Hi everyone, I'm looking for some guidance on what the recommended architecture is for SageMaker Unified Studio in an enterprise environment. Our current access model works roughly like this: Users request AWS access through our enterprise identity/access management process. Once approved, they receive an AWS application in Microsoft MyApps. Selecting that application signs them into the AWS Console. The problem is that everyone ultimately assumes the same highly privileged role in a shared AWS account. As a result, every user effectively shares the same environment. If User A creates resources (EC2 instances, SageMaker notebooks, S3 buckets, uploads datasets, etc.), User B can generally see or interact with them because they're operating with the same permissions. This obviously isn't ideal from a governance, security, or data privacy perspective. What we'd like instead is something along these lines: Each user has their own isolated SageMaker environment/workspace. We can control which datasets or S3 buckets each user can access. We can control which instance types or compute sizes users are allowed to launch. Different users or teams can have access to different projects without exposing everything to everyone. We'd still like to manage everything centrally rather than creating completely separate AWS accounts for every individual (unless that's actually considered best practice). For those of you running SageMaker Unified Studio (or even SageMaker Studio more generally) in an enterprise, how have you solved this? Thanks in advance! submitted by /u/DieLyn [link] [comments]
The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.
I've been curious how different teams approach this in practice. Imagine you're on call and something in production starts behaving differently. It's not immediately obvious whether it's a deployment, infrastructure change, configuration change, scaling event, cloud service issue, or something else. Once the alert fires, how do you actually answer questions like: What changed? When did it change? Was the change intentional? What's the fastest way to confirm the root cause? I'm less interested in the tools themselves (Terraform, Kubernetes, CloudTrail, Grafana, etc.) and more interested in the actual investigation workflow that experienced engineers follow. For example: Where do you usually look first? Which sources of truth do you trust the most? What part of the investigation tends to consume the most time? Are there still manual steps that you wish were easier? I'm trying to understand how this is handled in real production environments, especially at companies running on AWS/Kubernetes. Thanks in advance—I’m hoping to learn from people who've been through enough incidents to know what actually works. submitted by /u/Narrow_Power [link] [comments]
Slow TCP in one direction only on VPN
by NetAcademic9904
I have two sites, A and B - connected by a S2S IPSec VPN on gigabit links. Site A has a Fortigate 400E running latest v7.2. Site B has a Fortigate 120G running latest v7.6. Site B is able to line-rate on iPerf3 to A on TCP/UDP. Site A is able to line-rate on iPerf3 to B on UDP only. TCP is very slow (less than 1% of UDP). I have the same config on both sides. VPN interface(s) have tcp-mss set to 1418 on both sides. No profiles applied to impact performance. DH is 21 w/ AES256GCM-PRFSHA384 if it makes any difference. What am I missing here? Thanks, real head scratcher. submitted by /u/NetAcademic9904 [link] [comments]
MapiExceptionNetworkError: unable to make connection to the server
by Unlikely-Repair-8733
Need help with a starting direction to troubleshoot this error. At a new job managing an exchange server I do not have much info on. I just got access to creds/ docs today. The new user I created cannot access inbox via web url. OWA enabled, inbox pointing to DB file, DC1/DC2/Exch appear syncd. submitted by /u/Unlikely-Repair-8733 [link] [comments]
I am a SysAd at my Uni and I need to create a Win11 installation stick that is completely preconfigured. I do not have time to reinstall win11 and all its user configs/programs over and over again and my DAU colleagues need to be able to install win11 like that : Stick into PC, press enter a bunch, select user, everything works again. Every program, option and user password has to be as is atm on the prepared machine. I know I did this years ago for win10 when I was working in another branch of the Uni, but I can not remember how I did it. Something like bootstick + bootstick CMD = profit It has to be as easy as possible to install and maintain for ppl that are art students and profs that are 60+ and type with one finger. Any idea? I found some stuff on the net with Rufus, but I would argue that this is to "complicated" submitted by /u/elfricko [link] [comments]
VPN and MS365 Triggering IT Alert Only From iPadOS
by InKognetoh
I have a strange situation, if this is the wrong sub, feel free to remove it. I have a VPN on both my iPad and iPhone that my wife and I use for streaming services. She loves the K-Dramas and J-Dramas, so at night she uses my iPad. My iPad and work phone also both have the Outlook app that I have my work emails coming through w/ notifications. When my wife turns on the VPN on the iPad it triggers a ticket to my company’s IT security that there was an attempt to login to my work account from another country (she always chooses Japan). This does not occur when I turn on the VPN on my iPhone (I watch some of shows also). I have even went into the iPad and cleared Outlook and all MS365 apps from background, but sometimes it stills triggers a ticket to IT. This only started this year, and I have talked with IT about it, they took a look at both my devices and just told me to clear the apps logged into my work accounts from background before turning on the VPN. I don’t need to have Outlook on my iPad, but it is useful. We use a third party for IT services, so my company is charged for support and those tickets are being counted. I believe that I have push notifications enabled for both, but am at a loss as to why it happens on the iPadb, but not the iPhone. Both devices are updated, iPad is on iPadOS 26.6. Any help is much appreciated. submitted by /u/InKognetoh [link] [comments]
Windows 11 - Any confirmed working options for custom text on lockscreen/lockscreen background image?
