Previous-Low4715

Built a working enterprise IT platform (asset management + ticketing). Have leads. Still can't close. What's the actual move here?

Posted by This_Nerve1892@reddit | sysadmin | View on Reddit | 40 comments

Intune is not fit for purpose.

Posted by Hobbit_Hardcase@reddit | sysadmin | View on Reddit | 385 comments

Blocking sites with Microsoft Global Secure Access

Posted by No_Calligrapher_3247@reddit | sysadmin | View on Reddit | 4 comments

Using AI agents for real IT troubleshooting (not just coding) — anyone else doing this at scale?

Posted by pck-grb@reddit | sysadmin | View on Reddit | 11 comments

I caught a notary in our office

Posted by TrainingOrchid516@reddit | sysadmin | View on Reddit | 64 comments

Previous-Low4715@reddit

Claudeslop answer: Based on the context provided in image.png, the IT admin's actions cross several major legal, ethical, and procedural lines, especially from a UK compliance perspective. While a corporate AUP typically allows IT to maintain systems and preserve logs, the proactive, unprompted investigative steps detailed in image.png go far beyond standard operational mandates and enter highly problematic territory. Here is a breakdown of why the actions in image.png lean heavily into illegal or severe non-compliant territory rather than just "borderline" policy breaches. 1. Unauthorized Access and "Snooping" In image.png, the admin admits to looking at the content of a stuck page, searching HR systems for a name match, auditing printer logs, and directly jumping into the user's corporate OneDrive without a formal request or ticket. The Reality: While corporate assets belong to the employer, access to individual user data must still be justified under a specific legal basis. Proactively digging through an individual's OneDrive or live browser history based on a hunch, rather than acting on an explicit threat vector or a formal HR/legal escalation, can violate data protection laws. Computer Misuse Risks: In strict jurisdictions, accessing a specific user account or remote-controlling a machine while an employee is away without explicit, documented authorization or an open security incident ticket can blur into unauthorized access. 2. Serious Data Protection Violations (UK GDPR / DPA 2018) The admin in image.png actively looks up an individual in the internal HR system to check for a match. Purpose Limitation: HR data is highly sensitive and collected for specific employment purposes. An IT administrator utilizing their administrative privileges to cross-reference data in an HR database for an independent, unassigned investigation is a direct breach of the Purpose Limitation principle under data protection laws. Proportionality and Privacy: Remote controlling a user's PC while they have "stepped out for an hour" to actively read their open browser tabs and Google searches violates reasonable expectations of workplace privacy. Even under strict corporate monitoring policies, targeted surveillance must be proportionate, justified, and typically vetted via a Data Protection Impact Assessment (DPIA). Siloed, unsupervised IT snooping completely fails this standard. 3. Destruction of Evidence The edit in image.png states: "I was instructed by HR AND the employee to delete the files." Compliance Failure: If the documents contain third-party Social Security Numbers (SSNs) and financial data, they represent a severe data breach for the organization (and potentially the notary's external clients). Simply ordering IT to "delete the files and backups" to make the problem go away, without logging a formal data breach, identifying the affected data subjects, or following a standard incident response protocol, is a massive regulatory compliance violation. Summary The comment at the bottom of image.png highlights the organizational reality: "You're not really supposed to do any of this unless someone in HR asks you to." By acting as an independent investigator, processing HR database records without cause, and conducting targeted live surveillance on an endpoint without a formal ticket, the IT administrator in image.png exposed themselves and their company to significant liability. Securing a perimeter or preserving logs during an active infrastructure alert is standard IT protocol; digging through a specific user's private folders and live browser sessions without authorization is a severe overreach.

I caught a notary in our office

Posted by TrainingOrchid516@reddit | sysadmin | View on Reddit | 64 comments

Previous-Low4715@reddit

In the UK this would be borderline illegal depending on the wording in the AUP, at the very least it would make it very difficult for the company to remove the employee in question. The employer is still bound by GDPR regardless of what is in the contract and there are numerous laws and precedents separating IT technical gathering from HR/conduct investigation.

I caught a notary in our office

Posted by TrainingOrchid516@reddit | sysadmin | View on Reddit | 64 comments

DFS and Entra/Autopilot

Posted by Callewalle@reddit | sysadmin | View on Reddit | 5 comments

I caught a notary in our office

Posted by TrainingOrchid516@reddit | sysadmin | View on Reddit | 64 comments

Previous-Low4715@reddit

You’re not really supposed to do any of this unless someone in HR asks you to. If they’re friends with management and you jeopardise their employment or out management in an impossible situation, you’ll come off badly if not worse than the person in question.

