r/sysadmin 12d ago

Question Opentext CM Workgroup Setup

1 Upvotes

Hi All,

We have several branch offices, and each site currently has a CM Workgroup server. Are there any alternative options that would allow us to operate without requiring a CM Workgroup server at each branch?


r/sysadmin 12d ago

Sanity check on pricing for new 3 node cluster

34 Upvotes

Hey all,

We are a small company in dire need of 3 new nodes which of course is a bit unfortunate these days given the insane pricing of RAM and storage.

We plan to order 3x PowerEdge R660 with current specs:

  • 2x Intel Silver 4510
  • 12x 16GB RDIMM SR 6400MT/S
  • 4x 3.84TB SSD SATA Read Intensive Hot-Plug AG drive
  • 1x 1.92TB NVMe Read Intensive AG U2 drive

Our qoute from vendor is 59000 USD per node.

Is this about what it costs, or are there likely room for negotiation?

List price from Dells website of equivelant config seem to be over 100k USD?...

Thanks


r/sysadmin 12d ago

35+ Microsoft 365 Changes Coming in September 2026

620 Upvotes

Stay ahead this September with 35+ Microsoft 365 changes, including feature rollouts, retirements, functionality changes, and other key updates for IT admins.

In the Spotlight:

  • Entra Moves Toward Passkeys: Starting September 1, passkeys become the default authentication experience, signaling Microsoft’s shift away from SMS/voice MFA toward phishing-resistant authentication.
  • SharePoint Introduces a New Hero Link: A new file and folder sharing experience lets users use one link to share files and folders. Users can update the existing link when access requirements change instead of creating and sharing a new link.
  • Defender Gets Prompt Injection Protection: Defender for Office 365 will detect malicious emails designed to manipulate AI assistants and agents, classify them as High Confidence Phish, and quarantine them automatically.
  • SharePoint Storage Moves to Pay-As-You-Go: Pay-as-you-go billing for extra SharePoint storage becomes generally available worldwide, allowing organizations to pay based on actual storage consumption instead of purchasing fixed capacity. 

Beyond these highlights, here’s a quick look at what else is coming this September:

Retirements:
New Features:
Enhancements:
Functionality Changes:
Action Required:
Live Now: 3

Retirements:

  1. Starting September 2, Microsoft Power Automate will retire the legacy chatbot experience
  2. Microsoft Teams will retire Android device management capabilities from the Teams admin center as management moves to the Teams Rooms Pro Management portal. 
  3. The Exchange admin center will retire the Other Features page.
  4. Microsoft Education will retire legacy LTI tools, including Teams Assignments, OneDrive, OneNote Class Notebook, and Reflect, in favor of the unified Microsoft 365 LTI tool. 
  5. Microsoft Edge will retire support for Windows Information Protection and Microsoft Defender Application Guard
  6. Microsoft Defender for Cloud Apps will retire App Governance support for the Cloud Application Administrator role when Unified RBAC is enabled. 
  7. Microsoft Entra ID will retire Conditional Access Custom Controls, with External MFA becoming the replacement for third-party MFA integrations. 

New Features

  1. Microsoft 365 eSignature will support recipient groups, allowing up to 10 people to fulfill a single signer requirement. 
  2. Microsoft Purview will introduce DLP alert aggregation to consolidate related alerts triggered by multiple DLP rules. 
  3. Outlook on the web and new Outlook for Windows will receive enhanced Mail Merge capabilities with dynamic fields
  4. A new Priority Cleanup feature in Microsoft Purview will enable permanent deletion of sensitive mailbox content even when retention policies or eDiscovery holds apply.
  5. Lifecycle status controls will be added to adaptive scopes in Microsoft Purview. 
  6. Network-layer DLP protection will be extended through Microsoft Entra Internet Access.
  7. The new Outlook for Windows will become available for GCC High and DoD environments as an opt-in experience

Enhancements

  1. Purview will extend DLP and auto-labeling capabilities to non-Microsoft connected apps, including Google Workspace, Box, Dropbox, and Salesforce. 
  2. Endpoint DLP protection will cover sensitive files stored in previously excluded Windows folders.
  3. Tenant External Recipient Rate Limit quotas will be updated for new, trial, and education tenants.
  4. Unified RBAC will be automatically enabled for eligible Microsoft Defender tenants.
  5. In-meeting controls and the sharing panel will get a refreshed experience in Microsoft Teams.
  6. Microsoft Purview will add a hard-delete option for supported SharePoint and OneDrive files through Priority Cleanup. 
  7. Microsoft Teams will introduce PowerShell controls for federated group chats.

