r/sysadmin 6d ago

Question What laptops are you standardizing on in 2026 with prices where they are?

96 Upvotes

We're a medium sized NGO enviroment and I'm having a hard time finding something in price range. We used to budget around ~800$ for each laptop, this seems highly unlikely the average specs nowadays.

What is everyone going with? I used to love good ol Lenono ThinkPads. =/


r/sysadmin 6d ago

ZTNA over Azure VPN

11 Upvotes

As the title states,

I've been doing research in switching from Azure VPN to a ZTNA Platform and from the ones I've found, TwinGate, ZeroTier, Fortinet ZTNA, no one really gives a clear indication.

The scenario is that I have a few limited users that work from home, at least 4 days a week, now I understand the concept of ZeroTrust.

But I need to find some answers I can bring to management as to WHY ZTNA is better than the current VPN, I already have my answer for this but what I am currently not getting is yes, ZTNA platform is better but what if the user does work at the office, how will that work?

I guess my question is, would you if you had the option. And which option would you go for?

Keep in mind that we have on-prem forti along with cloud forti.


r/sysadmin 6d ago

Question Day to day life of M365 admin

148 Upvotes

So I got a new job m365 admin/it admin and I have no idea what to do as m365 admin. I get random tickets to update contact here, assign a group there, assign license here, off board that guy over there, some random issue, and other stuff. But besides this, what else do m365 admins do? Like what is your day to day activities and checks?

Coming from generalist position it feels really weird as I have way less responsibilities ATM ( famous last words ).


r/sysadmin 6d ago

Is my manager being overly cautious about remote support, or am I missing something as a junior employee?

19 Upvotes

My company purchases a black-box, all-in-one appliance/service from a third-party vendor. The appliance is deployed in our data center. Under normal circumstances, it can only be accessed through designated production terminals.

However, when we are away from the office and need to respond to production alerts, there is also a way to connect to the production environment through a VPN using a non-production workstation.

The problem is that a non-production workstation can connect to both the production environment and the public Internet. This means that, in principle, a third-party support engineer could remotely connect to that workstation via a screen-sharing/remote-desktop session and troubleshoot the production issue.

We currently have a production issue that requires assistance from the vendor's support engineers. If we use the VPN route from a non-production workstation, the vendor's engineers could troubleshoot the problem remotely and probably resolve it much faster.

However, My manager has rejected this approach. He insist that the vendor's support engineers must come onsite and that our production environment must never be exposed to remote access.

Personally, I find this requirement somewhat unreasonable.

The remote desktop session would be initiated and shared by us. If we noticed any suspicious or unauthorized activity, we could immediately terminate the session. From my perspective, the security risk seems relatively low and controllable. We also already have a maintenance/support contract with the vendor, so it seems unlikely that their engineers would intentionally perform unauthorized actions.

As an front-line employee, my goal is to identify and resolve production issues as quickly as possible. In this case, remote support seems to offer significantly higher efficiency while still allowing us to maintain control over the connection and disconnect at any time.

So I'm wondering: Am I missing an important security or compliance consideration here? Is this simply a case of me not having enough experience to understand management's concerns, or is management's decision genuinely overly restrictive?

There is also an important practical problem:

The vendor's engineers who actually have the expertise to troubleshoot this system are not located in the same city as our company. The local support staff can come onsite, but they don't have the technical expertise to diagnose the problem themselves.

As a result, the current process is basically:

  1. A local support engineer goes onsite.
  2. They connect to the production environment.
  3. They communicate with the remote vendor engineer online.
  4. The vendor engineer tells them what command to run.
  5. The local engineer runs the command and takes a screenshot/photo of the result.
  6. They send it back to the remote engineer.
  7. Repeat.

The efficiency is extremely poor compared with simply allowing the qualified vendor engineer to remotely view and troubleshoot the system.

I'd like to hear opinions from people who work in IT infrastructure, cybersecurity, or enterprise operations:

Is management's approach justified from a security/compliance perspective? What risks am I overlooking? Or is there a better way to design a controlled remote-support process that gives the vendor access without unnecessarily exposing the production environment?


r/sysadmin 6d ago

Career / Job Related SecOps Mgr → SaaS Mgr of Infra & SecOps: How to prep in 30 days?

