r/sysadmin 21d ago

General Discussion Patch Tuesday Megathread - (August 11, 2026)

110 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 4d ago

General Discussion Weekly 'I made a useful thing' Thread - August 28, 2026

3 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin 5h ago

Work Environment UPDATE: Hospitality Guy in IT

256 Upvotes

previous post (got removed by mods, but its the same post)

So basically, i joined today and after the onboarding, i met with the current IT guy (who is on his notice period)

The situation is precarious to say the least.

IT budget is severely limited, a bunch of systems are on Active Directory (controlled by an older IBM Intel Xeon machine running Windows Server 2008) , a bunch of systems are not on Active directory

There are 3 headless Windows Machines around the offices acting as fileservers, disk management is messy all around, the entire network is flat with no segmentation or separation of any kind, no NVRs, just 2 DVRs

All Windows installs are not genuine/cracked versions (not by massgrave but the sketchy iso you get from shady websites)

The primary database of the Dealership lives on a 1TB SATA HDD on a headless windows PC , which holds data of a tally server , file server and an apache based website that is used for storing purchase information

This disk has NO BACKUPS OR REDUNDANCY! and this disk is accessed constantly everyday for 9hrs

There is a FortiGate 50G Firewall standing between this network and the wide open web

After work hours, they shut down all systems including the servers.

Now, im not an expert, but this felt like it was one disk failure away from complete catastrophe.

The existing sysadmin shares the same sentiment, he proposed a proper system, however management does not feel very enthusiastic about it, citing costs, they see IT as a simple tool

I don't blame the current sysadmin, but i feel like i should unfuck this clusterfuck before it blows up in my face.

Now, the total number of clients in the network is about 60 systems, running anywhere between Windows 8.1 to Windows 10 and about 5 printers

Now, a lot of the data was stored on premise, however in 2018, the OEM mandated a lot of the data stored on cloud via their proprietary website, due to which they retired a server, which is sitting in the closet collecting dust.

Now, kindly tell me if what im thinking is stupid, but

I was thinking to recommission it, setup Proxmox to fire up a Windows Server VM to handle AD and migrate the Win Server 2008 to something newer, and a Debian based VM to unify all these scattered fileservers (and hopefully setup something like snapraid+mergerfs so that disk failures=me getting fired)


r/sysadmin 8h ago

Microsoft is rolling out change meeting organizer feature in Outlook

105 Upvotes

Microsoft is rolling out a Change organizer option that lets meeting organizers transfer meeting ownership directly from Outlook.

It’s not entirely unexpected. When Microsoft introduced admin-initiated meeting transfers a few months ago, many users were also asking for a way to transfer meetings themselves. It looks like Microsoft is now addressing that gap by bringing the capability directly into Outlook.

The feature is currently rolling out.


r/sysadmin 7h ago

Linux What did you do to make yourself a terminal wizard?

65 Upvotes

I look at some of the other sysadmins who flow through the terminal at such ease and then know these random facts about the internals of the linux OS. Not to mention the random keyboard shortcuts and a hundred of them.

If you are what i just described, how did you get to that point? What contributed to that skill the most other than “experience”. A homelab maybe? Tinkering around? Reading?


r/sysadmin 4h ago

General Discussion Interview Question: How often do you update/patch your system?

28 Upvotes

I was asked this question during an interview and I said "it depends on what exactly you're updating, but I update as often as it's needed."

I don't think this was the answer they were looking for, but how would you answer this question?


r/sysadmin 1h ago

Question Any alternative to Note taking besides OneNote for sys admin notes

Upvotes

Hi everyone,

Hope everyone is doing well.

Currently all my notes and learning new tools/skills is linked to my work onenote.

I want to use alternatively note taking tool beside onedrive that linked to work account for anything im learning for my own need. It has to similar features like one note where i can take screenshots and save them for reference.

If you use or selfhost any tool let me know. I dont want something where am paying monthly subscription.

Let me know


r/sysadmin 12h ago

Another PaperCut patch, and blog post explaining

71 Upvotes

Patch 3 available: URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut

Also a blog post from one of their executives explaining why they decided to release updates as they had them, instead of waiting for one big perfect patch. Behind the scenes - What happened after 9:42 a.m. on the 27th August 2026 | PaperCut


r/sysadmin 10h ago

General Discussion Which technology do you still have in place that should have been updated years ago?

47 Upvotes

Mine is faxing and this isn't finance or medical it is strictly because a person/group on either side of the process won't do anything about updating the process. We have some fax machines on POTs lines and some are running through a PRI. This is simply location based and not just because.

