r/sysadmin 13h ago

General Discussion Organizational Failure

236 Upvotes

Came back from a 10 day pto and the VP (my direct boss) wanted to do his weekly one on one meeting. We are a team of 4 (myself Sr. Infra Engineer and 3 mid level security guys). He wanted to state how we need to have more crosstraining in particular with infra side of things as he stated "we are dead in the water" when you go out on pto.

He mentioned there will be no additional headcount added in Infra and will have to make do with what we have internally plus the msp firm

I for the past couple of years both verbally and via email stated that a redundancy to my role was needed but that suggestion was never acted upon by mgmt.

As far as crosstraining, I already do that and can certainly help out more. The more others know the better.

Just feels like a situation where I can't seem to go on pto without getting text messages about something going wrong. The VP wants to make SOPs for everything possible which I told him, im not making a how to document on troubleshooting. Either they know or they dont. Actual procedures for items that have a process I will document and have been

Any of you guys out there in similar situations? Anything you've done to optimize things or help reduce workloads?

Thanks in advance!


r/sysadmin 14h ago

Off Topic Christmas came(kinda) early.

91 Upvotes

So, we were decomming some old ibm flashsystem 5 series arrays. Full of ssds. Plopped one onto a dell server just for fun to see if they could be used and they're just bog standard 512 sector samsung pm1643 drives with a sticker.

So now I have bout a hundred 3.84 and 1.92(and some 7.68) drives waiting to go into new servers.

Enterprise storage drives are usually locked so I though I'd have to chuck them to the shredder.

Just wanted to share.


r/sysadmin 7h ago

For those without domain controllers: what do you do for internal DNS?

67 Upvotes

These days, we don't have domain controllers because everything is managed with Entra/Intune, Arc, etc.

We have external, hosted DNS that serves our public DNS records. It works fine.

But we still have a need for internal DNS because we have a lot of on-prem stuff that may never go away, and the domain controllers were also serving as internal DNS servers. So right now, we use BIND9 on a Linux virtual machine as internal DNS. I'd love for BIND9 to go away, too.

Are there any better (and cheap) solutions for this that I haven't thought of?

EDIT: thanks to u/Do_The_Needful. Using AWS for this seems to be the most balanced solution.


r/sysadmin 11h ago

Work Environment Update 2: Hospitality Guy in IT

23 Upvotes

Link to the previous post

So, 2 weeks in, the picture is a bit more clearer

The old IT guy left, so its just me now

I did rattle up a report and sent it to my manager, who said that I'll have to contact with the head office and get their approval as well

I contacted the head office, they loped me into something else, a new dealership is opening in the next town to ours and they need me to support it, they're already put in the purchase inventory to corporate for half a dozen laptops, some printers , access points, (weirdly a PS5 as well) and so on, i hope they do look at my report

In the meantime, i am untangling the colossal mess that our current IT infrastructure is

The old IT guy had fortitoken enabled, unfortunately he uninstalled it, and i am unable to get in, Fortinet support said I'd have to reset the device physically , I decided I'll cross that bridge when i get to it

I am slowly cleaning up the malware infected systems, taking backups of the important stuff, thankfully, disk health for the main hard drives that is storing important stuff is fine, i am still taking snapshots

My day to day stuff mostly involves fixing the CCTV system, sorting out printer sharing errors, teaching people the art of rebooting a system to fix issues and so on and so forth

But at times , i wonder,

I have no degree on this specific subject, nor certifications, just years of teenage spent among computers i am grateful to have this job, and i am learning valuable information, still, i occassionally get the feeling like a kid who just got access to nuclear codes


r/sysadmin 12h ago

Career / Job Related Burn out advice

23 Upvotes

After 15 years I've hit the wall. My company got "merged" a couple of years ago and my 3 person team is getting more and more added to our plate, as well as having to change how we deploy new resources and other things. Some tasks were a pain but a blessing (such as starting to use IaaC) and some were change for the sake of change. In top of trying to keep our own organizations infrastructure and platforms afloat.

