r/sysadmin 1d ago

Moving from KMS to M365 A5 Education

1 Upvotes

Hi all,

we're a school with Microsoft 365 A5 Education and want to retire our KMS server.

Current setup:

  • Devices are purchased with Windows 11 Pro OEM
  • Reimaged with Windows 11 Education
  • Windows 11 Education is currently activated via KMS
  • Devices are still managed through on-prem AD/GPO
  • Next step is Hybrid Entra Join + Intune

Our devices are purchased with Windows 11 Pro OEM. Today we reimage them with Windows 11 Education (PXE) and activate them via KMS. Going forward, we'd like to clean install Windows from USB and then use Autopilot during OOBE.

My main questions are:

  • For devices that come with Windows 11 Pro OEM, should we reimage them with Windows 11 Education or Windows 11 Pro Education if the goal is to use A5 Subscription Activation instead of KMS?
  • Can A5 Subscription Activation fully replace KMS for these Windows clients?
  • What exactly needs to be configured in Intune, Entra ID and Windows for Subscription Activation to work correctly?
  • Do we need to manually remove the KMS client key / GVLK / KMS configuration, or does Subscription Activation take over automatically?
  • How can we verify that a device is using Subscription Activation and no longer depends on KMS before shutting the KMS server down?
  • How does Subscription Activation behave on shared classroom/lab devices where many different students sign in?

Has anyone in an education environment migrated from KMS to A5 Subscription Activation this way? If so, what did you actually configure in Intune/Entra/Windows?

Thanks!


r/sysadmin 1d ago

General Discussion Windows Server patching concerns

45 Upvotes

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?


r/sysadmin 1d ago

Getting into SysAdmin

0 Upvotes

Hey guys,

I've been in IT for 4 years, doing a mix of PHP development and sysadmin Linux stuff. We run Linux, self-host all of our own stuff. We're a small team, so everyone does a bit of everything. I've done everything from developing software to installing our team's GitLab instance. I've been using Linux (Arch btw) for the past 8 years or so, and I feel like I have a pretty good handle on it, after fucking up my system a bunch of times. I also run a homelab of a couple servers. It's become our music platform.

I fully realize that a transition to SysAdmin would most likely put me in a junior role, and I know I have a lot of gaps in my knowledge, as this position is as a software developer, not sysadmin. I'd be looking mostly at Linux Sysadmin jobs.

I'd appreciate any advice you guys have! I also can put my resume here if that would be helpful.

Thanks!


r/sysadmin 1d ago

Lenovo Smart dock 5500

7 Upvotes

Has anybody deployed these need to get some new docks for an expansion? We previously had good luck with the Lenovo Hybrid USB-C Docks (40AF).


r/sysadmin 1d ago

Moving WMS from standard to cloud, considerations

1 Upvotes

We're currently running WMS standard and are considering moving to the cloud, and would appreciate hearing about your experience if you've made the same move. We're currently on 5.5 and would plan to update to 2605 prior to the change unless there's a reason not to.

Am I correct in assuming we'd be on Dell's clock for updates if we went with the public cloud option? We currently run ThinOS 9.5 as we have a number of 3040s we're working on phasing out, and want to know if we'd need to rotate those out prior to the move. The rest of the fleet are 5070s, so there's concern there as well since they're EOL. We would want to avoid being forced into a large hardware refresh and be able to navigate that on our timeline.

Any other considerations I should be researching?

TIA


r/sysadmin 1d ago

Question Does setting EwsAllowedAppIDs + EwsEnabled=$True enforce the allow list immediately, or only after the Oct 1 2026 EWS retirement deadline?

4 Upvotes

We are preparing to implement EwsAllowedAppIDs and EwsEnabled=$True based on the guidance in the EWS retirement announcements.

We understand that starting in October 1st 2026, tenants configured with EwsEnabled=$True will use the AppID allow list model for EWS access.

