r/sysadmin 25m ago

Enabling "Restrict Unauthenticated RPC clients" (Authenticated) on Exchange Server — any real-world breakage?

Upvotes

We're working through a CIS Benchmark remediation and one of the findings is:

>

We're planning to set this to **"Authenticated"** (not "Authenticated without exceptions" — we're aware that level is much riskier and more likely to break things) on our **Exchange Server SE** environment.

Before we push this via GPO, I'd like to hear from anyone who has actually applied this in a production Exchange SE (or 2019) environment:

* Did it break **Outlook Anywhere / RPC over HTTP** for any legacy clients?
* Any issues with **MAPI/RPC** connections from older Outlook versions?
* Any impact on **DAG replication** or **Active Manager**?
* Did it cause problems with **Exchange Management Shell / EAC** functionality?
* Any unexpected issues with **AD communication** (since Exchange talks to DCs heavily over RPC)?
* Did you apply it to Domain Controllers as well, or keep DCs and Exchange servers on separate rollout schedules?
* Since Exchange SE is fairly new, has anyone tested this specifically against SE's RPC dependencies, or is it safe to assume behavior is the same as 2019?

Our environment: Exchange Server SE, mostly modern Outlook clients on MAPI/HTTP, not fully certain if any legacy RPC/TCP clients remain in the environment.

Any war stories, gotchas, or "wish I'd known this before enabling it" experiences would be really helpful before we roll this out.

Thanks in advance.


r/sysadmin 44m ago

Headless Remote Win10

Upvotes

I have a few HP Mini's deployed to remote locations that are headless and a real pain in the ass to access physically. They are running Windows 10 pro (I know!). Anyway I added a smart plug so I can remotely reboot them, but even so I regularly find they don't come back online (at least not so I can go on with Teamviewer or Tailscale).

Whenever I go out after one of these outages I find that usually its on a pre-login screen asking if I want Windows Backup or something like that.

To get around this I am seriously thinking of installing Proxmox and running Tailscale on the host or is there a better way?

I assume Proxmox would come backup cleanly after any reboot.


r/sysadmin 1h ago

Question WSUS SyncFailure

Upvotes

WSUS sync failing with ImportUpdateError — Server 2025 / MECM 2509

I'm setting up a lab with Windows Server 2025 and Configuration Manager 2509. WSUS is installed on the primary site server and the SUP is configured.

WSUS synchronization starts but consistently fails with:

Result: Failed
Error: ImportUpdateError

UpdateErrors: {}

Server:

  • Windows Server 2025
  • WSUS version: 10.0.26100.33158
  • Configuration Manager 2509
  • WSUS upstream: Microsoft Update
  • No proxy

I've also confirmed outbound TCP 443 connectivity to sws.update.microsoft.com.

The WSUS SoftwareDistribution.log contains:

invalid update identity (AtLeastOne Prerequisite) in XML for update

and this is occurring with multiple different update GUIDs.

Has anyone encountered this on Server 2025 recently, and is there a known fix or workaround?


r/sysadmin 1h ago

General Discussion GLPI vs Zammad: What’s Your Experience?

Upvotes

Hi SysAdmin family,

Is anyone here using GLPI or Zammad as a helpdesk/ticketing system?

I’d love to hear about your experience with either platform, especially:

  • Pros and cons
  • Number of users
  • Number of agents
  • Average tickets per day
  • Overall environment/setup
  • Performance and reliability
  • Any issues or limitations you’ve encountered

If you’ve used both, I’d especially appreciate a comparison between GLPI and Zammad.


r/sysadmin 1h ago

Dell Repository Manager ISO gives errors when running on host

Upvotes

Hello. I've used the DRM successfully dozens of times in the past. I recently have seen errors when I attempt to run the ISOs I create from DRM. This is happening on both DRM 3.5.0 and 3.5.1 running on a Win11 client and being applied to all my R640 servers and they are running the latest BIOS: 2.28.1. All of the catalogs and plugins are up to date.

Using the DRM software I simply choose the "Platform Bootable ISO" option, I select the system: R640, chose the location to save the ISO file, and then I click on CREATE. The job runs successfully.

When I go to apply the ISO to the system, either using iDRAC to virtually present the ISO file on boot or using any type of application to send the ISO to a USB drive I can get the system to successfully boot into the loaders after starting Suse Linux. That's when I get the errors.

