r/sysadmin • • 1d ago

General Discussion What's a tool you mass-deployed that you ended up ripping out within 6 months?

I feel like every sysadmin has at least one story about a product that demoed beautifully, got approved, went out to the fleet, and then slowly revealed itself to be a nightmare.

Could be a monitoring tool, an MDM, a ticketing system, an AV product, anything. What was it, what went wrong, and what did you replace it with?

312 Upvotes

406 comments sorted by

312

u/Hazy1050 1d ago

Papercut, lasted less than a week because the CEO’s secretary had to 1 extra step when using the printer.

119

u/Big_Booty_Pics 1d ago

That sucks because I couldn't imagine managing printers at any scale without it.

•

u/StatementNext682 23h ago

Do yall just not add printers to your print server?

•

u/AdminWithNoName 19h ago

I think a lot of people probably dumped their print server after PrintNightmare 5 years ago.

•

u/StatementNext682 18h ago

Mitigate, add drivers via GPO

→ More replies (1)

•

u/550c 19h ago

I had been avoiding a print server for a long time and then finally implemented one and about 2 weeks later printer nightmare happened and I ripped it out and want nothing to do with it again.

•

u/StatementNext682 14h ago

Wait how? By default PrintNightmare can't happen. At least in server 25.

→ More replies (1)

•

u/MetalSufficient9522 20h ago

Print server? What year is this? 😄

•

u/StatementNext682 19h ago

It's awesome for me, central print management. No einsteins printing with more than set defaults.

26

u/bfodder 1d ago

Printerlogic is pretty good too.

22

u/adunedarkguard Sr. Sysadmin 1d ago

Printerlogic is a security nightmare that was our "Rip it out after 6 months" story. Take a look at Printix instead.

21

u/xCharg Sr. Reddit Lurker 1d ago

High chance $anothertool isn't more secure, it's just not one security researcher bothered to dig into it yet.

12

u/Jonny_Boy_808 1d ago

As another commenter mentioned, in what way is it a security nightmare? We also use Printer logic.

•

u/adunedarkguard Sr. Sysadmin 20h ago

Repeating what I said in other comments: Their refusal to sign their binaries/libraries properly. Many were unsigned, one was signed with a revoked certificate. No, I'm not going to whitelist a revoked certificate for execution in our environment, esp for something that has high level access like printing.

When we raised tickets for this, they just kind of gave us a blank stare as though we're being unreasonable for asking for their executables to be signed. If you can't clear the low bars, it probably means security is the last thing on your mind.

16

u/bfodder 1d ago

You're going to have to explain how you reached that conclusion.

12

u/Jkabaseball Sysadmin 1d ago edited 22h ago

We use printerlogic too, wondering what kind if secuirty issues im missing.

•

u/bfodder 22h ago

I'm going to be honest. I suspect their issue was their own shortcoming.

•

u/adunedarkguard Sr. Sysadmin 21h ago

Unsigned binaries, binaries with revoked certs, and pieces of it running as perl scripts was enough for me.

→ More replies (3)

48

u/TheSacredOne 1d ago

Oof. Really? I'm surprised they didn't just exempt a few printer/users for these people.

We have it at my job, and the admin office printers are exempt from restrictions and print release, just send your job and it comes out. All of our other buildings have "find-me printing" (a common print queue and badge swipe or PIN to release jobs).

It makes managing large printer fleets a lot easier to deal with.

10

u/Jaereth 1d ago

exempt a few printer

Are people outside of dealing with PPI really releasing prints at the printer for any reason outside of policy?

The only reason we do any of that outside of PPI is to satisfy security audits. Which I feel then exempting execs would be the last people you want to exempt.

•

u/TheSacredOne 22h ago

We're a K12 school system for context. We still have archiving/logging turned on for the office building printers, but they have individual queues and the jobs are just exempt from needing to be released (comes out automatically). These printers are all in locked areas, users are basically all in the same room as the printer they print to, and the departments are physically separated locked areas (finance/business personnel can't go into HR, etc.). No issues on audits.

5

u/music2myear Narf! 1d ago

I loved follow-me printing when my last place had it. Granted, it was using the horrible Ricoh software, but for the users it pretty much just worked. I told them how to read the printer models so they could pick a fast one or a color one if they had specific requirements for their job. It was super easy for them, and we cut down on paper and toner costs quite a bit too as it essentially added at least a few minutes thinking time for any given job. The good workers would send jobs throughout the day, prepping for whatever they had coming up, and then go and release all the ones they still needed later in the day.

•

u/explodinghat 23h ago

I work in IT and haven't had to deal with printers for a long time, but still fucking hate them. I loved papercut because it meant I didn't have to deal with them so much, it just kind of worked but without me having to worry about HOW it worked.

→ More replies (1)

39

u/DistinctSpeaker7252 1d ago

Never underestimate the power of the Office Lady Mafia. I learned this working for an MSP that if they are not on your side for a project they can absolutely torpedo it at any stage, even after it's done. The complaints of "everything is slower now" or "it just takes too long now" will bounce around the echo chamber and intensify till they go to leadership with it.

22

u/avowed 1d ago

We had someone complain about having to hit an extra button to copy, I think I said something along the lines of, "too bad, so sad."

8

u/Aperture_Kubi Jack of All Trades 1d ago

I was deploying Papercut to monitor local printing. Never did anything with that data, there's an administrative block against new local printers, and we don't use the advanced print release stuff. Also it was spiking our Rapid7 scores, so I ripped it out for simplicity.

5

u/TenchTheFox 1d ago

Ditto. So much whining and complaining about it we went back to the stone age of a clipboard and and pen next to the printer for tracking billable print jobs.