by RightPassage
It doesn't seem to be possible to add easily modifiable custom text to the lockscreen anymore. We've used Desktop Info for that in the past but it doesn't seem to work with the lockscreen image in Windows 11, at least on current builds. Organizational Messages for Windows Spotlight also doesn't do that as far as we were able to test. Does anyone have any working options for this? Thanks very much in advance! submitted by /u/RightPassage [link] [comments]
Which one to learn first Azure or A.W.S ?
by Obvious_Fly_1046
submitted by /u/Obvious_Fly_1046 [link] [comments]
Enterpreneurs
by Important_Bid3319
Hi everyone Where can I find entrepreneurs who previously worked as system/network administrators and later started their own businesses in the same field? I would like to hear their experiences, how they made the transition, and any advice they could share... submitted by /u/Important_Bid3319 [link] [comments]
CIS benchmarks
by Traditional_Mousse97
Hello, Any ideas how to implement cis benchmarks across many Linux and windows servers(different distros and versions)? Are you using ansible to do so or any other configuration management tool? submitted by /u/Traditional_Mousse97 [link] [comments]
Cloud Billing Horror Stories?
by Notalabel_4566
Hello Folks I'm doing a small case study trying to understand what is it that generally leads to worst bills for different cloud services. Just want you guys to help out with the worst cloud bills you received? What triggered it ? Whose mistake was it? How do you generally handle such cases after that Did you set up anything to make sure this doesn't happen submitted by /u/Notalabel_4566 [link] [comments]
I work in IT and have a understanding of cloud VMs etc, but I do not fully understand a lot of the other services, e.g. cloud apps, App Services, containers, APIs, pipelines etc etc I am ideally looking for video course that explains at a high level all the main components of the cloud and how they work, any ideas? Advice appreciated :) submitted by /u/corpjones [link] [comments]
I'm writing this post with extreme frustration. I recently bought some Gemini API key credits using Google cloud billing UPI payment method. The money got deducted from my account but the credits are not loaded. So I reached out to their support, first of all their billing support team had no idea about UPI payment method and now they are saying that they are unable to track the payment. Like who told you to support UPI payment method if you can't track it's payment and how would a customer know all of this? I've submitted the bank account statement too. I never expected a google scale company get this low. submitted by /u/sh_ark [link] [comments]
where is the enterprise security stack heading in 2026?
