01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| EDR Alert Triage, Enrichment & Containment |
| 0.9% | 11 11 active |
| Identity Threat Monitoring & Response |
| 24.5% | 2 2 active |
| DLP Exception Lifecycle Management |
| 63.3% | 7 7 active |
| Stale Device Lifecycle Automation |
| 1.8% | 4 4 active |
| Password & Credential Management |
| 0.7% | 7 7 active |
| Server Vulnerability & Asset Lifecycle |
| 0.0% | 5 5 active |
| Agentic SOC Toolset | 0 executions | 0.0% | 11 11 active |
| Phishing Alert Triage & Response |
| 8.6% | 4 4 active |
| Power Platform Security Posture Monitoring |
| 0.0% | 1 1 active |
| Total | 47,052 executions | 100% | 52 52 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
High-volume DLP enforcement at scale. The DLP exception lifecycle is the most operationally active use case, with 35,072 automated exception removals and 371 additions over 12 months. This represents a mature, production-grade compliance automation covering the full add-track-expire-revoke lifecycle with no manual queuing required.
Analyst-gated SOC workflow architecture. Alert response is structured around an explicit human approval gate (web form + email), meaning automation handles enrichment, context aggregation, and orchestration while analysts retain decision authority. This is a defensible, audit-friendly design appropriate for a regulated financial services environment.
Dual-EDR coverage with unified pipeline. Both CrowdStrike and Microsoft Defender for Endpoints are integrated into a single alert triage pipeline, with IOC extraction and enrichment abstracted as reusable subflows. Cross-platform alert correlation happens automatically before any analyst interaction.
IAM automation breadth. Password lifecycle, stale device cleanup, user restoration, and privileged credential management are all automated across Entra ID, Active Directory, Delinea, and UserCube — covering the most common IAM failure modes in an enterprise environment.
Agentic SOC foundation in place. A structured Ability library covering CrowdStrike, Defender, Entra ID, Splunk, and Power Platform is deployed in a dedicated workspace. Initial execution counts (13 executions across 6 abilities) indicate early-stage adoption with a platform ready to scale into autonomous investigation workflows.
New phishing triage pipeline established. A 15-minute scheduled driver now logs phishing submissions to tracking tables, links related threat IDs for cross-case correlation, and dispatches analyst notifications — 1,252 combined executions across the driver and its subflows indicate immediate high-volume adoption.
###
Gaps
CrowdStrike alert pipeline inactive. Ingest - Crowdstrike Alert has 0 executions despite the full workflow being built with webhook trigger and alert enrichment steps. CrowdStrike-originated alerts are not flowing through Blink, leaving Microsoft Defender as the sole active EDR ingest source. This is a coverage gap given CrowdStrike is also deployed for containment.
Vulnerability management pipeline not operationalized. The Tenable integration handles server onboarding and offboarding (30 executions combined) but Server Vulnerability Submissions, Run Tenable Scan, and Rescan all have 0 executions. Vulnerability scanning, prioritization, and remediation tracking are not yet automated beyond asset registration.
Containment response actions unused. Subflow - AV Scan Host, Subflow - Auto Investigate, and Subflow - Isolate Host with Crowdstrike all have 0 executions. These response capabilities are built and integrated with CrowdStrike and Defender but are not being triggered through the alert response facilitation workflow.
DLP USB exception flow not activated. DLP USB Exception Workflow exists with a webhook trigger but has 0 executions. USB-based DLP exception requests are likely still being handled through a manual process outside of Blink.
Agentic SOC at early adoption. The Ability library has 11 workflows built but only 5 have been invoked (13 total executions). The agentic investigation pattern has not yet been scaled into continuous autonomous workflows.
Power Platform posture monitoring at early adoption. Wiz Integration for Power Platform is Forvis's first Cloud Security automation, running daily but with only 11 executions to date — early-stage compared to the mature DLP and identity pipelines.
