Blackpoint's CompassOne ITDR Update Puts Microsoft 365 Sign-Ins at the Centre
Blackpoint describes itself as a company protecting small to mid-sized businesses "and their MSP allies." The Denver company announced a broad set of new Identity Threat Detection and Response (ITDR) capabilities in CompassOne, its unified security platform. It says the additions are designed to help businesses detect identity-based attacks earlier, respond without disrupting the business, and prove exactly what happened after an incident. IT Brief Australia picked up the story on September 23. The Manila Times and CIO Influence published the same text, but those are syndicated copies of the press release, not independent reporting. Everything below comes from Blackpoint's own record.
The release is really three things: new detections, new automated responses, and new documentation for after an incident. Almost all of it targets Microsoft 365. Six detections are for Microsoft environments, two are for Microsoft Teams, and one covers phishing through Microsoft's device code sign-in flow. The Historical Scan Report and the Forensic Report are both limited to Microsoft 365.
A few pieces reach further. Blackpoint's resources page says the ITDR product protects Microsoft 365, Google Workspace, and Cisco Duo accounts from identity threats, and one new alerting feature covers all three. Its AI SOC Agent has a narrower scope: Blackpoint's AI page says it covers identities across M365 and Google Workspace accounts. That scope affects how you read the speed claims later in this piece.
Device Code Phishing, PRT Access and Teams Impersonation Join the CompassOne Detection List
These are the six new Microsoft detections:
- Suspicious Sending Pattern
- Anomalous Token
- Attacker in the Middle
- Possible PRT Access
- Verified Threat Actor IP
- Suspicious Browser Sign-In
Some general context on the terms, since the release doesn't explain them. Attacker in the Middle (AiTM) phishing uses a proxy page that sits between the user and the real Microsoft sign-in page. The proxy captures the session token after the user completes MFA, so the attacker gets a working session. PRT stands for Primary Refresh Token. It's the long-lived credential that Entra-joined and registered Windows devices use for single sign-on, so theft or misuse of a PRT affects every app that token can reach. Blackpoint hasn't published how any of these detections work: no logic, thresholds, or false-positive rates.
The two Teams detections look for helpdesk-impersonation chats and tenant-name spoofing attempts, which, in Blackpoint's words, closes "a gap in a channel that attackers increasingly use to reach employees directly." The attack being described is one where someone messages an employee from an external Teams tenant, poses as internal IT support, and uses a lookalike tenant name to seem legitimate. Admins who have left external Teams access wide open should take note.
The ninth detection covers device code phishing. According to Blackpoint, it flags sign-ins that used Microsoft's device code authentication flow in patterns consistent with phishing, which is an attack that otherwise looks like an ordinary, legitimate sign-in. As general background: the device code flow exists for devices with poor input options, like TVs and conference-room hardware. The device shows a short code, and the user enters it on a Microsoft web page from another device. In a phishing version, the attacker starts the flow and gets the victim to enter the code. The victim then signs in on the real Microsoft page, with real MFA, and hands the attacker a valid token. That's why the sign-in logs look clean and why a behaviour-based detection helps.
Geo and VPN Automation and Google Workspace Auto Logout Replace Blunt Lockouts
On the response side, Blackpoint's new Geo & VPN Policy Automation automatically blocks logins from unapproved countries or commercial VPNs as they happen. Policy updates can be pushed in bulk to every managed tenant at once. The bulk update is aimed squarely at MSPs, who would otherwise edit the same policy tenant by tenant. Blackpoint hasn't said how approved countries are set, whether per-user exceptions exist for travelling staff, or how commercial VPN traffic is identified. You'll need those answers before switching the feature on for a client whose staff travel or use privacy VPNs legitimately.
Auto Logout applies only to Google Workspace. It ends a compromised session and resets the account password, but leaves the user's mailbox and calendar running. Blackpoint positions it as a way to avoid the data loss of disabling the account outright. The release doesn't describe an equivalent for Microsoft 365 or Cisco Duo, so don't assume one exists. It also doesn't explain how the user gets back into the account after the reset.
Two accountability features cover automated actions. User Disabled Notifications provide alerts in real time whenever CompassOne disables an account across Microsoft 365, Google Workspace, or Cisco Duo, with the target user, the actor who took the action, and the reason included in every notification. ITDR Policy Change Visibility shows who last changed a Geo or VPN policy and when, directly on the Cloud Response policies page. Note the word "last": Blackpoint describes the most recent change, not a full change history. If you need a complete audit trail for compliance, confirm with Blackpoint that older changes are kept.
The 180-Day Microsoft 365 Historical Scan Looks for Attackers Already Inside
The most useful addition for anyone onboarding a new client is the look-back scan. Blackpoint ITDR now has a historical scan that delivers a retrospective analysis of Microsoft 365 environments to understand if attackers already have a foothold. The Historical Scan Report gives partners a retrospective view of up to 180 days of Microsoft 365 activity during tenant onboarding, complete with AI-driven analysis, MITRE ATT&CK mappings, and prioritized remediation guidance.
