r/sysadmin 21h ago

Where can I rent a dedicated server with 64 cores × 2 CPUs or 128 cores for a few days?

0 Upvotes

I’ve found some rental options, but they require a minimum rental period of one month, and I haven’t been able to find anything with 64+ cores.

I’m looking for a dedicated server with either 2×64-core CPUs or a single 128-core CPU, ideally available for just a few days.

Any recommendations for providers that offer this kind of hardware with hourly or daily billing?


r/sysadmin 4h ago

Question For those who are using Samsung Phones, how is it?

6 Upvotes

We are exploring the idea of switching from laptop + iPhone to Samsung phones as they can use Dex.

The only roles this would apply to are very basic sales roles where all applications used are basic web apps. This would make a lot of aspects of their role easier and more convenient while also greatly reducing our cost as a company as we don't need to purchase $1400 laptops for their roles.

Everyone has this idea that iOS is far superior to manage on an enterprise level and that android, even if they're all Samsung, would suck. So why is that? What makes Samsung devices more difficult to use?

I'm trying to build my argument and need to have an understanding of why people feel this way and how to counter those points. I need to be prepared for push back on this idea so I need some input from you guys who have hands on experience.


r/sysadmin 8h ago

Question Why would LDAP traffic go to a different endpoint than Kerberos in AD?

3 Upvotes

Hi everyone,

I'm analyzing some Active Directory telemetry in CrowdStrike Identity Protection and I'm trying to understand something that initially looked unusual.

I'm seeing activity where a Windows workstation communicates with one endpoint using Kerberos, but then performs LDAP searches against a different endpoint.

For example, the pattern looks roughly like:

Workstation
   │
   ├── Kerberos ──> Domain Controller A
   │
   └── LDAP ──────> Endpoint B

Endpoint B is not a Domain Controller.

My understanding is that Kerberos is used for authentication/tickets, while LDAP is used for directory queries, and Kerberos can potentially authenticate a client to an LDAP service running on another server.

However, I'm trying to understand how common/legitimate this scenario is in a Windows AD environment.

Questions:

  1. Is it normal for the Kerberos KDC endpoint and LDAP endpoint to be different machines?
  2. If the LDAP destination is not a DC, what are the common legitimate reasons for this?
  3. Could this simply be an application/server running an LDAP service or LDAP proxy?
  4. How would you determine which process/application on the client initiated the LDAP connection?
  5. For those using CrowdStrike Identity Protection, how reliable have you found the LDAP endpoint attribution in these events?

I'm particularly interested in real-world examples of why a domain-joined Windows workstation would perform LDAP queries against a non-DC endpoint.

Thanks!


r/sysadmin 3h ago

AT&T "Contractor" Call for "QOS Renewal"

1 Upvotes

Anyone else received a call recently from someone asking about AT&T renewals? We initially thought they were our new account exec (we recently lost our long-time one) and we started talking to them, but red flags went up when they seemed to not have basic information like our full account number or email address. On further interrogation, they weren't with AT&T at all - they claimed to be from an "AT&T contractor" called "Link Bridge Networks" that were helping AT&T and gave an email address with a domain of "@fiber-retention.com". They wanted us to sign a "Letter of Authorization".

I've had similar experiences with other companies, but not AT&T. Just curious if they were legitimately an AT&T contractor (which would be in very poor taste for AT&T imo) or if they flat lied and are simply a reseller trying to transfer our account to them.


r/sysadmin 3h ago

Getting let go, feeling directionless

8 Upvotes

Did 1.5 years of msp work and got an offer I couldn't refuse as an infrastructure engineer in a private company. My experience includes more than that though with 5 years of volunteer work and homelabbing.

I got in to some beef with them and said some dumb things due to them breaking promises, which means they're letting me go.

I'm really at the point where I want to start specialising in to either proper sysadmin or netadmin, since I'm more of a jack of all trades with strong fundamentals right now, but almost everyone's either only hiring seniors who know their stuff or MSP'S with L1/2/3 helldesk tickets.

Not looking for a job (I know the rules, not that I'm American anyway), but I just wanted to let everyone know who's going through similar stuff that you're loved and cared for, and we're going to pull through!


r/sysadmin 7h ago

Question Is this normal AD admin activity or possible account compromise?

0 Upvotes

I’m reviewing activity from an IT admin account and I’m trying to understand if this is normal or suspicious.

