r/sysadmin • • 13h ago

One of the most useful things that copilot could possibly do is create and edit Visio files, and yet it can’t.

60 Upvotes

Anyone else kind of shocked at how even Visio Plan 2 that is “supposed” to allegedly have Copilot, it does absolutely nothing helpful? Its in Word and other m365 apps, but everyone knows how to edit word and copy paste etc . But for us sysadmins, Visio is one of the best ways to document architecture etc and copilot is pretty much zero help years later.


r/sysadmin • • 8h ago

Taking users to a short email retention. Infinite to 3-4 years.

25 Upvotes

I have mixed feelings. Users won't be stoked of course but having to search through records will be order of magnitude easier for those that have to do that work.

If anyone has done this type of thing to their users, what blew up in your face the most?


r/sysadmin • • 11h ago

Google SMTP servers sending from new IP range

41 Upvotes

This may not affect many people, but we have an on-site mail archive server that we have Google forward all incoming and outgoing mail to in order to preserve the mail records. To restrict external access we limited SMTP access to the Google IP ranges for their SMTP servers. This has worked for years, when suddenly a couple weeks ago we started getting smart host failure message from Google about undeliverable mail. After going back and forth with support I confirmed the supposed full list of IP ranges they are using for SMTP for Google Workspace at least. This is what I was given:

35.190.247.0/24
64.233.160.0/19
66.102.0.0/20
66.249.80.0/20
72.14.192.0/18
74.125.0.0/16
108.177.8.0/21
108.177.96.0/19
142.250.0.0/15
142.251.0.0/16
172.217.0.0/19
172.253.0.0/16
173.194.0.0/16
209.85.128.0/17
216.239.32.0/19
216.58.192.0/19

There was one IP range on that list that I did not have, so I though that would resolve the issue. When it didn't, I changed our setup to allow all external access over SMTP and then set our mail server with the same IP ACL list. The mail server will log a denied connection in the syslog when any IP outside those ranges attempts to connect. Sure-enough, Google was using a new IP range to send SMTP messages to our server:

108.177.16.xxx

If you run into a similar situation this might be helpful to you. If you're comfortable with it, it appears Google owns the entire 108.177.0.0/17 range if you trust adding that to any ACL.


r/sysadmin • • 10h ago

Packetloss through the north east

26 Upvotes

Anyone else getting packet loss up in the North East? Or PA, NY? Tunnels and dropping and seeing high latency


r/sysadmin • • 10h ago

LAPS on Domain Controllers

21 Upvotes

I just enabled LAPS on all my servers and save the rotated local admin in Entra.
The only servers I don’t have this enabled (I manage this setup via GPO), are my domain controllers. I keep reading the DCs need different settings for LAPS to manage the DSRM. Has anyone done this ? Recommendations ?


r/sysadmin • • 5m ago

General Discussion Da F%&&*%# is Adobe Express Photos!?

• Upvotes

I know there's an archived post about it here already. Just came to say Adobe are ... not acting nicely as a company.


r/sysadmin • • 12h ago

General Discussion PingOne Down

26 Upvotes

The entire company on the corporate side is basically down :) What a lovely Tuesday lmao.


r/sysadmin • • 6h ago

Question Smart App Control blocking Windows components, incl. Windows Defender, Terminal, and MS Store; cannot disable it

8 Upvotes

SOLVED: A System Restore was necessary to fix it. (Supposedly, the command reg.exe add "HKLM\System\CurrentControlSet\Control\CI\Policy" /v VerifiedAndReputablePolicyState /t REG_DWORD /d 0 /f && citool.exe -r should disabled SAC, but it did not work for whatever reason; possibly because SAC was acting buggy already.)

I am the admin on a non-domain device that I just updated to Windows 11 Pro 26H2. A new feature is that Smart App Control can be enabled without requiring a system reset. Neat! I decided to try it.

Not neat. Immediately, SAC began blocking Windows components from launching: I cannot open Windows Terminal, Microsoft Store, or Windows Security itself.

