Web appOpen in Telegram
RReddit Sysadmin

Reddit Sysadmin

@r_systemadmin · channel · Tech · indexed since 2026-05-22
78subscribers
2average post reach
420posts in 30 days
40 843posts in the index
Reddit Sysadmin
Link
click to show
All USB keyboards suddenly start sending random/repeated inputs, but PS/2 works fine I work IT support and I've had this weird issue happen on multiple PCs over time. A USB keyboard will work perfectly fine for months/years, then suddenly it starts acting completely broken. The symptoms are not just random Windows shortcuts. The keyboard also: repeats keys multiple times types different keys than the ones I pressed mixes random characters into normal words sometimes triggers Windows shortcuts / Start menu / network panel For example, if I try to type: Joca I might get: jocaca Joccccccc Jorre84i I've tested 3 different known-good USB keyboards on the affected PC and all of them behave the same way. A PS/2 keyboard works perfectly normally. Sometimes, while the USB keyboard is connected and freaking out, the USB mouse also becomes unresponsive. As soon as I unplug the keyboard, the mouse starts working normally again. This has happened on around 4 different PCs over time, including Windows 8.1 and Windows 10 machines. I've already tried: multiple known-good USB keyboards different USB ports reinstalling HID keyboard devices reinstalling USB/composite devices reinstalling USB controllers/root hubs checking keyboard/HID UpperFilters and LowerFilters checking Scancode Map reinstalling chipset drivers reinstalling Intel Management Engine Nothing fixed it. The weirdest part is that the keyboard was working completely normally less than an hour before the issue started. No hardware change, no new keyboard, nothing. Has anyone seen this exact behavior before? What could cause every USB keyboard to suddenly generate duplicated, incorrect and random HID input while PS/2 continues to work normally, and sometimes make the USB mouse freeze too? I'm looking for the actual root cause / fix, not “try another keyboard or USB port”, since I've already ruled those out. https://redd.it/1wzah7m @r_systemadmin
1 ·
Link
click to show
is it just me or anyone else feel like all this AI security stuff is moving way faster than the actual security controls? Every week there is some new AI security platform with agent discovery dashboards risk scores attack paths and all that meanwhile Im still figuring out what actually happens when an agent is already running in production and suddenly tries to access something it should not i mean it didnt have permission to access it or makes some tool call it should not. Feels like everyone is focused finding out what happened after the fact but not enough on actually stopping thing when it happens. Where are we heading with all this?? https://redd.it/1wzod1e @r_systemadmin
1 ·
Link
click to show
Finally scored a job after 1,5 years without one I have 15 years of experience. Was let go from my last one because reasons (mainly the global economic desaster I guess) 1,5 years ago. The time without a job was hard mentally and financially. In the end I got a job with a not to bad pay cut and start this month. Due the tax systems in Germany I earn maybe 500 € less, but still have a decent salary. Before taxes it was a 10k pay cut. My advise if you have trouble finding a job: mass apply. I was registered at so many portals I sometimes lost track where a reply came from (Indeed, Instaffo etc.). Make your CV easy to read. Let someone look at the layout. Get a professional portrait photo if needed. We all hate AI, yes. But if the company wanted a tailored reply I used Open AI to generate it and proof read it. Otherwise it would have been way to time consuming. Long story short: even in this fucked up market there is a chance. A slim one but a chance. My guesstimate is that I applied for 700 positions in the last 10 months. Keep your heads up and keep trying! https://redd.it/1wzp7pt @r_systemadmin
1 ·
Link
click to show
3 Year Redundancy Plan - what to learn? I've recently learned that due to company shakeups I might be being made redundant in 1.5-3 years. I have about 12 years' experience in IT, but this is my first sysadmin role (2 1/2 years ish). Our org. has a good development budget etc so there's scope to teach myself a lot for free. During that time, what skills should I focus on learning, in order to position myself for a new role? I am considering aiming for the M365 Administrator certification set - but not really sure what else is out there/what is most beneficial for a sysadmin/IT projecty role? My role covers: Daily admin of our M365 + Windows environment, including coding everything I can via PowerShell Monitoring sign-ins and reported phishing, managing licences, deploying software/updates, etc. Overseeing all joiner, leaver, and ongoing staff access to M365, and to \~25 third-party platforms Managing commercial relationships/contractual agreements with vendors Phishing simulations, annual/user training/inductions Leading or supporting on IT team initiatives - and other company initiatives like AI adoption, tool governance (We have a separate 1st line and security team) https://redd.it/1wzrf6d @r_systemadmin
