FirstHR

System Administrator Interview Questions and Scorecard

Free system administrator interview questions for small businesses without IT or HR: 6 question sets, answer guides, and a scorecard. Download as DOCX.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Hiring
15 min

System Administrator Interview Questions and Scorecard

Six question sets for the employer side of the table: core systems, backup and recovery, security and access, troubleshooting scenarios, judgment, and a 1-to-5 scorecard. Every question comes with what a good answer sounds like. Download as DOCX.

The first system administrator a small business hires is usually the only person who will ever touch its servers, its email, its files, and its backups. I have watched owners interview for that role by reading a list of technical questions off a screen, nodding at answers they had no way to evaluate, and hiring on confidence. It works until the day something breaks.

The fix is not to become technical. It is to ask questions that reveal method and evidence rather than vocabulary, and to know in advance what a good answer sounds like. A candidate who has personally restored a server at 2 a.m. tells that story differently from one who has only watched a backup console show green.

At FirstHR, we build for companies hiring without an HR department, where the owner runs the interview alone between everything else. These six question sets cover the role the way a small business actually experiences it, and every core question carries a note on what a strong answer includes. Browse the full hiring template library for the rest of the process.

TL;DR
Interview a system administrator on five things: core systems (servers, patching, accounts, monitoring), backup and tested restore, security and privileged access, troubleshooting method, and judgment while working alone. The single most revealing question is what they last restored from backup and how long it took, because it separates managed backups from proven ones. Score all candidates on the same 1-to-5 rubric. Download six question sets and the scorecard as DOCX.

What to Assess in a System Administrator

Assess five things: core systems administration, backup and recovery, security and access control, troubleshooting method, and judgment when nobody is around to escalate to. Technical breadth matters less than evidence, because a small business needs someone who has actually owned an environment rather than someone who has read about one.

The role at your size is broader than the title suggests. A system administrator here usually covers servers, laptops, accounts, email, vendors, and end-user support in the same week. That is closer to the scope described in a system administrator job description for a small company than to the specialist version at an enterprise, so interview for range and method.

Weight backup and recovery above everything else. It is the one area where a weak hire produces a loss the business may not recover from, and it is the area candidates most often overstate. Every other gap is fixable over time.

The Six Question Sets

The questions below are grouped into five competency sets plus a scorecard. Each set targets a different part of the role, and a strong candidate should hold up across all of them rather than shining only in the technical set they rehearsed.

Core Systems and Servers
The base set
Servers, operating systems, patching, virtualization, accounts, monitoring, and automation, each with a note on what a good answer sounds like. Start here.
Backup and Recovery
Highest stakes
The set most interviews skip. Has the candidate actually restored from a backup, do they test them, and can an attacker with admin rights delete the copies?
Security and Access
They hold the keys
Privileged accounts, least privilege, offboarding, endpoint protection, and how they respond when someone asks them to bypass a control.
Troubleshooting Scenarios
Grade the method
Seven realistic incidents. You are grading how they scope a problem, form a theory, and communicate while working, not the final technical answer.
Judgment and Working Solo
Often your only IT
Triage under competing urgency, explaining technology to non-technical people, owning a past failure, and staying sharp without a senior engineer nearby.
Scorecard and Red Flags
Score, do not guess
A 1-to-5 rubric across six areas, a red-flag checklist, and an access checklist to complete before day one. The asset generic question lists leave out.
Do Not Skip the Sets That Feel Uncomfortable
Owners who are not technical tend to spend the whole interview on the core systems set, because it feels like the real test, and then run out of time. The sets that predict the most are backup and recovery, where a single question exposes whether the practice is real, and judgment, where you learn how someone behaves as the only IT person in the building. Ask at least two questions from every set, and use the scorecard so a strong answer in one area does not cover a hollow one in another.

Questions and a Scorecard to Download

Download all six as a single Word document or copy the sets individually. Each follows the same structure: when to use it, the questions with good-answer notes, what to listen for, and space for notes. The final file is the scorecard, with a red-flag checklist and an access checklist to complete before day one.

Download All 6 Question Sets and the Scorecard
Core systems, backup and recovery, security and access, troubleshooting scenarios, judgment, and a 1-to-5 scorecard. All in one DOCX.

Set 1: Core Systems and Server Administration

The base set: servers, operating systems, patching, virtualization, accounts, monitoring, documentation, and automation, each with a note on what a good answer sounds like. Start here for every candidate.

