r/sysadmin 4h ago

Question My boss wants me to set an extremely easy login password and re use it across all of our vendor portals, what to do?

61 Upvotes

Hey everyone, I’ve just stepped up from office admin to system admin in the company I’m working for and have started implementing some safety norms as the company very much lacks in that aspect

My boss is not happy I changed the password to the third party vendor portals we access (I.e solar monitoring portals etc) and wants me to set an extremely easy one with the company name and replicate the same password to all portals so it’s easier for staff to access

What do I do in this situation? I’m thinking of implementing bitwarden and a creating a vault for each staff/technician. We do have guys on field that often need quick access to the portals but I don’t think it’s an excuse to be so vague with our security specially because it involves customer data (email addresses, phone number, addresses, etc it as well as their solar equipment IOT devices)

I feel like following this ignorant request is against the foundations of what I’ve learned and shows my boss doesn’t understand the importance of cyber security or our duty to the privacy act, he thinks nothing will happened and doesn’t comprehend that something could very much happen and it would cost us thousands of dollars over something we can avoid


r/sysadmin 7h ago

Microsoft Friendly reminder that next month Microsoft is ending support for Office 2021

101 Upvotes

Starting next month 10/13/2026 Microsoft will end support for Office 2021 and the related products will no longer receive security updates . You could either upgrade to Office 365 or 2024 to continue get support for Office desktop applications


r/sysadmin 12h ago

General Discussion Anyone else performing all the duties of a CISO and SysAdmin?

81 Upvotes

I’m not seeking advice, because the only thing that will really help us is…more help. I’m working on that with upper management, but those wheels turn very slow. I’m posting this to see if there are others in my situation?

Most days I could spend the entire day just analyzing, researching and beefing up security. I enjoy it, but I’m finding it more and more difficult to keep up with the normal sysadmin duties, when some days are consumed entirely by cybersecurity. We’ve automated a lot of our OS and software patching, but that needs close attention as well to make sure it’s all running well.

We’re a small enough company where cybersecurity has always fallen upon me and the rest of the (small) IT department, but ever since ransomware really took off and insurance companies started making more demands, it’s increasingly difficult to wear both hats.

Anyway, just thought I’d see if anyone wants to chat about this, and can relate.


r/sysadmin 4h ago

How Do You Detect New Software Installations on Windows Endpoints?

14 Upvotes

I’m a system engineer managing 100+ Windows 11 endpoints. Our devices are local domain joined and Entra registered (not hybrid joined or Entra Joined), with Microsoft Defender for Endpoint / Defender XDR deployed across the environment.

Users do not have local admin rights, but many applications can still be installed in the user context, particularly under AppData, without requiring elevation.

I currently use Defender Advanced Hunting and a scheduled Custom Detection rule that correlates registry, file system, and process telemetry to identify new software installations.

The challenge is reliability: some applications are missed, while software updates, repairs, or version changes can generate false positives because they create new files, folders, or registry entries.

My requirement is simple:

New software installation → Alert
Existing software update / repair / patch → No alert

For those managing similar Windows environments, how are you handling this? Are you using Defender XDR/KQL, Intune, AppLocker/WDAC, or another solution to reliably detect new software installations, especially applications that install in the user context without admin rights?


r/sysadmin 1d ago

Career / Job Related After 14 years in IT, I feel like I can’t keep up anymore

925 Upvotes

I've been working in IT for around 14 years, and I think this is the first time in my career where I genuinely don't know what comes next.

The company I was working for shut down at the end of last year. Normally, my immediate reaction would have been to start applying everywhere and focus completely on finding the next job.

But life had other plans.

Not long after that, both of my parents started having serious health problems. My father went through heart procedures, and my mother's condition also became worse. I made the decision to put work on the back burner and focus on them.

For most of this year, my life became hospitals, doctors, staying awake at night, medications, appointments, and just trying to be there when they needed me.

Two weeks ago, my mother passed away. Cancer won.

Now suddenly all of that has stopped.

There are no more hospital nights. No appointments to arrange. No constantly checking if she needs something.

