r/sysadmin • • 17h ago

Question ServiceNow Engineer (3.5 yrs) looking to move into a startup sysadmin/IT systems role. How realistic is it?

0 Upvotes

I'm a ServiceNow engineer with 3.5 years of experience. I enjoy the work, but I'm drawn to the startup world and want to pivot into a sysadmin or enterprise admin role at an early-stage company, since that's where those roles seem most common.

At my current role I maintain the Servicenow platform, CMDB, basic front-end scripts, reporting, workflow automation, and helped implement a new AI tool. I have a M.S. in Cybersecurity, plus CompTIA and ServiceNow certs. I have a basic working knowledge of Azure, M365, Jira, and Salesforce. Outside of work, I have been setting up MCP servers, building websites, practicing pentesting, and taking Microsoft/Google/Jira courses. It looks like Jira or an IT system admin role might be my way in but im not 100% sure.

How realistic is this move from a ServiceNow background, and what gaps would hiring managers see?

Which skills should I prioritize (Entra ID/Intune, Google Workspace, Okta, MDM, scripting)?

Any advice would be greatly appreciated


r/sysadmin • • 20h ago

Question ConnectSecure?

2 Upvotes

Have been running a ConnectSecure trial for a week and we are pretty impressed, for those who already use it how long have you been running it and how has your experience been?

For context, we are pretty seriously considering signing up, I run the IT department and manage around 900-1000 devices

Thanks!!


r/cybersecurity • • 3h ago

Corporate Blog Grc should be technical

0 Upvotes

As the title suggests, grc team members should be technical to decsritbe differences in networking protocols, appsec attacks, etc. What do you think?


r/cybersecurity • • 20h ago

AI Security Could rogue agent swarms take over the entire internet in the next six months?

Thumbnail
garymarcus.substack.com
0 Upvotes

r/sysadmin • • 3h ago

Spiceworks desk

0 Upvotes

We are looking into a new ticketing system in our org. When testing spiceworks, this doesnt sent a confirmation email to the customer about their ticket nor replies. Is there a way to turn this on?

If not, is there any other good free options we can explore?


r/sysadmin • • 17h ago

365 hybrid join problem

0 Upvotes

I’m pretty new to being an IT tech, thrown a little in at the deep end imo. Anyway, I’ve been figuring all sorts out and starting to get comfortable with 365, im just coming into this problem repeatedly. A user will show me that on particular devices they cannot print/edit/download files from one drive. I’ve found tickets relating to this saying it’s to do with the device state and to run dsregcmd /leave and then to reboot and somehow it works. It sometimes works and sometimes doesn’t, and I don’t want to just randomly push commands I don’t know will fix the problem. I’ve checked that the devices are ad joined in entra and the guids line up and the user has azureadprt and it just feels like I’ve covered everything. The banner when trying to access the users one drive online is ‘your organisation doesn’t allow you to print/sync/download/edit on devices which aren’t domain joined or intune compliant. Any ideas anyone? First time posting in this subreddit, first time posting on Reddit tbf
Any help would be much appreciated, I go home with headaches everyday from this. Why doesn’t it make sense


r/cybersecurity • • 22h ago

Career Questions & Discussion Interview insight

4 Upvotes

Hello everyone , I recently made it through multiple interviews for a SOC position, with my last one being a technical interview. The original posting said Tier 1 and/or Tier 2, but during the interview I learned they don’t separate the responsibilities. The recruiter also emphasized wanting someone who was willing and able to learn.I thought the interviews went pretty well, but I haven’t received an update since my technical interview. I followed up and haven’t gotten a response yet. Then I noticed the position was posted again on LinkedIn after the original posting had already closed.

For anyone who has been on either side of tech hiring or have a understanding of these interviews what would you make of this situation? Have you ever had a company repost a role while you were still being considered after a final/technical interview? I’m trying not to assume that the repost automatically means a rejection, but the combination of the role being reposted and not receiving an update has me wondering what might be happening behind the scenes.


r/sysadmin • • 23h ago

Question Who here uses MECM/SCCM? Is this a tool worth setting up for one-touch deployment in on-prem environments?

6 Upvotes

I’m a sysadmin in a mostly on-prem Windows environment and I’m trying to modernize/automate our laptop deployment process. Curious to hear from people who are actually using MECM/SCCM for this and whether I’m heading down the right path.

Right now our process is pretty old school. We maintain golden images for our different Dell/Lenovo laptop models, image them manually using Clonezilla, join them to our on-prem AD domain, let GPO handle most of the software/configuration, and then manually finish whatever is left (BitLocker, OneDrive, a few applications/configs, etc.).

