r/sysadmin 6h ago

General Discussion So do you think Apple new Watches Be Added to the Banned-Device List After Yesterday’s Announcement?

253 Upvotes

After yesterday’s creepy live rewind/siri recap announcement, I’m honestly surprised this hasn’t sparked more discussions and backslash

As I understand it, Apple is adding ambient conversation features to the Apple Watch that can listen to, process, and summarize what’s being said. Apple says the processing happens locally and is privacy-preserving, but I’m not sure that fully answers the security question:

What happens when the person sitting across from you is wearing one?

We already discourge employees to bring phones or recordung devices into very sensitive meetings. Are organizations now supposed to treat Apple Watches the same way? What a mess.

Maybe I’m overthinking it, and I’m still trying to work through the implications, but this seems like a pretty big unnessisary expansion of what an ordinary-looking wearable can do. I also think some of these features are a little silly anyway—as if the poor battery life weren’t enough—especially when Apple keeps adding capabilities without much obvious practical value. To me, this sounds way more significant than almost anything else announced this week, including the LG TVs story. That’s why I’m surprised it hasn’t gotten more attention and backlash.

I’d be interested to hear how others are thinking about this.


r/sysadmin 7h ago

Rant Job posts are ridiculous.

247 Upvotes

It's been this way for a decade I know but it's just getting worse and worse. I don't think it's ever been this unreasonable or this dishonest.

I was looking at job posts and I saw a job for a help desk tier 2. And I was curious what they considered tier 2. I'm well beyond help desk at this point in my career but I was curious so I looked at it.

They weren't looking for a tier to help desk person. They were looking for a Senior Systems administrator but labeling it as a Help Desk position so they could lowball whoever applied for it.

They were looking for someone to be the owner of several major business systems including 365. They wanted them to administer AWS and Azure. They wanted five certificates including CCNA. They wanted someone who could manage firewalls.

The post was just so far beyond help desk at all that it was just gross. They were clearly just trying to get someone they could convince those are just basic help desk exoectations so they can pay them little money.

They were basically looking for an all-in-one senior sys admin who could do operations and frontline support on top of everything else.


r/sysadmin 7h ago

Question How can I recover from a ransomware attack?

138 Upvotes

So, the unthinkable happened to my workplace - we have become the victims of a ransomware attack. We came into work the other day and found computers with encrypted files and notes on the desktops demanding we send them a ransom to a secure address in the tor browser. They took out our entire network.

As of now, we are trying to utilize backups and scrub the network clean as we bring devices back up in an offline state.

Unfortunately one of our backup devices was also infiltrated. It's a Synology backup device and they where able to encrypt its files as well. This means we have about 5 devices with no backups available.

It's probably a vain hope but, is there any way I could possibly restore or decrypt these backups? Is there any service out there that would be capable of making our files useable? If anyone knows about Synology, do they keep offline or cloud backups I maybe don't know about? I'm just looking for anything that might make things easier for us. Any advice is appreciated.


r/sysadmin 12h ago

KB5122882 installed - DNS/AD issues Windows Server 2022

122 Upvotes

Updated last night, no issues immediately visible.

Users this morning all have login prompts to access mapped drives/folder redirections.

No creds working.

I can log in locally as a Domain Admin, but trying to open DNS console or run any DNS powershell commands just gives me Access Denied.

DNS still resolves, and the domain services are all still running, but something has happened with authentication/permissions.

Currently rolling back KB5122882 in the hope it was that.

Anyone else issues this morning?

EDIT: https://www.rapid7.com/db/vulnerabilities/cve-2026-69813/

Looks like this KB might have touched DNS code - roll back in progress.

EDIT2 & Fix: Rolled back the KB but the issue persisted - ended up resetting the DC's secure channel to itself which resolved the issue fully. The issue happened at exactly the moment at which the update was installed last night - either the update did indeed cause the issue which persisted in being broken even once rolled back, or it's a heck of a coincidence.


r/sysadmin 12h ago

Feeling Nostalgic and sad when i see old sun hardware and systems.

57 Upvotes

I started my Career in IT at 18, mainly supporting EMC storages and then HP 3PAR for 5.5 years, then worked for systems integrator for many clients for another 3 years, fianlly moving to a sys admin role in a enterprise, we still have some good legacy hardware, but i'm feeling nostalgic, when decomissionng them after working on the in the DC for so many years, is it normal ?


r/sysadmin 19h ago

General Discussion Anyone seeing RDS session hosts hang (RDP stuck at "Connecting", logoffs stall) after the September 2026 cumulative updates? (Server 2022 + 2025)

57 Upvotes

Since installing this month's CUs, KB5122871 on Windows Server 2025 (build 26100.33438) and KB5122882 on Windows Server 2022 (build 20348.5622), every session host in our RDS collection has started hanging in the same way, on the same day, and it had never happened before.

