ServiceDeskSimulator
AI coaching on Start

Knowledge base

Escalating an incident

Reference: Contoso IT operations standard OPS-07

← All articles
processincidentsop

Most of what reaches a service desk is a request from one person. Some of it is a

single fault wearing several tickets. Recognising the difference quickly is the most

valuable thing a first-line analyst does.

Signals that this is one problem, not several

change, a group.

Two reports of the same unusual thing is enough to stop treating them individually

and spend five minutes looking for the common cause.

Check service health first

Before deep-diving a tenant, rule out a Microsoft-side incident. It is free, it takes

thirty seconds, and it changes both the diagnosis and what you tell users.

Size it before you escalate

An escalation is far more useful with a blast radius attached. Answer:

a stopped directory sync also means disabled leaver accounts still have access.

What not to do

one cause hides the incident and produces twelve divergent workarounds to undo.

three coincidences costs a few minutes. The reverse costs hours.

actionable; "delta sync last succeeded 18 July 17:02, failing with event 6900,

connector account password expired, 1,284 objects pending" is.

While it is open

accept a problem far better than they accept being told to try again later.

Related