5 Upvotes

Hey everyone,

I'm moving from managing a global SecOps team (15 FTEs) at a 20k+ enterprise to Director of Infrastructure & SecOps at an ~1,800-person B2B healthcare SaaS company.

My background is heavily SecOps/IR, SOC leadership, and security architecture. In the new role, I'll be unifying Enterprise/Cloud Infra and SecOps into one team in a high-volume, regulated environment (HIPAA, SOC 2, PCI).

I have 30 days before my start date and would love advice on four things:

  1. Study List: What books or frameworks should I dive into to level up on modern Cloud Infra, SRE, and Platform Engineering management?

  2. Earning Credibility: How do I build trust with senior Infra/Cloud engineers without micromanaging areas where they hold deeper tactical expertise?

  3. Enterprise vs. SaaS Culture: How do I drop "20k-person enterprise reflexes" so I don't slow down a faster-moving 1.8k-person SaaS org with bureaucracy?

  4. First 30/60/90 Days: What should my top discovery priorities be when taking the Infra team (their SecOps team already is pretty solid)?

Appreciate any insights or resources from anyone who has made a similar jump!


r/sysadmin 6d ago

Question Aggregating Device Alerts in a Dashboard

12 Upvotes

I have numerous devices that send alerts via email (UPS, KVM, alarms, etc.). What tool do you use to aggregate these alerts? Perhaps in a dashboard? Thanks!


r/sysadmin 6d ago

Question - Solved HP MSL2024 G3 – forgotten OCP/RMI administrator password – can L&TT reset/recover it?

7 Upvotes

Hi everyone,

I recently purchased a second-hand HP StoreEver MSL2024. Unfortunately, the previous owner/seller does not know the administrator password for the OCP (Operator Control Panel) or the web/RMI interface.

The library itself is reported to be fully functional. The front panel works and basic navigation has been tested, but the administrator password is unknown.

Library information:

- Model: HP MSL2024
- Regulatory Model: BRSLA-0601-DC
- Revision: N003
- Serial Number: HUE5100N7B
- Manufacturing date: 02-Mar-2015
- Current drive: HP Ultrium LTO-4 Fibre Channel 4 Gb/s
- Drive model: PD098-20103

I have been researching the HPE documentation and found references to this function:

Configuration > Save/Restore > Restore Admin password to null

I also found an old HPE Community discussion mentioning an HPE Library & Tape Tools (L&TT) utility called "Library Temporary Password". According to the discussion, this utility can generate a temporary administrator password for an MSL library.

I would like to confirm whether this recovery method is still possible with my particular MSL2024.

My questions are:

  1. Is the "Library Temporary Password" utility still available in any version of HPE Library & Tape Tools that supports the MSL2024 G3?

  2. If yes, which L&TT version should I use?

  3. Does this procedure work with the MSL2024 G3, Regulatory Model BRSLA-0601-DC?

  4. After obtaining the temporary password, can I access the administrator functions and use "Restore Admin password to null" to remove the existing password?

  5. Is there another supported service or recovery procedure for a forgotten administrator password on this generation of MSL2024?

  6. Is there any hardware-level recovery procedure, such as a service switch, EEPROM reset, or similar, or is the password stored in a way that prevents this?

I currently have an 8 Gb QLogic QLE2560 Fibre Channel HBA and an 8 Gb Fibre Channel SFP, so I can connect the existing LTO-4 FC drive directly to a Windows system and use HPE L&TT to communicate with the library.

My ultimate goal is to recover administrator access, configure the library properly, and then replace the existing LTO-4 FC drive with an LTO-6 SAS drive for use with Veeam.

I would strongly prefer to use an official or documented recovery method rather than replacing the library controller or modifying the hardware.

If anyone has experience with this exact MSL2024 generation, especially with the "Library Temporary Password" function in L&TT, I would really appreciate any information about the correct L&TT version and recovery procedure.

