01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Identity Threat Response |
| 44.8% | 5 5 active |
| Credential & MFA Lifecycle |
| 3.0% | 3 3 active |
| Utility Subflows (supporting infrastructure) | 2,796 executions | 52.2% | 2 2 active |
| Total | 5,355 executions | 100% | 10 10 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- High-volume identity threat automation. With 1,668 user risk resolutions and 521 session revocations in 12 months, the identity threat response use case is clearly operational and running at production scale. This represents meaningful SOC time saved on Entra ID Identity Protection alerts.
- Well-structured subflow architecture. The "Get User" utility subflow is called consistently across all response playbooks, indicating a clean, reusable design pattern that keeps individual playbooks lean and avoids duplicated lookup logic.
- Multi-tenant coverage. The presence of BTSG-prefixed playbooks (BTSG Entra ID tenant) alongside IMC playbooks shows the automation layer spans multiple Entra ID tenants, likely reflecting IMC's managed service or multi-entity structure.
###
Gaps & Opportunities
- Enable/Disable User and BTSG playbooks show zero executions. The Enable/Disable User playbook exists but has never run — this could indicate it was built speculatively or is pending integration into a trigger flow. The BTSG credential playbooks are similarly dormant, suggesting the BTSG tenant may be underutilized or the integration is not yet fully activated.
- No trigger-driven (event-based) playbooks observed. All playbooks are
automation_type: on_demand, meaning they are manually invoked or called from external orchestrators. There is no evidence of Blink-native alert triggers or scheduled automation. Attaching the identity threat response playbooks to an Entra ID Identity Protection alert trigger would reduce response time and remove the human initiation step entirely. - Narrow integration footprint. The entire automation estate is built on a single integration: Microsoft Entra ID. There are no EDR, SIEM, ticketing, or communication integrations present. Expanding into adjacent tools (e.g., auto-creating a ticket on compromise confirmation, or notifying a Slack channel on session revocation) would increase the business value and audit trail of existing workflows.
- Confirm User Compromise is almost unused (3 runs). This playbook sits at the end of the investigation chain but sees very low usage relative to the upstream risk-resolution workflows. This may indicate analysts are skipping the confirmation step, or that the workflow is not surfaced prominently enough in the response process.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID (IMC tenant) | All active playbooks |
| Microsoft Entra ID (BTSG tenant) | Dormant playbooks |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 3 use cases | 5,355 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| User risk states resolved in Entra ID | 1,668 | IMC - Microsoft Entra ID - Resolve User Risk |
| Risky user sessions revoked | 276 | IMC - Microsoft Entra ID - Revoke risky user session |
| User sessions revoked on demand | 245 | IMC - Microsoft Entra ID - Revoke User Session |
| Passwords reset via automation | 100 | IMC - Microsoft Entra ID - Password Reset |
| MFA devices reset for users | 36 | IMC - Microsoft Entra ID - MFA Reset |
| Account compromise events confirmed | 3 | IMC - Microsoft Entra ID - Confirm User Compromise |
Use Case Summary
| Use Case | Category | Playbooks (total) | Active Playbooks | Subcategory |
|---|---|---|---|---|
| Identity Threat Response | SOC | 5 | 4 | Identity threat response |
| Credential & MFA Lifecycle | IAM | 3 | 2 | Password & credential lifecycle |
| Utility Subflows | — | 2 | 1 | — |
Use Cases
1. Identity Threat Response
Category: SOC — Identity threat response
Description: Automated detection-to-response pipeline for identity-based threats surfaced by Microsoft Entra ID Identity Protection. Covers the full remediation arc: resolving elevated risk scores, revoking live sessions on compromised accounts, and formally confirming user compromise for downstream case handling.
Business problem solved: Identity threats are time-critical — every minute a risky or compromised session remains active extends attacker dwell time. These playbooks remove the manual lookup-and-act cycle from SOC workflows, enabling sub-minute remediation at scale.
Integrations: Microsoft Entra ID (Identity Protection, Graph API)
| Playbook | Executions (12 mo) | Workflow Link |
|---|---|---|
| IMC - Microsoft Entra ID - Resolve User Risk | 1,668 | Open |
| IMC - Microsoft Entra ID - Revoke risky user session | 276 | Open |
| IMC - Microsoft Entra ID - Revoke User Session | 245 | Open |
| IMC - Microsoft Entra ID - Confirm User Compromise | 3 | Open |
| IMC - Microsoft Entra ID - Enable/Disable User | 0 | Open |
2. Credential & MFA Lifecycle
Category: IAM — Password & credential lifecycle
Description: On-demand credential operations for Entra ID users — password resets and MFA device resets. These playbooks validate user identity before acting, then execute the credential change and return a structured status output.
