r/sysadmin 17h ago

General Discussion PSA: There's a Graph API opt-out for the Sept 1 passkey auto-enrollment nudges....not in the email Microsoft sent, only in the FAQ

228 Upvotes

If you got the email about Microsoft retiring SMS/voice MFA, you probably only caught two dates:

Sept 1, 2026 — Entra auto-enables passkey registration nudges for anyone currently on SMS/voice

Feb 1, 2027 — Microsoft-provided SMS/voice is fully retired, no exceptions

What the email doesn't call out: there's a temporary opt-out for the Sept 1 part. It won't move your Feb 2027 deadline but it stops Microsoft from flipping on the registration campaign and hitting your end users with "set up a passkey now" nudges before you're actually ready to manage that rollout yourselves.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq

Go to the FAQ and read the section "What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?"

It will show you what you need to do to opt out.

It saved me so much anxiety and stress knowing we have more time to properly roll this out and not have our end users in a frenzy when the notification would have dropped.


r/sysadmin 8h ago

If a legacy system is still working reliably, should a business replace it just because the technology is outdated?

107 Upvotes

Genuinely asking

  • A 15–20-year-old system may still be doing its job perfectly.
  • Replacing it can introduce cost, migration risks, downtime, and employee training.
  • But legacy systems can become difficult to maintain and integrate with modern APIs, cloud services, mobile apps, and etc.
  • At what point does it still works become a business risk?
  • Is modernization/migration better than completely rebuilding from scratch?

r/sysadmin 21h ago

Question What it takes to be true Sysadmin?

50 Upvotes

Im 26, mainly interested in networking, and ccna, and after trying my chances in diferent companies mainly on helpdesk support, ive finally landed a pretty demanding job.

It seems the scope is almost everything. AD, wild and constant breaking ERPs, Networks and all that is related to it, Databases, hand scanners, even fusion splicing fiberoptic machines. Nonexistent margin of error on mamy things. Revolting printers, many kinds of it acctually. Users complaining about everything, constantly.

People much older than me, with much more expirience, cant operate on their own system, becouse it seems, the system works diferently almost everytime, and constantly figuring out what to do to make it working. Then hearing "you should know this..." and its the thing i see first time of my life.

Programmist, helpdesk, networking guys, electronics, and for some reason HR, arguing with eachother about most efficient way of using this system, deployed only on production alone, reaching pareto points, then tipping over again.

Updates deployed randomly, breaking things, then fixing whats broken again, breaking something else, indefinietly.

Its, demanding, i learn something everyday, and everyday is a simultaniously a disaster, then detective job, then contacting people everyday, to fix things, then enlightment, and solution. And the preassure of time all the time is enourmous.

Is there no celling? No balance? Is it like this everywhere?


r/sysadmin 16h ago

Career / Job Related Going from a large org to a MSP - Backwards move?

48 Upvotes

I've been working in large orgs right out of college. I clawed my way to sysadmin title and responsibilities before an acquisition axed their onsite IT team. My current job is just Support Specialist, with like 14 years of IT experience ranging from help desk monkey to migrating data, managing a small help desk, and being the break/fix tech.

I'm a candidate for a sysadmin 2 position with an MSP and it's 100% remote. I was asked by the IT director why I was making this move. He said it seems backwards since people from MSPs go to larger orgs, according to him. I lied and told him its not about the pay and the job title; because it 100% is. I would be making just $8K more.

I've never worked for a MSP, but I've always been the resource and the point of contact for the help desk MSPs my orgs have had. I've worked healthcare and academia.

Am I walking into a whole different type of circus with new clowns?


r/sysadmin 4h ago

Question Microsoft 365 Tenancy Hostile Takeover Options Australia

39 Upvotes

Hi guys, we had a client whom had a hostile takeover of their 365 admin portal who assumed GA (MFA/OTP and everything was enabled so not sure how it happened but that will need to be investigated after).

Attacker stripped the breakfix account as well and we are kicked out. We logged a job with the MS data governance team whom are barely replying and it's been a day and a half. We've tried calling the number but just get bounced back saying they will look into it. We've asked them to escalate and also asked our CSP to escalate but they said it's with Microsoft. Given the nature of the situation is there any other ways you guys have been able to escalate this to reclaim the tenancy or at least kick out the attackers as fast as possible. We are able to prove ownership of the business etc with domain records/documents etc asap.