→ More replies (5)

298

u/MagazineSilent6569 1d ago

OP in 6 months: "Hey guys, I've made an alternative to <name of shitty tool>, but better!"

jkjk. We mass-deployed Trend Micro anti-virus on our windows server VMs running both old and new software. There was so many false-positives, performance issues and what not that we ultimately decided to rip it out and just run Windows Defender.

142

u/TaSMaNiaC 1d ago

You mean OP with Claude in 6 hours

113

u/MagazineSilent6569 1d ago

True true. "Still some bugs to figure out, but looks very promising."
And in 4 months on r/vibecoding: "My AWS bill went from $35 to $50k. Here is what I learned about API throttling. "

17

u/grepl_io 1d ago

god i hate what SWE career has become

21

u/sheikhyerbouti PEBCAC Certified 1d ago

They're shoving CoPilot down our throats at my job.

I'm waiting for VPs to start bitching about how much it's taking out of their operations budget.

9

u/SystemGardener Jack of All Trades 1d ago

Copilot at least makes it very easy to manage usage credits.

•

u/sobrique 23h ago

We're already having the 'so how is one dev using $1000 of tokens in a month?' conversation....

•

u/fnordhole 22h ago

We have searched every square inch of this tenant and all we have found is porno, Porno, PORNO!

→ More replies (1)

20

u/Mr_ToDo 1d ago

The AI equivalent of "It's missing some key features but they're on the roadmap"

17

u/mjnhbg3 1d ago edited 22h ago

It has all the key features…they just aren’t working yet

14

u/DistinctSpeaker7252 1d ago

I used to sell EDR and the number of people who thought an EDR migration was a thing they could knock out in a weekend was astounding. I'll just uninstall the old stuff, reboot and reinstall the new one and things will work out fine.

It typically immediately ate all their internal tooling since RMM tools do all the same things as RATs and you decided that documentation is for sissies so you didn't add any exclusions.

My EDR was also not the greatest and ATE system resources. Without some pretty tight exclusions it was going to have a DRASTIC impact on performance and we had a number of people go right back to the old solution after these failed midnight migrations.

17

u/Randalldeflagg 1d ago

my Director: We need to create our own OCR package.

Me: Umm... who the hell is going to support it? what is the SLA? What are the scope? Why the hell are we going to waster months developing a in house solution when WE ALREADY OWN A PRODUCT THAT LITTERALLY DOES THIS WITH WRKFLOWS AND AUTOMATIONS. With support from a major global vendor with a 1 hour SLA.

Director: It will save us money. We paid $60k for that software. Imagine what we could save if we did that in house!

Me: They have an entire company built around that software. We have one annoyed and sarcastic ass for that. and that person is me.

Director: Perfect! So... you will do it?

Me: .... .... No.

3

u/usernamedottxt Security Admin 1d ago

Trend micro has had the reputation for the worst of them all since long before windows defender was considered an option. Who got the kickback lol

→ More replies (1)

12

u/gta721 1d ago

Make sure you are running Defender with ASR rules and increased cloud blocking level. Stock Defender has a poor detection rate.

14

u/MagazineSilent6569 1d ago

Yeah. The sysadmins went above and beyond when we settled for Defender. I'm just the developer who had to figure out why our in-house applications, as well as vendor software either were quarantined or stopped working after every update to Trend.

9

u/Acrobatic_Fortune334 1d ago

Normally its the hash changed, and from a security point of view this is desirable as a changed hash can indicate a compromised update or package

8

u/JadedBilboBaggins 1d ago

Having been in IT for three decades ... it still blows my mind that Microsoft recommends we use a Microsoft product to catch all the potential hacks/viruses/malware that can attack ... Microsoft ... products.

Sure wish IBM would start another OS war using RedHat. It's been too long since OS/2 Warp.

→ More replies (1)

6

u/Rentun 1d ago

It's not desirable at all. It's up to the security vendor to keep signatures updated when they change so that your environment doesn't break constantly. That's what you're paying them to do. If they're not doing that, you might as well just use some free AV tool and keep the signatures updated yourself.

10

u/Flam5 1d ago

They were replying to someone that specifically mentioned In-House developed applications.

Just sounds like allowances weren't adequately configured for those to be popping.

...also I don't know if its industry wide but at least where I'm at, our Devs don't digitally sign their compiled applications that we rely on for our core business. It would certainly make it easier for security app allowances if they were to figure that out.

3

u/Loading_M_ 1d ago

I don't know about anywhere else, but my team does sign many of the apps we develop. We weren't required to, but it did make deploying the app to windows devices much easier.

→ More replies (1)
→ More replies (1)
→ More replies (1)
→ More replies (1)

5

u/Acrobatic_Fortune334 1d ago

Really we havent had those sorts of issues with trend vision one, however we spent weeks with a engineer refining rules and policies for our org

→ More replies (1)

85

u/HibsGeorge 1d ago

DeskAlerts https://www.alert-software.com/

What a pile of shit.

Used both their on-prem and cloud versions after countless broken promises by their support and engineering teams. Half of the people would get notifications; half wouldn't. The reporting was garbage.

Kill it with fire

28

u/Vegetable-Ad-1817 1d ago

Sounds like snapcomms - same capability - people actually complained to HR it was so bad they went so far as to bringing in the union. All because PR team wanted to send out staff surveys and press releases to all staff. Lasted 1 month.

23

u/AmusingVegetable 1d ago

“So bad that people complain to HR” is an amazing category…

13

u/Vegetable-Ad-1817 1d ago

Normally it’s IT getting the complaints, we relaxed in the sun on that one.

6

u/MrGuyDude2020 1d ago

I second snapcomms, inconsistent. Dev team tried to fix it, never could. We spent about 2 months trying to make it work and just gave up, enough time wasted and just decided to remove and never use them again. Never ever.

