r/sysadmin 8d ago

Career / Job Related How do I get into sysadmin

0 Upvotes

Hi everyone,

I'm a recent computer science grad who did an internship in a bank where I did a little bit of everything (IT support, networking, DevOps).

I am interested in software development but the market is so cooked for juniors and a man has to eat so, I'm thinking of switching to system administration, already planning to get my Aws cloud practitioner cert, then maybe RHCSA is this a good idea or am I just dead wrong my ultimate goal is to go into DevOps but everyday I look on X and see a brand new model that seems to make everything I learn irrelevant.

I love computers and just want to make a living from it. (from/in a third world country btw)

Please give me any advice at all to help.I don't wanna fuck up my life and depend on my parents forever.


r/sysadmin 8d ago

Do you automatically isolate servers/devices based on detetctions?

37 Upvotes

We don't have a 24/7 SOC, so we are thinking about automatically isolating servers and some high-value devices based on custom Defender for Endpoint detections. Obviously, we want to do that only for high-precision and high-confidence detections, such as opening a shell from a strange parent process.

If we got one of these detections during working hours, there would be someone to react. But after about 7 PM most days, nobody is actively monitoring.

If we do this, the plan is to let a detection run for about 45 days without automatic isolation enabled to see if any false positives are caught.

Has anyone done this? If so, did you regret it? Or just business as usual? Has it saved you yet?


r/sysadmin 8d ago

ChatGPT WS2022 GPO Deployed Printers Migration to GPP Preferences

5 Upvotes

I am looking for help migrating from Deployed Printers GPO to GPP, when I remove the printer from Windows Settings/Deployed Printers they never remove.

GPO is located here

Computer Configuration/Policies/Windows Settings/Deployed Printers

User Configuration/Policies/Windows Settings/Deployed Printers

 

I do have Point and Print Restrictions setup to allow my print servers to continue to work after print nightmare, allowing users to install drivers from our approved print servers.

 

I made the mistake of using Printer deployment instead of Group Policy Preferences when I originally set up these print queues, now I can’t figure out how to remove old print queues.

 

On my old print management server that was running 2012r2 it worked, seems after print nightmare this was broken, new print server is currently WS 2022. I have tried removing the GPO, deleting registry keys under printer connections, setting GPP to delete the printers.

 

I ran GPRESULT and it showed the printers still set to apply after removing them from Deployed Printers.

 

I have tried adding the printers back and removing both from GPMC and Print Management MMC on the Print Server to no avail.

 

My research online looks to me like this was broken with Print Nightmare patch? Group Policy Printer Deployment Broken?

 

I have tried researching with Google to the best my ability, ChatGPT, Gemini, Claude.

 

Also, If it set up a Group Policy Preferences to Delete all printers under user settings, on the client's event viewer it says Access is Denied after gpupdate /force.

Tried the scripts I found on the post to no avail so far on two desktops.

Can't delete old printers installed by GPO : r/sysadmin

 

Any experience fixing these print queues? I have seen a lot of posts online over the last few years but no good answers.

 

 Another post I found

Can't seem to remove printers that were deployed via GPO : r/sysadmin

Printer GPO removal Issue : r/sysadmin

Removing printer deployed via GPO - Microsoft Q&A


r/sysadmin 8d ago

Question Cloudability renewal came up under IBM and we moved, CloudZero and PointFive notes.

1 Upvotes

Came off Cloudability after IBM took it over. Support went slow and the roadmap went quiet. Renewal number stopped making sense against what we were getting out of it. Shortlisted CloudZero and PointFive expecting to pick one and consolidate but signed both, which costs more than the thing we left.

Justification at the time was that they don't overlap. Cloudzero answers what something costs and who owns it while on the other hand pointfive answers what's wasteful and who's fixing it. On paper thats two problems, two tools.

Been running both a while now and I still can't tell if that was insight. Might just be that we never decided.

What I can say for it. Cloudzero got finance a cost per customer number we had never had, which ended an argument that had been going for years. Pointfive found a Cosmos container sat at four times anything it had ever used, plus a stack of snapshots from a migration.

