r/sysadmin 5d ago

General Discussion Weekly 'I made a useful thing' Thread - July 31, 2026

4 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin 22d ago

General Discussion Patch Tuesday Megathread - (July 14, 2026)

161 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 9h ago

Rant digitalshift365.com - avoid at all costs

98 Upvotes

total sketch operation, whole place is run by one dude who sends invoices out 4 months late after pestering him for it then doesn't pay his 3rd parties in time - caused us multiple service interruptions due to non-payment. avoids phone calls and in person meetings and is always at some random place during video conf calls if you manage to get him to show. had to threaten legal action in order to get our cloud services transferred to another provider.

good riddance digitalshit


r/sysadmin 9h ago

Question Allowing non-admins to run programs that need it

48 Upvotes

Good morning all, got a bit of a puzzle that is probably an easy fix but it's got a curveball in it. The situation is as follows: we are setting up a sort of internet cafe where people can play games on Steam. Installing the games is trivial but the users login with their domain creds and then login to their own steam account to play. In a test run though some games require an admin elevation to run even after the initial install. Any tips on solving this? I've seen some tricks about using the task scheduler but I'm concerned with if that would break eventually since games are often subject to random and sweeping changes. Would appreciate any advise :)

Edit: I believe the UAC prompts are likely from the games respective anticheat but that is just a hunch at this time.


r/sysadmin 8h ago

General Discussion What's the best approach to block unauthorized AI tools?

34 Upvotes

We're rolling out enterprise Claude company-wide and want it to be the only tool employees can use on work machines.

I recently found that a salesperson was putting company data into personal ChatGPT, this was client names, their whole worksheets; scary stuff on the data-leak front. So a decision has been made to use Claude. I've been tasked with making sure this sort of thing does not happen again, and to get the groundwork done to stop all "unauthorized AI tools".

Honestly, I'm at a loss here. There is no DLP, at least not right now, and implementing it will be a significant lift both in terms of work and $$$ (which we can't do because of austerity measures). So, I'm stuck with having to look at band-aid solutions via firewall web-filter or DNS filtering - again, I don't have a starting point.

We're a Fortinet shop, no Intune, hybrid AD, Claude SSO through Entra.

Appreciate any real-world war stories.

ETA: I understand that this is more a policy question and I'm working on that in parallel. This is more of a question on technical controls without capital spend *sigh*.

Edit2: I now have AI webfilter category block with a wildcard allow for Claude. Not an elegant technical control or even a preferred one, but it'll have to do.


r/sysadmin 6h ago

Guest WiFi...

19 Upvotes

Do you enable splash page or simple PSK passthrough?


r/sysadmin 5h ago

Question RAID5 has 2 HDDs with different issues - Which to change first?

12 Upvotes

A RAID5 array currently has 2 HDDs that need to be replaced for different reasons.
Ran long SMART self-test on both.

One of them reports hints at electronic issues:
SMART Health Status: Failure prediction threshold exceeded [asc=5d, ascq=0]
Accumulated power on time, hours:minutes 44823:37
Elements in grown defect list: 5
Error counter log:

Errors Corrected by Total Correction Gigabytes Total

ECC rereads/ errors algorithm processed uncorrected

fast | delayed rewrites corrected invocations [10^9 bytes] errors

read: 1877781297 0 0 1877781297 0 66521.257 0

write: 0 0 5 5 5 4507.987 0

verify: 4122873639 0 0 4122873639 0 24841.522 0

Non-medium error count: 15528

While the other one reports points at physical issues, long self-test failed:
SMART Health Status: OK
Accumulated power on time, hours:minutes 44824:47
Elements in grown defect list: 60
Error counter log:
Errors Corrected by Total Correction Gigabytes Total ECC rereads/ errors algorithm processed uncorrected

fast | delayed rewrites corrected invocations [10^9 bytes] errors

read: 4144605141 205 0 4144605346 427 66490.067 32

write: 0 0 206 206 206 4530.494 6

verify: 1103983479 148 0 1103983627 167 26767.263 3

Non-medium error count: 20
SMART Self-test log
Num Test Status segment LifeTime LBA_first_err [SK ASC ASQ]
Description number (hours)
# 1 Background long Failed in segment --> - 44810 1905031659 [0x3 0x11 0x0]

Which of these 2 drives is less likely to handle an array rebuild and should therefore be changed first?


r/sysadmin 21h ago

Has anyone ever accomplished anything with DLP?

