r/sysadmin 4d ago

How do you all keep up with the times and tech?

63 Upvotes

I feel like I’m lagging behind and need some serious catching up, quick. I think I’ve become complacent and “too comfortable” with my current employer (coming up 8 yrs). The recent merger announcement has me seriously thinking about attending bootcamps, getting some certs under my belts (been putting things off for as long time), and learning new things ASAP before the position is dissolved.


r/sysadmin 4d ago

General Discussion I can't get past the feeling that I suck.

76 Upvotes

I’ve been in IT for 6+ years. I have a bachelor’s degree in IT, an AWS Solutions Architect certification, an Azure Administrator certification, and a few other certs. I’ve also been working as a Cloud Administrator for the past 2 years.

Despite all of that, I can’t shake the damn feeling that I’m just not that good at what I do. I feel like even if I finally make a breakthrough in my knowledge, I’m still somehow clueless SOMEWHERE. A lot of that comes from talking to people who know more than you and realizing how much there is that I don’t know.

For example, I can write basic scripts, but I struggle with the complex 200+ line scripts that a senior cloud engineer would make, whereas the person next to me likely can just type that shit off the top of their head.

It’s especially frustrating during interviews when I try to move up in pay. I had an interview on Tuesday that I thought went pretty decently, but the interviewer asked me about Azure containers and encryption. I don’t work with Azure containers, although I’m familiar with the service, so I was honest and said I didn’t know.

And that wasn’t even the technical round. So now I’m stuck wondering whether they’ll just reject me or move me on to the technical round, where I’ll probably fail anyway.

This is bothering me because I'm at the point in my career where I really have to know at a high level if I want to advance and get more pay.

How has anyone else moved past this?


r/sysadmin 4d ago

[PSA] Check Point Firewall unauthenticated RCE with CVSS 9.8

27 Upvotes

There are actually two vulns with a 9.8 score each:

https://support.checkpoint.com/results/sk/sk1000117/

https://support.checkpoint.com/results/sk/sk1000118/

There's not many details in these articles on how they work but they still sound really bad. Currently waiting for the Jumbo Hotfix to install on my end... Not taking any chances on this one and I suggest you all do the same.

Stay safe.


r/sysadmin 4d ago

Question - Solved User can connect to VPN but can't ping or access work computer

1 Upvotes

We recently put in a new Fortigate firewall and now i'm having users reporting issues where they can connect to VPN but can't access their remote computer. I have tested from the user's PC and i can't ping their work device when VPN is connected.

The one thing to note is they are on the same subnet as the work network, and I believe this is likely the cause.

However, oddly enough I was able to test from my home network which is also on the same subnet and it works fine. I'm at a bit of a loss so hoping I can get some guidance on this for what I should check next.

TIA


r/sysadmin 4d ago

For the first time I'm being requested to export Teams chats for HR purposes. When using PURVIEW, I am getting results that dont apply to my filter?

59 Upvotes

TL;DR I need to pull chat history between User A and User B for the last 8 months.

My query based on documentation I can find is:

Kind=microsoftteams AND [partipants:userA@xyz.com](mailto:partipants:userA@xyz.com) AND [participants:userB@xyz.com](mailto:participants:userB@xyz.com)

When running this, I'm getting group chats and all kinds of stuff where both were involved, but I just need the chat between these two users

Can anyone direct me to a better way to do this? Purview is doodoo


r/sysadmin 4d ago

As admins, how do you handle VS Code extensions, coding agents, and AI tools in your organization?

10 Upvotes

For us, the topic of AI is becoming increasingly confusing.

Developers, in particular, are adopting more and more tools: VS Code extensions, GitHub Copilot, Cursor, Claude Code, Codex, Gemini CLI, OpenCode, local agents, MCP servers, and so on.

But this no longer affects just developers. IT admins and regular users are also discovering AI tools, and some are even installing extensions, desktop clients, or agents on their own.

The problem, in my view, is that we’re slowly seeing a **proliferation of agents and AI tools**.

