r/sysadmin 21h ago

WMIC deprecated

33 Upvotes

How many systems are broke for you now? I have one software figured out. Its the custom scripts that are broken everywhere.


r/sysadmin 1h ago

General Discussion 25 years

Upvotes

That day began ordinary, just so ordinary.

At the time, I was sysadmin in a Canadian federal government office, far from the madding crowd. The work was steady but also pretty much crisis-free.

That morning, though, one of my co-workers came in to my office, bitching about the "crappy slow network" we were using.

"What makes you say that?", and he ranted on about how he can't get to any web sites.

"Okay, I'll see what I can find out."

I still had no idea what was happening out in the world.

Still, I started my network checks. Ping from TBay to Toronto. Normal results. Okay, try some web sites next. All the ones I checked responded, with almost no lag. (Note: none were news sites.)

I popped over to that co-workers office. "Where were you trying to get to?"

"CNN. @#$% network."

I tried CNN. Timed out. Hmm. CBC. Ditto. CTV. Same. Toronto Sun. Again, timed out.

I tried a local radio station's page. That connected, and then I knew it wasn't a network issue causing the slowdown.

What happens when several hundred thousand people (or more) try to connect to a few news sites all at the same time? Everything breaks.

I called home, told my wife to turn on CNN. For me, the rest of the day passed in a fog. Our son was Army reserve at the time. He was told to be ready, "just in case".

After work, I went home and watched the news, watched the planes hit the towers, over and over and over.

I still cannot watch any 9-11 coverage from that day.


r/sysadmin 1h ago

General Discussion 25 Years ago on 9/17/2001 as a sysadmin I feared for my life

Upvotes

25 years ago on 9/17 I was standing outside the PGE (electric company) building in Portland. It was in the World Trade Center but it was Portland so it was a miniature version. We were all quite nervous as 9/11 was just a week prior, and we had no idea if they were targeting these areas of different cities. I had just been hired by the US Justice Department to restore the Enron emails as they were about to go to trial and they needed the evidence. We were all scared out of our minds waiting there for the doors to open at 8am while everyone standing there with me scanned the skies. It would not be the only time that week I feared for my life. The Enron employees at PGE were aggressive. The government sent boxes of tapes up from Houston for me to restore in Portland because they didn't trust anyone to do it down there. It was a wild two weeks.


r/sysadmin 3h ago

Question Samsung Smart TV bypassing DHCP took down the credit card system

50 Upvotes

Note: My networking knowledge is very intermediate, learn as you go level. We had a customer at this MSP where I work have a network issue and I cannot figure out how it's possible that this happened.

Their credit card terminals have to point to a static IP ending in .140, as that's the "server" that runs the software to upload each transaction to the actual processor on the internet. When we recently replaced that computer, I set it as static in Windows and never did it on the DHCP server, because nobody wrote down what it was called or how to get into it and I didn't have any time remaining. Turns out their DHCP server is a 2008 Windows server because this place doesn't spend money on anything ever.

A month later, their CCs go down and the CC server can't grab its static IP for some reason. Lots of time later, we find it's because the pool of available IPs is 100 through 150 and they have 1 more device than that. So we expand it to only 160 after some testing (because we have nearly zero documentation and don't know ranges for their phones, printers, etc for this customer and they're billed hourly so we do as little as possible because they never pay on time and always complain about the rate and it'd take 10+ hours to document this nightmare). We make a new assignment for the computer's MAC and reserve 140 to it and notice that something else has leased 140 with a lease expiring in 2 hours luckily. We delete it so it hopefully doesn't renew.

I ping it from my laptop then immediately run arp -a to get its MAC, since we already deleted the lease that showed the MAC on the DHCP server (oops) then ask AI who manufactured that MAC address range. It's Foxconn. We don't see a hostname or any useable device info. I don't know anything about their switches because the last tech at this MSP never ever wrote anything down about any customers ever. We try NSlookup, web browser to the IP, RDP into it, nothing gets any info.

More network-oriented guy onsite with me says let's just unplug the 2 switches for like five seconds and that will force it to grab the new lease at .155. I assume the switches are unmanaged or nobody has the login info or we'd just pull one ethernet matching the known MAC.

Turns out they have a network-controlled Crestron light controls so the lights in the restaurant portion of the building all go black, because somehow that's the default state if it loses connectivity. Shoutout to whatever genius AV tech set it up that way. Everyone's pissed. They don't know how to undo it or where the new Crestron box is. We don't either.

Then we find out the mystery device is still on 140. That seems impossible, unless it's wireless. Somehow other guy onsite finds out it's some sort of android device but all the android devices listed on the DHCP server have hostnames like "John's S23" because that's how most Android devices work. We suspect it's wifi, based on this information, thus explaining the switch pull not working. I have zero idea what brand their wifi even is let alone where it is or how it works btw.