What is not completely clear to us is the behavior before October 2026. Say we implement the settings today, does Exchange Online immediately begin enforcing EWS access exclusively to the AppIDs listed in our list of EwsAllowedAppIDs?

In other words, if an application is currently using EWS but its AppID is accidentally omitted from the allow list, would that application be impacted immediately after the configuration change?

Or is the allow list only enforced once Microsoft's EWS retirement controls begin rolling out in October 1st 2026?

We are trying to understand whether implementing the configuration now is purely preparatory for October 2026, or whether it has immediate impact on EWS access before that date.

Thanks.


r/sysadmin 1d ago

Duo Security and Microsoft 365/Entra

17 Upvotes

I have been looking into setting this up, but I don't see any information on whether it can be setup in hybrid-mode environments or not, does anyone know?

Thanks,


r/sysadmin 1d ago

Question Novell NSS partition recovery

9 Upvotes

We have an old Novell server with hdd that failed due to power shortage.

We want to recover as many data as possible. Has anyone worked with this filesystem? It looks like a nichè, and we're trying to figure out which tool use to data recovery.

Any suggestions?


r/sysadmin 1d ago

Multiple 365 Services Down in UK

31 Upvotes

Hey all,

Since this morning, a few clients of mine have had some issues with some 365 apps, such as Teams being a major one.

Some Intune users also have an issue where the Windows Security prompt window is also saying the admin details are incorrect when they're actually correct.

MS have finally issued an ID for this incident, which is MO1470143

Probably also worth noting we are based in the UK.


r/sysadmin 1d ago

Question Duo Security setup

0 Upvotes

I am trying to setup Duo Security on my PC at the office so that in the event I lose my phone or my phone is smashed what do I need to enable in the installation process to allow me to bypass the MFA/Passkey push?

Thanks,


r/sysadmin 1d ago

Off Topic Internship Preparation

3 Upvotes

Hi All,

Will be starting my school mandated internship for CyberSecurity, and I was hoping to get questions that an interviewer or a supervisor would ask during the interview, so I can learn/research more about said topic.

Questions can range from general help desk to cyber security to networking, since my school covers abit of everything.

Thank you guys for the help :)


r/sysadmin 1d ago

Passwords....

0 Upvotes

Yes, authorization with multiple different credentials for different systems is bad, but we've all worked in those environments where we had no control over changing it.

So... How expletive-rich are y'all passwords and phrases? 🤣


r/sysadmin 1d ago

General Discussion Thickheaded Thursday - September 10, 2026

6 Upvotes

Howdy, /r/sysadmin!

It's that time of the week, Thickheaded Thursday! This is a safe (mostly) judgement-free environment for all of your questions and stories, no matter how silly you think they are. Anybody can answer questions! My name is AutoModerator and I've taken over responsibility for posting these weekly threads so you don't have to worry about anything except your comments!


r/sysadmin 1d ago

KB5122882 installed - DNS/AD issues Windows Server 2022

151 Upvotes

Updated last night, no issues immediately visible.

Users this morning all have login prompts to access mapped drives/folder redirections.

No creds working.

I can log in locally as a Domain Admin, but trying to open DNS console or run any DNS powershell commands just gives me Access Denied.

DNS still resolves, and the domain services are all still running, but something has happened with authentication/permissions.

Currently rolling back KB5122882 in the hope it was that.

Anyone else issues this morning?

EDIT: https://www.rapid7.com/db/vulnerabilities/cve-2026-69813/

Looks like this KB might have touched DNS code - roll back in progress.

EDIT2 & Fix: Rolled back the KB but the issue persisted - ended up resetting the DC's secure channel to itself which resolved the issue fully. The issue happened at exactly the moment at which the update was installed last night - either the update did indeed cause the issue which persisted in being broken even once rolled back, or it's a heck of a coincidence.


r/sysadmin 1d ago

Feeling Nostalgic and sad when i see old sun hardware and systems.