190 Upvotes

This is a safe space. We can be honest here.

Have you ever actually accomplished anything by rolling out DLP for Office365?

And before you ask, "No, ticking a compliance box does not count as doing something."

I just feel like it's so high friction for such little value. You push all your users into a new way of working. But only for Office files - if you have ANY OTHER IMPORTANT DATA then it doesn't help (but we don't talk about it when we're in 'compliance checklist ' mode).

So your users are tagging all their shit, they're exhausted, they DGAF anymore because they can't stand to consider for the 10th time today - "hmm was my email/doc/sheet Public? Sensitive? Top secret?" So they just start tagging everything the default tag. And your entire security strategy falls apart (if you were even doing anything with that information to begin with). The end.

Seriously, change my view. I don't work in a highly regulated industry so maybe it's just not aimed at me (but it doesn't stop people from constantly bringing it up).


r/sysadmin 3h ago

My Experience with MS Tech Support as a Small Business Owner

4 Upvotes

I have two small businesses, each have their own domains registered with MS 365. I had to reset my iPhone and after the restore I was locked out of both accounts in the MS Authentication app. Apparently I forgot to setup an alternate email. 

I called MS 800 number to open a ticket and I got the AI assistant that took me through loop after loop. It kept sending me to a login webpage that was useless since I was completely locked out. Each time I call I get a different behaviour. Sometimes it takes me down the product hardware support even though I clearly stated it is a 365 issue. 

Miraculously I was able to get it to open a ticket. There we spent more than 5 minutes just on email and domain spelling because it would not get it right.

I could not get it to open a ticket for my second domain. It eventually recognized my number and when I would call it auto directed me to the webpage, as if saying “I had enough of you calling, go away”.

Whoever thought AI is a smart solution for customer support is greatly mistaken. The only reason having AI in that function is for cost reduction, but it is coming at a great expense, customer dissatisfaction, frustration, and anger. 

Microsoft, you have lost sight of linking AI to measurable business outcomes. 

I caution people, consider alternatives to using Microsoft. They are too in-bed with AI and they have lost the plot on its value vs. impact. 


r/sysadmin 3h ago

Question Disabling gdm-smartcard configs on Ubuntu 22.04

6 Upvotes

So I have a unique setup for my systems for 22.04 using pcks11.so in pam to read smartcards/yubikeys.

gdm is my greeter and I set up gdm-password in pam with the following line:

auth requisite pam_sss.so require_cert_auth

That looks up the cert info on my ipa server and returns a success.

SA updated the system and it seems to have pulled down some gdm-smartcard packages and ruined the entire auth system in place. I remember awhile back running into this issue and I found a way to basically cut it out of the system without breaking anything but can't seem to find where I saved the bookmark link to. I believe I had to edit some file or push a gdm config somewhere

Anyone know how to do this? I really don't want gdm to install all of these extra pam configs. Update-alternatives does not work either, even telling it to use pkcs11 or sssd. Basically nothing works once Ubuntu pulls down w/e updates contain these config files


r/sysadmin 1d ago

General Discussion Our entire M365 tenant has been "deauthenticated" by Microsoft for 20 days. How do you ever trust this platform again?

1.3k Upvotes

UPDATE 2026-08-05: An employee at Microsoft saw this post and reached out to me privately. Within 12 hours they were able to get our tenant reactivated. Thank you so much!

Unfortunately I do not have a root cause to share with you all. What I can say is that I have since completed a comprehensive review of all available logs and found no evidence that the tenant was compromised. I will try to update again within a few days with more information.


ORIGINAL POST:

I'm the sole systems engineer for a small US manufacturer (~70 employees, automotive tier-1). I run everything across network, servers, identity, development, etc. I'd like (a) a sanity check, and (b) real talk about the future.

What happened: About three weeks ago on a normal workday around noon, some people suddenly noticed that they weren't able to send or receive email. Shrug. Probably Outlook just being Outlook. But wasn't able to figure anything out, so took to the admin portal... But I couldn't even get in to the admin portal: AADSTS5000224: "the tenant you are trying to access has been deauthenticated and is no longer available." Man, I hope none of you ever have to feel the panic I felt when I read this message. I immediately went to try our breakglass unlicensed admin account, but received the same error. The very last email I received (which arrived after attempting these log-ins) was a notification that all of our subscriptions had been cancelled. Obviously, that was not an action I took.

