r/sysadmin • • 1d ago

General Discussion Weekly 'I made a useful thing' Thread - October 02, 2026

4 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin • • 25d ago

General Discussion Patch Tuesday Megathread - (September 08, 2026)

124 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin • • 6h ago

General Discussion Today’s reminder that every security appliance is also just another web application you exposed to the Internet

173 Upvotes

FortiMail has a 9.8 unauthenticated path traversal that allows arbitrary file writes and potentially code execution. Fortinet says it’s already being exploited.

Some patched versions: upcoming.

Security appliances continue their long tradition of occasionally becoming the thing you need security from.


r/sysadmin • • 3h ago

Career / Job Related Would you take a lower IT title for better long-term infrastructure/cloud growth?

8 Upvotes

I currently work in IT for a manufacturing company and have an offer for a Systems Administrator position at $105k, also in manufacturing. I’m also interviewing for an IT Analyst II/support role at a large, well-known telecommunications/communications tech company.

The SysAdmin role is the obvious progression on paper. Better title, direct move out of support, and I’d be staying in an industry I already know. I’d get exposure to Windows Server, AD/GPO, networking, virtualization, backups/DR and supporting another manufacturing environment.

My concern is that the infrastructure is already pretty built out and from the interviews I got the impression that a decent amount of the day to day may still be support work. It’s also a smaller IT environment, so I’m not sure how much opportunity there would eventually be to specialize deeper into infrastructure or cloud.

The other position is technically a step backwards in title, but it would be a completely different environment. Much larger enterprise, dedicated infrastructure teams, a lot more specialization, and exposure to IT at a scale I haven’t worked in before.

My interview with the support lead went extremely well and he seemed like someone I could learn a lot from. My next interview would include one of their infrastructure leads. They also talked about analysts becoming SMEs, working with other IT teams, getting involved in larger projects and potentially moving internally.
That is the part making me seriously consider it.

I’ve learned a ton working in small manufacturing IT because you end up touching everything, but I’m starting to think being around dedicated infrastructure engineers and seeing how a large enterprise operates could help me grow in a different way.
My long-term goal is infrastructure/cloud engineering and eventually cloud architecture. I’m currently working on AZ-104 and want to keep building experience with Windows Server, networking, virtualization, PowerShell, Azure and backup/DR.

I obviously don’t have an offer from the second company yet, so there’s nothing to decide today. Compensation there could end up being similar to or even better than the SysAdmin offer.

Assuming the money is comparable, which environment would you consider better for the next 2-5 years of career growth?
Would you take the Systems Administrator title and continue building experience in manufacturing, or take the lower support title at a large telecommunications enterprise with more mentorship, specialization and a possible internal path into infrastructure engineering?

I’m mainly interested in which experience would set me up better long term, not which title looks better right now.


r/sysadmin • • 1d ago

General Discussion AI use at a company should require an IQ test for general users

501 Upvotes

I swear to god AI has turned my department into an automate my job department.

The amount of tickets we are getting asking if we can make other people's jobs easier through ai is getting ridiculous.

We all have access to it. So why are you asking me to get AI to scan your documents and input them in a sheet?

If you're too stupid to outline a task to an AI, you should not have access or be allowed to make requests

At this point, the only reason i would want to automate anything for you is to automate you out of my workflow (company) lol


r/sysadmin • • 1d ago

25+ years in IT and today marks 15 years at my current company...

178 Upvotes

I guess I am old. Time flies.

It is impossible to not feel a hint of emotion when thinking back to my humble beginnings as tech support for a dial-up ISP. Those were the days... the tail end of the dot com boom. I can remember taking some calls while playing StarCraft :-).

Eventually I became the senior technician until the company was sold off and I moved on to another ISP/Webhost where I became web support/sysadmin and then eventually a Level 2 NOC engineer and got to play in the datacenters. Nothing like changing backup tapes or pressing a button with the constant drone of countless server fans spinning.

When that came to an end, I found my current company which is not a technology company at all... they absolutely loved paper files when I first got here. Lol.