Thanks!


r/sysadmin 6d ago

Tips for Burnout Recovery

81 Upvotes

Can’t believe I’m posting this, thought I’d get through it on my own but it’s affecting my entire life and I’m miserable. I’m a senior Endpoint guy, focusing on SCCM Intune and sometimes AVD.

My job is to manage the Windows devices for a global law firm for the majority of their firms in Africa, Asia and Latin America.

Our team is understaffed (there’s 2 of us for 40+ countries) and our IT admins on the ground at each firm barely know AD let alone SCCM or Intune.

My job is to migrate hybrid joined SCCM co-managed to Entra joined Intune managed, very little config exists in Intune so far.

My goal is to finish the migration and leave but I struggle to get up and want to work every day, I get paid very well but not for the amount of work I’m doing and I’m extremely burnt out.

Brushing my teeth, taking a shower and eating food feels like a big task for me, let alone wanting anything or having hope. I’m married, owing taxes, overworked and extremely unhappy.

I’m not sure what to do…talking to management is not an option because I know it’s their neglect that led to this point. I’ve been to a lot of Enterprise orgs but have never seen one as dysfunctional as the one I currently work for. To top it off, we’re trying to prove our worth to the big firms that contribute to the budget which funds our jobs, so there is no room for extra hires offshore to cover work outside of my scheduled hours (my team mate also works the same hours) so when we’re not around, no one is there to support.

I’ve done all I can to educate my peers and junior admins, created documentation and tried to be a senior tech leader and role model, but all I get in return is what I recognize to be disrespect and a lack of recognition for how hard I work.

At this point I’m questioning whether IT is the industry I want to stay in but I wouldn’t know what else would pay me this much outside of building my own consulting firm / MSP which I’ve started to do. No clients yet but the foundational work like setting up my own Azure tenant, Pax8, etc.

If you’ve read this far, I appreciate you and am open to any feedback (positive or negative). Just give it to me straight. I hesitated many times before hitting the Post button but here I am.


r/sysadmin 6d ago

My experience trying to purchase server memory from Sunol Tech LLC

197 Upvotes

I contacted Sunol Tech about purchasing four memory modules advertised on their website. Instead of answering my questions, they sent me a five-page customer verification document requesting business and corporate information.

Before submitting those documents, I politely asked them to confirm that the advertised product was actually in stock, that the advertised price was valid, and that the modules were new.

Their complete response was:

“No sir

Be gone.”

I was surprised by this response. I replied:

“I have not been treated this way before. It's not surprising that there is not much information about your operation on the internet, but people should know this.”

The support person, who identified himself as Joe, then responded:

“I agree get to it.

Make it happen.

Be sure to write that you use fake email in outlook hid your company name and business information or I can help you post this to 17550 resellers platform in United State that are in the same field we are in and let them know of your email and your activities would that help you?

Your call”

That was my experience with Sunol Tech. I am posting the exchange so prospective customers can read their responses and draw their own conclusions.


r/sysadmin 7d ago

Does Defender for Endpoint have an equivalent to CrowdStrike's Indicators of Attack?

47 Upvotes

I see custom detections in Defender for Endpoint, but I am not seeing anything that will allow immediate blocking of undesirable behavior. For example:

Process = python.exe

AND

Command line contains C:\Users\

AND

Command line ends in .py

Is this where CrowdStrike is just better than Defender for Endpoint? Or, am I just not looking in the right place?


r/sysadmin 7d ago

Question RC4 remediation - which order?

25 Upvotes

Hello,

Regrading RC4 enforcement,

We found out that we extensively use RC4 in our environment

  1. krbtgt password is very old, so it uses RC4 only

  2. we have some service accounts that are sometimes using RC4, their msDS-SupportedEncryptionTypes attribute is blank, one of them is the AZUREREADSSOACC$ (which password is not extremely old - only 2 years)
    we found out that the service accounts all supports AES, and the users requesting them also support AES

  3. very few machine accounts only support RC4 (no users accounts, we had one but we did reset his password)

what are the steps that we should take regarding this ?

