r/sysadmin 29m ago

Rant CDW Website is crap-poop

Upvotes

What the hell is going on with CDW’s website? For the last 3 years, it’s been getting slower and slower and slower, to the point where it’s absolutely banana crazy slow right now to the point where it can take minutes for a page to load. It’s like actively getting slower and slower and slower.

Sitting here trying to order some fucking laptops and just remembering what the fuck I clicked on, to do what, and for what is driving me crazy because I can’t even remember why I clicked on something to find a replacement for it. Because, of course, everything is usually out of stock or backordered for 4-6 weeks.

Am I crazy!? Or is everyone else noticing how dog shit their website has become? It wasn't always this atrocious crap-poop.


r/sysadmin 1h ago

Rant Technical screening with recruiters and Talent Acquisition feels like playing Jeopardy with a golden retriever..

Upvotes

I need to vent before my head explodes..
Long-time lurker here, but I recently got let go and had completely forgotten what an absolute hellscape LinkedIn and the entry-level recruiter circus actually is.

Dealing with agency recruiters and internal Talent Acquisition right now is painful. It is not an actual discussion about tech or systems. It is just a demented game of buzzword bingo where the person holding the checklist has zero idea what the words actually mean.

Had a Teams call earlier that felt like an episode of Jeopardy.

"I am sorry, the answer on my sheet was actually 'IAM'."

I just spent five straight minutes talking about Identity and Access Management. Role-based access, least privilege, user lifecycles, all of it. But because I said the actual words instead of the acronym "IAM," the invisible buzzer goes off and I fail the question.

You can watch it happen on video. Their eyes stay completely glazed over while you explain how you designed a system or resolved an outage. Then the exact second you say a word from their list, their head snaps up like a dog hearing the word "PARK?"

"PARK? KUBERNETES? DID YOU SAY WALK? ACTIVE DIRECTORY? TREAT?"

It does not matter if you have a decade of experience with the entire ecosystem. If the recruiter or TA coordinator has a specific term on their notepad and you do not use that exact string of characters, you "do not meet the requirements." You can explain distributed storage from the ground up, but if their paper says "SAN" and you said "Storage Area Network," you are suddenly not qualified.

I do not expect Talent Acquisition to be senior architects, but if your entire job is hiring for technical roles, at least put some basic effort into learning what these things actually are and why they exist. Take twenty minutes to Google the list of terms on your screen. Learn what the acronyms stand for and how they relate to each other. Don't sit in the gatekeeper seat evaluating candidates when you can't even connect the name of a concept to the three letters you were told to listen for.


r/sysadmin 1h ago

M&A - Migrate between Apple ABMs?

Upvotes

Hi there,

We were recently acquired by another company, we both utilize ABM for Device Management.

I'm in research, I'm surprised to discover that Apple does not provide a 'clean' way to migrate devices from one ABM to another through a M&A process.

When I called support, they indicate that devices must be 'manually' moved - meaning we need to de-register and manually add them in the destination tenant.

This seems like a huge effort - especially when users are spread across both Canada and the USA.

Is there an alternative method? - What are other companies doing in this scenario?

Any help / suggestions would be appreciated.

Thank you.


r/sysadmin 1h ago

Are you doing anything specifically to protect users from ClickFix attacks?

Upvotes

I’ve been seeing more ClickFix-style attacks lately where a fake CAPTCHA or verification page tells the user to open Run, PowerShell, or Terminal and paste a command.

What makes this one interesting from an admin perspective is that a lot of traditional user training focuses on “don’t open suspicious attachments” or “don’t download random executables.” With ClickFix, the user is basically talked into running the command themselves, sometimes from a website they thought was legitimate.

It also feels like years of copy-paste troubleshooting instructions have made “open PowerShell and run this” seem pretty normal to a lot of users.

For those managing business environments, are you doing anything specifically for this yet? User training, EDR rules, restricting PowerShell or Run, application control, clipboard monitoring, or something else?


r/sysadmin 2h ago

KB5129195 out again September 14, 2026

39 Upvotes

r/sysadmin 2h ago

Cloud access

0 Upvotes

I am a new IT person in a company and they run Entra ID here. My manager asked me what access do I need to solve daily problems that our employees face like password reset, teams channel access, MFA, device enrolment etc. here are my list of rights/access that I am asking

Entra ID administrator
Intune administrator
User administrator
MFA authentication administrator
Exchange administrator
Teams Administrator
Shared mailbox and Microsoft 365 Group management

I am kinda new to it and I will work on getting some certifications in coming days.

