PODCAST · technology
SysAdmin Weekly
by Andy Syrewicze and Eric Siron
Welcome to the SysAdmin Weekly Podcast, your go-to source for IT-related content tailored to busy system administrators in the trenches. Hosted by longtime sysadmins and Microsoft MVPs Andy Syrewicze and Eric Siron, this show dives deep into the challenges and solutions that matter most to sysadmins on any given day. From technical know-how to real-world insights, SysAdmin Weekly is dedicated to those tireless professionals who keep our digital world running. Tune in for relevant topics, expert advice, and engaging discussions to make your busy schedule a little bit easier.
-
60
059 - How Should SysAdmins Handle Remote Access in 2026?
Which protocol you use to reach the box is the least interesting decision you will make about remote access.Andy Syrewicze and Eric Siron go after the piece they cut from the tools episode. Eric lands the sharpest version half an hour in: what you are actually doing is moving from one-sided authentication to mutual authentication. Around that sit overlay networks against the VPN concentrator, the RMM console as the most attractive target in an MSP estate, the outbound tunnel nobody watches for, and whether just-in-time access holds up at 3am with something down and nobody awake to approve it.Chapters:00:00:00 - Cold Open: Remote Access Gets Its Own Episode00:01:20 - Welcome and Show Plugs00:04:16 - News React: Anthropic Safety Researcher Resigns00:12:54 - News React: Broadcom Pulls Public VDDK Access00:16:21 - Nerd Hour: Eric's Hugo Migration00:17:24 - Three Gates Against a Runaway API Bill00:20:38 - Main Topic: The Tooling Is the Small Part00:23:08 - SSH on 22, and the Port Change Experiment00:24:21 - Name a Reason to Expose a Management Port00:27:10 - Overlay Networks, Tailscale, and WireGuard00:29:31 - Eric: This Is About Mutual Authentication00:32:20 - RMM Tools and the Central Console Problem00:33:41 - Do You Need Remote Management All the Time?00:34:36 - Just Enough Administration Meets Just in Time00:36:00 - Eric: I Attack the Endpoint, Not the Protocol00:40:16 - Risk Assessment Is a SysAdmin Skill00:42:47 - The Firewall Is Also the VPN, and Fortinet00:45:17 - Outbound Access, Attacker's Side00:47:32 - Is Anyone Watching Outbound Traffic?00:50:52 - The 3am Phone Call00:52:46 - Eric: MFA Everything, No Remember Me00:55:44 - PAM, PIM, and Where to Read Up00:56:14 - Nothing Revokes Itself Unless You Build It00:58:13 - Key Takeaways: Never Rely on One Control00:59:40 - Access Should Be Ephemeral01:01:46 - Risk Profiles: Tomcat vs Medical Records01:03:52 - The Tools: Tailscale, SSH, Remmina01:07:56 - Eric's Kit: PuTTY, WinSCP, rsync01:11:17 - Do This Monday01:13:52 - Wrap Up and OutroResources / Show Notes:- NBC News, Anthropic researcher Jacob Coxon resigns: https://www.nbcnews.com/tech/tech-news/anthropic-safety-researcher-resigned-warning-rapid-ai-development-gamb-rcna596767- RentAHuman, where AI agents hire people for real world tasks: https://rentahuman.ai- Brandon Lee (vExpert), Broadcom pulled public VDDK access: https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/- CISA, hardening Fortinet devices after credential exposure: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure- Microsoft Learn, Entra PIM, eligible versus active access: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure- Tailscale, free Personal plan covers 6 users: https://tailscale.com/pricing- WireGuard, what Tailscale manages under the hood: https://www.wireguard.com- Cisco Duo, free tier for teams of 10 or fewer: https://duo.com- Remmina, open source RDP, VNC and SSH client: https://remmina.org- PuTTY: https://www.chiark.greenend.org.uk/~sgtatham/putty/- WinSCP: https://winscp.net- SysAdmin Weekly: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
-
59
058 - What Tools Do SysAdmins Actually Use Every Day?
The tools that stay in the kit for a decade are the ones that still work when the network, the domain, or the boot volume is the thing that broke.Andy Syrewicze and Eric Siron open their real toolboxes and argue about what earns permanent residency. nmap and Wireshark for what is actually on the wire, Sysinternals for what a box is really doing, GParted and SystemRescue for the volume that will not mount, and the chkdsk, DISM, then SFC sequence Eric can run in his sleep. Andy's list skews hard toward triage because MSP work meant walking into a stranger's burning network every week. Remote access is missing on purpose; RDP, SSH, and overlay networks are getting their own episode.Chapters:00:00:00 - Cold Open: The Tools That Save Your Bacon00:01:13 - Welcome and Show Plugs00:03:11 - News React: Anthropic's Enterprise Frontier Safeguards00:07:01 - News React: The US Goes Openly Offensive in Cyber00:12:57 - Nerd Hour: CC Top and a Pomodoro Timer That Remembers00:15:53 - What Earns a Permanent Spot in the Toolbox00:17:32 - Why MSP Years Produce a Triage Kit00:20:13 - nmap, and the Licensed Cisco Utility Story00:22:31 - Sysinternals and Process Monitor00:23:16 - Wireshark Past the Basics00:24:09 - netstat and nslookup Are Not Wizardry00:25:12 - dig, and Why ping Is Not a DNS Tool00:27:22 - Test-NetConnection Instead of ping00:27:59 - Why Anyone Blocks ICMP in the First Place00:30:11 - MXToolbox, PingPlotter, and the Neighbor's Air Conditioner00:33:18 - GParted, SystemRescue, and the Live CD Shelf00:35:58 - chkdsk, DISM, then SFC, in That Order00:38:06 - DBAN and Decommissioning Disks00:40:51 - The Multi-Pass Wipe Myth00:43:25 - Greenshot and Capture Last Region00:46:07 - Spectacle, Client Hypervisors, Docker and Podman00:47:33 - Get-Help and man: Nobody Remembers Syntax00:48:28 - OpenSSL, Qualys SSL Labs, and testssl.sh00:50:13 - WSL as the Whole Toolbox00:51:37 - The Everyday List: Vim, Bitwarden, Git, Package Managers00:54:20 - Remote Access Gets Its Own Episode00:55:30 - The Platform Tax After Leaving Windows00:58:18 - Edge on WSL on Windows, for Certificate Chains01:01:02 - Do This Monday01:03:31 - Eric's Advice: Go Look for the Tool01:04:37 - Wrap Up and OutroResources / Show Notes:- Anthropic, Developing Enterprise Frontier Safeguards: https://www.anthropic.com/news/enterprise-frontier-safeguards- Nmap: https://nmap.org/- Wireshark: https://www.wireshark.org/- Microsoft Sysinternals, and Sysinternals Live: https://learn.microsoft.com/en-us/sysinternals/- MXToolbox, external DNS and blacklist checks: https://mxtoolbox.com/- PingPlotter, latency and packet loss per hop: https://www.pingplotter.com/- GParted, and the live image: https://gparted.org/- SystemRescue: https://www.system-rescue.org/- DBAN, still there, spinning disk era, not for SSDs: https://sourceforge.net/projects/dban/- Greenshot, Windows only: https://getgreenshot.org/- Qualys SSL Labs, tick the box to stay off the public board: https://www.ssllabs.com/ssltest/- testssl.sh, for internal sites: https://testssl.sh/- DevToys, clipboard certificate parser: https://devtoys.app/- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, what is in your toolbox: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
-
58
057 - Is Your Air Gap Actually an Air Gap? Port 22 Says No
Somewhere inside that isolated network, port 22 is open, and it has been open since the outage six months ago that nobody wrote up.Andy Syrewicze and Eric Siron take apart a term the industry uses constantly and almost never earns. They walk the management plane hole by hole: SSH and RDP so somebody can patch the thing, SMB for the files that have to move, DNS and NTP because nothing works without them, and the iDRAC, iLO, and IPMI boards that get parked on the management VLAN and then never patched at all. The argument they land on is not that a real air gap is impossible, it is that calling something an air gap ends the conversation, and a promise nobody re-verifies is worse than a risk everybody can see.Chapters:00:00:00 - Cold Open: Your Air Gap Probably Is Not an Air Gap00:01:12 - Welcome and Show Plugs00:04:19 - News React: An AirTag, a Rare Book, and an Amazon Scanning Facility00:10:10 - News React: Bill Gates Changes His Mind on AI and Jobs00:13:03 - What the Entry Level Job Market Looks Like Right Now00:15:05 - When Nobody Is Left Who Knows How to Program It00:19:25 - Nerd Hour: Claude Code, Agents, and Building CC Top00:23:54 - Nerd Hour: Moving Project Runspace to Hugo, JavaScript Free00:28:22 - What an Air Gap Actually Means00:31:22 - Logical, Network, Virtual: How the Word Got Laundered00:32:36 - Every Hole You Poke Just to Manage the Thing00:34:18 - The One Nobody Segments: iDRAC, iLO, and IPMI00:36:26 - A Brief and Deserved Detour About Printers00:37:23 - NTP, DNS, License Activation, and Telemetry00:40:34 - Why Leaving Hyper-V Out of the Domain Is Not Security00:43:16 - VLANs, Switch Fabric, and Breakout Attacks00:44:40 - Assume Breach: Zero Trust, JIT, and JEA00:50:36 - Sneaker Net and Poisoned USB Drives00:52:20 - Stuxnet and the Gap That Was Real00:54:59 - How Would You Even Safely Clean a USB Drive?00:56:58 - Say What You Have, Then Defend It00:57:29 - The Real Danger Is the False Sense of Security01:00:23 - The Windows Firewall Lesson01:03:11 - What a Genuine Air Gap Actually Costs01:04:59 - Wrap Up and OutroResources / Show Notes:- Symantec Security Response, W32.Stuxnet Dossier, the canonical technical analysis: https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en- Ralph Langner, To Kill a Centrifuge, on why post-Stuxnet air gap strategies miss the point: https://www.cs.yale.edu/homes/jf/Langner.pdf- The 2008 USB breach of US military networks, Agent.btz and Operation Buckshot Yankee: https://en.wikipedia.org/wiki/2008_malware_infection_of_the_United_States_Department_of_Defense- Microsoft Security Advisory 967940, the update that killed USB AutoRun: https://learn.microsoft.com/en-us/security-updates/securityadvisories/2009/967940- NIST SP 800-82 Rev. 3, Guide to Operational Technology Security, for naming what you actually have: https://csrc.nist.gov/pubs/sp/800/82/r3/final- 404 Media, tracking a shipment of rare books to an Amazon AI training facility: https://www.404media.co/we-tracked-a-shipment-of-rare-books-it-ended-at-an-amazon-ai-training-facility/- Semafor, Bill Gates has changed his mind about AI and jobs: https://www.semafor.com/article/08/25/2026/this-is-crazy-this-is-insane-bill-gates-has-changed-his-mind-about-ai-and-jobsGates Notes, the essay itself: The turbulent AI era is here: https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, tell us about your air gap and why you have one: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
-
57
056 - How People Actually Get Into SysAdmin Work
Two careers, two completely different entry points, and the exact same first catastrophe: data gone, no idea if it was coming back.Andy Syrewicze and Eric Siron trade full origin stories, from the 486 and the VIC-20 through the first paid tech jobs neither of them was qualified for. They get specific about the failures that rewired how they work, the mentor advice that still holds up decades later, the advice that aged badly, and the question underneath all of it: the on-ramp that produced both of them was cheap hardware, full access, and time to break things, and most of that is gone. Whether that actually matters for anyone starting in 2026 is the argument they finish on.Chapters:00:00:00 - Cold Open: How We Actually Got Into IT00:01:01 - Welcome, Show Plugs, and Why There Was a Gap00:05:03 - News React: Meta Goes Open Source Again With Muse Glimmer00:07:55 - News React: Lithium Battery Farms, Data Centers, and Zoning Boards00:16:39 - Nerd Hour: A Black Hat Demo on Local LLMs and M365 Spear Phishing00:19:34 - Nerd Hour: Fish Tape, a Whole House Vacuum, and a 160 Degree Attic00:24:51 - The Stuff We Broke Before Anyone Paid Us00:26:31 - Andy: The 486, the Matrix Boot Screen, and Getting Told to Change It Back00:30:41 - Eric: The VIC-20, a Xerox 286, and Overclocking With a Box Fan00:37:53 - Andy's First IT Job: A K-12 Summer Gig and 30 Cables a Foot Short00:44:05 - Eric's First IT Job: Freight Dock to Phone Support00:49:14 - Would Either of These Paths Still Get You Hired Today?00:56:02 - Andy Nukes the Application Share and Prays at a Tape Drive01:00:11 - Eric's Version: Dad, I Deleted All Your Files01:02:46 - Why Almost Every SysAdmin's First Disaster Involves Data01:04:21 - Advice That Held Up: The Key to IT Is Laziness01:10:06 - Being Decent Beats Being Smart, and Learning to Say I Don't Know01:15:01 - Advice That Aged Badly: Always, Never, and Best Practice01:17:31 - Nobody Ever Got Fired for Buying IBM01:23:02 - Does This On-Ramp Still Exist in 2026?01:26:07 - You Do Not Need Commercial Gear to Learn This01:27:56 - Wrap Up and OutroResources / Show Notes:- VentureBeat - Meta returns to open source with Muse Glimmer: https://venturebeat.com/technology/meta-returns-to-open-source-with-muse-glimmer-an-apache-2-0-licensed-30b-parameter-ai-model-optimized-for-agents-available-now- MultiState - Federal AI data center policy meets resistance from state lawmakers: https://www.multistate.us/insider/2026/4/14/federal-ai-data-center-policy-meets-resistance-from-state-lawmakers- Black Hat official YouTube, where the USA 2026 Briefings recordings post: https://www.youtube.com/@BlackHatOfficialYT- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, tell us your first broke something moment: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
-
56
055 - How Do You Run IT With No Budget?