Integration Ecosystem
Forvis's automation estate spans 16 distinct integrations:
| Integration | Use Cases |
|---|---|
| Microsoft Entra ID / Active Directory | Identity threat response, EDR enrichment, Password management, Stale device cleanup, Agentic SOC |
| CrowdStrike | EDR alert ingest (built, inactive), Device isolation, Alert enrichment, Agentic SOC |
| Microsoft Defender for Endpoints | EDR alert ingest (active), Alert enrichment, Agentic SOC |
| Microsoft Intune | Device enrichment in EDR pipeline |
| Splunk | Stale device validation, EDR enrichment, Agentic SOC |
| Delinea | DLP bypass removal, Onboarding password cleanup |
| SendGrid | Alert notifications, Analyst approvals, End-user notifications, Phishing notifications |
| Tenable | Server vulnerability scanning, Asset lifecycle management |
| EasyVista | Server onboarding/offboarding triggers, DLP exception requests |
| UserCube | Password provisioning trigger via IGA webhook |
| SSH / WinRM | AD computer object management, DLP group enforcement |
| Blink Web Forms | Alert approvals, Vulnerability submissions, Risky user approvals, Phishing response forms |
| Blink Tables | Case tracking, Exception expiry tracking, EDR record management, Phishing data tracking |
| Wiz | Power Platform security posture monitoring |
| Microsoft Power Platform | Power Platform security posture monitoring |
| Microsoft SQL Server | Offboarding compliance reconciliation (Missed Offboards) |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents 0 active | 0 tasks (12m)
AI Agents
| # | Agent | Workspace | Tasks (12m) | Tasks (30d) | Data (12m) |
|---|---|---|---|---|---|
| 1 | Security Alert Investigation & Enrichment Analyst | Agents POC | 0 | 0 | 0 |
| Workspace | Tasks (12m) |
|---|---|
| Agents POC | 0 |
C Self-Service & Webforms 0 app runs | 0 form submissions
Self-Service Applications
| # | App | Runs (12m) | Runs (30d) |
|---|---|---|---|
| 1 | Risky Users | 0 | 0 |
Webforms
| # | Form | Total | Completed |
|---|---|---|---|
| 1 | header | 0 | 0 |
| 2 | Testing Webform | 0 | 0 |
| 3 | Server Vulnerability Submission | 0 | 0 |
D Full Use Case Analysis 9 use cases | 47,077 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Expired DLP access exceptions automatically revoked | 35,072 | DLP Exclusion Remove Expired |
| Risky user monitoring scans completed | 11,521 | Parent - Find Risky Users |
| Phishing incident records created or updated in tracking tables | 423 | Subflow - Add or Update New Phishing Data to Tables |
| Phishing alerts processed by automated triage driver | 372 | Phishing Driver |
| DLP access exception requests processed end-to-end | 371 | DLP Exclusion Addition |
| User passwords provisioned or reset without manual intervention | 272 | Set User Password |
| Devices isolated in response to confirmed security threats | 219 | Isolate Device |
| Endpoint alerts ingested and triaged | 124 | Ingest - MD Alert |
| Phishing-related threat IDs linked to incident records | 85 | Subflow - Add or Update Phishing_related_threat_ids table |
| Security alert response workflows orchestrated with analyst gate | 80 | Parent - Alert Response Facilitation |
| Risky users investigated and remediated | 51 | Subflow - Risky User Approval and Remediation |
| Stale device cleanup cycles run against Active Directory | 28 | Parent - Disable_Delete Stale Devices |
| Server onboarding vulnerability scans triggered via ITSM ticket | 16 | Ingest EasyVista Ticket Data |
| Server offboardings processed with automated asset removal | 14 | Server Offboarding - Ingest EasyVista Ticket |
| Power Platform environments scanned for security posture issues | 11 | Wiz Integration for Power Platform |
Use Case Summary
| Use Case | Category | Subcategories | Playbooks | Total Executions (12 mo.) |
|---|---|---|---|---|
| EDR Alert Triage, Enrichment & Containment | SOC | EDR containment & response, Alert enrichment / IOC lookup, Case mgmt & SOAR | 11 | 716 |
| Identity Threat Monitoring & Response | SOC | Identity threat response | 2 | 11,572 |
| DLP Exception Lifecycle Management | GRC | DLP triage & exposure resp | 7 | 35,527 |
| Stale Device Lifecycle Automation | IAM | Access review & group mgmt, Identity sync & directory mgmt | 4 | 315 |
| Password & Credential Management | IAM | Password & credential lifecycle, Privileged account mgmt, Identity lifecycle automation | 7 | 315 |
| Server Vulnerability & Asset Lifecycle | Vulnerability Mgmt | Vuln scan lifecycle automation, Vuln scanning ingest & report | 5 | 30 |
| Agentic SOC Toolset | SOC | Agentic SOC, Alert enrichment / IOC lookup | 11 | 13 |
| Phishing Alert Triage & Response | SOC | Phishing detection & response | 4 | 1,252 |
| Power Platform Security Posture Monitoring | Cloud Security | CSPM ingest & triage | 1 | 11 |
Use Cases
1. EDR Alert Triage, Enrichment & Containment
Category: SOC — EDR containment & response, Alert enrichment / IOC lookup, Case mgmt & SOAR
Description: A full-stack EDR alert pipeline spanning CrowdStrike and Microsoft Defender for Endpoints. Each alert is ingested, enriched with device, user, and IOC context from Intune, Entra ID, CrowdStrike, and Splunk, then routed through an analyst-gated approval form before automated response actions (dismiss, isolate, AV scan, or auto-investigate) are executed. Device isolation requests from Azure runbooks flow through the same containment engine.
