Okta unveiled new Okta for AI Agents capabilities at its Oktane conference, including an Agent Gateway for real-time policy enforcement, agent-to-resource governance, and interaction logging; Shadow AI Agent Discovery for Endpoints to identify unmanaged agents on employee devices; third-party identity-provider support; and configuration mapping. Okta plans to add a kill-switch capability to the gateway by the end of 2026, enabling organizations to revoke an agent’s tokens, terminate sessions, or remove granular permissions when behavior becomes anomalous or prohibited.
Okta also joined the 12-vendor Blueprint Alliance alongside organizations including AWS, Google Cloud, Salesforce, CrowdStrike, Wiz, ServiceNow, and Proofpoint. The alliance will develop an open, multivendor reference architecture focused on locating AI agents, defining their permissions, monitoring their activity, and responding to incidents. Its approach emphasizes centralized identity controls, OAuth token revocation, and broader security telemetry to prevent autonomous agents from retaining excessive or ungoverned access to sensitive enterprise systems.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Okta demonstrated a Claude-based agent accessing Slack, Salesforce, Atlassian, and GitHub through two agent gateways. After detecting an attempted transfer of confidential Salesforce data to a personal email address, a second agent revoked the Claude agent's Salesforce token, notified its owner, and sent remediation details to IT.
At Oktane, Okta introduced Okta Identity Threat Protection, which consolidates AI-agent risk information from other security tools into a single view. The article identifies CrowdStrike, Zscaler, SentinelOne, and Palo Alto Networks as potential telemetry sources.
Okta announced Shadow AI Agent Discovery for Endpoints to identify unmanaged agents on employee devices, along with third-party identity-provider support and Configuration Designer for mapping and auditing agent-to-resource connections. It also introduced Agent Gateway, an MCP server for governing agent access to resources.
The alliance published six operational principles centered on determining where agents are, what they can do, what they are doing, and how organizations should respond. Its guidance calls for each agent to have an immediate kill switch and a defined restoration path.
At its Sept. 23 Oktane conference in Las Vegas, Okta announced the Blueprint Alliance with founding members including AWS, CrowdStrike, Google Cloud, Salesforce, Wiz, ServiceNow, and Proofpoint. The consortium aims to develop open standards addressing AI-agent discovery, permissions, activity monitoring, and incident response.
Okta for AI Agents became generally available in April following its introduction at the prior year's Oktane conference.
Okta introduced its Okta for AI Agents product at the prior year's Oktane conference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcezdnet.com
Open sourcescworld.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.