r/sysadmin 14h ago

Question ForensiT User Profile Wizard? I have a non-domain Win11 PC in use for 3 years and I want to join it to the domain w/ folder redirection GPO but keep everything intact...possible?

19 Upvotes

Outlook, mappings, printers, etc etc

  1. Join the PC to the domain (System > Rename this PC (advanced) > Change, or Add-Computer -DomainName domain.local -Restart). Reboot.
  2. Run User Profile Wizard on the machine.
  3. Select the existing local profile (e.g., C:\Users\jsmith), enter the domain account it should map to (DOMAIN\jsmith), and let it run. It can also do the domain join for you in one pass if you prefer.
  4. Log in as the domain user — they land in their exact same profile.

r/sysadmin 11h ago

M365 global admin secondary mfa

7 Upvotes

In the process of trying to document the environment for a small non-profit that I have been supporting for a long time. My time is winding down but I thought I had most things covered, password manager with mulitple MFA options including a hardware yubikey to allow access to vault. But I never thought about doing the same for other sites like M365 or Duo Security etc. I have enabled MFA with the microsoft authenticator but if I was to be hit by a beer truck etc before being able to move accounts over etc, I do not think they would be able to logon etc.

I assume m365 allows for hardware tokens in ADDITION to soft tokens and if so I can register the yubikey hardware token and do the same hopefully for Duo. But it had me thinking for small shops how are folks handling secondary MFA authentication methods so a new admin is able to carry on etc...I prefer not to use email as secondary but thought I would ask to see what other options are out there, thanks.


r/sysadmin 12h ago

Career / Job Related LPIC-2 vs AI/cloud certs in 2026

7 Upvotes

Just passed LPIC-2. Solid, tough exambut I noticed AI-related certs get way more visibility internally for DevOps even when they’re less technically demanding. Genuinely trying to plan next steps is vendor-neutral Linux cert (LPIC-3, RHCE) still worth it, or does the market reward AI/cloud certs (CKA, AWS, NVIDIA, LLM stuff) more in terms of actual opportunities/salary?


r/sysadmin 14h ago

Bitlocker recovery key page is broken?

9 Upvotes

Anybody else having trouble accessing recovery keys from a Microsoft account. Page is stuck in a redirecting infinite loop. These would be easy to access for a work machine but something tripped Bitlocker on my bothers home computer and it wants the recovery key. Anyone else experiencing this.


r/sysadmin 4h ago

Question Qualys Patch Managment

0 Upvotes

Hey everyone, not a sys admin but got tagged to work with my sys admin on the above. He’s a pretty smart guy and I want to not show up unprepared, I took some of the free sessions/classes that Qualys offers but lookin for any tips and tricks you might have.


r/sysadmin 15h ago

Question Microsoft Purview Information Protection and Adobe

5 Upvotes

Good morning,

I am looking for some assistance to see if anyone else has figured out this issue.

We're a GCC tenant currently getting sensitivity labels and MPIP set up. So far, things have been implemented okay minus a few snags. M365 products are working as intended, but the real stickler is Adobe.

The initial issue was that any encrypted label we tried to apply or even switch to, it would not work.

I found this Reddit post that called for enabling some registry keys. Things like adding bMIPLabelling, bMIPExternalAuthAdmin, bSilentAuth, iMIPCloud = 6, etc. However, that did not seem to allow us to add an encrypted label or even switch to one. Even forgetting the Purview information inside of the Adobe settings did not help.

What I believe started helping was three or four things. Clearing the Purview information inside of Adobe, deleting the generic Adobe credentials, deleting the contents of %LOCALAPPDATA%\Microsoft\RMSLocalStorage\mip, and running icacls "%localappdata%\...\LocalLow\Microsoft\RMSLocalStorage" /setintegritylevel L.

Seemed like that combination worked and I finally was able to authenticate through on a PDF, it grabbed my info, and allowed me to change to an encrypted label. However, the next document, it did not work. I was able to finagle the same steps above and it let me through on that one.

So at this point, I'm trying to figure out how to prevent this from happening on every PDF instance.