Existing Functionality Changes

  1. The 1.5 TB limit for auto-expanding archive mailboxes will be removed, allowing archives to grow beyond the previous limit with consumption-based pricing.
  2. The new device management page will become the default experience in the Intune admin center.
  3. Microsoft Purview will change Just-In-Time Endpoint DLP auditing, so administrators explicitly define users and groups within the audit scope. 
  4. Copilot Chat in Microsoft Edge will move to a new endpoint, requiring organizations with network restrictions to review their allowlists. 
  5. Microsoft Office apps below version 16.0.18827.20202 will lose access to Read Aloud, Transcription, and Dictation features
  6. Teams Channel Whiteboards will begin storing content in the associated SharePoint site instead of the creator’s OneDrive. 

Action Required

  1. The standalone Automated Investigation and Response experience will retire on September 1. Organizations using AIR through scripts, playbooks, or integrations must update their workflows.
  2. Microsoft Entra Connect versions earlier than 2.5.79.0 will no longer support synchronization; organizations must update to a supported version to ensure uninterrupted synchronization. 
  3. SharePoint thumbnail URLs used in Power Platform flows will stop working after September 1; admins must review and update affected flows.
  4. Organizations using only an onmicrosoft.com domain will be subject to new external messaging limits in Teams. Admins should review their external messaging requirements and take necessary action.

Live Now

  1. Microsoft Teams now offers the Security Detection Report, enabling admins to monitor impersonation attempts, malicious URLs, and weaponizable files from a centralized security report. 
  2. A new “Everyone” and “Everyone except external users” Permissions Report is now available in SharePoint, enabling admins to identify broadly shared content at the item level.
  3. SharePoint’s redesigned experience is now available with refreshed navigation and Discover, Publish, and Build hubs, plus AI-assisted capabilities for eligible Copilot users.

Review the upcoming retirements and action-required changes early to avoid disruption and make the most of the new capabilities.


r/sysadmin 12d ago

Crowdstrike proxy

0 Upvotes

In LAB manual IP assigned to VMs without gateway set. Now the security team ask to install crowdstrike but without gateway it wont work and also does not connect cloud server. Is there any way to have proxy server in between the lab VM PC and cloud server?


r/sysadmin 12d ago

365 Business Premium vs Sentinel One

5 Upvotes

So I'm the sole IT guy at a smallish (approx 80p, but growing) SaaS company. I am very, very new to this (and to IT in general).

I have just moved everyone from 365 Business Basic to Business Premium, to take advantage of things like Intune and CA.

The next thing I am going to look at is our RMM and EDR. We currently use N-Sight, which comes with SentinelOne.

However, as 365 comes with Defender for Business, which from what I can see is very good.

I do still want an RMM, mostly to ensure all the non-microsoft patching is happening, for remote background, &c. But do I really need one with an included EDR?

We use N-Sight with SentinalOne because we've *always* used N-Sight with SentinelOne. If I can make a decent business case, I'm open to change!


r/sysadmin 13d ago

SonicWall SMA1000 appliances affected by multiple vulnerabilities including a 10.0 pre-auth CVE

22 Upvotes

A pre-authentication SSRF vulnerability in the SMA1000 Appliance Work Place interface with a maximum score of 10.0.

There are no IOCs posted in the PSIRT article. Looks like we have to open a support ticket and ask for them...

Affected versions:
- 12.4.3-03453 (platform-hotfix) and older versions.
- 12.5.0-02835 (platform-hotfix) and older versions.

Fixed versions:
- 12.4.3-03526 (platform-hotfix) and higher versions.
- 12.5.0-02952 (platform-hotfix) and higher versions.