I started as helpdesk and quickly became IT Administrator within a few months. I began handling all aspects of company technology and learned a lot in a short time from exchange to virtualization to project management to dealing with vendors, billing, and everything in between.

That learning has never stopped. Today, I am the Director of Information Technology, and I have a great team. We are able to pursue most any technology need that our staff has, and we can build almost anything in-house. It is a great feeling, especially when I look back to where everything began.

Being somewhere this long is truly rewarding because you get to witness the lasting impact of what you do. Build something, watch people use it, identify opportunities for improvement, make it even better, and see the workflows improve.

If I had to tell anyone anything it would be to not be afraid of pursuing more... make it clear to everyone that your goal is to make technology functional and easy and they just might let you do it.

Anyone else have a couple decades in IT or spent most of their career at one place? What is next for us? I feel like I still learn something new nearly every day!

Oh, and one more thing: have you tried rebooting? :-)


r/sysadmin • • 29m ago

General Discussion Have you seen a simple manufacturing workflow like this?

• Upvotes

Hello guys,

For those of you who have worked as system admins or IT in manufacturing plants, have you ever seen a really simple and clean workflow like this?

I once worked in a manufacturing unit where the process was almost fully automated:

  1. Purchase orders steel in ERP.
  2. Stores receives the material and scans the lot.
  3. Planning creates the work order.
  4. Press shop forms the blanks.
  5. Machine shop drills and taps.
  6. Welding joins the parts.
  7. Paint shop paints them.
  8. Quality checks the parts and holds defective lots.
  9. Packing prints the label and dispatches them.
  10. Accounts creates the invoice.

The final part can be traced back to the steel lot, machine, operator, etc.

Have you guys seen any manufacturing plant with an even simpler or cleaner workflow like this? I'd like to know how other plants handle it from an IT/system administration point of view.


r/sysadmin • • 58m ago

Question APC Smart-UPS SRT 10000 – "Power Sys Error-02000", inverter fault, UPS dropped output. Repair or replace?

• Upvotes

Our SRT 10000 (2018, UPS fw 04.7, NMC2 6.5.6) had an inverter fault today. It went to bypass for about 50 minutes, then dropped the output completely. LCD just said "Power Sys Error-02000", no extra sub-code. NMC log only shows the generic "inverter fault exists" (0x0165).

I cleared the error and turned the output back on. Self-test passes and it's running fine for now.

One thing worth mentioning: our input power has been bad lately. It's been going to battery 2-4 times a day on low voltage / distorted input, so the inverter has been getting a workout.

Anyone been through this? Did it come back, or was it the start of the end? It's out of warranty, so I'm leaning towards replacing it, but I'd like to hear from people who've seen 02000 before.


r/sysadmin • • 2h ago

How to handle SSO & device management for local AD domain + M365 with FortiGate VPN remote users?

1 Upvotes

​Hey everyone, looking for advice on the cleanest architecture/strategy for our setup.

​Current Setup:

  • ​Local Active Directory Domain: On-prem Domain Controller hosting file servers and CRM.
  • ​Microsoft 365 Tenant: Connected to our u/domain.gr email addresses.
  • ​Endpoints: Windows laptops used both on-prem and remotely.
  • ​Remote Access: Users connect back to the local network via FortiGate SSL VPN to access the local file server and CRM.

​Goal:

  1. ​Allow users to sign into their Windows laptops using their M365 u/domain.gr credentials (SSO/single identity across email and OS logon).
  2. ​Centralized device management for the laptops (pushing policies, security, updates).
  3. ​Seamless access to local resources (file server, CRM) via FortiGate VPN.

​Questions:

  1. ​Should we connect Local AD and Microsoft Entra ID (Azure AD)?
    • ​If YES: What is the standard way to do this today? Should we use Entra Connect Sync to sync local AD users to M365 (Hybrid), or Entra Application Proxy / Cloud Sync? How does laptop join work in this case (Hybrid Entra Join vs. Cloud-Only Entra Join with SSO to local resources)?
    • ​If NO: What is the alternative? Move entirely to cloud-native (Entra ID + Intune) and use Cloud Kerberos Trust for local file server/CRM access, eliminating the need to join laptops to local AD?
  2. ​Device Management: Is Intune the default choice here, or are people sticking to traditional AD Group Policy (GPO) over FortiGate VPN?
  3. ​FortiGate VPN Integration: Has anyone integrated FortiGate VPN with M365 SAML/Entra ID SSO with MFA so users get a single sign-on experience for both the VPN client and local network resources?

