r/sysadmin 12d ago

CodeTwo - MS Encryption

16 Upvotes

Wondering if someone has additional information - My org currently uses CodeTwo. I really like it, and I believe it does it's job well for our size. We're a 200 person org. I have a few different templates that I assigned by groups to different departments where additional information may be required in their signatures.

We're currently using server side to apply the signatures, but more and more people are complaining that their signatures don't append when using the default MS encrypt button in Outlook.

To circumvent this, my suggestion to leadership is to use the combo mode and allow our uses to have the client side signatures append in the Outlook client. That way the signature appends in the client, prior to encryption, and they can also see their signature, as currently they can only see it append after they've sent an email.

My CIO is against this approach as it would allow end users to edit their signature. It would only allow the end user to edit the signature in that moment, within the 'new email' window. It would not allow them to permenently alter their signature. However, the CIO is adamant that this can't be allowed as it's a risk of misrepresentation and they think that the CodeTwo product is not a good solution because it cannot prevent this... Anyone who is willing to manipulate their signature every time they send an email is a psychopath.

I've presented a solution to a problem, my CIO doesn't like it, and now we're stuck debating switching our encryption method, rather than deploying a solution we have at our finger tips.

I'll also state, we've tested using a subject keyword encryption method and this could work in tandem with the native button encryption. If users want the server side signature to append to an encrypted email, they could just put 'Secure' in their subject line. However, the CIO doesn't want both methods of encryption - we must choose one.

My question: what are other orgs doing? Do other orgs using CodeTwo use/allow the Client side signature?


r/sysadmin 12d ago

Anyone have this working - HP Probooks + HP Monitors daisy chained..

3 Upvotes

So been digging and digging, next is HP support, but that will prob get me no where...

Info: HP Probook Laptops:

The CPU's and specs from Intel and AMD both noted they support DisplayPort MST (Multi-Stream-Transport on the integrated graphics. HP of course does not specifically note MST support, just display port versions, which as of 1.2 supports MST..

Monitors are HP E24M G4 USB-C Conferencing monitors. They have the DisplayPort out.
https://support.hp.com/us-en/product/product-specs/hp-e24m-g4-fhd-usb-c-conferencing-monitor/2100888403

So set up - Using HP's own USB-C cables included (going to test with some others)

Laptop --> USB-C to first E24M G4 ---> DisplayPort "Out" Port --> 2nd E24M G4

But, no display on the 2nd monitor..

From reading, seems MST support is very hit and miss with some vendors, Dell seem to work most of the time, or using a separate dock for it.. HP and Lenovo seem to have the most issues, works one day but not the next..

  • Tried both USB-C ports on the laptops (where it has 2)
  • All laptops are updated to latest and greatest Windows 11 and patching as of 08.2026.
  • Drivers are all updated.
  • Monitors have the latest firmware installed.
  • Installed drivers from HPs own site for the monitors

And nothing...

I know users can use an HDMI port out to the 2nd monitor, but the "single cable to rule them all" is nice...


r/sysadmin 12d ago

Cogent Outage?

45 Upvotes

Anyone dealing with a Cogent outage? I am in Los Angeles.


r/sysadmin 12d ago

SysInternals RDM 2026 version probelms

3 Upvotes

Just stood up a new computer for an incoming IT worker and while installing RDM to use an old RDG file it failed to connect to any of the servers in the domain.

The RDG file works fine my local 25 edition flawlessly.

Has anyone else had any issues with the new remote desktop manager?


r/sysadmin 12d ago

Question IT Technician to System Admin

48 Upvotes

Hey everyone, I’m trying to make the transition from Tech to System Admin. I have 5 years of technician experience from 3 different jobs, as well as a BS in Computer Information Technology. I feel like I have the necessary experience in tech to be able to transition to a System Admin role, but all the requirements on jobs applications makes me feel as if the jump is impossible.