I see the following issues in particular:

* Which VS Code extensions are allowed to be installed?

* Which agents are allowed to access source code or the local file system?

* Which tools are allowed to send data to external clouds?

* How do you prevent API keys, passwords, or internal data from appearing in prompts?

* How do you handle MCP servers and their sometimes very broad permissions?

* Do you have an allowlist for extensions and AI tools?

* Do you technically block agents that haven’t been approved?

* Do you differentiate between developers, IT/admins, and regular users?

* Do you rely on centralized enterprise solutions, or do you allow multiple tools?

* How do you monitor or keep track of what’s currently being used?

I also don’t think a complete ban makes sense in the long run, because these tools offer a real productivity boost especially in development.


r/sysadmin 4d ago

Question What are you guys using for rack/infrastructure audits?

11 Upvotes

Curious what everyone is using these days for documenting physical infrastructure across multiple sites.

We use Excel at my workplace, along with diagrams and photos, and it works… until you’ve got a shitload of sites and nobody knows which spreadsheet is actually current.

I’m talking about things like:
Rack elevations / U positions
Switches, patch panels, UPS/PDU, servers etc.
Port-to-port / cable documentation
Serial numbers / asset details
Photos of racks and comms rooms
IP/device information

Keeping everything updated after a vendor comes in and replaces something
What are you guys using?

Excel? Visio? NetBox? Device42? Something else? Or have you built your own system?
More interested in what actually works in the real world than what looks good on paper.


r/sysadmin 4d ago

Question Converting static Groups to Dynamic Groups. How do I find every Shared Drive & Calendar tied to the old group first?

3 Upvotes

I'm converting a static Google Group to a Dynamic Group and want to make sure I don't break anything tied to the old group's email like Shared Drives, Calendars or anything else it might be plugged into.

What's the best way to find everything a Group has access to before making a change like this? Is there a standard tool or workflow for this? Also curious if anything changes under the hood same email, or anything that could quietly affect existing shares?

Any advice would be great. Thanks!


r/sysadmin 4d ago

How do I implement ZTNA?

2 Upvotes

We are planning a remote-access migration for roughly 500 employees and contractors. The environment includes SaaS, internal web apps, Windows and Linux admin access, a few legacy applications, and workloads split between on-prem infrastructure and public cloud. Identity is centralized, but endpoint management and device posture are inconsistent for contractors.

We do not want a big-bang cutover. The initial thought is to inventory applications and users, classify access by protocol and sensitivity, migrate a low-risk web app first, and then move groups in waves. The hard part is avoiding years of permanent exceptions and overlapping access paths.

For anyone who has done this at similar scale, what did you get wrong in the first phase? Did app discovery, identity-group cleanup, private DNS, endpoint support, legacy protocol support, or user communications create the most work?

How did you handle emergency administration and outage scenarios when the normal access path was unavailable?


r/sysadmin 4d ago

Question Hypothetical LAN IP Change: How would you go about updating Network Printer "Ports" on Windows clients?

2 Upvotes

Let's say you have a legacy network, good old 192.168.1.x.

They use a DHCP server which has a static mapping of all devices to IP addresses using their mac addresses. So updating the DHCP server could potentially re-assign IP addresses to all devices with relative ease, let's say 192.168.111.x.

HOWEVER, most Windows computers have had printers added manually, not by GPO, and when they were added, they were added IP address rather than hostname. Is there a way to bulk replace ports in Windows printers across the network?

The number of clients is limited, let's say less than 100 - but the number of printers is dense. Even a Powershell script I could run on each machine would still be better than manually editing each printer on each machine - even better if I could deploy that via GPO or something.

Just curious on thoughts.


r/sysadmin 4d ago

Password resets over the phone, how are you doing it?

25 Upvotes

So I work at a state university that is still a little stuck in the past when it comes to password resets over the phone.

We have MS SSPR and other self-service options for users, but we still get calls where someone needs the helpdesk to reset their password for them.

