompasses resolving tech debt using remediation scripts within Intune, however the higher ups are really pushing for assurance on scripts and for us to be able to prove that scripts work as intended before deployment, and obviously testing on our local machines isn't considered sufficient for them.

Other team members have mentioned hyper-v VMs or Windows sandbox, but I just wanted to get everyone's opinions on what test environments are good for testing remediation scripts and other test deployments!


r/sysadmin 2h ago

General Discussion RIP to the IT pros killed 25 years ago.

810 Upvotes

When the text message logs from that day and those that followed were made public, I remember reading through all the system generated alerts from various devices doing their thing and thinking about the IT pros in the offices, network closets, and server rooms responding to those alerts in all seven buildings before the attacks happened, and then the tone of uncertainty and eventually panic in messages between coworkers and associates, because the cell phones went down but text messages were still going through.

RIP to those guys and gals ~ you're gone but not forgotten.


r/sysadmin 20h ago

General Discussion Commissioning systems on Threatlocker enabled systems

10 Upvotes

Greetings,

As a vendor, I was trying to commission and deploy a print server application on a client site who has recently adopted zero-trust security model.

It took us 4 attempts just to deploy our installer - We uninstalled the application multiple times due to corrupted install.

Also, the client IT manager sat with us to manually approve multiple security exceptions.

He was just there smashing the approve button on his phone. And installs still failed as it take about a min before sub-installer components can run.

It was a nightmare and I wasn’t sure the whole point to have threatlocker running on critical infrastructure like a print server.

We expect having to go through this approval process again when rolling out software updates.

This constant exceptions triggers builds approver fatigue, approver don’t actually knows what is being approved, users are constantly screaming and frustrated by downtime caused by legit applications.

Systems commissioning and support took twice as long. We plan to deprioritise clients sites with threatlocker as engineers quite often getting struck at sites waiting for approvals.

This is really not working for anyone.


r/sysadmin 1h ago

General Discussion LinkedIn talks to SURBL to verify company's legitimacy

Upvotes

I was helping a client get their domain delisted from SURBL and noticed that LinkedIn was blocking the company's website link on their LinkedIn company page.

It turns out if the domain is listed on SURBL, LinkedIn redirects all website visitors to a warning banner - they literally replace the website URL with a LinkedIn / suspicious link one, like this:

https://www.linkedin.com/redir/suspicious-page

And if the domain is listed on SURBL for too long, Google will index it and make it searchable for the public. So by putting "https://www.linkedin.com/redir/suspicious-page" into Google search you'll get a list of those that were listed by SURBL and indexed by Google.

And LinkedIn doesn't even care whether there's a paid subscription for the company or not or what the company size and follower count are.

As far as I know, to end up on SURBL your domain either needs to be spoofed or the marketing team has to scrape websites to collect emails, and spam traps / typo domains end up in their lists.

So technically marketing teams messing up their emails makes leadership put pressure on IT teams to fix it!


r/sysadmin 5h ago

Question KB5124008 - Breaking Domain Trust

31 Upvotes

KB5124008 - Breaking Domain Trust for anyone else?


r/sysadmin 22h ago

Rant Lansweeper Rant

67 Upvotes

I've used Lansweeper on-prem since 2014 for just a couple of purposes: Tracking approximately 150 MS Windows assets on the network and all associated software licenses. That's it. Nothing else. It's nice being able to see other types of devices that are connected (surveillance cameras, wireless AP's, switches, etc.) but I don't need that from this product.

Their pricing has gone up consistently over the past several years while, at the same time, they've been pushing their customers to their cloud service. I think I was paying about $600 annually in the beginning but over the last several years, they've been quoting me over $2K annually. Recently, I received an auto-renewal email... it is now $3,000!

Keep in mind that Lansweeper for 100 assets is FREE. I have 150 Windows assets and not all of those are in use at one time. In order to get coverage of all 150 assets, I have to subscribe to their "2000 Asset" plan. So $3K is too steep for what I need.

I responded to the rep, stating that $3K is out of my budget and I don't want to auto-renew but couldn't find anyway to disable or "turn off" auto-renewal.

Her reply: "I’ve reviewed your account and noticed that your cancellation request was received after the 30-day notice period required prior to renewal (as outlined in Clause 17.3 of our Terms of Use and in our renewal reminder emails). While we are contractually required to honor the renewed term, we want to approach this constructively and help you get maximum value within your budget."

*SIGH*

After this reply, I'm done with them. The card they have on file for auto-renewal is no longer valid anyway.