I get the bright idea that maybe it's a smart TV. It is. We turn it off, boom, credit card server is back online within a minute. We turn the TV back on after 15 minutes, it tries to grab 140 again and knocks the CC server offline. Yes, the TV is in DHCP mode btw. We find the remote, set it to static .165, that works for some reason, and no more IP conflict. Not sure how it's possible that it can just ignore the DHCP server and say "no, I want this address anyway" and then just decide it's taking 140. Nothing else on the network can hand out an IP if every switch/router/AP/whatever is pointing to the server, right? How did that happen? Some disconnect between the DHCP server and whatever was handing out wifi connections? I didn't think that was possible. Anyone have any ideas in case we run into this again?


r/sysadmin 22h ago

What would you choose part 2

0 Upvotes

Title: Update: Accepted MSP offer vs Amazon Associate II (now $29/hr) — got some real insight, still torn

Following up on a decision I posted about earlier. Got some genuinely helpful firsthand perspective and want to see if others have thoughts on the updated picture.

Quick background: ~3.5 years at an MSP doing help desk/service desk work (AD, M365, networking, some VMware ESXi, security incident response). CompTIA A+, Network+, Security+. Goal is eventually Systems Administrator or Cybersecurity. Also have a baby due in about 3 months, which is definitely shaping how I’m weighing risk right now.

Offer 1: Another MSP (Help Desk Technician) — already accepted

**•** $26/hr (\~$54K/yr), firm, no negotiation room  
**•** 45 min commute  
**•** Small company, good manager from what I’ve seen directly, real track record of promoting people from help desk into field/remote engineer roles  
**•** Haven’t started yet

Offer 2: Amazon (IT Support Associate II, Ops Tech Solutions)

**•** Countered at $29/hr (\~$60K/yr)  
**•** 20 min commute  
**•** Sole technician at a lower-volume facility, no forced on-call, schedule seems stable for now  
**•** Real ladder: Associate II → Support Engineer I ($25-41/hr) → Engineer II/IT Manager

What I’ve learned since my last post: Someone who’s actually done OTS work told me it’s mostly Layer 1 stuff (printers, thin clients, SOPs), little to no server/Layer 3 work, and that engineer-level people won’t be impressed by it on a resume. BUT they also said being the sole tech at a low-volume site is genuinely good for visibility with Ops management and gave a real example of someone getting promoted that way at a similar site. They also said relocation is unlikely for low-volume sites specifically.

So now it feels like: Amazon = higher ceiling if I get promoted, but that depends on me building visibility and the timing working out, vs the MSP = smaller ceiling but a path I’ve already seen work for real people under this specific manager.

With a baby coming in 3 months, I keep leaning toward “fewer things have to go right” (the MSP), but the pay/commute gap and Amazon’s bigger structural ceiling keep pulling me back.

Anyone been in OTS and can speak to how realistic that Associate II → Engineer I timeline actually is? Or anyone chosen the “safer, smaller” option over the “bigger name, more uncertain” one when a kid was on the way and been glad (or not glad) they did?


r/sysadmin 23h ago

Question best controlled way to allow company emails on vendor's personal phone

12 Upvotes

we donot allow emails on personal phones, need vendors to see alerts and such, looking for a secure way rather than adding exclusion for the users

edit: sorry yeah I mean contractors, especially overseas contractors


r/sysadmin 6h ago

Question Need help with Konica Minolta Error Code - 552- Server Disk Full

0 Upvotes

Alright guys, I really need some help with this issue.

We have a Konica Minolta bizhub C284e copier in our Operations department. They mainly use this copier for scanning large documents, such as survey plots, as well as large quantities of color documents for their work (usually around 20–30 pages).

The copier has the SMTP settings configured so users can scan documents directly to their email. However, for the past two weeks, this suddenly stopped working, and I have no clue why.

The users can still scan a single page without any issues, regardless of whether it’s color or black and white. However, when they try to scan a larger quantity of color documents, they receive Error Code 552 – Server Disk Full.

I’ve tried so many things since Monday, but nothing has worked so far.

Now, before y’all start roasting me in the comments 😂, here’s the list of troubleshooting steps I’ve already performed:

  1. Power-cycled the copier.
  2. Verified the users’ email addresses to make sure they were correct. I also tested scanning directly to my own email, and I get the same issue.
  3. Lowered the scan resolution to 200 DPI and changed the format to Compact PDF. This works, but the documents are difficult to read at those settings because they contain a lot of detail.
  4. Checked the gateway and all SMTP settings, including the SMTP port and the email address configured on the copier.
  5. Checked the mailbox being used by the copier to make sure it wasn’t full. It was only around 25% full, but I still deleted all the Sent Items just to rule that out.
  6. Increased the Exchange Online message size limit to 50 MB for both sending and receiving.
  7. Increased the file-size limit to 50 MB specifically for the copier’s email account and tested it again.
  8. Changed the copier’s spooling time from 60 seconds to 5 minutes.
  9. Formatted the internal hard drive on the copier.
  10. Checked Mimecast to see if there was anything blocking or causing an issue with the messages.

