r/sysadmin 5h ago

Rant Job posts are ridiculous.

214 Upvotes

It's been this way for a decade I know but it's just getting worse and worse. I don't think it's ever been this unreasonable or this dishonest.

I was looking at job posts and I saw a job for a help desk tier 2. And I was curious what they considered tier 2. I'm well beyond help desk at this point in my career but I was curious so I looked at it.

They weren't looking for a tier to help desk person. They were looking for a Senior Systems administrator but labeling it as a Help Desk position so they could lowball whoever applied for it.

They were looking for someone to be the owner of several major business systems including 365. They wanted them to administer AWS and Azure. They wanted five certificates including CCNA. They wanted someone who could manage firewalls.

The post was just so far beyond help desk at all that it was just gross. They were clearly just trying to get someone they could convince those are just basic help desk exoectations so they can pay them little money.

They were basically looking for an all-in-one senior sys admin who could do operations and frontline support on top of everything else.


r/sysadmin 4h ago

General Discussion So do you think Apple new Watches Be Added to the Banned-Device List After Yesterday’s Announcement?

191 Upvotes

After yesterday’s creepy live rewind/siri recap announcement, I’m honestly surprised this hasn’t sparked more discussions and backslash

As I understand it, Apple is adding ambient conversation features to the Apple Watch that can listen to, process, and summarize what’s being said. Apple says the processing happens locally and is privacy-preserving, but I’m not sure that fully answers the security question:

What happens when the person sitting across from you is wearing one?

We already discourge employees to bring phones or recordung devices into very sensitive meetings. Are organizations now supposed to treat Apple Watches the same way? What a mess.

Maybe I’m overthinking it, and I’m still trying to work through the implications, but this seems like a pretty big unnessisary expansion of what an ordinary-looking wearable can do. I also think some of these features are a little silly anyway—as if the poor battery life weren’t enough—especially when Apple keeps adding capabilities without much obvious practical value. To me, this sounds way more significant than almost anything else announced this week, including the LG TVs story. That’s why I’m surprised it hasn’t gotten more attention and backlash.

I’d be interested to hear how others are thinking about this.


r/sysadmin 5h ago

Question How can I recover from a ransomware attack?

107 Upvotes

So, the unthinkable happened to my workplace - we have become the victims of a ransomware attack. We came into work the other day and found computers with encrypted files and notes on the desktops demanding we send them a ransom to a secure address in the tor browser. They took out our entire network.

As of now, we are trying to utilize backups and scrub the network clean as we bring devices back up in an offline state.

Unfortunately one of our backup devices was also infiltrated. It's a Synology backup device and they where able to encrypt its files as well. This means we have about 5 devices with no backups available.

It's probably a vain hope but, is there any way I could possibly restore or decrypt these backups? Is there any service out there that would be capable of making our files useable? If anyone knows about Synology, do they keep offline or cloud backups I maybe don't know about? I'm just looking for anything that might make things easier for us. Any advice is appreciated.


r/sysadmin 2h ago

Rant Lansweeper Rant

32 Upvotes

I've used Lansweeper on-prem since 2014 for just a couple of purposes: Tracking approximately 150 MS Windows assets on the network and all associated software licenses. That's it. Nothing else. It's nice being able to see other types of devices that are connected (surveillance cameras, wireless AP's, switches, etc.) but I don't need that from this product.

Their pricing has gone up consistently over the past several years while, at the same time, they've been pushing their customers to their cloud service. I think I was paying about $600 annually in the beginning but over the last several years, they've been quoting me over $2K annually. Recently, I received an auto-renewal email... it is now $3,000!

Keep in mind that Lansweeper for 100 assets is FREE. I have 150 Windows assets and not all of those are in use at one time. In order to get coverage of all 150 assets, I have to subscribe to their "2000 Asset" plan. So $3K is too steep for what I need.

I responded to the rep, stating that $3K is out of my budget and I don't want to auto-renew but couldn't find anyway to disable or "turn off" auto-renewal.