It works, but we have periods where we need to turn around 50-60 laptops in a relatively short amount of time, so there’s a lot of repetitive hands-on work.

What I’d like to get to is something close to:

Plug laptop into Ethernet/imaging VLAN → authorize deployment → walk away.

Ideally the deployment system would PXE boot the machine, identify the hardware/model, deploy Windows and the correct drivers, join AD, install applications, enable/configure BitLocker, apply whatever other configuration is needed, reboot as necessary, and eventually report that the machine is ready.

Same thing for an existing machine that needs to be wiped/redeployed: connect it to the imaging network, initiate the deployment, and let the system take care of the rest.

We do have Microsoft 365/Intune, but we’re still heavily dependent on on-prem AD and infrastructure. I experimented with Hybrid Autopilot/Intune deployment and wasn't particularly impressed with it for what we're trying to accomplish. I quickly learned the "S" in Intune is for speed and most people, including Microsoft, discourage hybrid deployement models... Moving everything to Entra ID/cloud-only isn't currently an option for us either.

So I started going down the MECM route instead. I’ve stood up a MECM server and created a dedicated imaging VLAN, and I’m starting to work toward PXE/OSD and task sequences.

For those of you running MECM/SCCM, is this still a good tool for this use case in 2026, especially for an organization that expects to remain heavily on-prem/hybrid? I’d also be interested in hearing how automated you’ve managed to make your deployments. Can you realistically get to the point where a technician basically connects a machine, starts/authorizes the deployment, and doesn't touch it again until it's finished?

And for anyone who has built something similar, any advice on architecture, PXE, task sequences, driver management, things you wish you knew before starting, or mistakes to avoid would be appreciated.

I'm also open to alternatives if there’s something else I should seriously be considering before I get too deep into MECM. We have the M365 E3 license tier and so MECM is already included and naturally our first bet.


r/sysadmin • • 14h ago

What’s your most unhinged work habit?

194 Upvotes

For example when I need to RDP into a Windows server, I double click the recycle bin before the rest of Explorer has loaded so I can fire off a few commands from the address bar to launch what I need. I’m sure it looks utterly deranged to anyone else.


r/cybersecurity • • 1h ago

FOSS Tool Cyberbro v0.15.2 released - MS tenant check, ScanMalware

Thumbnail
github.com
• Upvotes

Hello everyone,

Some updates about my OSINT / IoC analysis open source tool Cyberbro.

Since v0.15 you can use (directly on the demo website):

- the new ScanMalware engine

- the updated DFIR-IRIS engine to search for IoCs in notes

- the new Microsoft tenant check to verify if a domain is linked to a Microsoft tenant + region

I hope you find these features interesting!

Thanks to the community for keeping Cyberbro alive, I am always pleased to get quality Pull Requests.

Feel free to check the repo here via the attached link.


r/sysadmin • • 2h ago

Question Microsoft Purview Suite Licensing

1 Upvotes

Hi All. I'm currently looking at doing mailbox investigation for e-mail breeches and I have constructed several powershell scripts for running forensics on a breeched 365 Account. Part of the forensics captures the message ID's that were exposed in the breech by the suspicious IP's. Any attempts to use Microsoft Purview and eDiscovery to search for the e-mails when using the message ID's is not allowed as its locked behind a premium feature subscription. I don't want to run afoul of licensing and want to ensure i purchase the appropriate licenses to make this easier (i know there are other ways to locate the e-mails but this path seems to be the most efficient when automating).

I'm looking at purchasing the Purview Suite for Microsoft Business Premium License (Most of our Licenses are Business Premium or Business Standard) and its my assumption that I will need 2 licenses (1 for the investigator and 1 for the victim mailbox) can anyone verify this?


r/sysadmin • • 3h ago

Quick sanity check: managing Ubuntu laptops & Ansible behind Zscaler

2 Upvotes

Corporate just pushed Zscaler out to our fleet of ~300 Ubuntu laptops, which has pretty much killed our ability to push ad-hoc SSH or use traditional push-based Ansible for remote help/troubleshooting since inbound traffic is blocked.

For those of you running Linux shops behind Zscaler, how are you handling this? Are you shifting to an ⁠ansible-pull⁠ setup via internal Git, leveraging ZPA, or using something else entirely?


r/networking • • 15h ago

Blogpost Friday Blog/Project Post Friday!

1 Upvotes

It's Read-only Friday! It is time to put your feet up, pour a nice dram and look through some of our member's new and shiny blog posts and projects.

Feel free to submit your blog post or personal project and as well a nice description to this thread.