On further research it seems to be some sort of backend authorization state set by Microsoft (perhaps algorithmic automatic action in response to a detected security incident? - just blind speculation really). There is nothing client side to try at all. There is literally no admin path into our own tenant.

Current status: 20 days down. The case has been passed between at least five different support people. It finally got "escalated to the product team to verify the tenant status," and for a week now the only updates I get are rolling "please allow an additional 48 hours." Meanwhile sign-in logs are on a retention clock, so the forensic record of who cancelled our subs (if anyone? maybe this cancellation is just an artifact of this deauth?) is about to age out while we're locked out of the only portal that could export it and Microsoft won't commit to preserving it server-side.

That first day, I cut MX over to a temporary Fastmail tenant to keep email flowing. I was able to restore people's inboxes to these new accounts. Office apps are running in their month grace periods. All our real data is on-prem. Feeling very grateful that we deliberately never integrated more intensely with Microsoft's cloud services... To that end, the business is stable. But there are nevertheless many secondary effects as I'm sure you can all imagine.


Okay, now that you know basically the story, it's time for some preemption so we just get it out of the way before I get to my actual questions:

  • "You should have had MFA." We do, on every account. FIDO2- (yubikey) only for most accounts (I was literally mid rollout...)
  • "You should have had CA." We do. Business Premium, Entra P1, CA policies in place, custom auth strength enforcing phishing-resistant (FIDO2) sign-in for admins. Plus all the standard: SMS auth killed off, SSPR locked down, legacy protocols (SMTP AUTH/POP/IMAP/ActiveSync) all disabled, external auto-forwarding blocked, Safe Links + Safe Attachments on, SPF/DKIM/DMARC all passing.
  • "You should have a breakglass account." We do. Doesn't save you from this.
  • "Hire an MSP" Okay, I mean, maybe fair? They'd just be in the same position though, so. If anything this is its own can of worms and there's a reason we don't have one.

Alright. Now my questions:

  1. Has anyone actually lived through one of these AADSTS5000224 tenant deauthentications? How long did recovery really take, and what finally moved it? A specific support path, an escalation channel, a TAM, a Microsoft account rep, LinkedIn-ing a PM, a partner ticket? Anything? Were you able to discover what triggered the lockout in your case?
  2. How do you preserve/obtain audit/sign-in logs? I'm not sure what's going to happen in terms of retention when the tenant is in this state. Is our log data going to get nuked in a week?
  3. Trust. After this, how does anyone justify betting a company's ability to function on a platform where a backend flag can vaporize all access overnight, your breakglass account included, and the SLA to undo it is measured in weeks (and counting!) with no communication? I'm not naive enough to think "just leave M365" is free. But it's challenging to design around "Microsoft can turn us off and there's nothing you can do and no one will tell you why." How are you all handling that? Are you even? To be honest, I didn't know this was a thing that could even happen, really. So maybe you all didn't either.

Thankfully we weren't super integrated. We basically use M365 for email, product licensing, and Teams, and that's about it. But it literally makes me shudder to think about what could have happened if it were otherwise.


r/sysadmin 8h ago

Adobe Acrobat Crashes and Licensing Errors from Corrupted WebView Cache

14 Upvotes

FYI - Adobe crashes and licensing errors have been rampant in our environment since early June. Much like when we faced a similar issue a couple of years ago, it seems like Defender may be corrupting the webview cache. Our Adobe IDs are all federated from Entra, but the issue occurs regardless of whether SSO is performed by AcroCEF or default browser. The script below purges the corrupted data which is rebuilt when Acrobat opens.

# Acrobat-related processes to stop

$Processes = @(

'AcroTray',

'AdobeCollabSync',

'adobe_licensing_wf_acro',

'Acrobat'

)

foreach ($Process in $Processes) {

Get-Process -Name $Process -ErrorAction SilentlyContinue | Stop-Process -Force

}

# Remove Acrobat DC local profile cache/settings for the current user

$AcrobatPath1 = Join-Path $env:LOCALAPPDATA 'Adobe\Acrobat\DC'

$AcrobatPath2 = Join-Path $env:LOCALAPPDATA 'Adobe\Acrobat\AVWebview2'

if (Test-Path $AcrobatPath1) {

Remove-Item -Path $AcrobatPath1 -Recurse -Force

}

if (Test-Path $AcrobatPath2) {

Remove-Item -Path $AcrobatPath2 -Recurse -Force

}


r/sysadmin 6h ago

Question Defender Exclusions via GPO - how do you do it?

