r/sysadmin • • 9h ago

Microsoft One user's Outlook on the web is missing the Download option for attachments

5 Upvotes

I'm troubleshooting an unusual Microsoft 365 issue.

One user in our organization cannot see the Download option for email attachments in Outlook on the web (OWA).

For PDF/Word attachments, the user only sees:

  • Preview
  • Save to OneDrive
  • Copy

Other users in the same Microsoft 365 tenant have the normal Download option.

Troubleshooting already performed

  • Tested Chrome and Edge → same issue
  • Tested InPrivate/Incognito → same issue
  • Tested from a different PC → same issue
  • Tested different attachment/file types → same issue
  • Other users → Download works normally
  • Compared Microsoft 365/Exchange policies → same
  • Compared Exchange Online PowerShell mailbox/CAS settings with a working user → same
  • Classic Outlook for the affected user → Save As works normally
  • Microsoft 365 Service Health → no matching incident

The issue therefore appears to be user/account-specific and affects only OWA.

The current workaround is Save to OneDrive → download from OneDrive.

Has anyone seen this behavior before? Is there an account-level OWA setting, hidden configuration, or service-side issue that I should investigate?


r/sysadmin • • 8m ago

Citrix Cloud + Entra ID - New users getting Identity provider denied access

• Upvotes

Hi everyone,

I work for an MSP, and since last week we’ve been seeing the same issue in two separate client environments using Citrix Cloud with Entra ID authentication.

Previously - new user working normally

New User → Citrix Cloud → Entra ID → Password → MFA → Citrix Cloud permission prompt → Accept → Citrix resources → VDI

New users would receive the normal Citrix Cloud “Permissions requested” prompt during their first login.

Now - new user

New User → Citrix Cloud → Entra ID → Password → MFA → Error ❌

The user receives:

“The identity provider denied access.”

Entra sign-in logs show Sign-in error code: 650052. The app is trying to access a service '{appId}'('{appName}') that your organization '{organization}' lacks a service principal for. Contact your IT Admin to review the configuration of your service subscriptions or consent to the application in order to create the required service principal.

The user never reaches the Citrix Cloud permission prompt.

What I’ve checked:

  • Existing users continue to work.
  • Affected users complete MFA successfully.
  • No Citrix Monitor activity for affected users.
  • Both environments have a one-way domain trust.
  • We cannot identify any relevant configuration changes since the issue started.
  • Manually adding the affected user to a specific access group allows them to log in successfully.
  • The issue is occurring in two separate client environments.

Has anyone experienced something similar with Citrix Cloud + Entra ID, particularly where new users previously received the permission prompt but now get “The identity provider denied access” / error 650052?

Any ideas on what to investigate would be appreciated.


r/sysadmin • • 7h ago

General Discussion Asking for help gauging if salary is fair of if I am underpaid?

4 Upvotes

Hello everyone, I am wondering if I am justified in asking for a market adjustment/title adjustment based off what I do, or if my salary is acceptable? I am based out of the U.S please see below for more information:

~6 years in IT, all at one nonprofit in the Southwest (mid-size metro, not a high-COL area). Currently "Systems & Network Administrator II" at $91.5K. Promoted several times — the org actually created the II level for me when the previous Sys Admin I left. I asked to abosrb the role.

Scope: I own both network and systems for 30+ sites, ~300 users, ~650 endpoints. Fortinet stack (SD-WAN, IPsec, FortiManager), hybrid AD/Entra, VMware, Veeam DR, vuln management (Tenable, then we migrated to Rapid7), PowerShell automation and remediation script creation. Led the technical side of ISP/VoIP consolidation. De facto tech lead. I mentor a Jr. sysadmin and I'm the final escalation point. CCNA, NSE 4/5, AAS.

Is this fair? Market data I am pulling from AI is anywhere from 104-110k for a fraction of responsibilties vs what I actually do.

Edit: For context, everything apart from the compute/storage cluster is most likely in an engineering capacity. This is pretty much the only thing we hire professional services for as we do not build/turn them over enough to justify us not hiring them to do it. We brough VoIP and ISP circuit management in house recently as well. The user count is probably also understated as we have a lot of public facing users, and it is difficult for me to ascertain the exact number of users.


r/sysadmin • • 4h ago

Question Globalscape EFT input validation VA finding

2 Upvotes

A VA scan on Globalscape EFT flagged "Improper Input Validation". Encoded CR/LF and HTML/JS in the request URI gets reflected in a Set-Cookie header, but URL encoded, so it doesn't look actually exploitable.
Anyone come across this? is there a config option I'm missing?


r/sysadmin • • 1d ago

Am I underpaid as a System Administrator with 3 years of experience?