Core Systems and Server Administration Questions
SYSTEM ADMINISTRATOR INTERVIEW: CORE SYSTEMS AND SERVERS
Candidate: __
Business: __
Interviewer: __
Date: _

HOW TO USE THIS SET

This is the base set for almost every system administrator hire. Ask 6 to 8 of
these and use the good-answer notes to judge the response even if you are not
technical yourself. You are listening for specifics: named systems, named tasks,
and a method. Score every candidate on the same rubric in Set 6.

QUESTIONS TO ASK

1. Describe the environment you administer today. How many users, how many
servers, and which operating systems?
(Good answer: concrete numbers and named platforms, Windows Server, Linux,
macOS, and a clear description of what they personally own.)
2. Walk me through how you would take over an environment you have never seen.
(Good answer: inventory first, find the documentation, check backups and
patch status, identify who has admin rights, then change nothing risky in
week one.)
3. How do you handle patching and updates across servers and end-user machines?
(Good answer: a schedule, a test group before broad rollout, a maintenance
window, and a rollback plan. Not "I update when something breaks.")
4. What is your experience with virtualization and with cloud infrastructure?
(Good answer: names hypervisors and cloud providers they have actually used,
and can say what they built or migrated rather than just listing logos.)
5. How do you manage user accounts, groups, and permissions?
(Good answer: a directory service, group-based permissions rather than
per-person exceptions, and a documented joiner and leaver process.)
6. What do you monitor, and how do you find out something is wrong?
(Good answer: named monitoring and alerting, with thresholds. The weak answer
is "the users tell me.")
7. How do you document what you build and change?
(Good answer: a runbook, a wiki, or a ticket trail. Documentation is what
makes a solo administrator replaceable, so treat this as a real question.)
8. Which scripting or automation do you use, and what have you automated?
(Good answer: PowerShell, Bash, Python or similar, with a specific example of
a repetitive task they removed.)

WHAT TO LISTEN FOR

Named systems and named tasks, not categories and buzzwords
A schedule and a method rather than reacting to breakage
Honesty about what they have owned versus assisted with
Documentation treated as part of the job, not an afterthought

NOTES

__
__

Set 2: Backup, Restore, and Disaster Recovery

The highest-stakes set and the one generic lists skip. Has the candidate personally restored, do they test their backups, and can an attacker holding admin rights delete every copy?

Backup, Restore, and Disaster Recovery Questions
SYSTEM ADMINISTRATOR INTERVIEW: BACKUP AND RECOVERY
Candidate: __
Business: __
Interviewer: __

WHY THIS SET MATTERS MOST

For a small business, this is the set with the highest cost of a wrong hire.
Almost every candidate says they run backups. Far fewer have actually restored
from one. Ask these questions of every finalist, and weight the answers heavily.

QUESTIONS TO ASK

1. Tell me about the last time you restored something from backup. What was it,
and how long did it take?
(Good answer: a specific, recent incident with a real timeline. A candidate
who has never performed a restore has never tested the backup.)
2. How do you verify that a backup is actually usable?
(Good answer: scheduled test restores, not just a green status in a console.)
3. How would you design backups for a business our size, and where would copies
live?
(Good answer: more than one copy, at least one off-site or offline, and a
stated retention period tied to what the business needs.)
4. What is your target recovery time if the main file server dies on a Monday
morning, and how did you arrive at it?
(Good answer: distinguishes how much data we can lose from how long we can be
down, and ties both to business impact rather than to a technical preference.)
5. Walk me through what you would do in the first hour of a suspected
ransomware incident.
(Good answer: isolate first, preserve evidence, escalate to the owner, then
assess backups. A candidate who starts by wiping and rebuilding is destroying
the evidence you may need.)
6. What have you done to make sure a backup cannot be encrypted or deleted by an
attacker who already has admin access?
(Good answer: offline, immutable, or separately credentialed copies. This is
the question that separates a senior answer from a junior one.)
7. Tell me about a time a recovery did not go as planned. What did you change?

WHAT TO LISTEN FOR

A real restore they personally performed, with a real timeline
Tested backups, not monitored backups
At least one copy an attacker with admin rights cannot reach
Business impact language, not only technical language

NOTES

__
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Set 3: Security, Accounts, and Access Control

Privileged accounts, least privilege, offboarding, endpoint protection, and how the candidate responds when someone asks them to bypass a control because they are in a hurry.

