KickedAbyss

I am going to get fired today. I accidentally sent a shutdown loop to the entire company.

Posted by ExoticAd1059@reddit | sysadmin | View on Reddit | 761 comments

KickedAbyss@reddit

Most normal AD don't allow root gpo to apply to the DC OU. Heck your server OU also shouldn't. This sounds like either a fake story, or a very poorly engineered AD

Our cybersec team are getting onto us about all our servers having web browsers installed.

Posted by stone500@reddit | sysadmin | View on Reddit | 594 comments

KickedAbyss@reddit

Underrated comment right here. "The tool says vulnerable" okay but context, friend. Same with exploits that require console access - like my guy if they have console access, we're already in trouble.

You have to be joking Microsoft

Posted by Holiday_Disastrous@reddit | sysadmin | View on Reddit | 763 comments

KickedAbyss@reddit

I get your feelings on it. Personally, I can't get off hybrid-exchange fast enough. I am 100% okay shoving Msft under the bus on Exchange, because it's a pain to manage/upgrade/maintain, generally. For other things? That's something I'm not sold on. We have a few of our line-of-business apps in 3 different clouds (one cloud per solution, not one app between multiple), all managed by the vendors. In those instances, it's kinda bemusing when there are performance issues or outages, because as IT we are still 'blamed' but in reality, the Owners of those LoB Apps are the ones who pushed for 'the cloud' and thus we happily pass the buck. Doing it smart is the hard part. i.e. not putting all your eggs in one basket. In a perfect world, I would modernize a business application into a Container based/Kubernetes type cloud-native solution, and spread it between two different clouds in two different regions, in either an active/active or at very least active/passive manner where failover is very simple and quick. You mitigate your risk by leveraging multiple 'hosts' no different than you would either a DR site, or even just a local cluster/replica. When people complain about things like bandwidth, it's easy enough to float an ISP upgrade quote to the CFO and watch them have angry outbursts, because at the end of the day, you're basically shifting costs around, not getting rid of them. That's not always true, of course. Some apps don't need much bandwidth, and thus are fine for the cloud on a connectivity level; but it also adds complexity to securely cross-connect systems, when they aren't all inside your datacenter on the same VLANs. But even that can run you into things like physical ingress of fiber lines - where the hated North American fiber seeking back-hoe can always do you in and kill all connectivity to your 'cloud'. We have some in VP level leadership who HATE "legacy" solutions like on prem file servers for example, yet we do not have technology (affordable technology) to truly move 'everything' to a cloud, especially when dealing with large files (Video, CAD, etc) that have to be transferred with frequency between client & server or server & server. At the end of the day, the cloud isn't going away. Our job at this point appears to be mostly doing our best to inform leadership the pro/cons of moving specific workloads to the cloud, or keeping them onprem.

CEO retired. How do you politely say "no" without burning a bridge?

Posted by oaomcg@reddit | sysadmin | View on Reddit | 2436 comments

Please take a freshmen level accounting course at your local community college.

Posted by rumblegod@reddit | sysadmin | View on Reddit | 288 comments

IT Salary - lowering

Posted by Few-Dance-855@reddit | sysadmin | View on Reddit | 566 comments

Bought RAM in October to dodge price spikes… now I have to return it because “year-end optics”

Posted by icekeuter@reddit | sysadmin | View on Reddit | 278 comments

Dear Microsoft

Posted by GoWest1223@reddit | sysadmin | View on Reddit | 93 comments

I Warned them and they didn't Listen!

Posted by ArtificialDuo@reddit | sysadmin | View on Reddit | 339 comments

KickedAbyss@reddit

You could submit a waste identification request. How could we have proactively avoided these costs. How could we have better budgeted with proper numbers. What is our procedure around investigating alternate solutions to products when they're priced higher than we are comfortable paying. Etc etc. Our renewal is next year, and I've got (3)R740xd I'm about to deploy in a proxmox solution as a PoC, but I fully expect we'll renew. We're already on vsphere+ licensing so VVF won't be insanely higher. Biggest issue for me is the C-Level obsession with cloud. Already provided an estimate for lift and shift to my boss, who's dead set against the cloud for 70% of our workload. And we've already moved most out stuff that works well in the cloud (relatively) so moving everything is hilariously high. Like, even if we replaced our entire infrastructure and put it in a 5 year outlay, cloud would still be 4-5x more easily.

Update: I quit

Posted by Dank-Miles@reddit | sysadmin | View on Reddit | 258 comments

Good day fellow admins. I just accepted an offer as an IT Administrator for a company that currently relies completely on a MSP. They are looking to bring IT in-house with this new role. I will be the go-to for all things IT. Could use some advice.

Posted by thatflacoman@reddit | sysadmin | View on Reddit | 289 comments

KickedAbyss@reddit

So, if you want to impress a C level while also doing a damn good job, start by filling out a NIST Special Publication 800-37 self audit. I'm not joking. You 100% will have blank sections. Those are areas for improvement and results in a gap analysis of your current environment vs where you want to be. Go another step further and find a NIST specific to your industry. For example, NIST IR 8183 is a cybersecurity framework focused on the manufacturing industry. I started my last job with my boss on vacation so I spent the first week going through it, and quickly got a lay of the land purely from doing that.

