Education & healthcare
IT HelpdeskResolving a multi-user identity and access outage
Client anonymised. Named references are available under NDA during due diligence.
The client delivers education and healthcare services in Australia, where a member of staff locked out of their account is a member of staff who cannot work. Canaan provides remote L1 and L2 helpdesk and infrastructure support across the estate, including identity and access management, user provisioning and the joiner-mover-leaver controls underneath both.
The challenge
Multiple users lost access at once — authentication failures, account lockouts, and no route into email or the applications they needed.
The difficulty was attribution. An authentication failure looks identical from the user's side whether it originates in their credentials, in Active Directory or Entra ID, in a permission policy, in network connectivity or in the application's own authentication layer. Each of those has a different fix, and the wrong one carries real cost: remediating at the wrong layer risks opening a security exposure or extending the outage rather than ending it.
The solution
Canaan ran systematic L1 and L2 IAM incident triage, isolating the failures across user accounts, endpoints and application access layers.
Affected accounts were isolated and RBAC, Active Directory and Entra ID authentication dependencies reviewed. Authentication-path analysis then separated credential failures from directory-service, network and application-layer failures — establishing which layer was actually at fault before anything was changed on it.
With service restored, the underlying controls were strengthened: joiner-mover-leaver controls, provisioning and de-provisioning workflows, and access governance, all aimed at the recurrence rather than the incident.
Known error records, knowledge base articles and standardised remediation playbooks were established so the next occurrence is resolved from a documented path rather than diagnosed from scratch.
The outcome
User access was restored within SLA, with minimal productivity impact.
First contact resolution improved on recurring authentication and access incidents, and repeat access-related tickets fell as the standardised IAM workflows and knowledge base articles took effect. Access governance and user lifecycle controls were left stronger than the incident found them.
Structured triage restored service without compromising security — and the access controls put in place to prevent recurrence reduced both the operational and the security risk carried forward.
Each figure is published with its calculation basis on request.
- Within SLA
- User access restored
- ↑
- First contact resolution on access incidents
- ↓
- Repeat access-related tickets
Key takeaways
What carries across.
- An authentication failure looks the same to the user whichever layer causes it — establish the layer before remediating on it.
- Remediating at the wrong layer is not a neutral mistake: it risks security exposure on top of the outage.
- Joiner-mover-leaver controls are where recurring access incidents are actually solved, not in the ticket queue.
- Known error records and playbooks convert a diagnosis into a documented path, which is what moves first contact resolution.