Go Pro

Okta Unveils AI Agent Security Blueprint Alliance at Oktane

Okta logo with Technology background
Image from MarketBeat Media, LLC.

Key Points

  • Okta launched a Blueprint Alliance with AWS, CrowdStrike and Salesforce to establish common standards for securing AI agents, including unique identities, least-privilege access, runtime monitoring and emergency “kill switches.”
  • Okta expanded Agent SSO through the open Cross App Access standard, allowing agents to securely connect to multiple enterprise applications without repeated user logins and consent prompts.
  • Okta for AI Agents is generally available with new capabilities such as agent discovery, an Agent Gateway for controlling MCP connections and support for third-party identity providers. Okta said customers including Dell, Yahoo and Ramp are deploying the technology.
  • Five stocks to consider instead of Okta.

Okta NASDAQ: OKTA outlined its strategy for securing artificial intelligence agents at its Oktane event, introducing an industry “Blueprint Alliance,” expanding its Agent SSO standardization efforts and highlighting the generally available Okta for AI Agents platform.

The company said AI agents can improve efficiency and create new capabilities, but their growing access to enterprise systems also creates security and governance risks. Okta’s keynote speaker argued that enterprises need “visibility and control” to avoid choosing between locking down AI systems and allowing them broad, unmanaged access.

Blueprint Alliance Targets Agent Security

Okta said it has formed a Blueprint Alliance with technology companies including AWS, CrowdStrike and Salesforce to address what it described as market confusion around AI-agent security. The alliance’s framework centers on four questions:

  • Where are an organization’s agents?
  • What can they do?
  • What are they actually doing?
  • How should an organization respond when something goes wrong?

The blueprint calls for an agent registry that assigns unique identities, access governance to ensure agents retain only appropriate permissions, runtime monitoring and observability, and response capabilities such as a “kill switch” to disconnect an agent. It also includes common risk signals and standardized formats for sharing telemetry across participating technologies.

Chet Kapoor, vice president at Amazon, said AI agents differ from traditional software because they are probabilistic rather than deterministic. He said organizations need controls that let them deploy agents at speed without relying on additional manual reviews and approval gates.

Kapoor said enterprises should verify each agent’s identity and owner, use task-scoped access, monitor and trace activity in real time, and contain an agent without affecting the rest of the environment. He also described the blueprint as a way to avoid vendor lock-in as customers use agents from cloud providers, software vendors and their own internal development teams.

Agent SSO and Cross App Access

Okta also presented Agent SSO, which it said is available at no additional charge across its products. The capability is designed to allow AI agents to access enterprise resources without requiring users to repeatedly enter credentials and approve individual consent prompts.

During a demonstration, Mallory Sword Glenn, Okta’s director of product marketing, showed an AI workflow that needed access to Atlassian, GitHub and Slack. Without Agent SSO, the workflow required separate logins and approvals for each application. With Agent SSO, she said, the AI system was already connected to those resources after the user signed in through Okta FastPass.

Okta said Agent SSO is based on an open standard called Cross App Access. Rather than relying on a conventional OAuth consent flow for each connection, Cross App Access allows an enterprise identity provider to supply a predefined authorization policy for the agent.

David Soria Parra, a member of the technical staff at Anthropic and a co-creator of the Model Context Protocol, or MCP, said open standards give enterprises choice and enable the industry to build secure agent infrastructure together. He said enterprise-managed authorization can shift security decisions from end-user consent screens to IT administrators while maintaining a smoother user experience.

Okta said Claude now supports Cross App Access with Okta as its first identity provider. The company encouraged other software vendors and identity providers to adopt the protocol.

Okta for AI Agents Expands

Okta said its flagship Okta for AI Agents product has been generally available since April. The platform is intended to provide the identity-related components of the broader agent-security blueprint, including unique agent identities, ownership, access controls and runtime governance.

The company said it has released 25 major features since April. Among the highlighted additions were Shadow AI Agent Discovery for Endpoints, Agent Gateway and support for third-party identity providers.

