Current + Petra Security integration
A view-only Petra Security feed that brings Microsoft 365 posture scores, the 31 controls behind them, open account compromises and failed sign-in attacks onto the company record and into strategic business reviews.
Petra Security is identity threat detection for Microsoft 365, built for MSPs. It watches a tenant's audit trail for one thing, a real account compromise, and around that it assesses 31 controls in how the tenant is configured, scores the result out of 100, and counts the sign-in attacks that failed. Current's Petra integration is a view-only feed into the company record, the strategic business review module, the roadmap and the company alert band. It reads what Petra already knows and never writes back.
What the integration does
Current authenticates to Petra with one API key minted in your Petra organization, then reads your tenant roster, the licensing figures, the account compromises, the newest posture report for each tenant and a rolling window of failed attacks, every six hours. Instead of opening the Petra dashboard tenant by tenant the week of the review, the Microsoft 365 numbers are already sitting on the company record when you open it.
It answers a question no other feed can
Every other security connector in Current has a machine as its unit. Datto EDR, Huntress, SentinelOne, ThreatLocker and AutoElevate all answer some version of "is this laptop protected". Petra's unit is an identity, so it answers a different question: did somebody get into this company's email, and is their Microsoft 365 configured so it can happen again. That is why its numbers sit in the People posture on a company record rather than being folded into endpoint coverage, where a seat count would corrupt a fleet figure without anyone noticing.
What data flows
- Tenants and licensing: the Petra tenant roster matched to your Current companies, how many users each one licenses, and whether Petra is monitoring the tenant or has only scanned it.
- Account compromises: when each happened, whether an attacker is still in the account, how far the clean-up has got, an estimate of the dwell time, the compromised account and the phishing email's subject and sender. Staff-only, and never printed in a pack.
- Posture reports: the score out of 100 with Petra's grade, the score before it on a follow-up, and how many of the 31 controls are met, open, drifted or not assessed.
- The controls themselves: each one's name, category, severity, plain-English current state and the fix Petra wrote for it, which is a roadmap item already written.
- Global administrators: how many there are against the maximum Petra recommends, how many sign in with strong MFA, and whether Microsoft returned the full list.
- Failed attacks: a rolling 30-day count per tenant, the countries behind them, and the people being targeted most.
The feed is one-way, and here it is one-way by construction rather than by restraint: Petra's public API declares no write address at all. Current cannot lock an account, revoke a session, retract a phishing email, apply a posture fix or unpause a tenant, because none of those exist to call. Remediation stays in the Petra dashboard; Current uses the evidence.
The person is the incident, so the line is drawn elsewhere
For most feeds Current can drop the person and keep the event. An account compromise does not work that way: a technician cannot act on "somebody was breached". So Current keeps the compromised account's name and sign-in address and the phishing subject, and walls them instead. They are staff-only, blocked from partner viewers at the database rather than hidden in the interface; they never enter an AI prompt, which also keeps an attacker-written subject line out of one; and they never reach a business review a client reads. Petra ships its own Anonymize Incidents feature for the same reason. Lists of everyone else who got the same phish are stored as counts, and Current never calls Petra's billable-users address at all, because mirroring a named roster of every licensed employee to learn a headcount the licensing read already returns would be a trade with nothing on Current's side of it.
Not assessed is not a failure
A posture control comes back secure, fixed, open, drifted, in progress or not assessed, and the last of those means Petra is missing a Microsoft permission for that control rather than that the setting is wrong. A Microsoft 365 tenant authorised in Petra before 17 July 2026 predates the permission set the assessment needs, which is the usual reason; Petra can grant it from its own Posture reports page. Current keeps those controls out of both halves of every share it prints and gives them a tile of their own, the same treatment Petra's own score gives them. A control Petra has not ranked for severity is unranked rather than low, and a compromise Petra marked as an authorised pen test or a false positive is excluded from every count, because reading "not remediated" as "open" would put a pen test on a company record as a breach.
Two alerts, and deliberately not a third
Current raises an entry in the company alert band while an account compromise is still open, critical while an attacker is still inside the account and a warning when only historical ones are outstanding, and a second entry when a control Petra rates critical is open or has drifted. The posture score raises nothing. Petra recommends a floor of 61 out of 100 and its own example tenant scores 52, so a rule on the score would open an alert on nearly every company in the workspace the day the connector is turned on, and an alert everybody has is an alert nobody reads. The score belongs on the company card, in the review and on the roadmap, where a 52 starts a conversation.
Matching tenants to companies
Each Petra tenant is one end-customer, and its Petra id is the one in the dashboard address, so an unmapped row is one click to verify. Current matches on the normalized company name, punctuation and Inc/LLC/Ltd-style suffixes stripped, and links it when exactly one company matches; a name that fits two waits on an unmapped list for a person to decide rather than being paired on a guess. Mapping one by hand attaches its posture, compromises and attacks immediately instead of waiting for the next scheduled sync. Petra also sends each tenant's Microsoft 365 directory id, which Current stores and does not match on, because a workspace that has not connected Microsoft 365 would have nothing to match it against.
Where the data appears
- In strategic business reviews, in the security chapter beside detection feeds such as Huntress and application control from ThreatLocker: the score and its direction since the baseline, the controls fixed since then, the critical ones still open by name, and the attack volume the tenant absorbed.
- On the company record, where the Petra card shows the posture score and grade, the four control counts, what is open with Petra's own description of it, the account compromises and their clean-up state, the global administrators against the recommended maximum, and the attacks stopped in the last 30 days.
- In the company's People posture, as the licensed identities and the global administrator figures. They stay separate from a workspace-wide MFA rate, because Petra counts administrators and a general MFA feed counts everyone.
- On roadmaps, where every open or drifted control rated critical or high arrives in the Suggested tray carrying its own rationale and the fix Petra wrote for it.
- On dashboards, as a Microsoft 365 posture tile averaging the score across the companies that have a completed assessment.
- In the company alert band, as an open account compromise and as a critical control that is not in place.
Why it matters
An MSP running Petra for a partner like Northwind Traders can open the account and see a Microsoft 365 posture of 58 out of 100, up from 49 at the baseline, with nineteen of the 31 controls met, three critical ones still open by name, and two the assessment could not reach for want of a Microsoft permission. Beside them sit one account compromise from March that was closed in a day, 1,204 sign-in attacks that failed in the last month, and fourteen global administrators where Petra recommends no more than four. The three critical controls are the next quarter's roadmap, written by the product that found them. The administrator count is the conversation nobody was having.
Sources
- 1.Petra Security API reference — Petra Security