Hiring for this role?
Start free with this planFree for your first open role.
Why Hirezen?
- Every interviewer runs the same script and marks the same signals.
- AI drafts the write-ups, and the debrief puts every read side by side.
- No ATS to set up first, and no bot in the call.
System Administrator interview questionsTechnical Interview round
A 60 min interview plan with a time-boxed script, what each question is for, and the signals to score against. Key skills: Identity and access, privileged access and device management, on one company's sign-in setup: where MFA does not reach, closing it without lockouts, who could take the domain and the cloud, and what a company laptop proves.
Opening
Who is interviewing, how the round will run, and a question to settle the candidate in. The standard openingWhere a password is still enough
What this part is for
Purpose
Runs over one page you build yourself, handed over at the start and read in silence for six minutes, which come out of this section; nothing is sent ahead. Write it to this content so every candidate reads the same company. About 215 people: 160 staff, about 60 of them working from home most days; 15 contractors on their own laptops, browser only; and 40 production-floor workers sharing twelve accounts, `floor01` to `floor12`, on twelve floor terminals — accounts in the same groups as staff, on a floor where phones are banned for safety. One on-premises domain. `SYNC01` synchronises it to the cloud identity service with password hash synchronisation, so the cloud password is the domain password; mail, files and 26 other apps sign in through the cloud service. Its only sign-in policy requires a second factor for all users and all cloud apps, except `breakglass01`, members of `MFA-Exempt`, and sign-ins from 203.0.113.10, the office's public address, marked as trusted. `MFA-Exempt`, a group synced from the domain, has 15 members: the floor accounts, "no phones on the floor"; `hlindqvist`, the CEO, "her assistant signs in as her to run her mail and calendar"; `ofarouk`, the finance director, "temporary — travelling, no signal, 14 March"; and `admin-it`, "so IT can always get in". Of 175 personal accounts, 125 use the authenticator app, 27 get codes by text message, and 23 have registered nothing: 9 new starters, whose accounts HR's onboarding form created, enabled, three weeks before they start, with a first password emailed to their manager; 8 contractors who have never signed in; and 6 staff who have only ever signed in from the office, the CEO among them. The VPN, which home workers keep connected to reach the file servers, checks passwords against the domain over RADIUS, with no second factor, and is full tunnel: while connected, a laptop's internet traffic leaves through the office connection. The guest Wi-Fi, whose password is on a card at reception, uses the same connection. Last month 71% of successful cloud sign-ins came from 203.0.113.10. Global administrator, the cloud's top role, has seven holders: `akim`, `rboateng` and `tsilva`, the three IT staff's everyday accounts, synced, used for mail, browsing and signing in at people's desks to fix laptops; `hlindqvist`, "so she is never locked out"; `msp-support`, the support provider's synced account, shared by whichever technician is on shift, its password in the provider's own vault; `admin-it`, synced, its password in IT's shared vault; and `breakglass01`, cloud-only, its 30-character password and a hardware security key sealed in the safe, kept out of the policy so a mistake in it cannot lock everyone out, alerting all three IT staff when used, last tested in August. Domain Admins: the built-in `Administrator`, its password sealed in the safe with `breakglass01`'s; the three everyday accounts; `admin-it`; and `msp-support`. `SYNC01` is a VM beside the file and print servers, administered with IT's everyday accounts, with the provider's remote management agent — which runs whatever their console sends — installed, as on every server and laptop. Devices: 140 Windows laptops, domain-joined, registered with the cloud service and enrolled in device management, whose compliance policy requires disk encryption, a supported OS and the firewall on — 128 compliant, 9 unencrypted, 3 silent for 45 days; the floor terminals, joined, enrolled and compliant the same way; 20 Macs, enrolled by their users from a web page, with no compliance policy assigned, under a setting that treats a device with no policy as compliant; and personal phones with the mail and files apps signed in, not enrolled and without app protection. All staff are local administrators of their own Windows laptops. The page describes Microsoft Entra ID and Intune because they are common; the mechanisms carry to other identity services. The 27 text-message users are this section's red herring; `breakglass01`'s exclusion and the sealed `Administrator` are deliberately correct and are there to be left alone. Book 70 minutes; the close is outside the 60.
I'm [YOUR_NAME] and I look after identity and the servers at [COMPANY_NAME]. This is a technical interview about one page: how a company of about two hundred people signs in. Treat it as what you would inherit on your first day. Take six minutes with it before you say anything — not everything on it is a problem.
What this line is for
Purpose
Makes the page the material and the candidate its new owner, so the hour goes on what they read in it rather than on what they could recite.
In June the board was told that every account has multi-factor authentication. Using this page, tell me every way someone holding one of our passwords gets in without a second factor, and which you would close first.