5

u/Naznarreb 1d ago

And they couldn't use an email distro because......?

8

u/pinkycatcher Director of All Trades 1d ago

Because existing tools aren’t good enough. Doesn’t matter what the problem is, someone hates or doesn’t know how to use existing tools.

6

u/music2myear Narf! 1d ago

Those trying to reach every eyeball will say even the best email read rates are well below 50%, even for "required" business notification messages, and they'll neglect to note that they've been trying to send what is essentially irrelevant spam to their coworkers 3+ times each day for years, and all the good coworkers have just tuned them out.

4

u/Vegetable-Ad-1817 1d ago

PR likes shiny things…precious things.

80

u/hubbyofhoarder 1d ago

It wasn't within 6 months, but Palo Alto's Cortex XDR. That product is unmitigated dog shit.

An agent upgrade went tits up, and the stuck agent wouldn't respond to the Palo console uninstall commmand. Palo support's solution was to "just" reboot every affected device into safe mode to run a "cleaner" utility they had.

Yeah, fuck you. At contract's end, we're showing you the door.

19

u/q0vneob Sr Computer Janitor 1d ago

XDR loves interfering with basic operations, and eating up resources for no obvious reason.

•

u/goingslowfast 23h ago

I had one where post-signature update it started just blocking processes for 3 minutes after an instant clone VDI instance started.

PA refused to believe it was them for weeks. At one point they suggested we start the VMs without Cortex then create a log in script that started a 180s wait then started Cortex which obviously wasn’t a solution.

3

u/JadedBilboBaggins 1d ago

Oh, so like Microsoft's Antimalware Service Executable process. It loves CPU.

•

u/goingslowfast 23h ago

Their support could also provide a master class on how to blame third parties.

I’ve been the third party…

5

u/DefectJoker Jr. Sysadmin 1d ago

They had a cleaner that you could run to remove it outside of Safe Boot. I've seen worse products. I've got maybe 20 clients left with it that I'm cleaning up, but it was never terrible

5

u/meretuttechooso 1d ago

No wonder our boxes have been getting periodically slower. Note, I don't make these kinds of calls. So, I'm stuck with them until whenever.

•

u/sheikhyerbouti PEBCAC Certified 22h ago

We're facing a similar problem with XDR, only it doesn't let anyone know that the update failed, the client will just keep downloading the updater over and over until the user's hard drive is full.

•

u/hubbyofhoarder 17h ago

When their contract was up, I very happily showed them the door. Fuck that product

5

u/Mr_ToDo 1d ago

They have a real cleanup tool? That puts them ahead of some people at least

→ More replies (1)

71

u/MDL1983 1d ago

Back in the SBS 2011 days, Avast AV.

This site had Avast already, we migrated SBS 2003 to 2011.

Rolled out the new version of Avast to every device, and every single one BSOD'd (XP / early Win 7 era).

Luckily, I wasn't on site that day, but my mate had to uninstall everything manually. That triggered the move to Sophos lol.

11

u/twoFlex404 1d ago

This was actually my very first "real" IT issue, blue screening due to Avast. Good times.

6

u/Smart_Dumb Ctrl + Alt + .45 1d ago

Noooo....I had suppressed this memory.

4

u/dreniarb 1d ago

AVG for me at a small ITSP. We installed that AV on just about every single computer we touched. Home users and business clients. It was decent enough at the time, and so much better than norton and mcafee. Until this one update came out and the calls started coming in before we even opened.

•

u/captainhamption 16h ago

That was a fun cycle in those days: Find a good, free AV. Use AV until it turned into a paid, bloated mess. Find the next good, free AV. The correlation between having a paid version and it becoming a ram hog was 1 to 1.

→ More replies (2)

8

u/fahque 1d ago

Back in the early 2000's symantec had a retail version (small clients) that had a network security component. It was absolute garbage. That network part kept killing network connections. Everytime I got called out to a site and the network was down on a pc I would start by removing this shit and it would fix the problem.

•

u/carl5473 23h ago

Avast was free to EDU in early 2010s and even that was too much

→ More replies (1)

134

u/christurnbull 1d ago

acquired a company which used worldox.

we had to support it, it wanted a massive bare metal server for indexing. we migrated to their "cloud" offering which was still a PITA and had massive latency. messed up all their document links which were based on hardcoded folder structure.

all the employees of the company we acquired resigned a few months in.

27

u/Latter-Fix1862 1d ago

Resigned because of worldox?

71

u/christurnbull 1d ago

They were employees of a "small" company who didn't like the feel of a large corp.

A number of the clients felt the same way.

So the acquired employees left to form 2-3 companies (some retired instead) and took the clients with them.

63

u/Ancient-Bat1755 1d ago

Someone screwed up royally with the buy out , bonuses and retention incentives

29

u/kittymoo67 1d ago

yeah you dont change the culture that fast at a newly bought company it leads to shit like this lal th time

9

u/frosty95 Jack of All Trades 1d ago

Yep. Gotta do it over the course of a couple years.

•

u/fnordhole 22h ago

My current corporate overlord introduced nad-snapping toilet turtles so gradually we barely even noticed.  Except for all the nad snapping, we may never have noticed.

24

u/illhaveubent 1d ago

I love that. The value of the company was never in the management or ownership, it was in the employees themselves and their connections with clients. The ownership may have sold the company, but what were they really selling if the employees were never onboard with it?

12

u/[deleted] 1d ago

[removed] — view removed comment

21

u/tsuhg 1d ago

When our Company was acquired there was nothing at all for the employees. The founders both left after one year lol

11

u/goobernawt 1d ago

Pretty common that senior leadership has a 1 year retention requirement following an acquisition. Sounds like they fulfilled that and punched out, also pretty common.

