Enterprises now manage identities that span employees, partners, customers, workloads, and emerging AI agents, each with different risk profiles and lifecycle demands. Disconnected governance, access, and threat-detection tools make it difficult to enforce policy consistently or respond to attacks quickly. An identity security fabric provides a unified architectural layer that centralizes visibility, standardizes controls, and automates responses across every identity and system.
Alejandro Leal, Senior Analyst at KuppingerCole will outline the market forces reshaping identity security, explain why siloed architectures persist, and highlight strategies for consolidating identity layers. He will share guidance from recent research and show how coordinated detection and response strengthen enterprise resilience across diverse systems and environments.
Arkadiusz Krowczynski, Principal Product Acceleration Specialist at Okta will demonstrate how to operationalize an identity security fabric using Okta’s platform, showcasing orchestration-driven response automation and protection before, during, and after authentication. He will address securing AI agents, reduce misconfigurations, and achieving unified visibility across cloud, on-premises, and hybrid ecosystems.
Hello, everyone. Welcome to the webinar, Creating a Unified View of Identity Risk. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole. And today I'm here sharing the stage with Arkadiusz Krowczynski.
Hey, Arkadiusz, how are you? Thanks, Safar. Awesome. Thank you for joining me today. I will be setting the stage for this webinar for the next 20 minutes, and then Arkadiusz will join, and then he will go deeper into the topic, and then we'll have some time for Q&A. So if you have any question at any time, just feel free to enter the questions in the panel. So just a few rules here. All of you are muted centrally, so there's no need to mute or unmute yourself. Another thing to consider is that we will be conducting a couple of poll questions, so feel free to answer those.
And as I said, we will do Q&A at the end, so drop questions in the control panel anytime. We will also be recording, and the recording and the slides, they will be shared on the website in a couple of days. So let's just begin, because there's a lot of things to talk about today. So as I said, I will begin, then I will give the floor to Arkadiusz, and then we'll have time for Q&A.
But first, the first poll question, do you already have a comprehensive understanding of identity? Do you already have a comprehensive identity fabrics in place?
So now, let's start with a simple but, let's say, consequential observation, which is, as we all know, many of us that have been in the identity industry for some time, we know that identity has moved to the center of enterprise security, not only as an enabler or as a supporting layer, but as the through which access, trust, and risk are now mediated. At the same time, identity has become the attacker's preferred entry point. So this is not a coincidence.
Cloud, SaaS, and distributed architectures have reduced the relevance of static network boundaries. So security enforcement has shifted upward from infrastructure to identity-driven decisions. We could say that every meaningful action in modern IT should be identity-mediated. So who is requesting access, from where, under which conditions, and what level of privilege. And attackers are also catching up. They have adapted accordingly. So instead of exploiting vulnerabilities in software, they increasingly exploit trust relationships embedded in identity systems.
So this dual role, identity as a both control plane and attack ventor, it creates tension. If identity fails, security fails. If identity is fragmented, security becomes inconsistent. And if identity risk is invisible, and we don't have the visibility of what's going on, response becomes reactive by definition. So the rest of this session will build on this premise. If identity is a control plane, then security architecture detection and response must be designed around identity, not bolted onto it.
So if we look at today's threat landscape, I mean, we see the news and there's always something going on. And when we examine real world incidents, identity appears early and persistently in the attack chain. So you could say that identity is now the dominant initial access vector, whether through compromised credentials, session hijacking, MFA fatigue, token abuse, misused service accounts, credentials are no longer the only target. Trust itself is. So we also see a structural shift. So privilege abuse increasingly replaces technical exploitation.
So once access is obtained, attackers just move laterally by abusing entitlements, roles, and delegated permissions. And in many cases, often without triggering traditional alerts. And fragmentation is also making things more complicated.
So IAM, PAM, IGA access management tools, they often operate in silos with limited shared context. Each sees part of the picture, but none of them see the whole picture. And at the same time, the attack surface is expanding.