"No budget" is almost never no budget. It is no budget yet, and the thing that closes the gap is your ability to put a real dollar figure on the risk you are carrying.Andy Syrewicze and Eric Siron have both run IT for organizations where getting the credit card out meant you had done something wrong. They walk through what that actually looks like: a PC DOS 4 machine still passing parts in a quality lab, an end of life Cisco ASA swapped for an open source firewall on scavenged workstations, NetGear ReadyNAS units kept on a shelf for SAN emergencies, and the iSCSI arguments that never die. Then the harder part: where the first dollar goes when budget finally shows up, and how to translate aging gear into risk language that a business owner will actually fund.Chapters:00:00:00 - Cold Open: Keeping the Lights On With No Budget00:01:00 - Welcome and Show Plugs00:03:32 - News React: 25 Companies Sign On for Open Weight Models00:07:51 - News React: OpenAI, Profitability, and the Missing CFO00:12:56 - Nerd Hour: A Baldur's Gate Randomizer on GitHub Pages00:16:02 - Nerd Hour: Unicode, MiniForge, and Why the Human Said No00:20:51 - Community Comments: Cable Pulls and Fat WIM Files00:24:34 - The Reality of the Zero Budget Shop00:29:56 - End of Life Cisco ASA to an Open Source Firewall00:34:04 - You Do Not Have to Buy Cisco00:40:00 - Where Open Source Wins: Monitoring, Logging, Nmap00:43:35 - Budget Storage: NAS Stopgaps and the iSCSI Argument00:51:31 - Spending the First Dollar on Maximum Risk Reduction00:52:44 - Backups: The One Place Not to Go Free00:57:02 - No Budget Usually Means No Budget Yet01:01:40 - Document the Risk, Get the Decision in Writing01:03:40 - Wrap Up and OutroResources / Show Notes:- Microsoft - Open Weights and American AI Leadership, the letter itself: https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/- TechCrunch - Industry urges against broad open-weight restrictions: https://techcrunch.com/2026/07/24/as-us-weighs-response-to-chinese-ai-industry-urges-against-broad-open-weight-restrictions/- Fortune - OpenAI CFO reportedly at odds with Altman over spending: https://fortune.com/2026/04/28/openai-cfo-sam-altman-missed-revenue-target/- Andy's Infinity Engine party randomizer, the Nerd Hour web app: https://asyrewicze.github.io/infinity-engine-randomizers/- PomoCLI, Andy's terminal Pomodoro timer: https://github.com/asyrewicze/pomocli- Miniforge, the package manager Andy declined to add as a dependency: https://github.com/conda-forge/miniforge- OPNsense, open source firewall: https://opnsense.org/- pfSense, open source firewall: https://www.pfsense.org/- Nagios, open source monitoring: https://www.nagios.org/- Nmap, free network scanner: https://nmap.org/- Restic, fast secure backup program: https://restic.net/- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, share your no budget stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussionsSources and clarifications (News React):- The open weights letter had 25 signatories on July 24, 2026. OpenAI and Google were absent that day and signed by July 26; the list has since passed 270. Anthropic has not signed.- Eric flagged the Sam Altman "no path to profitability" clip as possibly a deep fake, and we could not verify that specific video. The underlying reporting on OpenAI's CFO and spending tension is real; see the Fortune link above.
-
55
054 - Windows Admin Center in 2026: Good Tool, Broken On-Ramp?
Windows Admin Center is a genuinely useful tool wrapped in an on-ramp so rough it took Andy four hours, a from-scratch certificate authority, and a pile of misleading error messages just to reach the login screen.Andy rebuilt his lab on an all-Core Windows Server 2025 fleet, set out to manage it from a browser the way Microsoft keeps telling us to, and hit a certificate wall that most SysAdmins would never fight through. He and Eric Siron walk the full gauntlet: the 60-day self-signed cert trap, an ERROR_DS_RANGE_CONSTRAINT that pointed the wrong way, a web server template that blocks computer requests, a silent blank SAN that kills the HTTPS binding, and the bigger question of whether a web tool is even the right way to manage Windows. Along the way: a News React on open-source AI, China, and a possible federal clampdown, plus the domain-join debate that never dies.Chapters:00:00:00 - Cold Open: Four Hours to Install a Free Tool00:01:15 - Welcome and Show Plugs00:03:52 - News React: Apple, the EU, and the Walled Garden00:08:55 - News React: Open-Source AI, China, and a Possible Federal Clampdown00:16:00 - Nerd Hour: Ripping Out KVM, Putting Hyper-V Back00:18:55 - Setting the Scene: An All-Core Lab and the Certificate Wall00:30:08 - The Four-Hour Gauntlet: A Sequence of Failures00:44:00 - What WAC Gets Right, and Where It Falls Down00:59:24 - Azure Arc and the Real Agenda01:07:45 - Does WAC Move the Needle? The VerdictResources / Show Notes:- Microsoft - Windows Admin Center overview: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/overview- Hornetsecurity (Eric Siron) - Public Key Infrastructure explained, including why to stop using self-signed certificates: https://www.hornetsecurity.com/en/blog/public-key-infrastructure/Sources and clarifications (News React / AI segment):We referenced several press claims from memory during the AI segment. The claims hold up, but a few were under-attributed on air, so here is the precise record.- Moonshot AI - Kimi K3, the open-weight model released the week before we recorded that benchmarks near frontier US models. The whole news cycle is downstream of it: https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems- Dean Ball, OpenAI's Head of Strategic Futures and a former senior AI adviser in the Trump administration, is the source of the "AI communism" line, in a post on X. On air Andy first said "CEO of Claude" and "CEO of Anthropic," then corrected to "someone from OpenAI." The correct attribution is Ball at OpenAI, NOT Anthropic. Naming note: Claude is the model, Anthropic is the company: https://x.com/deanwball/status/2078133895766114412- Dean Ball - follow-up clarifying he was predicting that outcome, not advocating for it: https://x.com/deanwball/status/2078619513575137330- Axios (July 20, 2026) - the federal-action angle. Frame it as reportedly under consideration; no formal policy has been proposed. Mechanisms discussed include Commerce Entity List additions, security advisories, and federal procurement rules: https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi- David Sacks, former White House AI adviser, publicly argued that closed labs want the government to eliminate their open-source competition, in a post on X: https://x.com/DavidSacks/status/2078826291638522127- Dario Amodei has called open-source AI a dangerous path; the source quotes are collected in this r/Anthropic thread: https://www.reddit.com/r/Anthropic/comments/1ui759l/amodei_says_open_source_is_dangerous/
-
54
053 - How to Survive as a Solo SysAdmin: Where to Start When You're the Only One
When you are the only person standing between a working business and total collapse, the job stops being about doing everything and starts being about deciding what not to do this week.Andy and Eric Siron tackle a listener-requested topic: you just became the solo SysAdmin, whether by hire, downsizing, or promotion, and now you own the firewall, the servers, the backups, and the printer nobody wants to replace. This one is heavy on the career and survival skills that keep a team of one sane: triage before projects, documentation as an insurance policy, buying time back through automation and managed services, and speaking business value instead of acronyms to leadership. Plus a News React on Windows Server hot patching and 1Password for Claude, and a Nerd Hour on Debian 13.6 Secure Boot certs and SAML auth for Nagios.Chapters:00:00:00 - You're the Only SysAdmin. Now What?00:01:02 - Welcome and Show Plugs00:05:13 - News React: Windows Server Hot Patching via Azure Arc00:11:00 - News React: 1Password for Claude and AI Guardrails00:13:50 - Nerd Hour: Debian 13.6 and Secure Boot Certificate Updates00:16:33 - Nerd Hour: SAML Auth for Nagios via ADFS00:23:20 - Main Topic: The Case of the Solo SysAdmin00:28:23 - Triage Before Projects00:30:57 - Note-Taking Systems: ARC, Bullet Journal, Rocketbook00:46:40 - Documentation Is Survival and the Hit-By-A-Bus List00:50:25 - Greenshot and Fast Screenshot Documentation00:54:14 - Buying Time Back: Automation00:58:16 - Buying Time Back: Managed Services01:03:44 - Communicating Business Value to Leadership01:09:09 - Managing and Documenting Risk01:10:17 - Wrap-UpResources / Show Notes:- MacRumors - 1Password for Claude lets AI log in without seeing your passwords: https://www.macrumors.com/2026/07/16/1password-claude-integration/- Microsoft Learn - Enable Hotpatch for Azure Arc-enabled servers (now free for Windows Server 2025): https://learn.microsoft.com/en-us/windows-server/get-started/enable-hotpatch-azure-arc-enabled-servers- Debian - 13.6 release notes and Secure Boot CA guidance: https://www.debian.org/News/2026/20260711- Greenshot, free open-source screenshot tool: https://getgreenshot.org/- Rocketbook, reusable notebook: https://getrocketbook.com/- Bullet Journal method: https://bulletjournal.com/- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- SysAdmin Weekly GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Andy on Tech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org
-
53
052 - Why is Homelab Hardware So Expensive in 2026 (and When Will It Get Cheaper)?