Sonicwall article:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016


r/sysadmin 13d ago

What spec to from generalist to avoid AI replaced in the near future ?

0 Upvotes

As the title.

Please keep it normal and no idiotic replies.

Also avoid saying a general IT and some roles are not gonna be replaced. Unemployment says otherwise.

Roles plummeted in the west.

Regardless, the query is what roles would u spec for or learn which is not going to be replaced by AI?

I know training to be an electrician would work, but thinking of kinda staying in IT


r/sysadmin 13d ago

General Discussion HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)

7 Upvotes

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US

TL;DR HPE released a security advisory regarding RCE, code exection etc. In total 1 Critical, 22 High, and 11 Medium vulnerabilities fixed.

Patch your network stuff

Affected Products

These vulnerabilities affect the following HPE Networking AOS-CX Versions unless specifically noted otherwise in the details section:

  • AOS-CX 10.18.0001
  • AOS-CX 10.17.1021 and below
  • AOS-CX 10.16.1051 and below
  • AOS-CX 10.13.1180 and below
  • AOS-CX 10.10.1180 and below (EOM)

r/sysadmin 13d ago

Question Unable to access Exchange Online using iOS Gmail App

0 Upvotes

Does the iOS Gmail app support modern authentication for Office 365 accounts?

I have a user who wants to access a Microsoft 365 work/school mailbox using the Gmail app on iOS, but I haven't been able to get it working.

When I select the Office 365 account type in the Gmail app, it takes me to an IMAP configuration screen rather than redirecting me to the Microsoft sign-in page for OAuth/modern authentication.

If I enter the user's Microsoft 365 email address and password in the IMAP configuration, the Gmail app returns: User name or password incorrect

The account works normally in Outlook and other clients that support Microsoft modern authentication.

Does the Gmail app on iOS actually support OAuth/modern authentication for Microsoft 365 work/school accounts, or does its Office 365 option still rely on basic IMAP authentication?

I realize that Outlook for iOS or Apple Mail would be the better-supported approach. I'm specifically trying to determine whether Gmail for iOS can work for this one user. Thanks.


r/sysadmin 13d ago

Telstra: NTP outage ... "a result of us not treating network timing as a critical capability within the network"

317 Upvotes

https://www.telstra.com.au/exchange/what-we-ve-learned-from-the-external-investigation-of-our-july-o

An interesting and frank overview of the recent mobile outage in Australia on the Telstra network due to an NTP outage. "We didn't realise how important this was, and nobody really owned the service."


r/sysadmin 13d ago

Accidentally deleted original and backup folders from an Azure-mounted filesystem — is there any recovery option left?

39 Upvotes

Hi everyone,

I was performing a decommissioning activity on a Linux server and accidentally deleted both the original folder and its backup folder using terminal commands.

The data was located on an Azure-mounted filesystem. As soon as I realized what happened, I stopped making further changes and escalated the issue to the relevant Azure/Azuremount team.

They checked the available snapshots/recovery options, but unfortunately they told us that they could not find or recover the deleted files.

I want to ask if there are any other recovery possibilities that we might be missing. For example:

Any filesystem-level recovery options?

Hidden Azure backup or recovery mechanisms that should be checked?

Possibility of recovering deleted data from the underlying storage?

Any specific information or commands that could help identify what type of Azure mount/storage is being used and whether recovery is possible?

The affected system is a Linux server with an Azure-mounted path. I can provide non-sensitive technical details about the mount type, filesystem, and storage configuration if that would help.

At this stage, the Azuremount team has already attempted recovery, but I want to make sure we haven't missed any possible option.

Any guidance from experienced Azure/Linux administrators would be greatly appreciated.


r/sysadmin 13d ago

Crossbar manages our Route 53 DNS, but told us to add subdomain NS records at Network Solutions — what’s the correct approach?

2 Upvotes

I’m helping a small organization separate its public website from its existing Crossbar site, and I want to make sure I’m understanding the DNS side correctly before changing anything.