Business Problem: SOC analysts were manually triaging alerts across two EDR platforms, correlating device and user context without tooling, and executing response actions without a structured approval workflow — leading to inconsistent triage quality and undocumented response decisions.
Integrations: CrowdStrike, Microsoft Defender for Endpoints, Microsoft Intune, Microsoft Entra ID, Splunk, SendGrid, Blink Tables
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Ingest - Crowdstrike Alert | Event (webhook) | 0 | SOC | Alert enrichment / IOC lookup, Case mgmt & SOAR |
| Ingest - MD Alert | Event (polling) | 124 | SOC | Alert enrichment / IOC lookup, Case mgmt & SOAR |
| Parent - Alert Response Facilitation | On-demand | 80 | SOC | Case mgmt & SOAR, EDR containment & response |
| Subflow - IOC Extraction | On-demand | 134 | SOC | Alert enrichment / IOC lookup |
| Subflow - Enrich Device User and IOC | On-demand | 90 | SOC | Alert enrichment / IOC lookup |
| Subflow - Dismiss EDR Alert | On-demand | 13 | SOC | EDR containment & response |
| Subflow - AV Scan Host | On-demand | 0 | SOC | EDR containment & response |
| Subflow - Auto Investigate | On-demand | 0 | SOC | EDR containment & response |
| Isolate Device | Event (webhook) | 219 | SOC | EDR containment & response |
| Subflow - Isolate Host with Crowdstrike | On-demand | 0 | SOC | EDR containment & response |
| EDR Tracking Table Cleanup | Scheduled | 56 | SOC | Case mgmt & SOAR |
2. Identity Threat Monitoring & Response
Category: SOC — Identity threat response
Description: Entra ID is polled every 5 minutes for risky user detections. When a risky user is identified, an analyst approval workflow is triggered — delivering enriched sign-in context and IP geolocation data via a web form and email notification. Upon analyst confirmation, automated remediation actions are executed with a full audit record written back to the case table.
Business Problem: Risky user detections in Microsoft Entra ID required manual analyst review with no structured triage or remediation workflow, creating response delays and inconsistent handling across analysts.
Integrations: Microsoft Entra ID, SendGrid, Blink Web Forms, Blink Tables
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Parent - Find Risky Users | Scheduled | 11,521 | SOC | Identity threat response |
| Subflow - Risky User Approval and Remediation | On-demand | 51 | SOC | Identity threat response |
3. DLP Exception Lifecycle Management
Category: GRC — DLP triage & exposure resp
Description: The full lifecycle of DLP exclusions is automated — from ingesting exception requests via EasyVista webhooks, validating destination TLS certificates, provisioning users or hosts into exclusion groups, tracking expiry dates in a Blink table, to automatically revoking exceptions when they expire. A scheduled daily cleanup enforces timely removal of untracked and expired exclusions, and a USB exception workflow handles device-based bypass requests.
Business Problem: DLP exception management was manual and error-prone. There was no automated mechanism to track expiry, enforce timely revocation, or audit active exclusions — creating both compliance exposure and operational overhead for the security team.