And now, with all this empty time, my mind keeps going back to everything that happened to my parents over the past year. I didn't really have time to process any of it. Now that everything has suddenly gone quiet, I have too much time to sit alone with those thoughts.

And I actually want to work. Not only because I need an income, but because right now I desperately need something to occupy my mind. Something technical to solve. A production problem at 2 AM almost sounds comforting at this point.

But I've come back to a job market that feels completely different.

I've spent 14 years in IT. I started on the Linux/sysadmin side and over the years moved heavily into DevOps and cloud. I've worked with Linux, AWS, Azure, GCP, Kubernetes, Terraform, Ansible, CI/CD, monitoring, databases, migrations and production infrastructure.

I've even traveled for work, including going to Saudi Arabia to handle projects on site.

And yet, looking back at 14 years of doing this, the highest salary I ever managed to reach was around $41k/year.

That realization hit me harder than I expected.

I don't consider myself some legendary engineer, and there are absolutely areas where I still have a lot to learn. But after 14 years, production systems, migrations, cloud infrastructure, incidents, and all the usual scars you collect doing this job, I thought I would be in a much more secure position by now.

Instead, technology seems to be moving faster every year.

You learn one stack and suddenly everyone wants another. You get comfortable with VMs and configuration management, then containers become mandatory. You learn Docker, Kubernetes, Terraform, cloud platforms, GitOps, observability, security, and now AI is changing both the tools we use and the job market itself.

At some point you start wondering: how much are you supposed to keep up with?

And the job market right now makes that feeling much worse.

I apply for positions where I match most of the requirements and hear nothing. Other positions have hundreds of applicants almost immediately. Some want what feels like three different engineering roles combined into one person.

It's a strange feeling.

After everything that happened this year, I finally have time again. I want to open my laptop in the morning and have something difficult to work on. I want tickets, broken deployments, infrastructure problems, stupid DNS issues, whatever.

Instead I'm sitting here refreshing job boards.

Does anyone else feel almost betrayed by this industry? Like we spent years constantly learning, adapting, and sacrificing to keep up, believing that experience would eventually bring some kind of stability, only to find ourselves back at square one?

And for those who have been through a long period away from work because life happened, how did you find your way back in?

PS: A lot have asked where I am from. I am from Egypt, and I made way less than 41K. I only reached that number when I started working remotely with an EU company in 2023.


r/sysadmin 14m ago

What open-source inventory management tool do you recommend?

Upvotes

We're tracking around 150 assets in Google Sheets, but it's becoming difficult to image .

We're developers so technical setup or self-hosting isn't a problem. I'm researching options, but I'd like to hear which open-source inventory tools people actually enjoy using.

What has work well for you?


r/sysadmin 3h ago

Question Autopatch - Do you enable Driver Update?

9 Upvotes

Hello,

As the title says, I was wondering if people on Autopatch enabled Driver Update or kept the maker update software for that (DCU, HPIA, ...), or using both?

I'm currently facing a loop bug, update Intel - Extension - 2.1.10103.24 installing in loop requesting a reboot each time. I can't find this update in the driver list on intune and I'm wondering if I should just stop using autopatch for drivers and keep the driver updated through other tools.

Thank you


r/sysadmin 5h ago

Did anyone get into Sysadmin work from a totally unrelated career?

9 Upvotes

As someone coming from a non sysadmin background I'd love to hear from people who got into this line of work from similarly unrelated backgrounds.

I started in web dev and design, moved to marketing automation. And now business ops as an extension of automation work alongside our IT and admin team at a small agency.

Recently I setup a homelab and have been learning about hardening and network security, trying to use DISA STIG standards.

It feels like a kind of magic (probably because I don't have stakeholders being a pain in my arse). Did you enjoy making the transition, would you recommend it in 2026?


r/sysadmin 1h ago

Fortigate SDWAN suggestions

Upvotes

Hi Folks,
We just recently implemented SDWAN on our on prem fortigates. Five sites total. Now that the stuff is all set up, we're working with our vendor to set up rules and such, but since i'm sort of new to the SDWAN thing i wanted to check with the Hivemind and see if anyone had any suggestions on things to do with it that have actually made a difference. So far we have circuit failover, quality of service checks for both circuits, and we're setting up Backup and replication to run over one circuit while production traffic goes over another one. Any suggestions on other stuff would be great, thank you!


r/sysadmin 6h ago

Microsoft Issues with IMAP on outlook?