What this question is for, and what to listen for
Purpose
Reads identity and access as coverage, not as a setting. The separator is whether the candidate follows each password to where it is checked — the policy's exclusions, the address it trusts, the systems that never ask the cloud — and finds the routes that join up.
Signals to score
- Connects the full-tunnel VPN to the trusted address: home workers sign in from 203.0.113.10 and are never asked for a second factor
- Counts the guest Wi-Fi, its password at reception, as another way onto the trusted address
- Says the VPN itself takes a password alone, because it checks the domain over RADIUS, out of the cloud policy's sight
- Joins them up: one phished password opens the VPN, and the VPN then exempts every cloud sign-in that follows
- Reads the 71% as the share of last month's sign-ins that were never asked for a second factor
- Says the 23 unregistered accounts belong to whoever first signs in with the password — the new starters' emailed ones above all
- Puts the CEO's account near the top: exempt, shared with her assistant, nothing registered, and a global administrator
- Notices that the floor exemption follows the accounts rather than the terminals, so a password forty people know works from anywhere
- Treats the finance director's March exemption as temporary in name only, on an account that can open payroll
- Leaves `breakglass01`'s exclusion alone, and ranks the 27 text-message users below every account with no second factor
Follow-up questions
- A colleague is working from home on the VPN. What happens when she signs in to her mail?
- What does the VPN ask for, and what checks the answer?
- Nine new starters already have accounts. Who will register their second factor?
- `breakglass01` is excluded from the policy too. Is that a hole?
- Twenty-seven people get their codes by text message. Where does that sit on your list?
Seven global administrators
What this part is for
Purpose
Privileged access, from the administrator lists and how IT works day to day; nothing new is handed over. Keep it on who can take control and through what — accounts, machines, habits — not on MFA again.
Tell me every account and every machine on this page that, in the wrong hands, gives someone both the domain and the cloud. Then tell me what you would change in your first month, in order, without leaving us unable to get in ourselves.
What this question is for, and what to listen for
Purpose
Reads privileged access: whether the candidate finds control where it actually sits, and takes it away without creating a lockout. Counting role members finds seven accounts; following credentials also finds `SYNC01`, the provider's agent, the synced exemption group and the laptops IT signs in to.
Signals to score
- Names `admin-it` as the worst single account: shared, synced, exempt from the MFA policy, in both top roles
- Says the CEO's shared password makes her assistant a global administrator in practice
- Says IT's everyday accounts expose Domain Admin twice over: in inboxes that receive phishing, and typed at users' desks on laptops whose users are local administrators
- Treats `SYNC01` as sensitive as a domain controller, because password hash synchronisation needs an account that can read every password hash
- Sees the provider's agent on every server and its shift-shared login as a way into the domain the company neither controls nor audits
- Says a synced administrator can be taken over from the domain — its password reset on-premises, then used from the trusted address — and moves cloud roles to cloud-only accounts
- Notices `MFA-Exempt` is synced, so whoever can edit it in the domain decides who skips the company's MFA policy
- Gives the IT staff separate admin accounts with no mailbox, keeps domain admin rights off users' laptops, and fixes those with Windows LAPS or a workstation-only account
- Moves the CEO and the provider off the top roles, with the provider's technicians named and given access only when needed
- Proves both sealed accounts work before removing anyone, and adds a second cloud one
Follow-up questions
- Which of these accounts reads email?
- `SYNC01` is on no administrator list. Why might it matter more than some accounts that are?
- The provider says their technicians need Domain Admin to support us. What do you offer instead?
- The CEO wants to keep global administrator, just in case. What do you tell her?
- You have removed four global administrators. How do you know we can still get in on Saturday night?
Tuesday, without locking anyone out
What this part is for
Purpose
The change that follows from the first section. Before the question, tell the candidate that the CEO wants her assistant to keep running her mail and calendar, and that the finance director travels again next month.
The new policy goes live next Tuesday. Tell me what replaces each exemption, how you find out before Tuesday who it would lock out, and what you check on Wednesday morning.
What this question is for, and what to listen for
Purpose
Reads identity and access as a change to how two hundred people sign in. The separator is whether each exemption is replaced by something that serves the reason it was granted — shared terminals, an assistant, a traveller — and whether the effect is measured before it is enforced.
Signals to score
- Runs the new policy in report-only mode first and reads the sign-in log for who it would have stopped, and from where
- Has the 23 unregistered people register first, in person or with a one-time pass, so no first prompt is answered by someone else
- Creates new starters' accounts disabled until their start date, with a short-lived first-day pass instead of a password emailed to a manager
- Gives the assistant delegated access to the CEO's mail and calendar, so the CEO gets her own password and her own second factor
- Allows the floor accounts only from the floor terminals and into the floor's apps, or moves the floor to security keys or badges — never phones
- Ends the finance director's exemption with a method that needs no signal — the authenticator app's offline codes or a security key
- Adds a second factor to the VPN itself, through the cloud identity service or a RADIUS-based check
- Stops the office address exempting anyone, and says what that changes for VPN users and the guest Wi-Fi
- Keeps `breakglass01` outside the policy, and rolls back by returning the policy to report-only, not by restoring exemptions
- Defines Wednesday's check: old exemptions now signing in with a second factor, the first floor shift in, the service desk's calls counted
Follow-up questions
- What does a week in report-only mode tell you that the page does not?