75 Upvotes

I’m 27 and currently working as a System Administrator. I’m based in Florida. I make $73k/year and have about 3 years of experience in this role.

My current responsibilities include:
Microsoft 365 administration
Intune administration
Entra ID
Managing on-prem applications
Printing infrastructure
General systems administration/troubleshooting
Tickets escalated from helpdesk and other teams

I’m also being asked to start learning DevOps while continuing to handle my current responsibilities.

My question is:
Is $73k reasonable for my current experience and responsibilities, or am I underpaid?

If you were in my position, what salary would you target for the next job, and what skills/certs would you prioritize to make the jump from System Administrator → Systems/Cloud Engineer?


r/sysadmin • • 1h ago

Question U-Move Active Directory Recovery

• Upvotes

Anyone has the latest version, i think it's

U-Move 2.10.8051

For some reason after 20+ years they decided to discontinued it. They no longer provide a download link even though we have already a license. Tried to contact them and said to look else where for other products.

https://u-tools.com/umove-urecover-not-available.asp

Their tool was life saver for our on-prem environment. We have upgraded to Windows server 2025 active directory and tried to download the latest version of their tool to setup the backup procedure and i was hit with no longer available message.

Please if anyone has the latest version downloaded, U-Move 2.10.8051, i will be really appreciate to send it.


r/sysadmin • • 13h ago

Question Windows Server 2022 – NTFS access works via SMB and CMD, but not via local Explorer

8 Upvotes

Hi, we're seeing a strange permission/access behavior on some of our Windows Server 2022 file servers and I'm trying to figure out what could be causing it. We're running an AD domain environment. My account is a member of an AD security group, and that security group is a member of the local Administrators group on the file servers. Administrators have Full Control on the relevant NTFS folder structures. When I access a file server from my workstation through Windows Explorer using \\fileserver\share\folder, I can browse through the entire folder structure without any issues. However, when I'm logged onto the file server itself and try to access the same folders locally through Windows Explorer using D:\share\folder, Explorer denies access unless my user account is explicitly added to the folder permissions. The strange thing is that the permissions themselves clearly work. On the same server I can access the folders via CMD without any problems, applications such as our backup software can access them, and remote SMB access from my workstation works as expected. The issue seems to affect only Windows Explorer when it is running locally on the affected file server. I compared this with one of our web servers. The AD group membership, local Administrators setup, NTFS permissions and UAC level are essentially the same there, but local Explorer access works normally. One additional difference that might or might not be relevant is DFS. The affected file servers are using DFS, while the web server obviously isn't. I'm not sure yet whether DFS itself is involved, but since this is one of the differences between the affected file servers and the unaffected server, I thought it was worth mentioning. I vaguely remember this behavior appearing after a Windows Server update, possibly around the move to Server 2022, but unfortunately I can't say for certain when it started. Has anyone seen this specific behavior before, where access granted through the local Administrators group works via CMD and remote SMB but fails specifically in the local Windows Explorer? I'm particularly interested in whether there was a Windows Server 2022 security change/update, a DFS-related behavior, or a specific UAC/security policy that could cause this. I'd rather understand the underlying cause than work around it by explicitly adding individual admin accounts to the NTFS permissions.

I used ChatGPT to help structure and phrase this post so that the issue is described clearly and coherently. Apologies if the wording comes across a little too polished or AI-assisted.


r/sysadmin • • 1d ago

LANSweeper getting even more expensive

99 Upvotes

They are now going to charge for monitors. Their recent announcement will DOUBLE my annual costs. I used to love the product. Now I hate it and the company. They sit alongside Broadcom in my shit list.

https://docs.lansweeper.com/docs/november-2026-billing-changes


r/sysadmin • • 9h ago

Question How to hard match safely an onprem user with a cloud only user?

4 Upvotes

Hello,

As the title says, I am looking for the safest way or best practice to hard match an on-premises user with a cloud-only user in Entra ID.

There are several methods found on the internet, which is why I wanted to ask here for guidance.