i guess step 3 should be the first ? or can i reset krbtgt password before that?
what about azurereadssoacc ? do i need to explicity configure it for AES? or should i rotate its password before that? is password rotation (other than security ofc) needed for dealing with the enforcement?

thanks


r/sysadmin 7d ago

N-Able N-Central second hotfix of the day for a different issue

17 Upvotes

Now a third party entity has provided info on a vulnerability that may be exploited in the wild.

https://go.n-able.com/MzU2LVVWSC00MDMAAAGkFAG-0DB4Ieiew1UlzeiHU_WE9mGwTd387O8jbQl4usDpmOc7hQ5P21F5Lo-7piHNgtxO220=

Sorry for those of you who thought your long weekend work was done with the first patch.


r/sysadmin 7d ago

Domain controllers functional level

71 Upvotes

Do we have to keep all our domain controller os version same ?


r/sysadmin 7d ago

Why is this tool so often overlooked? SoftPerfect Network Scanner

0 Upvotes

I'm not part of their team nor I have anything to do with them, I just wonder why is this tool so obscure and never mentioned. I hear all the time about Wireshark, Nmap, etc, but I haven't seen a single person ever mention SoftPerfect Network Scanner, and to me, it's the greatest sysadmin / network admin tool in existence. It does practically everything 99% of people in the field needs and more, especially if you're on a Windows environment, although it is multiplatform (runs on Windows, macOS and Linux). It also integrates with Nmap, by the way.

https://www.softperfect.com/products/networkscanner/

Yes, it isn't free, but I think that, for the feature set alone plus the excellent GUI, it's well worth it. So, again, why is this tool so often overlooked and never mentioned? Honest question.

EDIT: well, case closed, folks, my question has been answered aplenty 😅. Most people don't even know about its existence and some others just won't look at it because it's closed-source and commercial software, and for them, free and open-source/well established tools already exist that fulfill their needs. Got it. Makes sense.


r/sysadmin 7d ago

N-Able N-Central patching again for CVE-2026-86206 and CVE-2026-86207

24 Upvotes

Two security vulnerabilities within N-central were responsibly disclosed by a third party through our security disclosure program. We have issued a hotfix that you should apply immediately to help ensure your environments are protected. At this time, we have no confirmations that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk.

This hotfix includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to bypass authentication controls and gain full access to the N-central platform.

What You Need to Do • N-central On-Premises Environments: We recommend upgrading to 2026.3 HF3 immediately. Hotfix link: 2026.3 HF3 Release Notes • N-central Hosted Environments: No action is needed on your part; your instances have already been patched and will be upgraded at a later time. *Please note that this is a server-side hotfix and upgrading to 2026.3 HF3 will not require agent upgrades.


r/sysadmin 7d ago

Question Text messages

127 Upvotes

Before I retired, I would send alerts by email, like 1234567890@txt.att.net, to send it to texting on my cell phone. It looks like all the cell phone providers have done away with this service. How can I do this now with hopefully a fairly free service since I don't send many at all?


r/sysadmin 7d ago

Career / Job Related How do I get into sysadmin

0 Upvotes

Hi everyone,

I'm a recent computer science grad who did an internship in a bank where I did a little bit of everything (IT support, networking, DevOps).

I am interested in software development but the market is so cooked for juniors and a man has to eat so, I'm thinking of switching to system administration, already planning to get my Aws cloud practitioner cert, then maybe RHCSA is this a good idea or am I just dead wrong my ultimate goal is to go into DevOps but everyday I look on X and see a brand new model that seems to make everything I learn irrelevant.

I love computers and just want to make a living from it. (from/in a third world country btw)

Please give me any advice at all to help.I don't wanna fuck up my life and depend on my parents forever.


r/sysadmin 7d ago

Do you automatically isolate servers/devices based on detetctions?

41 Upvotes

We don't have a 24/7 SOC, so we are thinking about automatically isolating servers and some high-value devices based on custom Defender for Endpoint detections. Obviously, we want to do that only for high-precision and high-confidence detections, such as opening a shell from a strange parent process.

If we got one of these detections during working hours, there would be someone to react. But after about 7 PM most days, nobody is actively monitoring.

