Blackpoint Cyber vs Petra

One tool for identity threats. One platform for everything else.

Blackpoint and Petra are both identity threat detection and response (ITDR) platforms built for MSPs. Blackpoint covers Microsoft 365, Google Workspace, and Cisco Duo in a single platform that also includes endpoint and cloud protection. Petra is a standalone ITDR tool built specifically for Microsoft 365. Blackpoint’s AI SOC Agent averages under 2 minutes to containment, compared with Petra’s 3.8-minute average.

Identity coverage across Microsoft 365, Google Workspace, and Cisco Duo

AI SOC Agent with human oversight averages under 2 minutes to containment, as fast as 21 seconds

ITDR built into the CompassOne platform alongside endpoint, network, and cloud protection

Transparent, per-seat and per-cloud user pricing


Request a Demo →

Why MSPs Are Choosing Blackpoint Over Point Solutions

One Blackpoint partner evaluated both Blackpoint and Petra before making a decision. Here’s how they described the difference:

“Blackpoint had the first Google Workspace solution. They beat everybody to that, and that was a big reason we went with Blackpoint. The depth of what Blackpoint offers goes well beyond identity protection, which is really Petra’s main thing. There’s a whole suite of cybersecurity services, SIEM included, that lets Blackpoint go further than Petra.”
“My clients trust me to pick vendors who’ve done the hard things: certifications, audits, a real track record. Blackpoint is just so much more established and mature, which makes it the right choice for a mature MSP like use”

— MSP Owner, Blackpoint Partner

Read More Partner Success Stories →

Blackpoint vs Petra – At a Glance

Group 19
Petra Security*

Scope

Identity threat detection and response, unified with endpoint, network, and cloud protection in one platform
Standalone ITDR focused specifically on Microsoft 365

Identity coverage

Microsoft 365, Google Workspace, and Cisco Duo
Microsoft 365

Response model

AI SOC Agent automates response to high-confidence threats; human SOC analysts investigate and respond to all other activity that automation alone can misjudge
Fully automated detection and remediation, tuned for clear, high-confidence indicators of compromise

Response speed

Average under 2 minutes to autonomous containment, as fast as 21 seconds
Average MTTR of 3.8 minutes

Platform breadth

Endpoint MDR ITDR, Cloud Posture, Vulnerability Management, Security Posture Rating, and SIEM options in one platform
Identity/M365 only; separate tools needed for endpoint and cloud coverage

Pricing

Transparent, per-device or cloud user, monthly and annual options based on license purchased, no setup fees
Unavailable
Group 19
Scope
Identity threat detection and response, unified with endpoint, network, and cloud protection in one platform
Identity coverage
Microsoft 365, Google Workspace, and Cisco Duo
Response model
AI SOC Agent automates response to high-confidence threats; human SOC analysts investigate and respond to all other activity that automation alone can misjudge
Response speed
Average under 2 minutes to autonomous containment, as fast as 21 seconds
Platform breadth
Endpoint MDR ITDR, Cloud Posture, Vulnerability Management, Security Posture Rating, and SIEM options in one platform
Pricing
Transparent, per-device or cloud user, monthly and annual options based on license purchased, no setup fees
Petra Security*
Scope
Standalone ITDR focused specifically on Microsoft 365
Identity coverage
Microsoft 365
Response model
Fully automated detection and remediation, tuned for clear, high-confidence indicators of compromise
Response speed
Average MTTR of 3.8 minutes
Platform breadth
Identity/M365 only; separate tools needed for endpoint and cloud coverage
Pricing
Unavailable

*Competitor information is based on publicly available sources as of August 2026 and may be subject to change. All comparisons are for informational purposes only.

 

What to Evaluate Beyond the Feature List

  • Coverage breadth – Does it protect only Microsoft 365, or every identity surface your clients actually use?
  • Response model – Is a human SOC involved in high-impact decisions, or is response fully automated end to end?
  • Platform fit – Is it a point solution, or is it part of the same platform as your endpoint and cloud tools?
  • Total cost – One more login and one more bill, or bundled into a platform you’re already paying for?

Why MSPs Choose Blackpoint’s ITDR

Does it cover more than Microsoft 365?

Coverage breadth matters because clients rarely run on a single identity provider. Blackpoint protects Microsoft 365, Google Workspace, and Cisco Duo; tools scoped to M365 alone leave every other identity surface unmonitored.

