-
Reddit SystemAdmin. Thanks @reddit2telegram and @r_channels.
First for me - outlook used as a literal file server
Been working with outlook for 30 years now. Had a user call because they couldn't see the to and from fields in some emails. turned out these weren't emails - they were literal files that the user had dragged and dropped into outlook. (the actual problem was they had switched between compact and single view - but that's not the point of my post).
user has hundreds of files stored in outlook.
I've seen users with lots of emails with attachments but i've never seen a user literally drag emails into outlook for storage.
They're close to retirement - it's not a battle i have any desire to fight. surprisingly they're not even in the top 20 of mailbox sizes so it's not a big deal.
i guess i should be surprised i haven't encountered this already.
https://redd.it/1vef1q4
@r_systemadmin
Claude (Anthropic) Office add-ins won't deploy via Integrated Apps — Business Standard tenant, stuck on "Deployment failed"
Hoping someone here has run into this before, because I've been going in circles for a while.
Setup: Microsoft 365 Business Standard tenant. I'm Global Admin (permanent assignment, not PIM — we don't have Entra ID P2/Governance so PIM isn't even in play). Trying to centrally deploy the "Claude for Microsoft 365" AppSource listing (bundles Word/Excel/PowerPoint) and separately "Claude for Outlook" (beta) via Microsoft 365 Admin Center > Settings > Integrated Apps.
What happens: Deployment fails every time with "Deployment failed." Digging into the network trace, the backend response is:FailedWriteToExchange, with ResponseResultDetails.Code = AddInStoreUnavailable
On a separate attempt I got a different, more generic error: "This operation was unsuccessful" pointing vaguely at permission/eligibility requirements, different correlation ID.
What I've already ruled out:
Global Admin role — confirmed, permanent assignment, not PIM-eligible
Exchange RBAC "Org Marketplace Apps" role — already active on my account
License eligibility — Business Standard is on Microsoft's own supported list for centralized deployment
Tried both the "Get apps" flow and the "Deploy Add-in" flow in Integrated Apps — identical failure
Tried assigning to "Entire organization" vs. "Just yourself" — identical failure both times, so it's not a bad user/group in a bulk assignment
No admin consent / permissions popup ever even appears before the failure, so it's not stuck in a consent handshake
Anthropic also provides a manifest XML file per app (Word/Excel/PowerPoint/Outlook) as an alternate upload-based deployment method, bypassing the AppSource catalog entirely — I haven't tried that route yet and would rather avoid it for now if there's a proper fix for the standard flow.
At this point it really looks like something backend-side (Microsoft's AppSource/Exchange write path, or possibly something specific to how this app is categorized/registered in AppSource), rather than anything fixable from the tenant admin side. About to open a Microsoft support ticket, but figured I'd ask here first since it's usually faster.
Has anyone successfully deployed the Claude Office add-ins (Word/Excel/PowerPoint/Outlook) on a Business Standard tenant? Or seen AddInStoreUnavailable before with a different app? Any known fix appreciated.
(Note: I used AI to help translate and polish this post — English isn't my first language.)
https://redd.it/1vecc1e
@r_systemadmin
password-protected files like ZIP, RAR, PDF, and Office documents.
2. Microsoft Entra ID now *blocks cross-domain sign-ins* by default whenever internal federation and UPN domains don't match.
3. Microsoft Forms is transitioning automated notification emails to *no-reply@forms.mail.microsoft**,* so admins should update email filtering rules and safe sender lists to prevent delivery issues.
4. SharePoint Embedded will update driveItem.webUrl to return browser launch URLs starting mid-August 2026; switch to driveItemId for stable file tracking or opt out by Aug 17.
**Action Required:**
1. Starting Aug 2026, Microsoft will deprecate *Teams Android device management* in the Teams admin center as features move fully to the Pro Management portal.
2. From Aug 1, Exchange Online deprecates *TLS 1.0/1.1 for POP3 and IMAP4*, so admins should upgrade connections to TLS 1.2 or higher.
