r/sysadmin 10h ago

Dell Repository Manager ISO gives errors when running on host

3 Upvotes

Hello. I've used the DRM successfully dozens of times in the past. I recently have seen errors when I attempt to run the ISOs I create from DRM. This is happening on both DRM 3.5.0 and 3.5.1 running on a Win11 client and being applied to all my R640 servers and they are running the latest BIOS: 2.28.1. All of the catalogs and plugins are up to date.

Using the DRM software I simply choose the "Platform Bootable ISO" option, I select the system: R640, chose the location to save the ISO file, and then I click on CREATE. The job runs successfully.

When I go to apply the ISO to the system, either using iDRAC to virtually present the ISO file on boot or using any type of application to send the ISO to a USB drive I can get the system to successfully boot into the loaders after starting Suse Linux. That's when I get the errors.

Every package in the bootable ISO attempt to install the updates. Then I get:
Trying to Upgrade DSU
Failed to create Support Directory
<Package Name>.BIN Error: Package execution requires 'root' user privileges.

I see this for multiple packages and then it eventually just hangs. With this being an automated process in the DRM to create the ISO I'm not able to intervene and elevate privileges. But I shouldn't need to with this process. Has anyone else seen these issues before and successfully resolved them?


r/sysadmin 10h ago

Question How often do you see "consultants" in smaller labs?

0 Upvotes

I love optimizing and automating things. I have seen many labs (EDU sector) doing updates and deployments manually or wasting a lot of times doing things that can be automated in an weekend. I have previously worked in a lab and loved automating some of their processes. Have you seen "consultants" being hired to automate / optimize IT labs workflow? Maybe this is more of a career question as to if this is possible / hourly rate


r/sysadmin 10h ago

Microsoft Microsoft documentation written by AI

35 Upvotes

r/sysadmin 11h ago

General Discussion Interview Question: How often do you update/patch your system?

34 Upvotes

I was asked this question during an interview and I said "it depends on what exactly you're updating, but I update as often as it's needed."

I don't think this was the answer they were looking for, but how would you answer this question?


r/sysadmin 11h ago

Trying to force policy that user account may not be shared.

10 Upvotes

Hi it's normal in IT that you enforce a policy that user accounts may not be shared or transferred /given to new users right?

Situation is that a partner company that uses our infrastructure used 1 user account for interns for a long time. If the next intern started they give the account To the next...and so on and on. They did not even change the password.

As IT responsible I said they cannot do this any longer that way. And I do not want to support this any longer. Every user also interns need to have an individual/ personal account. Reasons are obvious for me... Accountability, managing the accounts in general, gdpr,...

Example of 1 risk: access to the mailbox or onedrive of the account can have personal data stored from the previous user. So I say sharing accounts is not ok period. But they still keep fighting me for this. They do not want to understand. I'm tired of the discussion. The arguments that they use are : we used it before like this without any issues .

In the new it policy for them it's included. I have no mandate to enforce but I warned my boss about this and I hope my boss will support me..
I was right... With the call on this with the partner... Am I right to try enforcing this?

The only thing is if directors can formally accept the risk to me. But then why bother with security in general? I'm tired and frustrated by this bullshit. I'm doing it the correct way or on the long run I'm changing jobs ...

Any advice?


r/sysadmin 11h ago

Work Environment UPDATE: Hospitality Guy in IT

375 Upvotes

previous post (got removed by mods, but its the same post)

So basically, i joined today and after the onboarding, i met with the current IT guy (who is on his notice period)

The situation is precarious to say the least.

IT budget is severely limited, a bunch of systems are on Active Directory (controlled by an older IBM Intel Xeon machine running Windows Server 2008) , a bunch of systems are not on Active directory

There are 3 headless Windows Machines around the offices acting as fileservers, disk management is messy all around, the entire network is flat with no segmentation or separation of any kind, no NVRs, just 2 DVRs

All Windows installs are not genuine/cracked versions (not by massgrave but the sketchy iso you get from shady websites)

The primary database of the Dealership lives on a 1TB SATA HDD on a headless windows PC , which holds data of a tally server , file server and an apache based website that is used for storing purchase information

This disk has NO BACKUPS OR REDUNDANCY! and this disk is accessed constantly everyday for 9hrs

There is a FortiGate 50G Firewall standing between this network and the wide open web

After work hours, they shut down all systems including the servers.

