r_systemadmin | Unsorted

Telegram-канал r_systemadmin - Reddit Sysadmin

-

Reddit SystemAdmin. Thanks @reddit2telegram and @r_channels.

Subscribe to a channel

Reddit Sysadmin

opinions on vaultwarden or psono for self hosting

I am planning to self host a password manager and deciding between Vaultwarden and Psono. Vaultwarden looks easier to set up, but Psono also seems popular and more feature rich. I would likely expose it to the internet so family members can access it, probably through a Cloudflare tunnel.



before I move forward, I wanted to ask if anyone here is running something similar. are there any risks I should be aware of when exposing a password manager like this.

https://redd.it/1qdfme0
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Help desk time spent on account recovery keeps rising as we move to passwordless authentication

We reviewed our help desk metrics last month and found that roughly forty percent of total time is being spent on account recovery requests. This was already a noticeable workload, but it has increased as we transition more users to passwordless authentication.

The pattern is consistent. Users lose a phone, replace a device, or forget to set up their passkey on a new device before wiping the old one. Without a password, there is no self service recovery path. They call the help desk, we perform manual identity checks over the phone, and then reset access. It is slow, resource intensive, and difficult to scale with our current staffing.

Previously, many of these users could resolve the issue themselves through standard self service password reset. Now those same scenarios require human intervention, and projections show this workload increasing as passwordless adoption grows.

At this pace, account recovery is quietly becoming our primary help desk function, even though it was never designed to be.

https://redd.it/1qdgu6z
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Thickheaded Thursday - January 15, 2026

Howdy, /r/sysadmin!

It's that time of the week, Thickheaded Thursday! This is a safe (mostly) judgement-free environment for all of your questions and stories, no matter how silly you think they are. Anybody can answer questions! My name is AutoModerator and I've taken over responsibility for posting these weekly threads so you don't have to worry about anything except your comments!

https://redd.it/1qdfmad
@r_systemadmin

Читать полностью…

Reddit Sysadmin

My Confusion with Microsoft's Secure Boot Changes

*If you're seeking guidance or clarity, skip this post.*

I admit I'm a bit behind on taking all the info here but I got to say, I've been trying to read up on this the last couple days and I'm more confused than ever. I'm thinking of taking a "let Microsoft take the wheel" on this because their documentation and guidance leaves a LOT unsaid, which I try to explain by way of questions below.

* Whereas a UEFI compliant device can have multiple certificates at once, why is Microsoft being so damn cautious about this rollout? (Microsoft's answer to this boils down to "all firmware is different, our early testing showed problems on some devices")

* Whereas UEFI is a standard where the whole point and promise was that vendors were doing things the same to avoid these very problems, has UEFI failed in some fundamentally important way that we aren't talking about in industry? Should we be?

* Whereas Microsoft is saying they update the certificates on devices meeting "high confidence" thresholds, how are devices being considered high confidence in the first place?

* Is Microsoft randomly updating a small number of devices within each "bucket" to gain confidence? Is there an opt-out of *that* (I haven't seen it if so)?

* Is confidendence building dependent on people opting into either the `0x5944` value or the CFR (`MicrosoftUpdateManagedOptIn`) updates? What's the "vacccine critical mass" analogy here?

* Whereas Microsoft allows customers to opt in CFR (`MicrosoftUpdateManagedOptIn`), what's the *actual* difference between CFR and high confidence? What's the logical difference? What other grades of "confidence" influence whether a device exposed to CFR is updated?

* Whereas Microsoft describes the use of the `0x5944` value to trigger the updates and whereas Microsoft describes the associated `AvailableUpdates` value as dynamic in nature, does Microsoft's scheduled task operate in an idempotent manner (in case automations reset the value back to 0x5944 on a regular basis)?

* Whereas Hyper-V's Gen2 VM firmware doesn't yet have the 2023 certificates and whereas Hyper-V doesn't yet support KEK updates, how can we take Microsoft at all seriously with their rollout?

* Whereas Microsoft notes that the expiration of the 2011 certificates doesn't cause systems to fail to boot and whereas the real impact is Microsoft's inability to timestamp new boot managers after the expiration, what is Microsoft's (ideal) target date (monthly LCU) for all devices buckets to reach a high confidence (or at the very least a *firm* confidence level)?

