incident-investigator

Investigate IcM incidents and Android Broker/MSAL authentication issues with log correlation.

5|5|Updated Jan 18, 2019
One-click install
npx skills add https://github.com/AzureAD/android-complete --skill incident-investigator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-investigator
Source: https://github.com/AzureAD/android-complete/tree/main/.github/skills/incident-investigator
Command: npx skills add https://github.com/AzureAD/android-complete --skill incident-investigator

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Systematically investigate IcM incidents and customer-reported authentication issues for Android Broker/MSAL, providing evidence-based diagnosis and structured recommendations.

Core Features & Use Cases

  • Context gathering: Collects affected apps, user accounts, devices, symptoms, and repro steps from IcM or logs.
  • Evidence-driven analysis: Extracts and correlates logs (eSTS, broker) to form a timeline and hypotheses.
  • Guided remediation: Outputs actionable recommendations and verification steps for remediation and follow-up.
  • Use Case: Given an IcM ticket about an authentication failure, compile context, identify likely root causes, and propose validation steps.

Quick Start

Begin the investigation by gathering IcM context and relevant logs to establish the incident scope.

Frequently Asked Questions about incident-investigator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate Android Broker MSAL authentication failures from IcM incidents?

To investigate Android Broker MSAL authentication failures, collect IcM context including affected apps, user accounts, devices, and repro steps. Extract and correlate eSTS and broker logs to build a timeline and form root cause hypotheses.

What is the process for correlating eSTS and broker logs during an authentication incident?

Correlating eSTS and broker logs requires extracting entries across affected apps, devices, and tenants to construct a chronological timeline. This structured log correlation forms evidence-based hypotheses for identifying root causes.

How do I troubleshoot customer-reported MSAL authentication issues on Android?

Troubleshoot customer-reported MSAL Android issues by systematically compiling symptoms and reproduction steps. Apply structured log analysis to extract evidence, identify likely root causes, and output actionable verification steps.

Can I use incident investigation techniques for authentication issues across multiple tenants and apps?

Yes, incident investigation applies to authentication issues across affected apps, devices, and tenants. It enforces evidence-based diagnosis by gathering context and correlating logs to output structured remediation recommendations.

What is the best way to identify root causes from IcM authentication logs?

The best way to identify root causes from IcM logs is evidence-driven analysis. Extract and correlate eSTS and broker logs to form a timeline, generate hypotheses, and output actionable recommendations with verification steps.

Why does my Android Broker authentication investigation lack actionable remediation steps?

Authentication investigations lack remediation steps without structured log correlation. Enforce evidence-based diagnosis by extracting eSTS and broker logs to build a timeline, which outputs actionable recommendations and verification steps.