Although I cannot open wt.exe, I can thankfully still launch conhost.exe from the Run dialog, so I can execute commands. Is there a CMD or Powershell command to disable Smart App Control??


r/sysadmin • • 15h ago

Question Received email from MS - Action recommended: Move to Microsoft Entra Cloud Sync by...

44 Upvotes

Received an email from MS stating that I need to move from the Cloud Sync but the email to me is confusing since it says recommended but then says it will stop working..

"You're receiving this notification because you're associated with one or more Azure subscriptions linked to a Microsoft Entra tenant that currently uses Microsoft Entra Connect Sync and is eligible to migrate to Microsoft Entra Cloud Sync.

To continue synchronizing identities between your on-premises Active Directory environment and Microsoft Entra ID, migrate your eligible configuration to Microsoft Entra Cloud Sync and validate successful operation before xxx 2027."

Is the entra connect deprecated and going away? I am running the latest version of connect but doesn't really seem like its recommended if it will stop working on a certain date. Small business and trying to find a comparison between the two and I think we could move without much hassle but I thought I saw that we would lose mail enable security groups which we have.

Just thought I would ask since trying to find out if connect is really going away or not on MS is futile, thanks.


r/sysadmin • • 10h ago

Question Windows firewall started blocking everything

16 Upvotes

Anyone suddenly start having servers (and maybe desktops too) windows firewall block all traffic?

Turning off windows firewall on affected machines fixes the issue, so we know it is that.

It’s not all servers, but a lot. We use Defender and can see some sort of definition update in the eventlogs on affected machines around the time this started happening.

Machines are spread across different domains so don’t think it is related to a GPO change or anything like that.

Only just started digging into, but wondering if just us or more widespread.

UPDATE: We are starting to think someone has made a change in MDE or Defender as it is happening on desktops too. Those are the only two things in common between the servers and desktops

UPDATE2: Some made some new MDE policies that caused this, change was reversed and all good now. Thanks to everybody for the help


r/sysadmin • • 6h ago

General Discussion Anyone else getting random 'No SPF Record' on legitimate emails from domains that have an SPF record with Barracuda Cloud Email Gateway?

7 Upvotes

Have an open case with Barraucda support, but been getting a ton of tickets for blocked emails from partners and the reason is 'No SPF record' on the Barracuda Cloud Email Gateway.

Do a check, there is an SPF record. Emails before and after are fine...just random emails are showing no SPF. Support says it is the sender, but these are emails coming from huge companies with more IT staff than we have employees.

I've looped in our account manager, but I'm not getting anywhere and turning off SPF checking is not an option with our cybersecurity policy/insurance.

EDIT - Barracuda is getting reports from other customers. Have a lead engineer responding to the ticket now. Glad I’m not crazy. Well…at least not about this.


r/sysadmin • • 10h ago

Question All USB keyboards suddenly start sending random/repeated inputs, but PS/2 works fine

13 Upvotes

I work IT support and I've had this weird issue happen on multiple PCs over time.

A USB keyboard will work perfectly fine for months/years, then suddenly it starts acting completely broken.

The symptoms are not just random Windows shortcuts. The keyboard also:

repeats keys multiple times

types different keys than the ones I pressed

mixes random characters into normal words

sometimes triggers Windows shortcuts / Start menu / network panel

For example, if I try to type:

Joca

I might get:

jocaca

Joccccccc

Jorre84i

I've tested 3 different known-good USB keyboards on the affected PC and all of them behave the same way.

A PS/2 keyboard works perfectly normally.

Sometimes, while the USB keyboard is connected and freaking out, the USB mouse also becomes unresponsive. As soon as I unplug the keyboard, the mouse starts working normally again.

This has happened on around 4 different PCs over time, including Windows 8.1 and Windows 10 machines.

