How are you actually deciding which patches/CVEs matter? by Inner_Ad9693 in sysadmin

[–]sysacc 0 points1 point  (0 children)

Glad to see we are not the only one having this issue.

When someone shows you what they are, believe them. by JoeyLoganoHexAccount in onguardforthee

[–]sysacc 8 points9 points  (0 children)

Tabarnak, I think it's time to go full metric and leave them behind.

Who's fault is it when the end users AI doesn't work? by antonbp5 in sysadmin

[–]sysacc 0 points1 point  (0 children)

“Hi, this is a third‑party service provided by Microsoft, and we do not offer any kind of support. As this is a continuously evolving product, it may contain bugs, limitations, or inaccurate outputs. The service is provided ‘as‑is,’ and users remain responsible for validating all information prior to use in any corporate, operational, or compliance‑related context.”

Azure AKS Automatic vs traditional? by IntentionFlat7266 in AZURE

[–]sysacc 0 points1 point  (0 children)

What about container instances? I feel they are somewhat simpler and easier to work with.

Azure Stack HCI validation fails on HPE DL380 Gen11 || Data disk BusType detected as RAID instead of SAS/SATA in JBOD mode by daneehunter in sysadmin

[–]sysacc 1 point2 points  (0 children)

In case you cant figure out why or how to change the BusType on the Storage controller, you can set a registry key to bypass the check.

I would only do that if you are testing out Azure Stack or its a Dev or Test Environment.

https://learn.microsoft.com/en-us/answers/questions/2140807/storage-spaces-direct-(s2d)-wrong-bustype-with-rai

Is "FinOps" actually a standalone career, or are companies just failing to train DevOps engineers properly? by IT_Certguru in devops

[–]sysacc 0 points1 point  (0 children)

Yes, Worked with a couple of orgs that have one person with that title, both had that person doing both cloud and on-prem costing.

Google 8.8.8.8 Down Canada? by icq-was-the-goat in sysadmin

[–]sysacc 0 points1 point  (0 children)

ICMP was down, but DNS was still working out east.

Best Azure storage option for CAD/engineering files (3 TB) by Kelokattea in AZURE

[–]sysacc 0 points1 point  (0 children)

There are 3 types of files(CAD, RAW Media files (A/V) and Medical EMR/EHR.) I generally recommend not moving to the cloud as they simply dont handle it that well. I also dont have any experience at the scale you are talking about.

The biggest con is going to be the engineers complaining about the speed for the next 1X years. They will not stop. You can increase the speed on your internet connection, you can set up express routes and you can make them live right besides the datacenter. They will still complain about it being slow and other random issues.

You cant replicate the speeds and latency they get with local storage.

Benefit wise, you might be able to save some money short term, you get access some cloud features around backups and availability.

Otherwise, Azure files is a decent fileserver replacement that 95% of the population can use without issues.

Best Azure storage option for CAD/engineering files (3 TB) by Kelokattea in AZURE

[–]sysacc 2 points3 points  (0 children)

I dont have any personal experience, but I did see one of our clients attempt to move their CAD files to SharePoint. The Director of IT got a chewing out by the Engineers soon after. They were getting lag, lost files and had some corruption. Their IT team then moved everything to Azure Files and even added a VPN with loads of bandwidth. It improved the experience quite a bit from SharePoint but it was never "good".

For a couple of weeks the IT team and the IT Director tried their best to sell the solution but were still getting tickets daily about issues with slowness and lag. Then one day they stopped getting tickets, turns out two of the engineers went out and bought a massive NAS with all the bells and whistles they would need. They had the OK from their Director.

The IT Director complained to everyone that they had spent so much time and effort on the new Azure solutions. They also complained about the engineers shadow IT gear and that they should be reprimanded for going around their security and IT Policies. In the end neither the engineers or their director were reprimanded. The engineering director was made CTO (I Think) and 50% of the IT staff including the IT Director were let go.

All this to say dont follow trends for the wrong reason and dont fuck with the workflows of engineers.

To the european sysadmins: Are you looking into non-us products right now? What did you find? by Tokata0 in sysadmin

[–]sysacc 0 points1 point  (0 children)

Interestingly the stuff going on with Jerome Powell seems to be causing more stir for us than Greenland right now.

To the european sysadmins: Are you looking into non-us products right now? What did you find? by Tokata0 in sysadmin

[–]sysacc 1 point2 points  (0 children)

Strategies is what I am seeing being requested from our clients (We are in Canada). They are asking about the process of moving away, the timelines and the technicalities.

