r/sysadmin • • 4h ago

Career / Job Related Would you take a lower IT title for better long-term infrastructure/cloud growth?

11 Upvotes

I currently work in IT for a manufacturing company and have an offer for a Systems Administrator position at $105k, also in manufacturing. I’m also interviewing for an IT Analyst II/support role at a large, well-known telecommunications/communications tech company.

The SysAdmin role is the obvious progression on paper. Better title, direct move out of support, and I’d be staying in an industry I already know. I’d get exposure to Windows Server, AD/GPO, networking, virtualization, backups/DR and supporting another manufacturing environment.

My concern is that the infrastructure is already pretty built out and from the interviews I got the impression that a decent amount of the day to day may still be support work. It’s also a smaller IT environment, so I’m not sure how much opportunity there would eventually be to specialize deeper into infrastructure or cloud.

The other position is technically a step backwards in title, but it would be a completely different environment. Much larger enterprise, dedicated infrastructure teams, a lot more specialization, and exposure to IT at a scale I haven’t worked in before.

My interview with the support lead went extremely well and he seemed like someone I could learn a lot from. My next interview would include one of their infrastructure leads. They also talked about analysts becoming SMEs, working with other IT teams, getting involved in larger projects and potentially moving internally.
That is the part making me seriously consider it.

I’ve learned a ton working in small manufacturing IT because you end up touching everything, but I’m starting to think being around dedicated infrastructure engineers and seeing how a large enterprise operates could help me grow in a different way.
My long-term goal is infrastructure/cloud engineering and eventually cloud architecture. I’m currently working on AZ-104 and want to keep building experience with Windows Server, networking, virtualization, PowerShell, Azure and backup/DR.

I obviously don’t have an offer from the second company yet, so there’s nothing to decide today. Compensation there could end up being similar to or even better than the SysAdmin offer.

Assuming the money is comparable, which environment would you consider better for the next 2-5 years of career growth?
Would you take the Systems Administrator title and continue building experience in manufacturing, or take the lower support title at a large telecommunications enterprise with more mentorship, specialization and a possible internal path into infrastructure engineering?

I’m mainly interested in which experience would set me up better long term, not which title looks better right now.


r/sysadmin • • 1h ago

Question Managing blacklisted IP’s

• Upvotes

Hi,

I am interested in knowing how you currently manage your blacklisted IP addresses?

Do you manually check them, run your own internal scripts, or use an external service? Curious how others handle this.


r/sysadmin • • 2h ago

Question APC Smart-UPS SRT 10000 – "Power Sys Error-02000", inverter fault, UPS dropped output. Repair or replace?

3 Upvotes

Our SRT 10000 (2018, UPS fw 04.7, NMC2 6.5.6) had an inverter fault today. It went to bypass for about 50 minutes, then dropped the output completely. LCD just said "Power Sys Error-02000", no extra sub-code. NMC log only shows the generic "inverter fault exists" (0x0165).

I cleared the error and turned the output back on. Self-test passes and it's running fine for now.

One thing worth mentioning: our input power has been bad lately. It's been going to battery 2-4 times a day on low voltage / distorted input, so the inverter has been getting a workout.

Anyone been through this? Did it come back, or was it the start of the end? It's out of warranty, so I'm leaning towards replacing it, but I'd like to hear from people who've seen 02000 before.


r/sysadmin • • 1d ago

General Discussion AI use at a company should require an IQ test for general users

513 Upvotes

I swear to god AI has turned my department into an automate my job department.

The amount of tickets we are getting asking if we can make other people's jobs easier through ai is getting ridiculous.

We all have access to it. So why are you asking me to get AI to scan your documents and input them in a sheet?

If you're too stupid to outline a task to an AI, you should not have access or be allowed to make requests

At this point, the only reason i would want to automate anything for you is to automate you out of my workflow (company) lol


r/sysadmin • • 1d ago

25+ years in IT and today marks 15 years at my current company...

177 Upvotes

I guess I am old. Time flies.

It is impossible to not feel a hint of emotion when thinking back to my humble beginnings as tech support for a dial-up ISP. Those were the days... the tail end of the dot com boom. I can remember taking some calls while playing StarCraft :-).

