Blink Security Automation — Confidential

BDO Denmark — Customer Success Report

Generated 2026-09-10 | bdo-denmark-value-report.md
2026-09-10Report Date
38Total Playbooks
7Unique Workflows (12m)
7,414Actions Automated (12m)
$1,907Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

38
Total playbooks built
all non-deleted workflows
8
Active playbooks
currently enabled
7
Unique workflows executed (12m)
distinct workflows that ran
7,414
Actions automated (12m)
completed action steps
41.2h
Hours saved (12m)
@ 20s per action
$1,907
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 193 IT support requests ingested and routed from Zendesk without manual triage - 185 MFA resets resolved end-to-end without helpdesk involvement - 175 password resets completed automatically, end-to-end - 172 user sessions revoked in response to security or access events - 8 user account activations and deactivations executed on demand

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Use Case 1: IT Helpdesk Automation via Zendesk196 executions
25.7%
1
1 active
Use Case 2: Identity Lifecycle Management376 executions
49.3%
3
3 active
Use Case 3: Identity Threat Response176 executions
23.1%
3
3 active
Total748 executions100%
7
7 active

Use Case Growth Over Time

10 unique playbooks  |  3 operational use cases  |  762 total executions (12m)  |  2025-11 to 2026-07
Toggle:
Toggle:

03Integration Ecosystem

Use Case 2: Identity Lifecycle Management
Microsoft Entra ID
Use Case 3: Identity Threat Response
Microsoft Entra ID
Use Case 1: IT Helpdesk Automation via Zendesk
Zendesk

04Key Observations

✓  Strengths

Strengths

  • High-volume IAM automation is fully operational. MFA Reset (185), Password Reset (175), and Revoke User Session (172) together account for 532 automated actions in 12 months — all routine but high-cost operations when handled manually. This is a strong core of proven, production-grade automation.
  • Zendesk integration bridges helpdesk and identity ops. With 193 Zendesk webhook events processed, there is an active pipeline connecting the ticketing system to identity workflows. This suggests a mature self-service or L1-automation model for common IT requests.
  • Session revocation at scale. 172 automated session revocations is significant — this indicates active use of identity containment as a response action, not just as a built-in capability.

###

△  Gaps & Growth Opportunities

Gaps

  • Identity threat investigation is built but dormant. *Confirm User Compromise* and *Resolve User Risk* both have zero executions. These workflows are deployed but not yet integrated into an active SOC process or alert-driven trigger. Connecting them to a SIEM, XDR, or Entra ID Identity Protection alert would unlock their value immediately.
  • Narrow integration surface. The entire automation footprint is built on a single integration: Microsoft Entra ID. There is no coverage for endpoint detection, cloud security posture, vulnerability management, or broader GRC use cases. Expansion opportunities exist across all major security domains.
  • No automated alert ingestion. There is no SIEM or XDR feed into Blink. Alert enrichment, triage, and case management are absent — the identity threat response use case is triggered manually rather than by real-time detections.
  • Enable/Disable User underutilized. Only 8 executions against a backdrop of 175+ password resets and 185+ MFA resets suggests that account lifecycle changes (e.g., onboarding, offboarding, access suspension) are still handled manually or through a separate system.

Integration Ecosystem

Integration Usage
Microsoft Entra ID Core — all IAM and identity threat response workflows
Zendesk Event trigger for helpdesk routing
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 3 use cases | 762 executions (12m)

Business KPIs

Metric Count Playbook
IT support tickets routed & processed via Zendesk 193 Webhook from Zendesk
MFA resets completed without IT intervention 185 Microsoft Entra ID - MFA Reset
Password resets completed end-to-end 175 Microsoft Entra ID - Password Reset
User sessions revoked in response to security events 172 Microsoft Entra ID - Revoke User Session
User accounts enabled or disabled 8 Microsoft Entra ID - Enable/Disable User
In the last 12 months, Blink automated: - 193 IT support requests ingested and routed from Zendesk without manual triage - 185 MFA resets resolved end-to-end without helpdesk involvement - 175 password resets completed automatically, end-to-end - 172 user sessions revoked in response to security or access events - 8 user account activations and deactivations executed on demand

Use Case Summary

Use Case Category Total Playbooks Active Playbooks (executions > 0)
IT Helpdesk Automation via Zendesk Other 1 1
Identity Lifecycle Management IAM 4 3
Identity Threat Response SOC 3 1

Use Cases

Use Case 1: IT Helpdesk Automation via Zendesk

Description: Zendesk tickets are ingested as webhook events and routed into Blink workflows for automated resolution. This serves as the integration layer connecting the IT helpdesk ticketing system to downstream identity management actions.

Business problem solved: Eliminates the manual triage step where helpdesk agents read Zendesk tickets and hand off identity-related requests to IT admins. Incoming requests are captured and dispatched automatically, reducing response latency and analyst toil.