Security, Accounts, and Access Control Questions
SYSTEM ADMINISTRATOR INTERVIEW: SECURITY AND ACCESS
Candidate: __
Business: __
Interviewer: __

WHEN TO USE THIS SET

A system administrator holds the keys to everything: email, files, payroll
systems, and the owner's own account. Security judgment is therefore part of the
core evaluation, not an optional add-on for a security-titled role. Use this set
for every finalist.

QUESTIONS TO ASK

1. How do you handle administrator accounts and privileged access?
(Good answer: separate admin and daily-use accounts, no shared logins,
multi-factor authentication on everything privileged.)
2. Walk me through your offboarding process when someone leaves the company.
(Good answer: a checklist, same-day account disable, mailbox and file
handover, device return, and a record of what was revoked and when.)
3. How do you decide who gets access to what?
(Good answer: least privilege by role and group, reviewed periodically, with
exceptions written down rather than remembered.)
4. What would you fix first if you inherited an environment with no security
controls in place, and why that first?
(Good answer: prioritizes by risk, usually multi-factor authentication,
backups, and patching, and can explain the reasoning.)
5. How do you handle a user who asks you to bypass a control because they are in
a hurry?
(Good answer: offers a safe alternative, escalates rather than quietly
granting it, and does not make the user the enemy.)
6. What is your approach to endpoint protection and to keeping laptops secure
off-site?
(Good answer: managed devices, disk encryption, and a plan for a lost laptop.)
7. Tell me about a security incident you handled. What happened and what changed
afterward?
(Good answer: describes the incident calmly, owns any part they got wrong,
and names a concrete control added afterward.)
8. How do you keep the owner informed about risk without turning every
conversation into a technical briefing?

WHAT TO LISTEN FOR

Separate privileged accounts and no shared credentials
A written, repeatable offboarding checklist
Risk-based prioritization, explained in plain language
Comfort saying no to a bad request without creating conflict

NOTES

__

Set 4: Troubleshooting Scenario Questions

Seven realistic incidents to pose out loud. You are grading how the candidate scopes a problem, forms a theory, and keeps people informed, not whether they name the exact cause.

Troubleshooting Scenario Questions
SYSTEM ADMINISTRATOR INTERVIEW: TROUBLESHOOTING SCENARIOS
Candidate: __
Business: __
Interviewer: __

HOW TO USE THIS SET

These are situational questions. You are not grading the final technical answer.
You are grading the method: does the candidate gather information, form a theory,
test it, and communicate while they work? A structured troubleshooter is worth
more than someone who guesses quickly and happens to be right.

SCENARIOS TO POSE

1. It is 8:30 on a Monday and nobody can log in. Walk me through your first
fifteen minutes.
(Good answer: confirms scope first, is it everyone or one office, checks the
obvious shared dependency, and tells people something while working.)
2. One employee says their computer is slow. Everyone else is fine. What do you
do?
(Good answer: asks what changed and when, checks resources and startup items,
and does not jump straight to a rebuild.)
3. A server is running out of disk space at 2 a.m. and paging you. What now?
(Good answer: buys time safely, then finds the cause, then fixes the growth
rather than deleting files repeatedly.)
4. Email delivery to one customer domain is failing. Where do you start?
(Good answer: checks logs and bounce messages first, then DNS and reputation,
and knows this is often not a problem on our end.)
5. A critical update you deployed broke a business application. Walk me through
the next hour.
(Good answer: rolls back, communicates early, then investigates in a test
environment instead of experimenting in production.)
6. A file everyone needs was deleted this morning. What do you do?
(Good answer: checks the recycle bin or snapshot before touching backups, and
knows the restore path they described in Set 2.)
7. Someone reports a suspicious email that two employees already clicked. Go.
(Good answer: contains the accounts first, resets credentials, checks for
forwarding rules, and reports to the owner rather than handling it silently.)

WHAT TO LISTEN FOR

Scope before solution: how many people, since when, what changed
A theory that gets tested rather than a guess that gets applied
Communication with users while the work is happening
Fixes the cause, not only the symptom

NOTES

__
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Set 5: Judgment, Communication, and Working Solo

Triage under competing urgency, explaining technology in plain language, owning a past failure, and staying current with no senior engineer nearby. The set that predicts fit at a small company.

