ServiceNow Incident Resolution, Escalation and Knowledge Management
ServiceNow Level 1 Support Lab
I used a ServiceNow Personal Developer Instance to practise realistic Level 1 service desk workflows.
The focus was simple.
Create useful tickets, record technical evidence, resolve appropriate incidents, escalate when Level 1 should stop, and document reusable support knowledge.
Incident Management
Microsoft 365
Microsoft Entra ID
Escalation
Knowledge Management
Lab environment
Environment
- ServiceNow Personal Developer Instance
- Microsoft 365 Business Premium lab tenant
- Microsoft Entra ID
- Fictional Yarra River Services users
- Controlled Level 1 support scenarios
Microsoft 365 sign in incident
Incident intake and prioritisation
The first incident involved Sophie Bennett being unable to sign into Microsoft 365.
I treated this as an incident because an existing service was not working as expected.
The issue affected one user.
I recorded the incident in ServiceNow with Low impact and Medium urgency.
ServiceNow calculated the resulting priority as Low.

Investigation and work notes
I reviewed Microsoft Entra sign in evidence from the affected account.
The sign in logs showed error code 50126.
The failure information indicated invalid username or password credentials.
Authentication details also showed that cloud password authentication had failed.
Finding
The evidence pointed to a credential problem affecting one user rather than a wider Microsoft 365 outage.
I recorded the investigation in ServiceNow work notes so another technician could understand exactly what had already been checked.

Resolution and verification
The credential issue was corrected in the Microsoft 365 lab.
Sign in was tested again.
The incident was then moved to Resolved with resolution notes documenting the investigation and outcome.
Key lesson
Work notes should explain what the technician investigated.
Resolution notes should explain what fixed the problem and how the result was verified.
Hardware escalation workflow
Warehouse printer incident
The second scenario involved a fictional warehouse label printer at Dandenong South.
The printer was unavailable for warehouse dispatch work.
The issue was limited to one device.
I set Medium impact and Medium urgency.
ServiceNow calculated the incident as Moderate priority.

Level 1 troubleshooting and escalation
I documented a structured Level 1 troubleshooting process.
- Confirmed the scope
- Checked power and physical connections
- Reviewed the Windows printer status
- Reviewed the print queue
- Performed a device restart
- Reviewed driver and device detection
The simulated issue remained after reasonable Level 1 checks.
The next action was escalation.

Escalation decision
The evidence suggested a hardware specific fault that required deeper diagnosis or possible warranty assessment.
The incident was assigned to the Hardware support group with the troubleshooting history already documented.
Key lesson
Escalation should not mean simply passing a difficult ticket to someone else.
A useful escalation tells the next technician what happened, what was tested, what the results were and why further support is required.
Knowledge management
Microsoft 365 account access checklist
I created a reusable ServiceNow knowledge article for Level 1 Microsoft 365 account access troubleshooting.
The article provides a repeatable process for another technician to follow.

The checklist covers user verification, issue scope, account status, authentication methods, Microsoft Entra sign in logs, safe corrective actions, verification and escalation.
Consistency matters here.
A documented process reduces guesswork and helps technicians approach similar incidents in the same structured way.
Skills demonstrated
Impact Assessment
Urgency Assessment
Priority
Work Notes
Resolution Notes
Microsoft Entra Logs
Technical Escalation
Assignment Groups
Knowledge Articles
Outcome
This lab gave me practical experience with the core ServiceNow workflow expected from a Level 1 support technician.
I practised taking an issue from initial report through investigation and resolution, while also recognising when another technical team should take ownership.
I also created reusable troubleshooting documentation so the same knowledge could support future incidents.
Lab disclosure
This work was completed in a ServiceNow Personal Developer Instance and Microsoft test environment.
Yarra River Services, its users and the incidents shown here are fictional scenarios created for hands on IT support practice.
The screenshots show my own lab configuration and ticket documentation.