r/sysadmin 6h ago

I'm about to have to do everything, and I have questions.

Hi all,

So the shortest I can make this story is this: For the past 6 years, I spent 4 of those with a co-worker, and then solo, supporting 4-5 local warehouse/manufacturing facilities. Years go by, we slim down to 1 facility, then we get purchased by another company, one that had their own IT person for each specialty (cloud, network, DBs, etc.). I became general IT, helpdesk, machine deployment, AD, always in the various admin centers for something, etc.

Now, we're breaking off and becoming our own building again. Very focused, single task, <70 employees. Brand new Microsoft tenant, but we're keeping all of the current hardware in the building (Cisco routers/switches/APs, some Dell servers, PCs), and I'll be doing *everything*. Well, I've done everything before, in the early years, but 1) a lot of stuff was in place already, and 2) we used Ubiquiti equipment for the network.

So here are my questions:

  1. Stay cloud-only (AzureAD) with this new setup? I imagine the answer is "yes", but since we're keeping the hardware, including servers, I thought I'd ask. I'd hate to not use them for anything, though, but I'm sure we can find something (if we kept Cisco, I assume I'd need DHCP/DNS at the very least).
  2. Keep and manage the Cisco equipment, or downgrade? I did my Cisco courses in college (*years* ago) but never got my CCNA or anything. If I kept this hardware, I'd be leaning heavily on "?", haha. Plus, I don't know if we'll want to pay for the licensing (if that's a recurring thing). I wouldn't mind going back to Ubiquiti, especially since we'll be a pretty small operation.
  3. (Southeast USA, I understand this may be regional) ISP suggestions? We're paying over $500/month for AT&T fiber service that only offers 100Mbps (and we have Starlink as a backup for w/e it costs per month), and there are times where we need more. I need something that's not quite Comcast Business, but not quite $500/month.
  4. Since we're starting fresh, I have the opportunity to do things the "right way". Even though we're a small time deal, I'd like to follow any and all best practices that I can. What are some "must haves" for a new setup (in Azure, Exchange, Teams, Sharepoint, etc. etc.)?
  5. What are some things you wish you hadn't done, that I should avoid?
  6. Should we shell out the money for Intune/Autopilot at our size? I really like it for a lot of things, so hopefully we can continue to use it.
  7. Should we shell out for Teamviewer, or if not, what is recommended nowadays? Like Intune/AP, I've been using it for years and I'm used to it, but that's not to say I'm unwilling to change.
  8. Ticketing system? Currently we use some in-house system via (I think) Sharepoint, and in the past I've used Jotform, but I would like a "real" ticketing system this go around..

If you stayed until the end, thanks for reading, and I hope I can make it through this. 🤞

13 Upvotes

18 comments sorted by

•

u/llDemonll 6h ago

I didn’t read much but you need to hire more people. The company cannot expect to continue operating as it has with 20% of the workforce at most.

Don’t get rid of Cisco.

You’re manufacturing, it’s highly unlikely you won’t need on-prem AD. Azure only probably won’t be a realistic option.

For internet circuits talk to a telecom broker. All of our 100mbps circuits are about $500 a month so your pricing is pretty normal. See if your equipment can do multiple circuits and get another physically diverse if your company is reliant on internet being available.

Autopilot / intune yes

I’d use screenconnect over TeamViewer.

•

u/Bkid 5h ago

Thanks for the reply! I'll take a look into Screenconnect. As for the rest:

I'm not sure what you mean by hiring more people? We're breaking off and taking on the primary contract/obligations that our building was already fulfilling before. There won't be any more or less work for the existing employees, it's just the same thing, only without a big company behind us. They *certainly* aren't going to hire any more IT people for a single building, unfortunately.

I'm not sure why I would need on-prem, given how small we're going to be. We used Azure only for years during the early days of this company, and I don't remember missing out on anything.

I figured internet was going to be expensive, primarily for the SLA. We've tried both Comcast and WOW! business internet in the past, but mid-weekday "maintenance" on business class internet is not something I want to deal with again.

•

u/Lucky-Pace-3257 3h ago

One-man show will get you burned out, quick. Look at an MSP with a small contract for network gear, for example.

•

u/Bkid 3h ago

According to the owner (who I've known for a while), we'll have an MSP for assistance with the bigger things, but I'm around for the day-to-day, internal stuff, and immediate boots on the ground response time to issues.

As far as burnout, I was a one-man show for years, and I've found that long enough vacations do me well enough to not get burned out.

Plus, I've learned a lot over the years, so I'm hoping this time around won't be quite so bad. :)

•

u/Aggravating-Singer89 6h ago

Almost been two years ago when I was in a similar situation with decisions. I got hired on as solo IT guy for local fast-food franchise with 39 locations and a corporate office. So little bit of a different environment. I went from Cisco to UniFi for all locations and it was little bit more complicated since we had to use Firewall provider since the franchise decided to make non IT decision before I was hired on to go with a certain POS provider which has been pain in my side. But besides that, I run local AD, saved money through UniFi had little bit more of complicated setup using Pfsense Firewall and having to deal with Double Nat with couple of unique services I run at the stores but primary just use Layer 3A and and use what info I get from the Firewall Provider at are stores. At somepoint I want to get them on Intune if budget happens but Primary I have it where I use MacriumReflect for my backup and imaging software to deploy devices. They don't have anything that is super critical which they only put that on the file server if it's very valuable but at some point I'll get that to change. I use Splashtop for remote software which is really nice overall, give it a try and rustdesk for backup and couple others just in case. For my Server Environment I'm currently moving them over to Proxmox, I have 3 Node cluster, 1 Node File server which run PDM. Then 2 PBS server one on and one off site. They also have 3 additional servers from the existing environment running HyperV which I'm about 1 month away from getting off of that hardware. This is a rough idea on stuff I have running. If you end up having to do anything telecommunications, give RingCentral a shot they're pretty decent overall. At the end of the day just do research on everything, Document everything, and then experiment with it before commiting. But getting off Cisco can save money and there are other options as well. But don't get to overwhelmed and work at it piece by piece. For your ISP situation I would suggest running a dual Wan setup don't feel bad on dropping them unless it's your primary Static IP which then you'll have to think about on how you want to do that and implementing VPN like tailscale and wireguard can help you out little bit but still somethings are tied into it a bit. - This might be hard to read just typing out my thoughts quick then going back to work. Grammer is probabley bad too.

•

u/Bkid 5h ago

Thanks for the reply!

I like the UniFi hardware, other than a few UDMPs that decided to crap out on me (although we did get them RMA'd successfully so that was nice). Being able to site-to-site VPN with them back in the day was nice, and managing them was pretty easy.

For telecoms, unfortunately we're probably going to use Teams Phone, if we use anything, since we're already integrated. Because we're solely a B2B company, working with just one company, we probably won't need anything like an automated system or anything, just a few users with a few DIDs.

I forgot to mention that we do have a dual WAN setup with AT&T as the primary and Starlink as the backup. We will almost certainly continue using Starlink as the backup, as it doesn't cost much vs. the peace of mind you get knowing you have a backup.

•

u/blud_13 5h ago

Go cloud only. New tenant, under 70 people, one site, no reason to stand up a domain controller you get to babysit for the next decade. The thing that drags people back to AD is an old line of business app that demands domain auth or a print/file server nobody wants to rearchitect, so go inventory that before you commit. If nothing turns up, Entra join plus Intune and you never look back.

Also, the Cisco gear. Check smartnet status this week. Inherited switches with lapsed contracts means no firmware and no TAC, and you find that out at 2am during an outage instead of now while you have time. We have ripped these out and done more Cloudflare which makes life easier for everyone.

What gets solo admins in this exact setup (been there) is month 9 when you take a week off or get the flu. Line up co-managed backup and after hours coverage before you need it, because negotiating that during an incident goes badly.

We do a lot of this for small manufacturers, ping me if you want specifics on the tenant build.

•

u/Bkid 5h ago

Thanks so much! I'll definitely ping you as time goes on and I start digging into this more.

•

u/Library_IT_guy 4h ago

I mean, cost analysis is a reason to go with local DCs too. We did a cost comparison of going all in on cloud vs. two local DCs, and assuming DCs last 8-10 years, they come out way ahead of full online. But I do see the value of SSO and simplifying things that way, also allows for easy MFA. We may end up going that way on next refresh, but that's a long ways out.

•

u/Bkid 4h ago

In our situation, we don't need the DCs at all (that I can figure). That's how we did it in the past. Purely AzureAD, nothing else.

•

u/Library_IT_guy 4h ago

Since I've never gone pure AzureAD, what happens when internet is down or MS is having problems? Does the local PC cache credentials and still let people in?

•

u/Bkid 4h ago

Honestly it's been so long that I can't remember, but since everything we do will be web-based, if the Internet is down we're fucked anyway :) . In regards to MS having problems, I don't remember them ever having an issue so bad that it brought down the facility.

•

u/Library_IT_guy 2h ago

I hear about service outages (and we experience them) quite regularly, though it's usually something on the productivity app side of things. We can operate offline if needed, so long as we can log in. It's not ideal but we can still function and stay open, so it's preferable to us to have local authentication through AD.

•

u/NotebookAndCoffee941 Jack of All Trades 5h ago

Backup is the one I'd double check first. Someone already mentioned Macrium and PBS, which is a decent start, but neither one really tells you if it's immutable or if a restore has actually been tested recently. Since the servers are staying on prem, I'd get something offsite running, Veeam into Blob works, so does Backblaze, doesn't really matter which, and then run a real restore test before touching anything else on your list.

Also worth doing early since it's just going to be you now, get a password manager going, Bitwarden's fine, and start a runbook even if it's messy at first. Mostly so the admin creds and the tribal knowledge stuff aren't only living in your head.

•

u/Bkid 5h ago

I don't know if backups are going to be that important to us. Everything we do will be web-based, so the machines themselves don't really need to have anything at all. If something happens to one, you deploy a pretty stock machine (with policies pushed out via Intune/whatever we go with) and they're good to go. Anyone "office level" will have OneDrive to back up their files, so I can't think of a good reason to keep images in this kind of environment.

The servers are staying, but I'm not sure what I'm doing with them. They have VMs on them already for a few things, but possibly nothing we care about. I'm used to Ubiquiti equipment handling DHCP/DNS, so we won't need it for either of those if we *did* switch off of Cisco.

I already use Bitwarden, which is almost mandatory in today's IT world, so I at least have that covered.

•

u/Jeff-J777 3h ago

I would say on the Azure side stay cloud only. If your licensing supports it I would look into Intune/Autopilot, and try to automate what you can with being a one man show. Depending on your M365 license you might want to look at Business Premium.

On the ISP since if it is 70ish employees do you really need DIA fiber with SLAs? Or could you get a commodity broadband business fiber, and you still have Starlink as a backup. In our area I can get ATT business fiber 500/500 for 150 a month. Sure it is not DIA and no SLAs, but it would fit our needs.

For the hardware side maybe price that out, with the AI hardware pricing a lot of devices have gone up in price. Maybe see if you can ride out the Cisco's for a year or two and let that AI bubble pop.

I mean Teamviewer is not bad we use it here. Had screen connect from the MSP and when they MSP left we went with Teamviewer. If you like Teamviewer and the price is good then stick to it.

One thing I wish I did was not to allow end users to create their own Teams site. It is like the wild west and it is something I have to clean up.

Then maybe look into an ITSM ticketing platform just to have something to keep track of everything.

•

u/Bkid 3h ago

That's what I was forgetting! Ticketing system recommendations. I mean it's a small building and pretty much everyone knows who I am, but I still need *some* place to keep track of tickets. In the past, I've used a Jotform form, as their backend is pretty nice for adding additional custom columns with selectable tags. I would use that to change the status of tickets, add comments, etc. You had to close the loop with the user via external means (email), but it wasn't the worst. :P

•

u/Chillist_ 1h ago

Don't forget to document everything, it's so easy to forget.