Is a human SOC involved, or is response fully automated?

Blackpoint’s AI SOC Agent contains high-confidence identity threats in an average of under two minutes, as fast as 21 seconds. Threats that don’t meet the high-confidence threshold are routed to the human SOC for investigation and response. Look for a response model that pairs fast automated containment with human SOC review for anything automation alone might misjudge.

Is it a standalone tool, or part of your existing platform?

A point solution means a separate login, a separate bill, and a separate thing to explain to clients. ITDR built into CompassOne, the same platform as endpoint, network, and cloud protection that gives one view instead of another tool to manage.

What’s the real total cost?

Blackpoint ITDR is available on a transparent, per device or per cloud user basis, with no setup fees; it’s priced to scale with your business, not against it.

Detections That Keep Pace With How Attacks Actually Happen

Total cost isn’t just the license, it’s the extra login, the extra bill, and the extra integration work. Platform-bundled ITDR is often less overhead than a standalone tool priced separately.

Deeper Dive: Blackpoint vs Petra

Group 19
Petra Security*

Detection approach

Behavioral ITDR across M365, Google Workspace, and Cisco Duo
Behavioral ITDR (all M365 activity)

Detects known-bad IPs in login logs

Yes
Yes

Attacker intent analysis in Exchange & SharePoint

Yes
Yes

Detects residential proxies

Yes
Yes

Dynamic tuning for per-client VPN usage

Yes, VPN usage can be dynamically tuned per client. Specific VPNs can be allowlisted or blocklisted, so recognized VPN use doesn’t trigger a false alert
Yes

Catches credentials blocked by MFA or Conditional Access

Yes
Yes

Manual tuning needed

Tuning is optional per-client customizations that are available around things such as policies, notification options, and allowlisting for MSPs that want finer control.
No manual tuning needed

24/7 US-based SOC

Yes, with follow-the-sun methodology that includes the UK, Australia, and New Zealand, and always available by phone.
Yes, but does not human SOC analysts on their staff.

Disables account & revokes sessions

Yes
Yes

Removes malicious inbox rules & forwarding

Yes
Yes

Reset password in the portal

Forced password resets are often handled automatically by the SOC, so no manual step is needed in the portal.
Yes

Fleet-wide phishing email retraction

Not yet
Yes

Reverses attacker activity in SharePoint

Yes
Yes

Reverses malicious MFA & device registrations

Yes
Yes

Finds root-cause phishing email

Yes, this is included in the Forensics Report.
Yes

Shows IP address of attacker sign-in

No???
Yes

Attacker timeline across M365

Yes, detailed reporting with the timeline along with the action taken.
Yes

Generates client-ready PDF

Yes, includes forensic incident reports, a historical threat lookback for new customer environments, and executive summary reports tracking month-over-month progress and security maturity.
Yes

M365 SIEM included with ITDR

M365 logs are ingested and surfaced per incident or detection; full SIEM search for M365 is in development.
Yes

Targeting analytics per client

Client-specific reports surface threat and vulnerability trends over time, making targeting patterns easy to spot.
Yes

Pre-sales incident response report

Yes
Yes

Anonymized incident library for sales

Yes
Yes

Managed Detection and Response (MDR)

Yes, MDR provides the same SOC and 24/7 coverage as our ITDR.
No, ITDR only.

Cloud Posture

Yes, catches cloud drift and provides conditional access governance.
Potentially, via Conditional Access Policy recommendations, version history, and simulation for M365 (not a dedicated cloud posture product).

Vulnerability Management

Yes, identifies and prioritizes risks across identities, endpoints, and network.
No

Security Posture Rating

Yes, NIST-based scoring benchmarks security maturity and tracks progress over time.
No

Original Threat Intelligence and Research

Yes, Blackpoint’s Adversary Pursuit Group conducts original research identifying novel malware, tactics, and identity-based threats, feeding new detections directly into the SOC and ITDR.
No, ITDR tool only; no dedicated research team identifying novel threats ahead of time