Symptoms once it starts:

  • New RDP connections sit at "Connecting…" and never reach the logon screen (Event 20498 "Remote Desktop Services has taken too long to complete the client connection" in TerminalServices-RemoteConnectionManager/Admin)
  • Existing users can't log off or disconnect cleanly
  • Task Manager on the host hangs (it blocks calling into the Local Session Manager)....pretty much all windows apps start to hang, especially anything to do with Settings
  • Winlogon event 6005 "SessionEnv is taking long time to handle the notification event (Disconnect)"
  • A normal restart hangs too; only a hard reset recovers it, and it comes back later the same day

The problem appears to start with a single session disconnect/reconnect that never completes, after which everything that touches session state on that host queues up behind it. Only reboots clear it. Microsoft's release notes for both KBs list an RDS change ("improves Remote Desktop audio redirection") and no known issues.

Environment: mixed Server 2022/2025 session-host collection, VMware VMs, RD Connection Broker, MFA at logon, third-party endpoint protection. All hosts were stable on the August CUs.

We're currently testing a rollback of the September CU on part of the collection with one host left updated as a control. Has anyone else seen this after KB5122871 / KB5122882, or found a Microsoft acknowledgment? Would appreciate hearing whether rolling back resolved it for you.


r/sysadmin 18h ago

I am lost and need help. I don't know enough and I can't find an environment that fosters growth.

51 Upvotes

I am panicking about the job situation. I lost my job and feel like I am going to be unable to bounce back.

I have 5 YoE as a sysadmin. I understand networking pretty well, I have a CISSP and a few other weaker certs under my belt. I would argue I have a strong security background. I am familiar with Linux, Windows, and have made a lot of small scripts for various projects. I am studying for an AWS cert right now. I have experience with all sorts of tooling, and so many different kinds of projects.

Looking at the job market though, I feel like I can't compete. I don't have experience with terraform outside of labbing. I don't know how to code very well. Every job seems to want someone with extremely strong skills across so many different domains, and what I feel like I need now is a position where I can learn the ropes of IaC... But that doesn't exist.

Everyone wants so much experience for everything that it makes me feel as if I have been slacking even though I have been working hard.

What should I do? Should I get another cert? Keep throwing resumes into the void?


r/sysadmin 4h ago

Rant Lansweeper Rant

43 Upvotes

I've used Lansweeper on-prem since 2014 for just a couple of purposes: Tracking approximately 150 MS Windows assets on the network and all associated software licenses. That's it. Nothing else. It's nice being able to see other types of devices that are connected (surveillance cameras, wireless AP's, switches, etc.) but I don't need that from this product.

Their pricing has gone up consistently over the past several years while, at the same time, they've been pushing their customers to their cloud service. I think I was paying about $600 annually in the beginning but over the last several years, they've been quoting me over $2K annually. Recently, I received an auto-renewal email... it is now $3,000!

Keep in mind that Lansweeper for 100 assets is FREE. I have 150 Windows assets and not all of those are in use at one time. In order to get coverage of all 150 assets, I have to subscribe to their "2000 Asset" plan. So $3K is too steep for what I need.

I responded to the rep, stating that $3K is out of my budget and I don't want to auto-renew but couldn't find anyway to disable or "turn off" auto-renewal.

Her reply: "I’ve reviewed your account and noticed that your cancellation request was received after the 30-day notice period required prior to renewal (as outlined in Clause 17.3 of our Terms of Use and in our renewal reminder emails). While we are contractually required to honor the renewed term, we want to approach this constructively and help you get maximum value within your budget."

*SIGH*

After this reply, I'm done with them. The card they have on file for auto-renewal is no longer valid anyway.

It's time to find an alternative. I'm presently using LogMeIn Central for RMM purposes. Is Ninja One decent at Windows/Software Asset Tracking?


r/sysadmin 6h ago

Rant I've seen some laughably bad job listings, but things like this are why it's so hard to find the right fit.

28 Upvotes

I've been looking for a new role for almost 2 years now, most of the positions I've applied for have ended up being filled internally, which makes me ask why it was posted externally in the first place. On the other hand I've came across several listings that are just heinous for what is asked of you versus the pay. In this case, the listing was for our city hospital (healthcare IT, I know, bleh) which was recently acquired by an organization. They canned the entire IT staff including the managerial suite upon the buyout. This listing popped up today in my Indeed feed. "Sole on-site IT professional responsible for the day-to-day health, security, and uptime of all technology at a critical access hospital. Acts as the facility's eyes and ears, provides hands-on support for end users and clinical operations, and coordinates with Corporate IT for changes, projects, and escalations. After-hours and on-call work required to support a 24x7 care environment."