Integrations: Zendesk (webhook trigger)

Category: Other — IT helpdesk & ticket routing

Playbook Executions (12 mo) Trigger Type Category Subcategory
Webhook from Zendesk 193 Event (custom webhook) Other IT helpdesk & ticket routing

Use Case 2: Identity Lifecycle Management

Description: On-demand automations that handle the full range of routine Entra ID operations — resetting MFA methods, resetting passwords, enabling or disabling accounts, and looking up user details. These workflows validate inputs, execute the action against Microsoft Entra ID, and return a structured status output.

Business problem solved: Routine identity operations (password resets, MFA resets, account state changes) are among the highest-volume helpdesk requests in any enterprise. Automating them eliminates manual admin steps, reduces wait times for end users, and frees IT staff for higher-value work.

Integrations: Microsoft Entra ID (active-directory connector)

Category: IAM — Password & credential lifecycle, Identity lifecycle automation, Identity sync & directory mgmt

Playbook Executions (12 mo) Trigger Type Category Subcategory
Microsoft Entra ID - MFA Reset 185 On demand IAM Password & credential lifecycle
Microsoft Entra ID - Password Reset 175 On demand IAM Password & credential lifecycle
Microsoft Entra ID - Enable/Disable User 8 On demand IAM Identity lifecycle automation
Microsoft Entra ID - Get User *(subflow)* 14 On demand IAM Identity sync & directory mgmt
*Microsoft Entra ID - Get User* is a shared utility subflow called internally by other workflows; its executions are not counted as independent business actions.

Use Case 3: Identity Threat Response

Description: On-demand security response automations targeting compromised or at-risk Entra ID accounts — revoking active sessions, confirming user compromise status, and resolving flagged user risks. Session revocation is the most active workflow in this group.

Business problem solved: When an account is suspected of compromise, speed of containment determines blast radius. Automating session revocation and risk resolution lets security teams respond in seconds rather than minutes, without requiring an admin to manually navigate the Entra ID portal under pressure.

Integrations: Microsoft Entra ID (active-directory connector)

Category: SOC — Identity threat response

Playbook Executions (12 mo) Trigger Type Category Subcategory
Microsoft Entra ID - Revoke User Session 172 On demand SOC Identity threat response
Microsoft Entra ID - Confirm User Compromise 0 On demand SOC Identity threat response
Microsoft Entra ID - Resolve User Risk 0 On demand SOC Identity threat response

Key Observations

Strengths

  • High-volume IAM automation is fully operational. MFA Reset (185), Password Reset (175), and Revoke User Session (172) together account for 532 automated actions in 12 months — all routine but high-cost operations when handled manually. This is a strong core of proven, production-grade automation.
  • Zendesk integration bridges helpdesk and identity ops. With 193 Zendesk webhook events processed, there is an active pipeline connecting the ticketing system to identity workflows. This suggests a mature self-service or L1-automation model for common IT requests.
  • Session revocation at scale. 172 automated session revocations is significant — this indicates active use of identity containment as a response action, not just as a built-in capability.

Gaps

  • Identity threat investigation is built but dormant. *Confirm User Compromise* and *Resolve User Risk* both have zero executions. These workflows are deployed but not yet integrated into an active SOC process or alert-driven trigger. Connecting them to a SIEM, XDR, or Entra ID Identity Protection alert would unlock their value immediately.
  • Narrow integration surface. The entire automation footprint is built on a single integration: Microsoft Entra ID. There is no coverage for endpoint detection, cloud security posture, vulnerability management, or broader GRC use cases. Expansion opportunities exist across all major security domains.
  • No automated alert ingestion. There is no SIEM or XDR feed into Blink. Alert enrichment, triage, and case management are absent — the identity threat response use case is triggered manually rather than by real-time detections.
  • Enable/Disable User underutilized. Only 8 executions against a backdrop of 175+ password resets and 185+ MFA resets suggests that account lifecycle changes (e.g., onboarding, offboarding, access suspension) are still handled manually or through a separate system.

Integration Ecosystem

Integration Usage
Microsoft Entra ID Core — all IAM and identity threat response workflows
Zendesk Event trigger for helpdesk routing

1. Business KPIs — Last 12 Months

Metric Count Playbook
IT support tickets routed & processed via Zendesk 193 Webhook from Zendesk
MFA resets completed without IT intervention 185 Microsoft Entra ID - MFA Reset
Password resets completed end-to-end 175 Microsoft Entra ID - Password Reset
User sessions revoked in response to security events 172 Microsoft Entra ID - Revoke User Session
User accounts enabled or disabled 8 Microsoft Entra ID - Enable/Disable User
In the last 12 months, Blink automated: - 193 IT support requests ingested and routed from Zendesk without manual triage - 185 MFA resets resolved end-to-end without helpdesk involvement - 175 password resets completed automatically, end-to-end - 172 user sessions revoked in response to security or access events - 8 user account activations and deactivations executed on demand

2. Use Case Summary

Use Case Category Total Playbooks Active Playbooks (executions > 0)
IT Helpdesk Automation via Zendesk Other 1 1
Identity Lifecycle Management IAM 4 3
Identity Threat Response SOC 3 1

3. Use Cases

Use Case 1: IT Helpdesk Automation via Zendesk

Description: Zendesk tickets are ingested as webhook events and routed into Blink workflows for automated resolution. This serves as the integration layer connecting the IT helpdesk ticketing system to downstream identity management actions.

