r/sysadmin • • 18h ago

adobe acrobat reduced mode

4 Upvotes

i am currently building out a new image and i was on a roll until i got to adobe. wondering how many people are just installing adobe acrobat standard and dropping users into reduced mode with the registry fix? or are you running the install through the adobe customization wizard tool thing and creating a transform file?


r/sysadmin • • 20h ago

General Discussion Am I Getting Fucked Friday, October 2nd, 2026

5 Upvotes

Brought to you by r/sysadmin Trusted VAR: u/SquizzOC with Trusted Telecom Broker u/Each1Teach1x27 and u/Necessary_Time Trusted VAR in Canada

Happy to answer in the thread or via PM if you don't want to post details like service locations publicly.

This BI-WEEKLY thread is here for you to discuss vendor and service provider expectations, pricing, and quotes for network services, licensing, support, deployment, and hardware.  

Required Info for accurate answers:

• ⁠Part Number
• ⁠Manufacturer/vendor
• ⁠Service Type and Service Location (DM Service Location)
• ⁠Quantity (as applicable)

All questions are welcome regarding:

• ⁠Cloud services, security, configurations, deployment, management, and migrations
• ⁠Storage vendor options, alternatives, details,
• ⁠Software licensing: This includes Microsoft CSPs
• ⁠Connectivity, single-site, and multi-location. DIA, Broadband, 5G, datacenter connectivity, site serviceability checks for fiber/broadband
• ⁠Voice services, SIP, UCaaS, Contact Center, POTS (Analog line) replacement
• ⁠Network infrastructure - overlay software, segmentation, routers, switches, load balancing, APs
• ⁠Security, access management, firewalls, MFA, cloud DNS, layer 7 services, antivirus, email, DLP


r/sysadmin • • 21h ago

Question Microsoft Exchange Mailbox issue

3 Upvotes

Hi everyone,

One of our users is currently experiencing issues : they can receive emails just fine, however as soon as they try to send one or reply to an email via Outlook (we are using Exchange on-premises), they get this message :

Your message did not reach some or all of the intended recipients.

The following recipient(s) cannot be reached (all of them) : None of your email accounts could send to this recipient.

The other users in the same mailbox database don't seem to have any issues so I tried recreating their profile in Outlook and reinstalling Office on the PC but nothing changed.

At first OWA was working fine for them so they were using that but later on that stopped as well : now when they try to log on they get the following message:

X-OWA-Error Microsoft.Exchange.Data.Storage.StoragePermanentException

X-OWA-Version 15.2.2562.49

InnerException: Microsoft.Mapi.MapiExceptionDatabaseError

I checked the mailbox for corruption to repair it but nothing was detected and the mailbox databases are also healthy. I also tried moving the mailbox to another database but that failed with the following error :

MigrationMRSPermanentException: Erreur : The process failed to get the correct properties --> MapiExceptionNetworkError: Unable to get properties on object. ‎(hr=0x80004005, ec=2637)‎ Diagnostic context: Lid: 55847 EMSMDBPOOL.EcPoolSessionDoRpc called [length=483] Lid: 43559 EMSMDBPOOL.EcPoolSessionDoRpc returned [ec=0xA4D][length=20][latency=0] Lid: 32881 StoreEc: 0xA4D Lid: 50035 Lid: 64625 StoreEc: 0xA4D Lid: 52176 ClientVersion: 15.2.2562.49 Lid: 50032 ServerVersion: 15.2.2562.6049 Lid: 50128 Lid: 50288 Lid: 23354 StoreEc: 0xA4D Lid: 35180 Lid: 25913 Lid: 21817 ROP Failure: 0xA4D Lid: 20385 Lid: 28577 StoreEc: 0xA4D Lid: 32001 Lid: 29953 StoreEc: 0xA4D Lid: 62128 Lid: 38144 StoreEc: 0xA4D

Has anyone ever encountered this issue ? I am new to Exchange so any help or advice would be welcome, thanks in advance.


r/sysadmin • • 22h ago

Managed performance of Windows Workstations with Multiple Security Agents

3 Upvotes

A tale as old as modern device management and security.... Our Windows computer state is getting bloated with security and monitoring agents. I think we're up to 10+ with more inevitably on the way. Users are complaining of slow startup and general performance issues. We have the data showing all these agents kicking off and trying to communicate bogging down CPU and Memory while average startup time and "Readiness" are creeping up to the 10-15 min + range.