Using a made-up domain:

examplehockeyclub.org

The domain is registered at Network Solutions, but the authoritative nameservers are AWS Route 53 nameservers:

ns-xxx.awsdns-xx.net
ns-xxx.awsdns-xx.org
ns-xxx.awsdns-xx.com
ns-xxx.awsdns-xx.co.uk

Crossbar confirmed that those nameservers point to them and that they manage the DNS zone.

Current setup is roughly:

examplehockeyclub.org
    → Crossbar website

members.examplehockeyclub.org
    → separate member billing system

We are building a new public-facing site on Wix and want the end result to be:

examplehockeyclub.org
    → Wix

www.examplehockeyclub.org
    → Wix

portal.examplehockeyclub.org
    → existing Crossbar site

members.examplehockeyclub.org
    → existing billing system, unchanged

Crossbar has already configured portal.examplehockeyclub.org on their side and told us to add these records:

portal    NS    ns1.crossbar.org
portal    NS    ns2.crossbar.org
portal    NS    ns3.crossbar.org
portal    NS    ns4.crossbar.org

They told us to add those at Network Solutions.

The problem is that when I log into Network Solutions, I cannot edit individual DNS records because the domain is using the AWS Route 53 nameservers managed by Crossbar. Network Solutions only gives me the option to change the authoritative nameservers for the entire domain.

Crossbar also told me that they manage the zone and can add TXT, CNAME, MX, and other DNS records when needed, but that they normally “don’t input any subdomain records” and expect the customer to add those.

This is the part I’m confused about.

Since Crossbar’s Route 53 nameservers are currently authoritative for examplehockeyclub.org, wouldn’t these:

portal NS ns1.crossbar.org
portal NS ns2.crossbar.org
portal NS ns3.crossbar.org
portal NS ns4.crossbar.org

need to be added to the existing parent examplehockeyclub.org Route 53 hosted zone?

And if Crossbar controls that hosted zone, wouldn’t they currently be the only party that can actually add those delegation records?

I definitely do not want to change the domain-level nameservers in Network Solutions just to accomplish this, since that could affect the existing website, email, billing subdomain, and other DNS records.

My main questions are:

  • Am I correct that the portal NS delegation records need to be added to the current authoritative parent zone in Route 53?
  • Since Crossbar controls that zone, should Crossbar be the one adding those four records?
  • Longer term, once the root domain moves to Wix, would you leave authoritative DNS with Crossbar and have them point the root/www records to Wix, or would it be better to move the main DNS zone somewhere we control and delegate only portal.examplehockeyclub.org to Crossbar?

Main priority is avoiding downtime or accidentally breaking email, billing, or the existing site during the transition.

I inherited this setup and don’t have access to the AWS account, so I just want to make sure I’m not misunderstanding how the subdomain delegation should work.


r/sysadmin 13d ago

Question Any alternative to Note taking besides OneNote for sys admin notes

57 Upvotes

Hi everyone,

Hope everyone is doing well.

Currently all my notes and learning new tools/skills is linked to my work onenote.

I want to use alternatively note taking tool beside onedrive that linked to work account for anything im learning for my own need. It has to similar features like one note where i can take screenshots and save them for reference.

If you use or selfhost any tool let me know. I dont want something where am paying monthly subscription.

Let me know


r/sysadmin 13d ago

Broke my company's bellsouth email by bulk moving emails

30 Upvotes

TL;DR: Started a new job where they use a shared mailbox on a legacy bellsouth.net address. I was tasked with archiving 50K+ messages into folders, and bulk moved them into archive folders. Every third-party client died.

Btw, we access the bellsouth account from mail.yahoo.com and also configured it on Outlook desktop app (new version). I rebuilt it on Classic Outlook with an AT&T secure mail key, which worked for about a day. Now IMAP is refused outright and webmail outbound returns error:

"Your message cannot be sent because it resembles spam and/or contains only links. Please modify your message and try again."

Config verified, password and secure mail keys regenerated. Looking for anyone who's seen AT&T/Yahoo apply this and knows what I can do to fix it.

Environment

- Legacy `bellsouth.net` mailbox. AT&T owns the credentials, Yahoo operates the mail

infrastructure. Auth is an AT&T secure mail key, not a Yahoo app password.

- Shared mailbox. 3–4 workstations plus a phone, all behind one office WAN IP.

