When users report outages, login failures, application issues, or unexpected behavior, identifying the root cause often requires technicians to manually compare settings across multiple systems and determine what changed.
Use LiongardIQ's change detection, timeline history, asset visibility, and AI-powered search capabilities to quickly identify configuration drift, correlate related changes, and accelerate root cause analysis.
Step 1: Start the Investigation in LiongardIQ
Open the PSA ticket generated by Liongard Actionable Alerts, or begin your investigation directly in LiongardIQ.
Use Global Search or AI-Enriched Search to quickly locate the affected user, device, server, application, or environment.
Examples:
"What changed on the accounting server yesterday?"
"Which users don't have MFA enabled?"
"Are there any backup failures today?"
This provides immediate context before beginning a deeper investigation.
Step 2: Review the Affected Asset or System
Navigate to the impacted Environment, Asset Inventory record, or Inspector.
Review relevant information such as:
User account status
Device information
Microsoft 365 licensing
MFA status
Backup coverage
Security controls
Related assets and dependencies
Use the centralized view to understand the complete operational context without switching between multiple tools.
Step 3: Investigate What Changed
Open the Inspector associated with the affected system and select Timeline.
Compare:
Today vs yesterday
Today vs the last known good state
Previous and current values
Look for:
Firewall rule changes
Policy modifications
Group membership changes
Configuration drift
System setting changes
Determine exactly what changed, when it changed, and whether the timing aligns with the reported issue.
Step 4: Correlate Related Changes
Review nearby timeline events and related systems to identify potential downstream impacts.
Investigate connected technologies such as:
Microsoft 365
Azure AD
Teams
SharePoint
Backup platforms
Endpoint management tools
Security platforms
Build a complete timeline of environmental changes to identify the most likely root cause.
Step 5: Validate with Historical Comparisons
Use LiongardIQ's side-by-side metric comparison capabilities to validate whether a meaningful configuration change occurred.
Review:
Latest values
Historical values
Date-to-date comparisons
Identify:
What changed
When it changed
Whether no configuration change occurred at all
This helps distinguish true configuration drift from unrelated incidents and reduces unnecessary escalations.
Step 6: Document Findings and Confirm Resolution
Add investigation findings, detected changes, timestamps, and remediation actions to the PSA ticket. Confirm whether the change was authorized or unexpected. After remediation, verify the corrected state appears in LiongardIQ following the next inspection cycle.
Why It Matters
Reduce time spent manually reconstructing incidents
Quickly answer "What changed?" without searching across multiple tools
Identify configuration drift before it causes prolonged outages
Accelerate root cause analysis with historical change visibility
Improve escalation workflows with evidence-backed investigations
Reduce mean time to resolution (MTTR)
Resolve incidents faster with complete operational context
When troubleshooting issues that "worked yesterday," LiongardIQ provides the historical evidence needed to move from assumptions to answers.