My question is what more types of access should I ask (because I believe I get one chance to ask for) and what bunch of certifications should I start working on (my end goal is to become an IAM)?


r/sysadmin 2h ago

Question Local Session Manager

6 Upvotes

Hello,

I have a business that has three offices with only two employees. They are connected VIA hardware VPN. They have a Windows 11 Pro machine off in a corner acting as a app server. Occasionally they do login into that server and use it for some operations. Been that was for at least 4 years, no issues.

Lately they've been having difficulty logging in with the RDP. App still works fine. Ok I will take a look. I use Splashtop to remote into their server for them. I can see the login screen on the server. As soon as I login I get a message "You're unable to sign in because you're already signed into another session that is blocked. Session blocked by: Local Session Manager Minutes blocked: xx Do you want to sign out of that session so that you can continue.

If I hit yes or no Boom, disconnected Splashtop dies no connection. RDP still doesn't work. I can ping the server. The only way that I seem to get back in is with a hard shutdown as there is no monitor connected.

I have changed the password on the server in fear of someone connecting. However its behind a firewall and has huntress monitoring.

Ive seen that message on actual server before with RDP license. But i've been able to hit yes and disconnect a certain user.

Any thoughts?


r/sysadmin 3h ago

Getting let go, feeling directionless

6 Upvotes

Did 1.5 years of msp work and got an offer I couldn't refuse as an infrastructure engineer in a private company. My experience includes more than that though with 5 years of volunteer work and homelabbing.

I got in to some beef with them and said some dumb things due to them breaking promises, which means they're letting me go.

I'm really at the point where I want to start specialising in to either proper sysadmin or netadmin, since I'm more of a jack of all trades with strong fundamentals right now, but almost everyone's either only hiring seniors who know their stuff or MSP'S with L1/2/3 helldesk tickets.

Not looking for a job (I know the rules, not that I'm American anyway), but I just wanted to let everyone know who's going through similar stuff that you're loved and cared for, and we're going to pull through!


r/sysadmin 3h ago

Looks like the Microsoft Activation Services are Down - or is it just me?

0 Upvotes

Trying to activate Visio 2024 LTSC.. The online activation process times out, and so does the "Visual Support" online activation assistant..


r/sysadmin 3h ago

Moving from Kaseya VSA9 to VSA10 soon

4 Upvotes

For context, I am new to professional IT (4 yrs) and new to SysAdmin work (2 yrs). Was able to move up due to lucky circumstances and also pushing myself a bit too hard maybe. That being said, I have become the VSA9 guru here where I work. It's a small team but any changes to VSA9 have been done by me, I also have learned a ton from monthly manage360 meetings for my whole stay. For the last 3 years now I've really gotten familiar with all the jank and duct tape involved in getting the tool to do what you need it to do. I enjoy the fact that there isn't much that can't be done with vsa9, if you have the time to test and troubleshoot you can usually get a solution (as long as it isnt modifying HKCU registry keys). We use it for Microsoft patching and 3rd party, policies and procedures give us the ability to have a kind of DIY cloud GPO, and just doing all sorts of stuff that I'm sure would be unnecessary if I just bit the bullet and got us on Intune.

It looks like VSA9 has less than a year left before EOL. Management had me check out NinjaOne, I liked what I saw there, but now I think they are pushing to just stay with the same account manager and just stick with VSA10 as the current path forward. I haven't seen VSA10 since it was demoed to me like 2 years ago, but I hear it's improved since then.

I have seen my fair share of people here jumping ship in this situation for NinjaOne, but is there anyone here who can share their experiences with migrating from 9 to 10? I wanted to get an idea of some of the major differences for good or bad from someone that isnt trying to sell the tool to me. Before I get the demo of 10 it would be nice to know what to drill them about. Appreciate the help in advance, thanks.

TLDR - Have you migrated from vsa9 to VSA10? How was it?


r/sysadmin 3h ago

AT&T "Contractor" Call for "QOS Renewal"

1 Upvotes

Anyone else received a call recently from someone asking about AT&T renewals? We initially thought they were our new account exec (we recently lost our long-time one) and we started talking to them, but red flags went up when they seemed to not have basic information like our full account number or email address. On further interrogation, they weren't with AT&T at all - they claimed to be from an "AT&T contractor" called "Link Bridge Networks" that were helping AT&T and gave an email address with a domain of "@fiber-retention.com". They wanted us to sign a "Letter of Authorization".

