ITSM Knowledge Wiki¶
Categories
- AD Lockout from Stale Cached Mobile Credentials
- BitLocker Not Enabled / Recovery Key Not Escrowed
- Corporate Wi-Fi 802.1X Authentication Failures
- GlobalProtect VPN Immediate Post-MFA Disconnect
- Integration Gateway API Timeouts
- Internal DNS Resolution Failures
- Internal Web Service Load-Balancer TLS Certificate Expiry
- Intune Device Non-Compliant Encryption (Conditional Access Block)
- Laptop Slow Post-Login (CPU / Disk Contention)
- Outlook / Exchange Online Mailbox Sync Failures
- Print Server Stuck Jobs / Driver Failure
- Shared Drive Access Denied
- Software Center Install Blocked (Endpoint Protection)
- SSO / MFA Prompt Loop (Okta / Azure AD)
AD Lockout from Stale Cached Mobile Credentials¶
- Incomplete Password Reset Due to Expired Reset Token
- Mobile Cached Credentials Trigger AD Lockout With Expired Reset Token
- Recurring AD Lockouts From Stale Cached Credentials on iOS Mobile Devices
- Recurring AD Lockouts from Unidentified Stale Credential Source Post-Reset
BitLocker Not Enabled / Recovery Key Not Escrowed¶
- BitLocker Enabled Locally but Intune Reports Noncompliant Due to Escrow and Compliance Reporting Desynchronization
- BitLocker Not Initialized on Endpoint Preventing Recovery Key Escrow
- Deprecated Intune Encryption Policy Prevents BitLocker Activation and Key Escrow
- Recovery Key Escrow Failure Leaves Device Noncompliant Despite Healthy TPM
- Uninitialized TPM Protector Prevents BitLocker Encryption and Recovery Key Escrow
Corporate Wi-Fi 802.1X Authentication Failures¶
- Corrupted Endpoint Wireless Profile Causes Intermittent 802.1X Authentication Failure
- Expired Wireless Controller or RADIUS Certificate Blocks 802.1X Authentication
- Incomplete EAP-TLS Certificate Propagation Across Wireless Controller Cluster
- Incorrect NAC Policy Mapping Causes Post-Authentication VLAN Misassignment
- Intermittent 802.1X Wi-Fi Rejection After Certificate Rotation and Profile Mismatch
- Wireless AP Radio Instability Causing Repeated Client Deauthentication
GlobalProtect VPN Immediate Post-MFA Disconnect¶
- Expired Device Certificate Causes Post-MFA GlobalProtect Tunnel Teardown
- GlobalProtect Profile Certificate Mapping Mismatch Causing Post-Auth Disconnects
- Intermittent GlobalProtect VPN Disconnections After Successful MFA Authentication
- Post-Authentication GlobalProtect Gateway Instability Terminating VPN Sessions
- Stale VPN Profile After Certificate Renewal Causes Tunnel Teardown
Integration Gateway API Timeouts¶
- Downstream API Latency Exceeds Integration Gateway Timeout Causing 504 Errors
- Downstream API Rate-Limit Throttling Causes Gateway Timeout Integration Failures
- Expired Integration Gateway API Token Causes Sync Timeouts
- Integration Gateway Timeout and Sync Failures During Scheduled Batch Windows
- Stale Retry Policy Amplifies Downstream Latency Into Gateway Timeout Storms
Internal DNS Resolution Failures¶
- Client-Side DNS Cache or Local Network Condition Causing Resolution Failures
- Inconsistent Internal Resolver Cache or Forwarder State After DNS Maintenance
- Missing or Incorrect Conditional Forwarder on Internal DNS Resolver
- Stale A Record in Authoritative Internal DNS Zone
- Stale Resolver Cache Serving Outdated Records After Internal Zone Update
Internal Web Service Load-Balancer TLS Certificate Expiry¶
- Expired Certificate on Load Balancer After Automated Renewal Failure
- Expired or Incomplete TLS Certificate Chain Served by Load Balancer