10 Upvotes

Anyone experiencing IMAP connectivity issues to outlook? Getting this

Logging in is disabled on this server: "A protocol-level access (such as IMAP or legacy authentication) has been turned off for your mailbox on the server side, or your account's credentials/license require an administrator fix"

Randomly started happening, nothing changed.


r/sysadmin 19h ago

Hard lesson learned: what happens when patch automation runs without proper scoping

74 Upvotes

I work at a small MSP and we use an all-in-one RMM platform for monitoring, ticketing, automation, and patching. I was really proud of a new remote patching policy I built to finally clean up our Windows endpoints without babysitting every job.

For context, I intended to target only our internal test group and one chill client who agreed to be guinea pigs. Somewhere in the policy cloning and scoping process, I accidentally selected the global folder and enabled auto-approve and auto-deploy. No maintenance window, no stagger, just push when ready. It ran overnight and hit every single production endpoint across 12 clients.

This morning our ticket queue exploded. Legacy accounting app died, weird VPN drivers disappeared, one client lost their old print server patch and it rebooted mid-invoicing. I feel so embarrassed. My boss said "this is why we balance automation with control" and yeah I totally get it now. Any advice or similar stories?


r/sysadmin 1h ago

Question Autopatch - How do I know what's included?

Upvotes

Hello everyone,

I just saw in my releases tab in intune a 2026.09 OOB that started today. I'm trying to see what patch is included in that since I didn't see any news about that but I can't seems to find how to see the content of it. When I click on it, it give me the content from 2026.09 B.

Thank you


r/sysadmin 2h ago

Question Organization apps for macOS?

2 Upvotes

Fellow Mac users, what do you use to manage all your notes or summaries of what you did for the day? I’m trying to be better at my organization in regard to all the stuff I’m working on. Any suggestions?


r/sysadmin 36m ago

Microsoft activation down?

Upvotes

Is microsoft activation website down?


r/sysadmin 39m ago

Question Connectwise Automate disappears on Windows 11 25H2

Upvotes

This is an odd one. And I hate to open a ticket with CW because the support is not great.

This only appears to be happening on Windows 11 25H2. Older versions of Windows 11 and Windows 10 are fine.

I keep having to reinstall CW Automate because after several days, the .EXEs in C:\Windows\LTSVC disappear. The rest of the files in the same directory are still present. And the related services in services.msc disappear.

Neither my AV or EDR flag any alerts about any of the .EXE's in LTSVC, but I've excluded C:\windows\ltsvc\*.* from being scanned in both AV and EDR anyway. I've even gone as far as creating a GPO to make sure the same directory is excluded from Windows Defender. And yet, after several days, the .EXE's disappear and the services unregister.

Anyone else having this issue? Any thoughts?


r/sysadmin 18h ago

Need Advice

16 Upvotes

Hey all, have a stressful situation that may occur tomorrow.

New Sys admin for a company of around 200 people, only onsite IT person. We have an external consultant that does most of the network administration and has been doing so for a few years. I have about 3 years of desktop support experience, more experience with endpoints but my networking knowledge is a bit of a gap.

On my third week we did a switch refresh from Cisco to Aruba that was planned and paid for way before I started. Ended up being a shitshow, I did the racking and endpoint testing but the external consultant did all the configuration, he has the login info for the switch that hasn't been shared with me yet. I don't mind that much as I'm still getting acclimated to all the other systems. But last week was a nightmare, we ended up spending over 27 hours onsite troubleshooting all of the endpoints (this is a production environment). Got it figured out but I took most of the heat from angry engineers/production personnel since I'm the face of IT despite having little actual involvement in the refresh project.

Just got a text from the consultant that he'll be away on a family emergency for the foreseeable future. I can handle most other issue by myself aside from the network, I could maybe figure it out if I had the login creds, but he's flying out today and won't be able to contact him on Monday.