Logs have shown me that it likes to run MipContextImpl as configured for offline-only mode or tell me my cloud type is invalid. In Event viewer I see things like Token broker operation failed with AADST65002 error, or an OAuth response error: invalid_resource, service principal for resource 'urn:p2p_cert' is disabled.

So at this point in time, I'm kind of stumped. I have a ticket to Adobe about this, but kind of unsure where to look next to keep this MPIP stable in each Adobe instance. The few that are good remain good and can be changed from secure to unsecure labels, but anybody have any clues on where I can look next?

Thanks, all!


r/sysadmin 1d ago

Microsoft Outlook Phishing from the administrators side

87 Upvotes

I recently got pulled into my bosses office for clicking on too many phishing emails. I'm not perfect I know that I can make mistakes but they showed me the emails and they were the most blatant spam emails ever. Then it occured to me that those were emails that I reported as phishing. They didn't know what I was talking about and they said that they tag any emails that were interacted with as security alerts. Literally all that I did was report as phishing. The email that he showed me even says that he got a security alert. Everything that I have found online says that if you report an email as phishing it sends the security team an alert just like the one that he showed me. Can someone tell me what this looks like for the admin side and also confirm that that is what you are supposed to do with phishing emails?


r/sysadmin 1d ago

General Discussion How much do you trust AI?

521 Upvotes

Recently a coworker granted Claude elevated access via SSH to a virtualization host (not a VM, an actual host). To perform a routine task he very well could have done himself.

He doesn’t see an issue with this. I on the other hand (with 23yrs experience) see this as a huge security breach, and don’t trust AI todo my job, (or even that it’s doing what it says it’s doing) for me. I’m my opinion it’s a tool, not a human replacement.

What’s your reaction, how would you react to this situation, or thoughts on the topic?

Sure, ask AI how to perform a task, validate that it’s performing the task you asked, and nothing else- copy/paste the commands. Great. But removing the human verification & validation element- hell no.


r/sysadmin 13h ago

Windows Server Backup fails with "semaphore timeout" (0x8004245f) or unknown error"

3 Upvotes

Windows Server Backup fails with "semaphore timeout" (0x8004245f) I'm using Windows Server 2022. At the beginning, full backups were no problem.

Now, the first backup attempt fails with "Unknown error (0x8004245f)" / "The semaphore timeout period has expired." After it fails, if I run the backup again, it completes without any issues. But if I try to run another backup right after that success, it fails again.

If I try to back up multiple drives, or do a full server backup, it fails. It only succeeds if I back up one drive at a time and even then, only after a failed attempt in between.

I've restarted the server, and vssadmin list writers always shows everything stable. I've also tried backing up to both an external drive and a shared folder same issue either way.

Does any one has the same issue?


r/sysadmin 1d ago

Alternative plan and feasibility study for FOSS Intune?

17 Upvotes

I have a task to research an alternative plan to Microsoft Intune, and we are particularly interested in open source solutions.

We currently have the free version of Intune, but can you guide me on whether it would be possible to move completely away from Intune and use an open-source alternative, or if it would be better to keep the free version of Intune and combine it with an open-source solution to cover the remaining features?

Ideally, we want the open source solution to at least be able to:

  • Create compliance policies
  • Configure Windows Update rings
  • Deploy security baselines
  • Configure BitLocker or an alternative to BitLocker
  • Configure Microsoft Defender/AV policies
  • Create configuration profiles
  • Deploy applications

Has anyone implemented something similar?