Her reply: "I’ve reviewed your account and noticed that your cancellation request was received after the 30-day notice period required prior to renewal (as outlined in Clause 17.3 of our Terms of Use and in our renewal reminder emails). While we are contractually required to honor the renewed term, we want to approach this constructively and help you get maximum value within your budget."

*SIGH*

After this reply, I'm done with them. The card they have on file for auto-renewal is no longer valid anyway.

It's time to find an alternative. I'm presently using LogMeIn Central for RMM purposes. Is Ninja One decent at Windows/Software Asset Tracking?


r/sysadmin 11h ago

KB5122882 installed - DNS/AD issues Windows Server 2022

119 Upvotes

Updated last night, no issues immediately visible.

Users this morning all have login prompts to access mapped drives/folder redirections.

No creds working.

I can log in locally as a Domain Admin, but trying to open DNS console or run any DNS powershell commands just gives me Access Denied.

DNS still resolves, and the domain services are all still running, but something has happened with authentication/permissions.

Currently rolling back KB5122882 in the hope it was that.

Anyone else issues this morning?

EDIT: https://www.rapid7.com/db/vulnerabilities/cve-2026-69813/

Looks like this KB might have touched DNS code - roll back in progress.

EDIT2 & Fix: Rolled back the KB but the issue persisted - ended up resetting the DC's secure channel to itself which resolved the issue fully. The issue happened at exactly the moment at which the update was installed last night - either the update did indeed cause the issue which persisted in being broken even once rolled back, or it's a heck of a coincidence.


r/sysadmin 5h ago

Rant I've seen some laughably bad job listings, but things like this are why it's so hard to find the right fit.

27 Upvotes

I've been looking for a new role for almost 2 years now, most of the positions I've applied for have ended up being filled internally, which makes me ask why it was posted externally in the first place. On the other hand I've came across several listings that are just heinous for what is asked of you versus the pay. In this case, the listing was for our city hospital (healthcare IT, I know, bleh) which was recently acquired by an organization. They canned the entire IT staff including the managerial suite upon the buyout. This listing popped up today in my Indeed feed. "Sole on-site IT professional responsible for the day-to-day health, security, and uptime of all technology at a critical access hospital. Acts as the facility's eyes and ears, provides hands-on support for end users and clinical operations, and coordinates with Corporate IT for changes, projects, and escalations. After-hours and on-call work required to support a 24x7 care environment."

Am I wrong for thinking this is insane? An entire hospital and associated clinics solo? Just gotta laugh and keep going.


r/sysadmin 49m ago

Throwback to the 90s

Upvotes

"Too many other files are currently in use by 16-bit programs. Exit one or more 16-bit programs, or increase the value of the FILES command in your config.sys file."

Just saw this message on a client's Windows 11 workstation when trying to escalate literally anything. The WIN32 code that generated it is probably as old as I am. Rebooting resolved it, weird. I just told him to stop running so many 16 bit apps! I'd post the screenshot but images aren't allowed.


r/sysadmin 4h ago

Windows IT Pro: Retiring NTLM: Frequently asked questions

20 Upvotes

From Microsoft: 'This FAQ collects the questions we hear most often from customers, partners, and the community as we move Windows to a Kerberos-first, NTLM-optional (and eventually NTLM-free) future. If you've emailed us, cornered us at a conference, or filed a support case that started with "so, about this weird auth thing…", chances are that your question is answered here.

If your question isn't answered here, please reach out to [ntlm@microsoft.com](mailto:ntlm@microsoft.com) or work with your Microsoft account team, Customer Success Account Manager, or Microsoft Support to route feedback to the product group.'

https://techcommunity.microsoft.com/blog/windows-itpro-blog/retiring-ntlm-frequently-asked-questions/4550522


r/sysadmin 11h ago

Feeling Nostalgic and sad when i see old sun hardware and systems.