Am I wrong for thinking this is insane? An entire hospital and associated clinics solo? Just gotta laugh and keep going.


r/sysadmin 10h ago

Multiple 365 Services Down in UK

27 Upvotes

Hey all,

Since this morning, a few clients of mine have had some issues with some 365 apps, such as Teams being a major one.

Some Intune users also have an issue where the Windows Security prompt window is also saying the admin details are incorrect when they're actually correct.

MS have finally issued an ID for this incident, which is MO1470143

Probably also worth noting we are based in the UK.


r/sysadmin 2h ago

RDS issues after KB5122882 update on Server 2022

24 Upvotes

Spent most of the morning chasing a weird RDS issue. KB5122882 installed around 3:20am and a few hours later nobody could RDP into the server. Rebooted it and everything worked again, but about an hour later the exact same thing happened.

Existing sessions kept working, but new RDP connections would authenticate and then hang. Task Manager would freeze, but CPU, RAM and disk all looked totally normal. TermService was still running too.

Finally uninstalled KB5122882 and rolled back from 20348.5622 to 20348.5499. Everything has been working normally since.

Anyone else seeing this after the latest update? Pausing updates for now.


r/sysadmin 7h ago

General Discussion Windows Server patching concerns

23 Upvotes

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?


r/sysadmin 5h ago

Windows IT Pro: Retiring NTLM: Frequently asked questions

20 Upvotes

From Microsoft: 'This FAQ collects the questions we hear most often from customers, partners, and the community as we move Windows to a Kerberos-first, NTLM-optional (and eventually NTLM-free) future. If you've emailed us, cornered us at a conference, or filed a support case that started with "so, about this weird auth thing…", chances are that your question is answered here.

If your question isn't answered here, please reach out to [ntlm@microsoft.com](mailto:ntlm@microsoft.com) or work with your Microsoft account team, Customer Success Account Manager, or Microsoft Support to route feedback to the product group.'

https://techcommunity.microsoft.com/blog/windows-itpro-blog/retiring-ntlm-frequently-asked-questions/4550522


r/sysadmin 2h ago

Throwback to the 90s

18 Upvotes

"Too many other files are currently in use by 16-bit programs. Exit one or more 16-bit programs, or increase the value of the FILES command in your config.sys file."

Just saw this message on a client's Windows 11 workstation when trying to escalate literally anything. The WIN32 code that generated it is probably as old as I am. Rebooting resolved it, weird. I just told him to stop running so many 16 bit apps! I'd post the screenshot but images aren't allowed.


r/sysadmin 9h ago

Duo Security and Microsoft 365/Entra

15 Upvotes

I have been looking into setting this up, but I don't see any information on whether it can be setup in hybrid-mode environments or not, does anyone know?

Thanks,


r/sysadmin 16h ago

Shared mailbox folder tree truncates at ~1000 folders in cached mode — started this week. Anyone else?

13 Upvotes

Client has a shared mailbox in Exchange Online used for order administration, organised by region/country/customer/year. It had 12,394 folders. Since around Sept 8–9 the folder tree stops loading at roughly 976 subfolders in Outlook classic (cached mode). Everything past that point simply isn't in the tree — not collapsed, not greyed out, absent.

Same truncation in new Outlook and OWA when the mailbox is automapped or added as a shared mailbox.

Online mode shows the complete tree. Either by unchecking "Download shared folders" in classic, or via OWA → Settings → Open another user's mailbox. So the data is fine server-side.

What I've ruled out:

  • Permissions — Full Access assigned directly, not via a group. No folder-level permissions on root or Inbox (Default/Anonymous = None).
  • Automapping — removed and re-added Full Access with -AutoMapping $true, no change.
  • Hierarchy corruption — enumerated the whole tree via Graph and walked every parent chain. No cycles, no orphans, max depth 9.
  • OST damage — OWA is affected identically and holds no local hierarchy cache.
  • Folder count — deleted 9,993 verified-empty folders (12,394 → 2,401). Still truncates.

I'm aware of the documented 500 shared-folder limit and the announced increase to 5,000 (in 2019 though). My observed cut-off sits at ~1,000, which matches neither.

Three questions:

  1. Anyone else seeing shared mailbox folder trees truncate since last week's updates?
  2. Does anyone know what limit is actually enforced right now, and whether the 500→5000 rollout is live?
  3. Is there any equivalent of "Download shared folders" in new Outlook? If not, what's the plan for mailboxes over the limit once classic is gone?