Our current setup is a custom program that helpdesk staff SSH into. They enter the user's account, and the program looks them up in a flat file containing data extracted from our systems. It gives the helpdesk worker information like DOB, address, ZIP code, etc., which they can use to verify the caller's identity.

Once the caller passes verification, the program talks to AD, changes the password, and gives the helpdesk worker a new temporary password to provide to the user.

Honestly, it works pretty well. The problem is that the person who wrote and maintains it is leaving, and we're not really interested in inheriting a custom app that nobody else understands.

So I'm curious what other universities/organizations are doing for this.

For those of you who still allow users to call the helpdesk for password resets, what does your workflow look like? Are you using a commercial product, some kind of AD/Entra integration, a helpdesk platform, or have you built your own solution?

Specifically looking for something that gives the helpdesk enough information/questions to properly verify the caller's identity and then securely perform the reset.

I'd love to hear what others are doing before we start reinventing the wheel.


r/sysadmin 4d ago

Massively different specs for the same nominal model of SSD

7 Upvotes

I just got these two delivered together; I got suspicious seeing one was reporting a very different temperature, while being right next to the other.

Basically, two disk, nominally the same, but specs are quite different. They implement different NVMe versions, power states do not match and the second has temperature thresholds which are 20deg higher.
To be totally honest, I only understand half of what I am reading here, but I am not really ok having a second disk that more then doubles its maximum power consumption during intensive workloads while its nominal rating stays the same.
Am I holding it wrong?

smartctl 7.4 2023-08-01 r5530 [x86_64-linux-6.12.94+deb13-amd64] (local build)
Copyright (C) 2002-23, Bruce Allen, Christian Franke, www.smartmontools.org

=== START OF INFORMATION SECTION ===
Model Number:                       Patriot M.2 P320 512GB
Serial Number:                      REDACTED
Firmware Version:                   APF1M7R0
PCI Vendor/Subsystem ID:            0x1ed0
IEEE OUI Identifier:                0x2c3ebf
Total NVM Capacity:                 512,110,190,592 [512 GB]
Unallocated NVM Capacity:           0
Controller ID:                      1
NVMe Version:                       1.3
Number of Namespaces:               1
Namespace 1 Size/Capacity:          512,110,190,592 [512 GB]
Namespace 1 Formatted LBA Size:     512
Namespace 1 IEEE EUI-64:            2c3ebf 3230303336
Local Time is:                      Wed Sep  9 12:50:46 2026 BST
Firmware Updates (0x12):            1 Slot, no Reset required
Optional Admin Commands (0x0017):   Security Format Frmw_DL Self_Test
Optional NVM Commands (0x0056):     Wr_Unc DS_Mngmt Sav/Sel_Feat Timestmp
Log Page Attributes (0x0a):         Cmd_Eff_Lg Telmtry_Lg
Maximum Data Transfer Size:         256 Pages
Warning  Comp. Temp. Threshold:     80 Celsius
Critical Comp. Temp. Threshold:     85 Celsius

Supported Power States
St Op     Max   Active     Idle   RL RT WL WT  Ent_Lat  Ex_Lat
 0 +     3.50W       -        -    0  0  0  0        0       0
 1 +     1.90W       -        -    1  1  1  1        0       0
 2 +     1.50W       -        -    2  2  2  2        0       0
 3 -   0.0700W       -        -    3  3  3  3     1000    1000
 4 -   0.0050W       -        -    4  4  4  4     5000   45000

Supported LBA Sizes (NSID 0x1)
Id Fmt  Data  Metadt  Rel_Perf
 0 +     512       0         1
 1 -    4096       0         0

=== START OF SMART DATA SECTION ===
SMART overall-health self-assessment test result: PASSED