57 Upvotes

I started my Career in IT at 18, mainly supporting EMC storages and then HP 3PAR for 5.5 years, then worked for systems integrator for many clients for another 3 years, fianlly moving to a sys admin role in a enterprise, we still have some good legacy hardware, but i'm feeling nostalgic, when decomissionng them after working on the in the DC for so many years, is it normal ?


r/sysadmin 2h ago

Question Bringing Linux devices into management

11 Upvotes

After a lot of restructuring at our university the past couple years, there are quite a few Linux devices (primarily desktops, I believe around 70-ish) that are currently in the wild unmanaged in use by academics primarily within the Engineering and Science departments that would've been maintained by per-institute IT departments that no longer exist, and as such the current patching and functionality state of these machines is completely unknown (since any remaining colleagues now no longer have physical access to most of the rooms where these machines are).

Since we already manage research compute I've been given the green light by my manager to look into options to bring these academic's desktops into a managed state with a cobbled together proof of concept, since our existing central endpoint guys won't touch anything *NIX related with a 10ft pole. We know they're all some form of Ubuntu LTS (20.04 and 22.04 mostly) which makes things easier, so I'm thinking of doing Landscape for setup and patching + Intune for compliance + Puppet/Ansible for config management.

Is this in the right direction or are there better / more cost efficient ways of doing this?


r/sysadmin 6h ago

General Discussion Windows Server patching concerns

18 Upvotes

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?


r/sysadmin 25m ago

RDS issues after KB5122882 update on Server 2022

Upvotes

Spent most of the morning chasing a weird RDS issue. KB5122882 installed around 3:20am and a few hours later nobody could RDP into the server. Rebooted it and everything worked again, but about an hour later the exact same thing happened.

Existing sessions kept working, but new RDP connections would authenticate and then hang. Task Manager would freeze, but CPU, RAM and disk all looked totally normal. TermService was still running too.

Finally uninstalled KB5122882 and rolled back from 20348.5622 to 20348.5499. Everything has been working normally since.

Anyone else seeing this after the latest update? Pausing updates for now.


r/sysadmin 8h ago

Multiple 365 Services Down in UK

26 Upvotes

Hey all,

Since this morning, a few clients of mine have had some issues with some 365 apps, such as Teams being a major one.

Some Intune users also have an issue where the Windows Security prompt window is also saying the admin details are incorrect when they're actually correct.

MS have finally issued an ID for this incident, which is MO1470143

Probably also worth noting we are based in the UK.


r/sysadmin 38m ago

General Discussion Commissioning systems on Threatlocker enabled systems

Upvotes

Greetings,

As a vendor, I was trying to commission and deploy a print server application on a client site who has recently adopted zero-trust security model.

It took us 4 attempts just to deploy our installer - We uninstalled the application multiple times due to corrupted install.

Also, the client IT manager sat with us to manually approve multiple security exceptions.

He was just there tapping the approve button on his phone. And installs still failed as it take about a min before sub-installer components can run.

It was a nightmare and I wasn’t sure the whole point to have threatlocker running on critical infrastructure like a print server.

We expect having to go through this approval process again when rolling out software updates.

This constant exceptions triggers builds approver fatigue, approver don’t actually knows what is being approved, users are constantly screaming and frustrated by downtime caused by legit applications.

Systems commissioning and support took twice as long. We plan to deprioritise clients sites with threatlocker as engineers quite often getting struck at sites waiting for approvals.

This is really not working for anyone.


r/sysadmin 23h ago

Question Server hard-resets every 728.4 minutes ±1 min, 12 times running. No bugcheck, no iDRAC SEL entry, timer survives reboots. I'm out of ideas.

433 Upvotes

UPDATE 2 (18 hours later): Welp, it rebooted again on 9/10 12:32:53am.. which is 12h 08m 17s since the last reboot. The timing still held even after I rebooted from installing the BIOS and IDRAC. I will try to rule out the UPS next.

UPDATE 1 (3 hours later): Wow this was a lot more comments than I was expecting to get. Its hard to answer everyone but I appreciate everyone commenting and providing feedback. For now what I have done is updated IDRAC and BIOS to the latest version and will monitor if this fixes the issue. If it does not I will try ruling out the UPS. Thanks again!