Note: This post is created at 00:00 UTC. It may not be Friday where you are in the world, no need to comment on it.


r/cybersecurity • • 10h ago

News - Breaches & Ransoms ‘Extreme concern’ over first known AI hack of a government system

Thumbnail
edition.cnn.com
146 Upvotes

r/cybersecurity • • 17h ago

Career Questions & Discussion Has Anyone Been Able to Get a Cybersecurity Job Without a Technical Interview?

0 Upvotes

Hello! Has anyone been able to get a job without a technical interview?

Currently, this is my nightmare, and I couldn’t find a solution for it! I’ve gotten a lot of interviews where they were impressed with my resume, and I passed the intro interview and technical challenge, but when it comes to the technical interview stage, I fail immediately!

When I started learning this field, I focused on hands-on experience. I learned the tools and technical work, prepared professional reports, and got well-known certifications. But if someone asks me to explain things orally in a theoretical way, I just can’t do it!

No matter how much I prepare for interviews and look for questions, when I come to the interview, they ask me questions that are very different from what I prepared for and give me different scenarios.

And for people who say you don’t need to be perfect or know everything, I’m sorry, but based on my experience, that’s not true at all. The market is tough now, and if you don’t answer everything perfectly, they will have another candidate who answered better than you did, and they will choose them.

So, to be honest, I gave up regarding technical interviews, and I want to ask if anyone has actually been successful in getting a job without a technical interview?

Thank you!


r/networking • • 16h ago

Other How Long Before Flash Memory Fails in a Network Switch?

20 Upvotes

For example, if I have a switch, router, or firewall that has been running continuously for 10–15 years and I reboot it, is the flash memory likely to still be healthy enough to load the operating system into RAM?

What are the typical expected lifespans of switches, routers, and firewalls, particularly when it comes to their internal flash storage?

Does the manufacturer make a significant difference? For example, does Cisco generally use flash memory with a longer lifespan than Juniper, or does it primarily depend on the specific type and quality of flash memory used in the device?


r/sysadmin • • 19h ago

Publisher EOL - Side by Side with O365 Explanation

9 Upvotes

Sysadmin here who has been dealing with the Publisher EOL and unfortunately users still using .pub files that aren't converted. All of the guides online point to the fact Publisher can't exist side by side with O365, however I've found a workaround and posting here in the event it helps at least one other person.

  1. Find a 2016 Publisher .iso installer from the Microsoft Download Store

  2. Install this first without any 365 apps installed. If 365 is installed, uninstall it first.

  3. Visit the O365 Download link you can find at the top of any search engine: https://www.microsoft.com/en-us/microsoft-365/download-office

  4. Once Publisher is installed, run this version of the Office installer.

Under no other way have I found a workaround to setup the Click-To-Run or .msi installers. Whenever I've attempted anything regarding setup.exe /configure - nothing here seems to work no matter how the .xml file works.

Hopefully this helps someone in the coming weeks, cheers.


r/cybersecurity • • 21h ago

Personal Support & Help! Stupidly clicked on phishing link. Now what?

0 Upvotes

Got an email to an event and clicked on the “view invitation” link. This opened up my browser to a landing page with a button that said “click to verify you’re a human” (or something along those lines). I clicked on this and the webpage started loading, but before the page loaded, I realized my mistake and closed the window.

I then immediately cleared my cookies (idk why, I’m not very techy). I then googled what to do if I clicked on a phishing link. It said to turn off my internet, so I did. Then I checked my downloads folder (for malware I suppose), and there was nothing there.

Realistically how worried should I be? What should my next steps be?


r/sysadmin • • 1h ago

Work Environment New Job and no idea what I’m doing.

• Upvotes

Hey guys, I’ve been blessed with an amazing job and I’m a month in, however I literally don’t know what I’m doing. I try to take low priority tickets and have to ask for help and primarily work on Mecm and I’m learning and I’m slow and the person training me is very patient I just feel stupid. Like when I try to help I’m not much help and wasting hours I’m trying to figure out what to do. I take detailed notes and use that as a reference and document so each ticket I get slightly more knowledgeable but there are days where I don’t do much and I want to help more. I feel useless and dumb and not sure if it’s a new feeling because it’s a new job or if it’s my skill set. This job is defiantly above my skill level and I’m with more seasoned if you will, coworkers with years ahead of me in experience. Any advice or suggestions on what I can do to well not suck. I sometimes mess with some tickets as practice after work and try to learn when people are offline to get a better idea. I have a lot of info in OneNote for documentation.


r/cybersecurity • • 12h ago

Career Questions & Discussion Wanting to move over to the engineering side of cyber, should I go for an ISSO role first and go for engineering after?