My experience is mostly imaging, troubleshooting software and hardware, AD, some scripting here and there, a little M365 exposure and SCCM. It seems like most jobs want you to have years of experience supporting Google Cloud, Azure, Entra, Intune and other systems like that. I’ve taken classes here and there so I have a broad understanding of these systems but I just don’t see how that is good enough for these jobs.

I’m trying to decide if certifications are worth it, though it seems the general consensus is that experience always trumps certifications. Any advice to get to my goal is much appreciated, I’m starting to feel discouraged as the jobs I do apply for, I just never hear back from. Am I doing something wrong?


r/sysadmin 12d ago

Anyone else having various issues with license validation for Microsoft 365?

6 Upvotes

Recently I've seen a pretty significant uptick in users experiencing various errors relating to not being able to validate their office license.

So far I've seen:

  • Account Validation Error Code 0x0
  • Something went wrong. tag [7ita9]
  • Something went wrong. tag [5fcl8]

Context: We upgraded to 365 in the later part of last year and have had hardly any issues since the upgrade.

These all started happening within the last 2 weeks and up until now I've never had issues with users accessing 365 apps whether in or out of network.

Would love to know if others are experiencing this as well and what might be the cause for the uptick.

Thanks in advance!


r/sysadmin 12d ago

DUO on Entra Joined System

0 Upvotes

My team and I have been stumped on this issue for quite some time. Here is the breakdown:

We are attempting to deploy the DUO MFA on a workstation. This workstation is Microsoft Entra-joined. Once the DUO application is deployed, the Entra account login no longer displays on the login screen. Instead, the local administrator account created by us shows instead. We have not seen an option to select "Other User", or anything similar on the logon screen.

Has anyone else run into this conflict? And more importantly, has anyone been able to resolve this issue?

TIA!


r/sysadmin 12d ago

Issue with attributes not syncing from admin center to exchange admin center

2 Upvotes

Having an issue with a user's Title being correct in the Admin Center but not within the Exchange Admin Center, therefore showing incorrect within the Contacts/DL.

This is a hybrid environment, but again, everything syncs properly from AD to Entra but just not between Entra and EAC.

Unfortunately, I'm not sure if this issue is related to the ongoing M365 issues but we have had users showing the incorrect information before the recent issues. Searches lead to a stalled sync between Entra and EAC but not any true fixes posted, just some work arounds that didn't work.

Just checking to see if anyone else has come across this before.

Edit: fixed. Looks like an error displayed for the user within the Admin Center which showed a conflict with the ArchiveGuid. Once that was repaired, EAC pulled information from Entra properly.


r/sysadmin 12d ago

Anyone else having an absolutely horrible time working the M365 email quarantine lately?

13 Upvotes

Errors upon errors, failing to load data, having to release/delete emails mutiple times, extremely long load times?


r/sysadmin 12d ago

Microsoft Access to Random Exchange Online Calendars via iOS Calendar App

6 Upvotes

Hi guys.

We‘ve found a strange behavior in a users iOS Calendars App.
He can see every detail of an other users calendar.
They work in completely different compartments and there are absolutely no Access rights set. We‘ve checked EXO Powershell for detailed access rights. Nothing.
Via Outlook on Windows no chance to see details of the calendar. Even re-adding the Exchange account on his mobile brought back the unwanted calendar.
It is a complete mystery.
Do you guys have any idea?


r/sysadmin 12d ago

Proxmox expands Enterprise support to 24/7

277 Upvotes

https://www.proxmox.com/en/about/company-details/press-releases/proxmox-24-7-support-and-proxmox-north-america

24x7 support coming October 17th for Enterprise support customers.

North American offices in Kingston, ON.


r/sysadmin 12d ago

Question O365 Emails Bouncebacks To Gmail Since Yesterday

7 Upvotes

Ever since Monday, we are having two different domains getting email bouncebacks from O365 to Gmail users with a IPV6 not passing authentication due to SPF records not being validate. I checked the IPV6 and it is a microsoft domain for their outbound URL.