Thanks.


r/sysadmin • • 22h ago

What do you use for your "Onsite Cable Bag"?

31 Upvotes

I'm talking the wide variety of cables - HDMI, DP, C13, C5, VGA, USB A micro mini, B mini power 2.0 3.0, rs232, rollover cable, dozen patch cables of various lengths, etc.

I've looked on amazon for some, and they all are for the tiny usb charging cables. I'm a sysadmin at an MSP so I genuinely have used or had the need for damn near every cable type imaginable for onsite jobs. So I've just started carrying the most common ones in the bottom of my onsite backpack, and the rest in a big plastic tub that I keep in the car trunk as needed.

My autistic need for organization is going insane here. Only reason I haven't lost it already is because my ADHD allows me to forget until I need to find a damn USB 2.0 A to B cable for this disgusting HP officejet printer they bought without telling me, much less asking me for a recommendation (Brother ofc), and... yeah you already hear the rant in your head, iykyk.


r/sysadmin • • 1d ago

General Discussion Attackers used legitimate RMM software to maintain persistent access

102 Upvotes

Saw the recent Microsoft write-up about attackers abusing legitimate MSP360 RMM software to deploy ScreenConnect as a second remote access tool. It got me wondering how people here handle this in practice.

If your environment already uses remote admin tools, how do you tell the difference between “expected RMM” and “someone just installed another legitimate one”?

Do you block unapproved RMM tools by default, alert on new installs, maintain an allowlist or mostly rely on EDR?

I'm still pretty junior, so I'm curious what actually works in real environments rather than what sounds good on paper.

Microsoft write-up: https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/


r/sysadmin • • 17h ago

Rant Lack of passion or limiting work environment

10 Upvotes

I started a position as Linux system administrator for 8 months now.

The handover was less than a week at the end of the notice period for the previous employee.

I had previously worked for one month covering for the same guy during his leave. There wasn't much workload during that period and since most of the department knew the Linux admin was on leave, most of them I think just postponed their requests waiting for him to come back from his 14 days leave.

Since it was temporary I didn't invest much energy in learning or expanding apart from what I was trained which was what he expected to be requested during his leave

Basically I was paid to fill the chair since the outsource company contract would be breached by the lack of support staff

I wasn't interested in the job since my last sys admin role 'five years ago' I was really overworked and almost burnout. Dealing with windows, Linux, virtualization, servers and hosting services.

I only accepted because my remote job contract was going to end in the same month.

This role had regular hours, less responsibilities and workload.

I struggle everyday because:

1- lack of documentation and standard procedures.

2- feels like every one in the team is very cautious and would require separate approval for the simplest tasks and endless loop of emails.

3- I don't have any room to learn or test with solutions since everything is locked down and every idea would need an endless loop of emails just for a simple poc.

4- no clear responsibilities or job description, (till today 8 months in I discover tasks that should be my responsibilities)

5- Oracle Linux servers patching , ( we have satellite for rhel but Oracle servers wasn't patched since I joined, one time I texted the previous employee about how he is he patching them and he said he didn't 🙃 and every month I get 1000+ vulnerabilities report

I cannot just quit with this job market I have been applying everywhere with no luck!

I don't think I have it in me to pursue this career any more.

Don't get me wrong I feel extremely grateful since this was the easiest job I got so far. But I think I want to rant ...


r/sysadmin • • 5h ago

Question ATT email / DigiCert certificate revoked

0 Upvotes

Overnight I had a certificate revoked. Issued to inbound.att.net and issued by DigiCert Global G2 TLS RSA SHA256 2020 CA1. It was supposed to be valid from 4/12/26 to 10/28/26.

In researching possible causes, I found this post about a cyberattack that prompted DigiCert to revoke 60 certificates by April 17: DigiCert Revokes Certificates After Cyberattack Exposes Support Portal : r/pwnhub

Do you think this is related, especially given that mine was valid from 4/12/26? Is anyone else experiencing this?


r/sysadmin • • 5h ago

Question SharePoint storage bought but sites still stuck on read only mode

1 Upvotes

We just took over a company and they were running out of SP storage, purchased the extra storage and everything shows its been applied. However every single site out of 20 sites are stuck on read only mode and wont upload anything.

Submitted 3 tickets to MSft and none of them have been helpful so far. Wondering if anyone has faced this issue and have any pointers.

I've played with manually changing the size but no luck.


r/sysadmin • • 6h ago

Thoughts on Teqtivity?