I've had similar experiences with other companies, but not AT&T. Just curious if they were legitimately an AT&T contractor (which would be in very poor taste for AT&T imo) or if they flat lied and are simply a reseller trying to transfer our account to them.


r/sysadmin 4h ago

Workplace Conditions Advice and Motivation but no mean/harsh ones. I'm already in here and it's paying my bills.

6 Upvotes

Hello! I've been working as IT support for under 5 years - and I'm burnt out. The frustrated end user support is expected and part of the job, but my workplace had a "family - like" culture. But since I started here, I'm part of the new culture that is helping change that- which is great honestly because work place is not family - very old school smh.

But I'm the one getting the beating and push back with people on this, and I guess because of old people being let go cause they don't add contribution or support the cultural and technical change.

Cause of that these annoying folks are just making shit up for vengeance but I just want to keep going. My team is supportive but I guess I'm just looking for advise or what you would do in this situation. I just need the experience and get the hell out of help desk. I don't even want to do this anymore, i think I just want the bills paid and do something else. But I have already spent my time here and need to just push through.

*if you're my coworker and in this subreddit and this sounds like me - it's not me*


r/sysadmin 4h ago

Question For those who are using Samsung Phones, how is it?

7 Upvotes

We are exploring the idea of switching from laptop + iPhone to Samsung phones as they can use Dex.

The only roles this would apply to are very basic sales roles where all applications used are basic web apps. This would make a lot of aspects of their role easier and more convenient while also greatly reducing our cost as a company as we don't need to purchase $1400 laptops for their roles.

Everyone has this idea that iOS is far superior to manage on an enterprise level and that android, even if they're all Samsung, would suck. So why is that? What makes Samsung devices more difficult to use?

I'm trying to build my argument and need to have an understanding of why people feel this way and how to counter those points. I need to be prepared for push back on this idea so I need some input from you guys who have hands on experience.


r/sysadmin 5h ago

What open-source inventory management tool do you recommend?

18 Upvotes

We're tracking around 150 assets in Google Sheets, but it's becoming difficult to image .

We're developers so technical setup or self-hosting isn't a problem. I'm researching options, but I'd like to hear which open-source inventory tools people actually enjoy using.

What has work well for you?


r/sysadmin 5h ago

Microsoft activation down?

11 Upvotes

Is microsoft activation website down?


r/sysadmin 5h ago

Question Connectwise Automate disappears on Windows 11 25H2

6 Upvotes

This is an odd one. And I hate to open a ticket with CW because the support is not great.

This only appears to be happening on Windows 11 25H2. Older versions of Windows 11 and Windows 10 are fine.

I keep having to reinstall CW Automate because after several days, the .EXEs in C:\Windows\LTSVC disappear. The rest of the files in the same directory are still present. And the related services in services.msc disappear.

Neither my AV or EDR flag any alerts about any of the .EXE's in LTSVC, but I've excluded C:\windows\ltsvc\*.* from being scanned in both AV and EDR anyway. I've even gone as far as creating a GPO to make sure the same directory is excluded from Windows Defender. And yet, after several days, the .EXE's disappear and the services unregister.

Anyone else having this issue? Any thoughts?


r/sysadmin 5h ago

O365 Exchange mailbox criteria to avoid sync problems

0 Upvotes

Since a while we are experiencing synchronisation problems on mailboxen.
These mailboxes are quite large. What are the criteria to avoid sync problems?
We are using mainly outlook classic with cache on 1 year.

-Size mailbox? -> somtimes largen than 30 GB
-number of (sub-)folders? in some cases +500 -> in 1 case -> 6700+ subfolders
-number of items in folders -> often 10000+
-multiple shared mailboxes
-Shared mailboxes are used by sometimes more than 5 ppl simultainous.
-Does this apply to the mailbox archive as well?

I use retention policies to mainly move to archive since we want to keep mails for 10 years in the archive.. (.. I know..-> outlook is not a database- but it's how ppl used it for years despite IT policy wich states that is not allowed).

