Reminds me of my early PFE days when I had to fly to Alaska last minute because a customer was experiencing AD authentication issues. I get there, nothing wrong with the DCs, but nothing outside the datacenter can auth. Run packet captures, smells like network issue. Customer swears it isn't. On a hunch, I ask them if they recently rotated keys on a TACLANE (classified network), they say no, but they just upgraded one right before the issue started. Lucky for them I was former USAF and still in the ANG at the time, with experience managing TACLANEs. I tell them to rotate keys on both ends. Problem solved. Customer POC is super embarrassed for calling in a crit-sit when it wasn't remotely a MSFT problem.