DEV Community

AdminPackStudio
AdminPackStudio

Posted on

Helpdesk Tier-1 triage cards: how to build a small ticket card library (with 4 copy-ready cards)

Helpdesk Tier-1 triage cards: how to build a small ticket card library

Most Tier-1 queues don't have a knowledge problem. They have a consistency problem. The same ticket ("VPN says connected but I can't reach anything") gets handled four different ways by four techs. One flushes DNS, one reinstalls the client, one escalates right away, and one asks the user to "try again tomorrow."

A triage card library fixes that without a 400-page wiki. Each card is one page for one common ticket: what the user sees, what to check in order, what Tier-1 is allowed to fix, and the exact point where you stop and escalate. Ten to fifteen cards cover most of a Tier-1 day.

This post covers:

  1. The card format, and why it beats long KB articles for Tier-1
  2. How to organize a small card library (naming, IDs, ownership)
  3. An intake card that every other card depends on
  4. Four copy-ready cards: MFA prompt loop, VPN with no internal access, "PC is slow," and OneDrive stuck syncing
  5. An escalation matrix and handoff note
  6. A monthly upkeep routine so the library doesn't rot

If you only want one card to start with, the earlier post on the "Outlook keeps asking for my password" card walks through a single card in depth. This one is about building the set.

Scope: Windows 10/11, Microsoft 365, Entra ID (Azure AD) accounts. Menu names and commands move around, so check every card against your own build, tools, and policies before you publish it to your team. Only work tickets for users and devices you're authorized to support.


1. Why cards beat long KB articles for Tier-1

Long knowledge base articles are written for the person who already understands the problem. Tier-1 techs need something different. They're on a call, the user is waiting, and they need to know the next check in the order that matters.

A good card is:

  • Short. One screen, or one printed page.
  • Ordered. The checks run cheapest and most decisive first, and each one says what a result means.
  • Bounded. It names what Tier-1 may fix and, just as important, what Tier-1 must not do.
  • Escalation-aware. It says exactly when to stop, who gets the ticket, and what to attach.

The format used throughout this post:

CARD <ID>: <the user's words, not the technical cause>

SYMPTOMS     what the user sees / reports
CHECKS       ordered, read-only first, each with "if X -> Y"
TIER-1 FIXES only what your playbook allows
DO NOT       the common mistakes that make things worse
ESCALATE     specific triggers -> specific queue
ATTACH       what Tier-2 needs so they don't call the user back
Enter fullscreen mode Exit fullscreen mode

Name cards with the user's words ("PC is slow," "VPN connected but nothing works"), not the root cause ("DNS suffix misconfiguration"). The tech searches for what the user said, because the cause isn't known yet.


2. Organizing a small card library

You don't need a fancy tool. A folder of Markdown files, a OneNote section, a Confluence space, or a set of ticket macros all work. What matters is structure.

Group cards into four shelves:

Shelf Example cards
0. Intake & rules Intake script, priority rubric, escalation matrix, note template
1. Identity & sign-in Password doesn't work, MFA prompt loop, repeated Office password prompt, VPN no internal access
2. Endpoint basics PC is slow, disk full, Wi-Fi with no internet, printer, dock/monitor
3. M365 apps Outlook can't send, Outlook search, Teams audio, OneDrive stuck, "I lost a file"

Give every card a short ID (ID-02, EP-01, M365-04). Then a ticket note can say "Ran EP-01 checks 1–4," and the next tech knows exactly what was done.

Put a header on every card:

ID: EP-01   Owner: <team/lead>   Last reviewed: <date>   Applies to: Win 10/11
Enter fullscreen mode Exit fullscreen mode

An owner and a review date are what keep a card library alive. Cards without them quietly go stale.

Start small. Pull your last 30 days of tickets, sort by category, and write cards for the top 8–10. That usually covers most of the volume. Add a card only when the same ticket shows up three times without one.


3. The intake card (every other card depends on it)

Most bad escalations aren't caused by bad troubleshooting. They're caused by missing basics. An intake card makes sure every ticket starts with the same facts.

