AI Playbook

Microsoft 365 service-impact investigation

Determine the scope and likely cause of a Microsoft 365 service problem.

Copy this prompt

Replace the bracketed values, then paste it into an AI client connected to Stackyapper.

Run the "Microsoft 365 service-impact investigation" playbook using Stackyapper.

Inputs
- symptom: [Observed Microsoft 365 symptom or service failure]
- affected users: [Optional affected users or population] (optional)
- time window: [Optional bounded incident window] (optional)

Objective
Determine the scope and likely cause of a Microsoft 365 service problem.

Required evidence
- User directory

Use when available
- Identity security
- Licensing
- Mailbox settings
- Identity configuration
- Service tickets

Procedure
1. Resolve affected identities and determine whether impact is isolated or widespread.
2. Review security, licensing, mailbox, and configuration evidence relevant to the symptom.
3. Correlate existing reports and prior resolutions.
4. State the affected scope, likely fault domain, confidence, and next diagnostic or escalation step.

Return
- Impact scope
- Tenant evidence
- Likely fault domain
- Confidence
- Recommended response

Use only evidence available through the Stackyapper Apps and permissions connected to this AI client. If required evidence is unavailable, say what is missing before continuing. Do not guess or make changes in connected systems.

Before you paste

Replace every bracketed value in the prompt. Delete an optional input line if it does not apply.

  • symptom: Observed Microsoft 365 symptom or service failure. (required)
  • affected users: Optional affected users or population. (optional)
  • time window: Optional bounded incident window. (optional)

What Stackyapper will use

The exact tools depend on the Apps connected to your workspace and the current user's permissions.

  • User directory (required)
  • Identity security (used when available)
  • Licensing (used when available)
  • Mailbox settings (used when available)
  • Identity configuration (used when available)
  • Service tickets (used when available)

What you'll get

  • Impact scope
  • Tenant evidence
  • Likely fault domain
  • Confidence
  • Recommended response

How it works

  1. Resolve affected identities and determine whether impact is isolated or widespread.
  2. Review security, licensing, mailbox, and configuration evidence relevant to the symptom.
  3. Correlate existing reports and prior resolutions.
  4. State the affected scope, likely fault domain, confidence, and next diagnostic or escalation step.