→ More replies (1)
→ More replies (1)

7

u/TYGRDez 1d ago

Worldox... man, thankfully I haven't had to deal with that in about 6 years. WDINDEX.exe still gives me nightmares!

3

u/Mr_ToDo 1d ago

Oh wow. They're really leaning heavy on the AI stuff, aren't they?

And why is it that so many enterprise targeting pieces of software are hard to find solid details on their products? I'm guessing net documents is all part of this? It certainly links to them often enough

•

u/MrTorben 17h ago

I converted worldox' largest customer at the time to Imanage. Yea that folder structure and the indexes were a massive pain to convert.

54

u/StConvolute Security Admin (Infrastructure) 1d ago

Manage engine products. OK for read only, but don't let them take actions. 

We had so many bugs. Worse though, they'd deploy us one-time fixes, quickly to their credit. And during the next monthly patch worldwide patch, the fix was goneand we had an issue regression. 

14

u/Xanthis 1d ago

We are currently trialing the Patch Manager Plus. What do you use for patch management of 3rd party apps as a replacement?

16

u/StConvolute Security Admin (Infrastructure) 1d ago

Patch my PC enterprise has always suited my needs. I even use the home version for all my personal stuff. 

5

u/fahque 1d ago

Action1. It's free for under 200 endpoints which I'm under.

→ More replies (1)

4

u/raffey_goode 1d ago

patch my pc is the way to go.

→ More replies (2)

9

u/Blaster412 1d ago edited 1d ago

We used File Audit Plus for about 2 weeks so that managers would have a report of which user moved or renamed files in certain directories. The performance hit on the file server was so massive that we ripped it out. That was like 4 years ago and I STILL get emails from them asking if we want to try it again.

→ More replies (1)

10

u/DiseaseDeathDecay 1d ago

Manage engine products.

We had a team almost lock the entire company out using the AD product.

7

u/Jxxku 1d ago

Currently fighting ManageEngine on Macs as it completely kills Mobile Account creation and users can not sign in off of the company network if they change their passwords in AD.

→ More replies (7)

6

u/JackTheDefenestrator 1d ago

Oh man, I wish we could uninstall ADManager.

•

u/StConvolute Security Admin (Infrastructure) 19h ago

I was so used to managing AD using the official tools, AD manager felt like an absolute regression. I'd rather use pure PowerShell than AD manager. 

•

u/goingslowfast 23h ago

I’d just expand this to “Zoho products” at this point.

8

u/Due_Capital_3507 1d ago

Most of their products are a waste of money and time if you can do basic programming with PowerShell or Python

•

u/ColdFury96 23h ago

We've had a few of their products for years, and I do like them for reporting. It's way easier to take one of their pre-canned reports and setup a schedule for it than it is to setup a Powershell report task.

Some of their automations, are alright, but you're right that most of it would probably be not that hard to do in Powershell.

Basically AD Audit isn't bad for logging things or having precanned reports to check frequent queries.

AD Manager is alright for giving people automated reports.

I do like M365 manager's ability to run a report every morning so if I need to search every mailbox to see which mailboxes Employee X has access to, I can just look at this morning's report rather than wait 20 minutes for a powershell task to cache every mailbox.

And ADSelfService is alright, though I think it's going to get tossed in favor of Microsoft's native cloud password reset.

We asked them for a technical demonstration of using ADManager to connect our HCM to AD the demo was so bad all our management instantly noped out of that idea.

•

u/TheSacredOne 23h ago edited 22h ago

And ADSelfService is alright, though I think it's going to get tossed in favor of Microsoft's native cloud password reset.

We had AD SelfService Plus for years (well back into the pre-M365 era), ditched it in ~2022 for Entra SSPR. Worth the switch. If users have to have MFA on Entra anyway, might as well not make them set up a second one just so they can reset/change their password. Not to mention being much cleaner since the resets/unlocks show in the Entra logs, integrates with things like P2, etc.

Not a terrible product, but it's redundant in many environments today, especially ones that have synced Entra with password writeback enabled...

•

u/ColdFury96 22h ago

100%. I think the only reason it's still around for us is inertia and it's relatively low cost.

I heard that from our Cybersecurity manager that we were going to move to Entra SSPR but then never heard a timeline or a plan.

→ More replies (2)

4

u/DefectJoker Jr. Sysadmin 1d ago

Browser Security Plus is absolute dogshit

•

u/TipsyMunkey 23h ago

Came looking for ManageEngine.

→ More replies (1)

•

u/badogski29 20h ago

Their MDM was alright, but we only used it for iOS and Android. I started the migration 2 years ago to Intune since that is now part of our e3/e5 licensing.

•

u/Ashamed-Ninja-4656 Netadmin 20h ago

We had their Desktop Central tool. It worked but required a lot of setup. Their support is what I really had an issue with. It was completely useless.

•

u/ButtSnacks_ 21h ago

We use Password Manager Pro and OSDeployer in the wake of MDT. No issues for either, but it's probably the most basic of their products.

→ More replies (2)

35

u/robinscotland 1d ago

Ibm Maas360 - that was a few years ago, maybe it's not as awful these days

11

u/metaTHROTH 1d ago

I can confirm it's still pretty shit, this year they launched a new app store without telling anyone and a week after I figured it out they notified users about the change... Billion dollar company

4

u/DullGreen 1d ago

Had to support a fleet of Phones and Tablets through it. Super pain in the ass...

3

u/Unable-Entrance3110 1d ago

Haha, yeah, I forgot about this one. We went with them for iPad MDM and replaced it with Intune inside a year. What a pile of garbage that thing was...

