Skip to main content

Accelerate Incident Response with Full Context

When an incident occurs, detecting the problem is only the beginning. The next challenge is understanding the environment around it: What asset is involved? Who has access? What changed recently? Is the configuration normal? Are other systems affected?

Without that context, responders spend valuable time jumping between portals, checking documentation, gathering configuration data, and trying to reconstruct what happened.

Liongard gives service and security teams access to current and historical asset intelligence across supported systems, helping them quickly establish context, investigate changes, and make more informed response decisions.

This helps MSPs:

  • Reduce time spent gathering incident context

  • Investigate configuration changes faster

  • Understand affected assets and identities

  • Validate current versus previous system state

  • Reduce portal hopping during investigations

  • Improve escalation and handoff between teams

  • Support root-cause analysis with historical evidence

Why context matters during incident response

An alert can tell you something happened. Responders still need to determine:

  • What system or asset is involved?

  • How is it configured?

  • Which identities or accounts are associated with it?

  • What changed before the incident?

  • Is the current configuration expected?

  • Is this isolated or part of a broader issue?

Liongard helps provide that surrounding operational context so teams can spend less time collecting evidence and more time investigating the incident.

Step 1 — Identify the affected asset or identity

Start by establishing what is involved in the incident.

Depending on the issue, use Liongard to review relevant:

  • Devices

  • Identities and accounts

  • Systems

  • Network infrastructure

  • Security configurations

  • Cloud environments

Asset Inventory can provide a centralized view of applicable device and identity data, helping responders understand what they are dealing with before taking action.

For an identity-related incident, for example, you might review the user's accounts, privileged access, MFA status, and other available identity information.

Step 2 — Establish the current state

Once you've identified the affected system, review its current configuration.

Depending on the Inspector and incident, this could include:

  • Account and permission settings

  • Security policies

  • Firewall configurations

  • Microsoft 365 settings

  • Endpoint configurations

  • Network settings

  • Licensing or service configurations

This gives responders a factual starting point for the investigation rather than relying on potentially outdated documentation.

Step 3 — Determine what changed

If the current state looks suspicious, use Liongard's historical inspection data and Change Detection to investigate what changed. Review:

  • Previous versus current values

  • Configuration changes

  • Identity and access changes

  • Policy modifications

  • Other changes relevant to the affected system

The timing of those changes can provide important clues during root-cause analysis.

For example, if a user suddenly experiences an authentication issue, seeing that MFA, group membership, or another relevant configuration changed shortly before the problem began can dramatically narrow the investigation.

Step 4 — Investigate with Roar Assistant

Roar Assistant can help responders quickly explore Liongard data and gather context conversationally.

Instead of manually searching through individual systems, responders can ask questions related to the investigation, such as:

  • What do we know about this device?

  • Which users have privileged access in this environment?

  • Which privileged accounts don't have MFA enabled?

  • Show me the relevant configuration for this system.

  • What should I review when investigating this issue?

Roar Assistant can help accelerate the initial investigation and point responders toward relevant Liongard data for deeper validation.

Step 5 — Correlate the evidence

An individual configuration change doesn't necessarily explain an incident.

Bring together the available context to understand the larger picture:

Asset context
What system is affected and what role does it play?

Identity context
Which users, administrators, or service accounts are relevant?

Configuration context
What is the system's current state?

Historical context
What changed before or during the incident?

Looking at these together helps responders distinguish normal operational activity from changes that may have contributed to the incident.

Step 6 — Escalate with context attached

When an issue needs to move from the service desk to a senior engineer, security team, or SOC, include the relevant Liongard findings in the escalation.

Instead of: “User can't log in. Please investigate.”

the receiving team can start with information about:

  • The affected identity or asset

  • Current configuration

  • Relevant historical changes

  • Privileged access

  • MFA or security-control status

  • Other findings already validated

That reduces duplicate investigation and helps the next responder start further into the troubleshooting process.

Step 7 — Use findings to prevent repeat incidents

Incident response shouldn't end when service is restored. After resolution, review what Liongard surfaced during the investigation and determine whether the finding should become part of a proactive workflow. For example:

  • Recurring configuration issue → Create or refine an Actionable Alert

  • Unexpected privileged access → Add it to your user access review process

  • Configuration drift → Establish a security change tracking workflow

  • Visibility gap → Expand Inspector or Asset Inventory coverage

This turns individual incidents into opportunities to strengthen future operations.

Example: Investigating a suspicious sign-in

A security team receives an alert for suspicious authentication activity involving a Microsoft 365 user. Using Liongard, the responder can:

  1. Identify the user and review available identity context.

  2. Check MFA and privileged-access information.

  3. Review relevant configuration data.

  4. Investigate historical changes that may provide additional context.

  5. Use Roar Assistant to quickly explore related Liongard data.

  6. Escalate the incident with the relevant evidence already collected.

Rather than beginning the investigation by gathering basic environmental information, the responder starts with a clearer understanding of the affected environment.

Best practices

  • Use Liongard early in the investigation to establish environmental context.

  • Review current and historical state before making configuration changes.

  • Look at asset, identity, configuration, and change data together.

  • Validate Roar Assistant findings against the underlying data when making response decisions.

  • Include relevant context when escalating incidents between teams.

  • Turn recurring findings into Actionable Alerts or standardized review processes.

  • Preserve historical context for post-incident and root-cause reviews.

Operational outcomes

Using asset intelligence during incident response helps MSPs:

  • Reduce investigation time

  • Reduce portal hopping

  • Improve root-cause analysis

  • Provide stronger escalation context

  • Reduce duplicate technician work

  • Make more informed remediation decisions

  • Improve collaboration between service and security teams

  • Turn incident findings into proactive operational improvements

Did this answer your question?