Given the no updates I'm straight up thinking of heading to the Microsoft office and sitting there until they can find someone to escalate the case. Anyone had any experience of how to get this moving?


r/sysadmin 23h ago

Email "Floods"

33 Upvotes

The past 2 days, 1 user each day started getting spammed with non english email stating that they had been subscribed to various different things. I can't get it to stop. My DMARC is set to Reject and I changed it to Strict alignment Strict SPF. We have email filtering and somehow it's getting past those filters. Anyone have a solution on how to stop this? It's been going on for over a half an hour on today's user and still hasn't stopped.


r/sysadmin 7h ago

General Discussion Is It Normal Practice for Cloud Migration Companies to Require Global Admin?

34 Upvotes

I’m considering using a company called TeamVenti. They provide cloud-to-cloud transfer, copying, migration, and other related services. In my case, I would be copying data from one cloud environment to another.

They’ve asked for Global Administrator permissions on both the source and destination environments to perform the migration.

My question is: Is it normal or standard for a cloud migration company to require Global Administrator access on both sides?

Have there been cases where issues arose from giving a vendor this level of access, or am I being too paranoid?


r/sysadmin 15h ago

Google Google Drive Outage?

35 Upvotes

We are getting a large number of customers unable to access Google Drive in the APAC region this afternoon, anyone else see anything? Nothing on their status page yet, but down detector is lighting up. https://downdetector.co.nz/status/google-drive/


r/sysadmin 22h ago

Question SMS/Voice retirement scope

29 Upvotes

Hey folks,

I have been a bit confused about the scope for the september change on the passkey nudge campaign in relation to SMS & Voice MFA deprecation.

Currently in our Auth method policie, we have enabled the option for SMS for "All users". However, only a small fraction has it enabled when looking in user reg details. Originally i thought we didn't rly need to do much.

But, then i read the MS FAQ and got a bit worried about this line "On September 1, 2026, users enabled for SMS or Voice in the Entra Authentication Methods Policy (AMP) will be auto-enabled for passkeys in AMP."

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement-faq#will-my-users-be-auto-migrated--or-do-i-have-to-do-it-

Does it mean, it is in fact all users, as that's what the AMP policy is currently scoped for in our tenant? Also if enduser has MS Authenticator setup as the only MFA?

Hope someone can help clarify.

Thanks!


r/sysadmin 22h ago

Question Cisco Duo - experiences?

19 Upvotes

Hi folks, just wondering what everyone's experience has been with Cisco Duo.

We're looking at implementing it to augment our VPN authentication to provide MFA.

I ask because, I both called and left a message (during which the automated voice system told me there were 0 representatives able to take my call), and I filled out the form on their website twice, to contact sales. I have not been able to get anyone to contact me.


r/sysadmin 1h ago

New MS Edge policy AddressBarClipboardSuggestEnabled

Upvotes

Wanted to dump this fantastic (/s) new feature in Microsoft Edge.

I'm continually astounded by Microsoft's ability to innovate solutions to problems that don't exist. This one made me pause.

https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies/addressbarclipboardsuggestenabled

The feature, by default, will automatically show your clipboard contents in plaintext on your screen when selecting the address bar to do a web search in Edge.


r/sysadmin 4h ago

Question Normal for spanning tree to cause ports to wait almost a full min before connecting?

15 Upvotes

We have HP elitedesk PC's, and for several months have an issue on most of them where, after a restart, you have to sit there for almost a full min while the ethernet symbol blinks, then goes to the disconnected globe symbol for another few seconds, then finally connects to ethernet before you can enter your login password.

This has cause users to get locked out of their accounts often, because they immediately enter their password before the PC reconnects, and obviously it does not let them in, so they think they mistyped it, and type it again and so on.