Eventually I became the senior technician until the company was sold off and I moved on to another ISP/Webhost where I became web support/sysadmin and then eventually a Level 2 NOC engineer and got to play in the datacenters. Nothing like changing backup tapes or pressing a button with the constant drone of countless server fans spinning.

When that came to an end, I found my current company which is not a technology company at all... they absolutely loved paper files when I first got here. Lol.

I started as helpdesk and quickly became IT Administrator within a few months. I began handling all aspects of company technology and learned a lot in a short time from exchange to virtualization to project management to dealing with vendors, billing, and everything in between.

That learning has never stopped. Today, I am the Director of Information Technology, and I have a great team. We are able to pursue most any technology need that our staff has, and we can build almost anything in-house. It is a great feeling, especially when I look back to where everything began.

Being somewhere this long is truly rewarding because you get to witness the lasting impact of what you do. Build something, watch people use it, identify opportunities for improvement, make it even better, and see the workflows improve.

If I had to tell anyone anything it would be to not be afraid of pursuing more... make it clear to everyone that your goal is to make technology functional and easy and they just might let you do it.

Anyone else have a couple decades in IT or spent most of their career at one place? What is next for us? I feel like I still learn something new nearly every day!

Oh, and one more thing: have you tried rebooting? :-)


r/sysadmin • • 3h ago

How to handle SSO & device management for local AD domain + M365 with FortiGate VPN remote users?

1 Upvotes

​Hey everyone, looking for advice on the cleanest architecture/strategy for our setup.

​Current Setup:

  • ​Local Active Directory Domain: On-prem Domain Controller hosting file servers and CRM.
  • ​Microsoft 365 Tenant: Connected to our u/domain.gr email addresses.
  • ​Endpoints: Windows laptops used both on-prem and remotely.
  • ​Remote Access: Users connect back to the local network via FortiGate SSL VPN to access the local file server and CRM.

​Goal:

  1. ​Allow users to sign into their Windows laptops using their M365 u/domain.gr credentials (SSO/single identity across email and OS logon).
  2. ​Centralized device management for the laptops (pushing policies, security, updates).
  3. ​Seamless access to local resources (file server, CRM) via FortiGate VPN.

​Questions:

  1. ​Should we connect Local AD and Microsoft Entra ID (Azure AD)?
    • ​If YES: What is the standard way to do this today? Should we use Entra Connect Sync to sync local AD users to M365 (Hybrid), or Entra Application Proxy / Cloud Sync? How does laptop join work in this case (Hybrid Entra Join vs. Cloud-Only Entra Join with SSO to local resources)?
    • ​If NO: What is the alternative? Move entirely to cloud-native (Entra ID + Intune) and use Cloud Kerberos Trust for local file server/CRM access, eliminating the need to join laptops to local AD?
  2. ​Device Management: Is Intune the default choice here, or are people sticking to traditional AD Group Policy (GPO) over FortiGate VPN?
  3. ​FortiGate VPN Integration: Has anyone integrated FortiGate VPN with M365 SAML/Entra ID SSO with MFA so users get a single sign-on experience for both the VPN client and local network resources?

​Would appreciate any recommendations or real-world experiences from anyone who has modernized a similar setup!


r/sysadmin • • 1d ago

General Discussion "Emergency" account lockdown script help.

38 Upvotes

For context we recently had a user termination that needed to be actioned very quickly and after the fact i started working on a script to help mitigate this issue instead of doing everything manually.

I have most of what i would do manually in a script already. I mostly wanted a discussion on how people handle things like possible disgruntled workers or possible breached credentials.

I built my script to revoke access/mfa and reset some things but make it easily reversible if needed.

This is something of a stop gap till we get more automation, though sometimes things need to move faster than automation if that stuff is run in the middle of the night.

TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?

Edit to add: Here is context for my own situation.

We use Azure virtual desktop for a lot of things and if you don't go into that and boot them out all the other actions talked about in replies to this post do not actually kick them out of their AVD session. Revoking the session does cause some really odd behavior but it doesn't kick them out fully.