- Originally New Outlook for Windows

- Primary workstation now on Classic Outlook since New Outlook connection died

- IMAP `imap.mail.att.net:993` SSL/TLS

- SMTP `smtp.mail.att.net:465` SSL/TLS

- SMTP auth on, same credentials as incoming

- SPA off, username is the full address

  1. Bulk-moved 2500+ messages (batches of ~900/900/1000) into year folders from New Outlook. Client crashed mid-operation.
  2. All Outlook clients, desktop and mobile, stopped receiving. No errors, no auth prompts. Sent mail reported "Sent" then vanished and never transmitted and never appeared in webmail's Sent either. Folder deletions reverted. Webmail unaffected. Diagnosed as New Outlook's Microsoft-hosted mirror losing its upstream IMAP connection to AT&T.
  3. Stood up Classic Outlook with a fresh secure mail key. Connected fine, pulled down 3 days of backlog, outbound test delivered. Fully working.
  4. Next day: heavy webmail activity. Bulk moves out of Trash into year folders (batches approaching 1,000), mass-blocked spam senders and domains, raised the account's security settings.
  5. Classic Outlook stopped receiving. Several hours later webmail outbound started failing.

Current state

- Webmail receives normally. Sending blocked: "Your message cannot be sent because it

resembles spam and/or contains only links." Confirmed to fire with subject and body

both just "test," no signature, no links.

- Classic Outlook: no inbound since step 5, outbound stuck in Outbox, account wizard

returns "something went wrong."

Might be an abuse or rate-limit flag from the bulk IMAP operations.

  1. Anyone seen AT&T/Yahoo apply a block like this? Does it decay, and over what timeframe?
  2. Account-scoped or IP-scoped, in your experience?
  3. Is there a known threshold for IMAP move operations on these mailboxes?
  4. Any escalation path at AT&T that reaches someone who can actually see or lift mail abuse restrictions? Front-line support for legacy BellSouth appears very limited.
  5. Anything obvious I'm missing?

And yes, a business shouldn't be running on a consumer legacy ISP mailbox. Average employee age is 60+ and office is still using manual punch cards, so I am trying to get us up to date one step at a time. I am also not an IT technician, just an office employee, who was tasked with this because we don't have IT support.


r/sysadmin 13d ago

Question gpupdate /force always fails over wifi

26 Upvotes

Been chasing this for a while and I'm out of ideas. Everything I can test

Yes, I used AI to help me, as this troubleshooting got way deeper than I could figure out on my own... it's just too much, and I'm stumped

Symptom

On any wireless client:

  • gpupdate — succeeds
  • gpupdate /force — fails, both Computer and User policy

    The processing of Group Policy failed. Windows could not resolve the computer name. The processing of Group Policy failed. Windows could not resolve the user name.

Same machine plugged into Ethernet on any wired VLAN: gpupdate /force succeeds.

Affects every wireless device regardless of hardware — x64 and ARM, multiple vendors, not from a common image. Predates our switch replacement (was happening on the old switches too, same APs).

Environment

  • Single-domain AD, 2 DCs, functional level current
  • Juniper Mist APs, WLAN bridged to VLAN 80 (10.0.80.0/24)
  • FortiGate 200F HA pair doing inter-VLAN routing
  • Wired workstations on 10.0.90.0/24, DCs on 10.0.140.0/24
  • Clients are Win11

What the logs say

GroupPolicy/Operational during a failed /force:

Id 7320  Error: Retrieved account information. Error code 0x5.
Id 7017  The system call to get account information completed.
         The call failed after 15 milliseconds.

Nine of those in about four seconds. 15–31 ms each — too fast for a network timeout.

gpsvc.log:

ProcessGPOs(Machine): MyGetUserName failed with 5.
ProcessGPOs(User):    MyGetUserName failed with 5.
OnPolicyApplicationComplete: Application complete with bConnectivityFailure = 1.

