No more typing reviews! Try our Samantha, our new voice AI agent.

CompassOne by Blackpoint Cyber vs Kandji comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
CompassOne by Blackpoint Cyber
Ranking in Endpoint Detection and Response (EDR)
39th
Average Rating
9.0
Reviews Sentiment
7.8
Number of Reviews
5
Ranking in other categories
Security Information and Event Management (SIEM) (34th), Vulnerability Management (47th), Application Control (10th), Managed Detection and Response (MDR) (12th), Identity Threat Detection and Response (ITDR) (14th)
Kandji
Ranking in Endpoint Detection and Response (EDR)
12th
Average Rating
8.8
Reviews Sentiment
6.4
Number of Reviews
20
Ranking in other categories
Vulnerability Management (20th), Mobile Device Management (MDM) (3rd), Enterprise Mobility Management (EMM) (3rd)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Gary Herbstman - PeerSpot reviewer
Owner at Byte Solutions Inc.
Experienced reduced alert fatigue with streamlined notifications
We use Blackpoint Cyber MDR for our higher-end clients who need a higher level of control over security We get a deeper look into security related events that are otherwise difficult find and analyze. Security operations does a good job of weeding out the noise. I appreciate that there are…
CD
SysAdmin at a recreational facilities/services company with 11-50 employees
Strong security structure has supported fast Mac and iOS administration with minimal IT effort
One area for improvement for Kandji would be having a bigger suite of applications. I noticed that some of the niche apps our data software firm needs were not in the regular library. We were able to use the custom app feature to create those apps ourselves, but I would love it if Kandji could expand the library. I also wish Kandji could lock down different ports on MacBooks based on which ones we wanted to shut down, and I hope there is an easier way to sandbox people's bring your own device devices because when we're doing SOC 2, it really wants us to sandbox things so that if someone were to take a device that is not ours, we could delete just our data off there and not theirs. An improvement needed for Kandji would be the ability to remote into devices. I would appreciate something that is really reliable for that without having to buy third-party software.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that you can select remote access of any machine for sandboxing."
"We use Cortex XDR by Palo Alto Networks for its ability to detect based on behavior rather than simple virus scan to prevent malicious activities."
"The most valuable aspect of Cortex XDR by Palo Alto Networks for me is its integration with AI detection, where we get to know the behavioral detection based on users, traffic patterns, and different services that we consume."
"Once you become familiar with it, Cortex XDR by Palo Alto Networks is a more powerful tool and I would say that I prefer it over MDE because it is a stronger tool for me."
"Stability is a primary factor, and then there's the ease of distribution and policy management; Cortex XDR by Palo Alto Networks is very easy to work with, and we're quite happy with them."
"Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
"Palo Alto is the best security solution in the market."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"On a scale from one to ten, I would rate the overall solution as a ten."
"Their SOC is phenomenal in not monitoring and responding and taking action."
"On my end, the most valuable feature of this solution is that I can install it and forget about it. After that, their SOC team takes over and they only call me when there's a problem."
"I appreciate that there are people behind the scenes sorting out valuable alerts from those that are not, so I only get alerts when they are real."
"The solution is all encompassing and can incorporate email monitoring."
"The solution also watches over Microsoft 365 and keeps a copy of logs."
"Kandji has positively impacted my organization because it is very user-friendly, and among the multiple MDM solutions I have used, such as JumpCloud and Intune, Kandji stands out as one of the best for Mac devices."
"Kandji has positively impacted my organization by increasing our security, reducing our resolution times, and ensuring that all employees who work from home have their computers working from day one."
"Kandji has positively impacted my organization because it helps us be more secure and enforce compliance."
"Kandji has positively impacted our organization by making it easy to manage all of our MacBook devices and applications."
"I have seen a return on investment with Kandji, as I save time."
"Kandji offers excellent features, including the ability to erase devices remotely without needing to be in front of the laptop."
"I highly recommend Kandji to others looking into using it since I have not seen any game-breaking issues; it is highly reliable, scalable, improves security, and reduces the time individuals need to spend on system configuration for security updates."
"The customer support is the best I have ever seen."
 

Cons

"One thing that was missing was the integration part. Currently, they don't have out-of-box integration with IBM QRadar, or if they have the integration, the integration doesn't work well."
"The onboarding process could be better."
"Cortex XDR could be improved with more GUI features."
"It would be good to have a better way to search for a file within the UI."
"The connection to the internet has not performed as expected."
"Every 30 or 40 days, there's a new version and we need to go and make sure our customer's laptops are upgraded."
"The negative aspect I see is the economic model used by Palo Alto."
"It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
"The interface could be more intuitive."
"The feature we keep asking for is a vulnerability scan."
"Some texts seem to report items as normal too quickly."
"The interface could be more intuitive. More transparency is needed in the interface as a lot of details are hidden behind the scenes, making them difficult or impossible to access."
"The solution does not tie into other EDR products like CyberArk or CrowdStrike but that might be more useful."
"While I am very satisfied with the service, supporting additional platforms, particularly Linux support, would be a beneficial improvement."
"I rated Kandji an eight because the laptop needs to be connected to Wi-Fi to erase it."
"One way Kandji can be improved is through pricing, as other market providers comparatively have a lower price."
"There are certain limitations with blueprints where each machine can only have one or must have a blueprint, which is frustrating since certain machines may not need to have a blueprint straight away for testing."
"I think Kandji could be improved with a better UI."
"Kandji can definitely be improved by the complexity. I feel we cannot necessarily tweak the Blueprints in the ways that we need to or there are just complex one-off situations where we need more customization and more ability to run custom scripts."
"One thing I have noticed is that Kandji is mainly for Mac devices."
"I believe Kandji can be improved by having more self-service options, as users can complete a few steps before reaching out to IT support, which will give us more context on the issue."
"One area for improvement for Kandji would be having a bigger suite of applications."
 

Pricing and Cost Advice

"I don't recall what the cost was, but it wasn't really that expensive."
"Very costly product."
"I am using the Community edition."
"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"This is an expensive solution."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"Its pricing is kind of in line with its competitors and everybody else out there."
"The pricing is in line with other products."
"The pricing is reasonable."
"Users have to pay a yearly licensing fee for Kandji, which is expensive."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Outsourcing Company
9%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
9%
Comms Service Provider
14%
Outsourcing Company
12%
Financial Services Firm
10%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
No data available
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise5
Large Enterprise7
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Blackpoint Cyber MDR?
While I am very satisfied with the service, supporting additional platforms, particularly Linux support, would be a b...
What is your primary use case for Blackpoint Cyber MDR?
The solution serves as a baseline security offering. We have implemented it for every client that we do business with.
What is your experience regarding pricing and costs for Kandji?
My experience with pricing, setup cost, and licensing is that we are using nearly 100 machines in Kandji, which comes...
What needs improvement with Kandji?
One thing I have noticed is that Kandji is mainly for Mac devices. We cannot manage Windows devices on Kandji. This i...
What is your primary use case for Kandji?
Kandji, which is now called Hero, is used for mobile device management. We use it to manage Mac devices, Apple device...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Blackpoint Cyber Managed Detection + Response, Blackpoint Cyber Managed Detection and Response
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
CoreRecon, Peerless Tech Solutions, Lorien Health
Information Not Available
Find out what your peers are saying about CompassOne by Blackpoint Cyber vs. Kandji and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.