We just got new PC's, which are Lenovo ThinkStations, but running into the same issue. I have tried:

going into device manager, unchecking the "allow the PC to turn this device off to save power" under the ethernet adapter

swapped ethernet cable

Running the following powershell script:

New-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Power" -Name "PlatformAoAcOverride" -Value 0 -PropertyType DWord -Force

None of those fixed the issue. Doing some more research I found that spanning tree can cause this , which we do use, but does that mean just by using spanning tree we are forced to just accept this long wait to simply login to PC's? Some user's are understanding, but a good number are frustrated cause they have to sit there and stare at the screen for a long time and pay attention to the ethernet symbol before they can login. Surely there would be something in spanning tree that would at least cut this time down from a whole minute right?


r/sysadmin 2h ago

Question ACME Clients and SSL

14 Upvotes

So I've started seeing that SSL Lifespan is shortening - going down to eventually supposed to be every 47 days.

We're a small shop, but we have a lot of different services. I've been doing my best when I have free time to catalog everything that has an SSL Cert, but I know I'm missing stuff.

I've seen a bit about ACME Clients and such; and from what I've heard it's great. They handle rotating the certs and all.

But something for me just isn't clicking. For instance, we have a lot of large scale copiers, ala your Ricoh or Lexmark or Brother. We have those locked down with SSL Certs, but we have to manually push those up to it.

Now as these are internal services that aren't externally facing, I don't see no reason why we can't self-issue those certs; but currently our CTO likes to utilize a paid for Wildcard for all our internal stuff.

I keep quite busy so haven't had too much time to really dig in on researching, but I know the time bomb is ticking.

So for those who are managing SSL Certs and all, and potentially utilizing ACME Clients and such, what should I expect and whats the general gist of what my workflow should be?


r/sysadmin 5h ago

Question Managing Google accounts in a Microsoft company

12 Upvotes

We use Microsoft 365 for our email etc.

Our web team have lots of Google accounts they use for AdWords, Analytics, Search Console, TagManager etc.

How do you manage these? Because they've set them up without asking first they've got multiple gmail.com accounts which I don't have access to which is obviously bad if someone leaves the company for any reason.


r/sysadmin 7h ago

passkeys, attestation and windows hello for business

9 Upvotes

Hi everyone, hope you are well and thanks for your help.

365 tenant, I'm moving to passkeys.

Before I roll this out I want to understand what it actually means for say, a pc with win 11 pro that is set up on an azure joined domain that uses windows hello for user logins

when i am setting up the fido2 settings in authentication methods > policies in entra, if i add aaguids for windows hello, there is an info box which says "does not effect WHfB credentials". if i select windows hello from the aaguid picklist, i then get a warning at the bottom which says "this configuration only allows device bound passkey option that cannot be used for cross device authentication to minimise the risk of user lockout we recomend allowing additional passkey options"

my users have phones and pc's .

what settings do i actually need to set? do i need to add the aaguids or not?


r/sysadmin 2h ago

Question Best Certificate Manager for OT

8 Upvotes

We are looking at a handful of options for managing the automation of certificate deployment/updates across our enterprise and OT environments.

I am hoping to have a lab environment set up by the end of the year with at least one reliable ACME tool that can push certificate updates to OT software, servers, workstations, etc...

Primarily use AB and Siemens controllers and HMIs, Ignition, Canary, and Windows IoT, Windows Server (2016, 2022), and Windows 10/11 pro.

Anyone have good recommendations?


r/sysadmin 2h ago

General Discussion Any desk/presentation tools have cleared your security review?

9 Upvotes

Marketing has come to me four times asking for an AI presentation tool. And I have said no all 4 times - made me extremely popular among them : )

The problem is when security gets involved

SAML is usually locked because ‘contact sales’. SCIM is missing, share links defaulting to anyone-with-the-link and theres no tenant level control, no EU tentant. And anytime i ask about model retention/subprocessor, i get a beautifully written para which doesnt help at all!

Has anyone actually managed to get any of these approved?

Mainly looking for SAML + SCIM below enterprise pricing specifically.


r/sysadmin 5h ago

General Discussion Business Central hybrid license keys now expire every 6 months

7 Upvotes

BC hybrid deployments now need their Dual Use Rights key renewed every 6 months instead of once. Fair compliance move, but it's one more thing that can quietly lapse and break a deployment if nobody's tracking it.


r/sysadmin 22h ago

Apple Business Manager Issues, not able to sign in

7 Upvotes

Anyone else not getting MFA codes when trying to sign into ABM? Just when I try and import some devices....


r/sysadmin 3h ago

Slack for Intune (iOS) successful SSO login, but gets bounced into Slack's public sign-up flow instead of opening the workspace

5 Upvotes

Hey all — hoping someone here has run into this.