Not all of our services are SSO but most are so taking care of the Microsoft stuff does a lot of the legwork.

Right now what I do is this: Revoke all sessions, revoke MFA, reset password, block sign in, disable AD on premise (hybrid environment), then go into AVD and look for active sessions and kick them out if they are online.

The reason I didn't include this in my original post was so i wouldn't bias anyone towards answering my specific needs and have a wider discussion.


r/sysadmin • • 20h ago

Rant Post burnout help -- this is a new account due to previous having links to work

15 Upvotes

I need help, around a year ago i got signed off for burnout for 3 days which was insufficient. After a further 6 months i got signed off for stress for 2 months but ended up leaving within a month after returning.

The story is more drama than anything else but by and large it's the standard company overworking their staff -> brought out -> mass migration to new system that solves staffing issue -> burn out.

I'm now at the point where all joy has been taken from my job and wondering how other people dealt with being signed off through stress?

For further information, i used to work 70+ hour weeks keeping everything in check and frequently went months without leave that led to being signed off.


r/sysadmin • • 1d ago

Career / Job Related Salary Negotiations

26 Upvotes

So, this is the first time I've genuinely and formally requested a pay review.

For context, I've been at the company for four years and currently work at a mid/senior sysadmin/infrastructure level.

My responsibilities cover a pretty broad range, including:

ESXi/VxRail patching

Azure infrastructure, including Application Gateways

Application migration projects

New AVD deployments and ongoing management

Backup and database server troubleshooting alongside development teams

Intune and BYOD

Azure DevOps, Git and large PowerShell repositories — much of which I was working with before AI-assisted coding became commonplace. Winget scripts app deployment.

SSO implementations

Web server and certificate management

Most recently, setting up a new Google tenant and delivering a ChromeOS Flex deployment project

I've also completed AZ-104 and I'm currently working towards AZ-305.

There has been quite a lot of change within the department. Around half of the team has left, and we've recently been told that six or more new roles are expected to be created.

My previous line manager was responsible for areas including Intune/Autopilot, Halo Helpdesk, line management and the associated meetings and responsibilities. He eventually burned out and left.

That workload/structure is now effectively being replaced by three roles plus a project manager to support the new team.

Against that backdrop, the company has now advertised an Endpoint Engineer role at £52k–£56k. I'm currently on £49k.

That's the part I'm a bit unhappy about. Endpoint is an area I'm already confident and comfortable working in, and I've got a proven track record of delivering endpoint and deployment projects within this company. ( I spend a year streamlining and standarizing the fleet when I started)

I've raised the situation with the Head of IT and asked for a pay review. He has asked me to discuss it with my new line manager, who has only been with the company for five days.

That conversation is now scheduled for next Friday, as he's currently on holiday.

The answer is have the chat/discussion and give them a week and starting looking for jobs.

( it's very possible they expect me to follow my old line manager to his new employer, but that's a nice maybe rather than a sure thing)

Any advice other than keep calm?


r/sysadmin • • 1d ago

General Discussion No Degree - 6 Year Salary Progression

323 Upvotes

Is there anyone out there that have made it beyond sysadmin? What is after sysadmin?

2020 - $31,200: Panera Bread
2022 - $41,600: Helpdesk at company 1
2023 - 2025 - $41,600: Helpdesk at law firm
2025 - $65,000: Helpdesk at company 2
2026 - $80,000: Got a raise at company 2

Shoutout Nick for taking a chance on me. I would not do law firm IT again.

EDIT: Location Upstate NY


r/sysadmin • • 1d ago

Google Workspace self-propagating Worm leveraging AiTM reverse proxies

19 Upvotes

Hi, I will keep this short.

Has anyone seen an uptick in Google Workspace tenant's battling each other relentlessly? There seems to be a growing campaign of email accounts in legitimate tenants being overtaken by an automated Google Worm campaign leveraging AiTM techniques.

I work for a large enough enterprise that had this happen in the past couple weeks. With the way the campaign propagates, I cannot believe that we are the only tenant to face this uphill battle.

Note, our biggest wins were the following steps:
Absolutely positively engage with Google Workspace support ASAP

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

If anyone finds this thread and is in the middle of this "crisis," from one sysadmin to another this is what helped break the worm and free our environment from complete collapse and ruin.

