r/sysadmin 8h ago

Microsoft is rolling out change meeting organizer feature in Outlook

104 Upvotes

Microsoft is rolling out a Change organizer option that lets meeting organizers transfer meeting ownership directly from Outlook.

It’s not entirely unexpected. When Microsoft introduced admin-initiated meeting transfers a few months ago, many users were also asking for a way to transfer meetings themselves. It looks like Microsoft is now addressing that gap by bringing the capability directly into Outlook.

The feature is currently rolling out.


r/sysadmin 8h ago

Has anyone actually had an AI automation go wrong badly enough to change their approach?

0 Upvotes

I've been thinking about where the line should be drawn as AI moves from answering questions to actually taking action in IT environments.

It's one thing for an AI to suggest a fix or pull information from the KB. It's another for it to execute the fix without a human in the loop.

Password resets and basic troubleshooting seem relatively low-risk. But what about account provisioning, access changes, endpoint actions, software deployments, firewall rules, or changes to production systems?

At what point does the efficiency gained from autonomy stop being worth the risk?


r/sysadmin 8h ago

General Discussion Why do companies choose to depend almost entirely on Microsoft?

0 Upvotes

TL;DR: I understand why non-technical companies choose M365, but why do technically capable companies, especially in the EU, place so many critical services behind Microsoft SaaS when on-premises or hybrid infrastructure is a realistic alternative? If you genuinely considered both, what ultimately made Microsoft win?

I’m probably what many people here would call an old-fashioned sysadmin. I run a mixture of Linux services and Windows Server, with authentication, storage and other important services kept on infrastructure under our control and largely detached from Microsoft SaaS.

This is not intended as a “cloud bad, on-prem good” post. I’m genuinely trying to understand the reasoning of companies that have chosen the Microsoft-first approach.

The recent Outlook outage, together with posts about entire M365 tenants becoming disabled or “deauthenticated,” made me think about this again. A general outage is usually temporary and affects many customers, while a tenant-specific issue may leave a small company completely dependent on Microsoft support. Both cases demonstrate how many critical business functions can depend on the same provider.

From a business-continuity perspective, being locked out of a tenant for a day, or any prolonged period, is no better than hardware-related downtime in an on-premises environment. If employees cannot access email, files or other essential systems, the business is down regardless of whether the failed component is in the company’s server room or a provider’s cloud.

Microsoft’s infrastructure is obviously far more redundant than anything a small company could build. What worries me is not only a normal service outage, but a tenant-specific administrative problem where the company depends on Microsoft support to restore access. A smaller customer may not have an enterprise account team capable of escalating the issue immediately, so the business could potentially be seriously affected for days.

I understand many of the advantages: remote onboarding, tight integration between identity and endpoint management, collaboration through Teams and SharePoint and no need to maintain certain local infrastructure.

I also understand that the Microsoft route may well be the most sensible option for many non-technical organizations. A small law firm, for example, probably does not want to operate its own server room or rent and maintain servers somewhere else.

What puzzles me more is seeing technology companies make the same choice even when they already have the necessary knowledge in-house. They could realistically operate at least some of these services themselves, or design a hybrid environment, yet many still place identity, email, documents, endpoint management, telephony and authentication for unrelated SaaS applications under the same tenant. That seems to create an enormous common failure domain that they have the technical ability to avoid.

I’m also not convinced that this necessarily eliminates much administration. Operating local servers requires hardware maintenance, patching, monitoring, backups and disaster recovery. But properly managing M365 means dealing with licensing, Entra, Intune and who knows how many other interconnected services, along with constantly changing portals and Microsoft support. It seems more like a different type of system administration than substantially less system administration.

The question is especially interesting to me in the EU. Apart from GDPR and data residency, there is also the broader issue of making a company’s entire operation dependent on a single US provider.

So my question is mainly for people who genuinely considered both options, especially those working at technology companies with the skills to self-host: if on-premises infrastructure was a realistic alternative and there was an actual debate, what ultimately made you choose the Microsoft route?