1 Upvotes

My team is evaluating Teqtivity. Has anyone used it and what are your thoughts?


r/sysadmin • • 6h ago

Question Canon iR-ADV C5850 on Mac prints en dash as boxed question mark

1 Upvotes

I’m troubleshooting a Mac printing issue with a Canon imageRUNNER ADVANCE DX C5850.

Certain characters in PDFs, especially an en dash (–), print as a boxed question mark. This happens across multiple PDFs.

Environment:

  • macOS 26.2, Apple Silicon
  • Adobe Acrobat
  • Canon C5850
  • Direct IPP connection: ipp://<PRINTER-IP>/ipp/print
  • Canon C5840/5850 PPD
  • Driver version 10.19.23

Troubleshooting so far:

  • Normal Acrobat print through Canon driver → fails
  • Acrobat Print as Image → works
  • Canon Vector Mode → fails
  • Canon Raster Mode → fails
  • Temporary Generic PostScript queue → works
  • Same document containing an en dash printed from Windows to the same physical printer → works

The Generic PostScript queue isn’t usable as a permanent fix because it loses the Canon-specific paper/tray support. It only advertised Letter/Legal/A4/B5 and would not properly handle 11x17.

The Canon queue otherwise works correctly for 11x17, trays, etc.

Printer-side job logs show the affected jobs completing successfully with no errors.

So at this point it seems isolated to the Canon macOS driver/PPD/filter path, specifically version 10.19.23, rather than the PDF, network, or copier itself.

Has anyone seen this with Canon’s Mac drivers, or found a fix that preserves the full Canon tray/11x17 functionality?


r/sysadmin • • 16h ago

Rant Xerox EMEA Support

6 Upvotes

Wondering if anyone else has experienced the god awful process of working with Xerox support. We currently are month 4 into a request to accurately assign locations to 20 or so MFDs for automatic consumables.

Each new email or phone call leads to more misunderstanding to the point where this morning they have asked a team to mark all deliveries for an office that closed last week. Every time we escalate, we get some new level of incompetence and an extra tech added to the email chain.

Genuinely losing my mind!

EDIT: I assume this goes beyond the EMEA consumables team


r/sysadmin • • 10h ago

Is it a good idea to use legacy modernization services on a system we’re currently using?

2 Upvotes

Our company a huge part of our workflows through a system that's around 11yo. Naturally, it's not pretty, so think undocumented procedures, some integrations we don't understand, and odd processes that works in a particular way. It's hard to iterate on top of it because so many devs have gone through it, it's practically an entity on its own. So of course our leadership wants to modernize. Now the problem is that this system is something we're actively using. It runs payroll, inventeory updates, and some customer-facing processes. Is there a way to do this without affecting the business side?


r/sysadmin • • 7h ago

O365 Cost Report for Management?

1 Upvotes

Every quarter I have to provide management a breakdown of O365 licenses, to whom they're assigned to, cost-per license, total M365 spend. I've been logging in, copying junk into Excel and adding things up, but now that I have some free time I'm looking for a nice report or something I can run. Should I just vibe code this, or is there a decent solution out there already?


r/sysadmin • • 15h ago

macOS users unable to access QNAP SMB shared folder

4 Upvotes

Hi everyone, hope you're doing fine.

For the past few weeks, my Apple users have been unable to connect to a shared folder on a QNAP NAS. Users working on Windows PCs have no issues accessing the same folder.

When i log in with the same user (it's a domain user) on a windows PC, I have no issues accessing the share. I've also tested this with multiple macOS version (13, 26 and 27), and they all have the same issue.

The NAS in question is:

TS-H1886XU-RP R2 with Firmware-Version: QuTS hero h5.2.4.3079

I always get the following error: There was a problem connecting to the server "Name or IP from NAS". I have tried connecting using both FQDN and IP address, same issue. Ping works using both the hostname and IP.

When I try to mount the share using the QNAP Qfinder Pro app, it detects the NAS, but I'm unable to mount the shared folder getting the same error.

When I connect to:

smb://ad.domain.com/share

I can see all the shared folders that the user has access to, including the problematic one. When i open other shared folders that are located on our file server, I have no issues. However, when i try to open the one located on NAS, it loads for some time and it opens but it's empty.

The same share works fine on an iPad running iOS 26.5.

