Reddit Sysadmin – Telegram
Hot take: People shouldn't go into DevOps or Cybersecurity right out of school

So this may sound like gating, and maybe it is, but I feel like there's far too many people going into "advanced" career paths right out of school, without having gone through the paces first. To me, there are definitively levels in computing jobs. Helpdesk, Junior Developer, those are what you would expect new graduates to go into. Cybersecurity, DevOps, those are advanced paths that require more than book knowledge.

The main issue I see is that something like DevOps is all about bridging the realm of developers and IT operations together. How are you going to do that if you haven't experienced how developers and operations work? Especially in an enterprise setting. On paper, building a Jenkins pipeline or GitHub action is just a matter of learning which button to press and what noscript to write. But in reality there's so much more involved, including dealing with various teams, knowing how software developers typically deploy code, what blue/green deployment is, etc.

Same with cybersecurity. You can learn all about zero-day exploits and how to run detection tools in school, but when you see how enterprises deal with IT in the real world, and you hear about some team deploying a PoC 6 months ago, you should instantly realize that these resources are most likely still running, with no software updates for the past 6 months. You know what shadow IT is, what arguments are likely to make management act on security issues, why implementing a simple AWS Backup project could take 6+ months and a team of 5 people when you might be able to do it over a weekend for your own workloads.

I guess I just wanted to see whether you all had a different perspective on this. I fear too many people focus on a specific career path without first learning the basics.

https://redd.it/1o5sh3a
@r_systemadmin
Handling requests to Merge PDF or sign without Acrobat?

What’s everyone doing for users who just need to sign or edit PDFs occasionally? Buying full Acrobat licenses for everyone feels like total overkill.

https://redd.it/1o5rhic
@r_systemadmin
How to approach an IT employee about possible theft?

This is an ongoing investigation.

I did an audit of our business phone portal, and noticed several ex employees still on the account. At first I thought to re-visit our offboarding procedures, and ask the support team why they haven’t off-boarded these lines from our account.

I decided to dig deeper instead. I discovered several of these ex employees had brand new phone upgrades, and the transaction history, in all cases, shows one specific IT staff member fulfilling these orders.

I decided to call a few of these numbers. None answered, but one number did go to a real human voicemail, of an even older user that hasn’t worked here in 10 years. What’s even weirder: that phone number is associated with a different ex employee!

Is my IT employee stealing, or (this is me giving them a huge benefit of doubt) do they have some whacky convoluted way of organizing our accounts, which needs to change anyways because wtf is this mess

https://redd.it/1o5x48o
@r_systemadmin
Leadership wants to nuke staging and test everything in prod. am I being paranoid or is
this a terrible idea?

Newish Senior DevOps at a 80 eng company. Standard setup: local dev → dev env → staging (mirrors prod) → production. Costs are being scrutinized and staging is eating 25–30% of infra spend. New leadership wants to delete staging entirely. Basically he believes “staging never mirrors prod anyway and feature flags + progressive rollouts + good monitoring > staging". He plans to kill staging, deploy everything to prod behind feature flags and use progressive rollouts (1% → 5% → 25% → 100%).


Here’s why I’m panicking we’re not a FAANG, we only have three DevOps people, our test coverage is a flaky @ 60%, and we deal with sensitive financial data where a production breakage would be a lawsuit. I don't know how we're supposed to "progressively roll out" something like a database schema migration, especially when our monitoring is a basic combination of Grafana, logs, and vibes, and some of our devs still hotfix the main branch directly without PRs.



When I brought this up, my manager's reply was, “If you can't safely deploy to prod, that’s a culture problem, not an environment problem.” Now the junior devs are hyped, the seniors and PMs are confused, its a shit show This is all happening at a company that already deploys 15–20 times daily, had three production incidents last quarter (including a 45-minute outage), and where rollbacks are basically just revert and pray. I'm the one expected to lead this rollout, so someone please tell me if I’m just being an old man yelling at clouds or if this is as bad as it feels.

https://redd.it/1o5xleg
@r_systemadmin
Do password resets on Admin Center sync with on prem AD?

I’m fairly new to IT and work for a university.

When staff need their password reset by us, the head of IT says we should change the password for them using both on prem AD and the Admin Center so they can immediately log into their laptops using our network.

