Signing in to CyberQP could fail intermittently — a significant proportion of attempts returned a "Forbidden" error instead of completing. Retrying usually worked, so most people just tried again, sometimes several times. It affected every region and any client that signs in through CyberQP, including the Tech Vault browser extension.
Signing in involves two steps that need to be handled together, and the second step could be picked up by a different server from the one that started the process — a server with no record of the sign-in already underway. The sign-in then couldn't be completed, even though the credentials and permissions involved were perfectly valid.
The information needed to complete a sign-in is now shared across all servers, so the second step succeeds whichever server handles it. Sign-in completes reliably on the first attempt.
If your technicians ran into this, it was
not
a problem with their account, credentials or permissions, and it didn't mean access had been revoked. Using Revoke all tokens
seemed to help at the time but had no actual bearing on it — the next attempt simply had a chance of working. That step is no longer needed.