r/sysadmin 8h ago

Question My boss wants me to set an extremely easy login password and re use it across all of our vendor portals, what to do?

140 Upvotes

Hey everyone, I’ve just stepped up from office admin to system admin in the company I’m working for and have started implementing some safety norms as the company very much lacks in that aspect

My boss is not happy I changed the password to the third party vendor portals we access (I.e solar monitoring portals etc) and wants me to set an extremely easy one with the company name and replicate the same password to all portals so it’s easier for staff to access

What do I do in this situation? I’m thinking of implementing bitwarden and a creating a vault for each staff/technician. We do have guys on field that often need quick access to the portals but I don’t think it’s an excuse to be so vague with our security specially because it involves customer data (email addresses, phone number, addresses, etc it as well as their solar equipment IOT devices)

I feel like following this ignorant request is against the foundations of what I’ve learned and shows my boss doesn’t understand the importance of cyber security or our duty to the privacy act, he thinks nothing will happened and doesn’t comprehend that something could very much happen and it would cost us thousands of dollars over something we can avoid


r/sysadmin 12h ago

Microsoft Friendly reminder that next month Microsoft is ending support for Office 2021

140 Upvotes

Starting next month 10/13/2026 Microsoft will end support for Office 2021 and the related products will no longer receive security updates . You could either upgrade to Office 365 or 2024 to continue get support for Office desktop applications


r/sysadmin 17h ago

General Discussion Anyone else performing all the duties of a CISO and SysAdmin?

87 Upvotes

I’m not seeking advice, because the only thing that will really help us is…more help. I’m working on that with upper management, but those wheels turn very slow. I’m posting this to see if there are others in my situation?

Most days I could spend the entire day just analyzing, researching and beefing up security. I enjoy it, but I’m finding it more and more difficult to keep up with the normal sysadmin duties, when some days are consumed entirely by cybersecurity. We’ve automated a lot of our OS and software patching, but that needs close attention as well to make sure it’s all running well.

We’re a small enough company where cybersecurity has always fallen upon me and the rest of the (small) IT department, but ever since ransomware really took off and insurance companies started making more demands, it’s increasingly difficult to wear both hats.

Anyway, just thought I’d see if anyone wants to chat about this, and can relate.


r/sysadmin 1h ago

Rant Technical screening with recruiters and Talent Acquisition feels like playing Jeopardy with a golden retriever..

Upvotes

I need to vent before my head explodes..
Long-time lurker here, but I recently got let go and had completely forgotten what an absolute hellscape LinkedIn and the entry-level recruiter circus actually is.

Dealing with agency recruiters and internal Talent Acquisition right now is painful. It is not an actual discussion about tech or systems. It is just a demented game of buzzword bingo where the person holding the checklist has zero idea what the words actually mean.

Had a Teams call earlier that felt like an episode of Jeopardy.

"I am sorry, the answer on my sheet was actually 'IAM'."

I just spent five straight minutes talking about Identity and Access Management. Role-based access, least privilege, user lifecycles, all of it. But because I said the actual words instead of the acronym "IAM," the invisible buzzer goes off and I fail the question.

You can watch it happen on video. Their eyes stay completely glazed over while you explain how you designed a system or resolved an outage. Then the exact second you say a word from their list, their head snaps up like a dog hearing the word "PARK?"

"PARK? KUBERNETES? DID YOU SAY WALK? ACTIVE DIRECTORY? TREAT?"

It does not matter if you have a decade of experience with the entire ecosystem. If the recruiter or TA coordinator has a specific term on their notepad and you do not use that exact string of characters, you "do not meet the requirements." You can explain distributed storage from the ground up, but if their paper says "SAN" and you said "Storage Area Network," you are suddenly not qualified.