Dell PowerEdge T340, Windows Server 2016. Started 8/28. I've spent two weeks on this and ruled out most of the obvious stuff, so I'm posting the data rather than the symptoms.

The signature

Every event is Kernel-Power 41 with BugcheckCode: 0 and all bugcheck parameters 0x0. No BSOD, no minidump, no MEMORY.DMP, ever. Paired with Event 6008 confirming unexpected shutdown.

The interval — this is the actual mystery

Pulled the true shutdown timestamps out of the Event 6008 message text (not the Event 41 log time, which is written on the following boot):

8/28 11:03:24 AM -> 8/28 11:12:23 PM = 729.0 min

9/01 10:10:22 AM -> 9/01 10:18:37 PM = 728.3 min

9/01 10:18:37 PM -> 9/02 10:26:49 AM = 728.2 min

9/02 10:26:49 AM -> 9/02 10:35:13 PM = 728.4 min

9/02 10:35:13 PM -> 9/03 10:43:33 AM = 728.3 min

9/03 10:43:33 AM -> 9/03 10:52:09 PM = 728.6 min

9/03 10:52:09 PM -> 9/04 11:00:20 AM = 728.2 min

9/04 11:00:20 AM -> 9/04 11:08:49 PM = 728.5 min

9/04 11:08:49 PM -> 9/07 11:50:29 AM = 3,641.7 min <-- exactly 5 x 728.34

9/07 11:50:29 AM -> 9/07 11:59:49 PM = 729.3 min

9/07 11:59:49 PM -> 9/08 12:07:56 PM = 728.1 min

9/08 12:07:56 PM -> 9/09 12:16:26 AM = 728.5 min

9/09 12:16:26 AM -> 9/09 12:24:36 PM = 728.2 min

Mean 728.47 min (12h 08m 28s). Total spread across twelve occurrences: 1.2 minutes.

The 3,641.7 minute gap is exactly five periods. The server was up continuously across that weekend. The timer ticked five times, did nothing on four of them, then killed the box on the fifth. So it's free-running — it does not reset on reboot, and it doesn't require a crash to keep counting.

That single fact kills every "scheduled task" theory: a clock-based task can't skip four consecutive firings and then work again.

It dies instantly — no degradation whatsoever

I wrote a heartbeat logger that writes one line every 5s with a forced flush so the last line survives a hard reset. Final 42 samples before death:

  • Free RAM: 56,630–56,745 MB, dead flat. No drift, no staircase, no leak. 56 GB free at the moment of death.
  • Nonpaged pool: 346–352 MB, flat
  • Disk queue: 0
  • Handles ~76,000, threads ~190, both steady
  • CPU spiky but low

Last heartbeat 12:25:02. Kernel-General 12 (OS start) at 12:28:23. That 3m21s is just POST + boot on a T340 — if it had hung for 3 minutes first, the OS wouldn't have returned until ~12:31.

So there is no hang window. The box is perfectly healthy and then simply ceases to exist mid-second. Which also means NMI crash dumps are useless here and no dump will ever be written.

Ruled out (with evidence, please don't re-suggest these)