Judgment, Communication, and Working Solo Questions
SYSTEM ADMINISTRATOR INTERVIEW: JUDGMENT AND COMMUNICATION
Candidate: __
Business: __
Interviewer: __

WHEN TO USE THIS SET

At a small business the system administrator is often the entire IT department.
There is no senior engineer to escalate to and no service desk to absorb the
interruptions. This set tests whether the candidate can prioritize, explain
technology to non-technical people, and operate without a team around them.

QUESTIONS TO ASK

1. You would be our only IT person. How do you decide what to work on when three
things are urgent at once?
(Good answer: a triage rule based on business impact and number of people
blocked, communicated to whoever is waiting.)
2. Explain something technical you did recently as you would explain it to me,
assuming I am not technical.
(Good answer: plain language, an analogy that fits, and no condescension.
This is a working sample, not small talk.)
3. Tell me about a time you told an owner or executive that something they
wanted was a bad idea. How did it go?
4. How do you keep improving when there is no one senior to learn from?
(Good answer: named communities, labs, certifications, or vendor training,
with something specific they learned in the past year.)
5. What would you want from us in your first 30 days to be effective?
(Good answer: access, documentation, a budget conversation, and time with the
people who use the systems. A candidate who wants nothing has not thought
about it.)
6. Tell me about a mistake you made that took something down. What happened?
(Good answer: names it plainly, describes the recovery, and states the control
they added. A candidate who has never broken anything is either new or not
being straight with you.)
7. How do you handle being interrupted constantly while working on a project?
8. What parts of this job do you not enjoy?
(Good answer: honest and specific. Useful for predicting where they will
quietly stop doing the work.)

WHAT TO LISTEN FOR

A stated triage rule, not "I do whatever is loudest"
Plain-language explanation without talking down
Ownership of a real failure and a control added afterward
Self-directed learning, since there is nobody senior here to copy

NOTES

__

Set 6: Scorecard and Red Flags

A 1-to-5 rubric across all six areas, a red-flag checklist, and an access checklist to finish before the new hire starts. Use it with any set above so decisions rest on evidence.

System Administrator Scorecard and Red Flags
SYSTEM ADMINISTRATOR INTERVIEW SCORECARD AND RED FLAGS
Candidate: __
Business: __
Interviewer: __
Date: _

HOW TO SCORE

Score each area from 1 to 5 immediately after the interview, while it is fresh.
Anchor every score to something the candidate actually said. If more than one
person interviews, each scores independently before you discuss, so the most
confident voice does not set the tone for everyone else. Use the same rubric for
every candidate.
Rating scale:
5 = Strong, specific evidence 4 = Solid evidence 3 = Some evidence
2 = Weak or mixed evidence 1 = No evidence or red flags

SCORING AREAS

Core systems: servers, operating systems, patching, accounts, monitoring
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Backup and recovery: has personally restored, tests backups, protects copies
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Security and access: privileged accounts, least privilege, offboarding
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Troubleshooting method: scope, theory, test, fix the cause
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Communication: explains technology plainly, keeps people informed
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Working solo: triage, self-direction, documentation habits
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______

RED FLAGS (WEIGH CAREFULLY)

[ ] Has never personally performed a restore from backup
[ ] Cannot name a single system, tool, or task with any specificity
[ ] Has never broken anything, or blames every past outage on someone else
[ ] Dismissive or condescending about non-technical users
[ ] Treats documentation as a waste of time
[ ] Resists the idea that the owner should hold a break-glass admin credential
[ ] Wants to replace everything in month one before understanding the business

ACCESS CHECKLIST BEFORE DAY ONE (PROTECT THE BUSINESS)

[ ] The owner holds an emergency admin credential the administrator cannot remove
[ ] Domain, DNS, and cloud tenant registrations are in the company's name
[ ] Admin accounts are individual, never shared, with multi-factor enabled
[ ] A written offboarding checklist exists before the new hire needs it
[ ] Confidentiality agreement signed before access is granted

DECISION

Total score: ______ / 30
Recommendation: [ ] Strong yes [ ] Yes [ ] Maybe [ ] No
Notes: __

How to Judge Answers If You Are Not Technical

You do not need to grade the technology; you need to tell a specific answer from a vague one. The pattern holds across every set: strong answers name real systems, describe a real incident with a timeline, and explain a method. Weak answers stay abstract, claim broad familiarity, and never produce an example you could verify with a reference.