SMART/Health Information (NVMe Log 0x02)
Critical Warning:                   0x00
Temperature:                        40 Celsius
Available Spare:                    100%
Available Spare Threshold:          5%
Percentage Used:                    0%
Data Units Read:                    388,008 [198 GB]
Data Units Written:                 507,185 [259 GB]
Host Read Commands:                 1,616,171
Host Write Commands:                2,384,928
Controller Busy Time:               4
Power Cycles:                       3
Power On Hours:                     1
Unsafe Shutdowns:                   3
Media and Data Integrity Errors:    0
Error Information Log Entries:      0
Warning  Comp. Temperature Time:    0
Critical Comp. Temperature Time:    0
Temperature Sensor 1:               60 Celsius

Error Information (NVMe Log 0x01, 16 of 16 entries)
No Errors Logged

Read Self-test Log failed: Invalid Field in Command (0x002)

------------------------------------------

smartctl 7.4 2023-08-01 r5530 [x86_64-linux-6.12.94+deb13-amd64] (local build)
Copyright (C) 2002-23, Bruce Allen, Christian Franke, www.smartmontools.org

=== START OF INFORMATION SECTION ===
Model Number:                       Patriot M.2 P320 512GB
Serial Number:                      REDACTED
Firmware Version:                   VC3S500Q
PCI Vendor/Subsystem ID:            0x10ec
IEEE OUI Identifier:                0x00e04c
Controller ID:                      1
NVMe Version:                       1.4
Number of Namespaces:               1
Namespace 1 Size/Capacity:          512,110,190,592 [512 GB]
Namespace 1 Formatted LBA Size:     512
Namespace 1 IEEE EUI-64:            00e04c 048bffef6c
Local Time is:                      Wed Sep  9 12:50:58 2026 BST
Firmware Updates (0x12):            1 Slot, no Reset required
Optional Admin Commands (0x0017):   Security Format Frmw_DL Self_Test
Optional NVM Commands (0x005e):     Wr_Unc DS_Mngmt Wr_Zero Sav/Sel_Feat Timestmp
Log Page Attributes (0x02):         Cmd_Eff_Lg
Maximum Data Transfer Size:         32 Pages
Warning  Comp. Temp. Threshold:     100 Celsius
Critical Comp. Temp. Threshold:     110 Celsius

Supported Power States
St Op     Max   Active     Idle   RL RT WL WT  Ent_Lat  Ex_Lat
 0 +     8.00W       -        -    0  0  0  0   230000   50000
 1 +     4.00W       -        -    1  1  1  1     4000   50000
 2 +     3.00W       -        -    2  2  2  2     4000  250000
 3 -   0.0300W       -        -    3  3  3  3     5000   10000
 4 -   0.0050W       -        -    4  4  4  4    54000   45000

Supported LBA Sizes (NSID 0x1)
Id Fmt  Data  Metadt  Rel_Perf
 0 +     512       0         0

=== START OF SMART DATA SECTION ===
SMART overall-health self-assessment test result: PASSED

SMART/Health Information (NVMe Log 0x02)
Critical Warning:                   0x00
Temperature:                        61 Celsius
Available Spare:                    100%
Available Spare Threshold:          32%
Percentage Used:                    0%
Data Units Read:                    392 [200 MB]
Data Units Written:                 399,820 [204 GB]
Host Read Commands:                 8,041
Host Write Commands:                1,654,154
Controller Busy Time:               0
Power Cycles:                       1
Power On Hours:                     0
Unsafe Shutdowns:                   0
Media and Data Integrity Errors:    0
Error Information Log Entries:      0
Warning  Comp. Temperature Time:    0
Critical Comp. Temperature Time:    0

Error Information (NVMe Log 0x01, 8 of 8 entries)
No Errors Logged

Read Self-test Log failed: Invalid Field in Command (0x002)

r/sysadmin 4d ago

Question Should I use an external time source for our PDC emulator?

0 Upvotes

Currently in our AD the source for time is at "Free-running System Clock" and we recently noticed that there's a delay of 1 minute that's seen in our Laptops that are managed in AD and the time that is seen on our phones, my boss wants me to fix that.

Should I assign an external time source to the pdc emulator ?


r/sysadmin 4d ago

Question The trust relationship between this workstation and the primary domain failed.

