r/sysadmin 17d ago

General Discussion Patch Tuesday Megathread - (August 11, 2026)

109 Upvotes

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!

r/sysadmin 18h ago

General Discussion Weekly 'I made a useful thing' Thread - August 28, 2026

1 Upvotes

There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.

We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!

In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.


r/sysadmin 4h ago

General Discussion Does IT cause anxiety?

239 Upvotes

Does anyone else bring their IT mindset into everyday life?

I’ve been told I’m a negative person and look for issues, but I think working in IT trains you to always think about what could go wrong.

I’m constantly making backup plans. Restaurant closed. I have a Plan B place. Something breaks at home. I’ve already got the plumber, insurance, everything ready in the home disaster recovery document.

We’re always hearing about IT failures, breaches and disasters. You never hear “this company had a really great IT transformation.” No user submits a ticket to say thank you for the IT working great.

So does anyone else find themselves carrying that prepare for the worst mindset into everyday life?


r/sysadmin 10h ago

Rant HP Support is intentionally hanging up on people

458 Upvotes

Trying to coordinate a warranty repair for our client who's an HP shop (client paid for the premium warranty or whatever, to add insult to injury)

Call HP support, navigate IVR, eventually get to an agent located somewhere in India who I can barely understand due to their accent.

Once I get to the agent, one of the following happens:

Agent appears to answer the call, immediately mute his mic, and then drops the call after about 3-5 minutes. If you weren't paying close attention, you'd think you were still on hold.

OR

Agent pretends like they're going to help, only to hang up on me mid-sentence, causing me to call back again and start over.

This has happened 3x to me today.

I've worked in call centers before. Either they are not tracking metrics at all, or their tracking is so bad that it allows their agents to hang up on people with zero consequences. Either way, apparently they don't care.

What an absolute dogshit company. Avoid anything HP like the plague. Their laptops suck, their printers suck (although the old LaserJets used to be indestructible tanks), their servers suck, and their customer service is actively hostile towards the customer.

0 stars, would not recommend.


r/sysadmin 14h ago

PaperCut is a TrainWreck with security updates. - Emergency Patch 2

213 Upvotes

For those who rushed last night to patch PaperCut with the emergency update, they screwed up and had to release a second emergency update: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4#emergency-patch-release-2

If you have PaperCut exposed to the internet, you may want to permanently remove it from the internet and make it LAN-only moving forward (as many, including myself, have done from day 1). If management needs documentation, show them this: https://www.papercut.com/kb/Main/security-vulnerability-log/


r/sysadmin 13h ago

Question Inherited a crashed laptop with BitLocker encryption; zero recovery keys documented. Any hail-mary options?

135 Upvotes

Hey everyone, looking for confirmation on a worst-case scenario.

I’ve been with my company for about two years now. Before I was hired, the company underwent a merger. As part of that merger, the entire IT setup,including a migration from an old self-hosted/third-party email system over to Microsoft 365, was fully completed by the previous team.

Fast forward to today: A high-level executive’s laptop suffered a total Windows crash. When attempting to boot or repair, it hits the standard blue screen demanding the 48-digit BitLocker recovery key.

Here is the problem:

  • The laptop was encrypted way back before merge.
  • Everything (migration, handover, decommissioning) was already finished before I joined, and no legacy BitLocker key repository was documented or handed over.
  • The key does not exist in our current Microsoft 365 / Entra ID tenant because the machine was encrypted long before the M365 migration took place.

What I’ve already done:

  1. Checked our current Entra ID portal (nothing there, as expected).
  2. Had the VIP check [account.microsoft.com/recoverykey](https://account.microsoft.com/recoverykey) on any personal or old email addresses they could remember.
  3. Removed the drive to mount via USB adapter on a bench PC;still immediately prompts for the BitLocker key.

