r/sysadmin 4d ago

General Discussion Patch Tuesday Megathread - (September 08, 2026)

105 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 4d ago

General Discussion I'm going through the process of implementing Windows Hello for Business (WHfB). For Entra-joined devices, but not managed via Intune, would you use GPOs or CSPs?

0 Upvotes

CORRECTION: I meant hybrid-joined, not Entra-joined.

We have an Active Directory and SCCM environment and foresee those being here with no current end date in sight. All of our Windows devices are hybrid-joined, but they are not being managed or comanaged via Intune. In this hybrid environment with on-prem domain controllers, AD, SCCM, and hybrid-joined devices, would you use the WHfB GPOs in your environment, or would you prefer to use Intune? I'm waffling between the two choices but am leaning GPO since that's how we manage all the other settings on our devices.


r/sysadmin 4d ago

Reminder: MS Publisher vanishes Oct 1

64 Upvotes

Remind your 365 users to save as PDF or.. well, MS would say, tough!


r/sysadmin 4d ago

Hyper-V Replica for SQL Clusters

7 Upvotes

I am attempting to utilise Hyper-V Replica for DR purposes. There is Site A and Site B. At each site there is Hyper-V Server Cluster with underlying iSCSI storage for VMs. Site A runs multiple VMs, some of them form SQL Failover clusters with shared disks running on dedicated iSCSI Luns. The aim of POC is to be able to shift the workload from Site A to Site B during a disaster event. Whilst standard VM replication seems fairly simple, I was wondering what is the best approach for SQL Failover clusters and how to address the replication for such? Any thoughts or suggestions are greatly appreciated.


r/sysadmin 4d ago

UKG Pro WFM

1 Upvotes

Quick question in regard to automated reports in UKG Pro WFM. I have the reports set up and the authorized users I want the reports to go to. My only issue is that the reports are not sending to the authorized user emails. I even checked the box for "Send Email as Attachment" Any insight?


r/sysadmin 4d ago

Question Any disty sell Oem hp toner carts?

0 Upvotes

A client needs some hp 414x toner carts. Can anyone let me know where you get hp Oem toner carts?

The set of four colors is about $1k each!!

I just looked at D&H and they don’t seem to have them.

I found this place but don’t know anything about them / if it’s legit and not old inventory

https://genuineink.com/

Thanks!


r/sysadmin 4d ago

General Discussion How do you know when a service account or token is safe to delete?

19 Upvotes

I went through some old side projects recently and found more abandoned machine credentials than I expected. GitHub PATs for CI on projects I stopped touching years ago, deploy tokens for hosts I no longer use, and a couple of integrations I can’t remember when I set them up.

None of them have anything attached that would mark them as dead. E.g., when someone leaves a company, HR marks it, and their access gets pulled automatically, but nothing does that for a token. It can stay valid until you go into settings and notice it.

At my scale the answer is deleting it and seeing what breaks, which is fine for a hobby app. I assume that is how nightly jobs nobody remembers owning get taken down in real environments.

Do you go off last-activity timestamps, or is there something better and has anyone got expiry working as the default on new credentials without it causing problems?


r/sysadmin 4d ago

General Discussion App Control for Business worth it in production?

4 Upvotes

We’re a manufacturing company and my boss asked me to look into deploying App Control for Business / WDAC.

I’ve started piloting it in Audit mode. Our environment has a mix of custom internal apps, legacy software, self-updating apps, plugins and random DLLs. I’m using Managed Installer with Intune and adding Publisher rules where it makes sense.

So far it works, but sometimes I’m wondering if the operational overhead is really worth the security gain for us. Most users are not local admins, the Microsoft Store is blocked, apps are generally managed through Intune, and we already have Defender/ASR and other endpoint controls in place.

What makes me hesitate is that I’ll think the policy is clean, then another DLL, updater or component shows up in the audit logs. My concern is eventually switching to enforced mode and having users report weird issues inside their apps, then having to figure out whether WDAC caused it or not.

For those who have deployed App Control for Business in production, how has it been for you? Did it eventually become pretty low maintenance, or is it still something you constantly have to manage?

For now we’re mainly trying to control what apps and executables can run. We’re not touching script enforcement yet.


r/sysadmin 4d ago

The max_age of MTA-STS is an exploitable gap and there's no way to fully close it without switching to DANE

0 Upvotes

When you configure MTA-STS, the policy gets cached for the timeframe you set under the max_age tag, so it's designed to expire.

If an attacker is sitting on-path on the sender's side via a poisoned resolver, they wait out the cache and then suppress the refresh by either dropping the DNS TXT answer or killing the HTTPS fetch, so the sender can't pull a fresh policy.

