Overview
If a remote worker can browse the internet but cannot reach company resources, the internet connection itself is working. The problem is more likely related to VPN, DNS, authentication, permissions, device policy, or the specific business service.
Why this happens
Remote access depends on several layers working together: home internet, DNS, VPN or secure access, the user's identity, device compliance, permissions, and the business resource itself.
Before you begin
- Identify the exact business resource that fails.
- Confirm whether one resource or all business resources are affected.
- Record the error message and time.
- Do not disable endpoint security or firewall controls.
Click-by-click troubleshooting
Step 1: Confirm ordinary internet access
Action: Open a browser and test two unrelated public websites.
Why this matters: This confirms the home connection is working before troubleshooting company access.
What to look for: Confirm both sites load normally without redirects or captive-portal prompts.
Expected result: Public internet access should work consistently.
Step 2: Confirm whether VPN is required
Action: Check the organization's normal remote-access instructions. If Windows built-in VPN is used, open Settings > Network & internet > VPN and review the approved profile. Otherwise open the organization's approved VPN client and review connection status.
Why this matters: Many internal resources are intentionally unavailable from the public internet.
What to look for: Look for Connected, Disconnected, authentication prompts, or connection errors.
Expected result: VPN should show a healthy connected state before internal resources are tested.
Step 3: Test the resource by its normal address
Action: Open the normal business URL, mapped path, or application after VPN is connected if required.
Why this matters: This confirms whether the original problem remains after the secure-access layer is established.
What to look for: Record access denied, page not found, name resolution, timeout, or sign-in errors.
Expected result: The exact failure type should identify whether the issue is connectivity, name resolution, or authorization related.
Step 4: Verify the work identity
Action: Sign out of the affected business application or browser session if safe, then sign in with the intended work account.
Why this matters: Remote workers can have personal and work identities cached in the same browser or application.
What to look for: Look for an old, personal, guest, or unintended account.
Expected result: The resource should be tested using the correct organizational identity.
Step 5: Compare another business resource
Action: Test another approved internal resource that normally uses the same VPN or identity path.
Why this matters: This distinguishes one-resource failure from a broader remote-access problem.
What to look for: Note whether all internal services fail or only one.
Expected result: The test should isolate the problem to a specific resource or the remote-access path generally.
Step 6: Capture network evidence
Action: Open Command Prompt and run ipconfig and nslookup for the business hostname if known. Do not change settings.
Why this matters: These read-only checks show local network and DNS behavior without altering the device.
What to look for: Look for valid network addressing, VPN adapter presence, and whether the hostname resolves.
Expected result: IT should have enough evidence to determine whether routing, VPN, or DNS is failing.
What to look for
- Internet works but all internal resources fail: VPN or secure-access layer.
- Only one resource fails: service or permission issue.
- Name fails but IP works: DNS issue.
- Wrong account: identity issue.
When to stop
When to contact IT
Contact J3 Systems Group if VPN is connected but resources remain unavailable, DNS does not resolve, access is denied with the correct account, or multiple internal resources fail. Include article code KB-15.001, the resource name, VPN status, error text, and read-only network results.
Need help with this issue?
J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.
Contact J3 Systems GroupAuthoritative references
Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.