Executive summary:
Identity Threat Protection (ITP) for Okta Customer Identity is now Generally Available (GA). ITP delivers continuous, real-time security across the customer journey by detecting and mitigating threats before login, during login, and across active user sessions.
Customer trust takes years to build and only seconds to lose. Today, sophisticated attacks, from AI-driven bots creating fake accounts to silent session hijacking, are putting customer data and brand reputations at unprecedented risk.
Back in February, we introduced Early Access to Identity Threat Protection (ITP) for Okta Customer Identity, shifting the paradigm from point-in-time authentication to continuous, end-to-end security.
Today, we are thrilled to announce that Identity Threat Protection for Okta Customer Identity is officially Generally Available (GA)!
With this GA release, organizations can now deploy continuous, real-time threat detection and response directly into their production environments, protecting customer accounts and business revenue without adding friction for legitimate users.
See Identity Threat Protection in action
In customer identity and access management (CIAM), every millisecond of friction matters. You need security that runs continuously behind the scenes, stepping in only when it detects real risk.
What does that look like in practice? Watch our new demo to see how ITP for Okta Customer Identity detects threats across the user session and automates response in real time:
Key security capabilities across the customer journey
Whether you are protecting a high-traffic retail drop, securing loyalty rewards, or scaling an enterprise digital platform, ITP for Okta Customer Identity delivers end-to-end security across three critical login stages:
Pre-login stage: Automated bot mitigation
Shield your digital apps before automated attacks reach your user database. Using AI-powered detection, IP reputation, and behavioral signals, ITP blocks bad bots and scripted sign-ups used for promo abuse and credential stuffing. This keeps your user database clean and helps make sure growth metrics reflect real human customers.
Login stage: Breached credential protection
With Enhanced Breached Credentials Protection, Okta detects if a user attempts to log in using stolen or compromised credentials. If Okta detects compromised credentials, it blocks the attempt or triggers immediate credential resets, preventing large-scale account takeovers (ATO) and reducing support ticket overhead.
Post-login stage: Continuous session hijacking prevention
Security shouldn't stop after the user authenticates. ITP for Okta Customer Identity continuously monitors active sessions for context changes and threats like impossible travel. If session theft or suspicious behavior occurs post-login, ITP triggers automated remediation to kill compromised sessions across all connected applications simultaneously.
Build a safer customer journey
Session-based threats thrive in disconnected systems. Download our whitepaper Unlock the power and potential of unified identity to learn how to avoid the risks of identity fragmentation and discover the true value of an identity-first approach.
Okta Customer Identity is your low-code, high-security solution for building effortless customer experiences. With thousands of pre-built integrations, this all-in-one platform centralizes authentication and authorization across your entire ecosystem so you can seamlessly defend against fraud and identity attacks.
Ready to discuss how to unify your customer identity strategy? Contact us to learn more.
These materials are intended for general informational purposes only and are not intended to be legal, privacy, security, compliance, or business advice. © 2026 Okta, Inc. and/or its affiliates.