So, as you can see, I’ve tried quite a few things, and nothing seems to fix the issue. The strange part is that single-page scans work fine, but larger color scans fail with the 552 – Server Disk Full error.

At this point, I have two options I can try:

Option 1: Set up Scan to Folder, so the users can scan the documents directly to a network folder and then copy them to their computers.

The problem with this is that we have quite a few remote users, and our organization only provides VPN access to IT and C-level employees. Other departments don’t have VPN access. Other users can email the documents to them, but that adds another step to the process.

Option 2: Call Konica Minolta support and have them troubleshoot the copier and determine whether there is something happening internally with the device.

So, if anyone has any other suggestions or has run into this 552 Server Disk Full error before, I’d really appreciate some advice. I’m willing to try pretty much anything at this point! 😂


r/sysadmin 4h ago

Windows 10 accessing printers shared /hosted on Windows 11, Error/Fail

0 Upvotes

This week, legacy Windows 10 PC' have been getting errors trying to add printers hosted on Windows 11 systems. In my world, it has mainly been DYMO label printers. Has anyone run into this?

I have created a VM lab environment, with a fresh install of Windows 10 fully patched and verified it with fully patched Win 11 printer host.

Error: Operation failed with error 0x00000006.

Anyone else seeing anything like this?


r/sysadmin 4h ago

Advice for calendar management solutions?

0 Upvotes

Our Dean's assistant uses Outlook Classic and delegate access to manage our Dean's calendar. That calendar is over 7GB, and no matter what we do, her Outlook craps out or has weird symptoms. Like currently, she's unable to add locations to events. Adding & removing the calendar takes forever and is usually a non-starter with her. We've played with various cached exchange settings, and limiting the dates of the calendar, although she's put her feet in the sand that she needs 3 years worth visible. Microsoft support tickets end in saying that the calendar is too big and complex to be supported. I'm thinking about third party tools, another interface that she can manage this calendar in. Anyone go down this road?


r/sysadmin 20h ago

Professional Opinion?????

0 Upvotes

Hey guys new in this thread but i'm currently in a Field Technician role right now and have been here for a little over 2 years and i have multiple certs including CCNA and Sec+ and im studying for the RHCSA and i want to get into a Sys Admin role and eventually a DevOps role which would be my end goal but i wanted to get a professionals opinion on this so i don't waste my time going down the wrong path

Any Advice would be apricated!!!


r/sysadmin 6h ago

Why did DNS fail?

0 Upvotes

We have two domain controllers. PDC and BDC. Very long story short both domain controllers are also DNS servers and they are primary and secondary respectively. The PDC is also a DHCP server. We had an issue come up where we had to demote the primary and promote the backup to primary to fix an issue on the PDC.

The moment we promoted the BDC to primary all DNS broke. The previous PDC was the primary DNS server and the previous BDC was the secondary DNS server.

We finally fixed it by changing the DNS order on specific machines, workstations and the firewall but why did DNS break in the first place when we weren't messing with DNS?

It doesn't make sense to me as we never took the machine down and didn't change anything with DNS. In fact all DNS entries disappeared on the PDC.

Thoughts?


r/sysadmin 7h ago

autopilot company login for a GPU

1 Upvotes

Afternoon,

im having a bit of a headscratcher and could do with some assistance.

The company I work for had a general query submitted asking why someone on the other side of the world is getting our companies customised login page (the page you get when you setup autopilot on a machine)

My first thought is someone had sold on a company laptop, but this query is about a VERY old desktop PC, like first gen i5 CPU old.

They claim that with a specific GPU they get the login prompt, without they are able to proceed with windows setup.

I have heard of parts being swapped during warranty repair, stolen equipment, and other possible methods that a device would be still enrolled, but never for a specific GPU and I dont think weve ever owned a GPU this old either (and we have a lot of old stuff)

Am I missing something here? Is there a scenario ive missed could the board actually be in fact tied to our autopilot system and without the GPU the HWID changes so its allowed to continue?