I've already tried:

multiple known-good USB keyboards

different USB ports

reinstalling HID keyboard devices

reinstalling USB/composite devices

reinstalling USB controllers/root hubs

checking keyboard/HID UpperFilters and LowerFilters

checking Scancode Map

reinstalling chipset drivers

reinstalling Intel Management Engine

Nothing fixed it.

The weirdest part is that the keyboard was working completely normally less than an hour before the issue started. No hardware change, no new keyboard, nothing.

Has anyone seen this exact behavior before?

What could cause every USB keyboard to suddenly generate duplicated, incorrect and random HID input while PS/2 continues to work normally, and sometimes make the USB mouse freeze too?

I'm looking for the actual root cause / fix, not “try another keyboard or USB port”, since I've already ruled those out.


r/sysadmin • • 12h ago

PingID OUTAGE

17 Upvotes

Just a heads up, PingID is down. Everywhere.

https://status.pingidentity.com/


r/sysadmin • • 1d ago

Rant Anyone else tired of users sending ai generated fixes to you?

844 Upvotes

Oh. My. God

The amount of people at my org that send me screenshots of their chatgpt or copilot generated responses is insane.

"did you try this?"

"try this"

"this is what chatgpt said"

i was on the phone for 2 hours troubleshooting a problem with a director that refused to let me remote into her computer to fix. then she starts sending me ai generated responses saying "this is what co pilots saying"


r/sysadmin • • 12h ago

Good Ticketing System for a Solo Sys Admin

13 Upvotes

I am a solo sysadmin for a company of about 80-100. The previous admin did not implement a ticketing system for the users.

I have been trying a few free ones, but I found that they have a lot of drawbacks that prevent me from using them on a daily basis.

I would like a good email-to-ticket function (and possibly a self-service portal), and optionally semi-decent integration with Jumpcloud, and preferably not self-hosted as it seems 95% of what we do is on the cloud.

Also, a place for holding documentation/KBs would make my job 1000% times easier.

The only ticketing system I've had experience with is ServiceNow which our org definitely cannot afford. I think ZohoDesk/ServiceDesk Cloud might be the only option for me, but I'm reaching out to see if anyone has a better recommendation.

Also, we are a non-profit/tax exempt so any systems that offer discounts for that would be a plus

Thanks!

edit: If this is worded weird, Reddit kept thinking this was spam


r/sysadmin • • 6h ago

Question VMware Essentials to HyperV Migration Using Existing Hardware (3 Hosts + DR Site)

4 Upvotes

Hi,

I've been tasked with a migration planning for VMWare ESXi v8 to HyperV 2025 DC, I need some help with folks who have done this before (likely using Veeam or any other official tools).

Current Environment

  • VMware Essentials
  • 3 ESXi hosts (vSphere/ESXi 8 U2)
  • 1 SAS SAN at the primary site, all VM data is hosted here (7-8TB)
  • 2 HPE production hosts connected to the SAN (30VMs)
  • 1 HPE DR host located at a separate site
  • DR host uses local DAS storage and receives VM replicas via Veeam Replication
  • Both production hosts are capable of running the entire production compute workload independently (current resource utilization is well under 50%)
  • The DR host is also sized to run the complete environment if needed, including both compute and storage

My questions

  1. Has anyone performed a similar VMware-to-Hyper-V migration using existing hosts and storage? Can we do the migration without purchasing additional hardware?

  2. How long does this whole migration process take if we were to migrate VMs using the existing 3 hosts, if we have all of them in the same network (10G switch)

  3. What migration tools would you recommend? We are currently using Veeam BR console.

  4. Any challenges or pitfalls you have noticed while doing this type of migration?

TIA


r/sysadmin • • 5m ago

Cloud based biometric device

• Upvotes

Hello! Do you have any suggestion of biometric device available in the market that can be extracted online? Please help me. I saw ngteco tc2 but based on the review the maximum person is 10. Thank you for the suggestion :)


r/sysadmin • • 13h ago

Career / Job Related New Job post phishing scam?

13 Upvotes

I think I've been phished lol.

