Skip to content

Risk Register

#RiskLikelihoodImpactMitigation
1GP coexistence triggers WireGuard restart during parallel operationHIGHMEDIUMDeploy with --network-monitor=false. Safe for production. Remove after GP is fully removed.
2Entra ID OIDC misconfiguration locks users outMEDIUMHIGHTest with pilot group. Maintain local break-glass admin accounts. Document exact App Registration settings.
3Management server outageMEDIUMMEDIUMExisting tunnels survive. Monitor with alerting. Docker restart: unless-stopped. Recovery: minutes.
4Credential-spraying breach on PA-2020 before migration completesLOW-MEDIUMCRITICALAccelerate timeline. Block known malicious IP ranges as interim measure.
5Self-hosted deprovisioning gap — terminated user retains accessMEDIUMMEDIUMSet login expiration to 24h. Documented offboarding checklist: disable in Entra ID + remove from NetBird + revoke setup keys.
6pfSense package incompatibility on Boulder Netgate 6100LOWMEDIUMTest in maintenance window. Linux VM fallback plan ready. Package is actively maintained.
7User productivity loss during transitionHIGHMEDIUMSilent deployment (users see nothing). Step-by-step guides. Per-team VPN champions. Wave-based rollout.
8Insurance claim denial due to EOSL hardwareMEDIUMHIGHDocument migration as security improvement. Notify broker proactively.
9Auto-update resets client settings (bug #5128)MEDIUMLOWPin version via dashboard during initial deployment. Use TacticalRMM for controlled updates.
10Rollback fails — GP cannot be re-enabledLOWHIGHDo NOT uninstall GP until NetBird stable for 30+ days. Keep PA-2020 powered on. Rollback RTO: <1 hour.