Reddit Sysadmin – Telegram
These extra hidden fees need to stop, making a mistake is far too expensive

Moved a small, low-traffic dataset to object storage and expected a straightforward bill: pay for GB stored, end of story. Instead I get a breakdown with egress, request charges, “management” operations and a few other line items that quietly push the number up.

A simple helper noscript being too chatty with metadata was enough to nudge costs in a noticeable way, and a file we assumed lifecycle had removed was actually sitting in a different tier still generating charges. Add minimum retention on top and you end up paying for data that is either idle or already gone.

I understand why the pricing model exists, but it makes cost control far harder than it needs to be.

https://redd.it/1phf1rr
@r_systemadmin
Intern here… is every helpdesk tool this confusing or is it just me? 😭

So I’m doing an IT internship for my university and they have me doing basic helpdesk triage (password resets, printer drama, the usual).

But omg the tool we’re using feels like it was built in 2005 and never updated.
Half the buttons don’t make sense, things are buried under 3 menus, and I swear I need a map just to find the comment history.

Is it normal for ticketing systems to be this… ancient? Or am I just spoiled by modern apps?

Not asking for recommendations or anything (I don’t think they’ll change it lol), I’m just curious how different tools are in the real world.

https://redd.it/1phi036
@r_systemadmin
Company purchased Thin Clients without also purchasing licenses

The company I work for ordered several HP Elite t755 Thin Clients that run on IGEL OS. They did not realize at the time that this OS needs licenses to have the ability to RDP, which essentially makes them useless to us once the trial license expires.

We want to avoid using subnoscription based licenses, which seem to be the only option with the current OS. So the decision I have to make now is between 1. Just getting the subnoscription for IGEL OS 2. Install a new OS on these Thin Clients 3. Order new thin clients the use an OS that does not require a subnoscription based OS. Ordering new Thin Clients would not be a total waste of the old ones since we may be able to sell them back or repurpose them for a future project. I also figure we will not be doing option 2 since there are too many things that could go wrong with hardware compatibility or possibly voiding warranty/support from HP.

I looked into HP ThinPro and HP Smart Zero Core Operating Systems, they both seem more promising but I could not find any licensing information on HP Smart Zero Core. Does the license for either of these come build in to the Thin Clients, and are there any other HP SKUs that would make more sense if we were to buy other Thin Clients.

Note: This is being set up for a client and we usually try to avoid forcing them into subnoscriptions if it is avoidable even if it means a little more money in the long run.

https://redd.it/1phk4o2
@r_systemadmin
This is going to sound insane but... Is there a reason not to: Windows 11 IoT Enterprise LTSC over regular Windows 11 Enterprise/Enterprise LTSC?

Context is that management learned about Windows 11 IoT Enterprise. They heard that it is meant to be locked down and locked into place and has 10 years support with the release schedule that doesn't seem to care as much about features as it does security/stability.

We are in manufacturing so security/stability is the prime objective.

I cannot find a definitive list of "here is what is NOT in IoT that you get with regular" list and instead just says that licensing isn't as straight forward (like anything with Microsoft is licensing-wise?) I can't find a reason to say what I want to say which is "That is the dumbest idea ever!"

Any help guidance anything here?

The best I can find is that IoT is meant to be locked down which is what mgmt is looking to do. Each person has a small handful of applications they are to run and that is it. Extremely locked down GPOs as-is anyway.

Any reason to not do this? Has anyone actually seen/done this?

Unless there is something in licensing then can someone say why you would not do this? The best I've seen is that the end-user may notice some differences when using the device when compared to standard W11 LTSC which is already different than W11 anyway.

https://redd.it/1phgwuv
@r_systemadmin
Python or PowerShell?

I'm like 10 years into IT/security at a small but successful org (Windows shop with a few Linux appliances). I've gotten a lot of experience doing almost every (common) thing you can do in IT from basic help desk, user and endpoint management, switches, servers, firewalls, backup and restoration, etc.

The one thing I haven't done a lot of is noscripting. Of course I've used PowerShell plenty of times in the past and made a few of my own very basic noscripts, but I am so far from using it on the daily that I have virtually no experience. I've taken a Python course in the past too and have done basic bat noscripting but I feel like I haven't done enough noscripting at all to list it on a resume.

