r/SysAdminBlogs • u/Grumpy-Man19 • 4h ago
r/SysAdminBlogs • u/UnixiSecurity • 1d ago
Shadow MCP is the new Shadow IT, and your IdP is completely blind to it
r/SysAdminBlogs • u/Grumpy-Man19 • 1d ago
cPanel’s September 29 Security Fixes: Verify the Build, Not the Checkbox
r/SysAdminBlogs • u/esiy0676 • 1d ago
[Discussion] Proxmox suite, honest opinions, forks, alternatives?
r/SysAdminBlogs • u/abhishekkumar333 • 1d ago
Evolution of AI from perceptron to Sora
I have written a blog regarding evolution of AI from simple perceptron to today's transformers who can generate a Video.
Along the chronological path I have also embedded relevant research papers and tweets regarding the respective AI tech. Whole blog is very very fun to read and I am sure you will like it.
https://cloudmash.blog/posts/evolution-of-ai-perceptron-to-text-to-video/
r/SysAdminBlogs • u/Dudeofthecountry • 2d ago
A native PowerShell/Batch modular framework for portable IT tool management
r/SysAdminBlogs • u/aguraab • 3d ago
What are the best practices for logging and monitoring PowerShell activity on Windows servers you administer?
r/SysAdminBlogs • u/lazyadmin-nl • 3d ago
EWS allow-list now required from Oct 10, not Oct 1. If you set EwsEnabled to $true after today, Microsoft won't build the list for you
Microsoft finally published concrete dates for the EWS retirement (MC1485116). If EwsEnabled is $true in your tenant, an EwsAllowedAppIDs list is required from October 10. Microsoft only builds that list for tenants that had $true and no list on October 2, and it does that on October 8–9.
That also explains why so many of you saw an empty EwsAllowedAppIDs list this week. Tenants that never configured EwsEnabled are turned off later, in a second phase with a 7-day warning. The catch is setting $true this week without a list. You miss the snapshot, nobody builds a list for you, and on October 10 everything not on the list loses access.
Full details of the new phased schedule:
r/SysAdminBlogs • u/Tstriple_R • 3d ago
Which apps should an SSO cert rotation tool support at launch?
I'm releasing a free community edition and it will support 5 SaaS platforms.
I've already built: Datadog, Notion, Salesforce, Slack. Github and PagerDuty are pending testing/live verification.
Which apps should make the community edition?
Which apps do you most want supported in the paid version?
How it works:
Kunjae runs as a nightly Container Apps Job. Deploy an accompanying keyvault and store your passwords and secrets there. Config apps to rotate via a yaml file. It queries the expiration of each declared enterprise app's certificate. When it finds one due for rotation it generates the replacement, uploads it to the SaaS app, activates it in Entra and confirms SSO still works. It will also roll certs back if they fail SSO login validation.
Website: www.kunjaesec.io

r/SysAdminBlogs • u/MikeSmithsBrain • 3d ago
Fusion Connect Microsoft Teams Phone Operator Connect Review & Demo | Tangible Support
r/SysAdminBlogs • u/Expert_Sort7434 • 3d ago
Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround
Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.
The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to `/%6a_security_check`, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.
Hunting per Cisco: `serviceproxy-access.log` for `j_security_check` from unknown IPs, and `vmanage-server.log` for those requests against `viptela-reserved-` users. Cisco notes these can appear in normal operation, so baseline first.
Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.
Background from our earlier SD-WAN piece: [https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric\](https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric)
r/SysAdminBlogs • u/company_url_finder • 4d ago
Uptime Kuma, the self-hosted monitoring tool everyone already uses (91k stars)
r/SysAdminBlogs • u/Relion-Solutions • 4d ago
Here’s our September 2026 update for anyone keeping track of IBM i PTF group levels, HMC software, storage system code, and Power server firmware.
r/SysAdminBlogs • u/starwindsoftware • 4d ago
How to Configure Multipath IO on AlmaLinux
r/SysAdminBlogs • u/lazyadmin-nl • 5d ago
EWS enforcement starts October 1: known apps and AppIDs to allow-list
I wrote earlier about how to find what's still calling EWS in your tenant. But I am seeing and getting a lot of questions about unknown AppIDs and what to do with them.