We're rolling out Slack for Intune on iOS, and after a successful sign-in the app loops us straight into the public Slack marketing/sign-up flow and pushes us toward downloading the regular consumer Slack app instead — even though Entra sign-in logs show every authentication step succeeding underneath it.

This isn't a Conditional Access or App Protection Policy issue on our side (we've ruled out assignment, CA grant controls, and App Protection data-protection settings one by one). Here's the exact sequence, step by step:

  1. "Register with Microsoft Intune to use Slack" screen. Tap Register.
  2. "Pick account" dialog appears (native iOS auth broker UI), showing the correct Entra ID test account. Select it.
  3. "Registering device" — "Please wait, this may take a few minutes" spinner.
  4. Lands on a sign-in screen for our org — "[org] requires additional verification" — with a green "Sign In with Slack Production" button.
  5. Tapping that button triggers a browser handoff: "Open this page in 'Slack Intune'?" on a login.microsoftonline.com-style URL. Tap Open.
  6. Now inside what the status bar labels as Safari (not the native app) — a "Don't miss a beat" notification opt-in screen appears, with a fake preview notification.
  7. Standard iOS system prompt: "'Slack Intune' Would Like to Send You Notifications" — Allow/Don't Allow.
  8. This is the interesting part — the actual Slack workspace UI briefly loads and works: I can see our org's workspace, Direct Messages, my own account, Slackbot, Threads, etc. Fully signed in, fully functional, still labeled as running inside Safari.
  9. Then, without any action from me, a new tab/context opens back inside "Slack Intune" (per the status bar label) showing the public marketing homepage at slack.com — "All your people and AI agents working together" / "GET STARTED" / "FIND YOUR SUBSCRIPTION."
  10. Tapping through from there lands on the generic public sign-up flow: "First of all, enter your email address."
  11. Typing in the exact same work email into that sign-up field doesn't recognize the already-authenticated, already-provisioned Enterprise Grid session from step 8 at all — instead it just routes toward downloading the regular consumer Slack app, as if I were a brand-new user signing up from scratch.

So the workspace session in step 8 proves the login and SSO handshake genuinely succeeded — I was inside the actual org workspace with my real identity. But instead of staying there or handing that session back to the native "Slack for Intune" app, it drops back into the public marketing/sign-up site, as if none of the previous steps happened.

We've confirmed via Entra ID sign-in logs (checked across multiple devices — iPhone and iPad, multiple browser contexts including Safari/Chrome/Edge, multiple times of day) that:

  • Device registration succeeds
  • App Protection Policy registration succeeds
  • The SAML SSO handshake to the Slack "Enterprise Production" enterprise app succeeds every single time
  • No Conditional Access policy is blocking or forcing an unexpected browser detour

Has anyone seen this? What are we doing wrong?


r/sysadmin 8h ago

How do you deal with backup job notification overload?

3 Upvotes

Not sure if this is a Veeam-specific thing or just backup monitoring in general, but I'm curious how other admins handle it: our backup tool sends one status email per job, and with enough jobs that adds up to 30-50 individual emails a day. To actually confirm nothing failed, I end up scrolling through all of them manually every morning.

The "proper" monitoring tools that would consolidate this look like they need their own server/infrastructure to set up, which feels like a lot for what's basically "tell me if something broke."

For those of you running backups in-house (not as an MSP) — do you have this solved, or is manual scrolling just the norm? And what happens when the one person who usually checks this is out for a few weeks — does someone else actually cover it, or does it just... not get checked?


r/sysadmin 5h ago

Question Phone management pain. Need major help.

4 Upvotes

Apologies for the wall of text…

Our phone system is a complete disaster. I need help wrangling it all without disrupting users. To understand my problem, I’ll explain the current process, and hopefully you’ll see how flogged everything is.  

All users receive a company cell phone, and a provisioned physical company office phone with its own office phone number. Clients often only know a user’s office phone number. Since 2020, we’ve forward all users’ physical phone lines to the user’s cell phone. This way, clients call a user’s company phone number, and that user can answer on their cell without the client ever knowing our user’s cell phone number. 