Question for the Mods About AI Slop Posts

Posted by Greg1010Greg@reddit | sysadmin | View on Reddit | 35 comments

How Do OEMs Create Factory Windows Images? Looking to Build a Clean Windows 11 Golden Image / Recovery Image

Posted by Cute_Ad_4906@reddit | sysadmin | View on Reddit | 38 comments

Previous-Low4715@reddit

Not really. It’s just another albatross around your neck. I sold the switch to autopilot to my security team (who were obsessed with getting “gold images” tested by a third party for no real reason) as a switch to “gold configs”.

Uninstall disabled Windows Defender or enable it for updates?

Posted by dirmhirn@reddit | sysadmin | View on Reddit | 41 comments

Barclays iPortal asking for Web Signer / signing software — is this normal?

Posted by yoldevam@reddit | sysadmin | View on Reddit | 9 comments

How Do OEMs Create Factory Windows Images? Looking to Build a Clean Windows 11 Golden Image / Recovery Image

Posted by Cute_Ad_4906@reddit | sysadmin | View on Reddit | 38 comments

Uninstall disabled Windows Defender or enable it for updates?

Posted by dirmhirn@reddit | sysadmin | View on Reddit | 41 comments

Previous-Low4715@reddit

Defender works with other antivirus solutions. Defender antivirus is just one component of defender. You can have windows defender running while sophos is the antivirus module for example

Lightweight Intune companion - thoughts ?

Posted by Sysadmin_in_the_Sun@reddit | sysadmin | View on Reddit | 8 comments

Begin browsing instantly: Chrome can now launch when Windows starts.

Posted by PowerShellGenius@reddit | sysadmin | View on Reddit | 97 comments

How do you keep track of all your company's SaaS subscriptions?

Posted by Absolute_Xero7@reddit | sysadmin | View on Reddit | 19 comments

Opinions on Tanium for patching, application and OS deployments?

Posted by ZachVIA@reddit | sysadmin | View on Reddit | 33 comments

Wallpaper to differentiate prod or non-prod server

Posted by deejay7@reddit | sysadmin | View on Reddit | 153 comments

Moving 15TB of SMB file shares to Google Drive — good idea or risky oversimplification?

Posted by MajoriteSilencieuse@reddit | sysadmin | View on Reddit | 44 comments

Moving 15TB of SMB file shares to Google Drive — good idea or risky oversimplification?

Posted by MajoriteSilencieuse@reddit | sysadmin | View on Reddit | 44 comments

Moving 15TB of SMB file shares to Google Drive — good idea or risky oversimplification?

Posted by MajoriteSilencieuse@reddit | sysadmin | View on Reddit | 44 comments

CTO banned the use of remote access tool

Posted by uw4yn3@reddit | sysadmin | View on Reddit | 533 comments

Previous-Low4715@reddit

Depends entirely upon a few key details like the organisational risk appetite and the current configuration of local user access. But this isn’t a technical problem, it’s either a communication breakdown or a genuine idiot making roles untenable, and it can’t be solved by a technical solution. If it’s one of those horror show situations we see on here occasionally where everyone has local admin access, that’s a massive security issue but also provides a technical route to adopt this ridiculous positioning. I’ve been management for a few years now but if I were still doing senior sysadmin, In his position I would simply get it in writing as published guidance. I’d support the customer until a UAC escalation prompt appears, then tell them no further support is available because of a new policy from named CTO and point them to the published guidance. Once you hit critical mass of enough customers unable to work, heads of department and line manager executives will solve the problem for OP through direct outside on the CTO. The key thing for OP is to get the guidance in writing and to have a product in mind when he’s very quickly asked to get one up and running. Most of intune premium suite is coming to E5 soon, so that might be an option. IF CTO is a career executive who has no technical knowledge he may genuinely not understand why you can’t simply cancel the remote support contract to save a few bucks. All OP can do is lay out very simply what can and can’t be done without a remote support tool, in writing, and escalate.

CTO banned the use of remote access tool

Posted by uw4yn3@reddit | sysadmin | View on Reddit | 533 comments

Why are developers some of the most IT inept users?

Posted by sccm_sometimes@reddit | sysadmin | View on Reddit | 782 comments

Previous-Low4715@reddit

Scientists are the worst, trust me. "I don't care if it's triggering 140 separate CVEs, I need to run this cobbled together Access database "app" on a Windows 95 VM on this unmanaged Windows 8 machine connected to the internal network because there's no other way to operate this bespoke machinery we paid half a million for 19 years ago and never maintained or bought support for, stop making my job difficult"

Question - How far do you generally go, to subdivide devices into groups?