I’m also entirely open to the possibility that I am overestimating the risks or underestimating the advantages. I would simply like to understand why the industry is moving so decisively in this direction while the traditional on-premises approach appears to be gradually disappearing.


r/sysadmin 8h ago

Question Defender Cloud Apps - info on policies matched

0 Upvotes

So I'm a first line tech just trying to improve my knowledge about stuff and wondered if anyone could point me in the right direction. We have cloud apps policies in place to prevent users downloading company files on their personal devices. Every now and again this policy gets matched on users corporate devices, but I'm unable to work out why.

Is there anywhere it says what has caused a policy to match? The device is compliant, the user isn't a risky user or anything like that. By everything I can see the policy shouldn't have matched and blocked the user but I don't know if there is somewhere else I should be checking.


r/sysadmin 9h ago

General Discussion IT Site Support Specialist - advise

12 Upvotes

Hi all,

I have an opportunity to transition to a new Site IT Specialist role at a mine site (Perth AU) it's a full time 6 month fixed term role [possible for extension]

I have been with the company for around 3 years now [full time and contracted], and I have good IT support experience [service desk / desktop support], most recently in project-based windows 11 rollouts at mine sites [fifo] covering Corporate and OT environments.

My main worry is that I don't have a lot of knowledge and experience around:

- Network configs/servers/netwroking lingo and terminolgies

- Setting up comms racks, configuring, troubleshooting Cisco switches, Wi-Fi APs setup and troubleshooting

I do have an open to learn attitude and i know alot of these things ill learn hands on when im up there and asking alot of questions etc.

Are there any readings/courses anyone can recommend i can look into?

Thanks in advance :)


r/sysadmin 9h ago

General Discussion Which technology do you still have in place that should have been updated years ago?

48 Upvotes

Mine is faxing and this isn't finance or medical it is strictly because a person/group on either side of the process won't do anything about updating the process. We have some fax machines on POTs lines and some are running through a PRI. This is simply location based and not just because.

On that note, there has to be a fax setup out there where each side is using some type of fax to email service, meaning both ends are not using a POTs line, but users refuse to scan/email and/or devs refuse to update code to allow PDF so faxing is still used but w/o actual phone lines.


r/sysadmin 10h ago

Nexthink and 1E/TeamViewer DEX - Real World Experiences

2 Upvotes

Hi all!

So, we're in the midst of selecting a DEX solution for a large Enterprise, and I'm looking for some general feedback on TeamViewer's and Nexthink's DEX solution, "in the real world", as it were.

Suffice it to say, we have dealt heavily with the vendors themselves, and they have gotten us customer interviews, but all of those are clearly "curated".

I know DEX as a solution, as a whole, will have a lot of... "opinions", but from a "what we need next" perspective, we're well squared away with NEEDING one, or at least seeing value in the products as a whole.

If the response is "just do everything in Intune" or "fuck DEX it's silly" or "TeamViewer once hacked my Grandma", I will upvote you and give you a cursory "thanks", but I would ask to just get 'real' responses :)

If you're comfortable with meeting on LinkedIn/having a discussion over the phone, be 100% open to that. DMs/PMs and such!

For the product suite, to define this better:

1) Nexthink Workplace Experience | Nexthink

2) TeamViewer TeamViewer DEX | TeamViewer Which includes the TeamViewer tensor agent, remote control, Tia features throughout.

Thanks in advance, and feel free to farm karma if that's your thang!


r/sysadmin 10h ago

General Discussion Dell quivalent of HPE SPP ISO?

