Blink Security Automation — Confidential

IMC — Customer Success Report

Generated 2026-09-10 | imc-value-report.md
2026-09-10Report Date
41Total Playbooks
7Unique Workflows (12m)
56,802Actions Automated (12m)
$14,610Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

41
Total playbooks built
all non-deleted workflows
10
Active playbooks
currently enabled
7
Unique workflows executed (12m)
distinct workflows that ran
56,802
Actions automated (12m)
completed action steps
315.6h
Hours saved (12m)
@ 20s per action
$14,610
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 1,668 risky user states resolved in Microsoft Entra ID without manual analyst action - 521 compromised or suspicious sessions revoked across user accounts - 136 credential lifecycle operations (password resets & MFA resets) completed automatically - 3 account compromise events investigated and confirmed end-to-end

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Identity Threat Response
  • 1,668User risk states resolved in Entra ID
  • 276Risky user sessions revoked
  • 245User sessions revoked on demand
44.8%
5
5 active
Credential & MFA Lifecycle
  • 100Passwords reset via automation
  • 36MFA devices reset for users
3.0%
3
3 active
Utility Subflows (supporting infrastructure)2,796 executions
52.2%
2
2 active
Total5,355 executions100%
10
10 active

Use Case Growth Over Time

17 unique playbooks  |  3 operational use cases  |  5,355 total executions (12m)  |  2025-07 to 2026-07
Toggle:
Toggle:

03Integration Ecosystem

Utility Subflows (supporting infrastructure)
Microsoft Entra ID
Identity Threat Response
Microsoft Entra ID
Credential & MFA Lifecycle
Microsoft Entra ID

04Key Observations

✓  Strengths

Strengths

  • High-volume identity threat automation. With 1,668 user risk resolutions and 521 session revocations in 12 months, the identity threat response use case is clearly operational and running at production scale. This represents meaningful SOC time saved on Entra ID Identity Protection alerts.
  • Well-structured subflow architecture. The "Get User" utility subflow is called consistently across all response playbooks, indicating a clean, reusable design pattern that keeps individual playbooks lean and avoids duplicated lookup logic.
  • Multi-tenant coverage. The presence of BTSG-prefixed playbooks (BTSG Entra ID tenant) alongside IMC playbooks shows the automation layer spans multiple Entra ID tenants, likely reflecting IMC's managed service or multi-entity structure.

###

△  Gaps & Growth Opportunities

Gaps & Opportunities

  • Enable/Disable User and BTSG playbooks show zero executions. The Enable/Disable User playbook exists but has never run — this could indicate it was built speculatively or is pending integration into a trigger flow. The BTSG credential playbooks are similarly dormant, suggesting the BTSG tenant may be underutilized or the integration is not yet fully activated.
  • No trigger-driven (event-based) playbooks observed. All playbooks are automation_type: on_demand, meaning they are manually invoked or called from external orchestrators. There is no evidence of Blink-native alert triggers or scheduled automation. Attaching the identity threat response playbooks to an Entra ID Identity Protection alert trigger would reduce response time and remove the human initiation step entirely.
  • Narrow integration footprint. The entire automation estate is built on a single integration: Microsoft Entra ID. There are no EDR, SIEM, ticketing, or communication integrations present. Expanding into adjacent tools (e.g., auto-creating a ticket on compromise confirmation, or notifying a Slack channel on session revocation) would increase the business value and audit trail of existing workflows.
  • Confirm User Compromise is almost unused (3 runs). This playbook sits at the end of the investigation chain but sees very low usage relative to the upstream risk-resolution workflows. This may indicate analysts are skipping the confirmation step, or that the workflow is not surfaced prominently enough in the response process.

Integration Ecosystem

Integration Usage
Microsoft Entra ID (IMC tenant) All active playbooks
Microsoft Entra ID (BTSG tenant) Dormant playbooks
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 3 use cases | 5,355 executions (12m)

Business KPIs

Metric Count Playbook
User risk states resolved in Entra ID 1,668 IMC - Microsoft Entra ID - Resolve User Risk
Risky user sessions revoked 276 IMC - Microsoft Entra ID - Revoke risky user session
User sessions revoked on demand 245 IMC - Microsoft Entra ID - Revoke User Session
Passwords reset via automation 100 IMC - Microsoft Entra ID - Password Reset
MFA devices reset for users 36 IMC - Microsoft Entra ID - MFA Reset
Account compromise events confirmed 3 IMC - Microsoft Entra ID - Confirm User Compromise
In the last 12 months, Blink automated: - 1,668 risky user states resolved in Microsoft Entra ID without manual analyst action - 521 compromised or suspicious sessions revoked across user accounts - 136 credential lifecycle operations (password resets & MFA resets) completed automatically - 3 account compromise events investigated and confirmed end-to-end

Use Case Summary

Use Case Category Playbooks (total) Active Playbooks Subcategory
Identity Threat Response SOC 5 4 Identity threat response
Credential & MFA Lifecycle IAM 3 2 Password & credential lifecycle
Utility Subflows — 2 1 —

Use Cases

1. Identity Threat Response

Category: SOC — Identity threat response

Description: Automated detection-to-response pipeline for identity-based threats surfaced by Microsoft Entra ID Identity Protection. Covers the full remediation arc: resolving elevated risk scores, revoking live sessions on compromised accounts, and formally confirming user compromise for downstream case handling.