I guess what I wanted to ask here is if you were me, would you focus hard on PowerShell or Python? I feel like the obvious answer is probably PowerShell since we're a Windows shop, but still wanted to get input.

My past and present noscripts at the same org was/is: Network Administrator & Cybersecurity Engineer. I still do an equal amount of both and I'm not 100% sure what area I
want to grow in but yeah... I just think it's time to get wild and deep with noscripting so I'm more ready for what comes next.


EIDT: I should have added that I know I should probably learn both, but which one first I guess

https://redd.it/1phngbv
@r_systemadmin
Has anyone else dealt with an Adobe License audit?

Our organization got an email from EMEALicenseReview@adobe.com basically asking us to fill out a license verification form (Lizenzprüfungsformular) which has some questions about whether users share email addresses / adobe accounts. As far as I could see online, this is a legit request from Adobe.

Are they trying to crack down on shared accounts or what? Has anyone else gone through this? The timing seems random because we've been using Adobe for at least 10 years.

This is pretty frustrating after so many headaches with billing errors from Adobe where we sometimes can't even purchase new licenses if we wanted. If they're really just trying to milk us for a few more overpriced licenses, I'm going to lose even more respect for this company.

https://redd.it/1phhhka
@r_systemadmin
What is your horror story?

So everyone I know in IT has some kind of horror story when they screwed up in some way it another.

For me it was just as email virus/malware became a thing and the Love virus came out. I clicked on it on took out half the company in one day, over 1000 people.

Thankfully was not fired but I have never clicked on a link that I was not sure of since then.

What is your horror story?

https://redd.it/1phugc3
@r_systemadmin
Patch Tuesday Megathread (2025-12-09)

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

Deploy to a test/dev environment before prod.
Deploy to a pilot/test group before the whole org.
Have a plan to roll back if something doesn't work.
Test, test, and test!

https://redd.it/1phyxbt
@r_systemadmin
Microsoft Support, and the ridiculous way I hacked my way into my own tenant

Soooo... Last Friday, I was feeling lucky, I thought I'd push to prod what I've been testing for two months. What can go wrong ? After all, these Conditional Access Policies were in audit mode for what, two months ? And there were basically almost no failures.

I enabled them and lo and behold, everything went sideway. First, the one reducing the session duration for guest and unregistered devices started impacting users on their corporate devices (?!) and was quickly reversed. Nothing too bad.

But then, I started having difficulties logging to my tenant, and as it happened, I enforced PR MFA instead of 2FA (we're not ready for PR MFA yet) and... since I don't have PR MFA on my global admin account, I ended up locked out of my tenant, like my two other colleagues.

The good news was that users had only a minor inconvenient. The bad news was that I was stuck out of my admin access and no one would be able to help me but Microsoft.

So I did it, for the first time ever : I called Microsoft support.

After a 5 minutes wait, I ended up speaking with what seemed like a human, who understood I was locked out of my tenant, but apparently the phone number I dialed was for premium support only, so I was redirected to a second queue.

As it happens, the technician couldn't do anything because she wasn't in charge of business support, so she transfered me again to another queue.

30 minutes in and I ended up talking to someone who actually could help me. We opened a case, gave an e-mail address, a phone number to call back, and so on. I shall be called back within 8 hours.



In the meantime, I had my whole Friday night to figure out a way to solve my problem myself, and what I managed to do was beyond ridiculous : I logged to Power Automate with my global admin account, created a new flow that would add my own global admin account to an existing excluded group from the CA that was blocking me, ran the flow and... it worked. I regained access to my tenant by running a Power Automate flow.


Anyways, it's been 4 days since I supposedly opened a ticket to Microsoft. No mail, no call, nothing.

https://redd.it/1pi2ki1
@r_systemadmin
Honestly, there is no better job as a sysadmin if you are in the correct industry and size

I just love being a system administrator. Especially in smaller firms where the IT infrastructure was terrible. Just working project-based, designing and creating networks/server rooms, and doing DevOps. And don’t even get me started on all the detective work. As long as I don’t have to fix someone’s Outlook preferences, I can do this work for 16 hours and not get bored.