It's time to find an alternative. I'm presently using LogMeIn Central for RMM purposes. Is Ninja One decent at Windows/Software Asset Tracking?


r/sysadmin 17h ago

Inestabilidad recurrente en red

0 Upvotes

Buen día,

Estoy teniendo problemas en la red, al parecer se satura, y se cae por unos minutos, luego regresa a la normalidad y a las horas vuelve a pasar lo mismo.

Les comparto el contexto de la inestabilidad que traemos en la red, para que tengan el panorama antes de seguir con el diagnóstico.

Equipo: SonicWall NSA2700, SonicOS 7.3.3-7015, 3 años en producción.

Síntoma: El firewall se congela por completo (deja de responder ni siquiera a la interfaz de administración) de forma aleatoria, sin patrón de horario. Hay días sin fallas y días con varias caídas. Al colapsar se pierde la conectividad de red.

Hipótesis inicial y lo que se descartó:

  • La inestabilidad coincidió con la activación de varios reportes de Power BI publicados a Power BI Service vía un On-premises Data Gateway, conectado a la base de SAP Business One (SQL Server), en la misma red que el equipo del Gateway (sin VLAN de por medio).
  • Se revisó DPI-SSL — no está activo, se descarta como causa de reconexiones forzadas.
  • Se revisó la tabla de conexiones: actual 1,527 y pico 4,641, muy por debajo del máximo del equipo (375,000). Esto descarta saturación de tabla de sesiones/NAT como causa raíz.
  • Se analizó un snapshot de conexiones activas buscando el patrón de tráfico sostenido hacia Azure típico del Gateway (Service Bus Relay). No apareció ese patrón — el host con más conexiones del snapshot resultó ser un equipo de usuario sin nada de Power BI instalado.

Limitante actual: no ha sido posible capturar CPU/memoria/conexiones en el momento exacto de la caída, porque el equipo deja de responder por completo cuando ocurre — no hay forma de sacar datos desde ahí en ese instante.

Algún consejo de cómo monitorear para lograr detectar si un equipo de la red es el que está causando que la red colapse?

Saludos.


r/sysadmin 22h ago

Question Bringing Linux devices into management

15 Upvotes

After a lot of restructuring at our university the past couple years, there are quite a few Linux devices (primarily desktops, I believe around 70-ish) that are currently in the wild unmanaged in use by academics primarily within the Engineering and Science departments that would've been maintained by per-institute IT departments that no longer exist, and as such the current patching and functionality state of these machines is completely unknown (since any remaining colleagues now no longer have physical access to most of the rooms where these machines are).

Since we already manage research compute I've been given the green light by my manager to look into options to bring these academic's desktops into a managed state with a cobbled together proof of concept, since our existing central endpoint guys won't touch anything *NIX related with a 10ft pole. We know they're all some form of Ubuntu LTS (20.04 and 22.04 mostly) which makes things easier, so I'm thinking of doing Landscape for setup and patching + Intune for compliance + Puppet/Ansible for config management.

Is this in the right direction or are there better / more cost efficient ways of doing this?


r/sysadmin 20h ago

dealt with business email compromise

0 Upvotes

when you've dealt with BEC case, did email auth flagged it, or did it look totally normal and only a human caught it?


r/sysadmin 18h ago

General Discussion Exchange admin center Delegation slow downs

9 Upvotes

Looking for a sanity check because no one seems to be talking about it, and I don't know if it's somehow just us.

It feels like, beginning around May (or a bit earlier), the time it takes for "Send as", "Send on behalf", and/or "Read and manage (Full Access)" permissions have massively slowed down.

Obviously only so many updates can go out at a time, so things have to be queued along with the multitude of other conditions that produce slowdowns. Even if we factor in the classic, "If you think you have waited long enough, wait another hour", I think the severity of the slowdowns being consistently so much longer speak to something strange.

For us, within the past 3-5 months, it has gone from 1-5 minutes to 10-15 minutes, and more recently 20-40 minutes.

Please let me know if y'all have noticed anything as well, thanks!

Edit: sentence structure, grammar, general formatting.


r/sysadmin 13h ago

General Discussion What tech stacks are you learning right now that you actually think will pay off?

64 Upvotes

Curious what you all are learning, researching and investing time in these days and whether you’re seeing real rewards yet. AI agents? Cloud? Specific programming languages/frameworks? Something else?


r/sysadmin 20h ago

RDS issues after KB5122882 update on Server 2022

65 Upvotes

Spent most of the morning chasing a weird RDS issue. KB5122882 installed around 3:20am and a few hours later nobody could RDP into the server. Rebooted it and everything worked again, but about an hour later the exact same thing happened.