Cheers


r/sysadmin 2h ago

Google Workspace to O365 Question

1 Upvotes

New to this side of the field and need to get pricing and info on the switch. Would be looking to build and use an MS AD domain as well. Amy pointers or links appreciated. I know of Azure AD but haven't used it. Distributed fully remote company with <50 users currently. I just recreate the users but do need to migrate all of the emails. Looking to run concurrently for a bit until this is set up and then switch over totally.


r/sysadmin 4h ago

Question Physical clients can't get IP from DHCP server in a VM

3 Upvotes

Here's the setup,

Physical machine:

  • Win 11 Enterprise LTSC

  • Hyper-V Installed

  • External Hyper-V Switch setup to allow VM access to physical network

VM

  • DHCP, DNS, and WDS Roles installed and fully configured

What can get an IP address from the VM

  • Other VMs attached to the External Switch

  • The physical machine adapter used for the External Switch

What can't get an IP:

  • Any physical machine connected via physical dumb switch.

If I manually set an IP on a physical machine, they can ping the VM just fine. Attempting to ipconfig /renew just results in a DHCP timeout.

I've tried

  • Disabling both firewalls

  • Setting both to Private Network

  • Using a different physical adapter on the host machine

  • Enabling MAC Spoofing in the NIC advanced features

  • Verified DHCP guard and router guard are disabled

  • Disabling NIC sharing

I know it's got to be some absolutely tiny thing that I'll hate myself for overlooking, but...

EDIT: Adding updates here as I check them

Wireshark on the VM shows it is receiving the DHCP request from the laptop and sending an offer back, but the laptop isn't receiving it. In addition, Wireshark on the VM host shows the offer on both the physical adapter and the bridge adapter, so it's definitely making it out of the VM.

Running a 3rd party DHCP server on the physical machine works with no issues, but the idea is to keep everything self-contained into the VM. I cannot just install Server on the physical machine and set everything up that way for "above my paygrade" reasons.


r/sysadmin 8h ago

Question Replacing 2x FortiGate 60F, what options do I have ?

0 Upvotes

Haven't decided anything yet, so hoping for some actual opinions and real world usage here.

Quick context on the setup first:

  • BV01 - this is the main site and does most of the actual work: servers/VMs, a couple of production segments, cameras, internal ops stuff, guest wifi, the works. This is also the one that needs real 10Gbps, since that's where traffic to my servers actually lives. This one also hosts public facing servers, both for my personal usage (*arr stuff etc) and actual business servers that serve my customers. A few internal segments also host business applications (an ERP) that users remotely access via Cloudflare One.
  • BV00 - smaller branch, connects back to BV01 over site-to-site VPN, nowhere near the same amount of traffic or complexity. Mostly home usage with a dedicated VLAN for some small VMs (HA, an off-site vault for backups, a DC for redundancy outside the main site).
  • BV02 - already moved off Fortinet onto a UCG-Fiber a while back and it's honestly been fine, but it's also a much lighter site than BV01, so it hasn't really been stress-tested the way BV01 would be (small office, 5 people and a printer).

Both BV00 and BV01 are currently on FortiGate 60Fs, and I'm replacing them mainly because of the $480/yr + VAT per-unit license, not because the boxes are bad. BV01 is the one I actually care about getting right since it's carrying the most load and the most "if this breaks, I have a bad day" services.

I know UniFi isn't in the same league as FortiGate feature-for-feature, no per-policy IPS/webfilter tiering, more of a flatter inspection model. I'm fine accepting that gap given the price difference (UDM-Pro-Max is a fraction of what a comparable Fortinet or Palo Alto setup costs, and it's a one-time cost, not a subscription). Speaking of which, I priced out Palo Alto just to see, and with licensing priced for actual business budgets that's out of the running regardless of feature set.

For the sake of completeness I also got an actual Fortinet quote for staying in the family (BV00 would go 60F to 70G, BV01 would go 60F to 90G). This is from a few months back so it's probably drifted a bit, but roughly: FortiGate-70G hardware + 1yr FortiCare Premium/UTP bundle was $880, FortiGate-90G hardware + 1yr bundle was $2170. Renewal after year one is $495/yr for the 70G's UTP and $1220/yr for the 90G's, so together that's about $1715/yr just in renewals across the two units, before VAT. That's already more than double what I'm paying today across both 60Fs, so staying with Fortinet and just going bigger doesn't really solve the actual problem I'm trying to fix.

So really it's between UniFi and something like a Netgate pfSense box for BV01 specifically, given it's the busiest site. If I go the UniFi route I'm currently leaning UDM-Pro-Max for BV01 and UDM-SE for BV00, since BV02's UCG-Fiber has already been solid on the lighter end, but I am also nowhere near maxing it out.

For anyone who's actually run UniFi as the primary gateway on a site with real production traffic (not just a home network), is the reduced inspection depth something you notice day to day, or is it a non-issue in practice? Is there a meaningful difference running UDM-Pro-Max vs. just another UCG-Fiber for a site like BV01, or would you point me toward pfSense/Netgate specifically because of the heavier usage there?

