01
Scope the impact
Count affected users, devices, locations, departments, and workflows. Note whether unaffected users share anything different.
Everyday IT · Infrastructure
Multiple similar symptoms are evidence of a shared layer. The goal of first-line infrastructure triage is not to redesign the environment. It is to identify the common dependency and hand off a smaller, better-defined problem.Shared symptoms should move your attention upstream.
01
Count affected users, devices, locations, departments, and workflows. Note whether unaffected users share anything different.
02
Look for a shared server, application host, file share, DNS path, identity service, firewall, internet circuit, mail service, print server, database, or cloud service.
03
Use a known-good comparison from another user, workstation, location, or access path so one broken endpoint does not define the outage.
04
Capture reachability, service state, recent alerts, timing, resource pressure, dependency failures, and relevant monitoring without changing production yet.
05
Outlook failing may be identity, DNS, internet, Exchange, profile, or a wider service event. A mapped drive failure may be VPN, DNS, SMB, file server, or permissions.
06
State the affected scope, the common dependency you have isolated, what is still working, and the evidence that makes the issue infrastructure-wide.
Service state, resource usage, alerts, logs, and reachability can often narrow the issue without changing production configuration.
A restart can remove evidence, interrupt healthy dependencies, or make a partial outage worse. Establish a reason and rollback/recovery path first.
Domain controllers, DNS, DHCP, firewalls, hypervisors, databases, backup systems, and mail connectors deserve stronger change controls.
An alert is a clue. Correlate it with the actual user symptom and other infrastructure signals.
One user can be an endpoint problem. Ten users with the same symptom are telling you to look upstream.
Use the shared symptom to narrow the dependency without redesigning production.
Scope
Record affected and unaffected users, devices, locations, and workflows before changing the shared layer. Scope the outage
Compare
Hold one variable constant to separate an endpoint symptom from a shared service failure. Compare deliberately
Restart proposed
Do not reboot a shared system until its role, dependencies, recovery access, evidence, and success criteria are known. Review restart safety
Risk boundary
Preserve the scope, dependency map, service evidence, working paths, and exact unresolved question. Escalate with evidence