On that note, there has to be a fax setup out there where each side is using some type of fax to email service, meaning both ends are not using a POTs line, but users refuse to scan/email and/or devs refuse to update code to allow PDF so faxing is still used but w/o actual phone lines.


r/sysadmin 4h ago

Microsoft Microsoft documentation written by AI

16 Upvotes

r/sysadmin 11h ago

Cloudflare for families (1.1.1.2/1.1.1.3) down

43 Upvotes

Heads up, 1.1.1.3 seems to be down as of around 7AM EDT today. If you use that as a free filtered dns forwarder, change until the issue is resolved.


r/sysadmin 6h ago

General Discussion Does anyone actually understand what Microsoft Unified Support covers and how to evaluate alternatives?

17 Upvotes

I'll be upfront: I run a small nonprofit and I am very much not a tech person. Our IT guy left earlier this year and since then I've been the one fielding all the Microsoft-related issues for our organization. We use a bunch of Microsoft products, Teams, SharePoint, some Azure stuff I barely understand, and when things break I genuinely don't know where to turn.

Someone on our board mentioned we should look into Microsoft Unified Support as a way to get professional help when things go wrong. I looked at the Microsoft site and honestly it reads like it was written for someone with a computer science degree. I have no idea what a 'severity level' means in practice or whether we even qualify for certain tiers.

What I'm really trying to figure out is: is Microsoft Unified Support the only real option for getting serious help with Microsoft products, or are there alternatives that might make more sense for an organization like ours? I don't have a huge budget and I'm a little worried about locking into something expensive that's designed for Fortune 500 companies.

Any plain-English guidance from people who've actually navigated this would be genuinely helpful.


r/sysadmin 5h ago

Question 2 Servers with Identical SID's

12 Upvotes

I have 2 specific 2025 Server VMs that apparently have the same SID. I know what you are thinking.... they were imaged and I forgot to change them. That is not the case. They are both completely fresh installs and I have no idea how this happened. I have never cloned a machine as long as I have worked for this company.

Long story short, I need to get one of them changed.

If I run the following without the /oobe will anything on the system be effected such as any existing applications, software, settings, etc. My understanding is that it will have to be re-added to the domain. Anyone have any experience with this?

cd %WINDIR%\System32\Sysprep 
sysprep.exe /generalize /shutdown

r/sysadmin 4h ago

Trying to force policy that user account may not be shared.

8 Upvotes

Hi it's normal in IT that you enforce a policy that user accounts may not be shared or transferred /given to new users right?

Situation is that a partner company that uses our infrastructure used 1 user account for interns for a long time. If the next intern started they give the account To the next...and so on and on. They did not even change the password.

As IT responsible I said they cannot do this any longer that way. And I do not want to support this any longer. Every user also interns need to have an individual/ personal account. Reasons are obvious for me... Accountability, managing the accounts in general, gdpr,...

Example of 1 risk: access to the mailbox or onedrive of the account can have personal data stored from the previous user. So I say sharing accounts is not ok period. But they still keep fighting me for this. They do not want to understand. I'm tired of the discussion. The arguments that they use are : we used it before like this without any issues .

In the new it policy for them it's included. I have no mandate to enforce but I warned my boss about this and I hope my boss will support me..
I was right... With the call on this with the partner... Am I right to try enforcing this?

The only thing is if directors can formally accept the risk to me. But then why bother with security in general? I'm tired and frustrated by this bullshit. I'm doing it the correct way or on the long run I'm changing jobs ...

Any advice?


r/sysadmin 14h ago

General Discussion So, how are you guys dealing with the deprecation of 'memberof' dynamic groups?

51 Upvotes

Personally, I don't (just yet).

Jokes aside, I can't think of a solution that isn't overworked and/or (very, very) manual.


r/sysadmin 1h ago

Question gpupdate /force always fails over wifi

Upvotes

Been chasing this for a while and I'm out of ideas. Everything I can test

Yes, I used AI to help me, as this troubleshooting got way deeper than I could figure out on my own... it's just too much, and I'm stumped

Symptom

On any wireless client:

  • gpupdate — succeeds
  • gpupdate /force — fails, both Computer and User policy

    The processing of Group Policy failed. Windows could not resolve the computer name. The processing of Group Policy failed. Windows could not resolve the user name.

Same machine plugged into Ethernet on any wired VLAN: gpupdate /force succeeds.

Affects every wireless device regardless of hardware — x64 and ARM, multiple vendors, not from a common image. Predates our switch replacement (was happening on the old switches too, same APs).

