| What the role owns | The systems the business runs on, not the tickets about them: identity (Active Directory and Entra ID, or Okta), email and collaboration, file and print, endpoints and their build process, servers and hypervisors, patching, monitoring, and backup and restore. Accountable for whether people can work today and whether the company can get back after a bad day. |
|---|---|
| Closest confusions | A help desk technician owns the ticket. A network engineer owns the path between things: switches, routing, firewalls, wireless, SD-WAN. A DevOps engineer, SRE or platform engineer owns the delivery path for a product the company sells and is expected to have code under review in a repository. A cloud engineer owns resources in cloud accounts built with infrastructure as code. A systems administrator owns the running estate everyone else depends on. |
| Licence and credential gate | No US state licenses systems administration, and there is no apprenticeship or supervised-hours requirement to clear. Certifications are the de facto screening gate instead: CompTIA Security+ where the employer touches US Department of Defense work, otherwise Microsoft AZ-104, MS-102, SC-300 or MD-102 for the Microsoft estate, Red Hat RHCSA or Linux Foundation LFCS for Linux, CKA for Kubernetes. Study time is weeks of evenings for someone already administering the platform, not years. A background check is near universal; a security clearance applies only to government and defence work, is sponsored by the employer, and takes months. |
| Typical hiring loop | Short. Application with knockout questions (onsite days, on-call willingness, driving, lifting), a 15 to 30 minute screen on pay and logistics, then a 45 to 90 minute technical interview with the IT manager and a senior admin that is mostly troubleshooting scenarios. Sometimes a hands-on lab or scripting exercise, sometimes a conversation with a department head you would support. A large share of private-sector roles are filled as contract or contract-to-hire through staffing firms, which is a faster path with a recruiter screen in front of it. Managed service providers can offer in a week; public sector and cleared roles take two to six months. |
| Who screens you | Rarely a specialist technical recruiter. At a small or mid-sized employer the IT manager reads the resumes personally and screens for whether your environment looks like theirs. At a managed service provider a service delivery manager screens for breadth and billability. At a staffing firm an account recruiter screens on keywords and rate before anyone technical sees you. In public sector an HR analyst checks minimum qualifications against the posting word by word first, so matching the posting's stated requirements literally matters more there than anywhere else. |
| Pay | No single band worth quoting. Start from the US Bureau of Labor Statistics OES code 15-1244, network and computer systems administrators, and read the percentile spread and your own metro table rather than the national median, because that code lumps junior with principal and includes network work. Then read live ranges in states that require them in postings, including Colorado, California, Washington, New York, Illinois, Minnesota, Maryland, Massachusetts, New Jersey, Vermont, Hawaii and the District of Columbia; the list has grown most years, so check the current one. Federal roles publish their scale: the GS 2210 IT specialist series plus the locality pay table. |
| Resume evidence that lands | Counts with units: users supported, endpoints by platform, physical versus virtual servers, sites, hosts and VMs, mailboxes, terabytes protected, monthly ticket volume, size of the on-call rotation. Plus named migrations with a cutover date, patch compliance and restore times taken from your own reporting, and the platform nouns with version numbers. Two pages is normal and expected past a few years in the field. |
| What changed by 2026 | Five things set the current market. Windows 10 support ended 14 October 2025, and because Extended Security Updates were purchasable, fleet migrations are still running through 2026-27 rather than finished. Exchange Server 2016 and 2019 went out of support the same day, forcing a move to Exchange Online or Exchange Server Subscription Edition. Windows Server 2016 reaches end of extended support on 12 January 2027, so server refresh work is live right now. Broadcom's licensing changes after acquiring VMware put hypervisor migration on many roadmaps. And enforced multi-factor authentication plus cyber insurance questionnaires turned identity hygiene and tested restores into audited facts rather than intentions. |
What a systems administrator actually owns, and the titles that mean the same job
A systems administrator owns running systems. That is the whole distinction, and it is the one most candidates fail to make on paper. A help desk technician is measured on tickets closed and users unblocked. A systems administrator is measured on whether the thing itself keeps working: whether the domain controllers are healthy, whether patches landed on the agreed share of endpoints inside the window, whether the backup that ran last night can actually be restored, whether the certificate that expires in March gets renewed before it expires rather than at 6am on a Saturday.
In practice the estate is some mixture of: identity, meaning Active Directory and Entra ID or Okta, group and role structure, joiner-mover-leaver process, multi-factor authentication and Conditional Access; email and collaboration, usually Microsoft 365 or Google Workspace with whatever is left on-premises; endpoint management, meaning Intune and Autopilot for Windows, often co-managed with Configuration Manager in older estates, Jamf for Macs, imaging or provisioning, software deployment, local admin rights; servers and the hypervisor or cloud under them; networking at the level of DNS, DHCP, VPN and the firewall rules you asked for; monitoring and alerting; and backup, which in 2026 means an immutable or air-gapped copy and a restore you have tested on purpose.
The job also has a non-technical core that interviews probe harder than candidates expect: change control, documentation, vendor management, licence true-ups, and telling a senior person no in a way that leaves you both employed. A systems administrator who cannot produce a runbook is a single point of failure, and experienced hiring managers have been burned by exactly that.
The same job is posted under a long list of titles. Search for the work, not the words.
- Direct synonyms worth searching: Systems Administrator, Sysadmin, IT Systems Administrator, Systems Engineer, Infrastructure Engineer, IT Infrastructure Administrator, Network and Systems Administrator, IT Operations Engineer, Systems Administrator II or III.
- Platform-narrowed versions of the same job: Windows Systems Administrator, Linux Systems Administrator, Microsoft 365 Administrator, Endpoint Engineer, Modern Workplace Engineer, Identity Administrator, VMware Administrator, Virtualisation Administrator, Backup Administrator.
- Corporate IT at technology companies, where the fleet is Mac-heavy and automation is assumed: Corporate Engineering, IT Engineer, Workplace Technology Engineer, Client Platform Engineer.
- Adjacent but genuinely different, and applying with a sysadmin resume wastes your time: Network Engineer (owns the path between things), DevOps or Site Reliability Engineer (owns the delivery path and the service objectives for a product the company sells, and expects code review), Cloud Engineer (owns accounts and infrastructure as code), Security Engineer (owns controls and detection), IT Manager (owns budget, vendors and people).
One title trap worth naming: DevOps Engineer is sometimes used by non-technology employers to mean a systems administrator who also touches a CI pipeline. Read the responsibilities, not the heading. If the posting lists Active Directory, Group Policy, Veeam and a ticket queue, it is a sysadmin job regardless of the title, and you should answer it as one.
The reverse trap costs more. A genuine platform or SRE posting at a product company will screen for code in a repository, a testing story, and ownership of a service with error budgets. Applying to those with a resume made of migrations and patch compliance reads as a career change, which it is, and needs a different pitch rather than the same resume with the word DevOps inserted.
