DEV Community

AdminPackStudio
AdminPackStudio

Posted on

The sysadmin interview question you'll get anyway — "Tell me about a change that locked users out" (STAR drill + worked outline)

"Tell me about a change that locked users out": a STAR drill for sysadmin and M365 interviews

If you're interviewing for a sysadmin, M365, or endpoint role, expect some version of this question:

"Tell me about a time a change you made (or your team made) caused an outage. What happened, and what did you do?"

It's not a trick. The interviewer wants to know three things: do you check before you fix, do you communicate while it's broken, and do you change something so it doesn't happen again? Most weak answers skip straight to "I rolled it back" and stop there.

Here's one drill you can run in about 10 minutes, built around a very common M365 story: a Conditional Access policy flips to On and users get blocked on Monday morning.


1. The drill (do it out loud, timed)

  1. Set a timer for 3 minutes. Answer the question above out loud using your own real story. If you don't have a CA story, use any change that broke sign-in, mail, VPN, printing, or a line-of-business app.
  2. Stop at 3 minutes, even if you're mid-sentence. Interview answers that run past 3 minutes lose people.
  3. Score yourself with the table in section 5.
  4. Answer the follow-ups in section 4 without notes. That's where most candidates lose points.
  5. Run it again tomorrow. The second run is always tighter.

No real story yet? Use the scenario version in section 3 instead. It's fine to say "I haven't had this exact incident. Here's how I'd handle it." Don't invent one. Interviewers dig into details, and made-up stories fall apart on the second follow-up.


2. Worked STAR outline (illustrative composite)

This is an example structure, not a script. Swap in your own facts, numbers, and tools. Keep it small and true rather than big and vague.

S — Situation (about 20 seconds)

  • ~150-seat org on M365. We were rolling out a Conditional Access policy requiring a compliant device for Exchange Online and SharePoint.
  • The policy had run in report-only for a week, and it was switched to On late Friday.

T — Task (about 10 seconds)

  • Monday 8:05am the help desk queue filled with "can't open Outlook" tickets. I was the on-call admin, so I owned getting people working again and figuring out why.

A — Action (about 90 seconds, the heart of the answer)

  1. Scoped it first. Was it everyone, or one group? Sign-in logs showed failures only from a group of contractor laptops that had never enrolled in Intune. Employees were fine.
  2. Ruled out the obvious. Checked the Microsoft 365 service health page: no incident. The only recent change was our policy.
  3. Confirmed the cause. The sign-in log entries showed the new CA policy as the one that failed, with "device not compliant" / not managed as the reason.
  4. Contained with the smallest safe change. Rather than turn the whole policy off, we temporarily excluded the contractor group (with a ticket, a named owner, and a removal date). Employees stayed protected.
  5. Communicated on a cadence. A short message to affected users and their managers at 8:20 ("we know, here's the workaround, next update at 9:00"), then an all-clear at 8:50.
  6. Didn't break-glass for convenience. Emergency access accounts stayed untouched. This wasn't that kind of outage.

R — Result (about 20 seconds)

  • Contractors were back in ~45 minutes. No security policy was disabled for everyone.
  • Prevention: we added a pre-enforce check (review report-only results by group, not just overall) and stopped enforcing on Friday afternoons. Contractors got a documented path: enroll, or use web-only access.
  • What I'd do differently: I'd have asked "who would fail this policy?" before turning it on, not after.

That last line matters. Owning a miss calmly is often the strongest part of the answer.


3. Scenario version (if you don't have the story)

The interviewer says: "It's Monday, 8am. Fifty people can't get into Outlook. A Conditional Access change went in Friday. Walk me through it."

Talk through it in this order:

  1. Clarify scope: who, how many, which apps, which sites? Desktop and mobile both?
  2. Rule out the service: check Microsoft 365 service health before blaming your own change.
  3. Find evidence: look up one affected user in the Entra sign-in logs. Which policy applied, and what was the failure reason?
  4. Contain narrowly: a scoped, time-boxed exclusion or putting that one policy back to report-only. Not "turn off all CA."
  5. Communicate: first update within ~15 minutes, then a stated cadence.
  6. Prevent: a group-level review of report-only results, change windows, and a rollback note written before the change.

Say out loud that you'd follow the change process and get approval for an emergency exclusion. Interviewers listen for that.


4. The follow-ups they'll actually ask

Practice these without notes:

  • "Why not just turn the policy off?" (Answer: that removes protection for everyone to fix a problem for a few. Contain narrowly.)
  • "How did you know it was CA and not an M365 outage?" (Service health + sign-in log evidence.)
  • "Who did you tell, and when?"
  • "What's a break-glass account, and would you have used it here?"
  • "What changed in your process afterward?"
  • "What would you do differently?"

If a follow-up stumps you, say so: "I'm not sure. Here's how I'd find out." That beats guessing.


5. Score yourself (1–4)

Score What it sounded like
1 Jumped straight to the fix. No scoping, no evidence.
2 Some structure, but missed blast radius or communication.
3 Clear: verify → contain → communicate → result.
4 All of 3, plus prevention, a "what I'd do differently," and judgment about not overreacting.

Aim for a 3 on the first try and a 4 by the second or third run.

Common ways to lose points:

  • Blaming a coworker or "Microsoft."
  • Running past 3 minutes on the Situation.
  • No numbers at all. Even rough ones help ("about 30 users," "back in under an hour").
  • Claiming a bigger role than you had. "I was on the team that…" is fine.

6. Want more drills like this?

This is one of the scenario drills in the Sysadmin Interview & Career Cheatsheet Kit from Admin Pack Studio ($19). It includes a role map and a STAR story bank worksheet, core Windows/AD/networking/M365 Q&A, timed scenario drills (morning outage, new-hire day-one failure, Patch Tuesday fallout, "can you just make me admin?", phishing mailbox rules), offer and first-90-days prep, and a weekly scorecard with a 30-day study plan. It's practice material, not a brain dump, and no one can promise you a job. The practice is what does the work.

👉 https://cashflow4375.gumroad.com/l/nojrvg

On the job and want to avoid the Monday lockout in the first place? The Entra ID Conditional Access Starter Pack ($29) covers report-only → enforce with pilot groups, break-glass hygiene, and sign-in troubleshooting cards, with read-only export scripts: https://cashflow4375.gumroad.com/l/nhuyrc


Admin Pack Studio. Not affiliated with Microsoft. The worked example is an illustrative composite. Use your own true experience in interviews. Check current Microsoft documentation for portal names and features, which change over time.

Top comments (0)