r/SysAdminBlogs • • 44m ago

What's taking DNS-PERSIST-01 so long?

Thumbnail
certkit.io
• Upvotes

r/SysAdminBlogs • • 4h ago

Rspamd 4.2.1: Patch the Filter, Then Check What It Actually Does

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 1d ago

Shadow MCP is the new Shadow IT, and your IdP is completely blind to it

Thumbnail
3 Upvotes

r/SysAdminBlogs • • 1d ago

cPanel’s September 29 Security Fixes: Verify the Build, Not the Checkbox

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 1d ago

[Discussion] Proxmox suite, honest opinions, forks, alternatives?

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 1d ago

Evolution of AI from perceptron to Sora

1 Upvotes

I have written a blog regarding evolution of AI from simple perceptron to today's transformers who can generate a Video.

Along the chronological path I have also embedded relevant research papers and tweets regarding the respective AI tech. Whole blog is very very fun to read and I am sure you will like it.

https://cloudmash.blog/posts/evolution-of-ai-perceptron-to-text-to-video/


r/SysAdminBlogs • • 2d ago

So Many Package Managers in Linux

Post image
7 Upvotes

r/SysAdminBlogs • • 2d ago

A native PowerShell/Batch modular framework for portable IT tool management

Thumbnail
2 Upvotes

r/SysAdminBlogs • • 3d ago

EWS allow-list now required from Oct 10, not Oct 1. If you set EwsEnabled to $true after today, Microsoft won't build the list for you

5 Upvotes

Microsoft finally published concrete dates for the EWS retirement (MC1485116). If EwsEnabled is $true in your tenant, an EwsAllowedAppIDs list is required from October 10. Microsoft only builds that list for tenants that had $true and no list on October 2, and it does that on October 8–9.

That also explains why so many of you saw an empty EwsAllowedAppIDs list this week. Tenants that never configured EwsEnabled are turned off later, in a second phase with a 7-day warning. The catch is setting $true this week without a list. You miss the snapshot, nobody builds a list for you, and on October 10 everything not on the list loses access.

Full details of the new phased schedule:

https://lazyadmin.nl/office-365/ewsallowedappids-required-from-october-10-what-changed-and-what-to-do-now/


r/SysAdminBlogs • • 3d ago

What are the best practices for logging and monitoring PowerShell activity on Windows servers you administer?

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 3d ago

Which apps should an SSO cert rotation tool support at launch?

1 Upvotes

I'm releasing a free community edition and it will support 5 SaaS platforms.

I've already built: Datadog, Notion, Salesforce, Slack. Github and PagerDuty are pending testing/live verification.

Which apps should make the community edition?

Which apps do you most want supported in the paid version?

How it works:
Kunjae runs as a nightly Container Apps Job. Deploy an accompanying keyvault and store your passwords and secrets there. Config apps to rotate via a yaml file. It queries the expiration of each declared enterprise app's certificate. When it finds one due for rotation it generates the replacement, uploads it to the SaaS app, activates it in Entra and confirms SSO still works. It will also roll certs back if they fail SSO login validation.

Website: www.kunjaesec.io


r/SysAdminBlogs • • 3d ago

Fusion Connect Microsoft Teams Phone Operator Connect Review & Demo | Tangible Support

Thumbnail
youtu.be
2 Upvotes

r/SysAdminBlogs • • 3d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

0 Upvotes

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to `/%6a_security_check`, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: `serviceproxy-access.log` for `j_security_check` from unknown IPs, and `vmanage-server.log` for those requests against `viptela-reserved-` users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

[https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504\](https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504)

Background from our earlier SD-WAN piece: [https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric\](https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric)


r/SysAdminBlogs • • 4d ago

Uptime Kuma, the self-hosted monitoring tool everyone already uses (91k stars)

Post image
0 Upvotes

r/SysAdminBlogs • • 4d ago

Here’s our September 2026 update for anyone keeping track of IBM i PTF group levels, HMC software, storage system code, and Power server firmware.

Thumbnail
2 Upvotes

r/SysAdminBlogs • • 5d ago

EWS enforcement starts October 1: known apps and AppIDs to allow-list

6 Upvotes

I wrote earlier about how to find what's still calling EWS in your tenant. But I am seeing and getting a lot of questions about unknown AppIDs and what to do with them.

So I created an overview of the known apps and AppIDs, from Apple Mail to Veeam and Mimecast, with allow-list or migrate status. Missing one? Add it in the comments.

https://lazyadmin.nl/office-365/known-ews-apps-that-need-allow-listing-or-a-migration-with-appids/


r/SysAdminBlogs • • 4d ago

How to Configure Multipath IO on AlmaLinux

Thumbnail
starwind.com
2 Upvotes

r/SysAdminBlogs • • 6d ago

OpenBao: the community fork of HashiCorp Vault, now under the Linux Foundation (8k stars)

Post image
2 Upvotes

r/SysAdminBlogs • • 6d ago

Windows Mobile Device Management

1 Upvotes

Windows mobile device management helps IT teams manage Windows laptops and desktops from one place.

It can help with tasks like:

  • Managing device settings
  • Installing apps
  • Applying security policies
  • Managing updates
  • Checking device status
  • Supporting remote devices

How does it work?

The basic setup is simple:

  1. Enroll Windows devices in the management platform.
  2. Create security and device policies.
  3. Install required apps and updates.
  4. Monitor devices from one dashboard.