NHIs, including workloads, APIs, automation, and now AI agents, often outnumber human users, and yet they receive far less governance mechanisms and monitoring. And we know that in this industry, speed matters. Automation often favors the attackers, who can act faster and much faster than manual controls and ticket-driven processes.
So, you know, attackers don't simply deploy malware anymore. They just log in using valid credentials. So we look at this threat landscape, the environment demands a different approach, one that is centered on continuous identity risk visibility, rather than just pure static controls. So aside from the things that I just mentioned, there's also some of the market forces that are reshaping identity security. So first is the explosion of identity types.
Enterprises today now manage workforces, partners, customers, workload, services, AI-driven actors simultaneously, and each of them have distinct characteristics and risk. Second, many organizations have tool sprawl and identity silos. And since many of these organizations have these identity silos, over time, organizations have layered PAM, IGA, access management, and detection tools, often acquired independently. And that results, as I mentioned in the previous slide, in partial visibility, but it doesn't show that consistent policy enforcement.
Third, there's now demand for unified identity architectures. So enterprises are not looking to replace everything. They want integration, they want orchestration, and they want shared intelligence across their existing environments. And finally, as it's probably clear by now, identity has become the security enforcement point in zero-trust environments. So this is where the concept of the identity fabric becomes relevant and useful. The identity fabric is not a product and not a replacement strategy.
It's an architectural model for unifying identity capabilities across domains, tools, and identity types. And at the core, the the fabric provides shared services. So identity repositories, authentication, authorization, analytics, and integrations exposed consistently across all your digital services and SaaS environments. And it spans and covers both human and non-human identities from employees and partners and workloads and all of the things that you have.
It's supposed to connect identity governance and access management and PAM and detection through common APIs, common connectors and data models. And crucially, the fabric enables identity to operate as a platform rather than simply a collection of different tools. It should allow policy context and risk signals to be reused across different use cases. So this architectural perspective is essential if identity is to function as a true control plane rather than a set of disconnected tools.
But for most organizations today, and I'm sure Arkadius will probably talk more about it given that he has experience with end users and with what organizations are demanding today, most IAM environments today fall short of that identity fabric division. What we typically see is a collection of specialized tools, each with its own connectors, data models, and operational processes.
Of course, integration exists, but it's often brittle with custom build and expensive to maintain. So we see visibility gaps emerging precisely at the boundaries of these different tools, and that's where attacks often unfold. So in practice, this means that identity risk is detected late, it's investigated in isolation, and it's mitigated inconsistently. This is not only tooling fatigue, it's architectural limitation.
And if we try to enter this zero trust journey, these identity fabrics is quite important because, as we know, zero trust has become the dominant security paradigm, but it is often misunderstood. There's a lot of hype around it, we see a lot of products saying we are zero trust solutions, the latest in the market, so there's a lot of marketing around this term. And it's important to remember that zero trust is not about denying access, but it's about continuous verification across identity devices, services, applications, data, and software. And identity sits at the start of the chain.
Every zero trust decision begins with who or what is requesting access and under which conditions. But zero trust cannot function with static identity controls, it requires a more dynamic context, shared signals, and adaptive enforcement approach. So without a unified identity layer, zero trust becomes fragmented. I would say that identity is not just one pillar of zero trust, but it's the connective tissue that makes the model operational. So how can we close those gaps? Closing these gaps requires shifting from authentication-centric thinking to more of an identity insight thinking.
We know that hybrid environments demand consistent identity decisions across on-prem and cloud. Signals must flow between IAM, endpoint, and sub-platforms. And this is where ITDR plays a critical role. It's supposed to be this connective layer that connects identity events with security telemetry and response workloads. It's supposed to bridge the gap between identity teams and security teams. And in that context, the human endpoint becomes a continuous signal source, not a one-time authentication event.
