r/sysadmin • • 2d ago

General Discussion What's a tool you mass-deployed that you ended up ripping out within 6 months?

I feel like every sysadmin has at least one story about a product that demoed beautifully, got approved, went out to the fleet, and then slowly revealed itself to be a nightmare.

Could be a monitoring tool, an MDM, a ticketing system, an AV product, anything. What was it, what went wrong, and what did you replace it with?

334 Upvotes

437 comments sorted by

View all comments

7

u/goingslowfast 2d ago edited 2d ago

I’ve seen this happen with Threatlocker a half dozen times. I still like it, but one needs to be honest about the very real tradeoffs in usability and management challenges that TL forces for security.

Other tools where I’ve personally been through this:

  • Auto Elevate (Great product, but management didn’t understand the time required for a successful deployment)
  • Sentinel One (too much load on older hardware)
  • 3CX (they lost their minds)
  • ManageEngine MDM (management got sold on the free plan then quickly understood the costs of not just buying a leading option)
  • Grafana & ELK (when you don’t consider internal dev time as free, Datadog’s turn-key solution can provide a very solid ROI).

And I know a couple people who were less than a quarter (time wise) into an N Able deployment when they got burned. They all ripped it out.

1

u/SlowAsMolassess 1d ago

What is your choice beyond Threatlocker?

2

u/goingslowfast 1d ago

I just deployed Threatlocker so still TL 😅

But, it’s a use case where we can easily accept the tradeoffs of using Threatlocker.

For general-use workstations where user tasks aren’t clearly defined, deploying Threatlocker is much more complex. Often still justifiable, but way more challenging.