The five employers hiring sysadmins, and why that choice matters more than the title
The single biggest determinant of what your next three years look like is not the title or even the pay. It is which type of employer you join. They hire differently, interview differently, value different evidence, and leave you with different options afterwards. Work out which you are looking at before you write a word of the application.
- Internal IT at a non-technology company. Manufacturing, healthcare, legal, construction, logistics, distribution, education, local government, retail head offices, hotels. This is the majority of all systems administrator jobs. The stack is usually Windows plus Microsoft 365, some Linux, one headquarters and some number of sites or plants, a hypervisor estate, and genuine hands-on hardware work. You will be onsite most days because servers, switches and laptops are physical objects. Breadth is enormous, depth is whatever you make it, and the quality of the job depends almost entirely on your manager.
- A managed service provider. MSPs hire constantly, interview fast, and often offer within a week. You will see dozens of environments in a year, which is the fastest technical education available in this field, and you will do it under utilisation targets and timesheets with a queue that never empties. The tooling is a remote monitoring and management plus professional services automation stack: ConnectWise, Datto, NinjaOne, Kaseya, Autotask, Halo. Pay for the same skills usually sits below internal IT. Two to three years at a good MSP is the strongest possible start and a common cause of burnout at year four.
- Staffing firms and contract-to-hire. A large share of private-sector sysadmin work is posted by agencies rather than the employer, as a six or twelve month contract with a conversion option. It is the fastest way into a brand-name environment and into getting paid hourly for the Saturday cutover, and the trade is less job security, benefits that vary wildly, and a recruiter between you and the hiring manager. Ask three things before signing: the bill-to-pay relationship if they will discuss it, who holds the conversion decision, and whether overtime is paid at time and a half.
- Public sector and defence contractors. School districts, counties, state agencies, universities, hospitals, utilities, and the defence supply chain. Gated on a background investigation, often a drug screen, and for some work a clearance the employer sponsors over months. Defence work carries cyber workforce qualification requirements under DoD Directive 8140.01 and DoD Manual 8140.03, which in practice usually means holding a baseline qualification such as Security+ before you get privileged access. The Cybersecurity Maturity Model Certification programme rule took effect in December 2024 and the acquisition rule putting CMMC into new DoD contracts took effect in late 2025, so NIST SP 800-171 control and evidence work now lands on systems administrators in the defence supply chain. Slow hiring, scored panels, strong stability, published pay scales, real constraints on how fast you can change anything.
- Infrastructure or corporate IT at a technology company. Smaller in number, higher in pay, different culture: Mac fleets managed with Jamf, identity in Okta or Entra with SSO and SCIM everywhere, configuration in a repository with pull requests, and an expectation that you automate rather than click. Interviews here look more like software interviews, with a scripting exercise and a design discussion. Datacentre operations, hosting providers and research computing sit in this family too, with their own specialisations: remote hands, HPC schedulers, power and cooling.
Choose by the stack you want to be fluent in three years from now, because fluency is what gets you the job after this one. A candidate with four years of Windows, Microsoft 365, Intune and Veeam has a clear next step into identity, endpoint or security work. A candidate with four years of whatever the ticket needed, across six versions of everything, has breadth that is hard to prove and hard to price.
One warning about very small employers. A one-person IT department is the fastest way to own real scope early, and also the easiest place to spend five years with nothing you can describe to a stranger. If you take that job, take it with a plan: pick one project a year that has a start, a cutover, and a measurable result.
How systems administrator hiring actually works in 2026-27
This is not a software hiring loop and you should not prepare for one. There is usually no take-home project, no four-interview panel day, and no algorithm screen. There is a manager with an unfilled role and a queue that is behind, trying to find out two things: can you be trusted with privileged access to production in your second week, and will you still be here in two years.
The sequence, where there is one, looks like this.
- Application. Almost always through an applicant tracking system with knockout questions attached. The questions that eliminate most candidates are not technical: how many days onsite, will you join an on-call rotation, do you have a valid driver's licence, can you lift 50 pounds, are you authorised to work without sponsorship. Answer them honestly. A no on on-call is not fatal at every employer, but a yes you did not mean ends badly in month two.
- Screen, 15 to 30 minutes. Usually the hiring manager at a small employer, an internal recruiter at a larger one, an agency recruiter on a contract role, an HR analyst in public sector. Pay expectations, location, notice period, and a quick pass over your last environment. Have a one-sentence description of your estate ready: roughly 400 users across three sites, about 60 VMs on four VMware hosts, hybrid Entra, Veeam to an immutable repository, two of us on a one-week-in-two rotation. That sentence does more work than anything else you say.
- Technical interview, 45 to 90 minutes, with the IT manager plus a senior administrator or the person you would replace. Mostly scenarios, some depth questions, some tool specifics. This is where the offer is decided.
- Optional practical. A hands-on lab in a sandbox (join a machine to the domain, fix a broken GPO, correct share and NTFS permissions, write a PowerShell one-liner to list stale accounts), a short scripting exercise, or a whiteboard of the environment you most recently ran. More common at technology companies and MSPs than at internal IT.
- Stakeholder conversation. At internal IT, often a department head who will be your customer: the plant manager, the practice administrator, the head of finance. They are testing whether you can explain a problem without jargon and whether you will show up when their thing is broken. Do not treat this as a formality; people do get rejected here.
- Checks and offer. References, background check, sometimes a drug screen in manufacturing, healthcare, transport and government. For cleared work, the clearance process starts after the conditional offer and runs for months. Expect the written offer to specify on-call expectations and exempt or non-exempt status; read both.
Timelines, honestly: a week to a month at an MSP or through a staffing firm, two to six weeks at internal IT, two to six months in public sector, and longer again where a clearance has to be granted. If you need income soon, apply to MSPs and agencies in parallel with everything else, because they are the parts of this market that move quickly.
Where the postings actually are, by employer type: USAJOBS for federal, NEOGOV and GovernmentJobs for state, county and city roles, school district and university HR pages directly (their postings often never reach the big boards), the career pages of the MSPs within commuting distance of you (search for managed IT services plus your metro and apply to all of them), and LinkedIn, Indeed and Dice for private employers and agencies. Local employers with one IT person frequently post only on their own site and a local job board.
The two knockouts worth planning around are location and on-call. A large share of systems administrator work is onsite-bound because the hardware is in a building, and the remote postings that do exist attract very large applicant pools and usually want cloud and automation depth rather than general administration. If you want remote, aim at Microsoft 365 and identity administration, MSP remote support tiers, or cloud operations, and say in your first line that you work remotely in a named time zone.
Public sector deserves one specific tactic. The HR analyst screening you is comparing your application against the posting's stated minimum qualifications, often literally. If the posting says three years administering Windows Server and Active Directory, your application must contain those words attached to dates that add up. This is not keyword stuffing, it is clearing a check that a technical person never sees.
Certifications: which ones move a screen, and the one that is a contract condition
There is no licence for this work. That absence is why certifications carry so much weight at the screening stage: they are the only standard signal available to a non-technical filter. They matter in three specific places and almost nowhere else. HR screens and public sector minimum qualifications use them as pass or fail. Managed service providers need staff certifications to hold vendor partner tiers, so they will often pay for yours. And government contracts can mandate them outright.