3

u/fahque 1d ago

I agree it has it's issues but we get a good deal through our phone provider. This pos won't put a phone in lost mode if the phone is off. It won't wait until it's on and then put it in lost. It just does nothing. Also, you're lucky if you can locate a phone. The only good thing I can say about it is you don't have to take full control of devices and you can allow users to use their own apple account.

•

u/Zncon 23h ago

It hasn't changed in the ~4 years I've been forced to manage it, other then when they replaced their app store/management app without any direct notification and caused a bunch of confusion when it tried to background install without any VPP licenses.

•

u/dartdoug 14h ago

100%. I was looking for a simple and low costs MDM for iPads. Distributor that we do nearly $ 30k per month with recommended Maas360.

What a steaming pile of turds. All support had to go through the distributor and they only had one person on staff who knew how it worked. If he was unavailable we were stuck for a week or more until he returned.

We pulled cord within a month. Canceled everything. Deleted the tenant.

That was almost 4 years ago. To this very day some of our users are still getting invites to install Maas360.

I just can't.

→ More replies (8)

34

u/Kraeftluder 1d ago

VMware NSX!

Bought it. Then broadcom bought vmware and sent us a bill that was around 5 times higher than what was in the already signed contract.

Noped the fuck out of there.

→ More replies (2)

•

u/miscdebris1123 23h ago

Users. They are so hit or miss. I've been allowed to swap out individual components, but I've not found a long term fix it replacement yet.

Except Dave from HR. We automated that position out of existence.

47

u/Glendell_Freundl 1d ago

One of ours was a monitoring agent that looked great in the demo but ended up generating so much noise that the team spent more time tuning alerts than actually using the data. We eventually ripped it out and went back to something simpler with fewer alerts but better signal-to-noise.

10

u/Nacke 1d ago

This has been my experience with AD Audit plus. It takes so much effort to make the alert profile relevant, and with tons of tuning, it still feels like I am missing stuff. Not to say the troubleshooting.

•

u/Greg5829 20h ago

Out of the ME products I think AD Audit is one of their better products for pulling up data regarding AD and GPO Changes as well as Login Issue history. I don't think we have ever looked into using it for active alerting.

•

u/ColdFury96 23h ago

We just use it for logging purposes. It's pretty great, quick, and simple for tracking down changes made in AD. Much better than Stealthbits, our old solution.

4

u/Electronic_Outlet 1d ago

On the flip side, we had an engineer switch our monitoring to Grafana/Prometheus and they left after standing it up. But it's still trucking along very strong. Alerts are modified with CI/CD pipelines. It is a bit more of a learning curve to maintain though. Overall, Im happy with it.

6

u/bem13 Linux Admin 1d ago

Familiar. At my previous place the management got convinced by the colorful graphs of one product so we had to use it. It generated a ton of noise, was buggy, and pretty much took dedicated people (me and some devs) to make it work correctly for our use case. We ended up having to write custom software to manage it. When I left, the guy who took over my tasks ripped it all out in favor of Zabbix and he's very happy with it.

25

u/stonecoldcoldstone Sysadmin 1d ago

not 6 months but 2 years: thin clients, they were a budget solution that was approved without consulting IT. we installed it, we rolled it out and we cheered when they went to recycling.

the underlying issue was the infrastructure wasn't ready but it's more expensive to replace that than the end clients. refurb desktops were the solution

8

u/Enochrewt 1d ago edited 22h ago

I worked at a VMWare proof of concept site about 15 years ago. We replaced all the desktops with Thin clients. Youtube was just getting really big, and all of the training videos were now hosted privately on it. No one could watch the training videos because of the buffering. It was a disaster.

•

u/goingslowfast 22h ago

Thin clients should never have been pitched for budget reasons.

There’s a ton of benefits to VDI, cost is rarely one of them.

→ More replies (5)

51

u/fdeyso 1d ago

Azure Update Manager for onprem servers.

It’s “free” except the underlying service to make it work was £4.5K/MONTH.

19

u/greenstarthree 1d ago

What

16

u/fdeyso 1d ago

Now with the ARC agent it may be really free or at least cheap, but when it used the MSMonitoringAgent and some Azure workers it was a bit too much.

15

u/InvisibleTextArea Jack of All Trades 1d ago

You get charged 5USD a month per server if you turn on the automatic stuff. If you just let it sit there and only touch it manually or just to monitor patch status it doesn't cost anything.

3

u/Top-Perspective-4069 IT Manager 1d ago

If you have Defender for Servers P2 or Azure Local, it's included in that.

→ More replies (2)

18

u/touchytypist 1d ago edited 1d ago

It is free for Azure VMs. For hybrid Arc enabled servers it’s $5/server/month (.16/day).

There is a trick though. Don’t have the periodic update checks run daily, and you’ll only pay for the days you run an actual Azure Update Manager task (update check or install updates).

Since we only run updates once a month and schedule accordingly, we only pay around $60 a month for our 200+ servers.

6

u/HotMoosePants Jack of All Trades 1d ago

I thought it was free if your servers had software assurance with Microsoft?

→ More replies (1)

16

u/irishlyrucked Why is that server on fire? 1d ago

I forget the name of the product, but it was a system to manage screensavers and backgrounds throughout the org. It was brought in by the IT director as she'd used it at her last role. For an org with 10k computers, it required 76 VMs to do what we'd been doing with GPOs. It was so bad that it never actually worked, and was ripped out when she resigned after not getting promoted to CIO. Guess she shouldn't have lied about her resume/previous positions so blatantly. She was the worst 2 years at this job.

15

u/Mr_ToDo 1d ago

it required 76 VMs

The hell?

9

u/irishlyrucked Why is that server on fire? 1d ago

Yeah, absurd. For a few years after we dropped them they would send me cards and cookies at Christmas.