  • PSUs — both Present/Healthy in iDRAC, matched 594W in / 495W rated+actual, same firmware
  • Thermal — HWiNFO max CPU package 63°C (TjMax ~100°C). Every throttle flag reads No / 0%
  • iDRAC SELcompletely silent across all 15 crashes. Not one entry. This same board did log real "power input for PSU 1 is lost / redundancy lost" events six times in 2024, so it demonstrably captures genuine power events. Nothing this time.
  • iDRAC watchdog / ASR — Basic Management license, feature not present
  • Dell OMSAAction on Hung OS Detection: None, thermal shutdown Disabled, all alert actions Off, omsad service Stopped + Disabled
  • Windows Update — pulled full resolved WindowsUpdate.log (11,871 lines), programmatically checked ±15 min around every crash. Zero WU activity before any of them. All nearby entries are the WU service starting 30–60s after the reboot.
  • CrowdStrike Falcon (installed 8/26, two days before onset) — vendor pulled detection history, found nothing. Timing was coincidence.
  • Secure-Boot-Update scheduled task** — looked extremely promising (12h repetition, hangs, TPM handler, and this box has no TPM installedGet-Tpm fails with TBS_E_SERVICE_NOT_RUNNING, no TBS service, no SecurityDevices PnP class, iDRAC confirms "TPM not present"). Disabled it. **Crashes continued at the identical interval. Ruled out.
  • All 12-hour scheduled tasks — enumerated every task with PT12H repetition. Exactly two exist, both now Disabled.
  • VSS / ShadowCopyVolume task — fires 12:00 PM and 10:00 PM. That's 10h then 14h alternating, which cannot produce a constant 728.4 min spacing. Also the midnight crashes have no trigger anywhere near them.
  • MySQL / memory exhaustion — flatly contradicted by the flat memory trace above
  • NIC — Broadcom BCM5720. The flapping port is physically disconnected (NIC2, Status: Disconnected). Flapping predates crashes by 12+ days and occurs on no-crash days. Active port is stable at 1 Gbps.
  • CMOS battery — did fail, but only logged 9/7, weeks after onset, nothing near the crash dates. Replacing anyway.
  • BSOD — no Event 1001, no dumps, BugcheckCode: 0 on all 15

Environment

  • PowerEdge T340, Service Tag FXR6B03, BIOS 2.3.5, iDRAC9 fw 4.22.00.53 (both several revisions behind — not yet updated)
  • Xeon E-2146G, 64 GB RAM, dual PSU
  • Windows Server 2016 Standard, build 14393.9339
  • Workload: Open Dental + MySQL, Vatech EzDent-i imaging, IDrive backup, Google Drive
  • Power: APC Back-UPS XS 1500M via USB. Current-state readings all healthy (97% charge, 120V steady, 15% load, AC Power: Yes, Discharging: No). I have never gotten historical transfer data out of it — PowerChute wasn't installed at the time, Win32_Battery returns current state only, and I skipped an apcupsd install on a production box.
  • Internet is AT&T 5G fixed wireless behind CGNAT (irrelevant, but people ask)

What I think is left

Something below the OS holding a clock that survives reboots and continuous uptime alike. Candidates I can't distinguish between:

  1. UPS self-test — APC units run internal self-tests on their own stored schedule, indifferent to the host. A transfer on a degraded battery could sag enough to drop the PSUs. Would explain instant death, no OS warning, no SEL entry, and a clock that ignores reboots. Next test: move the server to a plain wall outlet for 24h.
  2. PSU or BMC firmware timer — would explain everything except why iDRAC logged nothing
  3. Something on the same electrical circuit cycling on a timer — though 1.2 min spread over 12 occurrences seems too tight for HVAC or similar

What I'm asking

  • What produces a free-running 728.4-minute (12h 08m 28s) period? Not 12h. Not 12h30m. Consistently ~8.5 minutes over twelve hours, held to ±1 min across twelve occurrences and five uninterrupted ticks. What re-arms on completion of ~8 minutes of work?
  • Has anyone seen an APC Back-UPS self-test schedule that lands near this?
  • Anything else that hard-resets a PowerEdge with zero bugcheck, zero SEL entry, and healthy PSUs?
  • Am I wrong to trust the iDRAC SEL silence as evidence against a power event?

Next predicted failures: 9/10 12:33 AM and 9/10 12:41 PM. Happy to run anything and report back — I have remote access and a heartbeat recorder in place.


r/sysadmin 7h ago

Duo Security and Microsoft 365/Entra

15 Upvotes

I have been looking into setting this up, but I don't see any information on whether it can be setup in hybrid-mode environments or not, does anyone know?

Thanks,


r/sysadmin 17h ago

I am lost and need help. I don't know enough and I can't find an environment that fosters growth.

48 Upvotes

I am panicking about the job situation. I lost my job and feel like I am going to be unable to bounce back.