* (Anecdotal) Whereas I've observed two newer systems (in support and with firmware up-to-date) both show the `WindowsUEFICA2023Capable` value set to `2` (which indicates the bootloader is booting with the 2023 certificate) but still logging error 1801 (indicating a failure to update the certificates), what am I to believe?

Really what I'm struggling to reconcile is these main points. They seem at least slightly contradictory:

* UEFI and secure boot being a set of specifications *should* make this all low-risk (especially given certificate plurality).

* Microsoft wants devices to enter a "high confidence" bucket before automating rollout of the new certificates.

* It's not clear how devices are entering high confidence without IT-admin intervention (Do we need to "volunteer" into this? If so, game theory suggests that's a flawed strategy).

I'm starting to wonder if the UEFI industry needs to rethink such long-lived certificates and knock these down to just a few years so that we force the OEMs to properly implement their KEK update processes.

https://redd.it/1qd3cfg
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Tracking pixels in mandatory email signatures. Is this acceptable?

Background:

For the first time, I'm not in the IT department. I now work with a team of developers. I manage infrastructure for the product, but my computer and email are managed by the company IT department. Being on this side of an IT policy is new to me.

What I discovered:

While getting set up to exchange emails with bug bounty researchers, I have been setting up privacy-focused settings, including PGP encryption, and a stripped down email signature. While testing, I discovered that our IT department is now appending a tracking pixel to all outbound messages, with a unique ID per sender (not per message). So, someone in our IT department or management is ostensibly able to track open rates, recipient locations, and probably a bit about recipient systems. The service is provided by Wisestamp.

Is this normal?

I know I value privacy more than most, so I need perspective. I'm sure our policies allow for this kind of thing, but it certainly isn't explicitly disclosed. And I'm not sure what I would say if a recipient asked me why it was present.

Is this kind of thing common and acceptable in the business world?

---

Edit: Enough of the distractions and accusations. This was not written with LLM. I just write so as to be understood.

https://redd.it/1qcypgv
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Downdetector is showing an uptick in outages with communications.

Anyone know what's going on? It seems to be everyone, Verizon, T-Mobile, AT&T, Fios, XFinity, US Cellular.. the list goes on.

Edit: Looks like their charts are relevant only that service. Verizon is showing over 100,000 outages while almost everyone else is below 500 so it seem to be a Verizon issue - and it looks like they're looking into it.

https://redd.it/1qcurj3
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Verizon Down Nationally?

We are getting blown up stating all verizon phones are going SOS. Looks like they are having problems.

Its down here in DFW TX

https://redd.it/1qctkqn
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Cloud vs On Prem: An Observation

This isn't intended to be a debate. :)

I was just thinking about this. Work is in a tizzy about the AWS bill for a bunch of data being backed up to an S3 bucket. Like thousands of dollars per month. OMG!!!

But it took months of back and forth to get approval to renew a $300 software license.

With Cloud, it's Pay or Die! But Onprem is, "it's not in the budget; see you next quarter".

https://redd.it/1qcr5un
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Do you guys have a system in place to remind you rotate security keys etc.

Is there a standard tool that pings you on Slack/Email when an API key is about to expire? Or do you just set Google Calendar invites and hope for the best?

I feel like there has to be a better way than a spreadsheet, but maybe I'm overthinking it.

https://redd.it/1qckra9
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Fired employee downloaded all company files before deactivation we need secure way to prevent this

Hey guys! Not an IT expert here. We are a startup and recently found out from reviewing the logs that a fired employee was able to download all of our company files from SharePoint before we got around to deactivating their account. We store a lot of important shared files that our team needs to constantly edit like lists of leads and company data but we don't want people to be able to download that information because it is sensitive and important. We still don't have a CRM or ATS in place so we are relying on SharePoint for now.

We know normal SharePoint permissions let people edit and download freely and the built in “block download” option only works when editing is off so that isn’t a practical solution for us given how many files the team needs to edit regularly.

Has anyone else in a small company faced this problem and found a reliable way to let people edit but not download or sync files?
What tools or settings have you used to make sure someone who still has access temporarily cannot exfiltrate data?
Have you setup Conditional Access or session controls to limit downloads or forced browser only access without download options?
Also curious about offboarding workflows so access is truly cut as soon as termination is triggered.

