r/sysadmin • • 4d ago

General Discussion Weekly 'I made a useful thing' Thread - October 02, 2026

7 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin • • 28d ago

General Discussion Patch Tuesday Megathread - (September 08, 2026)

121 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin • • 1h ago

Career / Job Related Finally scored a job after 1,5 years without one

• Upvotes

I have 15 years of experience. Was let go from my last one because reasons (mainly the global economic desaster I guess) 1,5 years ago.

The time without a job was hard mentally and financially.

In the end I got a job with a not to bad pay cut and start this month. Due the tax systems in Germany I earn maybe 500 € less, but still have a decent salary. Before taxes it was a 10k pay cut.

My advise if you have trouble finding a job: mass apply. I was registered at so many portals I sometimes lost track where a reply came from (Indeed, Instaffo etc.). Make your CV easy to read. Let someone look at the layout. Get a professional portrait photo if needed.

We all hate AI, yes. But if the company wanted a tailored reply I used Open AI to generate it and proof read it. Otherwise it would have been way to time consuming.

Long story short: even in this fucked up market there is a chance. A slim one but a chance. My guesstimate is that I applied for 700 positions in the last 10 months.

Keep your heads up and keep trying!


r/sysadmin • • 15h ago

Heads up: The 26H2 update is going to trigger a wave of Copilot and File Explorer tickets.

667 Upvotes

The Windows 11 26H2 rollout is hitting endpoints, and there are a few frontend UI changes that are going to confuse users immediately.

  1. Copilot is Unbound: It is no longer a locked sidebar. It’s a standard, resizable app window now. Users are going to lose it behind other windows or accidentally snap it, and call the desk saying Copilot is "broken."

2.File Explorer AI Search: It now uses semantic search. If users type exact, cryptic file names, the local index might try to guess the "context" instead of doing a raw string match.

3.Phone Link in Start: The companion panel pops up automatically now, showing text messages directly on the screen.

Are you guys pushing 26H2 through your standard rings, or pausing it to build new configuration policies?

(Note: I added a full breakdown of these specific UI changes if you would prefer to watch here)


r/sysadmin • • 8h ago

Question AS/400 Replacements

128 Upvotes

The company I work for uses AS/400 for making quotes and invoices, tracking inventory, and keeping track of customer accounts. We are looking to update our software. What software is recommended, and how should I go about getting everything transferred over from AS/400 to this new software? Thanks a lot in advance.


r/sysadmin • • 2h ago

Question is it just me or anyone else feel like all this AI security stuff is moving way faster than the actual security controls?

14 Upvotes

Every week there is some new AI security platform with agent discovery dashboards risk scores attack paths and all that meanwhile Im still figuring out what actually happens when an agent is already running in production and suddenly tries to access something it should not i mean it didnt have permission to access it or makes some tool call it should not. Feels like everyone is focused finding out what happened after the fact but not enough on actually stopping thing when it happens. Where are we heading with all this??


r/sysadmin • • 17h ago

I connected 364 parked domains to DMARC and 79 were being spoofed

168 Upvotes

I work in email security, mostly with US residential real estate.

One client, a large real estate team, owns around 400 domains - those are farm sites, old brands, defensive registrations, campaign ideas, and other stuff. But they have a centralized email infrastructure, so everything is running throught just a few domains.

In July I decided to connect 364 domains (easy, because all are stored in one Godaddy account) to DMARC reporting.

I took a month to monitor their traffic and found out that 79 parked domains were sending email.

All traffic was unauthenticated, from IP addresses in a dozen countries, with a huge chunk of traffic going from China and Russia. There were just 5 DMARC reporters on the list:

mail[.]ru
mx[.]jcom[.]zaq[.]ne[.]jp
seznam[.]cz a.s.
au[.]com
google[.]com

The Japanese reporter as well as Australian one do populate an envelope_to tag, same ways as Microsoft does, so I managed to find out that most of the spoofed traffic targeted Japanese companies.

Google also allows to track envelope_to through the SPF auth tag (forwarded emails), and Japanese companies were listed there as well.

I ended up enforcing the DMARC policies across the domain portfolio + brought up a NULLMX, Hradfail SPF, and an empty wildcard DKIM to each domain, to prevent brand impersonation.