That last case is the only one where a certification comes close to non-negotiable, and the detail matters because the rules changed. Work under US Department of Defense contracts falls under the cyber workforce framework in DoD Directive 8140.01, with the qualification requirements in DoD Manual 8140.03, which replaced the old 8570.01-M baseline certification tables. Under 8140.03 a person can be qualified by certification or by a combination of education, training and experience plus continuing education, so the blanket claim that Security+ is always legally required is wrong. In practice, individual contracts, contracting officers and company policies still specify a baseline certification, and privileged-access accounts are frequently gated on holding one, so the honest version is: read your contract's own requirement, and expect to be asked for Security+.
Beyond that, a technical interviewer will discount your certifications almost entirely and ask you questions instead. The exception is the hands-on exams, because they cannot be passed from a question dump.
- CompTIA. A+ is for help desk entry and does little once you have a job. Network+ is a reasonable foundation if your networking is weak. Security+ is the one with teeth, because of the DoD baseline and because it has become a generic HR proxy for having security awareness. Treat these as screen-passers, not as evidence.
- Microsoft, for the estate most of these jobs run on. AZ-104 Azure Administrator Associate is the most broadly recognised. MS-102 covers Microsoft 365 administration, SC-300 identity and access, MD-102 endpoint administration, and the AZ-800 and AZ-801 pair covers Windows Server hybrid work. Microsoft retires and renames exams regularly, so confirm the code, the price and the renewal rules on the current certification page rather than in a blog post. If you administer Microsoft 365 daily, SC-300 and MD-102 map most directly to what postings now ask for.
- Linux. Red Hat RHCSA, exam code EX200, is a hands-on practical exam in a live environment, and it is the credential Linux-heavy employers actually respect for that reason. RHCE, now Ansible automation, follows it. The Linux Foundation LFCS is cheaper and also performance-based. A multiple-choice Linux certification convinces nobody who runs Linux.
- Cloud and containers. AWS's SysOps Administrator Associate for AWS shops, AZ-104 for Azure, checking first that the exam is still current because AWS reshuffles its catalogue. The Certified Kubernetes Administrator is performance-based and open-book against the official documentation, which makes it genuinely hard if you have not used Kubernetes, which is exactly why it carries weight.
- Virtualisation, with a caveat. VMware certifications still appear in postings from shops that stayed on VMware, and the names and tracks changed under Broadcom, so check what the current equivalent of VCP is before paying. VMware skills remain in demand precisely because migrations off it need people who understand both sides. But the licensing changes moved the direction of travel, so Proxmox VE, Nutanix and Hyper-V experience is now worth as much on a resume as the certification is. If you are choosing where to spend a weekend, build a migration in a lab rather than sit an exam.
- MSP vendor certifications: ConnectWise, Datto, NinjaOne, Kaseya. Usually free, usually quick, valuable to exactly one employer type. Do them when you work there, not before.
If you have none and are trying to get the first job, the efficient order is: Security+ if you are anywhere near government or defence work, otherwise AZ-104 or MS-102 for the Microsoft path, or RHCSA for the Linux path. One certification plus a lab you can describe in detail beats three certifications and nothing to talk about, every time.
On degrees: a bachelor's is listed on many postings and waived in practice at most private employers, who will take equivalent experience. It stays a hard filter in three situations: public sector postings where the minimum qualification is written into a classification, federal GS classification, and visa sponsorship. If you have no degree, the certifications are doing more work for you, and the lab and project evidence are doing most of the rest.
What systems administrators are paid, and what moves it
Do not trust a salary number from an aggregator that does not say where it came from. Two sources are authoritative and free, and both beat a band someone quoted on a forum.
First, the US Bureau of Labor Statistics Occupational Employment and Wage Statistics code 15-1244, network and computer systems administrators. Read the percentile table and the state and metropolitan tables, not the national median: this code covers everyone from a two-year administrator at a school district to a principal administrator at a bank, and it includes network work, so the median describes nobody in particular. Your realistic target is a percentile band in your own metro, adjusted for employer type. The same agency's Occupational Outlook Handbook projects employment for this occupation growing more slowly than the average across all occupations; read the current entry for the figure rather than trusting a number you saw repeated. That is the real demand picture: a very large installed base of jobs turning over steadily, not a growth field.
Second, live postings in states that require a pay range by law, which currently include Colorado, California, Washington, New York, Illinois, Minnesota, Maryland, Massachusetts, New Jersey, Vermont, Hawaii and the District of Columbia, with several cities adding their own. Read those ranges even for jobs you are not applying to, because they are the only published numbers tied to a specific stack, level and city. A remote posting from a Washington employer tells you what that employer pays.
Federal and many public sector roles publish their scale outright. Federal systems administration sits in the GS 2210 IT specialist series, commonly with a parenthetical specialty, and the grade plus the locality pay table gives you the exact number before you apply. Universities, counties and school districts usually publish classification schedules too.
What actually moves pay for the same skill set, roughly in order of effect:
- Employer type. An MSP and an internal IT department in the same city, hiring for the same skills, can differ substantially, with the MSP lower. Finance, pharmaceuticals, energy and technology pay above education, nonprofit and local government for the same work.
- Geography and whether the role is onsite-bound. Onsite roles are priced to the local market. The remote roles that exist are priced nationally and competed for nationally.
- Specialisation. Identity and access, virtualisation migration, backup and disaster recovery, and Linux at scale all price above general administration. Generalists are paid for breadth, specialists for scarcity.
- Clearance. An active clearance is a durable premium in the defence market, for a simple reason: the employer avoids months of waiting. Nobody can grant it to themselves. If yours has lapsed, know the date your access ended, because reinstatement after a short break is far cheaper for an employer than a new investigation, and continuous vetting has replaced most periodic reinvestigations.
- On-call and shift. Ask directly whether on-call carries a stipend, whether call-outs are paid, and whether the role is exempt or non-exempt. Many systems administrator roles are classified exempt, which means Saturday cutovers are unpaid. A non-exempt or hourly contract role with overtime can out-earn a higher-banded exempt one.
- Title step rather than negotiation. Internal IT salary bands are usually narrow and tied to a job family. Moving from Administrator to Senior Administrator or Systems Engineer moves pay more than a strong negotiation inside one band does. If the band is capped, negotiate the title.
One negotiation note specific to this field: certification reimbursement, a training budget and lab or test hardware are frequently approvable when salary is not, because they come from a different budget line. So is a written on-call rotation size. Ask for those in writing in the offer, not verbally at the end of the interview.
The resume: make one environment legible in six lines
A systems administrator resume is read by someone deciding one thing: does this person's last environment resemble mine. Everything that helps them answer that belongs on the page, and everything else is noise. The failure mode is universal and easy to fix: candidates describe duties in adjectives and leave out every number that would make the estate real.