Malware Triage And Analysis

Yes, dedicated malware engineers triage and analyze threats found in the wild, detailing how and why they were identified, and their real-world impact.
No, no dedicated malware engineering team.
Group 19
Detection approach
Behavioral ITDR across M365, Google Workspace, and Cisco Duo
Detects known-bad IPs in login logs
Yes
Attacker intent analysis in Exchange & SharePoint
Yes
Detects residential proxies
Yes
Dynamic tuning for per-client VPN usage
Yes, VPN usage can be dynamically tuned per client. Specific VPNs can be allowlisted or blocklisted, so recognized VPN use doesn’t trigger a false alert
Catches credentials blocked by MFA or Conditional Access
Yes
Manual tuning needed
Tuning is optional per-client customizations that are available around things such as policies, notification options, and allowlisting for MSPs that want finer control.
24/7 US-based SOC
Yes, with follow-the-sun methodology that includes the UK, Australia, and New Zealand, and always available by phone.
Disables account & revokes sessions
Yes
Removes malicious inbox rules & forwarding
Yes
Reset password in the portal
Forced password resets are often handled automatically by the SOC, so no manual step is needed in the portal.
Fleet-wide phishing email retraction
Not yet
Reverses attacker activity in SharePoint
Yes
Reverses malicious MFA & device registrations
Yes
Finds root-cause phishing email
Yes, this is included in the Forensics Report.
Shows IP address of attacker sign-in
No???
Attacker timeline across M365
Yes, detailed reporting with the timeline along with the action taken.
Generates client-ready PDF
Yes, includes forensic incident reports, a historical threat lookback for new customer environments, and executive summary reports tracking month-over-month progress and security maturity.
M365 SIEM included with ITDR
M365 logs are ingested and surfaced per incident or detection; full SIEM search for M365 is in development.
Targeting analytics per client
Client-specific reports surface threat and vulnerability trends over time, making targeting patterns easy to spot.
Pre-sales incident response report
Yes
Anonymized incident library for sales
Yes
Managed Detection and Response (MDR)
Yes, MDR provides the same SOC and 24/7 coverage as our ITDR.
Cloud Posture
Yes, catches cloud drift and provides conditional access governance.
Vulnerability Management
Yes, identifies and prioritizes risks across identities, endpoints, and network.
Security Posture Rating
Yes, NIST-based scoring benchmarks security maturity and tracks progress over time.
Original Threat Intelligence and Research
Yes, Blackpoint’s Adversary Pursuit Group conducts original research identifying novel malware, tactics, and identity-based threats, feeding new detections directly into the SOC and ITDR.
Malware Triage And Analysis
Yes, dedicated malware engineers triage and analyze threats found in the wild, detailing how and why they were identified, and their real-world impact.
Petra Security*
Detection approach
Behavioral ITDR (all M365 activity)
Detects known-bad IPs in login logs
Yes
Attacker intent analysis in Exchange & SharePoint
Yes
Detects residential proxies
Yes
Dynamic tuning for per-client VPN usage
Yes
Catches credentials blocked by MFA or Conditional Access
Yes
Manual tuning needed
No manual tuning needed
24/7 US-based SOC
Yes, but does not human SOC analysts on their staff.
Disables account & revokes sessions
Yes
Removes malicious inbox rules & forwarding
Yes
Reset password in the portal
Yes
Fleet-wide phishing email retraction
Yes
Reverses attacker activity in SharePoint
Yes
Reverses malicious MFA & device registrations
Yes
Finds root-cause phishing email
Yes
Shows IP address of attacker sign-in
Yes
Attacker timeline across M365
Yes
Generates client-ready PDF
Yes
M365 SIEM included with ITDR
Yes
Targeting analytics per client
Yes
Pre-sales incident response report
Yes
Anonymized incident library for sales
Yes
Managed Detection and Response (MDR)
No, ITDR only.
Cloud Posture
Potentially, via Conditional Access Policy recommendations, version history, and simulation for M365 (not a dedicated cloud posture product).
Vulnerability Management
No
Security Posture Rating
No
Original Threat Intelligence and Research
No, ITDR tool only; no dedicated research team identifying novel threats ahead of time
Malware Triage And Analysis
No, no dedicated malware engineering team.

*Competitor information is based on publicly available sources as of August 2026 and may be subject to change. All comparisons are for informational purposes only.

Frequently Asked Questions

Ready to Experience the Difference?

CompassOne by Blackpoint brings prevention, detection, response, and compliance together in one platform, along with a 24/7 human SOC. Find out how Blackpoint’s ITDR compares to a standalone point solution for your business.

Request a Demo →

Explore Blackpoint ITDR →