1 ·
Link
click to show
How to merge asset inventory data after an acquisition? My company closed on a smaller one recently (\~ 6 weeks ago). Around 400 devices across two of their sites come over to us and I'm the (un)lucky one tasked with the reconciliation. We use ALVAO for asset management, every machine on our side has an owner, a cost centre, a purchase date, and a warranty date I trust. The company we acquired has a spreadsheet that one person maintained, plus a Lansweeper rollout that stopped at roughly half their estate. Naming is inconsistent between their two sites too (one site names machines after the user (JSMITH-LAPTOP), the other uses asset tags with no site prefix (AT-xxxx)), a lot of warranty dates are blank or obviously wrong, ownership is recorded at department level across most of the fleet, and \~30ish machines look like duplicates. My first thought is to import everything and clean in place. I get a full picture immediately and can work the gaps against live data. Risk is that I contaminate a register that took a long time to get right, and if the cleanup drags I lose the ability to tell verified records from imported ones. Alternatively, I could do a physical audit first and import only what's confirmed, though I'm blind on 400 devices for however long that takes, and we have an ISO 27001 surveillance audit early December that needs a complete register. Another issue, their IT lead is staying on and the sheet, to him, makes perfect sense, I brought up changing it and got a few huffs and puffs that I didn’t quite appreciate but let go of. I need him to understand it’s a merger thing, I’m not critiquing his processes in any way. Any help with the methodology (or dealing with the guy) would be immensely appreciated. Note: sorry if you saw this yesterday on r/ITManagers, they removed it before I could get a clear answer idk why. I hope I can manage to get one here. https://redd.it/1wzr8ze @r_systemadmin
1 ·
Link
click to show
Users and AI ... I just had a user asking me to allow claude to have complete access to his Microsoft mailbox. I told him no since sensitive mails are often sent to the entire company including discussions concerning projects etc. He went silent and then said ... "but how do you use your mail then ?" I had to explain to him that we old people used mail for decades without the use of an AI telling us what someone mailed. He was genuinely baffled how you can just open Outlook and read a mail without asking Claude what someone had sent. I fear this new generation of users who can't even do basic stuff any more because AI does it now for them. A few months ago another user wanted to give chatGPT complete access to a NAS with research data on it. It had to be able to modify/add/remove data directly. They wouldn't even try on a test batch of data beforehand. Ofc. the answer was NO, but i fear IT has less and less resources and people to shield data from "overeager youngsters" who try to insert AI tools in just about everything and actively seek ways to install or use them without admin rights. Are people going insane ? https://redd.it/1wzttxb @r_systemadmin
1 ·
Link
click to show
Firefox ESR 140 → 153 upgrade: share your enterprise findings Hi all, We're testing the Firefox ESR 140 → 153 upgrade in our environment (140 goes EOL October 13th). For those of you in enterprise IT who have already tested or rolled this out: what changes did you run into? What broke? What policies or settings needed adjusting? Just drop your findings below so we can all learn from each other. Thanks. https://redd.it/1wzv7a6 @r_systemadmin
2 ·
Link
click to show
How can I earn more, I earn £30k for 3k endpoints, 5k users and owning Intune policy, service reliability and some azure integrations + reports, scripts, apps, app packing, pmpc UK obviously. How can I earn more, I earn £30k for 3k endpoints, 5k users and owning Intune policy, service reliability and some azure integrations + reports, scripts, apps, app packing, pmpc. I work for an educational establishment. I’ve started applying for jobs again but I’m not getting a lot of bite for mid level https://redd.it/1wzvhxw @r_systemadmin
1 ·
Link
click to show