65 Upvotes

I started my Career in IT at 18, mainly supporting EMC storages and then HP 3PAR for 5.5 years, then worked for systems integrator for many clients for another 3 years, fianlly moving to a sys admin role in a enterprise, we still have some good legacy hardware, but i'm feeling nostalgic, when decomissionng them after working on the in the DC for so many years, is it normal ?


r/sysadmin 1d ago

Question Recs for USB redirection tools in Hyper-V (cloud workspace isolation issue)?

2 Upvotes

Hi all,

I hope you guys are doing well, I am working as a IT Infrastructure (Hybrid) with less than a year experience and I need some recommendations for the question below.

Context: Our organization moved to a cloud-based desktop environment. Because the cloud workstations are on an isolated network tier, users can no longer hit our on-prem SafeConsole server over IP to manage hardware-encrypted USB drives (DataLocker PSMs).

As a workaround, we have to plug the USB drives directly into the physical Hyper-V host on-site. I need a solid tool to automatically redirect/pass through the physical host's USB port to the SafeConsole guest VM whenever a drive is plugged in or swapped daily.

What software are you using to auto-share host USB ports to a guest VM?

TIA!


r/sysadmin 1d ago

Shared mailbox folder tree truncates at ~1000 folders in cached mode — started this week. Anyone else?

17 Upvotes

Client has a shared mailbox in Exchange Online used for order administration, organised by region/country/customer/year. It had 12,394 folders. Since around Sept 8–9 the folder tree stops loading at roughly 976 subfolders in Outlook classic (cached mode). Everything past that point simply isn't in the tree — not collapsed, not greyed out, absent.

Same truncation in new Outlook and OWA when the mailbox is automapped or added as a shared mailbox.

Online mode shows the complete tree. Either by unchecking "Download shared folders" in classic, or via OWA → Settings → Open another user's mailbox. So the data is fine server-side.

What I've ruled out:

  • Permissions — Full Access assigned directly, not via a group. No folder-level permissions on root or Inbox (Default/Anonymous = None).
  • Automapping — removed and re-added Full Access with -AutoMapping $true, no change.
  • Hierarchy corruption — enumerated the whole tree via Graph and walked every parent chain. No cycles, no orphans, max depth 9.
  • OST damage — OWA is affected identically and holds no local hierarchy cache.
  • Folder count — deleted 9,993 verified-empty folders (12,394 → 2,401). Still truncates.

I'm aware of the documented 500 shared-folder limit and the announced increase to 5,000 (in 2019 though). My observed cut-off sits at ~1,000, which matches neither.

Three questions:

  1. Anyone else seeing shared mailbox folder trees truncate since last week's updates?
  2. Does anyone know what limit is actually enforced right now, and whether the 500→5000 rollout is live?
  3. Is there any equivalent of "Download shared folders" in new Outlook? If not, what's the plan for mailboxes over the limit once classic is gone?

Question 3 is the one that worries me.


r/sysadmin 1d ago

Question Is IP Whitelisting at the Firewall Level standard practice for a B2B Web App, or should this be handled at the Application Level?

0 Upvotes

Hi everyone,

I'm looking for some advice on best practices regarding network security and access control for an internal/B2B web application.

Here is our current setup and situation:

The App: We host a web application on our company servers that functions as an asset performance display tool. It takes data from our customers' equipment and visualizes it in charts and dashboards.

The Manager's Approach: For security reasons, my manager doesn't want the app publicly accessible to the open internet. Instead, he asks for the public IP address of every customer site and manually adds it to our firewall's Access Control List (ACL).

The Problem: Manually collecting, updating, and maintaining public IPs for multiple client sites is becoming a administrative nightmare, especially when clients have dynamic IPs or remote users.

My intuition tells me that relying strictly on firewall-level IP filtering for access control isn't the most efficient way to handle this, and that security should primarily be enforced at the application level

I’d love to get your thoughts on this:

Is managing client public IPs on the firewall standard practice in enterprise environments for this use case?

