Reddit Sysadmin – Telegram
Drywall….

Going through a remodel. Contractor promised to use barrier, filtration and notify me when they were working on the server room. Everything coated in dust and sucked through everything. How screwed am I?

https://redd.it/1o6j8qk
@r_systemadmin
Company is increasing employee count four fold- what are some 'musts' for evolving IT practices / implementing new policies and/or platforms?

Basically just the topic noscript- what are some innovating approaches to new systems, policies, employee/customer engagement that a small IT team can think about when a company is expanding like this? What sort of things have you guys implemented that made a big impact to the work force, got you pats on the back, etc.?

Thanks for your time!

https://redd.it/1o6mkkd
@r_systemadmin
Production manager says MFA is causing production personnel to get distracted on their phones—he wants alternatives or MFA disabled

Production manager says when employees pull out their phones to accept MFA requests, they get distracted by notifications and spend more time on their phones that what he sees as acceptable. When employees are called out, they blame MFA for having their phones out. He's gone straight to the CEO, who is overreactive to productivity complaints.

They are asking IT if we can disable MFA for these employees, or make it so a phone is not required. Why are management issues always turned into tech issues? It sounds to me like there is a lack of discipline in that department.

CEO luckily understands the ramifications of disabling MFA, so he is not urging us to do so, but the production manager is still insisting something must be done.

https://redd.it/1o6q0qr
@r_systemadmin
How are you transferring PC files from old to new PCs in 2025?

Is OneDrive sync the easiest way to do this, or is there another tool that moves things over without too much hassle?

edit: how about apps/programs?

https://redd.it/1o6q5x3
@r_systemadmin
Randomly SSD not found - users get PXE boot prompt, reboot "solves" this

I seem to be seeing a rash of these across laptop models, more on ThinkPads than anywhere else over the past 6 months or so. The issue seems to be the SSD is not seen at boot causing the laptop to attempt to PXE boot. Power cycling the laptop seems to resolve this, but it eventually comes back. Laptops seem to have no other issues. Once running, they run fine.

I had been hoping it was a firmware issue that would be resolved, but it's still happening several months after we first started seeing it. Laptops are all new, ie within a year to 18 months old. Vendors (Lenovo, Dell) want to swap the SSD and start fresh. Users are hesitant because of downtime and needing to use spares that are 3-4 years old, so painfully slow by comparison.

Before we start replacing SSDs, has anyone else run into this and have you found a fix?

https://redd.it/1o6p5g6
@r_systemadmin
USA-based Admins: How do you negotiate a wage?

I am moving to the USA. I have a job offer that's median-low for "IT Engineer" (Win+Linux+AWS). What I don't know about is benefits. Do you negotiate that too?



i.e.
They might offer good Vision+Dental but poor medical (drugs?).

So do you counter-offer to improve those things too?

How does the average non-dev negotiate your salary?

https://redd.it/1o6oxg8
@r_systemadmin
Need office hoteling software recommendations (desk booking conflicts)

Our company went "hybrid" a couple of months ago (downsized our office space by 40% but they still expect everyone to come in most of the time) but desk booking conflicts are proving to be a bit of a problem.

I've been tasked with finding some kind of ‘office hoteling’ software (which I think is just a fancy term for desk booking? Please correct me if I’m wrong!)

I've been Googling but frankly getting a little overwhelmed, so wanted to ask what are you all using? 

Ideally we’d like something that either integrates with Slack or has a mobile app to make this more convenient for folks.

https://redd.it/1o70s3v
@r_systemadmin
How do I permanently fix "trust relationship failed" errors on domain-joined laptops connecting via VPN?

Looking for some help with a recurring issue that's been driving us nuts. We're an MSP and have a client with a relatively simple setup, but we keep hitting the same problem.

The client has a single office with a Windows Server 2019 Domain Controller. They've got 4 desktop PCs and 4 laptops. Two of the laptops are for hybrid workers, and the other two are for fully remote employees who never come into the office. Remote users connect back via SoftEther VPN.

Here's the issue: only the laptops are getting the "The trust relationship between this workstation and the primary domain failed" error. The desktops? Never have this problem.