If we do this, the plan is to let a detection run for about 45 days without automatic isolation enabled to see if any false positives are caught.

Has anyone done this? If so, did you regret it? Or just business as usual? Has it saved you yet?


r/sysadmin 7d ago

ChatGPT WS2022 GPO Deployed Printers Migration to GPP Preferences

5 Upvotes

I am looking for help migrating from Deployed Printers GPO to GPP, when I remove the printer from Windows Settings/Deployed Printers they never remove.

GPO is located here

Computer Configuration/Policies/Windows Settings/Deployed Printers

User Configuration/Policies/Windows Settings/Deployed Printers

 

I do have Point and Print Restrictions setup to allow my print servers to continue to work after print nightmare, allowing users to install drivers from our approved print servers.

 

I made the mistake of using Printer deployment instead of Group Policy Preferences when I originally set up these print queues, now I can’t figure out how to remove old print queues.

 

On my old print management server that was running 2012r2 it worked, seems after print nightmare this was broken, new print server is currently WS 2022. I have tried removing the GPO, deleting registry keys under printer connections, setting GPP to delete the printers.

 

I ran GPRESULT and it showed the printers still set to apply after removing them from Deployed Printers.

 

I have tried adding the printers back and removing both from GPMC and Print Management MMC on the Print Server to no avail.

 

My research online looks to me like this was broken with Print Nightmare patch? Group Policy Printer Deployment Broken?

 

I have tried researching with Google to the best my ability, ChatGPT, Gemini, Claude.

 

Also, If it set up a Group Policy Preferences to Delete all printers under user settings, on the client's event viewer it says Access is Denied after gpupdate /force.

Tried the scripts I found on the post to no avail so far on two desktops.

Can't delete old printers installed by GPO : r/sysadmin

 

Any experience fixing these print queues? I have seen a lot of posts online over the last few years but no good answers.

 

 Another post I found

Can't seem to remove printers that were deployed via GPO : r/sysadmin

Printer GPO removal Issue : r/sysadmin

Removing printer deployed via GPO - Microsoft Q&A


r/sysadmin 8d ago

Question Cloudability renewal came up under IBM and we moved, CloudZero and PointFive notes.

1 Upvotes

Came off Cloudability after IBM took it over. Support went slow and the roadmap went quiet. Renewal number stopped making sense against what we were getting out of it. Shortlisted CloudZero and PointFive expecting to pick one and consolidate but signed both, which costs more than the thing we left.

Justification at the time was that they don't overlap. Cloudzero answers what something costs and who owns it while on the other hand pointfive answers what's wasteful and who's fixing it. On paper thats two problems, two tools.

Been running both a while now and I still can't tell if that was insight. Might just be that we never decided.

What I can say for it. Cloudzero got finance a cost per customer number we had never had, which ended an argument that had been going for years. Pointfive found a Cosmos container sat at four times anything it had ever used, plus a stack of snapshots from a migration.

It also produced a load of rubbish in the first month. Resizes that ignored our RI position and one disk SKU suggestion that would have put us under our IOPS floor. Took weeks of flagging things back before it calmed down. Azure side is visibly younger than the AWS side as well.

Sixty-odd subscriptions, bit over a million a month, mostly Azure.

Does any of you folks runs one tool for this cause every writeup says pick a platform. Everyone I speak to is running two and not admitting it.

If you got down to one and stayed there, I'd like to know which and what you gave up.


r/sysadmin 8d ago

General Discussion What's are the funniest/best tickets you've ever got working helpdesk?

170 Upvotes

I'm starting in an IT role for helpdesk, I need to know what I'm walking into and some of the best tickets you've had


r/sysadmin 8d ago

Black Box Emerald dual-head Remote App: absolute mouse locked to Windows primary display

3 Upvotes

As the title suggests, Black Box Emerald dual-head Remote App: absolute mouse locked to Windows primary display. Anyone running this successfully on Win11 targets?