3. With *standalone MDTI retiring* on Aug 1, organizations must migrate to Microsoft Defender or Sentinel licenses to retain threat intelligence capabilities.
4. Admins must migrate Personal Bookings management to *OWA Mailbox Policy settings* before Aug 5, 2026, when legacy EWS controls are retired.
5. On Aug 20, 2026, Microsoft 365 will *permanently delete unresolved agent requests created before June 1, 2026*, unless admins approve or reject them beforehand.
**Live:**
1. Microsoft Entra Cloud Sync now supports *device sync* to align Active Directory computer objects for Entra hybrid joins in preview.
https://redd.it/1vea2os
@r_systemadmin
What do you wish existed when you started on a help desk?
I’ve spent 10 years doing help desk/support work and I’m putting together a set of SOP templates, canned responses, and troubleshooting decision trees based on what actually comes up day to day — mostly for smaller teams or solo techs who don’t have this stuff written down anywhere.
Before I finish it, I wanted to ask people who’ve actually been in the seat: what’s the thing that used to slow you down the most when you started? Or something you still wish was documented better where you work now?
Not trying to sell anything here yet — genuinely want to make sure this is useful before I put more time into it.
https://redd.it/1ve2kg8
@r_systemadmin
Is a volunteer SysAdmin role worth taking to transition out of Tier 1 Support?
Hello everyone,
I'm looking for advice and guidance from those with more experience in the field.
My Background:
Experience: 3+ years in a Tier 1 Helpdesk/Support role. My scope is somewhat limited, primarily revolving around User Management, Identity and Access Management (IAM), Incident Management, and Splunk observability for banking payments.
Education: Bachelor's degree in Accounting.
Certifications: Basic Splunk certification.
The Opportunity: I was recently offered a chance to volunteer as a SysAdmin for a non-profit, covering the following responsibilities:
Manage and secure the organization’s Google Workspace environment (user accounts, permissions, and onboarding/offboarding processes).
Provide technical support and troubleshooting for volunteers.
Maintain clear technical documentation, onboarding guides, and self-service resources.
Monitor system performance, security compliance, and cloud settings.
Collaborate with leadership to evaluate tech needs, recommend software, and configure tools as the org scales.
My Questions:
1. Is this volunteer role worthwhile?
2. Would combining my 3+ years of Tier 1 experience with a year of this SysAdmin volunteer work help me land a full-time SysAdmin role?
3. Are there any specific certifications you would recommend I target next to round out my resume?
Thanks in advance for your insights!
https://redd.it/1ve11ao
@r_systemadmin
UPDATE: Linux guy having been asked to do entraid/echange online hybrid, more questions for the experts
Hello fellow sysadmins,
I posted this some time ago:
https://www.reddit.com/r/sysadmin/comments/1uoc55f/linux\_guy\_being\_asked\_to\_do\_windows\_entraid\_stuff/
and you were all very helpful, thank you.
the entraid and exchange migration stuff went well, a few inboxes with too many folders, the local imap server serving folders with special name that broke the imap migration (fixed with -includefolder and -excludefolder list, obviously I generated all the stuff programmatically using a small DB where I wrote all the infos I needed that I got from the on prem email server, axigen)
autoconfigurations, outlook clients, teams, calendar, signatures, everything seems to be working well.
the MX record have been switched, mail deliverability, inbound and outbound seems good.
now I need to prepare the environment for the support people at the company to handle stuff like quarantine release and such.
any pointers? I see that under security.microsoft.com -> threat policies -> standard protection seems to have a bunch of decent defaults, is this something that people do?
I will spend some time learning this stuff because I have to say exchange online does seem like a well crafted product and I'm curious now of this side of things, my understanding of emails comes from using them, having read the IMAP and SMTP RFCs and having had adiacent issues with it from applications and infra management.
and yes, they will also get someone to at least audit this stuff, I was able to get at least this done from a proper expert on the subject.
https://redd.it/1vdr1jx
@r_systemadmin
How do you handle canceling software seats when someone leaves?