What's really strange is that it happens both when laptops are connected via VPN and sometimes even when they're on the same WiFi network as the DC in the office.

When it happens, sometimes a reboot fixes it. Other times users just wait and hope it sorts itself out. If a user brings their laptop back to the office, plugging into ethernet sometimes helps. When none of that works, we end up unjoining and rejoining the domain, which obviously isn't a real solution.

I'm looking for what we should actually be checking to solve this permanently. What causes the trust relationship to break specifically on laptops? Is there something about the VPN connection or laptops going to sleep that breaks the secure channel?

Any diagnostic steps or configuration changes we should be looking at?

https://redd.it/1o6xoav
@r_systemadmin
Microsoft 365 Online blocks its own emails as spam, because of their "Advanced Filter". How to stop this.

Emails from quarantine@messaging.microsoft.com are blocked. Reason is "Detection technologies: Advanced filter" which Microsoft doesnt let you edit or show how it works. Just says "advanced machine learning"

How can they block their own emails as spam?

https://redd.it/1o75v8g
@r_systemadmin
25H2 and WSUS

Hi all.

Anyone here still using wsus like we do? :)

Did you receive 25H2 enablement package to it?

We did not, just full blown 3,5GB install package.

https://redd.it/1o75mbc
@r_systemadmin
Windows 10 LTSC 2021 End of life? What the hell, Microsoft?

Just got into the office, and immediately saw that some of our LTSC 2021 Machines show the ESU Message in Windows Update, telling me we are out of support and should update asap or buy ESU. This is a sick joke, right? Last time i looked, we have got a few years still - also it didn't report any updates for last patchday.

Thanks Microsoft, this is fun.

Anybody else having issues?

EDIT: Guys, this is about LTSC, which is supported for quite some years still. Not about Enterprise, Pro or Home.

https://redd.it/1o77q40
@r_systemadmin
IT issues at orgs outside your control

My brother in law works for a place where he has crazy stories about his IT department. Usually its just laughable things that I can shake my head at and make myself feel superior because "i would never do it that way" or "that's so easy to fix".

But sometimes im left scratching my head in utter confusion.

They recently had a "firewall breach". IT has told everyone that from now on they're only allowed to have one browser tab open at a time. Multiple reminders have been sent.

That's a new one for me. No extra explanation given either.

The only thing I can think of is they're concerned about what a non-visible tab is doing in the background. Nothing else makes sense to me.

So if you want to remain safe only use one browser tab at a time.

https://redd.it/1o78nkd
@r_systemadmin
Windows Release Health Messages

I read every single Windows Release Health message that Microsoft emails. When relevant, I make colleagues and occasionally some guys in discord aware of things of note, but just about never post them in this community.

It also occurs to me that a huge amount of this community is not subscribed to Windows Release Health messages.

On several occasions over the last few months, I've read these messages, become aware of an issue, and then (days later) saw posts from highly frustrated system administrators that struggled for a day or two with that exact issue because they were not aware of what MS published.

I am wondering if it would do some good to post these here in r/sysadmin with regularity.

For example: Just this morning, MS has released a message indicating that currently directory sync will fail on Server 2025 for AD security groups exceeding 10,000 members. I can't imagine anyone using AD security groups that large, but I now imagine I'll see a post in the near future where my failure to imagine was someone else's reality.

As a PSA: Windows Release Health

If you're an enterprise user, you can log into the admin console and subscribe to these under Health -> Release Health

https://redd.it/1o7dmey
@r_systemadmin
Only buying tools that are "AI"

Hi guys,
our management just came up with a new WTF policy that says all new tools considered must be "AI-powered". This means that tools that do not use AI should be excluded from the selection if there is an alternative with AI. Anyone else dealing with this?

https://redd.it/1o7em4c
@r_systemadmin
Working in your personal time shouldn't be a requirement while applying for new jobs.

I've been in IT for about five years now, started as a level-one helpdesk and worked my way up the ladder into a managerial position where I help oversee my coworkers'. I'm burnt out and I feel like I've hit the ceiling, and I'm trying to just get out.

