Product → OPERATIONS RUNBOOK · RECOVERY
OPERATIONS RUNBOOK · RECOVERY
Recover access after an incorrect security change
Security controls must be reversible. Use this runbook when MFA, certificate binding, firewall rules, agent identity or time synchronization prevents a normal RDP connection.
Use a pilot and keep an independent recovery channel. Lira changes access controls on real Windows servers. Keep console, hypervisor, iLO/iDRAC, VPN or tested WinRM access available before applying a policy.
The recovery principle Keep one independent administrative channel outside the RDP flow.
Change one control at a time, preserve the previous state and verify the agent response before continuing.
Do not repeatedly retry a failed login: it can create additional blocks and obscure the original incident.
Related security guidance
MFA code rejected or session expired Check Windows, domain controller and authenticator-device time. Confirm the code belongs to the current enrollment; request a fresh challenge after an expired page. Use a documented temporary bypass only through the portal and remove it after testing. If the agent cannot receive policy, use console or WinRM to restore the service first. RDP certificate or listener mistake Connect through console or an existing session. Use Restore listener in the portal or restore the previously recorded certificate thumbprint. Verify DNS name, SAN, trust chain and private-key access before binding again. Restart Remote Desktop Services only in the approved maintenance window. Blocked administrator or wrong firewall rule Add the current external administration address to the allowlist. Wait for an online agent and confirm the local Windows Firewall rule was removed. If no agent is online, use the independent channel to repair service connectivity. Review the exact source, username and timestamps before changing the policy again. Wrong server identity or duplicate name Compare hostname, internal IP, external IP, agent key and last heartbeat timestamps. Stop the stale service before enrolling a replacement server. Use a new organization-specific key; never rely on a matching display name as identity. Keep the old record for audit until the incident is closed.
Recovery preparation Console or hypervisor access is documented. A break-glass account is tested and audited. Current certificate thumbprint is recorded. Server and authenticator time sources are known. Agent and WinRM status are visible.
Common questions Can the portal recover a server with no agent and no WinRM? No. At least one independent channel is required. Use a hypervisor, iLO/iDRAC/KVM/VNC or local console to restore the agent or firewall state.
What if the server clock is wrong? Correct time synchronization first. Incorrect time can invalidate MFA codes, distort event ordering and make certificate validation fail.
Record the recovery path before production rollout Test console or WinRM access, preserve the previous certificate and policy state, and assign an incident owner.
Open the Lira console