Harish Peri, Okta’s senior vice president and general manager for AI security, said each agent is treated as a “unique first-class identity” in Okta’s Universal Directory, rather than as a user or service account. He said the platform can identify agents across environments including endpoints, AWS, Salesforce, browsers and unapproved MCP servers.

Peri demonstrated how Okta’s Identity Security Posture Management capabilities could discover an unregistered endpoint agent and MCP server, register them in Universal Directory and map the agent’s connections to resources. He said the system is designed to provide traceability across a chain involving a user, agent, sub-agent, MCP server and resource.

Okta’s Agent Gateway acts as a centralized control point for MCP server connections, according to the presentation. Sword Glenn said it can apply granular policy to agent tool calls, log activity in real time and block access when an agent attempts an unauthorized action. In the demonstration, a sales agent was prevented from sending Salesforce-derived account information to a personal email address, and its Salesforce connection was severed.

Okta also said its platform now supports organizations that use another identity provider for human identities while using Okta for AI agent identities. The company said it is also supporting customer-facing agentic commerce through Auth0 for the Universal Commerce Protocol, which is intended to allow AI systems such as Gemini to interact with participating e-commerce services.

Customers Discuss Agent Deployments

Okta cited deployments at Ramp, Yahoo and Dell Technologies. The company said Ramp uses an internal AI agent called Glass for employee productivity, while Yahoo uses Okta for AI Agents to broker connections between an internal software-engineering agent system and virtual MCP servers.

Dell Technologies CIO and President Doug Schmitt said Dell began digitizing processes years ago and later built AI platforms focused on supply chain, direct sales, services and research and development. He said agent identities and observability became necessary as Dell sought to track where agents were used, what they were doing and who was using them.

Schmitt said AI adoption is more than a technology shift and should be led across the company rather than solely by IT. “Business models are changing,” he said, adding that the pace of change continues to accelerate.

Okta said it uses an internal AI agent called Dex to connect to internal systems and automate operational work. The company said it expects Dex to save 250,000 hours this year. It also said capabilities shown in its demonstrations are either currently available or expected to be available by January.

About Okta (NASDAQ:OKTA)

Okta, Inc provides cloud-based identity and access management solutions for organizations. Its platform helps businesses securely connect employees, customers, partners and applications while managing authentication, authorization and user access across cloud, on-premises and mobile environments.

The company's offerings include single sign-on, multifactor authentication, adaptive access controls, lifecycle management, identity governance and privileged access capabilities. Through its Customer Identity Cloud, powered by Auth0, Okta also provides tools for developers and businesses to embed authentication and authorization features into applications and digital services.

Founded in 2009 by Todd McKinnon and Frederic Kerrest, Okta completed its initial public offering in 2017.

This instant news alert was generated by narrative science technology and financial data from MarketBeat in order to provide readers with the fastest reporting and unbiased coverage. Please send any questions or comments about this story to contact@marketbeat.com.

Should You Invest $1,000 in Okta Right Now?

Before you consider Okta, you'll want to hear this.

MarketBeat keeps track of Wall Street's top-rated and best performing research analysts and the stocks they recommend to their clients on a daily basis. MarketBeat has identified the five stocks that top analysts are quietly whispering to their clients to buy now before the broader market catches on... and Okta wasn't on the list.

While Okta currently has a Moderate Buy rating among analysts, top-rated analysts believe these five stocks are better buys.

View The Five Stocks Here

7 Blue-Chip Stocks to Add To Your Forever Portfolio Cover

A strong long-term portfolio starts with companies that can survive recessions, inflation, changing consumer habits, and shifting market leadership.

This report names seven blue-chip stocks across technology, retail, consumer staples, healthcare, networking, sporting goods, and utilities that offer investors a mix of stability, income, growth, and staying power.

Get This Free Report
Continue following MarketBeat
Add MarketBeat as your preferred source on Google to see our latest stories in your feed.
Like this article? Share it with a colleague.

Featured Articles and Offers

Recent Videos

Stock Lists

All Stock Lists

Investing Tools

Calendars and Tools

Search Headlines