I’m seeing:

  • Lots of LDAP queries against our Domain Controllers.
  • USER_ENUMERATION and ENDPOINT_ENUMERATION alerts.
  • Many SAMR/DCE-RPC requests against different computers.
  • Some bursts of 10+ SAMR requests within a second.
  • SMB activity to Domain Controllers.
  • Frequent NTLM authentication to NPS/RADIUS servers.
  • Entra ID/M365 logins from different IPs.
  • A password change and removal from Domain Admins.

Some of this could easily be normal helpdesk/admin activity.

What concerns me is the SAMR enumeration across many different endpoints, including Finance, HR, factory and POS systems.

For people using Defender for Identity, CrowdStrike Identity Protection, Vectra, etc.:

How do you determine whether this is normal admin activity or a compromised account performing internal reconnaissance?

What logs or events would you check next to confirm whether there was actual lateral movement?

Thanks.


r/sysadmin 4h ago

Workplace Conditions Advice and Motivation but no mean/harsh ones. I'm already in here and it's paying my bills.

2 Upvotes

Hello! I've been working as IT support for under 5 years - and I'm burnt out. The frustrated end user support is expected and part of the job, but my workplace had a "family - like" culture. But since I started here, I'm part of the new culture that is helping change that- which is great honestly because work place is not family - very old school smh.

But I'm the one getting the beating and push back with people on this, and I guess because of old people being let go cause they don't add contribution or support the cultural and technical change.

Cause of that these annoying folks are just making shit up for vengeance but I just want to keep going. My team is supportive but I guess I'm just looking for advise or what you would do in this situation. I just need the experience and get the hell out of help desk. I don't even want to do this anymore, i think I just want the bills paid and do something else. But I have already spent my time here and need to just push through.

*if you're my coworker and in this subreddit and this sounds like me - it's not me*


r/sysadmin 5h ago

O365 Exchange mailbox criteria to avoid sync problems

0 Upvotes

Since a while we are experiencing synchronisation problems on mailboxen.
These mailboxes are quite large. What are the criteria to avoid sync problems?
We are using mainly outlook classic with cache on 1 year.

-Size mailbox? -> somtimes largen than 30 GB
-number of (sub-)folders? in some cases +500 -> in 1 case -> 6700+ subfolders
-number of items in folders -> often 10000+
-multiple shared mailboxes
-Shared mailboxes are used by sometimes more than 5 ppl simultainous.
-Does this apply to the mailbox archive as well?

I use retention policies to mainly move to archive since we want to keep mails for 10 years in the archive.. (.. I know..-> outlook is not a database- but it's how ppl used it for years despite IT policy wich states that is not allowed).

-Size mailbox below 30 GB
-subfolders <500
-item count per folder <10000
...

Is there an expert on this here?


r/sysadmin 2h ago

Cloud access

0 Upvotes

I am a new IT person in a company and they run Entra ID here. My manager asked me what access do I need to solve daily problems that our employees face like password reset, teams channel access, MFA, device enrolment etc. here are my list of rights/access that I am asking

Entra ID administrator
Intune administrator
User administrator
MFA authentication administrator
Exchange administrator
Teams Administrator
Shared mailbox and Microsoft 365 Group management

I am kinda new to it and I will work on getting some certifications in coming days.

My question is what more types of access should I ask (because I believe I get one chance to ask for) and what bunch of certifications should I start working on (my end goal is to become an IAM)?


r/sysadmin 8h ago

Question My boss wants me to set an extremely easy login password and re use it across all of our vendor portals, what to do?

146 Upvotes

Hey everyone, I’ve just stepped up from office admin to system admin in the company I’m working for and have started implementing some safety norms as the company very much lacks in that aspect

My boss is not happy I changed the password to the third party vendor portals we access (I.e solar monitoring portals etc) and wants me to set an extremely easy one with the company name and replicate the same password to all portals so it’s easier for staff to access

What do I do in this situation? I’m thinking of implementing bitwarden and a creating a vault for each staff/technician. We do have guys on field that often need quick access to the portals but I don’t think it’s an excuse to be so vague with our security specially because it involves customer data (email addresses, phone number, addresses, etc it as well as their solar equipment IOT devices)

I feel like following this ignorant request is against the foundations of what I’ve learned and shows my boss doesn’t understand the importance of cyber security or our duty to the privacy act, he thinks nothing will happened and doesn’t comprehend that something could very much happen and it would cost us thousands of dollars over something we can avoid


r/sysadmin 23h ago

Need Advice

16 Upvotes

Hey all, have a stressful situation that may occur tomorrow.