2 Upvotes

Hey guys, first time working with DELL PowerEdge R470 Server.
I just want to update the firmware of components in it, and install bare metal Windows Server 2025.
On HPE DL servers, i would just set up ILO, and update firmware using SPP ISO that i would download specifically for that model.
So, is there something similar for DELL iDRAC? Or is there a better method?
Thanks guys


r/sysadmin 10h ago

Question File Server Assessment

0 Upvotes

Hi All,

We have a few file servers and are trying to identify archived data based on the following conditions, but I believe something is not correct. We have 18TB but showing only 3TB for archive with following contion

Condition Classification
Modified ≤ 3 years OR accessed ≤ 180 days Migrate / Active
Modified > 3 years AND accessed > 180 days Archive Candidate

With this condition,

Migrate: ≤30% of folder data is older than the cutoff - actively used, recommend moving as-is.
Archive: ≥80% of folder data is older than the cutoff, AND no file in the folder was modified in the last 30 days.
Review: Falls between the two thresholds, OR is old by volume but was touched recently, OR had partial access errors during scanning.

Above condition give us more data to archive?


r/sysadmin 10h ago

Cloudflare for families (1.1.1.2/1.1.1.3) down

47 Upvotes

Heads up, 1.1.1.3 seems to be down as of around 7AM EDT today. If you use that as a free filtered dns forwarder, change until the issue is resolved.


r/sysadmin 11h ago

Another PaperCut patch, and blog post explaining

73 Upvotes

Patch 3 available: URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut

Also a blog post from one of their executives explaining why they decided to release updates as they had them, instead of waiting for one big perfect patch. Behind the scenes - What happened after 9:42 a.m. on the 27th August 2026 | PaperCut


r/sysadmin 12h ago

Question Can hardware bound credentials reduce session theft and token replay?

1 Upvotes

Hardware-backed credentials can make stolen secrets less useful because an attacker cannot complete the necessary cryptographic operation without access to the authenticator. That provides meaningful protection against several credential-phishing and replay scenarios, but the benefit can weaken if the post-authentication session or refresh token remains a portable bearer artifact.

Hardware binding clearly strengthens initial authentication. Reducing session theft and token replay after login usually requires the application or authorization server to enforce sender-constrained tokens, proof of possession, or another mechanism that binds use of the token to a device-held key.

How are teams balancing this additional protection with lost-device recovery, shared administrative workflows, break-glass access, browser compatibility, and endpoint-compromise risk?


r/sysadmin 12h ago

Question Can an identity graph uncover orphaned accounts and stale access grants?

1 Upvotes

We can run periodic reviews and export permissions from every system, but neither approach is very good at showing relationships. A graph model should connect people, accounts, groups, applications, credentials, roles, owners, and inherited permissions, then identify accounts without active employees, service identities without owners, or access that remains attached to retired projects.

Has anyone used this effectively? I would be interested in examples where relationship-based analysis found something that standard IGA certification or per-application access reviews missed, particularly for cloud, SaaS, automation, and non-human identities.


r/sysadmin 12h ago

Non Lenovo coded SSD for Lenovo ThinkSystem

0 Upvotes

Related to Lenovo ThinkSystem SR650 V3:

I have a bunch of generic Samsung PM893 SATA SSD I would like to use in the mentioned host. Are there any potential compatibility issues to be able to to utilize the disks (without errors)? It's not a production system, but I would still like to avoid any quirks related to the disk setup.


r/sysadmin 14h ago

General Discussion So, how are you guys dealing with the deprecation of 'memberof' dynamic groups?

47 Upvotes

Personally, I don't (just yet).

Jokes aside, I can't think of a solution that isn't overworked and/or (very, very) manual.


r/sysadmin 19h ago

Help Desk → Cloud/Infrastructure/SWE: How should I position myself for my next role?

0 Upvotes

Hey everyone! Looking for some career advice from people who have been in tech/IT for a while.

I’m currently a Help Desk Technician and have been in the role for about a month. I’m definitely not trying to quit immediately, but I want to start positioning myself now so that once I’ve gotten some solid experience here, I can move into something more advanced.

My long-term interests are Cloud, Infrastructure, or Software Engineering, and I’m trying to figure out what I should be doing while I’m in Help Desk to make that next jump easier.