by Illustrious_Bed_3214
From conversations with peers, the pattern seems to be: identity as the center of gravity (IdP plus conditional access), EDR as table stakes, and a growing browser security layer to cover the gap between endpoint and cloud that neither EDR nor CASB was really built for. SSPM is filling in around the edges now that SaaS sprawl is unavoidable. The GenAI piece is still unsettled, some add it to DLP, some use a dedicated AI gateway, and ownership varies. What's your org standardized on, and what's still an open question heading into H2? submitted by /u/Illustrious_Bed_3214 [link] [comments]
Thickheaded Thursday - July 30, 2026
by AutoModerator
Howdy, /r/sysadmin ! It's that time of the week, Thickheaded Thursday! This is a safe (mostly) judgement-free environment for all of your questions and stories, no matter how silly you think they are. Anybody can answer questions! My name is AutoModerator and I've taken over responsibility for posting these weekly threads so you don't have to worry about anything except your comments! submitted by /u/AutoModerator [link] [comments]
So I was previously head of IT of a company that was acquired by a large corporate in 2024. I have spent the last 2 years dealing with various integration projects, and then have been busy implementing Role based access and a new ITSM platform for the larger org. I am not enjoying the slowness and blockers of Corporate life, and generally being a small cog in a big machine - and have an interview next week at a 200 person startup. The recruiter I have been speaking with seems to think I am a good fit for the role - however he says "it's a shame that you've been at such a large Corporate during the AI Boom, as this company is quite far along with AI" He said I should start to think about things I would have wanted to implement if I'd stayed in my previous role and could get things implemented quickly. I'm looking for suggestions really of things folks at smaller startups / scaleups have implemented using AI that have really improved end user experience - We are obviously doing the AI thing too at the corporate level, but we have whole dedicated team for that. So i'm not as directly involved in the decision making process as I would have been otherwise if I'd stayed in Startup land. Any help would be appreciated! submitted by /u/Towelie888 [link] [comments]
One Mac window for SSH + RDP + serial console (built it because I was tired of three apps)
by Aromatic-Bottle5252
Managing Linux, a few Windows boxes and network gear from a Mac meant a terminal, RDP client and a serial app open at once. Noden puts them in one grid — saved connections, ProxyJump, RD Gateway, USB-to-serial with vendor baud presets (Cisco/Sophos/MikroTik/Aruba/Ubiquiti). Creds in Keychain, nothing on our servers. Free tier covers all four protocols. Curious what workflows I'm missing. submitted by /u/Aromatic-Bottle5252 [link] [comments]
Moving to a Linux environment
by I-Have-No-Life-146
Hey everyone I'm new as a sysadmin and my boss just gave me a new task. I'm IT for a small company with only about 30 employees and we want to switch from windows to all Linux. What distro do you recommend for the employees. I was thinking Ubuntu but thats mostly because thats what Im most familiar with. Also what do you recommend for managing the pcs. I was messing around with FreeIPA and ansable for that. Also most of the work they do is in a web browser but they would also like a way to collaborate on documents like in office365. I was thinking about using Nextcloud for this. Is this all a good idea? Are there other programs I should use? Any advice is appreciated. submitted by /u/I-Have-No-Life-146 [link] [comments]
Hi all, I've got a user on my tenant who has an AD (on-premise) account with an email address being : ******@mydomain.com with an smtp pointing to an external address from another tenant , let's say : ******@external.com. He is a mailUser on exchange (doesn't have a mailbox on our tenant, no e3 license, just mail-enabled : his email address is resolved and reaches to his external mailbox whenever someone sends his an email using ******@mydomain.com). Since yesterday, he was communicating with a third-party company (from a whole other tenant then) and the company in question was using the mydomain address to communicate with him. The problem now is that the emails from this company are not getting delivered. I've created a trace on exchange online to track the emails and these are the message events. The failure reason displayed is: Reason: [{LED=550 Administrative prohibition - envelope blocked - https://community.mimecast.com/docs/DOC-1369#550 [nyMds-WOM0Wfq7ynEsvxtQ.uk66]};{MSG=};{FQDN=eu-smtp-o365-outbound-2.mimecast.com};{IP=195.130.217.244};{LRT=7/29/2026 12:10:12 PM}]. OutboundProxyTargetIP: 195.130.217.244. OutboundProxyTargetHostName: eu-smtp-o365-outbound-2.mimecast.com. We do have mimecast in our system as an external layer (it's configured as : user | o365 | mimecast | outside) and mimecast says that this sender is blocked at policy level. The other users from our tenant are communicating fine with this external company and there is no policy preventing them from sending emails to the users in our tenant. My theory is that this comes from the external tenant in which he has his mailbox. I'm a bit confused, any thoughts on that? Many Thanks! submitted by /u/tfen_dep2 [link] [comments]
[Certification Thursday] Recently Certified? Post in here so we can congratulate you!
by AutoModerator
This is the only thread where you should post news about becoming certified. For everyone else, join us in celebrating the recent certifications!!! submitted by /u/AutoModerator [link] [comments]