Vendor131 problems· 4 reviewed

Azure

131 incident problems in Azure environments.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

LINUX-031SELinux context breaks web content after rsync-based restoreFile ownership and permissions look correct after a restore, but the service still cannot read content because the restored paths lost the expected SELinux labels.ReviewedLinuxIntermediate21 minFreeLINUX-096NTP is synchronized but the hardware clock drifts back after every reboot and breaks certificatesThe running host time looks correct, but restarts reintroduce skew because the persistent hardware clock was never aligned.ReviewedLinuxIntermediate14 minFreeNETWORK-020The CDN cache is fine, but a TLS version difference with the origin fails only miss requestsA situation where most requests are cache hits and look fine, but origin communication breaks only in the cache-miss segment.ReviewedNetworkIntermediate24 minProSECURITY-058OAuth device code session remains active after user offboardingThe user account is disabled, but a previously authorized device code flow keeps working because token revocation and downstream session invalidation were not linked tightly enough.ReviewedSecurityIntermediate20 minFreeSECURITY-002An intermediate certificate chain problem that fails only on certain clientsThe latest browsers connect fine, but some clients fail TLS verification because the server does not send the complete certificate chain.SecurityIntermediate21 minProSECURITY-1192Auth hardening breaks API clientsA public hardening checklist changed proxy header behavior. Browser auth appears fine, but downstream API flows now break because the app no longer sees the scheme and host headers it expects.SecurityIntermediate18 minPro

All problems (131)

SECURITY-058OAuth device code session remains active after user offboardingThe user account is disabled, but a previously authorized device code flow keeps working because token revocation and downstream session invalidation were not linked tightly enough.ReviewedSecurityIntermediate20 minFreeLINUX-096NTP is synchronized but the hardware clock drifts back after every reboot and breaks certificatesThe running host time looks correct, but restarts reintroduce skew because the persistent hardware clock was never aligned.ReviewedLinuxIntermediate14 minFreeLINUX-031SELinux context breaks web content after rsync-based restoreFile ownership and permissions look correct after a restore, but the service still cannot read content because the restored paths lost the expected SELinux labels.ReviewedLinuxIntermediate21 minFreeSECURITY-097Conditional access trusts the compliant device claim but the token was minted before the device fell out of complianceThe policy is sound, yet a risky session survives because token lifetime outlasts the compliance state transition the team expected to revoke it instantly.SecurityIntermediate15 minFreeSECURITY-152A browser isolation policy renders the admin portal remotely, but a direct-download allowlist still lets CSV exports bypass the isolated sessionThe riskiest interaction is protected, yet a side path still leaks the sensitive payload.SecurityIntermediate16 minFreeSECURITY-146A SIEM parser now splits IPv6 addresses and ports correctly, but one detection rule still assumes IPv4 colon counts and silently stops matchingThe data quality improved, yet one analytic depended on the previous broken representation.SecurityIntermediate16 minFreeSECURITY-086Federated logout succeeds in the IdP but leaves the local admin session alive on the legacy appThe user appears signed out globally, but the legacy admin panel still accepts requests because its local session invalidation is not coupled to federation logout.SecurityIntermediate16 minFreeSECURITY-068MFA-enforced sudo flow breaks non-interactive automation on one hostThe stronger policy is correct for humans, but the service account path now fails because the exempt automation group was never applied consistently.SecurityIntermediate16 minFreeSECURITY-071OAuth login fails after a vanity-domain cutoverThe app and IdP are healthy, but authentication loops because the new branded callback path does not exactly match the registered redirect URI set.SecurityIntermediate16 minFreeLINUX-075pam_faillock keeps accounts blocked after LDAP recoveryDirectory authentication is healthy again, but users still cannot log in because the host-local lock records survived the upstream outage.LinuxIntermediate16 minFreeSECURITY-192A parser becomes more correct while one detection silently depends on the old broken field shape during a failover rehearsalData quality improves and a rule built on yesterday's bug stops matching. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-288A parser normalization fix improves usernames while scheduled SIEM exports still query the old field shapes and emit empty reports during a failover rehearsalDashboards look healthy and nightly reporting continues living in the previous schema. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-240A telemetry parser lowercases usernames while one detection still depends on the old mixed-case service account form during a failover rehearsalThe data is normalized and one analytic still expects the previous representation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-059Conditional access blocks the break-glass admin path during a device compliance incidentThe stronger policy makes sense normally, but the emergency access route now fails because it was never carved out from the same device compliance requirements.SecurityIntermediate18 minFreeSECURITY-010Password policy update breaks automation account loginA stronger policy is applied broadly, but one unattended account still uses the old credential pattern and starts failing.SecurityBeginner13 minFreeK8S-114NetworkPolicy allows the namespace selector but cluster DNS still failsThe app can reach peer services, yet name resolution breaks because the policy only modeled TCP while the resolver path still needs UDP.KubernetesIntermediate15 minFreeSECURITY-035Identity provider session expires before a long-running admin workflow finishesThe user signs in successfully and starts a privileged operation, but the background confirmation step fails because the IdP session duration is shorter than the workflow window.SecurityBeginner17 minFreeSECURITY-061SAML login fails after an IdP migrationThe IdP is reachable and the assertion is signed, but the application still rejects login because the expected identity field changed during the migration.SecurityIntermediate18 minFreeLINUX-012A tmp directory cleanup policy that intermittently breaks only upload processingA tmp directory cleanup policy that intermittently breaks only upload... is a hands-on troubleshooting drill. A situation where a batch cleanup task collides with the application's temp files, breaking only a specific feature. Azure Linux Storage and Filesystems needs to be ch...LinuxIntermediate20 minFreeSECURITY-028CSP header blocks internal admin tool script after hardeningCSP header blocks internal admin tool script is a hands-on troubleshooting drill. A new browser security policy helps overall, but one internal tool script source was never added and breaks the page. Azure Identity and Access Management needs to be checked by narrowing scope,...SecurityBeginner13 minFree