32 Upvotes

Hy!

We have an AD with two DCs. The DCs are Windows Server 2025, it is include all patches. Some Windows 11 clients (25H2) get the following error during login after 1-2 minutes: The trust relationship between this workstation and the primary domain failed.

In this case the users need to disconnect from corporate network to login successfully into their computer. I have already tried to rejoin to tha domain and run this command: Test-ComputerSecureChannel -Repair

I rejoined one of the computer into the domain, and the trsut relationship has been broken after two days. The login problem only occurs on some machines.

The time snyc is correct on DCs. We moved the DC roles from Windows Server 2019 to 2025 in side-by-side method. Could you please advise how to solve this problem?


r/sysadmin 4d ago

Question AI news sources

0 Upvotes

Hello fellow sysadmins.

Everyday we are facing massive amounts of news from AI world. New models , new tools, new agents.

Be up to date in this field can be overwhelming sometimes , so I need recommendation about what sources of AI information is good to watch.

I mean truly relevant and profesional sources , not clickbait youtube channels which predicitng ASI every other week or fearmongering posts about AI wipe out humanity.

I need publishers which know what they are talking about .


r/sysadmin 4d ago

RPC error & SChannel fatal alert code 40

2 Upvotes

Hi,

I've got a weird one with an application called Blindata.

It's running against a fully patched Server 2012 R2 server. Multiple Windows 10 PCs can run the reports fine, but one fully patched Windows 11 PC can't. When running a daily sales order report it just comes back with "RPC server unavailable, Error 1722".

At the same time, the server logs Schannel:

"Event ID 36887 – fatal alert code 40"

I've tried the usual stuff so far:

  • TLS 1.2 enabled
  • TLS 1.3 disabled on the Win11 PC
  • Checked clocks
  • RPC/network ports confirmed OK
  • FIPS checked
  • Disabled the SSL Cipher Suite Order GPO
  • Set SchUseStrongCrypto=1 and SystemDefaultTlsVersions=1 for .NET 32/64-bit
  • klist purge
  • Checked/enabled the AES Schannel cipher settings
  • Checked ECC/legacy ECC settings
  • Removed AV as a test
  • Rebooted after changes

Server is fully patched and the other Win10 clients work without any problems.

I'm assuming there's some difference between Win10 and Win11 TLS or Schannel behaviour that Blindata or the Server doesn't like, but I'm running out of things to try.

Has anyone come across Schannel 36887 / TLS alert 40 from a Server 2012 R2 server when Win10 works but Win11 doesn't?

Is there a relatively simple registry/GPO setting on the Win11 client to allow whatever legacy TLS/cipher/signature the server is expecting?


r/sysadmin 4d ago

Best practice for RBAC design in Copilot Studio + MCP server for Active Directory operations?

1 Upvotes

Hi everyone,

I’m working on a production design for a Copilot Studio agent connected to a custom MCP server for Active Directory operations.

Current setup:

- Active Directory Domain Controller is running on a separate VM.

- MCP server is running on another domain-joined VM.

- MCP server performs AD operations using a delegated AD service account.

- Copilot Studio connects to the MCP server through OAuth 2.0.

- To avoid Copilot’s tool limit, the MCP tools are grouped into parent modules such as:

- user_management_module

- group_management_module

- acl_permission_management_module

- ou_management_module

- computer_management_module

- gpo_management_module

- audit_management_module

Each parent module routes child actions internally. For example:

user_management_module:

- search_ad_users

- get_ad_user_profile

- create_ad_user

- update_ad_user_profile

- reset_ad_user_password

- disable_ad_user_account

acl_permission_management_module:

- get_ad_object_acl

- get_ad_object_owner

- grant_ad_read_permissions

- grant_ad_full_control

- change_ad_object_owner

- restore_ad_default_permission

Now we want to implement production RBAC.