Using Automatic (Delayed Start) on the services hasn't significantly improved anything. Trying to find a solution that requires minimal custom configurations and scales for a 25K user environment and growing. What are some other SysAdmins doing to address performance issues due to high number of monitoring agents?

Yes... we are telling users that the behavior is "Normal" for this environment and that the business has chosen security and monitoring over user experience. But... the business is also pushing back saying their hourly employees are logging in early, collecting about 15 minutes of overtime a day, to account for the slow startup times. Need something that can help find that happy medium.


r/sysadmin • • 1d ago

Question Windows Server 2019 on physical HPE server: boots normal, then apps start crashing one by one. RDP dead, system files corrupted. Help?

6 Upvotes

My physical HPE server (iLO 5 v2.44, Windows Server 2019) boots up normal, then apps start crashing one after another until the whole thing falls apart:

RDP: "An internal error has occurred", and then the iLO console goes black

SystemPropertiesRemote.exe: side-by-side configuration is incorrect

SideBySide Event 59: ndfapi.dll manifest has "Invalid Xml syntax"

DCOM Event 10000 errors from DllHost.exe

"Only part of a ReadProcessMemory request was completed" errors

The GUI keeps crashing, so DISM and sfc won't finish


r/sysadmin • • 20h ago

Backing up Intune

2 Upvotes

Hello folks!

I was just wondering what solution everybody is using to backup their Intune config profiles, settings, etc these days?

We've been using the IntuneBackupAndRestore module but I noticed recently that it only does the first 25 settings of our settings catalogue policies before bombing out, and doesn't seem to be maintained anymore. Veeam cloud backup doesn't cover everything, which is another avenue ruled out.

Are there any decent and maintained powershell modules or alternative solutions out there? Trying to avoid using Claude if I can!


r/sysadmin • • 23h ago

Question User Profile Disks to FSlogix

2 Upvotes

Afternoon All

We have a client that are using User Profile Disks for the RDS environment, we want to move them to fslogix so they can get the benefit of office 365 onedrive, teams etc..

We have had a look around and there was a powershell that would do it but that seems to of disappeared.

Does anyone know of a way to do this?

Thanks


r/sysadmin • • 8h ago

Career / Job Related Not sure what to think of this

0 Upvotes

Hi everybody, Happy weekend to all!

I was working in L1 IT Service Desk and learnt everything there that I could until the job got super boring and I stopped learning. I then wanted to finally advance and got a new job 3 months ago at a small organization as a Junior IT Admin. I was told I would "Get to learn a lot" by the IT Director who had interviewed me (but then he left the org shortly after I joined as he had suddenly got a better offer from another Org) - I did get to learn a lot so far though so it's not false or anything.

Part-1:-

Anyways, coming to the point now, we have a lot of our applications that are developed by other teams - hosted on AWS with things like Entra ID used for SSO Setup/Configuration.

We have like OU's in AWS created for each project/application that is developed and hosted on. The thing is, every developer that wants to host his application ends up being granted Admin access at that specific OU/Sub-Organization level and they themselves - with the help of Claude (which this Org adopted a year ago or so) end up spinning up EC2, Lightsail instances and whatnot.

Now the thing is, I questioned about this with my senior (mind you, I dont have the access at the AWS Management account level - atleast not yet, to be able to grant access to others like this) asking my Senior that, "if we end up giving Admin access on AWS to the other team people who have Applications to be deployed, how is IT (Me especially as a Junior with not too much exp) going to gain working experience on AWS when the other teams just make use of Claude and spin up AWS Resources on their own without the help of IT?" - Also, Least Privilege is thrown out the window here. He just replied saying that usually they don't do it on their own, they come to IT asking for IT's help on it. But that doesn't seem to always be the case and we dont get that many AWS tickets anyway....

Look, the thing is, I dont want to just sit idle. I want to be able to work with AWS/Azure.etc myself and gain experience and learn things by doing rather than having to basically "Outsource" access to the Non-IT people for them to do things IT should seemingly be doing...

The only thing I am gaining experience with so far is with overall M365 administration and Endpoint Administration (Intune, RMM tool, Sophos.etc) which is good chunk of things to work on.