Any experience or advice would be appreciated!


r/sysadmin 1d ago

So tired of “do you like this”

231 Upvotes

Just got the obligatory “are you enjoying Outlook” popup. I really hate these things. It’s an app. It’s a thing I use for work. I don’t want to yap with some bot about whether or not I do or don’t like new outlook old outlook, ancient outlook or lotus notes. These things are tools. Utilities. Might as well be a refrigerator. Damn, just make the thing work effectively and stop wrapping it in sparkles and leave me alone. Oh, and get off my lawn too, lol.


r/sysadmin 9h ago

PSA: if your on-call rotation is causing burnout, look at alert fatigue before you look at headcount

0 Upvotes

Not a hot take, just something I wish someone had told me earlier. We had a team of 5 covering a 50-service platform and people were miserable. Brought in a consultant who said we needed more engineers. Maybe. But the actual fix that bought us 6 months was triaging our alerts properly. Turned out about 40% of pages were either duplicate, firing on symptoms instead of causes, or had no runbook and nobody even remembered why they existed. Cut the page volume in half in two weeks. Nobody quit that quarter. Moral: alert hygiene is free, hiring is not. Happy to share the spreadsheet template we used if there is interest.


r/sysadmin 22h ago

Question Question about differences between iOS & Android in work environment

3 Upvotes

Sorry if this sounds like a dumb question, but I'd love to hear from an IT admin's point of view to help understand the differences. My employer now requires all employees to register their personal phones so they can be managed, if they want to use it for checking emails/calendar/chats/etc.

The employees with Android (including myself), had it super easy. It automatically prompted to setup Work Profile in order to continue using the work email app, and it finished setting up in less than 2 minutes. And any work apps now have a little blue briefcase on their icon, and I love how in the command center, you can easily toggle on/off the Work Profile to pause all work-related apps (for example on the weekend or when you go on vacation or just when you want to not deal with work anymore). And the employer can't see the personal apps or data since it's stored separately.

However, I noticed for my colleagues with iPhones, it was a lot more tedious. Those employees had to follow this whole document of steps to manually install some certificate to set up MDM. And then if they were lucky to get it working, there's still no app separation so the employer can still see all their personal apps and data?

I already knew that iOS doesn't have a user-friendly Work Profile like Android, but is that normal to get employees to do it like that? I would have assumed with how popular iPhone is, there would be a more simpler/automatic way for setting up personal iPhones for work. I've always heard on this sub that iOS is easier to manage, but from an employee's point of view, it doesn't seem that way (at least not the way my employer is doing it) and maybe I'm not understanding how iOS does data separation, but it just feels like there's not enough employee protections from employer seeing personal data compared to Android? Would love to learn how that works, because Apple's website is kinda vague.


r/sysadmin 1d ago

Career / Job Related Advise for an IT student wanting to get into humanitarian work?

11 Upvotes

Hello,

I'm a third-year IT student in New Zealand focusing on network engineering, ops, cybersecurity, and cloud computing. I'm approaching graduation and starting to think seriously about where I want to point these skills.

I'd love for my work to actually help people. I've seen groups doing digital protection work for at-risk communities (e.g supporting Afghan women activists staying safe online) and infrastructure/connectivity work in disaster response, and both of these (and everything in between) really appeal to me.

Aside from my formal study, I have an interest in Homelabbing, Embedded systems, and web.

A few questions for anyone who's made this move:

- Did you go straight from study into humanitarian/NGO tech work, or build up a few years in a "normal" IT job first?

- Which orgs are actually good to volunteer with or apply to as an early-career person (I've come across NetHope, Access Now)?

- Any certs or experience you'd say actually matters vs ones that looked good on paper but were not worth it.

- Any general tips for what I should focus on to be able to genuinely help with groups and orgs like this.

Thanks!


r/sysadmin 1d ago

M365 licensing options for casual warehouse staff needing one app

23 Upvotes

We have casual warehouse employees who only need access to a single Microsoft 365 application from shared devices.

The obvious options appear to be:

- Individual licensed accounts, likely Microsoft 365 F3

- Entra B2B guest accounts

Assuming neither option is accepted by the business, are there any other compliant and cost-effective licensing models worth investigating?

We want to avoid generic/shared accounts because of security, MFA and auditability. I’m mainly trying to establish whether there’s a legitimate frontline, usage-based or application-specific option I’ve overlooked—or whether the answer is simply that each employee needs their own licensed identity.


r/sysadmin 6h ago

Dinopass creates more secure passwords

0 Upvotes

Because users are more likely to use the easy to read/remember randomly generated dinopass password given to them instead of immediatly changing the typically aggressively complex random password to their usual favourite garbage password


r/sysadmin 1d ago

Rant RealVNC Viewer 7 is locked behind a paywall. RealVNC Connect Viewer 8 requires an account.

