r/sysadmin 3h ago

Work Environment UPDATE: Hospitality Guy in IT

196 Upvotes

previous post (got removed by mods, but its the same post)

So basically, i joined today and after the onboarding, i met with the current IT guy (who is on his notice period)

The situation is precarious to say the least.

IT budget is severely limited, a bunch of systems are on Active Directory (controlled by an older IBM Intel Xeon machine running Windows Server 2008) , a bunch of systems are not on Active directory

There are 3 headless Windows Machines around the offices acting as fileservers, disk management is messy all around, the entire network is flat with no segmentation or separation of any kind, no NVRs, just 2 DVRs

All Windows installs are not genuine/cracked versions (not by massgrave but the sketchy iso you get from shady websites)

The primary database of the Dealership lives on a 1TB SATA HDD on a headless windows PC , which holds data of a tally server , file server and an apache based website that is used for storing purchase information

This disk has NO BACKUPS OR REDUNDANCY! and this disk is accessed constantly everyday for 9hrs

There is a FortiGate 50G Firewall standing between this network and the wide open web

After work hours, they shut down all systems including the servers.

Now, im not an expert, but this felt like it was one disk failure away from complete catastrophe.

The existing sysadmin shares the same sentiment, he proposed a proper system, however management does not feel very enthusiastic about it, citing costs, they see IT as a simple tool

I don't blame the current sysadmin, but i feel like i should unfuck this clusterfuck before it blows up in my face.

Now, the total number of clients in the network is about 60 systems, running anywhere between Windows 8.1 to Windows 10 and about 5 printers

Now, a lot of the data was stored on premise, however in 2018, the OEM mandated a lot of the data stored on cloud via their proprietary website, due to which they retired a server, which is sitting in the closet collecting dust.

Now, kindly tell me if what im thinking is stupid, but

I was thinking to recommission it, setup Proxmox to fire up a Windows Server VM to handle AD and migrate the Win Server 2008 to something newer, and a Debian based VM to unify all these scattered fileservers (and hopefully setup something like snapraid+mergerfs so that disk failures=me getting fired)


r/sysadmin 23h ago

General Discussion Rough Summer for Microsoft

174 Upvotes

Today's Exchange/O365 (EX1464935/MO1465074) outage seems to be a result of the instability we've been seeing the last 3 or 4 months due to the rapid change occurring regularly in the Microsoft ecosystem. This one is more visible to end users than other problems we've faced this summer. I'm curious if the stability of government tenants has been better. Are commercial tenants the beta testers for government tenant changes?


r/sysadmin 6h ago

Microsoft is rolling out change meeting organizer feature in Outlook

91 Upvotes

Microsoft is rolling out a Change organizer option that lets meeting organizers transfer meeting ownership directly from Outlook.

It’s not entirely unexpected. When Microsoft introduced admin-initiated meeting transfers a few months ago, many users were also asking for a way to transfer meetings themselves. It looks like Microsoft is now addressing that gap by bringing the capability directly into Outlook.

The feature is currently rolling out.


r/sysadmin 10h ago

Another PaperCut patch, and blog post explaining

66 Upvotes

Patch 3 available: URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut

Also a blog post from one of their executives explaining why they decided to release updates as they had them, instead of waiting for one big perfect patch. Behind the scenes - What happened after 9:42 a.m. on the 27th August 2026 | PaperCut


r/sysadmin 5h ago

Linux What did you do to make yourself a terminal wizard?

55 Upvotes

I look at some of the other sysadmins who flow through the terminal at such ease and then know these random facts about the internals of the linux OS. Not to mention the random keyboard shortcuts and a hundred of them.

If you are what i just described, how did you get to that point? What contributed to that skill the most other than “experience”. A homelab maybe? Tinkering around? Reading?


r/sysadmin 13h ago

General Discussion So, how are you guys dealing with the deprecation of 'memberof' dynamic groups?

49 Upvotes

Personally, I don't (just yet).

Jokes aside, I can't think of a solution that isn't overworked and/or (very, very) manual.


r/sysadmin 9h ago

Cloudflare for families (1.1.1.2/1.1.1.3) down

47 Upvotes

Heads up, 1.1.1.3 seems to be down as of around 7AM EDT today. If you use that as a free filtered dns forwarder, change until the issue is resolved.


r/sysadmin 8h ago

General Discussion Which technology do you still have in place that should have been updated years ago?

