r/sysadmin 10h ago

General Discussion Dell quivalent of HPE SPP ISO?

2 Upvotes

Hey guys, first time working with DELL PowerEdge R470 Server.
I just want to update the firmware of components in it, and install bare metal Windows Server 2025.
On HPE DL servers, i would just set up ILO, and update firmware using SPP ISO that i would download specifically for that model.
So, is there something similar for DELL iDRAC? Or is there a better method?
Thanks guys


r/sysadmin 5h ago

Dialpad Down

1 Upvotes

Down detector showing issues but no official announcement. I got a number of users reporting issues. Can't seem to make any calls on mine either


r/sysadmin 6h ago

Azure file permissions not persistent across different machines

1 Upvotes

Weird issue with Azure file

User created a number of new folders with strict permissions. She herself has full control to the folder.

It works on her desktop, but she can't access those same files from her laptop.

On the laptop she's logged in with the same account, she can see the folders and the share, but when she goes to open a file it says she doesn't have permission.

In the properties of the file I can see her username has full control.

Same file opens just fine on her desktop, same login.

Any idea?


r/sysadmin 12h ago

Question Can hardware bound credentials reduce session theft and token replay?

1 Upvotes

Hardware-backed credentials can make stolen secrets less useful because an attacker cannot complete the necessary cryptographic operation without access to the authenticator. That provides meaningful protection against several credential-phishing and replay scenarios, but the benefit can weaken if the post-authentication session or refresh token remains a portable bearer artifact.

Hardware binding clearly strengthens initial authentication. Reducing session theft and token replay after login usually requires the application or authorization server to enforce sender-constrained tokens, proof of possession, or another mechanism that binds use of the token to a device-held key.

How are teams balancing this additional protection with lost-device recovery, shared administrative workflows, break-glass access, browser compatibility, and endpoint-compromise risk?


r/sysadmin 12h ago

Question Can an identity graph uncover orphaned accounts and stale access grants?

1 Upvotes

We can run periodic reviews and export permissions from every system, but neither approach is very good at showing relationships. A graph model should connect people, accounts, groups, applications, credentials, roles, owners, and inherited permissions, then identify accounts without active employees, service identities without owners, or access that remains attached to retired projects.

Has anyone used this effectively? I would be interested in examples where relationship-based analysis found something that standard IGA certification or per-application access reviews missed, particularly for cloud, SaaS, automation, and non-human identities.


r/sysadmin 19h ago

Question Azure AD VM

1 Upvotes

Hi All,

We have a hybrid environment where the on-premises AD/DNS servers are currently configured with external DNS forwarders.

For the Azure VMs, should we use the same external DNS forwarders, or should the Azure VMs use Azure DNS (168.63.129.16) instead?

Thanks,


r/sysadmin 20h ago

Come to me lords of the network

1 Upvotes

We are transitioning off of UniFi switches to Aruba Instant On switches. We have a stack of 1960s that connect to a 1930 via fiber from one side of the building to the other that 1930 connects to another stack of 1960 10 gig switches. using just regular ethernet uplink the 1960 stack connects to two other 1930 switches. The unified architecture is the exact same minus the 10 gig switches every time we attempt to switch over the network to the Aruba switches something goes wrong. We’ve done it multiple different ways. I’ve staged the switches in production on a separate management LAN to eliminate any UniFi switches in between the Aruba communication but every time we try to do the switch over the health of the Aruba’s goes bad even once we connect everything to the DNS servers we get no DNS. The Aruba switches will be green all week long no issues. I plugged a laptop in. I get an address. I can connect to the Internet, but as soon as the day comes where we try to switch the connections to the Aruba switches something goes wrong and we can never figure out how to get it to work. Please help, I’m thinking there’s something wrong on layer 2 but I feel as though I’ve eliminated all these things and have hit a wall as soon as I start moving connections from the unifi to the Aruba it falls apart. I started with removing the firewall uplink to the Unifi switches and only had an uplink to the Arubas but everytime like I mentioned the health goes to or age for the cloud then I can’t even access google let alone get a dhcp address. Even if I do get a dhcp the dns doesn’t resolve even basic websites like google.


r/sysadmin 2h ago

Question WSUS SyncFailure

0 Upvotes

WSUS sync failing with ImportUpdateError — Server 2025 / MECM 2509

I'm setting up a lab with Windows Server 2025 and Configuration Manager 2509. WSUS is installed on the primary site server and the SUP is configured.

