/r/sysadmin
A reddit dedicated to the profession of Computer System Administration.
A reddit dedicated to the profession of Computer System Administration
Community members shall conduct themselves with professionalism.
Do not expressly advertise products or services outside of approved threads.
More details on the rules may be found in the wiki.
For IT career related questions, please visit /r/ITCareerQuestions
Please check out our Frequently Asked Questions, which includes lists of subreddits, webpages, books, and other articles of interest that every sysadmin should read!
Checkout the Wiki Users are encouraged to contribute to and grow our Wiki.
So you want to be a sysadmin? RTFM
Official IRC Channel - #reddit-sysadmin on irc.libera.chat Official Discord - https://discord.gg/sysadmin
/r/sysadmin
I am about to go to an interview where I'll be applying for IT support system admin role, the Hr said it will be for a person with backend experience this I have but I have never been a system admin how can I prepare to land the role, and what about the expected salary, what will I say?
Switch 3com 4500 obrigando colocar senha nova, como desativar?
Anyone else stick their finger into this particular MS light socket over and over and not learn? If you try to access an account's MB before assigning Read & Manage you'll get AccessDenied because of course you will. But if you go back right away and assign R&M you'll still be locked out no matter what browser/session/incognito/method you try to use until some arbitrary time later in the day. If you assign R&M first, you'll be granted access immediately. 🤦♂️🤦♂️🤦♂️🤦♂️🤦♂️
The number of times I have to explain to customers "MS has significant latency on some of their back-end configuration changes, and they are of random duration. Sometimes seconds, sometimes hours/days"
I am working on dynamically assigning membership to M365 groups and Teams. One of the fields I was hoping to use is the Employee Type field. My org would simply use this to distinguish between 'Salaried' and 'Non-Salaried' employees. The field has already been updated for all users, but when I go to make the rule inside of those M365 groups, I am not seeing value in the expression to add 'employeeType'. Maybe it's called something else? How could I go about this without needing to make custom attributes?
This is for folks out there not relying on gmail or similar, nor running their own mail server somewhere.
I have bought a domain as part of starting to develop my professional portfolio. I am looking for a straightforward, solid provider I can either point my MX records to and create a mailbox, or forward emails on to a gmail or similar.
I used to run Postfix and qmail servers back in the day for myself but that is far in excess of what I want to do now. Any recommendations for a solid provider?
Hi everyone,
I’m at my wit’s end with a frustrating issue we’ve been having since implementing iManage Cloud, and I’m hoping someone here might have experienced something similar. Here’s what’s going on:
I’m completely clueless as to what’s causing this inconsistency, and iManage support hasn’t been able to help. Are there any IT folks in the legal world (or beyond) who’ve run into similar issues with iManage and Office? Any advice or ideas would be greatly appreciated!
Thanks in advance for saving my sanity.
I knew very little about IT, and for my relatively small family business, have been tasked with researching and creating an ITAD operation. I am actively trying to learn the IT language, but I have a question. I’m trying to set up a station with a few PCs to run (1) hard drive wiping, (2)wipe verification software & (3) RAM testing
I’m leaning towards blancco for wiping, memtest86 for RAM, but unsure about wipe verification. What would you recommend for verification? Is there a better option out there for wiping and or RAM testing?
(Our secure destruction certification would require that 1 & 2 are not from the same vendor)
I appreciate whatever anybody would be willing to share. Thank you!
One of the drives in our backup is predicting failure what is a good replacement for it. 2.5”
Microsoft's Windows 11 suggestions seem to not be possible when I attempt to resolve this-
They suggested "- In the "Adapters and Bindings" tab, adjust the order of Ethernet and Wi-Fi so that they have the same priority, or set Wi-Fi to a higher priority than Ethernet." but there doesn't seem to be an Adapters and Bindings tab anywhere in the Network settings. I can't even go into the "Advanced" settings they suggest.
Second Suggestion was "- In the "Power Management" tab (within Device Installer -> Wifi Adapter), uncheck "Allow the computer to turn off this device to save power". When you are in the Wifi Adapter properties, there is no Power Management tab. It just does not exist.
gpedit.msc does not pull anything up in the command prompt.
As per someone's suggestion on the Microsoft forms, I tried to find the option to Minimize Connections to allow both Cell Modem and the Ethernet port to work simultaneously - but I can't find that anywhere either.