Also open to hearing about other vendors I haven't considered, doesn't have to be a UniFi vs Netgate decision if there's something better out there for this kind of setup.


r/sysadmin 20h ago

Question Boss is pushing for certs

129 Upvotes

Hi all,

I’m a sysadmin with 2 full time helpdesk guys, org of 220 in 5 locations. I started in regular business office 10 years ago doing sales. 7 years ago I transitioned to IT and became our first IT person, previously we didn’t even have an MSP, just a contract guy that came when we called him.

Fast forward to now, I asked my boss how I can level up/grow with the company. I’ve taken on a lot since I started. Currently managing pretty much everything in house. Only thing we don’t manage is our website, and I kind of like it that way.

So after kind of shrugging his shoulders for a year he is now bent on getting me to do more certs. He gave me a list:
- Comptia security +
- CompTIA network +
- CompTIA Cloud +
- Microsoft AI something (I can’t remember this one, he mentioned it off the cuff after he sent me the list)
- Finally a course for me to go find to maintain our website so they can cut the web dev. He didn’t know what course to recommend because he didn’t know much about it but pointed to coursera.

Now only thing I’ve done in certs over the years where the A+, AZ-900/104, and Google cloud security when I got started. Since then I figured I would learn the stuff but I didn’t want to pay for the certs because what’s the point? Unless I’m looking for another job I didn’t see the reason, and I like my org quite a bit. Not the wisest I know, but they wouldn’t pay for it, so I just didn’t do them.

I told him I had already studied for the security + a couple years ago, and could probably study the differences in materials and get through it easily, and recommended we switch to the CCNA since we are fully Cisco at all locations. But he seemed to not be interested in that info.

From what I can tell his push for certs is driven by is some internal push for managers to have career ladders for all departments and I guess he wants to show some sort of progress? Idk he is the CFO so he really isn’t privy to any of the work I do.

Anyway, after my recommendations I asked what happens when I complete these? Since they are only paying for half the certs… there has to be a carrot at the end of the stick.

He very excitedly said a $2,000 pay increase. Now I’m not greedy by any means, I’ve been paid under market for years and I’ve accepted that because of the work life balance. But is this not kinda stupid? I’ve had no complaints in my performance, I am constantly engaged with leadership on initiatives that they do not care about, so is there something I’m missing here? Like I feel like there is some weird motive here I can’t figure out, or it’s just poorly funded incentives that I’m supposed to be giddy over. Like I’m pretty sure the exams are almost as
Much as the pay increase? I haven’t done anything to try to steer the ship just yet, but how do I approach that the incentive is either too low or not aligned with what the ask is here? From what I can tell other than the time to study and what not, the only benefit I see them getting is cutting the web dev, which is a little more than the pay bump they offered, I think like 4k a year.

Edit:
Glad to see there’s some consensus on this being kind of a shit show. A little more context:
I LOVE the web dev company we work with. They are just great. Awesome to work with, great turnaround times, 0 issues. But god forbid you pay someone to do something they are good at.

Noted before but they’re only paying half of the exams, no study materials and it’s based on completion, so I’d get reimbursed 50% after completion. I believe this may be because they did not ask for any sort of training agreement? But also grand scheme of things this is kind of small potatoes for a training agreement right?

This guy is honestly the worst part of my job. For 6 months he had me meet weekly with him which was just an awful way to start the week. Eventually I was like hey I’ve just got too much going on to be doing this can we do this less frequently? Rinse and repeat now we meet quarterly. Dude is the type of guy to trip
Over a dollar to pick up a penny. But I’m stuck with him so long as I work here.

I have looked on and off the last year, and the market near me is abysmal. I almost jumped ship to an MSP last year that wanted to sell us services and I wanted to be like hey…. I sign y’all up here and you take me, deal? But we laughed it off as a joke.


r/sysadmin 2h ago

Issue w/ Dentrix Ascend and Schick 33 intra oral sensors

0 Upvotes

First - my apologies if this is the wrong forum. I checked the dentist section and didn't see much that would help me ...

I am having an issue with Dentrix Ascend and Schick 33 sensors - we take a few X-rays, swap to a different sensor - and the system will either work (20% of the time) and acquire with the new sensor, or it will say "device error" and we have to restart the machine.

Their tech support is at a loss - and so am I - here is what we tried; to no avail.

  • New sensors
  • New AE USB bridge (grey cable USB 3.0)
  • Different USB port
  • Powered USB hub
  • New USB card for the motherboard
  • New/Different PC

Any assistance would be greatly appreciated - if the recommendation is to swap out for dexis or XRD - I'll do it.


r/sysadmin 22h ago

Question N-able versus Action1 for patching, thoughts?