So when identity data is shared and contextualized, response becomes faster, more precise, and less disruptive. So quickly, what is ITDR and what does it do? It's not just another detection tool, it focuses on identity-specific attack techniques such as anomalous behavior, credential abuse, privilege escalation, and misuse of trust relationships. ITDR is supposed to correlate events across identity systems, visualize the attack paths, and support both manual and automated responses, such as terminating a session or blocking, disabling an account, or enforcing step-up authentication.
So when integrated properly, ITDR bridges IAM and the SOC rather than operating alongside them. A practical ITDR capability starts with telemetry. So it's not just about, you know, collect logs, but you need identity-aware collection analysis across AD, EnterID, IDAS, SaaS applications, identity, microservices, and ideally signals from endpoints. But many organizations assume, oh, we have SIM, we are already covered, we also have SOAR. But the question is, is everything plugged in? Is it identity-aware? Can it correlate identity events across thousands of apps? So that's the question.
And that's why ITDR is where identity detection meets identity control with response built-in. I know that Arkadiusz will talk more about the signal-shared framework, but here's just a quick glance to get an idea that signals are, in a way, the mechanism that makes identity-centric security adaptive. These signals represent discrete actionable events, changes in risk posture that can be shared across systems in real time. So if we look at standards like CAEP and SSF, these are enabling signals to propagate between identity providers, detection engines, and access systems.
And this allows security decisions to be continuously updated as the context changes without any manual intervention. In a way, signals turn identity from a static control into a dynamic participant in security operations. So how do we see, at Kupinger Coal, the future of identity fabrics and this identity risk framework? There's a very good webinar by Martin Kupinger on this topic, so I encourage you to to check it out. But before going into this slide, quickly, the 2040 framing is justified with this equation.
So I know that we're in 2026, but it requires, in today's world, sort of requires two years of planning on how to make that transition. It then takes three years of implementation plus 10 years of usage, which takes us to 2040, or I guess 2041 by now.
But the core message is that identity and access management investments are long-lived, and therefore today's architectural choices must both address immediate needs and remain viable for the next 15 years, because innovation and disruption are inevitable, but organizations must design for change readiness, not just optimization of the current stack. So, well, there you go. But going back to this slide, for the 2040s, Kupinger Coal describes a full mesh fabric.
So modular services orchestrated flexibly with orchestration and centralized authorization at the core, and likely AI becoming a core element. A key design stance is to avoid treating data centralization as the goal.
Instead, signals and flows should be a priority over building one monolithic identity data model. So a good analogy that Martin uses, security telemetry pipelines. So rather than funneling everything into a single seam, architectures increasingly rely on streaming signals. So we expect identity fabrics to follow a similar pattern, signals flowing into and out of the fabric, signal exchange, enabling adaptive access and entitlement decisions, and connector reuse across different components.
And that is the ultimate objective, to manage risk with the same rigor, visibility, and responsiveness that we expect in every other domain in cybersecurity. So before wrapping up and giving the floor to Arkadius, one more poll question. So how is your identity and access management infrastructure implemented? What is the approach that you have today? Is it a converged approach, or do you have orchestration with multiple tools, or are you also struggling with loosely coupled uncoupled tools? So now Arkadius, the floor is yours now.
So yeah, thanks again, Alejandro. That was a really insightful look at a strategy.
And yeah, we are super happy and excited to be here today. And I appreciate each and every one of you taking time off of your busy schedules to experience this webinar today. And let's start by taking a unified view of identity risk from Okta's perspective.
Yeah, let's talk about that. Okay, my name is Arkadius Kopczynski. I'm part of the product organization here at Okta and work as a principal product exploration specialist here. So some safe harbor, you know, please make only purchase decision, what's available in the product today, and talking about future state products. So first of all, Okta is the world's identity company, and our mission is really for everyone to safely use any technology.