Environment

  • Single-domain AD, 2 DCs, functional level current
  • Juniper Mist APs, WLAN bridged to VLAN 80 (10.0.80.0/24)
  • FortiGate 200F HA pair doing inter-VLAN routing
  • Wired workstations on 10.0.90.0/24, DCs on 10.0.140.0/24
  • Clients are Win11

What the logs say

GroupPolicy/Operational during a failed /force:

Id 7320  Error: Retrieved account information. Error code 0x5.
Id 7017  The system call to get account information completed.
         The call failed after 15 milliseconds.

Nine of those in about four seconds. 15–31 ms each — too fast for a network timeout.

gpsvc.log:

ProcessGPOs(Machine): MyGetUserName failed with 5.
ProcessGPOs(User):    MyGetUserName failed with 5.
OnPolicyApplicationComplete: Application complete with bConnectivityFailure = 1.

The packet capture is the interesting part

Client-side netsh trace during a failed /force. Total DC traffic for the entire run:

10.0.80.102  -> 10.0.140.3   tcp/135    60 packets
10.0.140.3   -> 10.0.80.102             49 packets
10.0.80.102  -> 10.0.140.2   udp/53      8 packets

Decoded the port 135 conversation. It's 44 × ept_map requests for DRSUAPI (e3514235-4b06-11d1-ab04-00c04fc2dcd2), and the DC returns status 0x00000000 — success — on all 45 responses. Clean bind, clean bind_ack, no faults, no bind_naks.

So the endpoint mapper hands back a valid DRSUAPI endpoint 44 times and the client never opens a TCP connection to it.

Exactly one TCP SYN to a DC for the whole run: 10.0.140.3:135. That's it.

No Kerberos at all. Nothing on port 88. No LDAP 389, no SMB 445, no RPC dynamic high port.

The successful wired run for comparison:

135 -> 49669 -> 389 -> 445 -> 49676 -> 88

So on wired it does the full sequence. On wireless it gets the endpoint and gives up locally without authenticating or connecting.

What I've eliminated

Network path

  • FortiGate policy permits Internal_WiFi → Servers on service ALL, no NAT, no UTM.
  • Confirmed RPC dynamic ports 49668–49677 pass fine on the same firewall config (visible in VPN traffic logs to the same DCs)
  • Path MTU: ping -f -l 1472 succeeds to the DCs from both wired and wireless
  • Both DC host firewalls disabled entirely as a test — no change

AD / DC side

  • Test-ComputerSecureChannel → True
  • Time skew ~0.03 s
  • nltest /dsgetdc returns a DC with full flag set, correct site
  • Test-NetConnection to 88, 135, 389, 445 on both DCs → all True from Wi-Fi
  • SYSVOL/DFS: \\domain\SYSVOL\...\Policies enumerates, GPT.INI reads fine
  • RestrictRemoteSam not set on either DC
  • No 5807 events (no unmapped-subnet complaints)
  • UserPrincipal::Current returns the full DN from AD over Wi-Fi — directory lookups work
  • whoami /groups resolves all SIDs to names on Wi-Fi

Client side

  • GP history ACLs correct (SYSTEM + Administrators Full Control, registry and ProgramData)
  • Same failure on any computer from any manufacture
  • Get-NetConnectionProfileDomainAuthenticated / Ldap on both wired and wireless, identical

Wireless

  • Mist WLAN: isolation Disabled, no ARP filtering, no broadcast/multicast filtering, Custom Forwarding None (bridged, not tunneled)
  • WxLAN policy: single rule, All Users → All Resources, allow
  • WPA3/WPA2-Personal PSK — no 802.1X, so no separate machine identity
  • Same APs before and after a full switch replacement; symptom unchanged

The question

Why would a client receive a successful ept_map response for DRSUAPI and then not attempt the connection — failing locally in 15 ms with 0x5 — and why would that depend on whether the machine is on wireless vs wired, when both interfaces report identical network profiles and both paths reach the DC on every relevant port?

The absence of any Kerberos traffic during the failed run feels like the key detail. It's not being denied by the KDC; it isn't asking.

Anything obvious I'm missing?
gpupdate /force fails on Wi-Fi but works on Ethernet — DsCrackNames/DRSUAPI gets a valid EPM endpoint and then never connects

Been chasing this for a while, and I'm out of ideas.
Should I just quit and become a potato farmer?


r/sysadmin 1d ago

In light of today's Exchange Online outage

687 Upvotes

ELT just asked me to send an all company email that email is down and the marketing people can't send their corporate drivel that they send every Monday.


r/sysadmin 2h ago

Headless Remote Win10

4 Upvotes

I have a few HP Mini's deployed to remote locations that are headless and a real pain in the ass to access physically. They are running Windows 10 pro (I know!). Anyway I added a smart plug so I can remotely reboot them, but even so I regularly find they don't come back online (at least not so I can go on with Teamviewer or Tailscale).

