Securing ADT’s 12k+ Employees from Modern Identity Threats with Okta

Vidyard video
12k+

employees securely managed across more than 150 locations with Okta

1

single pane of glass for identity

Vidyard video

“ISPM provides a single pane of glass where I can see all of the things we need to remediate, helping us prioritize vulnerabilities so we can stay ahead of risks and keep people safe.”

Tim Rains,

CISO, ADT

For more than 152 years, ADT has operated with a clear mission to help protect people, homes, and businesses when seconds matter most. In a connected world, physical protection is inseparable from cybersecurity. As life-safety technology connects with mobile apps, smart devices, and digital platforms, customer protection extends far beyond physical boundaries. Securing these modern connections required ADT to adapt its defense strategy to protect an expanding digital environment. 

At the heart of that defense is a distributed workforce of more than 12,000 employees across 150 locations, where scale introduces operational complexity for any security team. This large footprint of users, devices, and applications also represents the potential for a vast attack surface, making ADT's employees targets of social engineering, credential theft, and modern phishing attacks.

To simplify management and reduce this attack surface, ADT chose to build its defense strategy around a unified identity platform. "Complexity is the enemy of good in cybersecurity," explains Tim Rains, VP and Chief Information Security Officer. "A single pane of glass approach is the only way we can move fast and stop attackers at scale. We chose Okta Workforce Identity because it scales seamlessly, detects and contains threats quickly, and provides a partner that we can rely on."

Safeguarding access with phishing-resistant protection

To defend against modern credential attacks, ADT prioritized eliminating passwords wherever possible across the employee journey. The team protected access to the applications employees use every day by deploying Single Sign-On (SSO) and phishing-resistant Multi-Factor Authentication (MFA). This ensures that even if a threat actor steals valid credentials, they cannot be used to gain access. “If you’re going to introduce an authentication step, you want to do it right and do it once,” says Rains. “Using MFA protects all the applications our teams use daily, and that has been a game changer for us.”

The team then took the next step to secure its physical hardware. "Okta Device Access is helping us secure Windows-based devices on our network," says Rains.  By extending identity and access management directly to the desktop sign-in screen, Okta Device Access ensures protection begins at the first vulnerable touchpoint of the workday. Deploying this alongside FastPass across key user populations enabled ADT to create a unified, passwordless login experience that protects the entire access journey, from the device to the application, under a single, consistent identity policy.

Unifying posture management, real-time threat protection, and governance

Across its hybrid enterprise, ADT needed to identify and address identity risk before, during, and after authentication. By combining Identity Security Posture Management (ISPM) with Identity Threat Protection (ITP), ADT achieved continuous defense as part of a unified identity security fabric.

ISPM serves as ADT’s continuous security baseline, scanning the enterprise to identify and remediate hidden posture gaps, such as missing MFA or stale accounts, before attackers can exploit them. As users interact with systems, ITP continuously monitors current and historical session telemetry to detect suspicious behavior, session hijacking, or risky logins.

"The combination of ITP and ISPM gives me so much confidence that we are paying attention to the right signals," Rains shares. ”ISPM provides a single pane of glass where I can see what we need to remediate, helping us prioritize vulnerabilities so we can stay ahead of risks and keep people safe."

That visibility also helps ADT strengthen governance across the entire identity lifecycle. By pairing posture insights with automated lifecycle management via Okta Identity Governance (OIG), ADT streamlines account provisioning and deprovisioning while providing the framework for conducting access reviews, reducing administrative burden, and freeing up security personnel's capacity.

"We used to spend a lot of time provisioning and deprovisioning accounts," Rains explains. "With Okta-based policies automating those tasks, our SOC analysts no longer have to stare at screens. We can reallocate that labor to do proactive work, knowing that Okta has our back."

Future-proofing identity through continuous agentic security

With its identity architecture modernized on Okta, ADT has the foundation it needs to move forward and embrace the future of AI. As the company prepares to scale its use of autonomous agents, the team recognizes that human and non-human identities should be managed with the same rigor.

This requires a unified agentic control plane to manage permissions, enforce least-privilege access, and maintain full observability over agent activity. By establishing this framework now, ADT is taking the necessary steps to ensure every agent it deploys is secure by design and secure by default, protecting the brand trust it has earned over more than a century. Scaling AI safely starts with getting identity right," Rains notes. "For us, Okta is that trusted foundation."

About Customer

ADT is a leading provider of security, interactive and smart home solutions serving residential and small business customers in the U.S. Through innovative offerings, unrivaled safety and a premium customer experience delivered by the largest network of smart home security professionals in the U.S., ADT empowers people to protect and connect to what matters most, every second, every day. For more information, visit ADT.com.

Continue your Identity journey