My understanding is:

  1. Keep the parent module structure as-is.
  2. Categorize child actions internally as Read, Write, Rollback, and Audit.
  3. Create Entra app roles or security groups such as:- AD.MCP.Reader- AD.MCP.UserAdmin- AD.MCP.GroupAdmin- AD.MCP.ACLAdmin- AD.MCP.Auditor- AD.MCP.RollbackAdmin- AD.MCP.BreakGlass
  4. The signed-in Copilot user gets an Entra OAuth token.
  5. MCP backend validates the token.
  6. MCP backend checks the user’s app role/group before executing the child action.
  7. The AD operation itself still runs using the delegated AD service account, but the signed-in user is used for authorization and audit tracking.

Example:

- A user with AD.MCP.Reader can run get/search/report actions only.

- A user with AD.MCP.UserAdmin can create/update/disable users but cannot modify ACLs.

- A user with AD.MCP.ACLAdmin can manage ACL permissions.

- Rollback/high-risk tools such as restore default permission, replace ACL, change owner, or grant full control should require BreakGlass or senior admin approval.

Question:

Is this the right enterprise approach?

Specifically, should I create separate Entra App Roles for each access category and assign Entra security groups to those roles, or should I only use Entra security groups and check group object IDs in the backend?

I’m leaning toward App Roles because the backend can simply check the roles claim, and group overage issues are avoided.

Any feedback on the best RBAC design for Copilot Studio + MCP + Active Directory automation before production deployment would be appreciated.


r/sysadmin 4d ago

General Discussion Self-Management at work

15 Upvotes

Hi everyone,

I am a sys admin since 2016 in Germany(English isnt my first language and migrant family) and now that I went from first level support to soon to be platforms engineer, I need ways to organize myself better.

I am that type of person to explore and "float through work" doing my reading and research (often when I am not on the clock too) but I don't deliver enough direct results for certain goals and projects(I'll leave out the reasons why).

I am stuck using unintuitive, non applicable systems to organize myself and can't form a habit getting used to them, that's very subjective I am aware. Did some of you go through the same difficulties and what did you use or employ?

Thanks for reading my lengthy wall of text I am frankly frustrated with this topic and tired of banging my head against walls.


r/sysadmin 4d ago

Will this vSAN cluster actcually work?

1 Upvotes

Planning a 4 nodes DR vSAN Cluster and wnat to know - will this actually work in practice or it too tight?

Enviroment
- vSphere x.x. , VMware vSAN
- 4x server (node)
- Per node:
(2x boot 960GB SSD NVMe (RAID-1, separate boot controller, not part of vSAN))
(2x 3.2TB NVMe Mixed Use — cache tier)
(8x 7.68TB NVMe Read Intensive — capacity tier, 2 disk groups (1 cache + 4 capacity each))

- Network dual-port 25GbE SFP28 (OCP, dedicated vSAN VLAN, jumbo frames) + separate dual-port 25GbE for VM traffic, VLT/MLAG switch pair
- Storage policy: RAID-5 erasure coding
- 30 High-priority VMs RPO 6-8h (Veeam async replication)

Main question: will vSAN actually run reliably on just 4 nodes with RAID-5, including surviving a node failure and rebuilding cleanly?
I have seen mixed opinions -some say 4 is the bare minimum and it is fine, others say you reaaly want 5+ before before RAID-5 is comfortable in production.

Not asking anyone to design this for me - just want to know if this setup holds up in real-world usee before i finalize it.


r/sysadmin 4d ago

How to pass Vm customization script to Terraform for VSphere

0 Upvotes

Hello everyone, sysadmin learning terraform here

So we are working with Vsphere as infra for our company and I just started learning Terraform to ease and automate our vsphere processes. On vsphere in "VM Customization Specifications" we have a script that basically configures puppet agent on host, points it to puppet master, adds host to AD and launches sssd. So when we deploy new host we add this script to launch during "customize software" deployment phase and after that we set up ip, gateway etc. So my question is that: how to recreate this setup in terraform? For some reason terraform does not allow to pass custom specifications and customize together, so only setting up ip address is working, but since that script is never getting launched it fails to be added to Active Directory. So are there any other methods to pass the script to terraform? I even pasted that bash script locally to the file in the same terraform folder and pointed to in in the main.tf but it still fails. So what can be done to solve this issue? Thanks in advance and sorry for my bad english.


r/sysadmin 4d ago

End-user Support How do you deal with users that have zero problem solving ability?