A little about me:

  • BAS in Information Technology
  • Currently pursuing a Master’s in Software Engineering – DevOps
  • Currently studying for the CCNA
  • AWS and GCP certifications
  • 2 previous internships: Software Engineering and Marketing Engineering
  • Built and currently run a small startup/app with 250+ users that generates close to $100/month
  • Currently working full-time Help Desk

I know someone is probably going to ask why I didn’t just pursue SWE after my internship. Basically, it’s 2026 and the SWE market is insanely competitive lol. I spent around 8 months unemployed, applied to literally thousands of positions, and only landed one SWE interview. Meanwhile, when I started applying to IT/support/infrastructure-related positions, I was getting significantly more interviews and eventually landed my current Help Desk position.

So I took the opportunity instead of continuing to sit unemployed.

The Help Desk work itself has actually been easy and pretty fun so far, and I’ve already done a lot of this type of work before. I just don’t want to get comfortable and realize 2–3 years from now that I haven’t built the skills needed to move up.

If you were in my position, what would you focus on over the next 6–12 months?

What roles would you target after Help Desk? Sysadmin? NOC? Network Support? Cloud Support? Infrastructure Support?

And besides the CCNA, what skills/projects would give me the best shot at eventually moving toward Cloud/Infrastructure/SWE?


r/sysadmin 19h ago

Question Azure AD VM

1 Upvotes

Hi All,

We have a hybrid environment where the on-premises AD/DNS servers are currently configured with external DNS forwarders.

For the Azure VMs, should we use the same external DNS forwarders, or should the Azure VMs use Azure DNS (168.63.129.16) instead?

Thanks,


r/sysadmin 20h ago

Come to me lords of the network

2 Upvotes

We are transitioning off of UniFi switches to Aruba Instant On switches. We have a stack of 1960s that connect to a 1930 via fiber from one side of the building to the other that 1930 connects to another stack of 1960 10 gig switches. using just regular ethernet uplink the 1960 stack connects to two other 1930 switches. The unified architecture is the exact same minus the 10 gig switches every time we attempt to switch over the network to the Aruba switches something goes wrong. We’ve done it multiple different ways. I’ve staged the switches in production on a separate management LAN to eliminate any UniFi switches in between the Aruba communication but every time we try to do the switch over the health of the Aruba’s goes bad even once we connect everything to the DNS servers we get no DNS. The Aruba switches will be green all week long no issues. I plugged a laptop in. I get an address. I can connect to the Internet, but as soon as the day comes where we try to switch the connections to the Aruba switches something goes wrong and we can never figure out how to get it to work. Please help, I’m thinking there’s something wrong on layer 2 but I feel as though I’ve eliminated all these things and have hit a wall as soon as I start moving connections from the unifi to the Aruba it falls apart. I started with removing the firewall uplink to the Unifi switches and only had an uplink to the Arubas but everytime like I mentioned the health goes to or age for the cloud then I can’t even access google let alone get a dhcp address. Even if I do get a dhcp the dns doesn’t resolve even basic websites like google.


r/sysadmin 22h ago

Any help appreciated

0 Upvotes

We've migrated an email domain from one M365 tenant to another but an old exists on the 'old' tenant. This app sends messages via a mailbox in the tenant using EXO and M365 mail routing. However, the mailbox sends as a temporary domain (given the real domain is in the new tenant). How can we rewrite the domain on the way out with M365 or relay through an external SaaS solution that would send on the email and rewrite back to the old domain


r/sysadmin 23h ago

Windows 11 autounattend fun times

0 Upvotes

Can someone explain to me why both Windows Configuration Designer and schneegans.de Autounattend.xml generator both have a nice convenient way for you to set the hostname of the target PC to the serial number using the %SERIAL% variable... and ONLY ALLOW the %SERIAL% variable... ONLY FOR THAT TO NOT EVEN WORK.

Everything you find online regarding those tools says "This tool makes it SUPER easy to set the hostname to the serial number, just use the SUPER convenient hostname field and use variable %SERIAL%."

