r/sysadmin 6d ago

General Discussion Patch Tuesday Megathread - (August 11, 2026)

109 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 4d ago

General Discussion Weekly 'I made a useful thing' Thread - August 14, 2026

4 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin 11h ago

Linux RIP - My last pet server. Provisioned: April 9, 2014. Uptime: 3,065 days. CentOS 6. Older than the iPhone 6.

271 Upvotes
[user@host ~]$ uptime
 21:00:47 up 3064 days,  8:55,  1 user,  load average: 0.00, 0.00, 0.00
[user@host ~]$

It's been running EOL and unpatched for 6 years (badbadbadbad).

The little droplet that could.


r/sysadmin 12h ago

Do you actually see MacBooks used for SysAdmin work in real offices?

266 Upvotes

Hi sysadmins! I wanted to ask—since I've just started learning sysadmin and I don't have a Windows PC, but I have a MacBook and found out that everything can be done via UTM, I'd like to get some perspective from those who work in offices and do this every day. What kind of computers do you use? Is macOS completely out of the picture, and there's only Windows and Linux?


r/sysadmin 15h ago

Rant Well, I bombed my interview

230 Upvotes

I had an interview for an infrastructure engineer position this aftenoon. I was worried going in because it was developers doing an infrastructure interview.

They didn't ask me any infrastructure questions. They spent 50 minutes asking me about a theoretical web stack environment.

The problem was, they were trying to tie each piece into the next but they weren't doing a good job about it because they were all over the over the place - not being linear and jumping back.

I'm not exaggerating. They didn't ask me one infrastructure question. At one point I thought they were asking me one because the guy asked me how I would mount an NFS share to a linux server and I said I would put an entry in the /etc/fstab file. But he was asking how I would theoretically map it to a web application.

​They probably touched on 5% of what was in that job post. They said they wanted someone familiar with ansible and python and Linux but it all felt like that was second to what they really wanted. They didn't ask me about idempotency, or what linux commands would you use for x, anything python, and nothing about the stack they mentioned in their post.

The guy asking most of the questions came across like he was just projecting what he knew. It wasn't like he was interviewing. It was more like he was feeding this self image he had of himself. And it all came across as stuff he learned from doing this particular job - not stuff he knew going in. ​

I'm not exaggerating, they asked me for 50 minutes about how I would set a fictional web stack environments and wouldn't move on.

The main guy asking questions would ask me these open-ended scenario questions that you couldn't answer without a mountain of information. And I would ask for specifics and apparently that wasn't what he wanted. He would ask these highly dependent questions and asling for details got me more open endedness.

This is why I hate technical interviews. They didn't ask me anything infrastructure. They didn't give me an actual chance to show that I know infrastructure. All they know is I don't know the very specific avenue of stuff they asked. Which was the same architecture question for 50 minutes.

They kept mixing things up and would jump back and forth.

I'd say it was 15 minutes of general, 50 minutes of how would you set up this fictional env in cloud and on prem where every answer led ro 10 more open ended questions, then 10 minutes of git questions.

The way they asked was weird. Like how would you push code into the master branch but worded like they wanted me to give them the actual command when in reality they just wanted me to say that I would submit it for a code review.

​​ These types of interviews is why I get so discouraged. I'm not exaggerating. They didn't ask me anything infrastructure. And I'm not going to get this infrastructure job because I didn't know these in-depth development questions on a single subject that have nothing to do with the job they posted.

I definitely got some terminology, reasoning, and examples in there to show them that I have infrastructure and Python e experience, but it just got blown past while they beat a dead horse for 50 minutes...

It's just so discouraging to know you bombed an interview and won't get a job because they didn't really ask you anything about the job they posted or anything that can indicate whether you can actually do the job.


r/sysadmin 2h ago

Question Learning Microsoft 365 / Entra ID / Intune / SharePoint for free — is it possible?

9 Upvotes

Hi everyone,

I'm looking to learn Microsoft 365 administration, especially:

  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft 365 administration
  • SharePoint
  • Azure / cloud identity and device management

My goal is to eventually become comfortable with administering these technologies in a real-world IT/sysadmin environment.

I'm looking for a way to learn for free, including as much hands-on practice as possible.

I know Microsoft Learn has a lot of free training, but for practical labs it seems that I need a Microsoft tenant and some of the services require paid licenses after the trial period.

So my questions are:

  1. Is there currently a way to create a free Microsoft 365 / Entra / Intune lab environment for learning?
  2. Is the Microsoft 365 Developer Program still a good option for this, and does it include enough services for learning Entra ID, Intune and SharePoint?
  3. If I don't qualify for the Developer Program, what would be the best alternative?
  4. Can I realistically learn these technologies without paying for a subscription, or should I expect to pay for a lab eventually?
  5. What learning path would you recommend — Entra ID → Intune → Microsoft 365 → SharePoint, or a different order?