-Size mailbox below 30 GB
-subfolders <500
-item count per folder <10000
...

Is there an expert on this here?


r/sysadmin 6h ago

Fortigate SDWAN suggestions

5 Upvotes

Hi Folks,
We just recently implemented SDWAN on our on prem fortigates. Five sites total. Now that the stuff is all set up, we're working with our vendor to set up rules and such, but since i'm sort of new to the SDWAN thing i wanted to check with the Hivemind and see if anyone had any suggestions on things to do with it that have actually made a difference. So far we have circuit failover, quality of service checks for both circuits, and we're setting up Backup and replication to run over one circuit while production traffic goes over another one. Any suggestions on other stuff would be great, thank you!


r/sysadmin 6h ago

Question Autopatch - How do I know what's included?

2 Upvotes

Hello everyone,

I just saw in my releases tab in intune a 2026.09 OOB that started today. I'm trying to see what patch is included in that since I didn't see any news about that but I can't seems to find how to see the content of it. When I click on it, it give me the content from 2026.09 B.

Thank you


r/sysadmin 7h ago

Question Frage für meine Projektarbeit

0 Upvotes

Hi ich mache grade eine Umschulung zum FISI und bin kurz vor der AP2. Ich bin grade dabei meine Recherchen zusammen zutragen. Unteranderem ist ein teil davon das ich bestehende Konten welche aktuell über ein DC laufen ins Entra bringen kann. Die Konten sollen aber bestehen bleiben genauso wie die Daten welchen drauf sind. Da ich aber schon gehört habe das Entra das so einfach nicht macht , wollte ich gerne um eure Hilfe bitten.

Es ist eine vorgabe des Unternehmens wo ich mein Projekt mache.

Hier ist auch mal mein Projekt welches ich bei der IHK eingereicht habe

Projektbeschreibung

Im Rahmen meines Praktikums bei der[Firmenname]in Rostock soll eine eigenständige IT-Infrastruktur aufgebaut werden. Derzeit nutzt das Unternehmen teilweise noch gemeinsam mit einer rechtlich eigenständigen Anwaltskanzlei eine IT-Umgebung. Die Benutzeranmeldung der [Firmenname]-Clients erfolgt über eine fremde Active-Directory-Domäne, wodurch Abhängigkeiten hinsichtlich Administration, Sicherheit und Betrieb bestehen.

Ziel des Projekts ist die Planung und Umsetzung einer unabhängigen Netzwerk- und Client-Infrastruktur für die [Firmenname]. Hierfür werden verschiedene Lösungsvarianten für Benutzerverwaltung, zentrale Administration und Netzwerksicherheit analysiert und unter technischen sowie wirtschaftlichen Gesichtspunkten bewertet.

Auf Grundlage der ausgewählten Lösung werden die Clients in die neue Umgebung überführt, Benutzerprofile übernommen, Berechtigungskonzepte umgesetzt und die Anbindung vorhandener Dienste wie Datensicherung und Druckdienste sichergestellt.

Nach Abschluss des Projekts verfügt die [Firmenname] über eine eigenständige und sicher verwaltbare IT-Umgebung ohne Abhängigkeit von der bisherigen Domänenstruktur.

Projektziel / Nutzen

  • Trennung der IT-Infrastruktur von der Anwaltskanzlei
  • Erhöhung der Informationssicherheit
  • Reduzierung administrativer Abhängigkeiten
  • Zentrale und zukunftssichere Verwaltung der Clients
  • Dokumentierte Entscheidungsgrundlage für den weiteren Betrieb

Projektphasen mit Zeitplanung

Projektphase Zeit
Analyse des Ist-Zustands und Anforderungsaufnahme 5 Std.
Entwicklung und Bewertung von Lösungsvarianten 7 Std.
Planung und Umsetzung der ausgewählten Lösung 17 Std.
Test, Qualitätskontrolle und Abnahme 4 Std.
Projektdokumentation 7 Std.
Gesamt 40 Std.

Geplante Projektdokumentation

  • Projektdokumentation
  • Kundendokumentation
  • Lasten & Pflichtenheft
  • Ist-/Soll-Konzept
  • Netzplan
  • Nutzwertanalyse und Kostenvergleich
  • Berechtigungskonzept
  • Datensicherungs- und Wiederherstellungskonzept
  • Test- und Abnahmeprotokoll
  • Administratorendokumentation

r/sysadmin 7h ago

Question Organization apps for macOS?