WSUS synchronization starts but consistently fails with:

Result: Failed
Error: ImportUpdateError

UpdateErrors: {}

Server:

  • Windows Server 2025
  • WSUS version: 10.0.26100.33158
  • Configuration Manager 2509
  • WSUS upstream: Microsoft Update
  • No proxy

I've also confirmed outbound TCP 443 connectivity to sws.update.microsoft.com.

The WSUS SoftwareDistribution.log contains:

invalid update identity (AtLeastOne Prerequisite) in XML for update

and this is occurring with multiple different update GUIDs.

Has anyone encountered this on Server 2025 recently, and is there a known fix or workaround?


r/sysadmin 4h ago

Career / Job Related Want to become a sysadmin - do I continue with help desk or transition to the military

0 Upvotes

I currently work remotely for a Mac-based MSP. I'm making $23.50/hour. As soon as I got my Jamf 100 cert I applied and got lucky enough for them to give me a shot. I mostly do onboardings/offboardings and occasionally password resets and deleting MDM alerts.

I also have an offer to join the Canadian military as part of their IT team. It pays the same but I would have way more things to do especially in networking(ad-hoc networks, VSAT deployments, network security etc).

I'm guaranteed a promotion within 3 years that bumps me up to 82k if I don't wash out.

I don't know if I should stick with my help desk job, stack more certifications and find something better or if I should just join the military instead.

What do you think?


r/sysadmin 7h ago

Question Intune - iOS App Deployment Issue (VPP)

0 Upvotes

Hi all, please help cos my head is gonna explode.

I've got ABM set up with Intune for MDM and VPP.

This a virgin install so very basic.

my iPad is enrolled and registered and pulls policies.

The problems occur when trying to get apps down..

I've tried a few apps via VPP, assigned to "all devices".

on the iPad it says I need to sign in to the App Store to get it..

I've deployed the app via intune in device mode and I cannot figure out why this isnt playing - please help!


r/sysadmin 7h ago

Conditional access policies requirement

0 Upvotes

Hi,

Thanks in advance for any assistance - have a bit of a headache with the set-up.

We use Azure Virtual Desktop and currently have a Conditional Access policy that blocks access from locations outside our exempt locations, such as our office IP addresses.

We have a secondary Conditional Access policy that provides an exemption from this restriction. This policy is currently configured to block access from All locations, with a security group excluded from the policy so that members of the group are not subject to the block to facilitate travel.

We are now looking to limit this further to just the country that they are visiting.

For example, if a user is travelling to Spain and is a member of a security group such as "AVD Exclusions - Travel", we would want their exemption to apply only while they are accessing AVD from Spain.

I do not want to exclude Spain as a location, as this would allow all users to access AVD from Spain. On the other hand, the current set-up limits it to security group, so 1 user, but accessible from 'All locations'. Is this possible in a single policy?


r/sysadmin 8h ago

Question Four Cornerstone / Oracle partnership - I need an adult!!

0 Upvotes

Hello, does anyone here have experience with the Four Cornerstone / Oracle partnership?

They were our previous Oracle partner and we paid them $15,000 for license cost in March.

Four Cornerstone never submitted our renewal to Oracle in time before Oracle just recently severed their partnership with Four Cornerstone, and now Oracle is saying we never paid for our renewal even though they know we paid Four Cornerstone, and we are unable to get anyone from Four Cornerstone to reply to us in hopes of returning our $15,000 they never spent in the way we contracted them to.

We are not a big company, and we are also not having the best fiscal year, so $15,000 to us is a massive amount of money to have just basically given away with nothing in return, and the lack of response from Four Cornerstone honestly feels borderline criminal, I'm not sure how you can just keep someone's $15,000 and not return it while also not doing what you agreed and promised to fulfill.

We just want our money back, man.

If anyone has any experience with this exact situation, or maybe knows anyone at Four Cornerstone they can politely ask to reply to me, that would be spectacular.

