Most of what reaches a service desk is a request from one person. Some of it is a
single fault wearing several tickets. Recognising the difference quickly is the most
valuable thing a first-line analyst does.
Signals that this is one problem, not several
- Two or more users reporting the same symptom within a short window.
- The symptom starts at a specific time rather than gradually.
- The affected users share something — a shift, a site, a device model, a recent
change, a group.
- A read-only check shows a shared component in a bad state.
- The Microsoft 365 service health dashboard shows a matching advisory.
Two reports of the same unusual thing is enough to stop treating them individually
and spend five minutes looking for the common cause.
Check service health first
Before deep-diving a tenant, rule out a Microsoft-side incident. It is free, it takes
thirty seconds, and it changes both the diagnosis and what you tell users.
Size it before you escalate
An escalation is far more useful with a blast radius attached. Answer:
- What is failing, precisely — including the error code.
- Since when — the first failure, not the first report.
- How many are affected, and how you know.
- Who else is exposed that has not complained yet. This is the part people miss:
a stopped directory sync also means disabled leaver accounts still have access.
- What is the business impact — a payment run, a shift, a deadline.
- What you have already ruled out, so nobody repeats your work.
What not to do
- Do not keep treating symptoms. Individually resolving twelve tickets that share
one cause hides the incident and produces twelve divergent workarounds to undo.
- Do not wait for certainty. Escalating a suspected incident that turns out to be
three coincidences costs a few minutes. The reverse costs hours.
- Do not escalate a symptom with no evidence. "Sync seems broken" is not
actionable; "delta sync last succeeded 18 July 17:02, failing with event 6900,
connector account password expired, 1,284 objects pending" is.
While it is open
- Tell affected users it is a known wider fault and that it is being worked. People
accept a problem far better than they accept being told to try again later.
- Note the incident reference on every related ticket so they can be closed together.
- Give an honest timescale, or say plainly that you do not have one yet.
Related
- Microsoft Entra Connect health
- Responding to a compromised account