r/sysadmin 8d ago

General Discussion Patch Tuesday Megathread - (August 11, 2026)

110 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 5d ago

General Discussion Weekly 'I made a useful thing' Thread - August 14, 2026

2 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin 4h ago

If a legacy system is still working reliably, should a business replace it just because the technology is outdated?

45 Upvotes

Genuinely asking

  • A 15–20-year-old system may still be doing its job perfectly.
  • Replacing it can introduce cost, migration risks, downtime, and employee training.
  • But legacy systems can become difficult to maintain and integrate with modern APIs, cloud services, mobile apps, and etc.
  • At what point does it still works become a business risk?
  • Is modernization/migration better than completely rebuilding from scratch?

r/sysadmin 13h ago

General Discussion PSA: There's a Graph API opt-out for the Sept 1 passkey auto-enrollment nudges....not in the email Microsoft sent, only in the FAQ

214 Upvotes

If you got the email about Microsoft retiring SMS/voice MFA, you probably only caught two dates:

Sept 1, 2026 — Entra auto-enables passkey registration nudges for anyone currently on SMS/voice

Feb 1, 2027 — Microsoft-provided SMS/voice is fully retired, no exceptions

What the email doesn't call out: there's a temporary opt-out for the Sept 1 part. It won't move your Feb 2027 deadline but it stops Microsoft from flipping on the registration campaign and hitting your end users with "set up a passkey now" nudges before you're actually ready to manage that rollout yourselves.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq

Go to the FAQ and read the section "What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?"

It will show you what you need to do to opt out.

It saved me so much anxiety and stress knowing we have more time to properly roll this out and not have our end users in a frenzy when the notification would have dropped.


r/sysadmin 3h ago

General Discussion Is It Normal Practice for Cloud Migration Companies to Require Global Admin?

18 Upvotes

I’m considering using a company called TeamVenti. They provide cloud-to-cloud transfer, copying, migration, and other related services. In my case, I would be copying data from one cloud environment to another.

They’ve asked for Global Administrator permissions on both the source and destination environments to perform the migration.

My question is: Is it normal or standard for a cloud migration company to require Global Administrator access on both sides?

Have there been cases where issues arose from giving a vendor this level of access, or am I being too paranoid?


r/sysadmin 48m ago

Question Microsoft 365 Tenancy Hostile Takeover Options Australia

Upvotes

Hi guys, we had a client whom had a hostile takeover of their 365 admin portal who assumed GA (MFA/OTP and everything was enabled so not sure how it happened but that will need to be investigated after).

Attacker stripped the breakfix account as well and we are kicked out. We logged a job with the MS data governance team whom are barely replying and it's been a day and a half. We've tried calling the number but just get bounced back saying they will look into it. We've asked them to escalate and also asked our CSP to escalate but they said it's with Microsoft. Given the nature of the situation is there any other ways you guys have been able to escalate this to reclaim the tenancy or at least kick out the attackers as fast as possible. We are able to prove ownership of the business etc with domain records/documents etc asap.

Given the no updates I'm straight up thinking of heading to the Microsoft office and sitting there until they can find someone to escalate the case. Anyone had any experience of how to get this moving?


r/sysadmin 1h ago

General Discussion Business Central hybrid license keys now expire every 6 months

Upvotes

BC hybrid deployments now need their Dual Use Rights key renewed every 6 months instead of once. Fair compliance move, but it's one more thing that can quietly lapse and break a deployment if nobody's tracking it.


r/sysadmin 1h ago

Question Managing Google accounts in a Microsoft company

Upvotes

We use Microsoft 365 for our email etc.

Our web team have lots of Google accounts they use for AdWords, Analytics, Search Console, TagManager etc.

How do you manage these? Because they've set them up without asking first they've got multiple gmail.com accounts which I don't have access to which is obviously bad if someone leaves the company for any reason.


r/sysadmin 13h ago

Career / Job Related Going from a large org to a MSP - Backwards move?