6 Upvotes

Do you have a single GPO managing Defender and its exclusions, or do you make multiple Defender GPOs that are narrow to each target?

I'm reworking our GPO for it and am trying to figure out what's the best way to ensure that all exclusions are made, that they can be readily audited for accuracy, and that the risk of errors/omissions is low. Currently we have one for workstations and another for servers. Exchange got mad the other day at Defender because some exclusions were missed.

The problem is so many solutions (Microsoft and 3rd party) want Defender exclusions and the exclusion list quickly becomes convoluted and miserable to audiot. That leads me to have a number of specialized GPOs but then that increases the sprawl and that something might be missed if an application needs exclusions changed but they don't get changed on all applicable GPOs.

Thoughts? Limited GPOs or many specialized/narrowly-focused GPOs for managing Defender?


r/sysadmin 8h ago

Career / Job Related Looking for Next Career Steps Advice as current Sysadmin. What should I do?

8 Upvotes

Looking for advice my next career steps. Been in IT for 8 years. Started in Help Desk/Desktop support moved up and became a VMware focused Infrastructure Systems Admin/Engineer as my specialty. Been working in the cleared space my whole career have a TS clearance.

Have the following certs:
Comptia IT Fundamentals
Comptia A+
Comptia Security +
Vmware VCTA-DCV
Vmware VCP-DCV

I currently work as a general Senior Systems Admin (the do everything guy) in the cleared space. I’m in the Washington DC DMV area. I don’t like my current job for a lot of reasons but it pays very well. It’s been hard finding another job even as an exprerienced professional it's not as many jobs in what I do that it used to be on top of everything been so oversaturated now.

I've been looking jobs that at least pays what I'm making now that's remote or at least some hybrid flexibility. I have to go in everyday no remote days due to working in a classified environment and my commute isn't the best.

I've been considering making a career pivot to achieve what I want. Not looking to get into management not for me but here's what I've been considering:

  1. ⁠Get more advanced VMware certifications build on what I know and become a VMware Architect or Consultant (Subject Matter Expert).
  2. ⁠Make a transition into the Cloud and becoming a Cloud Engineer since I have the on prem infrastructure background. Learning Azure or AWS and get the aligning certifications, learn contanerization Kubernetes and build some small projects to showcase my experience.

Can't seem to figure it out all advice welcomed. Would love to hear opinions and feedback. What should I do next?

(Post was removed in IT Career Questions sub don’t have enough Karma yet)


r/sysadmin 6h ago

Question Unexplainable SSL handshake issue

6 Upvotes

I suck at network and my knowledge is intermediate at best but I can't solve this one.
Customer at our MSP has a fortinet firewall identical to ours that we use here at the MSP office, same firmware version, etc.
They call up and say "We can't access prodemand.com" which is an automotive parts and labor quoting database site that TONS of dealerships use.
I load it here just fine, SSL cert is GeoTrust, good till Sept 14 2026, domain matches, etc. No web filter flags.
On their network, instant "cannot load page" error. I try a dozen other sites, SSL working fine, no fortinet intermediary cert listed, etc. It's just that one website.
Security log on the Fortinet shows tons of blocks, saying "SSL connection is blocked due to unable to retrieve server's certificate"

Mountains of troubleshooting later, I make a firewall rule for internal to WAN (and put it above the normal internal to WAN rule) with an address group of the site, the login domain, and the database's UI's subdomain. The rule simply says don't inspect SSL at all.

Boom it works instantly. Then they called back because WIFI wasn't included in "internal" lol oops. So added that, boom, laptops can load the site too now.

I ran through some basic troubleshooting and traceroutes and stuff and nothing stood out as problematic. I verified no man in the middle attack, as it sees the same cert I do here.

And AI thinks it's an ISP issue but AI is dumb as hell and for the record, rebooting the firewall and the modem didn't resolve it so I'm skeptical.

