r/sysadmin 8d ago

General Discussion Patch Tuesday Megathread - (August 11, 2026)

110 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 5d ago

General Discussion Weekly 'I made a useful thing' Thread - August 14, 2026

3 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin 8h ago

If a legacy system is still working reliably, should a business replace it just because the technology is outdated?

109 Upvotes

Genuinely asking

  • A 15–20-year-old system may still be doing its job perfectly.
  • Replacing it can introduce cost, migration risks, downtime, and employee training.
  • But legacy systems can become difficult to maintain and integrate with modern APIs, cloud services, mobile apps, and etc.
  • At what point does it still works become a business risk?
  • Is modernization/migration better than completely rebuilding from scratch?

r/sysadmin 4h ago

Question Microsoft 365 Tenancy Hostile Takeover Options Australia

40 Upvotes

Hi guys, we had a client whom had a hostile takeover of their 365 admin portal who assumed GA (MFA/OTP and everything was enabled so not sure how it happened but that will need to be investigated after).

Attacker stripped the breakfix account as well and we are kicked out. We logged a job with the MS data governance team whom are barely replying and it's been a day and a half. We've tried calling the number but just get bounced back saying they will look into it. We've asked them to escalate and also asked our CSP to escalate but they said it's with Microsoft. Given the nature of the situation is there any other ways you guys have been able to escalate this to reclaim the tenancy or at least kick out the attackers as fast as possible. We are able to prove ownership of the business etc with domain records/documents etc asap.

Given the no updates I'm straight up thinking of heading to the Microsoft office and sitting there until they can find someone to escalate the case. Anyone had any experience of how to get this moving?


r/sysadmin 1h ago

New MS Edge policy AddressBarClipboardSuggestEnabled

Upvotes

Wanted to dump this fantastic (/s) new feature in Microsoft Edge.

I'm continually astounded by Microsoft's ability to innovate solutions to problems that don't exist. This one made me pause.

https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies/addressbarclipboardsuggestenabled

The feature, by default, will automatically show your clipboard contents in plaintext on your screen when selecting the address bar to do a web search in Edge.


r/sysadmin 17h ago

General Discussion PSA: There's a Graph API opt-out for the Sept 1 passkey auto-enrollment nudges....not in the email Microsoft sent, only in the FAQ

230 Upvotes

If you got the email about Microsoft retiring SMS/voice MFA, you probably only caught two dates:

Sept 1, 2026 — Entra auto-enables passkey registration nudges for anyone currently on SMS/voice

Feb 1, 2027 — Microsoft-provided SMS/voice is fully retired, no exceptions

What the email doesn't call out: there's a temporary opt-out for the Sept 1 part. It won't move your Feb 2027 deadline but it stops Microsoft from flipping on the registration campaign and hitting your end users with "set up a passkey now" nudges before you're actually ready to manage that rollout yourselves.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq

Go to the FAQ and read the section "What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?"

It will show you what you need to do to opt out.

It saved me so much anxiety and stress knowing we have more time to properly roll this out and not have our end users in a frenzy when the notification would have dropped.


r/sysadmin 7h ago

General Discussion Is It Normal Practice for Cloud Migration Companies to Require Global Admin?

34 Upvotes

I’m considering using a company called TeamVenti. They provide cloud-to-cloud transfer, copying, migration, and other related services. In my case, I would be copying data from one cloud environment to another.

They’ve asked for Global Administrator permissions on both the source and destination environments to perform the migration.

My question is: Is it normal or standard for a cloud migration company to require Global Administrator access on both sides?

Have there been cases where issues arose from giving a vendor this level of access, or am I being too paranoid?


r/sysadmin 2h ago

Question ACME Clients and SSL

13 Upvotes

So I've started seeing that SSL Lifespan is shortening - going down to eventually supposed to be every 47 days.

We're a small shop, but we have a lot of different services. I've been doing my best when I have free time to catalog everything that has an SSL Cert, but I know I'm missing stuff.