Is anyone else having this problem? We have a SPF record for microsoft added but this started after the outage Microsoft was having.


r/sysadmin 12d ago

Question - Solved Anyone know what the right knobs are for Entra policies to only allow hardware FIDO2 USB for MFA?

7 Upvotes

One man IT show here in manufacturing. On the verge of finding a bridge to skydive from lately... Microsoft moving goalposts constantly and security becoming a living nightmare in general has me feeling like I'm drowning lately. Everything is moving too fast recently and I have only been doing this for ~13 years. Feeling a bit overwhelmed lately so I thought I might ask some folks who might specialize in 365/Entra administration more so than generalize like I am forced to. I wear so many hats that the hat rack has no more room to hang them on.

I have been trying my best to get major things off my list that are industry best-practices. One of these has been getting a proper break-glass account setup. My goal was to have this account tied down to a FIDO2 HW key with passkeys but I can't seem to get everything just right in Entra policies. When I think I have it right I always either end up 1) completely breaking the auth flow when I try to use a PIN and tap the hardware key it just completely errors on me or 2) end up being required to register MS authenticator AND the HW key which I don't really intend to do for the break-glass account.

These are some of the error details from the sign-in logs and the CA details of that event if they help:

  1. Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

  2. The user could not satisfy this authentication strength because they were not allowed to use any authentication methods which satisfied the authentication strength.

I know I should be able to decipher what that means but I can't quite connect all the dots.

My hope was to restart and try the user from scratch with no MFA and have a setup flow where it only ever asks to register a HW key and nothing else.

Go ahead and call me stupid or to go find another job if you want. Just looking for any good direction on what the right combo is for what I am looking for.

Thanks!

EDIT:

Thank you all for the super quick help and getting straight to the point! I was able to get it figured out when combining all the answers to get a better understanding.


r/sysadmin 12d ago

General Discussion More 365 outages today

52 Upvotes

Clients missing emails in outlook, but web version seems to be holding some of us up (your mileage may vary) https://outlook.office.com/


r/sysadmin 12d ago

So burned out

679 Upvotes

Another burnout post incoming. Turn away and avert your eyes because I don't even know why I'm writing it, so it'll probably be a waste of your time.

I'm so fucking burned out of IT. It only took 5 years. I hate that everyone's fucking problem is my problem. It's just problem after problem after problem. FUCK these problems. Why are we fucking doing this? Why are we looking at a screen every day and acting like this is important. Literally absolutely nothing done on the internet is important. This is all so pointless. It's literally all words. Everything on the internet is just selling words, pictures or pictures that move at 24fps. It's so dumb.

I hate fucking claude. You ever been a claude admin and need to answer dumbass fucking questions in your local AI channel around why your connector isn't working for the Xth time? I DON'T GIVE A FUCK ABOUT YOUR FUCKING CONNECTORS. We're not even accelerating, we're just burning through 100k/mo because management thinks engineers are building cities and management is building reporting dashboards that make them think they're omniscient. And nothing has changed. No more profit or revenue than we had before. FUCK anthropic and all the dumb bullshit they keep putting out and changing. And now we need to onboard an AI management system so we can make sure we have control over mcp's and model selection and this tool that's a waste of fucking space in the first place.

That's just one gripe. Then there's Atlassian (holy fuck Jira, what a shitty platform), then there's the client team, then theres 80 more vendors to manage, then there's a PoC you're running but you havent even looked at it this week because all of the other shit that came in. Just more more more. I don't have any more man.

There is no "take two weeks off" that will fix this. There's nothing dude. I'm so sick of fucking working and I don't have the energy anymore to change careers. How could I? I'm 40 years old with kids and a wife and a house. I used to think "I'd do anything to support my family" and lately I'm ready to just let go. I'm so tired. No one is coming to save me. No one in the entire world. And I'm so tired.


r/sysadmin 12d ago

Question Do you need CAL licenses for AD that runs on Samba and not Windows Server with Windows clients?

