Home
Tech Grid
News Room
Interviews
CISO POV
Think Stack
Articles
  • Identity & Access Management

Blackpoint Cyber Delivers Stronger Protection Against Identity Threats


Blackpoint Cyber Delivers Stronger Protection Against Identity Threats
  • by: GlobeNewswire
  • |
  • September 14, 2026

Blackpoint Cyber, a leading cybersecurity company protecting small to mid-sized companies and their MSP allies worldwide, today announced a broad set of new Identity Threat Detection and Response capabilities in CompassOne, its unified security platform. The new capabilities include additional threat detections, automated containment controls, and incident-reporting tools designed to help businesses detect identity-based attacks earlier, respond without disrupting the business, and prove exactly what happened after an incident. In addition, Blackpoint ITDR now has a historical scan that delivers a retrospective analysis of Microsoft 365 environments to understand if attackers already have a foothold and can compromise systems.

Quick Intel

  • Blackpoint Cyber announces new ITDR capabilities in CompassOne

  • Historical scan provides retrospective analysis of Microsoft 365 environments

  • Nine new detections across Microsoft and Teams environments

  • Automated response controls including Geo & VPN Policy Automation

  • Forensic Report generates customer-ready PDF with attacker timeline

  • Responds to identity threats in average of under 2 minutes

Broadening Detections and Automated Response

Six new detections for Microsoft environments include Suspicious Sending Pattern, Anomalous Token, Attacker in the Middle, Possible PRT Access, Verified Threat Actor IP, and Suspicious Browser Sign-In. Two new Microsoft Teams detections identify helpdesk-impersonation chats and tenant-name spoofing attempts, closing a gap in a channel that attackers increasingly use to reach employees directly. A new Device Code Phishing detection flags sign-ins that used Microsoft's device code authentication flow in patterns consistent with phishing, an attack that otherwise looks like a routine, legitimate sign-in.

Geo & VPN Policy Automation auto-block logins from unapproved countries or commercial VPNs the moment they occur, with bulk policy updates that apply across every managed tenant at once. Auto Logout, a new response option for Google Workspace ITDR, terminates a compromised session and resets the account password while keeping the user's mailbox and calendar live, avoiding the data loss that comes with disabling the account outright.

Clearer Visibility and Accountability

User Disabled Notifications provide alerts in real time whenever CompassOne disables an account across Microsoft 365, Google Workspace, or Cisco Duo, with the target user, the actor who took the action, and the reason included in every notification. ITDR Policy Change Visibility shows who last changed a Geo or VPN policy and when, directly on the Cloud Response policies page, to validate configuration changes without hunting for the answer.

Faster, Cleaner Incident Documentation

The new Forensic Report automatically generates a branded, customer-ready PDF the moment an M365 incident is contained, with a complete attacker timeline, a blast-radius summary, and exfiltration tracking. The Historical Scan Report gives partners a retrospective view of up to 180 days of Microsoft 365 activity during tenant onboarding, complete with AI-driven analysis, MITRE ATT&CK mappings, and prioritized remediation guidance.

Executive Perspectives

"A compromised mailbox is not an inconvenience; it's a confidentiality problem with our clients' own clients attached to it. Much of what we saw when evaluating the competition, was alerts dressed up as detection, which just moves the work back to us. Blackpoint's SOC investigates and acts and every addition has been aimed at taking work off my team rather than handing them another dashboard to check," said William Kapes, Director of Technical Operations at Integritek.

"Threats are becoming agentic, and identities are the new threat vector where attackers are entering the business," said Sasmita Panda, VP of Engineering at Blackpoint Cyber. "We aren't here to merely defend, we are here to protect, and that requires more than adding another detection rule—it requires the ability to continuously recognize new attack patterns, make sense of identity activity in context, and act immediately. Our expanded ITDR capabilities and newly launched ITDR AI SOC Agent are a powerful combination of machine-speed detection and containment with the expertise of our human AI-accelerated SOC. That allows us to respond to identity threats in an average of under 2 minutes and as fast as 21 seconds without losing the judgment, accountability, and precision that effective incident response demands."

 

About Blackpoint Cyber

Blackpoint Cyber is a leading cybersecurity company serving small and mid-market businesses and their MSP partners worldwide. The company's managed detection and response platform, CompassOne, combines a 24/7 security operations center with proprietary detection technology to help protect networks, cloud environments, and identities from cyberattacks.

  • Identity SecurityCyber SecurityMDR
News Disclaimer
Want to reach B2B tech decision-makers through TechIntelPro? Get our Media Kit
  • Share
Enterprise Tech News