Tell me about the last time you restored something from backup.
Strong answer: A specific incident: what was lost, which copy they used, how long the restore took, and what they changed afterward. A strong candidate also distinguishes how much data the business could afford to lose from how long it could afford to be down, and ties both to the business rather than to a preferred tool.
Weak answer: A weak answer stays in the present tense (we have backups, they run nightly) and never lands on an actual restore. A candidate who has never restored has never proven the backup works.
Nobody can log in and it is 8:30 on a Monday. Walk me through your first fifteen minutes.
Strong answer: Scope before solution. A strong answer establishes how many people are affected and where, checks the shared dependency that would explain that pattern, and sends a short update to staff while investigating. They form a theory, test it, and only then change something.
Weak answer: A weak answer starts changing settings immediately, or names one specific cause with total confidence before asking a single question about scope.
Explain something technical you did recently as if I am not technical.
Strong answer: Plain language, a fitting analogy, and the business reason for the work. This question is a working sample of the thing they will do with your team every week, so treat the answer as evidence rather than as small talk.
Weak answer: A weak answer buries the point in acronyms, or is subtly condescending. Both predict friction with the people the administrator is supposed to support.

Two questions carry disproportionate weight for a non-technical interviewer. The first is the last restore they performed, because it is nearly impossible to fake a specific recovery timeline. The second is the plain-language explanation, which is a live sample of what this person will do with your team every week.

If you want a third data point, ask a technical friend or your outside IT provider to sit in on one call and score the same rubric independently. That is different from handing the decision to them, and it keeps the hire yours.

What to Probe For (and Red Flags)

The questions open the door; the follow-ups are where you learn. Push for the specific system, the actual timeline, the real outcome, and watch for the patterns that separate someone who has run an environment from someone who has assisted in one.

Technical specificity
Names real systems and real tasks they owned
Describes what they built, not what they saw
Has automated something repetitive and can say what
Recovery evidence
Has personally restored, with a real timeline
Tests backups instead of watching a status light
Keeps a copy an attacker with admin cannot reach
Communication under pressure
Tells people what is happening while fixing it
Explains a technical decision in plain language
Escalates to the owner instead of hiding an incident
Red flags
Has never performed a restore or broken anything
Condescending about non-technical users
Wants to replace the whole stack in month one

The most useful follow-up in any technical interview is some version of what happened next. Candidates with real operational experience have an ending to every story, including the part where something went wrong. Candidates without it drift back into the present tense.

The Access Questions Most Interviews Skip

A system administrator ends up holding the keys to everything the business runs on, which makes access hygiene part of the hiring decision rather than an onboarding detail. Ask about it in the interview, because the answer tells you how the candidate has handled the same trust elsewhere.

Keep a break-glass credential
As the owner, hold one emergency administrator account that the system administrator cannot remove or reset. A good candidate treats this as normal practice; visible irritation at the idea is worth noting.
Register domains in the company name
Domain names, DNS, and cloud tenants should be registered to the business, with billing on a company card. Ask in the interview how they have handled this before at other jobs.
Write the offboarding checklist first
The person who revokes everyone else's access will one day need their own revoked. Write that checklist before the new hire starts, not on the day you need it.
Check references on judgment
Call references and ask specifically about how the candidate handled an outage and how they treated non-technical colleagues. Both predict more than a skills list does.
Backups Only Count If They Survive the Attacker
Federal guidance is consistent on this point: CISA Cyber Essentials tells small organizations to keep backups offline and to test restores, and the recover function of the NIST Cybersecurity Framework treats verified recovery as a distinct capability rather than a byproduct of running backup software. Ask candidates directly how a copy would survive an attacker who already holds administrator rights.

The same logic applies to departures. The person who revokes everyone else's access will eventually need their own revoked, so build the IT offboarding checklist before you need it rather than on the day you do.

How to Run the Interview

Running this interview well is mostly structure. Fix the questions in advance, ask the same core set of everyone, pose the scenarios out loud, and score immediately. The sequence below works whether you are alone or bringing in a second opinion.

StepWhat to do
1. Scope the roleDecide cloud-first or on-premises, and weight the sets to match
2. StandardizeAsk the same core questions of every candidate, in the same order
3. Probe recoveryAsk what they last restored and how long it took
4. Pose scenariosGrade scope, theory, test, and communication, not the final answer
5. Test plain languageHave them explain a technical decision to a non-technical listener
6. Score and decideRate six areas 1 to 5 with evidence, independently, then compare

Score right after each conversation while the answers are fresh. If a second person interviews, have them complete the rubric before any discussion, so one confident opinion about a tool preference does not anchor the whole decision. This is the core of a structured interview, and the scores feed a clean interview feedback step.

