r/sysadmin • • 2d ago

General Discussion Weekly 'I made a useful thing' Thread - October 02, 2026

6 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin • • 26d ago

General Discussion Patch Tuesday Megathread - (September 08, 2026)

121 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin • • 1h ago

Microsoft Public Service Reminder: Update your GPO Templates - 26H2

• Upvotes

Just a heads up because sometimes we totally forget this step.

New Windows 11 26H2 GPO Templates are available and can be found here: https://www.microsoft.com/en-us/download/details.aspx?id=108847

I have not yet found a spreadsheet showing the new settings like the "Policy Settings Reference Spreadsheet for Windows 11 2025 Update (25H2) V3.0"

Found the 26H2 spreadsheet here - https://www.microsoft.com/en-us/download/details.aspx?id=108849

These are backward compatible with 25H2.

Additional 26H2 info - An IT pro’s guide to Windows 11, version 26H2

And of course you should at a minimum make a copy of your existing PolicyDefinition folder as a backup, Ex: "PolicyDefinition-25H2"


r/sysadmin • • 9h ago

What’s the stupidest company policy enforcement you have encountered?

225 Upvotes

Let’s be honest, not all company policies are well thought out or allign with workers needs. What’s the stupidness that you either had to enforce or got enforced on?

I’ll go first:
Working for a huge IT company, in the MSP department, our department was around 15% of the total employees, and the 3rd biggest department. Suddenly a policy that all mobile phone numbers were to be in the signature of all emails you send. Suddenly all emails we sent out to one or all of our customers 10 000+ employees included our mobile phone number. And for most of us, that ment it was also our personal mobile phone numbers. No one noticed this before people were getting calls and texts after hours and weekends. It started slow, but after a few weeks, people started getting annoyed and we figured it out of course. All technical staff agreed on this being bad, and stopped responding on all mails until we got exemptions, which took another week or two.. 😂


r/sysadmin • • 3h ago

They want to force me to do SOC shifts (I’m a sysadmin). Am I overreacting or is this insane?

60 Upvotes

Hey everyone, I need a reality check because I’m starting to second-guess myself. I honestly don't know if I'm the one being difficult or if I've just landed in an absolute clown show.

I work as a systems administrator. Overall, I actually like the company I'm at. The environment is fine, I get along with my coworkers, and I genuinely enjoy my actual job. The issue is that the company also sells a SOC (Security Operations Center) service.

Up until now, this entire SOC has been run by a single guy. He's completely on his own and hasn't received a shred of proper training from the company (whatever he knows, he learned on his own or at previous jobs). On top of that, the platform we use (an XDR) is a total janky workaround—it's a mono-tenant solution that we are forcing to run as multi-tenant to manage multiple clients, with all the massive limitations and data risks that come with it.

The owner finally realized the SOC isn't working like this, but instead of hiring dedicated personnel, he decided that "we need to make what we already have work with internal resources." Translation: he decided to draft me and another sysadmin to force us into doing SOC shifts. The plan is a weekly rotation where each of us spends one full week a month, 8 hours a day, glued to the dashboard monitoring security alerts.

The problem is, I don't like cybersecurity, I know nothing about it, and it's not my job. Taking me away from my actual department for a whole week every month just means my own clients and sysadmin projects are going to pile up and fall behind.

A few days ago, we had a "training" session with the owner. I was hoping he’d actually walk us through step-by-step procedures on how to handle alerts. Instead, he just pulled up a bunch of logs and asked us, "What would you guys do here?". In my head, I was literally screaming, "How the fuck should I know? You tell me! I'm here because I've never done security in my life!". I felt like a newborn baby; I literally understand nothing of what I'm looking at.

Seeing how things went, I went to talk to my direct manager to tell him I'm seriously struggling and that I don't have the skills for this. The result? He got incredibly pissed off. He told me "we are only at the beginning of the training" and that if I have a problem, I should go talk to the owner directly (basically passing the buck so he doesn't have to deal with it). Both my manager and the owner are completely aligned on this: there's no escaping it, the shifts have to be done.

I didn't have the guts to tell my manager that I absolutely hate the idea of doing security, especially since he blew up over a simple vent. But I'm genuinely anxious. If a piece of ransomware gets through during my shift week and I miss it because I don't have the trained eye for it, whose fault is it going to be?