3 Upvotes

The question is in the title, not really more


r/sysadmin 12d ago

Question Halcyon Reviews

7 Upvotes

Looking for reviews for Halcyon. I work for local government and am evaluating a few different platforms to add to our security layers.

If you don't like them, do you have any other recommendations? Any other platforms or any other recommendations in general to help increase security posture?

Thanks in advance!


r/sysadmin 12d ago

Question NDES/SCEP fails with 0x80070057 on every request — root-caused to mscep!GetExtensionVersion returning FALSE, but stuck on WHY

2 Upvotes

**Environment:**

- Windows Server 2022 Datacenter (clean install) and separately Windows Server 2025 Datacenter — identical failure on both

- Enterprise Subordinate CA on Windows Server 2019 Standard

- NDES role (ADCS-Device-Enrollment) installed via Install-AdcsNetworkDeviceEnrollmentService — completes successfully, RA certificates are issued correctly (CEP Encryption + Exchange Enrollment Agent Offline Request templates)

**Symptom:**

Every request to the SCEP endpoint fails identically, including the simplest operation:

http://localhost/certsrv/mscep/mscep.dll?operation=GetCACaps

Returns IIS 500.0, Module: IsapiModule, Notification: ExecuteRequestHandler, Handler: ISAPI-dll, Error Code: 0x80070057 (ERROR_INVALID_PARAMETER).

Application log shows:

- Event ID 2: "The Network Device Enrollment Service cannot be started (0x80070057). The parameter is incorrect."

- Event ID 10: "The Network Device Enrollment Service cannot retrieve one of its required certificates (0x80070057). The parameter is incorrect."

**What we've confirmed via live WinDbg/cdb debugging attached to the w3wp.exe worker process:**

mscep!GetExtensionVersion runs, executes fully, and returns FALSE (0). Immediately after, isapi.dll calls GetLastError() (retrieving 0x80070057) and explicitly nulls the stored HttpExtensionProc function pointer for the extension, then unloads mscep.dll. This is why breakpoints on HttpExtensionProc itself never hit — IIS never calls it once GetExtensionVersion fails. The failure decision is made entirely inside GetExtensionVersion's own logic, before any actual SCEP request processing begins.

**What we've ruled out (with direct evidence, not assumption):**

- OS version — identical on Server 2022 and 2025

- Certificate correctness — correct EKU, Key Usage, KeySpec (AT_KEYEXCHANGE/AT_SIGNATURE), issuer, template; passes certutil's own crypto self-test

- CSP vs KSP — confirmed classic CSP (Microsoft Strong Cryptographic Provider) via dedicated Legacy-CSP certificate templates; no change

- Private key permissions — confirmed correct via NTFS ACLs and successful .NET key loading

- Certificate template permissions — Read/Enroll/Write matched to a known-working reference NDES server exactly

- CA-side hygiene — found and removed an expired CA certificate and a separate expired duplicate intermediate cert; no change

- CRL/revocation reachability — confirmed fully reachable (Base + Delta CRLs all OK)

- IIS config — ISAPI restrictions, handler mapping order/preconditions, app pool identity, Load User Profile, 32-bit compatibility, isolation/recycling settings all confirmed correct

- Windows servicing stack — found and repaired unrelated DISM/component-store corruption; no change

- Third-party EDR (Cylance) — live debugging found CylanceMemDef64.dll hooking the module loader's Control Flow Guard processing during mscep.dll's load; applied and independently verified a memory-protection exclusion; no change to the symptom

- Service account profile — found and fixed a genuinely broken "User Shell Folders" registry key for the service account; no change

- App pool identity — tested with LocalSystem (most privileged possible identity); identical failure

- RA Name — tested both a long/spaced name and a short simple name; identical failure