Every package in the bootable ISO attempt to install the updates. Then I get:
Trying to Upgrade DSU
Failed to create Support Directory
<Package Name>.BIN Error: Package execution requires 'root' user privileges.

I see this for multiple packages and then it eventually just hangs. With this being an automated process in the DRM to create the ISO I'm not able to intervene and elevate privileges. But I shouldn't need to with this process. Has anyone else seen these issues before and successfully resolved them?


r/sysadmin 2h ago

Question How often do you see "consultants" in smaller labs?

3 Upvotes

I love optimizing and automating things. I have seen many labs (EDU sector) doing updates and deployments manually or wasting a lot of times doing things that can be automated in an weekend. I have previously worked in a lab and loved automating some of their processes. Have you seen "consultants" being hired to automate / optimize IT labs workflow? Maybe this is more of a career question as to if this is possible / hourly rate


r/sysadmin 2h ago

Microsoft Microsoft documentation written by AI

8 Upvotes

r/sysadmin 2h ago

General Discussion Interview Question: How often do you update/patch your system?

17 Upvotes

I was asked this question during an interview and I said "it depends on what exactly you're updating, but I update as often as it's needed."

I don't think this was the answer they were looking for, but how would you answer this question?


r/sysadmin 2h ago

Trying to force policy that user account may not be shared.

7 Upvotes

Hi it's normal in IT that you enforce a policy that user accounts may not be shared or transferred /given to new users right?

Situation is that a partner company that uses our infrastructure used 1 user account for interns for a long time. If the next intern started they give the account To the next...and so on and on. They did not even change the password.

As IT responsible I said they cannot do this any longer that way. And I do not want to support this any longer. Every user also interns need to have an individual/ personal account. Reasons are obvious for me... Accountability, managing the accounts in general, gdpr,...

Example of 1 risk: access to the mailbox or onedrive of the account can have personal data stored from the previous user. So I say sharing accounts is not ok period. But they still keep fighting me for this. They do not want to understand. I'm tired of the discussion. The arguments that they use are : we used it before like this without any issues .

In the new it policy for them it's included. I have no mandate to enforce but I warned my boss about this and I hope my boss will support me..
I was right... With the call on this with the partner... Am I right to try enforcing this?

The only thing is if directors can formally accept the risk to me. But then why bother with security in general? I'm tired and frustrated by this bullshit. I'm doing it the correct way or on the long run I'm changing jobs ...

Any advice?


r/sysadmin 3h ago

Work Environment UPDATE: Hospitality Guy in IT

193 Upvotes

previous post (got removed by mods, but its the same post)

So basically, i joined today and after the onboarding, i met with the current IT guy (who is on his notice period)

The situation is precarious to say the least.

IT budget is severely limited, a bunch of systems are on Active Directory (controlled by an older IBM Intel Xeon machine running Windows Server 2008) , a bunch of systems are not on Active directory

There are 3 headless Windows Machines around the offices acting as fileservers, disk management is messy all around, the entire network is flat with no segmentation or separation of any kind, no NVRs, just 2 DVRs

All Windows installs are not genuine/cracked versions (not by massgrave but the sketchy iso you get from shady websites)

The primary database of the Dealership lives on a 1TB SATA HDD on a headless windows PC , which holds data of a tally server , file server and an apache based website that is used for storing purchase information

This disk has NO BACKUPS OR REDUNDANCY! and this disk is accessed constantly everyday for 9hrs

There is a FortiGate 50G Firewall standing between this network and the wide open web

After work hours, they shut down all systems including the servers.

Now, im not an expert, but this felt like it was one disk failure away from complete catastrophe.

The existing sysadmin shares the same sentiment, he proposed a proper system, however management does not feel very enthusiastic about it, citing costs, they see IT as a simple tool

I don't blame the current sysadmin, but i feel like i should unfuck this clusterfuck before it blows up in my face.

Now, the total number of clients in the network is about 60 systems, running anywhere between Windows 8.1 to Windows 10 and about 5 printers

Now, a lot of the data was stored on premise, however in 2018, the OEM mandated a lot of the data stored on cloud via their proprietary website, due to which they retired a server, which is sitting in the closet collecting dust.