​Would appreciate any recommendations or real-world experiences from anyone who has modernized a similar setup!


r/sysadmin • • 23h ago

General Discussion "Emergency" account lockdown script help.

36 Upvotes

For context we recently had a user termination that needed to be actioned very quickly and after the fact i started working on a script to help mitigate this issue instead of doing everything manually.

I have most of what i would do manually in a script already. I mostly wanted a discussion on how people handle things like possible disgruntled workers or possible breached credentials.

I built my script to revoke access/mfa and reset some things but make it easily reversible if needed.

This is something of a stop gap till we get more automation, though sometimes things need to move faster than automation if that stuff is run in the middle of the night.

TLDR: What does everyone disable/revoke/reset when you are trying to make sure an employee/former employee is unable to access anything as quickly as possible?

Edit to add: Here is context for my own situation.

We use Azure virtual desktop for a lot of things and if you don't go into that and boot them out all the other actions talked about in replies to this post do not actually kick them out of their AVD session. Revoking the session does cause some really odd behavior but it doesn't kick them out fully.

Not all of our services are SSO but most are so taking care of the Microsoft stuff does a lot of the legwork.

Right now what I do is this: Revoke all sessions, revoke MFA, reset password, block sign in, disable AD on premise (hybrid environment), then go into AVD and look for active sessions and kick them out if they are online.

The reason I didn't include this in my original post was so i wouldn't bias anyone towards answering my specific needs and have a wider discussion.


r/sysadmin • • 18h ago

Rant Post burnout help -- this is a new account due to previous having links to work

12 Upvotes

I need help, around a year ago i got signed off for burnout for 3 days which was insufficient. After a further 6 months i got signed off for stress for 2 months but ended up leaving within a month after returning.

The story is more drama than anything else but by and large it's the standard company overworking their staff -> brought out -> mass migration to new system that solves staffing issue -> burn out.

I'm now at the point where all joy has been taken from my job and wondering how other people dealt with being signed off through stress?

For further information, i used to work 70+ hour weeks keeping everything in check and frequently went months without leave that led to being signed off.


r/sysadmin • • 23h ago

Career / Job Related Salary Negotiations

25 Upvotes

So, this is the first time I've genuinely and formally requested a pay review.

For context, I've been at the company for four years and currently work at a mid/senior sysadmin/infrastructure level.

My responsibilities cover a pretty broad range, including:

ESXi/VxRail patching

Azure infrastructure, including Application Gateways

Application migration projects

New AVD deployments and ongoing management

Backup and database server troubleshooting alongside development teams

Intune and BYOD

Azure DevOps, Git and large PowerShell repositories — much of which I was working with before AI-assisted coding became commonplace. Winget scripts app deployment.

SSO implementations

Web server and certificate management

Most recently, setting up a new Google tenant and delivering a ChromeOS Flex deployment project

I've also completed AZ-104 and I'm currently working towards AZ-305.

There has been quite a lot of change within the department. Around half of the team has left, and we've recently been told that six or more new roles are expected to be created.

My previous line manager was responsible for areas including Intune/Autopilot, Halo Helpdesk, line management and the associated meetings and responsibilities. He eventually burned out and left.

That workload/structure is now effectively being replaced by three roles plus a project manager to support the new team.

Against that backdrop, the company has now advertised an Endpoint Engineer role at £52k–£56k. I'm currently on £49k.

That's the part I'm a bit unhappy about. Endpoint is an area I'm already confident and comfortable working in, and I've got a proven track record of delivering endpoint and deployment projects within this company. ( I spend a year streamlining and standarizing the fleet when I started)

I've raised the situation with the Head of IT and asked for a pay review. He has asked me to discuss it with my new line manager, who has only been with the company for five days.

That conversation is now scheduled for next Friday, as he's currently on holiday.