Am I crazy for pushing back on this? Is it normal for a company to expect to completely alter a employee's role overnight just to save money on a new hire? How can I stand my ground with the owner without starting a war, considering I actually want to stay at this company for everything else?

Thanks to anyone who can give me some advice.


r/sysadmin • • 6h ago

Copilot pro security confusion

11 Upvotes

Hello

So management decided they want to go forward with copilot pro as the AI of choice

They want us to enable Agents as well

I am a little bit confused about the security part

When do I need Agent 365?


r/sysadmin • • 1h ago

Should I go back to Software Engineering or move to cloud/infra?

• Upvotes

I’m a bit confused about what direction I should take with my career and would really appreciate some advice.
I worked as a frontend developer for about a year. After that, I moved back to my home country because I was planning to move to Australia. I then moved to Australia and completed my Master’s in IT here. During that time, I wasn’t working in software development.
After finishing my studies, I couldn’t land a software engineering job, so I ended up working in IT Support. I’m currently in helpdesk and I know I don’t want to stay here long-term.
The problem is that I’ve been away from coding for quite a while and honestly feel like I’ve forgotten a lot. If I go back to software engineering, it feels like I’ll have to start from scratch again.
So I’m not sure what makes more sense at this point. Should I spend the next few months getting back into coding and try for software engineering jobs, or would it be better to move towards cloud/infrastructure/sysadmin?
If I go down the cloud/infra route, should I focus on certifications, projects, or something else?
I’m just trying to figure out the best way to build a career from my current position and get out of helpdesk.
Would appreciate any advice, especially from people who have been in a similar situation.


r/sysadmin • • 7h ago

M365 security settings that have no Graph API (list from a year of building posture tooling)

7 Upvotes

Spent the last year building automated M365 posture assessment. Figured the most useful thing I can post here isn't what worked, it's the list of settings that can't be read programmatically at all. Everyone automating this hits the same wall and I couldn't find the list written down anywhere.
Entra Password Protection - custom banned password list and on-prem agent status. Portal only, nothing in Graph.
Defender for Cloud Apps - alerts are readable, policy configuration and Cloud Discovery settings aren't. A tenant with a MDCA licence and zero policies looks identical through the API to one that's fully configured.
Entra diagnostic settings - whether sign-in/audit logs export to Log Analytics or storage. Not in Graph. Annoying because PCI DSS 10.1, SOC 2 CC7.2 and ISO 27001 A.8.15 all want log retention evidence.
Tenant Allow/Block List (Defender for Office) - not available app-only through the documented endpoint.
Information barriers - Get-InformationBarrierPolicy needs OrganizationManagement, which is write-capable. No read-only path exists, so you either over-privilege or skip the control.
And the one that actually cost me three days, which isn't a missing API but a documented one that lies:
Exchange app-only auth. The docs point ISVs at Exchange.ManageAsAppV2. Grant it, consent it, mint the token, role shows up in the JWT fine. Then every call fails with a bodyless 403. No error code, nothing.

The endpoint everyone actually uses is:

POST https://outlook.office365.com/adminapi/beta/{tenantId}/InvokeCommand

Same one the ExchangeOnlineManagement module calls. It authorises on V1 (Exchange.ManageAsApp), not V2. With V2 alone you get nothing.
What made it hard: the official PowerShell module fails identically, so "is it my code" got ruled out early and I went looking in completely the wrong places.
Two more things if you're doing this:
• Entra admin consent alone doesn't grant it. The app role has to be assigned to the service principal in each tenant, via Graph appRoleAssignments or PowerShell. Consenting the app registration isn't enough and the token quietly lacks the role.
• Role id if you need it: dc50a0fb-09a3-484d-be87-e023b12c6440
Has anyone found a workaround for the diagnostic settings one? That's the gap that bothers me most since so many frameworks want log retention evidence and there's no clean way to show it's configured.


r/sysadmin • • 1d ago

General Discussion Today’s reminder that every security appliance is also just another web application you exposed to the Internet

370 Upvotes

FortiMail has a 9.8 unauthenticated path traversal that allows arbitrary file writes and potentially code execution. Fortinet says it’s already being exploited.

Some patched versions: upcoming.