- Phones are banned on the floor. How does a floor worker sign in on Wednesday?
- The CEO says her assistant has always used her login and it works. What do you offer instead?
- Six people have only ever signed in from the office. What happens to them on Tuesday?
- It is 06:10 on Wednesday and the first shift cannot sign in. What do you do?
What counts as a company laptop
What this part is for
Purpose
Device management, from the device lines on the page and the request in the question. Payroll has its own site in the cloud file service, so a rule can target it alone.
From next month the finance director wants the payroll files to open only on company laptops. Tell me which machines on this page would count as one if you switched that on today, what you would require instead, and what happens to the contractors, the Macs and everyone's phones.
What this question is for, and what to listen for
Purpose
Reads device management: whether the candidate knows what each state a device can be in proves — joined, enrolled, compliant — and where a "company laptops only" rule leaks. The separator is the Macs, which pass a check that checks nothing.
Signals to score
- Separates a laptop that is joined or enrolled from one that is compliant, and asks for compliant for payroll
- Finds the nine unencrypted laptops and the three silent for 45 days, and deals with them before switching anything on
- Reads the no-policy setting as making all 20 Macs compliant with nothing on them checked, and assigns a policy before relying on it
- Says enrolment from a web page proves someone enrolled a Mac, not that the company owns it, and ties enrolment to company purchases
- Notices the floor terminals pass a device rule while forty people share them, and keeps shared devices out of payroll
- Removes everyday local administrator rights, because compliant is only the last report and a local administrator can switch off what it checks in between
- Keeps payroll off personal phones, and protects mail and files there with app-level controls and selective wipe rather than enrolment
- Checks whether any contractor can reach payroll today, and gives contractors no route to it
- Turns the rule on for finance in report-only mode first, and checks finance's own laptops before the deadline
- Says what happens to a lost laptop: recovery key held centrally, remote wipe, device disabled in the directory
Follow-up questions
- If the rule were domain-joined laptops only, which machines would get in?
- The Macs all show as compliant. What was checked?
- Everyone is a local administrator of their own laptop. Does that matter for this rule?
- The finance director reads payroll reports on her phone on the train. What happens to her next month?
- A finance laptop is left in a taxi tonight. What happens, and what does it cost us?
Closing
That's the page. Ask me anything about how sign-in really works here — who can grant an exemption, when the break-glass account was last used, what our support provider can reach.
What this line is for
Purpose
Scores nothing and goes in the notes. Someone who has run identity at a company this size tends to ask who approves exemptions and who else holds administrator rights.
Before you go, one true thing about us: [name one real gap in your own identity setup — an exemption nobody remembers granting, an administrator account that also reads email, a system that still accepts a password alone]. It would be on your list in the first month.
What this line is for
Purpose
Ends on a specific, current fact rather than a pitch. It is what this candidate wants to hear, and it only works if it is still true on the day, so check it first.
System Administrator interviews — common questions
- Who is this System Administrator interview plan for?
- It is written for the interviewer, not the candidate: the hiring manager, engineer or panel member running the Technical Interview round for a System Administrator role. It gives you a 60 min script to follow in the conversation — 4 questions with what each one is for and the signals to score against — so you are not writing the round from scratch the night before.
- What does the Technical Interview round assess?
- This round is focused on: Identity and access, privileged access and device management, on one company's sign-in setup: where MFA does not reach, closing it without lockouts, who could take the domain and the cloud, and what a company laptop proves. It works through Where a password is still enough, Seven global administrators, Tuesday, without locking anyone out and What counts as a company laptop, scoring against 40 observable signals, with follow-up prompts on all 4 questions for going deeper where an answer is thin.
- How is the 60 min split up?
- 60 min on 4 questions. The questions take in Where a password is still enough (20 min), Seven global administrators (14 min), Tuesday, without locking anyone out (13 min) and What counts as a company laptop (13 min). The timings are there so the round stays on schedule and every candidate gets the same shape of interview — which is what makes two candidates comparable afterwards.
- What other rounds should I run for a System Administrator?
A single round does not cover a whole role. The other rounds in this library for a System Administrator:
Hiring for this role?
Open this plan in Hirezen and make it a position in one click.
- Every interviewer runs the same script and marks the same signals.
- AI drafts the write-ups, and the debrief puts every read side by side.
- No ATS to set up first, and no bot in the call.
Free for your first open role.