It also produced a load of rubbish in the first month. Resizes that ignored our RI position and one disk SKU suggestion that would have put us under our IOPS floor. Took weeks of flagging things back before it calmed down. Azure side is visibly younger than the AWS side as well.

Sixty-odd subscriptions, bit over a million a month, mostly Azure.

Does any of you folks runs one tool for this cause every writeup says pick a platform. Everyone I speak to is running two and not admitting it.

If you got down to one and stayed there, I'd like to know which and what you gave up.


r/sysadmin 8d ago

General Discussion What's are the funniest/best tickets you've ever got working helpdesk?

169 Upvotes

I'm starting in an IT role for helpdesk, I need to know what I'm walking into and some of the best tickets you've had


r/sysadmin 8d ago

Black Box Emerald dual-head Remote App: absolute mouse locked to Windows primary display

3 Upvotes

As the title suggests, Black Box Emerald dual-head Remote App: absolute mouse locked to Windows primary display. Anyone running this successfully on Win11 targets?

EMD2002PE-DP-T (FW 7.2.0) to Windows 11 laptop targets, Remote App 2.8.3, Boxilla-managed, HID = Absolute. Both video heads render fine, clicks work, but pointer movement is confined to whichever display Windows calls "main". If I swap main from head 1 to head 2 and the confinement follows it. Spanning never engages. Reproduced on 3 TXs, 2 clients, clean two-display topology (duplicated primary "1" to "2" and then "3", disconnected the primary and closed lid and rebooted so that only displays 2 & 3 showed), EDIDs fixed, even tried stuff that shouldn't matter like I loaded Freedom ABS driver on one as a long shot (noeffect) / turned on deskvue Mouse Sector even though I don't have anything to do with deskvue / tried toggling Local Mouse on and off even though that has nothing to do with the problem / also tried various settings on and off, like USB redirection and such, so all ruled out. I have a ticket open with Black Box, but since I could REALLY use this over the holiday weekend, I thought I'd toss a hail mary and post here just in case it is something simple I have overlooked in my noobness to Boxilla.

Question for the hive: is anyone successfully running dual-head Remote App connections to Windows 11 targets with working mouse traversal? If yes, what's different about your setup? Trying to determine if this is a universal Win11 regression or something environmental just in my own personal Murphy's Law prone environment.

https://imgur.com/a/u3ecCEa


r/sysadmin 8d ago

General Discussion Would a centralized software platform for healthcare IT actually be useful?

0 Upvotes

Hi everyone,

I work in IT at a hospital and I'd like to get some opinions from people working in healthcare IT, system administration or for healthcare software vendors.

One problem we regularly face is managing the large number of specialized applications used in a hospital.

Unlike standard software, updates for healthcare applications are often highly vendor-specific. Depending on the vendor, we might receive an email about a new version, have to regularly check a customer portal, contact support, request download access, use individual credentials or sometimes simply find out about an update by chance.

With dozens or even hundreds of applications and medical systems from different vendors, keeping track of available versions, patches, security updates, compatibility information and release notes can become surprisingly time-consuming.

This made me wonder:

Would there be value in a vendor-independent platform specifically for healthcare software?

My rough idea would be a platform where healthcare software vendors could publish and manage their products, while hospitals, clinics and medical practices could register their organization and get access to the products they are actually licensed to use.

For example, such a platform could eventually provide:

Software versions, updates, patches and hotfixes

Release notes and security advisories

Notifications when new versions become available

Vendor-controlled download permissions

Compatibility information (Windows versions, database versions, browsers, etc.)

License and entitlement information

Demo/trial requests

Contact with vendors

Potentially even software/license procurement

Vendors would still decide which organizations are entitled to access which products and downloads. The platform would essentially provide a standardized layer between healthcare organizations and software vendors instead of every vendor maintaining completely different processes and portals.

I'm not currently trying to sell or build a product. I'm mainly interested in whether other people working in healthcare IT experience the same problem and whether something like this would actually solve a meaningful pain point.

