The summary.
RESOLVE THE ACTUAL PROBLEM, NOT THE REPORTED SYMPTOM
And know when to stop and escalate — time lost persisting is time the user is not working.
Say what you ruled out when escalating, and retain ownership unless it is formally transferred.
IF USERS BYPASS THE SUPPORT PROCESS, IT IS SLOWER THAN GOING DIRECTLY
Make it faster rather than enforcing it.
A RECURRING INCIDENT IS A PROBLEM TO INVESTIGATE, NOT A TASK TO REPEAT
Review records by category and by system. Incidents clustering in time suggest a change, an update, or a capacity limit reached.
ASK WHETHER THEY WANT TO UNDERSTAND IT OR SIMPLY HAVE IT WORKING
Both are legitimate, and the answer changes your approach entirely.
Never assume seniority indicates technical competence, in either direction.
RECORD WHAT ACTUALLY RESOLVED IT, SEPARATELY FROM WHAT YOU DID
They are frequently different. And write nothing in a record you would not want the user to read.
ESTABLISH VENDOR SUPPORT ARRANGEMENTS BEFORE YOU NEED THEM
FOR A SUSPECTED COMPROMISE
Contain, escalate, reset credentials from a clean device, end sessions, and check for mail rules the user did not create.
Never blame the user — it guarantees the next incident is concealed.