Here is the email correspondence between Oracle and us, I have redacted information that would identify anyone other than the Four Cornerstone and Oracle company names

Hi REDACTED (OP),

I’m reaching out regarding REDACTED (OP) renewal and, unfortunately, need to share some difficult news about the status of the MySQL renewal that was submitted through Four Cornerstone in the spring. Our records indicate that REDACTED (OP) provided its purchase order to Four Cornerstone in connection with the renewal; however, Four Cornerstone did not submit the renewal order to Oracle, and the renewal was therefore never completed with Oracle. As a result, REDACTED’s Oracle support and licensing renewal was not processed as expected.

I wish this situation was resolved sooner, particularly given that REDACTED (OP) believed the renewal had been completed. Four Cornerstone is no longer an Oracle partner and did not renew its annual Oracle partnership. REDACTED (Oracle employee) cc’ed made countless attempts to reaching out to REDACTED (FC employee) at Four Cornerstone to have the required partnership renewed and the REDACTED (OP) order submitted, but REDACTED (FC employee) went silent on us.

Because Oracle never received the renewal order from Four Cornerstone, any funds REDACTED (OP) paid directly to Four Cornerstone were not received by Oracle. REDACTED (OP) will need to pursue reimbursement of those funds directly with Four Cornerstone. I have included REDACTED (Oracle employee), our VP of Alliances and Channels, who has been involved in our efforts to address the situation with Four Cornerstone and can help support REDACTED (OP) through the transition.

From an Oracle standpoint, our priority is to get the account properly renewed and bring everything current. To accomplish this, we will need to backdate the new MySQL renewal order to May 5, 2025, with a renewal term through , May 4, 2027, so that the appropriate coverage is in place for both the prior renewal period and the upcoming year. Does REDACTED (OP) have another preferred reseller you would like to use for the renewal? If not, we would be happy to provide a partner recommendation and help coordinate the transition to make the process as smooth as possible.

I understand this is an extremely unfortunate situation, and I’m very sorry that REDACTED (OP) has been put in this position. My goal is to make the Oracle side of the resolution as straightforward as possible and help get the account back to a completed renewal without any further disruption. I would also be happy to schedule a call with you to walk through the situation and answer any questions you may have.

Thank you, and I look forward to hearing from you soon.

Best regards,

REDACTED (Oracle employee)

REDACTED (Oracle employee) | MySQL Enterprise Account Manager
Mobile: REDACTED
Oracle MySQL
Oracle Way | Austin, Texas 78741


r/sysadmin 9h ago

Question Defender Cloud Apps - info on policies matched

0 Upvotes

So I'm a first line tech just trying to improve my knowledge about stuff and wondered if anyone could point me in the right direction. We have cloud apps policies in place to prevent users downloading company files on their personal devices. Every now and again this policy gets matched on users corporate devices, but I'm unable to work out why.

Is there anywhere it says what has caused a policy to match? The device is compliant, the user isn't a risky user or anything like that. By everything I can see the policy shouldn't have matched and blocked the user but I don't know if there is somewhere else I should be checking.


r/sysadmin 5h ago

Question M365 sending out calendar invites randomly

0 Upvotes

Not sure if this is a general 365 bug or something on our tenant but currently all recurring meetings are being resent.

I can see them in the sent items for my own account and I’m also receiving lots of calendar invites for meetings I’m already part of from others.

Anyone else having weirdness or is it just us?


r/sysadmin 6h ago

Question Advice for troubleshooting random slowness

0 Upvotes

How do you troubleshoot random slowness reported only by a handful of users? Some background: these few users are on a site-to-site VPN and separate location than the primary network.

The main office does not report any slowness issues. A few weeks ago, users at the secondary office started to report slowness in Outlook, and other general applications they use for work. The ISP reports modem is good and all tests look good.

We ended up replacing the firewall because it was a slightly older model thinking it would resolve the issue. A couple days have passed and users are still reporting random slowness.

Speedtest comes back good, and the only time i was able to replicate the slowness is when I did a test Teams call with the user.

How would you approach a situation like this? They are plugged directly into the firewall and there is a switch at the location as well but its not an older model.

TIA


r/sysadmin 10h ago

Question File Server Assessment

0 Upvotes

Hi All,

We have a few file servers and are trying to identify archived data based on the following conditions, but I believe something is not correct. We have 18TB but showing only 3TB for archive with following contion

Condition Classification
Modified ≤ 3 years OR accessed ≤ 180 days Migrate / Active
Modified > 3 years AND accessed > 180 days Archive Candidate

With this condition,

Migrate: ≤30% of folder data is older than the cutoff - actively used, recommend moving as-is.
Archive: ≥80% of folder data is older than the cutoff, AND no file in the folder was modified in the last 30 days.
Review: Falls between the two thresholds, OR is old by volume but was touched recently, OR had partial access errors during scanning.