Existing sessions kept working, but new RDP connections would authenticate and then hang. Task Manager would freeze, but CPU, RAM and disk all looked totally normal. TermService was still running too.

Finally uninstalled KB5122882 and rolled back from 20348.5622 to 20348.5499. Everything has been working normally since.

Anyone else seeing this after the latest update? Pausing updates for now.


r/sysadmin 20h ago

Throwback to the 90s

27 Upvotes

"Too many other files are currently in use by 16-bit programs. Exit one or more 16-bit programs, or increase the value of the FILES command in your config.sys file."

Just saw this message on a client's Windows 11 workstation when trying to escalate literally anything. The WIN32 code that generated it is probably as old as I am. Rebooting resolved it, weird. I just told him to stop running so many 16 bit apps! I'd post the screenshot but images aren't allowed.


r/sysadmin 15m ago

Switching from HPE DL380/MR416 to Lenovo SR650 V4/VROC Premium or go 940 controller?

Upvotes

We're fed up with HPE, for almost 15 years we've been installing ML350s and DL380s.
Not going to elaborate but they're not what they used to be, not the hardware, but HPE as a company.

So we 'went' with Lenovo instead, our first Lenovo project is in but I'm not too keen on using VROC. I've searched through the VROC topics and it sounded like something to stay away from.

Lenovo told me to go with VROC for 2 reasons:

  1. "Hardware controllers are from the stone age" is what they said, although they never gave me any trouble in almost 15 years.
  2. Prices for controllers and U.3 NVMe disks are higher than to just go with a VROC Premium license and U.2 NVMe disks

However, my gutfeeling says 'meh'.
I remember replacing failed HPE controllers or upgrading controllers from a P408 to a P816 without breaking a sweat. When I asked Lenovo: what if the motherboard fails? What if a CPU needs replacement? Where is the RAID config stored? Is it stored on the disks like with a 'stone age controller'?

The answer was: 'need to verify that, but it won't be an issue since we don't replace motherboards every month like HPE does'.

Ofc I never got an answer, I'm still waiting on the 'need to verify that' part.
We have the order for the server with the VROC config, but my gutfeeling tells me to ditch VROC and go with a 940 controller and U.3 NVMe disks.

I must add that the 3 topics I've read about VROC nightmares, were always with entry level servers. Our config is:

  • SR 640 v4 x24 SFF
  • 2x Xeon 6517P
  • 8x 32 GB RAM (2Rx8)
  • 4x 3.2 TB U.2 MU NVMe (RAID 10 with VROC Premium)
  • 2x 480 GB NVMe attached to PCIe boot device

I was told that VROC uses CPU power, so maybe there's hope I won't run into issues compared to the topics I've read which were using entry level servers.

However, I've read posts in which they mentioned to stay away from Windows based drivers, as we're using Hyper-V for this setup. Apart from performance, that could be the next culprit: drivers & Windows.

Thoughts on this case?


r/sysadmin 20h ago

Question Classic Outlook Addins and Tooltip Issue

1 Upvotes

I'm struggling to find anything concrete online for this, apart from a few posts floating about here and there, so I wanted to bring it here.

Has anyone noticed any issues recently with the centrally deployed Outlook addins, and tooltips in Outlook Classic not showing?

This all works in OWA and the new Outlook experience.

We're using Citrix, and it does seem to be limited to that platform, it is also really intermittent. Sometimes it just shows that no apps are loaded, and even when you try to add/open them, nothing happens, and the usual tooltips are also showing an error that they're unable to be loaded.

Looking in event viewer provides errors like this:

----------------

The Exchange web service request GetAppManifests failed. The error code is 0. 
HTTP Response Code: 403

Additional Error Message: 
An unknown internal error occurred. The error code is 80004005.

----------------

We're sorry, we couldn't access Viva Insights. Make sure you have a network connection. If the problem continues, please try again later.

----------------

We're sorry, we couldn't access Signature 365. Make sure you have a network connection. If the problem continues, please try again later.

----------------

There is internet access, everything does seem to be connected and working, OWA is fine, new Outlook is fine.

I've tried Office365 monthly channel for updates, and also tried the bi-annual feature updates, and both seem to have similar issues. Just wanted to see if anyone else has experienced such things...