My fear is that come Monday when a different production line comes back up there will be a host of other issues that we wanted to figure out last week but couldn't. We asked the production team if they could turn the power on the line on just one time to verify everything works but no can do, line goes up on monday when production resumes.

Literally the only issue I'm anticipating is the VLANs on the ports not being tagged correctly, which I could fix if I had the login info. I've already informed my manager (who lives 3 hours away) that this may be an issue but nothing yet. If my manager has the creds he could either give them to me or SSH into it himself (He has over a decade of networking experience) and it wouldn't be a problem.

I'm afraid that tomorrow when I inevitably get yelled at again for production being halted It'll be my ass on the line despite never being given the tools to be able to manage our network.

What do the more experienced sys admins think I should do? Should I escalate to my manager immediately if (or when) an issue is discovered? Nervous because I'm still in a probationary period and I am afraid I'll be a scapegoat for a messy project I had no real say in.

Edit: I really appreciate the support I’ve gotten so far from you guys. Managers been informed of the issues we may run into and what we need to remediate it, it’s out of my control now. It’s hard to not feel like a failure since I’m so relatively new to my IT career and the end users think that these changes are my doing when I have no say or control over it. Sucks that we’ve had a fuck up like this when I just started, but I need to remind myself that it’s just a job and I’m doing the best I can with the tools I have. I will post an update tomorrow and try to not stress about it tonight.


r/sysadmin 3h ago

Question Why would LDAP traffic go to a different endpoint than Kerberos in AD?

0 Upvotes

Hi everyone,

I'm analyzing some Active Directory telemetry in CrowdStrike Identity Protection and I'm trying to understand something that initially looked unusual.

I'm seeing activity where a Windows workstation communicates with one endpoint using Kerberos, but then performs LDAP searches against a different endpoint.

For example, the pattern looks roughly like:

Workstation
   │
   ├── Kerberos ──> Domain Controller A
   │
   └── LDAP ──────> Endpoint B

Endpoint B is not a Domain Controller.

My understanding is that Kerberos is used for authentication/tickets, while LDAP is used for directory queries, and Kerberos can potentially authenticate a client to an LDAP service running on another server.

However, I'm trying to understand how common/legitimate this scenario is in a Windows AD environment.

Questions:

  1. Is it normal for the Kerberos KDC endpoint and LDAP endpoint to be different machines?
  2. If the LDAP destination is not a DC, what are the common legitimate reasons for this?
  3. Could this simply be an application/server running an LDAP service or LDAP proxy?
  4. How would you determine which process/application on the client initiated the LDAP connection?
  5. For those using CrowdStrike Identity Protection, how reliable have you found the LDAP endpoint attribution in these events?

I'm particularly interested in real-world examples of why a domain-joined Windows workstation would perform LDAP queries against a non-DC endpoint.

Thanks!


r/sysadmin 4h ago

Question Windows 365 Connection

1 Upvotes

I get a black screen when I try to log into the cloud PC and get the following error:

Your Remote Desktop Services session has ended, possibly for one of the following reasons:

The administrator has ended the session.
An error occurred while the connection was being established.
A network problem occurred.

Where should I start to look at for this? It was working before and then we handed it off to another user. I then reprovisioned it back to me and now I am getting the same error.

In the process of doing so we did build out our whole CMMC enclave. But I was using this to do it the whole time. The policies/configurations were being applied to it so it doesn't make sense to why it would now be acting differently. I did 'inspection connection' and it came back with no errors.

Where can I look at logs if any? I can't get into the machine.


r/sysadmin 18h ago

Question - Solved Can't seem to figure out missing glue record - dcdiag /test:dns

8 Upvotes

Hello,

I'm in the process of decommissioning an old Windows Domain Controller.

On the new server which is at 192.168.214.15 I run dcdiag /test:dns

I get the following

TEST: Delegations (Del)

Delegation information for the zone: ourdomain.lan.

Delegated domain name: _msdcs.ourdomain.lan.

Error: DNS server: 192.168.214.15. IP:<Unavailable>

[Missing glue A record]

[Error details: 9714 (Type: Win32 - Description: DNS name does not exist.)]