I feel though like you need to be very lucky finding the correct job. At bigger orgs with more structure means less fun honestly. Also right now I am this strong generalist where I can do different stuff to improve for everyone. But if i move to the next step becoming a network engineer or soc analyst or just a devops. Does it get more boring?

https://redd.it/1pi462w
@r_systemadmin
Parent company forcing unique phone numbers for account creation. Any easy workaround?

Hi all,

The parent company for our business, who we have accounts with for each employee, are now enforcing a rule that every new account created required to have a unique phone number to create the profile. Previously we've just been using the company number. I think the reason behind it is future use of SMS for 2FA but currently it serves no real purpose.

Our company has a rule that we do not expect our employees to have or use their personal devices for work and so we have to provide them. The most obvious solution is to purchase \~30 new phones, sim cards and phone plans just so we are able to make accounts?

There must be an easier solution? Ideally we'd have some cheap option for mass purchasing phone numbers that only serve to forward to a centralized real phone or something similar? Everything seems unaffordable and unrealistic?

https://redd.it/1pi3f58
@r_systemadmin
Anyone actually running an AI service desk (beyond a basic chatbot integration)

Kinda curious what folks are doing here. Most of the demos I see are just a chatbot slapped on top of a helpdesk. Im wondering if anyone is actually using something where the AI does triage, routing, maybe solves the simple stuff without being annoying.

If youve got it in production, whats working and whats just hype? Trying to get real answers before I waste more time on vendors. Thanks.

https://redd.it/1pi6lrr
@r_systemadmin
Old Firmware on Switches

Our Enterprise Switches are now out of date and not supported anymore. Are you guys always taking care to have Enterprise Switches that are on the newest FIrmware or at least update the firmware when there is an urgent issue or are you investing the money rather in other things?

I mean if you have a datacenter you better care for it, but in our own environment, with a closed building, basically no guests or so, should we really care to upgrade the hardware?

EDIT: How would you rate the security on it? All management Interfaces are on a Management VLAN and not accessible from anyone except our Privileged Access VMs.

https://redd.it/1pi7hx9
@r_systemadmin
I Fucking hate Microsoft

Fuck Microsoft. They changed the design again for the main Office home page. You can’t even find the Admin option anymore. Now you have to click on “Apps” first, and then you can pick the Admin option and pin it to the Office apps menu. Who designed this page? SMH. I’ve received so many tickets from users just trying to figure out how to open the apps from the main Office page. This Copilot thing really ruined everything, and now they’ve made this new change on top of it. Please, keep the Admin section separate from the applications. As admins, we should have a dedicated option under the apps. This whole design is so messed up — I hate it.

https://redd.it/1pib3rh
@r_systemadmin
Fibre channel vs iSCSI

A bit of an informal straw poll...

In my first job managing a datacenter for a medium business in the UK, and they have (before my joining) decided that they needed a separate storage network, using a pair of Brocade DS6520, connected to a Powerstore 3000T.

Being relatively green to datacenter infrastructure, Ive never actually seen this until now. Always dealt with collapsed core-type architecture, where SAN and LAN are over the same switches.

What's weirder, in my opinion, is the choice to have gone for storage switches that (currently) top out at 16Gbe per interface, while having 25Gbe on the LAN. We're currently hosting just about 200 VMs... If I was here circa 6 months sooner, I'd have pushed for iSCSI all the way.

Would love to hear stories, opinions etc.

https://redd.it/1pi9syf
@r_systemadmin
Kinda losing motivation to get into sysadmin

Just to be clear - SysAdmin is my end goal. I am applying for helpdesk/tier 1, 2 only. I have only applied for 1 junior system admin role and I had an interview for that. It's the only interview out of the hundreds of other helpdesk/tier 1,2 jobs I've had. This post is more of a help from you guys that are sysadmins and have been where I am do give me some advice or help.

Im 42. Been an industrial cleaner/team leader for 20 years. Decided to get into IT as thats what I wanted to do when I was young. Started my journey like 6-7 months ago now. Passed conptia tech+, a+ and networo+. Built a home lab. Learnt powershell, sql, excel, windows server, Linux server. I have a m365 business account and have added a few phones and vms.

I just can't get an entry level job at all. Ive had one interview and that was for a junior system admin and the interview went great and they were so close to choosing me but someone who they interviewed dead last had like 10 years it experience and because ive got 0 it was a no brainer.