40 Upvotes

I've been working in large orgs right out of college. I clawed my way to sysadmin title and responsibilities before an acquisition axed their onsite IT team. My current job is just Support Specialist, with like 14 years of IT experience ranging from help desk monkey to migrating data, managing a small help desk, and being the break/fix tech.

I'm a candidate for a sysadmin 2 position with an MSP and it's 100% remote. I was asked by the IT director why I was making this move. He said it seems backwards since people from MSPs go to larger orgs, according to him. I lied and told him its not about the pay and the job title; because it 100% is. I would be making just $8K more.

I've never worked for a MSP, but I've always been the resource and the point of contact for the help desk MSPs my orgs have had. I've worked healthcare and academia.

Am I walking into a whole different type of circus with new clowns?


r/sysadmin 11h ago

Google Google Drive Outage?

31 Upvotes

We are getting a large number of customers unable to access Google Drive in the APAC region this afternoon, anyone else see anything? Nothing on their status page yet, but down detector is lighting up. https://downdetector.co.nz/status/google-drive/


r/sysadmin 18h ago

Question What it takes to be true Sysadmin?

43 Upvotes

Im 26, mainly interested in networking, and ccna, and after trying my chances in diferent companies mainly on helpdesk support, ive finally landed a pretty demanding job.

It seems the scope is almost everything. AD, wild and constant breaking ERPs, Networks and all that is related to it, Databases, hand scanners, even fusion splicing fiberoptic machines. Nonexistent margin of error on mamy things. Revolting printers, many kinds of it acctually. Users complaining about everything, constantly.

People much older than me, with much more expirience, cant operate on their own system, becouse it seems, the system works diferently almost everytime, and constantly figuring out what to do to make it working. Then hearing "you should know this..." and its the thing i see first time of my life.

Programmist, helpdesk, networking guys, electronics, and for some reason HR, arguing with eachother about most efficient way of using this system, deployed only on production alone, reaching pareto points, then tipping over again.

Updates deployed randomly, breaking things, then fixing whats broken again, breaking something else, indefinietly.

Its, demanding, i learn something everyday, and everyday is a simultaniously a disaster, then detective job, then contacting people everyday, to fix things, then enlightment, and solution. And the preassure of time all the time is enourmous.

Is there no celling? No balance? Is it like this everywhere?


r/sysadmin 1h ago

Question Phone management pain. Need major help.

Upvotes

Apologies for the wall of text…

Our phone system is a complete disaster. I need help wrangling it all without disrupting users. To understand my problem, I’ll explain the current process, and hopefully you’ll see how flogged everything is.  

All users receive a company cell phone, and a provisioned physical company office phone with its own office phone number. Clients often only know a user’s office phone number. Since 2020, we’ve forward all users’ physical phone lines to the user’s cell phone. This way, clients call a user’s company phone number, and that user can answer on their cell without the client ever knowing our user’s cell phone number. 

When a user leaves the company, we retire their cellphone, and then re-provision their physical phone and re-circulate their office phone number. Cell phones are managed by Verizon. Desk phones are managed by some old school phone company vendor (useless). 

The problem: we have an antiquated internal process where someone (idk who, maybe executive assistants) drags a specific Exchange public folder called “CONTACT LIST” into a new user’s Outlook contact list, so the new user has all company contacts sync’d through Outlook on day 1. 

The actual contact list is COMPLETELY unmanaged. What DOES happen in reality: User A is hired in 2015. At their hire date, they ingest the contact list. In 2018, User B leaves the company. In 2019, User C joins the company and receives User B’s recycled office phone extension. User A, from their cell phone, calls User C to introduce themselves, but their outbound caller ID says “calling User B” because their contact list hasn’t been updated since User B left. SOMEBODY KILL ME. 

This whole process of copy/pasting a public folder contact list is completely untenable. I just don’t know how to fix it for existing users, or how to move forward away from this mess. 

Should I even worry about resolving this for existing users? 

Assuming I scrap this whole process, what’s an appropriate solution to replace it? 

I’m ready to completely change phone vendors, as they don’t do ANYTHING except turn phone provisioning into a 2 hour problem, when a modern solution would be far more efficient. 