Went through our subscriptions recently and realized we'd been paying for a couple of seats(zoom) belonging to people who left months ago. Nobody had a thought to cancel them, it just kept quitely billing.
For those of you managing this, whats your actual process when someone leaves? A checklist someone remembers to run? something automated?or does it slip through the cracks sometimes too?
Trying to figure out if im just disorganized or if this is normal. How do you handle it?
https://redd.it/1vdp47s
@r_systemadmin
Microsoft is rewriting the Print Management app in WinUI
Well, this was not on my bingo list. They're really redesigning Print Mnaagement app for Windows
https://www.windowslatest.com/2026/08/02/windows-11s-winui-3-modernization-just-reached-one-of-its-oldest-legacy-tools-meet-the-new-print-management/
https://redd.it/1vdpvj4
@r_systemadmin
Microsoft Purview Information Protection and Adobe
Good morning,
I am looking for some assistance to see if anyone else has figured out this issue.
We're a GCC tenant currently getting sensitivity labels and MPIP set up. So far, things have been implemented okay minus a few snags. M365 products are working as intended, but the real stickler is Adobe.
The initial issue was that any encrypted label we tried to apply or even switch to, it would not work.
I found this Reddit post that called for enabling some registry keys. Things like adding bMIPLabelling, bMIPExternalAuthAdmin, bSilentAuth, iMIPCloud = 6, etc. However, that did not seem to allow us to add an encrypted label or even switch to one. Even forgetting the Purview information inside of the Adobe settings did not help.
What I believe started helping was three or four things. Clearing the Purview information inside of Adobe, deleting the generic Adobe credentials, deleting the contents of %LOCALAPPDATA%\\Microsoft\\RMSLocalStorage\\mip, and running icacls "%localappdata%\\...\\LocalLow\\Microsoft\\RMSLocalStorage" /setintegritylevel L.
Seemed like that combination worked and I finally was able to authenticate through on a PDF, it grabbed my info, and allowed me to change to an encrypted label. However, the next document, it did not work. I was able to finagle the same steps above and it let me through on that one.
So at this point, I'm trying to figure out how to prevent this from happening on every PDF instance.
Logs have shown me that it likes to run MipContextImpl as configured for offline-only mode or tell me my cloud type is invalid. In Event viewer I see things like Token broker operation failed with AADST65002 error, or an OAuth response error: invalid_resource, service principal for resource 'urn:p2p_cert' is disabled.
So at this point in time, I'm kind of stumped. I have a ticket to Adobe about this, but kind of unsure where to look next to keep this MPIP stable in each Adobe instance. The few that are good remain good and can be changed from secure to unsecure labels, but anybody have any clues on where I can look next?
Thanks, all!
https://redd.it/1vdl99q
@r_systemadmin
Question about differences between iOS & Android in work environment
Sorry if this sounds like a dumb question, but I'd love to hear from an IT admin's point of view to help understand the differences. My employer now requires all employees to register their personal phones so they can be managed, if they want to use it for checking emails/calendar/chats/etc.
The employees with Android (including myself), had it super easy. It automatically prompted to setup Work Profile in order to continue using the work email app, and it finished setting up in less than 2 minutes. And any work apps now have a little blue briefcase on their icon, and I love how in the command center, you can easily toggle on/off the Work Profile to pause all work-related apps (for example on the weekend or when you go on vacation or just when you want to not deal with work anymore). And the employer can't see the personal apps or data since it's stored separately.
However, I noticed for my colleagues with iPhones, it was a lot more tedious. Those employees had to follow this whole document of steps to manually install some certificate to set up MDM. And then if they were lucky to get it working, there's still no app separation so the employer can still see all their personal apps and data?