Integrations: EasyVista (webhook), Delinea, Blink Tables, PowerShell, SendGrid
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| DLP Exclusion Addition | Event (webhook) | 371 | GRC | DLP triage & exposure resp |
| DLP Exclusion Remove Expired | On-demand | 35,072 | GRC | DLP triage & exposure resp |
| DLP Exclusion Removal Schedule | Scheduled | 40 | GRC | DLP triage & exposure resp |
| Subflow - DLP Bypass Host Removal | Scheduled | 40 | GRC | DLP triage & exposure resp |
| Adhoc - DLP Exclusion Addition | On-demand | 4 | GRC | DLP triage & exposure resp |
| DLP USB Exception Workflow | Event (webhook) | 0 | GRC | DLP triage & exposure resp |
| DLP Exclusion Remove Untracked | On-demand | 0 | GRC | DLP triage & exposure resp |
4. Stale Device Lifecycle Automation
Category: IAM — Access review & group mgmt, Identity sync & directory mgmt
Description: Active Directory is queried via SSH and WinRM to identify computer objects that have not authenticated within defined thresholds. Results are cross-referenced against Splunk authentication logs and a curated exclusion list to eliminate false positives. Devices inactive for 90+ days are automatically disabled; devices inactive for 120+ days are deleted. Each cycle generates an HTML summary report delivered via email.
Business Problem: Stale and unmanaged device objects in Active Directory expanded the attack surface and complicated compliance audits. Manual cleanup was infrequent and inconsistent, leaving disabled or forgotten endpoints active in the directory.
Integrations: SSH (Active Directory), WinRM, Splunk, SendGrid
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Parent - Disable_Delete Stale Devices | Scheduled | 28 | IAM | Access review & group mgmt |
| Subflow - Generate Stale Candidate List | On-demand | 28 | IAM | Identity sync & directory mgmt |
| Subflow - Disable Workstation in AD | On-demand | 143 | IAM | Identity sync & directory mgmt |
| Subflow - Delete Workstation in AD | On-demand | 116 | IAM | Identity sync & directory mgmt |
5. Password & Credential Management
Category: IAM — Password & credential lifecycle, Privileged account mgmt, Identity lifecycle automation
Description: User password lifecycle is managed across multiple pathways: automated provisioning triggered by the UserCube IGA platform via webhook, on-demand force-reset with end-user notification via Entra ID, and scheduled cleanup of temporary onboarding passwords in Delinea. A separate restoration workflow handles re-enabling terminated employees through a manager-approval email gate.
Business Problem: Password provisioning during onboarding, forced resets for compromised accounts, and cleanup of privileged temporary credentials all required manual IT intervention across Entra ID, Active Directory, and Delinea — creating delays and credential hygiene gaps.
Integrations: Microsoft Entra ID, Delinea, UserCube (webhook), SendGrid, SSH/WinRM, Blink Tables, Microsoft SQL Server, Splunk
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Set User Password | Event (webhook) | 272 | IAM | Password & credential lifecycle |
| Cleanup Delinea Onboarding Passwords | Scheduled | 40 | IAM | Privileged account mgmt |
| On-Demand Set User Password | On-demand | 1 | IAM | Password & credential lifecycle |
| Restore Termed User | On-demand | 1 | IAM | Identity lifecycle automation |
| Missed Offboards | Scheduled | 1 | IAM | Identity lifecycle automation |
| Subflow - Change PW | On-demand | 0 | IAM | Password & credential lifecycle |
| Set User Password (DEV) | Event (webhook) | 0 | IAM | Password & credential lifecycle |
6. Server Vulnerability & Asset Lifecycle
Category: Vulnerability Mgmt — Vuln scan lifecycle automation, Vuln scanning ingest & report
Description: Tenable vulnerability scanning is integrated with EasyVista IT service management. Server onboarding tickets automatically trigger a targeted Tenable scan; server offboarding tickets remove the asset from Tenable inventory. A web form portal enables system owners to submit targeted plugin-based vulnerability searches without requiring Tenable access.
Business Problem: New servers were not consistently scanned upon deployment, and decommissioned servers remained in Tenable scan targets, producing noisy and inaccurate reports. Asset lifecycle was managed manually across ITSM and vulnerability management platforms with no automation bridge.