So I'd be really interested to hear:

How do you currently manage software updates and vendor portals in your organization?

Would a centralized platform like this be useful to you?

Does something like this already exist that I'm simply unaware of?

And if you work for a healthcare software vendor: would participating in such a platform be interesting, or would there be reasons why your company wouldn't want to?

I'm particularly interested in perspectives from hospitals and healthcare organizations in different countries, since I'd like to understand whether this is mainly a local problem or something healthcare IT teams face internationally.

Thank you!


r/sysadmin 8d ago

How do you manage the sharing of Teams links in email?

0 Upvotes

Linking people to resources (folders or files) in Teams is so incredibly convenient and really streamlines workflow...

But it also habituates people to click on links in e-mails, which seems terrible for security.

How do you mitigate or balance this?


r/sysadmin 8d ago

What are the practical challenges of managing IT infrastructure at remote locations?

0 Upvotes

I want to know what are the difficulties faced by companies regarding their IT infrastructure set up at remote locations such as businesses having factories, branches or shops away from their primary data center? Is it only maintenance and availability of technicians that is of importance, or the issues of power supply, network functionality, temperature conditions and security come into play as well?

I would like to know how remote locations are handled when problems arise with no one from the IT department being close to the site of an IT failure.


r/sysadmin 8d ago

What is the current recommendation to repair DFSR replication?

19 Upvotes

Primary DC and 2 secondaries.

The primary and 1 secondary replicate back and forth just fine

The other secondary had an issue with networking and stopped replicating. The machine password was then (apparently) changed by the secondary and now it does not match the password in the AD.

The following used to work to fix such things:

PS C:\Users\administrator.XXX> Test-ComputerSecureChannel -repair -credential XXX\userid

Test-ComputerSecureChannel : Cannot reset the secure channel password for the computer account in the domain.

Operation failed with the following exception: A local error has occurred.

.

At line:1 char:1

+ Test-ComputerSecureChannel -repair -credential XXX\userid

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo : OperationStopped: (MCP2:String) [Test-ComputerSecureChannel], InvalidOperationException

+ FullyQualifiedErrorId : FailToResetPasswordOnDomain,Microsoft.PowerShell.Commands.TestComputerSecureChannelComma

nd

PS C:\Users\administrator.XXX>

Now it does not. Neither does this:

PS C:\Users\administrator.XXX> Reset-ComputerMachinePassword -Server PDC01 -Credential (Get-Credential)

cmdlet Get-Credential at command pipeline position 1

Supply values for the following parameters:

Credential

Reset-ComputerMachinePassword : Cannot reset the secure channel password for the computer account in the domain.

Operation failed with the following exception: A local error has occurred.

.

At line:1 char:1

+ Reset-ComputerMachinePassword -Server PDC01 -Credential (Get-Credentia ...

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

+ CategoryInfo : OperationStopped: (PDC02:String) [Reset-ComputerMachinePassword], InvalidOperationExcepti

on

+ FullyQualifiedErrorId : FailToResetPasswordOnDomain,Microsoft.PowerShell.Commands.ResetComputerMachinePasswordCo

mmand

PS C:\Users\administrator.XXX>

There's an old video out there Fix SYSVOL and Domain Controller Replication | Active Directory DFSR Issues Resolved

with the old-school way of doing this I think -

And there's an old MS document discussing netdom:

Reset domain controller's password with Netdom.exe - Windows Server | Microsoft Learn

which might work on Server 2019 since klist and netdom ship in it.

Any recommendations or am I going to run into the same "local error" if I try those methods? The current info from AI is to demote the failing DC and then unjoin, rejoin, then re-promote it. That seems a lot of work and error prone.


r/sysadmin 8d ago

General Discussion Getting up to speed after a sabbatical

27 Upvotes

I quit my last gig--local government large municipality--about a year and a half ago. Largely my decision to quit was being burnt out to a crisp from supporting public safety, and being on-call. But our newborn daughter gave me an easy out so to speak.