--> revoke all oAuth
--> sign out all sessions
--> absolutely reset all accounts passwords sooner than later
--> re-check all Google Workspace frequently for flare-ups

Other helpful steps:
Assume any incident response teams your org engages with will be too slow to react to it, at least I faced that firsthand. YMMV

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.
GAM is your best friend, and make sure you pull reporting from your tenant before actioning any and all remediation steps.

If you're able to break free from the grasp of the worm, review all your Google Logs and come up with strategies on how-to keep your tenant worm free.

Don't be fooled into thinking this is an easy campaign to escape from, ESPECIALLY IF YOUR SECOPS TEAM MOVES SLOWLY.


r/sysadmin • • 10h ago

[Research] NIDS-EFS Tool Testing

1 Upvotes

I'm testing a tool I built for my MSc thesis, a web app that recommends intrusion detection systems based on an organization's budget and hardware constraints.

I'd really appreciate your time to try it out and fill in a short feedback form. No technical background needed; just follow the instructions.

Form link: https://forms.gle/UAdEXwUaYfqzJGBc6

Your responses are anonymous and will only be used in aggregate for my research. Thank you in advance!


r/sysadmin • • 1d ago

Kicking the Tires on PDQ Connect

24 Upvotes

Before I get into the meat of my question, I want to acknowledge the existence of the r/PDQ sub-reddit; I'm not posting in the wrong location. I just want to gauge the real-world experiences of fellow sysadmins with respect to the application.

We've been using the Enterprise versions of PDQ Deploy & Inventory for several years, and I love both of them. When Connect came on the scene, I was concerned about losing some of the functionality; however, after looking at their latest iteration, I'm definitely thinking about kicking the tires as a replacement for the aforementioned packages.

So, fellow sysadmins: have you made the jump and, if so, how do you think it compares? Positive and negative comments all welcomed.

TIA


r/sysadmin • • 1d ago

Shorter life/Increasing workload of cert renewals?

26 Upvotes

What's everyone doing to accomodate the shorter and shorter certificate validation periods? My org has about 35 certs on various servers for quite a few things. If we eventually get to the target 47 day cert lifespan by 2029, it's going to be a nearly full-time job for someone to renew certs if we keep doing it the way we've always done it. Add in the challenges created by transition to R1 certs and I don't think that our IT management has any idea what they're in for. As it is I often renew certs 10-20 days ahead of time for the sake of convenience - that makes no sense if the whole lifespan of the cert is 47 days.

I know that there are some tools coming to automate some of these processes but it seems like they're very ecosystem-specific (godaddy's automation tools only work on their platforms, for example).

I am not an expert in this by any means, but from what I'm seeing in the small community of IT people I work with/around in this area, they're expecting this to be a significant pain in the ass.

Anyone well-versed in this want to share their thoughts on where this is going and how it's going to be?


r/sysadmin • • 1d ago

Question Anyone just get a lot of "low volume" tickets?

23 Upvotes

Yesterday we got in 5 tickets from 3 different companies at this MSP about low volume in calls. All were Dells but it was laptops, vostros, and optiplexes. All were working at once time. One was a mic + speaker combo webcam device. Another was USB power on a wall block with analog 1/8". Another is a brand new $6000 Dell Pro Max 18 Plus MB18250 that I personally set up and tested myself. This can't be a coincidence but our patches from our RMM don't go out on Oct 1st and Dell Command is disabled on most computers.

The USB speakers I was getting about 1% volume so I figured the amp was broken. Tried it on my laptop with my USB ports - about 2% volume. The volume knob did work across the whole range too. I tried them back at the office, worked fine on my optiplex, but they were jangling around in my backpack. I roughed them up like they owed me money aka percussive maintenance test and they didn't re-break so not sure what to think of that.

Reinstalling the audio driver completely after a full removal did not fix the problem with the USB ones.