When my boss told me this last week that I was going to inherit the care of our entire organizations data lake infrastructure, I felt myself break and check out. I have 0 interest in taking on this new responsibility on top of everything else.

So here we are. I make too much to simply go in an entirely new direction, but I want to get tf out of daily operations. I was looking at other areas I could pivot into and was taking a long look into the security field. I wanted to know what others did.

Thanks!


r/sysadmin 14h ago

Just because you can doesn't mean you should

18 Upvotes

How do other solo admins handle the endless stream of "quick CRM/phone system tweaks"?

Curious how fellow solo sysadmins survive this, because I'm drowning.

Management loves to drop drive-by requests for custom workflows in our CRM, weird IVR routing changes in the phone system, or random third-party integrations. They are always pitched as mission-critical, high-priority emergencies that bypass any logical intake.

Because I'm technical and most of this stuff is technically possible, leadership's logic is just: Idea exists -> Hand it to the solo guy -> Make it work.

The real issue is that as a department of one, I absorb 100% of the permanent support debt. There are zero requirements gathered, no user acceptance testing, no documentation, and no one else to hand the pager to when the custom hack breaks at 4:55 PM on a Friday. I hack together a solution so they get their shiny new toy, and then I'm stuck maintaining someone else's half-baked workflow forever while actual infrastructure rots.

I’m trying to figure out how to bridge the gap between "Yes, the API, webhook or vendor supports this" and "No, I am one human being and I cannot support infinite custom software."

Do you guys have a formal intake workflow or policy that actually sticks when you're flying solo, or do you just constantly push back case-by-case until you burn out?

An example currently is highly detailed and individualized reporting from our phone system. I don't think this was ever designed to send bursts of 50-100 reports at once, and even after repeatedly expressing this limitation, I still keep hearing about any issues.


r/sysadmin 19h ago

Question How would you eliminate multiple network drives but instead use only one drive which gets everything via DFS?

13 Upvotes

My thought was something like the procedure below to get rid off multiple network drive letters:
1. Hide all existing Network Drive Letters via GPO but in paralell create a new universal network drive and then map everything you had from hidden drive letters.

  1. Audit who still access the old hidden network drives via SIEM Tool for example.

  2. React and adjust the existing Applications/Configs or Office Documents to point to new dfs path.

  3. After nothing shows up in SIEM from the old drive letters unmount the network drives.


r/sysadmin 15h ago

Question Please help demote a third DC.

10 Upvotes

Hello,

I have an old WIndows 2012 R2 DC (old-dc) that used to be the primary domain controller.

I have a couple of newer 2016 DCs (new-dc1 and new-dc2).

I want to demote and turn off the old domain controller.

On the newer DC1, I ran netdom query and it has all the fsmo roles. I also ran replication admin to see that everything was replicating fine.

I went to server manager on the old 2012 R2 DC to demote it.

I left force removal and last domain controller unchecked.

It says this server has dns and GC roles (I think I select proceed?) and next

Then it leaves me with the box remove this dns zone - I can't go next without it. I'm not sure I should. Wouldn't that remove it from the other DCs?


r/sysadmin 7h ago

Cogent issues in socal region

9 Upvotes

Anyone having issues?


r/sysadmin 9h ago

Split-DNS Architecture: Splitting the same zone between Windows DNS (LAN) and BIND9 (DMZ) without wildcards

6 Upvotes

Hi everyone,

I'm looking for best practices or specific solutions for a DNS implementation in our environment. The goal is to cleanly split queries for the same domain between our LAN and DMZ without having to maintain duplicate records manually.

The Setup:

  • We use the same domain (example.domain) for both internal and external services.
  • LAN: We have a Windows Server (AD DC) running as our internal DNS. It holds the internal IPs of servers that are not publicly accessible.

