Scoop has an Ethical Paywall
Licence needed for work use Start Free Trial

Video | Agriculture | Confidence | Economy | Energy | Employment | Finance | Media | Property | RBNZ | Science | SOEs | Tax | Technology | Telecoms | Tourism | Transport | Search

 

New Okta Innovations Secure The AI-Driven Enterprise And Combat Fraud With An Identity Security Fabric

LAS VEGAS – September 25, 2025 – Okta, Inc. (NASDAQ: OKTA), the leading independent identity partner, today announced new Okta Platform and Auth0 Platform capabilities, enabling organisations to build secure, standards-rst AI agents that can be seamlessly woven into an identity security fabric for end-to-end lifecycle management. As part of the fabric, organisations will also be able to issue and verify tamper-proof digital credentials, helping establish trust and address rising AI-powered fraud.

Why it Matters:

  • AI agents–already in use by 91% of organizations [1]–promise immense productivity gains but also amplify existing security gaps and introduce new classes of risk.
  • Despite this, governance of AI is lagging, with only 10% of organisations having a strategy for managing non-human identities [1].
  • This is not a theoretical risk; real-world incidents, such as the AI hiring bot that exposed millions of applicants' data to hackers [2] who tried the password '123456', highlight the threats posed by miscongured or unmanaged AI agents.
  • AI agents need to be secure by design, with purpose-built controls for identity, access, and authorisation, and built on a new generation of standards that enable secure interoperability between agents, applications, and systems.
  • This makes agents fabric-ready, meaning they can plug into an identity security fabric for holistic visibility, control, and governance for every type of identity across ecosystems at scale.
  • In this new landscape, where AI agents operate at machine speed with high privileges and ephemeral lifecycles, and AI-driven deepfakes blur the line between legitimate users and malicious impersonators, fragmented architectures and legacy solutions can no longer keep.
  • By 2027, Gartner predicts [3] that identity fabric immunity principles will prevent 85% of new attacks.
Advertisement - scroll to continue reading

“AI is changing the workplace faster than organisations can adapt. We’re starting to see poorly built, deployed, or managed agents expose the risks of using a traditional patchwork of identity solutions,” said Kristen Swanson, SVP of Design and Research, Okta. “The modern enterprise requires an identity security fabric that can unify silos and reduce the attack surface. Our latest innovations weave agents into that fabric to manage their entire identity lifecycle, leveraging open standards like Cross App Access that help elevate the entire industry and create a more secure AI-powered ecosystem.”

End-to-End Security for the AI Agent Lifecycle with Okta for AI Agents

Okta for AI Agents seamlessly integrates AI agents into the identity security fabric for end-to-end security. It provides visibility to discover and identify risky agents, centralised control to manage their access, and automated governance to enforce security policies and manage their entire identity lifecycle. Planned to be available with Phase 1 in EA, FY27 Q1 and Phase 2 in GA, FY27.

  • Detect and discover: With Identity Security Posture Management (ISPM), organisations can discover AI agents and identify potential security risks with service accounts, API keys, and OAuth tokens.
  • Provision and register: Universal Directory helps establish and manage AI agent identities, attributing risk classication and ownership to every non-human identity.
  • Authorise and protect dynamically: Enforce security policies to apply the principle of least privilege, providing AI agents with the access they need only for the time they need it. Cross App Access (XAA), a new open protocol, standardizes how AI agents and applications connect securely, while Okta Privileged Access (OPA) will enforce security policies to provide the right level of access for agents that use static credentials like service accounts or API keys.
  • Govern, monitor, and respond: Okta Identity Governance (OIG) provides comprehensive audit trails and activity logging for all agent actions and decisions. Identity Threat Protection with Okta AI (ITP) continuously monitors user activity and employs behavioral analytics to identify anomalous behavior and trigger automated remediations to maintain security posture throughout active sessions.

Securing Agent and App interactions with Cross App Access

Cross App Access (XAA) extends OAuth to secure agent-driven and app-to-app interactions across the enterprise. With support from industry leaders like Automation Anywhere, AWS, Boomi, Box, Glean, Grammarly, Miro, and WRITER, XAA shifts control from individual applications to the identity layer, enabling real-time visibility, policy-driven security, and safer integrations.

XAA will soon be available with out-of-the-box support in Auth0, enabling B2B SaaS developers to build applications and AI tools that can natively participate in the protocol. It also complements Auth0 for AI Agents to simplify how developers embed identity-rst security into AI-driven applications. Together, XAA and Auth0 for AI Agents make it easier to deliver secure, “fabric-ready” applications, where each agent identity is governed and every connection is protected — at scale and with minimal developer effort.

For enterprises, XAA is now available within the Okta Platform in EA, enabling customers to experience it and benet from the below as more organisations adopt the protocol:

  • Centralised policy-based access management: IT and security teams control what data apps or agents can access, allowing for consistent enforcement and real-time visibility.
  • Enhanced security and auditability: Unauthorised requests can be audited or blocked. This reduces hidden connections and blind trust while providing the ability to immediately revoke access in case of an incident.
  • Reduced user friction: By pre-approving agent-to-app or app-to-app connections, XAA reduces the number of consent prompts a user encounters, leading to a more seamless experience.

“Enterprises everywhere are grappling with how to safely harness AI with company data. Our customers rely on Glean to unify that knowledge and empower AI agents to take meaningful action," said Sunil Agrawal, Chief Information Security Ofcer, Glean. "Glean agents act strictly on behalf of the user – with no extra privileges. Cross App Access takes that principle even further and represents the next step toward making it more secure and seamless for AI agents to connect across systems. We’re excited to support this emerging protocol and to help guide the industry toward standards-based agent interactions."

Preventing AI Fraud with Veriable Digital Credentials

Woven into the identity security fabric, the Okta Veriable Digital Credentials (VDC) platform, planned to be available in FY27, enables organisations to issue and verify tamper-proof, reusable identity data – like government IDs, employment records, or certications. It reduces AI-powered fraud and friction during onboarding by providing a way for people to digitally prove their identity and eligibility. End users will also gain a simplied, streamlined experience when interacting with consumer apps and websites, eliminating tedious manual verication.

Built on open standards for maximum control and future interoperability, VDCs will help establish trust in a world of AI agents, enabling secure, privacy-preserving credentials that help prove who someone is, what they've done, or what they're allowed to do. 

Beginning with a new Digital ID verication feature, planned to be available in EA Q4 FY26, businesses will be able to natively verify government-issued IDs, initially supporting mobile driver's licenses with plans to expand to more forms of identication in the future.

Note:

[1] AI at Work 2025: Securing the AI-powered workforce, Okta, August 12, 2025.

[2] AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’, Wired, July 9, 2025.

[3] Gartner Identies the Top Cybersecurity Trends for 2023, Gartner, April 12, 2023.

About Okta

Okta, Inc. is The World’s Identity Company™. We secure Identity, so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to use the power of Identity to drive security, efciencies, and success — all while protecting their users, employees, and partners.

© Scoop Media

Advertisement - scroll to continue reading
 
 
 
Business Headlines | Sci-Tech Headlines