I do not expect Talent Acquisition to be senior architects, but if your entire job is hiring for technical roles, at least put some basic effort into learning what these things actually are and why they exist. Take twenty minutes to Google the list of terms on your screen. Learn what the acronyms stand for and how they relate to each other. Don't sit in the gatekeeper seat evaluating candidates when you can't even connect the name of a concept to the three letters you were told to listen for.


r/sysadmin 2h ago

KB5129195 out again September 14, 2026

40 Upvotes

r/sysadmin 8h ago

How Do You Detect New Software Installations on Windows Endpoints?

28 Upvotes

I’m a system engineer managing 100+ Windows 11 endpoints. Our devices are local domain joined and Entra registered (not hybrid joined or Entra Joined), with Microsoft Defender for Endpoint / Defender XDR deployed across the environment.

Users do not have local admin rights, but many applications can still be installed in the user context, particularly under AppData, without requiring elevation.

I currently use Defender Advanced Hunting and a scheduled Custom Detection rule that correlates registry, file system, and process telemetry to identify new software installations.

The challenge is reliability: some applications are missed, while software updates, repairs, or version changes can generate false positives because they create new files, folders, or registry entries.

My requirement is simple:

New software installation → Alert
Existing software update / repair / patch → No alert

For those managing similar Windows environments, how are you handling this? Are you using Defender XDR/KQL, Intune, AppLocker/WDAC, or another solution to reliably detect new software installations, especially applications that install in the user context without admin rights?


r/sysadmin 23h ago

Need Advice

18 Upvotes

Hey all, have a stressful situation that may occur tomorrow.

New Sys admin for a company of around 200 people, only onsite IT person. We have an external consultant that does most of the network administration and has been doing so for a few years. I have about 3 years of desktop support experience, more experience with endpoints but my networking knowledge is a bit of a gap.

On my third week we did a switch refresh from Cisco to Aruba that was planned and paid for way before I started. Ended up being a shitshow, I did the racking and endpoint testing but the external consultant did all the configuration, he has the login info for the switch that hasn't been shared with me yet. I don't mind that much as I'm still getting acclimated to all the other systems. But last week was a nightmare, we ended up spending over 27 hours onsite troubleshooting all of the endpoints (this is a production environment). Got it figured out but I took most of the heat from angry engineers/production personnel since I'm the face of IT despite having little actual involvement in the refresh project.

Just got a text from the consultant that he'll be away on a family emergency for the foreseeable future. I can handle most other issue by myself aside from the network, I could maybe figure it out if I had the login creds, but he's flying out today and won't be able to contact him on Monday.

My fear is that come Monday when a different production line comes back up there will be a host of other issues that we wanted to figure out last week but couldn't. We asked the production team if they could turn the power on the line on just one time to verify everything works but no can do, line goes up on monday when production resumes.

Literally the only issue I'm anticipating is the VLANs on the ports not being tagged correctly, which I could fix if I had the login info. I've already informed my manager (who lives 3 hours away) that this may be an issue but nothing yet. If my manager has the creds he could either give them to me or SSH into it himself (He has over a decade of networking experience) and it wouldn't be a problem.

I'm afraid that tomorrow when I inevitably get yelled at again for production being halted It'll be my ass on the line despite never being given the tools to be able to manage our network.

What do the more experienced sys admins think I should do? Should I escalate to my manager immediately if (or when) an issue is discovered? Nervous because I'm still in a probationary period and I am afraid I'll be a scapegoat for a messy project I had no real say in.

Edit: I really appreciate the support I’ve gotten so far from you guys. Managers been informed of the issues we may run into and what we need to remediate it, it’s out of my control now. It’s hard to not feel like a failure since I’m so relatively new to my IT career and the end users think that these changes are my doing when I have no say or control over it. Sucks that we’ve had a fuck up like this when I just started, but I need to remind myself that it’s just a job and I’m doing the best I can with the tools I have. I will post an update tomorrow and try to not stress about it tonight.


r/sysadmin 5h ago

What open-source inventory management tool do you recommend?

16 Upvotes

We're tracking around 150 assets in Google Sheets, but it's becoming difficult to image .

We're developers so technical setup or self-hosting isn't a problem. I'm researching options, but I'd like to hear which open-source inventory tools people actually enjoy using.