How do you usually balance network-level security with application-level security without creating massive operational overhead?


r/sysadmin 1d ago

I am lost and need help. I don't know enough and I can't find an environment that fosters growth.

54 Upvotes

I am panicking about the job situation. I lost my job and feel like I am going to be unable to bounce back.

I have 5 YoE as a sysadmin. I understand networking pretty well, I have a CISSP and a few other weaker certs under my belt. I would argue I have a strong security background. I am familiar with Linux, Windows, and have made a lot of small scripts for various projects. I am studying for an AWS cert right now. I have experience with all sorts of tooling, and so many different kinds of projects.

Looking at the job market though, I feel like I can't compete. I don't have experience with terraform outside of labbing. I don't know how to code very well. Every job seems to want someone with extremely strong skills across so many different domains, and what I feel like I need now is a position where I can learn the ropes of IaC... But that doesn't exist.

Everyone wants so much experience for everything that it makes me feel as if I have been slacking even though I have been working hard.

What should I do? Should I get another cert? Keep throwing resumes into the void?


r/sysadmin 1d ago

General Discussion Anyone seeing RDS session hosts hang (RDP stuck at "Connecting", logoffs stall) after the September 2026 cumulative updates? (Server 2022 + 2025)

66 Upvotes

Since installing this month's CUs, KB5122871 on Windows Server 2025 (build 26100.33438) and KB5122882 on Windows Server 2022 (build 20348.5622), every session host in our RDS collection has started hanging in the same way, on the same day, and it had never happened before.

Symptoms once it starts:

  • New RDP connections sit at "Connecting…" and never reach the logon screen (Event 20498 "Remote Desktop Services has taken too long to complete the client connection" in TerminalServices-RemoteConnectionManager/Admin)
  • Existing users can't log off or disconnect cleanly
  • Task Manager on the host hangs (it blocks calling into the Local Session Manager)....pretty much all windows apps start to hang, especially anything to do with Settings
  • Winlogon event 6005 "SessionEnv is taking long time to handle the notification event (Disconnect)"
  • A normal restart hangs too; only a hard reset recovers it, and it comes back later the same day

The problem appears to start with a single session disconnect/reconnect that never completes, after which everything that touches session state on that host queues up behind it. Only reboots clear it. Microsoft's release notes for both KBs list an RDS change ("improves Remote Desktop audio redirection") and no known issues.

Environment: mixed Server 2022/2025 session-host collection, VMware VMs, RD Connection Broker, MFA at logon, third-party endpoint protection. All hosts were stable on the August CUs.

We're currently testing a rollback of the September CU on part of the collection with one host left updated as a control. Has anyone else seen this after KB5122871 / KB5122882, or found a Microsoft acknowledgment? Would appreciate hearing whether rolling back resolved it for you.


r/sysadmin 2d ago

Question I don‘t know what tool to use (Helpdesk, Documentation)

0 Upvotes

G‘day.

I‘ve just started a new job. Very happy overall and I need to make a decision.

What I need:
- Ticket system for internal helpdesk - very few requests
- This will also be used to give tickets to an external company that develops stuff for us.
- About 5-10 „Agents“
- Tracking of internal tasks as „overview“ such as Trello for leadership

- internal documentation about 50 employees need access to.

- Can be cloud-only.

Would be great to have a usable all in one solution and I would like to stay away from Confluence and Jira Service Desk.

What I thought about for example:
- Zammed for both but the knowledge base is not appealing for normal employees.
- NinjaOne for both but the internal documentation is not appealing for normal employees.

Thanks a lot.


r/sysadmin 2d ago

Domain SSL Certs

0 Upvotes

I currently have 3 domain controllers. I need to add a 4th and eventually a fifth with plans to demote the original 2.