Now, kindly tell me if what im thinking is stupid, but

I was thinking to recommission it, setup Proxmox to fire up a Windows Server VM to handle AD and migrate the Win Server 2008 to something newer, and a Debian based VM to unify all these scattered fileservers (and hopefully setup something like snapraid+mergerfs so that disk failures=me getting fired)


r/sysadmin 3h ago

Question 2 Servers with Identical SID's

10 Upvotes

I have 2 specific 2025 Server VMs that apparently have the same SID. I know what you are thinking.... they were imaged and I forgot to change them. That is not the case. They are both completely fresh installs and I have no idea how this happened. I have never cloned a machine as long as I have worked for this company.

Long story short, I need to get one of them changed.

If I run the following without the /oobe will anything on the system be effected such as any existing applications, software, settings, etc. My understanding is that it will have to be re-added to the domain. Anyone have any experience with this?

cd %WINDIR%\System32\Sysprep 
sysprep.exe /generalize /shutdown

r/sysadmin 3h ago

Career / Job Related Want to become a sysadmin - do I continue with help desk or transition to the military

0 Upvotes

I currently work remotely for a Mac-based MSP. I'm making $23.50/hour. As soon as I got my Jamf 100 cert I applied and got lucky enough for them to give me a shot. I mostly do onboardings/offboardings and occasionally password resets and deleting MDM alerts.

I also have an offer to join the Canadian military as part of their IT team. It pays the same but I would have way more things to do especially in networking(ad-hoc networks, VSAT deployments, network security etc).

I'm guaranteed a promotion within 3 years that bumps me up to 82k if I don't wash out.

I don't know if I should stick with my help desk job, stack more certifications and find something better or if I should just join the military instead.

What do you think?


r/sysadmin 3h ago

Dialpad Down

1 Upvotes

Down detector showing issues but no official announcement. I got a number of users reporting issues. Can't seem to make any calls on mine either


r/sysadmin 3h ago

Question Server hygiene checklist for someone self-managing a handful of VPS?

2 Upvotes

I inherited server management duties from a coworker who left, and honestly it was held together with cron jobs and good intentions, now I'm trynna get backups, firewall rules, and basic user hygiene acc consistent across our boxes instead of tribal data. What's on your baseline checklist?


r/sysadmin 4h ago

Question M365 sending out calendar invites randomly

0 Upvotes

Not sure if this is a general 365 bug or something on our tenant but currently all recurring meetings are being resent.

I can see them in the sent items for my own account and I’m also receiving lots of calendar invites for meetings I’m already part of from others.

Anyone else having weirdness or is it just us?


r/sysadmin 4h ago

General Discussion Does anyone actually understand what Microsoft Unified Support covers and how to evaluate alternatives?

19 Upvotes

I'll be upfront: I run a small nonprofit and I am very much not a tech person. Our IT guy left earlier this year and since then I've been the one fielding all the Microsoft-related issues for our organization. We use a bunch of Microsoft products, Teams, SharePoint, some Azure stuff I barely understand, and when things break I genuinely don't know where to turn.

Someone on our board mentioned we should look into Microsoft Unified Support as a way to get professional help when things go wrong. I looked at the Microsoft site and honestly it reads like it was written for someone with a computer science degree. I have no idea what a 'severity level' means in practice or whether we even qualify for certain tiers.

What I'm really trying to figure out is: is Microsoft Unified Support the only real option for getting serious help with Microsoft products, or are there alternatives that might make more sense for an organization like ours? I don't have a huge budget and I'm a little worried about locking into something expensive that's designed for Fortune 500 companies.

Any plain-English guidance from people who've actually navigated this would be genuinely helpful.


r/sysadmin 4h ago

Question Advice for troubleshooting random slowness

0 Upvotes

How do you troubleshoot random slowness reported only by a handful of users? Some background: these few users are on a site-to-site VPN and separate location than the primary network.

The main office does not report any slowness issues. A few weeks ago, users at the secondary office started to report slowness in Outlook, and other general applications they use for work. The ISP reports modem is good and all tests look good.

We ended up replacing the firewall because it was a slightly older model thinking it would resolve the issue. A couple days have passed and users are still reporting random slowness.

Speedtest comes back good, and the only time i was able to replicate the slowness is when I did a test Teams call with the user.

How would you approach a situation like this? They are plugged directly into the firewall and there is a switch at the location as well but its not an older model.

TIA


r/sysadmin 5h ago

Azure file permissions not persistent across different machines

1 Upvotes

Weird issue with Azure file

User created a number of new folders with strict permissions. She herself has full control to the folder.

It works on her desktop, but she can't access those same files from her laptop.