Above condition give us more data to archive?


r/sysadmin 12h ago

Non Lenovo coded SSD for Lenovo ThinkSystem

0 Upvotes

Related to Lenovo ThinkSystem SR650 V3:

I have a bunch of generic Samsung PM893 SATA SSD I would like to use in the mentioned host. Are there any potential compatibility issues to be able to to utilize the disks (without errors)? It's not a production system, but I would still like to avoid any quirks related to the disk setup.


r/sysadmin 22h ago

Any help appreciated

0 Upvotes

We've migrated an email domain from one M365 tenant to another but an old exists on the 'old' tenant. This app sends messages via a mailbox in the tenant using EXO and M365 mail routing. However, the mailbox sends as a temporary domain (given the real domain is in the new tenant). How can we rewrite the domain on the way out with M365 or relay through an external SaaS solution that would send on the email and rewrite back to the old domain


r/sysadmin 23h ago

Windows 11 autounattend fun times

0 Upvotes

Can someone explain to me why both Windows Configuration Designer and schneegans.de Autounattend.xml generator both have a nice convenient way for you to set the hostname of the target PC to the serial number using the %SERIAL% variable... and ONLY ALLOW the %SERIAL% variable... ONLY FOR THAT TO NOT EVEN WORK.

Everything you find online regarding those tools says "This tool makes it SUPER easy to set the hostname to the serial number, just use the SUPER convenient hostname field and use variable %SERIAL%."

Then when it doesn't work and you search online for that feature NOT WORKING and suddenly everything you find says "Yeah, it's just not possible for the installer to query the BIOS to get the SN." or something like that but essentially its endless information stating that it just doesn't work...

So... which is it people?

Also now I need to figure out where and how to inject a PowerShell script because even a single line won't cut it.


r/sysadmin 8h ago

Has anyone actually had an AI automation go wrong badly enough to change their approach?

0 Upvotes

I've been thinking about where the line should be drawn as AI moves from answering questions to actually taking action in IT environments.

It's one thing for an AI to suggest a fix or pull information from the KB. It's another for it to execute the fix without a human in the loop.

Password resets and basic troubleshooting seem relatively low-risk. But what about account provisioning, access changes, endpoint actions, software deployments, firewall rules, or changes to production systems?

At what point does the efficiency gained from autonomy stop being worth the risk?


r/sysadmin 19h ago

Help Desk → Cloud/Infrastructure/SWE: How should I position myself for my next role?

0 Upvotes

Hey everyone! Looking for some career advice from people who have been in tech/IT for a while.

I’m currently a Help Desk Technician and have been in the role for about a month. I’m definitely not trying to quit immediately, but I want to start positioning myself now so that once I’ve gotten some solid experience here, I can move into something more advanced.

My long-term interests are Cloud, Infrastructure, or Software Engineering, and I’m trying to figure out what I should be doing while I’m in Help Desk to make that next jump easier.

A little about me:

  • BAS in Information Technology
  • Currently pursuing a Master’s in Software Engineering – DevOps
  • Currently studying for the CCNA
  • AWS and GCP certifications
  • 2 previous internships: Software Engineering and Marketing Engineering
  • Built and currently run a small startup/app with 250+ users that generates close to $100/month
  • Currently working full-time Help Desk

I know someone is probably going to ask why I didn’t just pursue SWE after my internship. Basically, it’s 2026 and the SWE market is insanely competitive lol. I spent around 8 months unemployed, applied to literally thousands of positions, and only landed one SWE interview. Meanwhile, when I started applying to IT/support/infrastructure-related positions, I was getting significantly more interviews and eventually landed my current Help Desk position.

So I took the opportunity instead of continuing to sit unemployed.

The Help Desk work itself has actually been easy and pretty fun so far, and I’ve already done a lot of this type of work before. I just don’t want to get comfortable and realize 2–3 years from now that I haven’t built the skills needed to move up.

If you were in my position, what would you focus on over the next 6–12 months?