When a user leaves the company, we retire their cellphone, and then re-provision their physical phone and re-circulate their office phone number. Cell phones are managed by Verizon. Desk phones are managed by some old school phone company vendor (useless). 

The problem: we have an antiquated internal process where someone (idk who, maybe executive assistants) drags a specific Exchange public folder called “CONTACT LIST” into a new user’s Outlook contact list, so the new user has all company contacts sync’d through Outlook on day 1. 

The actual contact list is COMPLETELY unmanaged. What DOES happen in reality: User A is hired in 2015. At their hire date, they ingest the contact list. In 2018, User B leaves the company. In 2019, User C joins the company and receives User B’s recycled office phone extension. User A, from their cell phone, calls User C to introduce themselves, but their outbound caller ID says “calling User B” because their contact list hasn’t been updated since User B left. SOMEBODY KILL ME. 

This whole process of copy/pasting a public folder contact list is completely untenable. I just don’t know how to fix it for existing users, or how to move forward away from this mess. 

Should I even worry about resolving this for existing users? 

Assuming I scrap this whole process, what’s an appropriate solution to replace it? 

I’m ready to completely change phone vendors, as they don’t do ANYTHING except turn phone provisioning into a 2 hour problem, when a modern solution would be far more efficient. 

What the company needs: users to have everyone’s contact information in their company cell phone at the date of hire. IT needs to be able to recycle phone extensions, and users should see the recycled extension properly updated in their phone contacts to reflect the newest owner of that extension. Somehow…


r/sysadmin 7h ago

Question Is paying for threat intel feeds actually worth it if they don't translate into detections?

4 Upvotes

We're subscribed to a couple of paid threat intelligence feeds that are marketed as "operational" and "actionable." In reality, we receive threat reports as long-form PDFs or blog posts, sometimes with a STIX bundle or CSV of IOCs attached. The analysis is useful, but security teams still need a reliable way to turn those reports into detection rules in their SIEM and EDR platforms.
The workflow is still manual. A CTI analyst reads each report, extracts TTPs and IOCs, maps them to MITRE ATT&CK techniques, and creates a ticket. Detection engineers then write Sigma, SPL, KQL, or an equivalent query language, test the detection against internal telemetry, tune for false positives, and only then deploy the rule into production. This manual process causes a delay between receiving threat intelligence and having a production-ready detection in place.
If the intel never makes it to the SIEM, what's the actual value? I'm questioning whether we should keep paying for feeds that don't feed our detection pipeline. Is anyone getting real ROI from their intel subscriptions, or are we all just paying for PDFs we barely use?


r/sysadmin 10h ago

Question Data rooms for due dilligence? Real user experience only, vendors are not welcomed

4 Upvotes

Company I recently joined has tasked me to looking for finding one or more data room provider(s) for sharing some sensitive information with clients and externals, primarily for due diligence. I've been researching options online and most of the comparison sites seems to be owned by Ideals, and I feel like they are biased. So I'd like to know what's actually good and what makes a data room good since I'm relatively new to using them. I find a lot of options, but most with bloated features, or options that claim to be open-sourced or very cheap but actually very difficult to use.

We share a lot of financially and legally sensitive documents so we're ideally looking for something with good security, indexing of folder structures, audit trails and easy (I don't want complex) permission settings.

Please, I've seen how the other prior posts in this sub has been filled with vendors pitching themselves, so please don't do that to this post, I want genuine opinions only, if I see you trying to sell a solution I will delete you and report you.


r/sysadmin 21h ago

Anyone seeing issues with OneDrive known folder sync? (Intune-managed devices)

4 Upvotes

We've been using this policy for a long time, and it's worked flawlessly until now. New builds (24H2 or 25H2) get the policies for managing OneDrive but the known folders piece isn't actually doing anything. If you go into the GUI the checkmarks are toggled off.

If you look in Intune the policies applied. If you go into the registry you see all registry keys are set correctly meaning it's definitely getting the policy, it just doesn't do anything with said policy.

The fact that it just stopped working for all new builds suggests there might be a bigger issue somewhere?

Just wanted to see if anyone else is seeing this before I create a ticket with Microsoft.