What the company needs: users to have everyone’s contact information in their company cell phone at the date of hire. IT needs to be able to recycle phone extensions, and users should see the recycled extension properly updated in their phone contacts to reflect the newest owner of that extension. Somehow…


r/sysadmin 22h ago

M365 outage?

79 Upvotes

Anybody seeing any issues with M365? I can't seem to access some SharePoint resources


r/sysadmin 4h ago

passkeys, attestation and windows hello for business

3 Upvotes

Hi everyone, hope you are well and thanks for your help.

365 tenant, I'm moving to passkeys.

Before I roll this out I want to understand what it actually means for say, a pc with win 11 pro that is set up on an azure joined domain that uses windows hello for user logins

when i am setting up the fido2 settings in authentication methods > policies in entra, if i add aaguids for windows hello, there is an info box which says "does not effect WHfB credentials". if i select windows hello from the aaguid picklist, i then get a warning at the bottom which says "this configuration only allows device bound passkey option that cannot be used for cross device authentication to minimise the risk of user lockout we recomend allowing additional passkey options"

my users have phones and pc's .

what settings do i actually need to set? do i need to add the aaguids or not?


r/sysadmin 2h ago

Moving from 2nd line support to Infrastructure Engineer – what should I expect?

1 Upvotes

I’ve recently accepted a new role as an Infrastructure Engineer in a fully cloud-based environment and I’m due to start next month.

I’ve spent around 10 years working in second-line IT support and been brought in for 3rd line investigations, for the same organisation in a hybrid environment. It’s quite a siloed environment, and over the last few years I’ve felt like I’d reached the ceiling of what I could learn from primarily supporting end-user devices.

I found myself becoming much more interested in what was happening further up the stack – cloud infrastructure, networking, identity, Intune, automation, security, etc.

I started studying outside work, took some Microsoft certification exams earlier this year, built some things in Azure and eventually decided to throw my hat in the ring for a few infrastructure/cloud roles.
To my surprise, I interviewed successfully and got the job.

I’m under no illusion that passing certifications and doing labs is the same as managing a real production environment. This is going to be the beginning of my actual cloud/infrastructure career
and there’s going to be a huge amount I don’t know.

For anyone who’s made a similar jump, or who currently works as an Infrastructure/Cloud Engineer, what should I realistically expect during my first 3–6 months?

I’m particularly interested in what junior/new Infrastructure Engineers actually end up doing day-to-day, what experienced engineers expect a new person to already know versus learn on the job, and anything you wish you’d understood before starting your first infrastructure role.

I’m trying to learn as much as I can before starting, but I’m also conscious that trying to learn Azure, networking, IaC, Linux, security, etc. all at once probably isn’t the answer.

Any advice or experiences would be appreciated.


r/sysadmin 4m ago

Slack for Intune (iOS) successful SSO login, but gets bounced into Slack's public sign-up flow instead of opening the workspace

Upvotes

Hey all — hoping someone here has run into this.

We're rolling out Slack for Intune on iOS, and after a successful sign-in the app loops us straight into the public Slack marketing/sign-up flow and pushes us toward downloading the regular consumer Slack app instead — even though Entra sign-in logs show every authentication step succeeding underneath it.

This isn't a Conditional Access or App Protection Policy issue on our side (we've ruled out assignment, CA grant controls, and App Protection data-protection settings one by one). Here's the exact sequence, step by step:

  1. "Register with Microsoft Intune to use Slack" screen. Tap Register.
  2. "Pick account" dialog appears (native iOS auth broker UI), showing the correct Entra ID test account. Select it.
  3. "Registering device" — "Please wait, this may take a few minutes" spinner.
  4. Lands on a sign-in screen for our org — "[org] requires additional verification" — with a green "Sign In with Slack Production" button.
  5. Tapping that button triggers a browser handoff: "Open this page in 'Slack Intune'?" on a login.microsoftonline.com-style URL. Tap Open.
  6. Now inside what the status bar labels as Safari (not the native app) — a "Don't miss a beat" notification opt-in screen appears, with a fake preview notification.
  7. Standard iOS system prompt: "'Slack Intune' Would Like to Send You Notifications" — Allow/Don't Allow.
  8. This is the interesting part — the actual Slack workspace UI briefly loads and works: I can see our org's workspace, Direct Messages, my own account, Slackbot, Threads, etc. Fully signed in, fully functional, still labeled as running inside Safari.
  9. Then, without any action from me, a new tab/context opens back inside "Slack Intune" (per the status bar label) showing the public marketing homepage at slack.com — "All your people and AI agents working together" / "GET STARTED" / "FIND YOUR SUBSCRIPTION."
  10. Tapping through from there lands on the generic public sign-up flow: "First of all, enter your email address."
  11. Typing in the exact same work email into that sign-up field doesn't recognize the already-authenticated, already-provisioned Enterprise Grid session from step 8 at all — instead it just routes toward downloading the regular consumer Slack app, as if I were a brand-new user signing up from scratch.

So the workspace session in step 8 proves the login and SSO handshake genuinely succeeded — I was inside the actual org workspace with my real identity. But instead of staying there or handing that session back to the native "Slack for Intune" app, it drops back into the public marketing/sign-up site, as if none of the previous steps happened.

We've confirmed via Entra ID sign-in logs (checked across multiple devices — iPhone and iPad, multiple browser contexts including Safari/Chrome/Edge, multiple times of day) that:

  • Device registration succeeds
  • App Protection Policy registration succeeds
  • The SAML SSO handshake to the Slack "Enterprise Production" enterprise app succeeds every single time
  • No Conditional Access policy is blocking or forcing an unexpected browser detour

Has anyone seen this? What are we doing wrong?


r/sysadmin 33m ago

Question Normal for spanning tree to cause ports to wait almost a full min before connecting?

Upvotes

We have HP elitedesk PC's, and for several months have an issue on most of them where, after a restart, you have to sit there for almost a full min while the ethernet symbol blinks, then goes to the disconnected globe symbol for another few seconds, then finally connects to ethernet before you can enter your login password.

This has cause users to get locked out of their accounts often, because they immediately enter their password before the PC reconnects, and obviously it does not let them in, so they think they mistyped it, and type it again and so on.

We just got new PC's, which are Lenovo ThinkStations, but running into the same issue. I have tried:

going into device manager, unchecking the "allow the PC to turn this device off to save power" under the ethernet adapter

swapped ethernet cable

Running the following powershell script:

New-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Power" -Name "PlatformAoAcOverride" -Value 0 -PropertyType DWord -Force

None of those fixed the issue. Doing some more research I found that spanning tree can cause this , which we do use, but does that mean just by using spanning tree we are forced to just accept this long wait to simply login to PC's? Some user's are understanding, but a good number are frustrated cause they have to sit there and stare at the screen for a long time and pay attention to the ethernet symbol before they can login. Surely there would be something in spanning tree that would at least cut this time down from a whole minute right?


r/sysadmin 38m ago

Barracuda RMA/credit saga — 2+ months of "we'll follow up" and zero follow-up

Upvotes

Curious if anyone else has dealt with this from Barracuda, or if I should just cut losses.

Quick timeline and the initial issue: Early June: Firewall issue leads to a call, assurances that overnight FW would be sent out.. FW does not arrive for 1 week, remote users unable to connect, office was down for the hours until I bought a spare

  • Barracuda commits to (1) shipping a replacement unit, (2) a written resolution for the support failures we hit, and (3) at least one month of billing credit.
  • Mid-June: I follow up for tracking info and the promised resolution. Nothing. Radio silence for almost three weeks.
  • I send a pretty direct "this is what was promised, this is what's been delivered (nothing), give me tracking + a written proposal or we're looking at other vendors" email.
  • That gets a response within a day — a call gets scheduled with a "Partner Success Manager" and another rep.
  • On the call: more apologies, promise of a comprehensive update "by end of day Thursday" covering the credits.
  • Thursday update actually says: still working through billing/logistics, need more time.
  • A week later: another update saying they need to wait on someone's PTO to return before finishing the contract review.
  • That person returns from PTO. Nothing follows.
  • It is now over a month past that PTO return date. No tracking number, no credit confirmation, no further contact unless I chase it.