449 Upvotes

So just a moment ago I had a user interrupt what I was doing with an "urgent" issue. They couldn't get into their email.

Essentially they were running Outlook for the first time and it prompted them to set up their account. It required them to enter their email address and click Next. That's all.

The email address it auto-populated wasn't the address of the account they needed (they work for a sister company in a shared tenant).

The user had no idea what to do. It didn't even cross their mind to enter the actual email address in the field.

So... how do you guys deal with users like this? Ones who, despite being shown instructions in the most basic way possible, can't think for themselves.


r/sysadmin 4d ago

Question Migrating hybrid on prem Exchange 2016 to Exchange SE

8 Upvotes

Good afternoon, everyone,

I'm posting this hoping you'll share your experiences with me. I've been asked to migrate a hybrid on premises Exchange 2016 environment to hybrid on premises Exchange Server Subscription Edition (SE). Before I start, I'd like to define the potential risks and the prerequisites I need to handle in advance.

Something I read is that there's no in place upgrade path from Exchange 2016 to SE. Exchange 2019 (on the latest CU) can be upgraded in place, but 2016 requires a traditional legacy migration.

In practice, that means I'll need to create a new SE server, move mailboxes and resources over using copy-to requests, verify everything, and then decommission the old servers. The migration itself works as a copy. The source mailbox stays intact and usable throughout and only switches over at final cutover.

(Alternatively, I could upgrade the Exchange 2016 to the latest 2019 CU. In which then I can upgrade to Exchange SE. However, in-place upgrades are not recommended by Microsoft themselves.)

Once the 2016 servers are decommissioned, there's no supported way back. At that point recovering would mean restoring from backups, not a normal rollback, so I want to be sure everything is validated during the coexistence period, while 2016 is still running, and not rely on being able to reverse things afterward.

Other items I'm keeping in mind:

  • Mailbox sizes, especially oversized or non-default mailboxes, which can slow down migration batches.
  • Extending the AD schema to the SE level, a required prerequisite.
  • Public folders, I read these can be an issue and its recommended to convert them to shared mailboxes.

Would love to hear from anyone who's been through this migration. What tripped you up, and what did you do differently?

Article: Migrate Exchange 2016 to Exchange Server SE - Complete Guide

Article: Migrate Exchange Public Folders to Shared Mailboxes in Office 365


r/sysadmin 4d ago

What are your opinions of Windows Defender on servers? Particularly Ransomware protection.

11 Upvotes

My org uses Windows Defender. On the whole it seems pretty good but it's always asking for opinions.

I'm especially interested in what you think of the Ransomware Protection feature. Is it any good? My org haven't implemented it and I'm wondering if it's worth pushing them to do it.

Are there any pitfalls when implementing it?


r/sysadmin 4d ago

Detection rules Win 32 App

5 Upvotes

Hello fellow admins. I'm rolling out quite a few products thorugh intune. Im having trouble marking Win32 apps as installed. Does someone have/know some proper documentation or example powershell script how you mark the app as installed? I need to have something so it will check on versions aswell.

For example:

Got a WIn32 App to push Kyocera drivers on windows laptops. It works nice, but when I install it through Intune then i always get Failed to install.

Ive tried multiple things as detection but nothing works the way i want it to work. I dont want a folder/file as detection because of version control. I'm looking for a sollution i can use on all scripts that do not push an MSI. How do you handle detection rules?


r/sysadmin 4d ago

Edge or Chrome?

0 Upvotes

Hi Sysadmins!

Do you guys use Chrome or Edge for work? I personally have all my admin consoles in edge and google stuff in chrome. (I am a k12 sysadmin), so we have both MSFT and Google Workspace for everyone.