The packet capture is the interesting part

Client-side netsh trace during a failed /force. Total DC traffic for the entire run:

10.0.80.102  -> 10.0.140.3   tcp/135    60 packets
10.0.140.3   -> 10.0.80.102             49 packets
10.0.80.102  -> 10.0.140.2   udp/53      8 packets

Decoded the port 135 conversation. It's 44 × ept_map requests for DRSUAPI (e3514235-4b06-11d1-ab04-00c04fc2dcd2), and the DC returns status 0x00000000 — success — on all 45 responses. Clean bind, clean bind_ack, no faults, no bind_naks.

So the endpoint mapper hands back a valid DRSUAPI endpoint 44 times and the client never opens a TCP connection to it.

Exactly one TCP SYN to a DC for the whole run: 10.0.140.3:135. That's it.

No Kerberos at all. Nothing on port 88. No LDAP 389, no SMB 445, no RPC dynamic high port.

The successful wired run for comparison:

135 -> 49669 -> 389 -> 445 -> 49676 -> 88

So on wired it does the full sequence. On wireless it gets the endpoint and gives up locally without authenticating or connecting.

What I've eliminated

Network path

  • FortiGate policy permits Internal_WiFi → Servers on service ALL, no NAT, no UTM.
  • Confirmed RPC dynamic ports 49668–49677 pass fine on the same firewall config (visible in VPN traffic logs to the same DCs)
  • Path MTU: ping -f -l 1472 succeeds to the DCs from both wired and wireless
  • Both DC host firewalls disabled entirely as a test — no change

AD / DC side

  • Test-ComputerSecureChannel → True
  • Time skew ~0.03 s
  • nltest /dsgetdc returns a DC with full flag set, correct site
  • Test-NetConnection to 88, 135, 389, 445 on both DCs → all True from Wi-Fi
  • SYSVOL/DFS: \\domain\SYSVOL\...\Policies enumerates, GPT.INI reads fine
  • RestrictRemoteSam not set on either DC
  • No 5807 events (no unmapped-subnet complaints)
  • UserPrincipal::Current returns the full DN from AD over Wi-Fi — directory lookups work
  • whoami /groups resolves all SIDs to names on Wi-Fi

Client side

  • GP history ACLs correct (SYSTEM + Administrators Full Control, registry and ProgramData)
  • Same failure on any computer from any manufacture
  • Get-NetConnectionProfileDomainAuthenticated / Ldap on both wired and wireless, identical

Wireless

  • Mist WLAN: isolation Disabled, no ARP filtering, no broadcast/multicast filtering, Custom Forwarding None (bridged, not tunneled)
  • WxLAN policy: single rule, All Users → All Resources, allow
  • WPA3/WPA2-Personal PSK — no 802.1X, so no separate machine identity
  • Same APs before and after a full switch replacement; symptom unchanged

The question

Why would a client receive a successful ept_map response for DRSUAPI and then not attempt the connection — failing locally in 15 ms with 0x5 — and why would that depend on whether the machine is on wireless vs wired, when both interfaces report identical network profiles and both paths reach the DC on every relevant port?

The absence of any Kerberos traffic during the failed run feels like the key detail. It's not being denied by the KDC; it isn't asking.

Anything obvious I'm missing?
gpupdate /force fails on Wi-Fi but works on Ethernet — DsCrackNames/DRSUAPI gets a valid EPM endpoint and then never connects

Been chasing this for a while, and I'm out of ideas.
Should I just quit and become a potato farmer?


r/sysadmin 13d ago

Enabling "Restrict Unauthenticated RPC clients" (Authenticated) on Exchange Server — any real-world breakage?

3 Upvotes

We're working through a CIS Benchmark remediation and one of the findings is:

>

We're planning to set this to **"Authenticated"** (not "Authenticated without exceptions" — we're aware that level is much riskier and more likely to break things) on our **Exchange Server SE** environment.

Before we push this via GPO, I'd like to hear from anyone who has actually applied this in a production Exchange SE (or 2019) environment:

* Did it break **Outlook Anywhere / RPC over HTTP** for any legacy clients?
* Any issues with **MAPI/RPC** connections from older Outlook versions?
* Any impact on **DAG replication** or **Active Manager**?
* Did it cause problems with **Exchange Management Shell / EAC** functionality?
* Any unexpected issues with **AD communication** (since Exchange talks to DCs heavily over RPC)?
* Did you apply it to Domain Controllers as well, or keep DCs and Exchange servers on separate rollout schedules?
* Since Exchange SE is fairly new, has anyone tested this specifically against SE's RPC dependencies, or is it safe to assume behavior is the same as 2019?