Whenever I go out after one of these outages I find that usually its on a pre-login screen asking if I want Windows Backup or something like that.

To get around this I am seriously thinking of installing Proxmox and running Tailscale on the host or is there a better way?

I assume Proxmox would come backup cleanly after any reboot.


r/sysadmin 9h ago

General Discussion IT Site Support Specialist - advise

8 Upvotes

Hi all,

I have an opportunity to transition to a new Site IT Specialist role at a mine site (Perth AU) it's a full time 6 month fixed term role [possible for extension]

I have been with the company for around 3 years now [full time and contracted], and I have good IT support experience [service desk / desktop support], most recently in project-based windows 11 rollouts at mine sites [fifo] covering Corporate and OT environments.

My main worry is that I don't have a lot of knowledge and experience around:

- Network configs/servers/netwroking lingo and terminolgies

- Setting up comms racks, configuring, troubleshooting Cisco switches, Wi-Fi APs setup and troubleshooting

I do have an open to learn attitude and i know alot of these things ill learn hands on when im up there and asking alot of questions etc.

Are there any readings/courses anyone can recommend i can look into?

Thanks in advance :)


r/sysadmin 1d ago

General Discussion Rough Summer for Microsoft

172 Upvotes

Today's Exchange/O365 (EX1464935/MO1465074) outage seems to be a result of the instability we've been seeing the last 3 or 4 months due to the rapid change occurring regularly in the Microsoft ecosystem. This one is more visible to end users than other problems we've faced this summer. I'm curious if the stability of government tenants has been better. Are commercial tenants the beta testers for government tenant changes?


r/sysadmin 3h ago

Dell Repository Manager ISO gives errors when running on host

3 Upvotes

Hello. I've used the DRM successfully dozens of times in the past. I recently have seen errors when I attempt to run the ISOs I create from DRM. This is happening on both DRM 3.5.0 and 3.5.1 running on a Win11 client and being applied to all my R640 servers and they are running the latest BIOS: 2.28.1. All of the catalogs and plugins are up to date.

Using the DRM software I simply choose the "Platform Bootable ISO" option, I select the system: R640, chose the location to save the ISO file, and then I click on CREATE. The job runs successfully.

When I go to apply the ISO to the system, either using iDRAC to virtually present the ISO file on boot or using any type of application to send the ISO to a USB drive I can get the system to successfully boot into the loaders after starting Suse Linux. That's when I get the errors.

Every package in the bootable ISO attempt to install the updates. Then I get:
Trying to Upgrade DSU
Failed to create Support Directory
<Package Name>.BIN Error: Package execution requires 'root' user privileges.

I see this for multiple packages and then it eventually just hangs. With this being an automated process in the DRM to create the ISO I'm not able to intervene and elevate privileges. But I shouldn't need to with this process. Has anyone else seen these issues before and successfully resolved them?


r/sysadmin 2h ago

Microsoft [ Removed by Reddit ]

2 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/sysadmin 14m ago

General Discussion How can I monitor my own computers like they're company managed devices?

Upvotes

Hello, I apologize if this is the wrong subreddit but figured you guys probably would know the answer.

At my company we use Tenable to scan for CVE's, then use our MDM to make employees update applications. For things like homebrew we also use our MDM to run a script that sends an upgrade/update command once in a while.

Due to this, it's pretty easy to ensure all our endpoints are as up to date as we can get, and pretty easy for employees to know when they have an outdated app or need to install the latest version of MacOS.

Is there any (preferably free and/or open source) tool which can replicate this on my personal Mac?


r/sysadmin 4h ago

Question How often do you see "consultants" in smaller labs?

2 Upvotes

I love optimizing and automating things. I have seen many labs (EDU sector) doing updates and deployments manually or wasting a lot of times doing things that can be automated in an weekend. I have previously worked in a lab and loved automating some of their processes. Have you seen "consultants" being hired to automate / optimize IT labs workflow? Maybe this is more of a career question as to if this is possible / hourly rate


r/sysadmin 1d ago

Leaving company - $200/hr a reasonable post-departure rate?

265 Upvotes

I'm leaving my company. I was asked regarding the potential to do contract work following my departure. I really like my boss on a personal level and don't want to screw him over, but at the same time this company has had over a decade to build some redundancy into this role and they haven't.

I'm burnt out. I want to get out and be done. I really don't want the contract work, but I don't want to totally screw my coworkers either. Is $200 a good rate to set, not too insultingly high, if they need it they can pay it, but hopefully I won't be contacted all the time?