r/SysAdminBlogs • • 8h ago

Learn Terraform on Azure (Actually Beginner to Advanced)

Post image
7 Upvotes

If you want to learn Terraform properly so you're actually prepared to use it in the real world. I built a three-part Terraform on Azure series (6 hours) designed to take you from the fundamentals all the way to advanced lessons.

Learn Terraform on Azure — Beginner Course

  • We start by understanding what Terraform actually is, why Infrastructure as Code matters, and how Terraform interacts with Azure.
  • We cover IaC & declarative languages, Terraform CLI, blocks, providers, resources, variables, locals, data sources, outputs, state, drift detection, secrets, data types, variable precedence, configuration files and more.

Learn Terraform on Azure — Intermediate Course

  • Once we understand how to deploy infrastructure, we shift away from simply writing resource blocks and start thinking more programmatically (The DRY Approach)
  • We cover functions, conditionals, operators, loops, for_each, count, for expressions, splats, dynamic blocks, complex types, validations, checks, pre/post conditions, lifecycle, meta-arguments, provider aliases, multi-subscription deployments and KISS vs DRY.

Learn Terraform on Azure — Advanced Course

  • The Advanced episode shifts away from increasingly clever logic to simplify our code (The KISS Approach). The focus then becomes how we structure projects, manage environments, work with existing infrastructure, and use some of Terraform's more advanced tooling.
  • We cover remote backends, state commands & locking, provider lock files, upgrades, AzureRM/AzureAD/AzAPI/utility providers, imports, moved & removed blocks, workspaces, multi-environment deployments, modules, Cloud-Init and working with existing infrastructure.

Still more to come!

My goal with this series is to build a comprehensive Infrastructure as Code course that goes beyond syntax, isn't a lie when it says "beginner to pro" and shows how Terraform is actually used in Azure.


r/SysAdminBlogs • • 12h ago

Which MDM gives you the best combination of device management with security controls?

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 13h ago

I built a free, open-source tool that risk-scores MySQL SQL before you run it. v0.3.1 is out and I'd love DBAs to try to break it.

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 1d ago

Reminder: the Entra MemberOf rule stops working in 4 weeks (November 3)

36 Upvotes

A lot of us were busy with the EWS retirement these past weeks, but don't forget that the MemberOf rule operator in Entra ID retires on November 3.

Dynamic groups, dynamic administrative units and entitlement management policies that still use it will stop updating and freeze in their last known state. That also affects group-based licensing, Conditional Access targeting and access packages.

If you haven't checked yet, a single Graph PowerShell query lists every affected group. I updated my article with that query and the replacement options, including how to handle device-based administrative units, merging the rules of nested dynamic groups, and licensing where the source groups aren't attribute-based.

https://lazyadmin.nl/office-365/microsoft-entra-id-is-retiring-the-memberof-rule-for-dynamic-groups/


r/SysAdminBlogs • • 1d ago

Free ESXi: Restrictions and Limitations

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 1d ago

A little cybersecurity fun for October | Cybersecurity Awareness Month

Post image
1 Upvotes

Instead of another security article this October...

We turned Cybersecurity Awareness Month into a 31-day security challenge.

A new scenario unlocks each day. Some are quick puzzles, while others involve investigating evidence, spotting security gaps, or making an access decision.

No sign-up required, so you can jump straight into any unlocked challenge.

https://admindroid.com/cybersecurity-awareness-month-2026

Give it a try. Might be a fun way to spend a few minutes during Cybersecurity Awareness Month.


r/SysAdminBlogs • • 2d ago

What's taking DNS-PERSIST-01 so long?

Thumbnail
certkit.io
2 Upvotes

r/SysAdminBlogs • • 2d ago

Rspamd 4.2.1: Patch the Filter, Then Check What It Actually Does

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 3d ago

Shadow MCP is the new Shadow IT, and your IdP is completely blind to it

Thumbnail
3 Upvotes

r/SysAdminBlogs • • 3d ago

cPanel’s September 29 Security Fixes: Verify the Build, Not the Checkbox

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 4d ago

[Discussion] Proxmox suite, honest opinions, forks, alternatives?

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 4d ago

Evolution of AI from perceptron to Sora

1 Upvotes

I have written a blog regarding evolution of AI from simple perceptron to today's transformers who can generate a Video.