I have a customer out in the field that at this point is having us same day fly out to them to help in person and I need to figure this out for future issues.
All - I have been using the following tools:
cPanel (through Namecheap) private email to handle normal company email.
Beehiiv for my newsletter.
I am going to change over to Microsoft for my email. I have one domain there now, and I'm going to add the new domain (the one that's on Namecheap's private email now) to my existing 365 account. The DNS records appear to be a nightmare.
I've been using ChatGPT but it's hallucinating like a motherfucker.
I am most concerned about changes to DNS needed to keep Beehiiv working properly.
Does anyone have any high-level steps I should do here? Private email is like 20 years in the past, it's making me convulse and my hair is almost white.
Hey everyone,
I know this topic has come up in the past, but it looks like it’s been a couple of years since anyone asked here. I’m curious to hear what browser extensions you all find most useful in your day-to-day IT work.
Personally, I’ve found a few extensions that have made my life a lot easier, and I’m always looking to expand my toolkit.
What are your favorites? Do you have any hidden gems that save time or improve productivity?
I mean... what's this? :-D all company devices as well as personal devices have it in the search by default. Someone must have mistyped it 1000 times
I've got a file locked on a Hyper-V server and can't get it to delete or rename. It's the vhdx file, and when I attempt to rename it, it gives me the old, "file action denied you require permission to make changes to this file."
It's telling me I need permission from myself, though. That's the irritating thing. I have full control on it, and am the owner. Ugh...
I could reboot the machine, but it's a production machine, so that's a PITA. Any clever ideas? This is an old 2012 Hyper-V server (Yeah, I know... we're trying to get it all to go away) and it's driving me nuts. I have a functional backup and want to restore the machine, but it's just locked. It no longer shows up on Hyper-V Manager either. It's just the drive, not the machine files.
This is probably on me. I should have pushed back harder to make sure we really needed k8s and not something else. My fault for assuming the more senior guys knew what they wanted when they hired me. On the plus side, I'm basically irreplaceable because nobody other than me understands this Frankenstein monstrosity.
A bit of advice, if you think you need Kuberenetes, you don't. Unless you really know what you're doing.
Just wondering, as all of them breaking at the same time suggests there was a network change, but our network person says they've changed nothing so I'm wondering if MS maybe made a configuration change?
We are hybrid on-prem AD syncing to o365 environment and Exhange Online. I have approximately 500 users that have alias addresses (for Apple ID reasons). Now that our Apple ID project has completed, our user community is seeing the alias address for the recipient along with the default email address when composing email and it's causing some confusion.
Technically it doesn't matter which address the end-user sends an email to; we have the default and reply to address set to the proper email address. Unfortunately, we are getting a lot of noise from the user community and would love to just shut it down by hiding the alias addresses.
I did find some articles, but they all seem to be one at a time actions. I'd like to apply it to all users in the OU.
Any suggestions?
Looking for recommendations on a security camera system for a commercial building. Need something with LPR capabilities and remote real-time monitoring. It should cover entrances, parking lots, and interior hallways. Budget isn't an issue. Anyone here with experience or suggestions?
We have an old UPN suffix for a domain we have to remove from our AD/365 due to selling off a subsidiary.
Finding tons of documentation on how to add a UPN suffix, but nothing on removing one.
Anyone with experience doing this?
Is it just as easy as:
run a powershell script to find any accounts using that UPN
Change those accounts to use another UPN, or disable them
Delete the UPN from AD Domains and Trusts
I currently serve as a law enforcement officer, I’ll be graduating with a degree in cybersecurity around Fall 2026. I have no experience in tech fields. My classes involve some hardware, networking, operating systems, etc. Would I be able to apply for a system administrator role upon graduating? I do some Try Hack Me labs online. Should I be doing other things more related to system work?
That's one of those projects I think about for years and had it half implemented a couple of times, but never perfect. Time to check if there are new developments: We have a big storage server at Hetzner with far too much RAM and CPU. What I dream about is a big log sink, which takes all event logs of all clients and servers together with syslog from the unix machines and puts it into a big ELK like stack. We had this kind of running with Greylog some time ago (only for syslog) and I hear a lot of good things about Clickhouse now. The idea is, that, when we suspect a problem at a client we pull up a web interface, filter for client machine and errors/warnings, last hour instead of RDPing into the AD server and pulling up the event log of the PC.
