Root Cause
Users were unable to log in due to a security measure that blocked certain IP addresses. This was a preventive action taken because some authentication processes were incorrectly identifying the user's IP, leading to a block.
Resolution
The issue was resolved by removing the IP from the security rule after an incident was identified. This allowed users to log in again without any disruptions.
Action Plan
The plan includes changing the external DNS to direct requests internally, analyzing the authentication flow for better alert responses, reviewing login thresholds, and improving event logging. Additionally, updating support articles with relevant IP information is necessary.