Oktane '26 brings clarity to AI agent identity security
Many organizations are prioritizing agentic AI initiatives, but identity security remains a challenge. Okta's recent announcements aim to address the risks posed by AI agents.
As security vendors position themselves as the key to successful AI adoption, Okta made a strong case for its relevance last week at Oktane with a comprehensive portfolio enabling enterprises to securely deploy AI agents.
While last year's Oktane emphasized key standards, such as Cross App Access (XAA), Oktane 2026 focused on implementing and deploying solutions based on those standards and the technology groundwork. This blog provides a rundown on Oktane highlights and issues, such as gateway proliferation and identity resilience, that are coming to the fore.
The cybersecurity industry today is considerably confused about the optimal identity security stack for an agentic world and how to address AI agent risks. When Omdia, a division of Informa TechTarget, asked enterprise identity leaders about what was holding them back from investing in identity security for AI agents, the No. 1 issue was uncertainty around the security risks posed by AI agents.
There are solid resources, including the OWASP Top 10 risks for agentic applications, but AI agent threats are still nascent. Incidents such as the OpenAI-Hugging Face and Anthropic agent breaches are bringing the threats into focus, but we are still in the early days of agentic AI, and there is considerable confusion about what is needed to secure AI agents.
Blueprint Alliance: A reference architecture for the agentic enterprise
To help bring clarity to this confusion, Okta announced the Blueprint Alliance at Oktane 2026. This is a cross-industry coalition helping organizations operate their agentic stack as a unified, governed system. The alliance published an open, vendor-agnostic reference architecture that security leaders can use to answer four key questions:
- Where are my agents?
- What can they do?
- What are they doing?
- How do I respond?
The alliance is not proscriptive in what technologies need to be deployed; that would have blown up any industry-wide collaboration, given competing agendas. It does provide a useful framework for security leaders to understand what they need, determine how pieces fit together and identify potential gaps in what they already have.
Single sign-on for AI agents with XAA
Okta highlighted the XAA protocol in the form of its Agent SSO offering. Agent SSO, now generally available, streamlines the use of "on behalf of" agents so users do not have to repeatedly click through consent screens. It does this by standardizing how agents request permissions by querying an identity provider for predefined policies.
Agent SSO is underpinned by XAA, an OAuth-based protocol designed to provide centralized security for AI agents and app-to-app connections. Standards are part of Okta's DNA, and Okta helped to drive the XAA standard to fruition. Agent SSO is the productization of the XAA protocol and is available at no cost to Okta customers.
Agent Gateway for agent control
Okta for AI Agents treats AI agents as first-class identities alongside human and nonhuman identities. One enterprise challenge lies in discovering AI agents, both sanctioned and unsanctioned -- also known as shadow AI. Okta provides a holistic platform to provide visibility: agent discovery and inventory of agents across the enterprise, including endpoints and the cloud.
The endpoint agent discovery happens via an endpoint detection and response (EDR) integration with CrowdStrike Falcon (GA Q3 2026) as well as Okta Verify (GA Q4 2026). The network discovery using secure access service edge in conjunction with Zscaler arrives in Q1 2027 with Palo Alto Networks Panorama and Netskope after that. While agent discovery gaps need to be filled -- additional EDRs, unmanaged endpoints, thorough SaaS agent discovery -- this is a comprehensive approach.
A key element in the platform is the Okta Agent Gateway, which is currently generally available. This gateway provides authentication and observability to AI agents so enterprises can govern agent access at the tool level and deactivate access as necessary at the gateway. The gateway is a linchpin for secure AI agent deployment with additional enhancements, such as XAA-compatible MCP server support by the end of the year. Given the criticality of gateways in ensuring secure AI agent deployments, gateways will be a key space to watch.
While the above elements were some key pieces, Oktane had updates across the portfolio -- Okta Integration Network, Identity Governance, Privileged Access Management and Identity Threat Detection and Response -- following the Okta acquisition of identity threat detection and response player Permiso Security.
AI agent gateways galore
One space to watch is the evolution of AI agent gateways. Gateways provide an essential control point for intercepting, inspecting and authorizing agent actions in real time as agents execute tasks. The Blueprint Alliance architecture lays out seven different areas for gateways to monitor -- and I would not be surprised if more get added, given the fluid state of AI agent security.
Having a proliferation of gateways will be problematic across multiple dimensions: It makes IT operations more complex, performance can lag, policy administration across gateways can be painful, security gaps can emerge and gateway costs can skyrocket as they proliferate. And there's the additional complexity of gateways across the hyperscalers -- AWS, GCP, Azure -- along with various security vendor gateways.
Gateways will combine multiple things, and users can expect to see API integrations to mitigate gateway proliferation. For example, a gateway can be a policy enforcement point, while the policy decision point is outside of the gateway. This approach helps control against a potentially painful proliferation of AI gateways in the enterprise.
IdPs and identity resilience: A space to watch
Identity resilience focuses on the protection and operational state of identity providers (IdPs). Omdia research found that 42% of enterprises had multiple IdPs, and uptime is essential across the entire IdP estate. When incidents crop up, a simple copy is not enough. Identity and IT operations teams need to understand what has been changed or affected, what needs to be restored, and, if necessary, what to switch over. If you are an identity leader, you probably already have some solution in place for Active Directory resilience for ransomware threats from a vendor like Semperis, Cayosoft or Quest. Something to consider is how you ensure resilience for your cloud identity provider.
Resilience becomes imperative when you consider the criticality of cloud IdP to your operations and the risk of administrator error (fat-fingering an IdP configuration and needing to roll back accidental changes) or protecting against system-based drift (HR system drift, AI drift, etc.). This is about more than IdP uptime.
Focused identity resilience vendors -- such as Semperis, Cayosoft, Backupta and Acsense -- offer products and services, and the established data resilience players like Cohesity, Commvault, Druva, Rubrik and Veeam are adding identity resilience to their offerings as well. Identity resilience is integral to cyber resilience: Teams need to mitigate the risk of IdP outages to maintain enterprise operations.
Identity security for the agentic enterprise
A major theme of the event was that Okta is delivering the key identity security technologies so enterprises can safely deploy, manage and govern AI agents. To a significant degree, this is the year of AI agent pilot projects, with 2027 seeing a wave of production deployments. Enterprises are eager for the promised efficiency and speed of AI agents but want to deploy securely. And they do not want to put a project at risk by depending on a vendor's future roadmap item.
The bulk of the technologies Okta highlighted at Oktane are available now or will be before the end of the year. Omdia research showed that AI agents are a high or top priority for 82% of enterprises, and Okta's current portfolio can help organizations deliver identity security for their AI agent initiatives.
Todd Thiemann is a principal analyst covering identity and access management and data security for Omdia. He has more than 20 years of experience in cybersecurity marketing and strategy.
Omdia is a division of Informa TechTarget. Its analysts have business relationships with technology vendors.