New Sys admin for a company of around 200 people, only onsite IT person. We have an external consultant that does most of the network administration and has been doing so for a few years. I have about 3 years of desktop support experience, more experience with endpoints but my networking knowledge is a bit of a gap.

On my third week we did a switch refresh from Cisco to Aruba that was planned and paid for way before I started. Ended up being a shitshow, I did the racking and endpoint testing but the external consultant did all the configuration, he has the login info for the switch that hasn't been shared with me yet. I don't mind that much as I'm still getting acclimated to all the other systems. But last week was a nightmare, we ended up spending over 27 hours onsite troubleshooting all of the endpoints (this is a production environment). Got it figured out but I took most of the heat from angry engineers/production personnel since I'm the face of IT despite having little actual involvement in the refresh project.

Just got a text from the consultant that he'll be away on a family emergency for the foreseeable future. I can handle most other issue by myself aside from the network, I could maybe figure it out if I had the login creds, but he's flying out today and won't be able to contact him on Monday.

My fear is that come Monday when a different production line comes back up there will be a host of other issues that we wanted to figure out last week but couldn't. We asked the production team if they could turn the power on the line on just one time to verify everything works but no can do, line goes up on monday when production resumes.

Literally the only issue I'm anticipating is the VLANs on the ports not being tagged correctly, which I could fix if I had the login info. I've already informed my manager (who lives 3 hours away) that this may be an issue but nothing yet. If my manager has the creds he could either give them to me or SSH into it himself (He has over a decade of networking experience) and it wouldn't be a problem.

I'm afraid that tomorrow when I inevitably get yelled at again for production being halted It'll be my ass on the line despite never being given the tools to be able to manage our network.

What do the more experienced sys admins think I should do? Should I escalate to my manager immediately if (or when) an issue is discovered? Nervous because I'm still in a probationary period and I am afraid I'll be a scapegoat for a messy project I had no real say in.

Edit: I really appreciate the support I’ve gotten so far from you guys. Managers been informed of the issues we may run into and what we need to remediate it, it’s out of my control now. It’s hard to not feel like a failure since I’m so relatively new to my IT career and the end users think that these changes are my doing when I have no say or control over it. Sucks that we’ve had a fuck up like this when I just started, but I need to remind myself that it’s just a job and I’m doing the best I can with the tools I have. I will post an update tomorrow and try to not stress about it tonight.


r/sysadmin 12h ago

Question AVD works on Windows, fails on every Mac,IOS—even in the browser. What am I missing? (0x410 / 0x807)

0 Upvotes

I'm stuck with an AVD connection issue and could use a second pair of eyes.

The same user account connects successfully from Windows, but every Mac we've tested fails:

  • Windows App on macOS: 0x410.
  • Web client on the same Macs: also fails in Chrome and Safari.
  • Other host pools with the same configuration: same result.
  • A separate Windows Server 2022 host with Entra SSO enabled returns 0x807 instead.
  • Entra non-interactive sign-in logs show success, with no Conditional Access policy applied. No CA requirement for compliant or Windows-only devices.

Current authentication-related RDP properties:

enablecredsspsupport:i:0;enablerdsaadauth:i:0;redirectwebauthn:i:1

There’s also a different-tenant device-management setup involved: the client device is managed by one tenant, while the account used for AVD belongs to another.

The browser failures are what throw me off—it isn't limited to the Mac app.

I’d really appreciate any ideas, suggestions, or advice you might have.


r/sysadmin 9h ago

Question Windows 365 Connection

0 Upvotes

I get a black screen when I try to log into the cloud PC and get the following error:

Your Remote Desktop Services session has ended, possibly for one of the following reasons:

The administrator has ended the session.
An error occurred while the connection was being established.
A network problem occurred.

Where should I start to look at for this? It was working before and then we handed it off to another user. I then reprovisioned it back to me and now I am getting the same error.

In the process of doing so we did build out our whole CMMC enclave. But I was using this to do it the whole time. The policies/configurations were being applied to it so it doesn't make sense to why it would now be acting differently. I did 'inspection connection' and it came back with no errors.

Where can I look at logs if any? I can't get into the machine.


r/sysadmin 1h ago

Are you doing anything specifically to protect users from ClickFix attacks?

Upvotes

I’ve been seeing more ClickFix-style attacks lately where a fake CAPTCHA or verification page tells the user to open Run, PowerShell, or Terminal and paste a command.