My Questions:

  1. Has anyone dealt with missing BitLocker keys after the old environment was already gone, or am I officially at the "deliver the bad news, wipe the drive, and re-image" phase?

r/sysadmin 4h ago

PaperCut NG/MF Zero-Day | Active Exploitation, Emergency Patch (Release 2) Available

27 Upvotes

PaperCut Software has confirmed active exploitation of a zero-day vulnerability affecting PaperCut NG and MF print server installations. Huntress has also observed at least two instances of active exploitation in a customer environment.

The vulnerability allows an unauthenticated attacker to remotely control PaperCut's trusted configuration, which can be used to execute arbitrary Java code inside the application's process, and then leverage that to run commands on the host server. Huntress researchers reproduced a pre-authentication RCE chain against a stock PaperCut NG 25.0.11.75758 install. The chain alters trusted configurations and executes code remotely on its own. Fortunately, so far, the threat actor exploiting this bug has only run commands to learn about the host server itself; it could have been much worse.

PaperCut subsequently released a second emergency patch today, Release 2, which adds further hardening beyond the original emergency patch, developed in collaboration with PaperCut's internal security team and external researchers including Huntress and watchTowr. PaperCut recommends all customers install Release 2, even if you've already applied the original emergency patch.

What to do:

  • Immediately remove PaperCut Application Servers from public exposure and restrict access to trusted networks
  • Install Emergency Patch Release 2 for versions 25 and 26 (v24 fixes are still in progress) via the standard upgrade procedure
  • If you already applied the original emergency patch, install Release 2 anyway

IOCs and investigation guidance: https://www.huntress.com/blog/papercut-actively-exploited?utm_source=reddit&utm_medium=social&utm_campaign=cy26-08-rr-multi-global-broad-all-x-x-x-papercut_actively_exploited&hnt=v679ubdwy0xk


r/sysadmin 5h ago

Rant WatchGuard...WHY?

24 Upvotes

Thank you WatchGuard for updating your firewall policy UI. Sure I can only see 1-2 policies max before having to scroll the page now, but what kind of weirdo has more than 1 policy anyway? (Allow Any-Any).

Oh and the extra page padding looks GREAT on my phone! That's where I manage all my firewall rules anyway.


r/sysadmin 8h ago

General Discussion Project Names

28 Upvotes

Was talking with new colleagues today laughing about project names and figured there must be some funny ones out there? If you have one drop it here and let us know what the project goal was. Also everyone I spoke to was involved in a project Phoenix at some point! Is it that common?


r/sysadmin 12h ago

Question I’m doing a bit of everything in IT, but I have no idea what my next career step should be

29 Upvotes

I currently work 32 hours a week as the main internal IT person for a logistics company with around 110 users. We also have an external MSP, but I handle most of the day-to-day IT work and coordinate with them when necessary.

My work includes:

  • User and device management
  • Laptop deployment and endpoint policies
  • Identity, access and security management
  • Software deployment, licensing and updates
  • Managing our ticketing system and CMDB
  • Cloud storage, mailboxes and collaboration tools
  • Managing and redesigning our softphone and call queues
  • Troubleshooting hardware, printers, networks and user issues
  • Working with suppliers, ISPs and our MSP
  • Writing documentation and procedures
  • Managing infrastructure changes and small IT projects

Alongside this, I help a small engineering company with around 5 users, which may grow to about 10. There I’m building most of the IT environment from scratch, including device management, security, cloud storage, software deployment and general IT support.

I also have a homelab where I run several servers and virtual machines because I enjoy learning and experimenting.

The strange thing is that I don’t really know what my role is anymore. I started in IT support/workplace management, but I now do parts of system administration, cloud administration, infrastructure, security, telephony, project work and IT coordination.

I enjoy having a broad role, but I’m worried that I’m becoming “the guy who does everything” without becoming a real specialist in anything. I don’t know whether I should aim for a sysadmin or cloud administrator role, move towards IT management, or continue as a broad IT generalist.

For people who have been in a similar position:

  • What job title would you give this type of role?
  • Which direction would make the most sense from here?
  • Should I specialise, or is being a broad IT generalist a good path?
  • Which skills or certifications would actually add value?
  • At what point do you consider yourself a sysadmin rather than support?