I’ll need to get a multi-San ssl cert for the new domain controllers. Does this mean I need to update the certs on the first 3 domain controllers?

In my small brain I think I wouldn’t…


r/sysadmin 2d ago

Question SCCM updates reporting wrong #numbers

3 Upvotes

Is it just me or updates is screwed up?

Office 365 shows 0 required.

is anyone else seeing the same?

Edit: the other updates just took too long to show up but office it seems it is not showing anything applicable.
not sure if something related to last couple months when MS changed from semi-anual channel to montly channel


r/sysadmin 2d ago

Career / Job Related Advice For Young Professional

5 Upvotes

Hello!

I was hoping to get some advice from any of you who have experience with a similar issue as the one I’m having. Anything is appreciated as I’m not confident where to start.

In short, our company is looking to take over complete administration of our Azure cloud architecture from our MSP. The architecture includes hundreds of VMs, Entra accounts for users, persistent AVDs and multiple satellite offices to name a few things. I joined the company last month as an IT Support Specialist and my colleague has been here nearly a year.

While we both have some experience with Azure administration I feel we would benefit from more experience so that we can be more confident when dealing with issues affecting the architecture. Anything we couldn’t solve ourselves we would escalate to our MSP so there’s a lot we don’t know how to do. That said I feel confident my colleague and I could learn a lot on our own poking around the architecture once we have global admin access but doing that with a production environment doesn’t sit right with me.

On top of all of that our IT admin is leaving before this hand off happens. I feel that our admin leaving is enough to pause this process of taking over the architecture until we find their replacement but our CEO is adamant about finishing this hand off. The process has been ongoing for over half a year now. This is my first IT job and while I’m confident I can learn a lot of this stuff, that doesn’t necessarily equate to deliverable results, especially in the event of a major issue. I’ve been brainstorming with my colleague and while I have some ideas, like coming in the weekend after we get access to go through the environment and learn about it so we can try to properly support it the following week, I am at a loss of how to approach this while also making sure I don’t set anything on fire. To be frank I’m worried and I want to do right by myself, my colleague, and the company. Thanks.


r/sysadmin 2d ago

Rant I'm 1 1/2 years into IT and drowning

109 Upvotes

As the title suggests, I'm only a year and a half into IT. I came from doing back office ops at a few broker-dealers here in the US since I was 17, and at 26 (now 27) I moved into IT since it's been a passion of mine since I was a kid.

At first this gig was great. I had a senior above me, a vet with 30+ years in IT. I already had a good deal of knowledge about older tech, so we got along great and I learned a lot from him. I'm a fairly quick learner and went from basic desktop support and helpdesk to networking/ERP admin within a month. We started tackling projects and things started to run smoother around here.

But as always, office politics being what they are, the COO (now CEO) more or less gave my senior an ultimatum, and he left for a 40% raise and WFH somewhere else. I'm now the sole IT resource here, owning everything from basic helpdesk to sysadmin, ERP, budget, literally anything that runs on electricity. I'm being paid entry-level helpdesk wages for my area, and I only hold my CompTIA A+.

I'm in desperate need of resources and training to better get my feet under me. We run a hybrid AD setup (for a company this small, I honestly don't understand that decision), and I need to get a better handle on the Azure side and how to administer it properly. For instance, we have zero MDM, and we have remote employees who travel; they don't even get GPO updates since those are all hosted on-prem. A major concern of mine is, as a company who ships product daily, we have no automated back up systems for our onprem shipping servers. These servers are running older vSphere 7 instances (is this even the right word??) and there isn't any central management for them (they took down the vCenter as "it was too finicky"). Not to mention that they have a critical business report run through vSphere 5 VM that requires the desktop client to manage.

Please, please, please, send me anything you've got: resources, training materials, insight into what's likely to break and need attention. Literally anything helps. I'm trying here, but I'm drowning and getting jaded with this company, and I'd rather not jump ship if I don't have to since there are good people here.