What roles would you target after Help Desk? Sysadmin? NOC? Network Support? Cloud Support? Infrastructure Support?

And besides the CCNA, what skills/projects would give me the best shot at eventually moving toward Cloud/Infrastructure/SWE?


r/sysadmin 6h ago

Question I don't know where else to go for this!

0 Upvotes

So I have a handful of users, myself included, that are experiencing the weirdest issue with their mice and keyboards. We will be typing and suddenly it stops then after maybe 15 seconds it will type out everything but it will be missing some keystrokes. The mouse will do the same it just stops moving for like 15 seconds then comes back. Sometimes it happens once and then works after and sometimes it's a few minutes of it working on and off. It is only happening to maybe 10 users. I have replaced keyboards and mice, replaced dongles, changed out for wired sets, turned off the power settings that let windows turn off USB devices. It is happening on brand new devices and 4 year old devices. It happens on devices that are in intune and devices that aren't in intune. There doesn't seem to be a pattern. I'm going to pull out my non existent hair. Does anyone have any ideas?

Edit: I also tried plugging everything into all USB ports on the laptops and hub monitors.


r/sysadmin 8h ago

General Discussion Why do companies choose to depend almost entirely on Microsoft?

0 Upvotes

TL;DR: I understand why non-technical companies choose M365, but why do technically capable companies, especially in the EU, place so many critical services behind Microsoft SaaS when on-premises or hybrid infrastructure is a realistic alternative? If you genuinely considered both, what ultimately made Microsoft win?

I’m probably what many people here would call an old-fashioned sysadmin. I run a mixture of Linux services and Windows Server, with authentication, storage and other important services kept on infrastructure under our control and largely detached from Microsoft SaaS.

This is not intended as a “cloud bad, on-prem good” post. I’m genuinely trying to understand the reasoning of companies that have chosen the Microsoft-first approach.

The recent Outlook outage, together with posts about entire M365 tenants becoming disabled or “deauthenticated,” made me think about this again. A general outage is usually temporary and affects many customers, while a tenant-specific issue may leave a small company completely dependent on Microsoft support. Both cases demonstrate how many critical business functions can depend on the same provider.

From a business-continuity perspective, being locked out of a tenant for a day, or any prolonged period, is no better than hardware-related downtime in an on-premises environment. If employees cannot access email, files or other essential systems, the business is down regardless of whether the failed component is in the company’s server room or a provider’s cloud.

Microsoft’s infrastructure is obviously far more redundant than anything a small company could build. What worries me is not only a normal service outage, but a tenant-specific administrative problem where the company depends on Microsoft support to restore access. A smaller customer may not have an enterprise account team capable of escalating the issue immediately, so the business could potentially be seriously affected for days.

I understand many of the advantages: remote onboarding, tight integration between identity and endpoint management, collaboration through Teams and SharePoint and no need to maintain certain local infrastructure.

I also understand that the Microsoft route may well be the most sensible option for many non-technical organizations. A small law firm, for example, probably does not want to operate its own server room or rent and maintain servers somewhere else.

What puzzles me more is seeing technology companies make the same choice even when they already have the necessary knowledge in-house. They could realistically operate at least some of these services themselves, or design a hybrid environment, yet many still place identity, email, documents, endpoint management, telephony and authentication for unrelated SaaS applications under the same tenant. That seems to create an enormous common failure domain that they have the technical ability to avoid.

I’m also not convinced that this necessarily eliminates much administration. Operating local servers requires hardware maintenance, patching, monitoring, backups and disaster recovery. But properly managing M365 means dealing with licensing, Entra, Intune and who knows how many other interconnected services, along with constantly changing portals and Microsoft support. It seems more like a different type of system administration than substantially less system administration.

The question is especially interesting to me in the EU. Apart from GDPR and data residency, there is also the broader issue of making a company’s entire operation dependent on a single US provider.

So my question is mainly for people who genuinely considered both options, especially those working at technology companies with the skills to self-host: if on-premises infrastructure was a realistic alternative and there was an actual debate, what ultimately made you choose the Microsoft route?

I’m also entirely open to the possibility that I am overestimating the risks or underestimating the advantages. I would simply like to understand why the industry is moving so decisively in this direction while the traditional on-premises approach appears to be gradually disappearing.