Then when it doesn't work and you search online for that feature NOT WORKING and suddenly everything you find says "Yeah, it's just not possible for the installer to query the BIOS to get the SN." or something like that but essentially its endless information stating that it just doesn't work...

So... which is it people?

Also now I need to figure out where and how to inject a PowerShell script because even a single line won't cut it.


r/sysadmin 23h ago

Microsoft Microsoft Partner Benefits - 3 months, 5 support tickets, no resolution. Need help finding an escalation path.

32 Upvotes

I'm hoping someone here has dealt with something similar or knows how to get Microsoft to actually act.

Background:

We're a Microsoft AI Cloud Partner and hold Partner Success Expanded Benefits (MAICPP). In June 2026 we renewed and went to redeem our 35x Microsoft 365 Business Premium (no Teams) licences through the new Partner Center redemption experience.

The mistake:

The new redemption flow (introduced in Australia March 2026) changed from product keys to a billing account-based checkout. I wasn't aware the tenant selection happened at checkout and the licences were redeemed into our partner tenancy instead of our staff tenancy.

How it got worse:

The first support engineer we worked with was not aware of the new redemption flow and was unable to provide correct guidance. The correct resolution — documented by Microsoft — is to keep the subscription active, associate the staff tenancy as a billing tenant, and provision licences across without cancelling. However, this documentation was not provided to us until much later in the support process. Acting on incorrect early guidance, the subscription was cancelled in the belief it would reset the redemption. It didn't. Once cancelled, the subscription cannot be reactivated and Microsoft needs to generate a new redemption token. That token has never been issued despite 5 support tickets over nearly 3 months.

Support ticket history:

Ticket 2606040010000086 — Partner Centre — 4 June 2026 — Closed. Told it was opened with the wrong team.

Ticket 2606040010000086 — Admin Center — 4 June 2026 — Closed. Told it was opened with the wrong team.

Ticket 2606300030000389 — Admin Center — 30 June 2026 — Open. No resolution.

Ticket 2607210030005592 — Admin Center — 21 July 2026 — Closed. Told it was opened with the wrong team.

Ticket 2607240040000545 — Partner Centre — 24 July 2026 — Closed. Told it was opened with the wrong team.

At one point during this process, a support engineer called on a Friday to schedule a follow-up session for the following week. When that session finally took place, the outcome was simply being told the ticket had been opened with the wrong team and to open a new one. That call could have happened on the Friday.

Every single closed ticket was shut with a variation of "opened with the wrong team, please open a new ticket." No team has taken ownership in three months.

Current situation:

We have 23 staff currently riding on a 1-seat paid subscription — technically out of compliance — because our 35-seat MAICPP benefit is disabled and stuck in limbo. The disabled subscription is visible in our partner tenancy with 35 licences, 0 assigned, going nowhere. We're also receiving deletion notices for expired trial subscriptions we spun up as a stopgap, with a deletion date of 4 September 2026 — which is three days away. The situation is now urgent.

What I need:

A new redemption token for the MAICPP M365 Business Premium (no Teams) 35-licence benefit so I can redeem it correctly into our staff tenancy. That's it. One token. Three months and five tickets to get here. Notably, during ticket 2607240040000545 a Microsoft support engineer confirmed that a new token was indeed required to resolve this — but stated it was the other team's responsibility to issue it. Neither team has issued it.

Has anyone:

  • Successfully escalated a Partner Benefits issue past first-line support?
  • Got a direct contact in Microsoft's partner licensing or MAICPP team?
  • Had a redemption token regenerated after an accidental cancellation?

Any help appreciated. This is becoming a compliance issue and Microsoft's support structure appears completely unable to route this to the right team.


r/sysadmin 1d ago

Have standard users always been able to add local TCP/IP printers in Windows?

30 Upvotes

We have been doing some testing, and we have noticed that regular, standard, non-privileged users can add local TCP/IP printers through the Windows 11 Settings app. (Disclaimer: I am not talking about printer drivers; I am talking only about adding the printer itself to Windows as a queue.)