Now, im not an expert, but this felt like it was one disk failure away from complete catastrophe.

The existing sysadmin shares the same sentiment, he proposed a proper system, however management does not feel very enthusiastic about it, citing costs, they see IT as a simple tool

I don't blame the current sysadmin, but i feel like i should unfuck this clusterfuck before it blows up in my face.

Now, the total number of clients in the network is about 60 systems, running anywhere between Windows 8.1 to Windows 10 and about 5 printers

Now, a lot of the data was stored on premise, however in 2018, the OEM mandated a lot of the data stored on cloud via their proprietary website, due to which they retired a server, which is sitting in the closet collecting dust.

Now, kindly tell me if what im thinking is stupid, but

I was thinking to recommission it, setup Proxmox to fire up a Windows Server VM to handle AD and migrate the Win Server 2008 to something newer, and a Debian based VM to unify all these scattered fileservers (and hopefully setup something like snapraid+mergerfs so that disk failures=me getting fired)

EDIT: Thank you for all your comments and insights, i intend to draft proper documentation and pitch a middle ground solution to the management to secure some funds and bring the systems upto the times

Unfortunately, due to circumstances, i cannot run, atleast not for another 6 months until i get my certs and upskill myself on paper and in real life


r/sysadmin 11h ago

Question 2 Servers with Identical SID's

22 Upvotes

I have 2 specific 2025 Server VMs that apparently have the same SID. I know what you are thinking.... they were imaged and I forgot to change them. That is not the case. They are both completely fresh installs and I have no idea how this happened. I have never cloned a machine as long as I have worked for this company.

Long story short, I need to get one of them changed.

If I run the following without the /oobe will anything on the system be effected such as any existing applications, software, settings, etc. My understanding is that it will have to be re-added to the domain. Anyone have any experience with this?

cd %WINDIR%\System32\Sysprep 
sysprep.exe /generalize /shutdown

EDIT: Going with the general consensus.... rebuilding the VM.


r/sysadmin 12h ago

Career / Job Related Want to become a sysadmin - do I continue with help desk or transition to the military

0 Upvotes

I currently work remotely for a Mac-based MSP. I'm making $23.50/hour. As soon as I got my Jamf 100 cert I applied and got lucky enough for them to give me a shot. I mostly do onboardings/offboardings and occasionally password resets and deleting MDM alerts.

I also have an offer to join the Canadian military as part of their IT team. It pays the same but I would have way more things to do especially in networking(ad-hoc networks, VSAT deployments, network security etc).

I'm guaranteed a promotion within 3 years that bumps me up to 82k if I don't wash out.

I don't know if I should stick with my help desk job, stack more certifications and find something better or if I should just join the military instead.

What do you think?


r/sysadmin 12h ago

Dialpad Down

2 Upvotes

Down detector showing issues but no official announcement. I got a number of users reporting issues. Can't seem to make any calls on mine either


r/sysadmin 12h ago

Question Server hygiene checklist for someone self-managing a handful of VPS?

2 Upvotes

I inherited server management duties from a coworker who left, and honestly it was held together with cron jobs and good intentions, now I'm trynna get backups, firewall rules, and basic user hygiene acc consistent across our boxes instead of tribal data. What's on your baseline checklist?


r/sysadmin 13h ago

Question M365 sending out calendar invites randomly

0 Upvotes

Not sure if this is a general 365 bug or something on our tenant but currently all recurring meetings are being resent.

I can see them in the sent items for my own account and I’m also receiving lots of calendar invites for meetings I’m already part of from others.

Anyone else having weirdness or is it just us?


r/sysadmin 13h ago

General Discussion Does anyone actually understand what Microsoft Unified Support covers and how to evaluate alternatives?

24 Upvotes

I'll be upfront: I run a small nonprofit and I am very much not a tech person. Our IT guy left earlier this year and since then I've been the one fielding all the Microsoft-related issues for our organization. We use a bunch of Microsoft products, Teams, SharePoint, some Azure stuff I barely understand, and when things break I genuinely don't know where to turn.