42 Upvotes

Mine is faxing and this isn't finance or medical it is strictly because a person/group on either side of the process won't do anything about updating the process. We have some fax machines on POTs lines and some are running through a PRI. This is simply location based and not just because.

On that note, there has to be a fax setup out there where each side is using some type of fax to email service, meaning both ends are not using a POTs line, but users refuse to scan/email and/or devs refuse to update code to allow PDF so faxing is still used but w/o actual phone lines.


r/sysadmin 21h ago

Microsoft Microsoft Partner Benefits - 3 months, 5 support tickets, no resolution. Need help finding an escalation path.

34 Upvotes

I'm hoping someone here has dealt with something similar or knows how to get Microsoft to actually act.

Background:

We're a Microsoft AI Cloud Partner and hold Partner Success Expanded Benefits (MAICPP). In June 2026 we renewed and went to redeem our 35x Microsoft 365 Business Premium (no Teams) licences through the new Partner Center redemption experience.

The mistake:

The new redemption flow (introduced in Australia March 2026) changed from product keys to a billing account-based checkout. I wasn't aware the tenant selection happened at checkout and the licences were redeemed into our partner tenancy instead of our staff tenancy.

How it got worse:

The first support engineer we worked with was not aware of the new redemption flow and was unable to provide correct guidance. The correct resolution — documented by Microsoft — is to keep the subscription active, associate the staff tenancy as a billing tenant, and provision licences across without cancelling. However, this documentation was not provided to us until much later in the support process. Acting on incorrect early guidance, the subscription was cancelled in the belief it would reset the redemption. It didn't. Once cancelled, the subscription cannot be reactivated and Microsoft needs to generate a new redemption token. That token has never been issued despite 5 support tickets over nearly 3 months.

Support ticket history:

Ticket 2606040010000086 — Partner Centre — 4 June 2026 — Closed. Told it was opened with the wrong team.

Ticket 2606040010000086 — Admin Center — 4 June 2026 — Closed. Told it was opened with the wrong team.

Ticket 2606300030000389 — Admin Center — 30 June 2026 — Open. No resolution.

Ticket 2607210030005592 — Admin Center — 21 July 2026 — Closed. Told it was opened with the wrong team.

Ticket 2607240040000545 — Partner Centre — 24 July 2026 — Closed. Told it was opened with the wrong team.

At one point during this process, a support engineer called on a Friday to schedule a follow-up session for the following week. When that session finally took place, the outcome was simply being told the ticket had been opened with the wrong team and to open a new one. That call could have happened on the Friday.

Every single closed ticket was shut with a variation of "opened with the wrong team, please open a new ticket." No team has taken ownership in three months.

Current situation:

We have 23 staff currently riding on a 1-seat paid subscription — technically out of compliance — because our 35-seat MAICPP benefit is disabled and stuck in limbo. The disabled subscription is visible in our partner tenancy with 35 licences, 0 assigned, going nowhere. We're also receiving deletion notices for expired trial subscriptions we spun up as a stopgap, with a deletion date of 4 September 2026 — which is three days away. The situation is now urgent.

What I need:

A new redemption token for the MAICPP M365 Business Premium (no Teams) 35-licence benefit so I can redeem it correctly into our staff tenancy. That's it. One token. Three months and five tickets to get here. Notably, during ticket 2607240040000545 a Microsoft support engineer confirmed that a new token was indeed required to resolve this — but stated it was the other team's responsibility to issue it. Neither team has issued it.

Has anyone:

  • Successfully escalated a Partner Benefits issue past first-line support?
  • Got a direct contact in Microsoft's partner licensing or MAICPP team?
  • Had a redemption token regenerated after an accidental cancellation?

Any help appreciated. This is becoming a compliance issue and Microsoft's support structure appears completely unable to route this to the right team.


r/sysadmin 23h ago

Have standard users always been able to add local TCP/IP printers in Windows?

31 Upvotes

We have been doing some testing, and we have noticed that regular, standard, non-privileged users can add local TCP/IP printers through the Windows 11 Settings app. (Disclaimer: I am not talking about printer drivers; I am talking only about adding the printer itself to Windows as a queue.)