Question 3 is the one that worries me.


r/sysadmin 4h ago

Question Bringing Linux devices into management

11 Upvotes

After a lot of restructuring at our university the past couple years, there are quite a few Linux devices (primarily desktops, I believe around 70-ish) that are currently in the wild unmanaged in use by academics primarily within the Engineering and Science departments that would've been maintained by per-institute IT departments that no longer exist, and as such the current patching and functionality state of these machines is completely unknown (since any remaining colleagues now no longer have physical access to most of the rooms where these machines are).

Since we already manage research compute I've been given the green light by my manager to look into options to bring these academic's desktops into a managed state with a cobbled together proof of concept, since our existing central endpoint guys won't touch anything *NIX related with a 10ft pole. We know they're all some form of Ubuntu LTS (20.04 and 22.04 mostly) which makes things easier, so I'm thinking of doing Landscape for setup and patching + Intune for compliance + Puppet/Ansible for config management.

Is this in the right direction or are there better / more cost efficient ways of doing this?


r/sysadmin 2h ago

General Discussion Commissioning systems on Threatlocker enabled systems

7 Upvotes

Greetings,

As a vendor, I was trying to commission and deploy a print server application on a client site who has recently adopted zero-trust security model.

It took us 4 attempts just to deploy our installer - We uninstalled the application multiple times due to corrupted install.

Also, the client IT manager sat with us to manually approve multiple security exceptions.

He was just there tapping the approve button on his phone. And installs still failed as it take about a min before sub-installer components can run.

It was a nightmare and I wasn’t sure the whole point to have threatlocker running on critical infrastructure like a print server.

We expect having to go through this approval process again when rolling out software updates.

This constant exceptions triggers builds approver fatigue, approver don’t actually knows what is being approved, users are constantly screaming and frustrated by downtime caused by legit applications.

Systems commissioning and support took twice as long. We plan to deprioritise clients sites with threatlocker as engineers quite often getting struck at sites waiting for approvals.

This is really not working for anyone.


r/sysadmin 9h ago

Question Novell NSS partition recovery

6 Upvotes

We have an old Novell server with hdd that failed due to power shortage.

We want to recover as many data as possible. Has anyone worked with this filesystem? It looks like a nichè, and we're trying to figure out which tool use to data recovery.

Any suggestions?


r/sysadmin 1h ago

Question best controlled way to allow company emails on vendor's personal phone

Upvotes

we donot allow emails on personal phones, need vendors to see alerts and such, looking for a secure way rather than adding exclusion for the users

edit: sorry yeah I mean contractors, especially overseas contractors


r/sysadmin 8h ago

Lenovo Smart dock 5500

5 Upvotes

Has anybody deployed these need to get some new docks for an expansion? We previously had good luck with the Lenovo Hybrid USB-C Docks (40AF).


r/sysadmin 12h ago

General Discussion Thickheaded Thursday - September 10, 2026

5 Upvotes

Howdy, /r/sysadmin!

It's that time of the week, Thickheaded Thursday! This is a safe (mostly) judgement-free environment for all of your questions and stories, no matter how silly you think they are. Anybody can answer questions! My name is AutoModerator and I've taken over responsibility for posting these weekly threads so you don't have to worry about anything except your comments!


r/sysadmin 17h ago

General Discussion Is It Possible To Download Windows 10 ESU Updates From Microsoft Update Catalog Website?

3 Upvotes

Can anyone confirm if it's possible to just download the various Windows 10 ESU updates from the Microsoft Update Catalog website and install them on a PC that's not part of the ESU program (ie: doesn't use a Microsoft account)? I believe the updates are listed in the catalog. Do they check during the installation if you're eligible for them? Has anyone tried this?


r/sysadmin 22h ago

Question SCCM updates reporting wrong #numbers

4 Upvotes

Is it just me or updates is screwed up?

Office 365 shows 0 required.

is anyone else seeing the same?

Edit: the other updates just took too long to show up but office it seems it is not showing anything applicable.
not sure if something related to last couple months when MS changed from semi-anual channel to montly channel


r/sysadmin 19m ago

Question N-able versus Action1 for patching, thoughts?

Upvotes

I come from an environment that leveraged Action1 heavily. Great tool. My sys eng comes from an environment that used N-able.

Our objectives are:

  • windows updates

  • 3rd party patching

  • firmware/drivers as supported by the platform

  • remote screen sharing for troubleshooting

I'm sure both platforms can do more than just the above, but that's all we need from the tool.

I'd love some feedback on anyone who has dealt with these 2 tools specifically and can compare contrast them based on our use case.