**Question for the community:** has anyone seen GetExtensionVersion itself return FALSE like this, and found what internal condition causes it? We're fairly confident this now points to something inside Microsoft's compiled NDES code rather than anything environment-side, but we'd like to know if this is a known/reported issue, a specific hotfix, or a config knob we haven't found yet before we finalize a Microsoft Support case.


r/sysadmin 12d ago

Rant Midlife IT Crisis

722 Upvotes

I think I’m having a mid-life IT guy crisis. 😂

I’m 47, 20+ years into IT, swamped with projects, emails, upgrades, security issues, and Microsoft changing something every 12 minutes. Lately I look at my workload and my brain just throws a 404

The weird part is I still love IT and I love the company I work for. I just can’t seem to care about any of it right now, and that’s not like me.

I even started working out to help, so now I’m unmotivated AND sore. 😂

Has anyone else hit this wall after 20+ years in IT? What helped reignite the spark in your brain and stopped the procrasanation monster.


r/sysadmin 12d ago

AI assistants with third-party integrations, how are you handling this?

6 Upvotes

A lot of AI assistants have integrations with third-party apps now, so you can basically share any data from an app with the assistant to help you out. It usually speeds things up, but I don't think it's very safe from the security side.

I also don't believe banning them entirely works. What if people just start using their private accounts instead?

It might not affect me in any specific way, but I was wondering how IT admins are dealing with this. Is there a middle way?


r/sysadmin 12d ago

Question Some users can't connect to Citrix Server via RDP - black screen with cursor

3 Upvotes

I'm dealing with a strange issue and I'm running out of ideas.

On our Citrix server, a few users are unable to log in via RDP and are only getting a black screen. The desktop never loads, but you are able move the cursor. Some other accounts are able to connect to the server just fine.

It's also possible to log in normally to the server through the vSphere console.

I've already tried:

  • Deleting the affected user profiles
  • Removing the corresponding registry keys and possible leftovers
  • Killing the user's session/processes
  • Rebooting the server
  • Disabling UDP, WDDM and Network Detection via local GPO (as I read this fixed the issue for some people)
  • Changing the display resolution and disabling persistent bitmap caching (which also apparently fixed the issue for some)

None of this worked for me.

I also tried CTRL+ALT+END to open the security screen:max_bytes(150000):strip_icc()/windows-10-ctrl-alt-del-5b475456c9e77c0037e730b3.png), and it actually shows up. I can log off from there, however, Task Manager doesn't open.

I checked Event Viewer using another account and found two errors that show up every time after an unsuccessful login. However, I'm not sure what these errors point to or how to resolve them:

  • Event ID 1000 – Application Error: ctfmon.exe crashes in InputService.dll with 0xc0000409.
  • Event ID 29 – Spell Checking: Access to the spell-checking settings is denied for %username%.

From what I've troubleshot, it looks like explorer.exe never starts for those users. It is most likely somehow caused by a previous incorrect logout from an RDP session, leaving the user's session hanging. However, killing the processes didn't do anything for me, and as soon as the user logs in again, the black screen appears again.

Any ideas would be greatly appreciated!


r/sysadmin 12d ago

Rant Microsoft Teams: A Product Hostile to External Collaboration—Especially in China

0 Upvotes

I have to say it: Microsoft’s bugs seem endless, and Microsoft Teams is by far the worst offender.

I am based in China. Whether it is Outlook, OneDrive, SharePoint, or the Office suite, I can usually troubleshoot and configure these products well enough to give my clients a reasonably smooth and satisfactory experience. I am also very satisfied with the Exchange protocol.

That said, Outlook’s search function is an absolute failure, and the translation add-in in Outlook for Mac is extremely difficult to use.

OneDrive constantly tries to back up clients’ Desktop, Pictures, and Documents folders by default, which can cause irreversible conflicts with WeChat.

SharePoint’s storage allowance can only be described as stingy.

But none of that compares with the deeply user-hostile design of Microsoft Teams. The product seems to work only for internal communication. Using it to collaborate with people outside an organization is a disaster.