Keep the completed scorecards together in one folder rather than scattered across inboxes, so the comparison at the end is a document instead of a memory. Applicant tracking is coming soon to FirstHR, and until it ships, a shared folder and a consistent file name do the job for a hiring process this size.

System Administrator Pay

System administrator pay varies with scope, environment complexity, on-call expectations, and local market. Use federal data as the baseline, then adjust for your region and for how much of the job is generalist support rather than infrastructure engineering.

Median $99,130 a Year (BLS OEWS, May 2025)
Network and computer systems administrators had a median annual wage of $99,130, about $47.66 an hour, with the lowest 10 percent under $62,640 and the highest 10 percent above $155,050, according to the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025). The 25th percentile sits at $78,010 and the 75th at $126,640.

For a small business hiring a generalist, the range between the 25th and 75th percentiles is the realistic window, with location doing most of the work. Budget for the surrounding costs as well: certification renewals, tooling, and the on-call burden that falls on one person. Many small companies pair a single administrator with an outside provider for after-hours coverage rather than hiring a second.

If your scope leans toward networking rather than servers, compare against the network administrator version of the role, and if it leans toward strategy and vendor management, look at the IT manager level instead.

Fair, Legal, and Structured Interviewing

A good interview is fair, legal, and structured, and the three reinforce each other. Asking the same job-related questions of everyone keeps you compliant, reduces bias, and produces better hires at the same time. Technical interviews drift more than most, which makes the structure worth more here.

Ask about the job, not the person
Federal anti-discrimination law, enforced by the EEOC, prohibits basing hiring decisions on protected characteristics, and questions that probe them create risk even when they are asked casually. Avoid age, race, religion, national origin, sex, pregnancy or family plans, disability, and genetic information. Technical interviews have their own version of this trap: asking when someone started working with computers, or what year they finished school, is an age question wearing a technical costume. Ask how long they have administered a specific platform instead. You may ask whether a candidate can perform the essential functions of the role, including any on-call expectation, as long as you ask everyone. This is general information, not legal advice.
Use the same core questions for every candidate
A structured interview, where every candidate answers the same questions scored against the same rubric, predicts on-the-job performance far better than a conversation that wanders wherever the rapport goes. For a technical role this matters more than usual, because an unstructured technical interview drifts toward whatever the interviewer happens to know, which quietly favors candidates who share the interviewer's background rather than candidates who can do the work. Fix the question set in advance, ask it in the same order, and score it. The sets on this page are built to be used exactly that way.
Score independently, then discuss
If you bring in a technical friend or a contractor to help evaluate, have each person score the rubric alone before anyone speaks. Technical interviews are especially prone to anchoring: one confident opinion about a tool choice can pull a whole panel, and the loudest opinion is not always the most relevant to your environment. Compare written evidence first, then talk about the gaps. A 1-to-5 score per area with a sentence of evidence turns a debate about preferences into a comparison of candidates.
Match the questions to your actual environment
A system administrator for a fifteen-person office running cloud email and a handful of laptops is a different hire from one maintaining on-premises servers in a warehouse. Weight the sets accordingly. If almost everything you run is cloud-hosted, spend your time on accounts, access, endpoint management, and vendor coordination. If you have physical servers, spend it on hardware, virtualization, patching windows, and recovery. Interviewing for a generic enterprise administrator you do not need is the most common way small businesses overpay and still miss.
Same Questions, Scored on a Rubric, Predict Better Hires
A structured interview, where every candidate answers the same questions scored against a consistent rubric, predicts on-the-job performance more reliably than an unstructured conversation, and asking the same job-related questions of everyone also keeps you within the EEOC rules against basing decisions on protected characteristics. Structure is both the fairer and the more effective approach.

Watch the technical version of an age question in particular. When someone started working with computers, or what year they finished school, probes age rather than skill. Ask how long they have administered a specific platform instead. See our guide to illegal interview questions for the full list. This is general information, not legal advice.

Interviewing a System Administrator Without HR

A large company evaluates this role through a technical panel, a recruiter, and a hiring manager who administered systems themselves once. A small business evaluates it through an owner who cannot grade the answers, hiring the person who will hold every credential the company has. That gap is where the avoidable mistakes live.