gpupdate /force applies user policies, but not computer ones. Hello, I have a really weird problem that i've been fighting with for a few days now. In our company we have 2 DCs, all was well and all the policies i set on the main DC synchronised to correct computers/users. However, starting this week, whenever i try to gpupdate /force on my PC, i get an error: "Computer Policy could not be updated successfully. The following errors were encountered: The processing of Group Policy failed. Windows could not determine the computer account to enforce Group Policy Settings. This may be transient. Group Policy Settings, including computer configuration, will not be enforced for this computer." And right below that "User Policy update has completed successfully". Which means, only the computer GPOs don't apply. What i tried: * Reconnecting the pc to the domain * Checked DNS - everything is good * Checked Event Viewer - only interesting thing there was an Error in Windows Logs -> System with the same message i got in the cmd. No error logs in Windows -> GroupPolicy -> Operational * klist matches the DC and the allowed encryption on the PC object in the domain * Test-ComputerSecureChannel returns true, nltest is also successful * Connection to DC on all the important ports is fine * Uninstalling all the recent KB Patches Im kinda running out of ideas, and the bigger problem is that other computers in the company started getting similiar symptoms. Any ideas or even a direction? Am i missing something obvious? https://redd.it/1wzv7nz @r_systemadmin
1 ·
Link
click to show
What’s the oldest unsupported system you’re still being forced to keep alive in 2026? Every environment seems to have that one system nobody is allowed to touch. Ancient Windows server, old hardware, some business-critical app where the vendor disappeared 10 years ago, or a machine everyone is terrified to reboot. What’s the worst one you’re still supporting, and what’s the reason nobody will finally let it die? https://redd.it/1wzz4nz @r_systemadmin
1 ·
Link
click to show
How do you handle users signing up for random software/SaaS? Yes, I know this is technically more of an HR/Policies issue, but I'm hoping to learn about what some options might be. I am the IT department for a 20-person agency. We change software and test out new things pretty often, which is great because then we aren't stuck using legacy software because of inertia. The issue I'm becoming more concerned about is users signing up for a service (let's say Airtable for an example) and not letting me know. Sometimes they may be using internal data or connecting to other systems - then they either keep using it or drop it but don't bother deleting the account or cleaning the data out. That account is now a threat that I don't know about and am not monitoring for breaches or removing client data from when they leave. Is there a way to keep tabs on this? Or am I just at the mercy of people following our rules (or not)? I do have Google Workspace set to require approval from me before allowing other systems to connect with it (including SSO) but that doesn't have an effect on users creating accounts with other methods. https://redd.it/1wzzk8j @r_systemadmin
1 ·
Link
click to show
Leadership is dependent on AI, is this normal now? I need a reality check, and I’m not sure where to ask this. My IT department got a new leader early this year and since day 1 they have been very transparent about their AI usage. Except it looks like they are highly dependent on it because they are using it for almost everything they do i.e. setting KPIs, writing developer guidelines, troubleshooting, etc. It does not feel like they have had a thought that was not influenced by AI. There have been instances where they would fact-check the team with AI to see if we were “correct” about our statements (luckily or unluckily(?), we always are). It feels like we are now being governed by AI through a human proxy and that the words of the AI weigh more heavily than ours. Should I be concerned? I have been considering to look outwards because of this, but given how prevalent AI is nowadays especially in tech, it could just be that this is the norm at upper management and it would make no difference if I moved. So is this normal now? Are your leaders also just giving you AI generated KPIs/plans? https://redd.it/1x0307n @r_systemadmin
1 ·
Link
click to show
A senior dev overwrote .env and took down website Today a senior dev, who's the maintainer of our company internal sales website, overwrote the environment in GitHub Actions and pushed an update. CI/CD ran and took the whole sales site down. The baffling part is nobody contacted me about it till end of day. So now I'm sitting in a bar waiting for friends scrolling YouTube where i got recomedation "web dude vs sales guy" and i was laughing seeing it, and right then I get an urgent message that the website is down. I SSH into the server from my phone and find one variable set to "localhost". One variable, whole day of downtime. First thing tomorrow I'm revoking their access to edit the environment. PS: I did get an Uptime Kuma alert in the morning. But lately the devs push to prod without telling me, so I assumed it was another one of those. Should have checked anyway. https://redd.it/1x0494w @r_systemadmin