Someone on our board mentioned we should look into Microsoft Unified Support as a way to get professional help when things go wrong. I looked at the Microsoft site and honestly it reads like it was written for someone with a computer science degree. I have no idea what a 'severity level' means in practice or whether we even qualify for certain tiers.

What I'm really trying to figure out is: is Microsoft Unified Support the only real option for getting serious help with Microsoft products, or are there alternatives that might make more sense for an organization like ours? I don't have a huge budget and I'm a little worried about locking into something expensive that's designed for Fortune 500 companies.

Any plain-English guidance from people who've actually navigated this would be genuinely helpful.


r/sysadmin 13h ago

Question Advice for troubleshooting random slowness

0 Upvotes

How do you troubleshoot random slowness reported only by a handful of users? Some background: these few users are on a site-to-site VPN and separate location than the primary network.

The main office does not report any slowness issues. A few weeks ago, users at the secondary office started to report slowness in Outlook, and other general applications they use for work. The ISP reports modem is good and all tests look good.

We ended up replacing the firewall because it was a slightly older model thinking it would resolve the issue. A couple days have passed and users are still reporting random slowness.

Speedtest comes back good, and the only time i was able to replicate the slowness is when I did a test Teams call with the user.

How would you approach a situation like this? They are plugged directly into the firewall and there is a switch at the location as well but its not an older model.

TIA


r/sysadmin 13h ago

Azure file permissions not persistent across different machines

1 Upvotes

Weird issue with Azure file

User created a number of new folders with strict permissions. She herself has full control to the folder.

It works on her desktop, but she can't access those same files from her laptop.

On the laptop she's logged in with the same account, she can see the folders and the share, but when she goes to open a file it says she doesn't have permission.

In the properties of the file I can see her username has full control.

Same file opens just fine on her desktop, same login.

Any idea?


r/sysadmin 14h ago

Question I don't know where else to go for this!

0 Upvotes

So I have a handful of users, myself included, that are experiencing the weirdest issue with their mice and keyboards. We will be typing and suddenly it stops then after maybe 15 seconds it will type out everything but it will be missing some keystrokes. The mouse will do the same it just stops moving for like 15 seconds then comes back. Sometimes it happens once and then works after and sometimes it's a few minutes of it working on and off. It is only happening to maybe 10 users. I have replaced keyboards and mice, replaced dongles, changed out for wired sets, turned off the power settings that let windows turn off USB devices. It is happening on brand new devices and 4 year old devices. It happens on devices that are in intune and devices that aren't in intune. There doesn't seem to be a pattern. I'm going to pull out my non existent hair. Does anyone have any ideas?

Edit: I also tried plugging everything into all USB ports on the laptops and hub monitors.


r/sysadmin 14h ago

Linux What did you do to make yourself a terminal wizard?

89 Upvotes

I look at some of the other sysadmins who flow through the terminal at such ease and then know these random facts about the internals of the linux OS. Not to mention the random keyboard shortcuts and a hundred of them.

If you are what i just described, how did you get to that point? What contributed to that skill the most other than “experience”. A homelab maybe? Tinkering around? Reading?


r/sysadmin 14h ago

Question Intune - iOS App Deployment Issue (VPP)

0 Upvotes

Hi all, please help cos my head is gonna explode.

I've got ABM set up with Intune for MDM and VPP.

This a virgin install so very basic.

my iPad is enrolled and registered and pulls policies.

The problems occur when trying to get apps down..

I've tried a few apps via VPP, assigned to "all devices".

on the iPad it says I need to sign in to the App Store to get it..

I've deployed the app via intune in device mode and I cannot figure out why this isnt playing - please help!


r/sysadmin 14h ago

Connecting an innovation workflow to jira without creating a permissions nightmare

3 Upvotes

The integration between an innovation workflow and project management tools like jira is where most setups fall apart

Ideas get approved in one system and then someone manually creates a ticket in jira, which means duplicated data, broken context, and permissions that dont align between the two platforms

One way sync is almost worse than no sync because it creates a false sense of connection while the actual data drifts apart


r/sysadmin 15h ago

Conditional access policies requirement

0 Upvotes

Hi,

Thanks in advance for any assistance - have a bit of a headache with the set-up.