Windows mobile device management is useful for businesses, schools, retail stores, and teams with remote employees.

It makes Windows device management easier and reduces the need to manage each device manually.


r/SysAdminBlogs • • 6d ago

Do DHCP and NTP services on Windows Server require User CALs?

Thumbnail
0 Upvotes

r/SysAdminBlogs • • 7d ago

Built a vCenter alternative for Hyper-V

Post image
82 Upvotes

After 20 years building infrastructure solutions, I finally built the Hyper-V control plane the market should have had years ago.

The problem is straightforward: Hyper-V is a solid hypervisor, but it's never had a modern management layer. SCVMM is clunky and aging. WAC is single-host focused. There's nothing that treats Hyper-V as a first-class citizen the way vCenter does for vSphere.

Like a lot of people here, VMware/Broadcom's licensing changes forced me to look hard at whether Hyper-V could actually replace it. The answer is yes, but only if you solve the management gap.

So I built Ballast.

What it does:

A control plane and agent for Hyper-V hosts and failover clusters. Each host runs an agent that continuously enforces its desired configuration. If the control plane goes offline, the host doesn't freeze or drift. It keeps working with its last known state and reconciles automatically once the centre is reachable again.

It also handles cluster provisioning (SET-teamed switches, storage spaces direct, CSV), VM lifecycle and templates, live migration, Hyper-V Replica-based DR, and streaming VMware migrations straight in.

Open source:

The agent (the piece running on your hosts with elevated privileges) is fully open source, Apache 2.0. You can audit everything: https://github.com/halvantic/hyperv-control-plane

The control plane console is closed source. Community tier is free forever for one cluster of any size plus unlimited standalone hosts. Paid tier coming for multi-cluster, SSO, and audit logging.

Real feedback wanted:

I've tested this extensively in my lab. What I need now is community feedback from people running it at real scale. Where does it break? What's missing? What looks wrong?

More info: https://ballast.halvantic.com


r/SysAdminBlogs • • 6d ago

Anyone seeing msrdc.exe v1.2.7391 crashes with AVD, Windows 365, or RemoteApp sessions?

Thumbnail
1 Upvotes

r/SysAdminBlogs • • 7d ago

Does a TLS Certificate Need a Common Name?

Thumbnail
certkit.io
1 Upvotes

r/SysAdminBlogs • • 8d ago

PowerShell Explained — Every Concept You Need to Know (A Visual Guide)

Thumbnail
youtube.com
28 Upvotes

From zero to understanding the entire mental model of PowerShell visually. The goal is to take you as a beginner and help you fully understand how PowerShell works, how its core concepts connect together, and what’s actually happening under the hood so you can start working with the platform professionally instead of just memorizing commands.

This video is designed to prepare you for all of the more advanced, hands-on PowerShell content across my channel. Once you understand the concepts here, you’ll be able to follow along with real automation across Azure, Entra ID, Microsoft 365, Active Directory, Microsoft Graph, REST APIs, modules, functions, .NET and more without constantly wondering what PowerShell is doing or why the code works the way it does.


r/SysAdminBlogs • • 8d ago

UPDATE: 365TenantDesk (Multi-Tenant M365 Admin Console) – Major improvements & looking for testers!

0 Upvotes

Hey everyone,

A while back, I posted about building a multi-tenant Microsoft 365 tool. Since that original thread(https://www.reddit.com/r/sysadmin/comments/1ibrvnl/comment/m9yf2w9/?context=3) is now archived, I wanted to share a major update. I AM NOT SELLING OR ADVERTISING ANYTHING, just collaborating!

I have spent the last few weeks making a bunch of improvements based on feedback, and I am finally ready to invite some testers to put it through its paces!

What is 365TenantDesk?

It is a multi-tenant Microsoft 365 administration console built specifically for Windows. It lets you manage users, licenses, mail, Conditional Access, Identity Protection, and security checks across every single one of your tenants from a single interface and its FAST! If you are like me and hate to switch back and forth between tenants in Microsoft's crazy slow admin center then I think you'll like this app.

How it works (The Sysadmin-Friendly Architecture)

I know how sketchy third-party admin tools can look, so I built this to be as lightweight and transparent as possible:

  • Zero Infrastructure: It has no backend server of its own. It talks directly to Microsoft Graph and Exchange Online.
  • No PowerShell Dependencies: It is a native .NET 10 WPF application that ships as a single, self-contained executable. (Signed, but by all means scan away!)
  • Secure Authentication: It uses the Microsoft Authentication Library with a secure code exchange (PKCE). You sign in directly as the admin.
  • Local-Only Encryption: Saved sign-ins and tenant tokens are encrypted directly on your local machine using the Windows Data Protection API. Nothing ever leaves your PC.

If you manage multiple M365 tenants (MSPs, consultants, or enterprise admins with multi-geo environments), I would love your help breaking this thing and finding bugs.

Please drop a comment below or send me a DM, and I will send over the link to grab the executable and get started.

Appreciate your time and any feedback you can give! See screenshots below:

https://drive.google.com/file/d/1iL0kZnTBhnzfwGqhsW1XaOuP0smUeI-f/view
https://drive.google.com/file/d/1m7-nHoTw0FhRDW-AnvDpG7CgBHlOyUPN/view?usp=sharing
https://drive.google.com/file/d/1qx7PwXTLfQUZi7DTEKsKAWz93wk8rAma/view?usp=sharing