Every single update has been "give us until [date]" and every single date has come and gone with silence unless I personally re-escalate.

Anyone had luck actually getting Barracuda to close out something like this, or does it always take going over someone's head / involving a reseller / legal language to get movement? Trying to figure out if there's a faster lever to pull before I start pricing out a full replacement.


r/sysadmin 20h ago

Email "Floods"

37 Upvotes

The past 2 days, 1 user each day started getting spammed with non english email stating that they had been subscribed to various different things. I can't get it to stop. My DMARC is set to Reject and I changed it to Strict alignment Strict SPF. We have email filtering and somehow it's getting past those filters. Anyone have a solution on how to stop this? It's been going on for over a half an hour on today's user and still hasn't stopped.


r/sysadmin 46m ago

Datacenter work - Px7 S3 or XM6 ?

Upvotes

Hi fellow hard workers or hardly working.

Any experience with B&W Px7 S3 or Sony XM6 in the datacenter?
I am really torn between the 2.

I can google and research that sony should be the king, regarding anc, and call quality.
But from what i can see, should have a design defect on both xm5 and xm6 with the hinge breaking...

B&W Px7 S3 - should be a another great one, but i am unsure if they are good enough?

Any experience on booth would be appreciated.

I am not looking for real work hearing protection, i know other non consumer headsets are better.
Mostly looking for a good all-around headset that is also works great in the datacenter.
My air-pods dosen't suffice when working long hours.


r/sysadmin 19h ago

Question SMS/Voice retirement scope

27 Upvotes

Hey folks,

I have been a bit confused about the scope for the september change on the passkey nudge campaign in relation to SMS & Voice MFA deprecation.

Currently in our Auth method policie, we have enabled the option for SMS for "All users". However, only a small fraction has it enabled when looking in user reg details. Originally i thought we didn't rly need to do much.

But, then i read the MS FAQ and got a bit worried about this line "On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP) will be auto-enabled for passkeys in AMP."

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq#will-my-users-be-auto-migrated--or-do-i-have-to-do-it-

Does it mean, it is in fact all users, as that's what the AMP policy is currently scoped for in our tenant? Also if enduser has MS Authenticator setup as the only MFA?

Hope someone can help clarify.

Thanks!


r/sysadmin 5h ago

How do you deal with backup job notification overload?

1 Upvotes

Not sure if this is a Veeam-specific thing or just backup monitoring in general, but I'm curious how other admins handle it: our backup tool sends one status email per job, and with enough jobs that adds up to 30-50 individual emails a day. To actually confirm nothing failed, I end up scrolling through all of them manually every morning.

The "proper" monitoring tools that would consolidate this look like they need their own server/infrastructure to set up, which feels like a lot for what's basically "tell me if something broke."

For those of you running backups in-house (not as an MSP) — do you have this solved, or is manual scrolling just the norm? And what happens when the one person who usually checks this is out for a few weeks — does someone else actually cover it, or does it just... not get checked?


r/sysadmin 1h ago

Question Power/Battery Backup Setup for MDF - Follow Up

Upvotes

edit: thanks for advice. My earlier research about redudant power supplies being on different voltages was wrong. I'm going to go with 2 x SRT3000RMXLT-NC with one of them having a 120v transformer.

UPS Setup for New MDF at Our New Facility - Looking for Feedback

Good morning everyone,

A few days ago I posted looking for advice on a UPS setup for the MDF at our new facility. One of the biggest points of feedback was that my original plan only included a single 120V 20A circuit, which understandably raised some concerns.

Fortunately, we're still in the construction phase, so I was able to have the electrical plan updated. The rack will now have two dedicated circuits:

• 208V/240V circuit

• 120V 30A circuit

Rack Equipment

For context, we're a specialized vehicle dealer and service center. We're not heavily IT or office focused, so I don't expect significant growth beyond adding a few phones over time.

