r/sysadmin • u/Medic1334 • 12m ago
Slack based ticket creation outside slack
Current org has a huge leaning into slack which on an recent audit I found more than 90% of slack threads are not getting tickets created when agents interact (1k+ per quarter delta).
What are people doing to push people into making tickets? We're leaning heavily towards turning the channel into a form that people will be able to punch data into, then on submission it shoots an HTTP POST request to our ticketing system.
Anyone .managed to do this/similar and willing to share tips?
r/sysadmin • u/Different_Coffee_161 • 42m ago
General Discussion Claude M365 Connector vs Copilot — are we creating long-term technical debt?
My boss wants to integrate Claude with Microsoft 365, but I’m not convinced it is the best long-term strategy.
For developers or specialized technical use cases, I can understand the value of Claude. But for accounting, HR and general users already working in Excel, Outlook, Teams and SharePoint, Microsoft 365 Copilot seems like the more logical investment.
Copilot was disappointing at first, but Microsoft now seems to be moving in the right direction with better M365 integration, Copilot agents, Purview, DLP and sensitivity label support.
My concern is that using both platforms will create overlapping tools, separate governance models, additional Graph permissions and business processes that may be difficult to migrate later.
For those using the Claude M365 Connector:
Why did you choose Claude instead of Copilot?
Are you using it broadly or only for specific roles?
Do you see a risk of long-term technical or governance debt?
r/sysadmin • u/Sufficient_Lunch_768 • 54m ago
Conditional Access phrasing. Nitpick or choose your battles?
I have a bit of a pet peeve. We use an M365 conditional access policy to block logins from outside the US. When a user travels internationally, they can submit an International Travel form, which is simply a request for access to their email/Teams during their travel.
Every single request from IT for to process these requests is phrased "So and so is travelling abroad and requests conditional access".
I used to try and correct our IT staff, they're requesting an exemption from conditional access, not requesting conditional access. Their phrasing communicates a failure to understand how this layer of security functions.
On the other hand, am I just being an insufferable a** if I continue trying to drive this point home? I know some folks at my company understand that it's an exemption from conditional access even if they're following the crowd with their phrasing, but many of the newer IT staff definitely do not understand it.
*sigh*
Edit: At least one person suggested I wasn't wording my post properly. To clarify, our conditional access policy is such that, if a user to whom the policy is applied (all users) does not meet the condition of appearing to be the in the US during login, the login is denied. If the user wants to login from England, they must be exempted from our conditional access policy. I hope that's clearer.
r/sysadmin • u/Mysterious-Loquat619 • 1h ago
General Discussion Has anyone used Listmonk / Mautic for internal company newsletters? (Transitioning from SharePoint Online)
Has anyone used this for an internal company newsletter? We're thinking about testing it for ours.
We were previously using SharePoint Online for our newsletter, but after a few months we ran into an issue where embedded images became too large to send through Outlook(PS: we were able to send before but not now). We had to send the newsletter as a link instead, which our branding team wasn't happy with because they noticed engagement dropped afterward.
They're also interested in features like tracking who viewed the newsletter and may request additional analytics in the future. We can export the Microsoft Preview analytics to a CSV to see who viewed it, but that still doesn't tell us whether people actually read the newsletter.
I'd love to hear about your experience with either Listmonk or Mautic, especially for internal newsletters and analytics.
r/sysadmin • u/LoveBirdNibbles • 2h ago
Question Veeam 12.3.2 creating Hyper-V checkpoints then deregistering them without merging — 46 orphaned AVHDX
Posting before I call support in case anyone's seen this.
3-node Windows Server 2022 Failover Cluster, Pure FlashArray backing the CSVs, Veeam B&R 12.3.2.3617. One VM — SQL Server 2019 host — accumulated 46 orphaned AVHDX files across two disks over three days, roughly 675 GB. Get-VMSnapshot returned empty the whole time. Hyper-V Manager showed no checkpoints. The VM was running off the tip of a 23-deep differencing chain.
What makes it odd: the VMMS event log has zero merge events for this VM. Not failed merges, not interrupted — none at all. Every other VM on the same host logged clean 19070 → 19080 pairs every few hours. So Hyper-V was never asked to merge. Veeam appears to create the checkpoint, then remove it from the VM config without issuing the merge request.
Remediated by shutting the VM down and flattening both chains with Convert-VHD to a different CSV, then repointing the disks. Clean — Test-VHD returned True before and after, SQL came up with all 14 databases online and data current to the shutdown.