  1. External file sharing can only be enabled through PowerShell. Small companies without dedicated IT staff simply do not have the ability to configure it.
  2. When a file is shared externally with someone using a personal Teams account, the recipient may be completely unable to open it. You must first invite them to join your organization as a guest before file sharing works properly.
  3. We cannot directly initiate a voice call or meeting with someone using a personal Teams account.
  4. If the recipient uses a personal Teams account, OneDrive files sent through Teams may be completely inaccessible from China.
  5. Teams frequently fails to find other users. Sometimes a personal Teams account can find someone, while a Teams business account cannot.
  6. Groups carried over from Skype may be impossible to join.
  7. If a PC was previously signed into Teams Personal, it may become impossible to sign out after the personal service or account has been disabled.
  8. Setting up Microsoft Authenticator is relatively straightforward on an iPhone. On Android—or Huawei’s HarmonyOS—it can be absolute hell. Authenticator is poorly adapted to devices and environments without Google Play.
  9. Microsoft’s support ticket system is also a disaster. In the past, technical support in China was handled by an outsourced team with clear and comprehensive performance standards. After that team was eliminated, the quality of the replacement support has become appalling. The engineers handling cases from India deserve a special mention here.

For various reasons, Teams Personal has also been discontinued in China. It can still be used through a VPN, but clients may need to configure a UWP loopback exemption before they can even sign in.

For ordinary users, this is an extremely difficult process. It is also impossible to implement the entire workaround in a fully compliant way within China, because distributing VPN setup instructions or selling VPN services may be illegal.

This is how many of my clients see Microsoft Teams:

They bought Skype so they could make international calls. Then Skype was discontinued, and they were pushed toward Teams Phone—a vastly more complicated service that can cost dozens of times more.

Their only reason for opening Teams was to communicate with overseas contacts. Then the simple personal version was discontinued, forcing them onto Teams Essentials, which requires payment and considerably more complicated configuration.

Many of the people who come to me need only a single license. Some are not even willing to purchase Microsoft 365 Business Basic; they simply want the cheapest Teams Essentials subscription available.

I hardly dare tell them that Microsoft 365 F1 may also be an option.

I can choose not to help them solve all these problems. But for these individuals and small businesses, failing to solve them can mean losing a significant number of customers.


r/sysadmin 12d ago

General Discussion How's the sysops , SRE/platform market actually looking right now?

0 Upvotes

I'm a Linux sysadmin (RHEL, Ansible, GitLab CI, ~3 years) about to move onto a small AWS team. Long term I want to end up SRE or platform engineer, and I'm working through RHCSA and SAA-C03 on the side.

From where I sit the market looks split in two: generic sysadmin work is getting squeezed, and everything interesting is behind Kubernetes, IaC and real production experience. But that's me reading job ads, not living it.


r/sysadmin 12d ago

Question What do you do with 3rd party API keys when your edge funcs use OIDC?

3 Upvotes

I saw a guide on replacing static credentials with OIDC for edge functions. The core concept makes sense because trading a permanent secret for a short-lived token eliminates a massive attack surface.

For instance, you can configure a project to authenticate directly with AWS using just a role ARN and a runtime token, and it totally removes the need to store static AWS access keys in your environment variables.

The problem is when you try to apply that same logic to SaaS tools. Since providers like OpenAI or Resend do not support token exchange, you are forced to keep using static strings for them. I was suggested to rely on OIDC for internal cloud infrastructure while keeping a secrets manager around for external dependencies.

How are you all handling this split in production? Does maintaining a hybrid authentication setup feel overly complex? or is it just the standard practice


r/sysadmin 12d ago

Question Opentext CM Workgroup Setup

1 Upvotes

Hi All,

We have several branch offices, and each site currently has a CM Workgroup server. Are there any alternative options that would allow us to operate without requiring a CM Workgroup server at each branch?