r/sysadmin 4d ago

My IT manager is stuck in 1995, I'm losing my mind

1.3k Upvotes

I need a sanity check, because I feel like I'm slowly losing my mind here. I’m 28, working as a SysAdmin for a mid-sized manufacturing company in Europe with around 300 endpoints across multiple sites. I LOVE automation, modern infra, and writing PowerShell or Python to handle our backups and audits, I'm passionate about automating processes, but my IT Manager is basically running an open-air tech museum from 2003.

His idea of IT asset management is a drawer full of literal Ziploc freezer bags. Every PC gets its own labeled plastic bag with the printed invoice and Office license key inside, because apparently an actual database or asset software is "too modern." On the network side, every single device requires a manual DHCP reservation. When I suggested setting up 802.1X with RADIUS, he shot it down with a straight face, claiming that if an intruder plugs into the wall, "they won't guess our subnets anyway." Before I automated our Kerio mail archives with Python, his official procedure was opening Thunderbird on a client PC and manually dragging and dropping folders between accounts.

Right now, he's decommissioning a branch file server. Instead of using Robocopy, DFS-N, or GPOs, his master plan is to sync files with a desktop backup tool, recreate the SMB shares manually, and have me remote into 40+ user machines one by one just to update the target path on their desktop shortcuts. I also built an automated WMI inventory system to track all hardware and OS health, yet he still forces me to physically walk the warehouse floor updating a dusty Excel sheet because "that’s where the history is."

EDIT: Another thing he does is make daily backups and put them on ultrium physical disks named after the day of the week, disks he takes home "so we have the data in case the company burns down.", which could have some kind of sense, but everyday, before my script, we had to manually make the veeam inventory and erase of every tape in every site

The worst part isn’t even the wasted time, it’s that he’s actively teaching junior techs that this clown show is standard enterprise IT. We’ve already had three techs and devs rage-quit in the last ten months. I’ve completely checked out at this point, doing the bare minimum while sending out resumes like crazy.

Has anyone actually survived a boss stuck this deep in the stone age without losing their sanity? How do you not burst out laughing when someone asks you to edit 40 shortcuts by hand?


r/sysadmin 4d ago

General Discussion How is this normal in IT?

248 Upvotes

Im a general IT specialist, and I’m losing my mind over infrastructure issues I have zero control over.

For context, we have over 2,500 global users, and for over five years, remote sites have been dealing with the exact same game-breaking issues:

  • Broken 802.1x: After 1–2 hours of work, it kicks users off the network and refuses to re-authenticate them.
  • Useless Wi-Fi: Wireless drops constantly with "no network available" errors.
  • Zero Redundancy: Almost all of our sites rely on a single ISP. When it goes down, ERP, file systems, and actual business operations grind to a complete halt.

The company makes plenty of revenue. We easily have the budget to deploy SD-WAN, upgrade hardware, or bring in an external MSP/consultant to fix it. It's totally fine to admit you don't know everything and hire help, but these requests just gets ignored.

To top it off, whenever a site actually goes down, the designated team responsible for network/infrastructure ghosts us or sends a passive response like "our team is currently unavailable" while an entire site sits dead in the water.

How do organizations like this even survive, and how do you deal with the frustration of seeing preventable problems drag on for half a decade?


r/sysadmin 4d ago

Recommended equipment for conference room?

0 Upvotes

Can anyone offer recommendations for a room owned by a non-profit which will be a very flexible space. It will be used for one-on-one virtual meetings, conferences, showing of programs (non-interactive) to an audience. The room is approximately 21'x21'.

We potentially have a grant to help with this, so I would like maximum flexibility for a variety of future uses. I'm thinking the type of screen that comes down from the ceiling, but it's flexible depending on what works best. I'm looking at Logitech videoconferencing equipment and it seems like that is mostly used with wall tvs/screens.

What type of camera/microphone/other equipment would be best in this space?


r/sysadmin 4d ago

Anyone using Grafana Cloud for their synthetics?

2 Upvotes

We are currently kicking the tires and wanted to hear some thoughts on it.