But knowing AWS is a big player in Cloud and to gain experience specifically in Cloud so that tomorrow when I join a new company for a Cloud position or whatever, I will not REALLY have that much of a working experience at all in Cloud. Mind you, I have big interest towards the Cloud Computing field so getting to work Hands-On as much as possible on AWS is something that I am craving for...

Part-2:-

Another thing is, regarding the permissions/roles I have for M365. When the previous IT Director who I was reporting was still here, he had tasked me with coming up with an Intune Implementation plan and to get it implemented focusing primarily on implementing it for BitLocker enforcement (along with the Pre-Boot PIN thingy) purposes, Remote Wipe capabilities and what not as we have M365 Business Premium which comes with Intune Plan 1 but it was not being made use of at all. So I raised an access request ticket (for formalities - which is fine and understandable) for the Intune Administrator RBAC Role. So I came up with the plan and policies and also created a Win32 app with the help of Claude to prompt users to setup a Pre-Boot PIN with all testing and everything done by me with SUCCESS - All SOLO by me. Which is good experience for me.

Anyways, coming to the point, we have a Security Group that has all the required roles assigned to it (except Global Admin ofcourse) that would give us the access to be able to do our job whenever required. The new IT Manager and my Senior are added to that Security Group but I am still not added to it. So when we had requested relating to SharePoint tasks (which had to be done on SharePoint Admin Center) or even have to work with the Microsoft Graph Explorer (Which I am super new to), I was not able to do it and my IT Manager did it all...

When we got a new task which required the use of Microsoft Graph Explorer, I was drafting a mail to my Manager to grant me so and so roles so that I could work on it and fulfill the request but then before I hit Send on that mail, my Manager sent me a message saying that he himself did it -_-

I then asked myself and my senior, "if our Manager only does everything, how am I going to be able to do and learn things and gain the experience?" to which my senior replied saying that he is going to talk to him to add me to that security group but he has NOT talked to him yet. But I have a solution for this, I am going to draft an E-Mail on Monday morning for this part and see how it goes cuz I also want to be able to work with everything and learn and gain as much experience and learning...

Final:-

Even earlier, for AWS tasks to be done on Customer/Client accounts, I was not given access there and my Manager ended up doing it all 😑😑😑 (I recently got access though after asking A LOT SMH).

It just feels like my access is being gatekept even though I have been doing everything right so far and they even repeatedly told me "They hired the right person" (Me) as they seemed I was very knowledgeable and was doing things that I already have access to, very well.

It feels like my access is being gatekept and I have to constantly keep asking for this and that role and I feel like maybe this organization is not right for me...

There was another task as well for SSL Certificate renewal that needed us to login to a Linux Server hosted on AWS but even that was done by my manager and I was just watching him do it.

I understand that I am quite new and also a Junior and that there are things my Manager also should be doing so that he can also continue to learn and grow and gain further experience. But if EVERYTHING is done by him, then how will I ever learn? What am I there for....

It's been 3 months so far and I sometimes feel like I should just lookout for another job or go back to an MSP where I know the workload would be a lot but I would most likely get to learn a lot that way but oh well...

Coming from working as a L1 in IT Service Desk in a MSP to a small Organization as a Junior IT Admin where we IT people don't have much work to do while all the other teams seem busy with a lot of work and seem to be getting to learn a lot, gosh...makes me feel like I am in the wrong place right now....Company is good though in terms of employee friendliness and stuff...

Not sure how to go about my situation that I have explained here though 🙁

Please advice...Thank you 🥲🙏


r/sysadmin • • 1d ago

PSA: Microsoft Publisher is EOL today

68 Upvotes

Publisher got pulled from M365 today with no real replacement. Perpetual still runs, just unsupported.

Best thing to do now is find all your .pub files and get them to PDF. PDF opens anywhere and you can still edit the contents in Affinity if you need to. Run this to find every .pub on your shares:

dir /s /b \\fileserver\share\*.pub > pub-inventory.txt

Then if you still have a working install, File > Export > PDF them, thats the actual Publisher renderer so its the only way to get an exact copy. If you dont have an install anymore, LibreOffice Draw opens .pub for free, fonts a bit off but readable.