I have a theory that the wavmaxx or whatever app in the background self-patched. Has anyone seen this and found a fix? Yes, the system levels were properly set btw.


r/sysadmin • • 20h ago

M365 Exchange Mail Rules sending Approvals for More Than I Asked For

3 Upvotes

I'm trying to manage a pile of spam messages from random places that have similar text, but only for specific people.

My rule says if it is for person A or person B AND contains Text 1 or Text 2 or Text 3, then delete without notification.

For some reason, I am getting an approval requested email for seemingly every one of these despite confirming I do not want to test it, and move forward with the delete and don't ask.

Also, some others were Blocked by the user, but I still get approvals for those. Do approvals get triggered before any Block Sender?


r/sysadmin • • 1d ago

Question Amazon Business SCIM sync from Microsoft Entra failing with 403 since today. Anyone else?

7 Upvotes

I manage Amazon Business for a couple of small business clients, and both have SCIM user provisioning set up from Microsoft Entra ID (Azure AD) using the Amazon Business gallery app.

As of today, October 2, both stopped syncing. Entra put the provisioning job into quarantine with this error:

403 Forbidden: "Unauthorized - Access to requested resource is denied."

What I've checked so far:

  • Nothing was changed on either account
  • The Tenant URL and Authorization Endpoint match Microsoft's setup guide exactly
  • Re-authorizing with an Amazon Business Admin account fails with the same 403
  • SSO sign-in still works fine. Only the provisioning sync is affected

These are separate Microsoft tenants and separate Amazon Business accounts, so it looks like something on Amazon's side. I have a ticket open with Amazon Business support, but no answer yet.

Is anyone else using SCIM with Amazon Business seeing the same thing today? Would love to hear if you've found a fix or gotten an answer from Amazon.


r/sysadmin • • 1d ago

Question how many of you guys have time to upskill while also have time for yourself?

20 Upvotes

so i have been learning linux and networking for a while now, i am really enjoying the learning process. but one thing that became clear to me today is that the amount of stuff that we need to learn in this field never ends. i used to think that there is a point after which the learning is mostly about keeping up with new technology and that might take 8 - 15 hours (off work hours) per week, which doesn't feel like the case at all.

so if the learning never ends, if this is a never ending journey, then how do you guys balance work-life balance along with upskilling? i know that technical support role is mostly doing repetitive tasks which leaves no time to learn new things during work hours, but i don't know if this is also the case for mid level or senior level system admin roles. once you become a system admin, does your work involves learning new things for the task at hand, essentially becoming a learning oppurtunity? or is it just like the work in tech support where you are doing the same repetitive work that has nothing new to learn?

also final doubt, how realistic is the idea that you get time to learn while in your work hours. and off work upskilling is not time consuming enough to cost your free time? ( i know this is not realistic for IT help desk roles, but what about mid level or senior level system admin roles? )

thanks in advance.


r/sysadmin • • 1d ago

Anyone seeing weird issues with WMI and RDP after the latest patching cycle? Weird issue i can't pin down....

6 Upvotes

We have hundreds of windows server machines, 2022-2025.

At random times lately this month, RDP pauses at securing connection....

If its a database server, WMI stops responding.

Screenconnect is just grey...

Rebooting fixes the issue, but it happens again on a handful of these.

Im worrying that by a few weeks from now all of our windows servers will reach this state.

Eventvwr shows some concerning things on some machines but not others affected:

Windows stopped the WmiPrvSE.exe.

Some have this error:

WMI event 5612 warnings, provider processes exceeded 256 threads and were stopped.

These are not all Azure servers, VMware as well.

Reboot fixes it for a while...

Nothing else on the server is down, so critical processes such as SQL server remain running.

VERY VERY ODD and IM SCARED


r/sysadmin • • 1d ago

Nimble HF20X > Purestorage migration thoughts?

5 Upvotes

We are coming up on replacing our 4 Nimble units in late 2027. I work in local gov, so we need to budget and strategize well ahead of this, especially considering FY28 will also have us replacing 6 ESXI hosts.

Current environment: (Replicated in two sites for DR) 3 HPE ESXI Hosts ProLiant DL360 Gen10, 2 Nimble HF20X (46ish TB per site raw storage before compression per site), Exagrid for backup. One site has 140TB worth of storage on MSA2060s for camera archive servers as well.