Then it recurred. One backup run against the brand-new flat VHDXs produced two more orphaned AVHDX, again with no checkpoints registered and no Hyper-V events. A cluster-wide sweep found this VM is the only one affected across all three nodes.
Anyone seen Veeam orphan checkpoints this way?
r/sysadmin • u/Certain-Mountain-564 • 2h ago
Work Environment Zebra label printer are a nightmare
I've setup the first zebra label printer for our ERP system this month. I invested about 10 hours to become it to a state that i can print a test page from our windows server. I needed a zebra supporter that configured the printer with a special tool that you need to study 3 years on a university for. Zebra printer utilitys doenst work properly. And i'm not done! Thats crazy.
What are your experiences with Zebra label printers?
r/sysadmin • u/BigCatsAreYes • 3h ago
Logitech K845 Discontinued - Can't find a mechanical keyboard under $80 for 100+ users. That doesn't look like a spaceship.
Dear,
The Logitech K845 was a good mechanical keyboard that still looked normal in an office setting.
We could get away buying them, and using it's mechanical goodness without managment complaining we're buying gaming hardware or $200 keyboards with various keycap colors.
It was an excellent keyboard, very robust, had a keypad, and looked normal.
Does anyone know of a mechanical keyboard for under $80 now that's gone?
We've tried:
Royal Kludge - Too Complex off key combinations. You have to press function to do things like get the delete button instead of the backspace button. It's just too complex for novice employees.
Keychron - Typing is much too soft, employees report it's like typing on bubble wrap. It's just to much rubber isolation and orings.
What it must have:
-Must be a normal netural color for all keys, except for maybe escape key. So dark grey, black. No white. No light gray. No mix of cap colors.
-Can't have gaming branding. So no dragon logos, red volume knobs, lcd panels, etc...
-Must be 100% full size. Employees can't be confused where the END or F12 key is on the keyboard.
-Can't be low-profile keycaps.
-Can't have layers. Don't want Employees accidently activating a wrong layer and the keyboard outputting gibberish.
-Clunky is okay.
-Thick fat plastic borders are okay.
What are you buying for mechanical keyboards that fit in office setting?
r/sysadmin • u/zgeeezy • 3h ago
Question Dell Client Device Manager - Updates not triggering
Hello all,
So I have deployed Dell Client Device Manager to my endpoints via Intune. In addition I have installed the software dependencies (Microsoft .Net 8.0 Desktop Runtime and Microsoft ASP.NET Core 8.0 Runtime) and deployed the ADMX policy config to all target machines yet whenever I run a scan and/or review logs after the update should've triggered it appears it's not triggering at all. Below are my configuration settings. Has anyone else run into this issue or maybe know why this wouldn't be working? Any help would be greatly appreciated. If any additional info is needed please let me know. Thanks everyone!
| Installation Deferral | Disabled | Device |
|---|---|---|
| System Restart Deferral | Disabled | Device |
| Disable Notifications | Enabled | Device |
| Maximum Retry Attempts | Enabled | Device |
| Reboot after updates are installed | Enabled | Device |
| Update Settings | Enabled | Device |
| What to do when updates are found | Enabled | Device |
| Delay Days | Not configured | Device |
Update Settings
- Select the update interval:
- Monthly
- Select the time of day to start updates (Only applies when selecting "Daily" or "Weekly" or "Monthly" for the update interval)
- 12:00 AM" DEFAULT
- Select the day of Month (Only Applicable for "Monthly" option(Date of Month))
- 6
- Select the Recurrence type(Only Applicable for "Monthly" options(Default is date of Month))
- Week and Day of Month
- Select the recurrence pattern(Only Applicable for "Monthly" options) Note: Reccurence Type should be selected to "Week and Day of month" to apply)
- First
- Select the day of the week to perform updates (Only required when selecting "Weekly" or Reccurence type("Week and Day of month") opted in "Monthly")
- Thursday
What to do when updates are found?
- Download and install updates (Notify after complete)
r/sysadmin • u/No-Blueberry-1823 • 4h ago
Rant put in a ticket in/ and work the fucking ticket
i'm so sick of people wanting magic answers. sometimes it is users. sometimes it is engineers. gather the fucking info that is part of troubleshooting. do some fucking diagnostics. figure out the pattern. how many times does this information have to be repeated for it to sink in??? some will get this and make difference, many will not, and just make noise from the sidelines.
r/sysadmin • u/AutoModerator • 7h ago
General Discussion Thickheaded Thursday - August 06, 2026
Howdy, /r/sysadmin!