Business problem solved: Identity threats are time-critical — every minute a risky or compromised session remains active extends attacker dwell time. These playbooks remove the manual lookup-and-act cycle from SOC workflows, enabling sub-minute remediation at scale.

Integrations: Microsoft Entra ID (Identity Protection, Graph API)

Playbook Executions (12 mo) Workflow Link
IMC - Microsoft Entra ID - Resolve User Risk 1,668 Open
IMC - Microsoft Entra ID - Revoke risky user session 276 Open
IMC - Microsoft Entra ID - Revoke User Session 245 Open
IMC - Microsoft Entra ID - Confirm User Compromise 3 Open
IMC - Microsoft Entra ID - Enable/Disable User 0 Open

2. Credential & MFA Lifecycle

Category: IAM — Password & credential lifecycle

Description: On-demand credential operations for Entra ID users — password resets and MFA device resets. These playbooks validate user identity before acting, then execute the credential change and return a structured status output.

Business problem solved: Credential resets are high-frequency, low-complexity operations that consume helpdesk and SOC analyst time disproportionately. Automating them frees up staff for higher-value work while ensuring resets are executed consistently and auditably.

Integrations: Microsoft Entra ID (Graph API), BTSG Entra ID tenant

Playbook Executions (12 mo) Workflow Link
IMC - Microsoft Entra ID - Password Reset 100 Open
IMC - Microsoft Entra ID - MFA Reset 36 Open
BTSG - Microsoft Entra ID - Password Reset 0 Open

Utility Subflows (supporting infrastructure)

These playbooks are not counted in KPIs — they are shared subflows invoked by the workflows above, not standalone business actions.

Playbook Executions (12 mo) Called By Workflow Link
IMC - Microsoft Entra ID - Get User 2,539 Revoke Session, Password Reset, Resolve Risk, Confirm Compromise, Enable/Disable, Revoke risky session Open
BTSG - Microsoft Entra ID - Get User 0 BTSG - Password Reset Open

Key Observations

Strengths

  • High-volume identity threat automation. With 1,668 user risk resolutions and 521 session revocations in 12 months, the identity threat response use case is clearly operational and running at production scale. This represents meaningful SOC time saved on Entra ID Identity Protection alerts.
  • Well-structured subflow architecture. The "Get User" utility subflow is called consistently across all response playbooks, indicating a clean, reusable design pattern that keeps individual playbooks lean and avoids duplicated lookup logic.
  • Multi-tenant coverage. The presence of BTSG-prefixed playbooks (BTSG Entra ID tenant) alongside IMC playbooks shows the automation layer spans multiple Entra ID tenants, likely reflecting IMC's managed service or multi-entity structure.

Gaps & Opportunities

  • Enable/Disable User and BTSG playbooks show zero executions. The Enable/Disable User playbook exists but has never run — this could indicate it was built speculatively or is pending integration into a trigger flow. The BTSG credential playbooks are similarly dormant, suggesting the BTSG tenant may be underutilized or the integration is not yet fully activated.
  • No trigger-driven (event-based) playbooks observed. All playbooks are automation_type: on_demand, meaning they are manually invoked or called from external orchestrators. There is no evidence of Blink-native alert triggers or scheduled automation. Attaching the identity threat response playbooks to an Entra ID Identity Protection alert trigger would reduce response time and remove the human initiation step entirely.
  • Narrow integration footprint. The entire automation estate is built on a single integration: Microsoft Entra ID. There are no EDR, SIEM, ticketing, or communication integrations present. Expanding into adjacent tools (e.g., auto-creating a ticket on compromise confirmation, or notifying a Slack channel on session revocation) would increase the business value and audit trail of existing workflows.
  • Confirm User Compromise is almost unused (3 runs). This playbook sits at the end of the investigation chain but sees very low usage relative to the upstream risk-resolution workflows. This may indicate analysts are skipping the confirmation step, or that the workflow is not surfaced prominently enough in the response process.

Integration Ecosystem

Integration Usage
Microsoft Entra ID (IMC tenant) All active playbooks
Microsoft Entra ID (BTSG tenant) Dormant playbooks

Taxonomy Classification

Playbook Category Subcategory
IMC - Microsoft Entra ID - Resolve User Risk SOC Identity threat response
IMC - Microsoft Entra ID - Revoke risky user session SOC Identity threat response
IMC - Microsoft Entra ID - Revoke User Session SOC Identity threat response
IMC - Microsoft Entra ID - Confirm User Compromise SOC Identity threat response
IMC - Microsoft Entra ID - Enable/Disable User SOC Identity threat response
IMC - Microsoft Entra ID - Password Reset IAM Password & credential lifecycle
IMC - Microsoft Entra ID - MFA Reset IAM Password & credential lifecycle
BTSG - Microsoft Entra ID - Password Reset IAM Password & credential lifecycle
IMC - Microsoft Entra ID - Get User IAM Identity sync & directory mgmt _(utility subflow)_
BTSG - Microsoft Entra ID - Get User IAM Identity sync & directory mgmt _(utility subflow)_
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.