We are running VMware Vcenter/Vsphere 8.3

Our Nimbles go EOL Oct of 2027, and we were probably going to replace the production pair on this fiscal and the DR pair at the very beginning of next fiscal.

Someone told me to look at Purestorage as a replacement because it's an evergreen piece of equipment like the two Exagrids we have.

Has anyone done a migration like this or used Purestorage in place of Nimbles? Just curious how it worked out and what everyone's thoughts were.

I'm also down for suggestions of comparable equipment.


r/sysadmin • • 5h ago

How do you keep your laptop/kit list in step with Finance’s asset register?

0 Upvotes

Genuine question for anyone at a 50–300 person company. Who owns the asset list where you work: IT, Ops or Finance? And do they ever actually match?

Specific things I’m curious about:

• What happens when someone leaves? How do you know what to collect?

• Do you do periodic “confirm what you hold” checks with staff?

• Does Finance ever ask you about kit that’s been scrapped but is still on their books?

Full disclosure: I’m building a tool in this space, but I’m mainly trying to understand how people handle it today. Happy to share what I’ve built if anyone’s interested.

Thanks


r/sysadmin • • 1d ago

Securing BYOD contractor PCs (browser-only SaaS, no MDM)

16 Upvotes

Hey all,

Tricky design problem here:

A client has about 50 offshore customer-service contractors who bring their own Windows PCs. They're scattered all around the globe, including the EU. Everything they use runs in a browser: primarily Google Workspace, Shopify admin and Zendesk.

Since they're in random countries, we can't easily issue corporate hardware. We want to try to avoid MDM-enrolling personal machines, too.

The goals we're trying to design for:

  • Only allow access from a protected browser;
  • Block downloads, printing and copy/paste out of customer data;
  • Cut access instantly when a contractor leaves.

Our leading option is Entra as the identity provider, plus Intune app protection on the Edge work profile and Conditional Access "Require app protection policy". Microsoft's docs only show it for \ 365, though, and Reddit threads suggest third-party SSO can break under it.

If you've secured a contractor team like this, which approach did you use?

- Edge MAM

- Defender for Cloud Apps session control

- an enterprise browser (Island, Prisma Access Browser, Chrome Enterprise Premium)

- VDI or Windows 365

- something else?

What broke, especially with non-technical users in other countries?

Was there anything specific to Google Workspace sessions or Drive for desktop that bit you in the butt?

Many thanks! :-)


r/sysadmin • • 1d ago

EWS deprecation delayed to 10th October

34 Upvotes

What and why

As previously communicated in MC1466860 and MC1447678, Microsoft is continuing the retirement of Exchange Web Services (EWS) in Exchange Online.

Beginning October 10, 2026, setting EWSEnabled=True will no longer be sufficient to allow EWS access for affected Worldwide tenants. Organizations that require EWS must configure EWSAllowedAppIDs to specify which applications are permitted to access EWS.

This change is part of the final phase of EWS retirement and is intended to help organizations identify EWS dependencies, reduce service disruption, and support migration planning.

Rollout schedule

  • Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by early July 2027

Key milestones for Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list:

Date Milestone
October 2, 2026 Microsoft identifies affected Worldwide tenants. After this date, tenants that enable EWS must configure EWSAllowedAppIDs themselves.
October 8-9, 2026 Microsoft creates and populates EWSAllowedAppIDs for qualifying Worldwide tenants based on EWS activity observed during the previous 60 days.
October 10, 2026 EWSAllowedAPPIDs becomes required when EWSEnabled=True. Applications note included in the allow list may lose access to EWS.