Last year, we talked about our journey to become one of the most secure companies on earth. And this year, we want to share what we've learned about how the most secure companies innovate with an identity security fabric, and also how they innovate with AI. And for us, this means building everything on a foundation of security that you can trust. So let's start with some stats here. These ones really paint a symbolic picture. So more than 80% of all breaches stem from some sort of identity attacks. And we are not talking about this basic user password, a sprawl or different mechanisms.
So all the different billion session cookies that were extra filters from darknet where bad actors are literally moving your networks without an alarming ease. And on average, it really takes around 300 days to not only identify, but also to contain a breach. So that's really 10 months of potential exposure. And the overall we see a three time increase in breaches year over year. And three out of four, these breaches are identity based.
And yeah, I think as I'm no longer breaking in, they are logging in. So protecting identity must be our top priority as Alejandro mentioned.
And yeah, you are you wondering why all of this is happening. So it's super simple. It's a complexity, right? As we heard in the beginning, just look at everything we are trying to protect today, right? So it's no longer just employees accessing a kind of on-premise server. So we have a massive explosion in identities. We have the partners, we have the contractors, customers, and critically non-human identity like service accounts and nowadays AI agents, right?
So they're accessing every resource and manageable like infrastructure as a service platform like AWS and Azure to legacy on-premise application. And this kind of support really creates silos and different teams manage different identity types with different point solutions. And in those gaps is where all the attackers strive and the fragmentation expands the whole attack surface. And many of you know this because we've been saying it for many, many years. So to get security right, you really have to get identity right.
And now with the AI, that is the biggest platform shift since the internet, you really can't be successful in one without the other. And yeah, that's why nowadays AI security is identity security. And working with the problem of this case, so it requires really holistic approach because it all starts with a unified approach for every identity type. So we covered it in the first slide. This includes your employees, your contractors, your partners, your contractors, and all of your non-human identities.
And it has to really cover every identity use case, things like governance, privilege access, access management. We heard ITDR, the threat protection, but also poster management. And these aren't just individual products anymore. They are an essential feature of a comprehensive identity security fabric nowadays. And this whole fabric has to integrate across all of your resources, your applications, your whole infrastructure, your databases, and your APIs. So about everything. And this really allows you to orchestrate all of your security events across your whole fabric.
So the left hand knows what the right is doing, right? And you can share your risk signals for coordinated defense and automated actions, like in our use case, universal lockout, the moment a threat occurs. And you really need an identity security fabric that helps you to ensure that all of your identities, employees, non-employees, non-human identities, including AI agents, can be safely secured before, during, and after authentication.
And yeah, that's where our Okta platform comes into the game, because our platform is modern identity security in practice, goes beyond authentication and provides access management. So we are providing phishing-resistant passwordless access across all the different kinds of identity repositories. Then we are talking about identity poster management. So finding and fixing risky configurations like MFA bypasses or over-privileged accounts. So we see it very, very often. Then we are hovering over to privilege access management.
So the goal here is to really protect critical resources with step-out authentication and secret spotting, right? The next part of our modern identity security fabric is governance. So really proactively reducing compliance violation, policy gaps, and all of the different audit failures that can happen. Then we are also talking and covering devices and assurance. So we want to make sure that only trusted devices can access all of your different systems. This is super, super important. And last but not least, talking about the ITDR topic, our identity threat protection solution.
So stopping threats after the authentication, like session hijacking, and with this powerful real-time risk signal sharing and automatic attack prevention. And yeah, the whole magic is how it all works together. So with our powerful secure identity integrations, we at Okta doesn't just protect identities. So we are connecting everything in your security stack. We are automating the risk responses and we are delivering zero trust security across your entire environment. And this is what modern identity security looks like in action.
And you really can invest in Okta, which is built to handle not only human scenarios, but as already mentioned, build an AI and NHI. Now, I want to switch gears a little bit and tell you that in every conversations with customers, yeah, we hear the same three needs when it comes to a different type of identities, nowadays AI agents. Number one, visibility. Where are they and who owns the different identities? Number two, control. What apps and especially what data can they access, right? And last but not least, governance.