1 ·
Link
click to show
Passed over for a promotion... I've been working for a company for 5 years at the help desk. Applied for a promotion to sys admin, which I met or exceeded the requirements for, and they hired externally. I feel like shredding my bachelor's degree. What good is it doing? Current position requires hs or a.a.s. Was promised flat out falsehoods in my interview and after. Like "you'll be 45% wfh after training" and "we promote from within..." Even the cio said I was a shoe-in... It's great to have a favorite, sucks to know it's not you. https://redd.it/1x03yja @r_systemadmin
1 ·
Link
click to show
A new problem with New Outlook This has got to be the worst one so far, as it is costing them actual customers and missing vendor deadlines. Somehow a user snuck past us and is using New Outlook. A report came in that the first time he emails someone new, it fails. The 2nd time or any reply, it works. Turns out yep, that's a thing. And it "silently" fails so no outbox entry, sent item, or message trace. I think they show up in all 3 places as successes, but it never actually sends. Or it shows local but not in Trace. I don't remember. Here's AI's version of what happens because I'm too busy to write up my own summary today. * **Auto-Complete Entry Generation:** When a user types a brand-new address into the `To:` field, standard email clients create a temporary "Suggested Contact" or cache entry. In New Outlook, if a recipient isn't in Exchange/Outlook Contacts or the Auto-Complete cache, the initial submission occasionally drops off the queue during the background synchronization token handoff between the client and Exchange Online. * **"Silent Failure":** Because New Outlook operates as a web app wrapper (OWA interface), it doesn't utilize a traditional offline Outbox like Classic Outlook (`.pst`/`.ost` based). Emails render instantly as sent in the UI, but if the back-end handoff fails validation on an unverified/uncached address, Exchange drops the message without generating a Non-Delivery Report (NDR) back to the client. * **Why the 2nd email works:** The moment the first email is initiated, Microsoft 365 automatically writes that recipient's email address to the user's **Suggested Contacts / Auto-Complete cache**. By the time the user sends the 2nd email or a reply, the system recognizes the address as an existing object in their profile, allowing normal transit. There is no fix btw except "reinstall Outlook, clear app data cache, cross your fingers, etc." My fix: 1. uninstall it 2. set up Outlook Classic 3. complain about it on Reddit. http
1 ·
R
Link
click to show
Windows Update KB5120998 Causing Group Policy Refresh Failure and Enabling Administrator Protection on Windows 11 Hi All, The following update for Windows 11 released August 27, 2026: https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5120998-windows-11-24h2-25h2-update Also included in the following update for Windows 11 released September 8, 2026 (thanks u/Dissy614): https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5124008-windows-11-24h2-25h2-security-update Is causing Administrator Protection to be gradually enabled: https://techcommunity.microsoft.com/blog/windows-itpro-blog/administrator-protection-on-windows-11/4303482 If you don't know what Administrator Protection is, it essentaly enhances the separation between your elevated vs not elevated context, including giving your elevated context its own profile. Under a non-elevated context, whoami will return DOMAIN\\user, and your profile with be C:\\Users\\<username>. Under an elevated context, whoami will return DOMAIN\\ admin_ <username>, and your profile with be C:\\Users\\ ADMIN_ <username>. Conditions: If you have downloaded/configured the Windows 11 Security Baselines GPO, or you have otherwise set the following policy: MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\TypeOfAdminApprovalMode=2 Then this will cause three issues: 1. Computer Group Policy refresh fails. 2. User Account Control (UAC) prompts require user name and password. 3. Group Policy Management Console resulting settings shows the setting on an existing policy, but in the "other" section rather than the "User Account Control" section, if you are viewing from Group Policy Management Console on Windows Server rather than from Group Policy Management Console on Windows 11. As noted in the first link, enabling Administrator Protection is listed as a gradual rollout, meaning this is not affecting every Windows 11 computer with TypeOfAdminApprovalMode configured.
