Blink Security Automation — Confidential

NexCyber — Customer Success Report

Generated 2026-08-30 | nexcyber-value-report.md
2026-08-30Report Date
20Total Playbooks
3Unique Workflows (12m)
21Actions Automated (12m)
$5Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

20
Total playbooks built
all non-deleted workflows
3
Active playbooks
currently enabled
3
Unique workflows executed (12m)
distinct workflows that ran
21
Actions automated (12m)
completed action steps
0.1h
Hours saved (12m)
@ 20s per action
$5
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 1 Entra ID MFA compliance scan — identifying users without MFA registration across the directory

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
Entra ID Identity Hygiene & Access Governance0 executions
0.0%
3
3 active
Total0 executions100%
3
3 active

Use Case Growth Over Time

4 unique playbooks  |  1 operational use cases  |  0 total executions (12m)  |  2025-09 to 2025-10
Toggle:
Toggle:

03Integration Ecosystem

Entra ID Identity Hygiene & Access Governance
Microsoft Entra ID Email

04Key Observations

✓  Strengths

Strengths

  • IAM hygiene coverage is coherent. NexCyber has built a logical three-stage identity governance loop: detect stale accounts → confirm MFA compliance → disable non-compliant users. The playbooks form a natural workflow chain even if not explicitly linked.
  • Scheduled MFA compliance monitoring is operational. The quarterly MFA check is the one active automation, providing a repeatable audit cadence without manual effort.
  • Parameterized design. The stale accounts playbook accepts an inactivity_threshold input, making it reusable across different review policies without code changes.

###

△  Gaps & Growth Opportunities

Gaps

  • Low execution volume. Two of three playbooks show zero executions over 12 months. The stale account identifier and user disablement tool are deployed but idle — likely staged for use rather than integrated into a recurring process.
  • No automated remediation loop. Detection (stale accounts, missing MFA) and remediation (disable user) are separate on-demand playbooks with no automated handoff. Connecting them would reduce response latency and analyst burden.
  • Narrow automation footprint. All three automations address a single domain (Entra ID identity hygiene). There is no coverage across other security functions — no SOC, vulnerability management, cloud security, or GRC automation visible in the dataset.
  • Quarterly MFA cadence may be insufficient. A cron of 0 7 1 */3 * (quarterly) means newly onboarded users without MFA could go undetected for up to three months. A monthly or weekly schedule would close this gap.

Integration Ecosystem

Integration Usage
Microsoft Entra ID User queries, account disablement
Email (Blink core) Report delivery
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 1 use cases | 0 executions (12m)

Business KPIs

Metric Count Playbook
Entra ID MFA compliance scans executed 1 Check for NOT MFA Registered Entra ID Users
In the last 12 months, Blink automated: - 1 Entra ID MFA compliance scan — identifying users without MFA registration across the directory

_Note: Two additional playbooks (stale account identification and user disablement) are deployed but have not yet recorded executions in the last 12 months, indicating they are staged for on-demand use or pending broader rollout._

Use Case Summary

Use Case Category Playbooks Executions (12 mo)
Entra ID Identity Hygiene & Access Governance IAM 3 1

Use Cases

Entra ID Identity Hygiene & Access Governance

Description: Automated monitoring and remediation of identity hygiene issues within Microsoft Entra ID. Covers detection of stale/inactive accounts, enforcement of MFA registration policy, and on-demand user disablement.

Business problem solved: Manual identity reviews are time-consuming and prone to gaps. These playbooks automate the detection of accounts that violate hygiene policies (inactivity, missing MFA) and provide a direct remediation action (disable user), reducing the window of exposure from stale or non-compliant identities.

Integrations: Microsoft Entra ID, Email (Blink core)

Taxonomy: IAM — Access review & group mgmt, Employee offboarding, Identity lifecycle automation

Playbook Executions (12 mo) Trigger Subcategory
Identify Stale Accounts in EntraID 0 On-demand Access review & group mgmt
Disable user in EntraID 0 On-demand Employee offboarding, Identity lifecycle automation
Check for NOT MFA Registered Entra ID Users 1 Scheduled (quarterly) Access review & group mgmt

Playbook details:

  • Identify Stale Accounts in EntraID — On-demand workflow parameterized by inactivity threshold. Queries Entra ID for inactive users, formats results, converts to CSV, and emails a report. Designed for periodic access review cycles.
  • Disable user in EntraID — On-demand remediation playbook. Takes a UPN as input, retrieves the current date, and executes a custom Entra ID action to disable the account, with conditional logic to handle edge cases.
  • Check for NOT MFA Registered Entra ID Users — Scheduled quarterly (1st of every 3rd month at 07:00). Queries Entra ID for all users lacking MFA registration, formats the list, and triggers conditional downstream alerting.