However for students, we only need to change their passwords on the Admin Center and not on AD, as they log into their own devices (i.e their VLE or email)

My question is will the Admin Center password reset sync to AD? My understanding was that it syncs from on prem AD > Entra, and not the other way around. Is only changing their password for students using the Admin Center bad service desk etiquette?

https://redd.it/1o6238z
@r_systemadmin
Patch Tuesday Megathread (2025-10-14)

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

Deploy to a test/dev environment before prod.
Deploy to a pilot/test group before the whole org.
Have a plan to roll back if something doesn't work.
Test, test, and test!

https://redd.it/1o65i4e
@r_systemadmin
Please tell me my perspectives were right about the error they were getting when trying to Open Powerpoint files using PowerPoint Desktop apps

Actually I have been sick and tired from having to answer them the same fking error they are dealing with. But I hope I am right about it, If you guys have any solutions for this, please help me..

Situation:
\- They are working a pitch powerpoint file, the size is 600MB.
\- They need to work the file "together", so they can see each other updates.
\- So usually the first 2-4 users wouldnt have any issue to open that file using Powerpoint Desktop

\- The problem now is the following 5++, when they open it, they will get an error like :
"UPLOAD FAILED: Your file wasn't uploaded because your changes can't be merged with changes made by someone else. Save a Copy / Discard Changes:

My explanation:
This is due to the users that were managed to access the large ass file (600mb), is doing their editing work. So for those users that were trying to open, it requires to download from the sharepoint first before they can open, but if the first 4 users keep adding / editing stuff into the file, how the fck can the powerpoint downloads it completely. And eventually their powerpoint will crash and boom, my message box will have full of questions like why he can open , but not me. But they doesnt accept my logic.

Solution so far:
I asked the first 2-4 users to STOP editing, let others to open first, only start the editing work. HOWEVER, in spite everyone managed to open, but because the file size is so large, and 7 users editing at the same time, eventually the powerpoint will still crash out for "SOME" of them.

https://redd.it/1o66b91
@r_systemadmin
How realiable is file recovery in microsoft365 in real use?

Hey folks,

been digging into how orgs handle file recovery in m365 (onedrive, sharepoint, teams...).

from what ive seen, most admins just rely on version history and the recycle bin, but i keep hearing about people losing stuff after the 93-day window, or overwriting important files with no rollback.

for those of you managing m365:

how often do you actually run into file loss that you cant fix with microsoft's built-in tools?

do you use any third-party backups, or just trust microsoft’s recovery options?

just curious how people deal with this in real life, any lessons learned or horror stories welcome.

https://redd.it/1o62grf
@r_systemadmin
Roadmap to Windows Server for a tech support at a school district

Our school district has about 30ish servers, one for each school. Using hyper-v a lot, about 180ish vms to run as file servers, papercut servers and etc. Now we are beginning to fully adopt Intune to manage our pcs, laptops and macbooks & ipads.

As a tech support, school visits and ticketing are not challenging, would like to grow into sysadmin role, especially hands-on experience. Would much appreciate a detailed roadmap for a windows sysadmin in a school district.

Besides pursing MD-102 and MS-102 certs, I really want to b11th Gen Intel(R) Core(TM) i5-11600K @ 3.90GHzuild a homelab that can help me to get familiar with the skills required.

I have a gaming pc (11th Gen Intel(R) Core(TM) i5-11600K @ 3.90GHz, 12 cores, 64gram, 4 T ssd, gpu 3060 12G vram), is this enough to build a virtual homelab for practice? Or I have to purchase the used Dell server, switches to build a physical one? Or is there a cloud playground for Junior windows sysadmin?

https://redd.it/1o641f6
@r_systemadmin
How are you actually tracking assets across 200+ remote employees?

We've gone from 50 to 200+ remote employees in 3 years, and our asset management has become a nightmare.

The main issues we're facing:
Employees moving between states/countries with company equipment Devices falling off our radar when people use personal networks No clear chain of custody when hardware gets refreshed or people leave Shadow IT purchases that bypass procurement entirely Recovery logistics when someone quits (especially international)
For those managing distributed teams:
How are you handling this?
What tools or processes are you using to maintain asset visibility at scale?

https://redd.it/1o68x4d
@r_systemadmin
Anyone managed to get Cisco SmartNet for gear bought from the gray market?

Hey everyone,

Curious if anyone here has gone through this before.

We’re a small IT team running a few Catalyst 9300s and ISR 4Ks. Our local Cisco partner keeps telling us to buy everything new through them — otherwise “no SmartNet, no support.” The thing is, the quotes we’re getting are painful, and our budget isn’t keeping up with Cisco’s licensing changes.