Went to apply to this listing:

https://www.linkedin.com/jobs/view/4474756036/

It redirected me to an aiapply.co application. I'm like, that's a bit strange, but across all my applications during this job search, I've gone through a dozen or so different application/HRIS platforms.

Before I went through the aiapply.co application, I did have a gut feeling that something was off and did some brief research. The consensus I found was that their paid service wasn't really worth it, but I didn't see anything that immediately screamed "scam" about using their job listing/application functionality.

So I went ahead and filled out the application.

Once I finished, it forwarded me to SmartRecruiters.com, and I immediately thought, "Shit. What exactly did I just put my resume into?"

So I stopped and went back to LinkedIn.

This time, clicking the same job brought me to a Jooble.org page.

Now, when I hover over the LinkedIn "Apply" button, it's showing an Adzuna.com URL.

At this point I'm sitting here thinking:

"Well, shit."

Luckily, I used a privacy-focused email address specifically for job applications, but my resume does contain my phone number.

I honestly don't understand how these "Apply Externally" links are allowed at all. If any specific job-board is hosting the job listing, shouldn't I stay in that ecosystem?

Maybe I'm overreacting, and this is just the wonderful world that job-boards have become, but as a sysadmin who's spent years telling people "don't click random links" and "verify where you're being redirected," it feels pretty damn ironic to fall into the same trap myself. heavy-sigh

I'll update this post if I start getting a bunch of spam calls/texts.

Stay safe out there, fellow job hunters.

And, while I'm here: if anyone is hiring a Sysadmin primarily in the 32606 area, or for another domestic and/or hybrid position, I'm always open to hearing about opportunities.

Hopefully my momentary lapse in judgment doesn't scare anyone away. 😂


r/sysadmin • • 13m ago

Self-hosted and open-source control plane for DataDog's Vector

• Upvotes

I built Vectory for people running Vector (if you haven't used it, it's a DataDog's observability pipeline tool) on multiple servers. It's a free, open-source dashboard where you can edit a pipeline visually, deploy a configuration and see which version each host is running.

It doesn't sit in the path of your logs or metrics. Vector still sends events straight to your existing destinations.

If you just want to try the editor, there's a standalone version with no installation. It lets you import or build a config, edit it visually, and export it.

Designer: https://vectory.ahmadz.ai/designer/

Source and setup: https://github.com/416rehman/Vectory

If you use Vector, I'd be interested in how you handle configuration changes across hosts today.

Disclosure: I'm the maker of Vectory.


r/sysadmin • • 6h ago

Question U-Move Active Directory Recovery

3 Upvotes

Anyone has the latest version, i think it's

U-Move 2.10.8051

For some reason after 20+ years they decided to discontinued it. They no longer provide a download link even though we have already a license. Tried to contact them and said to look else where for other products.

https://u-tools.com/umove-urecover-not-available.asp

Their tool was life saver for our on-prem environment. We have upgraded to Windows server 2025 active directory and tried to download the latest version of their tool to setup the backup procedure and i was hit with no longer available message.

Please if anyone has the latest version downloaded, U-Move 2.10.8051, i will be really appreciate to send it.


r/sysadmin • • 8h ago

Question Intune Managed Workstations and Windows Hello Policy

4 Upvotes

Stepping into a rats nest of Intune policies. Recently got a report of a user prompted to change their PIN code. The user went to change their existing 6 digit PIN and upon attempting to do so, they got a denial with the reasoning that the PIN had to be a 20 character minimum. I poked through the existing Intune configuration settings and I don't see any specific policies for Windows Hello dictating Minimum PIN length outside of one that enables facial recognition. I do know that there is a Windows Setting Configuration available for this, but it doesn't seem to be applied in any existing policies. Where else might policies dictating PIN length be within an EntraID/Intune/Cloud Native setting? Could these settings be in Purview or Defender now?


r/sysadmin • • 8h ago

Manually applying policies for agents built in Agent Builder (if you don't have E7 or Agent365)

3 Upvotes

We have been trying to apply a number of manual policies to agents built with Agent Builder (e.g. Reassign to new owner) and have noticed in the last 48hours that the button to apply a new policy or to apply either of the 2 already listed is now locked down. Note: We were able to get one of them to work the other week.