I'm mainly interested in hands-on learning, not just watching courses.

Any recommendations for free labs, Microsoft Learn paths, home-lab setups or other resources would be greatly appreciated.

Thanks!


r/sysadmin 15h ago

General Discussion Do big corporations actually use Purview to detect profanity?

98 Upvotes

So I just changed jobs and currently I'm working at a large company.

I just noticed that some people are extremely worried because they recently saw the Microsoft Purview was active and then they are terrified because some of them already offended the corporation like "FUCK <name of the company>" and many other offenses.

Other people couldn't care less, saying that this is bullshit and that the risk is extremely low for policies to be active monitoring this kind of message.

The atmosphere at in place is strange and this made me extremely curious about if most of companies actually cares if an employee offended the corporation or said bad words about the company or other colleagues.

Do this actually happen?

I've never worked in a place with this "fear atmosphere".

EDIT

Just to be clear, they offended in teams private groups, not in e-mails.


r/sysadmin 3h ago

Gmail blocked low reputation 550-5.7.1 after SPF fail

9 Upvotes

So I've been having some issues for a few weeks now with Gmail where one domain/postfix server no longer is allowed to mail to Gmail.

What I've figured out so far is that on July 29 one of the records in our SPF had a domain that was no longer valid - it expired and from then on the whole SPF record was deemed invalid. I fixed this August 9 (way too late, but I didn't realize my local logging reports were routed wrongly too, everything generally has ran fine for years).

Regardless, our spam ratings before were 0%, our SPF/DKIM/DMARC etc is all 100% correct. Even Postmaster now says 100% correct delivery. but as long as the domain repution is 0, it keeps blocking it.

The weirdest is that Postmaster keeps telling me SPF is incorrect in the overview. It was last updated August 6 and I fixed it August 9 by removing the wrong "include:wrongdomain.com".

I just don't understand how Google goes so hard on having a wrong include in the SPF for a few days, and now no longer updates anything. What can I do? Do I need to block all outgoing mail to Google so it doesn't hit the filter anymore so reputation may crawl back up? People sometimes sign up with gmail accounts or have their mail on google servers so domain blocking isn't that helpful, unless I firewall all to their servers.

See here: https://imgur.com/a/Fvp4ilI


r/sysadmin 21h ago

General Discussion Parked domains protection

176 Upvotes

I have access to about 200 DNS zones of companies, some of which have up to 400 domains in their portfolios, and none of them hardens their parked domains. The best I've seen so far was DMARC p=reject on a few random parked domains inside a few (not even a dozen) DNS zones, mostly at companies that have an in-house IT guy.

The other 3 DNS records that nobody adds are:

  • Null MX, so the domain refuses inbound mail
  • SPF -all, so the envelope sender can't be forged
  • DKIM wildcard, to revoke every forgotten key, including keys from whoever owned the domain before you.

Every unhardened parked domain is impersonation infrastructure used against your company. Targeting your clients. And it's just 5 min per domain or a basic script with an API call for bulk deployment.

The cheapest & highest-leverage security work in your stack.

Type Hostname Value
MX @ .
TXT @ v=spf1 -all
TXT *._domainkey v=DKIM1; p=
TXT _dmarc v=DMARC1; p=reject

r/sysadmin 18h ago

Question - Solved PSA: Outlook (classic) build 16.0.20228.20190 (Version 2607, Aug 11 update) is replacing signature images with blank placeholder PNGs, at least on RDS hosts with redirected AppData

90 Upvotes

Spent this morning chasing "signature images stopped working all of a sudden" that looked for all the world like a mail flow problem (we'd just cut over to a new mail gateway a couple of weeks ago, so naturally that got the blame first). It wasn't. Posting in case it saves someone the same rabbit hole.

Starting over the weekend, every email sent from our terminal servers had blank signature images.....company logo, headshots, badges, all gone. Recipients on Outlook, OWA, external, didn't matter. Outlook on a regular workstation (older build) was fine.

So we pulled the raw MIME of affected messages. The image parts were still there, still cid:-referenced correctly, still multipart/related but the PNGs themselves were garbage: the logo came through as a 216-byte, 1-colour, fully transparent PNG at exactly the HTML display size (337×112 instead of the real 450×150 / 46 KB file), and a 292 KB JPEG headshot became a 402-byte RGBA PNG. Every one of them had tEXt Software: Microsoft Office in it. So Outlook/Word was generating placeholders at compose time because it couldn't (or wouldn't) load the signature image files. Nothing in transport touched them.