The stack itself was never really a problem, but what I am really looking for is an easy one click/script way to collect and send the logs from the senders to the sink. So, a powershell on a windows 11 PC we can roll out AD wide with a GPO or a one line shell script on the unix side (something like the checkmk installer).
ideas?
Hi guys,
I have the following scenario/problem:
Sophos XGS Version: SFOS 20.0.0 GA-Build222
Network1: 192.168.200.0/24
Network2: 192.168.44.0/24 (Connection through static route with Gateway: 192.168.200.20)
Connection NW1 to NW2 works fine.
Connection from VPN to NW1 works fine.
Connection from VPN to NW2 doesnt work.
Firewallrule: VPN to NW1 and NW2 allow all
SSL VPN Config:
Permitted network resources: NW1 and NW2
Tracert:
-> VPN Gateway
-> 192.168.200.20: Destination host unreachable.
Does someone know why i cant reach the host in NW2 from VPN?
Thanks!
Hi,
Does anyone esle have the issue that their Windows 11 clients are no longer respecting some GPOs, especially Windows Update policies.
Some settings were moved into a new "legacy-settings" sub category, but are still configured and applied.
I have it setup so that Updates are installed daily at 4pm, but restarts are not allowed during the hours 7am-6pm and restarts are not allowed while a user is logged in. The new "specify deadline..." policies are not configured.
The clients still respect the WSUS connection and only install what I approve, but they are just restarting without the option to delay at around 4pm +-15mins
gpresult shows that all GPOs are applied correctly without error
and yes, we pushed 24H2 to prod already and other than these GPOs, we have no problems.
This seems like a weird gap in Microsoft patching. I know it's 2024 and everything is connected and so on, but in the worlds entirely disconnected from the internet, there's no good way I've found to keep these stupid things updated. I shouldn't be having to use shady third-party link generators to get the update packages. How is everyone else handling this?
Hello, does anyone know why there's no DeviceEvents table in Microsoft Defender Advanced Hunting?
Hi everyone,
I’m from a mid-size organization, and we’ve been exploring VOIP.ms as a potential VOIP provider for our organization's business line. So far, it looks pretty promising, but I wanted to hear from others who’ve used their services.
How reliable is VOIP.ms in the long run? Have you faced any major downtime or issues with call quality? Also, how’s their customer support when things go wrong?
We’re trying to weigh our options, and hearing about real experiences would be super helpful. Thanks in advance!
Hi,
I'm managing IT for a school, every machine on our Educational network has an IP reservation on our DHCP server, but now their are some teachers that connect their personal Laptops via LAN cable to the Network instead of using the WiFi that is on a Seperate VLAN.
How can I prevent my DHCP server from leasing an IP to machines that do not have a MAC-Reservation? unused ports on our switches are already blocked, but they simply unplug the Computer in the classroom and use that cable.
Average hybrid environment with CA policies. Going to switch user sign in from password hash sync to pass-through auth. already setup the computer object. any issues like changing the way people sign in or forcing sign outs? the enable signgle sign on box, does that need to be checked or no?
You really can’t trust anyone but i feel like my manager doesn’t have my back and can’t trust him much.
He has told me many times that he doesn’t ask for a raise to his boss (why do I need to know this?)
He tells me he knows xyz but really doesn’t know.
I feel he doesn’t always like when I understand a technology better than him.
When a user has an issue he comes and says that the user must have done something to screw things up without even knowing all the details. Always pointing fingers at someone.
I ask him questions on teams and he doesn’t respond a lot of times.
He claims he knows Intune and told me that I was not an expert at it, but I set it up and he comes asking me questions about it. I was going to show him how to sync devices. I was literally at his office and he wasn’t doing anything and told me he will figure it out himself.
Maybe I’m exaggerating but I’m looking for a new job.
Is there a way to show how well MFA is protecting?
Specifically looking to see:
How many people have given up their credentials in the last 30/60/90 days?
Also, to see if those credentials were tried and then not able to get passed MFA?
All of the sudden since last week, websites we’ve been able to access regularly now won’t fully load or are completely blocked unless we allow United Arab Emirates on the geo-ip filter of the firewall. Seems that the websites in question are all hosted on AWS. Thought it was a DNS issue at first as flushing DNS on DCs looked like it resolved it, but seems to be back again and the only solution I’ve found is to unblock UAE on the firewall. We are based in the US. Anyone else experiencing this or any thoughts?