New historical scan, nine new detections, automated response controls, and incident-reporting tools improve early detection, containment and remediation with robust documentation
Blackpoint Cyber, a leading cybersecurity company protecting small to mid-sized companies and their MSP allies worldwide, announced a broad set of new Identity Threat Detection and Response (ITDR) capabilities in CompassOne, its unified security platform.
The new capabilities include additional threat detections, automated containment controls, and incident-reporting tools designed to help businesses detect identity-based attacks earlier, respond without disrupting the business, and prove exactly what happened after an incident.
In addition, Blackpoint ITDR now has a historical scan that delivers a retrospective analysis of Microsoft 365 environments to understand if attackers already have a foothold and can compromise systems.
โA compromised mailbox is not an inconvenience; itโs a confidentiality problem with our clientsโ own clients attached to it. Much of what we saw when evaluating the competition, was alerts dressed up as detection, which just moves the work back to us. Blackpointโs SOC investigates and acts and every addition has been aimed at taking work off my team rather than handing them another dashboard to check,โ said William Kapes, Director of Technical Operations at Integritek.
As attackers move from breaking in through doors and windows and into simply logging in via stolen credentials and email compromise, identities have become the new endpoint. Leveraging AI, attackers have evolved their tactics to include identity, vulnerability and social engineering to log their way into business systems.
โThreats are becoming agentic, and identities are the new threat vector where attackers are entering the business,โ said Sasmita Panda, VP of Engineering at Blackpoint Cyber. โWe arenโt here to merely defend, we are here to protect, and that requires more than adding another detection ruleโit requires the ability to continuously recognize new attack patterns, make sense of identity activity in context, and act immediately. Our expanded ITDR capabilities and newly launchedย ITDR AI SOC Agentย are a powerful combination of machine-speed detection and containment with the expertise of our human AI-accelerated SOC. That allows us to respond to identity threats in an average of under 2 minutes and as fast as 21 seconds without losing the judgment, accountability, and precision that effective incident response demands.โ
Also Read:ย CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight
Blackpoint is addressing todayโs emerging identity-based attacks with continuous updates to its managed ITDR offering including:
Broadening Detections Across Known Attack Vectors
- Six new detections for Microsoft environments include Suspicious Sending Pattern, Anomalous Token, Attacker in the Middle, Possible PRT Access, Verified Threat Actor IP, and Suspicious Browser Sign-In.
- Two new Microsoft Teams detections identify helpdesk-impersonation chats and tenant-name spoofing attempts, closing a gap in a channel that attackers increasingly use to reach employees directly.
- A new Device Code Phishing detection flags sign-ins that used Microsoft’s device code authentication flow in patterns consistent with phishing, an attack that otherwise looks like a routine, legitimate sign-in.
Automated, Safer Response
- Geo & VPN Policy Automation auto-block logins from unapproved countries or commercial VPNs the moment they occur, with bulk policy updates that apply across every managed tenant at once.
- Auto Logout, a new response option for Google Workspace ITDR, terminates a compromised session and resets the account password while keeping the user’s mailbox and calendar live, avoiding the data loss that comes with disabling the account outright.
Clearer Visibility and Accountability
- User Disabled Notifications provide alerts in real time whenever CompassOne disables an account across Microsoft 365, Google Workspace, or Cisco Duo, with the target user, the actor who took the action, and the reason included in every notification.
- ITDR Policy Change Visibility shows who last changed a Geo or VPN policy and when, directly on the Cloud Response policies page, to validate configuration changes without hunting for the answer.
Faster, Cleaner Incident Documentation
- The new Forensic Report automatically generates a branded, customer-ready PDF the moment an M365 incident is contained, with a complete attacker timeline, a blast-radius summary, and exfiltration tracking.
- The Historical Scan Report gives partners a retrospective view of up to 180 days of Microsoft 365 activity during tenant onboarding, complete with AI-driven analysis, MITRE ATT&CK mappings, and prioritized remediation guidance.
Catch more CIO Insights:ย How Are CIOs Aligning Technology with Workforce Agility?
[To share your insights with us, please write toย psen@itechseries.com ]