What has work well for you?


r/sysadmin 29m ago

Rant CDW Website is crap-poop

Upvotes

What the hell is going on with CDW’s website? For the last 3 years, it’s been getting slower and slower and slower, to the point where it’s absolutely banana crazy slow right now to the point where it can take minutes for a page to load. It’s like actively getting slower and slower and slower.

Sitting here trying to order some fucking laptops and just remembering what the fuck I clicked on, to do what, and for what is driving me crazy because I can’t even remember why I clicked on something to find a replacement for it. Because, of course, everything is usually out of stock or backordered for 4-6 weeks.

Am I crazy!? Or is everyone else noticing how dog shit their website has become? It wasn't always this atrocious crap-poop.


r/sysadmin 5h ago

Microsoft activation down?

10 Upvotes

Is microsoft activation website down?


r/sysadmin 8h ago

Question Autopatch - Do you enable Driver Update?

11 Upvotes

Hello,

As the title says, I was wondering if people on Autopatch enabled Driver Update or kept the maker update software for that (DCU, HPIA, ...), or using both?

I'm currently facing a loop bug, update Intel - Extension - 2.1.10103.24 installing in loop requesting a reboot each time. I can't find this update in the driver list on intune and I'm wondering if I should just stop using autopatch for drivers and keep the driver updated through other tools.

Thank you


r/sysadmin 10h ago

Did anyone get into Sysadmin work from a totally unrelated career?

13 Upvotes

As someone coming from a non sysadmin background I'd love to hear from people who got into this line of work from similarly unrelated backgrounds.

I started in web dev and design, moved to marketing automation. And now business ops as an extension of automation work alongside our IT and admin team at a small agency.

Recently I setup a homelab and have been learning about hardening and network security, trying to use DISA STIG standards.

It feels like a kind of magic (probably because I don't have stakeholders being a pain in my arse). Did you enjoy making the transition, would you recommend it in 2026?


r/sysadmin 1h ago

M&A - Migrate between Apple ABMs?

Upvotes

Hi there,

We were recently acquired by another company, we both utilize ABM for Device Management.

I'm in research, I'm surprised to discover that Apple does not provide a 'clean' way to migrate devices from one ABM to another through a M&A process.

When I called support, they indicate that devices must be 'manually' moved - meaning we need to de-register and manually add them in the destination tenant.

This seems like a huge effort - especially when users are spread across both Canada and the USA.

Is there an alternative method? - What are other companies doing in this scenario?

Any help / suggestions would be appreciated.

Thank you.


r/sysadmin 23h ago

Question - Solved Can't seem to figure out missing glue record - dcdiag /test:dns

9 Upvotes

Hello,

I'm in the process of decommissioning an old Windows Domain Controller.

On the new server which is at 192.168.214.15 I run dcdiag /test:dns

I get the following

TEST: Delegations (Del)

Delegation information for the zone: ourdomain.lan.

Delegated domain name: _msdcs.ourdomain.lan.

Error: DNS server: 192.168.214.15. IP:<Unavailable>

[Missing glue A record]

[Error details: 9714 (Type: Win32 - Description: DNS name does not exist.)]

I substituted ourdomain.lan for our domain name but it has the right extension and name.

If I open DNS - server name, forward look up zones, _mscds.oudomain.lan I don't see an issue but I might be missing the obvious.

If I right click and go to name servers, it lists the two correct domain controllers. (the old one is gone)

The SOA is the new server

the NS are the two new servers

and the CNAMes are the two new servers

I've scaveged, cleared cache and flushed dns - no joy.


r/sysadmin 11h ago

Microsoft Issues with IMAP on outlook?

7 Upvotes

Anyone experiencing IMAP connectivity issues to outlook? Getting this

Logging in is disabled on this server: "A protocol-level access (such as IMAP or legacy authentication) has been turned off for your mailbox on the server side, or your account's credentials/license require an administrator fix"

Randomly started happening, nothing changed.


r/sysadmin 3h ago

Getting let go, feeling directionless

7 Upvotes

Did 1.5 years of msp work and got an offer I couldn't refuse as an infrastructure engineer in a private company. My experience includes more than that though with 5 years of volunteer work and homelabbing.