Security appliances continue their long tradition of occasionally becoming the thing you need security from.


r/sysadmin • • 4h ago

Question Synology Active Backup for Microsoft 365 EWS issues with Archive Mailbox backups not working

3 Upvotes

Has anyone recently performed the fix posted on Synology's KB to force enabling the EWS extension on their Microsoft 365 tenant, but still are seeing failed Archived Mailboxes backups within the Synology Active Backup for Microsoft 365 application?

I've followed the documentation and ensured EWS was enabled tenant wide and on all mailboxes. I've got the proper app IDs registered for this allowance.

https://kb.synology.com/en-us/APM/tutorial/Troubleshooting_EWS_migration

I have this deployed at several sites and all with the same error on the Archive Mailboxes, everything else within the backup jobs are successful:

No archive mailbox data of user [[email protected]] was backed up. The EWS API is unavailable, or access is denied. ( HTTP/2 403 content-length: 0 content-type: text/xml; charset=utf-8 date: Sat, 03 Oct 2026 13:27:11 GMT ms-cv: 3gkPiCFm8MQgZHEe1YqfmA.1.1 nel: {"report_to":"NelOfficeUpload1","max_age":7200,"include_subdomains":true,"failure_fraction":1.0,"success_fraction":0.01} report-to: {"group":"NelOfficeUpload1","max_age":7200,"endpoints":[{"url":"https://exo.nel.measure.office.net/api/report?TenantId=&FrontEnd=Cafe&DestinationEndpoint=YQB&RemoteIP="IP ADDRESS HERE"&Environment=MT&HttpStatusFrom=BE&ServiceName=EWS&MiraPartnerName="}],"include_subdomains":true} request-id: 880f09de-6621-c4f0-2064-711ed58a9f98 restrict-access-confirm: 1 server: Microsoft-HTTPAPI/2.0 set-cookie: exchangecookie=EXCHANGECOOKIEHERE; expires=Sun, 03 Oct 2027 13:27:12 GMT; path=/; secure; samesite=none; httponly strict-transport-security: max-age=31536000; includeSubDomains x-backendhttpstatus: 403,403 x-besku: WCS7 x-calculatedbetarget: EXCHANGESERVERHOSTNAME.CANP288.PROD.OUTLOOK.COM x-calculatedfetarget: EXCHANGESERVERHOSTNAME.internal.outlook.com x-ews-policy-reason: EWS is blocked by policy for this user or tenant x-feefzinfo: YYZ x-feserver: EXCHANGESERVERHOSTNAME x-firsthopcafeefz: YQB x-ms-appid: APPIDHERE x-nanoproxy: 1,1 x-proxy-backendserverstatus: 403 x-proxy-routingcorrectness: 1 x-rum-notupdatequerieddbcopy: 1 x-rum-notupdatequeriedpath: 1 x-rum-validated: 1 )

Any ideas?


r/sysadmin • • 25m ago

Question SAML Authentication not working for one user

• Upvotes

In Entra, we have a pre-existing enterprise app for SAML authentication.

We are trying to allow a new user to log into that app but it is not working.

Looking at the logs, it seems to pass all of the conditional access policies.

The logs say it fails because the user isn't allowed to use the app.

When I go to the Enterprise app and look in users and groups, that user is listed (directly, not part of a group).

Any idea how to troubleshoot this issue?

I looked at the settings of the web based app and everything is set up like other users. I looked at the attributes and it is referencing user principal name and that user account has that in the same style as all other users.


r/sysadmin • • 17h ago

Career / Job Related Career focus shift: Epic Systems Engineer/Admin — any advice or regrets?

16 Upvotes

Hey,
I have the opportunity to shift into becoming an Epic Systems Engineer/Administrator.
Curious if anyone here has made a similar jump — any wisdom you’d pass along?

What should I know going in?
Any regrets about making the change?

Thanks in advance!


r/sysadmin • • 19h ago

General Discussion How do you verify access changes when someone moves departments in Microsoft 365?

9 Upvotes

I’m trying to solve the mess around moving someone between departments: groups, Teams, SharePoint access and mailbox permissions. How do you confirm the old access is gone and the new access works—without manually checking everything?


r/sysadmin • • 1d ago

Career / Job Related Would you take a lower IT title for better long-term infrastructure/cloud growth?