Business problem solved: Credential resets are high-frequency, low-complexity operations that consume helpdesk and SOC analyst time disproportionately. Automating them frees up staff for higher-value work while ensuring resets are executed consistently and auditably.
Integrations: Microsoft Entra ID (Graph API), BTSG Entra ID tenant
| Playbook | Executions (12 mo) | Workflow Link |
|---|---|---|
| IMC - Microsoft Entra ID - Password Reset | 100 | Open |
| IMC - Microsoft Entra ID - MFA Reset | 36 | Open |
| BTSG - Microsoft Entra ID - Password Reset | 0 | Open |
Utility Subflows (supporting infrastructure)
These playbooks are not counted in KPIs — they are shared subflows invoked by the workflows above, not standalone business actions.
| Playbook | Executions (12 mo) | Called By | Workflow Link |
|---|---|---|---|
| IMC - Microsoft Entra ID - Get User | 2,539 | Revoke Session, Password Reset, Resolve Risk, Confirm Compromise, Enable/Disable, Revoke risky session | Open |
| BTSG - Microsoft Entra ID - Get User | 0 | BTSG - Password Reset | Open |
Key Observations
Strengths
- High-volume identity threat automation. With 1,668 user risk resolutions and 521 session revocations in 12 months, the identity threat response use case is clearly operational and running at production scale. This represents meaningful SOC time saved on Entra ID Identity Protection alerts.
- Well-structured subflow architecture. The "Get User" utility subflow is called consistently across all response playbooks, indicating a clean, reusable design pattern that keeps individual playbooks lean and avoids duplicated lookup logic.
- Multi-tenant coverage. The presence of BTSG-prefixed playbooks (BTSG Entra ID tenant) alongside IMC playbooks shows the automation layer spans multiple Entra ID tenants, likely reflecting IMC's managed service or multi-entity structure.
Gaps & Opportunities
- Enable/Disable User and BTSG playbooks show zero executions. The Enable/Disable User playbook exists but has never run — this could indicate it was built speculatively or is pending integration into a trigger flow. The BTSG credential playbooks are similarly dormant, suggesting the BTSG tenant may be underutilized or the integration is not yet fully activated.
- No trigger-driven (event-based) playbooks observed. All playbooks are
automation_type: on_demand, meaning they are manually invoked or called from external orchestrators. There is no evidence of Blink-native alert triggers or scheduled automation. Attaching the identity threat response playbooks to an Entra ID Identity Protection alert trigger would reduce response time and remove the human initiation step entirely. - Narrow integration footprint. The entire automation estate is built on a single integration: Microsoft Entra ID. There are no EDR, SIEM, ticketing, or communication integrations present. Expanding into adjacent tools (e.g., auto-creating a ticket on compromise confirmation, or notifying a Slack channel on session revocation) would increase the business value and audit trail of existing workflows.
- Confirm User Compromise is almost unused (3 runs). This playbook sits at the end of the investigation chain but sees very low usage relative to the upstream risk-resolution workflows. This may indicate analysts are skipping the confirmation step, or that the workflow is not surfaced prominently enough in the response process.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID (IMC tenant) | All active playbooks |
| Microsoft Entra ID (BTSG tenant) | Dormant playbooks |
Taxonomy Classification
| Playbook | Category | Subcategory |
|---|---|---|
| IMC - Microsoft Entra ID - Resolve User Risk | SOC | Identity threat response |
| IMC - Microsoft Entra ID - Revoke risky user session | SOC | Identity threat response |
| IMC - Microsoft Entra ID - Revoke User Session | SOC | Identity threat response |
| IMC - Microsoft Entra ID - Confirm User Compromise | SOC | Identity threat response |
| IMC - Microsoft Entra ID - Enable/Disable User | SOC | Identity threat response |
| IMC - Microsoft Entra ID - Password Reset | IAM | Password & credential lifecycle |
| IMC - Microsoft Entra ID - MFA Reset | IAM | Password & credential lifecycle |
| BTSG - Microsoft Entra ID - Password Reset | IAM | Password & credential lifecycle |
| IMC - Microsoft Entra ID - Get User | IAM | Identity sync & directory mgmt _(utility subflow)_ |
| BTSG - Microsoft Entra ID - Get User | IAM | Identity sync & directory mgmt _(utility subflow)_ |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.