Polished my resume, applied, a handful of interviews but so far: Nothing. The advice I keep seeing is that you have to have a home-lab, etc.

This may be unpopular, but I don't like this mentality. I already bust my ass at work every single day, and I have other obligations (family, etc.) to manage in my personal time.

I shouldn't have to dedicate every moment of my private life for, like, months working on some personal project I have no interest in just to be able to crawl out of a shitty helpdesk role. No other field expects that kind of personal devotion, right??

I get that's what the field expects but, honestly I think this kind of 'just work in your off-hours too!' mentality needs to be restructured.

https://redd.it/1o7f0uw
@r_systemadmin
Directory synchronization fails for AD security groups exceeding 10,000 members

https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2025#3692msgdesc

**Message:**

Applications that use the Active Directory directory synchronization (DirSync) control for on-premises Active Directory Domain Services (AD DS), such as when using Microsoft Entra Connect Sync, can result in incomplete synchronization of large AD security groups exceeding 10,000 members. This issue occurs only on Windows Server 2025 after installing the September 2025 Windows security update (KB5065426), or later updates.

**Workaround:**

Affected customers can apply the following registry key to disable the feature change.

**Warning:** Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk. For more information, see Windows registry for advanced users.

**Path:** Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides

**Name:** 2362988687

**Type:** REG_DWORD

**Value:** 0

**Next steps:** We are investigating this issue and will provide a resolution in a future Windows update.


Affected platforms:

Client: None
Server: Windows Server 2025

https://redd.it/1o7dsl3
@r_systemadmin
Another day, another huge Vonage outage

So who's everyone using for their VOIP and call center systems these days? Because Vonage is apparently not the one to use.

https://redd.it/1o7guq8
@r_systemadmin
I have no idea how SSL certificates work

I've worked in IT for a few years now and occassionally have to deal with certificate renewals whether it be for VPN, Exchange, or whatever. Every time it's a pain and I don't really know 'what' I'm doing but manage to fumble through it with the help of another tech or reddit.

Anyone else feel like this? Is there a guide I can read/watch and have the 'ah ha' moment so it's not a pain going forward.

TIA

https://redd.it/1o7kpkw
@r_systemadmin
What is the best idiot-proof guide for domain controller replacements?

As a solo-admin "jack of all trades" I've done a few Windows Server replacements over the years but not the DC promotion method. I'd like to keep all my settings for DNS, DHCP, ADDS, and promote a new DC (2022) then retire the old one (2016). I've been researching and reading guides, just curious if anybody else that has found that one guide, that doesn't miss ANY steps, that really got them through the process despite not being a Windows Server expert.

https://redd.it/1o7dh27
@r_systemadmin
Bad Day for F5 and any F5 admins here.

https://thehackernews.com/2025/10/f5-breach-exposes-big-ip-source-code.html

https://my.f5.com/manage/s/article/K000154696

What a bad day for F5 and any f5 admins we on here. Thy were hacked by a nation state. F5 don't even how long they had access. Emergency Patches for all the vulnerabilities they had not patched yet.

It is not a good look for a cybersecurity to get hacked. I thought it should see the end of any company but Solarwinds has proved me wrong.

https://redd.it/1o7oof5
@r_systemadmin
How do you handle a tech who keeps replacing endpoint devices?

So we have this tech who has the habit of replacing the laptops even though the issue is software-related. Oftentimes he will try to troubleshoot with a very generic troubleshooting steps which is comparable to a bigbang approach and not really a logical and isolated troubleshooting. In our environment, 8gb ram on laptops is good enough. But once he sees its an older laptop and only has 8gb, he resolves to processing a replacement request and informs the users that the laptop replacement is the solution. We have been given information before that we only have limited quantity of devices and obviously if it’s a software issue we would have to fix it without replacement. Now the replacement request is passed on to the tech closest to the user and when the tech sees that it’s an issue that can be resolved without replacement, we would now have to deal with the users insisting to have it replaced as they were misinformed initially.

How can we stop him from doing this behavior or how do we deal with these misinformed users? Thanks in advance.

https://redd.it/1o7v3so
@r_systemadmin