- Renewed Certificate Chain Not Deployed to Load Balancer Before Expiry
- Suspected Transient Certificate-Serving Fault on Load Balancer Unconfirmed
- Wrong Certificate Bound to Load Balancer Causing Hostname Validation Failures
Intune Device Non-Compliant Encryption (Conditional Access Block)¶
- BitLocker Encryption Not Active or Attested Causing Noncompliance Block
- Deprecated Compliance Policy Reference Causes False Encryption Noncompliance
- Intermittent Encryption Signal Loss After OS Update Causes False Noncompliance
- Stale Compliance Refresh Leaves Devices Noncompliant Despite Sync Attempts
- Stale Compliance Signal Mismatch Between Intune and Conditional Access
- Stale Intune Check-In Causes Missing Encryption Signal and Noncompliance
Laptop Slow Post-Login (CPU / Disk Contention)¶
- Endpoint Protection Scan Backlog Causing Post-Login CPU Saturation
- Intermittent Post-Login Slowdown With High Antimalware CPU Usage · self-service
- Post-Login CPU Contention From Resource-Heavy Startup Policy Deployment
- Post-Login Laptop Sluggishness Due to Temp File Disk Exhaustion · self-service
Outlook / Exchange Online Mailbox Sync Failures¶
- Corrupted Microsoft 365 Authentication Tokens Blocking Outlook Sync
- Exchange Online Mailbox Throttling Disrupting Client Synchronization
- Exchange Online Mailbox-Side Sync Fault Across Multiple Clients
- Intune Device Compliance Block Disrupts Exchange Online Mobile Sync
- Stale Mobile Sync Partnership Blocks Outlook Mobile Email
- Stale Outlook Profile and Unhealthy Mobile Sync Partnership Block Mailbox Access
- Stale or Corrupted Outlook Desktop Profile Blocks Exchange Online Sync
Print Server Stuck Jobs / Driver Failure¶
- Corrupt Printer Driver Package Causes Queue Failures and Driver Unavailable Errors
- Intermittent Print Job Stalling on Complex Documents · self-service
- Print Spooler Fails Due to Incorrect Queue or Spool Directory Permissions
- Shared Print Queues Left Paused After Maintenance Window · self-service
- Stale Queue-to-Driver Mapping Causes Stuck Print Jobs
Shared Drive Access Denied¶
- Broken NTFS Inheritance or Explicit Deny ACE on Shared Folder
- Compound Missing AD Group Membership and Stale Cached Credentials Block Share Access
- Kerberos Token Not Reflecting AD Group Despite Confirmed Membership
- Mapped Drive Targeting Retired UNC Path After File Server Migration · self-service
- Missing AD Security Group Membership Denies Department Share Access
- Stale Cached SMB Credentials Cause Mapped Drive Access Denial
Software Center Install Blocked (Endpoint Protection)¶
- Endpoint Protection Application Control Blocking Software Center Installer
- Endpoint Protection Installer Block Combined With Stale Intune Inventory
- FinanceApp Unavailable in Software Center Despite Valid Entitlement
- Missing Entitlement Group Membership Blocks Application Install
- Missing Entitlement Group Membership Combined With Stale Device Inventory
- Missing Entitlement Group Membership With Endpoint Protection Blocking
- Missing Entitlement, Stale Inventory, and Endpoint Protection Block Combined
- Stale Endpoint Inventory and Policy State Blocking Application Deployment
SSO / MFA Prompt Loop (Okta / Azure AD)¶
- Federated SSO Claim Mapping Fault Causes Post-MFA Session Loop
- Group-Scope Policy Mismatch Between Okta and Azure AD Causes MFA Loop
- Stale MFA Enrollment and Group Policy Mismatch Cause SSO Authentication Loop
- Stale Okta MFA Enrollment Records Cause SSO Challenge Loop
- TOTP Clock Drift and Stale Factor Enrollment MFA Prompt Loop