March 19, 2026

    Customer Story: TR Computer Sales Cuts Finding Resolution from Minutes to Seconds Using Blumira EDR and ITDR

    Industry Driver Company Size
    Managed Service Provider Faster Time to Resolution 21

    The Challenge

    TR Computer Sales needed a faster way to contain security threats. While Blumira’s Microsoft 365 Threat Response helped address identity-based incidents, isolating compromised devices or disabling users still required navigating multiple dashboards and manual steps, slowing response times.

    The Solution

    With Blumira’s new ITDR and EDR response capabilities, TR Computer Sales can now contain threats by isolating endpoints, killing malicious processes, and disabling compromised users without leaving the Blumira dashboard.

    “We’re stopping breaches in seconds instead of minutes or hours. I don’t have to find a password, log in, get to the user, revoke MFA, and change their password. I can do all of that in one click.”

    Matt Timm
    Network Operations Center Team Lead

    socialmedia

    TR Computer Sales

    TR Computer Sales (TR) is a managed service provider based in White Bear Lake, Minnesota, delivering IT infrastructure, cybersecurity, and technology services to businesses. Over the past three years, the team has used Blumira to monitor security activity across client environments and respond quickly to threats while keeping security operations efficient.

    The Challenge: Responding to Threats Required Switching Between Tools

    Matt Timm, Network Operations Center Team Lead at TR, leads monitoring, security operations, and SIEM management. He also regularly works with Blumira as an early tester, providing feedback on new features and workflows.

    Before Blumira introduced its new ITDR and EDR capabilities, Matt and his team relied on existing Microsoft 365 Threat Response within Blumira to disable compromised users and revoke sessions. 

    “We’ve noticed an increase and are responding to more and more Microsoft 365 phishing compromises, cookie stealing, and man-in-the-middle attacks. Being able to respond as quickly as we can to those attacks is crucial,” Timm said.

    While that worked well for identity-based incidents, endpoint response actions still required additional steps outside the platform, which can slow down response during security events.

    “We didn't have any response actions for the endpoint, so in a security situation, it was a little clunky to go from the finding, into the device, into the device settings, and then back to the portal to isolate it,” Timm said.

    During security incidents, the biggest challenge was time. Isolating a device required navigating multiple menus and switching between dashboards, slowing the team’s ability to contain threats quickly.

    “Efficiency is key, especially in a security monitoring department,” Timm said. “For us to have everything in one central location, the information, what's happening, the ways that we can fix it, and then the feedback of how it was fixed is huge.”

    The Solution: One-Click Response Actions Directly from Blumira Findings

    With Blumira’s new ITDR and EDR response capabilities, TR can now take immediate action directly from the security finding itself.

    “We're really excited for this new feature because that one-click availability makes responding so much easier for us,” Timm said. “The ease of having it all in a central location, with the finding so you can make an informed decision right there and not having to toggle between screens is really nice. Now it’s one click, and it's isolated.”

    The new workflow allows the team to isolate compromised endpoints and trigger response actions without leaving the Blumira platform.

    “We’re stopping breaches in seconds instead of minutes or hours. I don’t have to find a password, log in, get to the user, revoke MFA, and change their password. I can do all of that in one click,” Timm said.

    For the TR team, the biggest benefit is the ability to move from alert to action immediately.

    “This allows us to quickly respond to threats, not just read about them, but to be able to take action within seconds,” Timm said.

    Another benefit for TR is that the new capabilities feel purposeful rather than overly complex.

    “[Blumira] has done a great job of giving us features that are helpful and not extra stuff we don't need. I think a lot of companies just feature spray and throw everything at you. [Blumira] continues to deliver features that are useful that we are going to be using on a daily basis,” Timm said.

    Eric Pitt

    Eric is a Product Marketing Manager at Blumira focusing on customer research and positioning to continuously improve the Blumira platform.

    More from the blog

    View All Posts