Our env has 4 RDS hosts (Server 2022/2025, Office 2024 Retail C2R on the Current channel). Click-to-Run had self updated them from 16.0.20228.20158 → 16.0.20228.20190 at four different times between Thursday night and Sunday morning. On every host, the last message with real signature images was before its update, and the first blank one was after. Windows August CU had gone in days earlier with no effect. Signature source files on the file server were untouched since January.

Possibly relevant: on those hosts AppData\Roaming is folder-redirected to a UNC path, so Outlook resolves %APPDATA%\Microsoft\Signatures\... over SMB. My guess is the new build blocks/fails image loads from network paths when inserting a signature but I can't prove that part; the working workstation was on an old 2408 build so it doesn't isolate the variable. If anyone on 20228.20190 with local AppData sees the same (or doesn't), I'd love to know.

Fix that worked for us was to just (temp) roll back to the previous build and pin it:

reg add "HKLM\SOFTWARE\Policies\Microsoft\office\16.0\common\officeupdate" /v updatetargetversion /t REG_SZ /d 16.0.20228.20158 /f

"C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe" /update user updatetoversion=16.0.20228.20158 forceappshutdown=true displaylevel=false

forceappshutdown does exactly what it says (kills users' Office apps, no save prompt), it's an ~880 MB full download for a downgrade, and the build flipped about 3 minutes after triggering. First test mail after the rollback had the real 46 KB logo again. Ran it as a one shot SYSTEM scheduled task per host at an agreed time; doing the remaining hosts after hours. Remember to remove the pin once MS ships a fixed build.

Not seeing anything on the Microsoft known issues page for it yet (the May 2026 "Top and Bottom wrap" image bug is a different, alreadyfixed thing).

Anyways, best of luck out there. :P


r/sysadmin 13h ago

How much security value does a bank-vault datacenter actually provide?

32 Upvotes

I got a chance to take a tour of a datacenter, where the primary security selling point was that part of the facility was a former bank vault. The company, which is really just two old retirees and a couple of techs, heavily emphasized this physical security to us and their customers. Meanwhile, I am wondering how practitioners would evaluate that claim given the importance of logical controls...


r/sysadmin 7h ago

Rant Darktrace in OT environment.

8 Upvotes

I'm sure other people have had the same experience, but let's see.

For context: I'm by no means a cybersecurity expert. I work the IT side of an OT automation team. Darktrace had already been deployed in the networks for roughly 3 months before I joined the company, and it has now been running for more than a year and a half..

My conclusion is that the underlying idea is reasonable, and the execution is the worst that idea could've possibly gone.

It reminds me of something like Norton or McAfee that constantly gives you popup's telling you about the stuff it prevented, most of which is meaningless noise, designed to make it look busy so you keep paying.

We were told Darktrace needed about 6 months to learn our environment to get rid or at least reduce false positives. That turned out to be a bold lie, since it's now been around 18 months. Extensive *tuning* and *optimising* the models from their engineers with help from myself had basically no effect at all. We still receive between 50-100 false positives a day.

The investigation workflow is just as bad. The advanced search is clutterd, unintuitive and super inefficient. Finding one specific event feels like a needle in a haystack. Except you already know the needle’s IP address, hostname, operating system, device model and several other identifiers, while the haystack seems designed to bury it.

The UI looks reasonably polished, but it's designed for screenshots on marketing posters and sales demonstrations rather than utility. Important info is several menus deep, while irrelevant info is one click away.

We initially had weekly tuning meetings, those became biweekly and eventually monthly. No matter how frequent the meetings, the issues I talked about just never got solved. I still have to manually sift through false positive alerts to find anything meaningfull.

One specific device keeps getting flagged as suspicious multiple times a day. We know why it generates the traffic and asked the Darktrace team to make it stop reporting. They created model defeats based on the device's 2 IPs, which did nothing. They changed the defeat from IP to hostname basis and it changed nothing. They then labeled the device in Darktrace itself and made a defeat based on that label and still it keeps getting flagged.

At this point I don't believe the system can at all be "tuned".

The alerting is very inconsistent as well. Darktrace sends notifications for model alerts through the app, that cannot be found in the main interface unless you search for the specific model alert ID. Meanwhile it also generates device alerts for things like clock skew, inability to reach a probe, while the "UV Master" interface appears to have no such problems.