CARD IN-00: Intake (use on every ticket)

ASK
1. Who: name + email/UPN. Verify identity per YOUR org's procedure.
2. Device: name or asset tag (if it's an endpoint issue).
3. Goal: what are you trying to do?
4. Error: exact text or a screenshot. "It doesn't work" isn't an error.
5. Since when? What changed? (password, new laptop, travel, VPN, update)
6. Where: office / home / hotel, wired / Wi-Fi, on VPN or not.
7. Impact: just you, your team, or customers?

DECIDE
- Many users, same symptom -> stop. Tell your lead / check service health.
- Security smell (unexpected MFA prompts, odd inbox rules, "I clicked a link")
  -> follow the security procedure. Don't troubleshoot it as a normal ticket.
- Otherwise -> pick the matching card.

NEVER
- Ask for a password in chat, email, or on the phone.
- Bypass MFA or Conditional Access "as a favor."

DONE WHEN
Another tech could pick up this ticket without calling the user back for basics.
Enter fullscreen mode Exit fullscreen mode

That last line is the whole test for good intake.


4. Four copy-ready Tier-1 cards

These are written to be pasted into your KB and edited. Replace the tool names, queues, and allowed actions with your own.

Card ID-03: MFA prompt loop / "it keeps asking me to approve"

CARD ID-03: MFA prompt loop / endless "approve sign-in"

SYMPTOMS
- Authenticator push arrives, user approves, and sign-in asks again
- "Try another way" goes nowhere
- Often after: new phone, restored phone backup, reinstalled Authenticator

CHECKS (in order)
1. Did the user START this sign-in? If they're getting pushes they didn't
   trigger -> STOP. Treat as possible account compromise. Security procedure.
2. Right account in Authenticator? (work account, not a personal one)
3. Number matching shown? Is the user entering the number from the screen,
   or only tapping "Approve"?
4. Phone time set automatically? (codes fail when the clock drifts)
5. New phone recently? The old phone may still be the registered method.
6. Can they sign in using a code (OTP) instead of a push?

TIER-1 FIXES (only if your role and playbook allow)
- Have the user use the code option instead of push.
- Walk them through re-adding the work account in Authenticator ONLY via
  your org's supported registration flow, after identity is verified.

DO NOT
- Remove or reset MFA methods without verified identity and the right role
- Approve or relay prompts on the user's behalf
- Reset the password to "fix" an MFA loop (it rarely helps)

ESCALATE WHEN
- Unrequested prompts / suspected MFA fatigue        -> Security, now
- Method reset needed and Tier-1 isn't allowed       -> Identity admin
- "Blocked by policy" / Conditional Access wording   -> Identity / CA owner

ATTACH
- Time of last attempt, app/browser used, exact error or screenshot,
  phone change details, whether the user started each prompt
Enter fullscreen mode Exit fullscreen mode

The most important line is check 1. An MFA loop the user didn't start isn't a helpdesk ticket. It's a security event.

Card ID-04: VPN connected but no internal resources

CARD ID-04: VPN says "connected" but file shares / intranet don't work

SYMPTOMS
- VPN client shows connected
- Internal sites, mapped drives, or apps time out
- Internet browsing may still work (split tunnel) or may not

CHECKS (in order)
1. Scope: one user or many? Many -> lead / network team. Stop.
2. One resource or all internal resources?
   One -> could be that app/server, or the user's access to it.
3. Name vs address: run  nslookup <internal-name>
   Fails -> likely DNS over the VPN. Try the full name (server.corp.example).
4. Read-only network info:  ipconfig /all
   Does the VPN adapter have an IP and the expected DNS servers?
5. Another VPN, a "privacy" VPN, or a security tool also running?
6. Right VPN profile / gateway for this user's group or region?
7. Did VPN MFA actually complete, or is the client stuck half-connected?

TIER-1 FIXES
- Disconnect fully, close the client, reconnect.
- Turn off any other VPN or proxy and retest.
- ipconfig /flushdns, then retest by full name (FQDN).
- Reboot once.
- Reinstall the VPN client ONLY from your approved source, and only after
  confirming the profile is correct.