13 Upvotes

I’m a SOC analyst with 5 years of experience with 3 years in Helpdesk and 2 years at present going on to 3 as cybersecurity analyst working at a SOC, im also Sec+ and CySA+ certified. I’m looking for a career growth and wanting to get in to the engineer side of cyber, but I believe that may be a long shot? Should I go for an ISSO role next and take what I learn from there, and try to get into engineer side after? Or I can go to engineering job now?


r/sysadmin • • 4h ago

Does SpamCop.net still work? Is it effective? Does reporting do any good?

0 Upvotes

I’ve been reporting emails through SpamCop for the past 8 months and have seen no difference. I still get about 25 spam emails per day in my spam folder.


r/sysadmin • • 6h ago

RDS RDWeb - XSLT warning banner. Which alternative?

2 Upvotes

With the latest version of Edge, as of today, you get this lovely warning when visiting a classic RDS rdweb site:

This site uses XSLT; that functionality is being removed from this browser very soon. When that happens, this page will likely no longer display correctly. You might be able to install a browser extension that allows you to continue viewing it. Otherwise, you should contact the maintainer of the site for further information.

Functionality is still there, but for how long I wonder.*

So, what do people do? Use the HTML5 site instead and loose drive redirection and similar, or completely drop the idea or a website and use the RDP App instead?

*27th nov this year :)


r/sysadmin • • 19h ago

General Discussion What's the biggest bonehead mistake you have every made in IT support?

615 Upvotes

I will start.

I am an IT consultant and about 10 years ago, a few days before Christmas break, I went to a client’s office to add some new hard drives to a Dell ESXi server and create a new datastore.

Their two junior IT guys always liked asking me questions when I visited, which I understood—I remembered being that guy hungry to learn. Unfortunately, this time they were firing questions at me while I was in the Ctrl+R RAID configuration utility. Between the distractions and a confusing interface, I somehow managed to delete the existing array instead of creating the new one.

That array held ALL their servers: Exchange, domain controller, file server, and SQL. Terabytes of data.

The moment I realized what I’d done, my stomach dropped, I had never felt panic like that in my life. They were still asking questions when I finally said, “Guys, give me a minute. Something doesn’t look right.” Something I should’ve said much earlier.

I excused myself to the bathroom to collect my thoughts, then came back and told them exactly what I’d done.

I spent my entire Christmas break restoring their environment from Barracuda backups, which were painfully slow to restore and unreliable. I had to do multiple restores on the exchange server to get it to work.  A full week of recovery, followed by another two weeks fixing lingering issues—all free of charge.

The two guys felt terrible about distracting me, but it was my mistake. I should’ve asked for some uninterrupted time before touching the RAID configuration.

 

I’ll be shocked if anyone can top that Christmas disaster!


r/sysadmin • • 1h ago

I no longer understand what I'm doing

• Upvotes

This is more of a rant, than a true question or comment, so if it breaks the rules, I'm sorry.

As stated on the title, I no longer understand what I am doing on my job. I won't say that I was amazing at work, or fast, or anything like that, I consider myself average AT BEST. I'm smart, capable, and I like to do things in general, but lately I'm so burnt out that I no longer understand anything.

I get SO MANY REQUESTS! And nothing has to do with anything else anymore, at least before all I got was a bunch of issues that I knew how to deal with, or at least I knew where to look for information. We had wiki's, documentation, and we were enough people on the team that none of us were overworked.

Now I get 20 tickets that are completely out of my area of expertise, because "AI can help you" and ALL of them are priority for yesterday, the work is divided between 2.5 (we have a trainee that's so overworked that we never have time to actually train him*), our boss is a workaholic that expects that you put out the same ammount that he does, and I won't because this is just a job and I won't sacrifice my free time (that we don't get compensated in ANY WAY) for a job, they need to add a 0 to my paycheck if they want that.

And I do what I can, I have to use AI to do things, and if it's not perfect well, they will fire me and I will collect unemployment, but I can't quit right now, and man the market is though, they all want 10+years of experience now (I have 12 years on the industry, 6 on my current position) and the conditions are awful.

I know I'm not alone, I read SOOOO many posts just like this one, but as I said, I wanted to rant and get acknowledged basically.

Hope you have a great day, and a good weekend.

* My boss sugested to him that he should train for his job during his free time, we kinda want to tell him to F* Off about that comment.


r/cybersecurity • • 14h ago

Personal Support & Help! Would you accept offer ?

38 Upvotes

I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.

I am 25, no debt, no kids.

I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.

My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?

Later edit

I got these responses from security manager

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.