On the laptop she's logged in with the same account, she can see the folders and the share, but when she goes to open a file it says she doesn't have permission.

In the properties of the file I can see her username has full control.

Same file opens just fine on her desktop, same login.

Any idea?


r/sysadmin 5h ago

Question I don't know where else to go for this!

0 Upvotes

So I have a handful of users, myself included, that are experiencing the weirdest issue with their mice and keyboards. We will be typing and suddenly it stops then after maybe 15 seconds it will type out everything but it will be missing some keystrokes. The mouse will do the same it just stops moving for like 15 seconds then comes back. Sometimes it happens once and then works after and sometimes it's a few minutes of it working on and off. It is only happening to maybe 10 users. I have replaced keyboards and mice, replaced dongles, changed out for wired sets, turned off the power settings that let windows turn off USB devices. It is happening on brand new devices and 4 year old devices. It happens on devices that are in intune and devices that aren't in intune. There doesn't seem to be a pattern. I'm going to pull out my non existent hair. Does anyone have any ideas?

Edit: I also tried plugging everything into all USB ports on the laptops and hub monitors.


r/sysadmin 5h ago

Linux What did you do to make yourself a terminal wizard?

56 Upvotes

I look at some of the other sysadmins who flow through the terminal at such ease and then know these random facts about the internals of the linux OS. Not to mention the random keyboard shortcuts and a hundred of them.

If you are what i just described, how did you get to that point? What contributed to that skill the most other than “experience”. A homelab maybe? Tinkering around? Reading?


r/sysadmin 5h ago

Question Intune - iOS App Deployment Issue (VPP)

0 Upvotes

Hi all, please help cos my head is gonna explode.

I've got ABM set up with Intune for MDM and VPP.

This a virgin install so very basic.

my iPad is enrolled and registered and pulls policies.

The problems occur when trying to get apps down..

I've tried a few apps via VPP, assigned to "all devices".

on the iPad it says I need to sign in to the App Store to get it..

I've deployed the app via intune in device mode and I cannot figure out why this isnt playing - please help!


r/sysadmin 6h ago

Connecting an innovation workflow to jira without creating a permissions nightmare

2 Upvotes

The integration between an innovation workflow and project management tools like jira is where most setups fall apart

Ideas get approved in one system and then someone manually creates a ticket in jira, which means duplicated data, broken context, and permissions that dont align between the two platforms

One way sync is almost worse than no sync because it creates a false sense of connection while the actual data drifts apart


r/sysadmin 6h ago

Conditional access policies requirement

0 Upvotes

Hi,

Thanks in advance for any assistance - have a bit of a headache with the set-up.

We use Azure Virtual Desktop and currently have a Conditional Access policy that blocks access from locations outside our exempt locations, such as our office IP addresses.

We have a secondary Conditional Access policy that provides an exemption from this restriction. This policy is currently configured to block access from All locations, with a security group excluded from the policy so that members of the group are not subject to the block to facilitate travel.

We are now looking to limit this further to just the country that they are visiting.

For example, if a user is travelling to Spain and is a member of a security group such as "AVD Exclusions - Travel", we would want their exemption to apply only while they are accessing AVD from Spain.

I do not want to exclude Spain as a location, as this would allow all users to access AVD from Spain. On the other hand, the current set-up limits it to security group, so 1 user, but accessible from 'All locations'. Is this possible in a single policy?


r/sysadmin 6h ago

Question MDE-managed Windows Server 2025 not receiving Intune ASR policies

2 Upvotes

I have a physical Windows Server 2025 Hyper-V host that is onboarded to Microsoft Defender for Endpoint through Azure Arc and managed through MDE Security Settings Management.

The server shows up normally in Defender, Intune, and Entra:

- Managed by MDE

- Enrollment status shows "Success"

- Recent check-in times in both Defender and Intune portals

- Entra device object has managementType = MicrosoftSense

- All other Intune Endpoint Security policies are applying successfully

The problem is specifically with Attack Surface Reduction policies.

I have a production ASR Rules policy assigned to All devices. Every other MDE-managed server gets it, but this server never appears in the policy reporting at all.

Get-MpPreference originally showed only 2 ASR rules. I discovered those 2 rules were being configured by Local Group Policy. I removed that local GPO, confirmed the registry policy path was removed, and Event ID 5007 showed both ASR rules being removed.

It has now been about a week and the Intune ASR policy still does not apply.