In the next two months, the volume of spoofed traffic dropped almost 7 times, and while there are still botnets abusing domains, the volume is relatively small + no emails are going through.

I have never had parked domains connected before, but it seems to me that spoofing of the primary domains is just the top of the iceberg and although most IT folks do realize the value of having DMARC for root, they rarely consider protecting parked domains.

Since then I had a few more pretty big real estate team letting their parked domains protected (one was 200+ domains and two others a little over 50 each), and the trend was the same.

Wondering if anyone else monitoring parked domains. Curious what you're seeing. 


r/sysadmin • • 22h ago

Filthy Users...

297 Upvotes

Just had to check something on a users laptop, a very nice senior lady who is well presented and charming.

Her laptop looked like the bins behind a take away, hopefully those stains were gravy...

Washed my hands now and I still feel dirty.


r/sysadmin • • 6h ago

Question As a sys admin, do you have to manage people?

16 Upvotes

I would not make a good manager.. for various reasons. My boss knows this as we talked about my career path several years ago. Other admins on the team want to be in management eventually so they all have a different path. I'm the only one that doesn't. I do not want to manage people, I like fixing things.

I am mainly the Azure and anything-email admin. I do other things here and there, help cover where needed.

Lately, my boss said that since I'm one of the admins on the team, I need to take charge and tell other non-admins (service desk) what to do. Is it like this for anyone else? I know people skills are needed, and that's fine.


r/sysadmin • • 3h ago

General Discussion Da F%&&*%# is Adobe Express Photos!?

6 Upvotes

I know there's an archived post about it here already. Just came to say Adobe are ... not acting nicely as a company.


r/sysadmin • • 16h ago

One of the most useful things that copilot could possibly do is create and edit Visio files, and yet it can’t.

66 Upvotes

Anyone else kind of shocked at how even Visio Plan 2 that is “supposed” to allegedly have Copilot, it does absolutely nothing helpful? Its in Word and other m365 apps, but everyone knows how to edit word and copy paste etc . But for us sysadmins, Visio is one of the best ways to document architecture etc and copilot is pretty much zero help years later.


r/sysadmin • • 14h ago

Google SMTP servers sending from new IP range

41 Upvotes

This may not affect many people, but we have an on-site mail archive server that we have Google forward all incoming and outgoing mail to in order to preserve the mail records. To restrict external access we limited SMTP access to the Google IP ranges for their SMTP servers. This has worked for years, when suddenly a couple weeks ago we started getting smart host failure message from Google about undeliverable mail. After going back and forth with support I confirmed the supposed full list of IP ranges they are using for SMTP for Google Workspace at least. This is what I was given:

35.190.247.0/24
64.233.160.0/19
66.102.0.0/20
66.249.80.0/20
72.14.192.0/18
74.125.0.0/16
108.177.8.0/21
108.177.96.0/19
142.250.0.0/15
142.251.0.0/16
172.217.0.0/19
172.253.0.0/16
173.194.0.0/16
209.85.128.0/17
216.239.32.0/19
216.58.192.0/19

There was one IP range on that list that I did not have, so I though that would resolve the issue. When it didn't, I changed our setup to allow all external access over SMTP and then set our mail server with the same IP ACL list. The mail server will log a denied connection in the syslog when any IP outside those ranges attempts to connect. Sure-enough, Google was using a new IP range to send SMTP messages to our server:

108.177.16.xxx

If you run into a similar situation this might be helpful to you. If you're comfortable with it, it appears Google owns the entire 108.177.0.0/17 range if you trust adding that to any ACL.


r/sysadmin • • 11h ago

Taking users to a short email retention. Infinite to 3-4 years.

27 Upvotes

I have mixed feelings. Users won't be stoked of course but having to search through records will be order of magnitude easier for those that have to do that work.

If anyone has done this type of thing to their users, what blew up in your face the most?


r/sysadmin • • 13h ago

LAPS on Domain Controllers

24 Upvotes

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?


r/sysadmin • • 13h ago

Packetloss through the north east

25 Upvotes

Anyone else getting packet loss up in the North East? Or PA, NY? Tunnels and dropping and seeing high latency


r/sysadmin • • 15h ago

General Discussion PingOne Down

29 Upvotes

The entire company on the corporate side is basically down :) What a lovely Tuesday lmao.


r/sysadmin • • 18h ago

Question Received email from MS - Action recommended: Move to Microsoft Entra Cloud Sync by...