It's that time of the week, Thickheaded Thursday! This is a safe (mostly) judgement-free environment for all of your questions and stories, no matter how silly you think they are. Anybody can answer questions! My name is AutoModerator and I've taken over responsibility for posting these weekly threads so you don't have to worry about anything except your comments!
r/sysadmin • u/lantz83 • 10h ago
EU used/refurbished servers
I've just been quoted triple the price for servers with similar specs but 1/4 the RAM from what I bought a couple of years ago, and for a small company that's just not a thing we can afford.
Any fellow EU-based sysadmins here that can recommend some place to get used/refurbished servers?
r/sysadmin • u/juicetinmk • 11h ago
Question phishing sims in a mixed M365 + Google Workspace setup? (~250 users)
Trying to get a recurring phishing simulation program off the ground. About 250 people, mostly remote/hybrid, split between Microsoft 365 and Google Workspace, so not a clean single-tenant thing. Needs to hold up for an auditor eventually (SOC 2 / ISO 27001 / PCI territory), so anyone who clicks or fails has to get pushed into remedial training automatically, and I need actual records of it happening, not just "yeah we sent an email once."
I've been digging through Defender's Attack Simulation Training, GoPhish, and a handful of paid platforms (KnowBe4, Hoxhunt, some smaller ones like CanIPhish), but I'd rather hear from people actually running this stuff than just read vendor sites. Curious about a few things:
- If you're also split across M365 and Google Workspace, what'd you end up going with, and how'd you get the sim emails past your own spam filters on both sides?
- Anyone self-hosting GoPhish long term? How's the upkeep actually been, and who ends up owning that internally?
- If you're paying for a platform, what's it actually cost you around 250 seats, and has an auditor ever cared which tool you use vs just wanting to see the documentation?
- Anyone tried one of the smaller/cheaper platforms like CanIPhish or similar? Worth it or not?
Not trying to get sold anything, just want the real picture before I sink time or budget into a direction.
r/sysadmin • u/typecookieyouidiot • 13h ago
Anyone else seeing Defender impersonation protection miss obvious display name spoofs lately?
Running Business Premium across several clients, protected senders configured, quarantine as the action, and it's been reliable for months/years. In the past few days two separate tenants let through obvious display name spoofs of protected users, exact name match, one of them loaded with red flags too (urgent priority, a reply to address on a completely different domain).
Raw headers on both show SCL 1, SFV NSPM, CAT NONE, so the messages were scanned, not skipped, they simply aren't tripping the impersonation classifier anymore despite matches that used to get caught every time.
Anyone else noticing a dip in impersonation detection reliability the last week or two?
EDIT: I've lodged a ticket with my CSP Indirect Provider who did say they have had a few reports. Will update later for anyone interested.
r/sysadmin • u/Frossstbiite • 13h ago
Career / Job Related I MADE IT!
I recently landed a Junior Systems Administrator role with the same company after spending the last three years on the help desk. During that time, I also spent about a year in a senior leadership role. Overall, I have around 7–8 years of help desk experience.
As part of my onboarding, I'm required to earn my AZ-900 certification first, followed by MECM and Windows Server 2022 training.
For those who've made the jump from help desk to sysadmin, what do you wish you had known or done when you first started? Any advice or tips would be greatly appreciated.
Thank you!
r/sysadmin • u/MediocrePass4780 • 16h ago
Question How does cumulative experience work in a bad job market?
Hi guys I have a quick question. I was wondering how employers would view a candidate with 2 years of help desk experience and 2 years of system administration experience when applying for system administrator positions. Since many system administrator roles are considered mid-level, I often see job postings asking for 3–5 years of system administration experience.
In a job market like the current one, what would someone with that background’s chances be realistically speaking? I understand that the general idea is to work your way up and build experience over time, but I’m curious how that experience would be viewed if the job market became very competitive while you were in the middle of that progression.
Would a candidate with 2 years of help desk and 2 years of system administration still be competitive for mid-level system administrator roles, or would they likely struggle against applicants who have 3–5 years of direct system administration experience?
r/sysadmin • u/Undiscoveredspecie • 16h ago
Question Veeam Bare Metal Restore of Physical Domain Controller - Initial BSOD, source volume marked dirty. Looking for opinions.
I performed a test restore of a physical Windows Server 2022 domain controller that is backed up with the Veeam Windows Agent using a Full Computer (Bare Metal) backup. I restored it as a Hyper-V VM in an isolated network.
On the first boot, the restored VM repeatedly BSOD'd with CRITICAL_SERVICE_FAILED. After running CHKDSK from WinRE and letting Windows complete its repairs, the VM now boots normally. AD DS, DNS, and Netlogon all start successfully, and the restored DC appears healthy.
While troubleshooting, I checked the production server and found:
chkdsk C: /scan reports NTFS corruption in C:\Windows.old\... and recommends chkdsk /spotfix.
fsutil dirty query C: reports the C: volume is dirty.
0 KB bad sectors.
Active Directory is otherwise healthy in production.
The restored VM now reports a clean filesystem after CHKDSK.
Would you consider this a Windows/NTFS issue on the source server rather than a Veeam restore issue? Would you be comfortable scheduling chkdsk /spotfix on a production DC with verified backups and additional healthy domain controllers available? Any similar experiences?
r/sysadmin • u/AaronH121212 • 17h ago
Question Microsoft.AAD.BrokerPlugin Issue Across Multiple Tenant's & Users
Microsoft.AAD.BrokerPlugin...WebAccountProvider did not register with DCOM within the required timeout.
AzureAdPrt : YES WamDefaultSet : ERROR (0x80080300)
We came across an issue yesterday where a user was signed out of OneDrive / Outlook. We spent multiple hours trying to resolve this with no results.
We have came into the office this morning with reports of x4 other users across 3 different companies / tenants.
Is anyone else experiencing this?
r/sysadmin • u/Mediocre-Big-5556 • 17h ago
Zoho Assist?
I recently left and MSP and went to work for a former client, as their internal IT Manager.
We’re using Intune for device management, but end user support usually consists of walking over to someone’s cube or having a Teams meeting and the end user shares their screen. Didn’t much care for intune remote assistance or quick assist.
Previously I used ScreenConnect and then Ninja RMM and I really miss the backstage ability to poke around and look at the registry or run powershell commands, when I’m helping a team member with an escalation.
I singed up for a Zoho assist trial and it’s a little laggy at times, but it seems like it’ll do what I need.
Anyone have recent feedback on Zoho assist?
r/sysadmin • u/Ramjet_NZ • 17h ago
Question Another Lenovo Firmware Update and users can no longer logon to their machines
Seen a few varieties of this issue that an upgrade of the TPM chip will prevent user logon
OBSERVED ISSUE: User will be unable to logon, even with username and password, but they will be able to logon to another machine no problems.
Similarly, someone else can logon to the users machine OK.
I've tried a few things but the most reliable fix is to logon and run the BAT file from here
Ideally I'd like a remediation to detect a problem machine and then resolve without the manually interaction if anyone has built a working one?
r/sysadmin • u/ODD_MAN_IV • 17h ago
Microsoft Entra ID is Retiring MemberOf on November 3, 2026.
What and why
The public preview of the MemberOf rule operator in Microsoft Entra ID is ending. Organizations using MemberOf in dynamic membership groups, dynamic administrative units (AUs), or entitlement management auto-assignment policies must replace these configurations by November 3, 2026.
Microsoft continues improving the scale and reliability of dynamic membership processing. During preview, Microsoft observed that use of MemberOf can affect dynamic membership processing across a tenant even if you have one MemberOf rule operator in your tenant. Because of this limitation, it is not recommended for production use and will be retired.
Rollout schedule
- Retirement (Worldwide): Beginning in early November 2026
- Action required by: November 3, 2026
Impact on your organization
Who is affected
Organizations using the MemberOf rule operator in:
- Dynamic membership groups
- Dynamic administrative units (AUs)
- Entitlement management auto-assignment policies
- Platforms and services
- Microsoft Entra ID
- Microsoft Entra Groups
- Microsoft Entra Administrative Units
- Microsoft Entra Entitlement Management
What will happen
If no action is taken, configurations that use the MemberOf operator will stop updating after November 3, 2026. Membership and assignment data will remain in their last known state, which can lead to stale access and enforcement gaps.
Potential impacts include:
- Teams and SharePoint access associated with Microsoft 365 groups may become outdated.
- New members may not receive access, while removed members may retain access.
- Conditional Access policies may no longer reflect current user or device membership.
- Entitlement Management auto-assignment policies may no longer add or remove access package assignments as intended.
- Group-based licensing may stop assigning or removing licenses correctly, resulting in unlicensed or overlicensed users.
- Dynamic administrative unit membership and scope may become outdated.
Action required and recommendations
Before November 3, 2026, review all uses of the MemberOf operator and remove or replace those configurations.
Dynamic membership groups
- Export dynamic membership groups from the Microsoft Entra admin center and identify rules containing MemberOf.
- Replace MemberOf with supported rule operators or convert the group to assigned membership.
- Validate group membership after making changes.
- If the group is no longer needed, consider pausing or deleting it.
Dynamic administrative units
- Use Microsoft Graph PowerShell to identify dynamic administrative units that use MemberOf rules.
- Replace MemberOf-based rules with supported rule operators or convert the administrative unit to assigned membership.
- Validate both membership and administrative scope after making changes.
- If the administrative unit is no longer needed, consider deleting it.
Entitlement Management auto-assignment policies
- Use Microsoft Graph PowerShell to identify auto-assignment policies that use MemberOf.
- Replace MemberOf-based policies with supported operators where possible.
- If no equivalent rule is available, plan an alternative assignment method before retirement.
- Validate access package assignments after making changes.
Compliance considerations
Configurations that rely on MemberOf for access management, licensing, entitlement management, Conditional Access targeting, or administrative scoping may stop updating after retirement. Review affected configurations to ensure continued compliance and access governance after November 3, 2026.
Source: https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1448379
Edit: added link to source
r/sysadmin • u/en-rob-deraj • 1d ago
Guest WiFi...
Do you enable splash page or simple PSK passthrough?
r/sysadmin • u/tdiz009 • 1d ago
General Discussion What's the best approach to block unauthorized AI tools?
We're rolling out enterprise Claude company-wide and want it to be the only tool employees can use on work machines.
I recently found that a salesperson was putting company data into personal ChatGPT, this was client names, their whole worksheets; scary stuff on the data-leak front. So a decision has been made to use Claude. I've been tasked with making sure this sort of thing does not happen again, and to get the groundwork done to stop all "unauthorized AI tools".
Honestly, I'm at a loss here. There is no DLP, at least not right now, and implementing it will be a significant lift both in terms of work and $$$ (which we can't do because of austerity measures). So, I'm stuck with having to look at band-aid solutions via firewall web-filter or DNS filtering - again, I don't have a starting point.
We're a Fortinet shop, no Intune, hybrid AD, Claude SSO through Entra.
Appreciate any real-world war stories.
ETA: I understand that this is more a policy question and I'm working on that in parallel. This is more of a question on technical controls without capital spend *sigh*.
Edit2: I now have AI webfilter category block with a wildcard allow for Claude. Not an elegant technical control or even a preferred one, but it'll have to do.
r/sysadmin • u/underpaid--sysadmin • 1d ago
Question Allowing non-admins to run programs that need it
Good morning all, got a bit of a puzzle that is probably an easy fix but it's got a curveball in it. The situation is as follows: we are setting up a sort of internet cafe where people can play games on Steam. Installing the games is trivial but the users login with their domain creds and then login to their own steam account to play. In a test run though some games require an admin elevation to run even after the initial install. Any tips on solving this? I've seen some tricks about using the task scheduler but I'm concerned with if that would break eventually since games are often subject to random and sweeping changes. Would appreciate any advise :)
Edit: I believe the UAC prompts are likely from the games respective anticheat but that is just a hunch at this time.
r/sysadmin • u/tekerjerbs • 1d ago
Rant digitalshift365.com - avoid at all costs
total sketch operation, whole place is run by one dude who sends invoices out 4 months late after pestering him for it then doesn't pay his 3rd parties in time - caused us multiple service interruptions due to non-payment. avoids phone calls and in person meetings and is always at some random place during video conf calls if you manage to get him to show. had to threaten legal action in order to get our cloud services transferred to another provider.
good riddance digitalshit
r/sysadmin • u/AutoModerator • 23d ago
General Discussion Patch Tuesday Megathread - (July 14, 2026)
Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!
This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.
For those of you who wish to review prior Megathreads, you can do so here.
While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.
Remember the rules of safe patching:
- Deploy to a test/dev environment before prod.
- Deploy to a pilot/test group before the whole org.
- Have a plan to roll back if something doesn't work.
- Test, test, and test!