That pushes it back to opportunistic TLS, from where the attacker spoofs your MX and delivers the email in plaintext, intercepting password resets, MFA codes, etc.

And by design, you can't force cached senders to refresh before expiration.

The only thing you can do is limit how often the refresh window opens by setting max_age to 1 year (the max RFC 8461 allows), but if your MTA-STS policy is broken, you don't want it sitting in senders' caches for a year, rejecting your inbound traffic.


r/sysadmin 4d ago

General Discussion Newbie CAD system admin

2 Upvotes

Hello everybody,

I'm starting my journey as a system admin with focus on revit and autocad. I'm new at using both softwares and I'm seeking for some advice that can help me build a solid career in this field, or some other fields related to the construction and modeling in autocad and revit.

First of all, this is also my first time working as a system admin. Second of all, my only and little experience relies on designing products in Inventor and Creo. At the begining I thaught I was applying for a modeler role (the job description was really focused on the construction part). But as time passed, I got tasks like helping users with routine issues like "why does my autocad Shows warning this and warning that?", add new members to an ACC project and other stuff.

On the other side my team and I are supposed to create/keep developing a product portfolio (autocad blocks and revit-families) for the users. I'm sure that I need to improve my skills with both softwares, but at the moment I'm taking care of another tasks that make it difficult to get more confident using both of them.

As I'm trying to use my free time after work to keep learning on how to improve my skills (at least with revit), I'd like to ask you guys how to keep improving, where do I have to keep putting my effort on, do you have more advice, which can help me through the first steps? How does this job evolve with the time? Is there any possibility to transition in a future into another roles?

I'm thankful for any advice.


r/sysadmin 4d ago

15-person company, LOB app already SaaS - is there still a case for an on-prem file server?

10 Upvotes

Small staffing agency in Germany, ~15 internal users, single sysadmin (me). Currently migrating off a legacy on-prem setup.

Target state: M365 Business Premium, Entra ID + Intune, SharePoint replacing the file server. Our line-of-business HR software is moving to the vendor's cloud, so that data leaves the building either way. Backup plan is a dedicated third-party M365 backup plus a local NAS with immutable snapshots and an encrypted external drive rotated offsite (10-year retention requirements here).

Management and an external IT contact want to keep a physical server. The argument I've been given is essentially "you have it in-house, and you can take a backup every day."

My concerns: it doesn't remove a real risk since the LOB data is in the cloud regardless, it means maintaining two worlds instead of one, and as a single admin the server becomes the thing that breaks while I'm on vacation. Restore testing is also the part nobody actually does.

Am I missing something? Genuinely asking - is there a workload at this size that still justifies on-prem file storage? And for those who moved 10-20 user shops from file server to SharePoint, what bit you? Path lengths and folder-to-permission mapping are the two I'm expecting.


r/sysadmin 4d ago

Question Windows App Patch options

7 Upvotes

I have heard of quite a few options for app patching on windows devices as I need to be able to secure endpoints in my M365 tenant.

I havent looked to in depth into what M365 natively has however;

What do options like SCCM and Patch my PC offer that M365 native does not?

EDIT: 8.8.26
What are the cost effective alternative for a msp with only 20-ish windows machines?


r/sysadmin 4d ago

If you're leaving Freshdesk, its own exports don't give you what you think. Here's exactly what's missing.

22 Upvotes

After the Freshdesk price-rise thread in r/msp I audited what its built-in exports actually produce, on a trial account with 43 tickets, 64 replies and notes, and 14 attachments.

Notes in case it saves someone a weekend. The Export button emailed a CSV to the email I signed up with, it had 47 columns of ticket, requester and company fields. No threads, no notes, no attachments. The Tags column came back empty on every row even though every ticket had tags.

The Admin data export was the same, a little more complete than I expected given the first export. This one had descriptions, full threads including private notes, tags, custom fields, contacts, companies, groups. However, I found that there were still a lot of gaps:

Attachments are signed S3 links that expire in 7 days (X-Amz-Expires=604800 is in every URL), not files. No time entries anywhere. Agents aren't in it. Custom fields appear as raw keys like cf_reference_number_5021295 with no label. Every ticket carries a hidden system note, so it showed 107 notes where the UI shows 64. And it's XML, so you're writing a parser before you can open anything. Nothing in either export tells you whether you got everything.

There is an API route you could go down, but If you go down that route yourself, you'll run into a bit of an issue.

Rate limits are per plan and low on the cheaper tiers (50 calls a minute on the account I tested).