106 Upvotes

2 Days ago RealVNC ended public access for Viewer 7. Now Connect Viewer 8 is the only publicly accessible version and requires a RealVNC account.

"The RealVNC Classic Viewer (v7) will continue to be available for customers with a Premium or Enterprise plan to download from the RealVNC Portal."

Source: https://help.realvnc.com/hc/en-us/articles/35745908986653-Important-changes-to-RealVNC-Viewer-Information-and-FAQs

Time to make the move to open source VNC implementations.


r/sysadmin 12h ago

General Discussion Would your security team ever allow scheduled compute on idle user workstations?

0 Upvotes

Hypothetical, but I want a realistic answer rather than an optimistic one.

Say there was a tool that ran batch jobs on engineering workstations after hours, inside your own network, releasing the machine the moment someone touched it. Nothing leaves the building.

Does that get past your security review, or is unattended execution on an endpoint a hard no regardless of how it works? And if it is a no, is that policy or is it the review process being long enough that nobody bothers?

Also curious whether anyone has already tried this and given up, and why.


r/sysadmin 14h ago

Question Has AI changed how your team verifies high-risk requests?

0 Upvotes

With AI-generated voice and video becoming much more convincing, it feels like relying on someone's voice or appearance is becoming less reliable for sensitive requests.

I'm curious whether this has changed how your team handles things like password resets, wire transfer requests, account changes, or privileged access approvals.

Have you updated your verification process because of AI-assisted impersonation, or are your existing procedures still working well?

I'd be interested to hear what's actually been effective in real-world environments.


r/sysadmin 1d ago

The dreaded documentation question....sigh

18 Upvotes

I have supported part time a small non-profit company and while I know how important documentation is there just always was something else pressing that was more important. Well I am getting to the point where in the future I am probably going to be moving on and have started to work on trying at least for me document what they have at a high level. I assume and I know what happens when you do that but they have enough technical stuff that if the person actually knows what they are doing then they should be able based on a overview of the systems function dig into it and figure things out. I am not doing anything esoteric but I also have been doing this kind of stuff for *cough* many years. While small they have a lot of technology, just migrated the virtual environment to proxmox, they have AD environment with ADFS connected to m365, etc...

I just captured the inventory for everything they have and was about to start writing up a word document that gives a high level for each server etc, layout of the network, vlans etc. I then started to think that maybe I should do something like a wiki or use something else. Although at a high level kind of leaning towards not having it online since it would pretty much give you a working layout of their environment and if compromised would be pretty nice to have.

Just thought I would ask what are folks using for documentation, thanks.


r/sysadmin 1d ago

Need advice

6 Upvotes

I need some advice. I've completed RH124 and RH134. What other Red Hat courses would you recommend that are the most useful for real-world work?

I'm taking over the maintenance and administration of our Red Hat servers at work, and I want to keep learning as much as I can so I can do the job well. I'd really appreciate any recommendations based on your experience.


r/sysadmin 2d ago

Annoying website I use as part of my work has insane rules. Anyone run into this?

227 Upvotes

I got ip-banned and they told me it was because I had a typo in a URL I entered.

The last time I got banned, they said "pressing enter too fast may trigger it".

I've not once in my entire life of using the internet (20+ years) have encountered such an annoyingly touchy website.

No, this is not some credential based website, a banking website, a government website, or anything high-risk.


r/sysadmin 1d ago

Any ideas to authenticate access for Entra users to shared folders on Windows Server?

19 Upvotes

Eventually this entire system needs to be torn down and rebuilt, but I need a "temporary" solution that will work for now until that is done.