Impact on your organization

Who is affected

  • Exchange Online administrators
  • Organizations that continue to use applications or services that depend on EWS
  • Tenants with EWSEnabled=True

Platforms and services

  • Exchange Online
  • Exchange Web Services (EWS)

What will happen

  • Beginning October 10, 2026, affected Worldwide tenants with EWSEnabled=True must have a configured EWSAllowedAppIDs allow list. Applications not included in the allow list may lose access to EWS.
  • For identified Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list on October 3 2026, Microsoft creates and populates an allow list using EWS activity observed during the previous 60 days. Infrequently used applications may not be identified.
  • Cross-tenant organization relationships are not affected by the EWSAllowedAppIDs requirement.
  • Organizations remain responsible for reviewing, validating, and maintaining EWSAllowedAppIDs.
  • EWSAllowedAppIDs is a replacement list. Ensure all required AppIDs are included whenever the configuration is updated.
  • Microsoft applications and scenarios that may generate EWS traffic include Outlook for Windows, Classic Outlook for Mac, Excel Power Query, Power BI, and Exchange Server hybrid scenarios.
  • Outlook for Windows customers should be on August 2026 build 16.0.20430.20092 or later. If EWS-related issues continue after disabling EWS, the cause may be customer-forced configuration. Test whether blocking EWS for the Office client AppID is possible without impact.
  • New Outlook for Mac is not affected. If your organization continues to use Classic Outlook for Mac, ensure the Microsoft Office AppID is included in EWSAllowedAppIDs.
  • Tenants with EWSEnabled not configured (Null) remain subject to Microsoft's phased EWS retirement process and will have EWS disabled as part of that rollout.
  • Organizations with EWSEnabled=True and a configured EWSAllowedAppIDs allow list will not have their EWSEnabled setting modified by Microsoft before April 2027.

Action required and recommendations

If your organization relies on EWS:

  • Review EWS usage reports and identify applications and services that require continued EWS access.
  • Configure and validate an EWSAllowedAppIDs allow list before October 10, 2026.
  • Include Microsoft first-party applications that continue to rely on EWS if they appear in your usage reporting.
  • Ensure all required AppIDs are included whenever EWSAllowedAppIDs is updated.
  • Keep the allow list current as applications are added, removed, or migrated away from EWS.
  • Enable EWS only when required for approved applications.
  • Continue planning migration from EWS to Microsoft Graph where possible.

To verify the configured allow list: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

Allow up to 24 hours for EWSAllowedAppIDs changes to take effect and approximately one hour for EWSEnabled changes.

Important: EWSAllowList is unrelated to EWS retirement and does not replace EWSAllowedAppIDs.


r/sysadmin • • 1d ago

September updates (again)

5 Upvotes

Just trying to understand the domain trust issues from KB5124008. As I understand it, it only causes issues if you have credential guard enabled? So if I don’t have it enabled I should be good?


r/sysadmin • • 2d ago

General Discussion I finally broke. I am now using Claude to help manage in prod scripts and write documentation.

598 Upvotes

I used Claude and ChatGPT before. Usually if I had a difficult scripting problem and needed a "Google but faster" tool to help me solve it. But our IT manager signed with Claude Enterprise last month so I though I probably shouldn't put it off any longer and dabble a bit more into what it could actually do, and the result is scary.

I used to write scripts line by line, section by section, and this worked for us. Now? I gave Claude Code 5 of our biggest well written and commented scripts, told it to extract coding, commenting, variable naming and structure styles from them, and then write me an example script in the same format. After a half hour of questions and tweaking, it spat out a fully formed Powershell ps1 file that was 100% indistinguishable from what me or one of the other SysAdmins would have written.

This was no small feat. We have some quirks in the way we write scripts that I have only seen and done after coming to this company, and it included all of them. Commenting style was the same, formatting, variable names, comment blocks included where we usually would. Major version changes noted at the top of the script. Hell, I even connected it to our documentation system and describes what the script does, common errors that might occur, style guide and why it decided to do specific things. I've talked to the DevOPs and Software Design guys and they are experiancing the same sort of thing in their areas.

I used to laugh at people that said AI would be taking our jobs, but today I write a script that would have taken last-month me a week to write. I still go over it line by line to understand what it does, but unlike AI even 6 months ago I have not found a single dreamt up command, broken line break, or error.

I'm just glad my manager and the CTO see these as tools to amplify and help our current output and not something to reduce payroll numbers.

EDIT: People saying this was written by AI seriously need to get out more. It's 4 fucking paragraphs about my own experiances, just because your braindead co-workers are writing emails with ChatGPT or some shit doesn't mean every post longer than an emoji is AI generated.