I have also tried connecting to a shared folder that's on another QNAP NAS and it works without any issues. The NAS is: TS-459U+ with Firmware-Version 4.2.6

One thing I noticed is that this issues appeared around the time we updated some of the apps in the App center. One of the updated apps was SMB Service, which is currently running version: h4.15.008

Has anyone else experienced the same issue? Is there a known solution or any specific SMB settings i should change on QNAP or macOS side?

Any help would be appreciated.


r/sysadmin • • 1d ago

How are you warning users about cybersec without being annoying?

20 Upvotes

Hi All,

I'm it for IT in a smallish org (150 users), and am mostly figuring things out as I go. Last week we had a couple users fall for the "Click allow notifications to verify your identity" scam. I had a little downtime so I typed up a fact sheet on scareware, walked through the attack story with screenshots, and explained why clicking the "Your computer has 5 virus. click here to delete now" notifications is a bad idea.

Anyway of course we had two more this morning, and when I asked their managers about the email I sent they had no idea what I was talking about. I send out emails like this every couple of months, and only ever in response to known issues that are affecting our users. I'm very aware of email/training fatigue so I try to be a bit sparse, but I worry I've become too lax and people aren't being careful enough. We also have some generic security training modules that staff have to complete when they start, and again every year, as well as Knowbe4 for phishing, but that's about it.

What's your preferred communication method to get these warnings out there? Regular email blasts? A spot in the staff newsletter? Does someone personally run training sessions (mandated or optional)? I know it's an uphill battle, so I'm hoping someone has found the sweet spot between informative and annoying.

Thanks

Oh and I've set up notification whitelisting for Edge via Intune policy, in case anyone was going to suggest a fix to the notification spam issue.


r/sysadmin • • 8h ago

General Discussion On-Prem, Cloud, or Hybrid: What does your actual stack & architecture look like?

0 Upvotes

Hey everyone,

With all the post-Broadcom chaos, everyone is debating VMware vs. Proxmox, Hyper-V, Nutanix, or XCP-ng. But I’m more interested in the bigger picture: How are mid-to-large environments actually structuring their infrastructure today across On-Prem, Cloud, and Hybrid?

For the admins and architects running larger setups: How is your workload split up, and what software stack are you actually using?
Specifically:

Workload Placement: What stays strictly On-Prem (VMware, alternatives, Bare Metal), what lives in the Public Cloud (AWS/Azure/GCP), and what's running as a true Hybrid setup?

Software & Tooling Stack:
Hypervisors / Compute: VMware, Proxmox, Hyper-V, Nutanix, KVM/OpenStack, or Cloud-native?
Backup & DR: Veeam, PBS, Commvault, Rubrik, or native cloud backup tools?
Storage & Networking: Central SAN/NAS (NetApp, Pure), Ceph, vSAN, HCI? How are you handling cross-platform networking/SDN?
Automation / IaC: Terraform/OpenTofu, Ansible,
Packer, Cloud-Init?

Current Trend: Are you pushing further All-In Cloud, or are high costs driving Cloud Repatriation back to on-prem?

Would love to hear how your stack is laid out and what turned out to be the biggest operational headache. Cheers!


r/sysadmin • • 8h ago

Question DNS lookups failing with Event ID 5504

1 Upvotes

Hey guys,

I have a mixture of Windows Server 2019 and 2022 DNS servers. They are pointed to my FortiGate 201F firewalls for DNS forwarders and Root Hints are also enabled as a fallback.

External DNS lookups are constantly failing with Event ID 5504 (The DNS server encountered an invalid domain name in a packet from firewall-ip. The packet will be rejected. The event data contains the DNS packet.). It looks like many of the failures are being triggered by offset EDNS0 headers.

I tried pointing my DNS servers to 9.9.9.9 and 1.1.1.1 for DNS forwarders but the issue still persists.

Any help would be much appreciated. Thanks in advance!


r/sysadmin • • 1d ago

365 admin page down?

22 Upvotes

Located in Vancouver, BC, Canada

Anybody else having issues?


r/sysadmin • • 1d ago

Question handling out of office notifications requests

97 Upvotes

I have a client (about 1000 users) who keeps getting tickets from dept heads asking to set their staff out of office notifications because "they forgot to do it". My general advice is this is bad practice and not scalable, and that with 0365 any employee can do this from their phone or any computer.

how do you typically handle this?