Does anyone else struggle with getting laptops back after employees leave from managers?

Posted by 13-months@reddit | sysadmin | View on Reddit | 155 comments

Oldest Technology Still Kicking

Posted by Intrepid_Stock1383@reddit | sysadmin | View on Reddit | 667 comments

Most overlooked IT ticketing system for smaller teams?

Posted by daphnegweneth@reddit | sysadmin | View on Reddit | 462 comments

KickedAbyss@reddit

Pretty sure it's open source, so I'd almost 100% guarantee if they dropped it then the open source synology app store would host it. Heck there might be others on that one since syno allows other repository

Most overlooked IT ticketing system for smaller teams?

Posted by daphnegweneth@reddit | sysadmin | View on Reddit | 462 comments

KickedAbyss@reddit

But honestly for really small teams? https://www.synology.com/en-us/dsm/packages/osTicket?os_ver=6.2 buy a syno and use it for your all in one server for all things.

Most overlooked IT ticketing system for smaller teams?

Posted by daphnegweneth@reddit | sysadmin | View on Reddit | 462 comments

Most overlooked IT ticketing system for smaller teams?

Posted by daphnegweneth@reddit | sysadmin | View on Reddit | 462 comments

I think I’m being underpaid

Posted by ObjectiveApartment84@reddit | sysadmin | View on Reddit | 234 comments

KickedAbyss@reddit

This. No matter how much school you've had, nothing beats living in the life of IT. IMHO everyone should start at an MSP or help desk no matter their schooling.

I knew it was going to happen, but not this soon

Posted by ComparisonFunny282@reddit | sysadmin | View on Reddit | 403 comments

KickedAbyss@reddit

1099 the crap out of it 🤣 We layed off one of our employees, who then went and opened her own contract company... Who we ended up hiring a couple months later haha

I knew it was going to happen, but not this soon

Posted by ComparisonFunny282@reddit | sysadmin | View on Reddit | 403 comments

Directive to move away from Microsoft

Posted by LetPrestigious3916@reddit | sysadmin | View on Reddit | 478 comments

What is happening with licenses?

Posted by frankv1971@reddit | sysadmin | View on Reddit | 260 comments

My coworkers are starting to COMPLETELY rely on ChatGPT for anything that requires troubleshooting

Posted by Leg0z@reddit | sysadmin | View on Reddit | 1016 comments

KickedAbyss@reddit

Yep. I'll use it for like, adding logging syntax on occasion or commenting. I don't trust it to the code logic and especially not powershell commands as it will absolutely make shit up. And then I will only use it for generic, I don't put anything remotely proprietary.

My coworkers are starting to COMPLETELY rely on ChatGPT for anything that requires troubleshooting

Posted by Leg0z@reddit | sysadmin | View on Reddit | 1016 comments

I feel Microsoft should reconsider this acronym.

Posted by godawgs1997@reddit | sysadmin | View on Reddit | 137 comments

KickedAbyss@reddit

Speak for yourself, our csam is actually very good. Then again we have a very large Microsoft account via our parent company (which is like over a $60 billion revenue company) so maybe we get a better assignment. I think though that you have to pay for Unified Support to get one.

I feel Microsoft should reconsider this acronym.

Posted by godawgs1997@reddit | sysadmin | View on Reddit | 137 comments

I feel Microsoft should reconsider this acronym.

Posted by godawgs1997@reddit | sysadmin | View on Reddit | 137 comments

KickedAbyss@reddit

CustomerSuccessAccountManagers have been around for a long time at Microsoft. I first just typed it out and realized how bad that looked so added the actual name.

Do logon banners have any legal weight?

Posted by Team503@reddit | sysadmin | View on Reddit | 141 comments

Wannabe SysAdmin Is Driving Me Up A F$%KING WALL

Posted by iansaul@reddit | sysadmin | View on Reddit | 198 comments

KickedAbyss@reddit

Yeah the dual networks was way more am 3 issue for them. But I've seen domain trust and similar issues multiple times from using public dns in clients. https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/best-practices-for-dns-client-settings#windows-server-member-servers https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/dns-client-resolution-timeouts#what-is-the-default-behavior-of-a-dns-client-when-two-dns-servers-are-configured-on-the-nic I've also seen evidence that it'll keep using the 2nd DNS if it had a faster lookup, which in many cases it will over an internal that has inherent latency by sending the request to an external itself. I've also seen that you can reliably use public if you have filters on your edge that catch requests for internal resources, though I've not tried that myself.

Wannabe SysAdmin Is Driving Me Up A F$%KING WALL

Posted by iansaul@reddit | sysadmin | View on Reddit | 198 comments

KickedAbyss@reddit

You never want a client of a domain to have anything but domain DNS server set. Windows DNS isn't sequential - it's not like it'll try the DC first and then to the public, it might just randomly pick the public dns. The exception being maybe an Entra authenticated client.

Has anyone's org *actually* seen a benefit from 365 Copilot?