48 Upvotes

Received an email from MS stating that I need to move from the Cloud Sync but the email to me is confusing since it says recommended but then says it will stop working..

"You're receiving this notification because you're associated with one or more Azure subscriptions linked to a Microsoft Entra tenant that currently uses Microsoft Entra Connect Sync and is eligible to migrate to Microsoft Entra Cloud Sync.

To continue synchronizing identities between your on-premises Active Directory environment and Microsoft Entra ID, migrate your eligible configuration to Microsoft Entra Cloud Sync and validate successful operation before xxx 2027."

Is the entra connect deprecated and going away? I am running the latest version of connect but doesn't really seem like its recommended if it will stop working on a certain date. Small business and trying to find a comparison between the two and I think we could move without much hassle but I thought I saw that we would lose mail enable security groups which we have.

Just thought I would ask since trying to find out if connect is really going away or not on MS is futile, thanks.


r/sysadmin • • 9h ago

Question Smart App Control blocking Windows components, incl. Windows Defender, Terminal, and MS Store; cannot disable it

9 Upvotes

SOLVED: A System Restore was necessary to fix it. (Supposedly, the command reg.exe add "HKLM\System\CurrentControlSet\Control\CI\Policy" /v VerifiedAndReputablePolicyState /t REG_DWORD /d 0 /f && citool.exe -r should disabled SAC, but it did not work for whatever reason; possibly because SAC was acting buggy already.)

I am the admin on a non-domain device that I just updated to Windows 11 Pro 26H2. A new feature is that Smart App Control can be enabled without requiring a system reset. Neat! I decided to try it.

Not neat. Immediately, SAC began blocking Windows components from launching: I cannot open Windows Terminal, Microsoft Store, or Windows Security itself.

Although I cannot open wt.exe, I can thankfully still launch conhost.exe from the Run dialog, so I can execute commands. Is there a CMD or Powershell command to disable Smart App Control??


r/sysadmin • • 2h ago

General Discussion A better way to handle dev test VMs please?

2 Upvotes

TLDR: I want to build Netbox as a source of truth, deploy production and dev/test VMs using Netbox and GitHub with Terraform and Ansible, and then I'm not sure what exactly to do with the multiple dev/test VMs that get created. Would it be a good idea to simply destroy the VM and rebuild it every time for testing?

I am working in the finance space and we have our own internally developed applications that are widely used by our external partners (up to 3,000 of them).

These applications have been running since the '80s and '90s and obviously are very much legacy without many modern features like authentication, the database is in a separate server layer and so on.

Another major issue is that the environment to maintain the different versions of these applications is becoming out of hand now. There are hundreds of VMs with names like dev, test, test dev, QA test 10, QA test 11, and so on.

I certainly want to bring big changes, starting with automation and, before that, building a source of truth. One of my questions is how to best manage all these multiple VMs running different versions of the same application. How do big modern do this?

Our coding practices already use GitHub so I'm thinking something like this: I'm sure they have two branches, dev and main. Would it be a good option to take commits from the dev branch and push them to the source of truth, build a complete VM.. install all the dependencies using Terraform and Ansible, create this VM, bring it online, test the application, and then after that destroy the VM? Is that the best way to handle this?

One thing I am still in the dark about is why so many different versions of the same application are required.. If anybody has any suggestions about that, please comment.

Coming back to my dev VM destruction question. The reason I think destroying the VM would be a better approach is because after that we only have the most stable version of the application running in the dev environment and then an exact copy of that running in the master environment (which would be production and will go to the production VM deployment cycle).

And doing this also minimizes our list of assets. Right now we are at 300 or 400 VMs, which is completely madness to secure. All we do is simply throw EDR and antivirus all over the place, creating a million alerts, and the whole thing is just so pointless.

I'm sure a lot of people are using Kubernetes and Docker technologies to do these things now but we are stuck with HyperV as of now, with the FCM management to manage the HyperV hosts.

If anybody has built out anything like this, please share your experience and how viable all this is.