You are hiring a system administrator, and you are not technical
Most owners making this hire cannot personally grade a technical answer, which is why generic question lists do not help: they hand you the questions and leave you alone with the answers. Every core question in these sets comes with a note on what a good answer sounds like, so you are matching a pattern rather than judging expertise. The pattern is consistent across every set: strong answers are specific, name real systems and real incidents, and describe a method. Weak answers stay in the abstract, claim everything, and never land on a concrete example you could check with a reference.
This hire will hold the keys to everything you own
A system administrator has access to email, files, employee records, and often the payroll and banking logins by extension. That makes access hygiene part of the hiring decision rather than an onboarding detail. Keep an emergency administrator credential the new hire cannot remove, register domains and cloud tenants in the company name, require individual admin accounts with multi-factor authentication, and get a confidentiality agreement signed before access is granted. A strong candidate will recognize all of this as normal practice. Someone who bristles at owner-held credentials is telling you something worth hearing.
There is nobody here to escalate to, and the role is the whole IT department
At a larger company a system administrator sits in a team with a service desk in front and senior engineers behind. At a small business the same title means the only person who touches technology, interrupted constantly, with no second opinion available. Interview for that reality: ask how they triage three urgent things at once, how they keep learning without a senior colleague, and what they would need from you in the first 30 days. Then be honest in the interview about the scope, because a candidate who expects a team and finds a solo role tends to leave inside a year.
ResponsibilitySystem AdministratorHelp Desk Technician
Resolves day-to-day user issues
Owns servers, storage, and operating systems
Designs and tests the backup and recovery plan
Controls privileged accounts and access policy
Escalates to someone more senior in-house

The simplest rule: if this person will own recovery and privileged access with nobody above them, interview with all six sets and pay at the administrator level. If they will handle tickets while an outside provider owns the infrastructure, a support-focused role is the cheaper and more honest hire. Applicant tracking is coming soon to FirstHR, so for now track candidates wherever you already keep them and keep the scorecards together.

From Interview to Onboarding

The interview is step one. Onboarding a system administrator has extra steps because of the access involved: a signed offer, a confidentiality agreement before any credential is issued, individual admin accounts with multi-factor authentication, and the owner's emergency credential set aside. Getting that sequence right is your first internal control.

Send the offer and the NDA
Confirm the role, pay, and any on-call expectation in writing, and have the confidentiality agreement signed before a single credential is issued.
Grant access with controls in place
Individual admin accounts with multi-factor authentication, the owner's break-glass credential set aside, and domains and cloud tenants confirmed in the company name.
Assign the first 30 days
Inventory, documentation, a backup test, and time with the people who use the systems. Give the ramp a structure instead of a stack of tickets.
Store the records
Keep the signed offer, the NDA, the new hire paperwork, and the access grants organized and easy to find, so an audit or a departure is not a scramble.

Give the first month a structure rather than a ticket queue: an inventory, documentation, one tested restore, and time with the people who use the systems. An IT onboarding plan and the standard new hire paperwork cover most of it, and the paperwork matters more than usual for a role with this much access.

FirstHR connects the offer letter, the confidentiality agreement, e-signatures, the onboarding workflow, and the signed records in one place, so a small business can run hiring to onboarding from a single system with the access controls built in. FirstHR is an onboarding and HR platform, not an IT management or endpoint tool, so pair it with those. Applicant tracking is coming soon to FirstHR.

Key Takeaways
Assess five areas: core systems, backup and recovery, security and access, troubleshooting method, and judgment while working alone.
Ask what the candidate last restored from backup and how long it took; managed backups and proven backups are different things.
Grade troubleshooting scenarios on method (scope, theory, test, communicate) rather than on the final technical answer.
Treat the plain-language explanation as a working sample, because explaining technology to your team is most of the job.
Settle access hygiene before day one: a break-glass owner credential, company-owned domains, individual admin accounts, and a written offboarding checklist.
Use BLS data as the baseline: the matching occupation reported a median of $99,130 a year in May 2025.
Score every candidate on the same 1-to-5 rubric, independently, and compare written evidence before discussing.

Frequently Asked Questions

What questions should I ask a system administrator candidate?