Integrations: Tenable, EasyVista (webhook), Blink Web Forms, Blink Tables
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Ingest EasyVista Ticket Data | Event (webhook) | 16 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Server Offboarding - Ingest EasyVista Ticket | Event (webhook) | 14 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Server Vulnerability Submissions | Event (web form) | 0 | Vulnerability Mgmt | Vuln scanning ingest & report |
| Run Tenable Scan | On-demand | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
| Rescan | On-demand | 0 | Vulnerability Mgmt | Vuln scan lifecycle automation |
7. Agentic SOC Toolset
Category: SOC — Agentic SOC, Alert enrichment / IOC lookup
Description: A library of modular "Ability" workflows designed for use by AI-driven SOC agents. Each ability is a discrete, input-driven action — querying Entra ID user context, executing Defender KQL advanced hunting queries, retrieving CrowdStrike host and alert details, searching Splunk, resolving Power Platform environments, or listing recent device activity. These serve as callable tools for autonomous investigation pipelines.
Business Problem: AI-assisted SOC investigation requires standardized, reusable action interfaces across security tools. Without structured abilities, agents cannot reliably retrieve and act on data from disparate platforms, limiting the effectiveness of autonomous triage.
Integrations: Microsoft Entra ID, Microsoft Defender for Endpoints, CrowdStrike, Splunk, Microsoft Power Platform
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Ability - Get Entra User Context | On-demand | 2 | SOC | Agentic SOC |
| Ability - Run Defender Advanced Hunting | On-demand | 2 | SOC | Agentic SOC |
| Ability - Get Defender Alert by ID | On-demand | 2 | SOC | Agentic SOC |
| Ability - Defender KQL Query Guide | On-demand | 2 | SOC | Agentic SOC |
| Ability - Defender Recent Logons for User (preset) | On-demand | 1 | SOC | Agentic SOC |
| Ability - Get CrowdStrike Host Context | On-demand | 1 | SOC | Agentic SOC |
| Ability - Get CrowdStrike Alert Details | On-demand | 0 | SOC | Agentic SOC |
| Ability - Search Splunk | On-demand | 0 | SOC | Agentic SOC, SIEM & log pipeline monitoring |
| Ability - Resolve Power Platform Environment | On-demand | 0 | SOC | Agentic SOC |
| Ability - Get User License Entitlement | On-demand | 0 | SOC | Agentic SOC |
| Ability - Defender List Recent Devices (preset) | On-demand | 0 | SOC | Agentic SOC |
8. Phishing Alert Triage & Response
Category: SOC — Phishing detection & response
Description: A scheduled driver polls for new phishing submissions every 15 minutes and orchestrates the full triage lifecycle — logging incoming reports to tracking tables, extracting and linking related threat IDs for cross-case correlation, and dispatching analyst notifications or web forms for review and response.
Business Problem: Phishing reports were not centrally logged or correlated with related threat indicators, and there was no structured, low-latency mechanism to notify analysts or end users as new phishing submissions arrived.
Integrations: Blink Tables, Blink Web Forms, SendGrid
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Phishing Driver | Scheduled | 372 | SOC | Phishing detection & response |
| Subflow - Add or Update New Phishing Data to Tables | On-demand | 423 | SOC | Phishing detection & response |
| Subflow - Add or Update Phishing_related_threat_ids table | On-demand | 85 | SOC | Phishing detection & response |
| Subflow - Send Emails and Webforms | On-demand | 372 | SOC | Phishing detection & response |
9. Power Platform Security Posture Monitoring
Category: Cloud Security — CSPM ingest & triage
Description: A daily scheduled job integrates with Wiz to assess the security posture of Microsoft Power Platform environments, extending cloud security posture management coverage to low-code/no-code application infrastructure.
Business Problem: Power Platform environments (apps, flows, connectors) lacked visibility into security posture and misconfiguration risk — an increasingly common blind spot as low-code platforms proliferate outside traditional IT governance.
Integrations: Wiz, Microsoft Power Platform
| Playbook | Type | Executions (12 mo.) | Category | Subcategory |
|---|---|---|---|---|
| Wiz Integration for Power Platform | Scheduled | 11 | Cloud Security | CSPM ingest & triage |
Key Observations
Strengths
High-volume DLP enforcement at scale. The DLP exception lifecycle is the most operationally active use case, with 35,072 automated exception removals and 371 additions over 12 months. This represents a mature, production-grade compliance automation covering the full add-track-expire-revoke lifecycle with no manual queuing required.