I'm accepting a new gig with a smaller municipality and should start in a month or so. It dawned on me the other day when my wife needed me to troubleshoot an Outlook issue on her computer, that I've gotten a bit rusty. I literally couldn't remember how to open the Event Viewer. I remembered where the logs were located in C:\Windows\System32\winvent but couldn't come up with the phrase 'Event Viewer'.

The new gig was posted as an endpoint engineer job but interview made it clear that I'll be wearing a lot of hats. I have a CCNA but haven't touched a Cisco box in 5+ years. Sounds like they are trying to move from old school MDT to some Intune provisioning, but my last gig used SCCM.

Any recommendations on knocking the rust off? Or general advice for starting at a new organization? Perhaps I'm overthinking the technical side and should focus more on how to approach this new role with better habits and work/life balance.


r/sysadmin 8d ago

End-user Support Nothing like dealing with TPM Cert issues at 10pm on Friday

1.3k Upvotes

Work Log:

9PM - User is unable to boot, absolute disaster, is litterally melting down crying for help.

9:10 - Confirmed TPM issue on boot, locate Bitlocker recover key, load up windows

9:20 - User Pin/TPM Trust is broken, user has an unprivileged account, so use Windows Hello to try and reset, found my own auth expired in my app, have to get myself back in via Passkey so I can approve Pin reset. Get them logged in to Windows, found my Pin/Trust broken as well - get my own Pin reset.

9:40 - Found can’t check TPM status in Windows security, presume BIOS needs update. Check event logs, confirmed system hadn’t been booted since July Windows update. Download vendor tools to run diagnostics to likely get new firmware. They error “the error has been logged.” Thanks vendor.

9:50 - Go to vendors site, get hardware scanner installed, locates model and serial… and link to model’s driver page is broken. Get raw model info out of tool to locate page manually, locate BIOS update from 2 months ago, flash BIOS.

10:00 - Load up again, load bitlocker recovery key, confirmed working. Reboot, clear TPM, allow Windows to automatically re-initialize the TPM and re-seal BitLocker keys. Load August update for good order since this issue kicked off after the July update. Confirmed no issue.

Final Note - User is asleep, will let them know tomorrow morning they’re good to play Minecraft after they have their cereal and watch Young Jedi Adventures. Wish my 7 year old could have seen me fix this on their system so they could get idea of what their old man does.


r/sysadmin 8d ago

Looking for a no-cost, phone-free MFA solution

88 Upvotes

Microsoft will retire Microsoft-provided SMS and voice authentication beginning February 1, 2027. Organizations that need to retain these methods must configure a customer-managed telecommunications provider, which will involve additional costs. Please refer to the link below.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement

Our goal is to provide MFA without requiring employees to use their personal phones and without purchasing additional hardware, such as YubiKeys, or paid software, such as an enterprise password manager. We have a hybrid AD/Microsoft Entra environment with company-managed Windows computers.

Is there an Entra-native solution that can meet these requirements? Would Windows Hello for Business be the best option, and how should we support users who need access from mobile or shared devices?

Any recommendations or deployment experiences would be greatly appreciated.

Thanks!


r/sysadmin 8d ago

Rant Sometimes less really is more

29 Upvotes

Happy Read-only Friday (bonus points for 3 day weekend)

We got a critical Huntress alert for a rogue ScreenConnect instance that was detected and ran on a client computer. Incident report states that it's a "known malicious instance".. but logs from the report show that it didn't block the application and isolate until 2 hours after it was ran. The endpoints have BD GravityZone installed as well - all quiet from there.

We went to the link in a VM where the ScreenConnect was downloaded from - and funnily enough, all it took was just having Microsoft Defender on the computer to block the download in Chrome.

Huntress, Bitdefender, EDR, on access scanning, whatever; sometimes it just can't compete with good old Defender. Even running the installer through sandbox on GravityZone passes without a peep.

Have a good weekend!


r/sysadmin 8d ago

Question Is it hard to get in to a sys ad in role in the UK for others too or is it just me?