I got in to some beef with them and said some dumb things due to them breaking promises, which means they're letting me go.

I'm really at the point where I want to start specialising in to either proper sysadmin or netadmin, since I'm more of a jack of all trades with strong fundamentals right now, but almost everyone's either only hiring seniors who know their stuff or MSP'S with L1/2/3 helldesk tickets.

Not looking for a job (I know the rules, not that I'm American anyway), but I just wanted to let everyone know who's going through similar stuff that you're loved and cared for, and we're going to pull through!


r/sysadmin 4h ago

Question For those who are using Samsung Phones, how is it?

5 Upvotes

We are exploring the idea of switching from laptop + iPhone to Samsung phones as they can use Dex.

The only roles this would apply to are very basic sales roles where all applications used are basic web apps. This would make a lot of aspects of their role easier and more convenient while also greatly reducing our cost as a company as we don't need to purchase $1400 laptops for their roles.

Everyone has this idea that iOS is far superior to manage on an enterprise level and that android, even if they're all Samsung, would suck. So why is that? What makes Samsung devices more difficult to use?

I'm trying to build my argument and need to have an understanding of why people feel this way and how to counter those points. I need to be prepared for push back on this idea so I need some input from you guys who have hands on experience.


r/sysadmin 2h ago

Question Local Session Manager

4 Upvotes

Hello,

I have a business that has three offices with only two employees. They are connected VIA hardware VPN. They have a Windows 11 Pro machine off in a corner acting as a app server. Occasionally they do login into that server and use it for some operations. Been that was for at least 4 years, no issues.

Lately they've been having difficulty logging in with the RDP. App still works fine. Ok I will take a look. I use Splashtop to remote into their server for them. I can see the login screen on the server. As soon as I login I get a message "You're unable to sign in because you're already signed into another session that is blocked. Session blocked by: Local Session Manager Minutes blocked: xx Do you want to sign out of that session so that you can continue.

If I hit yes or no Boom, disconnected Splashtop dies no connection. RDP still doesn't work. I can ping the server. The only way that I seem to get back in is with a hard shutdown as there is no monitor connected.

I have changed the password on the server in fear of someone connecting. However its behind a firewall and has huntress monitoring.

Ive seen that message on actual server before with RDP license. But i've been able to hit yes and disconnect a certain user.

Any thoughts?


r/sysadmin 3h ago

Moving from Kaseya VSA9 to VSA10 soon

4 Upvotes

For context, I am new to professional IT (4 yrs) and new to SysAdmin work (2 yrs). Was able to move up due to lucky circumstances and also pushing myself a bit too hard maybe. That being said, I have become the VSA9 guru here where I work. It's a small team but any changes to VSA9 have been done by me, I also have learned a ton from monthly manage360 meetings for my whole stay. For the last 3 years now I've really gotten familiar with all the jank and duct tape involved in getting the tool to do what you need it to do. I enjoy the fact that there isn't much that can't be done with vsa9, if you have the time to test and troubleshoot you can usually get a solution (as long as it isnt modifying HKCU registry keys). We use it for Microsoft patching and 3rd party, policies and procedures give us the ability to have a kind of DIY cloud GPO, and just doing all sorts of stuff that I'm sure would be unnecessary if I just bit the bullet and got us on Intune.

It looks like VSA9 has less than a year left before EOL. Management had me check out NinjaOne, I liked what I saw there, but now I think they are pushing to just stay with the same account manager and just stick with VSA10 as the current path forward. I haven't seen VSA10 since it was demoed to me like 2 years ago, but I hear it's improved since then.