Compare two versions of the same job. Responsible for maintaining servers, troubleshooting hardware and software issues, and supporting end users in a fast-paced environment. Against: sole administrator for 310 users across two plants and a head office, 48 VMs on three Hyper-V hosts, hybrid Entra ID with Conditional Access and MFA on all staff accounts, Veeam to a hardened Linux repository with quarterly tested restores against a four-hour recovery time objective, monthly patch compliance reported above 97 percent. Same job. Only one of them can be assessed. Those numbers are an example of the shape; use your own, taken from your own reporting.
Quantify the environment with real units.
- People and devices: users supported, endpoints by platform, mailboxes, sites or buildings, time zones covered.
- Servers and platforms: physical versus virtual, VM count and host count, hypervisor and version, operating system versions still in the estate, tenant count, data volume protected in terabytes.
- Operational numbers from your own reporting, never invented ones: monthly ticket volume, patch compliance percentage, uptime for a named service, restore time measured in a real test, mean time to resolve if your ITSM reports it, size and frequency of the on-call rotation.
- Money, if you have it: licence spend you reduced at a true-up, hardware refresh budget you ran, the cost of the thing you consolidated. Numbers with currency attached get read twice.
- Projects with a date and a verb that implies ownership: migrated, cut over, consolidated, decommissioned, rebuilt, rolled out, recovered.
The projects landing interviews in this cycle are specific and recent, and if you ran any of them they belong at the top of the bullet list: a Windows 10 to Windows 11 fleet migration and what you did about the hardware that could not take it, including whether you had to buy Extended Security Updates to finish; Exchange Server 2016 or 2019 out of support and onto Exchange Online or Subscription Edition; Windows Server 2016 off the floor ahead of its January 2027 end of support; a hypervisor migration off VMware to Hyper-V, Proxmox or Nutanix with the licensing reason stated plainly; file shares to SharePoint or OneDrive with permissions actually reviewed rather than copied; on-premises Active Directory to a hybrid or cloud-first identity with MFA enforced and an exceptions process; a backup redesign with an immutable or air-gapped copy and a restore test on the calendar; a patch compliance programme that moved a number; audit or framework evidence work for SOC 2, HIPAA, PCI DSS, NIST SP 800-171 or CMMC; a cyber insurance questionnaire you had to answer truthfully, and the gaps you closed in order to.
What gets skipped by every reader: a cloud of sixty technology nouns with no context, responsible for as the opening of every bullet, Microsoft Office proficiency, excellent communication skills, certifications in progress listed as if earned (interviewers verify, and this one ends candidacies), and generic lines like troubleshoot hardware and software issues that describe the whole occupation rather than you. A home lab belongs at the top only if you have no professional experience; for an experienced candidate it goes last, briefly.
Format advice specific to this field: one column, standard headings, dates on every role including months, and the platform nouns spelled the way the posting spells them, with versions. These postings are noun-dense, the screens are noun-matched, and the human reader is scanning for the same words. Two pages is normal past a few years. Use the second page for environment detail rather than for more adjectives.
If you can attach artefacts, attach the right ones. A sanitised network or identity diagram, a runbook you wrote, or a small public repository of scripts with readable comments all prove things a bullet cannot. Sanitise properly: no real hostnames, no internal IP ranges, no user data, nothing that identifies a former employer's topology. A hiring manager who sees you publish an employer's internals learns something about you that outweighs the script.
The interview: scenario troubleshooting, and the judgment test underneath it
The technical interview for this role is a troubleshooting conversation, and what is graded is method rather than trivia. A good interviewer does not care whether you remember the exact event ID. They care whether you establish scope before acting, whether you ask what changed, whether you look at evidence instead of guessing, and whether you would run a destructive command in production without a change record. Candidates who narrate their reasoning pass. Candidates who leap to an answer and are wrong fail even when the answer was right.
The questions below come up constantly in some phrasing. For each, what a strong answer actually contains.
- A user says the network is slow. Scope first: one user, one subnet, one site, or everyone. Then establish the path and test it piece by piece rather than guessing: name resolution, the local link, the VPN or SD-WAN, the application itself. Say what you would measure, not what you suspect. The tell of a weak answer is naming a cause in the first sentence.
- Users at one site cannot reach a file share; another site can. Authentication versus name resolution versus path. Kerberos and time skew, DNS and the site's own resolver, DFS referrals, the firewall rule someone changed on Friday. Good answers ask what changed in the last 24 hours before touching anything.
- Logins are taking four minutes. Group Policy processing, logon scripts, drive and printer mapping, roaming or redirected profile size, slow link detection, a dead domain controller the clients are still trying. Mention how you would measure it, with gpresult, event logs, or Group Policy operational logging, rather than listing suspects.
- Our mail is going to spam. SPF, DKIM and DMARC, and specifically alignment rather than mere existence; reputation, and whether anything on your network is sending without going through the gateway; how you would read the headers of an actual rejected message. A candidate who says check SPF and stops has seen the problem in a blog post. A candidate who asks for a message header has solved it.
- A certificate expired on a Saturday morning. The honest answer is about inventory and renewal process, not the incident. What do you use to know every certificate's expiry date, who owns the renewal, and what did you change after the first time this happened to you.
- Walk me through what happens when a domain-joined laptop boots and a user signs in. A depth probe with no trick in it. DHCP, DNS, domain controller location, secure channel, Kerberos ticket, Group Policy, profile load, then the token the applications use. How far you get tells the interviewer your actual level in about 90 seconds.
- Tell me about your last outage. The most predictive question in the loop. Give a timeline: how you found out, what you checked, what you tried that did not work, how service was restored, what the root cause turned out to be, who you told and when, and the specific thing that is different now because of it. Say the part where you were wrong. Candidates who present a flawless outage are not believed.
- When did you last restore from backup, and what did you restore? We have backups is a failing answer, and interviewers have learned to ask it this way deliberately. Name the restore, the thing recovered, how long it took, and whether the measured time met the recovery objective you were supposed to meet. If you have never performed a restore, do one in your lab this week so that you can.
- The CFO wants MFA turned off for their phone. A judgment question, not a security quiz. What the exception process is, what you would offer instead, what you would record, who approves the risk, and when it gets reviewed. The wrong answers are both extremes: doing it, and refusing with no alternative.
- What is the last thing you automated? Expect a follow-up on how you tested it and what it broke. See the AI section below, because in 2026 this question usually has a second half about assistance.
If there is a practical lab, narrate continuously while you work and say what you expect each command to show before you run it. Interviewers are watching for whether you check before you change, whether you reach for documentation without embarrassment (everyone does; pretending otherwise is a tell), and whether you would have taken a backup or a snapshot before editing. A wrong command with good narration beats silent correctness.
Three things belong in the questions you ask them, because the answers predict whether the job is good: how many people are in the on-call rotation and what a typical week of pages looks like; what state the documentation is in and whether you would be inheriting an estate nobody has mapped; and what the last two significant projects were, which tells you whether this team does projects at all or only firefights. A manager who cannot answer the third question is describing a job with no career in it.