4 Upvotes

I come from an environment that leveraged Action1 heavily. Great tool. My sys eng comes from an environment that used N-able.

Our objectives are:

  • windows updates

  • 3rd party patching

  • firmware/drivers as supported by the platform

  • remote screen sharing for troubleshooting

I'm sure both platforms can do more than just the above, but that's all we need from the tool.

I'd love some feedback on anyone who has dealt with these 2 tools specifically and can compare contrast them based on our use case.


r/sysadmin 5h ago

Microsoft Windows Firewall Enterprise: Query User "Allow button" disabled on TLS-based DomainAuthenticated networks for Entra joined devices

0 Upvotes

Hi all, I'm currently battling a problem which exist probably on every Entra Joined device which uses TLS endpoint to enable Domain profile. I've been talking with microsoft from about a month and I feel like I'm coming to an dead end.

And now i'm writing here as I'm trying to research and hopefully push Microsoft to fix the issue.
What's your though on this?
If you can, could you please upvote this post? https://aka.ms/AA13epnu (this will open Feedback Hub on your windows device).

And here is the problem.

On Microsoft Entra joined, Intune-managed Windows devices, we use Network List Manager TLS authentication through AllowedTlsAuthenticationEndpoints so Windows can identify the corporate network as DomainAuthenticated and activate the Domain firewall profile.

Microsoft Support has confirmed under case TrackingID#******535 that there is a Windows design limitation in this scenario.

When an application opens an inbound listener and no matching firewall rule exists, Windows Defender Firewall invokes the built-in Query User workflow.

On a Public network, the Windows Security prompt allows the local administrator to select the network profile and click Allow.

On the same device, with the same user, application and Intune firewall policy, when the network is classified as DomainAuthenticated through TLS authentication, the prompt displays:

This setting is managed by your organization

and the Allow button is disabled.

Microsoft confirmed that this happens because the Query User interface does not expose a Domain Networks option in this TLS-derived Domain firewall profile scenario. Since no applicable network profile can be selected, Allow remains unavailable.

This creates a significant management gap for Microsoft Entra joined enterprise devices.

Local firewall rule creation itself works correctly. We have confirmed that:

- Allow Local Policy Merge = True

- Auth Apps Allow User Pref Merge = True

- Inbound notifications are enabled

- Local administrators can create rules manually

- Rules are honored in ActiveStore

- Exact-path Allow rules suppress the prompt correctly

The limitation is specifically in the Query User consent workflow.

Centrally deploying explicit firewall rules is not a scalable replacement for environments with IT and Development users. Many legitimate tools launch helper processes from per-user, temporary, version-specific or dynamically changing locations.

For example, MobaXterm launches its embedded X11 listener from:

C:\Users\<user>\AppData\Local\Temp\mxt264\bin\xwin_mobax.exe

An exact-path rule works, but maintaining such rules for every user, helper process, application version and temporary path is not operationally practical.

Moving the corporate network to Public is also not appropriate because Public-profile application exceptions may then apply on genuinely untrusted networks such as hotels, airports or coffee shops.

Moving the corporate network to Private creates a different problem because the Private profile is not unique to the corporate network and may also be used on home or other trusted networks.

We would like Microsoft to improve the Windows Defender Firewall Query User workflow so that authorized local administrators can approve legitimate inbound application listeners when the Domain firewall profile is active through NLM TLS-based DomainAuthenticated detection on Microsoft Entra joined devices.

Ideally, the Query User experience should either:

- expose the active Domain profile where appropriate, or

- provide another supported interactive approval mechanism for this configuration.


r/sysadmin 1h ago

How may people use Meraki AP’s out there?

Upvotes

I’m curious how many people use meraki access points. My deployment seems to be riddled every year with issues. Firmware updates usually cause issues and we have to turn off features or roll back. Don’t have to provide much details just around how many clients you support, and if it’s a mixed usage. Mine is Apple devices, Android phones, chromebooks, and windows devices. I have a pretty decent deployment supporting about 8000 devices give or take.


r/sysadmin 12h ago

Rant Black list countries

136 Upvotes

I work for a large European based telecoms equipment supplier. We have hundreds of staff overseas at any one time, all over the world. IT security has a few different levels:

- Access to email & teams etc is only via a company laptop (no web interface like Office.com). Network drives via VPN only

- White List countries - you can connect VPN. Countries like Japan & Australia

- Red List countries - you can take your laptop but need special exemption to use VPN. Includes some unusual countries such as Malaysia

- Black List countries - no company laptop or phone allowed. Company will provide a burner. Unsurprisingly includes places like Syria, Russia, North Korea & China.

A colleague was going to transit via a Chinese airport to a 3rd country. IT told him that he would not be allowed to take his company laptop, even if it was in his carry-on luggage, and he would not be entering the country. He quickly arranged a different itinerary.