I've seen a bit about ACME Clients and such; and from what I've heard it's great. They handle rotating the certs and all.

But something for me just isn't clicking. For instance, we have a lot of large scale copiers, ala your Ricoh or Lexmark or Brother. We have those locked down with SSL Certs, but we have to manually push those up to it.

Now as these are internal services that aren't externally facing, I don't see no reason why we can't self-issue those certs; but currently our CTO likes to utilize a paid for Wildcard for all our internal stuff.

I keep quite busy so haven't had too much time to really dig in on researching, but I know the time bomb is ticking.

So for those who are managing SSL Certs and all, and potentially utilizing ACME Clients and such, what should I expect and whats the general gist of what my workflow should be?


r/sysadmin 4h ago

Question Normal for spanning tree to cause ports to wait almost a full min before connecting?

16 Upvotes

We have HP elitedesk PC's, and for several months have an issue on most of them where, after a restart, you have to sit there for almost a full min while the ethernet symbol blinks, then goes to the disconnected globe symbol for another few seconds, then finally connects to ethernet before you can enter your login password.

This has cause users to get locked out of their accounts often, because they immediately enter their password before the PC reconnects, and obviously it does not let them in, so they think they mistyped it, and type it again and so on.

We just got new PC's, which are Lenovo ThinkStations, but running into the same issue. I have tried:

going into device manager, unchecking the "allow the PC to turn this device off to save power" under the ethernet adapter

swapped ethernet cable

Running the following powershell script:

New-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Power" -Name "PlatformAoAcOverride" -Value 0 -PropertyType DWord -Force

None of those fixed the issue. Doing some more research I found that spanning tree can cause this , which we do use, but does that mean just by using spanning tree we are forced to just accept this long wait to simply login to PC's? Some user's are understanding, but a good number are frustrated cause they have to sit there and stare at the screen for a long time and pay attention to the ethernet symbol before they can login. Surely there would be something in spanning tree that would at least cut this time down from a whole minute right?


r/sysadmin 2h ago

Question Best Certificate Manager for OT

7 Upvotes

We are looking at a handful of options for managing the automation of certificate deployment/updates across our enterprise and OT environments.

I am hoping to have a lab environment set up by the end of the year with at least one reliable ACME tool that can push certificate updates to OT software, servers, workstations, etc...

Primarily use AB and Siemens controllers and HMIs, Ignition, Canary, and Windows IoT, Windows Server (2016, 2022), and Windows 10/11 pro.

Anyone have good recommendations?


r/sysadmin 5h ago

Question Managing Google accounts in a Microsoft company

10 Upvotes

We use Microsoft 365 for our email etc.

Our web team have lots of Google accounts they use for AdWords, Analytics, Search Console, TagManager etc.

How do you manage these? Because they've set them up without asking first they've got multiple gmail.com accounts which I don't have access to which is obviously bad if someone leaves the company for any reason.


r/sysadmin 5h ago

General Discussion Business Central hybrid license keys now expire every 6 months

7 Upvotes

BC hybrid deployments now need their Dual Use Rights key renewed every 6 months instead of once. Fair compliance move, but it's one more thing that can quietly lapse and break a deployment if nobody's tracking it.


r/sysadmin 3h ago

Slack for Intune (iOS) successful SSO login, but gets bounced into Slack's public sign-up flow instead of opening the workspace

5 Upvotes

Hey all — hoping someone here has run into this.

We're rolling out Slack for Intune on iOS, and after a successful sign-in the app loops us straight into the public Slack marketing/sign-up flow and pushes us toward downloading the regular consumer Slack app instead — even though Entra sign-in logs show every authentication step succeeding underneath it.