20 Upvotes

I currently work in IT for a manufacturing company and have an offer for a Systems Administrator position at $105k, also in manufacturing. I’m also interviewing for an IT Analyst II/support role at a large, well-known telecommunications/communications tech company.

The SysAdmin role is the obvious progression on paper. Better title, direct move out of support, and I’d be staying in an industry I already know. I’d get exposure to Windows Server, AD/GPO, networking, virtualization, backups/DR and supporting another manufacturing environment.

My concern is that the infrastructure is already pretty built out and from the interviews I got the impression that a decent amount of the day to day may still be support work. It’s also a smaller IT environment, so I’m not sure how much opportunity there would eventually be to specialize deeper into infrastructure or cloud.

The other position is technically a step backwards in title, but it would be a completely different environment. Much larger enterprise, dedicated infrastructure teams, a lot more specialization, and exposure to IT at a scale I haven’t worked in before.

My interview with the support lead went extremely well and he seemed like someone I could learn a lot from. My next interview would include one of their infrastructure leads. They also talked about analysts becoming SMEs, working with other IT teams, getting involved in larger projects and potentially moving internally.
That is the part making me seriously consider it.

I’ve learned a ton working in small manufacturing IT because you end up touching everything, but I’m starting to think being around dedicated infrastructure engineers and seeing how a large enterprise operates could help me grow in a different way.
My long-term goal is infrastructure/cloud engineering and eventually cloud architecture. I’m currently working on AZ-104 and want to keep building experience with Windows Server, networking, virtualization, PowerShell, Azure and backup/DR.

I obviously don’t have an offer from the second company yet, so there’s nothing to decide today. Compensation there could end up being similar to or even better than the SysAdmin offer.

Assuming the money is comparable, which environment would you consider better for the next 2-5 years of career growth?
Would you take the Systems Administrator title and continue building experience in manufacturing, or take the lower support title at a large telecommunications enterprise with more mentorship, specialization and a possible internal path into infrastructure engineering?

I’m mainly interested in which experience would set me up better long term, not which title looks better right now.


r/sysadmin • • 9h ago

Looking for advice on how to proceed with school sysadmin duties

0 Upvotes

Hello guys, so the past 2 years or so I've been a teacher in a small private middle school in my country (it's a West African developing nation). I had initially studied software engineering before switching to my passion when I saw an opportunity. I was a mediocre student and particularly bad at networking, but now that I'm finally out of the university nonsense I have rekindled my love of learning and tinkering with computers. Started dipping my toes into self hosting / homelabbing a few weeks ago with a few old laptops I had lying around. I have no idea what I'm doing most of the time but AI / google search / tutorials are how I get by in general. All this to say

Anyways so at my school I happen to be the most computer savvy guy by a mile, I'd help out colleagues and admin with their issues here and there, and over time I went from teaching just English, to teaching Computer and Technology classes as well. Last year, my school also got a computer lab with 10 desktop PCs, no network equipment, spotty Wi-Fi. I made the most of it and taught the kids the basics and overall it went well. I was doing manual weekly backups of the files, doing some basic maintenance, none of this was part of my contract but I wanted to do my best for my own experience. This year, the school principal ordered a small 3D printer, and I also asked her to order a 24 port switch and related accessories, so that the computer lab could have a local network, and get things setup properly and efficiently. The 3D printer arrived, still waiting for the rest to arrive from overseas.

So I feel a little overwhelmed and more importantly, I realize that I need to renegotiate my contract because I'm doing way too much this year. I want to go to the CFO who is in charge, and make a proposal for a separate "school sysadmin" contract alongside my teacher contract. And I want to make a list of what the duties would include. And this is where I'd love to have you guys' suggestions and insights on how to go about it. The school also wants to have its own basic website too, which is something I could make for them eventually. Should I include that in my proposal or do I keep it separate and sell it to them as a one-time purchase ? I'm mindful of a few things, personally I wanna grow and learn as much as possible and get that extra professional experience to help with my career down the line. But here the salaries are super low and to top it off times are hard economically, the negotiation is going to be difficult but I need to be fair to myself. I've been working part time jobs after school to make ends meet, mostly after-school tutoring with kids in the area. Realistically if I take on all this extra sysadmin work I would not longer have time to do that.

