CommPulse

CommPulse

1160 parked Settings

The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.

redditsysadminView on Reddit

I'm wondering what everyone's thoughts are on eol software that is perpetually licensed and whether the risk is minimal enough to run some programs that are eol? In this case I'm specifically referring to Bluebeam - we have a few users that use this program, and since we started using it they stopped offering perpetual licenses and switched to subscription only. We have licenses for a couple different versions as well as one user on the newest subscription option. Our oldest license is for Revu 17 which was eol in 2023. I suspect I'm going to be asked to shuffle it between workstations soon and trying to figure out whether its time for the conversation about purchasing a new license. I think their hesitation is that its used somewhat infrequently for specific tasks, so don't want to pay yearly for that. While not related to the situation that has me asking, I believe we also have a few older, spare machines which have older versions of Adobe. I may also end up running into this soon with Foxit perpetual licenses as we switched to them a couple years ago and they don't usually cover upgrade to the next major version. Any thoughts on how much risk older programs like these create, and how you deal with similar situations? submitted by /u/tr1ckd [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I'm the sole systems engineer for a small US manufacturer (~70 employees, automotive tier-1). I run everything across network, servers, identity, development, etc. I'd like (a) a sanity check, and (b) real talk about the future. What happened : About three weeks ago on a normal workday around noon, some people suddenly noticed that they weren't able to send or receive email. Shrug. Probably Outlook just being Outlook. But wasn't able to figure anything out, so took to the admin portal... But I couldn't even get in to the admin portal: AADSTS5000224: "the tenant you are trying to access has been deauthenticated and is no longer available." Man, I hope none of you ever have to feel the panic I felt when I read this message. I immediately went to try our breakglass unlicensed admin account, but received the same error. The very last email I received (which arrived after attempting these log-ins) was a notification that all of our subscriptions had been cancelled. Obviously, that was not an action I took. On further research it seems to be some sort of backend authorization state set by Microsoft (perhaps algorithmic automatic action in response to a detected security incident? - just blind speculation really). There is nothing client side to try at all. There is literally no admin path into our own tenant. Current status : 20 days down. The case has been passed between at least five different support people. It finally got "escalated to the product team to verify the tenant status," and for a week now the only updates I get are rolling "please allow an additional 48 hours." Meanwhile sign-in logs are on a retention clock, so the forensic record of who cancelled our subs (if anyone? maybe this cancellation is just an artifact of this deauth?) is about to age out while we're locked out of the only portal that could export it and Microsoft won't commit to preserving it server-side. That first day, I cut MX over to a temporary Fastmail tenant to keep email flowing. I was able to restore people's inboxes to these new accounts. Office apps are running in their month grace periods. All our real data is on-prem. Feeling very grateful that we deliberately never integrated more intensely with Microsoft's cloud services... To that end, the business is stable. But there are nevertheless many secondary effects as I'm sure you can all imagine. Okay, now that you know basically the story, it's time for some preemption so we just get it out of the way before I get to my actual questions: "You should have had MFA." We do, on every account. FIDO2- (yubikey) only for most accounts (I was literally mid rollout...) "You should have had CA." We do. Business Premium, Entra P1, CA policies in place, custom auth strength enforcing phishing-resistant (FIDO2) sign-in for admins. Plus all the standard: SMS auth killed off, SSPR locked down, legacy protocols (SMTP AUTH/POP/IMAP/ActiveSync) all disabled, external auto-forwarding blocked, Safe Links + Safe Attachments on, SPF/DKIM/DMARC all passing. "You should have a breakglass account." We do. Doesn't save you from this. "Hire an MSP" Okay, I mean, maybe fair? They'd just be in the same position though, so. If anything this is its own can of worms and there's a reason we don't have one. Alright. Now my questions: Has anyone actually lived through one of these AADSTS5000224 tenant deauthentications? How long did recovery really take, and what finally moved it? A specific support path, an escalation channel, a TAM, a Microsoft account rep, LinkedIn-ing a PM, a partner ticket? Anything? Were you able to discover what triggered the lockout in your case? How do you preserve/obtain audit/sign-in logs? I'm not sure what's going to happen in terms of retention when the tenant is in this state. Is our log data going to get nuked in a week? Trust. After this, how does anyone justify betting a company's ability to function on a platform where a backend flag can vaporize all access overnight, your breakglass account included, and the SLA to undo it is measured in weeks (and counting!) with no communication? I'm not naive enough to think "just leave M365" is free. But it's challenging to design around "Microsoft can turn us off and there's nothing you can do and no one will tell you why." How are you all handling that? Are you even? To be honest, I didn't know this was a thing that could even happen, really. So maybe you all didn't either. Thankfully we weren't super integrated. We basically use M365 for email, product licensing, and Teams, and that's about it. But it literally makes me shudder to think about what could have happened if it were otherwise. submitted by /u/SecaleOccidentale [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Backup Solutions