Business problem solved: Eliminates the manual triage step where helpdesk agents read Zendesk tickets and hand off identity-related requests to IT admins. Incoming requests are captured and dispatched automatically, reducing response latency and analyst toil.

Integrations: Zendesk (webhook trigger)

Category: Other — IT helpdesk & ticket routing

Playbook Executions (12 mo) Trigger Type Category Subcategory
Webhook from Zendesk 193 Event (custom webhook) Other IT helpdesk & ticket routing

Use Case 2: Identity Lifecycle Management

Description: On-demand automations that handle the full range of routine Entra ID operations — resetting MFA methods, resetting passwords, enabling or disabling accounts, and looking up user details. These workflows validate inputs, execute the action against Microsoft Entra ID, and return a structured status output.

Business problem solved: Routine identity operations (password resets, MFA resets, account state changes) are among the highest-volume helpdesk requests in any enterprise. Automating them eliminates manual admin steps, reduces wait times for end users, and frees IT staff for higher-value work.

Integrations: Microsoft Entra ID (active-directory connector)

Category: IAM — Password & credential lifecycle, Identity lifecycle automation, Identity sync & directory mgmt

Playbook Executions (12 mo) Trigger Type Category Subcategory
Microsoft Entra ID - MFA Reset 185 On demand IAM Password & credential lifecycle
Microsoft Entra ID - Password Reset 175 On demand IAM Password & credential lifecycle
Microsoft Entra ID - Enable/Disable User 8 On demand IAM Identity lifecycle automation
Microsoft Entra ID - Get User *(subflow)* 14 On demand IAM Identity sync & directory mgmt
*Microsoft Entra ID - Get User* is a shared utility subflow called internally by other workflows; its executions are not counted as independent business actions.

Use Case 3: Identity Threat Response

Description: On-demand security response automations targeting compromised or at-risk Entra ID accounts — revoking active sessions, confirming user compromise status, and resolving flagged user risks. Session revocation is the most active workflow in this group.

Business problem solved: When an account is suspected of compromise, speed of containment determines blast radius. Automating session revocation and risk resolution lets security teams respond in seconds rather than minutes, without requiring an admin to manually navigate the Entra ID portal under pressure.

Integrations: Microsoft Entra ID (active-directory connector)

Category: SOC — Identity threat response

Playbook Executions (12 mo) Trigger Type Category Subcategory
Microsoft Entra ID - Revoke User Session 172 On demand SOC Identity threat response
Microsoft Entra ID - Confirm User Compromise 0 On demand SOC Identity threat response
Microsoft Entra ID - Resolve User Risk 0 On demand SOC Identity threat response

4. Key Observations

Strengths

  • High-volume IAM automation is fully operational. MFA Reset (185), Password Reset (175), and Revoke User Session (172) together account for 532 automated actions in 12 months — all routine but high-cost operations when handled manually. This is a strong core of proven, production-grade automation.
  • Zendesk integration bridges helpdesk and identity ops. With 193 Zendesk webhook events processed, there is an active pipeline connecting the ticketing system to identity workflows. This suggests a mature self-service or L1-automation model for common IT requests.
  • Session revocation at scale. 172 automated session revocations is significant — this indicates active use of identity containment as a response action, not just as a built-in capability.

Gaps

  • Identity threat investigation is built but dormant. *Confirm User Compromise* and *Resolve User Risk* both have zero executions. These workflows are deployed but not yet integrated into an active SOC process or alert-driven trigger. Connecting them to a SIEM, XDR, or Entra ID Identity Protection alert would unlock their value immediately.
  • Narrow integration surface. The entire automation footprint is built on a single integration: Microsoft Entra ID. There is no coverage for endpoint detection, cloud security posture, vulnerability management, or broader GRC use cases. Expansion opportunities exist across all major security domains.
  • No automated alert ingestion. There is no SIEM or XDR feed into Blink. Alert enrichment, triage, and case management are absent — the identity threat response use case is triggered manually rather than by real-time detections.
  • Enable/Disable User underutilized. Only 8 executions against a backdrop of 175+ password resets and 185+ MFA resets suggests that account lifecycle changes (e.g., onboarding, offboarding, access suspension) are still handled manually or through a separate system.

Integration Ecosystem

Integration Usage
Microsoft Entra ID Core — all IAM and identity threat response workflows
Zendesk Event trigger for helpdesk routing
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.