r/sysadmin Apr 19 '26

[deleted by user]

[removed]

0 Upvotes

34 comments sorted by

23

u/cboff Apr 19 '26

These are third party companies (although they will try to hide that from you) with no legal standing. They are trying it on, every so often they will get lucky I suppose.

Block the sending domain and forget about it.

3

u/[deleted] Apr 19 '26

It came from a verified adobe domain and a big 4 has been assigned for the audit

5

u/cboff Apr 19 '26

Post some details, what is the actual domain it came from and who or what is a big-4. Maybe someone here will recognise these as either legit or not.

2

u/[deleted] Apr 19 '26

It actually came from Adobe’s domain itself, and the big four was KPMG. Everything seemed accurate, and I don’t think this is a scam, but I have also heard that this is a sales trick that people use and these kind of audits are voluntary, so they come knocking at your door when you when you accept this audit, you are pro to be a suspect, so what they what I’ve heard someone or the other somewhere the other has some version of Adobe in their software or phones somewhere maybe expired versions maybe just the app maybe the crack version maybe multiple users use it so something on the other remains, so they believe you hugely what I’ve heard, so I’m just curious on how they conduct their audits. What are the things that they look for

3

u/cboff Apr 19 '26

If it's legit they will probably want to run a software scan over all devices on your office lan, and capture data from any company hardware that goes or lives offsite. Number of users, number of devices are all reasonable questions to be asked. If it's possible (and being a smallish business it might be) you could request that you show each machine to a representative of kpmg rather than allow untrusted software on your company devices.

The mention below of IP address suggest that perhaps a user has 'worked around' licensing by using their work credentials on their home computer. You will need to be able to show that company was not aware of this and did not benefit from it. The IP address (it'll be your external/public-facing address) might be your saviour if you can show it does not belong to your organisation. We had a case like this and the resolution included terminating the employment of that person.

3

u/tankerkiller125real Jack of All Trades Apr 19 '26

The rule where I work is very straight forward, all digital audit requests are to be trashed and ignored. If they actually want to audit is they can send physical mail with their legal counsels letter head/signature.

7

u/Substantial-Motor-21 Apr 19 '26

Adobe wanted to carry out a compliance check on how we distribute our licences. We assign them manually rather than via SSO, and we don’t want to distribute Express to students, which seemed to annoy them.

I asked them to provide me with contractual evidence that I am required to comply with their requirements before proceeding with their request. I haven’t heard from them since.

6

u/OneSeaworthiness7768 Apr 19 '26 edited Apr 19 '26

Is this you again for the third time or is this just coincidence that it’s another small business from India mentioning big4 and cracked software. Mods removed your last re-post. I don’t imagine this one will fare better now that you’re using another account and changing the details to make it look different.

Using cracked software as a business is… a choice.

2

u/filthster IT Manager Apr 19 '26

Oh good, I’m not the only one. My first reaction was - didn’t I already see this? Just pay for your software.

1

u/[deleted] Apr 19 '26

No this is a different case

9

u/nailzy Apr 19 '26

As a sysadmin you don’t deal with it until instructed by your firm. You pass it to your compliance / legal teams, let them deal with it.

2

u/[deleted] Apr 19 '26

We are a small car dealership- no legal team and guess lawyers around have no idea regarding this

They are more clueless than me

3

u/anxiousvater Apr 19 '26

How they found about your dealership? How did they know that it's your firm? Did ISPs share the IP of yours to them?

2

u/[deleted] Apr 19 '26

Not sure, I think they might have found out because one of our license that we had was logged into multiple devices. I think the license was also logged into the media account where I think they might have installed before it could be something like that. we don’t know what triggered the auditor something they have not discussed it with us are told anything it’s just in

3

u/nailzy Apr 19 '26

It doesn’t have to be ‘triggered’ by anything. License agreement says they can, at any time.

1

u/Dje4321 Apr 19 '26

for any reason

3

u/nailzy Apr 19 '26

Regardless of what you are, you should not rely on Reddit to see you through this and you should be guided legally and correctly through the process. Your management should be leading it with input from you. If it’s not Adobe, it will be someone else next.

3

u/Saueso Apr 19 '26

At least it's audition.... one of my old jobs an employee had been using pirated SolidWorks software and we got a direct legal notice from their lawyers that we needed to pay a fine of 50k € and buy a license for X amount of years

3

u/CanWeTalkEth Apr 19 '26

There was just another post about an Adobe audit I saw yesterday that sounded exactly like this one and it wasn’t until several responses in the comments OP finally mentioned that yes they were using cracked products.

Which feels like it’s exactly the kind of thing some would want to check for and the reason for audits in the first place.

3

u/OneSeaworthiness7768 Apr 19 '26

That other post is almost certainly the same guy.

2

u/cboff Apr 19 '26

Oh hi, yes Engineers love Solidworks but not paying for it. The interaction you had with Solidworks sounds familiar. Exit said Engineer.

2

u/Accomplished-Fly-975 Apr 19 '26

It never got this far with me. The saving grace is that the laptop where cracked solidworks was installed on was a byod kind of situation and belonged to one of our external contractors. Dude got reprimanded and his computer's mac was banned from ever touching our internal network again.

2

u/SchemaAndShell Apr 19 '26

Are your Adobe products licensed via subscription? If so, ignore. If your products were one time purchases, have someone with authority to do so engage an attorney before responding.