by Ok_SysAdmin

We currently have Veeam in a Hyper-v environment. I backup to a local host, as well as do cloud copy jobs. In the vain of 3-2-1 backup philosophy, I would like to setup an additional redundant backup solution and our old Veeam host hardware. The server is just setting there. What additional redundant backup solution would everyone recommend to run adjacent to Veeam? submitted by /u/Ok_SysAdmin [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Going from VMware to hyper V at the moment. But once I finalize this I want to implement hot patching for servers. Is there any way to do so without azure VMs? submitted by /u/h9xq [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Nasty bug

by possibilities69

Not affiliated or selling. https://www.aikido.dev/blog/axios-npm-compromised-maintainer-hijacked-rat submitted by /u/possibilities69 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

We use them sparingly for foriegn contractors rather than shipping them a corporate laptop -- so that's the only nice part. But in the few months we've been using them I've noticed the following: Slower than hell to provision, like really slow even with Microsoft's stock images... Doesn't play well with Intune even though it is an Intune native solution. Configs/Apps/Compliance are hit or miss compared to actual local hardware like a laptop. Some stuff just doesn't even load, or you have to reboot the machine constantly They suffer horribly from performance issues, if you don't reboot these things daily (which there's no option in the OS to do a restart) you have to do it from the Windows App or Intune which is dumb as hell. Resizing, I've pushed the resize in Intune, added a bigger license, removed the old smaller license and it's been almost an HOUR and its still just sitting in "pending". Other little things suck with these as well, yet Microsoft has pushed these things at Ignite the past 2-3 years like they are IT God's gift to customers. These things are absolute ASS. submitted by /u/Dtrain-14 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Az 900 guide

by N4Naman

submitted by /u/N4Naman [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Somehow, it's hard to comprehend the networking costs in AWS. People see instances and databases as 'real resources' but totally miss out on networking costs. The following account is spending $500 per month while not using AWS. All instances stopped, DB paused, but networking remains. Just flushing this all out to save 70%. https://preview.redd.it/mt0zuouv3dhh1.png?width=782&format=png&auto=webp&s=f6eb4b84219fa37124fe78ed35439753c4204c07 submitted by /u/skpratik [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

Been doing security audits for a while (I’m a secops engineer) and the same patterns keep showing up. Regardless of the vendor, so these are the same whether it’s Akamai, Cloudflare, AWS WAF. **1.** Origin is directly reachable! Traffic bypasses the CDN/WAF (check cert transparency logs for leaked origin hostnames) **2.** They've got bypass rules that were meant to be temporary but never got removed **3.** Cache key too broad (cache poisoning risk) or too narrow (kills hit ratio, looks like a DDoS) **4.** WAF rule sets are treated as “once and done”. Rules deployed once and never tuned, so there are a lot of silent false positives on real traffic. **5.** TLS/cert management with no clear owner, resulting in expired certs, weak ciphers left on etc. Wrote up a longer breakdown with a checklist if anyone wants to run through their own setup, happy to share. submitted by /u/witchlike-monkey [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