Finally, the thing that quietly decides a lot of these interviews: how you talk about users. The occupation has a tradition of contempt for the people it serves, and hiring managers at internal IT screen it out hard, because the department head in the next interview will notice it in thirty seconds. Describe a frustrating user problem as a systems problem and you will stand out more than you expect.
Getting in, and getting out: the ladder changed at both ends
The traditional route into this job was tier-one help desk for a year or two, then a junior administrator role. That rung is thinner than it was, and the reasons are mundane rather than dramatic: self-service password reset removed the single highest-volume ticket type, device provisioning moved to Autopilot, Jamf and MDM so imaging benches disappeared, software distribution became a portal, and more recently chat-based deflection answered another slice of the easy questions. Budget pressure and offshored first-line support did as much of this as any AI feature. Fewer tier-one seats means fewer places to be taught the basics on someone else's payroll.
Where the entries actually are in 2026-27, in rough order of how reliably they work.
- A managed service provider at tier one or tier two. Still the single most reliable way in, still hiring constantly, still the fastest learning available. Say in your application that you want breadth and expect a queue; they are screening for people who will not be shocked by it.
- The only IT person at a small company, posted as IT Support or IT Coordinator. Enormous scope immediately, nobody to learn from, and a real risk of stagnation. Take it with a plan to leave with named projects.
- Public sector and institutional IT: school districts, community colleges, counties, hospitals, housing authorities. They hire at lower experience levels than private employers because their pay is lower, their process is slower, and their stability is better. The minimum qualifications are literal, so apply with the posting's words in your application.
- Datacentre technician, remote hands, NOC technician. Shift work, strong hardware and process grounding, and a clear path into systems or network administration at the same employer.
- A staffing firm contract. Agencies will place a candidate with thinner experience than an employer would hire directly, because the risk is shorter. A twelve-month contract inside a real estate is credible experience and names a real employer on your resume.
- Internal transfer. The most underrated route. If you already work somewhere with an IT department, you know the business, the people and the systems, and hiring you is low risk. Volunteer for the asset inventory, the migration pilot group, the offboarding cleanup. People get moved across on the strength of exactly that.
For a first job, the lab is not a hobby, it is your evidence, and the difference between a lab that works and one that does not is whether it contains a real environment rather than a single virtual machine. A credible one: a hypervisor on a used workstation (Proxmox VE is free, and the Hyper-V role comes with Windows Pro now that the standalone free Hyper-V Server is gone), a domain controller with DNS and DHCP and a second one so you can break the first on purpose, a Windows client joined to the domain and managed by Group Policy, a Linux host running something real, a backup target, and at least one restore you performed and documented. Add a cloud tenant, with one caveat worth knowing before you plan around it: the Microsoft 365 Developer Program now requires an eligible Visual Studio subscription, so a trial tenant or a single paid Business Basic licence is the reliable route to a tenant of your own. Then write the lab up as a runbook with the commands and the screenshots, and put the scripts in a public repository. In an interview, I broke replication between the two domain controllers deliberately and here is how I found it, is worth more than any certification on the page.
Volunteer IT for a nonprofit, a church, a youth sports league or a small charity is the most credible non-employment experience in this field, for one reason: it is a real environment with real users who complain. It is also the only kind of unpaid work worth doing here, and it should be time-boxed.
Where this job leads, and what each exit needs from you now. Security engineering or governance, risk and compliance is the shortest hop, because identity, endpoint and logging experience is exactly what those teams lack; start by owning the MFA rollout and the audit evidence. Identity and access management is the most direct specialisation and is hiring well; own joiner-mover-leaver and Conditional Access. Cloud engineering needs infrastructure as code in a repository, not console clicks, so build something with Terraform, OpenTofu or Bicep and keep it in version control. Platform engineering and SRE need a product-facing story with service objectives and code review, which is the biggest leap from here. IT management needs budget, vendor and people evidence, so volunteer to run the renewal and the vendor review. Pre-sales and solutions engineering pays well and wants the half of you that can explain things to a department head.
The dead end to avoid is specific and common: being the only person who understands an undocumented estate, with no project you could describe to a stranger, for five years. That person is hard to promote and hard to hire, and they are usually the last to notice. The exit is always the same: document the estate, then take the migration.
What a systems administrator has to know about AI in 2026-27
Start with the honest version, because the hype and the reality are further apart in this role than in almost any other. The automation that removed manual systems administration work did not arrive with large language models. It arrived over the previous decade, as cloud and SaaS removed servers, as MDM and Autopilot removed imaging, as configuration management and infrastructure as code removed hand-built machines, and as self-service removed the password reset queue. That transition is mostly done, and it is a large part of why this occupation's projected employment growth is slow rather than fast. If you are worried that AI is about to eliminate the job, the more accurate worry is that the thing you feared already happened, quietly, and the job that remains is the harder half of it.
What genuinely changed in the last two years is narrower and worth getting right. Three things. First, in shops that permit the tools, the first draft of a script, a policy, a KQL query or an Ansible playbook now arrives in seconds, which moved the scarce skill from authoring to reviewing and scoping. Second, you are now the person responsible for making AI tools safe for your company to use, and that is a real new workload with Microsoft 365 Copilot deployment at the centre of it. Third, AI-assisted ticket deflection thinned the rung below you, which changes how people get into this field more than it changes the field itself.
Be precise about the assistants inside the admin consoles too, because overclaiming here is easy to catch. Copilot in Intune, Security Copilot, and the AI features in monitoring and RMM platforms mostly summarise, correlate and suggest. Some will take remediation actions if you enable them, which is a configuration decision you own. Nothing in that stack takes accountability for the change, and no interviewer believes a candidate who implies otherwise.
What has not changed at all: hardware is physical, cutovers happen at night, identity data is messy because organisations are messy, licences get audited, restores either work or they do not, and somebody has to be accountable at 3am. Accountability is the thing employers pay for, and it does not generate. A script a model wrote in nine seconds that runs as Domain Admin against 400 machines is a blast radius, not productivity, and the senior administrator interviewing you knows that even if they have not phrased it that way.
In interviews this shows up as two questions, and they are not the same question. What have you automated with AI assistance is a warm-up; almost everyone has an answer. We are turning on Copilot next quarter, what would you check first, is the one that separates candidates, because the correct answer is not about AI at all. It is about who can currently open which SharePoint site, and whether anyone has looked.
If your employer has no AI programme at all, three of these are available to you anyway, and all three are things you can start this month without asking permission. Audit your tenant's broad-permission sharing and tenant-wide grants, which is useful on its own merits and gives you the Copilot readiness answer. Retire one shared service account in favour of per-automation identities with scoped roles. And put the safety rails on your own scripting: dry runs, counted scopes, pilot rings, a rollback written before the change. None of those need a budget, and each produces a specific interview answer with a number in it.
The claim to avoid is the inflated one. A candidate who says AI has transformed their work, automated their manual tasks and freed them for strategy is describing a LinkedIn post, and an experienced interviewer hears someone who has not spent a night rebuilding a failed domain controller. The credible version is narrower and more convincing: the drafts arrive faster, the review burden went up, the governance workload is new and real, and the accountability is exactly where it was.