When the printer is added, other users on the computer can see it, and those same users can delete it.

I swear, this feels like different behavior from the past. In the past, I thought a locally created TCP/IP printer was a computer-level print queue, which would require administrator rights to add, update, or delete.

So I see two possibilities:

  1. It was always like this, but when we moved from on-prem Active Directory/GPO to Entra/Intune, we missed migrating a setting that previously required admin rights to add or delete local TCP/IP printers; OR
  2. This is new-ish behavior that we are only now noticing.

r/sysadmin 4h ago

General Discussion Does anyone actually understand what Microsoft Unified Support covers and how to evaluate alternatives?

18 Upvotes

I'll be upfront: I run a small nonprofit and I am very much not a tech person. Our IT guy left earlier this year and since then I've been the one fielding all the Microsoft-related issues for our organization. We use a bunch of Microsoft products, Teams, SharePoint, some Azure stuff I barely understand, and when things break I genuinely don't know where to turn.

Someone on our board mentioned we should look into Microsoft Unified Support as a way to get professional help when things go wrong. I looked at the Microsoft site and honestly it reads like it was written for someone with a computer science degree. I have no idea what a 'severity level' means in practice or whether we even qualify for certain tiers.

What I'm really trying to figure out is: is Microsoft Unified Support the only real option for getting serious help with Microsoft products, or are there alternatives that might make more sense for an organization like ours? I don't have a huge budget and I'm a little worried about locking into something expensive that's designed for Fortune 500 companies.

Any plain-English guidance from people who've actually navigated this would be genuinely helpful.


r/sysadmin 2h ago

General Discussion Interview Question: How often do you update/patch your system?

16 Upvotes

I was asked this question during an interview and I said "it depends on what exactly you're updating, but I update as often as it's needed."

I don't think this was the answer they were looking for, but how would you answer this question?


r/sysadmin 7h ago

General Discussion IT Site Support Specialist - advise

12 Upvotes

Hi all,

I have an opportunity to transition to a new Site IT Specialist role at a mine site (Perth AU) it's a full time 6 month fixed term role [possible for extension]

I have been with the company for around 3 years now [full time and contracted], and I have good IT support experience [service desk / desktop support], most recently in project-based windows 11 rollouts at mine sites [fifo] covering Corporate and OT environments.

My main worry is that I don't have a lot of knowledge and experience around:

- Network configs/servers/netwroking lingo and terminolgies

- Setting up comms racks, configuring, troubleshooting Cisco switches, Wi-Fi APs setup and troubleshooting

I do have an open to learn attitude and i know alot of these things ill learn hands on when im up there and asking alot of questions etc.

Are there any readings/courses anyone can recommend i can look into?

Thanks in advance :)


r/sysadmin 2h ago

Microsoft Microsoft documentation written by AI

10 Upvotes

r/sysadmin 3h ago

Question 2 Servers with Identical SID's

10 Upvotes

I have 2 specific 2025 Server VMs that apparently have the same SID. I know what you are thinking.... they were imaged and I forgot to change them. That is not the case. They are both completely fresh installs and I have no idea how this happened. I have never cloned a machine as long as I have worked for this company.

Long story short, I need to get one of them changed.

If I run the following without the /oobe will anything on the system be effected such as any existing applications, software, settings, etc. My understanding is that it will have to be re-added to the domain. Anyone have any experience with this?

cd %WINDIR%\System32\Sysprep 
sysprep.exe /generalize /shutdown

r/sysadmin 2h ago

Trying to force policy that user account may not be shared.

5 Upvotes

Hi it's normal in IT that you enforce a policy that user accounts may not be shared or transferred /given to new users right?

Situation is that a partner company that uses our infrastructure used 1 user account for interns for a long time. If the next intern started they give the account To the next...and so on and on. They did not even change the password.

As IT responsible I said they cannot do this any longer that way. And I do not want to support this any longer. Every user also interns need to have an individual/ personal account. Reasons are obvious for me... Accountability, managing the accounts in general, gdpr,...

Example of 1 risk: access to the mailbox or onedrive of the account can have personal data stored from the previous user. So I say sharing accounts is not ok period. But they still keep fighting me for this. They do not want to understand. I'm tired of the discussion. The arguments that they use are : we used it before like this without any issues .