Appreciate any advice on how to secure this and protect sensitive company info.

https://redd.it/1qckxpm
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Help something like airtags for non-networked equipment need to replace a "solution" before it becomes my problem

Here's a more Reddit-friendly version:

Asset tracking for non-networked equipment need to replace a "solution" before it becomes my problem
Inherited a situation.
We have several high-value devices (~$30k each) that are currently being tracked via AirTags tied to one employee's personal Apple ID.
I've now been asked to "set up a shared account" so multiple people can track them.
No.
Before I become the official owner of this shadow IT nightmare, I need to propose something real.

The equipment:

Briefcase-sized, stored in cases
Zero network connectivity (just dumb expensive hardware)
Moves between warehouses, client sites, offices

What I need:

Multi-user access without shared credentials
Location on demand (no geofencing or history needed)
Works indoors and outdoors
Actual Enterprise support

Bonus points:

Centralized dashboard
Audit trail
Not tied to anyone's personal anything


Already considered:

Tile Pro: same shared account problem
GPS asset trackers: Overkill + terrible battery life

https://redd.it/1qcgo2e
@r_systemadmin

Читать полностью…

Reddit Sysadmin

IT Support Analyst asked to manually sort user emails

I've recently started work as an IT Support Analyst at a small company (only around 30 employees that actually use a computer). Most of my work so far has been establishing company policies around Security and putting systems in place to manage company devices, as well as helpdesk-type work. However, last night I got an email saying my boss has assigned me to a task. The task description is "Categorise [Employee Name\]'s emails into folders". My boss is fairly technical. IT Support is a new role created within the company. I have a hunch the task might've been passed down by his boss, who is also new at the company. Am I right to be annoyed that I'm being asked to cover this task, and how should I approach the conversation with my boss?


Edit: Removed details that could be used to identify the company.

https://redd.it/1qc40u9
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Vendor risk reviews are fine until they start changing things mid contract

We're set for vendor security reviews before onboarding. The annoying part is when the contract is signed and vendors change subprocessors, shift hosting, update their security posture and half the time we only learn about it from an email.

Customers expect us to have this under control but it feels like we’re relying on vendors to self report changes.
What's the best practice to keep vendor risk updated??

https://redd.it/1qbz8ps
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Where is the January Patch Tuesday Megathread?

I'm here, it's patch Tuesday, where's the party?

https://redd.it/1qbxzid
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Stonewalled by Citrix's new AI "Customer Service" model

This morning my entire Citrix infrastructure just... stopped working. Why? Because Citrix says my license expired.

Funny, I renewed it last August. It doesn't expire until next August. I see the license sitting right there in my portal.

Try to contact Citrix. Phone support has ended. Okay, lots of people are doing that, I hate it but I'll try to work with it. Chatbot asks for my info, finds the account, and promptly tells me it can't help me because I don't have an active license.

W... T... F? I need to talk to you because my ACTIVE LICENSE which I PAID FOR is being mishandled, but I can't talk to you because of the problem that I need to talk to you to solve?

Chatbot tells me to talk to my Account Representative. I haven't had one of those in years, been handling my renewals through their renewal portal. I've had to reach out to my CDW partner to see if they can connect me to their internal Citrix rep to get me anywhere near some sort of answers here.

So now I'm sitting here with my remote infrastructure completely down and I'm waiting on a phone call from CDW to fix it. I'm sure this whole problem could be solved in 5 minutes if I could just TALK TO A REAL PERSON!

https://redd.it/1qbtz9q
@r_systemadmin

Читать полностью…

Reddit Sysadmin

I just threw up in my mouth...

Crucial - 128GB of DDR5

£1414.79

One thousand four hundred pounds.

This is beyond f**ked, you guys.

https://redd.it/1qdiyfi
@r_systemadmin

Читать полностью…

Reddit Sysadmin

External users at different site buy laptops and don't tell IT so work locally on their Microsoft Accounts. Anyway to stop them?

Basically, we have a site in Dubai, but the main IT team is in the UK. These users have been told countless times about getting laptops and not telling us, however they continue to do it and ignore us. They keep buying laptops (probably dodgy too) then work locally and sign into their Microsoft Accounts. Is there a way I can stop it, like restrict their account login to certain devices or something like that? It feels very Micro manage, but they're also completely ignoring policies and management there just give the same response of, "okay we'll sort" but it continues happening.

https://redd.it/1qdgjxb
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Meraki Alternatives for 200 Low Site-Count Retail locations

6 months into a new role managing Meraki gear across 200 locations averaging 5 Entra ID-joined PCs or Azure Virtual Desktop thin clients per site with site-to-site VPN back to HQ for file shares. Transitioning away from file shares eliminates VPN needs except possibly corporate HQ to Azure connectivity.