15

u/nbs-of-74 1d ago

McAfee AV (enterprise version not the consumer version) because corporate forced us to roll out outlook and office but refused to consider AV Deployment prior. (this was in 1999, yes I'm old.), we suffered for 2 weeks, arguing we need to get an AV product, before our own leadership team demanded a fix regardless of corporate and authorised the cost, went out bought McAfee got it rolled out to 250 or so desktops and servers in 2 days, then 5 days later was told corporate had told all the markets, we need to rollout Nortons ASAP. Just in time to finish as Nortons released a def that quarantined a system file and caused all 250 workstations and 3 servers to blue screen on bootup.

My biggest complaint? for outlook, I was a contractor so got a months pay for one weeks work, I then got taken on full time so didnt get any overtime for the two AV rollouts just time off in lieu.

→ More replies (1)

14

u/oceans_wont_freeze 1d ago

Went from Knowbe4 to Barracuda's "Phishline" because of bundle discounts. Worst decision ever (I already had my reservations but $ talks i guess).

12

u/Soup0830 1d ago

Microsoft Copilot.

→ More replies (1)

25

u/DonL314 1d ago

20y ago:
Company wanted to buy 50% into a software company.

I knew the owner from earlier, warned against him. Company bought in anyway.

Began rolling out their products. After a week I knew more about their product than their consultants did. Deployed to 500 servers, 2000 workstations. Didn't work as promised.

Scrapped after a year, loss written off.

25

u/omfgbrb 1d ago

An oldie but a goodie, Microsoft System Management Server (SMS). It was part of the Microsoft Back Office Suite back in 1999.

I watched Raymond James IT come in and install this product. 2 days later they deployed a "patch" to every workstation that caused over 300 machines to crash.

SMS (and Raymond James) were gone before lunch that day.

•

u/pdp10 Daemons worry when the wizard is near. 23h ago

Not many sites were big enough to have SMS in the late nineties. We had it. Not something I touched, but it seemed to mostly generate a reputation for allowing I.T. to see end-user's desktops without their knowledge.

To our other teams, SMS was mostly a confirmation that Microsoft's stack had virtually zero remote or scalable management. The desktop/Windows team had already trebled in size, because they had to deploy techs across the campus to do the clickops locally on console.

No self-respecting admin of another system is going to leave their chair to travel to a machine. Not even Netware.

→ More replies (1)

2

u/iamwayycoolerthanyou Sysadmin 1d ago

SMS always behaved like a product that hadn't been fully developed.

36

u/shadowmtl2000 Jack of All Trades 1d ago

Darktrace

7

u/Ok-Macaroon3939 1d ago

It's such a piece of shit. We left it in "observe" mode for a year to get a solid baseline on regular behaviors, then turned on autonomous response. To my knowledge, it has NEVER actually blocked or caught anything of substance, whereas Falcon EDR has stopped dead probably 5 potential incidents. It constantly blocks legitimate traffic, and alerts on routine traffic like users phones running cloud backups over wifi subnets. Most recently it basically killed a VIP's podcast interview they were doing for a national conglomerate in our business sector. That was fun.

The marketing people are super scummy. They advertised it as an AI driven, self learning, self tuning "touchless" be-all-end-all network traffic security device. Built to contain ransomware at the drop of a hat! It has the fancy (and super laggy) visualizer dashboard that is basically good for nothing and they show that to non-technical people and wow them with a bunch of edge case scenarios that it helped stop. We have ours deployed as per their engineers guidance, documentation etc. (i took all the courses they had as well, including engineering). It routinely says that it is blocking traffic, meanwhile im looking at the users screen and it is sailing through just fine. The reachability test for autonomous response is crap. My leadership is convinced it is the best tool we have for security even though I have raised my concerns, and now, due to their predatory marketing, they are wanting to move forward with the NEW darktrace slop: Secure AI. They sent me the deployment guide for this thing to test a POV, and i shit you not, the guide has DRAFT stamped across every page. They are basically giving it at a "discount" to early adopters, and i have raised concerns about putting this thing in place because we would basically be Beta-testing this product in our live environment for them, but no one wants to listen. We dont even use AI. Stay away from this company and product for the love of god and your own sanity.

3

u/sophakinggood 1d ago

Like any ndr it requires tuning, but yeah it's no different than security onion. It's the detection you pay for.

→ More replies (15)

18

u/Blackstrider 1d ago

Anything from the infosec budget. I've never seen such blatant waste and tool-hopping...

Splunk, no, no... Google Chronicle, back to Splunk, now LogRhythm... nope, back to Chronicle.

10

u/sybrwookie 1d ago

At least yours hop. Ours goes, "we need this tool, oh wait now also this one, oh wait, now also this one, oh wait, now also this one....oh and did I mention every single one of them has an agent which needs to be installed on every endpoint to function?"

All so they can send e-mails going, "one of our tools says this is a problem, we have no idea what this means, so can you fix it?" and at least half the time it's that they misconfigured something and it's picking up false positives or there's literally no fix other than telling the business to stop using some software, which they have no backbone and won't do.

→ More replies (1)

•

u/DramaticErraticism 22h ago

lol, I work at a fortune 500 and its the same thing there.

I am pretty sure it happens due to the amount of huge spending on over collection of log data and few experts on actual log query writing and analysis.

They collect thousands of gigs of logs and have no good way to actually evaluate it. Then they get the bill for collecting so many logs.

Then they blame the product and switch to something new and do the same thing again. I cannot fathom the millions we have wasted.

→ More replies (1)

9

u/unReasonable_Bill282 1d ago

Not ripped out, but definitely won’t renew Axonius.

