An example team moves to a new office connection. Their Azure Windows VM remains running, and no guest configuration was intentionally changed. RDP now times out for everyone at that office. The inbound rule was originally restricted to the old office’s public address. What is a safe way to confirm the cause without exposing RDP to the internet?
A fictional author sees spelling checks in a new blank document, but one template-based file misses obvious errors. Office menus use the expected language. The file contains paragraphs copied from several sources. How can the author test document-level proofing without reinstalling Office?
An example service can retrieve a known object key but cannot enumerate the same bucket. The role policy was written specifically for object reads, and the application recently added a directory-style browser. Does successful GetObject access imply that the list request should also work?
A worked Cloud Run example references an enabled Secret Manager version as an environment variable. The deployer’s account can access the secret. The service uses a dedicated runtime service account, and new instances fail around startup. Which identity and permission should be checked?
In a worked migration scenario, an engineer changes the blob endpoint in application settings from the normal account hostname to the privatelink form. The aim is to guarantee private traffic, but connectivity becomes inconsistent between environments. What hostname should remain in the application, and what evidence actually proves the private route?
A worked deployment uses a Dockerfile USER instruction and runs the application as UID 1001. An audit of the host still shows a rootful Docker daemon. The team assumed the Dockerfile changed both processes. What boundary did the instruction actually change?
In this example, a web app has a system-assigned identity and a versionless Key Vault reference. The administrator can read the secret in the portal, but the app reports an unresolved setting. The vault uses Azure RBAC. The administrator assigned Key Vault Contributor to the app identity and assumed that included secret access. What should be checked before
A fictional application reads most objects under an allowed prefix. A newer object returns AccessDenied. The newer object uses a different customer-managed KMS key. The bucket policy appears unchanged. Which evidence would distinguish S3 access from encryption-key access?
A storage private endpoint and its DNS record exist. A VM in a connected network still resolves the ordinary blob hostname to a public address. The VM uses a custom DNS server, while another VM using the intended Azure resolver gets a private address. The application configuration has not changed. Which part of the DNS chain should be investigated?