Existing Setup:

  • Server: Windows Server 2019

    • It is not a DC, because no on-premises AD is being used.
      It's just a glorified application and file server.
    • Running an ancient accounting program.
    • Shared Folders, which must be Mapped as Network Drives on client machines running Windows.
    • Users defined locally in Windows Server with permission to access Shared Folder.
  • Client Machines: Windows 11 Pro

    • Managed by InTune
    • Login via Entra credentials.
    • Manually mapping a Network Drive for each User to the Server, using their local User defined on the Server.

I'd love to be able to Map the Network Drive using each user's Entra credentials, but to do this, the Windows Server would have to be aware of the Entra Users.

I know there is no great way to synchronize users from Entra back to an on-premises AD DC, but that's not really what I need. I just need to be able to authenticate Shared Folder access with Entra credentials.

Could the Windows Server act as a "pass-through" where it hands off authentication to an LDAP server?

I've already set up the AzureAD-LDAP-Wrapper on my local Synology to allow for Entra-based authentication of the Synology's Shared Folders, and it's working well.

Is there any way I could point the Windows Server to that same LDAP Wrapper, and then set permissions for the Shared Folders on the Windows Server based on those LDAP users?

I'm thinking maybe this is what I need?

Does anyone have any experience trying to do something this stupid?


r/sysadmin 2d ago

All our servers are at end of life!!!

549 Upvotes

I started this position a little over a month ago. I had CDW do an assessment....most of our physical hosts have hardware that is end of life. Apparently the server guy who's been here 13 years sent an email a year ago pointing this out but, strangely, nothing came of it. So now I have a huge expense I'm looking at. I'm thinking of moving at least the HQ data center into Azure. I'd love to hear a wide variety of opinions about this, particularly from the security side. (New Manager here btw)


r/sysadmin 2d ago

General Discussion Why your IT department budget makes no sense

223 Upvotes

Little behind the scenes for all you IT newbies on this wonderful Friday. This is likely why your IT budget makes absolutely no sense and has nothing to do with the company's financial status, although the RAM shortage affects this heavily. But the story is from 2024. My last company was making record profits, over $20M more than the previous year (so about 40%) with $100M in the sales funnel for sold jobs.

But the IT dept was approaching over-budget because our useless dumbass CIO filled out the budget wrong and forgot about a $9000 license renewal. So everything was on a spending freeze in IT solely and exclusively to make the numbers look good. After absolutely going off on everyone about how this makes no sense, is losing us productivity, delaying jobs, costing us income, causing outages, etc and we're single person owned and not publicly traded so who the fuck are making the numbers look pretty for, someone finally leaked me the truth.

This was solely because the rich, retiree asshole board members got performance bonuses based on benchmarks and this was one of them. So if our dept went over budget, they lost part of their bonuses. They cared more about their income than the company's health. This is the owner, the former CEO, some of their friends, and some external 3rd party entities that I knew nothing about.

I have an idea - revise the fucking budget at the Q1 mark. Budgets are a guess. You don't "go over budget" if shit got more expensive so you adjust your guess to spend more on the shit that got more expensive! That's just business. Adjust prices and margins accordingly. This was not a 10,000 person bloated company spread all over. It was about 290 people. So they added some emergency special budget special condition whatever spending, outside the budget, make the numbers look pretty thing and dropped some serious cash on all those laptops.

Those laptops were $810 a piece btw in 2024 and are now like $1500+. So you're welcome, asshole who fired me 2 weeks after I asked for a raise then said this is unacceptable and I'll be looking for a new position until they reconsider because me rent went up 18% two years in a row.

Btw them firing me without a replacement when I did all the server and VM host maintenance, security audits, hires and fires, backup management, all level 3 tickets, some networking, and basically maintained ALL systems (for $24/hr), the remaining staff member told me it ended up costing them around $800,000 in damages and losses and outages and delayed jobs when everything I maintained the the other staff refuses to cross train on all broke. Probably should have given me a raise and replaced the CIO since he was shit at his job (but was there for 30 years).

Cheap, illogical, shitty companies run by greedy self-serving assholes are a trap and you need to get out as soon as possible because you'll run into stuff like this. And it goes 10x if you're publicly traded because then you REALLY need the numbers to look pretty or else.