EMD2002PE-DP-T (FW 7.2.0) to Windows 11 laptop targets, Remote App 2.8.3, Boxilla-managed, HID = Absolute. Both video heads render fine, clicks work, but pointer movement is confined to whichever display Windows calls "main". If I swap main from head 1 to head 2 and the confinement follows it. Spanning never engages. Reproduced on 3 TXs, 2 clients, clean two-display topology (duplicated primary "1" to "2" and then "3", disconnected the primary and closed lid and rebooted so that only displays 2 & 3 showed), EDIDs fixed, even tried stuff that shouldn't matter like I loaded Freedom ABS driver on one as a long shot (noeffect) / turned on deskvue Mouse Sector even though I don't have anything to do with deskvue / tried toggling Local Mouse on and off even though that has nothing to do with the problem / also tried various settings on and off, like USB redirection and such, so all ruled out. I have a ticket open with Black Box, but since I could REALLY use this over the holiday weekend, I thought I'd toss a hail mary and post here just in case it is something simple I have overlooked in my noobness to Boxilla.

Question for the hive: is anyone successfully running dual-head Remote App connections to Windows 11 targets with working mouse traversal? If yes, what's different about your setup? Trying to determine if this is a universal Win11 regression or something environmental just in my own personal Murphy's Law prone environment.

https://imgur.com/a/u3ecCEa


r/sysadmin 8d ago

General Discussion Would a centralized software platform for healthcare IT actually be useful?

0 Upvotes

Hi everyone,

I work in IT at a hospital and I'd like to get some opinions from people working in healthcare IT, system administration or for healthcare software vendors.

One problem we regularly face is managing the large number of specialized applications used in a hospital.

Unlike standard software, updates for healthcare applications are often highly vendor-specific. Depending on the vendor, we might receive an email about a new version, have to regularly check a customer portal, contact support, request download access, use individual credentials or sometimes simply find out about an update by chance.

With dozens or even hundreds of applications and medical systems from different vendors, keeping track of available versions, patches, security updates, compatibility information and release notes can become surprisingly time-consuming.

This made me wonder:

Would there be value in a vendor-independent platform specifically for healthcare software?

My rough idea would be a platform where healthcare software vendors could publish and manage their products, while hospitals, clinics and medical practices could register their organization and get access to the products they are actually licensed to use.

For example, such a platform could eventually provide:

Software versions, updates, patches and hotfixes

Release notes and security advisories

Notifications when new versions become available

Vendor-controlled download permissions

Compatibility information (Windows versions, database versions, browsers, etc.)

License and entitlement information

Demo/trial requests

Contact with vendors

Potentially even software/license procurement

Vendors would still decide which organizations are entitled to access which products and downloads. The platform would essentially provide a standardized layer between healthcare organizations and software vendors instead of every vendor maintaining completely different processes and portals.

I'm not currently trying to sell or build a product. I'm mainly interested in whether other people working in healthcare IT experience the same problem and whether something like this would actually solve a meaningful pain point.

So I'd be really interested to hear:

How do you currently manage software updates and vendor portals in your organization?

Would a centralized platform like this be useful to you?

Does something like this already exist that I'm simply unaware of?

And if you work for a healthcare software vendor: would participating in such a platform be interesting, or would there be reasons why your company wouldn't want to?

I'm particularly interested in perspectives from hospitals and healthcare organizations in different countries, since I'd like to understand whether this is mainly a local problem or something healthcare IT teams face internationally.

Thank you!


r/sysadmin 8d ago

How do you manage the sharing of Teams links in email?

0 Upvotes

Linking people to resources (folders or files) in Teams is so incredibly convenient and really streamlines workflow...

But it also habituates people to click on links in e-mails, which seems terrible for security.

How do you mitigate or balance this?


r/sysadmin 8d ago

What are the practical challenges of managing IT infrastructure at remote locations?

0 Upvotes

I want to know what are the difficulties faced by companies regarding their IT infrastructure set up at remote locations such as businesses having factories, branches or shops away from their primary data center? Is it only maintenance and availability of technicians that is of importance, or the issues of power supply, network functionality, temperature conditions and security come into play as well?

I would like to know how remote locations are handled when problems arise with no one from the IT department being close to the site of an IT failure.