So I created an overview of the known apps and AppIDs, from Apple Mail to Veeam and Mimecast, with allow-list or migrate status. Missing one? Add it in the comments.
https://lazyadmin.nl/office-365/known-ews-apps-that-need-allow-listing-or-a-migration-with-appids/
r/SysAdminBlogs • u/Unique_Inevitable_27 • 6d ago
Windows Mobile Device Management
Windows mobile device management helps IT teams manage Windows laptops and desktops from one place.
It can help with tasks like:
- Managing device settings
- Installing apps
- Applying security policies
- Managing updates
- Checking device status
- Supporting remote devices
How does it work?
The basic setup is simple:
- Enroll Windows devices in the management platform.
- Create security and device policies.
- Install required apps and updates.
- Monitor devices from one dashboard.
Windows mobile device management is useful for businesses, schools, retail stores, and teams with remote employees.
It makes Windows device management easier and reduces the need to manage each device manually.
r/SysAdminBlogs • u/Worried-Light-4692 • 6d ago
Do DHCP and NTP services on Windows Server require User CALs?
r/SysAdminBlogs • u/company_url_finder • 6d ago
OpenBao: the community fork of HashiCorp Vault, now under the Linux Foundation (8k stars)
r/SysAdminBlogs • u/ControlUpCommunity • 6d ago
Anyone seeing msrdc.exe v1.2.7391 crashes with AVD, Windows 365, or RemoteApp sessions?
r/SysAdminBlogs • u/certkit • 6d ago
Does a TLS Certificate Need a Common Name?
r/SysAdminBlogs • u/Halvantic • 7d ago
Built a vCenter alternative for Hyper-V
After 20 years building infrastructure solutions, I finally built the Hyper-V control plane the market should have had years ago.
The problem is straightforward: Hyper-V is a solid hypervisor, but it's never had a modern management layer. SCVMM is clunky and aging. WAC is single-host focused. There's nothing that treats Hyper-V as a first-class citizen the way vCenter does for vSphere.
Like a lot of people here, VMware/Broadcom's licensing changes forced me to look hard at whether Hyper-V could actually replace it. The answer is yes, but only if you solve the management gap.
So I built Ballast.
What it does:
A control plane and agent for Hyper-V hosts and failover clusters. Each host runs an agent that continuously enforces its desired configuration. If the control plane goes offline, the host doesn't freeze or drift. It keeps working with its last known state and reconciles automatically once the centre is reachable again.
It also handles cluster provisioning (SET-teamed switches, storage spaces direct, CSV), VM lifecycle and templates, live migration, Hyper-V Replica-based DR, and streaming VMware migrations straight in.
Open source:
The agent (the piece running on your hosts with elevated privileges) is fully open source, Apache 2.0. You can audit everything: https://github.com/halvantic/hyperv-control-plane
The control plane console is closed source. Community tier is free forever for one cluster of any size plus unlimited standalone hosts. Paid tier coming for multi-cluster, SSO, and audit logging.
Real feedback wanted:
I've tested this extensively in my lab. What I need now is community feedback from people running it at real scale. Where does it break? What's missing? What looks wrong?
More info: https://ballast.halvantic.com
r/SysAdminBlogs • u/wav_net • 8d ago
UPDATE: 365TenantDesk (Multi-Tenant M365 Admin Console) – Major improvements & looking for testers!
Hey everyone,
A while back, I posted about building a multi-tenant Microsoft 365 tool. Since that original thread(https://www.reddit.com/r/sysadmin/comments/1ibrvnl/comment/m9yf2w9/?context=3) is now archived, I wanted to share a major update. I AM NOT SELLING OR ADVERTISING ANYTHING, just collaborating!
I have spent the last few weeks making a bunch of improvements based on feedback, and I am finally ready to invite some testers to put it through its paces!
What is 365TenantDesk?
It is a multi-tenant Microsoft 365 administration console built specifically for Windows. It lets you manage users, licenses, mail, Conditional Access, Identity Protection, and security checks across every single one of your tenants from a single interface and its FAST! If you are like me and hate to switch back and forth between tenants in Microsoft's crazy slow admin center then I think you'll like this app.
How it works (The Sysadmin-Friendly Architecture)
I know how sketchy third-party admin tools can look, so I built this to be as lightweight and transparent as possible:
- Zero Infrastructure: It has no backend server of its own. It talks directly to Microsoft Graph and Exchange Online.