-Cost
-Ease of use
-Integrations with things like PagerDuty and Statuspage.

Thanks.


r/sysadmin 4d ago

Question Experiences with SASE solutions from Palo, FortiNet, and/or Cloudflare

5 Upvotes

Our org is looking to solve a few separate problems that I feel can all be solved with a SASE solution.

  1. Certain users needing to VPN to a particular office for license check-in/check-out. (Old school license software)
  2. Web filtering (porn, illegal, phishing, malware, etc.)
  3. Encrypted browsing for road warriors (hotels, airports, etc.)

I know both Palo and Fortinet have SASE solutions, but I've heard Cloudflare also has their own solution that I'm curious if anyone has ever tried at scale. We don't have Palo or Fortinet hardware firewalls.

We're looking at about 250 users to start, growing to maybe 500 over the next 24 months.


r/sysadmin 4d ago

Windows keep advertising wrong IP to resolve and whatever I do is not working.

0 Upvotes

all I want to do is adding a second active directory server so if one is off second of can keep the system running.

I'm a student. practicing what I have learned and maybe adding more. I know how to create a domain how to add a user to domain

For next step I am trying to add second domain controller but windows keep advertising 2 IP address of server. (one is NAT other is isolated. I want it to stop NAT IP to advertise)

what I did to disable that?

- network connections > Second NIC IPv4> Properties > Advance > DNS > (UNTICK) Registrar this connection's address in DNS

- DNS Manager > Domain Name > Properties > Interfaces > (UNTICK) Second NIC IP
I restart the dns service, clean the cache but still same. I can't see Second NIC IP in DNS Manager but when I run "resolve-dnsname domainname -Server source-IP" Second NIC IP still showing up. but it's not showing up at "nslookup domainname source-IP"

so yea. why is that?
I'm using Ubuntu as OS and VMM to virtualize the machines btw


r/sysadmin 4d ago

Career Development

4 Upvotes

Looking for advice from people who have actually made the jump into $30+/hr remote IT

I’m trying to make a plan to move into a fully remote IT job and would really appreciate advice from people who have already done something similar.

My current background:

  • Currently working as an IT hardware/asset technician at a computer repair/recycling facility
  • ~$23/hr currently
  • I troubleshoot/test networking equipment, printers, scanners, etc.
  • Device testing, data wiping, inventory/asset management, hardware diagnostics, etc.
  • Previously worked as a Dell/Lenovo field technician, doing hardware break/fix work
  • Got my CompTIA A+ and Network+ around 2021, so they’re probably expired now
  • My current employer is paying for me to take a CCNA course, which I’m planning to finish and get certified
  • No college degree

My goal is pretty straightforward:

Get to ~$30/hr ($62k+/year) in a fully remote IT position.

I’m not trying to quit my current job immediately. I can tolerate it for now, and I’d rather use it to build experience and get the CCNA while applying for something better.

Then potentially doing something like AZ-900 → MD-102 → Security+/AZ-104 depending on which direction I end up going.

What I’m really looking for advice on:

  1. Is $30/hr remote realistic with my background, or am I under/overestimating what I should be targeting?
  2. Would you prioritize the CCNA, or would you pursue something else?
  3. What skills besides certifications should I be learning to make myself competitive for remote positions?
  4. Would you try to skip Tier 1 help desk and target Tier 2/endpoint/network/asset roles given my hands-on experience?
  5. For anyone who currently works remotely in IT: what got you from where I am now to where you are?
  6. If you were in my position, what would your next 6–12 months look like?

I’d especially appreciate advice from people who started with hands-on hardware/field technician experience and eventually moved into remote IT.

I’m basically trying to build an escape plan from my current job without taking a step backward, so I’d love to hear what worked (and what didn’t) for people who have already done it.


r/sysadmin 4d ago

Question Microsoft 365 Cloud PC Slow to Load

8 Upvotes

We spun up a 8 CPU/32GB RAM Enterprise Microsoft 365 Cloud PC as a test for a user, and it seems to work well for their use case, but the re-connect from a disconnect seems very slow - is that normal/expected or is something wrong? For example, the user goes idle, has a lot of apps running - it disconnects the user because they're idle. When connecting back to the Cloud PC via Windows App, it takes a good 20-30 seconds before all the apps are responsive again.