How do we keep them and their access secure over time, not at initial onboarding? And with Okta, you can really ensure that end-to-end threat for different type of identities before, during and after authentication. And let's kick things off and start with visibility and our identity security posture management solution. So with Okta's so-called, Okta's ISPM, our architecture really directly addresses the identity blind spots by connecting to all critical data sources where all the identities are created.
So our solution really ingests data from identity providers, cloud infrastructure, SaaS applications, and we are enriching it with a threat intelligence. So when you see in the middle here, this whole AI-powered graph engine performs the crucial functions that all of the security teams really can't do manually because we are collaborating accounts across all the different systems. We are normalizing permissions. Then we are performing a kind of analyzing the usage patterns of the different identities. And out of the box, we are prioritizing different risks.
And this comprehensive approach really eliminates blind spots and delivers actionable outcomes that make previously invisible identity risks clear and manageable because you can't protect what you don't see, right? So in short, Okta Identity Security Posture Management is taking care of, for example, your state service accounts, users or admins where MFA bypass is configured. We are taking care also of your unrotated API keys and all the different unmanaged warehouse routes.
And nowadays, we are also fully capable of connecting to your legacy on-premise Active Directory environments and give you a full-blown deep-dive visibility for this environment as well, which is great. The next thing to consider is, yeah, control. And this is possible with so-called Okta-privileged access. So we focus on four main areas in the pub space. Number one is password access, like just-in-time access to your Windows or Linux servers. Then we are providing a vault for all your privileged accounts. So you can add them to our meta directory and vault them in a proper way.
Then we are also providing a way to protect secrets across different teams because nowadays, we know that teams are working at different locations. So our Okta-privileged access solution provides you a way to protect the secrets. And last but not least, we are super deeply integrated into governance and audit trades.
And yeah, the magic or the big benefit here is also all of this is powered by our complete identity security system within our security fabric. And maybe to add additional insights, strategic investments in our OPA solution we recently announced is the acquisition of XM security. And in the upcoming months, Okta will provide privileged access to also access your Kubernetes and databases to really ensure a time-bound access and just-in-time access and full traceability for auditing and compliance, which is super important.
Beyond that, we are really continuing our investments in securing, guess what, all of the NHIs. So first, we are really providing you access certification for all of your service accounts. Then we want to really empower end-users to perform their own on-demand rotations while also introducing a kind of shared assignments to make managing the thousands of service accounts easier for our administrators.
And third and last but not least, we are releasing support for workflow identities such as machines and software like CI, CD pipelines and cloud VMs as an example that have their unique and often imperial identities. We know that most of the breaches stem from some sort of identity-related attacks, making identity the number one attack factor. We saw the surveillance pictures on one of my first slides. And we really see more attacks that go beyond the typical stolen username password scenario. Remember the 70 billion extra filter cookies. Why?
Because the attackers are finding other ways to just compromise systems, including the user session. And here on this slide, you see a handful of attacks that are related to session hijacking. And you might be wondering why this is happening. Because nowadays, many organizations focus on enforcing assurance at the point of notification. But ask yourself, what about after the user has already authenticated? How do you maintain the same level of assurance throughout the entire user session?
And yeah, what better product to talk about securing user sessions than our so-called cutting-edge threat defense tool, Identity Threat Protection with Octa-AI. So talking about so-called IDP, the key capabilities include continuously evaluating risks and continuously evaluates risk and user context throughout the session, not just as locked in. Alejandro mentioned it. The OpenIDK protocol, where we are continuously monitoring for user session and device session context changes.
We are ingesting different signals across the stack from Octa, from different SaaS applications, from our devices, and from third party security tools via the OpenID shared signals framework, where we are working with big security players and making this real-time shared signal sharing possible. Another big benefit or another capability of IDP is we are triggering automated responses in real time. So like step-up MFA, when there's a change in the session context change, we perform session termination like universal lockout for supported application.