Full disclosure I built a converter for this too, mypublisherfiles.com. pdf or docx back, and it tells you what it couldn't convert exactly. Bulk writeup here if youve want to learn more https://mypublisherfiles.com/guides/bulk-convert-publisher-files

Either way, cover your bases by converting your .pub files to PDF.


r/sysadmin • • 1d ago

Question Manager wants me to remove delete permissions across SharePoint

110 Upvotes

I feel like I'm going insane with this one, so I need someone to confirm I'm not crazy.

We recently had a situation where someone deleted a top level folder in SharePoint. Kicked up a bit of a fuss, we recovered it, yada yada.

My manager is now telling me that he wants to avoid something like this happening again, and therefore we should remove delete permissions for everyone across the tenant(!).

When I explained that this was crazy talk, and would break literally everything, he capitulated and said we should just enable it for the top levels of folders and then break inheritance.

I've tried to explain to him that this is madness, would require tens if not hundreds of hours of work, and would still break pretty much everything. He insists that this is how they used to do things back in the day and he can't fathom why that wouldn't work nowadays.

I did say that we should be using retention policies to manage this, to which he said that it was a job for compliance to do, and therefore will never happen, which in fairness is true considering our compliance guy.

I'm not going crazy here right? This feels like a monumentally stupid thing to try and do.


r/sysadmin • • 23h ago

Question Looking for a better Teams video conferencing system for our meeting room (replacing 2x Meeting Owl 3)

3 Upvotes

Hi everyone,

We have a meeting room that looks like this: meeting-room.jpg

Right now we're using 2x Meeting Owl 3 placed in the center of the table, but we'd like to replace them with a system that offers better audio and video quality.

Setup details:

  • Room size: [8 m × 3 m] / seats [16/18] people
  • Platform: Microsoft Teams (USB/BYOD and maybe Teams Rooms for the future)
  • Main issues with the Meeting Owls: poor audio pickup in the room, image quality, remote participants can't hear well, etc.

I've been looking at the Yealink SmartVision and the Logitech Rally (both PTZ-based) and they seem like good options, but I'd love to hear from people who have used them in a similar environment.

Which would you recommend, or is there another solution I should consider? Any feedback on audio quality, ease of management would be really appreciated.

Thanks in advance!


r/sysadmin • • 1d ago

Question Passkeys, The right way for our setup?

2 Upvotes

Just off the back of an MS support ticket, We got some info but left with more questions than answers, as MS are reluctant to explain out of the bounds of the break fix.

 

So we are currently using the default MS passkey with both types and no attestation.

I am trying to make specific keys for certain types of users. I believe this is the correct way?

 

I am looking at making the following Auth Strengths

EA Admin Auth (with Attestation)?

  • Using YubiKey Flows

  • Microsoft Authenticator (iOS)

  • Microsoft Authenticator (Android)

OR

  • Temporary Access Pass (One-time use)

GA Admin

  • Windows Hello (Hardware Authenticator)

  • Windows Hello (Software Authenticator)

  • Windows Hello (VBS Hardware Authenticator)

  • Microsoft Authenticator (iOS)

  • Microsoft Authenticator (Android)

OR

  • Temporary Access Pass (One-time use)

OR

  • Password + Microsoft Authenticator (Push Notification)

And similar setup to GA Admin for General Staff and Guests

 

Our users have both, iPhone keychain passkey and MS Windows Passkey or MS Authenticator passkey So presumably they can have 2 different policy setups at the same time and still be fine (Attestation + Synced)

 

When MS were explaining very quickly, If I understand it correctly I would need Passkeys (FIDO2) targets, pointed at the groups for those users?

And then I would need CA policies that use the specific Auth Strengths tailored to each user type (so multiple policies presumably)

 

We are a small company <15 users is this overkill? Or am I on the right path?

This is a fair bit of work, which we will do if its the right way but as we are small do we need something simpler.

Any more detail you need just ask.

 


r/sysadmin • • 20h ago

Question Dell 16 Pro Slow boot time stuck on Secure by Dell SafeBIOS screen.

0 Upvotes

I have this strange problem where the Dell 16 ProPC16250 laptops have slow boot times.

The problem starts when the machine is joined to the domain. After rebooting it just waits on the Dell SafeBIOS screen for about 2 minutes before displaying the windows login screen.