Somewhere between a $305 Raspberry Pi board and a used NVMe listing on eBay, the homelab hobby quietly stopped making financial sense.Andy and co-host Eric Siron dig into why memory, NAND, and storage prices went vertical in 2026, who is actually eating the supply, and what practitioners should do about it. They cover the AI buildout swallowing the manufacturing capacity, why prices probably never return to pre-shortage levels, and the return of a skill the industry let atrophy: right-sizing hardware to the workload instead of throwing spec at it.## Chapters:00:00:00 - The Hardware Market Is Fire and Brimstone00:01:18 - Welcome and Intros00:04:33 - News React: The First Fully AI-Run Ransomware (JadePuffer)00:08:16 - News React: AI Job-Blame and the Unix Lawsuit That Won't Die00:13:32 - Nerd Hour: Thunderbird Finally Speaks Exchange Online00:18:47 - Nerd Hour: Hugo, AI, and the 80% Problem00:23:13 - Show Plugs00:24:09 - Why Homelab Hardware Broke Me: The eBay Moment00:41:44 - Why This Is Happening: AI Is Eating the Supply Chain00:46:43 - Local Models and the Willingness-to-Pay Problem00:52:41 - The New Normal: Prices Aren't Coming Back00:59:05 - Right-Size the Hardware to the Problem01:06:02 - Could China Break the Bottleneck?01:09:29 - One More Casualty, and Wrap-Up## Resources / Show Notes- BleepingComputer, JadePuffer AI-run ransomware: https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/- Thunderbird Blog, native Microsoft Exchange (EWS) support in 145: https://blog.thunderbird.net/2025/11/thunderbird-adds-native-microsoft-exchange-email-support/- Raspberry Pi Foundation, memory-driven price rises: https://www.raspberrypi.com/news/more-memory-driven-price-rises/- GamersNexus, SSDs WTF (NAND makers sold out for 2026): https://gamersnexus.net/features/ssds-wtf- Gartner, surging memory costs (125% DRAM / 234% NAND surge): https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026- TechPowerUp, Samsung and SK Hynix $870B capacity plan and fab timelines: https://www.techpowerup.com/350478/samsung-and-sk-hynix-to-expand-semiconductor-capacity-with-usd-870-billion-plan- BBC, Samsung's memory-driven profit surge: https://www.bbc.com/news/articles/c1kyy8yrpxdo- IDC, why the memory market stays tight and makers aren't rushing capacity: https://www.idc.com/resource-center/blog/why-the-memory-market-is-still-tight-what-comes-next/- Tom's Hardware, SK Group chairman says the shortage runs until 2030: https://www.tomshardware.com/pc-components/dram/sk-group-chairman-says-memory-chip-shortage-will-last-until-2030- SemiAnalysis, China's CXMT challenging DRAM incumbents: https://newsletter.semianalysis.com/p/chinas-cxmt-is-set-to-challenge-dram- Tom's Hardware, China's YMTC and homegrown NAND tooling: https://www.tomshardware.com/pc-components/ssds/chinas-ymtc-moves-to-break-free-of-u-s-sanctions-by-building-production-line-with-homegrown-tools-aims-to-capture-15-percent-of-nand-market-by-late-2026- TrendForce, China's GPU makers scaling as enterprise accelerators: https://www.trendforce.com/news/2025/10/07/news-chinas-gpu-trio-rise-as-nvidia-retreats-decoding-moore-threads-metax-and-cambricon/- CSIS, China and global cyber supply chain risk: https://www.csis.org/blogs/strategic-technologies-blog/chinas-weaponization-global-cyber-supply-chains- AndyOnTech, Andy's hub for all his output: https://www.andyontech.com- Project Runspace, the organization behind the show: https://www.projectrunspace.org- SysAdmin Weekly GitHub Discussions, share your hardware battle stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
-
52
051 - What's Actually in Our Homelabs (and Why)
The hardest part of running a home lab in 2026 is not building it up; it is being honest about what earns its place.Andy is joined by returning guest and member of the SysAdmin Weekly community, Clay Tamam, a working SysAdmin over in the Netherlands, for a real tour of what is actually sitting in their labs: the hardware, the hypervisors, the services they use every day, and the reasoning behind each choice. Andy explains why he tore a four-node Kubernetes cluster down to five VMs on a single Debian box, Clay walks through building a rack from scratch on a practical budget, and both of them dig into what current memory and hardware prices are doing to the hobby. It closes with the Graveyard: the gear and services that got powered off, and why pruning is an important part of the discipline.## Chapters00:00:00 - Welcome and a Returning Guest: Clay from the Netherlands00:07:20 - News React: A US Firm's Bid for the Dutch DigiD Infrastructure00:15:21 - News React: An AI-Assisted Hack Hits US Festival Ticketing00:18:11 - Nerd Hour: Scoping AI Agents and Building a Lab From Scratch00:24:29 - Main Topic: What Is Actually in Our Home Labs00:25:15 - The Hardware: Andy's Pared-Down Single-Box Lab00:31:25 - The Hardware: Clay's From-Scratch Rack Build00:45:52 - The Foundation: KVM vs. Proxmox00:56:33 - The Services That Earn Their Keep01:02:37 - Self-Hosting, the Plex Price Hike, and Leaving Discord01:13:57 - Learning Goals and the Graveyard01:24:19 - Local Inference and the Urge to Panic-Buy01:25:49 - Wrap-Up## Resources / Show Notes- Wired - Researcher used Claude to break Front Gate Tickets: https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival/- NL Times - Netherlands blocks the US takeover of DigiD operator Solvinity: https://nltimes.nl/2026/05/26/netherlands-blocks-us-takeover-digid-operator-solvinity-security-concerns- Security Now with Steve Gibson: https://www.grc.com/securitynow.htm- Proxmox Virtual Environment and Backup Server: https://www.proxmox.com- Forgejo, the self-hosted Git forge (Gitea fork): https://forgejo.org- Tailscale, the overlay mesh VPN: https://tailscale.com- Foundry Virtual Tabletop: https://foundryvtt.com- Plex - New Lifetime Plex Pass pricing: https://www.plex.tv/blog/new-lifetime-plex-pass-pricing/- Jellyfin, the free software media system: https://jellyfin.org- Vaultwarden, a self-hosted Bitwarden-compatible server: https://github.com/dani-garcia/vaultwarden- Framework Desktop: https://frame.work/desktop- Connect with Clay on LinkedIn: https://www.linkedin.com/in/clay-tamam-00b6441b3/- AndyOnTech: https://www.andyontech.com
-
51
050 - How Do You Run a Blameless Incident Postmortem?
A postmortem that ends with a name instead of a root cause wasted everyone's time in the room.Andy and Eric Siron pull from a combined several-decades of incident reviews to break down what a postmortem actually is, what kind of outage earns one, and who really needs to be at the table. The throughline: keep it blameless without making it unaccountable, separate root cause from contributing factors, and remember that the follow-through is the entire point. Whether your postmortem is sixty people in a war room or just you writing a summary for one nervous boss, the discipline scales.## CHAPTERS00:00:00 - Why Postmortems Matter00:01:31 - Welcome and Show Plugs00:04:29 - News React: AI Job Hype Walkbacks, Teams Pain, Oracle Layoffs, AMD Trust00:17:42 - News React: Ubiquiti UniFi OS Max-Severity RCE CVEs00:19:41 - Nerd Hour: Claude Code, Hugo, and Pandoc00:23:36 - The Incident Postmortem Process00:26:40 - What Actually Earns a Postmortem00:29:22 - Who Needs To Be In the Room00:38:49 - Blameless, Not Unaccountable00:46:50 - What Information To Gather00:50:33 - Running the Review00:55:15 - Follow Through Is the Whole Point## RESOURCES / SHOW NOTES- SysAdmin Weekly home and show links: https://www.sysadminweekly.com- SysAdmin Weekly companion newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- BleepingComputer - Ubiquiti patches three max-severity UniFi OS RCE flaws (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910): https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/- Postmortem markdown template (free, CC BY 4.0, version-tracked in the show repo): https://github.com/ProjectRunspace/sysadmin-weekly/blob/main/resources/postmortem_markdown_process_template.md- Pandoc, universal document converter (Markdown to docx): https://pandoc.org- Hugo, the Markdown-driven static site generator: https://gohugo.io
-
50
049 - How Do Attackers Use Local LLMs to Phish At Scale?
Ask Claude or ChatGPT to write a phishing email and it politely refuses; pull the right open-weight model onto your own laptop and that refusal layer simply does not exist in many cases.Andy brings his InfoSecurity Europe session to the show, and Eric Siron joins to walk through how threat actors run local LLMs on their own hardware to generate targeted spear phishing at scale, in any language, with no internet connection and no guardrails. The guys break down what the attack workflow actually looks like, why these capabilities never disappear once a model is downloaded, and where the real defensive line sits. Spoiler: "spot the typo" awareness training is dead, and verification culture plus strong email authentication is what carries the load now.## Chapters:00:00:00 - Cold Open: Local LLMs and Phishing at Scale00:01:37 - Welcome Back and InfoSecurity Europe00:03:55 - News React: Washington Pumps the Brakes on Fable00:06:46 - News React: NY Ghost Gun Printing Law and Google AI Liability00:12:07 - Nerd Hour: Camera Gear and Mac Studio Dreams00:13:27 - Nerd Hour: Building the InfoSec Demo00:15:55 - Show Plugs and Community Links00:17:00 - Main Topic: What Local LLMs Actually Are00:21:23 - The Guardrail Gap: Cloud Refuses, Local Complies00:26:55 - The Demo: 15 Tailored Spear Phishing Lures in 90 Seconds00:30:04 - Why These Capabilities Never Go Away00:32:59 - AI on the Defensive Side00:39:01 - Voice Cloning, Deepfakes, and SPF for Phones00:46:20 - The Low-Tech Deepfake Defense00:47:26 - Why Spot-the-Typo Training Is Dead00:50:09 - Verification Culture and Email Authentication00:54:32 - Common Questions: Legality, Detection, and Adoption01:00:18 - Wrap Up: Stay Safe Out There## Resources / Show Notes:- Ollama, the easiest way to run open models locally: https://ollama.com- Hugging Face, open repository of machine learning models: https://huggingface.co- OpenCode, terminal coding agent that runs against local models: https://opencode.ai- Evilginx, reverse-proxy phishing framework referenced in the demo: https://github.com/kgretzky/evilginx2- SysAdmin Weekly Episode 024 - On-Prem AI with Ollama (Spotify): https://open.spotify.com/episode/1Huz7fy7axxOqjXei1HLI0- SysAdmin Weekly - all show links in one place: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- SysAdmin Weekly GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Project Runspace: https://www.projectrunspace.org- AndyOnTech: https://www.andyontech.com
-
49
048 - The AI Doom Narrative vs the Data: Layoffs, Energy, and Jobs in 2026
The AI doom headlines do not line up with what the actual data says, and that gap is doing real damage. Andy and Eric Siron take a practitioner read on the fear stories: the layoff narrative, the data center energy and water panic, and the executive predictions that office workers are gone in 18 months. They put the WEF Future of Jobs numbers, the hyperscaler nuclear and cooling commitments, and the post-COVID overhiring correction next to the headlines, and walk through what AI looks like at a SysAdmin's keyboard versus what the press would have you believe.Also in this one: Elon Musk's OpenAI lawsuit, Linus Torvalds on AI-generated bug reports clogging the kernel security list, Edge storing passwords in clear text, Eric on the Samsung browser on Windows, and Andy's Forgejo and Restic lab cleanup. Plus listener comments on broken IT job postings and the SCVMM question for Hyper-V shops.---## Chapters00:00 - Introduction to SysAdmin Weekly04:39 - AI Doom and Gloom Narrative07:36 - News React: Elon Musk vs OpenAI10:18 - News React: Linus Torvalds on AI Bug Reports13:36 - Nerd Hour: Exploring New Browsers16:30 - Microsoft Edge Password Concerns19:28 - AI's Impact on Jobs22:20 - The Reality of AI in the Workplace25:39 - AI's Role in Documentation28:28 - Critique of AI Predictions31:41 - Conclusion and Future Outlook34:12 - The Responsibility of Executives in AI Predictions38:16 - The Impact of AI on Job Markets41:42 - Understanding Layoffs in the Tech Industry49:56 - The Future of Jobs in the Age of AI56:00 - Energy and Water Concerns in Data Centers01:00:48 - The Shift in Carbon Neutral Promises01:03:37 - Concerns Over Water and Energy Resources01:05:32 - The Debate on Nuclear Power Safety01:08:40 - Real-World Applications of AI in Sysadmin01:11:12 - The Importance of Honest Communication in Tech01:13:44 - Job Market Realities for IT Professionals---## Resources / Show Notes- The Register - Linus Torvalds on AI-powered bug hunters: https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633- TechCrunch - A comprehensive archive of 2023 tech layoffs: https://techcrunch.com/2024/05/01/a-comprehensive-archive-of-2023-tech-layoffs/- Crunchbase News - Tech Layoffs Tracker: https://news.crunchbase.com/startups/tech-layoffs/- WEF - Future of Jobs Report 2025, 78 Million New Job Opportunities by 2030: https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces/- NPR - Three Mile Island will reopen to power Microsoft data centers: https://www.npr.org/2024/09/20/nx-s1-5120581/three-mile-island-nuclear-power-plant-microsoft-ai- Data Center Dynamics - Google signs nuclear SMR deal with Kairos: https://www.datacenterdynamics.com/en/news/google-signs-nuclear-smr-deal-with-kairos-for-data-center-power/- X-energy - Amazon invests in X-energy to support advanced SMRs: https://x-energy.com/news/amazon-invests-in-x-energy-to-support-advanced-small-modular-nuclear-reactors-and-expand-carbon-free-power/- Microsoft Cloud Blog - Sustainable by design, next-generation datacenters consume zero water for cooling: https://www.microsoft.com/en-us/microsoft-cloud/blog/2024/12/09/sustainable-by-design-next-generation-datacenters-consume-zero-water-for-cooling/- Consumer Reports - AI Data Centers, Big Tech's Impact on Electric Bills, Water, and More: https://www.consumerreports.org/data-centers/ai-data-centers-impact-on-electric-bills-water-and-more-a1040338678/- Forgejo, the self-hosted lightweight software forge: https://forgejo.org/- Restic, fast, secure, efficient backup program: https://restic.net/- SysAdmin Weekly - past episodes referenced are at https://www.sysadminweekly.com
-
48
047 - Is DNS Over HTTPS Actually Private? What ECH Fixes That DoH Doesn't
