entra1-2 Exercise 3: First Questions for a Client ================================================== THE CHECKLIST ------------- 1. What exactly happens? Ask for the screen, the wording of any message (copied exactly), the time it started, and a screenshot with IDs and names blanked out if you can't share them. 2. Who is affected? One person, some people, everyone at this client, or other clients too? 3. When did it start, and did anything change just before? (A password policy, a new security rule, an administrator leaving, a renewal?) 4. Is a person involved? Do users click "Sign in with Microsoft", or is it a background job or an automatic user sync? 5. What does the integration screen in our product ask for? A client ID and secret, a certificate, an Entity ID or Reply URL, or a provisioning URL and token? (This settles the pattern.) 6. Which tenant is it? Tenant ID or domain name, and who created the registration or enterprise application, you or us? 7. Who is your Entra administrator, and can they look at the integration page with us (screen share), or send us what they see? 8. Do you know when the secret or certificate was created or when it expires? HOW TO USE IT: TWO FICTIONAL REPORTS ------------------------------------ Report 1: "Since 9am Monday nobody at Fabrikam can use 'Sign in with Microsoft'. The message mentions a credential." Q2 everyone at one client -> likely a shared credential or a tenant change. Q4 users clicking -> pattern 1 or 2. Q5 shows a client ID and secret -> pattern 1. Q6: Fabrikam created the registration -> arrangement B, so the secret lives in Fabrikam's tenant. Next step: ask Fabrikam's administrator to open the app registration and check the secret's expiry date (Chapters 4 and 5), and look at the sign-in logs (Chapter 7). Report 2: "New staff haven't appeared in your system for three weeks. Our administrator sees a quarantine warning." Q4 no user involved -> pattern 3 or 4. "New staff appearing" and "quarantine" -> pattern 4, provisioning. Direction: Entra calls your system, so the credential to look at is the one your system issued; check whether it was rotated or expired on your side. Next step: generate a new credential if needed, have the administrator enter it in the provisioning settings and test the connection, then check the provisioning logs. WHY THIS WORKS AS AN ANSWER --------------------------- The questions, taken together, give you the four things you need: the pattern (Q4, Q5), the tenant (Q6), the owner (Q6, Q7) and the likely cause (Q1, Q2, Q3, Q8). Each fictional report ends with a specific first action rather than a guess.