We use Azure Virtual Desktop and currently have a Conditional Access policy that blocks access from locations outside our exempt locations, such as our office IP addresses.

We have a secondary Conditional Access policy that provides an exemption from this restriction. This policy is currently configured to block access from All locations, with a security group excluded from the policy so that members of the group are not subject to the block to facilitate travel.

We are now looking to limit this further to just the country that they are visiting.

For example, if a user is travelling to Spain and is a member of a security group such as "AVD Exclusions - Travel", we would want their exemption to apply only while they are accessing AVD from Spain.

I do not want to exclude Spain as a location, as this would allow all users to access AVD from Spain. On the other hand, the current set-up limits it to security group, so 1 user, but accessible from 'All locations'. Is this possible in a single policy?


r/sysadmin 15h ago

Question MDE-managed Windows Server 2025 not receiving Intune ASR policies

4 Upvotes

I have a physical Windows Server 2025 Hyper-V host that is onboarded to Microsoft Defender for Endpoint through Azure Arc and managed through MDE Security Settings Management.

The server shows up normally in Defender, Intune, and Entra:

- Managed by MDE

- Enrollment status shows "Success"

- Recent check-in times in both Defender and Intune portals

- Entra device object has managementType = MicrosoftSense

- All other Intune Endpoint Security policies are applying successfully

The problem is specifically with Attack Surface Reduction policies.

I have a production ASR Rules policy assigned to All devices. Every other MDE-managed server gets it, but this server never appears in the policy reporting at all.

Get-MpPreference originally showed only 2 ASR rules. I discovered those 2 rules were being configured by Local Group Policy. I removed that local GPO, confirmed the registry policy path was removed, and Event ID 5007 showed both ASR rules being removed.

It has now been about a week and the Intune ASR policy still does not apply.

Using a Get-MpPreference command shows no ASR rules being applied.

I also created a brand-new ASR test policy with only one rule in Audit mode and assigned it directly to a group containing this server. The server still does not appear in that policy's reporting either.

These are the things I have checked so far:

- Sense service is running

- WinDefend service is running

- Defender AV running normally

- MDE Client Analyzer confirms connectivity to MdeConfigMgr and other MDE cloud endpoints

- No remaining Defender/ASR local Group Policy settings present

- Other Intune security policies continue to apply successfully

- Server is not domain joined; it is a workgroup Hyper-V host connected through Azure Arc

At this point it seems like ASR policy evaluation/delivery is broken specifically for this device, while the rest of MDE Security Settings Management works normally.

Has anyone run into this with an MDE-managed/Azure Arc Windows Server, especially Server 2025? If so, what fixed it?


r/sysadmin 15h ago

Microsoft is rolling out change meeting organizer feature in Outlook

133 Upvotes

Microsoft is rolling out a Change organizer option that lets meeting organizers transfer meeting ownership directly from Outlook.

It’s not entirely unexpected. When Microsoft introduced admin-initiated meeting transfers a few months ago, many users were also asking for a way to transfer meetings themselves. It looks like Microsoft is now addressing that gap by bringing the capability directly into Outlook.

The feature is currently rolling out.


r/sysadmin 15h ago

Has anyone actually had an AI automation go wrong badly enough to change their approach?

0 Upvotes

I've been thinking about where the line should be drawn as AI moves from answering questions to actually taking action in IT environments.

It's one thing for an AI to suggest a fix or pull information from the KB. It's another for it to execute the fix without a human in the loop.

Password resets and basic troubleshooting seem relatively low-risk. But what about account provisioning, access changes, endpoint actions, software deployments, firewall rules, or changes to production systems?

At what point does the efficiency gained from autonomy stop being worth the risk?


r/sysadmin 16h ago

General Discussion Why do companies choose to depend almost entirely on Microsoft?

0 Upvotes

TL;DR: I understand why non-technical companies choose M365, but why do technically capable companies, especially in the EU, place so many critical services behind Microsoft SaaS when on-premises or hybrid infrastructure is a realistic alternative? If you genuinely considered both, what ultimately made Microsoft win?