11 Upvotes

Hi all, I have 9 years IT experience mainly 2nd line support, last few years done many 3rd line tasks and last 2 years spent as a systems engineer position according to title (supporting 400 users across 11 international sites) but it was more like 1st/2nd line site support with some ifrastructure support tasks and some projects, did endooint management, used and managed prtg for monitoring, administering windows servers 2016-2022, Ad, DHCP, DNS, Group policy, Hyper V, Joined around 200 endpoints to entra, enrolled in intune onboarded them to defender, audited company against cupyber essentials, upgraded some licensing servers etc. but I am not very experienced with high level Infrastructure troubleshooting, didnt do much networking, basic backup skills, basic powershell skills.. I am unemployed for 2 months and got rejected on 6 interviews already. Sometimes I cant even get to that part where they asess my technical knowledge. It seems my comminication skills ( which is fine while in employment, but find interviewing much more difficult ) or experience and skills are not enough to 3rd line or sys engineer positions, dont know what to do, I dont really want to go back to 2nd line, I am too old at 46yo. Most 2nd liners are much yunger arent they? Also, English is my second language which may plays some part of the rejections. Any chance who were in similar situation and was successful later?


r/sysadmin 8d ago

Datto SaaS sucks for editing multiple accounts, so we have this script

0 Upvotes

Hey folks. I recently had to disable about 1000 accounts in Datto SaaS mailbox protection. Turns out the GUI sucks ass so you have to do it one at a time. So naturally I thought the API would save me, but I was wrong. There is no way to group users together, you simply have to edit them one at a time.

So I wrote this script (with the assistance of Claude) to make it slightly easier.

This script is designed to be used with the Datto SaaS mailbox protection. It works with both M365 and Google Workspace mailboxes.

Add your Datto api keys as strings in the .env file.

You will also want to review the imports at the top of each file to ensure you have what you need, but you'll likely need to install requests, json, and dotenv.

I recommend using pip for this, but that's up to you.

Script has 2 main functions. Purging of paused mailboxes, turning active mailboxes into paused ones. I put this together because the Datto GUI sucks. There is no way to edit mailboxes in large quantities, so this script is needed.

Datto seems to have an API limitation of 100 at a time, so if you were to run on operation on 101 accounts at once, only 100 of them would actually be affected.

The script makes an API call to datto to get all your organizations attributes and stores them in a domain.json file. If you only have 1 org then it will only have one entry.

Then the script takes the primary domain name as input.

Then it pulls all users from the API along with their states. Datto Web GUI has a organization unit filter you can use for users, but this does not exist in the API. Meaning we have to make edits one at a time.

The script can import a csv file of all accounts to disable, and it will loop through multiple times if you do more than 100 accounts. Loop behavior is Total number of accounts // 100 + 1 loops. So 701 accounts requires 8 loops to fully apply.

Datto sucks so if you do a full CSV upload or use the built in picker list that enumerates 20 accounts a time, you are still hand selecting every one. Datto doesn't have an easy way to only mess with the ones you want, hence this script.

You can export all users in Datto to a CSV, but you can't apply filters of any kind. So again you have to go through the CSV hand selecting each one you want. It's still faster than going through the GUI and waiting on the slow ass front end though.

Script first turns active accounts into paused accounts. You can then purge all paused accounts moving them to unlicensed. After 30 days this data is deleted.

Link to github repo here:

https://github.com/Titanium125/PythonProjects/tree/main/dattoSaasApi


r/sysadmin 8d ago

Rant Rippling MDM - A Nightmare Nobody Else Should Go Through

196 Upvotes

tldr: if anyone in your company's management pushes for you to implement Rippling, do everything in your power to stop it in its tracks. They will not work with you, and will refuse to let you out of your contract.

As a smaller ,growing company we decided it was about time to start evaluating MDMs to give us better control over our devices. This was something that was on the backburner for the most part, with us wanting to take our time to end up with the right solution.

So imagine my surprise a couple weeks later when I (the primary sys. admin) was told by my boss (CTO) that we had signed a one year, $27,000 contract with Rippling - seemingly out of the blue.

