Security & Continuity

Practical troubleshooting paths for MSP technicians dealing with real-world support failures.

What This Category Covers

Security and continuity issues need evidence before containment or recovery work. Separate detection, policy, identity, endpoint state, backup/recovery status, and business impact.

First Layer to Isolate

Security signal first, then scope, containment, recovery path, and business priority.

Useful Tools, Logs, and Portals

  • Security portal
  • RMM/EDR logs
  • Backup console
  • Identity logs
  • Change history
  • Incident notes

Before You Escalate

  • Impact and scope captured
  • Security owner notified where needed
  • Recovery point verified
  • Changes documented

Articles in This Path

Pick the closest symptom and work from there.

ACME challenge path accessible publicly but renewal validation still failsACME renewal works on standby node not active nodeApplication aware backup disabled itself after patchingBackup copy job finishes but offsite repository missing newest restore pointsBackup job completes with warnings because application log truncation skippedBackup notifications arrive, but failure subject lines always show successBackup repository free space looks healthy while synthetic full job still failsBackups & Recovery alerts indicate success while end-user experience never changesBackups & Recovery configuration survives testing but resets after restart or syncBackups & Recovery credential or certificate rotation breaks an existing integrationBackups & Recovery feature works in web app but fails in desktop clientBackups & Recovery healthy dashboard status masks a failing production workflowBackups & Recovery new deployment works for pilot group but not for production rolloutBackups & Recovery policy change applies in admin console but target users never receive itBackups & Recovery quarantine or protection action triggers but recovery workflow failsBackups & Recovery workflow succeeds for one account but fails for shared or delegated accessBackups completing with warnings but not restorableBare metal restore media boots but cannot see RAID volumeBare-metal recovery media boots on BIOS hardware but not UEFI replacementBitLocker key rotates but inventory system shows old key IDBitLocker network unlock not working after certificate renewalBitLocker policy escrowed keys but startup PIN requirement never appliedBitLocker recovery key prompt after firmware updateBitLocker recovery repeats after docking station changesBitLocker recovery screen appears after firmware patch on multiple laptopsBitLocker suspended for maintenance and never resumedBitLocker to Go media prompts for recovery key after device policy refreshBrowser shows certificate warning on internal applianceBrowser trust warning appears only on mobile devicesCertificate auto-renewal failed silently on applianceCertificate chain valid on Windows not on macOSCertificate private key present on server but export option unavailableCertificate revocation check slows VPN login from remote regionsCertificates alerts indicate success while end-user experience never changesCertificates configuration survives testing but resets after restart or syncCertificates credential or certificate rotation breaks an existing integrationCertificates feature works in web app but fails in desktop clientCertificates healthy dashboard status masks a failing production workflowCertificates logging shows delivery yet the target workflow never completesCertificates new deployment works for pilot group but not for production rolloutCertificates policy change applies in admin console but target users never receive itCertificates quarantine or protection action triggers but recovery workflow failsCertificates workflow succeeds for one account but fails for shared or delegated accessCloud backup seed completes but daily incrementals resend full data setCloud backup throttled by ISP fair use policyCode signing certificate installed but build agent cannot use itCode signing certificate installed but signing pipeline cannot locate thumbprintConditional Access alerts indicate success while end-user experience never changesConditional Access blocks service account unexpectedlyConditional Access configuration survives testing but resets after restart or syncConditional Access connector health looks normal but data stops syncingConditional Access credential or certificate rotation breaks an existing integrationConditional Access feature works in web app but fails in desktop clientConditional Access healthy dashboard status masks a failing production workflowConditional Access logging shows delivery yet the target workflow never completesConditional Access new deployment works for pilot group but not for production rolloutConditional Access policy change applies in admin console but target users never receive itConditional Access policy exception fixes one case but similar workflows still failConditional Access quarantine or protection action triggers but recovery workflow failsConditional Access report-only logs differ from real enforcement outcome

Terms of use acceptance loops on first login after policy assignment

Field Summary

Terms of use acceptance loops on first login after policy assignment is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Service account blocked after policy intended only for interactive sign-ins

Field Summary

Service account blocked after policy intended only for interactive sign-ins is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Conditional Access template duplicated and now two policies conflict

Field Summary

Conditional Access template duplicated and now two policies conflict is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Trusted network exclusions work for IPv4 but not IPv6 clients

Field Summary

Trusted network exclusions work for IPv4 but not IPv6 clients is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Legacy app protected by app proxy bypasses expected Conditional Access policy

Field Summary

Legacy app protected by app proxy bypasses expected Conditional Access policy is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Session controls block file download in SharePoint but not in Teams preview

Field Summary

Session controls block file download in SharePoint but not in Teams preview is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Mac browser marked unsupported because device ID claim missing from session

Field Summary

Mac browser marked unsupported because device ID claim missing from session is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Policy excludes break-glass accounts yet sign-in frequency rule still applies

Field Summary

Policy excludes break-glass accounts yet sign-in frequency rule still applies is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Named location trusted list updated but browser sessions keep prompting MFA

Field Summary

Named location trusted list updated but browser sessions keep prompting MFA is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. Start with the exact sign-in attempt and policy result; password resets without log evidence often create a second problem.

Conditional Access report-only logs differ from real enforcement outcome

Field Summary

Conditional Access report-only logs differ from real enforcement outcome is a Conditional Access ticket where the visible symptom can be misleading. When this Microsoft 365 workflow fails, separate account access, web-versus-desktop behavior, token state, licensing, Conditional Access, and service health before changing the client. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.