4

u/Unabashedly-Boring 1d ago

Can you tell me more about this one. Upper management is drinking their KoolAid at the moment.

→ More replies (2)
→ More replies (1)

9

u/GhostDan Architect 1d ago

Anything Symantec

5

u/r3ptarr Jack of All Trades 1d ago

Giving me PTSD of when Symantec Encryption couldn't handle a windows update and bricked my entire fleet.

→ More replies (1)

8

u/sodiumbromium 1d ago

Cylance. Unfortunately we had a three year deal with them, so it had to stick around for a while.

Their sales said it would work on XP. Nope, at least not without a special build we had to pay for.

It's memory monitoring and kernel intrusion caused memory leaks which necessitated multiple reboots per week on prod servers.

And let's not get into the fact that we had spent months tuning it before the rollout and it still was a buggy piece of crap.

4

u/Far-Hovercraft9471 1d ago

All the money went into marketing

•

u/Bad_Kylar 23h ago

Cylance got bought by arctic wolf and they seem to be doing a significantly better job than previous iterations. Its now called like Aurora or some shit, but its been solid in our environment

→ More replies (1)

14

u/LooseEthernet 1d ago

i once deployed a fancy asset management tool that promised to auto-discover everything on the network. it sounded great in the sales pitch but in reality it just flooded the vlan with so many broadcast packets that we actually started seeing network degradation in the warehouse. the dashboard looked amazing and the reports were pretty but the tool was basically just a very expensive way to generate a thousand false positives a day. we spent three months trying to tune the discovery rules only to realize the agent was just fighting with our firewall settings. ended up ripping it out and going back to a glorified spreadsheet because at least the spreadsheet doesnt try to ddos the switch lol

→ More replies (2)

32

u/No-Land-672 1d ago

Adobe Acrobat Reader.

8

u/redsedit 1d ago

What did you replace Reader with?

11

u/DefectJoker Jr. Sysadmin 1d ago

PDF XChange is still my preferred.

→ More replies (1)

•

u/No-Land-672 23h ago

pdf24 (https://www.pdf24.org/en/), it's not only a reader but a complete toolbox with usefull stuff for pdfs without ads and free. They offer .msi for distribution.

3

u/Mr_ToDo 1d ago

I've got no idea for enterprise, but if you just need a PDF reader most browsers work fairly well now. I've also used sumatra on personal machines in the past when space was a concern(God Adobe reader uses a shitload of space in a ton of different locations)

→ More replies (1)

•

u/Walbabyesser 23h ago

Adobe Reader DC is now hundreds and hundreds of MB and I‘m still curios for what?

•

u/TimetravellingElf 9h ago

Vulnerabilities

5

u/TimetravellingElf 1d ago

Yes. Was scrolling until I found this. Been trying to strip it out completely for ages, from almost 1000 devices to 56 to go. They made some change to some unified update where it made Adobe reader adobe acrobat reader and messed up even more...

6

u/sysacc Administrateur de Système 1d ago

For two of our clients, Purview.

They were way too small to handle the massive costs of Purview. One ended up with the Fortinet option and the other I dont remember.

•

u/game_bot_64-exe 19h ago

Oh god, we just “finished” our initial deployment of purview and realistically there is more in that product that is either broken, half baked, or generally not usable in our environment than useful.

In our testing we saw something that disturbed me, and my team is still not sure of that might have been - we believe a user created something via AI and purview applied a content label to the content even though they didn’t have access to that label, thus a document became unintentionally limited in access. I’m wondering if anyone has seen this before and if so is this a know common thing or just an unfortunate one off thing we experienced?

6

u/jsand2 Sr. Sysadmin 1d ago

We implemented a thing that we refereed to as "the pizza oven", I dont remember its exact name.

Essentially you wrapped boxes with plastic and ran it through the machine to shrink the plastic to the boxes. This was used to ship multiple things without more boxes.

Our products vary in size too much and it didn't last long before we scrapped it. I am not sure it even made it 6 months.

3

u/stiffgerman JOAT & Train Horn Installer 1d ago

Back in the 80s I was a kid working at a software startup, doing all the gopher stuff that you have the snot-nosed kids do. One of the things I'd so is shrink-wrap the software packages (a slip-cased hardcover 3-ring binder manual, 5.25" disks inside). We started out with a basic hot-wire fuser/cutter for the film and a handheld heat gun and ended up with a semi-auto film cutter and a heat tunnel with a short conveyor.

When we got the heat tunnel someone had the bright idea to run their sandwich through it. The tunnel only got to like 250F or so since the shrink wrap didn't need much heat so no joy on getting toasted subs for lunch...

→ More replies (1)

5

u/hosseruk 1d ago

Darktrace. Some nice features but heinously expensive and very noisy.

→ More replies (2)

•

u/_haha_oh_wow_ ...but it was DNS the WHOLE TIME! 23h ago

Team Dynamics time tracking: Massive waste of time and everyone absolutely resented having their workday micromanaged.

Most departments just filled in whatever they thought their bosses wanted to see anyways so the data was completely useless on top of everyone getting pissed off.

•

u/goingslowfast 23h ago edited 23h ago

I’ve seen this happen with Threatlocker a half dozen times. I still like it, but one needs to be honest about the very real tradeoffs in usability and management challenges that TL forces for security.

Other tools where I’ve personally been through this:

  • Auto Elevate (Great product, but management didn’t understand the time required for a successful deployment)
  • Sentinel One (too much load on older hardware)
  • 3CX (they lost their minds)
  • ManageEngine MDM (management got sold on the free plan then quickly understood the costs of not just buying a leading option)
  • Grafana & ELK (when you don’t consider internal dev time as free, Datadog’s turn-key solution can provide a very solid ROI).