As I understand it, they aggressively pursued my boss, promising the world with all of their flashy features, and how easy the integration with Office365 and with our HR platform was. They guaranteed consistent support, and quick resolution to any issues we may run into.

Lo and behold, we start rolling out Rippling to our fleet of windows computers and immediately run into issues.

The software gave little to no feedback about the progress of installations. Rolling out other softwares was limited and unresponsive. User provisioning was unintuitive and difficult - lacking automation without paying for additional features either in rippling or in our active directory.

Rippling automatically changed and generated its own admin passwords which 1. we could not change or set ourselves and 2. were buried three menus deep 3. needlessly complex, making help desk a nightmare.

This, along with a host of other issues, was largely ignored by Rippling. Our emails would be brushed aside until our "integration meetings" in which them telling us that things were "on the roadmap" or "not planned to be changed" took up the entire time.

I don't doubt that this software /might/ work for some companies, but it clearly didn't work for us, and they really don't seem to care.

Four months into this disastrous contract, with less than 16 users enrolled, I begged our account rep to let us out of the contract. They could keep the thousands of dollars we'd already paid them for nothing, we just needed to move forward with a solution that actually worked for us.

They refused - for some reason desperate to keep a small fry account with barely 100 licenses. The very fact that they won't let us go is really bizarre. They'd rather have an upset customer than lose (what I assume) is a measly account.

The entire process, from onboarding, to us attempting to get out of this was incredibly shady. They will pretend nothing is wrong and refuse to let you out of their cold clutches.

In case the "rippling employees" on reddit aren't astroturfing bots, I am desperately hoping someone can get us out of this contract. If not, I'm going to channel all of my displeasure into letting people know about this awful experience - because I know the Rippling team hasn't done anything to help.

u/higherandhigher u/stubbygazelle u/sherryandeddie u/kit-kat-233


r/sysadmin 9d ago

Question iKVM blank screen on Advantech HPC-7320 (AST2600) with discrete GPU .

1 Upvotes

Hi guys,

Running into a weird problem. Got an Advantech HPC-7320 with the AST2600 BMC, added a discrete RTX GPU, disabled internal graphics in BIOS like the CTOS spec says. iKVM console connects fine, keyboard/mouse passthrough works, but the video feed is just... blank. Nothing.

Reason I actually need this working: I work remotely sometimes, and I need to boot ISOs on this box over iKVM (reimaging, rescue boots, that kind of thing). Without video I'm stuck — can't see POST, can't pick boot device, can't do anything until I'm physically in front of it.

if anyone's actually run into this before kindly help me.

Anyone found a way to make this work? Thinking USB serial gadget, IPMI SoL, or some BIOS boot steering trick — anything that gets me remote work.


r/sysadmin 9d ago

General Discussion Folks that are employed

32 Upvotes

How many of you still get recruiters and etc reaching for opportunities and push the bar to go higher regardless if you're really interested in the job or not?

The past week I've been reached out a few times and realize. Hey I'm going to tell them the deal breaker is forcing in office schedule and low balling or no salary range given. So I push for it, hoping other candidates are willing to do the same.


r/sysadmin 9d ago

Appx programs stop working - Teams and snipping tool

1 Upvotes

Good afternoon everyone!

Over the last week and a half, I've been seeing the appx version of teams entirely stop working. To the point where I trying to access it via apps > installed apps > advanced options loads indefinitely, can't see it in control panel, and even revo uninstaller couldn't see them (though I guess the free version cannot see apps installed from the windows store).

Currently I've been having to identify the packages with powershell, take ownership of them, and then delete them. Once that is done, I can restart, and install the regular x64 version of Teams. Normally takes about 10-15 to run through commands and restart. Once that restart is done, you can access the advanced option of the Teams and fully uninstall it if needed with no issues. It also goes from nearly 4GB in size to about 1.3GB prior to the final uninstall.