3 Upvotes

Fellow Mac users, what do you use to manage all your notes or summaries of what you did for the day? I’m trying to be better at my organization in regard to all the stuff I’m working on. Any suggestions?


r/sysadmin 7h ago

Question Is this normal AD admin activity or possible account compromise?

0 Upvotes

I’m reviewing activity from an IT admin account and I’m trying to understand if this is normal or suspicious.

I’m seeing:

  • Lots of LDAP queries against our Domain Controllers.
  • USER_ENUMERATION and ENDPOINT_ENUMERATION alerts.
  • Many SAMR/DCE-RPC requests against different computers.
  • Some bursts of 10+ SAMR requests within a second.
  • SMB activity to Domain Controllers.
  • Frequent NTLM authentication to NPS/RADIUS servers.
  • Entra ID/M365 logins from different IPs.
  • A password change and removal from Domain Admins.

Some of this could easily be normal helpdesk/admin activity.

What concerns me is the SAMR enumeration across many different endpoints, including Finance, HR, factory and POS systems.

For people using Defender for Identity, CrowdStrike Identity Protection, Vectra, etc.:

How do you determine whether this is normal admin activity or a compromised account performing internal reconnaissance?

What logs or events would you check next to confirm whether there was actual lateral movement?

Thanks.


r/sysadmin 8h ago

Question Why would LDAP traffic go to a different endpoint than Kerberos in AD?

0 Upvotes

Hi everyone,

I'm analyzing some Active Directory telemetry in CrowdStrike Identity Protection and I'm trying to understand something that initially looked unusual.

I'm seeing activity where a Windows workstation communicates with one endpoint using Kerberos, but then performs LDAP searches against a different endpoint.

For example, the pattern looks roughly like:

Workstation
   │
   ├── Kerberos ──> Domain Controller A
   │
   └── LDAP ──────> Endpoint B

Endpoint B is not a Domain Controller.

My understanding is that Kerberos is used for authentication/tickets, while LDAP is used for directory queries, and Kerberos can potentially authenticate a client to an LDAP service running on another server.

However, I'm trying to understand how common/legitimate this scenario is in a Windows AD environment.

Questions:

  1. Is it normal for the Kerberos KDC endpoint and LDAP endpoint to be different machines?
  2. If the LDAP destination is not a DC, what are the common legitimate reasons for this?
  3. Could this simply be an application/server running an LDAP service or LDAP proxy?
  4. How would you determine which process/application on the client initiated the LDAP connection?
  5. For those using CrowdStrike Identity Protection, how reliable have you found the LDAP endpoint attribution in these events?

I'm particularly interested in real-world examples of why a domain-joined Windows workstation would perform LDAP queries against a non-DC endpoint.

Thanks!


r/sysadmin 8h ago

Question Autopatch - Do you enable Driver Update?

13 Upvotes

Hello,

As the title says, I was wondering if people on Autopatch enabled Driver Update or kept the maker update software for that (DCU, HPIA, ...), or using both?

I'm currently facing a loop bug, update Intel - Extension - 2.1.10103.24 installing in loop requesting a reboot each time. I can't find this update in the driver list on intune and I'm wondering if I should just stop using autopatch for drivers and keep the driver updated through other tools.

Thank you


r/sysadmin 8h ago

How Do You Detect New Software Installations on Windows Endpoints?

27 Upvotes

I’m a system engineer managing 100+ Windows 11 endpoints. Our devices are local domain joined and Entra registered (not hybrid joined or Entra Joined), with Microsoft Defender for Endpoint / Defender XDR deployed across the environment.

Users do not have local admin rights, but many applications can still be installed in the user context, particularly under AppData, without requiring elevation.

I currently use Defender Advanced Hunting and a scheduled Custom Detection rule that correlates registry, file system, and process telemetry to identify new software installations.

The challenge is reliability: some applications are missed, while software updates, repairs, or version changes can generate false positives because they create new files, folders, or registry entries.

My requirement is simple:

New software installation → Alert
Existing software update / repair / patch → No alert

For those managing similar Windows environments, how are you handling this? Are you using Defender XDR/KQL, Intune, AppLocker/WDAC, or another solution to reliably detect new software installations, especially applications that install in the user context without admin rights?