Using a Get-MpPreference command shows no ASR rules being applied.

I also created a brand-new ASR test policy with only one rule in Audit mode and assigned it directly to a group containing this server. The server still does not appear in that policy's reporting either.

These are the things I have checked so far:

- Sense service is running

- WinDefend service is running

- Defender AV running normally

- MDE Client Analyzer confirms connectivity to MdeConfigMgr and other MDE cloud endpoints

- No remaining Defender/ASR local Group Policy settings present

- Other Intune security policies continue to apply successfully

- Server is not domain joined; it is a workgroup Hyper-V host connected through Azure Arc

At this point it seems like ASR policy evaluation/delivery is broken specifically for this device, while the rest of MDE Security Settings Management works normally.

Has anyone run into this with an MDE-managed/Azure Arc Windows Server, especially Server 2025? If so, what fixed it?


r/sysadmin 6h ago

Question Four Cornerstone / Oracle partnership - I need an adult!!

0 Upvotes

Hello, does anyone here have experience with the Four Cornerstone / Oracle partnership?

They were our previous Oracle partner and we paid them $15,000 for license cost in March.

Four Cornerstone never submitted our renewal to Oracle in time before Oracle just recently severed their partnership with Four Cornerstone, and now Oracle is saying we never paid for our renewal even though they know we paid Four Cornerstone, and we are unable to get anyone from Four Cornerstone to reply to us in hopes of returning our $15,000 they never spent in the way we contracted them to.

We are not a big company, and we are also not having the best fiscal year, so $15,000 to us is a massive amount of money to have just basically given away with nothing in return, and the lack of response from Four Cornerstone honestly feels borderline criminal, I'm not sure how you can just keep someone's $15,000 and not return it while also not doing what you agreed and promised to fulfill.

We just want our money back, man.

If anyone has any experience with this exact situation, or maybe knows anyone at Four Cornerstone they can politely ask to reply to me, that would be spectacular.

Here is the email correspondence between Oracle and us, I have redacted information that would identify anyone other than the Four Cornerstone and Oracle company names

Hi REDACTED (OP),

I’m reaching out regarding REDACTED (OP) renewal and, unfortunately, need to share some difficult news about the status of the MySQL renewal that was submitted through Four Cornerstone in the spring. Our records indicate that REDACTED (OP) provided its purchase order to Four Cornerstone in connection with the renewal; however, Four Cornerstone did not submit the renewal order to Oracle, and the renewal was therefore never completed with Oracle. As a result, REDACTED’s Oracle support and licensing renewal was not processed as expected.

I wish this situation was resolved sooner, particularly given that REDACTED (OP) believed the renewal had been completed. Four Cornerstone is no longer an Oracle partner and did not renew its annual Oracle partnership. REDACTED (Oracle employee) cc’ed made countless attempts to reaching out to REDACTED (FC employee) at Four Cornerstone to have the required partnership renewed and the REDACTED (OP) order submitted, but REDACTED (FC employee) went silent on us.

Because Oracle never received the renewal order from Four Cornerstone, any funds REDACTED (OP) paid directly to Four Cornerstone were not received by Oracle. REDACTED (OP) will need to pursue reimbursement of those funds directly with Four Cornerstone. I have included REDACTED (Oracle employee), our VP of Alliances and Channels, who has been involved in our efforts to address the situation with Four Cornerstone and can help support REDACTED (OP) through the transition.

From an Oracle standpoint, our priority is to get the account properly renewed and bring everything current. To accomplish this, we will need to backdate the new MySQL renewal order to May 5, 2025, with a renewal term through , May 4, 2027, so that the appropriate coverage is in place for both the prior renewal period and the upcoming year. Does REDACTED (OP) have another preferred reseller you would like to use for the renewal? If not, we would be happy to provide a partner recommendation and help coordinate the transition to make the process as smooth as possible.

I understand this is an extremely unfortunate situation, and I’m very sorry that REDACTED (OP) has been put in this position. My goal is to make the Oracle side of the resolution as straightforward as possible and help get the account back to a completed renewal without any further disruption. I would also be happy to schedule a call with you to walk through the situation and answer any questions you may have.

Thank you, and I look forward to hearing from you soon.

Best regards,

REDACTED (Oracle employee)

REDACTED (Oracle employee) | MySQL Enterprise Account Manager
Mobile: REDACTED
Oracle MySQL
Oracle Way | Austin, Texas 78741