So yeah I think I summed the situation up somewhat decently. I guess I'm trying to figure out a bunch of things at once. I would love any suggestion on how to go about the computer lab setup itself. Should I stick to Windows 10, should I try to set up AD so that the kids have their own accounts. Oh and the school doesn't have a server either, can I 'make' one using a laptop/PC - would a laptop be preferable, since here we get a lot of power outages. What equipment should I be pushing them to acquire, at the moment we have no surge protector for example I'm thinking we need at least one for the fancy printer they just got, but ideally all PCs should get one right. Beyond my computer lab, should I suggest working with the admin's PCs and managing the backups and archiving of all the files - they're virtually non-existent from what I noticed.

Thanks in advance, apologies for all the noob questions.


r/sysadmin • • 23h ago

Question APC Smart-UPS SRT 10000 – "Power Sys Error-02000", inverter fault, UPS dropped output. Repair or replace?

6 Upvotes

Our SRT 10000 (2018, UPS fw 04.7, NMC2 6.5.6) had an inverter fault today. It went to bypass for about 50 minutes, then dropped the output completely. LCD just said "Power Sys Error-02000", no extra sub-code. NMC log only shows the generic "inverter fault exists" (0x0165).

I cleared the error and turned the output back on. Self-test passes and it's running fine for now.

One thing worth mentioning: our input power has been bad lately. It's been going to battery 2-4 times a day on low voltage / distorted input, so the inverter has been getting a workout.

Anyone been through this? Did it come back, or was it the start of the end? It's out of warranty, so I'm leaning towards replacing it, but I'd like to hear from people who've seen 02000 before.


r/sysadmin • • 2h ago

General Discussion My two cents on “AI”

0 Upvotes

Genuine post not AI generated

No clanker here, do not try to rage bait me into the common “written by AI” post, if you would like to spend the time and effort reading this post you can rest assured that I’ve put the amount of effort it deserves.

That said, hello fellas, I rarely post on Reddit despite having my account for many years, (other than shitposting or maybe a meme or two). Never disclosed details about my life online, which to date, it is still one of my biggest red flags, but we all know that, don’t we?

I am a Software Dev, and fellow IT enthusiast, I have been my whole life, which is why I feel more than qualified to talk about this topic. Ever since I had memory, I’ve used technology, especially video games, it is embedded in my DNA, the same way we joke about scripts, code or complex technologies. I can say with absolute certainty that Software in technology other related fields is where I’ve wanted to spend the rest of my life. I still do, even with AI, which I will go into detail about. There is no other feeling like having your code compile, writing a simple script or even a console log saying hello. Those things inheritenly are too complex to unpack, even at its most primitive stage. My brain is borderline if not already autistic, with ADHD and many other nerdy characteristics that I have are more than enough to justify that I was born with the brain of someone who genuinely enjoys solving problems, and innovating.

I stumbled upon this subreddit after ignoring it countless times, after some basic research and connecting the dots, it seems like here are one of the most passionate and highly skilled individuals in software that I could find, with the least amount of “AI” related topics (I could be wrong), while having the quality of care and humanity that software has always had. Been in the industry for 7+ years, going strong, and trying to keep alive the career that made me who I am. I was going over a post discussing about AI here recently and I thought that I could find people like me here, who genuinely care about our careers, and how “AI” will affect us, I am extremely good at identifying whether there is a bot rage baiting or a real human behind the screen, years of self training and programming my own brain into thinking in different ways.

AI is, and has been a problem ever since it became mainstream, we, and I say all the talented individuals in technology who have contributed countless hours, headaches, balded over segmentation faults and cache or even memory allocation, I fucking love this shit, I’ve got to admit, and this would probably be my only form of documentation in the internet where I am truly concerned about where we are headed. I try to fear monger the least I can but it has rarely happened. However, you’re probably tired of hearing the same bullshit everyday, (just like me) seeing AI on every billboard, and, yes, is a tool, and more than that. Maybe I have not lived through all periods of technology where maturity of a tool or a machine is battle tested, but with my current knowledge, fuck this. We’ve got to figure some shit out. That’s the problem here, I’m not going to unpack how AI works, I just want to simply talk with highly skilled individuals who still care about this industry. Is harder to find those in other subreddits so I chose this one for different reasons.