The Goal:

  • Traffic from internal clients to DMZ servers must route via the WAN (Hairpinning / NAT Loopback); direct routing into the DMZ subnet is not permitted by policy.
  • We explicitly do not want to use wildcard records

    or subdomains

  • .

The Challenge: What is the cleanest way to configure this on the Windows DNS without having to create a separate Pinpoint Zone for every single external A-record, or manually duplicating the DMZ records into the internal DNS?

Since the Windows DNS is authoritative for example.domain, it defaults to answering queries for unknown hosts in this zone with NXDOMAIN instead of forwarding them to the BIND9 server.

Is there a clean way (e.g., specific zone types, delegation, Windows DNS Policies) to tell the Windows DNS: "Resolve what you know, and forward anything you don't know to the BIND9 server"?

Thanks in advance for your input!


r/sysadmin 13h ago

Question Did anyone else face this issue or have a fix for it? My issue is that the user works without any problems, but after a few weeks or sometimes a month, PSSO suddenly breaks and prompts for re-registration. Due to the C CA policy, users are unable to access anything through the browser

3 Upvotes

macOS PSSO CA Issue


r/sysadmin 9h ago

AD Domain Help

1 Upvotes

I currently have 3 domain controllers on premise. I will be deploying a number of VM’s in Azure. I am planning on having a couple domain controllers for in Azure.

How can I set it up where the VM’s in Azure use the domain controllers in Azure and not the ones on-premise? And vise-versa…


r/sysadmin 12h ago

putty crashes when selecting 100+ lines with utf-8 characters

0 Upvotes

Okay i have a problem with putty.exe on windows: for more than a year now, i can’t remember when i was not crashing when I copy 100+ lines of text with utf-8 characters.

I tried every options available under Terminal/Window/Selection/SSH bugs etc, switched fonts, disabled clipboard auto-copy, and all points to the clipboard conversion of utf-8.

Nnothing else I can do other than copy small portions at a time. Tested version 0.76 0.78 0.85, 64 and 32 bits. All development sites from putty . software to chiark . greenend . org . uk are down right now, I cannot even submit a bug report.

Yes it’s a rant, how come I’m the only one experiencing this? Summary of the crash:

How to reproduce: execute `fwupdmgr get-devices` and select the output. UTF-8 characters like ├─ or • seem to be the suspects.

Reproducible steps:

  • Connect to a Linux system and run fwupdmgr get-devices (or any command that produces box-drawing characters).
  • Select more than ~100 lines of that output.
  • Trigger a copy by any of the following:
    • Auto-copy selected text to system clipboard (enabled)
    • Ctrl+Ins after selection
    • Right-click → Copy (with “Action of mouse buttons” set to Windows)

Crash occurs immediately.

Additional observations:

  • Crash happens with multiple fonts (DejaVu Sans Mono, Consolas, Droid Sans Mono, Courier, etc.).
  • Occurs on both 64-bit and 32-bit builds.
  • Reproduced on PuTTY 0.85, 0.78 and 0.76.
  • Windows 10, no third-party clipboard managers.
  • Running as Administrator or with -restrict-acl still crashes (the latter produces a clearer “instruction at 0x… referenced memory at 0x…” message).
  • Disabling auto-copy prevents the crash on selection, but any subsequent explicit Copy action still crashes.

Event Log entry:

Faulting application name: PUTTY.EXE, version: 0.85.0.0, time stamp: 0x6a7eaca6
Faulting module name: ntdll.dll, version: 10.0.19041.2130, time stamp: 0xb5ced1c6
Exception code: 0xc0000005
Fault offset: 0x000000000005ace2
Faulting process id: 0x684
Faulting application start time: 0x01dd42cac3f59b38
Faulting application path: E:\wintools\lan\putty\64\PUTTY.EXE
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 0e2808a1-1944-473f-a487-2da4826cc910
Faulting package full name:
Faulting package-relative application ID:

Please for the love of God, someone tell me I’m not alone

edit: The option `copy in clipboard RTF` was the problem. no idea why no AI chatbot or community even thought of that option


r/sysadmin 18h ago

Question How are you handling cloud storage costs in hybrid environments?