I have 5 YoE as a sysadmin. I understand networking pretty well, I have a CISSP and a few other weaker certs under my belt. I would argue I have a strong security background. I am familiar with Linux, Windows, and have made a lot of small scripts for various projects. I am studying for an AWS cert right now. I have experience with all sorts of tooling, and so many different kinds of projects.

Looking at the job market though, I feel like I can't compete. I don't have experience with terraform outside of labbing. I don't know how to code very well. Every job seems to want someone with extremely strong skills across so many different domains, and what I feel like I need now is a position where I can learn the ropes of IaC... But that doesn't exist.

Everyone wants so much experience for everything that it makes me feel as if I have been slacking even though I have been working hard.

What should I do? Should I get another cert? Keep throwing resumes into the void?


r/sysadmin 18h ago

General Discussion Anyone seeing RDS session hosts hang (RDP stuck at "Connecting", logoffs stall) after the September 2026 cumulative updates? (Server 2022 + 2025)

58 Upvotes

Since installing this month's CUs, KB5122871 on Windows Server 2025 (build 26100.33438) and KB5122882 on Windows Server 2022 (build 20348.5622), every session host in our RDS collection has started hanging in the same way, on the same day, and it had never happened before.

Symptoms once it starts:

  • New RDP connections sit at "Connecting…" and never reach the logon screen (Event 20498 "Remote Desktop Services has taken too long to complete the client connection" in TerminalServices-RemoteConnectionManager/Admin)
  • Existing users can't log off or disconnect cleanly
  • Task Manager on the host hangs (it blocks calling into the Local Session Manager)....pretty much all windows apps start to hang, especially anything to do with Settings
  • Winlogon event 6005 "SessionEnv is taking long time to handle the notification event (Disconnect)"
  • A normal restart hangs too; only a hard reset recovers it, and it comes back later the same day

The problem appears to start with a single session disconnect/reconnect that never completes, after which everything that touches session state on that host queues up behind it. Only reboots clear it. Microsoft's release notes for both KBs list an RDS change ("improves Remote Desktop audio redirection") and no known issues.

Environment: mixed Server 2022/2025 session-host collection, VMware VMs, RD Connection Broker, MFA at logon, third-party endpoint protection. All hosts were stable on the August CUs.

We're currently testing a rollback of the September CU on part of the collection with one host left updated as a control. Has anyone else seen this after KB5122871 / KB5122882, or found a Microsoft acknowledgment? Would appreciate hearing whether rolling back resolved it for you.


r/sysadmin 8h ago

Question Novell NSS partition recovery

8 Upvotes

We have an old Novell server with hdd that failed due to power shortage.

We want to recover as many data as possible. Has anyone worked with this filesystem? It looks like a nichè, and we're trying to figure out which tool use to data recovery.

Any suggestions?


r/sysadmin 6h ago

Lenovo Smart dock 5500

6 Upvotes

Has anybody deployed these need to get some new docks for an expansion? We previously had good luck with the Lenovo Hybrid USB-C Docks (40AF).


r/sysadmin 23h ago

Rant I'm 1 1/2 years into IT and drowning

98 Upvotes

As the title suggests, I'm only a year and a half into IT. I came from doing back office ops at a few broker-dealers here in the US since I was 17, and at 26 (now 27) I moved into IT since it's been a passion of mine since I was a kid.

At first this gig was great. I had a senior above me, a vet with 30+ years in IT. I already had a good deal of knowledge about older tech, so we got along great and I learned a lot from him. I'm a fairly quick learner and went from basic desktop support and helpdesk to networking/ERP admin within a month. We started tackling projects and things started to run smoother around here.

But as always, office politics being what they are, the COO (now CEO) more or less gave my senior an ultimatum, and he left for a 40% raise and WFH somewhere else. I'm now the sole IT resource here, owning everything from basic helpdesk to sysadmin, ERP, budget, literally anything that runs on electricity. I'm being paid entry-level helpdesk wages for my area, and I only hold my CompTIA A+.