Posted by Donkey_God-D@reddit | sysadmin | View on Reddit | 15 comments

Why is triaging such a hard problem for observability AI vendors?

Posted by Unfair-Carob-4890@reddit | sysadmin | View on Reddit | 17 comments

ChatGPT / Claude / Copilot?

Posted by piggelin-@reddit | sysadmin | View on Reddit | 54 comments

ChatGPT / Claude / Copilot?

Posted by piggelin-@reddit | sysadmin | View on Reddit | 54 comments

IT Asset Management system recommendations?

Posted by No-Room2990@reddit | sysadmin | View on Reddit | 155 comments

IT people: what can companies actually detect?

Posted by Fit_Balance_2221@reddit | sysadmin | View on Reddit | 43 comments

Previous-Low4715@reddit

We can see exactly where you are signing in from every time you sign into Microsoft 365, I’ve used it many times in HR investigations to prove or disprove claims made by or about employees. Just fill in the forms and get permission to work abroad or don’t work abroad.

Joined an IT team that probably needs better defined goals and organization and I want to help them and I need your suggestions

Posted by Nisaria@reddit | sysadmin | View on Reddit | 15 comments

Are people really piping internal logs into cloud AI tools now?

Posted by Iwanttoberich_8671@reddit | sysadmin | View on Reddit | 49 comments

Previous-Low4715@reddit

People are vibe coding crap either Claude and then thinking they can sell it. Alternatively they’ve being told by chatgpt and Gemini to do market research here.

So now I report to some kid, who was level 1 service desk 4 years ago

Posted by Mr_Kill3r@reddit | sysadmin | View on Reddit | 39 comments

Previous-Low4715@reddit

From post history it sounds like you don't have a very good attitude and haven't gotten out of the Dunning Kruger bell curve towards strategy, business systems analysis and enterprise architecture which typifies a lot of sysadmin attitudes.

Tooling & Architecture for Automated Article-to-Video Pipeline (Consistent Avatars & Audio Sync)?

Posted by spicy-detective@reddit | sysadmin | View on Reddit | 2 comments

How do you track IT events that are not support tickets?

Posted by Aim_Fire_Ready@reddit | sysadmin | View on Reddit | 96 comments

How to Learn Microsoft Active Directory from Basics?

Posted by Prestigious-Owl1391@reddit | sysadmin | View on Reddit | 33 comments

Previous-Low4715@reddit

I know, I have been administering Active Directory in on premise and hybrid environments for 20+ years and currently do it for a large gov org transitioning to cloud. There’s an awful lot more in terms of prospects by learning hybrid or fully Entra environments in 2026, especially for someone starting out in the field. On premise AD is a career dead end for the most part.

How to Learn Microsoft Active Directory from Basics?

Posted by Prestigious-Owl1391@reddit | sysadmin | View on Reddit | 33 comments

How long does it take you to diagnose a network issue when your monitoring tool isn’t showing you why?

Posted by MilesAndMaps15@reddit | sysadmin | View on Reddit | 47 comments

How to Learn Microsoft Active Directory from Basics?

Posted by Prestigious-Owl1391@reddit | sysadmin | View on Reddit | 33 comments

Intune devices new UI

Posted by The-Dude-01@reddit | sysadmin | View on Reddit | 21 comments

IT Ticketing System for a Small IT Team

Posted by Apocoflips@reddit | sysadmin | View on Reddit | 135 comments

ArcGIS infrastructure preference? Windows or Linux?

Posted by biggreen96@reddit | sysadmin | View on Reddit | 9 comments

SaaS tool to manage shared resources across offices

Posted by ptpilla@reddit | sysadmin | View on Reddit | 7 comments

Need help!! How to mitigate Microsoft Blocks

Posted by scottrichardson@reddit | sysadmin | View on Reddit | 47 comments

Migrate to Azure Files

Posted by SisterLakesMI@reddit | sysadmin | View on Reddit | 31 comments

I've built an IT service catalog that finally works (for me)

Posted by JonyMaster91@reddit | sysadmin | View on Reddit | 1 comments

Sysadmins - what's the last weird internal IT issue that ate an hour of your day? (researching an AI debugging tool, not selling)

Posted by darklLz5@reddit | sysadmin | View on Reddit | 7 comments

#noobquestion How to finally automate Windows Update for free?

Posted by Commercial-Fun2767@reddit | sysadmin | View on Reddit | 49 comments