I already knew that iOS doesn't have a user-friendly Work Profile like Android, but is that normal to get employees to do it like that? I would have assumed with how popular iPhone is, there would be a more simpler/automatic way for setting up personal iPhones for work. I've always heard on this sub that iOS is easier to manage, but from an employee's point of view, it doesn't seem that way (at least not the way my employer is doing it) and maybe I'm not understanding how iOS does data separation, but it just feels like there's not enough employee protections from employer seeing personal data compared to Android? Would love to learn how that works, because Apple's website is kinda vague.
https://redd.it/1vdcef9
@r_systemadmin
Alternative plan and feasibility study for FOSS Intune?
I have a task to research an alternative plan to Microsoft Intune, and we are particularly interested in open source solutions.
We currently have the free version of Intune, but can you guide me on whether it would be possible to move completely away from Intune and use an open-source alternative, or if it would be better to keep the free version of Intune and combine it with an open-source solution to cover the remaining features?
Ideally, we want the open source solution to at least be able to:
* Create compliance policies
* Configure Windows Update rings
* Deploy security baselines
* Configure BitLocker or an alternative to BitLocker
* Configure Microsoft Defender/AV policies
* Create configuration profiles
* Deploy applications
Has anyone implemented something similar?
Any experience or advice would be appreciated!
https://redd.it/1vdb0ki
@r_systemadmin
Microsoft Outlook Phishing from the administrators side
I recently got pulled into my bosses office for clicking on too many phishing emails. I'm not perfect I know that I can make mistakes but they showed me the emails and they were the most blatant spam emails ever. Then it occured to me that those were emails that I reported as phishing. They didn't know what I was talking about and they said that they tag any emails that were interacted with as security alerts. Literally all that I did was report as phishing. The email that he showed me even says that he got a security alert. Everything that I have found online says that if you report an email as phishing it sends the security team an alert just like the one that he showed me. Can someone tell me what this looks like for the admin side and also confirm that that is what you are supposed to do with phishing emails?
https://redd.it/1vd55i1
@r_systemadmin
M365 licensing options for casual warehouse staff needing one app
We have casual warehouse employees who only need access to a single Microsoft 365 application from shared devices.
The obvious options appear to be:
\- Individual licensed accounts, likely Microsoft 365 F3
\- Entra B2B guest accounts
Assuming neither option is accepted by the business, are there any other compliant and cost-effective licensing models worth investigating?
We want to avoid generic/shared accounts because of security, MFA and auditability. I’m mainly trying to establish whether there’s a legitimate frontline, usage-based or application-specific option I’ve overlooked—or whether the answer is simply that each employee needs their own licensed identity.
https://redd.it/1vd04gr
@r_systemadmin
The dreaded documentation question....sigh
I have supported part time a small non-profit company and while I know how important documentation is there just always was something else pressing that was more important. Well I am getting to the point where in the future I am probably going to be moving on and have started to work on trying at least for me document what they have at a high level. I assume and I know what happens when you do that but they have enough technical stuff that if the person actually knows what they are doing then they should be able based on a overview of the systems function dig into it and figure things out. I am not doing anything esoteric but I also have been doing this kind of stuff for *cough* many years. While small they have a lot of technology, just migrated the virtual environment to proxmox, they have AD environment with ADFS connected to m365, etc...
I just captured the inventory for everything they have and was about to start writing up a word document that gives a high level for each server etc, layout of the network, vlans etc. I then started to think that maybe I should do something like a wiki or use something else. Although at a high level kind of leaning towards not having it online since it would pretty much give you a working layout of their environment and if compromised would be pretty nice to have.
Just thought I would ask what are folks using for documentation, thanks.
https://redd.it/1vcppko
@r_systemadmin
How much do you trust AI?
Recently a coworker granted Claude elevated access via SSH to a virtualization host (not a VM, an actual host). To perform a routine task he very well could have done himself.
He doesn’t see an issue with this. I on the other hand (with 23yrs experience) see this as a huge security breach, and don’t trust AI todo my job, (or even that it’s doing what it says it’s doing) for me. I’m my opinion it’s a tool, not a human replacement.