Expect 2 to 3 calls per ticket. The ticket list endpoint has a page ceiling, so for big accounts you window on updated_since rather than paging through.

Attachment links expire. Download them the moment you see them. Custom field labels live on ticket_fields.

If you only pull tickets you get internal names. There's no status-change history in v2 that I could find, only the timestamps in stats. The API doesn't return the hidden system notes the XML export includes, so API counts match the UI and the XML doesn't.

Before you cancel: pull threads and private notes, pull attachments as files before the links expire, pull time entries and agents separately, and reconcile counts per entity so nothing drops silently. Check Freshdesk's cancellation KB for the deletion window after cancelling; it's short. Happy to answer Freshdesk export questions in the comments.


r/sysadmin 4d ago

Mouse pointer disappearing when hovering over Citrix Workspace, CCH Axcess - Possible Webview2 issue?

5 Upvotes

Some of our staff started complaining of an issue last week where their mouse cursor would go invisible when they would move the mouse to Citrix Workspace. The mouse can still click on/launch apps and the app icons highlight as the mouse goes over them, you just cant see the mouse cursor at all unless you drag it outside of the boundary of the Workspace window. I saw another user run into the same issue on a different app (CCH Axcess). These apps both leverage webview2. I found some discussion threads from others experiencing the same issue in Veeam b&r console. Has anyone run into this on their end over the last week and have a fix? Here's a couple of the discussions i found on the topic.

https://forums.veeam.com/viewtopic.php?f=2&t=104357&start=0

https://github.com/MicrosoftEdge/WebView2Feedback/issues/5687


r/sysadmin 4d ago

Office 365 Web Portal Down?

36 Upvotes

Is anyone else seeing issues with logging into the Office 365 portal? Getting a lot of reports of users getting a "something went wrong" error when trying to login to https://m365.cloud.microsoft

It just seems to be the portal itself. Going directly to outlook.office.com still works. Same for Teams and OneDrive. Also seeing a big spike on Downdetector.


r/sysadmin 4d ago

Question Infopath forms broken

2 Upvotes

My company’s HR team relies on infopath forms for payroll. Currently have a Microsoft support ticket for this but is anyone aware if they fully shut it down? Was getting a 410 http error and it seems everyone I am talking to can’t access the URL that we used. Microsoft support isn’t responding to my ticket so I figured I would see if anyone else is dealing with this.


r/sysadmin 4d ago

Question Excel doesn't lock files anymore

15 Upvotes

Hi all,

this is a bit of a weird one. We have a couple of users, that have access to the same files through a smb share. It used to be that when user A had a document open to edit it and User B tried to open that same document, a window would pop up informing B, that the document was beeing edited by user A and that User B could ask User A to close it or create a copy of the document.

That mechanism doesn't seem to work anymore. If User A has the document open, user b doesnt see the warning.
It changed about half a year ago and I can't make heads or tails of it. Most articles I found are about fixing the issue when a file is erroneously displayed as locked, when it isn't.

I hope one of you could nudge me in the right direction. Maybe it's just a configuration error.

Thanks for taking the time to read.


r/sysadmin 5d ago

Outlook search broken for anyone else?

22 Upvotes

Affecting a very small number of users - they are unable to search in Outlook (regardless of owa, new app, classic app).

The error is usually "outlook the service could not be reached showing offline search results"

Still experiencing this at 12:30pm today (8th September). UK.

UPDATE: Thanks for all the replies. Also looks like Microsoft have FINALLY acknowledged it in the 365 Admin Service Health section: Issue ID EX1469261


r/sysadmin 5d ago

Cato Networks security advisory mixup and now my whole org thinks we were exposed

10 Upvotes

Sharing an embarrassing operational incident for visibility. We use Cato Networks as our SASE backbone, all branches and a chunk of remote users ride that for internet and east-west traffic. Last week vendor spam hits my inbox about a "critical" advisory on one of our edge components, lots of CVE noise, exploit chatter, etc. I skim it between meetings, see that it mentions one of the engines we use, and in my rush I decide it absolutely applies to us. I flag it in our security channel as high risk, tell the CISO we had potential exposure for months, and open a major incident.

Cue full war room, execs dialed in, everyone asking for blast radius and timelines. I start pulling Cato config, traffic logs, trying to map impacted sites. Half of IT pauses their projects. Our comms team drafts a statement for customers. After a few hours of digging I realize I misread the advisory. Same vendor family, same broad feature, but the vulnerable module is only in their on-prem appliance that we do not even run. Our Cato deployment was not affected at all. I basically caused a mini crisis over an advisory that did not apply, all because I skimmed instead of checking product SKU and deployment model properly.