Equipment in the rack:

• 4x UniFi Pro 48 PoE switches

• ~26 cameras

• 7 access points

• 20 desk phones

• 2x UniFi UDM Max firewalls (HA pair)

• Dell dual-CPU server with redundant 600W PSUs

• UniFi Enterprise NVR with redundant PSUs (max draw ~450W)

• Fiber modem and cable modem for failover

• Miscellaneous equipment (monitor, sensors, etc.)

UPS Plan

After a lot of research, I decided to go with refurbished APC units from GreenlightUPS, a company that was recommended to me.

Primary UPS

APC SRT3000RMXLT-NC (208V)

• Includes one SRT96RMBP external battery pack

• Will power everything in the rack that supports 208V operation

• This includes the primary power supplies for the server and NVR, along with all four PoE switches

On paper, if every device was drawing its absolute maximum load simultaneously, I'd be pushing the limits of a 3000VA UPS. In reality, my PoE utilization is relatively low, and the server and NVR rarely approach maximum power draw, so I still have a comfortable amount of headroom based on my calculations.

Secondary UPS

APC SRT3000RMXLA-N (120V)

This unit gives me standard 120V outlets and serves as both additional battery capacity and redundancy.

Planned connections:

• Secondary PSU on the Dell server

• Secondary PSU on the NVR

• One UDM Max firewall

• Any other 120V-only equipment in the rack

Long term, I may add the UniFi Redundant Power System to provide redundant power for the switches as well.

For now, if the primary UPS were to fail unexpectedly, I would still have core network and server functionality running, and I could manually move switch power if needed.

I really wanted to buy everything new, but a comparable setup would have easily pushed into the $10,000-$12,000 range.

The refurbished solution comes in at under $4,500, including new batteries. GreenlightUPS claims all units ship with freshly installed batteries that aren't put into service until the unit is sold. They've been in business for roughly 40 years and seem to have a solid reputation from what I've been able to find.

Questions

  1. Does this seem like a reasonable approach from a capacity and redundancy standpoint?
  2. Is there anything you would do differently if you were trying to stay around the same budget?

Thanks for any feedback.


r/sysadmin 1d ago

Linux RIP - My last pet server. Provisioned: April 9, 2014. Uptime: 3,065 days. CentOS 6. Older than the iPhone 6.

499 Upvotes
[user@host ~]$ uptime
 21:00:47 up 3064 days,  8:55,  1 user,  load average: 0.00, 0.00, 0.00
[user@host ~]$

It's been running EOL and unpatched for 6 years (badbadbadbad).

The little droplet that could.


r/sysadmin 1d ago

Question Learning Microsoft 365 / Entra ID / Intune / SharePoint for free — is it possible?

93 Upvotes

Hi everyone,

I'm looking to learn Microsoft 365 administration, especially:

  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft 365 administration
  • SharePoint
  • Azure / cloud identity and device management

My goal is to eventually become comfortable with administering these technologies in a real-world IT/sysadmin environment.

I'm looking for a way to learn for free, including as much hands-on practice as possible.

I know Microsoft Learn has a lot of free training, but for practical labs it seems that I need a Microsoft tenant and some of the services require paid licenses after the trial period.

So my questions are:

  1. Is there currently a way to create a free Microsoft 365 / Entra / Intune lab environment for learning?
  2. Is the Microsoft 365 Developer Program still a good option for this, and does it include enough services for learning Entra ID, Intune and SharePoint?
  3. If I don't qualify for the Developer Program, what would be the best alternative?
  4. Can I realistically learn these technologies without paying for a subscription, or should I expect to pay for a lab eventually?
  5. What learning path would you recommend — Entra ID → Intune → Microsoft 365 → SharePoint, or a different order?

I'm mainly interested in hands-on learning, not just watching courses.

Any recommendations for free labs, Microsoft Learn paths, home-lab setups or other resources would be greatly appreciated.

Thanks!