01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Entra ID Identity Hygiene & Access Governance | 0 executions | 0.0% | 3 3 active |
| Total | 0 executions | 100% | 3 3 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
- IAM hygiene coverage is coherent. NexCyber has built a logical three-stage identity governance loop: detect stale accounts → confirm MFA compliance → disable non-compliant users. The playbooks form a natural workflow chain even if not explicitly linked.
- Scheduled MFA compliance monitoring is operational. The quarterly MFA check is the one active automation, providing a repeatable audit cadence without manual effort.
- Parameterized design. The stale accounts playbook accepts an
inactivity_thresholdinput, making it reusable across different review policies without code changes.
###
Gaps
- Low execution volume. Two of three playbooks show zero executions over 12 months. The stale account identifier and user disablement tool are deployed but idle — likely staged for use rather than integrated into a recurring process.
- No automated remediation loop. Detection (stale accounts, missing MFA) and remediation (disable user) are separate on-demand playbooks with no automated handoff. Connecting them would reduce response latency and analyst burden.
- Narrow automation footprint. All three automations address a single domain (Entra ID identity hygiene). There is no coverage across other security functions — no SOC, vulnerability management, cloud security, or GRC automation visible in the dataset.
- Quarterly MFA cadence may be insufficient. A cron of
0 7 1 */3 *(quarterly) means newly onboarded users without MFA could go undetected for up to three months. A monthly or weekly schedule would close this gap.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID | User queries, account disablement |
| Email (Blink core) | Report delivery |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 1 use cases | 0 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Entra ID MFA compliance scans executed | 1 | Check for NOT MFA Registered Entra ID Users |
_Note: Two additional playbooks (stale account identification and user disablement) are deployed but have not yet recorded executions in the last 12 months, indicating they are staged for on-demand use or pending broader rollout._
Use Case Summary
| Use Case | Category | Playbooks | Executions (12 mo) |
|---|---|---|---|
| Entra ID Identity Hygiene & Access Governance | IAM | 3 | 1 |
Use Cases
Entra ID Identity Hygiene & Access Governance
Description: Automated monitoring and remediation of identity hygiene issues within Microsoft Entra ID. Covers detection of stale/inactive accounts, enforcement of MFA registration policy, and on-demand user disablement.
Business problem solved: Manual identity reviews are time-consuming and prone to gaps. These playbooks automate the detection of accounts that violate hygiene policies (inactivity, missing MFA) and provide a direct remediation action (disable user), reducing the window of exposure from stale or non-compliant identities.
Integrations: Microsoft Entra ID, Email (Blink core)
Taxonomy: IAM — Access review & group mgmt, Employee offboarding, Identity lifecycle automation
| Playbook | Executions (12 mo) | Trigger | Subcategory |
|---|---|---|---|
| Identify Stale Accounts in EntraID | 0 | On-demand | Access review & group mgmt |
| Disable user in EntraID | 0 | On-demand | Employee offboarding, Identity lifecycle automation |
| Check for NOT MFA Registered Entra ID Users | 1 | Scheduled (quarterly) | Access review & group mgmt |
Playbook details:
- Identify Stale Accounts in EntraID — On-demand workflow parameterized by inactivity threshold. Queries Entra ID for inactive users, formats results, converts to CSV, and emails a report. Designed for periodic access review cycles.
- Disable user in EntraID — On-demand remediation playbook. Takes a UPN as input, retrieves the current date, and executes a custom Entra ID action to disable the account, with conditional logic to handle edge cases.
- Check for NOT MFA Registered Entra ID Users — Scheduled quarterly (1st of every 3rd month at 07:00). Queries Entra ID for all users lacking MFA registration, formats the list, and triggers conditional downstream alerting.
Key Observations
Strengths
- IAM hygiene coverage is coherent. NexCyber has built a logical three-stage identity governance loop: detect stale accounts → confirm MFA compliance → disable non-compliant users. The playbooks form a natural workflow chain even if not explicitly linked.
- Scheduled MFA compliance monitoring is operational. The quarterly MFA check is the one active automation, providing a repeatable audit cadence without manual effort.
- Parameterized design. The stale accounts playbook accepts an
inactivity_thresholdinput, making it reusable across different review policies without code changes.
Gaps
- Low execution volume. Two of three playbooks show zero executions over 12 months. The stale account identifier and user disablement tool are deployed but idle — likely staged for use rather than integrated into a recurring process.