What’s your reaction, how would you react to this situation, or thoughts on the topic?
Sure, ask AI how to perform a task, validate that it’s performing the task you asked, and nothing else- copy/paste the commands. Great. But removing the human verification & validation element- hell no.
https://redd.it/1vcpu1g
@r_systemadmin
Looking for IT Ticketing + Asset Management System
Hey guys
at work we're trying to set up a system for both ticketing and asset management, and it needs to work for two departments, IT and Facilities. We want to be able to add custom fields, export everything to Excel, and tag assets with QR codes. SSO login is a must too, and the big thing is we need the two departments' assets to be fully separated, neither should be able to see what the other has. Been looking around but not sure what fits best.
Anyone gone through something similar or have a system to recommend? 🙏
https://redd.it/1vecati
@r_systemadmin
How to remove a guest organization if the other side blocked my account?
Stuck in an M365 loop. An external admin set my B2B guest account to **"Block sign-in"** (I no longer work with them). The organization is now a permanent zombie in my M365 profile backend.
# The Problem
* I cannot leave the organization myself
* Login fails instantly because my account is blocked
* Clearing browser data doesn't fix it; the entry just resyncs from the cloud
# My Question
If I contact their IT: **Is it enough if the external admin simply DELETES my guest object from their Entra ID?**
Will that automatically purge the tenant from my M365 profile backend? Or am I still required to manually "leave" on my end even after they delete me (which I cannot do)?
I'm really not a fan of a foreign organization being connected to my tenant like this. Even if Microsoft claims it's secure ... who actually believes that? Nevertheless, that's IMHO a major design flaw.
*(Note: Since I am not a native speaker, I translated/polished this post with the help of an AI.)*
https://redd.it/1ve8vua
@r_systemadmin
Microsoft 365 August 2026 Updates: 30+ Changes Every Admin Should Know
Stay ahead this August with **30+** Microsoft 365 changes, including feature rollouts, retirements, functionality changes, and other key updates for IT admins.
**In the Spotlight:**
* **Cross-Tenant Message Recall in Exchange Online:** Exchange Online allows users to recall emails sent to external tenants that have added their organization to an allowlist.
* **Security Detection Report in TAC:** The new Security Detection Report enables administrators to monitor impersonation attempts, malicious URLs, and weaponizable files to improve threat visibility.
* **Account Discovery in Entra:** The new Account Discovery feature helps organizations detect unmanaged application accounts and link them to Microsoft Entra ID identities for improved governance and security.
Here’s a quick overview of what’s coming:
* **Retirements:** 6
* **New Features:** 8
* **Enhancements:** 4
* **Functionality Changes:** 4
* **Action Required:** 5
* **Live Now:** 1
**Retirements:**
1. Starting Aug 3, 2026, Microsoft will *block new assignments* to the *Partner Tier 1 and Tier 2 Support roles,* which allow Microsoft partners to provide delegated support for customer tenants.
2. Outlook is retiring the legacy *Meeting Insights feature by Aug 2026* and replacing it with Copilot's "Prepare for this meeting" experience.
3. Microsoft is officially retiring the *Outlook for Windows report* in the Exchange admin center this August.
4. Effective Aug 15, 2026, the *OneDrive sync app* will stop receiving security patches, bug fixes, and feature updates on Windows 10 version 21H2 or older.
5. As the standalone *Whiteboard app reaches end of support*, starting Aug 22 users will no longer be able to create or edit Whiteboards.
6. Microsoft is retiring the *Teams CAPTCHA meeting policy* in late Aug 2026, replacing join verification checks with default-on automated bot detection.
**New Features:**
1. OneDrive on Windows and Mac will now let users & admins *exclude specific folders from cloud syncing* to keep sensitive or large data strictly local.
2. Microsoft Purview will introduce an *archive option to move inactive OneDrive and SharePoint files* to M365 Archive to lower storage costs.