Reviewing and scoping generated scripts rather than writing them from scratch
The bottleneck moved from authoring to verifying, and the characteristic failure of a generated administration script is not that it fails, it is that it runs successfully against the wrong set of objects. A plausible PowerShell filter that silently matches every enabled account instead of every stale one does not throw an error. Every employer is now exposed to this, and very few have a control for it beyond the judgment of the person who pressed enter.
Show it: Describe one change you ran with the safety rails named: a dry run with -WhatIf or Ansible --check, an explicit scope filter you verified by counting the objects it matched before acting, a pilot ring of a stated size, logging of what was changed, and a rollback you had ready. Then say what the dry run caught, because that single detail is what proves the habit is real rather than described.
Microsoft 365 Copilot readiness, which is almost entirely permission cleanup
Copilot can surface anything the user asking is already permitted to open. It grants no new access, which is exactly why it is dangerous: in most tenants the existing access is far broader than anybody realises. Years of anyone-with-the-link sharing, sites granted to Everyone except external users, an HR folder inherited into a Teams site, a finance workbook on someone's OneDrive shared company-wide in 2022. None of that was a visible problem while finding it required knowing where to look. The day a search assistant is enabled, it becomes one. This is the most common AI-related systems administration project of this cycle, and it is a governance job wearing an AI label.
Show it: Give the audit and the numbers: how you inventoried broad-permission links and tenant-wide grants, what you used (SharePoint admin reporting, SharePoint Advanced Management, Restricted Content Discovery, Purview and sensitivity labels, site-level access controls), how many sites or links you remediated, what you excluded from Copilot's reach entirely and why, and how you stopped the sprawl returning by changing the default sharing policy. Name the one site whose permissions you refused to fix in place and archived instead.
Governing which AI tools can touch company data, including the consent surface
Staff paste customer data into consumer assistants, install browser extensions with full page access, and click through OAuth consent for an AI note-taker that requests read access to every meeting and mailbox in the tenant. The controls for this already exist in the tooling you administer: app consent policies and the admin consent workflow, Conditional Access, DLP policies, browser enterprise policy, and the tenant's allow and block lists. Nobody else in the company is going to configure them.
Show it: Name the specific policy you set, the application you blocked and the reason, and most importantly the sanctioned alternative you provided. The difference between a systems administrator and an obstacle is whether a block came with a supported option attached. If you ran an approval path for new AI tools, say who the approvers were and how long a decision took.
Machine and agent identity: no shared accounts, no secrets in scripts
Automation and AI agents authenticate, and they are multiplying. A shared service account with a password in a scheduled task is the oldest audit finding in existence, and an agent acting on a user's behalf raises a newer question that is being asked in real reviews: can it read anything the person who invoked it could not. Cyber insurers and auditors both now ask about privileged account inventory, and we have one admin account everyone uses ends that conversation badly.
Show it: Describe the model: a distinct identity per automation rather than a shared account, managed identities or workload identity federation replacing stored secrets, scoped roles instead of Domain Admin or Global Admin, secrets in a vault with rotation, and an audit trail that shows which identity made which change. If you retired a shared account, say how many scheduled tasks and scripts you had to find first, because that number is the interesting part.
Knowing exactly what the AI in your monitoring and RMM stack is allowed to do
Monitoring platforms, endpoint tools and MSP remote management suites all shipped anomaly detection, automated remediation and AI ticket triage. Those features can make changes in your environment that you did not personally authorise, and a vendor-supplied auto-remediation that restarts the wrong service during month-end close is your incident, not theirs. The administrators who get burned are the ones who left the defaults on without reading what they do.
Show it: Say which automated remediations you enabled, which you deliberately disabled, and what convinced you: the false positive, the unexpected restart, the alert storm. Then say how the ones you kept are logged and reviewed. This answer reads as operational maturity in a way that no tool list does.
Treating documentation as production, because the assistant answers from it
Once a chat assistant or an AI-backed service desk answers staff questions from your knowledge base, a wrong or stale runbook produces wrong answers at scale and with apparent authority. Documentation moved from being an internal courtesy to being a user-facing system you own. This is the quiet consequence of deflection that almost nobody mentions in interviews, which is exactly why mentioning it lands.
Show it: Describe what you restructured and what it changed: which articles you rewrote or retired, how you handle the content that must never be self-served (anything involving identity verification or privileged access), the deflection or first-contact resolution numbers from your own ITSM rather than a vendor's marketing, and the escalation path for when the assistant is confidently wrong.
Keeping a deterministic, auditable path for anything that has to be provable
Every compliance regime in this space, SOC 2, HIPAA, PCI DSS, NIST SP 800-171 and CMMC, rests on being able to show who changed what, when, with whose approval. AI-assisted work is entirely compatible with that, and completely incompatible with the way it is often actually done: a suggested command, pasted into a privileged session, with no ticket. The skill is keeping the assistance inside change control rather than beside it.
Show it: Describe a change process that survived an audit or an insurance questionnaire with AI-assisted work inside it: the ticket, the approval, the tested rollback, the evidence captured automatically rather than by memory. If you were the person who wrote the standard for how your team uses assistants on privileged systems, say so, and say what it forbids.
AI infrastructure operations, if and only if your shop has any
A minority of systems administration jobs now include real AI hardware: GPU servers or an on-premises inference appliance, which arrive with power and cooling requirements most server rooms were not built for, driver and toolkit version dependencies that break jobs when updated carelessly, scheduler queues to manage, and model artefact storage that grows faster than anyone budgeted. Where this exists it is a genuine specialisation and it pays. Where it does not exist, claiming it is an easy thing for an interviewer to catch.
Show it: Real numbers only: kilowatts per rack and what you had to change about power or cooling, how you pin and stage driver and toolkit versions without breaking running jobs, how storage growth was forecast and controlled, and how access to expensive hardware is allocated between teams. If your estate has none of this, say plainly that you have not run GPU infrastructure, and talk about the capacity and power work you have done instead.
What a screen is looking for
These are the terms that a resume screen, human or automated, is matching against for this role. Use the ones that are true of you, in the words the posting uses.