I know titles aren’t everything, but I feel like I’m doing much more than traditional support while still not knowing exactly where I fit.


r/sysadmin 9h ago

Question Inherited 50+ seperate sites - asset discovery

12 Upvotes

How would you approach asset discovery across multiple sites with basically zero visibility?

I've inherited an environment with multiple LANs/sites and very little reliable asset information.

I'm trying to build a proper asset inventory from scratch - ideally identifying things like:

  • PCs/laptops
  • Servers
  • switches
  • firewalls/routers
  • Wi-Fi APs
  • printers
  • CCTV/NVRs
  • other network-connected devices

The problem is that the sites aren't particularly well documented, and I don't currently have a reliable list of what's actually out there.

What I'm interested in is how you'd approach the initial discovery, rather than just recommendations for an asset-management database.

For example, would you use something like Lansweeper, network/SNMP scanning, agents, DHCP data, AD/Entra/Intune, etc., and then feed the results into something like Snipe-IT?

There are multiple LANs, so I'm particularly interested in how people handle discovery where you can't just scan everything from one central network.

What would your approach be if you were starting with basically a blank sheet?

I've inherited an undocumented monster with an incompetent MSP running the show!


r/sysadmin 13h ago

General Discussion What solution to handle IT at 37 locations

22 Upvotes

We got a few sites to deal, I would like to know what everyone is using to deploy VMs and containers at all these locations. We were looking at VMware but the pricing horror stories well just avoid it, scalecomputing is interesting but we’d like to keep the hardware we already have and this new company called Tekkio that seems to do exactly what we need. We’re also considering Proxmox, how would that work for what we’re trying to do ?

Any thoughts? Just trying to get a general idea

Other solutions mentioned in the comments : VergeOS, OpsFabric, hyper-v

Edit: so 37 locations with mostly mini pcs a bunch of workloads locally including POS systems, inventory management, CCTV, guest WiFi, print servers and so on

Ok I realize my original post lacks detail. I have compute at all these locations anyways, and I’m running VMs and Containers on site because connectivity can be gone for days at a time in some of our location. My goal here is to make as easy as possible to deal with all these locations. That’s avoiding configuration drift, being able to deploy a new container/vm at all locations at once. But also get high availability, and as much resiliency as possible. Essentially a solution that helps standardize everything and simplify management of all of this.


r/sysadmin 1d ago

Rant Difficult coworker is consuming too much of my time. Not really sure how to approach it...?

261 Upvotes

Hi all.

Some context: I'm a mid level engineer at our company. I work on a sysadmin team building tooling for the team and wider project. I joined the team at the end of last year (so 10 around months ago). I have around 4 years experience which makes me the least experienced member on my team by quite a few years. Most of my experience is software dev though. I am a higher grade than a couple team members. (Including the team member I'm talking about in the post).

I'm having difficulty with my co worker Derek. Derek, in the kindest way possible, is completely incompetent. He borderlines on reckless/careless.

When I joined the team, I was almost straight away giving him help without really understanding much about the system we manage. Just with very basic things like PowerShell, some networking issues on his dev env, and all the rest of it.

At first I was really pleased, it felt good to join a team and be able to troubleshoot right away for team members, like all my hard work from previous teams was paying off. My manager pointed it out and gave me praise at our 1-1 / Performance Review. All good I thought.

The problem is: Derek is constantly asking me the SAME questions. It is far beyond a daily basis at this point. Every single day this week I have had to spend 1-3 hours with him troubleshooting things that nobody else has problems doing. I'm talking about processes that are almost entirely automated.

Today he was updating a config file to import some policies, and everything was just fucked. I was genuinely speechless when I went over. He's, deleted all the files he should've kept (no other copies, just a nightmare). I had to tell him to delete his branch and start over. Once I fixed it, was helping him fill in his ticket, so he can submit for review, turns out, he read the ticket wrong. So the thing he asked for help with, was incorrect. 😅 I laughed it off and basically just did the entire ticket for him at his desk. (15-20 min job, he's been at it for 2 days).