We are also capable of performance session termination on end-user devices like macOS. And last but not least, we are providing the powerful capability of security workflows. And with us, with Octa, protection really doesn't stop at the front door. So we are extending it across the full session and adapting to risk as it changes.
And yeah, we're also super excited and proud to announce that we as Octa were named as an overall leader in the 2025 IDP WAP report from Copenhagen. So this is the first time that Octa has been included in the report and all of you received badges as a market and product leader. So thank you so much. We are super happy and proud and we will continue to investing and making our capabilities and products better. We are extending the identity security fabric also to other services like device access. You remember the overall overview of our identity security fabric.
We just want to allow secured and managed devices. So our device access solution will give you a really seamless access from your OS authentication directly establishing the token with our phishing resistant authenticator for FastPass. Means that once you authenticate into your operating system, you have never to authenticate into anything again else unless the security risk is high enough for sure with this continuous monitoring part.
And on top of this, we are providing many, many other capabilities when it comes to Octa device access like introducing the device bound single sign-on capability where we are cryptographically bounding the session to the device. We are securing the first vulnerable touch point, the device lock-in with our desktop MFA solution for Windows and for macOS. And we are also leveraging Apple's native platform single sign-on capabilities to adapt the passwords and synchronization from your identity provider Octa down to your device so that there's always one less password to remember.
And last but not least, on the right side, you see the device lock-out capabilities where we are providing this session termination not only for an application level but also for the macOS devices itself. It makes it super, super, super, super powerful in different use cases within the identity security fabric. We also know that, yeah, over time roles change and permissions creep becoming a huge security risk. And finally, you need to be able to govern the entire life cycle of humans and energize.
And we at Octa are leading the charge from a really legacy reactive past to a modern proactive future because we are really pioneering a new security first approach that embeds governance directly into every identity workflow. So we detect and act on anomalies in real time, easily onboard and enforce least privilege over critical resources, and we are really prioritizing minimizing risk before, yeah, they ever become an issue. So we launched our Octa Identity Governance solution three years ago and have now over 1,600 customers, which is huge.
And from our point of view, Octa Identity Governance is the fastest growing modern governance product at the moment. So we have the most comprehensive enterprise ready end-to-end solution in helping you move beyond basic compliance. And overall, we are unlocking the next level of value by ensuring every single identity, doesn't matter which identity, has the right access at the right time and nothing more. And we also know that with so many tools and different configurations, security mistakes are easy to miss.
And most of the tools maybe also only tell administrators, hey, there's a problem, but we all know that that's not good enough. So our capabilities and our security access reviews are smarter. They identify the risk using intelligence and guide you really step-by-step from finding the issue to solving it. And we also want to know how the access is granted and how it's changing. And talking about governance and our governance analyzer quickly really cuts through complexity to strengthen security.
Because again here, it detects anomalies, recommends fixes, and ensures that all the reviewers really only focus on the highest risk item, last but not least, paired with security first. And we also know that effectively governed identities, you need to have integration that go deep and wide. And that's why we're up to offering the most extensive set of IGA integrations in the market, more than 800 scheme integrations, and 300 that go really deep to support role-based entitlements.
And really this step is a key reason our customers get faster time to value without having to build custom integrations.
And while legacy systems still may be your reality, we notice talking with so many customers, we're also actively investing to enable you to do more in the cloud by investing into governance for all your on-premise applications, like order provisioning to your local active directory, using kind of trickle migrations to move you away from password, going to efficient resistant authenticator state, and as already mentioned, introducing octa-join devices with our powerful device-bound single-sign-on feature.