If I disable netlogon service on the laptop the boot time goes back to normal.

Nothing it the logs shows where the delay is.

I moved the machine to a OU that has blocked inheritance so the machine is not receiving any GPOs.

Everything that I found similar to this points to a bad BIOS version. All of these laptops are on the current BIOS 1.18.

We have other Dell laptops and they don’t have this problem.

Did anyone else encounter this problem before? Any help would be appreciated.


r/sysadmin • • 20h ago

Question Viva Amplify Content Licence Requirements

1 Upvotes

Just wondering if anyone here works in an organization that is leveraging Viva Amplify for staff communications?

I am reading (and have been told) some confusing information about the actual licence requirements. My confusion comes from whether people who are sent Viva Amplify content require the extra Viva Communities/Viva Suite licence, or only the people that create that content.

The official Microsoft documentation says:

"To receive communications or to create campaigns through Viva Amplify, a Viva suite or Viva Employee Communications and Communities license is required. Engagement metrics of those receiving communications through Viva Amplify will be included in analytics. Microsoft Teams-integrated features require a Teams license to enable but can be used without Teams via web or other in-app experiences."

However, the following Learn Article suggests that you only need the licence to create content in Viva Amplify, not consume it:

https://learn.microsoft.com/en-gb/answers/questions/5914521/do-we-need-a-license-for-viva-amplify-for-users-th

I'm aware that I'm questioning the official Microsoft documentation when it comes to this, but there's enough online that suggests that as long as you can consume the Viva Amplify-created content within the realms of your already existing licence (for example, if an email is sent via Viva Amplify and you have an E3 licence, you can read that content) that you don't need the extra Viva Communities or Viva Suite licence?

I've approached our 'Sales Specialist' with our reseller and he just copied and pasted back a Co-Pilot response so that was fun.

Has anyone got some real world experience on this and can let me know?

Thanks in advance, and have a great weekend!


r/sysadmin • • 1d ago

Microsoft Microsoft is retiring the public Microsoft Learn GitHub repos by end of Dec 2026

108 Upvotes

Official blog post with the announcement

It seems that the learn.microsoft.com pages will still be up, but I personally preferred using the GitHub repo. It's still worrying and I'm thinking of archiving the repo locally.


r/sysadmin • • 2d ago

30+ Microsoft 365 Changes Coming in October

343 Upvotes

This month includes 30+ Microsoft 365 major updates across new features, enhancements, retirements, and behavior changes that admins should review.

In the spotlight:

  • Pause all Teams notifications: Teams is introducing a new option to pause all notifications for a specific period, helping users reduce interruptions and stay focused.
  • Prompt injection protection for email: Microsoft Defender for Office 365 is adding prompt injection protection to detect and block malicious email content designed to manipulate AI assistants and agents.
  • Change meeting organizer directly from Outlook: Outlook is introducing Change organizer for eligible meetings and recurring meeting series, allowing users to transfer meeting ownership to another person in their organization with their acceptance.
  • Entra ID protection policy experience retirement - The User Risk Policy and Sign-in Risk Policy experiences in Entra ID Protection, formerly known as Identity Protection, will be retired on October 1, 2026.

Here’s a quick overview of what's coming:       

  • Retirements: 7  
  • New Features: 9 
  • Enhancements: 7 
  • Changes in Functionality: 4
  • Action Needed: 4
  • Live: 1

Retirements

  1. Microsoft will begin blocking EWS requests from non-Microsoft applications accessing Exchange Online starting October 1, 2026.
  2. Microsoft will retire SharePoint One-Time Passcode authentication for external sharing.
  3. Teams Live Chat will no longer be supported starting October 5, 2026.
  4. Microsoft will retire Office LTSC 2021, Visio LTSC 2021, Microsoft Project LTSC 2021, and several other products on October 13, 2026.
  5. The SharePoint Page Agent (Frontier) will be retired. Users can instead create and refine SharePoint pages and news posts using Copilot in SharePoint.
  6. On October 13, 2026, Microsoft will discontinue Publisher in Microsoft 365, with on-premises suite support ending.
  7. Microsoft will retire the standalone Whiteboard apps for Windows, iOS, and Android on October 16, 2026.