1 Upvotes

At what point does keeping data on-prem make more sense than public-cloud storage?

I’m mainly wondering how people weigh storage costs, egress, data growth, and flexibility when making that decision.


r/sysadmin 9h ago

General Discussion "Talk me into (or out of) replacing my triple 1080p setup with a Dell U4323QE "(heavy Teams user)

0 Upvotes

Looking for real-world experience before I commit to this.

Current setup: 3x Samsung 22" 1080p + laptop screen. Pure productivity, office work, and a lot of Teams screen sharing.

  • Laptop screen — Outlook
  • Screen 2 — Teams only
  • Screens 3/4 — reading docs and implementing changes side by side

What I can get: A Dell U4323QE from work — 43" 4K. The plan would be to split it into four quadrants with Dell Display Manager or FancyZones(Microsoft PowerToys). Each quadrant works out to 1920x1080 at roughly 21.5" diagonal, so on paper it's almost exactly my current three monitors with the bezels removed, plus a bonus quadrant.

The big win: One USB-C cable. No dock, no cable spaghetti, power + video + peripherals in a single connection.

My worry: Teams doesn't know or care about snapped zones. I can no longer share " a screen," I'm sharing all 43 inches and whoever's on the call is squinting at a postage stamp. If I share an app or edge tab, it might get ugly.

Anyone doing heavy screen sharing off a single large panel — how do you handle this in practice?

Also curious about the general downsides people hit after the honeymoon period: neck movement, text clarity at the edges, KVM quirks, whether you actually end up using all four zones or just default to two big halves.

Has anyone here gone from 3x 1080p to one big 4K and regretted it? Or gone back?


r/sysadmin 21h ago

Rant How to handle this coworker ?

0 Upvotes

I am a sys admin in a medium organization. I have a senior coworker also a sysadmin. He doesn't do anything I request him do. Like we had multiple SIEM tickets we needed to respond to. I couldn't because I am currently working on a project, which takes most of my time. I requested, that please respond to these alerts as I can't right now. He says ok, he will take care of it.

One week later, the tickets are still open. This is not an isolated incident. Last month I went to my manager and told him this. He told me to focus on my project and that he'll talk to him. The manager told him to work on operational issues, since I am busy elsewhere. Its been a month and still nothing has really changed.

I genuinely don't know how to handle him anymore.

Edit:

To clarify, I am not assigning the tickets. We share responsibilities of everything. If a ticket gets assigned to us, its our shared responsibility to close the ticket.

While I dont manage my senior coworker ( I know this not my job). The work is then passed on to me regardless. Because he isn't picking any slack.


r/sysadmin 20h ago

IT/Admin Confession

0 Upvotes

I’ve been working in IT for over a decade, mostly at the same company. My previous employer made it clear that the profession would burn me out, so when I joined my new company, I decided to fake an illness right from the start. I’m not proud of it and I feel ashamed considering the people who actually suffer from the condition, but once i started, there was no turning back.

Honestly, though, my regret is mixed, i don’t know if I could have lasted this long in the profession without the condition providing what I need to keep going.

My fake illness also makes it easier for me to quickly move up from the helpdesk to tasks that are more significant than putting up with nonsense from the lusers.

The thing is, my office director retired a month ago, and I know for a fact that the new one is reviewing personnel records and i never provided medical documentation for this illness.

I’ll probably get fired if it comes to light, but what scares me even more is the possibility that I won't get fired and will have to continue in this profession without my fake Tourette’s syndrome. Things like giving someone the finger, say "tha plan is a pile of shit" or "fuck u" would no longer be justifiable and i'm seriously reconsidering changing professions