- Systems administrator
- Sysadmin
- Systems engineer
- Infrastructure engineer
- IT operations
- Active Directory
- Entra ID
- Azure AD
- Group Policy
- GPO
- Domain controller
- Kerberos
- LDAP
- DNS
- DHCP
- PKI
- Certificate services
- Certificate lifecycle
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2025
- Windows 11 migration
- Windows 10 end of support
- Extended Security Updates
- Exchange Server
- Exchange Online
- Exchange Server Subscription Edition
- Microsoft 365
- Microsoft 365 administration
- SharePoint Online
- OneDrive for Business
- Microsoft Teams administration
- Microsoft Purview
- Sensitivity labels
- Data loss prevention
- Microsoft 365 Copilot
- Copilot readiness
- Restricted Content Discovery
- Microsoft Intune
- Configuration Manager
- SCCM
- Co-management
- Autopilot
- Endpoint management
- MDM
- Jamf
- Mac fleet management
- Okta
- SSO
- SAML
- OAuth
- SCIM
- Conditional Access
- Multi-factor authentication
- MFA enforcement
- Privileged access management
- Least privilege
- Joiner mover leaver
- Identity and access management
- PowerShell
- PowerShell scripting
- Bash
- Python scripting
- Ansible
- Terraform
- OpenTofu
- Bicep
- Infrastructure as code
- Configuration management
- Git
- Version control
- VMware vSphere
- ESXi
- vCenter
- Hyper-V
- Proxmox VE
- Nutanix
- Virtualisation
- P2V migration
- Hypervisor migration
- Linux administration
- Red Hat Enterprise Linux
- RHEL
- Ubuntu Server
- systemd
- Docker
- Kubernetes
- Containers
- AWS
- Azure
- Azure administration
- Cloud migration
- Veeam
- Backup and recovery
- Immutable backup
- Air-gapped backup
- 3-2-1-1-0
- Disaster recovery
- RTO
- RPO
- Restore testing
- Business continuity
- Patch management
- WSUS
- Patch compliance
- Vulnerability remediation
- Microsoft Defender for Endpoint
- Endpoint detection and response
- EDR
- SIEM
- Microsoft Sentinel
- Monitoring
- Zabbix
- PRTG
- Datadog
- Grafana
- Alerting
- Capacity planning
- ITIL
- Change management
- Change control
- Incident response
- Root cause analysis
- Problem management
- ServiceNow
- Jira Service Management
- Freshservice
- Ticketing system
- ITSM
- Runbook
- Documentation
- Asset inventory
- Licence management
- Vendor management
- SLA
- On-call rotation
- Escalation
- NTFS permissions
- File share permissions
- DFS
- Storage administration
- SAN
- NAS
- RAID
- Firewall administration
- VPN
- VLAN
- Network troubleshooting
- SPF
- DKIM
- DMARC
- Mail flow
- Email security
- Phishing response
- CIS Benchmarks
- STIG
- NIST SP 800-171
- CMMC
- SOC 2
- HIPAA
- PCI DSS
- Cyber insurance questionnaire
- Security hardening
- Audit evidence
- CompTIA A+
- CompTIA Network+
- CompTIA Security+
- DoD 8140
- DoDM 8140.03
- AZ-104
- MS-102
- SC-300
- MD-102
- AZ-800
- RHCSA
- LFCS
- CKA
- AWS SysOps Administrator
- VMware certified professional
- ConnectWise
- Datto
- NinjaOne
- Kaseya
- RMM
- Managed service provider
- Help desk escalation
- Tier 2 support
- Tier 3 support
- Security clearance
- Public trust
- GS 2210
Mistakes that cost people this job
Describing duties instead of the environment, so nobody can tell what you have actually run.
Put the counts in the first two lines of each role: users, endpoints, sites, servers physical and virtual, hosts and VMs, mailboxes, terabytes protected, ticket volume, rotation size. The hiring manager is deciding whether your last estate resembles theirs, and adjectives give them nothing to decide with. Supported end users in a fast-paced environment, and sole administrator for 310 users across three sites with 48 VMs on three hosts, describe the same job, and only one of them survives a screen.
Answering when did you last test a restore with: we have backups, they run nightly and I check the job status.
Perform a real restore before your next interview, even in a lab, and be able to say what you recovered, how long it took, and whether that met the recovery time objective you were supposed to meet. Interviewers use this exact phrasing because it separates people who have run a recovery from people who have monitored a job. If your employer has never tested one, schedule it and bring the result; that story is stronger than a clean record.
Collecting multiple-choice certifications while having no environment you can describe in detail.
One certification plus a lab you can discuss for fifteen minutes beats four certifications and no stories. The hands-on exams, RHCSA, CKA and the Linux Foundation performance-based ones, carry weight with technical interviewers precisely because they cannot be passed from a dump. Spend the next weekend breaking replication between two domain controllers and fixing it, rather than on another exam voucher.
Saying yes to onsite requirements or an on-call rotation you do not intend to honour.
Answer the knockout questions truthfully and negotiate before the offer, not after. Ask how many people are in the rotation, how often it comes around, what a typical week of pages looks like, and whether call-outs are paid. These roles fail in month two over exactly this, and the reference you lose is worth more than the job you took.
Applying to DevOps, SRE or platform engineering titles with a systems administration resume and the word DevOps inserted.
Treat it as the career change it is and build the missing evidence: configuration in a repository with a review history, something deployed by a pipeline rather than by hand, a service you can discuss in terms of objectives and error budgets. Until then, aim at the titles that mean your actual job, including Systems Engineer, Infrastructure Engineer, Cloud Operations and Endpoint Engineer, which pay comparably and will not reject you in the screen.
Listing a certification as held when it is in progress, or inflating exposure to a platform you touched once.
Write AZ-104, exam scheduled for March 2027, and keep that date. Interviewers in this field verify certifications and probe platform claims with one specific question, and the candidate who cannot answer it loses the credibility of the whole resume rather than just that line. Honest narrower claims win: I have administered Hyper-V for four years and used VMware in a previous role, not recently.
Treating public sector applications like private ones and getting filtered out before any technical person sees you.
Mirror the posting's stated minimum qualifications in your own words, attached to dates that add up. An HR analyst is checking three years administering Windows Server and Active Directory literally, and a resume that demonstrates it without using those words fails a check the IT manager never sees. For defence-adjacent employers, state your certification status and your clearance status, including the date your access ended if it has lapsed, in the first lines.
Claiming AI transformed your work, or dismissing it entirely.
Say the narrow true thing, because both extremes are tells. The credible answer names one automation you built with assistance, how you scoped and dry-ran it, and what the dry run caught; and separately, one governance thing you own, such as the sharing audit you would run before enabling Copilot, or the OAuth consent policy you set. An interviewer who hears that AI freed you up to focus on strategy hears someone who has not done the work.
Showing contempt for users, in passing, while describing a frustrating ticket.
Describe user failures as systems failures, because that is what a hiring manager is listening for and because the next interviewer is usually a department head you would support. People kept bypassing it becomes the process was slower than the workaround, so I changed the process. This one costs more offers than any technical gap.
Staying five years as the only person who understands an undocumented estate, with no nameable project.
Pick one project a year that has a start, a cutover and a measurable result, and write the estate down. A migration, a backup redesign, an MFA rollout, a patch compliance programme, a hypervisor move. That is simultaneously what makes you promotable internally and the only thing that makes you legible to an outside employer. Documenting the environment is what makes it possible to leave it.
Questions people ask
Is systems administrator a dying job in 2026?