In the new it policy for them it's included. I have no mandate to enforce but I warned my boss about this and I hope my boss will support me..
I was right... With the call on this with the partner... Am I right to try enforcing this?

The only thing is if directors can formally accept the risk to me. But then why bother with security in general? I'm tired and frustrated by this bullshit. I'm doing it the correct way or on the long run I'm changing jobs ...

Any advice?


r/sysadmin 44m ago

Headless Remote Win10

Upvotes

I have a few HP Mini's deployed to remote locations that are headless and a real pain in the ass to access physically. They are running Windows 10 pro (I know!). Anyway I added a smart plug so I can remotely reboot them, but even so I regularly find they don't come back online (at least not so I can go on with Teamviewer or Tailscale).

Whenever I go out after one of these outages I find that usually its on a pre-login screen asking if I want Windows Backup or something like that.

To get around this I am seriously thinking of installing Proxmox and running Tailscale on the host or is there a better way?

I assume Proxmox would come backup cleanly after any reboot.


r/sysadmin 25m ago

Enabling "Restrict Unauthenticated RPC clients" (Authenticated) on Exchange Server — any real-world breakage?

Upvotes

We're working through a CIS Benchmark remediation and one of the findings is:

>

We're planning to set this to **"Authenticated"** (not "Authenticated without exceptions" — we're aware that level is much riskier and more likely to break things) on our **Exchange Server SE** environment.

Before we push this via GPO, I'd like to hear from anyone who has actually applied this in a production Exchange SE (or 2019) environment:

* Did it break **Outlook Anywhere / RPC over HTTP** for any legacy clients?
* Any issues with **MAPI/RPC** connections from older Outlook versions?
* Any impact on **DAG replication** or **Active Manager**?
* Did it cause problems with **Exchange Management Shell / EAC** functionality?
* Any unexpected issues with **AD communication** (since Exchange talks to DCs heavily over RPC)?
* Did you apply it to Domain Controllers as well, or keep DCs and Exchange servers on separate rollout schedules?
* Since Exchange SE is fairly new, has anyone tested this specifically against SE's RPC dependencies, or is it safe to assume behavior is the same as 2019?

Our environment: Exchange Server SE, mostly modern Outlook clients on MAPI/HTTP, not fully certain if any legacy RPC/TCP clients remain in the environment.

Any war stories, gotchas, or "wish I'd known this before enabling it" experiences would be really helpful before we roll this out.

Thanks in advance.


r/sysadmin 1h ago

Dell Repository Manager ISO gives errors when running on host

Upvotes

Hello. I've used the DRM successfully dozens of times in the past. I recently have seen errors when I attempt to run the ISOs I create from DRM. This is happening on both DRM 3.5.0 and 3.5.1 running on a Win11 client and being applied to all my R640 servers and they are running the latest BIOS: 2.28.1. All of the catalogs and plugins are up to date.

Using the DRM software I simply choose the "Platform Bootable ISO" option, I select the system: R640, chose the location to save the ISO file, and then I click on CREATE. The job runs successfully.

When I go to apply the ISO to the system, either using iDRAC to virtually present the ISO file on boot or using any type of application to send the ISO to a USB drive I can get the system to successfully boot into the loaders after starting Suse Linux. That's when I get the errors.

Every package in the bootable ISO attempt to install the updates. Then I get:
Trying to Upgrade DSU
Failed to create Support Directory
<Package Name>.BIN Error: Package execution requires 'root' user privileges.

I see this for multiple packages and then it eventually just hangs. With this being an automated process in the DRM to create the ISO I'm not able to intervene and elevate privileges. But I shouldn't need to with this process. Has anyone else seen these issues before and successfully resolved them?


r/sysadmin 1h ago

General Discussion GLPI vs Zammad: What’s Your Experience?

Upvotes

Hi SysAdmin family,

Is anyone here using GLPI or Zammad as a helpdesk/ticketing system?

I’d love to hear about your experience with either platform, especially:

  • Pros and cons
  • Number of users
  • Number of agents
  • Average tickets per day
  • Overall environment/setup
  • Performance and reliability
  • Any issues or limitations you’ve encountered

If you’ve used both, I’d especially appreciate a comparison between GLPI and Zammad.


r/sysadmin 2h ago

Question How often do you see "consultants" in smaller labs?