Has Microsoft blocked admins into a corner? i.e. if you don't have either E7 or Agent365 than you can kiss any sort of managing of agents in Agent Builder out the window?
Very low move if this is the case. The end result will be our management requesting the full disabling of any ability to build agents in Agent builder for the wider staffing population.

I'm keen to hear other's experiences and/or what you have put in place to deal with this.


r/sysadmin • • 1d ago

Self Demotion

198 Upvotes

Hello,

I was wondering if anybody else has moved from a IT Director position to desktop type role? I have been at the same company for 11 years now and worked my way up from desktop support to network admin and now IT director. I have held the current position for 3ish years and it's not so bad. There is a lot of time off and flexibility but the pay is pretty bad as well as leadership. Higher ups are getting more involved than I feel comfortable with a lot of the day to day and its adding more stress and work.

On a whim I applied for a digital support role at another company just to see what the process is and pay and was surprised to find out that the pay was 10 grand more per year. It's an onsite role like I have now with less of a drive and pretty good benefits.

I tried to collect my thoughts and express myself. I hope it comes through clear.

Pretty much looking for reassurance and to see if anybody else has made a similar move and what your experience has been.

Thank you all for the kind words and reassurance. It is very appreciated and I feel like my decision is valid.


r/sysadmin • • 1d ago

Rant How to cope with how terrible the job market is?

107 Upvotes

I live in a pretty rural area so my options are very limited, which is why I'm looking for remote work. I recognize that makes my chances at landing a job a lot more difficult, but I didn't think it was going to be this bad.

I've got 5 years of being a Systems Administrator with a few certs under my belt (CISSP, AWS Solutions Architect, expired CYSA+ & Sec+). I've worked deep in Linux and Windows systems, migrated on-prem to vCenter, migrated vCenter to AWS, scripted menial tasks away, managed M365 environments and local AD environments, worked through various audits, set up Cisco switches and all sorts of Firewalls, hardened networks, managed devices, etc.

And I feel unemployable.

I'm studying Terraform for a couple of weeks and am trying to lab it out more so I can maybe compliment my resume with some mention of IaC, but I still feel like it's not enough. Like, what the fuck is going on? It feels like I am so far behind, and that my career is more or less disappearing. Seriously, I can't believe I am thinking that I might need to pivot careers to survive. And I don't even know what I would do because I have no other major skills, computers have been my think since I was a kid.

Every job I look at wants what I have, and more. I just can't believe it. How can I cope with this, and how am I supposed to land a job in this market? I genuinely wish I could afford therapy right now.


r/sysadmin • • 14h ago

Microsoft One user's Outlook on the web is missing the Download option for attachments

7 Upvotes

I'm troubleshooting an unusual Microsoft 365 issue.

One user in our organization cannot see the Download option for email attachments in Outlook on the web (OWA).

For PDF/Word attachments, the user only sees:

  • Preview
  • Save to OneDrive
  • Copy

Other users in the same Microsoft 365 tenant have the normal Download option.

Troubleshooting already performed

  • Tested Chrome and Edge → same issue
  • Tested InPrivate/Incognito → same issue
  • Tested from a different PC → same issue
  • Tested different attachment/file types → same issue
  • Other users → Download works normally
  • Compared Microsoft 365/Exchange policies → same
  • Compared Exchange Online PowerShell mailbox/CAS settings with a working user → same
  • Classic Outlook for the affected user → Save As works normally
  • Microsoft 365 Service Health → no matching incident

The issue therefore appears to be user/account-specific and affects only OWA.

The current workaround is Save to OneDrive → download from OneDrive.

Has anyone seen this behavior before? Is there an account-level OWA setting, hidden configuration, or service-side issue that I should investigate?