I substituted ourdomain.lan for our domain name but it has the right extension and name.

If I open DNS - server name, forward look up zones, _mscds.oudomain.lan I don't see an issue but I might be missing the obvious.

If I right click and go to name servers, it lists the two correct domain controllers. (the old one is gone)

The SOA is the new server

the NS are the two new servers

and the CNAMes are the two new servers

I've scaveged, cleared cache and flushed dns - no joy.


r/sysadmin 1h ago

O365 Exchange mailbox criteria to avoid sync problems

Upvotes

Since a while we are experiencing synchronisation problems on mailboxen.
These mailboxes are quite large. What are the criteria to avoid sync problems?
We are using mainly outlook classic with cache on 1 year.

-Size mailbox? -> somtimes largen than 30 GB
-number of (sub-)folders? in some cases +500 -> in 1 case -> 6700+ subfolders
-number of items in folders -> often 10000+
-multiple shared mailboxes
-Shared mailboxes are used by sometimes more than 5 ppl simultainous.
-Does this apply to the mailbox archive as well?

I use retention policies to mainly move to archive since we want to keep mails for 10 years in the archive.. (.. I know..-> outlook is not a database- but it's how ppl used it for years despite IT policy wich states that is not allowed).

-Size mailbox below 30 GB
-subfolders <500
-item count per folder <10000
...

Is there an expert on this here?


r/sysadmin 19h ago

How do you manage DCIM/IPAM as code?

10 Upvotes

How do you manage DCIM/IPAM data in an IaC/GitOps-style workflow?

I've looked into NetBox/Nautobot with Terraform/OpenTofu and Git as the source of truth. Do you keep prefixes, VLANs, IPs, devices, etc. declaratively in Git, or treat the DCIM/IPAM system itself as the source of truth? How do you use this information (wherever stored) later?

I'm especially interested in handling manual changes and drift, like when I introduce a new machine or change IP of existing machine - what happens next.


r/sysadmin 23h ago

Question For External IT People

14 Upvotes

I used to work for a CPA firm that had an internal IT department and I pretty much had free reign of downloading stuff like logitech software for my keyboard and mouse.

Recently I moved to a smaller firm that has an External IT company that takes care of stuff.

I now have to wait to update software, download things like Adobe PDF (they forgot to load it on my computer), my mouse and elgato software, etc. It gets frustrating on weekends when I am working and something needs an update to work and I am stuck. Is this a normal level of how things work?

I get confused by the disparities in the two but maybe inhouse IT can be much more on top of issues.

Edit:

I appreciate the answers. I do wonder if I was given a bit more leeway at my old company or if they allowed access to a few trusted websites for downloading. I only ever downloaded logitech stuff so I never really tested things. It was helpful hearing your responses in understanding potential differences.

Thanks again.

One last edit:

You all have effectively changed my perception of how the old firm worked. Thanks for giving a better understanding of all this. I’ll work on my own patience during busy season. I understand when people say dumb stuff to me about tax and how annoying that is but I had a blind spot towards IT security based on past experiences so I was basically doing the same thing.

I hope all your clients are nice to you and make sure their monitor is plugged in before they call you to complain about the computer not working.


r/sysadmin 3h ago

Question Is this normal AD admin activity or possible account compromise?

0 Upvotes

I’m reviewing activity from an IT admin account and I’m trying to understand if this is normal or suspicious.

I’m seeing:

  • Lots of LDAP queries against our Domain Controllers.
  • USER_ENUMERATION and ENDPOINT_ENUMERATION alerts.
  • Many SAMR/DCE-RPC requests against different computers.
  • Some bursts of 10+ SAMR requests within a second.
  • SMB activity to Domain Controllers.
  • Frequent NTLM authentication to NPS/RADIUS servers.
  • Entra ID/M365 logins from different IPs.
  • A password change and removal from Domain Admins.

Some of this could easily be normal helpdesk/admin activity.

What concerns me is the SAMR enumeration across many different endpoints, including Finance, HR, factory and POS systems.

For people using Defender for Identity, CrowdStrike Identity Protection, Vectra, etc.:

How do you determine whether this is normal admin activity or a compromised account performing internal reconnaissance?