Ask across five areas: core systems, backup and recovery, security and access, troubleshooting method, and judgment when working alone. Strong opening questions include: describe the environment you administer today, with user and server counts; how do you handle patching across servers and laptops; tell me about the last time you restored something from backup and how long it took; walk me through your offboarding process when an employee leaves; and it is Monday morning and nobody can log in, what are your first fifteen minutes. The restore question is the single most revealing one, because almost every candidate runs backups and far fewer have ever proven one works. Each question on this page comes with a note on what a good answer sounds like, so an owner without a technical background can still evaluate the response.

What is the difference between a system administrator and a network administrator?

A system administrator owns servers, operating systems, user accounts, storage, backups, and the software employees rely on day to day. A network administrator owns the connective layer: switches, routers, firewalls, wireless, VPN, and the links between sites. The federal occupational classification groups both under network and computer systems administrators, which is one reason the titles are used interchangeably in job postings. At a small business the distinction usually collapses entirely, and one person covers both plus end-user support. If that is your situation, interview for breadth and troubleshooting method rather than for depth in one specialty, and be explicit in the posting about the full scope so candidates are not surprised by it after they start.

How do I interview a system administrator if I am not technical?

You do not have to grade the technology. You have to tell a specific answer from a vague one, and this page gives you the pattern for each question. A strong answer names real systems, describes a real incident with a timeline, and explains a method: scope the problem, form a theory, test it, fix the cause. A weak answer stays abstract, claims familiarity with everything, and never produces a checkable example. Two questions do most of the work for a non-technical interviewer: ask for the last restore they performed, and ask them to explain something technical as they would to you. The second is a working sample of what they will do with your team every week. Pair the interview with reference calls about outages and about how they treated non-technical colleagues.

What technical skills should a system administrator have?

For most small businesses the practical list is: server and operating system administration on the platforms you actually run, identity and account management through a directory service, patch and update management on a schedule, backup and tested restore, endpoint management and encryption for laptops, monitoring and alerting, and enough scripting to automate repetitive work. Cloud administration matters more every year, so ask which providers and tenants they have managed rather than whether they have heard of them. Certifications are a signal, not a substitute: they show study, while a described incident with a real outcome shows practice. Weight the skills toward your environment. Cloud-first offices need accounts, access, and endpoint management. On-premises setups need hardware, virtualization, and recovery.

What are red flags in a system administrator interview?

The strongest red flag is a candidate who has never personally restored from a backup, because it means the backups they managed were never proven. Others worth weighing: cannot name a single specific system, task, or incident; has never broken anything, or blames every past outage entirely on other people; speaks about non-technical users with contempt, which predicts exactly how they will treat your team; treats documentation as wasted time, which is a real risk when one person holds all the knowledge; and reacts badly to the idea that the owner should hold an emergency administrator credential. Wanting to replace the entire technology stack in the first month, before understanding how the business runs, is a subtler warning about judgment rather than about skill.

Should I give a system administrator candidate a practical test?

A short, scoped practical exercise is useful, and a long unpaid project is not. The most efficient version costs nothing extra: use the troubleshooting scenarios in these sets as a live discussion and grade the method rather than the answer. If you want something hands-on, keep it to about an hour, make it resemble real work such as documenting a small environment or writing a restore runbook, and pay for anything longer than that. Give every finalist the same exercise and score it on the same rubric, or the comparison is not fair and the exercise adds noise instead of signal. Avoid trivia quizzes on command syntax. They test recall, which is the part of the job a search engine already handles.

How much does a system administrator cost?

Pay varies with scope, environment complexity, on-call expectations, and local market. According to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025), network and computer systems administrators had a median annual wage of $99,130, about $47.66 an hour, with the lowest 10 percent under $62,640 and the highest 10 percent above $155,050. The 25th percentile sits at $78,010 and the 75th at $126,640, which is a useful range for a small business hiring a generalist rather than a specialist. Budget for the surrounding costs too: certifications, tooling, and the on-call burden of being the only IT person. Many small businesses pair a single administrator with an outside provider for after-hours coverage instead of paying for a second hire.

Are these system administrator interview questions legal to ask?

Yes. Questions about platforms administered, incidents handled, backup and restore practice, security decisions, and troubleshooting method are job-related and permitted. The caution is general to all interviewing: avoid questions that touch protected characteristics such as age, race, religion, national origin, disability, or family status, and apply the same questions to every candidate. Technical interviews have a specific version of this trap, because asking when someone first started working with computers, or what year they graduated, functions as an age question. Ask how long they have administered a particular platform instead. Background checks are common for a role with privileged access and are reasonable, but follow the applicable rules for running them. This is general information, not legal advice.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial