Overview
This playbook covers the implementation of four automation workflows that together reduce IT helpdesk ticket volume by 50–65% in most organisations. Each workflow is described with implementation steps, configuration details, and success metrics.
Workflow 1: Self-Service Password Reset (SSPR)
Problem
Password resets and account lockouts typically account for 20–30% of IT tickets. Each takes 5–10 minutes of IT staff time. SSPR eliminates 80–90% of these tickets.
Implementation Steps
Step 1: Choose your SSPR solution
| Solution | Best For | Cost |
|---|---|---|
| Azure AD SSPR | Microsoft 365 environments | Included in Azure AD P1 |
| Okta SSPR | Multi-IdP environments | Included in Okta Workforce |
| ManageEngine ADSelfService Plus | On-premise AD | ₹800–1,200/user/year |
| JumpCloud | SMBs without existing IdP | $9/user/month |
Step 2: Configure authentication methods
Require users to register at least 2 of:
- •Mobile phone (SMS OTP)
- •Authenticator app (Microsoft/Google Authenticator)
- •Alternate email address
- •Security questions (least secure - use only as fallback)
Step 3: Force registration
Option A (recommended): Enable "Registration required on next sign-in" for all users. Users are prompted to register when they next log in.
Option B: Send a company-wide communication with a registration link and a deadline. Follow up with non-registrants.
Step 4: Configure the self-service portal
- •Set the portal URL to something memorable:
password.yourcompany.com - •Add the URL to the company intranet homepage
- •Add a "Forgot Password?" link on the login page of all internal applications
- •Include the URL in the IT helpdesk auto-reply email
Step 5: Update password policy
Per NIST SP 800-63B and Microsoft's current guidance:
- •Remove mandatory password expiration (unless there's evidence of compromise)
- •Minimum length: 12 characters
- •No complexity requirements (length is more important than complexity)
- •Block known compromised passwords (use HaveIBeenPwned API)
Removing mandatory expiration alone reduces password reset tickets by 30–40%.
Step 6: Monitor and measure
Track weekly:
- •SSPR usage (successful self-service resets)
- •IT-assisted resets (tickets)
- •SSPR failure rate (users who start but don't complete self-service)
Target: 85%+ of password resets via self-service within 60 days.
Workflow 2: Automated Access Provisioning
Problem
New user setup and access changes account for 15–20% of IT tickets. Manual provisioning takes 30–60 minutes per user and is error-prone.
Implementation: HR-IT Integration
Architecture:
HR System (new employee record created)
↓ webhook / API call
Identity Provider (Azure AD / Okta / JumpCloud)
↓ automated provisioning
Email + License + Groups + Applications
↓ notification
Manager + New EmployeeStep 1: Define role-based access profiles
Create an access profile for each role in the organisation:
Role: Sales Executive
- Microsoft 365 E3 license
- Distribution groups: sales-team@, all-staff@
- Applications: CRM (Salesforce/Zoho), Slack, Expense tool
- Shared drives: Sales folder (read/write), Company folder (read)
- Restrictions: No access to Finance folder, HR folder
Role: Accounts Manager
- Microsoft 365 E3 license
- Distribution groups: finance-team@, all-staff@
- Applications: Accounting software, Banking portal, Slack
- Shared drives: Finance folder (read/write), Company folder (read)Step 2: Configure HR-IdP integration
For BambooHR + Azure AD:
- 1Install the BambooHR Azure AD provisioning connector
- 2Map HR fields to Azure AD attributes (department → department, job title → jobTitle, manager → manager)
- 3Configure provisioning scope (which employees to sync)
- 4Map roles to Azure AD groups (which trigger license and application assignment)
- 5Enable automatic provisioning
For other HR systems, use a middleware like Workato, Zapier, or a custom webhook.
Step 3: Configure automated offboarding
When HR marks an employee as terminated:
- 1Disable Azure AD account immediately (within 15 minutes)
- 2Revoke all application access
- 3Convert mailbox to shared mailbox, assign to manager
- 4Remove from all distribution groups
- 5Schedule account deletion after 30 days (for data retention)
- 6Generate offboarding checklist for manager (return equipment, etc.)
Step 4: Handle exceptions
Not all access requests fit the role profile. Create a self-service access request portal:
- •Employee requests additional access
- •Request goes to their manager for approval
- •If approved, IT provisions the access (or it's auto-provisioned if the access type is pre-approved)
- •All requests are logged for audit
Workflow 3: Knowledge Base Deflection
Problem
20–30% of tickets are for issues that have documented solutions. Users don't find the solutions because the knowledge base is poorly organised, poorly written, or not integrated with the ticket portal.