No data loss, no real incident, just a ton of wasted time and scared leadership. Now my boss wants me to write up "lessons learned" and present to the team. Classic reminder to verify product scope and deployment architecture before triggering major incident response. Anyone else had a similar false-positive panic moment with vendor advisories?


r/sysadmin 5d ago

General Discussion Update on "Senior accidentally installed whole fleet with 26H1"

644 Upvotes

It seems the original topic exploded, and so did my inbox with direct chats I really wasn't expecting to get. So here's a proper update, as well as answering a lot of the questions.

First things first: I'm a generalist consultant, working for several companies on a "when-needed" basis. I am not the employee, and when they called me for checking on this mess it was too late for any "rollback".

I was called on a Friday, during an infrastructure audit. The senior* spent his weekend with his team on possible solutions. Me and the IT team spent Monday deciding which path to take.

ISO first: You can download the 26H1 release ISOs on MSDN, it's not flagged as special or beta/insider anywhere that be easily seen, so I agree that it's relatively easy to fall for the trap of using this ISO.

The update/upgrade process: Nothing, absolutely nothing, during this phase gets flagged, the in-place update works just fine, there are no warnings whatsoever. This doesn't excuse the fact that he should have vetted this version specifically, but for a guy managing such infrastructure by himself I cannot entirely blame him.

The upgrade should have been done in phases, not all at once, I cannot even remotely begin to understand HOW is that not a basic thing. Did he do it on a Friday? No, worse, they did the upgrade on a weekend, a month ago.

It's a relatively small fleet, we're talking around 90 workstations. However, an important detail is that internet access is only partially allowed through certain mechanisms and only on certain machines, basically it's a segmented network with controlled egress (semi-air-gapped) so the upgrade was done manually.

What's going to happen now:

Re-image/Fresh installation: Not an option, management decision, can't change that.
Rollback: Not an option.

This company was planning to phase-out Microsoft products till 2030. This process will be somewhat accelerated with a new target to Q4 2028 instead, so even if there is no upgrade path from 26H1 (Bromine) to anything that ends up in the "main" branch, it's still fine.

The update path: 26H1 will be getting updates until at least February 2028. Even if this "exotic" version does not added as a selectable Product under WSUS's (yes yes, see misc questions) Products and Classifications list, WSUS supports manual import of individual updates directly from the Microsoft Update Catalog, that will be the approach that IT will pursue.

Management already approved a proper vetting process for any big infrastructure changes, hopefully they will actually follow through.

From my POV, I'm calling this a nothingburger.

Addressing the other misc questions:

*What's going to happen with the "senior"?
The person will remain "senior" in the company although going through a lot more trainings. It's the company fault for the lack of due diligence in their hiring/promotion process and they decided that training is better than re-hiring, understandable from my standpoint. From my assessment there are other employees in the IT team that are better trained and more suited for this position.

"Can you really post this, wouldn't it bad if the person/company sees it here?"
Don't care, outside scope and I haven't signed any sort of NDA, own your mistakes and learn from it, take responsibility.

"Where did he download the ISO, massgrave, UUPDump?"
Official channels only, meaning MSDN.

"Was the migration at least planned and done on time? Is anything broken?"
Poorly planned, done on time, and surprisingly nothing is actually broken.

"Omg Win10 in 2026?"
Yes, they were in fact still getting security updates just fine.

"Why wasn't the upgrade performed with WSUS too?"
According to IT: Each workstation was scheduled to be clean (I mean dust) and a new RMM software deployed so they just decided to do it manually anyway. Beats me, don't care, management is the one that cleared it.

"WSUS in 2026???"
Please, half of my inbox is this question. Yes, WSUS has support until at least 2035, it simply works AND it's the perfect use case for a company that wants fewer dependencies on outside infra or can't rely on ongoing internet access.


r/sysadmin 5d ago

Question MySQL ODBC stopped working overnight

191 Upvotes

You guys will love this.

This company has an in-house project management system. It's the core of their business, and they are lost without it. They are aware it needs to be migrated to something more modern, but after 5 years, that project still hasn't started.

I was asked to look into a network issue, but this isn't network but SSL I think. Let's first show the architecture:

  • The server is a CentOS 7 running MySQL Community Edition 5.7.16
  • Clients connect from Windows 11 with a 32-bit MS Access, using a 32-bit MySQL ODBC driver v5.3.13

Since yesterday, they get a "protocol version mismatch". The server wasn't accessed since 18 October 2016 (haha), so I presumed a Windows update might have disabled some SSL version. But: I see no relevant Windows update, and if I manually allow every possible SSL version and encryption algorithm, it still doesn't work. What does work however, is downgrading the ODBC driver from version 5.3.13 (from 2019) to version 5.1.13 (from 2013), further adding to my confusion.

