Diagnoses AWS Systems Manager (SSM) Session Manager failures via a systematic 7-symptom decision tree: target instance not reachable (SSM agent not running, not managed, wrong region), session fails to start (IAM role missing ssm:StartSession, session-manager console permission not attached), port forwarding fails (local port in use, SSH config conflict), shell access fails (SSM agent version too old, shell not configured), VPC connectivity issues (SSM endpoints not configured for private instances), session disconnects (network timeout, idle disconnect), and latest features (Session Manager with key pairs, cross-account sessions).