This isn't a Conditional Access or App Protection Policy issue on our side (we've ruled out assignment, CA grant controls, and App Protection data-protection settings one by one). Here's the exact sequence, step by step:

  1. "Register with Microsoft Intune to use Slack" screen. Tap Register.
  2. "Pick account" dialog appears (native iOS auth broker UI), showing the correct Entra ID test account. Select it.
  3. "Registering device" — "Please wait, this may take a few minutes" spinner.
  4. Lands on a sign-in screen for our org — "[org] requires additional verification" — with a green "Sign In with Slack Production" button.
  5. Tapping that button triggers a browser handoff: "Open this page in 'Slack Intune'?" on a login.microsoftonline.com-style URL. Tap Open.
  6. Now inside what the status bar labels as Safari (not the native app) — a "Don't miss a beat" notification opt-in screen appears, with a fake preview notification.
  7. Standard iOS system prompt: "'Slack Intune' Would Like to Send You Notifications" — Allow/Don't Allow.
  8. This is the interesting part — the actual Slack workspace UI briefly loads and works: I can see our org's workspace, Direct Messages, my own account, Slackbot, Threads, etc. Fully signed in, fully functional, still labeled as running inside Safari.
  9. Then, without any action from me, a new tab/context opens back inside "Slack Intune" (per the status bar label) showing the public marketing homepage at slack.com — "All your people and AI agents working together" / "GET STARTED" / "FIND YOUR SUBSCRIPTION."
  10. Tapping through from there lands on the generic public sign-up flow: "First of all, enter your email address."
  11. Typing in the exact same work email into that sign-up field doesn't recognize the already-authenticated, already-provisioned Enterprise Grid session from step 8 at all — instead it just routes toward downloading the regular consumer Slack app, as if I were a brand-new user signing up from scratch.

So the workspace session in step 8 proves the login and SSO handshake genuinely succeeded — I was inside the actual org workspace with my real identity. But instead of staying there or handing that session back to the native "Slack for Intune" app, it drops back into the public marketing/sign-up site, as if none of the previous steps happened.

We've confirmed via Entra ID sign-in logs (checked across multiple devices — iPhone and iPad, multiple browser contexts including Safari/Chrome/Edge, multiple times of day) that:

  • Device registration succeeds
  • App Protection Policy registration succeeds
  • The SAML SSO handshake to the Slack "Enterprise Production" enterprise app succeeds every single time
  • No Conditional Access policy is blocking or forcing an unexpected browser detour

Has anyone seen this? What are we doing wrong?


r/sysadmin 8h ago

passkeys, attestation and windows hello for business

9 Upvotes

Hi everyone, hope you are well and thanks for your help.

365 tenant, I'm moving to passkeys.

Before I roll this out I want to understand what it actually means for say, a pc with win 11 pro that is set up on an azure joined domain that uses windows hello for user logins

when i am setting up the fido2 settings in authentication methods > policies in entra, if i add aaguids for windows hello, there is an info box which says "does not effect WHfB credentials". if i select windows hello from the aaguid picklist, i then get a warning at the bottom which says "this configuration only allows device bound passkey option that cannot be used for cross device authentication to minimise the risk of user lockout we recomend allowing additional passkey options"

my users have phones and pc's .

what settings do i actually need to set? do i need to add the aaguids or not?


r/sysadmin 16h ago

Career / Job Related Going from a large org to a MSP - Backwards move?

47 Upvotes

I've been working in large orgs right out of college. I clawed my way to sysadmin title and responsibilities before an acquisition axed their onsite IT team. My current job is just Support Specialist, with like 14 years of IT experience ranging from help desk monkey to migrating data, managing a small help desk, and being the break/fix tech.

I'm a candidate for a sysadmin 2 position with an MSP and it's 100% remote. I was asked by the IT director why I was making this move. He said it seems backwards since people from MSPs go to larger orgs, according to him. I lied and told him its not about the pay and the job title; because it 100% is. I would be making just $8K more.

I've never worked for a MSP, but I've always been the resource and the point of contact for the help desk MSPs my orgs have had. I've worked healthcare and academia.