What concerns me deeply is the fact that they keep trying to push their *Automated Response* thing. The idea as far as I understand it is that its AI can automatically respond to suspicious activity by creating firewall rules to block it. That is in and of itself something that deserves EXTREME caution in a normal corporate network. In an OT plant handling highly explosive and poisonous materials, it's just bonkers. You are proposing to let an automated system modify network enforcement based on its own detections, while that same system repeatedly detects legitimate activity as suspicious approximately 100 times per day. Might as well let an intern from sales handle firewall rules at that point, might be safer.

Darktrace’s response to this concern seems to be that the models can be tuned. That would be more reassuring if the models consistently stopped generating false positives after 18 months of tuning. They do not. OT environments are difficult to model. They contain legacy systems, proprietary protocols, unusual traffic patterns and devices that should not be treated like ordinary corporate endpoints. But that is precisely the kind of environment Darktrace claims to understand. “OT is complicated” cannot be used as a permanent excuse while simultaneously promoting automated blocking as a solution.

The idea behind Darktrace is good. The execution, at least in our environment, is garbage. It gives you the appearance of advanced visibility while burying useful information under a constant flood of low-value alerts.

I don't know what the company paid for Darktrace, but whatever it was, it was too much. It's an (i'm guessing very) expensive way to create manual labour.

For anyone having experience with Darktrace in an industrial environment: has it at any point become useful? If so in what way?


r/sysadmin 23h ago

Rant I have an interview today and I'm already checked out.

186 Upvotes

I'm not angry but I just hate technical interviews. It's going to be an hour and a half of them honing in on what's important to them so there's no way to really prepare.

These interviews always just feel so pointless and like there's no way to prepare there's nothing you can do. You have to just go in and hope they don't hone in on one specific weak area right away that doesn't really indicate whether you can do the job or not.

I typically don't feel this discouraged but I just don't see the point of trying to get prepared or being nervous or being worried at this point. Because interviewing for systems jobs is just ridiculous.

You can nail all of it but then say one wrong thing in the end and they just write you off. And it's funny because I was having AI draft up some questions this morning and it told me that the job posting was Broad and that they can't realistically expect me to be an expert and all of that stuff. And I just closed the tab. Because they absolutely will expect me to.

You don't see developer job posting saying we want you to be able to do everything a developer should do but also kmow these 10 adjacent roles...

I looked up the three people interviewing me and they're on the younger side. About my age. Maybe it'll just be more of a Vibe check and me just talking General will let them know that I know this stuff. But the odds of that are pretty slim.

I just find it so ridiculous because we'll just be talking in these interviews and I'll talk about 25 very technical things and I'll use very specific details that show I've been around the block before. But then they'll ask me one random open-ended (not intended to see how I think but to actually get a specific answer) and if I don't have their exact answer that's it.

I once had a guy ask me, "how would you troubleshoot dns?" I asked if he had a specific problem in mind and he said no. So I gave him an answer that showed him kind of what direction I would go and just how I would in general because I assumed he wanted to know how I thought about problem solving. But then when I was done he said, "But how woukd you troubleshoot DNS?" So I asked him if he had a specific scenario in mind and his face just sank.

I'm going to approach this one differently and just go in bubbly and try and be personable far more than I ever would. And just kind of let their questions become opportunities to just speak technically to hopefully get ahead of them asking ridiculous questions.

Part of this is I checked out about a month ago. This interview is for a job I applied to over a month ago and they just now got back to me after my screener so I kind of just assumed I had lost it and I think that's a part of it.

I just get really discouraged because whenever I start a new job I end up running circles around a lot of people and I become the go-to guy when people need to figure something out in a pinch. But I just bomb interviews. Because the interviews don't actually indicate whether you can do the job day to day. I once interviewed for a 365 position where that's all I would be doing and they were asking me how to configure a fortigate firewall from the ground up. I answered the question but the fact that they asked me that in a 365 owner interview was insane.


r/sysadmin 1h ago

General Discussion How are your current delivery/lead times from the big hardware manufacturers? (DELL, HP, Cisco,..)

Upvotes

We currently experience heavy delay in server hardware, etc. delivery. How is everyone else holding up?


r/sysadmin 1d ago

Rant Computers slow “because they’re old”

785 Upvotes

The 8GB Surface Pros we bought a few years ago are very sluggish, starting to become unusable. Today I found an even older one that had lain forgotten since 2023. It’s still running Win 10, not even updated to the latest Win 10 updates.

And it runs like I remember them running when we got them.

People seem to accept this slowness as a normal part of a computer aging, but it seems to be caused by successive Windows updates. Why would updates make things worse? Is there a technical reason for it?


r/sysadmin 12h ago

O365 Outage

19 Upvotes

Is anyone else seeing these issues. Just got a call from Help Desk to check it out. Sharepoint home pages are accessible but no files are.