It solves a real onboarding problem. When an MSP starts monitoring a tenant, it only sees activity from that point on. An attacker who set up a mailbox forwarding rule or consented to a malicious app three months earlier stays invisible unless someone goes back through the history. Blackpoint's datasheet for the scan lists suspicious sign-ins, unauthorised mailbox-forwarding rules and overprivileged applications as examples of what it can find.
Keep the scope in mind. This is a one-time look-back at onboarding, not a promise of 180 days of ongoing history for every tenant. "Up to" 180 days also means the window can be shorter. Blackpoint doesn't say what decides the actual window, though in practice it's limited by how much log data the tenant has kept. Blackpoint's comparison material also mentions forensic reports for malicious ITDR detections, as well as the capability to conduct up to 180-day historical scans, so the scan appears to be part of the standard CompassOne reporting package.
After an incident, the new Forensic Report takes over. It automatically generates a branded, customer-ready PDF the moment an M365 incident is contained, with a complete attacker timeline, a blast-radius summary, and exfiltration tracking. IT Brief Australia connects this to a wider push for structured evidence after incidents, as customers and insurers want clearer records of what happened and what data may have been exposed. Blackpoint doesn't define how it calculates "blast radius" or tracks exfiltration. The report also appears to cover only Microsoft 365 incidents.
Blackpoint's 21-Second Response Claim Comes From Blackpoint Alone
Blackpoint ties the release to its ITDR AI SOC Agent, which it launched in July. Sasmita Panda, the company's VP of Engineering, said the new features and the agent together let Blackpoint respond to identity threats in an average of under two minutes, and in as little as 21 seconds. The AI page describes the same action more specifically: for identity threats detected through ITDR, the Agent suspends the compromised account and cuts active sessions in as little as 21 seconds, with an average of two minutes.
The two versions don't quite match. Panda's quote says "under two minutes" on average, while the AI page says "an average of two minutes." Either way, these are figures Blackpoint measured on its own service. No independent test is on record, and Blackpoint hasn't said which threats they cover. The AI page also says every autonomous action is grounded in standards established and validated by Blackpoint's SOC, and its ITDR page describes an AI SOC with human analysts always available. In other words, the fast automated containment applies to high-confidence cases, and humans handle the rest.
The release also includes a customer testimonial from William Kapes, Director of Technical Operations at Integritek. He said competing products looked like "alerts dressed up as detection" and that Blackpoint's additions were meant to take work off his team. That's one satisfied customer's opinion, not a comparison study, but it does describe what MSPs are buying: a service that investigates and acts, not another console full of alerts.
What this means for MSPs and Microsoft 365 admins on CompassOne
If you already use Blackpoint ITDR, your job is to learn how the new automated actions behave before they fire on a client. If you're evaluating it, the 180-day onboarding scan is the feature to press on during a trial. Microsoft 365 shops get the most from this release. Google Workspace clients get Auto Logout. Cisco Duo coverage is limited to the account-disable notifications.
Before enabling Geo & VPN Policy Automation across all tenants, list each client's legitimate travel and VPN use. A bulk policy that blocks a sales team abroad is still an outage. Ask Blackpoint directly about plan eligibility, prerequisites and how users regain access after Auto Logout, because the announcement covers none of these. Treat the Historical Scan Report as a starting point, not a clean bill of health: its findings still need you to act, whether that's removing forwarding rules, revoking app consents or resetting credentials.
- The nine new detections focus on Microsoft 365 and Teams, including device code phishing, AiTM, possible PRT access and Teams helpdesk impersonation.
- The Historical Scan Report reviews up to 180 days of Microsoft 365 activity once, during tenant onboarding, and ranks remediation by priority.
- Auto Logout is Google Workspace-only: it ends the session and resets the password while leaving mail and calendar live.
- User Disabled Notifications cover Microsoft 365, Google Workspace and Cisco Duo, and name the affected user, who acted and why.
- Policy Change Visibility shows only the most recent geo or VPN policy change, so check whether older history is kept if you need a full audit trail.
- The sub-two-minute average and 21-second fastest response times are Blackpoint's own figures, with no independent testing behind them.
For MSPs and small businesses without their own security staff, Blackpoint's update targets the account-takeover methods that get past MFA, such as device code phishing, AiTM token theft and Teams impersonation. Its most practical tool is the one that looks backwards: the 180-day scan checks a new Microsoft 365 tenant for an intruder before monitoring starts. The detections and automation are credible additions to a managed service, but no one outside Blackpoint has measured how accurate or fast they are. Until someone does, test them on your own tenants and judge them on what they catch.