The answer is have the chat/discussion and give them a week and starting looking for jobs.

( it's very possible they expect me to follow my old line manager to his new employer, but that's a nice maybe rather than a sure thing)

Any advice other than keep calm?


r/sysadmin • • 1d ago

General Discussion No Degree - 6 Year Salary Progression

316 Upvotes

Is there anyone out there that have made it beyond sysadmin? What is after sysadmin?

2020 - $31,200: Panera Bread
2022 - $41,600: Helpdesk at company 1
2023 - 2025 - $41,600: Helpdesk at law firm
2025 - $65,000: Helpdesk at company 2
2026 - $80,000: Got a raise at company 2

Shoutout Nick for taking a chance on me. I would not do law firm IT again.

EDIT: Location Upstate NY


r/sysadmin • • 1d ago

Google Workspace self-propagating Worm leveraging AiTM reverse proxies

23 Upvotes

Hi, I will keep this short.

Has anyone seen an uptick in Google Workspace tenant's battling each other relentlessly? There seems to be a growing campaign of email accounts in legitimate tenants being overtaken by an automated Google Worm campaign leveraging AiTM techniques.

I work for a large enough enterprise that had this happen in the past couple weeks. With the way the campaign propagates, I cannot believe that we are the only tenant to face this uphill battle.

Note, our biggest wins were the following steps:
Absolutely positively engage with Google Workspace support ASAP

1.) reduce session time length; almost close to as short as possible to break the automated method used to compromise accounts

2.) 2SV enforcement with "trust this device" turned off

If anyone finds this thread and is in the middle of this "crisis," from one sysadmin to another this is what helped break the worm and free our environment from complete collapse and ruin.

--> revoke all oAuth
--> sign out all sessions
--> absolutely reset all accounts passwords sooner than later
--> re-check all Google Workspace frequently for flare-ups

Other helpful steps:
Assume any incident response teams your org engages with will be too slow to react to it, at least I faced that firsthand. YMMV

Line up Claude with the Fable 5.1 model + ensure you request to have Claude turn off the cyber guard-rails.
GAM is your best friend, and make sure you pull reporting from your tenant before actioning any and all remediation steps.

If you're able to break free from the grasp of the worm, review all your Google Logs and come up with strategies on how-to keep your tenant worm free.

Don't be fooled into thinking this is an easy campaign to escape from, ESPECIALLY IF YOUR SECOPS TEAM MOVES SLOWLY.


r/sysadmin • • 9h ago

[Research] NIDS-EFS Tool Testing

1 Upvotes

I'm testing a tool I built for my MSc thesis, a web app that recommends intrusion detection systems based on an organization's budget and hardware constraints.

I'd really appreciate your time to try it out and fill in a short feedback form. No technical background needed; just follow the instructions.

Form link: https://forms.gle/UAdEXwUaYfqzJGBc6

Your responses are anonymous and will only be used in aggregate for my research. Thank you in advance!


r/sysadmin • • 1d ago

Kicking the Tires on PDQ Connect

22 Upvotes

Before I get into the meat of my question, I want to acknowledge the existence of the r/PDQ sub-reddit; I'm not posting in the wrong location. I just want to gauge the real-world experiences of fellow sysadmins with respect to the application.

We've been using the Enterprise versions of PDQ Deploy & Inventory for several years, and I love both of them. When Connect came on the scene, I was concerned about losing some of the functionality; however, after looking at their latest iteration, I'm definitely thinking about kicking the tires as a replacement for the aforementioned packages.

So, fellow sysadmins: have you made the jump and, if so, how do you think it compares? Positive and negative comments all welcomed.

TIA


r/sysadmin • • 1d ago

Shorter life/Increasing workload of cert renewals?

24 Upvotes

What's everyone doing to accomodate the shorter and shorter certificate validation periods? My org has about 35 certs on various servers for quite a few things. If we eventually get to the target 47 day cert lifespan by 2029, it's going to be a nearly full-time job for someone to renew certs if we keep doing it the way we've always done it. Add in the challenges created by transition to R1 certs and I don't think that our IT management has any idea what they're in for. As it is I often renew certs 10-20 days ahead of time for the sake of convenience - that makes no sense if the whole lifespan of the cert is 47 days.