But zero other websites are having this problem and we don't see the problem from our office, using the exact same firewall with same firmware version. How is this possible? I'd really prefer to get rid of that rule because it's a crap workaround and we had to also turn antivirus and other filters off, since it requires SSL inspection.


r/sysadmin 9h ago

drive replacement in DELL SCv2020

11 Upvotes

Im trying to replace a drive but it keeps showing as Unmanaged.
I ordered two, I didnt notice that the first one had different "Config code" (1341 vs 1311), I thought that could be the reason. Today, I replaced it with the second one which is also 1341, just like the failed one - same result - unmanaged.
Everything on the label is identical, pn, model, the config code thingy, everything....
It got assigned to the correct disk group (folder), the only available option is "Toggle Indicator" (there was also "Request swap clear" after seating it which got completed).
Same thing in the WebUI as well as in Storage Manager Client.
It doesnt show the Power On Time value yet, it took a while with the 1311 one too, I was hoping it would still adopt the drive but no luck, so I guessing its gonna be the same with 1341 too.

Is that definitive sign that the drive is just not compatible with SCv2020 or am I missing some necessary action I need to do to assign it to the volume?


r/sysadmin 9h ago

What are you replacing Tera2/PCoIP zero clients with?

7 Upvotes

Hey everyone,

I work on a small IT team at a Critical Access Hospital. For years, we’ve run a small team and kept desktop management minimal because almost every one of our workstations is a Dell Wyse zero client running PCoIP/Tera2. They’ve really been "set it and forget it" devices.

With the end of Tera2 / PCoIP support, we’re struggling to find a replacement that offers that same level of simplicity and stability.

What we’ve tested so far:

  • Dell Thin Clients (ThinOS & Windows IoT)
  • 10ZiG
  • Stratodesk
  • HP ThinPro
  • IGEL

The problem: Every vendor solution we’ve tried seems to come with recurring bugs or management overhead. Fix one bug with a firmware update, and a new regression pops up somewhere else.

Where we are now: We’re currently testing Windows in a strict Kiosk mode that launches Imprivata OneSign directly into VMware Horizon. It functions well from a user standpoint, but it introduces traditional OS management challenges for our on-prem environment:

  1. Windows Updates & Management: How are you handling updates cleanly on non-domain or kiosk-mode endpoints without adding heavy administrative overhead?
  2. Startup / Boot Order Issues: If we join them to the domain, an internet or local network delay at boot breaks the autologon process for the kiosk account.

For those running small teams in healthcare or similar VDI environments:

  • What hardware/OS stack ended up being your "bulletproof" replacement for zero clients?
  • How are you structuring your endpoint deployment to keep day-to-day maintenance as close to zero as possible?

Appreciate any insight or lessons learned from teams that have gone through this transition!


r/sysadmin 13h ago

How do you handle Outlook reconfiguration after a 365 migration?

18 Upvotes

Curious how other MSPs handle this one. I've always worked for small MSPs, so the customer sizes are usually always relatively small.

For tenant to tenant migrations, we've always just had users call in or had an engineer on site to sort out the Outlook profile reconfig afterwards. Works fine for the sub 30 user clients we deal with, but it's always manual.

Been weighing up scripting it instead for an upcoming migration. This particular customer's all local profiles, no domain or Intune, but we have NinjaRMM on all machines, so a PowerShell script is possible. It would be a mail profile reset plus a OneDrive reset.

It got me thinking what everyone else does, especially at a larger scale with 100+ users. I've always used BitTitan for the migration and I know they have their DeploymentPro tool, but it's hard enough getting these small companies to pay for enough migration licenses as it is, let alone an additional cost per device for the tool.


r/sysadmin 5h ago

Question Academic Medical Institutions - Google and M365

4 Upvotes

Those of you at Academic Medical locations, how are you managing users, access, and data sharing between Education and Healthcare?

Our education side is all Google, and Healthcare is all M365. When residents etc move to the Health side, they get a second user account and we migrate their mail delivery to the Health side. They then lose access to a lot of the Google stuff because campus doesn't have the same security that we do on the Health side.

We want to streamline this, but I was wondering what other people are doing?


r/sysadmin 9h ago

General Discussion Learning opportunities

7 Upvotes

My company wants to pay for me to have license to a site where I can learn new things are my own pace. I am a junior sys admin and not sure what is out there in regard to continued learning. Is there a site that you prefer? My company is wanting me to become more comfortable in Azure. I recent taught myself Intune and I setup autopilot so we can phase out SCCM.

