Handle widespread sign-in failures after a change when rollback evidence is incomplete
Instruction: Give a restoration recommendation without claiming a root cause you have not established. State who can approve and execute any change, what evidence they need, and how you would validate recovery.
A fictional tenant has 42 reports of sign-in failure beginning at 09:05, five minutes after a Conditional Access change. Eight reports include correlation IDs; three reviewed sign-in events name the new policy as a blocking policy. Other logs are delayed. An unrelated high-risk sign-in alert is also under security review. The previous approved configuration is recorded in the change ticket. Help desk may gather permitted diagnostics and coordinate an incident but cannot change Conditional Access. The identity owner executes changes; either the change owner or security duty lead must authorize rollback. The emergency runbook names a backup identity on-call engineer and security duty lead. A director wants the service restored immediately.
Updated
Official answer available
Read the opening below, then unlock the full answer and practical guidance.
I would declare a widespread authentication incident and recommend that the identity owner evaluate a narrow rollback of the recent change. The timing and three policy-linked failures make that change a credible lead, but they do not prove it explains all forty-two reports. I would keep the security alert visible as a separate unresolved concern. I would send the identity owner the change identifier, rollout time, previous approved configuration, affected applications, the eight correlation IDs, and the three reviewed results...
Related Questions
-
easy
-
easy
-
easy
-
easy
-
easy
-
easy