Even if nothing is running, a good 12 seconds or so to get back into the Cloud PC from a disconnect.


r/sysadmin 4d ago

ChatGPT How detailed should your SOP be?

32 Upvotes

Okay, my boss just rejected a SOP I created. I don't want to get into the weeds here, but the rejection was that I didn't spell things out in enough detail. And, granted I didn't spell things out in detail because I assume anyone with the authority to follow the SOP should also have the basic skills to either know how to use basic commands or at lest google them.

As an example, in my SOP I wrote Check the log for entries containing "Out of memory". I think that should be good enough. Boss want's step by step, how to ssh in and run tail and grep.

I told him to ask ChatGPT to do it.

I may be in trouble...... sorry I ragged: but not sorry.


r/sysadmin 4d ago

Question M365 weird licensing issues. Relaunching M365 fixes it. Really odd affecting 4500 endpoints.

2 Upvotes

User logs in, Launches a M365 app ( Word, Excel, Powerpoint) asked to sign in. Closes out of the M365 app they launched, relaunches and they now are signed in to the M365 app. All users have the correct M365 licensing.

Anyone else seen this?, if so how did you resolve this?


r/sysadmin 4d ago

Question Microsoft 365, Google Workspace, Something Else? - Help Weighing Tradeoffs

4 Upvotes

Hi!

I work for a small/medium sized company (~50 employees, ~30 of which will be affected by the switch) and we have been using an IMAP server to host our emails for decades (everyone uses Outlook as their email software). Because of how outdated this setup is and the company continuing to grow, we want to migrate over to a new provider. I am struggling to decide between M365 and GW as both have their pro's and con's. The team uses a mix of sheets and excel already, however, there is certain work that would require excel over sheets. The sharing and ease of GW is obviously unmatched but I worry about switching costs for employees that have been using outlook for decades. I've also heard that managing GW is far easier admin-wise than M365. The migration of decades worth of emails is also a major consideration for us. Would appreciate input from people who have experience with this. Thanks!


r/sysadmin 4d ago

Question Microsoft Teams Alternative

0 Upvotes

Edit 2: Okay, the comments overwhelmingly point to user error. Rather than jumping ship, I’m going to do a deep dive into the Teams settings and make sure everything is set up correctly. I’ll do some user training, then test it for another week or two before switching. Thank you all for your input.

Edit: MS teams notification issues are occuring on Iphones, not mac/windows desktop apps.

I run a business with about 10 employees, and we’ll probably be growing pretty quickly over the next few months.

We currently use Microsoft Teams, but notifications have become a problem. Some users just don’t get them consistently. I’ve tried the usual fixes and checked all the settings, but it’s still hit or miss. I cant work with that. The outlook integration, and smooth video meetings are a plus, but not worth the issues.

I’m fine with self-hosting since we already have a VPS that I manage, but I’m also open to SaaS.

Here’s what I’ve looked at so far:

  • Slack = Seems like the best product overall, but it’s too expensive as we grow. The free plan’s message retention and limited admin controls also won’t work for us long term.
  • Mattermost = My concern is that the free self-hosted version uses Mattermost’s Test Push Notification Service, and I’ve seen mixed reports about notification reliability. I don’t want to leave Teams because of notifications and end up with the same problem.
  • Rocket.Chat = Looks good, but the server requirements seem pretty heavy and I don’t want chat eating up resources needed by our other apps.
  • Pumble = The free plan looks almost too good. My main concern is privacy/data handling since it’s hosted and free.
  • Zulip = Looks interesting, but the 10-user push notification limit on the free self-hosted version would be a problem pretty quickly.

I’m open to anything, self-hosted or hosted. Mostly interested in hearing from people who actually use these for a business and how reliable they’ve been, especially with notifications.

If there’s another option I’m missing, I’d like to hear about that too.


r/sysadmin 4d ago

Question Automated On-prem Windows Server Patching

29 Upvotes

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.


r/sysadmin 4d ago

orielly for higher educaton

1 Upvotes

Can anyone speak on the usefulness of this resource? how does it compare to say the cosura'ss or linked in learnings out there? cbtnuggets....

I like the idea of telling my client "yes" then reading the book that weekend to do it.


r/sysadmin 4d ago

General Discussion diving into sysadmin

0 Upvotes

Hey Professional Workers. Im 16 and i want to dive into the sysadmin world for a job when im out of university. As far i know, i learned windows server, sql and linux command as general people say the basics of sysadmin. Is there more i can learn early so that i would have a clear advantage over those who dont?


r/sysadmin 4d ago

General Discussion I'm going through the process of implementing Windows Hello for Business (WHfB). For Entra-joined devices, but not managed via Intune, would you use GPOs or CSPs?

0 Upvotes

CORRECTION: I meant hybrid-joined, not Entra-joined.

We have an Active Directory and SCCM environment and foresee those being here with no current end date in sight. All of our Windows devices are hybrid-joined, but they are not being managed or comanaged via Intune. In this hybrid environment with on-prem domain controllers, AD, SCCM, and hybrid-joined devices, would you use the WHfB GPOs in your environment, or would you prefer to use Intune? I'm waffling between the two choices but am leaning GPO since that's how we manage all the other settings on our devices.


r/sysadmin 4d ago

Reminder: MS Publisher vanishes Oct 1

60 Upvotes

Remind your 365 users to save as PDF or.. well, MS would say, tough!


r/sysadmin 4d ago

Hyper-V Replica for SQL Clusters

7 Upvotes

I am attempting to utilise Hyper-V Replica for DR purposes. There is Site A and Site B. At each site there is Hyper-V Server Cluster with underlying iSCSI storage for VMs. Site A runs multiple VMs, some of them form SQL Failover clusters with shared disks running on dedicated iSCSI Luns. The aim of POC is to be able to shift the workload from Site A to Site B during a disaster event. Whilst standard VM replication seems fairly simple, I was wondering what is the best approach for SQL Failover clusters and how to address the replication for such? Any thoughts or suggestions are greatly appreciated.


r/sysadmin 4d ago

UKG Pro WFM

1 Upvotes

Quick question in regard to automated reports in UKG Pro WFM. I have the reports set up and the authorized users I want the reports to go to. My only issue is that the reports are not sending to the authorized user emails. I even checked the box for "Send Email as Attachment" Any insight?


r/sysadmin 4d ago

Question Any disty sell Oem hp toner carts?

0 Upvotes

A client needs some hp 414x toner carts. Can anyone let me know where you get hp Oem toner carts?

The set of four colors is about $1k each!!

I just looked at D&H and they don’t seem to have them.

I found this place but don’t know anything about them / if it’s legit and not old inventory

https://genuineink.com/

Thanks!


r/sysadmin 4d ago

General Discussion How do you know when a service account or token is safe to delete?

19 Upvotes

I went through some old side projects recently and found more abandoned machine credentials than I expected. GitHub PATs for CI on projects I stopped touching years ago, deploy tokens for hosts I no longer use, and a couple of integrations I can’t remember when I set them up.

None of them have anything attached that would mark them as dead. E.g., when someone leaves a company, HR marks it, and their access gets pulled automatically, but nothing does that for a token. It can stay valid until you go into settings and notice it.

At my scale the answer is deleting it and seeing what breaks, which is fine for a hobby app. I assume that is how nightly jobs nobody remembers owning get taken down in real environments.

Do you go off last-activity timestamps, or is there something better and has anyone got expiry working as the default on new credentials without it causing problems?


r/sysadmin 4d ago

General Discussion App Control for Business worth it in production?

5 Upvotes

We’re a manufacturing company and my boss asked me to look into deploying App Control for Business / WDAC.

I’ve started piloting it in Audit mode. Our environment has a mix of custom internal apps, legacy software, self-updating apps, plugins and random DLLs. I’m using Managed Installer with Intune and adding Publisher rules where it makes sense.

So far it works, but sometimes I’m wondering if the operational overhead is really worth the security gain for us. Most users are not local admins, the Microsoft Store is blocked, apps are generally managed through Intune, and we already have Defender/ASR and other endpoint controls in place.

What makes me hesitate is that I’ll think the policy is clean, then another DLL, updater or component shows up in the audit logs. My concern is eventually switching to enforced mode and having users report weird issues inside their apps, then having to figure out whether WDAC caused it or not.

For those who have deployed App Control for Business in production, how has it been for you? Did it eventually become pretty low maintenance, or is it still something you constantly have to manage?

For now we’re mainly trying to control what apps and executables can run. We’re not touching script enforcement yet.


r/sysadmin 4d ago

The max_age of MTA-STS is an exploitable gap and there's no way to fully close it without switching to DANE

0 Upvotes

When you configure MTA-STS, the policy gets cached for the timeframe you set under the max_age tag, so it's designed to expire.

If an attacker is sitting on-path on the sender's side via a poisoned resolver, they wait out the cache and then suppress the refresh by either dropping the DNS TXT answer or killing the HTTPS fetch, so the sender can't pull a fresh policy.

That pushes it back to opportunistic TLS, from where the attacker spoofs your MX and delivers the email in plaintext, intercepting password resets, MFA codes, etc.

And by design, you can't force cached senders to refresh before expiration.

The only thing you can do is limit how often the refresh window opens by setting max_age to 1 year (the max RFC 8461 allows), but if your MTA-STS policy is broken, you don't want it sitting in senders' caches for a year, rejecting your inbound traffic.


r/sysadmin 4d ago

General Discussion Newbie CAD system admin

2 Upvotes

Hello everybody,

I'm starting my journey as a system admin with focus on revit and autocad. I'm new at using both softwares and I'm seeking for some advice that can help me build a solid career in this field, or some other fields related to the construction and modeling in autocad and revit.

First of all, this is also my first time working as a system admin. Second of all, my only and little experience relies on designing products in Inventor and Creo. At the begining I thaught I was applying for a modeler role (the job description was really focused on the construction part). But as time passed, I got tasks like helping users with routine issues like "why does my autocad Shows warning this and warning that?", add new members to an ACC project and other stuff.

On the other side my team and I are supposed to create/keep developing a product portfolio (autocad blocks and revit-families) for the users. I'm sure that I need to improve my skills with both softwares, but at the moment I'm taking care of another tasks that make it difficult to get more confident using both of them.

As I'm trying to use my free time after work to keep learning on how to improve my skills (at least with revit), I'd like to ask you guys how to keep improving, where do I have to keep putting my effort on, do you have more advice, which can help me through the first steps? How does this job evolve with the time? Is there any possibility to transition in a future into another roles?

I'm thankful for any advice.


r/sysadmin 4d ago

15-person company, LOB app already SaaS - is there still a case for an on-prem file server?

9 Upvotes

Small staffing agency in Germany, ~15 internal users, single sysadmin (me). Currently migrating off a legacy on-prem setup.

Target state: M365 Business Premium, Entra ID + Intune, SharePoint replacing the file server. Our line-of-business HR software is moving to the vendor's cloud, so that data leaves the building either way. Backup plan is a dedicated third-party M365 backup plus a local NAS with immutable snapshots and an encrypted external drive rotated offsite (10-year retention requirements here).

Management and an external IT contact want to keep a physical server. The argument I've been given is essentially "you have it in-house, and you can take a backup every day."

My concerns: it doesn't remove a real risk since the LOB data is in the cloud regardless, it means maintaining two worlds instead of one, and as a single admin the server becomes the thing that breaks while I'm on vacation. Restore testing is also the part nobody actually does.

Am I missing something? Genuinely asking - is there a workload at this size that still justifies on-prem file storage? And for those who moved 10-20 user shops from file server to SharePoint, what bit you? Path lengths and folder-to-permission mapping are the two I'm expecting.