OPERATIONS RUNBOOK · RECOVERY

Recover access after an incorrect security change

Security controls must be reversible. Use this runbook when MFA, certificate binding, firewall rules, agent identity or time synchronization prevents a normal RDP connection.

Use a pilot and keep an independent recovery channel.

Lira changes access controls on real Windows servers. Keep console, hypervisor, iLO/iDRAC, VPN or tested WinRM access available before applying a policy.

The recovery principle

Keep one independent administrative channel outside the RDP flow.

Change one control at a time, preserve the previous state and verify the agent response before continuing.

Do not repeatedly retry a failed login: it can create additional blocks and obscure the original incident.

Related security guidance

MFA code rejected or session expired

  • Check Windows, domain controller and authenticator-device time.
  • Confirm the code belongs to the current enrollment; request a fresh challenge after an expired page.
  • Use a documented temporary bypass only through the portal and remove it after testing.
  • If the agent cannot receive policy, use console or WinRM to restore the service first.

RDP certificate or listener mistake

  • Connect through console or an existing session.
  • Use Restore listener in the portal or restore the previously recorded certificate thumbprint.
  • Verify DNS name, SAN, trust chain and private-key access before binding again.
  • Restart Remote Desktop Services only in the approved maintenance window.

Blocked administrator or wrong firewall rule

  • Add the current external administration address to the allowlist.
  • Wait for an online agent and confirm the local Windows Firewall rule was removed.
  • If no agent is online, use the independent channel to repair service connectivity.
  • Review the exact source, username and timestamps before changing the policy again.

Wrong server identity or duplicate name

  • Compare hostname, internal IP, external IP, agent key and last heartbeat timestamps.
  • Stop the stale service before enrolling a replacement server.
  • Use a new organization-specific key; never rely on a matching display name as identity.
  • Keep the old record for audit until the incident is closed.

Common questions

Can the portal recover a server with no agent and no WinRM?

No. At least one independent channel is required. Use a hypervisor, iLO/iDRAC/KVM/VNC or local console to restore the agent or firewall state.

What if the server clock is wrong?

Correct time synchronization first. Incorrect time can invalidate MFA codes, distort event ordering and make certificate validation fail.

Record the recovery path before production rollout

Test console or WinRM access, preserve the previous certificate and policy state, and assign an incident owner.

Open the Lira console