From phishing to AI agents: Solving the authorization crisis

From phishing to AI agents: Solving the authorization crisis

Attackers aren't just bypassing MFA – they're stealing sessions and exploiting agent and app-to-app trust using sophisticated consent phishing. In this session, we’ll break down how OAuth abuse enables data exfiltration even in well-defended environments and why today’s fragmented app-to-app authorization models are no match for agentic AI and modern phishing.

Key Takeaways:

  • Solving authorization from IdP: Get insights into how securing OAuth connections starts with authentication policies at the Identity Provider (IdP) layer.
  • Maintaining visibility and control: See how Okta Cross App Access restores visibility and control of the app ecosystem for IT and security teams.
  • Practical security approaches: Learn from real-life customer use cases to secure app-to-app or agent-to-app connections.
  • Phishing-resistant authentication: Understand how solutions like Okta FastPass can directly mitigate emerging risks from modern phishing tactics.

 

Speakers

Brett Winterford, Vice President, Okta Threat Intelligence, Okta

Jen Vaccaro, Sr. Manager, Product Marketing, Okta

Patricia Voight , CISO & Head of Tech Risk, Webster Bank