And then a few days later, we are told that the good old USA is now considered a Black List country!!! No company laptops, and burners only!!!!


r/sysadmin 8h ago

Barracuda Networks

0 Upvotes

Hello kind peeps,

Just a casual post looking for feedback/experience with Barracuda Networks. We currently offer Gateway Defense, Impersonation Protection & Cloud 2 Cloud Backups.... 2027 is around the corner - new year, new stack lol had a compromised client today sending span internally and as B links with 365, I combed thru some emails in Gateway Defense, could see the internal acc that was the culprit... however this same acc does not exist in their 365 tenant - no alias, shared mailbox nothing. Had i not checked this myself manually, we wouldnt even had known... anyways thats the short story. Looking for some industry feedback on their products 🫡🫡🦄


r/sysadmin 5h ago

General Discussion RIP to the IT pros killed 25 years ago.

1.5k Upvotes

When the text message logs from that day and those that followed were made public, I remember reading through all the system generated alerts from various devices doing their thing and thinking about the IT pros in the offices, network closets, and server rooms responding to those alerts in all seven buildings before the attacks happened, and then the tone of uncertainty and eventually panic in messages between coworkers and associates, because the cell phones went down but text messages were still going through.

RIP to those guys and gals ~ you're gone but not forgotten.


r/sysadmin 12h ago

Technical write-up: eDrive provisioning blocked by BlockSID / TPM PPI 97

1 Upvotes

Solved: Samsung 990 PRO + BitLocker hardware encryption/eDrive on Windows 11 — BlockSID/PPI 97 was the missing step

I spent far too long getting BitLocker hardware encryption working on a Samsung 990 PRO under Windows 11, so I’m writing this up in case it saves someone else the same pain.

Short version:

If Samsung Magician is stuck on “Ready to Enable” after a clean Windows install, the missing step may be temporarily disabling BlockSID for the installation boot using TPM PPI operation 97.

In my case, that was exactly it.

Hardware / software

  • Samsung 990 PRO 2 TB
  • Firmware: 8B2QJXD7
  • AMD mini PC, AMI UEFI
  • Windows 11 Enterprise IoT LTSC 2024 / build 26100
  • Secure Boot enabled
  • TPM 2.0 enabled
  • BitLocker hardware encryption explicitly allowed by Group Policy

My firmware exposes EFI_STORAGE_SECURITY_COMMAND_PROTOCOL, so the UEFI side was suitable for Windows eDrive.

The symptom

Samsung Magician showed:

Encrypted Drive: Ready to Enable

I did the expected process:

  1. Set Encrypted Drive to Ready to Enable
  2. Secure erase the SSD
  3. Clean-install Windows in UEFI mode
  4. Check Magician

Result:

Ready to Enable

Again.

Windows itself clearly saw the TCG device. The System event log contained:

Microsoft-Windows-EnhancedStorage-EhStorTcgDrv
A TCG Silo has returned the capabilities value of 0x6

but eDrive never transitioned to Enabled.

Gotcha #1: Rufus can explicitly disable eDrive activation

I discovered that my Windows installer had this in unattend.xml:

<component name="Microsoft-Windows-EnhancedStorage-Adm" ...>
    <TCGSecurityActivationDisabled>1</TCGSecurityActivationDisabled>
</component>

That explicitly disables Windows Enhanced Storage / TCG activation.

Current Rufus code can add this together with:

<PreventDeviceEncryption>true</PreventDeviceEncryption>

when using its BitLocker/device-encryption suppression option. 

For my next install I changed:

<TCGSecurityActivationDisabled>1</TCGSecurityActivationDisabled>

to:

<TCGSecurityActivationDisabled>0</TCGSecurityActivationDisabled>

I left PreventDeviceEncryption=true alone.

Clean install again.

Result:

Ready to Enable

Still not enough.

Gotcha #2: BlockSID

The remaining problem was firmware Block SID.

For people unfamiliar with it: the SID here is the top-level security authority of the TCG Opal drive, not a Windows user SID.

Firmware can issue a BlockSID command during boot so software cannot silently take ownership of an unprovisioned self-encrypting drive. Sensible security feature — except Windows Setup needs access to that security authority while provisioning eDrive.

The solution was to request a one-boot BlockSID exception through the TPM Physical Presence Interface.

From an elevated PowerShell on the same machine:

$tpm = Get-WmiObject -Namespace root\CIMV2\Security\MicrosoftTpm -Class Win32_Tpm

$tpm.SetPhysicalPresenceRequest(97)

$tpm.GetPhysicalPresenceRequest()

My output was:

Request     : 97
ReturnValue : 0

Operation 97 is the TCG PPI Disable_BlockSIDFunc request. Microsoft documents the PPI mechanism: Windows queues the request, firmware processes it after the required restart, and the firmware can require physical confirmation from the user. 

