Login failures spike right after the city rotates MFA tokens. Some users show successful second-factor challenges; others never receive prompts. How should ops triage?
Select an answer to reveal the explanation.
Short Explanation
After an MFA rotation, some folks just need a re-enroll while a true IdP outage looks different in the logs. Use clean test accounts and auth logs to separate user mistakes from a broken auth system.
Full Explanation
Authentication troubleshooting after MFA changes must separate end-user enrollment mistakes from systemic IdP or MFA service faults. Comparing successful versus failed challenge patterns, reviewing auth logs, and validating with known-good test accounts guide remediation. Permanently disabling MFA, mass-wiping profiles, or opening all inbound ports are unsafe and poorly targeted.