{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
        "slug": "dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/"
        },
        "title": "Investigate an NCSI connectivity indicator using the network transition that triggered it",
        "summary": "How should administrators investigate a Windows connectivity indicator after a network change?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:17:06+00:00",
        "modified_at": "2026-09-08T18:17:13+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 215,
        "potentially_affected": "Use this review for an unexpected Windows connectivity indication after connecting or changing networks.",
        "dse_recommendation": "Build a timeline from the actual transition: connection establishment, portal interaction, and the indicator shown to the user.",
        "primary_source": {
            "name": "Network Connectivity Status Indicator FAQ for Windows",
            "url": "https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>NCSI sends active connectivity probes when a network interface becomes usable after changed conditions, including wired, wireless, and VPN connections. After a successful probe without a proxy, NCSI records that condition and updates the connectivity indicator. A captive portal that still requires input can leave the interface classified as local connectivity. <a href=\"https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for an unexpected Windows connectivity indication after connecting or changing networks. Record the interface, connection method, portal state, and any proxy involvement before selecting a troubleshooting step.</p>\n<h2>DSE recommendation</h2>\n<p>Build a timeline from the actual transition: connection establishment, portal interaction, and the indicator shown to the user. Compare the indicator with access to the particular business application being investigated. Preserve the network conditions during reproduction and change one approved variable at a time. Ask the network owner to review any proposed probe or proxy policy change.</p>\n<h2>Verification</h2>\n<p>Repeat the connection in an approved test and record when the indicator changes. For portal networks, record the state before and after completing the required interaction. Retain evidence for both the probe path and the business application path. If they disagree, describe the disagreement precisely instead of closing the incident solely because one test succeeds.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Network Connectivity Status Indicator FAQ for Windows</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nNCSI sends active connectivity probes when a network interface becomes usable after changed conditions, including wired, wireless, and VPN connections. After a successful probe without a proxy, NCSI records that condition and updates the connectivity indicator. A captive portal that still requires input can leave the interface classified as local connectivity. Microsoft documentation.\nApplicability\nUse this review for an unexpected Windows connectivity indication after connecting or changing networks. Record the interface, connection method, portal state, and any proxy involvement before selecting a troubleshooting step.\nDSE recommendation\nBuild a timeline from the actual transition: connection establishment, portal interaction, and the indicator shown to the user. Compare the indicator with access to the particular business application being investigated. Preserve the network conditions during reproduction and change one approved variable at a time. Ask the network owner to review any proposed probe or proxy policy change.\nVerification\nRepeat the connection in an approved test and record when the indicator changes. For portal networks, record the state before and after completing the required interaction. Retain evidence for both the probe path and the business application path. If they disagree, describe the disagreement precisely instead of closing the incident solely because one test succeeds.\nOfficial references\nMicrosoft Learn: Network Connectivity Status Indicator FAQ for Windows. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nNCSI sends active connectivity probes when a network interface becomes usable after changed conditions, including wired, wireless, and VPN connections. After a successful probe without a proxy, NCSI records that condition and updates the connectivity indicator. A captive portal that still requires input can leave the interface classified as local connectivity. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions).\n\n## Applicability\n\nUse this review for an unexpected Windows connectivity indication after connecting or changing networks. Record the interface, connection method, portal state, and any proxy involvement before selecting a troubleshooting step.\n\n## DSE recommendation\n\nBuild a timeline from the actual transition: connection establishment, portal interaction, and the indicator shown to the user. Compare the indicator with access to the particular business application being investigated. Preserve the network conditions during reproduction and change one approved variable at a time. Ask the network owner to review any proposed probe or proxy policy change.\n\n## Verification\n\nRepeat the connection in an approved test and record when the indicator changes. For portal networks, record the state before and after completing the required interaction. Retain evidence for both the probe path and the business application path. If they disagree, describe the disagreement precisely instead of closing the incident solely because one test succeeds.\n\n## Official references\n\n[Microsoft Learn: Network Connectivity Status Indicator FAQ for Windows](https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Investigate an NCSI connectivity indicator using the network transition that triggered it",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/",
                "headline": "Investigate an NCSI connectivity indicator using the network transition that triggered it",
                "description": "How should administrators investigate a Windows connectivity indicator after a network change?",
                "abstract": "How should administrators investigate a Windows connectivity indicator after a network change?",
                "articleBody": "Source facts\nNCSI sends active connectivity probes when a network interface becomes usable after changed conditions, including wired, wireless, and VPN connections. After a successful probe without a proxy, NCSI records that condition and updates the connectivity indicator. A captive portal that still requires input can leave the interface classified as local connectivity. Microsoft documentation.\nApplicability\nUse this review for an unexpected Windows connectivity indication after connecting or changing networks. Record the interface, connection method, portal state, and any proxy involvement before selecting a troubleshooting step.\nDSE recommendation\nBuild a timeline from the actual transition: connection establishment, portal interaction, and the indicator shown to the user. Compare the indicator with access to the particular business application being investigated. Preserve the network conditions during reproduction and change one approved variable at a time. Ask the network owner to review any proposed probe or proxy policy change.\nVerification\nRepeat the connection in an approved test and record when the indicator changes. For portal networks, record the state before and after completing the required interaction. Retain evidence for both the probe path and the business application path. If they disagree, describe the disagreement precisely instead of closing the incident solely because one test succeeds.\nOfficial references\nMicrosoft Learn: Network Connectivity Status Indicator FAQ for Windows. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:17:06+00:00",
                "dateModified": "2026-09-08T18:17:13+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-005-investigate-an-ncsi-connectivity-indicator-using-the-network-transition-that/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Investigate an NCSI connectivity indicator using the network transition that triggered it"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 215,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Network Connectivity Status Indicator FAQ for Windows",
                    "url": "https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions"
                }
            }
        ]
    }
}