Goal is shrinking Meraki footprint and Cisco licensing costs while retaining centralized management visibility on small business ISP gateways from AT&T or Charter handling basic DHCP and NAT. Zero visibility feels risky despite minimal on-site networking demands. Ubiquiti works at home but scaling concerns persist for retail reliability without VPN overhead.

Seeking lightweight single-pane platforms cheaper than Meraki reliable across dispersed sites with simple ISP internet. Prioritizing cloud-managed SD-WAN or dashboard simplicity over deep feature sets.

Open to hardware appliance or virtual options fitting sub-10 device footprints. Specifics on current MX67/68 counts & bandwidth available if helpful.

https://redd.it/1qdbpu8
@r_systemadmin

Читать полностью…

Reddit Sysadmin

What percentage of your job is actually IT vs. managing expectations and politics?

I've been in IT/infrastructure for 15+ years and I swear the ratio has shifted dramatically. Early in my career it felt like 80% technical work, 20% people stuff. Now it feels reversed.

Is this just what happens as you move up, or is this a broader industry shift? And for those who've managed to keep it mostly technical - how?

https://redd.it/1qd11qn
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Verizon Outage Cause

I may be completely wrong about this, but given the current outage of Verizon service, I figure it might bring a possible explanation to some folks. I was asking around my friends and family that also have Verizon, and the common denominator with the ones who lost service is the SIM card. Anyone who has a physical SIM card in their phone told me they haven't had any problems. Myself and a few other people have only the eSIM, and we don't have any service. Just my findings, please feel free to give your input and correct any of my mis-statements.

Edit: After seeing some responses, I do want to note that the only ones I've been told to have problems are Androids so far. Not sure if that may have anything to do with it

https://redd.it/1qcy8k4
@r_systemadmin

Читать полностью…

Reddit Sysadmin

What's the best office chair for lower back pain you've ever purchased?

Lower back pain is killing me, and i've realized that my cheap gaming chair is the main problem. I sit at my desk long hours a day so i'm looking to invest in something really good for my back, ideally an ergonomic chair that's built to last too. My budget is under $700.

Does anyone have any recs for that budget?

https://redd.it/1qcs5r2
@r_systemadmin

Читать полностью…

Reddit Sysadmin

After a downsizing scare, how do you all prepare “just in case”?

Last week I had a bit of a scare. I got that email from the CEO about budgets and downsizing. Thankfully, I wasn’t one of the people let go this time.

I’ve been through layoffs before, so I know how lucky I am—both to have a job right now and to have found one at all in this market. At the same time, I also know that luck doesn’t last forever, so I’m trying to stay realistic and prepared instead of assuming I’ll be fine.

I’ve started doing some research on my own, and this post is part of that. I’m curious how people here stay “ready” in case they suddenly have to look for a new job.

A few things I’m wondering about:

Do you keep in touch with recruiters even when you’re not actively looking?
Have professional groups, communities, or networks actually helped you when it mattered?
Are there any sites or platforms you’ve found useful beyond LinkedIn?
Last time I job hunted, I relied heavily on LinkedIn.
I’ve seen Glassdoor has something called Fishbowl now—has anyone used it?
Any newer or lesser-known networking sites worth checking out?

Basically, what do you do to stay market-ready without constantly job hunting or stressing yourself out?

Would appreciate hearing what’s worked (or hasn’t) for people who’ve been through this.

https://redd.it/1qcqrc2
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Abnormal and M365 E5

Hi All

500 user company in the finance sector, we are reviewing our email security due to the increasing number of threats getting through Mimecast (and Microsoft) including vendor email compromise emails.

We are considering binning Mimecast in favour of an AI solution (Abnormal is the frontrunner) with Microsoft E5 MDO as the SEG.

It would be great to hear from others who have been on this journey and whether Abnormal and Microsoft have provided solid protection vs Mimecast.