No, systems administrator is not a dying job, but it is not a growth field either, and the honest framing matters. The US Bureau of Labor Statistics projects employment for network and computer systems administrators, SOC and OES code 15-1244, growing more slowly than the average across all occupations; read the current Occupational Outlook Handbook entry for the figure rather than a number repeated secondhand. What that describes is a very large installed base of jobs turning over steadily rather than expanding: almost every organisation with more than a few dozen staff needs someone accountable for identity, email, endpoints, servers and backups. The work that disappeared, imaging benches, password reset queues, hand-built servers, went to cloud, SaaS, MDM and self-service over the past decade, not to AI in the past two years. What remains is the harder half: identity, security, migrations, recovery and accountability.
Do I need a degree to become a systems administrator?
You do not need a degree to become a systems administrator at most private employers, who accept equivalent experience and weight certifications and demonstrable hands-on work more heavily. A degree remains a hard filter in three specific places: public sector postings where the minimum qualification is written into a job classification, federal GS classification in the 2210 IT specialist series, and visa sponsorship. If you have no degree, your certifications and a documented home lab carry the load it would have carried, and managed service providers and staffing firms are the employer types least likely to care.
Which certification should a systems administrator get first?
It depends on the market you are entering. If you are anywhere near US government or defence work, CompTIA Security+ first, because the cyber workforce qualification rules in DoD Directive 8140.01 and DoD Manual 8140.03 mean contracts and privileged-access policies commonly require a baseline qualification before you get an account. For the Microsoft estate that most of these jobs run on, AZ-104 (Azure Administrator Associate) or MS-102 (Microsoft 365 Administrator) first, then SC-300 for identity or MD-102 for endpoints depending on what you do daily. For a Linux path, Red Hat RHCSA, exam code EX200, which is a hands-on practical exam in a live environment and is the reason Linux employers respect it. Check current exam codes and prices on the vendor's own certification page, because they change. One certification plus a lab you can discuss in depth beats a stack of certifications with nothing behind them.
How long does it take to go from help desk to systems administrator?
Moving from help desk to systems administrator commonly takes one to three years, and the variable is not time served but what you were allowed to own. The people who move in about a year are the ones who volunteered for work sitting above the ticket queue: the asset inventory, the migration pilot group, the offboarding cleanup, the patch reporting, the backup checks. The people still at tier one after four years are usually in an environment with no projects, where every day is the queue. If that is you, the move is sideways to a managed service provider, a staffing firm contract, or a small company where the scope is unavoidable, rather than waiting for a promotion that is not structurally available.
What does a systems administrator get paid?
There is no single national systems administrator salary worth quoting, and anyone who gives you one without a source is guessing. Use two authoritative sources instead. First, the US Bureau of Labor Statistics OES code 15-1244, network and computer systems administrators, reading the percentile spread and your own metropolitan table rather than the national median, because that code covers everyone from a junior at a school district to a principal at a bank and includes network work. Second, live postings in states that legally require a pay range, currently including Colorado, California, Washington, New York, Illinois, Minnesota, Maryland, Massachusetts, New Jersey, Vermont, Hawaii and the District of Columbia. Within any market, employer type moves pay most, with managed service providers typically below internal IT for the same skills, and specialisation in identity, virtualisation migration or backup and disaster recovery above general administration.
Should a systems administrator learn Windows or Linux?
Learn the one your target employers run, then learn enough of the other to be useful. In internal IT at non-technology companies, the estate is predominantly Windows with Microsoft 365, Active Directory and Entra ID, and Linux appears as appliances and specific workloads, so Windows and identity depth gets hired. At technology companies, hosting providers, research computing and anywhere running containers, Linux is the base skill and Windows is the corporate fleet. Scripting follows the same split: PowerShell for the Microsoft estate, Bash and increasingly Python for Linux, Ansible for configuration at scale, and version control so your scripts live somewhere other than a share called Scripts. The strongest generalist position is real depth in one platform plus genuine working competence in the other, because almost every real estate is mixed and most candidates can only discuss half of it.
Can I get a remote systems administrator job?
Remote systems administrator jobs exist but are fewer than in adjacent roles, because a large share of this work is physically bound to hardware in a building, and return-to-office pressure hit onsite-leaning roles hardest. The remote postings that do exist cluster in specific areas: Microsoft 365 and identity administration, cloud operations, managed service provider remote support tiers, and multi-site companies hiring a specialist rather than a generalist. They attract very large applicant pools and screen for automation and cloud depth rather than general administration. If remote is a requirement for you, specialise deliberately in identity, Microsoft 365 or cloud operations rather than applying more widely.
What is the difference between a systems administrator and a DevOps engineer?
The difference between a systems administrator and a DevOps engineer is what they are accountable for. A systems administrator owns the systems the company runs on, meaning identity, email, endpoints, servers, backups and patching, and is measured on whether the business can work today and recover tomorrow. A DevOps engineer or site reliability engineer owns the delivery path and reliability of a product the company sells, is measured on deployment frequency, change failure rate and service level objectives, and is expected to have code under review in a repository. They overlap in tooling, automation, containers, cloud and infrastructure as code, which is why people move between them, but the interviews differ: one is scenario troubleshooting of a running estate, the other is system design plus a coding exercise. Note that some non-technology employers use the DevOps title for what is functionally a systems administration job, so read the responsibilities rather than the heading.
What do systems administrator interviews actually ask?
Systems administrator interviews ask troubleshooting scenarios, almost always, and what is graded is method rather than trivia recall. Expect: a user says the network is slow (do you establish scope before guessing), one site cannot reach a file share but another can (name resolution versus authentication versus path), logins take four minutes (Group Policy, profiles, drive mappings, a dead domain controller), our mail is going to spam (SPF, DKIM, DMARC alignment and reading a real message header), walk me through what happens when a domain-joined machine boots and a user signs in (a depth probe), describe your last outage with a timeline and what you changed afterwards, and when did you last restore from backup and what did you restore. Add one judgment question such as an executive asking to bypass MFA, and one on what you automated recently and how you tested it. Narrating your reasoning out loud is what passes these; naming a cause in the first sentence is what fails them.
Is AI going to automate systems administration?
AI is not automating the core of systems administration, and the hype is ahead of the reality in this role specifically. AI writes the first draft of scripts, policies and queries quickly, which moved the scarce skill from authoring to scoping and reviewing, and AI-assisted ticket deflection reduced tier-one volume, which has thinned the traditional entry rung more than it has changed the job itself. The assistants inside admin consoles, Copilot in Intune, Security Copilot, and the AI features in monitoring and RMM tools, mostly summarise and suggest; where they can act, enabling that is your configuration decision and the resulting incident is yours. What has not changed: hardware is physical, cutovers happen at night, identity data is messy because organisations are messy, restores either work or they do not, and somebody is accountable at 3am. What is genuinely new work rather than removed work is governance: making AI tools safe to use in your tenant, which in practice means the SharePoint and OneDrive permission cleanup that Microsoft 365 Copilot exposes, OAuth consent policies for AI applications requesting access to your data, and distinct machine identities for automations and agents instead of a shared service account.
Put this on a resume in about a minute
Paste your history once and point it at the Systems Administrator posting you are looking at. No account, no card.
Build my resume free More roles