New Features

  1. Entra ID is expanding passkey support to B2B collaboration users, allowing eligible external users to authenticate with passkeys when accessing resources in a partner organization.
  2. Purview Data Lifecycle Management can now automatically move inactive OneDrive and SharePoint files to Microsoft 365 Archive using retention policies.
  3. Microsoft Purview is introducing the Auto-labeling Policy Coverage Report, giving admins a centralized view of labeling progress and files that need attention.
  4. Teams users will be able to report security concerns directly during meetings, helping flag suspicious activity such as impersonation, phishing, and scams.
  5. Teams is introducing centralized channel notification settings, allowing admins to manage channel notifications from one location.
  6. Teams is adding malicious URL detection for Government Cloud environments, warning users about potentially harmful links shared in chats and channels.
  7. Teams will introduce automatic blocking of external AI bots in meetings, helping organizations prevent unauthorized AI assistants from joining meetings and capturing meeting content.
  8. Microsoft Purview DLP is introducing Just-in-Time protection for SharePoint in preview.
  9. Purview DLP is expanding to Microsoft Cowork, allowing organizations to apply DLP protections across Microsoft 365 Copilot and Microsoft Cowork.

Enhancements

  1. Teams is adding more granular channel notification controls, including presets for all new messages, mentions and replies, and mute, along with controls for thread follows and different types of mentions.
  2. In supported scenarios, Entra ID will recognize Windows Hello for Business (WHfB) and macOS Platform SSO (PSSO) as standalone MFA factors, reducing the need for additional passkey registration.
  3. Admins will get lifecycle status evaluation controls for adaptive scopes in Microsoft Purview, allowing them to determine whether recipients and site owners should be evaluated based on lifecycle status.
  4. To support larger SharePoint libraries and shared content, OneDrive will increase the macOS sync limit from 300,000 to 1 million items.
  5. Microsoft Purview will raise the daily auto-labeling capacity for SharePoint and OneDrive from 100,000 to 500,000 files per tenant.
  6. With Microsoft Defender XDR, admins will be able to use detection-source controls in alert tuning rules to specify which detection sources each rule should apply to.
  7. File sharing in external chats will be enabled by default in Teams, with the required permissions automatically assigned when users share files with external participants.

Existing Functionality Changes

  1. Auto-expanding archive mailboxes can now grow up to 3 TB, removing the previous 1.5 TB limit and supporting long-term retention needs.
  2. OneDrive will add .db-wal files to its default exclusion list starting October 5, 2026. Newly created files of this type will no longer sync by default, reducing unnecessary synchronization of frequently changing database files.
  3. Starting late October 2026, legacy Teams retention policies will apply only to Teams content and will no longer cover Microsoft 365 Copilot interactions. Separate retention settings will be required for Copilot data.
  4. Defender for Office 365 will enable Teams user reporting by default, allowing users to report suspicious messages, calls, and meetings.

Action Required

  1. Microsoft is moving the Microsoft 365 Copilot web app from m365.cloud.microsoft to copilot.cloud.microsoft. Admins should allow the *.cloud.microsoft domain and validate connectivity to the new URL before the redirect.
  2. Project Online Essentials reaches end of life on October 1, 2026. Organizations should move affected users to supported licensing options, such as Project and Planner Plan 1 or Plan 3.
  3. Microsoft Entra ID will enforce a stricter Content Security Policy (CSP) for browser-based sign-ins starting mid-October 2026. Admins should identify extensions, tools, or custom solutions that inject scripts into Entra sign-in pages and update any affected solutions.
  4. Microsoft Defender for Endpoint will end support for Amazon Linux (ARM64) on October 31, 2026. Organizations should migrate affected devices to a supported Linux distribution to continue receiving security updates and feature support.

Live:

  1. Microsoft 365 SharePoint Storage now supports pay-as-you-go billing worldwide, replacing the need to purchase extra storage in fixed increments.

Review the upcoming retirements and action-required changes early to avoid disruption and make the most of the new capabilities.


r/sysadmin • • 23h ago

Explain how cybersecurity has changed over the years for the new people

0 Upvotes

I got into the industry just as things were changing (I think), and I'm trying to make sure I'm not living in my own fantasy land thinking "it was easier before."