3. Teams Rooms Pro on Android will support *attending webinars & structured meetings as attendees*, featuring interactive tools like chat, reactions, and live captions.
4. Global Readers and Security Readers will soon gain *view-only access* to role assignments and scopes across Microsoft Purview and Defender.
5. Organizations can now access *Teams audit records* for their own users in *cross-tenant meetings* without exposing cross-tenant participant data.
6. Microsoft Teams adds support for *linking meetings to existing Planner plans* to manage all project tasks in one place.
7. Microsoft Entra ID is updating *passkey registration across My Sign-Ins, Authentication Strengths, and Registration Campaigns* to automatically enforce admin policies and prioritize local device passkeys.
8. Microsoft Purview now supports *time-limited role group assignments,* so admins can set temporary access expirations between *1 day and 2 years* to enforce least privilege.
**Enhancements:**
1. Microsoft Teams is extending *custom recording and transcription notifications to 1:1 calls*, automatically applying existing meeting policies to one-on-one desktop conversations.
2. Entra now extends Microsoft Purview *sensitivity labels directly to cloud security groups* to simplify group governance and policy management.
3. Microsoft Purview now reduces *DLP policy sync from 2 hours to 30 minutes* for faster tenant-wide enforcement.
4. Microsoft Teams now lets users *add Planner tabs directly to Shared and Private channels* for seamless task management across restricted and cross-organization workspaces
**Existing Functionality Changes:**
1. A new *opt-in Safe Attachments policy* in Defender for Office 365 automatically quarantines unscannable
Azure VM and Trusted Launch VM security advisory
Hi, look like nearly all Azure VM's world wide, especially those with Trusted Launch, have a very high security vulnerability and need to be rebooted to apply unknown security fix.
We received advisory below for some but not all out tenants, but when checking 'Impacted Resources' none VM's are affected.
I wonder if MS bulk sent this advisory and our tenants are not affected or perhaps tenants are affected, but 'Impacted Resources' is incorrect.
>You’re receiving this notification because you’re associated with one or more Azure subscriptions that currently use affected Azure virtual machines with Trusted Launch enabled.
>Microsoft has deployed a security update to Azure infrastructure. A restart is required for the updated protection to take effect on affected running virtual machines.
>Action required
>To activate the updated protection:
>
>Review the affected virtual machines listed in the Account information section.
>Schedule a maintenance window based on your operational requirements.
>Restart each affected virtual machine.
>After the restart, verify that your applications and workloads are operating as expected.
>A standard virtual machine restart is sufficient. You don’t need to redeploy or re-create the virtual machine, or make application or configuration changes.
>During the restart, affected workloads will experience the interruption normally associated with a planned virtual machine restart.
>What happens if you don’t take action
>Until an affected virtual machine is restarted, the updated protection won’t be active for that virtual machine.
>Microsoft won’t automatically restart your virtual machines. You must schedule and complete the restart based on your operational and business-continuity requirements.
>Restart your virtual machines
>You can restart affected virtual machines by using the Azure portal, Azure CLI, Azure PowerShell, or the Azure REST API.
>Azure portal
>In the *Azure portal*, open the affected virtual machine, select Restart on the Overview page, and then confirm the restart.
>Azure CLI
>az vm restart --resource-group
>For more information, see *az vm restart documentation*.
>Azure PowerShell
>Restart-AzVM -ResourceGroupName "
>For more information, see *Restart-AzVM documentation*.
>Azure REST API
>For information about restarting a virtual machine programmatically, see *Virtual Machines - Restart REST API documentation*.
>Help and support
>If you have questions about this update or need assistance with restarting your affected virtual machines, create an *Azure support request*.
>You can also ask questions in *https://learn.microsoft.com/answers/tags/94/azure-virtual-machines.*
https://redd.it/1ve63cg
@r_systemadmin
thinking of transitioning from help desk to sysadmin
so... my company's only sysadmin was let go.