3 Upvotes

I love optimizing and automating things. I have seen many labs (EDU sector) doing updates and deployments manually or wasting a lot of times doing things that can be automated in an weekend. I have previously worked in a lab and loved automating some of their processes. Have you seen "consultants" being hired to automate / optimize IT labs workflow? Maybe this is more of a career question as to if this is possible / hourly rate


r/sysadmin 3h ago

Question Server hygiene checklist for someone self-managing a handful of VPS?

2 Upvotes

I inherited server management duties from a coworker who left, and honestly it was held together with cron jobs and good intentions, now I'm trynna get backups, firewall rules, and basic user hygiene acc consistent across our boxes instead of tribal data. What's on your baseline checklist?


r/sysadmin 6h ago

Connecting an innovation workflow to jira without creating a permissions nightmare

2 Upvotes

The integration between an innovation workflow and project management tools like jira is where most setups fall apart

Ideas get approved in one system and then someone manually creates a ticket in jira, which means duplicated data, broken context, and permissions that dont align between the two platforms

One way sync is almost worse than no sync because it creates a false sense of connection while the actual data drifts apart


r/sysadmin 6h ago

Question MDE-managed Windows Server 2025 not receiving Intune ASR policies

2 Upvotes

I have a physical Windows Server 2025 Hyper-V host that is onboarded to Microsoft Defender for Endpoint through Azure Arc and managed through MDE Security Settings Management.

The server shows up normally in Defender, Intune, and Entra:

- Managed by MDE

- Enrollment status shows "Success"

- Recent check-in times in both Defender and Intune portals

- Entra device object has managementType = MicrosoftSense

- All other Intune Endpoint Security policies are applying successfully

The problem is specifically with Attack Surface Reduction policies.

I have a production ASR Rules policy assigned to All devices. Every other MDE-managed server gets it, but this server never appears in the policy reporting at all.

Get-MpPreference originally showed only 2 ASR rules. I discovered those 2 rules were being configured by Local Group Policy. I removed that local GPO, confirmed the registry policy path was removed, and Event ID 5007 showed both ASR rules being removed.

It has now been about a week and the Intune ASR policy still does not apply.

Using a Get-MpPreference command shows no ASR rules being applied.

I also created a brand-new ASR test policy with only one rule in Audit mode and assigned it directly to a group containing this server. The server still does not appear in that policy's reporting either.

These are the things I have checked so far:

- Sense service is running

- WinDefend service is running

- Defender AV running normally

- MDE Client Analyzer confirms connectivity to MdeConfigMgr and other MDE cloud endpoints

- No remaining Defender/ASR local Group Policy settings present

- Other Intune security policies continue to apply successfully

- Server is not domain joined; it is a workgroup Hyper-V host connected through Azure Arc

At this point it seems like ASR policy evaluation/delivery is broken specifically for this device, while the rest of MDE Security Settings Management works normally.

Has anyone run into this with an MDE-managed/Azure Arc Windows Server, especially Server 2025? If so, what fixed it?


r/sysadmin 8h ago

Nexthink and 1E/TeamViewer DEX - Real World Experiences

2 Upvotes

Hi all!

So, we're in the midst of selecting a DEX solution for a large Enterprise, and I'm looking for some general feedback on TeamViewer's and Nexthink's DEX solution, "in the real world", as it were.

Suffice it to say, we have dealt heavily with the vendors themselves, and they have gotten us customer interviews, but all of those are clearly "curated".

I know DEX as a solution, as a whole, will have a lot of... "opinions", but from a "what we need next" perspective, we're well squared away with NEEDING one, or at least seeing value in the products as a whole.

If the response is "just do everything in Intune" or "fuck DEX it's silly" or "TeamViewer once hacked my Grandma", I will upvote you and give you a cursory "thanks", but I would ask to just get 'real' responses :)

If you're comfortable with meeting on LinkedIn/having a discussion over the phone, be 100% open to that. DMs/PMs and such!

For the product suite, to define this better:

1) Nexthink Workplace Experience | Nexthink

2) TeamViewer TeamViewer DEX | TeamViewer Which includes the TeamViewer tensor agent, remote control, Tia features throughout.

Thanks in advance, and feel free to farm karma if that's your thang!