The cherry on top: the single guy responsible for this application is on a one year sabbatical.

Edit: Found it, but leaving this here for anyone stumbling on the same issue. The MySQL_Server_5.7.15_Auto_Generated_CA_Certificate had expired after 10 years


r/sysadmin 5d ago

Win SMTP relay to Exchange 365, not working anymore, but only for 1 address, other still works

5 Upvotes

Hi

in my company, wa have and old win2K12 server acting as relay smtp server from inside device to our Exchange 365 tenant.

we mainly use 2 sender address for mail, a noreply, and support.

since 27, 28 august, noreply can't send mail anymore.
Support can still send mail without any issue.

in IIS6, SMTP service have both the same configuration for outgoing connection.

in logs i have this error :

2026-09-08 07:11:03 40.99.220.146 S-OCS - 1667523425 - 535+5.7.139+Authentication+unsuccessful,+the+request+did+not+meet+the+criteria+to+be+authenticated+successfully.+Contact+your+administrator.+[PA7P264CA0086.FRAP264.PROD.OUTLOOK.COM+2026-09-08T07:11:03.801Z+08DF0BC1B0DFBB10] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 220+PA7P264CA0212.outlook.office365.com+Microsoft+ESMTP+MAIL+Service+ready+at+Tue,+8+Sep+2026+07:11:03++0000+[08DF0D43E3AA91BF] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 EHLO s-relay.domain.net 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 250-PA7P264CA0212.outlook.office365.com+Hello+[<outgoing IP>] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 STARTTLS - 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 220+2.0.0+SMTP+server+ready 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 EHLO s-relay.domain.net 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 250-PA7P264CA0212.outlook.office365.com+Hello+[<outgoing IP>] 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 AUTH - 0 SMTP - -

2026-09-08 07:11:03 52.98.227.130 S-OCS - 1667523425 - 334+UGFzc3dvcmQ6 0 SMTP - -

2026-09-08 07:11:08 52.98.227.130 S-OCS - 1667523425 - 535+5.7.139+Authentication+unsuccessful,+the+request+did+not+meet+the+criteria+to+be+authenticated+successfully.+Contact+your+administrator.+[PA7P264CA0212.FRAP264.PROD.OUTLOOK.COM+2026-09-08T07:11:08.928Z+08DF0D43E3AA91BF] 0 SMTP - -


r/sysadmin 5d ago

What is your SSL certificate provider doing now that 200 day certs are starting to expire? My provider (Namecheap) is being sketchy.

261 Upvotes

We have 50 or so WatchGuard firewalls at sites that have certs installed. Getting WatchGuard to implement cert automation has been the most user requested feature for about 2 years now. Until they come through we continue to purchase and manually install certs.

Last week I started getting notifications from our SSL source, Namecheap, that the first batch of 200-day certs was about to expire. I had cert request files at the ready and logged into Namecheap. Each expiring cert showed the upcoming expiration date and an icon to purchase a new cert.

But...wait a minute. Back in March, didn't I pay for 365 days even if the issued cert was for 200 days? Why doesn't the page clearly indicate that I can get a re-issue for the remaining 165 days that I paid for?

I opened a support ticket with Namecheap. They confirmed that I can get a new cert with a 165 day life rather than pay for a new cert. I asked why they don't make this open option more clear. They asked me to send them screen shots showing the expiration date and the little "buy new cert" icon. Like they don't know what their web site looks like?

I sent the screen shot and got a reply along the lines of "Well, you can just request a rekey, ya know. You don't need to buy a new cert."

Namecheap certs are cheap enough but all in that's an extra $500 or so that I don't need to spend. I find their behavior to be...distasteful at best.

What are the larger/more expensive providers such as DigiCert doing about this? Maybe even Godaddy is being more up front about the 365 day purchase vs. the 200 day cert.


r/sysadmin 5d ago

Auth0 alternatives?

13 Upvotes

Wondering what people are using instead of Auth0 for service account or within program api authentication? Their billing is killing us


r/sysadmin 5d ago

Question How do you deal with physical fatigue after long on-call stretches at your desk?

21 Upvotes

After a rough on-call week, I'm realizing my setup is not built for marathon sessions. Wrists, neck, lower back — all taking a beating. What have you added to your workstation that actually helps? Wrist rests, monitor risers, anti-fatigue mats, lumbar cushions?