Analyst-gated SOC workflow architecture. Alert response is structured around an explicit human approval gate (web form + email), meaning automation handles enrichment, context aggregation, and orchestration while analysts retain decision authority. This is a defensible, audit-friendly design appropriate for a regulated financial services environment.
Dual-EDR coverage with unified pipeline. Both CrowdStrike and Microsoft Defender for Endpoints are integrated into a single alert triage pipeline, with IOC extraction and enrichment abstracted as reusable subflows. Cross-platform alert correlation happens automatically before any analyst interaction.
IAM automation breadth. Password lifecycle, stale device cleanup, user restoration, and privileged credential management are all automated across Entra ID, Active Directory, Delinea, and UserCube — covering the most common IAM failure modes in an enterprise environment.
Agentic SOC foundation in place. A structured Ability library covering CrowdStrike, Defender, Entra ID, Splunk, and Power Platform is deployed in a dedicated workspace. Initial execution counts (13 executions across 6 abilities) indicate early-stage adoption with a platform ready to scale into autonomous investigation workflows.
New phishing triage pipeline established. A 15-minute scheduled driver now logs phishing submissions to tracking tables, links related threat IDs for cross-case correlation, and dispatches analyst notifications — 1,252 combined executions across the driver and its subflows indicate immediate high-volume adoption.
Gaps
CrowdStrike alert pipeline inactive. Ingest - Crowdstrike Alert has 0 executions despite the full workflow being built with webhook trigger and alert enrichment steps. CrowdStrike-originated alerts are not flowing through Blink, leaving Microsoft Defender as the sole active EDR ingest source. This is a coverage gap given CrowdStrike is also deployed for containment.
Vulnerability management pipeline not operationalized. The Tenable integration handles server onboarding and offboarding (30 executions combined) but Server Vulnerability Submissions, Run Tenable Scan, and Rescan all have 0 executions. Vulnerability scanning, prioritization, and remediation tracking are not yet automated beyond asset registration.
Containment response actions unused. Subflow - AV Scan Host, Subflow - Auto Investigate, and Subflow - Isolate Host with Crowdstrike all have 0 executions. These response capabilities are built and integrated with CrowdStrike and Defender but are not being triggered through the alert response facilitation workflow.
DLP USB exception flow not activated. DLP USB Exception Workflow exists with a webhook trigger but has 0 executions. USB-based DLP exception requests are likely still being handled through a manual process outside of Blink.
Agentic SOC at early adoption. The Ability library has 11 workflows built but only 5 have been invoked (13 total executions). The agentic investigation pattern has not yet been scaled into continuous autonomous workflows.
Power Platform posture monitoring at early adoption. Wiz Integration for Power Platform is Forvis's first Cloud Security automation, running daily but with only 11 executions to date — early-stage compared to the mature DLP and identity pipelines.
Integration Ecosystem
Forvis's automation estate spans 16 distinct integrations:
| Integration | Use Cases |
|---|---|
| Microsoft Entra ID / Active Directory | Identity threat response, EDR enrichment, Password management, Stale device cleanup, Agentic SOC |
| CrowdStrike | EDR alert ingest (built, inactive), Device isolation, Alert enrichment, Agentic SOC |
| Microsoft Defender for Endpoints | EDR alert ingest (active), Alert enrichment, Agentic SOC |
| Microsoft Intune | Device enrichment in EDR pipeline |
| Splunk | Stale device validation, EDR enrichment, Agentic SOC |
| Delinea | DLP bypass removal, Onboarding password cleanup |
| SendGrid | Alert notifications, Analyst approvals, End-user notifications, Phishing notifications |
| Tenable | Server vulnerability scanning, Asset lifecycle management |
| EasyVista | Server onboarding/offboarding triggers, DLP exception requests |
| UserCube | Password provisioning trigger via IGA webhook |
| SSH / WinRM | AD computer object management, DLP group enforcement |
| Blink Web Forms | Alert approvals, Vulnerability submissions, Risky user approvals, Phishing response forms |
| Blink Tables | Case tracking, Exception expiry tracking, EDR record management, Phishing data tracking |
| Wiz | Power Platform security posture monitoring |
| Microsoft Power Platform | Power Platform security posture monitoring |
| Microsoft SQL Server | Offboarding compliance reconciliation (Missed Offboards) |
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Forvis | mssql | my_microsoft_sql_server_connection | 2026-08-31 |