DO NOT
- Edit hosts files or hard-code DNS on the user's laptop
- Install a different VPN client from the internet
- Add the user to network/VPN groups yourself unless that's your role

ESCALATE WHEN
- Multiple users, same resource                   -> Network team
- Adapter has no DNS servers / wrong subnet       -> Network team
- User lacks access to the resource itself        -> App owner / access request
- Works on hotspot, fails on home network         -> Tier-2 (likely IP conflict
                                                     or router issue; document)

ATTACH
- ipconfig /all output, nslookup result, resource(s) affected,
  network type (home/hotel/office), VPN client version, time of test
Enter fullscreen mode Exit fullscreen mode

Check 3 settles most of these. If the name won't resolve but the full name or IP works, it's DNS, not "the VPN is broken."

Card EP-01: "My PC is slow"

CARD EP-01: "My computer is slow"

SYMPTOMS
- Apps hang, long boot, fan loud, "Not responding"

CHECKS (in order)
1. Slow at everything, or one app? One app -> that app's card / vendor.
2. Task Manager > Processes: sort by CPU, Memory, Disk. Note the top 3.
3. Free space on C:. Under ~10% free is a red flag.
4. Last reboot (Task Manager > Performance > CPU > Up time).
   Days or weeks? Pending updates?
5. Anything new: an install, update, or browser extension?
6. Anything suspicious: pop-ups, unknown processes, security alerts?
   -> STOP. Security procedure. Don't "clean it up" yourself.

TIER-1 FIXES
- Reboot (a real restart, not just closing the lid).
- Close runaway apps; trim browser tabs and extensions.
- Free disk space: Storage Sense / Disk Cleanup, Recycle Bin, Downloads.
- Install pending updates if policy allows.
- On managed devices: sync from Company Portal / Settings rather than
  disabling management components.

DO NOT
- Install "PC optimizer" or registry-cleaner tools
- Disable antivirus / Defender to "speed it up"
- Delete files you can't identify, or user data without consent

ESCALATE WHEN
- Disk health warnings, or drive always near full on a standard image -> Tier-2 / hardware
- Malware suspicion                                                  -> Security
- Repeated high CPU from a managed/security agent                    -> Endpoint team
- Hardware age/spec clearly below standard                           -> Lead (refresh)

ATTACH
- Top processes (CPU/Mem/Disk), free space, uptime, recent changes,
  what you already tried
Enter fullscreen mode Exit fullscreen mode

Card M365-04: OneDrive stuck on "processing changes"

CARD M365-04: OneDrive stuck syncing / "processing changes" forever

SYMPTOMS
- Sync icon keeps spinning; files show pending or have a red X
- "Processing changes" or "Looking for changes" for hours

CHECKS (in order)
1. Click the OneDrive cloud icon. Is there a specific error or file listed?
   Screenshot it.
2. Free disk space on the device.
3. Problem file names/paths: very long paths, unusual characters,
   or files open/locked in another app.
4. A huge folder just added or moved? (it may just be slow, not stuck)
5. Can the user open the same files at office.com / in the browser?
   Yes -> the cloud copy is fine; the problem is the local client.
6. Shared library: does the user still have permission to that site?

TIER-1 FIXES
- Pause sync, wait a minute, resume.
- Fully quit OneDrive (cloud icon > Settings > Pause/Quit), reopen.
- Close apps holding the problem file; rename it if the name/path is the issue.
- Free up disk space.
- Make sure the OneDrive client is up to date.

DO NOT
- Unlink the account or delete the local OneDrive folder as a first step
- "Fix" a conflict by deleting one copy before confirming which one is current
- Move the user's data around without telling them

ESCALATE WHEN
- Files exist locally but not in the cloud, and the user needs them  -> Tier-2 (data risk)
- Permission errors on a SharePoint library                          -> Site owner / Tier-2
- Storage quota warnings                                             -> M365 admin
- Unlink/reset is the next step and your playbook reserves it        -> Tier-2

ATTACH
- Error text/screenshot, affected paths, free disk space,
  browser test result, client version, what you already tried
Enter fullscreen mode Exit fullscreen mode

Check 5 is the OneDrive version of the Outlook web test. If the files look right in the browser, the data is safe, and you're only fixing the sync client.


5. The escalation matrix

Cards tell a tech when to escalate. A single matrix tells them where. Keep it on its own page and link every card to it.