1 ·
Reddit Sysadmin
Link
click to show
Next Tuesday is the final cutoff for Server 2012 ESUs. How are you guys isolating the boxes you can't kill? Year 3 ESUs for Server 2012 and 2012 R2 officially end on Tuesday. We all know the official answer is "just migrate it to Azure," but let's be realistic—most of us are stuck with at least one ancient access control server, a legacy piece of machinery, or a dead-vendor database that management absolutely refuses to let us turn off. For your legacy boxes you physically cannot upgrade next week, what does your isolation strategy actually look like? Are you just stripping the default gateway so it can't route out to the internet, or are you going full air-gapped VLAN with strict allow-listing for specific endpoints? (Also, as a quick heads up for the desktop teams: Office 2021 LTSC loses security patches on the exact same day. Definitely expecting a spike in macro/document phishing targeting those unpatched clients soon.) Curious to hear how many 2012 servers everyone is still hiding in their racks and how you're handling the triage this week! https://redd.it/1x093wb @r_systemadmin
1 ·
Link
click to show
Stale Inventory - do you keep pending locks on PC are never returned? So, when a user terms, we send lock commands to all laptops. Sometimes they'll return them after receiving the self-addressed box, but often they just never be seen again. At this point, I have hundreds of "dead" devices in inventory that are eating licenses, with no way to ever confirm that they received a lock command. My peer believes that we should keep this charade and device count indefinitely for security reasons just in case they do ever come back online. Security was ok after a short period. Legal doesn't care. I'm of the time period suggestion, such as a year. Keep in mind that if devices do come online again, they reconnect to the MDM and then can be sent a lock again. What do you guys do? EDIT: Thanks for all the responses. My main question was around tolerance for "how long to keep a wipe or lock task pending?" more than any recovery responsibility. I'm more of I want to keep these things off the books and stop paying $$$ with very low benefit. For some reason, my peer also thinks that if a laptop is found "improperly disposed of", that some authority is going to come back and fine us. Honestly, I see that as a very remote responsibility. https://redd.it/1x04na9 @r_systemadmin
1 ·
Link
click to show
Best Varonis alternatives that actually support on-prem? We're reviewing our data security stack and looking at Varonis alternatives, but on-prem support is a must for us. A lot of the newer options I've looked at seem to be built mostly around SaaS environments. We have sensitive internal data that needs to stay inside our environment, so anything that requires sending the actual data out to a vendor isn't really an option. For anyone running on-prem, what alternatives have you actually used? Anything you'd recommend looking into? https://redd.it/1x0dppx @r_systemadmin
1 ·
Link
click to show
Captchas from Dante's Inferno Anyone know how to remedy this situation? I started seeing captchas at google.com searches. Noticed it wasn't just my logins, and had a handful of users bring it to my attention. Went through the logs and exhausted all possible leads on bad clients causing this for our public IP(s)....then I noticed that the captchas followed me across my workstations and across public IP addresses (went from WAN1, to WAN2, to work hotspot, to personal hotspot.....the captchas followed my browser! I also had captchas pop up on my first login on a given public IP, so it's not a numbers problem--it's my browser that Google doesn't look. Further, it's something in Intune's Edge profile that Google doesn't like, because other users do experience the same thing. Nothing significant has changed in the Intune profile that goes out to all Windows clients, however it is based off of a STIF from \~a year ago when implemented. So what do you think it is that suddenyl Google despises about our Edge profile? (Same behavior across Chrome and Firefox, too, by the way.) https://redd.it/1x0emce @r_systemadmin
1 ·
Link
click to show
Unresponsive vm after rdp Dealing with a strange issue. Hyper v VMs server 2019 randomly will stop accepting rdp connections and also when trying to login via console will take the login and hangs at welcome screen. So far only a reboot fixes the issue (turn off only not normal shutdown) No changes or updates recently. When it hangs I can still connect via remote powershell and run commands fine but commands like query session just hangs. From what I was able to gather there are no resources exhaustion and all roles or services still run fine just seems like the ability to login isn’t working. Event log does show connection accepted, rdp will try to connect for a while after entering credentials then fails eventually. Event log does show ip helper and NLA (network awareness ) services rebooting multiple times, maybe network stack crashing ? Ideas what to check ? I’m unable to reproduce the user but it seems to happen with only a few VMs users rdp into and normally these users rdp from a 2025 server. https://redd.it/1x0h37c @r_systemadmin
1 ·
Link
click to show
MD-102 Endpoint administrator exam Anyone here pass the official exam when they were only getting around 65% on the measure up Exam questions or do you really need to get it up to 80% on measure up first? https://redd.it/1x0jcar @r_systemadmin
1 ·
R
Link
click to show
How much are junior sysadmins actually expected to know? I’m curious what the expectations are for someone with only 1–2 years of IT experience. Do employers actually expect a sysadmin to know the ins and outs of every major platform and tools like Microsoft, AWS, Google, different IAM systems, networking, endpoint management, security, etc.? I feel like I’m constantly trying to learn more and more because I worry that if I don’t know a particular technology, I won’t be qualified for a job. But realistically, there are so many tools and platforms that it seems impossible to know everything, especially early in your career. At what point should someone stop trying to learn everything and instead pick a few areas to become really good at? Would love to hear some advice as I am really lost and already feel tired and burnt out of IT and it’s barely been 2 years working ( currently in IT support ) and it’s partially my fault as I am constantly trying to learn something new every single day to the point where my brain feels fried and doesn’t retain things anymore. https://redd.it/1x0k2ms @r_systemadmin
1 ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count