When the printer is added, other users on the computer can see it, and those same users can delete it.

I swear, this feels like different behavior from the past. In the past, I thought a locally created TCP/IP printer was a computer-level print queue, which would require administrator rights to add, update, or delete.

So I see two possibilities:

  1. It was always like this, but when we moved from on-prem Active Directory/GPO to Entra/Intune, we missed migrating a setting that previously required admin rights to add or delete local TCP/IP printers; OR
  2. This is new-ish behavior that we are only now noticing.

r/sysadmin 1d ago

General Discussion Rough Summer for Microsoft

172 Upvotes

Today's Exchange/O365 (EX1464935/MO1465074) outage seems to be a result of the instability we've been seeing the last 3 or 4 months due to the rapid change occurring regularly in the Microsoft ecosystem. This one is more visible to end users than other problems we've faced this summer. I'm curious if the stability of government tenants has been better. Are commercial tenants the beta testers for government tenant changes?


r/sysadmin 1d ago

Question Google Workspace Email Signature Management

5 Upvotes

TL;DR - Client uses Exclaimer for email signature creation & management, have had issues with it, want something else. Prefer API-based solution instead of SMTP routing. WiseStamp, Signite, and SyncSignature are candidates. Any feedback on them or other ideas?

Hey, everyone! I am looking for suggestions when it comes to creating and managing email signatures in Google Workspace.

I work for an MSP and a client of ours is currently using Exclaimer. There have been a few times over the last few years where their emails grind to a halt - cannot send externally or internally, access denied error. Email delivery logs point to the Exclaimer rules as the issue. Disable the rules/routing and email works again no problem.

We have tried removing and setting Exclaimer up again from scratch, but it has happened again recently and they are tired of it. Everything was set up exactly according to their guide. There is no indication that anyone has made an unannounced change that would cause things to break. It just simply stops working and breaks email delivery maybe once per year. At this point they want to get away from it - not sure they want to bother going the support route.

Unfortunately, CodeTwo only supports Microsoft email solutions. I have found a few other potential candidates like WiseStamp, Signite, and SyncSignature. Ideally, we are looking for an API-based solution and not something like Exclaimer where outbound traffic gets routed via SMTP in an attempt to keep this from happening again.

Is anyone familiar with these 3 platforms? Any feedback that you can offer? Any other suggestions? I have also seen LastLine, but, the obvious Claude Code website design kind of throws me off and there isn't much about it to be found. Not sure how big of a company it is, if it will even exist in 2 years, or how the support is. It gives strong LLM/vibecoded signals.

I am aware of Patronum, which looks cool, but goes way beyond the simple email signature scope in mind. I have also seen the Free Signature Manager for Gmail from Revolgy, but also am not sure about support and quality. If this was me tinkering around in our GW tenant, sure, but this will be for a school with about 125-150 users. Something they can understand and manage themselves would be great. I know there are options for GAM scripts, etc. but I don't think that would be user friendly for them to monitor or troubleshoot if needed. We would prefer they have more control over this.

Thank you!


r/sysadmin 1d ago

Is this the MS Outage folks are talking about?

8 Upvotes

Or do I just need to "clear my cache"?

Here's what I'm seeing:

Something went wrong.

Please try the recommended action below.

Refresh the application

BootResult: fail

Back Filled Errors: None err: System. Security. Cryptography. CryptographicException esrc: StartupData et: ServerError estack: Error: 500

t Object.w [as createStatusErrorMessage] (https://res.public.onecdn.static.microsoft/owamail/hashed-v1/scripts/owa.mailindex.491fdc82.js:1:806

t https://res.public.onecdn.static.microsoft/owamail/hashed-v1/scripts/owa.mailindex.491fdc82.is:1:19276

st: 500

ehk: X-OWA-Error

ewsver: 15.21.360.13

egid: 752d9ee1-da5a-9b97-e479-18581a572c9|