Turning on DNS over HTTPS does not make your browsing private. The hostname you are trying to reach still leaks in the TLS handshake through the Server Name Indication field, and that is the part most coverage of DoH quietly skips.Andy and Eric pick up where the DNS deep dive in episode 045 left off, this time focused on the privacy half of the problem. The episode walks through why DoH on its own only solves part of the equation, what Encrypted Client Hello (ECH) is doing to close the SNI gap, and which browsers actually support it today. Andy also unpacks Cloudflare's quiet deprecation of cloudflared's proxy-dns feature, what that means for every Pi-hole plus cloudflared setup still in the wild, and the Quad9 plus UDM Pro stack he landed on instead.Also in this one: California's age verification law and the operating system level approach the state landed on, Microsoft Edge keeping decrypted passwords in memory at all times (and Microsoft initially calling it "working as intended"), the Humble Bundle SysAdmin and Linux book bundle that is live right now, and Andy retiring his last Windows machine in favor of Debian.## Resources- SysAdmin Weekly Episode 045 - Why Is It Always DNS? (the prior DNS deep dive referenced throughout this episode): https://open.spotify.com/episode/2oAh0KzE7J2o7NQFJK8Mza?si=D0OO9XwkRb2GQ-hxM9duUA- Cloudflare announcement on the deprecation of cloudflared's proxy-dns feature (November 2025): https://developers.cloudflare.com/changelog/post/2025-11-11-cloudflared-proxy-dns/- Pi-hole, network-wide ad blocking and DNS sinkhole: https://pi-hole.net- cloudflared, the Cloudflare Tunnel client referenced in the proxy-dns discussion: https://github.com/cloudflare/cloudflared- Quad9, the Swiss-based privacy-focused DNS resolver Andy migrated to: https://www.quad9.net- Ubiquiti UDM Pro, which Andy moved his DNS forwarding onto: https://techspecs.ui.com/unifi/cloud-gateways/udm-pro- Microsoft Edge password manager vulnerability, security researcher disclosure from May 4 showing credentials decrypted and held in memory: https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/- Humble Bundle's SysAdmin and Linux book bundle from Packt (live for ~20 days from the recording date): https://www.humblebundle.com/books/ultimate-linux-sysadmin-bundle-books- Andy's prior AndyOnTech post on the state of web browsers, referenced for the Safari and Brave standardization context: https://www.andyontech.com/posts/there_are_no_good_web_browsers_left_and_thats_a_problem/- Encrypted Client Hello, Cloudflare's reference write-up on how ECH works alongside DoH: https://blog.cloudflare.com/announcing-encrypted-client-hello- Apple iCloud Private Relay, referenced as Apple's likely answer to the SNI privacy problem in lieu of shipping ECH in Safari: https://support.apple.com/en-us/102602- California's age verification law and the operating system level approach: https://www.theregister.com/software/2026/03/06/us-state-laws-push-age-checks-into-the-operating-system/4750249- SysAdmin Weekly main site, all episode links and platforms: https://www.sysadminweekly.com- SysAdmin Weekly newsletter, the companion weekly newsletter: https://newsletter.sysadminweekly.com- Contact the show: [email protected]## Chapters02:29 - Exploring Secure DNS Lookups04:17 - Tech News Reactions08:25 - Microsoft Edge Security Concerns14:58 - Humble Bundle Book Recommendations20:05 - Nerd Hour: Home Lab Updates26:23 - Understanding DNS Over HTTPS and Its Importance30:11 - The Role of Encrypted Client Hello (ECH)36:13 - Rebuilding the DNS Stack: A Personal Journey42:06 - Cloudflare's Changes and Privacy Concerns47:11 - The Future of Privacy and Quantum Cryptography
-
47
046 - Can Claude Code Help SysAdmins? Scripting, Log Analysis, and the Claude.md workflow
The skepticism is earned. Most AI demos are built for developers. Most AI hype is vendor noise. And most SysAdmins have better things to do than adopt another tool that solves a problem they may or may not have.That said: this is Andy putting the grumpy SysAdmin argument aside for an hour to make the honest case for Claude Code in SysAdmin workflows. With caveats. With the parts that still fall short. With a clear line between where it helps and where you should keep your hands on the wheel.The episode also covers a rough few weeks for the Linux kernel: three local privilege escalation vulnerabilities publicly disclosed in quick succession. All local, not remote. Still worth knowing about before your next patch cycle.In this episode:- A rundown of the three recent Linux kernel LPE vulnerabilities (Fragnesia, DirtyFrag, and CopyFail) and what they mean for SysAdmins running Linux in their environments- Nerd Hour: Restic offsite backups via Hetzner storage, Beszel and Uptime Kuma monitoring running on K3S- What Claude Code actually is, and why the CLI-based workflow changes the value proposition compared to chatbot-style AI use- The CLAUDE.md file: the single biggest thing most SysAdmins are missing when they try AI tools. What it is, how to build one, and how it turns Claude into something that actually knows your environment- Practical use cases: script generation with real AD and environment context, incident triage as a thinking partner, log analysis, documentation from terminal history, run book drafting, and YAML/Kubernetes help- Where to stay skeptical: sensitive data, the "do whatever you want" permission mode, and always reviewing AI-generated scripts before running them anywhere near productionThe tool amplifies competence. It doesn't substitute it. That framing is the whole episode.---## Resources and Show Notes### Linux Vulnerabilities:- Fragnesia (CVE-2026-46300): https://www.helpnetsecurity.com/2026/05/14/fragnesia-cve-2026-46300-linux-lpe-vulnerability/- DirtyFrag (CVE-2026-43284 + CVE-2026-43500): https://www.helpnetsecurity.com/2026/05/08/dirty-frag-linux-vulnerability-cve-2026-43284-cve-2026-43500/- CopyFail (CVE-2026-31431): https://www.helpnetsecurity.com/2026/04/30/copyfail-linux-lpe-vulnerability-cve-2026-31431/### Claude Code:- Claude Code Security Documentation: https://code.claude.com/docs/en/security- Claude Code Permissions Documentation: https://code.claude.com/docs/en/permissions### Tools Mentioned:- Restic Backup: https://restic.net- Beszel Monitoring: https://beszel.dev- Uptime Kuma: https://github.com/louislam/uptime-kuma- Hetzner Object Storage: https://docs.hetzner.com/storage/object-storage/- Hetzner Object Storage + Restic Setup Guide: https://docs.hetzner.com/storage/object-storage/howto-backups/restic/### Community:- Friends and Family IT Support Stories on GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Andy's Music TUI Terminal Apple Music Controller: https://github.com/asyrewicze/music_tui### Previous Related Episodes:- SysAdmin Weekly 008 - Getting Started with GitHub Copilot: https://open.spotify.com/episode/2eTtoAgeKEikKeLzYExfOY?si=ySl9Ho7mQ861mHAKiTAQ5w- SysAdmin Weekly 016 - AI Agents for IT Admins episodes featuring Mike Nelson: https://open.spotify.com/episode/7u5T3Tp04EEP0hZRst3KPZ?si=zTpzVTXZR42vle4Gk0-tow## Chapters04:32 - Community Comments and News React07:16 - Linux Vulnerabilities Overview10:08 - Nerd Hour: Personal Projects and Backups13:21 - Exploring Claude Code for Sysadmins16:09 - The Grumpy Sysadmin and AI Adoption19:24 - Understanding Claude Code's Functionality22:35 - Use Cases for Claude Code30:01 - The Importance of Documentation in Sysadmin Work32:52 - Leveraging Claude.md for Enhanced Context37:27 - Practical Applications of Cloud Code in Sysadmin Tasks42:11 - Challenges and Limitations of Cloud Code53:54 - Future of Cloud Code and Its Value in Sysadmin Work
-
46
045 - Why is It ALWAYS DNS?!?
It's always DNS. Every SysAdmin has said it, usually at the worst possible moment. This episode is the explanation for why that joke is only half a joke.Andy and Eric walk through how DNS actually works from first request to final answer: recursive resolvers, root servers, authoritative name servers, TTLs, and caching. From there they get into Windows Server and Active Directory DNS integration, covering SRV records, dynamic registration, and scavenging. The back half covers DNS security: DNSSEC, DNS over HTTPS, Encrypted Client Hello, DNS-based content filtering, and how attackers use DNS for C2 traffic and exfiltration. Throughout, the guys pull from real war stories, including a ticketing system that silently failed every few weeks because one of four DNS servers had a stale record, and a BIND config that refused to load because of a trailing space.---## Show Notes and Resources### News React- Cloudflare DNS filtering tiers: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/- AI token costs exceeding replacement labor costs: https://fortune.com/2026/04/28/nvidia-executive-cost-of-ai-is-greater-than-cost-of-employees/- Claude deleting company data and backups: https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue- Backyard RAM manufacturing: https://www.theregister.com/2026/04/23/youtuber_builds_working_dram/### Nerd Hour- Andy's PomoCLI app: https://github.com/asyrewicze/pomocli### Main Segment Resources- Cloudflare: What is DNS?: https://www.cloudflare.com/learning/dns/what-is-dns/- MXToolbox: https://mxtoolbox.com- DNS over TLS vs. DNS over HTTPS - Cloudflare Learning: https://www.cloudflare.com/learning/dns/dns-over-tls/- Encrypted Client Hello - the last puzzle piece to privacy: https://blog.cloudflare.com/announcing-encrypted-client-hello/### Community- GitHub Discussions: Friends and family IT support stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15.## Chapters12:45 - Understanding DNS: The Final Boss25:49 - The DNS Resolution Process38:43 - Exploring DNS Services and Tools39:45 - Managing DNS: Windows vs. BIND43:36 - Active Directory and DNS Integration48:38 - Dynamic Registration and Scavenging in DNS52:42 - Understanding DNS Record Types54:44 - Common DNS Tools and Their Uses59:28 - DNS Security: Threats and Protections01:06:27 - DNS Filtering and Content Control01:12:36 - Should You Run Your Own DNS?
-
45
044 - Hyper-V Failover Clustering in 2026
Failover clustering is the part of Hyper-V that trips up the most people, especially anyone arriving from the VMware side. In this episode Andy Syrewicze and Eric Siron pick up directly where episode 043 left off: you have standalone Hyper-V running, now what does it actually take to make it highly available in 2026?The guys start with the "why bother" question: Azure Local versus a traditional Hyper-V failover cluster comes down mostly to billing and governance overhead, not capability. From there the conversation moves into prerequisites: shared storage options (Storage Spaces Direct, iSCSI, SMB shares, Fiber Channel), Active Directory integration, and the heartbeat NIC myth Eric has been fighting against since he started seeing outdated Microsoft docs still getting passed around. The bulk of the episode is quorum: what split-brain means, why a two-node cluster needs a third vote, and the practical tradeoffs between a file share witness, a disk witness, and a cloud witness in Azure. Dynamic quorum gets its own explanation, including how graceful node shutdowns allow a cluster to shrink without taking everything offline. They close on the creation experience (PowerShell over Windows Admin Center, period), the gotcha that catches every VMware migrant (creating the cluster and adding VMs as clustered roles are two separate steps), live migration and shared nothing live migration.In the news and nerd hour segments this week: the FCC ban on foreign-made consumer routers (with Netgear already approved as an exception before anyone finished reading the press release), 3D printing of circuitry using microwave-based manipulation now down to the width of a human hair, Tim Cook stepping down from Apple, Andy using Claude Code to build a master index of every topic covered across all 43 episodes and every newsletter edition, and Eric deep in research on a home routing setup built around a mini PC with a separate router component so the internet does not require an IT degree to reset when he is traveling.---## Episode ResourcesSysAdmin Weekly Website: https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter: https://newsletter.sysadminweekly.comCommunity Discussion Board: https://github.com/ProjectRunspace/sysadmin-weeklyShare Your Family/Friends IT Support Stories (community post): https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15AndyOnTech: https://www.andyontech.comProject Runspace: https://www.projectrunspace.org**Previous episodes referenced in this episode:**- Episode 043: Getting Started with Hyper-V in 2026: https://open.spotify.com/episode/4J77iiMVDWvvf8fshSurAL?si=D1hPaG7eSKiX6uU7UPBL3g- Episode 042: Should SysAdmins Job Hop or Stay Put?: https://open.spotify.com/episode/0o7EMW8JTGDm8rJv7Xu6Pg?si=uv1KIDZwS-y4l0g6yIV8jA- Episode 13: Should Hyper-V Be Domain Joined?: https://open.spotify.com/episode/0KWjIe5xgqZV9XYHuV2UF3?si=oK6XKjJiQ_mvpEEDqY_vyg- Episode 017: Hyper-V Management Story episode: https://open.spotify.com/episode/0rHwIc4U297R7I6KFayhlm?si=oTB7nX3bTgG7xekebnIU5g**Articles referenced in this episode:**- FCC ban on foreign-made consumer routers: https://www.wired.com/story/us-government-foreign-made-router-ban-explained/- What's New with Hyper-V in Windows Server 2025 (Microsoft Docs): https://learn.microsoft.com/en-us/windows-server/get-started/whats-new-windows-server-2025#hyper-v-ai-and-performance---## Chapters03:30 - Tech News Highlights14:38 - Nerd Hour: Personal Projects and Innovations21:02 - Listener Feedback and Career Insights25:54 - Hyper-V Failover Clustering in 202632:56 - Automated Setup and Shared Storage Solutions35:03 - Active Directory Integration and Clustering Best Practices36:55 - Understanding Quorum in Failover Clustering46:15 - Establishing a Failover Cluster: Tools and Processes57:18 - Live Migration and Storage Migration in Hyper-V01:01:14 - Day Two Operations and Cluster Management
-
44
043 - Getting Started with Hyper-V in 2026
Hyper-V has been around since 2008, runs Azure, runs Xbox, and still gets overlooked by shops fleeing VMware/Broadcom pricing. In this episode Andy Syrewicze and Eric Siron go back to basics: what Hyper-V actually is under the hood, why it is still worth your attention in 2026, and everything you need to know to stand it up and run your first virtual machine without losing your mind in the process.They walk through licensing (Standard versus Data Center, OSEs, core-based math, and the very short answer: call your licensing rep), then peel back the architecture to explain why Hyper-V is a genuine Type 1 hypervisor even though it boots into Windows. From there the conversation covers hardware requirements, the virtual switch types that trip up every VMware migrant, storage options, Gen 1 versus Gen 2 VMs (short answer: go Gen 2), Integration Services, and Dynamic Memory. Checkpoints and clustering get flagged as topics that deserve their own full episodes.In the news and nerd hour segments this week: CPU component prices climbing again with Intel and AMD reportedly raising costs by 15% or more, Microsoft announcing plans to rebuild Windows apps natively instead of relying on WebView, the MacBook Neo stirring up comparisons to the original Surface, Eric's week spent patching NetScaler appliances through a critical CVE while fighting Citrix's new licensing model, and Andy's experience standing up a Forgejo self-hosted git forge and putting Claude Code to work as a local repository agent.---## Episode ResourcesSysAdmin Weekly Website: https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter: https://newsletter.sysadminweekly.comCommunity Discussion Board: https://github.com/ProjectRunspace/sysadmin-weekly/discussionsShare Your Family/Friends IT Support Stories (community post): https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15AndyOnTech: https://www.andyontech.comProject Runspace: https://www.projectrunspace.orgForgejo (self-hosted git forge): https://forgejo.orgClaude Code: https://claude.ai/code**Previous episodes referenced in this episode:**- VMware/Broadcom coverage: https://open.spotify.com/episode/764MqlqHjNimkiAdoWNoRb?si=pLZoVGM9RCivR6iBOW7b0A- Hyper-V management tools episode: https://open.spotify.com/episode/0rHwIc4U297R7I6KFayhlm?si=X_lxLkBDTuejzC_NCsoo2w---## Chapters02:50 - Getting Started with Hyper-V in 202615:25 - Nerd Hour: Personal Projects and AI Tools27:47 - Main Segment: Hyper-V Fundamentals29:06 - The Evolution of Hyper-V31:33 - Understanding Hyper-V Licensing37:53 - Navigating Hyper-V Licensing Complexities41:44 - Hyper-V Architecture Explained56:40 - Getting Started with Hyper-V01:03:45 - Understanding Hyper-V Networking Challenges01:08:45 - Exploring Hyper-V Storage Options01:13:29 - Choosing Between Generation 1 and Generation 2 VMs01:18:34 - Key Features of Hyper-V: Integration Services and Dynamic Memory01:20:50 - Managing Hyper-V with System Center Virtual Machine Manager
-
43
042 - Should SysAdmins Job Hop or Stay Put? There's a Secret Option C....
Andy and Eric Siron tackle one of the most debated questions in IT careers: do you find a company and stay for the long haul, or do you job hop every few years to chase better pay and new challenges? With over four decades of combined industry experience between them, they've lived both sides of the equation and they make the case that the real answer is neither.In News React, Eric calls out Nvidia CEO Jensen Huang's proposal that engineers should burn through AI tokens worth half their salary as a productivity metric, and Andy flags Intel's announced 10% consumer CPU price hike as the compute consolidation squeeze continues to tighten. Nerd Hour covers Andy's maddening K3S node kernel lockup mystery and Eric's journey from WordPress to Hugo for the Project Runspace site.For our main segment the guys walk through the case for staying long term at a job bringing deep institutional knowledge, ownership of your environment, the satisfaction of building something to your standards along with the real downsides: skill calcification, salary stagnation, and the risk of becoming so embedded you can't leave. Then they flip to the case for hopping. This method typically lands meaningful pay jumps, escaping bad culture, and breadth of experience alongside the pitfalls of being labeled a flight risk, never building depth, and fueling the contract economy. The guys then end the episode with Secret Option C....---## Episode Resources- Nvidia CEO Jensen Huang: Engineers Should Spend 50% of Salary on AI Tokens (CNBC) - https://www.cnbc.com/2026/03/20/nvidia-ai-agents-tokens-human-workers-engineer-jobs-unemployment-jensen-huang.html- Intel (AND AMD!!!) Preparing 15% Consumer CPU Price Increase (PCMag) - https://www.pcmag.com/news/intel-amd-reportedly-set-to-raise-cpu-prices-by-up-to-15-percent- SysAdmin Weekly Website - https://www.sysadminweekly.com- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- AndyOnTech - https://www.andyontech.com- Project Runspace - https://www.projectrunspace.org- SysAdmin Weekly GitHub Community Discussions - https://github.com/ProjectRunspace/sysadmin-weekly/discussions- SysAdmin Weekly GitHub Discussion: Share Your Family & Friends IT Support Stories - https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15## Episode Chapters00:00 - Introduction to Sysadmin Weekly03:02 - Navigating Career Choices in IT17:59 - The Case for Staying in One Organization34:13 - The Case for Job Hopping34:40 - The Job Hopping Dilemma42:42 - Navigating the Contract Economy47:47 - Finding Your Forever Home in IT58:22 - Advice for Sysadmins at Different Career Stages
-
42
041 - Is Microsoft Giving Up on Security? - The SFI Leadership Shakeup Explained
Andy and Paul Schnackenburg dig into a leadership change at Microsoft that has the security community raising eyebrows. Charlie Bell, the executive vice president of security who championed the Secure Future Initiative, is out and being replaced by a go-to-market sales executive from the Google Cloud. Satya Nadella's announcement focused on selling more security products, with no mention of continuing the SFI's mission. That omission says a lot.In News React, the crew covers the new Microsoft 365 E7 SKU (Copilot, Agent 365, and a $99/user/month price tag aimed squarely at mega-enterprises), and the Iran-linked Stryker wiper attack where hackers compromised an Intune admin account and remotely wiped devices across 79 countries (no malware required). Nerd Hour features Andy's Forgejo self-hosted Git setup and Paul's new electric vehicle.From there Andy and Paul trace the arc from Microsoft's repeated security breaches, to the scathing CSRB report that seemingly forced the creation of the SFI, to what now looks like the initiative quietly losing steam. Included is discussion on Microsoft's pattern of treating security as a profit center, the ethical tension of selling security add-ons for your own platform's vulnerabilities, and what SysAdmins should be watching for as this plays out. SysAdmin Weekly Website - https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com SysAdmin Weekly GitHub Community Discussions - https://github.com/ProjectRunspace/sysadmin-weeklyAndyOnTech - https://www.andyontech.comProject Runspace - https://www.projectrunspace.orgKrebsOnSecurity: Iran-Backed Hackers Claim Wiper Attack on Stryker - https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/CSRB Report: Review of the Summer 2023 Microsoft Exchange Online Intrusion (PDF) - https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdfRisky Business Podcast (Recommended by Paul) - https://risky.biz
-
41
040 - Big Tech Owns Your Compute... Should you be Worried?
After a brief hiatus, the crew is back! Andy is joined by both Paul Schnackenburg and Eric Siron to tackle a big question: what happens when access to compute becomes a subscription privilege instead of an owned capability?This week's topic goes deep! Big tech bankrolling elections, Bezos pushing rented cloud PCs over owned hardware, a global RAM shortage driven by AI demand. All the ingredients for a dangerous consolidation of compute seem to be in place. The crew explores the erosion of trust in cloud providers, geopolitical implications for non-US businesses, how consolidated AI models could subtly shape reality, the environmental cost of AI data centers, and the growing movement toward cloud repatriation and on-prem infrastructure. There's no silver bullet, but awareness and intentional choices about where we place our trust and spend our money are the first steps.## Episode Resources ##SysAdmin Weekly Website - https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.comSysAdmin Weekly GitHub Community Discussions - https://github.com/ProjectRunspace/sysadmin-weeklyVoidLink AI-Generated Malware Framework (The Hacker News) - https://thehackernews.com/2026/01/voidlink-linux-malware-framework-built.htmlGoogle Quietly Removes Net-Zero Carbon Goal Amid AI Data Center Buildout (Tom's Hardware) -https://www.tomshardware.com/tech-industry/google-quietly-removes-net-zero-carbon-goal-from-website-amid-rapid-power-hungry-ai-data-center-buildout-industry-first-sustainability-pledge-moved-to-background-amidst-ai-energy-crisisGoogle Plans to Power Data Center with Fossil Fuels and Carbon Capture - https://theconversation.com/google-plans-to-power-a-new-data-center-with-fossil-fuels-yet-release-almost-no-emissions-heres-how-its-carbon-capture-tech-works-270425Why a Carbon Capture Breakthrough Will/Won't Save Us (PBS Reactions) - https://www.pbs.org/video/why-a-carbon-capture-breakthrough-willwont-save-us-9cmmk0/
-
40
039 - BitLocker, Key Escrow, and the Microsoft Trust Question
Microsoft reportedly handed over BitLocker recovery keys to the FBI as part of a criminal investigation and that raises some uncomfortable questions.In this episode of SysAdmin Weekly, Andy and Eric unpack what actually happened, how BitLocker key escrow works, and why the default behavior in Windows 11 matters more than most users realize.We dig into:- How BitLocker recovery keys get stored in Microsoft accounts without end users knowing - What “key escrow” really means in practice - The difference between consumer and enterprise configurations - The privacy vs. law enforcement debate - Why encryption is meaningless if someone else controls the key - The broader implications for trust in cloud vendors We also discuss the “tyranny of the default,” the quiet shift toward mandatory Microsoft accounts in Windows 11, and what this means for SysAdmins responsible for protecting executive devices and sensitive data.If you manage endpoints, run M365, or care about privacy, this one’s worth your time.And yes… we also manage to cover frozen beach vacations, AI replacing CEOs, SMTP auth drama, and why abstraction always comes back to bite you eventually.## Episode Resources- SysAdmin Weekly Website - https://www.sysadminweekly.com- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- New SysAdmin Weekly Discussion Boards - https://github.com/ProjectRunspace/sysadmin-weekly/discussions- AndyOnTech - https://www.andyontech.com- Project Runspace - https://www.projectrunspace.org- Forbes Article - Microsoft hands over BitLocker encrypted data keys to FBI - https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/- Office 365 for IT Pros article on SMTP AUTH Basic Authentication retirement delay - https://office365itpros.com/2026/01/29/smtp-auth-basic-retirement/- SysAdmin Weekly - 036 - The Hidden Cost of Abstraction in Modern IT - https://open.spotify.com/episode/0B4SfPgTbUlXTzSuJyfiby?si=OOehzhGTSnyda-zTKoW4tA - SysAdmin Weekly - 035 - AI Browser, Chromium Monoculture, and the Future of Browser Security - https://open.spotify.com/episode/0zZDUAtcCJQ74d6zQdKV6N?si=R286nY4UTmaBIULFvArAcg
-
39
038 - Making Security Decisions Based on Data, Not Fear
This week on SysAdmin Weekly, we push back hard on one of the most damaging patterns in modern IT security: making decisions based on fear instead of facts.Security headlines love absolutes: “everything is broken,” “encryption is useless,” “the cloud can’t be trusted.” But in the real world, those claims often fall apart the moment you slow down and examine the actual mechanics behind them. In this episode, we walk through why responsible security decisions must be grounded in verifiable data, not outrage-driven interpretations or half-read articles.We break down how encryption, key access, and lawful access actually work, where trust boundaries truly exist, and why conflating possibility with probability leads to bad architecture, bad policy, and unnecessary panic. Just because something can happen does not mean it is happening and SysAdmins are expected to know the difference.This isn’t an episode about dismissing risk. It’s about measuring it correctly. Understanding threat models. Asking “what evidence do we have?” before rewriting policies, re-architecting systems, or blowing up trust relationships that were never the real problem.If you’re tired of security discourse driven by vibes, doomscrolling, and worst-case hypotheticals and you still believe SysAdmins should be the adults in the room, this episode is for you.## Episode Resources- New SysAdmin Weekly GitHub Discussions Board - https://www.github.com/ProjectRunspace/sysadmin-weekly- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- Paul's Article About Making Security Decisions Based on Data - https://virtualizationreview.com/articles/2025/12/03/refining-your-cybersecurity-strategy-based-on-data.aspx- YouTube Video From Lars Klint about Australian Bushfires - https://www.youtube.com/watch?v=mNEPSWcOheY- Paul and Amy's Defender + InTune Monthly Training Course - https://www.thirdtier.net/product/defender-intune-continued-learning/- Decipher Podcast Episode on Vulnerability Management - https://www.buzzsprout.com/228511/episodes/18495360-the-future-of-vulnerability-management-with-jeremiah-grossman-and-robert-rsnake-hansen- SysAdmin Weekly - 036 - The Hidden Cost of Abstraction in Modern IT - https://open.spotify.com/episode/0B4SfPgTbUlXTzSuJyfiby?si=OuycyiFISKeKm9HmiimpKw- Project Runspace - https://www.projectrunspace.org- AndyOnTech - https://www.andyontech.com
-
38
037 - When Incident Response Plans Meet Reality
It’s a new year, which means it’s time for every SysAdmin’s favorite activity...... dusting off the incident response and disaster recovery plans that haven’t been touched since the Apollo moon landing.In this episode of SysAdmin Weekly, Andy and Eric dig into why incident response, disaster recovery, and business continuity plans so often exist… but completely fall apart when something actually goes wrong. They talk through what makes a response plan useful versus useless, why roles and decision-making matter more than tools, and how slow human processes can undo even the fastest detection systems.The conversation spans real-world tabletop exercises, ransomware scenarios, MFA bombing, on-call failures, and the uncomfortable reality that many organizations still don’t empower anyone to make business-impacting decisions during an incident. Eric even shares fresh lessons learned from a recent tabletop exercise, including what happens when critical people are unavailable, how communication can fail under pressure, and why “solo warrior” response patterns collapse fast.Along the way, Andy and Eric also touch on Broadcom’s ongoing VMware licensing chaos, cease-and-desist letters, the continued enshittification of enterprise software, and why supply-chain dependency should make every IT pro a little nervous.If you’ve ever wondered whether your incident response plan would actually survive first contact with reality or if you’ve never tested one at all this episode is your wake-up call.### Episode Resources- New SysAdmin Weekly GitHub Discussion Boards! - https://www.github.com/ProjectRunspace/sysadmin-weekly- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- SysAdmin Weekly Website - https://www.sysadminweekly.com- AndyOnTech - https://www.andyontech.com- Project Runspace - https://www.projectrunspace.org- Bastard Operator From Hell - https://bofh.bjash.com- Continued VMware / Broadcom Drama - https://www.reddit.com/r/sysadmin/comments/1pzp3eo/vmware_now_threatening_outages_to_perpetual/- SysAdmin Weekly - 029 - When Good Tech Goes Corporate - https://open.spotify.com/episode/6tDkgEmzjJQgmBSxCRcDeR?si=31S2s8ATTCuRnach82MUHw- WMI Documentation - https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page
-
37
036 - The Hidden Cost of Abstraction in Modern IT
Abstraction has made modern IT faster, easier, and more scalable but it’s also quietly eroding the deep technical understanding that SysAdmins used to rely on.In the first SysAdmin Weekly episode of 2026, Andy and Eric dig into how layers of abstraction stretching from cloud platforms and managed services to Kubernetes and modern software design are changing what it means to be a SysAdmin.The guys explore where abstraction helps, where it actively hurts, and why losing visibility into how systems actually work becomes a serious problem the moment something breaks underneath the hood.Along the way, they connect abstraction to real-world examples: cloud VMs, Microsoft 365, Kubernetes misconfigurations, browser monocultures, Rust’s “memory safe” reputation, and even how modern generations interact with technology differently than those who lived through the pre-cloud era.The episode wraps with practical advice for SysAdmins who want to stay sharp in an increasingly abstracted world while focusing on curiosity, home labs, documentation, and rebuilding deep product knowledge before the defaults fail you.If you’ve ever felt like IT is turning into a collection of black boxes, this episode is for you.Episode Resources- SysAdmin Weekly Website - https://www.sysadminweekly.com- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- Github Discussions is Coming Soon! - I Promise!- AndyOnTech - https://www.andyontech.com- Project Runspace - https://www.projectrunspace.org- What are IRQs? - https://en.wikipedia.org/wiki/Interrupt_request- Code: The Hidden Language of Computer Hardware and Software - https://www.amazon.com/Code-Language-Computer-Hardware-Software/dp/0137909101- From Mathematics to Generic Programming - https://www.amazon.com/Mathematics-Generic-Programming-Alexander-Stepanov/dp/0321942043
-
36
035 - AI Browsers, Chromium Monoculture, and the Future of Browser Security
This week on SysAdmin Weekly, Andy goes on a (fully justified) rant about the current state of browsers and why it feels like there are no good options left for sysadmins. From Chromium monoculture and browser bloat, to AI creeping into the most trusted piece of software we use every day, this episode breaks down what’s changing, why it matters, and why “just turn it off” isn’t a real security strategy.Along the way, Andy digs into:Firefox’s push toward becoming an “AI browser”Why agentic AI inside browsers introduces serious, unresolved threat modelsReal-world examples of prompt injection and AI-assisted data exfiltrationWhy browser forks are a stopgap, not a long-term escape hatchAnd the question: would a "boring" and "security-first" browser have a place in the market?This is less about tools and more about trust, threat boundaries, and the slow erosion of choice in the browser ecosystem.If you use a browser to manage infrastructure, security, or SaaS platforms (so… all of us), this one’s for you.Episode Resources- Firefox News from Windows Central - https://www.windowscentral.com/software-apps/mozilla-says-firefox-will-evolve-into-an-ai-browser-and-nobody-is-happy-about-it-ive-never-seen-a-company-so-astoundingly-out-of-touch- Browser Market Share Data - https://www.tech2geek.net/most-used-web-browsers-in-july-2025-market-share-statistics/- SysAdmin Weekly: "Good Enough" Software is Ruining IT - https://open.spotify.com/episode/6uUdRBvUHpo15x6h2dXpEO?si=ItOqAFpaT8eS11wHIkBa9w- SysAdmin Weekly: The Importance of Documentation - https://open.spotify.com/episode/6OWL5VPiGx08QMIhpGMFsT?si=z3legxgwQXuehPxT4ix_yA- DNS over HTTPS resources - https://en.wikipedia.org/wiki/DNS_over_HTTPS- Encrypted Client Hello resources - https://blog.cloudflare.com/announcing-encrypted-client-hello/- Comet-Jacking Article - https://thehackernews.com/2025/10/cometjacking-one-click-can-turn.html- SysAdmin Weekly Website - https://www.sysadminweekly.com- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- Project Runspace - https://www.projectrunspace.org- AndyOnTech - https://www.andyontech.com
-
35
034 - "Good Enough" Software is Ruining IT (and SysAdmins are Paying the Price)
Modern IT feels stuck in a vicious cycle: software ships faster than ever, quality keeps slipping, and SysAdmins are left cleaning up the mess. In this episode of SysAdmin Weekly, Andy Syrewicze and Eric Siron dig into the growing disconnect between developers and operations teams and why “good enough” software has become dangerously normalized across the industry.We talk about brittle releases, missing error handling, forced beta testing in production, and how operational debt quietly drains time, money, and morale. From real-world outages and monoculture risks to AI hype, “vibe coding,” and the slow disappearance of software testing roles, this episode breaks down how we got here and why it’s not sustainable.To be clear, this isn’t a developer-bashing session. It’s a reality check.If software is going to keep the world running, it needs to be treated as a craft again, NOT a content pipeline. And that means shared accountability, better defaults, meaningful error messages, and respecting the people who have to run this stuff after it ships.Episode Resources- Cloudflare Outage - https://www.bleepingcomputer.com/news/security/cloudflare-blames-todays-outage-on-emergency-react2shell-patch/- Satya Nadella Copilot skills challenge - https://www.youtube.com/watch?v=gBcwQaNoP5A- SysAdmin Weekly Website - https://www.sysadminweekly.com- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- AndyOnTech - https://www.andyontech.com- Project Runspace - https://www.projectrunspace.org
-
34
033 - Why IT Job Postings Are Completely Broken
IT job postings have gotten… weird.In this episode of SysAdmin Weekly, Andy flies solo to take a realistic look at modern IT job listings amongst historic industry layoffs and why so many of them feel disconnected from the actual work SysAdmins do every day.We scroll through real-world postings, talk about unrealistic expectations, role creep, and “unicorn” requirements, and break down how vague or overloaded job descriptions contribute to burnout, churn, and impostor syndrome across the industry.This isn’t a recruiter or HR dunk session. It’s a candid discussion about how job postings act as signals, why those signals are often confusing, and how both candidates and companies can do better by asking the right questions and setting clearer expectations.Whether you’re actively job hunting, passively browsing, or just wondering who exactly these postings are written for, this episode is for you.Episode Resources- Anthropic Report on AI-Enabled Cyber Espionage- IT Specialist Simulator- SysAdmin Weekly - What Makes a Great SysAdmin?- SysAdmin Weekly - Is University Worth it for Aspiring SysAdmins?- Microsoft Learn - Discrete Device Assignment- What are DMARC, DKIM, and SPF?- SysAdmin Weekly Website- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace
-
33
032 - Microsoft Ignite 2025: What SysAdmin Actually Need to Know
Microsoft Ignite just wrapped and shockingly, it wasn’t only about AI.(Okay, it was mostly about AI.)In this episode of SysAdmin Weekly, Andy and Paul cut through the marketing noise and walk through what actually matters to SysAdmins from Microsoft Ignite’s Book of News. From AI agents showing up everywhere, to Azure resiliency, security posture management, and why massive cloud outages are still very much a thing. This is the practical, admin-focused breakdown you didn’t get from the keynote.We dig into:What Microsoft’s push toward AI agents really means for control, governance, and securityNew Copilot and Azure features that might actually help… and a few that should make you cautiousWhy resiliency keeps failing at scale (and what Ignite quietly admitted about it)How Microsoft is trying to simplify security and management and where the complexity is just shifting insteadThe ongoing reality of cloud dependencies, outages, and shared responsibilityNo hype. No sales pitch. Just two SysAdmins reacting honestly to what Ignite announced and what it means when the slides become production.If you manage Microsoft environments, cloud workloads, or security policies, this one’s for you!Episode Resources- SysAdmin Weekly Website- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- Microsoft Ignite Book of News- Paul Schnackenburg on LinkedIn
-
32
031 - How the IT Community Makes You a Better SysAdmin
This week, Andy and Eric dive into one of the most underrated superpowers in IT: community. Not the cringe corporate “community,” but the real stuff. Think mentors, friends, people who help you level up, and the shared hive-mind that keeps SysAdmins alive during outages, zero-days, and career pivots.From basements full of beige boxes to global open-source conferences, the IT world has evolved into something way more connected and way more essential than ever before. Andy and Eric share personal stories from Microsoft MVP circles, KubeCon 2025, early career mentors, and the weird ways community quietly shapes your entire trajectory in tech.In this episode you’ll learn:- Why community is an actual career accelerator- How mentors and advocates appear when you least expect them- Why open-source communities operate differently than vendor ones- Why contributing (even small stuff) builds reputation and opportunity- Why community-first companies thrive.....and community-hostile ones declineIf you’ve ever wondered whether getting involved is worth it (spoiler: it absolutely is), this episode brings the stories, lessons, and laughs to prove it.Episode Resources- SysAdmin Weekly Website- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- Bank hit by audio deepfake scam- Earlier SysAdmin Weekly episode on “enshittification”
-
31
030 - New NIST Password Guidelines Explained
Ready to leave password chaos behind? In this episode of SysAdmin Weekly, Andy and Eric break down the latest National Institute of Standards and Technology (NIST) password and identity-guideline updates and what they mean for you as a SysAdmin.We cover:- What changed and why (goodbye “special characters just because”)- How to align your org with SP 800-63’s new structure and expectations- Real-world tactics: from passkeys and token theft to legacy systems refusing to dieAlso in this episode: bonus snark, smart home horror stories, PKI headaches, and identity as the new firewallWhether you’re revamping your password policy or finally ready to ditch the “rotate every 90 days” mindset, this one’s for you.Episode Resources- SysAdmin Weekly website- SysAdmin Weekly companion newsletter- AndyOnTech- Project Runspace- NIST Digital Identity Guidelines (SP 800-63 suite)- NIST SP 800-63B “Authentication & Authenticator Management”- Evilginx2 (GitHub repo for the MITM/phishing framework)
-
30
029 - When Good Tech Goes Corporate
In this episode, Andy and Eric dive deep into one of tech’s ugliest trends, the ULTRA-Corporatization of once-great vendors all for the sake of excessive profit at the expense of the company and customers. From Intel’s fall from grace to Dell’s support horror stories and VMware’s Broadcom-induced meltdown, the guys unpack how innovation-driven companies lose their soul chasing shareholder dollars.They trace the full "life-cycle" of this process, from scrappy startup to bloated monopoly and look at how these same behaviors are infecting SaaS and the MSP world. Along the way, expect a few spicy rants about Microsoft’s licensing labyrinth, ARM vs. x86, 47-day certificate rotations, and why SysAdmins now spend more time managing vendors than managing servers.If you’ve ever screamed at an E5 SKU, cursed a firmware update, or watched your favorite tech brand go corporate zombie, this one’s for you.Episode Resources- SysAdmin Weekly Website- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project RunspaceReferenced in this episode:- WSUS Remote Code Execution Patch (CVE-2025-59287)- What Is Cloud Native? (Episode 25)- Microsoft Learn: SharePoint Limits and Boundaries- VMware Episode (Referenced)- GitHub Copilot Episode
-
29
028 - SysAdmin Horror Stories Volume 1
Welcome to the Halloween special of SysAdmin Weekly, where Andy, Eric, Paul, and Mike gather ‘round the flickering glow of their monitors to share true tales from the trenches, the ones that still haunt their uptime dreams. From flooded data centers and cursed SAN swaps to Novell nightmares, rogue backup tapes, and the eternal terror of “it’s always DNS,” this episode dives into the real-life horror stories that only SysAdmins could survive. Expect nostalgia, gallows humor, and a reminder that in IT, every scream has a log entry. Grab your candy corn, dim the lights, and join us as we celebrate the season of outages, late-night restores, and phantom pings. Because sometimes… the scariest thing in tech isn’t ransomware, it’s the guy who forgot to check the backups.... #####Episode Resources- SysAdmin Weekly Website- SysAdmin Weekly Companion Newsletters- AndyOnTech- Project Runspace- Azure 15-Year Anniversary News – Microsoft vs AWS Revenue Comparison- OpenAI Atlas Browser- KQLBench – Test LLMs on Microsoft Kusto Query Language- Novell NetWare (for the brave and nostalgic)- OS/2 Warp (IBM Historical Reference)- SharePoint Online Storage and Retention Best Practices
-
28
027 - Is University Worth It for Aspiring SysAdmins?
In this episode of SysAdmin Weekly, the crew tackles one of the most debated questions in IT: Is university still worth it for aspiring SysAdmins in 2025?Joining Andy is a friend of the show, Clay, a newly graduated IT professional from the Netherlands who shares his journey from tinkering with PCs as a kid to landing his first SysAdmin role. Together, they unpack how well higher education prepares students for real-world IT and where it still falls short. Listeners can expect an honest, grounded look at the difference between theory and practice in modern IT. The conversation covers: - Whether university programs keep pace with the speed of tech. - What parts of formal education still provide lasting value. - How certifications, home labs, and real-world experience stack up against degrees. - Clay’s early-career lessons, including his first big outage (spoiler: it *wasn’t* DNS this time). - The timeless SysAdmin truths about troubleshooting, documentation, and learning by breaking things. This episode bridges the gap between the classroom and the server room with a mix of humor, career wisdom, and a few painful flashbacks to subnet calculations. Whether you’re a student, a career-switcher, or a long-time admin wondering how the next generation is being trained, this one’s worth your time.Episode Resources - SysAdmin Weekly Website- SysAdmin Weekly Companion Newsletter- Email the show- AndyOnTech- Project Runspace- Clay’s LinkedIn- F5 Networks breach news article- SolarWinds Supply Chain Breach
-
27
026 - Burnout in IT: Why So Many Tech Pros Are Struggling (and How to Cope)
Burnout in IT is not just “being tired”, it’s a silent crisis affecting countless tech professionals, SysAdmins, engineers, and ops folks who are running on empty. In this episode of SysAdmin Weekly, we dig into the mental health stressors built into the tech industry: constant change, imposter syndrome, “always-on” culture, notification overload, and more.Co-host Eric Siron and Andy share real stories, data, and actionable tactics from boundary-setting to seeking help that can make the difference between surviving and thriving. Whether you’re feeling burnt out, concerned about a teammate, or just want to build a healthier tech culture, this episode is for you.Covered in this episode: - The mental health “baseline” in tech: diagnosis rates, productivity loss, burnout prevalence- Why imposter syndrome is especially tough in IT- The role of organizational culture, remote work, and tool overload- Practical practices: micro-breaks, peer support, therapy / coaching, building psychological safety- What leaders and managers can do to make tech workplaces more sustainableTune in and pass it on to anyone in tech who needs a reminder they’re not alone.Episode Resources: - SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- Perplexity CometJacking Attack- Satya Nadella Microsoft AI Interview- Slack: Mental Health in Tech (2020)- TechUK - Addressing Mental Health in the Tech Industry (Burnout Index 2022)
-
26
025 - What is Cloud-Native? (And Should You Care?)
In this episode, Andy teams up with Microsoft expert and Aussie tech legend Paul Schnackenburg to break down the buzzword that’s haunting every IT strategy deck: Cloud-Native. Together, they unpack what it really means in a Microsoft ecosystem from ditching on-prem Active Directory and ConfigMgr to embracing Entra ID, Intune, and Autopilot.Along the way, they hit on real-world migrations, the trade-offs of control vs. convenience, and why hybrid identity might actually make you less secure. Expect analogies about Death Stars, cruise ships, and even the Magic School Bus, because of course they did.Whether you’re an MSP plotting your clients’ next move or an IT pro trying to future-proof your environment, this episode’s your field guide to surviving (and thriving) in a Cloud-Native world.NOTE: As a reminder, be sure to share your IT Horror stories with us! We’d love to share as many as we can during an upcoming Halloween episode!Episode Resources:- CVE-2025-32463 (Sudo vulnerability details)- CISA KEV Catalog (Known Exploited Vulnerabilities)- SysAdmin Weekly Episode 22 – IT Documentation (Referenced in comments segment)- SysAdmin Weekly Episode 3 – WSUS Deprecation Discussion- Azure Files Overview- Microsoft Intune Autopilot Device Preparation (v2)- Microsoft Universal Print- Windows Autopatch Overview- Azure Arc for Servers- PowerShell Summit Session: Secure Management of Secrets with Azure Arc (Referenced by Andy)- SysAdmin Weekly Companion Newsletter- Contact the show
-
25
024 - On-Prem AI with Ollama
This week on SysAdmin Weekly, Andy is joined once again by Mike Nelson for a deep dive into the world of local AI. Together, they unpack Ollama and Open WebUI, exploring how SysAdmins can run large language models on-prem to unlock powerful workflows while keeping sensitive data in-house.From hardware setups (yes, even that dusty old GPU in your basement), to why privacy-conscious SysAdmins are moving workloads local, Andy and Mike cover it all. Along the way, they swap stories on home labs, Ubiquiti gear, Ghost CMS, Hugging Face models, and where open-source AI really shines.If you’ve ever wondered why you’d bother with local AI when ChatGPT is just a browser tab away, this episode lays out the practical sysadmin use cases, security considerations, and future of AI in the trenches.Episode Resources:- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- Ollama Models Directory- BookStack Wiki Software- Confluence Free Instance (Atlassian)- Hugging Face Model Hub- Awesome MCP Servers (GitHub curated list)- Previous SysAdmin Weekly Episode: “The Importance of IT Documentation”- Previous SysAdmin Weekly Episode: “Building a Home Lab on the Cheap”
-
24
023 - Budget Home Lab Setup for IT Pros
In this episode of SysAdmin Weekly, Andy and Eric dig deep into how to build a fully functional home lab without selling a kidney. We cover picking hardware on the cheap, virtualization (Proxmox, Hyper-V, etc.), managing storage, navigating Microsoft licensing, layering in free cloud tiers, network tricks, and the kind of “what if I push this button?” experiments that keep us awake at 2 a.m.Whether you’re starting from a pile of old PCs or trying to mix in cloud credits, this show gives you the blueprint, the trade-offs, and, most importantly, the sanity checks.In this episode:- How to stretch every dollar on lab hardware- When to go physical vs. virtual (or hybrid)- Proxmox tips, license workarounds, and pitfalls- Cloud free/low-cost tiers you can use for testing- Network, storage & routing hacks we swear by- Real talk about maintenance, scaling, and failuresEpisode Resources- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- Windows Server Eval- Proxmox Installation Guide- Azure Free Services / Free Tier- Azure Free Account / $200 Credit- Azure Free Services Documentation
-
23
022 - Why IT Documentation Matters (Even if You Hate Writing It)
Hey folks! Andy here, and in this episode of SysAdmin Weekly Eric and I answer the hard questions regarding the documentation we all put off, but secretly depend on.... whether we like it or not.In this episode we cover:- Why poor (or missing) documentation is the root of so many SysAdmin nightmares- War stories where “future you” had to clean up past you’s mess- Tools, templates, and mindset shifts to make living documentation actually .....live- Change control, accuracy, and how to trust what your docs sayWhether you're flying solo or managing teams, this episode will give you ideas to start building docs you’ll thank yourself for later.Hit subscribe, ring the bell, and share this with someone whose servers are mysterious even to them. Let’s make documentation less boring, more usable, and fearless.Episode Resources:- SysAdmin Weekly Companion Newsletter- AndyOnTech Blog- Project Runspace- Incident Response Markdown Template- Greenshot Screenshot Tool
-
22
021 - Microsoft Entra ID Conditional Access Explained
This week on SysAdmin Weekly, Andy is joined by regular co-host Paul Schnackenburg for a deep dive into Conditional Access, the cloud-era identity firewall you could say? and a cornerstone of Zero Trust security in Microsoft 365 and the Microsoft Cloud.We cover everything from the basics of conditional access policies to the nuances of break-glass accounts, layered policies, and how to avoid locking yourself (and your entire org) out of Entra ID. Along the way, we touch on Microsoft’s security defaults, authentication strengths, and the role of risky sign-ins and user risk detection in identity protection.Paul and Andy also share war stories from the trenches: configuring fresh tenants, wrangling MFA requirements, and learning why documentation and backups of your conditional access policies matter more than ever. Plus, there’s plenty of SysAdmin banter on Intel’s decline, ARM’s dominance, and even foldable phones!If you’ve ever wondered how to design policies without creating chaos or how to modernize your security controls without overwhelming your users, this is the episode is for you.Episode Resources- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- Microsoft Security Defaults Overview- Microsoft Entra Conditional Access Documentation- Microsoft Identity Protection (Risky Sign-ins & Users)- Authentication Strengths in Entra ID- Meister.dev – Conditional Access Testing Tool- Meryl Fernando’s Conditional Access Documentation Tool- Podcast with Tarek Dawoud on Entra ID Architecture
-
21
020 - Top Microsoft Skills that Every SysAdmin Needs
Andy and Eric break down the actual Microsoft skills that move the needle with no fluff, and no buzzword salad. We hit the core Windows/AD fundamentals, the PowerShell magic you’ll use every day, and the cloud/M365 bits that keep modern shops sane. If you’re trying to level up without wasting cycles, this is your roadmap.What we cover (at a glance):- Identity & Directory - AD/Entra basics, Group Policy that won’t bite you later, hybrid gotchas- Automation - PowerShell patterns you’ll use forever (loops, pipeline, remoting, “please don’t run that in prod”)- Networking for Windows admins: DNS/DHCP sanity checks, practical troubleshooting, knowing when it’s actually the firewall- Microsoft 365 - mail flow triage, Teams/SharePoint survival skills- Security stack - Defender realities, Conditional Access guardrails, least privilege that people will actually follow, Just in time administration.- Azure orientation - VMs, storage, networking, Arc and what’s worth learning first- Career path - what to learn now vs. what to park for later, and which certs are signal vs. noiseBring coffee. Leave with a plan. And yes, a little snark, because ticket queues were meant to be mocked.Episode Resources- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- SysAdmin Weekly - 018 - What did Broadcom do to VMware?- SysAdmin Weekly - 014 - How SysAdmins can Showcase Value- SysAdmin Weekly - 008 - Getting Started with GitHub Copilot
-
20
019 - What Counts as a Security Breach (and What Doesn't)
"Compromised." We throw the word around like everyone agrees what it means, but do we? This week, Andy and Eric dig into the many faces of compromise in a security context and why it’s not a simple definitionIn this episode:- What actually counts as a security compromise (and why the answer is “it depends”)- Full breach vs. partial breach: Does it even matter?- Why lateral movement should keep you up at night- Session token hijacking in M365 and why MFA isn’t a silver bullet- The Myth of the Green Matrix Terminal Hacker (aka Hollywood hacking nonsense)- How risk profiling and layered defenses can contain the blast radius- Real-world detection failures and the “10,000 alert problem”- Practical steps to tune logs, outsource monitoring, and avoid burnout📬 Reminder! - You can subscribe to the SysAdmin Weekly Companion Newsletter (link below) or email your own security horror story to [email protected]!Episode Resources:- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- SysAdmin Weekly 012 - Identity is the New Firewall- Evilginx (Reverse Proxy Phishing Toolkit)- Debian 13 “Trixie” Release Notes- Ghost CMS Overview
-
19
018 - What Broadcom Did to VMware (and Why SysAdmins are Furious)
Broadcom’s acquisition of VMware has left the sysadmin community reeling. From gutting VMware’s workforce to skyrocketing license costs (1000+ percent increases in some cases), cease-and-desist letters for perpetual licenses (really?), and a collapse in customer support, the VMware we once knew is gone.In this episode of SysAdmin Weekly, Andy Syrewicze and Eric Siron dig into:- How Broadcom’s handling of VMware triggered massive customer backlash- Why small and mid-sized businesses (SMBs) are being pushed away- The licensing and pricing nightmare (including lawsuits from giants like AT&T and UnitedHealthcare)- Declining customer experience and security patch transparency- Alternatives on the rise: Hyper-V, Proxmox, Nutanix- And even a spicy debate: will SysAdmins return to physical servers?If you’ve ever managed a VMware environment, are considering your virtualization options, OR you just need to share in VMware Grief, this one’s for you.Episode Resources:SysAdmin Weekly Companion NewsletterAndyOnTechProject RunspaceJen Easterly Joins Huntress Advisory Board
-
18
017 - Hyper-V Management Drama, What Tool to Use, and When
In this episode of SysAdmin Weekly, Andy and Eric wade through the sometimes mess that is managing Hyper-V. From MMC snap-ins to Azure Arc and everything in between, we’re talking about the confusing pile of tools Microsoft throws at you when you just want to manage some virtual machines.Topics include:- The evolution (and stagnation) of Hyper‑V Manager- Why Failover Cluster Manager feels like an insider secret- SCVMM: A tool that should be great… but isn’t- Windows Admin Center and its 80-inch monitor problem- Azure Arc: Is it helpful or just cloud cosplay?- PowerShell, Live Migration, CSVs, and sysadmin war storiesIf you've ever screamed at a clustered VM that just *won’t* move, this episode’s for you.---EPISODE RESOURCES - AndyOnTech- Project Runspace- Create a Failover Cluster- System Center Virtual Machine Manager Overview- Manage Hyper‑V Integration Services- Cluster Shared Volumes- Microsoft 365 Direct Send Abuse---Subscribe to the companion newsletter: https://newsletter.sysadminweekly.comGot a Hyper‑V horror story? Share it with us in the comments!
-
17
016 - AI Agents for IT Admins
In this episode of SysAdmin Weekly, Andy sits down with Mike Nelson to talk about how SysAdmins can harness the power of Generative AI to make their day-to-day lives easier. From writing PowerShell scripts to reducing cognitive load during incidents, Andy and Mike break down real-world use cases that go beyond hype.They dive into what AI agents really are, how large language models (LLMs) fit in, and introduce the concept of Model Context Protocol (MCP), a game-changer for future infrastructure automation. Mike shares his home automation experiments, Andy nerds out about running open-source models locally with Ollama, and together they discuss where tools like Microsoft Copilot and Azure MCP might take SysAdmins next.If you’ve ever wondered how AI can move from buzzword to genuine productivity tool in IT operations, this episode is for you!---Episode Resources---- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- ProPublica article on Microsoft support risk- Ollama GitHub Repository- Open WebUI for Ollama- Azure Model Context Protocol (MCP) Overview- GitHub MCP Servers Repository (Awesome MCP)
-
16
015 - The Art of Troubleshooting in Tech
If you've ever stared at a blinking cursor at 2 a.m. whispering, "please just work…", this episode’s for you. Andy Syrewicze and Paul Schnackenburg roll up their sleeves and wade into the messy, glorious world of troubleshooting. From stopping junior techs from “chaotic clicking” themselves into a production outage, to real-world stories of SQL process murder and Comcast cables zapped by neighborly air conditioners, this one’s packed with hard-earned wisdom.You’ll learn how to scope problems without panicking, why you should onlychange one thing at a time (seriously, ONE), and how to use logs, diagrams, and even your own voice (rubber-duck style) to untangle gnarly IT messes. We talk when to escalate, how to survive vendor support roulette, and why sometimes the best fix is simply tossing the old PC in the bin and giving the user a shiny new one.Plus, in news this week, the guys discuss:- SK Telecom’s “3-year breach”- CitrixBleed 2 makes NetScaler owners sweat- Push Security drops a free MFA-verification tool for help desks- Notepad finally speaks Markdown (YAY!)- And Andy debates whether Hugo or a “Swiss-cheese WordPress” should power his next projectThis is SysAdmin troubleshooting in its purest, funniest, most caffeinated form. Bring your ticket queue and a strong coffee. --------Episode Resources- SysAdmin Weekly Companion Newsletter- AndyOnTech- Project Runspace- SK Telecom breach- CitrixBleed 2 (CVE‑2025‑5777)- Push Security browser extension- Notepad Markdown support- Hugo static site generator
-
15
014 - How SysAdmins Can Prove Their Value (Before the Next Layoff)
Let’s be real, the better you are at your job in IT, the less anyone notices. Welcome to the Visibility Paradox, where success means silence, and failure? Oh, that gets EVERYONES attention!In this week’s episode, we break down how SysAdmins can fight back against being invisible by quantifying wins, showcasing strategic value, and learning to speak fluent exec (without falling asleep doing it).We talk dashboards, automation ROI, watercooler politics, and the underrated power move of asking: “Who’s in the room?” before every meeting.Because if you want to survive the next round of budget cuts....or better yet, get that promotion, you're going to need more than technical skills. You're going to need career armor.---Topics Covered Include:- The Visibility Paradox: Why good IT flies under the radar (and why that’s a problem)- Making leadership *see* your impact....and care- Turning boring automation into juicy ROI metrics- Getting a seat at the table (without being *that* guy)- Translating Geek Speak into Exec Speak™- Real-world sysadmin stories from the trenches---Don’t forget to check out the companion newsletter at https://newsletter.sysadminweekly.com ! Every week we include commentary, curated tools, security headlines, and all the sysadmin goodness that didn’t fit in the mic..... which is kind of a lot it turns out!A reminder! The show is available on Apple Podcasts, Spotify, Amazon Music, and soon… Substack Podcasts (hopefully)!---Episode ResourcesProject RunspaceAndyOnTechIranian-Linked PLC Breach:CISA Advisory (AA23-335A)CISA Fact Sheet PDFMinecraft Modpack Setup (For those interested!):CurseForge Install Guide
-
14
013 - Hyper-V Hosts in the Domain? Yea or Nay?
This week on SysAdmin Weekly, Andy and Eric finally settle one of the most persistent questions in the Hyper-V world: Should your Hyper-V hosts be domain joined or live outside the domain? Spoiler: we have strong feelings.Before the main event, we hit a few hot headlines:- Microsoft is booting AV vendors out of the kernel (finally)- CrowdStrike’s recent disaster knocked out 8.5 million devices- Notepad++ had a nasty privilege escalation flaw in its installer- And no, China did NOT break RSA encryption (at least, not the kind that matters)Then, in Nerd Hour, Andy talks Debian 13 upgrade best practices, and Eric explores scripting virtual TPM keys in Hyper-V without going full-HGS.In the main segment, we compare the tradeoffs of domain-joined vs workgroup-mode Hyper-V hosts, from security implications (Kerberos, pass-the-hash, curb roasting) to the operational challenges of backups, automation, and monitoring.Got a spicy opinion? Want to challenge our take? Email us at [email protected] Resources:- Newsletter signup- Project Runspace- AndyOnTech- Kerberoasting (MITRE ATT&CK technique T1558.003)- Workgroup vs Domain- Active Directory Security Best Practices- Microsoft is moving antivirus providers out of the Windows kernel- CrowdStrike’s faulty update crashed 8.5 million Windows devices- CVE‑2025‑49144 – DLL planting privilege escalation in Notepad++ installer- Chinese researchers break RSA encryption with a quantum computer (22‑bit only)- Debian 13 (Trixie) release notes
-
13
012 - Is Identity the New Firewall? The SaaS Cyber Kill Chain Examined
This week on SysAdmin Weekly, Andy is joined by returning guest Paul Schnackenburg to dive headfirst into one of the most important (and overlooked) topics in modern IT: SaaS Security.From token theft and malicious OAuth apps to adversary-in-the-middle attacks and the harsh truth about identity becoming the new firewall, we unpack how attackers are adapting to the cloud-first world, and why most orgs are woefully unprepared.We explore:- The SaaS cyber kill chain from recon to persistence- Other real-world security incidents like CitrixBleed2 and the Fortinet hardcoded credentials fiasco- The dark art of malicious OAuth apps and shadow IT exploitation- Why EDR and XDR fall short in a SaaS world- What you can do *right now* to harden your defenses (Hint: MFA is not enough)This one’s loaded with insights and practical tips, don’t miss it!## Episode Resources ##- SysAdmin Weekly Companion Newsletter - AndyOnTech- Project Runspace- CitrixBleed 2- X Post re: Fortinet Hard-Coded Credentials- Paul's SaaS Cyber Kill Chain Article
-
12
011 - How is Agentic AI Changing DevOps?
This week on SysAdmin Weekly, Andy is joined by Luke Orellana, a fellow IT war buddy from the MSP trenches who's now a Senior Engineering Manager at Microsoft (yes, that Microsoft) working with AI Agents on a daily basis!In this episode we unpack the good, the bad, and the "seriously, who thought YAML was a good idea"? parts of Infra-as-Code from Terraform and Pulumi to PowerShell DSC and Packer pipelines. Luke drops wisdom on platform engineering, the rise of AI agents with their impact on DevOps, and how he rewrote entire Terraform libraries because apparently, sleep is optional.Also in this episode:- Why password resets are a scam (Forrester says $70 a pop — no thanks).- The glorious chaos of auditors asking for 30-day resets in 2025 (because security theater must go on).- Andy’s obsession with Linux Mint Debian Edition and the Tux shrine on his desk.- The legendary Domino’s Pizza Terraform provider. Yes. That’s real. We also answer critical questions like:- Can an AI agent wreck your entire Git repo?- Should sysadmins fear change or just automate it?- And what’s more powerful: Terraform CDK or the sheer willpower of a sysadmin trying to avoid YAML?Grab your favorite caffeine source, commit to main (regrets optional), and get ready to laugh, learn, and question your life choices. This one’s got code, chaos, and caffeine-fueled commentary.Episode Resources Below!- SysAdmin Weekly Companion Newsletter- All Available Podcast Platforms- AndyOnTech- ProjectRunspace- Luke Orellana on LinkedIn- Terraform CDK Constructs
-
11
010 - Tips for Tech Conferences in 2025
This week, Andy is back from InfoSecurity Europe (and yes, still fighting off a conference cold), so naturally, we’re talking all about IT conferences. The big, the small, the budget-busting, and the badge-scanning bonanzas that are IT Events. Paul Schnackenburg returns to help unpack the real value of these events: learning (but not just in sessions), community (a.k.a. the hallway track), and how to dodge aggressive booth folks without pretending to answer a fake phone call. Also covered:- A news react segment on Trend Micro vulnerabilities and the Coinbase supply chain scare- The reality of conference session overload (triple-booked? Same.)- Why the expo hall isn’t just a capitalist trap (spoiler: you might stumble on tools that blow your mind)- Why speaking at events could be your career’s best power-upOh! And don’t skip the outro. We tease a future episode on “what’s in your conference bag” (nerd edition). BTW, you can subscribe to the companion newsletter at https://newsletter.sysadminweekly.com!-- Episode Resources --- AndyOnTech- Project Runspace- SysAdmin Weekly Companion Newsletter- Trend Micro Vulnerabilities- Coinbase Insider Threat- Ookla Speedtest PS Script
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Welcome to the SysAdmin Weekly Podcast, your go-to source for IT-related content tailored to busy system administrators in the trenches. Hosted by longtime sysadmins and Microsoft MVPs Andy Syrewicze and Eric Siron, this show dives deep into the challenges and solutions that matter most to sysadmins on any given day. From technical know-how to real-world insights, SysAdmin Weekly is dedicated to those tireless professionals who keep our digital world running. Tune in for relevant topics, expert advice, and engaging discussions to make your busy schedule a little bit easier.
HOSTED BY
Andy Syrewicze and Eric Siron
CATEGORIES
Loading similar podcasts...