Posted by fluffy_warthog10@reddit | sysadmin | View on Reddit | 527 comments

KickedAbyss@reddit

There has been a definite uptick in user dissatisfaction over not deploying it. I consider that a win. Then again we also blocked access to all other AI.

Got paged at 3AM last night for a "critical" alert that turned out to be a monitoring system testing itself

Posted by Tiny_Habit5745@reddit | sysadmin | View on Reddit | 103 comments

KickedAbyss@reddit

We just today went through what we want to have page overnight with a new system (Everbridge). I said all I care about is my primary Datacenter vcenter/hosts are offline, and if UPS time on battery is > 5 minutes (which would indicate Generator issues) 🤣

Got paged at 3AM last night for a "critical" alert that turned out to be a monitoring system testing itself

Posted by Tiny_Habit5745@reddit | sysadmin | View on Reddit | 103 comments

A DC just tapped out mid-update because someone thought 4GB RAM and a pagefile on D:\ with MaxSize=0 was a good idea.

Posted by Funkenzutzler@reddit | sysadmin | View on Reddit | 158 comments

KickedAbyss@reddit

Even our large locations where we run NPS on the DC (and thus GUI, and required because Microsoft is stupid) I rarely see more than 6gb usage. Especially where it's core, 4gb is fine.

A DC just tapped out mid-update because someone thought 4GB RAM and a pagefile on D:\ with MaxSize=0 was a good idea.

Posted by Funkenzutzler@reddit | sysadmin | View on Reddit | 158 comments

KickedAbyss@reddit

Uh.... What? EDR on a DC is critical. There are so many situations where a bad actor can perform malicious actions against or on a DC via a horizontal attack. We had a pen test where that happened and our EDR alerted and stopped the action. Even if it only alerted, that would be worth it. To say nothing of Defender for Identity which requires install on all DCs.

Do you still install Windows Server without the GUI?

Posted by easyedy@reddit | sysadmin | View on Reddit | 473 comments

Why did you want to become a sysadmin?

Posted by Abject_Serve_1269@reddit | sysadmin | View on Reddit | 218 comments

The quintessential Microsoft ticket experience

Posted by requiemofthesoul@reddit | sysadmin | View on Reddit | 103 comments

Holy F up.

Posted by DougThorn@reddit | sysadmin | View on Reddit | 551 comments

Thanks for making licensing for 365 confusing Microsoft.

Posted by idrinkpastawater@reddit | sysadmin | View on Reddit | 41 comments

KickedAbyss@reddit

Microsoft loves confusing licensing. SQL and most of the rest are just as bad. If you haven't seen it, https://m365maps.com/[https://m365maps.com/](https://m365maps.com/)

Completely stumped by this mail routing issue

Posted by CeC-P@reddit | sysadmin | View on Reddit | 28 comments

It's never DNS, it's always DNS but sometimes it's the default gateway. DOH!

Posted by AHrubik@reddit | sysadmin | View on Reddit | 37 comments

anyone switching to hyper-v?

Posted by jfgechols@reddit | sysadmin | View on Reddit | 273 comments

What are you doing with Win10 machines that can't be upgraded?

Posted by j5kDM3akVnhv@reddit | sysadmin | View on Reddit | 483 comments

Cloud provider let us overrun usage for months — then dropped a massive surprise bill. My boss is extremely angy. Is this normal?

Posted by Curiousman1911@reddit | sysadmin | View on Reddit | 354 comments

KickedAbyss@reddit

Large public clouds don't care. They provide reports you can create and systems you use to monitor. You screw up it's on you. Smaller private ish clouds, it depends. Some are greedy, some would rather keep a client vs lose one. IMHO I'd leave that cloud if they truly didn't provide any reporting or warnings.

Cloud provider let us overrun usage for months — then dropped a massive surprise bill. My boss is extremely angy. Is this normal?

Posted by Curiousman1911@reddit | sysadmin | View on Reddit | 354 comments

KickedAbyss@reddit

Welcome to the cloud. The person responsible for the bill is whoever pushed you into the cloud without properly planning. Because a key element of anyone going cloud is ensuring 100% you have accurate and LIVE cost analysis both before and after migration. Repatriation is a thing for a very good reason.

Your lack of preparation is not my emergency

Posted by Ivy1974@reddit | sysadmin | View on Reddit | 453 comments

KickedAbyss@reddit

You just suddenly got a new iPhone 69? And a new phone number? And now all your MFA magically doesn't work?! Oh no. Emergency new iPhones. (one time I was okay with this type ticket was when a coworker had his stolen in Mumbai)

Rebuilt a legacy desktop app into a cloud-based system. Biggest win wasn’t what we expected

Posted by Techie_Justin@reddit | sysadmin | View on Reddit | 93 comments

Your Opinion on Warning Header on Email

Posted by CapitalG14@reddit | sysadmin | View on Reddit | 248 comments

It's really nice when money is no object, only deadlines.

Posted by GallowWho@reddit | sysadmin | View on Reddit | 43 comments

KickedAbyss@reddit

I've seen same day plenty of times on under warranty stuff, but I've also seen Parkplace rush ship international... I don't want to know what it costs to rush ship from California to the EU but I'm sure it's not cheap.