Implementation
Step 1: Audit existing knowledge base
For each article:
- •When was it last updated?
- •How many views in the last 90 days?
- •How many tickets were submitted for the same issue despite the article existing?
- •Is the article written for users or for IT staff?
Delete or archive articles that are outdated. Rewrite articles that are written for IT staff.
Step 2: Identify the top 20 ticket types
Pull the last 3 months of tickets. Identify the 20 most common ticket types. For each:
- •Does a knowledge base article exist?
- •If yes, is it findable and usable?
- •If no, create one.
Step 3: Write user-facing articles
Article structure:
Title: [Symptom the user experiences, not the technical cause]
✓ "My screen is frozen and won't respond"
✗ "Application deadlock resolution procedure"
Section 1: Quick fix (for the most common cause)
- Step 1: [Screenshot]
- Step 2: [Screenshot]
- Step 3: [Screenshot]
- Expected result: [What the user should see]
Section 2: If the quick fix didn't work
- Alternative steps
Section 3: When to contact IT
- Specific conditions that require IT involvement
- What information to include in the ticketStep 4: Integrate with ticket portal
Configure your ticketing system (Freshdesk, Zendesk, Jira Service Management) to:
- 1Suggest articles as the user types the ticket subject
- 2Show the top 3 relevant articles before the user submits the ticket
- 3Ask "Did this article solve your problem?" after showing articles
- 4If yes, close the ticket automatically (deflection)
- 5If no, allow the user to submit the ticket with the article attached
Step 5: Track deflection rate
Deflection rate = Articles that resolved the issue / Total article views × 100Target: 25–35% deflection rate within 90 days.
Workflow 4: Intelligent Ticket Routing
Problem
Manual ticket triage takes 5–10 minutes per ticket and is inconsistent. Tickets are often routed to the wrong team, causing delays.
Implementation
Step 1: Define routing rules
IF subject contains ["password", "locked out", "can't log in", "forgot password"]
→ Route to: Password Reset Queue
→ Priority: P3
→ SLA: 4-hour response
IF subject contains ["laptop", "computer", "screen", "keyboard", "mouse", "hardware"]
→ Route to: Hardware Queue
→ Priority: P3
→ SLA: 4-hour response
IF subject contains ["VPN", "network", "internet", "wifi", "can't connect"]
→ Route to: Network Queue
→ Priority: P2
→ SLA: 2-hour response
IF subject contains ["down", "outage", "not working for everyone", "multiple users"]
→ Route to: Critical Incidents Queue
→ Priority: P1
→ SLA: 15-minute response
→ Notify: IT Manager immediatelyStep 2: Configure in your ticketing system
Most ticketing systems (Freshdesk, Zendesk, Jira SM) support keyword-based routing rules natively. Configure the rules above as automation rules.
Step 3: Add ML-based routing (optional, for 500+ tickets/month)
For higher-volume helpdesks, train a simple text classifier on historical tickets:
- •Input: ticket subject + description
- •Output: category + priority
- •Training data: last 12 months of tickets with correct categories
Libraries: scikit-learn (Python), fastText. Accuracy typically reaches 85–90% after training on 1,000+ labelled tickets.
Step 4: Auto-close resolved tickets
Configure auto-close rules:
- •If ticket status is "Resolved" and no response from user in 48 hours → Close automatically
- •If ticket status is "Waiting for User" and no response in 72 hours → Close with note
This prevents the queue from filling with stale tickets.
Implementation Timeline
| Week | Activity |
|---|---|
| 1–2 | SSPR setup and user registration |
| 3–4 | Access provisioning role profiles and HR integration |
| 5–6 | Knowledge base audit and top-20 article creation |
| 7–8 | Ticket portal integration for knowledge base deflection |
| 9–10 | Ticket routing rules configuration |
| 11–12 | Measurement, tuning, and documentation |
Success Metrics
| Metric | Baseline | 90-Day Target |
|---|---|---|
| Weekly ticket volume | 80 | 35 |
| Password reset tickets | 20/week | 2/week |
| Access provisioning tickets | 15/week | 1/week |
| Knowledge base deflection rate | 0% | 25% |
| Ticket routing accuracy | 60% | 90% |
| First contact resolution rate | 55% | 75% |
*See how IdeaSprout IT Support implements these automations →*