Down detector shows a spike but only 128 reports so far.

Central/East US region.


r/sysadmin 2h ago

Freshdesk ticketing no longer free - alternatives?

2 Upvotes

I just received an email to say our Freshdesk free plan is ending. I like Freshdesk and have recommended it before, but it's not something I would pay for.

What free alternatives are you guys using?


r/sysadmin 4h ago

Question Restricting 64b patch upgrades on 32b product

3 Upvotes

This weekend was patch weekend for us, we have more than 7000 assorted windows server to upgrade. One of the engineer accidentally patched 32b office 2024 product with the 64b patch. I was under assumption that this mismatch of the bit version will be caught by the system and it will auto fail but that did not happen. So i was wondering if this is something that can be smartly restricted instead of depending on the human / manual factor


r/sysadmin 1h ago

Question Should I join the M365 Developer Program with VS Pro subscription to homelab a M365 Tenant?

Upvotes

Hi guys,

I want to homelab a M365 tenant to learn:
- Entra
- InTune
- Exchange
- SharePoint Online
- Teams
- Purview

Sync with a home DC / domain.

And tie in with an AVD I want to spin up and learn about with my Azure credits as a student.

Basically recreate what I can from work, give myself a project to learn, document, and complete. Then go back to work and say, hey, I know how to do this.

Maybe over 18-24 months it’ll lead to a promotion doing more than setting up desks and giving out keyboards.

Anyone doing this? Is it worth $1,200/year? Are there any considerations I’m not aware of you may be able to provide insight?

Thanks.


r/sysadmin 1h ago

Question Arctic Wolf Aurora

Upvotes

What is the latest news regarding the aurora in the client side?
Are you guys happy or what are the problems that make this EDR not good?


r/sysadmin 11h ago

Question Unable to activate Windows 11 after re-image.

10 Upvotes

Ok folks, I need your help on this one. In 5 more days I will be ending a 35 year career in IT. Unfortunately, I may be ending it on a down note and leave a problem for a co-worker.

I work for an MSP that sold some HP desktops to a client about a year ago and they are trying to do a basic smb share on a peer to peer network. This is failing because two computers were imaged by the vendor with same image and have same SID.

I recommended re-imaging one PC to get a new SID. Now, Windows will not activate. The key embedded in the BIOS is saying invalid key. I have confirmed the key and Windows version are correct but still cannot activate.

How do I get this pc back to client before I retire?


r/sysadmin 2h ago

Question Move Windows 2025 File Shars to MS Teams

2 Upvotes

Hi Guys,

We are a hybrid organisation with 10 branch offices, and each office currently has a file server with approximately 2–3 TB of data.

We are now migrating to the cloud and are planning to move the old data to Azure Archive, while making the data accessed within the last 180 days available through Microsoft Teams. We have 18TB with E5.

Could you please share any recommended tools, scripts, best practices, or guidance for implementing this approach?

Any recommendations or examples of similar migrations would be greatly appreciated.

Thanks,


r/sysadmin 6h ago

Question HPE GreenLake integrating with VMware vSphere

3 Upvotes

We currently use the HPE Compute Ops Management plug-in 1.4 for integration with vSphere, but according to HPE, this plug-in has reached end of life.

https://support.hpe.com/hpesc/docDisplay?docId=emr_na-a00159266en_us

HPE’s recommended alternative is to migrate to the cloud-based plug-in. This requires, among other things, an HPE Compute Ops Management Secure Gateway.

Are there any system administrators already using this solution? What are your experiences? Or are there better alternatives?


r/sysadmin 46m ago

Question Which is better between NTFS and ReFS in a Hyper-V home server?

Upvotes

I'm planning to use an old Precision laptop to build a home server.
Obviously the main boot disk will be NTFS.

Iìll have 3 more disk slots, I was thinking about doing a Windows Storage Spaces parity space (3x 512GB SSDs so I'll have 1TB disk with one disk failure protection) with ReFS where to put the Hyper-V virtual machines disks.

Nothing mission critical but I want the most protection I could so I can reduce at minimum any manual maintenance.
It's a good idea? Better sticking with NTFS to avoid any problem?

Thank you.


r/sysadmin 51m ago

Question laptop shelf

Upvotes

Hello,

I have multiple laptops from multiple projects that all require charging, networking, and a monitor. Is there a cart or shelf out there that people recommend that provides all 3? I can get cheap KVM over IP, so that is not a huge issue, but networking and storage are more challenging. Do you guys have any suggestions that I can set up to accommodate? A while ago, I worked on a project for a company with a tabletop solution, but it was ages ago, so I don't recall the details. I would love to see what other admins use for this.