ESCALATION MATRIX (edit queue names to match yours)

Trigger                                              -> Queue
-----------------------------------------------------------------------------
Many users, same symptom                             -> Lead + service health
Suspected compromise / unrequested MFA / phishing    -> Security (immediately)
Sign-in blocked: "policy", "compliant", "managed"    -> Identity / CA owner, or
                                                        Endpoint / Intune admin
Device missing from management / enrollment broken   -> Endpoint / Intune admin
Network: DNS, VPN gateway, Wi-Fi floor-wide          -> Network team
App-specific access or data                          -> App owner
Possible data loss (sync, deleted files)             -> Tier-2, flagged as data risk
Hardware failure                                     -> Tier-2 / hardware / RMA
Card's fixes done, problem back within a day         -> Tier-2
Enter fullscreen mode Exit fullscreen mode

Handoff note (paste into the escalation):

Escalating to: <queue>        Card used: <ID>, checks 1–<n>
User / UPN:                   Device:
Business impact:
Ruled out:
Tried (and result):
Key errors + timestamps:
Attachments: (screenshots, ipconfig/dsregcmd output, etc.)
User available: <window>
Enter fullscreen mode Exit fullscreen mode

"Card used: ID-04, checks 1–7" tells Tier-2 more in one line than a paragraph of "tried everything."


6. Keeping the library alive (monthly, ~30 minutes)

Card libraries die quietly. Here's a routine that keeps one useful:

  1. Pull the top 10 ticket categories for the month. Any without a card? Draft one.
  2. Check reopened and bounced tickets. If a card's fixes keep failing, the order or the escalation trigger is wrong. Fix the card, not the tech.
  3. Ask Tier-2 one question: "Which escalations arrived missing something?" Add that item to the card's ATTACH list.
  4. Update menu names after major Windows or Microsoft 365 changes.
  5. Bump the "Last reviewed" date on every card you touched, and archive cards for tickets that no longer happen.

A useful signal to watch: escalations that bounce back to Tier-1 for missing information. When that number drops, the cards are working.


FAQ

What's the difference between a triage card and a KB article?
A KB article explains a topic. A triage card drives a live ticket: ordered checks, allowed fixes, and a hard stop for escalation. Many teams keep both and link the card to the deeper article.

How many cards does a Tier-1 team need?
Start with 8–10 that match your top ticket categories. Most small teams level off around 15–25. If a card hasn't been used in six months, archive it.

Should Tier-1 be allowed to reset passwords and MFA?
That's your org's decision, and it should be written down. If it is allowed, it should always come after identity verification. The cards above keep it behind "only if your role and playbook allow."

Can I automate data collection for cards?
Yes, carefully. A read-only script that gathers local info (OS, uptime, disk space, network config, join state) and saves it to a file saves a lot of back-and-forth. Keep collection scripts read-only so Tier-1 can run them without risk.


Want a ready-made card library?

The cards above are samples of the format used in the IT Helpdesk Tier-1 Break/Fix Runbook Pack ($24) from Admin Pack Studio. It's a ready-made version of the library described in this post:

  • Intake and escalation rules: an intake script, a priority rubric, escalation triggers, and verification steps before any password reset
  • Identity and sign-in cards: password problems, MFA loops, work-account sync errors, VPN with no internal access, guest access to SharePoint links
  • Endpoint cards: slow PC, disk full, Wi-Fi with no internet, printers, docks and monitors
  • Microsoft 365 cards: Outlook send/receive and search, Teams audio/video, OneDrive sync, "I lost a file"
  • Notes and handoff templates plus a weekly queue hygiene routine
  • One read-only PowerShell local snapshot script for Windows triage. It only reads: no password changes, no device actions, no Graph writes.

All of it is plain Markdown, so you can paste it into whatever KB or ticket tool you use.

👉 https://cashflow4375.gumroad.com/l/tezla

If a lot of your escalations end up at Intune enrollment or device compliance, the Intune & M365 Admin Starter Pack covers that side for admins ($19 during launch week, normally $29): https://cashflow4375.gumroad.com/l/joonf

You don't need either one. The intake card, the four cards, and the matrix above are enough to start a library this week.


Admin Pack Studio. Not affiliated with or endorsed by Microsoft. For IT staff authorized to support their organization's users and devices. Follow your own policies, and check current Microsoft documentation for menu names and behavior.

Top comments (0)