Security & Continuity

Practical troubleshooting paths for MSP technicians dealing with real-world support failures.

What This Category Covers

Security and continuity issues need evidence before containment or recovery work. Separate detection, policy, identity, endpoint state, backup/recovery status, and business impact.

First Layer to Isolate

Security signal first, then scope, containment, recovery path, and business priority.

Useful Tools, Logs, and Portals

  • Security portal
  • RMM/EDR logs
  • Backup console
  • Identity logs
  • Change history
  • Incident notes

Before You Escalate

  • Impact and scope captured
  • Security owner notified where needed
  • Recovery point verified
  • Changes documented

Articles in This Path

Pick the closest symptom and work from there.

ACME challenge path accessible publicly but renewal validation still failsACME renewal works on standby node not active nodeApplication aware backup disabled itself after patchingBackup copy job finishes but offsite repository missing newest restore pointsBackup job completes with warnings because application log truncation skippedBackup notifications arrive, but failure subject lines always show successBackup repository free space looks healthy while synthetic full job still failsBackups & Recovery alerts indicate success while end-user experience never changesBackups & Recovery configuration survives testing but resets after restart or syncBackups & Recovery credential or certificate rotation breaks an existing integrationBackups & Recovery feature works in web app but fails in desktop clientBackups & Recovery healthy dashboard status masks a failing production workflowBackups & Recovery new deployment works for pilot group but not for production rolloutBackups & Recovery policy change applies in admin console but target users never receive itBackups & Recovery quarantine or protection action triggers but recovery workflow failsBackups & Recovery workflow succeeds for one account but fails for shared or delegated accessBackups completing with warnings but not restorableBare metal restore media boots but cannot see RAID volumeBare-metal recovery media boots on BIOS hardware but not UEFI replacementBitLocker key rotates but inventory system shows old key IDBitLocker network unlock not working after certificate renewalBitLocker policy escrowed keys but startup PIN requirement never appliedBitLocker recovery key prompt after firmware updateBitLocker recovery repeats after docking station changesBitLocker recovery screen appears after firmware patch on multiple laptopsBitLocker suspended for maintenance and never resumedBitLocker to Go media prompts for recovery key after device policy refreshBrowser shows certificate warning on internal applianceBrowser trust warning appears only on mobile devicesCertificate auto-renewal failed silently on applianceCertificate chain valid on Windows not on macOSCertificate private key present on server but export option unavailableCertificate revocation check slows VPN login from remote regionsCertificates alerts indicate success while end-user experience never changesCertificates configuration survives testing but resets after restart or syncCertificates credential or certificate rotation breaks an existing integrationCertificates feature works in web app but fails in desktop clientCertificates healthy dashboard status masks a failing production workflowCertificates logging shows delivery yet the target workflow never completesCertificates new deployment works for pilot group but not for production rolloutCertificates policy change applies in admin console but target users never receive itCertificates quarantine or protection action triggers but recovery workflow failsCertificates workflow succeeds for one account but fails for shared or delegated accessCloud backup seed completes but daily incrementals resend full data setCloud backup throttled by ISP fair use policyCode signing certificate installed but build agent cannot use itCode signing certificate installed but signing pipeline cannot locate thumbprintConditional Access alerts indicate success while end-user experience never changesConditional Access blocks service account unexpectedlyConditional Access configuration survives testing but resets after restart or syncConditional Access connector health looks normal but data stops syncingConditional Access credential or certificate rotation breaks an existing integrationConditional Access feature works in web app but fails in desktop clientConditional Access healthy dashboard status masks a failing production workflowConditional Access logging shows delivery yet the target workflow never completesConditional Access new deployment works for pilot group but not for production rolloutConditional Access policy change applies in admin console but target users never receive itConditional Access policy exception fixes one case but similar workflows still failConditional Access quarantine or protection action triggers but recovery workflow failsConditional Access report-only logs differ from real enforcement outcome

BitLocker to Go media prompts for recovery key after device policy refresh

Field Summary

BitLocker to Go media prompts for recovery key after device policy refresh is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Encrypted archive created successfully but recipient cannot open with provided password

Field Summary

Encrypted archive created successfully but recipient cannot open with provided password is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Self-encrypting drive reports compliant while BIOS leaves device unlocked preboot

Field Summary

Self-encrypting drive reports compliant while BIOS leaves device unlocked preboot is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Endpoint DLP encrypts files at rest but blocks backup agent reads

Field Summary

Endpoint DLP encrypts files at rest but blocks backup agent reads is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. Portal status is not proof of local execution; verify run history, service state, and security blocks.

S/MIME certificate present in Outlook but encrypt option unavailable for contacts

Field Summary

S/MIME certificate present in Outlook but encrypt option unavailable for contacts is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. Record subject, issuer, SAN, expiration, binding, and trust chain before replacing certificates.

FileVault escrow status shows unknown despite successful encryption completion

Field Summary

FileVault escrow status shows unknown despite successful encryption completion is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

BitLocker policy escrowed keys but startup PIN requirement never applied

Field Summary

BitLocker policy escrowed keys but startup PIN requirement never applied is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

EFS-protected files copied to server lose access for original owner

Field Summary

EFS-protected files copied to server lose access for original owner is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Encrypted USB drive opens on one workstation but demands format on another

Field Summary

Encrypted USB drive opens on one workstation but demands format on another is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

BitLocker recovery screen appears after firmware patch on multiple laptops

Field Summary

BitLocker recovery screen appears after firmware patch on multiple laptops is a Encryption ticket where the visible symptom can be misleading. Endpoint tickets usually live in profile state, local services, drivers, update health, management policy, encryption, or security tooling. Prove whether the issue follows the user or the machine before rebuilding anything. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.