In this guide
- What is system administration?
- What a system administrator does
- The sysadmin's role in the organization
- Users, groups and directory services
- Operating systems: Windows Server and Linux
- Network services every administrator runs
- Patching and updates
- Backup and recovery
- Monitoring, logging and troubleshooting
- Automation and scripting
- Endpoint and device management
- Documentation and change management
- Sysadmin tools by category
- Sysadmin skills and tools
- FAQ
System administration basics, from one server to a managed estate
System administration basics are the routines that keep computers useful to the people who depend on them: accounts that work, systems that stay patched, data that can be restored, and problems found before users report them.
The job title changes from sysadmin to IT administrator to infrastructure engineer, and the platforms change from a server in a closet to the cloud, but the responsibilities underneath are the same.
This guide covers the fundamentals of system administration in the order a new administrator meets them: what a sysadmin does, the core responsibilities, users and identity, operating systems, patching, backup, monitoring, automation, endpoint management, security, and the skills and tools worth learning. Each section links to a full page in this library.
DefinitionWhat is system administration?
System administration is the work of installing, configuring, maintaining and securing an organization's computer systems: its servers, operating systems, user accounts, software and the services they provide. A system administrator, or sysadmin, is the person responsible for keeping those systems available, performing well and recoverable.
In a small company one person does all of it. In a larger one the work splits into neighboring roles, and knowing the boundaries helps when you are hiring or being hired:
| Role | Looks after | Typical work |
|---|---|---|
| System administrator | Servers, operating systems, accounts, core services | Builds, patching, backups, permissions, troubleshooting |
| Help desk technician | Users and their devices | Password resets, software installs, first-line fixes, escalating the rest |
| Network administrator | Switches, routers, firewalls, Wi-Fi | Connectivity, VLANs, VPNs, capacity |
| Security administrator | Controls, monitoring, incidents | Hardening, vulnerability management, response |
| DevOps or platform engineer | The pipeline between code and production | Automation, infrastructure as code, deployments |
DutiesWhat a system administrator does
The responsibilities of a sysadmin fall into a handful of areas, and the rest of this guide takes them one at a time:
- Provisioning: building servers and workstations to a standard, and accounts for the people who use them. See what provisioning is.
- Identity and access: creating, changing and removing accounts, groups and permissions.
- Maintenance: patching, upgrades, capacity and the replacement of systems before they fall out of support.
- Backup and recovery: making sure data can be restored, and proving it.
- Monitoring: knowing a disk is filling or a service is down before a user calls.
- Troubleshooting: finding the cause when something breaks, under time pressure.
- Security: hardening systems, limiting privileges and responding to incidents.
- Documentation: recording what exists and how it is configured, so the knowledge does not live in one head.
A useful way to picture the work is by rhythm. Daily: check backups, alerts and tickets. Weekly: review patches and capacity. Monthly: test a restore, audit accounts, and review what is approaching end of support. Yearly: refresh the disaster recovery plan and the hardware roadmap.
ContextThe sysadmin's role in the organization
System administrators are responsible for technology that the rest of the organization only notices when it fails. That makes the role partly technical and partly a service: sysadmins translate what the business needs, such as a new office, a new application or a compliance requirement, into computer systems, software and network services that work and keep working.
Where the role sits depends on size. In a company of twenty, one administrator, or an outside provider, covers servers, the network, security and the help desk.
In a company of two thousand, teams of administrators specialize by platform, and the work is governed by change control and on-call rotas. Organizations too small for a full-time administrator often hand the role to a managed service provider; what an MSP is explains how that works.
IdentityUsers, groups and directory services
Most of a sysadmin's tickets come down to who is allowed to do what. A directory service keeps the answer in one place, so that an account created once works everywhere and an account disabled once is disabled everywhere.
- Active Directory is the directory in most Windows networks: it holds users, computers and groups, and authenticates them. Active Directory explained covers domains, domain controllers and organizational units.
- LDAP is the protocol used to query a directory, by Active Directory and by Linux and application logins alike. See LDAP explained.
- Group Policy pushes settings to users and computers from the directory: password rules, drive mappings, software restrictions. See Group Policy explained.
The working rules are short. Assign permissions to groups, never to individuals. Give each person the least access their job needs. Keep administrator accounts separate from everyday accounts, and protect them with MFA. Disable an account the day its owner leaves.
PlatformsOperating systems: Windows Server and Linux
A sysadmin's systems run one of two families. Windows Server dominates office infrastructure: file and print, Active Directory, and line-of-business applications. Linux dominates web servers, containers and the cloud. Most administrators end up needing a working knowledge of both.
Under either one, the kernel is the core that manages the hardware, memory and processes, and everything else is a service on top. The open source operating systems page surveys the Linux and BSD options and what each is used for.
Every version has a support lifetime, after which it receives no security fixes. Tracking those dates is part of the job; Windows Server end of life lists them for the versions still in service.
ServicesNetwork services every administrator runs
A computer network is only useful because of a few quiet services, and when one of them fails the symptoms look like something else entirely. Administrators are responsible for maintaining them whether or not there is a separate network team:
- DNS turns names into addresses. A failed or misconfigured DNS server breaks logins, email and the web at once. See DNS on port 53.
- DHCP hands computers their network settings. See what DHCP is.
- Time is kept in step by NTP. Kerberos authentication fails when clocks drift apart, which is why NTP stratum matters to a Windows domain.
- File and print sharing runs over SMB. See SMB port 445.
- Remote access to servers uses SSH on Linux and RDP on Windows, neither of which should be exposed to the internet directly.
MaintenancePatching and updates
Applying updates is the single most effective security task a sysadmin performs, and the one most often deferred, because a patch can break something. The answer is a routine, described in full on the patch management page:
- Inventory what you have, since you cannot patch what you do not know about.
- Prioritize by severity and exposure: internet-facing systems first.
- Test on a small group before everyone.
- Deploy in a maintenance window, with a way back.
- Verify that the patch installed, and report what did not.
On Windows, a damaged system image can block updates altogether; the DISM command repairs it.
RecoveryBackup and recovery
Users forgive downtime sooner than they forgive lost data. The sysadmin's obligations are to follow the 3-2-1 backup rule, to keep one copy out of reach of ransomware, and to test a restore on a schedule.
The storage library covers RAID, which keeps a server running through a disk failure, and why it is not a substitute for a backup.
VisibilityMonitoring, logging and troubleshooting
Monitoring turns surprises into tickets. At minimum, watch whether each system is up, how full its disks are, how busy its processor and memory are, whether its services are running and whether its backups finished.
Logs explain what monitoring only flags. Collect them centrally so they survive the failure of the machine that wrote them; syslog is the standard transport, and the ELK stack is a common place to search them.
On Windows, the Event Log is the first stop: reboot event IDs show why a server restarted, and the blue screen of death page explains how to read a stop code.
Troubleshooting follows a method, not a hunch: define the symptom, ask what changed, form one theory, test it, and write down the fix. The measure teams track is MTTR, the mean time to repair.
AutomationAutomation and scripting
Anything done twice by hand will eventually be done wrong. Automation makes the work repeatable, and it is the skill that most separates a junior administrator from a senior one.
- Scheduled tasks: a cron job on Linux, or Task Scheduler on Windows, runs a script at set times.
- Scripting: PowerShell on Windows and Bash or Python on Linux turn a checklist into a command.
- Infrastructure as code: servers and cloud resources defined in files, reviewed and versioned like software. See infrastructure as code.
- Event-driven integration: a webhook lets one system notify another the moment something happens.
EndpointsEndpoint and device management
Laptops and phones outnumber servers and leave the building every day. Managing them by hand does not scale, so they are enrolled in a management platform that enforces encryption, pushes software and can wipe a lost device.
MDM explained covers mobile device management, and UEM vs MDM covers the broader tools that manage every device type from one console. Managed service providers use a related class of tool, described in what RMM is.
RecordsDocumentation and change management
A system nobody has documented is a system only one person can fix. Keep an inventory of hardware, software and how they depend on each other; at scale that inventory is a CMDB.
Record every significant change with what was done, why, and how to undo it. Most outages follow a change, so the change log is also the first place to look when something breaks.
ToolkitSysadmin tools by category
The products vary from one organization to the next, but the categories of sysadmin tools do not. A working toolkit has one of each:
| Category | What it does | Read more |
|---|---|---|
| Directory service | One place for accounts, groups and authentication | Active Directory explained, free Active Directory tools |
| Patch management | Inventories, tests and deploys updates | Patch management software, ranked |
| Monitoring | Watches availability, capacity and performance, and raises alerts | Network management software, ranked |
| Log management | Collects and searches logs from every system | The ELK stack |
| Device management | Enrolls, configures and wipes laptops and phones | MDM software, ranked |
| Remote management | Reaches and fixes machines that are somewhere else | What RMM is |
| Ticketing | Tracks requests and incidents so nothing is forgotten | PSA software, ranked |
| Configuration records | Inventory of systems and how they depend on each other | What a CMDB is |
CareerSysadmin skills and tools
Once the system administration basics above are familiar, these are the technical skills a system administrator needs, roughly in the order worth learning them:
- One operating system in depth, then a working knowledge of the other.
- Networking basics: IP addressing, DNS, DHCP and how to tell a network fault from a server fault. The networking library covers them.
- Directory services and permissions.
- Scripting in PowerShell or Bash.
- Virtualization and cloud, since most servers are now virtual. See the virtualization library.
- Security fundamentals, covered in the security library.
The career usually runs from help desk or junior administrator to systems administrator, then to a senior or lead role. From there sysadmins tend to specialize: cloud engineering, security, DevOps, or architecture, where the job becomes designing computer systems instead of maintaining them.
There is no single route into the role. Many sysadmins start on a help desk and take on server work as they prove themselves; others come through a computer science or information technology degree.
Vendor-neutral certifications such as CompTIA A+, Network+ and Security+ show the fundamentals, and vendor certifications from Microsoft, Red Hat and the cloud providers show depth on one platform. Employers weigh hands-on experience above either, which is why a home lab, a few virtual machines and a network to break and fix, is the most common advice experienced administrators give.
The skills that are not technical matter as much: writing things down, explaining a problem to someone who is not technical, and staying methodical when a system is down and people are watching.