I found a supplier outside our region offering brand-new, sealed Cisco gear. They claim everything’s legit — registered serials, no refurb, no grey tags — and they even offered to share serials for verification before purchase.



So here’s the question:

Has anyone actually been able to register SmartNet for gear that wasn’t bought through a local authorized Cisco partner? Does Cisco really reject SmartNet for gray market hardware, or is it up to the partner handling the request?



Not looking to do anything shady - just trying to keep the network healthy without breaking the bank.

Would love to hear from anyone who’s dealt with this recently.

https://redd.it/1o6adz7
@r_systemadmin
Just now bombed my HPE6-A86

Hello,

I just now failed my Aruba Exam, I learned with the study guide from the previous exam and had a Course 2 months ago to prepare for the Certification.
How would you recommend to me to learn for it, I failed with 50 percent.
There were questions that I had never seen before and didn't really understand. It was my first real Exam besides ITIL that I did.

https://redd.it/1o6bctf
@r_systemadmin
Veeam - Multiple Critical Vulnerabilities (CVSS 9.9) Resolved in latest B&R patch

https://www.veeam.com/kb4771

Looks like the worst of the vulnerabilities (CVE-2025-48983 and CVE-2025-48984) only affect domain-joined Veeam servers, which is not a best practice.

https://redd.it/1o6cwgr
@r_systemadmin
Microsoft Issues - Teams/Outlook/Sharepoint?

I know there was an outage around 4 5 days back, looks like we are still getting some weird issues.

In particular.

\- When trying to get into sharepoint files across different locations it states invalid, will randomly start working again after a certain amount of time

\- Teams messages/photos not sending and just stuck on spinning?


Anyone else experiencing any of the issues, I am based in europe.

https://redd.it/1o6dorv
@r_systemadmin
Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4165 Patch

Here are the details.

https://www.veeam.com/kb4771


https://redd.it/1o6ejfg
@r_systemadmin
AI Rant

Ok, it's not like I didn't know it was happening, but this is the first time it's impacted me directly.

This morning, before coffee of course, I over hear one of my coworkers starting OneDrive troubleshooting for a user who does not have OneDrive. While they can work with OnrDrive in a quazi-broken state, it will not fix the actual problem (server cannot be reached), and will get annoying as OneDrive is left in a mostly broken state. Fortunately I stopped her, verified that I was right and then set her on the correct path. But her first response was "But AI said..."

God help me, This woman was 50+ years old, been my coworker for 8 years and in the industry for a few more. Yet her brain turned off *snaps finger* just like that… She knew this user, and that whole department, does not even have OneDrive and she blindly followed what the AI said.

Now I sit here trying to find a way to gracefully bring this up with my boss.

https://redd.it/1o6h3ta
@r_systemadmin
Drywall….

Going through a remodel. Contractor promised to use barrier, filtration and notify me when they were working on the server room. Everything coated in dust and sucked through everything. How screwed am I?

https://redd.it/1o6j8qk
@r_systemadmin
Company is increasing employee count four fold- what are some 'musts' for evolving IT practices / implementing new policies and/or platforms?

Basically just the topic noscript- what are some innovating approaches to new systems, policies, employee/customer engagement that a small IT team can think about when a company is expanding like this? What sort of things have you guys implemented that made a big impact to the work force, got you pats on the back, etc.?

Thanks for your time!

https://redd.it/1o6mkkd
@r_systemadmin
Production manager says MFA is causing production personnel to get distracted on their phones—he wants alternatives or MFA disabled

Production manager says when employees pull out their phones to accept MFA requests, they get distracted by notifications and spend more time on their phones that what he sees as acceptable. When employees are called out, they blame MFA for having their phones out. He's gone straight to the CEO, who is overreactive to productivity complaints.

They are asking IT if we can disable MFA for these employees, or make it so a phone is not required. Why are management issues always turned into tech issues? It sounds to me like there is a lack of discipline in that department.

CEO luckily understands the ramifications of disabling MFA, so he is not urging us to do so, but the production manager is still insisting something must be done.

https://redd.it/1o6q0qr
@r_systemadmin
How are you transferring PC files from old to new PCs in 2025?

Is OneDrive sync the easiest way to do this, or is there another tool that moves things over without too much hassle?

edit: how about apps/programs?

https://redd.it/1o6q5x3
@r_systemadmin