I’m probably what many people here would call an old-fashioned sysadmin. I run a mixture of Linux services and Windows Server, with authentication, storage and other important services kept on infrastructure under our control and largely detached from Microsoft SaaS.

This is not intended as a “cloud bad, on-prem good” post. I’m genuinely trying to understand the reasoning of companies that have chosen the Microsoft-first approach.

The recent Outlook outage, together with posts about entire M365 tenants becoming disabled or “deauthenticated,” made me think about this again. A general outage is usually temporary and affects many customers, while a tenant-specific issue may leave a small company completely dependent on Microsoft support. Both cases demonstrate how many critical business functions can depend on the same provider.

From a business-continuity perspective, being locked out of a tenant for a day, or any prolonged period, is no better than hardware-related downtime in an on-premises environment. If employees cannot access email, files or other essential systems, the business is down regardless of whether the failed component is in the company’s server room or a provider’s cloud.

Microsoft’s infrastructure is obviously far more redundant than anything a small company could build. What worries me is not only a normal service outage, but a tenant-specific administrative problem where the company depends on Microsoft support to restore access. A smaller customer may not have an enterprise account team capable of escalating the issue immediately, so the business could potentially be seriously affected for days.

I understand many of the advantages: remote onboarding, tight integration between identity and endpoint management, collaboration through Teams and SharePoint and no need to maintain certain local infrastructure.

I also understand that the Microsoft route may well be the most sensible option for many non-technical organizations. A small law firm, for example, probably does not want to operate its own server room or rent and maintain servers somewhere else.

What puzzles me more is seeing technology companies make the same choice even when they already have the necessary knowledge in-house. They could realistically operate at least some of these services themselves, or design a hybrid environment, yet many still place identity, email, documents, endpoint management, telephony and authentication for unrelated SaaS applications under the same tenant. That seems to create an enormous common failure domain that they have the technical ability to avoid.

I’m also not convinced that this necessarily eliminates much administration. Operating local servers requires hardware maintenance, patching, monitoring, backups and disaster recovery. But properly managing M365 means dealing with licensing, Entra, Intune and who knows how many other interconnected services, along with constantly changing portals and Microsoft support. It seems more like a different type of system administration than substantially less system administration.

The question is especially interesting to me in the EU. Apart from GDPR and data residency, there is also the broader issue of making a company’s entire operation dependent on a single US provider.

So my question is mainly for people who genuinely considered both options, especially those working at technology companies with the skills to self-host: if on-premises infrastructure was a realistic alternative and there was an actual debate, what ultimately made you choose the Microsoft route?

I’m also entirely open to the possibility that I am overestimating the risks or underestimating the advantages. I would simply like to understand why the industry is moving so decisively in this direction while the traditional on-premises approach appears to be gradually disappearing.


r/sysadmin 16h ago

Question Defender Cloud Apps - info on policies matched

1 Upvotes

So I'm a first line tech just trying to improve my knowledge about stuff and wondered if anyone could point me in the right direction. We have cloud apps policies in place to prevent users downloading company files on their personal devices. Every now and again this policy gets matched on users corporate devices, but I'm unable to work out why.

Is there anywhere it says what has caused a policy to match? The device is compliant, the user isn't a risky user or anything like that. By everything I can see the policy shouldn't have matched and blocked the user but I don't know if there is somewhere else I should be checking.


r/sysadmin 16h ago

General Discussion IT Site Support Specialist - advise

11 Upvotes

Hi all,

I have an opportunity to transition to a new Site IT Specialist role at a mine site (Perth AU) it's a full time 6 month fixed term role [possible for extension]

I have been with the company for around 3 years now [full time and contracted], and I have good IT support experience [service desk / desktop support], most recently in project-based windows 11 rollouts at mine sites [fifo] covering Corporate and OT environments.

My main worry is that I don't have a lot of knowledge and experience around:

- Network configs/servers/netwroking lingo and terminolgies

- Setting up comms racks, configuring, troubleshooting Cisco switches, Wi-Fi APs setup and troubleshooting

I do have an open to learn attitude and i know alot of these things ill learn hands on when im up there and asking alot of questions etc.

Are there any readings/courses anyone can recommend i can look into?

Thanks in advance :)