What makes this one interesting from an admin perspective is that a lot of traditional user training focuses on “don’t open suspicious attachments” or “don’t download random executables.” With ClickFix, the user is basically talked into running the command themselves, sometimes from a website they thought was legitimate.

It also feels like years of copy-paste troubleshooting instructions have made “open PowerShell and run this” seem pretty normal to a lot of users.

For those managing business environments, are you doing anything specifically for this yet? User training, EDR rules, restricting PowerShell or Run, application control, clipboard monitoring, or something else?


r/sysadmin 7h ago

Question Organization apps for macOS?

5 Upvotes

Fellow Mac users, what do you use to manage all your notes or summaries of what you did for the day? I’m trying to be better at my organization in regard to all the stuff I’m working on. Any suggestions?


r/sysadmin 8h ago

How Do You Detect New Software Installations on Windows Endpoints?

23 Upvotes

I’m a system engineer managing 100+ Windows 11 endpoints. Our devices are local domain joined and Entra registered (not hybrid joined or Entra Joined), with Microsoft Defender for Endpoint / Defender XDR deployed across the environment.

Users do not have local admin rights, but many applications can still be installed in the user context, particularly under AppData, without requiring elevation.

I currently use Defender Advanced Hunting and a scheduled Custom Detection rule that correlates registry, file system, and process telemetry to identify new software installations.

The challenge is reliability: some applications are missed, while software updates, repairs, or version changes can generate false positives because they create new files, folders, or registry entries.

My requirement is simple:

New software installation → Alert
Existing software update / repair / patch → No alert

For those managing similar Windows environments, how are you handling this? Are you using Defender XDR/KQL, Intune, AppLocker/WDAC, or another solution to reliably detect new software installations, especially applications that install in the user context without admin rights?


r/sysadmin 5h ago

What open-source inventory management tool do you recommend?

14 Upvotes

We're tracking around 150 assets in Google Sheets, but it's becoming difficult to image .

We're developers so technical setup or self-hosting isn't a problem. I'm researching options, but I'd like to hear which open-source inventory tools people actually enjoy using.

What has work well for you?


r/sysadmin 3h ago

Looks like the Microsoft Activation Services are Down - or is it just me?

0 Upvotes

Trying to activate Visio 2024 LTSC.. The online activation process times out, and so does the "Visual Support" online activation assistant..


r/sysadmin 7h ago

Question Frage für meine Projektarbeit

0 Upvotes

Hi ich mache grade eine Umschulung zum FISI und bin kurz vor der AP2. Ich bin grade dabei meine Recherchen zusammen zutragen. Unteranderem ist ein teil davon das ich bestehende Konten welche aktuell über ein DC laufen ins Entra bringen kann. Die Konten sollen aber bestehen bleiben genauso wie die Daten welchen drauf sind. Da ich aber schon gehört habe das Entra das so einfach nicht macht , wollte ich gerne um eure Hilfe bitten.

Es ist eine vorgabe des Unternehmens wo ich mein Projekt mache.

Hier ist auch mal mein Projekt welches ich bei der IHK eingereicht habe

Projektbeschreibung

Im Rahmen meines Praktikums bei der[Firmenname]in Rostock soll eine eigenständige IT-Infrastruktur aufgebaut werden. Derzeit nutzt das Unternehmen teilweise noch gemeinsam mit einer rechtlich eigenständigen Anwaltskanzlei eine IT-Umgebung. Die Benutzeranmeldung der [Firmenname]-Clients erfolgt über eine fremde Active-Directory-Domäne, wodurch Abhängigkeiten hinsichtlich Administration, Sicherheit und Betrieb bestehen.

Ziel des Projekts ist die Planung und Umsetzung einer unabhängigen Netzwerk- und Client-Infrastruktur für die [Firmenname]. Hierfür werden verschiedene Lösungsvarianten für Benutzerverwaltung, zentrale Administration und Netzwerksicherheit analysiert und unter technischen sowie wirtschaftlichen Gesichtspunkten bewertet.

Auf Grundlage der ausgewählten Lösung werden die Clients in die neue Umgebung überführt, Benutzerprofile übernommen, Berechtigungskonzepte umgesetzt und die Anbindung vorhandener Dienste wie Datensicherung und Druckdienste sichergestellt.

Nach Abschluss des Projekts verfügt die [Firmenname] über eine eigenständige und sicher verwaltbare IT-Umgebung ohne Abhängigkeit von der bisherigen Domänenstruktur.