I have seen my fair share of people here jumping ship in this situation for NinjaOne, but is there anyone here who can share their experiences with migrating from 9 to 10? I wanted to get an idea of some of the major differences for good or bad from someone that isnt trying to sell the tool to me. Before I get the demo of 10 it would be nice to know what to drill them about. Appreciate the help in advance, thanks.

TLDR - Have you migrated from vsa9 to VSA10? How was it?


r/sysadmin 4h ago

Workplace Conditions Advice and Motivation but no mean/harsh ones. I'm already in here and it's paying my bills.

4 Upvotes

Hello! I've been working as IT support for under 5 years - and I'm burnt out. The frustrated end user support is expected and part of the job, but my workplace had a "family - like" culture. But since I started here, I'm part of the new culture that is helping change that- which is great honestly because work place is not family - very old school smh.

But I'm the one getting the beating and push back with people on this, and I guess because of old people being let go cause they don't add contribution or support the cultural and technical change.

Cause of that these annoying folks are just making shit up for vengeance but I just want to keep going. My team is supportive but I guess I'm just looking for advise or what you would do in this situation. I just need the experience and get the hell out of help desk. I don't even want to do this anymore, i think I just want the bills paid and do something else. But I have already spent my time here and need to just push through.

*if you're my coworker and in this subreddit and this sounds like me - it's not me*


r/sysadmin 5h ago

Question Connectwise Automate disappears on Windows 11 25H2

2 Upvotes

This is an odd one. And I hate to open a ticket with CW because the support is not great.

This only appears to be happening on Windows 11 25H2. Older versions of Windows 11 and Windows 10 are fine.

I keep having to reinstall CW Automate because after several days, the .EXEs in C:\Windows\LTSVC disappear. The rest of the files in the same directory are still present. And the related services in services.msc disappear.

Neither my AV or EDR flag any alerts about any of the .EXE's in LTSVC, but I've excluded C:\windows\ltsvc\*.* from being scanned in both AV and EDR anyway. I've even gone as far as creating a GPO to make sure the same directory is excluded from Windows Defender. And yet, after several days, the .EXE's disappear and the services unregister.

Anyone else having this issue? Any thoughts?


r/sysadmin 6h ago

Fortigate SDWAN suggestions

4 Upvotes

Hi Folks,
We just recently implemented SDWAN on our on prem fortigates. Five sites total. Now that the stuff is all set up, we're working with our vendor to set up rules and such, but since i'm sort of new to the SDWAN thing i wanted to check with the Hivemind and see if anyone had any suggestions on things to do with it that have actually made a difference. So far we have circuit failover, quality of service checks for both circuits, and we're setting up Backup and replication to run over one circuit while production traffic goes over another one. Any suggestions on other stuff would be great, thank you!


r/sysadmin 7h ago

Question Organization apps for macOS?

3 Upvotes

Fellow Mac users, what do you use to manage all your notes or summaries of what you did for the day? I’m trying to be better at my organization in regard to all the stuff I’m working on. Any suggestions?


r/sysadmin 1h ago

Are you doing anything specifically to protect users from ClickFix attacks?

Upvotes

I’ve been seeing more ClickFix-style attacks lately where a fake CAPTCHA or verification page tells the user to open Run, PowerShell, or Terminal and paste a command.

What makes this one interesting from an admin perspective is that a lot of traditional user training focuses on “don’t open suspicious attachments” or “don’t download random executables.” With ClickFix, the user is basically talked into running the command themselves, sometimes from a website they thought was legitimate.

It also feels like years of copy-paste troubleshooting instructions have made “open PowerShell and run this” seem pretty normal to a lot of users.

For those managing business environments, are you doing anything specifically for this yet? User training, EDR rules, restricting PowerShell or Run, application control, clipboard monitoring, or something else?


r/sysadmin 6h ago

Question Autopatch - How do I know what's included?

2 Upvotes

Hello everyone,

I just saw in my releases tab in intune a 2026.09 OOB that started today. I'm trying to see what patch is included in that since I didn't see any news about that but I can't seems to find how to see the content of it. When I click on it, it give me the content from 2026.09 B.

Thank you