Key Observations

Strengths

  • IAM hygiene coverage is coherent. NexCyber has built a logical three-stage identity governance loop: detect stale accounts → confirm MFA compliance → disable non-compliant users. The playbooks form a natural workflow chain even if not explicitly linked.
  • Scheduled MFA compliance monitoring is operational. The quarterly MFA check is the one active automation, providing a repeatable audit cadence without manual effort.
  • Parameterized design. The stale accounts playbook accepts an inactivity_threshold input, making it reusable across different review policies without code changes.

Gaps

  • Low execution volume. Two of three playbooks show zero executions over 12 months. The stale account identifier and user disablement tool are deployed but idle — likely staged for use rather than integrated into a recurring process.
  • No automated remediation loop. Detection (stale accounts, missing MFA) and remediation (disable user) are separate on-demand playbooks with no automated handoff. Connecting them would reduce response latency and analyst burden.
  • Narrow automation footprint. All three automations address a single domain (Entra ID identity hygiene). There is no coverage across other security functions — no SOC, vulnerability management, cloud security, or GRC automation visible in the dataset.
  • Quarterly MFA cadence may be insufficient. A cron of 0 7 1 */3 * (quarterly) means newly onboarded users without MFA could go undetected for up to three months. A monthly or weekly schedule would close this gap.

Integration Ecosystem

Integration Usage
Microsoft Entra ID User queries, account disablement
Email (Blink core) Report delivery

1. Business KPIs — Last 12 Months

Metric Count Playbook
Entra ID MFA compliance scans executed 1 Check for NOT MFA Registered Entra ID Users
In the last 12 months, Blink automated: - 1 Entra ID MFA compliance scan — identifying users without MFA registration across the directory

_Note: Two additional playbooks (stale account identification and user disablement) are deployed but have not yet recorded executions in the last 12 months, indicating they are staged for on-demand use or pending broader rollout._

2. Use Case Summary

Use Case Category Playbooks Executions (12 mo)
Entra ID Identity Hygiene & Access Governance IAM 3 1

3. Use Cases

Entra ID Identity Hygiene & Access Governance

Description: Automated monitoring and remediation of identity hygiene issues within Microsoft Entra ID. Covers detection of stale/inactive accounts, enforcement of MFA registration policy, and on-demand user disablement.

Business problem solved: Manual identity reviews are time-consuming and prone to gaps. These playbooks automate the detection of accounts that violate hygiene policies (inactivity, missing MFA) and provide a direct remediation action (disable user), reducing the window of exposure from stale or non-compliant identities.

Integrations: Microsoft Entra ID, Email (Blink core)

Taxonomy: IAM — Access review & group mgmt, Employee offboarding, Identity lifecycle automation

Playbook Executions (12 mo) Trigger Subcategory
Identify Stale Accounts in EntraID 0 On-demand Access review & group mgmt
Disable user in EntraID 0 On-demand Employee offboarding, Identity lifecycle automation
Check for NOT MFA Registered Entra ID Users 1 Scheduled (quarterly) Access review & group mgmt

Playbook details:

  • Identify Stale Accounts in EntraID — On-demand workflow parameterized by inactivity threshold. Queries Entra ID for inactive users, formats results, converts to CSV, and emails a report. Designed for periodic access review cycles.
  • Disable user in EntraID — On-demand remediation playbook. Takes a UPN as input, retrieves the current date, and executes a custom Entra ID action to disable the account, with conditional logic to handle edge cases.
  • Check for NOT MFA Registered Entra ID Users — Scheduled quarterly (1st of every 3rd month at 07:00). Queries Entra ID for all users lacking MFA registration, formats the list, and triggers conditional downstream alerting.

4. Key Observations

Strengths

  • IAM hygiene coverage is coherent. NexCyber has built a logical three-stage identity governance loop: detect stale accounts → confirm MFA compliance → disable non-compliant users. The playbooks form a natural workflow chain even if not explicitly linked.
  • Scheduled MFA compliance monitoring is operational. The quarterly MFA check is the one active automation, providing a repeatable audit cadence without manual effort.
  • Parameterized design. The stale accounts playbook accepts an inactivity_threshold input, making it reusable across different review policies without code changes.

Gaps

  • Low execution volume. Two of three playbooks show zero executions over 12 months. The stale account identifier and user disablement tool are deployed but idle — likely staged for use rather than integrated into a recurring process.
  • No automated remediation loop. Detection (stale accounts, missing MFA) and remediation (disable user) are separate on-demand playbooks with no automated handoff. Connecting them would reduce response latency and analyst burden.
  • Narrow automation footprint. All three automations address a single domain (Entra ID identity hygiene). There is no coverage across other security functions — no SOC, vulnerability management, cloud security, or GRC automation visible in the dataset.
  • Quarterly MFA cadence may be insufficient. A cron of 0 7 1 */3 * (quarterly) means newly onboarded users without MFA could go undetected for up to three months. A monthly or weekly schedule would close this gap.

Integration Ecosystem

Integration Usage
Microsoft Entra ID User queries, account disablement
Email (Blink core) Report delivery
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.