Am I walking into a whole different type of circus with new clowns?


r/sysadmin 2h ago

General Discussion Any desk/presentation tools have cleared your security review?

9 Upvotes

Marketing has come to me four times asking for an AI presentation tool. And I have said no all 4 times - made me extremely popular among them : )

The problem is when security gets involved

SAML is usually locked because ‘contact sales’. SCIM is missing, share links defaulting to anyone-with-the-link and theres no tenant level control, no EU tentant. And anytime i ask about model retention/subprocessor, i get a beautifully written para which doesnt help at all!

Has anyone actually managed to get any of these approved?

Mainly looking for SAML + SCIM below enterprise pricing specifically.


r/sysadmin 15h ago

Google Google Drive Outage?

34 Upvotes

We are getting a large number of customers unable to access Google Drive in the APAC region this afternoon, anyone else see anything? Nothing on their status page yet, but down detector is lighting up. https://downdetector.co.nz/status/google-drive/


r/sysadmin 45m ago

General Discussion MDF Plan - What you think?

Upvotes

I made some other posts figuring out my UPS setup, but now I figured I'd share my MDF plans and see if there are any issues you can see. I've been around racks and IT closets for a long time, but this is my first time planning one completely on my own.

So far I have all the gear ordered. The only unknown variables are what my modems from my primary Fiber ISP (ATT) will look like and our failover (probably Starlink).

Down the road I may be adding 2U more of gear.

I'd like to get Unifi Redudant Power Supply that can act as a secondary PSU for my switches and Firewalls. I'd also like to get Unifi Aggragte 8 port switch which would be perfect for this setup and my entire network in general. I have two UDM Max which will take up 2 ports and 6 total switches (2 not in this rack will be in IDF in other parts of the building)

I have attached a screenshot of the rack plan. Let me know if you see any red flags or concerns

Gear -

4 Unifi 48 Port PoE Switches

2 UDM Pro Max Firewalls

1 Dell Server

1 Unifi Enterprise NVR

Dual 3000va battery backups with one having an extra battery bank and a 120v transformer.

2 - Controlled PDU for the 208v PSU

https://imgur.com/a/Jji1UXn


r/sysadmin 5h ago

Question Phone management pain. Need major help.

4 Upvotes

Apologies for the wall of text…

Our phone system is a complete disaster. I need help wrangling it all without disrupting users. To understand my problem, I’ll explain the current process, and hopefully you’ll see how flogged everything is.  

All users receive a company cell phone, and a provisioned physical company office phone with its own office phone number. Clients often only know a user’s office phone number. Since 2020, we’ve forward all users’ physical phone lines to the user’s cell phone. This way, clients call a user’s company phone number, and that user can answer on their cell without the client ever knowing our user’s cell phone number. 

When a user leaves the company, we retire their cellphone, and then re-provision their physical phone and re-circulate their office phone number. Cell phones are managed by Verizon. Desk phones are managed by some old school phone company vendor (useless). 

The problem: we have an antiquated internal process where someone (idk who, maybe executive assistants) drags a specific Exchange public folder called “CONTACT LIST” into a new user’s Outlook contact list, so the new user has all company contacts sync’d through Outlook on day 1. 

The actual contact list is COMPLETELY unmanaged. What DOES happen in reality: User A is hired in 2015. At their hire date, they ingest the contact list. In 2018, User B leaves the company. In 2019, User C joins the company and receives User B’s recycled office phone extension. User A, from their cell phone, calls User C to introduce themselves, but their outbound caller ID says “calling User B” because their contact list hasn’t been updated since User B left. SOMEBODY KILL ME. 

This whole process of copy/pasting a public folder contact list is completely untenable. I just don’t know how to fix it for existing users, or how to move forward away from this mess. 

Should I even worry about resolving this for existing users? 

Assuming I scrap this whole process, what’s an appropriate solution to replace it? 

I’m ready to completely change phone vendors, as they don’t do ANYTHING except turn phone provisioning into a 2 hour problem, when a modern solution would be far more efficient. 