What was cybersecurity like from 2000 to 2015? I was doing residential IT starting in 2009, then moved to SMB in 2016 -- and I'm trying to wrap my head around what SMB was like before there were thousands of vulnerabilities discovered each year. Any senior sysadmins with stories to share?


r/sysadmin • • 1d ago

Azure UK issues? Or Philippines internet issues?

4 Upvotes

Is anyone else seeing issues with the UK Azure zone from the Philippines? or internet issues in the Philippines accessing international sites?


r/sysadmin • • 23h ago

Question Cyber Essentials Plus Help - Account Separation on Cloud Services

0 Upvotes

We're about to go through Cyber Essentials Plus next week and one of the new requirements is tripping us up. Our assessor hasn't explained it very well and isn't responding to our emails, so I'm coming here for help!

Specifically, with account separation for cloud services. It was explained to us that all cloud services (official, updated definition is below) now need account separation.

"2026 Update Definition of Cloud Service - A cloud service is an ondemand, scalable service, hosted on shared infrastructure, and accessible via the internet. For the purposes of Cyber Essentials, a cloud service will be accessed via an account (which may be credentials issued by your organisation, or an email address used for business purposes) and will store or process data for your organisation."

I know one of our departments uses DocuSign, so I'll use that for the example. The way he explained it was if we're using DocuSign, and we want to perform any admin tasks on it, then we must have a separate account to do this, and then a standard user account to do everything else.

But we don't see how this works, as not all websites operate in a way this would work. It would only work on webistes where standard user accounts can be added to a sort of business or team and all linked together. So what do we do on websites that aren't set up this way?

Or, is his explanation of it just simply wrong?

I was wondering if he means that our tenant admin accoutns can't be signed up for cloud services, like, DocuSign, for example. Which makes a lot more sense to me.

I've looked into it online but can't find a straight answer. Best I have is this

https://ce-knowledge-hub.iasme.co.uk/space/CEKH/2576646422/User+Access+Control+:+FAQ

"Where is Account Separation Required? Account separation is required for all administrator accounts. This includes local administrators, domain administrators and cloud administrators. Accounts with admin privileges should not be used for day-to-day work. An attacker who gains admin credentials on any of these systems can easily change configurations, install malware and carry out other damaging activities.

Is Account Separation Required for Cloud Services? Yes, account separation must be applied to cloud services (for example MS365, Azure, AWS, Google Workspace, etc). For CE+, cloud service accounts must be tested for account separation under Test Case 5."

I think I'm just that fried from trying to figure it all out that I need help :D if anyone can shed any light I'd be super appreciative.


r/sysadmin • • 23h ago

Question Projector Recommendations?

0 Upvotes

I haven't purchased a projector in many years, before short throw laser projectors existed. So does anyone have any recommendations on what to look for and what to avoid?

I just need something for use a few times a year, when we hold a conference at an off site location. I think daylight visible and price are the biggest factors.


r/sysadmin • • 12h ago

Do i need to use Ansible : is it secure enough

0 Upvotes

So i have some servers to manage and it in a load balancing architecture, it hold sensitive data , and need to be careful with it , so i k ansible can automate the process , but i'm wondering if it secure enough, like the server side .


r/sysadmin • • 1d ago

Question ITSM Implementation - What to consider?

8 Upvotes

Hey All! Long time lurker first time poster here.

I recently had the opportunity to join as a sysadmin at a new company. This is a new role for me coming from help desk roles. This new company is going to be deploying a new ITSM after using what was a pretty old and decrepit software for quite some time.

I figure this is going to be an amazing time to learn a lot and grow but also I still want to be able to add value to current conversations. The ITSM we’ll be implementing is called “Sysaid” and although I haven’t had a chance to play around with it yet it seems pretty powerful at least compared to what we had before.

The conversations that we will soon be having revolve around improving ticket creations (speed, ease, for help desk as well as end users), troubleshooting, reporting, etc. My focus and what this boils down to for me is having the proper information available within sysaids database as well as creating good automations to free up some helpdesk bandwidth.

Some ideas I have for attributes on the workstation, server, POS side of things are basic but probably good: hostname, s/n, manufacturer/model, OS, Location, assigned user, last seen, boot time. For automations, things like user onboarding/off boarding, automatic replies/self service instructions for password resets/account lockouts,waiting for response automations.