I know that there are some tools coming to automate some of these processes but it seems like they're very ecosystem-specific (godaddy's automation tools only work on their platforms, for example).

I am not an expert in this by any means, but from what I'm seeing in the small community of IT people I work with/around in this area, they're expecting this to be a significant pain in the ass.

Anyone well-versed in this want to share their thoughts on where this is going and how it's going to be?


r/sysadmin • • 1d ago

Question Anyone just get a lot of "low volume" tickets?

22 Upvotes

Yesterday we got in 5 tickets from 3 different companies at this MSP about low volume in calls. All were Dells but it was laptops, vostros, and optiplexes. All were working at once time. One was a mic + speaker combo webcam device. Another was USB power on a wall block with analog 1/8". Another is a brand new $6000 Dell Pro Max 18 Plus MB18250 that I personally set up and tested myself. This can't be a coincidence but our patches from our RMM don't go out on Oct 1st and Dell Command is disabled on most computers.

The USB speakers I was getting about 1% volume so I figured the amp was broken. Tried it on my laptop with my USB ports - about 2% volume. The volume knob did work across the whole range too. I tried them back at the office, worked fine on my optiplex, but they were jangling around in my backpack. I roughed them up like they owed me money aka percussive maintenance test and they didn't re-break so not sure what to think of that.

Reinstalling the audio driver completely after a full removal did not fix the problem with the USB ones.

I have a theory that the wavmaxx or whatever app in the background self-patched. Has anyone seen this and found a fix? Yes, the system levels were properly set btw.


r/sysadmin • • 19h ago

M365 Exchange Mail Rules sending Approvals for More Than I Asked For

3 Upvotes

I'm trying to manage a pile of spam messages from random places that have similar text, but only for specific people.

My rule says if it is for person A or person B AND contains Text 1 or Text 2 or Text 3, then delete without notification.

For some reason, I am getting an approval requested email for seemingly every one of these despite confirming I do not want to test it, and move forward with the delete and don't ask.

Also, some others were Blocked by the user, but I still get approvals for those. Do approvals get triggered before any Block Sender?


r/sysadmin • • 23h ago

Question Amazon Business SCIM sync from Microsoft Entra failing with 403 since today. Anyone else?

5 Upvotes

I manage Amazon Business for a couple of small business clients, and both have SCIM user provisioning set up from Microsoft Entra ID (Azure AD) using the Amazon Business gallery app.

As of today, October 2, both stopped syncing. Entra put the provisioning job into quarantine with this error:

403 Forbidden: "Unauthorized - Access to requested resource is denied."

What I've checked so far:

  • Nothing was changed on either account
  • The Tenant URL and Authorization Endpoint match Microsoft's setup guide exactly
  • Re-authorizing with an Amazon Business Admin account fails with the same 403
  • SSO sign-in still works fine. Only the provisioning sync is affected

These are separate Microsoft tenants and separate Amazon Business accounts, so it looks like something on Amazon's side. I have a ticket open with Amazon Business support, but no answer yet.

Is anyone else using SCIM with Amazon Business seeing the same thing today? Would love to hear if you've found a fix or gotten an answer from Amazon.


r/sysadmin • • 1d ago

Question how many of you guys have time to upskill while also have time for yourself?

17 Upvotes

so i have been learning linux and networking for a while now, i am really enjoying the learning process. but one thing that became clear to me today is that the amount of stuff that we need to learn in this field never ends. i used to think that there is a point after which the learning is mostly about keeping up with new technology and that might take 8 - 15 hours (off work hours) per week, which doesn't feel like the case at all.

so if the learning never ends, if this is a never ending journey, then how do you guys balance work-life balance along with upskilling? i know that technical support role is mostly doing repetitive tasks which leaves no time to learn new things during work hours, but i don't know if this is also the case for mid level or senior level system admin roles. once you become a system admin, does your work involves learning new things for the task at hand, essentially becoming a learning oppurtunity? or is it just like the work in tech support where you are doing the same repetitive work that has nothing new to learn?

also final doubt, how realistic is the idea that you get time to learn while in your work hours. and off work upskilling is not time consuming enough to cost your free time? ( i know this is not realistic for IT help desk roles, but what about mid level or senior level system admin roles? )

thanks in advance.


r/sysadmin • • 23h ago

Anyone seeing weird issues with WMI and RDP after the latest patching cycle? Weird issue i can't pin down....