I apply for so many jobs and only had 1 interview and that was only because my friend works at the company. The more I look at jobs and what they expect you to know is just putting me off and I just keep thinking if giving up and sticking to what I know even though I hate it now. Its mainly previous experience they are looking for

Any advice?

https://redd.it/1pih10y
@r_systemadmin
Hero Complex

Stop trying to be a hero.

Stop replying to every email within 20 seconds.

The best IT guys don’t try to be hero’s every fucking minute of the day.

You don’t need to be a hero and prove yourself even though you’re a classic imposter.

Silence. Patience. Refrain.

Actions speak louder than email replies inferring how great you are.




https://redd.it/1pihmen
@r_systemadmin
Fortinet - New Auth Bypass CVE for fortiOS 7.x FG-IR-25-647

Didn't see a thread about it yet but looks like all but the latest pretty much of all of the 7.x builds but the latest are effected https://www.fortiguard.com/psirt/FG-IR-25-647 as well as fortiweb/fortiproxy :/ Unclear if trusted hosts would prevent abuse, would think it would but since it's related to forticloud not 100% clear, just thought I'd post for awareness

https://redd.it/1piiixk
@r_systemadmin
Anyone else been force promoted?

I have been in IT for about 10 years now. I have been at the same company the whole time. The company wants me to step into a cyber security director role against my will lol. It feels like I live in a clown world sometimes. The impostor syndrome is real. I have been an soc analyst for 2 years....

I absolutely want nothing to do with managing people. Systems are much easier in my mind. So I am curious is it worth leaving a company that is forcing a promotion that I dont want? Important to add they have not delivered any raise yet. They also havent gotten that kind of work out of me yet because I won't do the work without the pay. Supposedly the money is on the way.

Supporting a few hundred servers and about 1500 endpoints.

Anyone else experience this or something similar? How did you handle it? If the answer is leave I am willing to I just love the people I work with and thats hard to find.

I do well on my own. I dont like to be stuck between my friends and top management. Translating that mess = a monkey humping a football!

I feel like maintaining my peace at this point is a more intelligent move, or maybe I should stop being a little bitch and "sack up" as they say? Embrace the suffering 🤷‍♂️.

Let's say I do stay, I would be managing two security team members two analysts and one engineer at some point. How much of a salary should I ask for? Thanks reddit mob in advance!

https://redd.it/1pim1de
@r_systemadmin
How do you handle certified destruction of HDDs/SSDs during large fleet refreshes?

In large-scale replacement scenarios, I keep seeing three recurring paths: NIST 800-88 overwrite for HDDs (one pass + verification), crypto-erase for SSDs where the controller supports it, and, when it doesn’t, physical destruction with controlled particle size. What mattered for us was having serial-to-device mapping before and after, a verifiable chain of custody, and reports that can go straight to auditors without extra translation.

For big batches we used E-Waste Squad specifically for the operational side: uniformed team and tamper seals at pickup, tight per-serial inventory, destruction certificates delivered within 24 hours, and reports that include serial matching plus timestamps for each stage. It also helped that their processes align with R2v3, ISO 14001, NAID AAA, and NIST 800-88-documented erasure, which cut down audit friction.

What do you require in the SOW when you outsource ITAD: on-site witness, photo/video of shredding, sub-24h SLA for certificates, CSV/JSON serial exports, or even on-site destruction for certain media?

https://redd.it/1pih7nd
@r_systemadmin
I now understand why other IT teams hate service desk

I started on a service desk, moved my way to L2&3 support then now to where I am in cyber security and while on service desk never really understood the animosity other people had for SD, I now really do! Whether it is the rambling "documentation", no troubleshooting or just lack of screenshots forcing me to chase up with the end user rather than actually fix the problem.


The issue is that while there are some amazing people working on it the majority are terrible. Something I forget is that most decent support people move out of SD as fast as possible so that the remaining are just shite.


Don't say "we did some troubleshooting" then not document what you actually did, and for the love of christ I'd take a blurry screenshot or even you taking a pic of the screen with your phone over nothing at all.


\- signed frustrated AF support person

https://redd.it/1pioxb2
@r_systemadmin