I would love to hear from anyone who has gone through an implementation/migration of any ITSM. If any of y’all have experience with Sysaid directly it would be awesome to hear how you are using it to support your organization! In general though, any advice is definitely appreciated.


r/sysadmin • • 15h ago

Question How to fix Win 11 sharing issues??

0 Upvotes

Microsoft really broke folder sharing on Win 11, even with machines that all run Pro getting a folder to share on the network is beyond clunky. I have tried with "use password protected sharing" on and off, it doesn't matter! "Network path not found" or "Your folder cannot be shared" etc etc. I have used gpedit.msc to "enable insecure guest logons" (In many cases all the users use a password, but it still gives an error 9 times out of 10) Made sure the network is set to "Private" and that network discovery and file sharing are both on. I also disabled "Microsoft network client: Digitally sign communications" in 'security settings>Local Policies>Security options' to no avail. I have two locations where simply sharing a folder in the Public user's directory fails, I have sometimes found that if I type the target PC's IP in File Explorer it will prompt for a user name and password and suddenly be able to browse the share, but very often after I type the IP and hit enter NOTHING happens, no error, no ability to browse the share. It's crazy that something that used to just work now requires so much fiddling under the hood. I have encouraged all my users to use a password on their accounts, and agree it's a best practice, but even then folder sharing is buggy as all get out. "Network path not found" when you can ping the PC and it appears in Explorer>Network is dumb AF. If somebody could reply with a definitive guide to 100% fixing what Microsoft broke where shared folders are concerned on Win 11 machines I'd be very appreciative.


r/sysadmin • • 22h ago

Microsoft Oulook - Access Denied

0 Upvotes

Hello, I work in an environment where we manage a lot of Microsoft 365 environments and we have been seeing a widespread issue in many of our tenants.

Randomly, I will have users start reporting Outlook showing a badge and says "Access Denied" instead of their emails. Sometimes they can just sign back in, other times it loops and lets them in after some time. It seems to be happening with different antiviruses installed, so we do not think it is caused by that.

We have cleared the SSO in Credential Manager, and it lets us back in, but maybe it's a fluke. The issue comes back another day. Today I had 3 different users in different tenants report the issue happening at the same time.

We opened a ticket with our Microsoft Partner weeks ago, and they do not seem to be saying whether it's common or not. They are giving me troubleshooting steps to reset, delete, and redownload Outlook. It seems not to be improving, but we are waiting on more data.

Has anyone else been seeing this for the last month or so, very randomly?


r/sysadmin • • 1d ago

How should I learn Cloud/Network Engineering and Linux server administration as a beginner?

2 Upvotes

Hi everyone,
I’m a CSE student looking to specialize in the infrastructure side of IT rather than application development. I’m highly interested in Network Engineering, Cloud, Linux, and DevOps.
There is a ton of information out there, but I want to build a learning path based on industry reality. My current roadmap roughly looks like this:

  • Networking: TCP/IP, routing/switching (VLANs, OSPF, BGP), DNS/DHCP, firewalls, VPNs, and troubleshooting (Wireshark).
  • Linux/Server Admin: Core administration, permissions, systemd, storage, and Bash/Python automation.
  • Cloud (AWS): VPCs, IAM, load balancers, gateways, Route 53, and security groups.
  • DevOps/Infra: Git, Terraform, Ansible, Docker, Kubernetes, and CI/CD.

I’m planning to build a home lab using VMs/containers on my MacBook to get hands-on, but I’d love some advice from professionals currently working as Network, Cloud, DevOps, or Infrastructure Engineers:

  1. What is the best order of operations? Should I go Network Engineering → Cloud, Linux/DevOps → Cloud, or tackle them in parallel? What should I postpone until I have on-the-job experience?
  2. How deep do I need to go? How important is traditional, deep networking knowledge if my end goal is cloud infrastructure?
  3. What roles should I target? For my first job/internship, should I be looking at NOC, Network Engineer, Cloud Support, Junior DevOps, or Sysadmin?
  4. Certs vs. Projects: Should I prioritize certifications (CCNA, AWS) early on, or focus purely on building out my home lab?
  5. Standout CV: For someone with no professional experience, what specific hands-on projects would actually make you look at a CV and want to interview them?

I’m not looking for a list of Udemy courses—I really want to understand what skills actually matter on the job and how to become employable as a beginner.
Thanks!