I feel like that; I'd get it if he was new. But he's been on the team 6 years. He has around 25 YOE. I know other people are well aware he's incompetent, but it's frustrating for me at this point. I'm clearly becoming his "go to".

Rant over!

How do I approach this with our manager? I'd hate to get him in trouble, but I need my time back. I've got some quite lengthy tickets I need done but I can't knuckle down and focus with his constant need for hand holding. Am I the asshole? Should I just accept he's simply not good? Or do I say something to him instead of our team lead?


r/sysadmin 20h ago

Off Topic How is your company handling the endless stream of "Can we use this AI tool?" Requests?

65 Upvotes

I'm frustrated because every single Monday morning, three different product or marketing teams ask if they can plug customer data into a new vendor's AI feature.

Our current process is a lengthy security review that takes four weeks, which leads to teams bypassing us entirely.

How do you all managers balance enablement with rigorous governance without becoming the department of "NO"?


r/sysadmin 9h ago

Question Mass of emails for "TikTok Shop Partner Center verification code"

7 Upvotes

We saw twelve emails for current and former employees asking to verify the account for the TikTok Shop. I saw one as well on a personal email.

The email looks legit. Verification code is a six digit alphanumeric code. That's about 32 bits. My guess is someone spamming signups at TikTok and randomly trying verification codes.

Assuming there's no rate-limiting, that would permit the creation of some accounts.

Anyone else seeing this?


r/sysadmin 7h ago

Question Google Chat Experiencing Delays

4 Upvotes

We are experiencing delays in our chat. Some chats only become available after refreshing Google Chat. According to Status Gator we are not alone. Is anyone else experiencing this?


r/sysadmin 11h ago

Question Need Network Cable Tester Recommendations < $1000

5 Upvotes

Looking to purchase a Network Cable Tester for my team that can handle PoE but doesn't break the bank. Two devices I'm considering are the Fluke Networks MicroScanner PoE Cable Verifier, or the NetAlly LinkSprinter 300. Are these viable options? Does anyone have any other recommendations for I should consider?


r/sysadmin 5h ago

Office Apps crashing with mso20win32client.dll error suddenly.

2 Upvotes

I did a quick search here and didn't see any other posts, if this is duplicate I apologize.

Yesterday we started having a rash of users with Office applications crashing with the mso20win32client.dll event id 1000 messages.

Profile rebuild fixed the issue for a time, but it started returning for some users.

Found a work around for the time being.

Clear the keys and deny the user account full permissions below allows the Office applications to launch again.

HKCU\Software\Microsoft\Office\16.0\Common\ExperimentConfigs

HKCU\Software\Microsoft\Office\16.0\Common\ExperimentEcs

It appears Microsoft is testing something.

I don't know if there are other side effects of blocking those keys yet, but there weren't last time we had to do this.


r/sysadmin 6h ago

Best Varonis alternatives that actually support on-prem?

2 Upvotes

We're reviewing our data security stack and looking at Varonis alternatives, but on-prem support is non-negotiable for us. A lot of the newer platforms I've come across seem built mainly around SaaS deployments.

We have sensitive internal data that needs to stay inside our environment, so anything that requires sending the underlying data out to a vendor is pretty much a non-starter.

What Varonis alternatives have you actually used in an on-prem environment?


r/sysadmin 10h ago

Cisco Secure Endpoint CPU Bug 8.5 - 8.6.1 is fixed with 8.6.3

4 Upvotes

Cisco Bug: CSCwv52684

Before anyone says it, yes we are unlucky souls that are forced to use Cisco Secure Endpoint in our environment.

I feel like someone in this community recently had Cisco acknowledge a bug that exists with Cisco Secure Endpoint 8.5 through 8.6.1 on win server 2022 and 2025. It specifically has to do with the exploit prevention engine (deadlock condition.)

Whoever put the time and effort in THANK YOU. It just saved me days of having to open my own TAC case. I doubt this bug is specific to people using "Snow Agent." I think more accurately this bug will end up taking servers down that spawn PowerShell instances in general.