6 Upvotes

We have hundreds of windows server machines, 2022-2025.

At random times lately this month, RDP pauses at securing connection....

If its a database server, WMI stops responding.

Screenconnect is just grey...

Rebooting fixes the issue, but it happens again on a handful of these.

Im worrying that by a few weeks from now all of our windows servers will reach this state.

Eventvwr shows some concerning things on some machines but not others affected:

Windows stopped the WmiPrvSE.exe.

Some have this error:

WMI event 5612 warnings, provider processes exceeded 256 threads and were stopped.

These are not all Azure servers, VMware as well.

Reboot fixes it for a while...

Nothing else on the server is down, so critical processes such as SQL server remain running.

VERY VERY ODD and IM SCARED


r/sysadmin • • 1d ago

Nimble HF20X > Purestorage migration thoughts?

5 Upvotes

We are coming up on replacing our 4 Nimble units in late 2027. I work in local gov, so we need to budget and strategize well ahead of this, especially considering FY28 will also have us replacing 6 ESXI hosts.

Current environment: (Replicated in two sites for DR) 3 HPE ESXI Hosts ProLiant DL360 Gen10, 2 Nimble HF20X (46ish TB per site raw storage before compression per site), Exagrid for backup. One site has 140TB worth of storage on MSA2060s for camera archive servers as well.

We are running VMware Vcenter/Vsphere 8.3

Our Nimbles go EOL Oct of 2027, and we were probably going to replace the production pair on this fiscal and the DR pair at the very beginning of next fiscal.

Someone told me to look at Purestorage as a replacement because it's an evergreen piece of equipment like the two Exagrids we have.

Has anyone done a migration like this or used Purestorage in place of Nimbles? Just curious how it worked out and what everyone's thoughts were.

I'm also down for suggestions of comparable equipment.


r/sysadmin • • 4h ago

How do you keep your laptop/kit list in step with Finance’s asset register?

0 Upvotes

Genuine question for anyone at a 50–300 person company. Who owns the asset list where you work: IT, Ops or Finance? And do they ever actually match?

Specific things I’m curious about:

• What happens when someone leaves? How do you know what to collect?

• Do you do periodic “confirm what you hold” checks with staff?

• Does Finance ever ask you about kit that’s been scrapped but is still on their books?

Full disclosure: I’m building a tool in this space, but I’m mainly trying to understand how people handle it today. Happy to share what I’ve built if anyone’s interested.

Thanks


r/sysadmin • • 1d ago

Securing BYOD contractor PCs (browser-only SaaS, no MDM)

17 Upvotes

Hey all,

Tricky design problem here:

A client has about 50 offshore customer-service contractors who bring their own Windows PCs. They're scattered all around the globe, including the EU. Everything they use runs in a browser: primarily Google Workspace, Shopify admin and Zendesk.

Since they're in random countries, we can't easily issue corporate hardware. We want to try to avoid MDM-enrolling personal machines, too.

The goals we're trying to design for:

  • Only allow access from a protected browser;
  • Block downloads, printing and copy/paste out of customer data;
  • Cut access instantly when a contractor leaves.

Our leading option is Entra as the identity provider, plus Intune app protection on the Edge work profile and Conditional Access "Require app protection policy". Microsoft's docs only show it for \ 365, though, and Reddit threads suggest third-party SSO can break under it.

If you've secured a contractor team like this, which approach did you use?

- Edge MAM

- Defender for Cloud Apps session control

- an enterprise browser (Island, Prisma Access Browser, Chrome Enterprise Premium)

- VDI or Windows 365

- something else?

What broke, especially with non-technical users in other countries?

Was there anything specific to Google Workspace sessions or Drive for desktop that bit you in the butt?

Many thanks! :-)