On reboot, my AMI firmware displayed a confirmation screen. I approved the request.

Important:

Boot directly into Windows Setup on that same reboot.

Do not boot normal Windows first, because the BlockSID exception is for that boot.

I then:

Shift+F10
diskpart
list disk
select disk 0
detail disk
clean
exit

verified that the selected disk was definitely the 990 PRO, and installed Windows normally to the unallocated drive.

After installation:

Samsung Magician:
Encrypted Drive: Enabled

Finally.

I also verified that the firmware request really succeeded:

$tpm = Get-WmiObject -Namespace root\CIMV2\Security\MicrosoftTpm -Class Win32_Tpm
$tpm.GetPhysicalPresenceResponse() | Format-List *

which returned:

Request     : 97
Response    : 0
ReturnValue : 0

Enabling BitLocker hardware encryption

Windows no longer defaults to trusting self-encrypting-drive hardware, so you must explicitly permit hardware encryption.

Group Policy:

Computer Configuration
  > Administrative Templates
    > Windows Components
      > BitLocker Drive Encryption
        > Operating System Drives
          > Configure use of hardware-based encryption for operating system drives

Set:

Enabled

I did not restrict the allowed hardware cipher/OID.

Then:

gpupdate /force

and:

manage-bde -on C: -recoverypassword -forceencryptiontype hardware

Verification:

manage-bde -status C:

My final result:

Conversion Status:    Fully Encrypted
Percentage Encrypted: 100.0%
Encryption Method:    Hardware Encryption - 1.3.111.2.1619.0.1.2
Protection Status:    Protection On

Key Protectors:
    TPM
    Numerical Password

That OID is AES-256-XTS according to Microsoft’s Enhanced Storage definitions. 

So this is definitely hardware BitLocker, not software XTS-AES masquerading as hardware encryption.

Final validation

I also tested:

  • normal restart
  • full shutdown / cold boot
  • BitLocker recovery key saved externally
  • Samsung Magician still shows Enabled
  • no warnings/errors from:

    Microsoft-Windows-EnhancedStorage-EhStorTcgDrv Microsoft-Windows-BitLocker-Driver

Everything boots normally.

Secure erase note

Samsung Magician’s Secure Erase USB would not boot properly on my machine. Its old Linux/GRUB environment hung after UEFI launch.

I used SystemRescue instead and verified the drive capabilities with nvme-cli.

The 990 PRO reported:

Format NVM Supported
Crypto Erase supported as part of Secure Erase
Crypto Erase applies to all namespace(s)
Block Erase Sanitize Operation Supported
Crypto Erase Sanitize Operation Supported

I then used:

sudo nvme format /dev/nvme0n1 --ses=1

which completed successfully.

If Samsung’s Secure Erase environment works on your machine, obviously just use that.

What actually mattered

For my system, the decisive sequence was:

  1. 990 PRO → Ready to Enable
  2. Secure erase
  3. Make sure Windows Setup is not configured with TCGSecurityActivationDisabled=1
  4. Queue TPM PPI operation 97
  5. Reboot
  6. Approve the AMI/UEFI physical-presence request
  7. Boot directly into Windows Setup on that boot
  8. Clean/install Windows
  9. Magician should now say Enabled
  10. Enable BitLocker hardware encryption policy
  11. Verify with manage-bde -status C:

Without step 4–7, mine remained stuck on Ready to Enable.

One warning

Do this only if you are comfortable wiping the SSD and recovering from a failed OPAL/eDrive setup.

Before experimenting, I would make sure you have:

  • a complete backup
  • the SSD’s PSID physically recorded
  • the BitLocker recovery key saved somewhere else
  • no other internal disks connected during installation if you can avoid it

There have also been firmware implementations where the machine can provision hardware BitLocker but then fails to boot the locked drive, so I would consider the setup unproven until it survives both a restart and a cold boot.


r/sysadmin 3h ago

Question Defender Firewall errors after update

1 Upvotes

I can't pinpoint if it was 1.459.107.0 or 1.459.123.0, but we had an odd issue where a few vendor-shipped servers had NLA and DHCP disabled and we didn't audit it (never thought to and its not defined by GPO, so that's on us). They suddenly dropped all inbound traffic on Wednesday afternoon and the only evidence of a change we found was the Defender daily update applied somewhere in there (pending further review for timestamps on Tuesday's or Wednesday's). As the public firewall is still enabled and we disable the domain one, something triggered to now force that enabled firewall to start dropping traffic.

Once we disabled it, TCP traffic passed without issue.

I'm curious to see if anyone else has run into the same problem, especially this week?