I'm thinking of applying for the position and requesting reduced salary (enough to make it a Jr. Sysadmin position) as I lack experience.
I asked, weeks ago, for a list of certs from the then sysadmin, which I never got, in the event he ever retired.
I have a BAS Degree only from a local community college that is aimed at producing sysadmins.
I don't want to be in the help desk for life.
Would anyone be willing to advise me on what I'd need?
Related: we're a windows and cisco based internal healthcare help desk. there are 900+ employees and 5 of us in help desk, 30 data services folks (programmers) a network engineer, plus the open sysadmin.
thanks!
https://redd.it/1vdxrpd
@r_systemadmin
Looking for affordable server colocation in Canada
Hi everyone,
I recently watched this video and found the idea of colocating my own server in a data center very interesting:
[https://www.youtube.com/watch?v=zbkqRPIUYAo](https://www.youtube.com/watch?v=zbkqRPIUYAo)
I’m interested in putting my own physical server in a Canadian data center instead of keeping it at home.
Does anyone know a company that offers affordable colocation services for a small setup (for example, 1U or 2U server space)?
I’m mainly looking for:
* Reasonable monthly pricing
* Space for my own hardware
* Good internet connectivity
* Reliable power and cooling
* Remote hands support would be a bonus
I’m located in Canada and would appreciate recommendations from people who have actual experience with providers.
Thanks!
https://redd.it/1vdspue
@r_systemadmin
N-Able System Performance Issues
Our new co-managed MSP recently swapped us to N-Able from our old MSP who used Ninja.
After the swap, system performance has degraded significantly on machines. I’m the IT manager so I am keenly aware of the drop in how reliable and stable my system is.
Is there any reason this would happen? Any other MSP experienced this before?
https://redd.it/1vdogin
@r_systemadmin
N-CENTRAL active exploitation, Mitigate immediately.
N-Central earlier today reported active exploitation and post exploitation actions of connections and persistence on managed RMM/client devices (cloudflare tunnels being installed on end user devices/servers) status page advisory includes hosted installs.
Take your installs offline immediately and threat hunt.
Earlier today n-central said servers on the latest release were safe but have updated the advisory to include the latest release and working on a new hotfix, keep an eye on https://uptime.n-able.com/
Current IOCs listed here, also affects hosted instances so monitor accordingly. Community information suggests that a n IOC maybe be if your server is suddenly showing as unlicensed.
https://www.n-able.com/blog/n-central-security-update-august-1-2026
https://redd.it/1vdo5w2
@r_systemadmin
ForensiT User Profile Wizard? I have a non-domain Win11 PC in use for 3 years and I want to join it to the domain w/ folder redirection GPO but keep everything intact...possible?
Outlook, mappings, printers, etc etc
1. Join the PC to the domain (System > Rename this PC (advanced) > Change, or Add-Computer -DomainName domain.local -Restart). Reboot.
2. Run User Profile Wizard on the machine.
3. Select the existing local profile (e.g., C:\Users\jsmith), enter the domain account it should map to (DOMAIN\jsmith), and let it run. It can also do the domain join for you in one pass if you prefer.
4. Log in as the domain user — they land in their exact same profile.
https://redd.it/1vdmayc
@r_systemadmin
What If I’m Lost?
I’ve been working as a ssr cloud sysadmin for about a year and a month at my current company as a remote contractor. I make around $2.5k USD/month before taxes and deductions. In my country, that’s roughly 4x the minimum wage, so financially it’s a very good job.
The problem is that this job is slowly killing my motivation. There are barely any projects assigned to me. During daily standups, I mostly just try to survive by saying something because I don’t really have anything to report.
Everyone on my team is busy with their own work, so asking for mentorship or guidance isn’t really an option either.
Because I’m a contractor outside the US, I have very limited access to systems and very few opportunities to contribute. Even when I want to help, I’m restricted by permissions. Honestly, I don’t even know why I haven’t been let go yet. I just feel empty and useless.