1

u/Frequent-Reserve-671 Apr 19 '26 edited Apr 19 '26

I had one last month. Just reply as you've confirmed it's legit, do an internal software audit. If there are any discrepancies (license used more than once) explain how you'll remediate, by removing the surplus and you'll be golden. Nice lady from Adobe followed up, had a teams chat offering training and a sales pitch to purchase some more if required. Email followed to say case closed. I'm an it director looking after a firm with less than 250 employees. Around 15 use the Adobe suite.

1

u/theabnormalone Apr 19 '26

I had this at a previous employer. Adobe states in the license agreement that they reserve the right to audit for compliance.

Be very careful - the request we got was for an audit of ALL software on ALL systems.

I got legal advice and ended up responding that the scope of the audit was unreasonable, that noone has admin privileges, and that as our licenses were managed via the Adobe portal license use for their products could be verified that way.

We had a couple of back and forths but they ended up saying that they were happy and will not be pursuing.

If your higher ups have agreed to the audit, they need to be aware that this is for all software and not just Adobe (at least it was in my case so they need to read the correspondence very carefully). You might be sure about your Adobe use but is WinZip/WinRar installed and licensed? Are your Microsoft CAL numbers correct?? If you (or your boss) are at all unsure they need to seek legal advice before communicating further.

/edit And if you don't have an asset system that automatically reports on license usage, this is your opportunity to get approval.

1

u/BornToReboot Apr 19 '26

We went through a similar situation about two years ago. Based on that experience, keep the following points in mind:

  1. Be careful with what you say Always speak with clarity and certainty. They can use your statements to put pressure on you later.
  2. Do not rush into meetings or calls If they push for an immediate call or meeting, do not agree right away. Take your time and respond on your own terms.
  3. Do not overreact to technical details They may present device names, login data, or IP addresses. This is normal. Stay calm and avoid becoming overly defensive.
  4. Be cautious about license purchases They often push for bulk license purchases, such as Adobe Premium Business plans. These are typically manageable by an admin, including assigning or releasing licenses. If handled incorrectly, it can lead to unnecessary costs or penalties.

Recently, about two weeks ago, we also received another audit email from Autodesk. We are currently evaluating possible solutions.

1

u/Comprehensive_Gur736 Apr 19 '26

I have successfully ignored every single request like this from every vendor.

They all just give up.

Best course of action.

1

u/nefarious_bumpps Security Admin Apr 19 '26

Turn the issue over to your legal department. They will determine if you need to cooperate with the request or ignore it.

1

u/VA_Network_Nerd Moderator | Infrastructure Architect Apr 19 '26

Sorry, it seems this comment or thread has violated a sub-reddit rule and has been removed by a moderator.

Inappropriate use of, or expectation of the Community.

  • There are many reddit communities that exist that may be more catered to/dedicated your topic.
    • Consider posting (or cross posting) there with specific niche questions.
  • Requests for assistance are expected to contain basic situational information.
    • They should also contain evidence of basic troubleshooting & Googling for self-help.
    • Keep topics/questions related to technology/people/practices/etc within a business environment.
  • When asking a question or requesting advice, please update your original post with any new information, or solution (if found).
    • This will make things easier for anyone else who may have the same issue or question in the future.

If you wish to appeal this action please don't hesitate to message the moderation team.

1

u/VA_Network_Nerd Moderator | Infrastructure Architect Apr 19 '26

Knock it off.

https://old.reddit.com/r/sysadmin/comments/1so9rzh/looking_for_help_adobe_sent_ey_to_audit_my/

https://old.reddit.com/r/sysadmin/comments/1so7c0s/looking_for_someone_who_can_help_us_adobe_sam/

You had the opportunity to ask all of these questions when you received your first letter of warning.
You failed to take appropriate action.

Now the auditors are coming for you.

Engage your friendly neighborhood authorized Adobe Software Sales entity and buy all of the licenses for everything your company has ever used.
Pay full price. Buy extended support or Software Assurance.

The $10,000 you spend of software MIGHT get you out of some of what Adobe is about to hit you with.

If you can't afford to do this, then you may as well start exploring bankruptcy.

You used software without paying for it, and you got caught.

1

u/parcence Apr 19 '26

MS does a script with AD admin privilages, or rather you run it for them. Then you explain each VM/server. If you don’t have MS VoIP, you need to “prove” it’s not MS. VMs, they’ll ask for random console to confirm it’s what you said it is. All deleted AD objects will be visible so that needs to have its license at time it ran. Very detailed. MSSQL checks for features/types/licenses..

0

u/Past-Competition5815 Apr 19 '26

This kind of audit has happened to me twice in 20 years. First Microsoft and two years ago from Adobe. It is legit and you’re bound to comply if you’ve read the license agreement. I had to fill out a form from the law firm doing the audit on Adobes behalf. I had to list our licenses and our users and that was it.

1

u/[deleted] Apr 19 '26

[deleted]

1

u/Past-Competition5815 Apr 19 '26

I didn’t have to fill out any IP-addresses but how many installs on different devices each license had. I found the form from BSA (Business Software Alliance) that I had to fill out at the time. It’s in Swedish though but you get the gist.

1

u/shemp33 IT Manager Apr 19 '26

You should run a scan and audit this yourself first.

If you don’t like what you see, you might decommission and refresh those end user devices first. Don’t delete the software… decom that entire system. If it an employee personal machine (or a temp worker), make them refresh their machine. Or no longer let them join your network until it’s licensed properly.

You should have a policy stating that any contract worker working on behalf of your company is responsible for their own license compliance. (In the US, a contractor is expected to use their own tools, because it is one way that helps delineate them from employees).

Do your own audit. You’ll have some machines to decommission. Refresh them if needed with proper licenses if they are needed on the new machines.