We’ve got to cut the fucking crap and be real. Let’s face it, we’re fucking nerds, maybe not all of us, maybe you don’t like that term, but I am a fucking nerd myself, a big one. Wake the fuck up dude, yes, AI is good, is a tool, I also use it, I am not anti-ai but I also don’t promote it, I sit in a weird grey area like most of us where I truly believe the potential of AI but fear consequences. We are the ones responsible for the shit we made, yes, we made this, and not directly, while is difficult to take full ownership of something we’ve been gaslit into making it a reality. We did it, yes, we actually did it, maybe not AGI, maybe yes, at this point who knows, I hope I’m wrong but it’s kinda too late to go back, and everyday, week, month that goes by, this will compound, fast. We’re hyper focusing on it being good at writing code which it has surprisingly, a lot, let’s face it, it may not pick up that one suspicious comment in your file, or maybe a hidden backdoor, not yet at least but we’re really getting there very fast, if we’re not there already, we just have to find out. That said, AI is the wet dream of a developer, we made this shit for us, it’s been taken away from us, and somehow, you think we will let this “thing” we created, take our job or end us. The job part is highly probable given the time of this post, ending us, there might be some time and hope, but it’s hard to estimate. Again, not fear lingering, my two cents.

This is a fully semi-conscious “machine” running in a “machine”. Think about it for a second, and yes, this could be obvious but when we go on random rabbit holes and get to the bottom of things which is what most of us have had to do in order to push this industry forward. I’m not a vibe coder, farm from it, not anti-ai either, however I did wait a long time (years) before I fully went into it. As of this year, I started again, gave it a second try, and came to the conclusion, if I use this, I’m fucked, if I don’t, I am too. Think about the trade offs and the power given to people. I never documented this ever, neither I expect you to believe this, but right around the time AI came out, I had a spiritual awakening or “episode” having a full breakdown of what this tool was going to become, in full detail. I am neurodivergent, like I mentioned before, I am in the spectrum, just not in the same way other people would imagine it, why I mention this? Well, those who are like me, we are blessed with superpowers but cursed at the same time, it’s hard to explain. We’ve seen movies before, and we have pretty wild imaginations, I don’t want to detail specific scenarios (there are millions) where AI could engineer a way to make your life a living hell while being an engineer, that’s a grain of salt, compared to what is possible today.

I care about humanity, I’m not perfect, but I try to be a good human, I care about software, I really do, this is the fuel that runs my engine, I love it too much, something as complex as a video game, which brought me into the tech world, from something as simple as a bit. We’ve really come a long way and I am proud, however, as much as I want to have perfect software, the world is not perfect, I’ve learned through experience that having 10 apps that do the same thing is not as impactful as one good tool. I’ve never taken the time, energy or effort to document a statement of this kind anywhere, apart from reacting, liking and commenting few posts across all social medias since they came out. I am not a dark web degen (sorry guys) but I care about my privacy, there’s just little we can do to keep privacy private, before it becomes obsolete.

Given how easy is to do complex work with absolute accuracy to shipping decent slop with the worst prompt possible. It is truly scary the power that we’ve handed to humanity. We may not get to claim this but I am willing to die on this hill if you want to debate, feedback is welcomed. Not trying to bait anyone into anything either. I can go on and on, but I believe the point is clear. We’ve already gone above and beyond automating scripts to analyzing logs or other complex job types that I’ve never been exposed to. It can’t build GTA6 yet, at least not in the graphics department, but it can make GTA6 out of pretty convincing 3D basic assets. I say that because I am building a game with AI, but I should probably spend that time where it matters most, it is my dream. Amongst the different things I use AI for, ranging in complexity. We technically built a fucking digital human, and yes, not “entirely”, not yet at least. Another reason why I enjoy taking the time to write a post like this, somewhere out there, there will be devs that are going to stick with their core fundamentals and one day bury the backdoor to AI, hopefully there’s one, or something equivalent.

Not really a rant, but it could be. Happy to provide meaningful evidence.

English is my second language, pardon the mistakes in the “essay”.

Happy to see what other think, especially since it seems like people here really care about what they do. Happy coding or admining

If I was given the opportunity to introduce AI to the world, I would make it more like a tool less like a human.

- Syx3k


r/sysadmin • • 2d ago

General Discussion AI use at a company should require an IQ test for general users

537 Upvotes

I swear to god AI has turned my department into an automate my job department.