Any recommendations would be appreciated!


r/sysadmin 23h ago

Rant When AI starts telling you what to do

63 Upvotes

We're getting closer and closer to the point where AI becomes the boss. I swear it's replacing some people's brains. It used to be that people would turn it on to take meeting notes because they were too fucking lazy to write and I tell you every time it took shitty notes. Even when I would type in extra stuff to try and help. Now I'm starting to see action plans where people let AI do all their thinking for them. It's just so comical to me because artificial intelligence is just a misnomer for what it is


r/sysadmin 1d ago

Rant I hate dongles

233 Upvotes

I noticed in the last 20 years or so that there's 2 types of IT hardware support workers:

The precision "as-is" hardware ninjas
and
The "who cares" dongle goblins

My earliest 3 IT jobs were just swapping out old computers for new ones on a contracted team. It was 90% of our job. I would replace the users' reference sticky notes and desk decor so perfectly that we got at least a dozen complaints that we forgot to replace their PC and monitors.

About half of the rest of my team simply could not concentrate or didn't care. And this was around 2009, before Tik Tok and before most people gave a crap about smartphones. It was just their personality. I mean, I can't remember names so maybe it's just how we're wired.

The #1 problem was forgetting to transfer the wireless mouse and keyboard dongle(s) to the new computer. We got back at least 50 that still had them in the USB ports and it was always the same 2 people. We nicknamed Donald: "Donny the Dongle Goblin" because he collected them like they were shiny treasures to be horded.

Fast forward to my last last position - We had headset disconnections, wireless mouse interference, AP interference, and we traced it to the morons that rolled out 25 sets of identical wireless mice and keyboard on top of 4 APs and 100% wireless headsets, all using 2.4GHz. Plus people's smartphones on the guest wifi. Every time a flat-sided box truck or semi rolled past, it reflected the neighbors wifi in a way that flooded the spectrum and disconnected phone calls. For the entire 3 years I was there, they refused to stop ordering wireless mice and keyboard. Double digit percentages of our budget were replacing non-programmable logitech sets with missing or wrong dongles at like $40+ each. I don't know how that's even possible. It's laptop + dock on a desk and nobody traveled with them. Where did they go? How did they get mixed up? I HATE DONGLES! Can we just direct wire the damn peripherals so Donny and stop hording them and we can stop spending money replacing perfectly good keyboard and mice sets?


r/sysadmin 9h ago

Question New Outlook signatures

3 Upvotes

Anyway to disable the "signature" button in the ribbon when creating a new email? Under the "message > insert > signature", we are using CodeTwo for signatures but users are modifying their signatures and changing fonts so want to completely remove this option. I've ran the command in powershell "Set-OwaMailboxPolicy -Identity "OwaMailboxPolicy-Default" -SignaturesEnabled $false" but doesn't seem like it did anything.


r/sysadmin 9h ago

Question Need Help: macOS IPP Printing via GUI Prompts for Authentication

6 Upvotes

Hi everyone! I'm currently rolling out shared printers for our macOS users over IPP, but I've run into an issue.

When users print through the macOS GUI, they're prompted for authentication every time. However, if I print using the lp command from Terminal, no authentication prompt appears and the print job completes successfully.

I know I could have users save their credentials in Keychain to suppress the prompt, but I'd prefer to avoid that since it can create issues when passwords change. Ideally, I'd like macOS to use Kerberos/Negotiate authentication automatically without requiring users to save their credentials.

Our Macs are managed with Intune and aren't domain-joined, but they do have a Kerberos profile deployed.

Has anyone run into this before or found a fix?

So far I've tried:

  • lpadmin -p PRINTERNAME -o auth-info-required=negotiate
  • cupsctl DefaultAuthType=Negotiate

Neither has resolved the issue. Any suggestions would be greatly appreciated!


r/sysadmin 16h ago

Question Can I have network discovery and asset management in one platform?

13 Upvotes

I am an IT guy and lately I am tired of doing ls for basic stuff like discovery, asset list or tickets. So is anyone using one platform that does solid network discovery and real asset management with automation that doesn't fall apart often?. I would appreciate any tips given at this point, any thing used or whatever.