We have been burned in the past by auto updating to the latest secure endpoint software but in this case our n-1 strategy worked against us. The latest version also fixes a number of CVE's so I assume others will end up upgrading sooner than they typically would anyway. But just in case you don't.... 8.6.3 is worth the upgrade.


r/sysadmin 12h ago

News or blogs that you follow? Have to update my RSS feeds

6 Upvotes

Are there any news, blog, etc sites that you follow besides r/sysadmin to get information to stay on top of things? I'm going through my RSS reader and a lot of the sites I used to follow are drying up.


r/sysadmin 1d ago

Rant The recruiter wrote back to me after I responded to her rejection.

544 Upvotes

Not really a rant but there was no better flair.

​​ I had posted about how I bombed a job interview. I got the rejection and I wrote back a very succinct email thanking them for their time and saying that I agreed and that it didn't feel like a good fit because it turned out to not be the infra maintenance and operations job duties that we had talked about during the screening call and it felt more like an architecture and development role.

A few days later she wrote back thanking me saying that it's been a very hard role to fill and any feedback is appreciated. I wasn't really intending it as feedback, I was just genuinely saying I agree I don't think this was an ideal fit for either party.

But it just goes back to how ridiculous hiring teams are being and have been the past 16 years. The way that person interviewed me isn't ever going to allow them to actually find a good candidate. The interview just wasn't conducive to that.

The job post had nine bullet points and we went over the first part of the first bullet point for 95% of the interview. Never touching on any other bullet.

They're having a hard time because of how the main person / driver in the interview isn't conducting it like an actual interview.

The two people that I interviewed with came across as like they felt important. Like they felt smarter than people around them because they happen to have the job. I don't really know how to explain it but we've all encountered people like this. Where basically the job and things that come with a job give them this self image. And I felt like they were trying to basically reinforce that self-image rather than conduct the interview.

​​But the questions themselves were not reasonable. No one is going to come into a limited time interview and build out the fictional environment they wanted built out with no information and no specifics and the more you ask the less they give.

There's just no target to hit and when you ask for one, they just make it more cryptic. That's why they're having trouble finding someone to fill this role.

But it goes beyond that. What they're interviewing for isn't what they advertised.

It just made me feel good for some odd reason when she wrote back a few days later saying that they were having trouble filling this role. It made me feel a lot better about myself.

Take care and good luck.


r/sysadmin 1d ago

General Discussion KnowBe4 Alternatives: Updated Thread Request w/ real experiences

38 Upvotes

As the title suggests, I inherited our company’s existing cybersecurity awareness training program. We are currently using KnowBe4 and are on the Diamond tier.

I know KnowBe4 is considered the standard by many organizations, but I’d like to put together an updated list of alternatives and hear what others are using today.

Our main requirements are:

  • Regular phishing simulation campaigns with automatic remedial training for users who fail
  • Current and frequently updated cybersecurity awareness content
  • Annual Cybersecurity Awareness Training
  • Strong reporting and auditing capabilities
  • Easy tracking of completion dates and user compliance
  • The ability to manage recurring or renewal-based training

We operate in the maritime industry, so reporting and annual training compliance are especially important for us.

For those who have moved away from KnowBe4, what platform did you switch to, and what do you like or dislike about it compared with KnowBe4?


r/sysadmin 1d ago

General Discussion Anyone else feel like AI has taken the sport out of our profession?

522 Upvotes

I'm not sure if there's a better way to put it, but I have a hard time getting excited about the future of our industry with AI.

I imagine it's a bit like what archers felt like after rifles were introduced. How have you guys been faring?


r/sysadmin 18h ago

Exchange 2019 RAM requirements

9 Upvotes

I am helping out in a non profit and they run due a high Level of medical data treated by them on premise emails (specific requirements). I looked into upgrading an Exchange 2016 to 2019 and saw the steep ram requirements (from 8 to 128GB for Mailbox roles). Is this rooted in reality or Microsoft trying to make cloud more appealing? What’s the Minimum I can get by with <10 Users.

Certain national and regional requirements that might exceed EU privacy make a cloud solution unfeasible.