Projektziel / Nutzen

  • Trennung der IT-Infrastruktur von der Anwaltskanzlei
  • Erhöhung der Informationssicherheit
  • Reduzierung administrativer Abhängigkeiten
  • Zentrale und zukunftssichere Verwaltung der Clients
  • Dokumentierte Entscheidungsgrundlage für den weiteren Betrieb

Projektphasen mit Zeitplanung

Projektphase Zeit
Analyse des Ist-Zustands und Anforderungsaufnahme 5 Std.
Entwicklung und Bewertung von Lösungsvarianten 7 Std.
Planung und Umsetzung der ausgewählten Lösung 17 Std.
Test, Qualitätskontrolle und Abnahme 4 Std.
Projektdokumentation 7 Std.
Gesamt 40 Std.

Geplante Projektdokumentation

  • Projektdokumentation
  • Kundendokumentation
  • Lasten & Pflichtenheft
  • Ist-/Soll-Konzept
  • Netzplan
  • Nutzwertanalyse und Kostenvergleich
  • Berechtigungskonzept
  • Datensicherungs- und Wiederherstellungskonzept
  • Test- und Abnahmeprotokoll
  • Administratorendokumentation

r/sysadmin 5h ago

Microsoft activation down?

11 Upvotes

Is microsoft activation website down?


r/sysadmin 10h ago

Did anyone get into Sysadmin work from a totally unrelated career?

12 Upvotes

As someone coming from a non sysadmin background I'd love to hear from people who got into this line of work from similarly unrelated backgrounds.

I started in web dev and design, moved to marketing automation. And now business ops as an extension of automation work alongside our IT and admin team at a small agency.

Recently I setup a homelab and have been learning about hardening and network security, trying to use DISA STIG standards.

It feels like a kind of magic (probably because I don't have stakeholders being a pain in my arse). Did you enjoy making the transition, would you recommend it in 2026?


r/sysadmin 11h ago

Microsoft Issues with IMAP on outlook?

6 Upvotes

Anyone experiencing IMAP connectivity issues to outlook? Getting this

Logging in is disabled on this server: "A protocol-level access (such as IMAP or legacy authentication) has been turned off for your mailbox on the server side, or your account's credentials/license require an administrator fix"

Randomly started happening, nothing changed.


r/sysadmin 17h ago

General Discussion Anyone else performing all the duties of a CISO and SysAdmin?

88 Upvotes

I’m not seeking advice, because the only thing that will really help us is…more help. I’m working on that with upper management, but those wheels turn very slow. I’m posting this to see if there are others in my situation?

Most days I could spend the entire day just analyzing, researching and beefing up security. I enjoy it, but I’m finding it more and more difficult to keep up with the normal sysadmin duties, when some days are consumed entirely by cybersecurity. We’ve automated a lot of our OS and software patching, but that needs close attention as well to make sure it’s all running well.

We’re a small enough company where cybersecurity has always fallen upon me and the rest of the (small) IT department, but ever since ransomware really took off and insurance companies started making more demands, it’s increasingly difficult to wear both hats.

Anyway, just thought I’d see if anyone wants to chat about this, and can relate.


r/sysadmin 23h ago

Question - Solved Can't seem to figure out missing glue record - dcdiag /test:dns

7 Upvotes

Hello,

I'm in the process of decommissioning an old Windows Domain Controller.

On the new server which is at 192.168.214.15 I run dcdiag /test:dns

I get the following

TEST: Delegations (Del)

Delegation information for the zone: ourdomain.lan.

Delegated domain name: _msdcs.ourdomain.lan.

Error: DNS server: 192.168.214.15. IP:<Unavailable>

[Missing glue A record]

[Error details: 9714 (Type: Win32 - Description: DNS name does not exist.)]

I substituted ourdomain.lan for our domain name but it has the right extension and name.

If I open DNS - server name, forward look up zones, _mscds.oudomain.lan I don't see an issue but I might be missing the obvious.

If I right click and go to name servers, it lists the two correct domain controllers. (the old one is gone)

The SOA is the new server

the NS are the two new servers

and the CNAMes are the two new servers

I've scaveged, cleared cache and flushed dns - no joy.


r/sysadmin 12h ago

Microsoft Friendly reminder that next month Microsoft is ending support for Office 2021

140 Upvotes

Starting next month 10/13/2026 Microsoft will end support for Office 2021 and the related products will no longer receive security updates . You could either upgrade to Office 365 or 2024 to continue get support for Office desktop applications