Yeah, and to sum this up, so this level of visibility, access control, and governance is what it means to have an identity security fabric. So all the identities fully orchestrated in one place, and Octa's identity fabric is really designed to secure access for humans, service accounts, and also AI agents through a unified pipeline. So we really have a secure by default architecture that eliminates risky data synchronization between platforms while really maintaining super super high speed authentication.
And yeah, Octa is the only security platform that you will ever need and really gives you the confidence to say to you, to say to what's next, because you don't just reduce risk, you transform, you really transform the complexity into resilience, and you really need a platform that delivers comprehensive security outcomes. And that's why, yeah, so many organizations that embrace a unified platform approach to identity are seeing really measurable results. They're improving security, streamlining operations, and reducing the whole complexity without sacrificing agility or productivity.
We are super happy that they are trusting Octa to be more than just a vendor. We are the strategic partner for them, and we are helping them to secure everything from a traditional workforce access to the growing sprawl of AI agents and non-human identities. And that again is why a true identity security fabric is so crucial. It's not just about managing access anymore. It's about unifying visibility, controlling governance across all the different identities, human, non-humans alive.
And it really integrates deeply across your whole environment, continuously evaluates risk, and gives you the ability to act fast before all the different threats become breaches. That is super important.
And yeah, thank you for this opportunity, and thank you for joining us today. If you have any questions or want to really dive deeper into any of these topics we discussed, we'd love to continue the conversation with you. Thank you so much, Arkadius, for such a comprehensive presentation. You really touched all the points that I discussed, and the importance of unifying visibility, control, and governance in one place. And thank you for those practical recommendations that you also suggested.
We already have some questions in the chat, but before we do that, I will just go quickly to my final slides. We would like to let you know that we have more research on our website, from Identity Fabrics, to ITVR, to PAM, and other topics.
Also, we will be having the European Identity and Cloud Conference in May this year, taking place in Berlin. Would you be attending, Arkadius?
Yes, I will be there, waiting for my spot in the speaker session, so happy to meet you again and grab a coffee. Perfect, awesome, looking forward to that.
And yeah, some of our other services, we do also webinars, events, research, and advisory. So thank you.
As I said, there are questions in the chat directed to you, a few of them I could maybe contribute, but maybe we can start with the questions that were directed to you. So the first question is saying, if we implement your solution when we already have an adversary residing in our infrastructure, so that baseline behavior includes data exfiltration, how will this be detected?
Yeah, so good question. Also, it's always depending which solutions you have in place and how these are interacting. So as I described, the whole concept of the identity security fabric, let's pick, for example, the ITDR solutions where we are performing this continuous evaluation and we are interacting with different security point solutions or checking why the user is interacting with applications and while interacting with Okta.
So by getting all the different user session context changes and device session context changes, we can grab the data, normalize it, and based on our so-called first party detections, we can grab this information and map it against our AI detection models and perform the precise responses. So it's a little bit tough to give you an exact detail on your solution, but interconnect your infrastructure, grab all the details, grab all the signals, put it into Okta, and then get all the details, user and device context change and perform the outcomes like session termination or security workflows.
I hope that this answers the question, but again, super happy to jump on a dedicated caller meeting. Yes, please feel free to reach out to Arkadius if you have any more questions or you would like to elaborate more on his answer. We have another question for you. Could you please share some insights on AI identity security? What capabilities does Okta support here?
Yeah, good question. So definitely one of the top priorities and number one question since we are getting. So last year at our annual conference Okta in Las Vegas, we introduced our Okta Secure AI capabilities and we will provide very soon capabilities of protecting all the different AI agents within Okta.
Because for us, based on our so-called universe and meta directory, we will be able to discover the AI agents within our posture management, take control of these agents and put these agents into the visibility layer or universe directory, and then set the guardrails, map owners, assignments, different other capabilities, plus functionalities like cross-app access, where we can define where the agent with which application can communicate. So stay tuned. There will be some announcements in the upcoming weeks on Okta for AI agents and again here, feel free to reach out to us.
