New Okta innovations close governance blind spots and extend zero standing privilege to secure the agentic enterprise

Okta expands its independent and neutral identity security fabric with new capabilities across governance, PAM, and ITDR that let businesses secure human, AI agent, and other non-human identities.

Acerca de Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

09 septiembre 2026 Tiempo de lectura: ~

Today, Okta is announcing a series of new innovations across Okta Identity Governance (OIG) and Okta Privileged Access (OPA), along with expanded identity threat detection and response capabilities from Permiso Security. Now CIOs, CISOs, and AI leaders can automate compliance, reduce standing privileges, and enable real-time control of identities across their organization—accelerating AI adoption without compromising security.

Static permissions and traditional credential vaults leave critical gaps that attackers routinely exploit via humans, service accounts, and autonomous workflows. These gaps widen as approvals get rubber-stamped and reviews fall behind. Real-time, automated access decisions can give security teams continuous control, while letting the broader business implement AI quickly and securely.

“Nobody wants to slow AI down, but you can’t simply hand out access and hope for the best,” said Ely Kahn, Chief Product Officer, Okta. “Enterprises need a one-stop shop to govern, secure, and monitor every identity: humans, AI agents, and non-human workloads alike. By bringing governance, privileged access management, and threat detection together on a single, independent platform, we’re giving security leaders dynamic, real-time control and turning zero standing privilege from a theoretical goal into an everyday operational reality.”

Governing identity at enterprise scale

As cloud adoption accelerates, managing access has become a major bottleneck and security risk. Manual reviews, complex permission overlaps, and approval backlogs force organizations into an unsustainable trade-off between business agility and compliance.

A unified approach changes the equation: a study by Forrester Consulting found that Okta's unified platform enables customers to onboard new apps 75% faster and achieve an overall ROI of 216%, demonstrating that strong governance helps drive business velocity rather than slowing it down.

New innovations coming soon in Okta Identity Governance deliver automated, context-driven control to reduce operational burdens:

  • Advanced Entitlement Management for AWS: Centralize fine-grained permission tracking across developers, workloads, and AI agents, letting engineering teams ship code faster while maintaining separation of duties. 

  • Intelligent Request Recommendations: Get AI-powered intelligent insights backed by request history, usage patterns, and resource sensitivity data to access request approvers. These insights can help automate low-risk access requests, reduce approval fatigue, and flag anomalies for human review.

  • Automated Drift Detection & Remediation: Quickly identify unapproved access changes and revoke rogue permissions in real time, shifting from intermittent compliance audits to continuous containment.

To extend governance across the full ecosystem, Okta is also introducing 48-Hour Integrations. Building on Okta’s catalog of more than 8,000 pre-built integrations, Okta now leverages AI to deliver new integrations for governance, privileged access, and beyond in as little as 48 hours (down from a manual process that took two to three months), enabling teams to rapidly unify and govern access for people, machines, and AI agents in one place.

“We’ve been able to automate most of our access campaign work with Okta Identity Governance. It now takes one of us a day of work instead of two of us spending a full month of our time,” said Ashley Taylor, IT Security Analyst at Instructure. 

Reducing risk with zero standing privilege

Governance ensures organizations know exactly who should have access, but when that access touches an enterprise's critical infrastructure—from cloud databases to network hardware—standing privilege becomes a liability. Today, credential abuse accounts for 39% of all breaches, meaning attackers aren’t breaking in; they’re logging in. 

Anchored in the same identity fabric that governs access decisions, Okta Privileged Access closes that gap by verifying access does not outlive its purpose. New features expand and enforce just-in-time access across humans, workloads, and AI agents:

  • Unified Database Security: Centralizes policy enforcement across servers, SaaS accounts, and Active Directory, reducing credential sprawl and automatically vaulting and rotating database secrets to protect sensitive data against breaches.

  • Dynamic Kubernetes Protection: Teams running autoscaling apps no longer need to hardcode service account tokens or manually rotate secrets when a pod spins up, reducing long-lived credentials as businesses scale.

  • Network Device Coverage: Extends coverage to historically isolated assets like routers, firewalls, and switches, closing forgotten backdoors and audit nightmares.

  • Machine-Speed Workload Protection: Authorizes automated identities, CI/CD pipelines, and AI agents at machine speed to retrieve vaulted credentials securely without slowing down automation, verifying each action is traced back to the accountable human.

Inside the innovations: advancing identity threat detection 

Beyond governing and securing access, organizations also need to detect and respond to identity risk as it emerges. Following Okta's recent acquisition of Permiso Security, Okta is broadening and deepening its existing identity threat detection and response capabilities. 

Permiso brings identity risk signals, behavioral analytics, and threat-informed detections across multiple identity providers, cloud environments, and SaaS applications. Together, Okta and Permiso will help organizations discover, monitor, and respond to identity threats across human, non-human, and AI identities.

Discover how Okta is powering continuous governance and zero standing privilege. Join us at Oktane from September 23–24, or watch online to learn more. 

Availability

All OIG capabilities are planned to be available in early access by Q4.

All OPA capabilities are planned to be generally available by Q1.

Any mention in this article of solutions, features, functionalities, certifications, authorizations, or attestations that are not currently generally available or have not yet been obtained may not be delivered or obtained on time or at all. We assume no obligation to deliver on such items and you should not rely on them to make your purchase decisions.

Acerca de Okta

Okta

Okta, Inc. is The World’s Identity Company™. We secure AI, machine, and human identity so everyone is free to safely use any technology. Our customer and workforce solutions empower businesses and developers to protect their AI agents, users, employees, and partners while driving security, efficiencies, and innovation. Learn why the world’s leading brands trust Okta for authentication, authorization, and more at okta.com.

Get our Identity newsletter