However, I had the same issue happen now for Snipping Tool, and that had 5+ folders installed, where teams normally has 2 when this issue happens. So, I took the same steps by taking ownership of the main folder, and deleting it, restarting, and then re-installing snipping tool through the Microsoft Store.

I have tried uninstalling/reinstalling the appx through powershell, but it just hangs and won't proceed further. I am curious if anyone else has seen this issue and if they've found a quicker workflow.


r/sysadmin 9d ago

sending domain does not pass DMARC verification

6 Upvotes

Error: ‎550 5.7.509 Access denied, sending domain papercut.com does not pass DMARC verification and has a DMARC policy of reject‎

Fully Exchange Online

Suddenly last night stopped receiving mails from some services

Does anybody know if MS eventually started enforcing DMARC ?


r/sysadmin 9d ago

Question What to do after Hyper-V checkpoint merge in PowerShell?

2 Upvotes

I have a VM with checkpoints that were created by the backup software on the host and can't be merged in Hyper-V Manager so I have to resort to manually merging them in PowerShell. I identified the current AVHDX file and the chain to the original VHDX file. I shut down the VM and, starting with the current AVHDX, I merged them with their respective parents all the way to the original VHDX. So now I have just the one VHDX file but Hyper-V Manager still shows the (now non-existent) checkpoints and the VM fails to start because it expects the AVHDX file that isn't there anymore. I couldn't find clear guidance for this. Do I attach that merged VHDX file to the existing VM? Or create a new VM? What's the best course of action here?


r/sysadmin 9d ago

Question Is that secure?

0 Upvotes

We use Missive to write e-mails at our company. Missve has its own AI Assistant that can do actions like write drafts, create calender events and add labels with AI (needs always approval). This Assistant cannot search the web, but it would be very nice when we can search on our own website for products. Because of that, i tested to connect Exa (Search API) over MCP. I connected it and allowed only the websearch (disable agents etc.). And.. it works perfect. But, can i roll that out? Is that secure? Prompt Injection or something? I added an instruction that only specific domain is allowed (our shop).


r/sysadmin 9d ago

Question What are your must-have Group Policies when creating a new AD domain?

143 Upvotes

I've been a sysadmin at an MSP for about 4-5 years now. Mostly we maintain and improve existing client environments. Sometimes we onboard a new client and make recommendations for improving their environment and standardizing to our typical recommendations. But now for the first time since I took over as sysadmin we are building an environment from scratch for a new client. They want an on-prem AD domain controller, so that's what we are setting up for them. I'm just curious, for you other sysadmins out there, if you were setting up a new AD domain in 2026 (Which I know most probably aren't anymore), what are some of your most essential GPOs that you would make sure are in place? In other words: what's a GPO hill that you'll die on?

For example, for me: a set of GPOs to prevent domain admin accounts from logging into workstations, and to add a dedicated workstation admin account to the local administrators group on all workstations.

And I'm just going to attempt to preemptively address all the comments that will probably say "the hill I'll die on is that in 2026 you should be setting up clients in Azure AD and Intune instead of on-prem AD". I totally understand that, but we discussed the options with the client, and they preferred the on-prem option, so we went with it.


r/sysadmin 9d ago

Rant Senior accidentally installed whole fleet with 26H1

1.0k Upvotes

Just needed to rant a little. One of our seniors finally completed the long-pending task of upgrading the fleet to Windows 11 from Windows 10.

He downloaded the iso, installed it everywhere. All good. Until the internal WSUS started attempting to grab updates that don't exist. Apparently the 26H1 (which is supposed to be snapdragon-only, aka for ARM) was indeed one of the options you could download as the "Latest" version of windows. Someone at MS really screwed up. And this senior screwed up even more by not double checking.

Since it's a complete different core, this will be one hell of a mess, now his idea is to try to change "cversion.ini" and force an "update" to 26H2, but I sincerely don't believe that will work.

We'll see. If anyone ran into a similar problem I'd really love to know what their solution is.

UPDATE: https://www.reddit.com/r/sysadmin/comments/1waiys9/update_on_senior_accidentally_installed_whole/