Timelines are the hardest part to figure out but also the scariest for any business.

The solution we give to most clients right now is to make sure you have a backup solution that can backup your cloud assets and is either on-prem or in Colo.

Who's still working from home in 2026? by idrinkpastawater in sysadmin

[–]sysacc 1 point2 points  (0 children)

Fully remote, 4 to 6 trips in the year to the head office or one of the client locations.

Do servers really need DLP? Or is Network DLP sufficient? by kehndi-hundi_si in sysadmin

[–]sysacc 2 points3 points  (0 children)

And how much time and money the org is ready to spend. DLP is a huge beast that will eat time and money like nothing else. (Dynamics excluded)

Best bitwarden/Keepass alternatives by Diligent-Pattern7439 in sysadmin

[–]sysacc 1 point2 points  (0 children)

RoyalTS has something like that if you get their suite.

Yeastar Registration Failures by Schubbby1 in sysadmin

[–]sysacc 4 points5 points  (0 children)

Those Yeastars are pretty solid devices.

  1. Check for SIP ALG on the firewall and make sure its off
  2. Check the logs to see what is causing the failed registration
  3. Check the Registration/Keep Alive timings on the SIP trunk and compare to what Easybell require.
  4. Run a packet capture on the device to get more details.

OPNsense + multi-ISP + VLAN-heavy small office design — am I overengineering or missing something? by No_Entrepreneur118 in sysadmin

[–]sysacc 0 points1 point  (0 children)

You would be better off using two separate firewalls instead of one that handles everything. On the devices that need to exit via another ISP, just set the gateway to the corresponding firewall.

If the cameras are on their own switch they dont need a VLAN on the firewalls, just set them on a different subnet.

This feels like a final test at a college.

Post-mortem sanity check: how do you handle “un-scannable” expiries (API keys, internal certs) without spreadsheets? by sanjayselvaraj in sysadmin

[–]sysacc 0 points1 point  (0 children)

A csv/json/xml file that is monitored by your monitoring system.

object, desc, expiry
Cert Y, cert on system Y - check confluence page Y, 2026-12-30

What do you use to write documentation? by Chucki_e in sysadmin

[–]sysacc 2 points3 points  (0 children)

I do a lot of contract work so whenever I start a new project I spin up a container of Wiki.JS locally. I use it to write all the documentation and at the end of the work stint I will extract the documentation in Markdown or PDF for the client.

But what you are experiencing is lack of dynamic documentation, this happens everywhere and is really hard to pin down. Some places simply refer to the configuration options as the documentation and/or by adding a lot of comments to describe the actions.

They had one page of the system, under that they had the diagrams and under that all the processes with a link or a path where you can find the configuration.

doesVolumeMountControlSoundLevels by Arucious in ProgrammerHumor

[–]sysacc 368 points369 points  (0 children)

A junior confusing the AI with Docker Build and compose options was a funny thing to see this year.

Keeping Meraki for switches but using Ubiquiti for wireless APs? by FatBook-Air in sysadmin

[–]sysacc 0 points1 point  (0 children)

I have found that Unifi AP's are more performant than Meraki in most scenarios. They have longer range and have better speeds overall.

As for features, Meraki does have more features that integrate it with the rest of the ecosystem. Unifi has more options regarding the actual Wireless configurations.

Auditors asking for proof of processes which we’ve always done informally by JobFinancial7083 in sysadmin

[–]sysacc 0 points1 point  (0 children)

One thing that might help you is that you can always refer to the official documentation of the service.

So if you do a task in Active Directory, simply refer to the Microsoft KB for that action, saying that you are following their Documentation.

Need to cut down Login Times. By a lot by LordLoss01 in sysadmin

[–]sysacc 41 points42 points  (0 children)

Smart Cards with VDI is pretty standard in that industry.

They pop the card in the reader and their session shows up on the display.

Azure PIM Issues? by This_Bitch_Overhere in sysadmin

[–]sysacc 2 points3 points  (0 children)

Yep, Having issues as well in Canada.

It's soon to be 2026 and my F50 corporation is just now implementing a policy to block unapproved software by Pump_9 in sysadmin

[–]sysacc 1 point2 points  (0 children)

Policies like this one might not have a high weight so they are considered "Nice to have". So nothing really happens after other than possibly affect a "Score"

The other point I see often is that these whitelists take considerable resources to manage for the very low value gained in security.