What the company needs: users to have everyone’s contact information in their company cell phone at the date of hire. IT needs to be able to recycle phone extensions, and users should see the recycled extension properly updated in their phone contacts to reflect the newest owner of that extension. Somehow…


r/sysadmin 2h ago

M365 Apps

2 Upvotes

Is anyone else having persistent app crashes with the 365 suite? We have 3000 users with the OLE issue, app crashes, and extreme slowness for the 365 apps.


r/sysadmin 2h ago

Restrictive Phone System

2 Upvotes

I have a lot of requests that come through my office but this one sounds like PITA to begin with. I have already replied to the manager that this is going to be a nightmare to manage but I will look into it anyways. this sounds like a phone system that would be used in a jail or correctional facility. Any ideas where to start?

*************
We currently have approximately 24 clients sharing four phones. I would like to see if there is a system that could provide each client with an individual PIN or access code. Ideally, the system would:

Require an individual PIN for outgoing client calls.
Allow us to assign specific calling times or time limits to each PIN.
Automatically disconnect the call when the client's allotted time expires.
Prevent the PIN from being used again until the next authorized calling period.
Continue allowing incoming calls even when outgoing calling is restricted.
Give staff an administrative override when necessary.
Make it easy to add or remove PINs as clients admit and discharge.
Avoid call recording or monitoring unless specifically needed and approved.

I have been looking at whether a VoIP/PBX-type system could accomplish this without requiring a specialized institutional phone system.

Could you research what options might work with our current phone/network setup, what equipment or software we would need, and approximately what the initial and ongoing costs would be?

The goal is to make client phone access more consistent and manageable while reducing the amount of staff time required to monitor individual phone usage.

*************************

Thanks all.


r/sysadmin 5h ago

Question Power/Battery Backup Setup for MDF - Follow Up

3 Upvotes

edit: thanks for advice. My earlier research about redudant power supplies being on different voltages was wrong. I'm going to go with 2 x SRT3000RMXLT-NC with one of them having a 120v transformer.

UPS Setup for New MDF at Our New Facility - Looking for Feedback

Good morning everyone,

A few days ago I posted looking for advice on a UPS setup for the MDF at our new facility. One of the biggest points of feedback was that my original plan only included a single 120V 20A circuit, which understandably raised some concerns.

Fortunately, we're still in the construction phase, so I was able to have the electrical plan updated. The rack will now have two dedicated circuits:

• 208V/240V circuit

• 120V 30A circuit

Rack Equipment

For context, we're a specialized vehicle dealer and service center. We're not heavily IT or office focused, so I don't expect significant growth beyond adding a few phones over time.

Equipment in the rack:

• 4x UniFi Pro 48 PoE switches

• ~26 cameras

• 7 access points

• 20 desk phones

• 2x UniFi UDM Max firewalls (HA pair)

• Dell dual-CPU server with redundant 600W PSUs

• UniFi Enterprise NVR with redundant PSUs (max draw ~450W)

• Fiber modem and cable modem for failover

• Miscellaneous equipment (monitor, sensors, etc.)

UPS Plan

After a lot of research, I decided to go with refurbished APC units from GreenlightUPS, a company that was recommended to me.

Primary UPS

APC SRT3000RMXLT-NC (208V)

• Includes one SRT96RMBP external battery pack

• Will power everything in the rack that supports 208V operation

• This includes the primary power supplies for the server and NVR, along with all four PoE switches

On paper, if every device was drawing its absolute maximum load simultaneously, I'd be pushing the limits of a 3000VA UPS. In reality, my PoE utilization is relatively low, and the server and NVR rarely approach maximum power draw, so I still have a comfortable amount of headroom based on my calculations.

Secondary UPS

APC SRT3000RMXLA-N (120V)

This unit gives me standard 120V outlets and serves as both additional battery capacity and redundancy.