Next month I’m planning to visit my family in Spain, and it made me wonder if I should start looking for a job there instead, even if the salary is only around the Spanish minimum wage.
Context: 25-year-old male. Currently working as an SSR Cloud SysAdmin with about 4 to 5 years of IT experience overall, including Systems Administration, Cloud, Server Administration, IT Support, and IT Specialist roles.
Has anyone been in a similar situation? Would you prioritize career growth over a comfortable salary?
https://redd.it/1vdc2ij
@r_systemadmin
Advise for an IT student wanting to get into humanitarian work?
Hello,
I'm a third-year IT student in New Zealand focusing on network engineering, ops, cybersecurity, and cloud computing. I'm approaching graduation and starting to think seriously about where I want to point these skills.
I'd love for my work to actually help people. I've seen groups doing digital protection work for at-risk communities (e.g supporting Afghan women activists staying safe online) and infrastructure/connectivity work in disaster response, and both of these (and everything in between) really appeal to me.
Aside from my formal study, I have an interest in Homelabbing, Embedded systems, and web.
A few questions for anyone who's made this move:
\- Did you go straight from study into humanitarian/NGO tech work, or build up a few years in a "normal" IT job first?
\- Which orgs are actually good to volunteer with or apply to as an early-career person (I've come across NetHope, Access Now)?
\- Any certs or experience you'd say actually matters vs ones that looked good on paper but were not worth it.
\- Any general tips for what I should focus on to be able to genuinely help with groups and orgs like this.
Thanks!
https://redd.it/1vd7hg9
@r_systemadmin
Need advice
I need some advice. I've completed RH124 and RH134. What other Red Hat courses would you recommend that are the most useful for real-world work?
I'm taking over the maintenance and administration of our Red Hat servers at work, and I want to keep learning as much as I can so I can do the job well. I'd really appreciate any recommendations based on your experience.
https://redd.it/1vcx2vw
@r_systemadmin
You don't know your real SaaS count until you check what's connected to your identity provider. Learned this the hard way this week
So we ran a proper SaaS audit this month. Our SSPM reported 340 managed apps, which looks reasonable on a dashboard.
Then we pulled the raw OAuth grant data from Google Workspace and found another 180 apps that no one in IT knew that it existed. 40 of them had full Drive access. One was a project management platform that the marketing team signed up for in early 2024, and three people are still using it. We don’t have a problem with the tool, but the IT team found out about it during the audit.
The SSPM flagged none, but I am thinking its because the apps were never provisioned through IT in the first place. Someone just clicked sign in with Google and that was it. They were living entirely outside the managed ecosystem.
What are you all doing about the SaaS your SSPM will never see?
https://redd.it/1vcq8j8
@r_systemadmin
So tired of “do you like this”
Just got the obligatory “are you enjoying Outlook” popup. I really hate these things. It’s an app. It’s a thing I use for work. I don’t want to yap with some bot about whether or not I do or don’t like new outlook old outlook, ancient outlook or lotus notes. These things are tools. Utilities. Might as well be a refrigerator. Damn, just make the thing work effectively and stop wrapping it in sparkles and leave me alone. Oh, and get off my lawn too, lol.
https://redd.it/1vcqsi7
@r_systemadmin
RealVNC Viewer 7 is locked behind a paywall. RealVNC Connect Viewer 8 requires an account.
2 Days ago RealVNC ended public access for Viewer 7. Now Connect Viewer 8 is the only publicly accessible version and requires a RealVNC account.
"The RealVNC Classic Viewer (v7) will continue to be available for customers with a Premium or Enterprise plan to download from the RealVNC Portal."
Source:
https://help.realvnc.com/hc/en-us/articles/35745908986653-Important-changes-to-RealVNC-Viewer-Information-and-FAQs
Time to make the move to open source VNC implementations.
https://redd.it/1vcmlpy
@r_systemadmin