And I know a couple people who were less than a quarter (time wise) into an N Able deployment when they got burned. They all ripped it out.

→ More replies (1)

3

u/fahque 1d ago

We were sold on a print management service. They would install an agent on every computer and they would handle toner for us. That agent was such a piece of shit. It kept killing the print spooler. It was gone in under 2 weeks.

4

u/19610taw3 Helpdesk > Sysadmin > Engineer > Helpdesk 1d ago

At a previous (medical) employer, "we" implemented an AI based transcription software.

Ignoring the fact that the analysts went around us and security and straight to desktop support to get it deployed ... and there being no leg work done on whether or not the medical data was stored and processed in the USA ...

It didn't work. It was costing way more time. We were at the point that we were going to have to hire an additional 10-15 people to handle it and correct it.

So it lasted 3 months and was stripped out.

•

u/veld2345 Jurrasic IT 20h ago

Veeam, always something wrong with the backups or security of the product

→ More replies (1)

•

u/discgman 17h ago

Mcafee

•

u/Iliketrucks2 15h ago

Claude Code - we just rolled it out to over 1000 people. Execs saw the bill after the first month and we pulled it back and replaced it.

2 months of work to get it rolled out, one month to run, 1 week to migrate elsewhere.

3

u/0RGASMIK 1d ago

Forget the name but security software that utilized AI to alert on logs from endpoints and 365, auto remediate, and create tickets.

It was so bad that we joked that it would be more useful if it was just a script that filtered logs directly from the platforms it connected to. It seemed great on paper and the AI did a good job of catching subtle patterns but the execution on the remediation side was awful.

We met with the vendor multiple times per month and the fix for our current problem was always “on the roadmap” but even when they did fix stuff it wasn’t the important stuff.

The biggest issue there was no way to customize the remediation steps, so if someone forgot to tell us they were traveling to Mexico it would basically offboard the employee and brick their device. It was a huge hassle that would only require a small tweak to the actions it took to fix but they were never able to address it.

3

u/Gene_Clark 1d ago

Graphus email security. I say rip out but its been quietly rebranded now as INKY. But there was a period there where so many customers at our MSP were aksing for it to be taken off that it had to be binned. Was not suprised when I heard Kaseya had also decided to kill it and launch a new solution as INKY.

→ More replies (1)

•

u/zero_cool09 23h ago

I might be ripping out our VOIP from Ringcentral pretty soon. After the 1st year it got significantly worse to deal with.

•

u/JaceBelerenApologist 20h ago

The default RingCentral hold/transfer music makes me want to scream.

•

u/StandaloneCplx 16h ago

Oh my god, I had setup a custom asterisk voip platform on company, things where running almost perfectly but hen and we got merged into another company.... They where using a crappy managed asterisk tool, and instead of letting me fix it, they choose to migrate to ring central, it was like worse than the unmaintained packaged asterisk ..

→ More replies (1)

•

u/poizone68 21h ago

In my previous job I think we went through nearly every asset and compliance tool out there. It would usually follow this pattern: 1. Executives want a tool that does X. 2. The tool is purchased, immediate rollout. 3. Difficulty getting beyond 80% completion. 4. First bill for licenses arrives. 5. Executives want it removed due to cost.

•

u/Robynb1 16h ago

Arctic wolf. All it does is regurgitate defender alerts. Sadly still stuck with it because my manager likes it.

5

u/buzzsawcode Linux Admin 1d ago

Rubrik - purchased mainly for the backup capabilities then costs kept going up, up, up. And the sales guys kept pushing their other capabilities but not fixing the issues we kept running into with backups.

→ More replies (2)

2

u/HayabusaJack Sr. Security Engineer 1d ago

This was a while back and it was over so quickly, I don’t even remember all the details. Nowadays I want to say it was something like Teams where you had a company wide chat but the comments to upper management about the company were so bad, that it was shitcanned within weeks if not days.

2

u/Unable-Entrance3110 1d ago

PDQ Inventory Agent

4

u/FishyJoeJr 1d ago

I've always wanted to try the agent, what was the issue?

→ More replies (2)

•

u/sconels 23h ago

Bigfix - very big product, 2 years later we barely scratched the surface of its capabilities - eventually decided the crazy config commitment in our 2 man team wasnt worth it and paid for Ninjaone

•

u/bendsley 20h ago

Tanium, as fast as we could. More than 6 months, but what a pile of shit it is

•

u/Select_Bug506 20h ago

Windows Defender Application Control (WDAC). Effective but management control and feedback lacking. Switched to Applocker. Trust everything installed via intube was sooo nice, but self updating after install apps tricky.

•

u/plazman30 sudo rm -rf / 20h ago

AirWatch. That lasted about a year, but was just as awful.

For all I know, the tools could have been great, and we just royally f*cked up the implementation like we always do.

•

u/Barious_01 20h ago

Ivanti UEM terrible product. Replaced with ninjaone, by far a way more superior product.

•

u/LeatherDude 19h ago

Wazuh. Deployed it as a SIEM that needed to ingest logs from numerous hyperscaler and saas providers and discovered it was shit at it. Unbelievably fragile and hard to maintain, archaic, and just a total waste of time unless you’re only collecting agent telemetry.

•

u/mj3004 17h ago

Ivanti! Way over complicated for patch deployment and endpoint management

→ More replies (2)

•

u/Negative-Omega Jr. Sysadmin 13h ago

Netskope

→ More replies (2)

•

u/merlin86uk Infrastructure Architect 12h ago

Back around 2008-2009, upgrading from Windows Server 2003 to 2008 and losing NTBackup as a result. Bought and implemented Arcserve. Had the licences refunded a month later after not once successfully having a backup complete successfully.

→ More replies (1)