I spent way too long trying to fix something recently before realizing nothing was actually wrong. It turned out to be a configuration mistake that I had made myself. It got me wondering how much time people in ML and software spend debugging their own setups rather than actual code. What's the dumbest "bug" you've ever chased? submitted by /u/Crypton228 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

shipped an LLM feature, felt fine at launch, moved on to other work. a while later the bill showed up noticeably higher than expected and that was the first real signal anything had changed. no alert, no dashboard flag, just a number at the end of the month that made me go "wait, what happened." went back and actually set up proper tracing and token/cost monitoring per request instead of just trusting it'd be fine, and found a specific workflow was making way more calls than i thought due to a retry loop that wasn't being logged anywhere visible. it had been quietly running up cost for weeks with zero visibility until the invoice. also added latency budgets and caching for repeated queries after this, which cut cost noticeably on top of the retry fix. feels like a pretty basic devops instinct (you monitor what you ship, you don't wait for the bill) that somehow gets skipped constantly once "AI feature" is involved, like people ship LLM stuff with less observability discipline than they'd ever accept for a normal service. anyone else's team caught something similar the hard way before actually building proper monitoring in from the start submitted by /u/camerongreen95 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Azure Files

by DickBalczak

Anyone using Azure files for file shares for remote employees? I have seen horror stories in the past but saw some positive reviews on it recently. I am an Entra ID, cloud only shop and the new updates to the service look promising. submitted by /u/DickBalczak [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Yubikey Setup

by The_Ent1

So I'm wondering how people are registering Yubikeys for Microsoft tenant GA accounts that are cloud only. We don't login to a computer with those accounts and when I open up a browser to set up the key it wants to tie it to the device and the account in currently logged into the computer with. Is there a workaround? submitted by /u/The_Ent1 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Does anyone have recommendations for a replacement UPS. The company that I work for has two server rooms. In each server room there is a tower UPS unit that provides 120v/240v single phase power to the equipment in our server room. The UPS unit is no longer supported and the support that we had on the unites cannot get replacement parts (new or used). The power usage in our server room is currently using about 5kw. We would like to have about 30 minutes of backup to allow us to shut down our servers in case the building's generator fails to start. The buildings are in southwest Michigan; we are also looking at companies to provide support on the units also. submitted by /u/gizmo_202010 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Should we as admins just assume that once a system boots and seemingly all Data is restored that after a major security incident the system would work? Im talking about more or less complex systems that maybe communicate to a variety of other clients and servers maybe have an API etc etc. What is best practice here in big comapnies? just pray all the servers will work with each other after a major incident? submitted by /u/Lockenheada [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Hi all, Wanting to get some recommendations for a new precision screwdriver set for mainly laptop/desktop/server work. The one i have currently has been with us around 6 years, and it's about time to retire it, some tips are rusting a little, and most are a little bent/chewed up. It was one of the cheapest on amazon at the time, so genuinely surprised it lasted this long. Any recommendations for a kit that will stand the test of time. submitted by /u/WelcomeFun9037 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

https://github.com/jaredwray/cacheable/issues/1692 Many, many downstream packages affected, seems to be self-replicating. Be safe out there. The issues created by the reporter has previously been taken down, so likely to happen again with the above link. https://web.archive.org/web/20260804120723/https://github.com/jaredwray/cacheable/issues/1692 submitted by /u/mallalex [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Hi All, I'm currently testing Azure File Shares with ADDS Identity-based access. After a few issues, its now working well. However, I have just come across a user who cannot connect to the share. The user has CBA configured which I think is the cause. They repeatedly get username and password errors. If I run klist, I get the following error. klist get cifs/testshare.file.core.windows.net Error calling API LsaCallAuthenticationPackage (GetTicket substatus): 0x6fb klist failed with 0xc000018b/-1073741429: The SAM database on the Windows Server does not have a computer account for this workstation trust relationship. So it looks like the user is not getting any Kerberos tickets. Has anyone else come across this before? submitted by /u/No-Pack8932 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Hi, I'm pretty new to Kinesis and I can't find a definite answer to this. When does it make sense to use Firehose on its own vs using it in combination with MSK or Data Streams? It is my understanding that Firehose allows for high data troughput on its own, so in which case does it make sense to manage Data Stream shards and incur potentially more costs while Firehose can be used directly? Should Data Steam / MSK only be used when the Firehose throughput limitations are exceeded? Thanks submitted by /u/JustBeLikeAndre [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X