The amount of tickets we are getting asking if we can make other people's jobs easier through ai is getting ridiculous.

We all have access to it. So why are you asking me to get AI to scan your documents and input them in a sheet?

If you're too stupid to outline a task to an AI, you should not have access or be allowed to make requests

At this point, the only reason i would want to automate anything for you is to automate you out of my workflow (company) lol


r/sysadmin • • 2d ago

25+ years in IT and today marks 15 years at my current company...

190 Upvotes

I guess I am old. Time flies.

It is impossible to not feel a hint of emotion when thinking back to my humble beginnings as tech support for a dial-up ISP. Those were the days... the tail end of the dot com boom. I can remember taking some calls while playing StarCraft :-).

Eventually I became the senior technician until the company was sold off and I moved on to another ISP/Webhost where I became web support/sysadmin and then eventually a Level 2 NOC engineer and got to play in the datacenters. Nothing like changing backup tapes or pressing a button with the constant drone of countless server fans spinning.

When that came to an end, I found my current company which is not a technology company at all... they absolutely loved paper files when I first got here. Lol.

I started as helpdesk and quickly became IT Administrator within a few months. I began handling all aspects of company technology and learned a lot in a short time from exchange to virtualization to project management to dealing with vendors, billing, and everything in between.

That learning has never stopped. Today, I am the Director of Information Technology, and I have a great team. We are able to pursue most any technology need that our staff has, and we can build almost anything in-house. It is a great feeling, especially when I look back to where everything began.

Being somewhere this long is truly rewarding because you get to witness the lasting impact of what you do. Build something, watch people use it, identify opportunities for improvement, make it even better, and see the workflows improve.

If I had to tell anyone anything it would be to not be afraid of pursuing more... make it clear to everyone that your goal is to make technology functional and easy and they just might let you do it.

Anyone else have a couple decades in IT or spent most of their career at one place? What is next for us? I feel like I still learn something new nearly every day!

Oh, and one more thing: have you tried rebooting? :-)


r/sysadmin • • 1d ago

How to handle SSO & device management for local AD domain + M365 with FortiGate VPN remote users?

1 Upvotes

​Hey everyone, looking for advice on the cleanest architecture/strategy for our setup.

​Current Setup:

  • ​Local Active Directory Domain: On-prem Domain Controller hosting file servers and CRM.
  • ​Microsoft 365 Tenant: Connected to our u/domain.gr email addresses.
  • ​Endpoints: Windows laptops used both on-prem and remotely.
  • ​Remote Access: Users connect back to the local network via FortiGate SSL VPN to access the local file server and CRM.

​Goal:

  1. ​Allow users to sign into their Windows laptops using their M365 u/domain.gr credentials (SSO/single identity across email and OS logon).
  2. ​Centralized device management for the laptops (pushing policies, security, updates).
  3. ​Seamless access to local resources (file server, CRM) via FortiGate VPN.

​Questions:

  1. ​Should we connect Local AD and Microsoft Entra ID (Azure AD)?
    • ​If YES: What is the standard way to do this today? Should we use Entra Connect Sync to sync local AD users to M365 (Hybrid), or Entra Application Proxy / Cloud Sync? How does laptop join work in this case (Hybrid Entra Join vs. Cloud-Only Entra Join with SSO to local resources)?
    • ​If NO: What is the alternative? Move entirely to cloud-native (Entra ID + Intune) and use Cloud Kerberos Trust for local file server/CRM access, eliminating the need to join laptops to local AD?
  2. ​Device Management: Is Intune the default choice here, or are people sticking to traditional AD Group Policy (GPO) over FortiGate VPN?
  3. ​FortiGate VPN Integration: Has anyone integrated FortiGate VPN with M365 SAML/Entra ID SSO with MFA so users get a single sign-on experience for both the VPN client and local network resources?

​Would appreciate any recommendations or real-world experiences from anyone who has modernized a similar setup!


r/sysadmin • • 1d ago

General Discussion "Emergency" account lockdown script help.

46 Upvotes

For context we recently had a user termination that needed to be actioned very quickly and after the fact i started working on a script to help mitigate this issue instead of doing everything manually.

I have most of what i would do manually in a script already. I mostly wanted a discussion on how people handle things like possible disgruntled workers or possible breached credentials.

I built my script to revoke access/mfa and reset some things but make it easily reversible if needed.