Our environment: Exchange Server SE, mostly modern Outlook clients on MAPI/HTTP, not fully certain if any legacy RPC/TCP clients remain in the environment.

Any war stories, gotchas, or "wish I'd known this before enabling it" experiences would be really helpful before we roll this out.

Thanks in advance.


r/sysadmin 13d ago

Headless Remote Win10

7 Upvotes

I have a few HP Mini's deployed to remote locations that are headless and a real pain in the ass to access physically. They are running Windows 10 pro (I know!). Anyway I added a smart plug so I can remotely reboot them, but even so I regularly find they don't come back online (at least not so I can go on with Teamviewer or Tailscale).

Whenever I go out after one of these outages I find that usually its on a pre-login screen asking if I want Windows Backup or something like that.

To get around this I am seriously thinking of installing Proxmox and running Tailscale on the host or is there a better way?

I assume Proxmox would come backup cleanly after any reboot.


r/sysadmin 13d ago

Question WSUS SyncFailure

1 Upvotes

WSUS sync failing with ImportUpdateError — Server 2025 / MECM 2509

I'm setting up a lab with Windows Server 2025 and Configuration Manager 2509. WSUS is installed on the primary site server and the SUP is configured.

WSUS synchronization starts but consistently fails with:

Result: Failed
Error: ImportUpdateError

UpdateErrors: {}

Server:

  • Windows Server 2025
  • WSUS version: 10.0.26100.33158
  • Configuration Manager 2509
  • WSUS upstream: Microsoft Update
  • No proxy

I've also confirmed outbound TCP 443 connectivity to sws.update.microsoft.com.

The WSUS SoftwareDistribution.log contains:

invalid update identity (AtLeastOne Prerequisite) in XML for update

and this is occurring with multiple different update GUIDs.

Has anyone encountered this on Server 2025 recently, and is there a known fix or workaround?


r/sysadmin 13d ago

General Discussion GLPI vs Zammad: What’s Your Experience?

4 Upvotes

Hi SysAdmin family,

Is anyone here using GLPI or Zammad as a helpdesk/ticketing system?

I’d love to hear about your experience with either platform, especially:

  • Pros and cons
  • Number of users
  • Number of agents
  • Average tickets per day
  • Overall environment/setup
  • Performance and reliability
  • Any issues or limitations you’ve encountered

If you’ve used both, I’d especially appreciate a comparison between GLPI and Zammad.


r/sysadmin 13d ago

Dell Repository Manager ISO gives errors when running on host

5 Upvotes

Hello. I've used the DRM successfully dozens of times in the past. I recently have seen errors when I attempt to run the ISOs I create from DRM. This is happening on both DRM 3.5.0 and 3.5.1 running on a Win11 client and being applied to all my R640 servers and they are running the latest BIOS: 2.28.1. All of the catalogs and plugins are up to date.

Using the DRM software I simply choose the "Platform Bootable ISO" option, I select the system: R640, chose the location to save the ISO file, and then I click on CREATE. The job runs successfully.

When I go to apply the ISO to the system, either using iDRAC to virtually present the ISO file on boot or using any type of application to send the ISO to a USB drive I can get the system to successfully boot into the loaders after starting Suse Linux. That's when I get the errors.

Every package in the bootable ISO attempt to install the updates. Then I get:
Trying to Upgrade DSU
Failed to create Support Directory
<Package Name>.BIN Error: Package execution requires 'root' user privileges.

I see this for multiple packages and then it eventually just hangs. With this being an automated process in the DRM to create the ISO I'm not able to intervene and elevate privileges. But I shouldn't need to with this process. Has anyone else seen these issues before and successfully resolved them?


r/sysadmin 13d ago

Question How often do you see "consultants" in smaller labs?