- No automated remediation loop. Detection (stale accounts, missing MFA) and remediation (disable user) are separate on-demand playbooks with no automated handoff. Connecting them would reduce response latency and analyst burden.
- Narrow automation footprint. All three automations address a single domain (Entra ID identity hygiene). There is no coverage across other security functions — no SOC, vulnerability management, cloud security, or GRC automation visible in the dataset.
- Quarterly MFA cadence may be insufficient. A cron of
0 7 1 */3 *(quarterly) means newly onboarded users without MFA could go undetected for up to three months. A monthly or weekly schedule would close this gap.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID | User queries, account disablement |
| Email (Blink core) | Report delivery |
1. Business KPIs — Last 12 Months
| Metric | Count | Playbook |
|---|---|---|
| Entra ID MFA compliance scans executed | 1 | Check for NOT MFA Registered Entra ID Users |
_Note: Two additional playbooks (stale account identification and user disablement) are deployed but have not yet recorded executions in the last 12 months, indicating they are staged for on-demand use or pending broader rollout._
2. Use Case Summary
| Use Case | Category | Playbooks | Executions (12 mo) |
|---|---|---|---|
| Entra ID Identity Hygiene & Access Governance | IAM | 3 | 1 |
3. Use Cases
Entra ID Identity Hygiene & Access Governance
Description: Automated monitoring and remediation of identity hygiene issues within Microsoft Entra ID. Covers detection of stale/inactive accounts, enforcement of MFA registration policy, and on-demand user disablement.
Business problem solved: Manual identity reviews are time-consuming and prone to gaps. These playbooks automate the detection of accounts that violate hygiene policies (inactivity, missing MFA) and provide a direct remediation action (disable user), reducing the window of exposure from stale or non-compliant identities.
Integrations: Microsoft Entra ID, Email (Blink core)
Taxonomy: IAM — Access review & group mgmt, Employee offboarding, Identity lifecycle automation
| Playbook | Executions (12 mo) | Trigger | Subcategory |
|---|---|---|---|
| Identify Stale Accounts in EntraID | 0 | On-demand | Access review & group mgmt |
| Disable user in EntraID | 0 | On-demand | Employee offboarding, Identity lifecycle automation |
| Check for NOT MFA Registered Entra ID Users | 1 | Scheduled (quarterly) | Access review & group mgmt |
Playbook details:
- Identify Stale Accounts in EntraID — On-demand workflow parameterized by inactivity threshold. Queries Entra ID for inactive users, formats results, converts to CSV, and emails a report. Designed for periodic access review cycles.
- Disable user in EntraID — On-demand remediation playbook. Takes a UPN as input, retrieves the current date, and executes a custom Entra ID action to disable the account, with conditional logic to handle edge cases.
- Check for NOT MFA Registered Entra ID Users — Scheduled quarterly (1st of every 3rd month at 07:00). Queries Entra ID for all users lacking MFA registration, formats the list, and triggers conditional downstream alerting.
4. Key Observations
Strengths
- IAM hygiene coverage is coherent. NexCyber has built a logical three-stage identity governance loop: detect stale accounts → confirm MFA compliance → disable non-compliant users. The playbooks form a natural workflow chain even if not explicitly linked.
- Scheduled MFA compliance monitoring is operational. The quarterly MFA check is the one active automation, providing a repeatable audit cadence without manual effort.
- Parameterized design. The stale accounts playbook accepts an
inactivity_thresholdinput, making it reusable across different review policies without code changes.
Gaps
- Low execution volume. Two of three playbooks show zero executions over 12 months. The stale account identifier and user disablement tool are deployed but idle — likely staged for use rather than integrated into a recurring process.
- No automated remediation loop. Detection (stale accounts, missing MFA) and remediation (disable user) are separate on-demand playbooks with no automated handoff. Connecting them would reduce response latency and analyst burden.
- Narrow automation footprint. All three automations address a single domain (Entra ID identity hygiene). There is no coverage across other security functions — no SOC, vulnerability management, cloud security, or GRC automation visible in the dataset.
- Quarterly MFA cadence may be insufficient. A cron of
0 7 1 */3 *(quarterly) means newly onboarded users without MFA could go undetected for up to three months. A monthly or weekly schedule would close this gap.
Integration Ecosystem
| Integration | Usage |
|---|---|
| Microsoft Entra ID | User queries, account disablement |
| Email (Blink core) | Report delivery |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.