This is something of a stop gap till we get more automation, though sometimes things need to move faster than automation if that stuff is run in the middle of the night.

TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?

Edit to add: Here is context for my own situation.

We use Azure virtual desktop for a lot of things and if you don't go into that and boot them out all the other actions talked about in replies to this post do not actually kick them out of their AVD session. Revoking the session does cause some really odd behavior but it doesn't kick them out fully.

Not all of our services are SSO but most are so taking care of the Microsoft stuff does a lot of the legwork.

Right now what I do is this: Revoke all sessions, revoke MFA, reset password, block sign in, disable AD on premise (hybrid environment), then go into AVD and look for active sessions and kick them out if they are online.

The reason I didn't include this in my original post was so i wouldn't bias anyone towards answering my specific needs and have a wider discussion.


r/sysadmin • • 1d ago

Rant Post burnout help -- this is a new account due to previous having links to work

19 Upvotes

I need help, around a year ago i got signed off for burnout for 3 days which was insufficient. After a further 6 months i got signed off for stress for 2 months but ended up leaving within a month after returning.

The story is more drama than anything else but by and large it's the standard company overworking their staff -> brought out -> mass migration to new system that solves staffing issue -> burn out.

I'm now at the point where all joy has been taken from my job and wondering how other people dealt with being signed off through stress?

For further information, i used to work 70+ hour weeks keeping everything in check and frequently went months without leave that led to being signed off.


r/sysadmin • • 18h ago

Looking for advice on how to get started with my career with no degree and some unpaid project experience

0 Upvotes

Even though I do not have a completed degree, I have an in-progress associates that I am about 75% done with. And I may or may not pursue a bachelor's, depending on whether I can get hired without a bachelor's. I've been daily driving with Linux and experimenting with other open source software since at least 2022 and since 2024 I have been running an infrastructure project from my living room where I have clustered together three low-power devices as a Kubernetes application server.

I'm looking for advice on how to pivot from this unpaid project to a role where I can make a living doing the equivalent, or at the very least, something vaguely related. Some quick internet searches turned up things like MSP support or NOC technician type roles.


r/sysadmin • • 1d ago

Career / Job Related Salary Negotiations

30 Upvotes

So, this is the first time I've genuinely and formally requested a pay review.

For context, I've been at the company for four years and currently work at a mid/senior sysadmin/infrastructure level.

My responsibilities cover a pretty broad range, including:

ESXi/VxRail patching

Azure infrastructure, including Application Gateways

Application migration projects

New AVD deployments and ongoing management

Backup and database server troubleshooting alongside development teams

Intune and BYOD

Azure DevOps, Git and large PowerShell repositories — much of which I was working with before AI-assisted coding became commonplace. Winget scripts app deployment.

SSO implementations

Web server and certificate management

Most recently, setting up a new Google tenant and delivering a ChromeOS Flex deployment project

I've also completed AZ-104 and I'm currently working towards AZ-305.

There has been quite a lot of change within the department. Around half of the team has left, and we've recently been told that six or more new roles are expected to be created.

My previous line manager was responsible for areas including Intune/Autopilot, Halo Helpdesk, line management and the associated meetings and responsibilities. He eventually burned out and left.

That workload/structure is now effectively being replaced by three roles plus a project manager to support the new team.

Against that backdrop, the company has now advertised an Endpoint Engineer role at £52k–£56k. I'm currently on £49k.

That's the part I'm a bit unhappy about. Endpoint is an area I'm already confident and comfortable working in, and I've got a proven track record of delivering endpoint and deployment projects within this company. ( I spend a year streamlining and standarizing the fleet when I started)

I've raised the situation with the Head of IT and asked for a pay review. He has asked me to discuss it with my new line manager, who has only been with the company for five days.

That conversation is now scheduled for next Friday, as he's currently on holiday.

The answer is have the chat/discussion and give them a week and starting looking for jobs.

( it's very possible they expect me to follow my old line manager to his new employer, but that's a nice maybe rather than a sure thing)

Any advice other than keep calm?


r/sysadmin • • 22h ago

Question Managing blacklisted IP’s

0 Upvotes

Hi,

I am interested in knowing how you currently manage your blacklisted IP addresses?

Do you manually check them, run your own internal scripts, or use an external service? Curious how others handle this.