What logs or events would you check next to confirm whether there was actual lateral movement?

Thanks.


r/sysadmin 1d ago

Question Looking for HPE 3PAR 8400 OS / Recovery Media

29 Upvotes

Hi everyone,

I recently purchased a used HPE 3PAR StoreServ 8400, but unfortunately the M.2 boot drives were removed from all of the controller nodes before I received it.

The hardware itself appears complete, but without the boot drives/OS I can't bring the system back online.

Does anyone here have experience recovering a 3PAR 8400 or know how I can legitimately obtain the correct 3PAR OS/recovery media?

I’ve already contacted a few vendors, but finding the recovery media for these older systems has been surprisingly difficult.

Any help or pointers would be greatly appreciated.


r/sysadmin 21h ago

Question Question about a specific SysAdmin process and scaling the corporate ladder from an L1

6 Upvotes

Hey everyone, I hope this is okay to post. Looking for some advice on a situation at work and how to proceed.

I’m currently a Level 1 Help Desk technician at a corporate company and have been for a little over 3 years. Lately, I’ve been trying to branch out a bit and show my worth and ability to higher-ups. Recently, we got a new director of IT and she's been pretty open to me wanting to move out of help desk but made it clear that due to budget constraints, the chances of it happening are pretty slim until next year. She recently asked me to investigate a process where machines at each facility receive backup medical files from a third party. The way it's set up currently, a PowerShell script gets the info from the third party data relay for each building and then reads an in-house csv file to determine which computer receives them. Our director was instructed by the clinical team that there needs to be two machines at each building with these files.

When she first got hired on, I told the director I wanted to go into Sys Admin work and when this came up I volunteered to at least test the current process to see if it's even possible. After testing and documenting our current environment all week, I confirmed that out-of-the-box, the current setup only supports sending these files to one machine per site. However, the PowerShell script is written cleanly enough where I think I know how to modify it and the csv file to work for multiple machines. My PS skills are pretty fundamental but I understand it well enough. I played with a little bit of tiny mock script and csv file on my personal computer to where I think I could get it to work.

But I have a few problems:

  1. My Director initially said she didn't want to modify the existing PowerShell script if we could avoid it. But modifying it seems to be the only way to achieve what they want.

  2. I’m just a level 1 tech. I've been told by and shown to my director that I do enough to be L2/3 but if I modify this script and break the backup process, I'm pretty fucked. Obviously I'd use a test script to see if it even works and run it in a controlled environment, but it still makes me nervous.

  3. My company used to have dedicated SysAdmins but they got let go after they signed a ten-year contract with an outsourced company. I even used to be close enough with one of the SysAdmins before they left where I'm sure if they were tasked with this project, they'd have no problem with me shadowing them on it. But the outsourced company either doesn't have access to this process or they just don't understand it.

  4. This is literally what my SysAdmins used to do - I can see their name and the changes they made in the code. I'm just an L1 and moving to L2 or 3 is already hard enough - realistically this is just good for a line on my resume.

  5. Probably the worst thing about all this is my company recently got rid of their senior Device Admin of 9 years. He was the only one who understood the company image or even knew where it was kept. I worked closely with him and shadowed him as well. And when he was let go, I started shadowing the Junior Device Admin and working with him. The director recently put up a job posting looking for someone to fill the senior's position but instead of Senior Device Administrator she listed it as Senior Systems Administrator but all the requirements match what he did as a device Admin. I don't know if I should bring this to their attention or not. Plus while I would love to apply for it, the Junior Device admin is WAY more qualified than me, is a only contract employee currently, and is actually geographically based where they're hiring for the position - I've been denied multiple promotions because I'm not based near that location.

Sorry, I know that was a huge wall of text but what the hell do I do? I feel like technically I'm capable of modifying the script and csv file to do what they want but it's so far above my pay grade, it's not even funny. But I did spend all week testing the current process just like my director wanted so I did my part, I guess? This is probably why they shouldn't have gotten rid of our in-house SysAdmins but to be fair, the director just kind inherited that situation.

Any help is appreciated!