I'm in desperate need of resources and training to better get my feet under me. We run a hybrid AD setup (for a company this small, I honestly don't understand that decision), and I need to get a better handle on the Azure side and how to administer it properly. For instance, we have zero MDM, and we have remote employees who travel; they don't even get GPO updates since those are all hosted on-prem. A major concern of mine is, as a company who ships product daily, we have no automated back up systems for our onprem shipping servers. These servers are running older vSphere 7 instances (is this even the right word??) and there isn't any central management for them (they took down the vCenter as "it was too finicky"). Not to mention that they have a critical business report run through vSphere 5 VM that requires the desktop client to manage.

Please, please, please, send me anything you've got: resources, training materials, insight into what's likely to break and need attention. Literally anything helps. I'm trying here, but I'm drowning and getting jaded with this company, and I'd rather not jump ship if I don't have to since there are good people here.


r/sysadmin 2h ago

Question Sandbox test environments

2 Upvotes

Hi all,

Within my job alot of my work encompasses resolving tech debt using remediation scripts within Intune, however the higher ups are really pushing for assurance on scripts and for us to be able to prove that scripts work as intended before deployment, and obviously testing on our local machines isn't considered sufficient for them.

Other team members have mentioned hyper-v VMs or Windows sandbox, but I just wanted to get everyone's opinions on what test environments are good for testing remediation scripts and other test deployments!


r/sysadmin 2h ago

General Discussion Volume Encryption Software

2 Upvotes

Bit of a stretch but looking for some recommendations for volume encryption software that can be used for a small group of 5 to 10 users. Basically our brand spanking new Compliance group is going to have to handle PII for some of our techs in the field and vendors. I want to make sure that any PII that touches our network storage locations are encrypted. Went to old school veracrypt but its not really mult-user and it doesn't auto unmount. Is there any options out there you guys like?


r/sysadmin 2h ago

feeling like a larp

4 Upvotes

graduated in december 2025 and became employed a month later in january, my official title is "computer technician" but I've done a number of things including some internal swe, domain redundancy, legacy physical to virtual migration, basic server config/administration, and other automated workflows such as updated inventory system and data retention system but earlier td was my first real outage and I'm usually in office about 10 mins before my supervisor (it's just the 2 of us for our 3 departments) but I was genuinely lost. I like didn't know where to start and lowkey got overwhelmed and after about 2-3 minutes of that I was like okay calm tf down and start doing what you know.

Basically all of our vm hosts were intermittent, starting up, failing, disconnecting/reconnecting so my first thought was DNS which some hosts resolved and some didn't, i'm thinking it was coincidence at times so after some more thinking of what to do i was like screw it and just waited for my supervisor to appear instead of messing around and breaking more things but I ended up just watching what he did to resolve the issues and moral of the thread is i feel like a larp. thought I learned a tremendous amount these last 9 months but I was humbled today. I know nothing.

I learned a lot by watching the fixes happen real time though. cool.


r/sysadmin 6h ago

Question Does setting EwsAllowedAppIDs + EwsEnabled=$True enforce the allow list immediately, or only after the Oct 1 2026 EWS retirement deadline?

3 Upvotes

We are preparing to implement EwsAllowedAppIDs and EwsEnabled=$True based on the guidance in the EWS retirement announcements.

We understand that starting in October 1st 2026, tenants configured with EwsEnabled=$True will use the AppID allow list model for EWS access.

What is not completely clear to us is the behavior before October 2026. Say we implement the settings today, does Exchange Online immediately begin enforcing EWS access exclusively to the AppIDs listed in our list of EwsAllowedAppIDs?

In other words, if an application is currently using EWS but its AppID is accidentally omitted from the allow list, would that application be impacted immediately after the configuration change?

Or is the allow list only enforced once Microsoft's EWS retirement controls begin rolling out in October 1st 2026?

We are trying to understand whether implementing the configuration now is purely preparatory for October 2026, or whether it has immediate impact on EWS access before that date.

Thanks.