Locked Out Of Azure, Working Again Today
RDP refusing to connect, SSH timing out, a site to site tunnel that dropped overnight and will not come back, or a peered network that stopped resolving. We read the logs and the effective rules rather than guessing, find the change that caused it, and fix it the way Microsoft intends rather than by opening everything and hoping.
Almost all of these come down to one rule, one route or one permission. The difficult part was never the fix. It is proving which of the forty possible causes is the actual one, while the portal shows healthy on a network that is quietly dropping your traffic.
What We Get Called About
Find your symptom below and you will find what actually causes it. These five cover most emergency calls, and the cause is almost never where the error message points, which is why they take days to solve alone and an hour with someone who has seen them before.
RDP Or SSH Times Out With Nothing Useful In The Error
A timeout tells you where the traffic stopped and never why. We check the effective security rules on the machine rather than the rules you think apply, the operating system firewall inside it, whether the public address is still attached after the last restart, and the boot diagnostics to see whether the machine ever reached a login prompt. Serial console gets us in when the network path is the broken part.
A Rule Change Broke Something That Worked Yesterday
Security groups can sit on the subnet and on the network card at the same time, so a permit in one place means very little if the other denies. Add priority ordering, the default rules people forget are there, and service tags that cover more or less than expected, and you have the most common cause of a healthy looking network dropping traffic silently.
Two Networks Are Peered And Still Cannot Reach Each Other
Peering does not pass through a third network on its own, so hub and spoke designs need gateway transit or routes written by hand, and plenty of these were built expecting otherwise. We also check custom DNS servers set at the network level, and route tables sending everything to an appliance that is powered off or no longer exists.
The Tunnel Dropped Overnight And Will Not Rebuild
Site to site failures usually come from a settings mismatch with the device at the other end, a shared key that was rotated on one side only, or address ranges that overlap somewhere. For point to site it is more often an expired certificate or a client pool that collides with a network already in use. We read the gateway diagnostics rather than restarting it repeatedly and hoping.
Locked Out, Or Permission Denied On Your Own Resource
Lost administrator passwords are recoverable and the machine does not need rebuilding. Permission errors are usually a role granted at the wrong scope, so it looks assigned and applies to nothing you are trying to reach. Both get fixed properly, with the access left in a state you can hand to somebody else without it breaking again.
Why The Portal Keeps Saying Everything Is Fine
Status pages report whether resources are running, not whether your traffic is arriving. A machine can be perfectly healthy while a rule three layers away drops every packet aimed at it, and the portal has no reason to mention that. The tools that do answer the question, effective rules, flow logs, connection troubleshooting and the gateway diagnostics, are the ones we start with rather than the ones we reach for after a day of restarts.
That is also why a screenshot of the exact error is worth sending before anything else. The wording of a failure narrows forty possible causes down to about three, and it costs you nothing to send.
How An Urgent One Runs
Server down work goes to the front of the queue, and most of these are resolved the same day. The sequence below is the same whether it is a machine that has been unreachable for an hour or a tunnel that has been broken for a week.
You Send The Error And Get An Opinion
A screenshot of the exact failure, the type of resource involved, when it started and anything that changed around that time. That is usually enough for a first read, and you get told what it looks like and roughly how big a job it is before money is discussed. Vague quotes on emergency work suit neither side.
Read Only Is Enough To Start
Diagnosis needs visibility, not control. A reader role scoped to the affected resource group lets us pull the effective rules, the route tables, the flow logs and the gateway diagnostics without the ability to change a single thing. If what we find needs a change, you widen the access at that point, for that job.
The Smallest Change That Solves It
One rule, one route, one role assignment, applied deliberately. It is always faster to open everything up and watch the traffic flow, and it leaves you with a network that works today and an audit finding later. Where a service is already down the change goes in immediately, and where it is degraded rather than dead we agree a time first.
You Get The Cause, Not Just The Result
What was wrong, what changed, and why it broke in the first place, written plainly enough to forward to whoever asks. Where the cause was a rule somebody added without a note, the fix includes leaving the reason behind so the next person to look at it understands what they are seeing.
What Sits Outside This
Redesigning your architecture is a different piece of work, and we will say so rather than quietly turning a two hour fix into a project. Support cases with Microsoft stay under your own subscription, though we will prepare one properly if the problem genuinely belongs on their side. Ongoing management is an arrangement you can ask for, never an assumption written into a repair.
And where the honest answer is that the environment needs rebuilding rather than patching, that is what you will hear, with the reasoning, on the first call rather than after three invoices.
Send The Error, Get An Answer Today
A screenshot of the exact failure, the resource it involves, and roughly when it started. That is enough to tell you what it looks like and how big a job it is, before there is anything to pay for. Anything already down goes to the front of the queue, and if it turns out to be a five minute fix you will be told that too.
Send us the error