Thanks!

https://redd.it/1qcoend
@r_systemadmin

Читать полностью…

Reddit Sysadmin

DMARC monitoring is driving me insane - need recommendations for a solution that doesn't suck

Alright im not exactly ashamed to say that manually parsing DMARC reports for our 50% domains hasn't been a piece of cake lately. Our current setup is legit a nightmare, we spend so much time making sense of raw XML reports, couple that with SPF issues and a management that doesn't understand why we need proper DMARC monitoring.

What's an alternative to this other than writing my own script? (For reference, I've checked out EasyDMARC, Bouncer, and Valimail - didn't really work out.)

https://redd.it/1qclrm2
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Some windows PCs fail DHCP on boot, but work after manu renew

Hello everyone, so im a schools computer engineer and new one at that, after i joined a month later this started happening, teacher would come to me saying theres no internet, unplugging and plugging ethernet cable back in would work but later no more so i did ipconfig /release and /renew and that would seem to fix the issue only for the teacher next morning to come either same issue, anyways it started happening to more and more but its always the same teachers from same like 8-10 pcs. The DHCP pool is not exhausted it uses about 430~ addresses and the subnet is 192.168.4.0/22, lease time is 1h and the switches that pcs connect to are unmanaged. Also for some teachers the problem went away but for new ones it started. Im completely lost on how to fix this

https://redd.it/1qck4w1
@r_systemadmin

Читать полностью…

Reddit Sysadmin

What is your standard monitor deployment?

What do you deploy for your standard users for monitors? We have been deploying dual 24 inch to all users for nearly 15 years. I'd love to hear what your standard is for a better idea what the norm is in the enterprise.

https://redd.it/1qc9uww
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Do you regret your choice becoming a sysadmin

In early 2000s I was seeing IT is the future, it's the new era industry, but now, with AI, automation and remote support, I think our jobs became obsolete, today I was looking at my office, 0 on perm servers, a Meraki that's controlled by HQ, and 95% of work is responding to user tickets, how much longer we will stay in business, that's what I was thinking about

https://redd.it/1qbz8y3
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Patch Tuesday Megathread (2026-01-13)

Apologies, y'all - We didn't get the 2026 Patch Tuesday threads scheduled. Here's this month's thread temporarily while we get squared away for the year.

Hello r/sysadmin, I'm ~~u/ automoderator~~ err. u/mkosmo, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC. Except today, because... 2026.

Remember the rules of safe patching:

Deploy to a test/dev environment before prod.
Deploy to a pilot/test group before the whole org.
Have a plan to roll back if something doesn't work.
Test, test, and test!

https://redd.it/1qbzwiu
@r_systemadmin

Читать полностью…

Reddit Sysadmin

What are small and mid-size IT teams actually doing for cybersecurity right now?

Hi everyone,

I’m trying to get a clearer picture of how small and mid-size IT teams (not Fortune 500s with SOCs) are really handling security in 2025.

Most of the environments I see look like some mix of:

• Defender or basic endpoint tools

• A firewall

• An MSP or outsourced helpdesk

• And a lot of “best effort” processes

But I’m curious how that looks from people actually running it.

A few things I’d love to hear about:

• How do you handle vulnerability management today?

• Do you do security awareness training in-house or outsource it?

• If something suspicious happens, who actually investigates and responds?

• Are compliance and cyber-insurance driving your security stack more than actual risk?

What feels like the biggest gap right now? Tools, time, budget, expertise, or something else?

just trying to understand what the real-world security stack looks like outside of big enterprises.

https://redd.it/1qbup84
@r_systemadmin

Читать полностью…

Reddit Sysadmin

Terminated Employees and OneDrive

Our IT manager recently had a called with our CSP and they were looking over SharePoint usage and found we have a tone of space used for terminated employees in OneDrive. I thought that this data was wiped when the 365 license was pulled.

Our typical termination process involves disabling their account in the on-premise DC, converting their mailbox to shared, removing their 365 license, disabling them anywhere that isn't using SSO, and removing them from our Veeam for O365 backup. We don't delete the user in case they return in the future, or someone needs in their account for some locked file (which has happened maybe once).

Is there something else others are doing so they're not paying for OneDrive usage on terminated employees? And if so, are there steps outlined somewhere I can follow to review and delete this data?

https://redd.it/1qbrouj
@r_systemadmin

Читать полностью…
Subscribe to a channel