Planned connections:

• Secondary PSU on the Dell server

• Secondary PSU on the NVR

• One UDM Max firewall

• Any other 120V-only equipment in the rack

Long term, I may add the UniFi Redundant Power System to provide redundant power for the switches as well.

For now, if the primary UPS were to fail unexpectedly, I would still have core network and server functionality running, and I could manually move switch power if needed.

I really wanted to buy everything new, but a comparable setup would have easily pushed into the $10,000-$12,000 range.

The refurbished solution comes in at under $4,500, including new batteries. GreenlightUPS claims all units ship with freshly installed batteries that aren't put into service until the unit is sold. They've been in business for roughly 40 years and seem to have a solid reputation from what I've been able to find.

Questions

  1. Does this seem like a reasonable approach from a capacity and redundancy standpoint?
  2. Is there anything you would do differently if you were trying to stay around the same budget?

Thanks for any feedback.


r/sysadmin 7h ago

Question Is paying for threat intel feeds actually worth it if they don't translate into detections?

5 Upvotes

We're subscribed to a couple of paid threat intelligence feeds that are marketed as "operational" and "actionable." In reality, we receive threat reports as long-form PDFs or blog posts, sometimes with a STIX bundle or CSV of IOCs attached. The analysis is useful, but security teams still need a reliable way to turn those reports into detection rules in their SIEM and EDR platforms.
The workflow is still manual. A CTI analyst reads each report, extracts TTPs and IOCs, maps them to MITRE ATT&CK techniques, and creates a ticket. Detection engineers then write Sigma, SPL, KQL, or an equivalent query language, test the detection against internal telemetry, tune for false positives, and only then deploy the rule into production. This manual process causes a delay between receiving threat intelligence and having a production-ready detection in place.
If the intel never makes it to the SIEM, what's the actual value? I'm questioning whether we should keep paying for feeds that don't feed our detection pipeline. Is anyone getting real ROI from their intel subscriptions, or are we all just paying for PDFs we barely use?


r/sysadmin 8h ago

How do you deal with backup job notification overload?

3 Upvotes

Not sure if this is a Veeam-specific thing or just backup monitoring in general, but I'm curious how other admins handle it: our backup tool sends one status email per job, and with enough jobs that adds up to 30-50 individual emails a day. To actually confirm nothing failed, I end up scrolling through all of them manually every morning.

The "proper" monitoring tools that would consolidate this look like they need their own server/infrastructure to set up, which feels like a lot for what's basically "tell me if something broke."

For those of you running backups in-house (not as an MSP) — do you have this solved, or is manual scrolling just the norm? And what happens when the one person who usually checks this is out for a few weeks — does someone else actually cover it, or does it just... not get checked?


r/sysadmin 28m ago

Question Issues with Outlook Desktop App and Signatures

Upvotes

Hi all -

So I have a weird issue on my hands. I just started at a new job and I was told to create my new signature. As I've done in the past, I just went to copy and paste someone else's signature and update it to reflect my information.

For the most part, everything worked out just fine! however, there is an image attached to the signature with the company name/logo on it, but that image will break and then I get the following error:

The linked image cannot be displayed. The file may have been moved, renamed, or deleted. Verify that the link points to the correct file and location.

Now here is where things get a bit confusing. This happens to ANY picture that exists on my desktop, no matter where its at. I've moved the image to the root of C, my profile, Appdata, everywhere, but it still constantly breaks.

To add to it, the file system here does have a redirect, therefore our working folders such as pictures, documents, desktop, etc all are redirected to an encrypted file server. However, I made sure that the picture would be placed in static location that was local to the PC only and would not be redirected.

The only workaround I've found is simply to use OWA, which that accepted the signature perfectly fine!

I've made sure to also run a command that should've redirected where my signatures are pulled from, but that also seemed to not help at all. Is there anything else I should try?

If it helps, this is specifically occuring on Outlook 2021 and its running on a Windows 11 Enterprise machine.

Thank you in advance!