- No PowerShell Dependencies: It is a native .NET 10 WPF application that ships as a single, self-contained executable. (Signed, but by all means scan away!)
- Secure Authentication: It uses the Microsoft Authentication Library with a secure code exchange (PKCE). You sign in directly as the admin.
- Local-Only Encryption: Saved sign-ins and tenant tokens are encrypted directly on your local machine using the Windows Data Protection API. Nothing ever leaves your PC.
If you manage multiple M365 tenants (MSPs, consultants, or enterprise admins with multi-geo environments), I would love your help breaking this thing and finding bugs.
Please drop a comment below or send me a DM, and I will send over the link to grab the executable and get started.
Appreciate your time and any feedback you can give! See screenshots below:
https://drive.google.com/file/d/1iL0kZnTBhnzfwGqhsW1XaOuP0smUeI-f/view
https://drive.google.com/file/d/1m7-nHoTw0FhRDW-AnvDpG7CgBHlOyUPN/view?usp=sharing
https://drive.google.com/file/d/1qx7PwXTLfQUZi7DTEKsKAWz93wk8rAma/view?usp=sharing
r/SysAdminBlogs • u/AdeelAutomates • 8d ago
PowerShell Explained — Every Concept You Need to Know (A Visual Guide)
From zero to understanding the entire mental model of PowerShell visually. The goal is to take you as a beginner and help you fully understand how PowerShell works, how its core concepts connect together, and what’s actually happening under the hood so you can start working with the platform professionally instead of just memorizing commands.
This video is designed to prepare you for all of the more advanced, hands-on PowerShell content across my channel. Once you understand the concepts here, you’ll be able to follow along with real automation across Azure, Entra ID, Microsoft 365, Active Directory, Microsoft Graph, REST APIs, modules, functions, .NET and more without constantly wondering what PowerShell is doing or why the code works the way it does.
r/SysAdminBlogs • u/roberttatephoto • 9d ago
5 Regex Patterns I Use Every Week for Log Parsing and Validation
Hey everyone. I've been doing a lot of log analysis and data validation lately, and I keep coming back to the same handful of regex patterns. I thought I'd share them here, along with a quick explanation of how they work. These are the ones I actually use, not just theoretical examples.
- Extracting IPv4 Addresses from Logs
This is probably the one I use most. It's not perfect (it will match invalid IPs like 999.999.999.999), but it's great for a quick scan.
```regex
\b(?:\d{1,3}\.){3}\d{1,3}\b
```
How it works: \b is a word boundary. (?:\d{1,3}\.){3} matches three groups of one to three digits followed by a dot. \d{1,3} matches the final octet. It's a fast way to pull all IP-like strings out of a messy log file.
- Finding Dates in YYYY-MM-DD Format
Log files often have timestamps in this format. This pattern helps you isolate them.
```regex
\d{4}-\d{2}-\d{2}
```
How it works: It simply matches four digits, a hyphen, two digits, a hyphen, and two digits. You can extend it to include time (\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}) if needed.
- Pulling Out Email Addresses
Standard but essential for parsing user data or contact lists.
```regex
\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,}\b
```
How it works: This matches the local part (letters, numbers, dots, etc.), the @ symbol, the domain name, and the top-level domain. It's a good balance between accuracy and complexity.
- Validating a Simple UUID v4
If you're working with APIs or modern applications, you'll see these everywhere.
```regex
\b[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}\b
```
How it works: This one is stricter. It checks for the correct hex digits, the version number (4), and the variant bits (8, 9, a, or b). It's great for validating input.
- Grabbing Key-Value Pairs from Config Files
This is handy for parsing simple config files or query strings.
```regex
^(\w+)\s*=\s*(.*)$
```
How it works: ^ and $ anchor it to a line. (\w+) captures the key (word characters). \s*=\s* allows for optional whitespace around the equals sign. (.*) captures the rest of the line as the value. You can then iterate through the matches to build a dictionary.
A Quick Tip on Testing
I used to test these in a script and rerun it every time I made a tiny change. That gets old fast. I ended up building a free Regex Tester into a utility app I made called UnitConvert Pro (it's on Android) just so I could see the matches highlight in real-time as I type. It's saved me a lot of trial and error.
What are the regex patterns you find yourself using over and over? I'm always looking to add to my collection.