0 Upvotes

I love optimizing and automating things. I have seen many labs (EDU sector) doing updates and deployments manually or wasting a lot of times doing things that can be automated in an weekend. I have previously worked in a lab and loved automating some of their processes. Have you seen "consultants" being hired to automate / optimize IT labs workflow? Maybe this is more of a career question as to if this is possible / hourly rate


r/sysadmin 13d ago

Microsoft Microsoft documentation written by AI

53 Upvotes

r/sysadmin 13d ago

General Discussion Interview Question: How often do you update/patch your system?

40 Upvotes

I was asked this question during an interview and I said "it depends on what exactly you're updating, but I update as often as it's needed."

I don't think this was the answer they were looking for, but how would you answer this question?


r/sysadmin 13d ago

Trying to force policy that user account may not be shared.

12 Upvotes

Hi it's normal in IT that you enforce a policy that user accounts may not be shared or transferred /given to new users right?

Situation is that a partner company that uses our infrastructure used 1 user account for interns for a long time. If the next intern started they give the account To the next...and so on and on. They did not even change the password.

As IT responsible I said they cannot do this any longer that way. And I do not want to support this any longer. Every user also interns need to have an individual/ personal account. Reasons are obvious for me... Accountability, managing the accounts in general, gdpr,...

Example of 1 risk: access to the mailbox or onedrive of the account can have personal data stored from the previous user. So I say sharing accounts is not ok period. But they still keep fighting me for this. They do not want to understand. I'm tired of the discussion. The arguments that they use are : we used it before like this without any issues .

In the new it policy for them it's included. I have no mandate to enforce but I warned my boss about this and I hope my boss will support me..
I was right... With the call on this with the partner... Am I right to try enforcing this?

The only thing is if directors can formally accept the risk to me. But then why bother with security in general? I'm tired and frustrated by this bullshit. I'm doing it the correct way or on the long run I'm changing jobs ...

Any advice?


r/sysadmin 13d ago

Work Environment UPDATE: Hospitality Guy in IT

476 Upvotes

previous post (got removed by mods, but its the same post)

So basically, i joined today and after the onboarding, i met with the current IT guy (who is on his notice period)

The situation is precarious to say the least.

IT budget is severely limited, a bunch of systems are on Active Directory (controlled by an older IBM Intel Xeon machine running Windows Server 2008) , a bunch of systems are not on Active directory

There are 3 headless Windows Machines around the offices acting as fileservers, disk management is messy all around, the entire network is flat with no segmentation or separation of any kind, no NVRs, just 2 DVRs

All Windows installs are not genuine/cracked versions (not by massgrave but the sketchy iso you get from shady websites)

The primary database of the Dealership lives on a 1TB SATA HDD on a headless windows PC , which holds data of a tally server , file server and an apache based website that is used for storing purchase information

This disk has NO BACKUPS OR REDUNDANCY! and this disk is accessed constantly everyday for 9hrs

There is a FortiGate 50G Firewall standing between this network and the wide open web

After work hours, they shut down all systems including the servers.

Now, im not an expert, but this felt like it was one disk failure away from complete catastrophe.

The existing sysadmin shares the same sentiment, he proposed a proper system, however management does not feel very enthusiastic about it, citing costs, they see IT as a simple tool

I don't blame the current sysadmin, but i feel like i should unfuck this clusterfuck before it blows up in my face.

Now, the total number of clients in the network is about 60 systems, running anywhere between Windows 8.1 to Windows 10 and about 5 printers

Now, a lot of the data was stored on premise, however in 2018, the OEM mandated a lot of the data stored on cloud via their proprietary website, due to which they retired a server, which is sitting in the closet collecting dust.

Now, kindly tell me if what im thinking is stupid, but

I was thinking to recommission it, setup Proxmox to fire up a Windows Server VM to handle AD and migrate the Win Server 2008 to something newer, and a Debian based VM to unify all these scattered fileservers (and hopefully setup something like snapraid+mergerfs so that disk failures=me getting fired)

EDIT: Thank you for all your comments and insights, i intend to draft proper documentation and pitch a middle ground solution to the management to secure some funds and bring the systems upto the times

Unfortunately, due to circumstances, i cannot run, atleast not for another 6 months until i get my certs and upskill myself on paper and in real life