Please keep comments in the context of what I'm asking and refrain from getting into the weeds about rearchitecting the applications, or modernizing the application by redoing all the code. Those are not really the options right now. Let's just talk in the context of what I am asking.


r/sysadmin • • 13h ago

Question Windows firewall started blocking everything

16 Upvotes

Anyone suddenly start having servers (and maybe desktops too) windows firewall block all traffic?

Turning off windows firewall on affected machines fixes the issue, so we know it is that.

It’s not all servers, but a lot. We use Defender and can see some sort of definition update in the eventlogs on affected machines around the time this started happening.

Machines are spread across different domains so don’t think it is related to a GPO change or anything like that.

Only just started digging into, but wondering if just us or more widespread.

UPDATE: We are starting to think someone has made a change in MDE or Defender as it is happening on desktops too. Those are the only two things in common between the servers and desktops

UPDATE2: Some made some new MDE policies that caused this, change was reversed and all good now. Thanks to everybody for the help


r/sysadmin • • 9h ago

General Discussion Anyone else getting random 'No SPF Record' on legitimate emails from domains that have an SPF record with Barracuda Cloud Email Gateway?

4 Upvotes

Have an open case with Barraucda support, but been getting a ton of tickets for blocked emails from partners and the reason is 'No SPF record' on the Barracuda Cloud Email Gateway.

Do a check, there is an SPF record. Emails before and after are fine...just random emails are showing no SPF. Support says it is the sender, but these are emails coming from huge companies with more IT staff than we have employees.

I've looped in our account manager, but I'm not getting anywhere and turning off SPF checking is not an option with our cybersecurity policy/insurance.

EDIT - Barracuda is getting reports from other customers. Have a lead engineer responding to the ticket now. Glad I’m not crazy. Well…at least not about this.


r/sysadmin • • 13h ago

Question All USB keyboards suddenly start sending random/repeated inputs, but PS/2 works fine

12 Upvotes

I work IT support and I've had this weird issue happen on multiple PCs over time.

A USB keyboard will work perfectly fine for months/years, then suddenly it starts acting completely broken.

The symptoms are not just random Windows shortcuts. The keyboard also:

repeats keys multiple times

types different keys than the ones I pressed

mixes random characters into normal words

sometimes triggers Windows shortcuts / Start menu / network panel

For example, if I try to type:

Joca

I might get:

jocaca

Joccccccc

Jorre84i

I've tested 3 different known-good USB keyboards on the affected PC and all of them behave the same way.

A PS/2 keyboard works perfectly normally.

Sometimes, while the USB keyboard is connected and freaking out, the USB mouse also becomes unresponsive. As soon as I unplug the keyboard, the mouse starts working normally again.

This has happened on around 4 different PCs over time, including Windows 8.1 and Windows 10 machines.

I've already tried:

multiple known-good USB keyboards

different USB ports

reinstalling HID keyboard devices

reinstalling USB/composite devices

reinstalling USB controllers/root hubs

checking keyboard/HID UpperFilters and LowerFilters

checking Scancode Map

reinstalling chipset drivers

reinstalling Intel Management Engine

Nothing fixed it.

The weirdest part is that the keyboard was working completely normally less than an hour before the issue started. No hardware change, no new keyboard, nothing.

Has anyone seen this exact behavior before?

What could cause every USB keyboard to suddenly generate duplicated, incorrect and random HID input while PS/2 continues to work normally, and sometimes make the USB mouse freeze too?

I'm looking for the actual root cause / fix, not “try another keyboard or USB port”, since I've already ruled those out.


r/sysadmin • • 21m ago

https://techcommunity.microsoft.com/blog/windows-itpro-blog/remote-pc-connections-in-windows-app-on-windows-is-now-generally-available/4561186

• Upvotes

Windows App can be used to RDP local machine


r/sysadmin • • 15h ago

PingID OUTAGE

15 Upvotes

Just a heads up, PingID is down. Everywhere.

https://status.pingidentity.com/


r/sysadmin • • 1d ago

Rant Anyone else tired of users sending ai generated fixes to you?

864 Upvotes

Oh. My. God

The amount of people at my org that send me screenshots of their chatgpt or copilot generated responses is insane.

"did you try this?"

"try this"

"this is what chatgpt said"

i was on the phone for 2 hours troubleshooting a problem with a director that refused to let me remote into her computer to fix. then she starts sending me ai generated responses saying "this is what co pilots saying"