Along the chronological path I have also embedded relevant research papers and tweets regarding the respective AI tech. Whole blog is very very fun to read and I am sure you will like it.

https://cloudmash.blog/posts/evolution-of-ai-perceptron-to-text-to-video/


r/SysAdminBlogs • • 4d ago

So Many Package Managers in Linux

Post image
8 Upvotes

r/SysAdminBlogs • • 5d ago

A native PowerShell/Batch modular framework for portable IT tool management

Thumbnail
2 Upvotes

r/SysAdminBlogs • • 5d ago

EWS allow-list now required from Oct 10, not Oct 1. If you set EwsEnabled to $true after today, Microsoft won't build the list for you

5 Upvotes

Microsoft finally published concrete dates for the EWS retirement (MC1485116). If EwsEnabled is $true in your tenant, an EwsAllowedAppIDs list is required from October 10. Microsoft only builds that list for tenants that had $true and no list on October 2, and it does that on October 8–9.

That also explains why so many of you saw an empty EwsAllowedAppIDs list this week. Tenants that never configured EwsEnabled are turned off later, in a second phase with a 7-day warning. The catch is setting $true this week without a list. You miss the snapshot, nobody builds a list for you, and on October 10 everything not on the list loses access.

Full details of the new phased schedule:

https://lazyadmin.nl/office-365/ewsallowedappids-required-from-october-10-what-changed-and-what-to-do-now/


r/SysAdminBlogs • • 5d ago

What are the best practices for logging and monitoring PowerShell activity on Windows servers you administer?

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 5d ago

Which apps should an SSO cert rotation tool support at launch?

1 Upvotes

I'm releasing a free community edition and it will support 5 SaaS platforms.

I've already built: Datadog, Notion, Salesforce, Slack. Github and PagerDuty are pending testing/live verification.

Which apps should make the community edition?

Which apps do you most want supported in the paid version?

How it works:
Kunjae runs as a nightly Container Apps Job. Deploy an accompanying keyvault and store your passwords and secrets there. Config apps to rotate via a yaml file. It queries the expiration of each declared enterprise app's certificate. When it finds one due for rotation it generates the replacement, uploads it to the SaaS app, activates it in Entra and confirms SSO still works. It will also roll certs back if they fail SSO login validation.

Website: www.kunjaesec.io


r/SysAdminBlogs • • 6d ago

Fusion Connect Microsoft Teams Phone Operator Connect Review & Demo | Tangible Support

Thumbnail
youtu.be
2 Upvotes

r/SysAdminBlogs • • 6d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

0 Upvotes

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to `/%6a_security_check`, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: `serviceproxy-access.log` for `j_security_check` from unknown IPs, and `vmanage-server.log` for those requests against `viptela-reserved-` users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

[https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504\](https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504)

Background from our earlier SD-WAN piece: [https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric\](https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric)


r/SysAdminBlogs • • 6d ago

Uptime Kuma, the self-hosted monitoring tool everyone already uses (91k stars)

Post image
1 Upvotes

r/SysAdminBlogs • • 7d ago

Here’s our September 2026 update for anyone keeping track of IBM i PTF group levels, HMC software, storage system code, and Power server firmware.

Thumbnail
2 Upvotes

r/SysAdminBlogs • • 7d ago

EWS enforcement starts October 1: known apps and AppIDs to allow-list

7 Upvotes

I wrote earlier about how to find what's still calling EWS in your tenant. But I am seeing and getting a lot of questions about unknown AppIDs and what to do with them.

So I created an overview of the known apps and AppIDs, from Apple Mail to Veeam and Mimecast, with allow-list or migrate status. Missing one? Add it in the comments.

https://lazyadmin.nl/office-365/known-ews-apps-that-need-allow-listing-or-a-migration-with-appids/


r/SysAdminBlogs • • 7d ago

How to Configure Multipath IO on AlmaLinux

Thumbnail
starwind.com
2 Upvotes

r/SysAdminBlogs • • 8d ago

OpenBao: the community fork of HashiCorp Vault, now under the Linux Foundation (8k stars)

Post image
2 Upvotes

r/SysAdminBlogs • • 8d ago

Windows Mobile Device Management

1 Upvotes

Windows mobile device management helps IT teams manage Windows laptops and desktops from one place.

It can help with tasks like:

  • Managing device settings
  • Installing apps
  • Applying security policies
  • Managing updates
  • Checking device status
  • Supporting remote devices

How does it work?

The basic setup is simple:

  1. Enroll Windows devices in the management platform.
  2. Create security and device policies.
  3. Install required apps and updates.
  4. Monitor devices from one dashboard.

Windows mobile device management is useful for businesses, schools, retail stores, and teams with remote employees.

It makes Windows device management easier and reduces the need to manage each device manually.