It's a super, super important and exciting topic and a lot of topics to come in the next weeks. And where can they find that information? On the website?
Yes, on the website, yeah. Awesome. One more question for you. Could you please provide a real world example of how a unified identity security approach has helped a company mitigate a specific type of cyber threat? Absolutely. So a great example would be a company that was, for example, I don't know, targeted by a sophisticated phishing attack. So the attacker managed to steal a user credential, but because the company had, for example, implemented strong adaptive MFA or phishing resistant authentication, the attacker's login attempt was flagged as high risk.
And this was due to a combination of different factors, like including an unfamiliar location, a new device, and this so-called high risk assessment automatically triggered up a cyber authentication challenge because we got the signal, we continuously evaluated, checked against our policies with our ATDR, and the attacker could not satisfy this. And this real-time risk-based decision prevented the attacker from gaining access to your company system.
And with this, we really can demonstrate the power of a unified security approach in mitigating this real world threat because at the point of authentication, phishing resistant is super important. And nowadays, it's standard because we know the basic MFA is there. But after the authentication, continuously monitoring, having the ability to check for changes, location, devices, etc.
And once a change or a threat appeared because IDX cookie or phishing resistant email was sent out, we are able to get this information, continuously evaluate against your guardrails, against your authentication or global session policy, and then perform the precise responses like in best case, press the red button, terminate all the sessions, and lock the user out of all the devices. Thank you for sharing that example. I could maybe add something here. Maybe not a concrete example, but more of a general idea.
If you have a unified view of identity risk, it primarily delivers value by reducing friction where it is unnecessary and also increases control where it matters. So from an operational perspective, if you have fragmented identity tooling, you can create duplicated investigations, manual correlation, and slow response cycles. But when you have all these identity signals together, the access context and behavioral telemetry are unified. So security teams spend less time stitching the data together and they can have more time on validating that risk.
And from a user experience standpoint, having this unified identity risk, it enables more adaptive risk-based enforcement instead of applying blanket controls. So yeah, I think there's clearly some business value in having this approach. We have one more question. How does Okta's identity security fabric address the security challenges of a hybrid environment with both on-premise and cloud applications?
Yeah, so we know that this is the reality for nearly every enterprise today. So it's a core strength of our platform because we at Okta was built to bridge the gap between on-premises and cloud environments. So we are using lightweight agents and standard protocols to extend to modern identity like Salmonet and OIDC. And as I mentioned during the presentation, not only every identity type, every identity use case, but every resource.
So we are having tools and capabilities where you can interconnect via small and powerful secure proxy gateways to interconnect to your on-premise environments and getting this visibility into your on-premise environments and having the continuous risk signal sharing and continuous authentication part. We can also perform this powerful precise action responses like security workflows and or session termination. And I also mentioned it in the first phase of the whole visibility.
Here, one of our latest releases when it comes to the whole security posture management software, we are now also capable of interconnecting to your legacy AD environment. So not only our cloud with our more than 8,000 integrations where we are super strong, but most important that we are fully supporting hybrid environments, we can connect to your on-premise application and give you the full power of this whole identity security fabric for the cloud, but also for your on-prem applications.
Thank you, Kadir. Maybe just before we wrap it up quickly, I would like to take a look at the results of the poll that we conducted. So the question was, do you already have a comprehensive identity fabric? And 50% of the respondents said work in progress, while 25% said yes, the other 25% said no. Are you surprised with that? Does that resonate with what you see in the market? Yeah. What do you think of the number?
Yeah, absolutely. I mean, that's why I guess we're having this webinar.
Yeah, I agree. I agree. So it's shifting, but it will take some time.
So, yeah, this is definitely the numbers and the stats that we see while talking with so many customers. Absolutely.
Well, thank you so much, Kadir, for joining us today. Do you have any maybe key takeaway, any concluding thoughts before we wrap it up?
No, stay safe, stay secure, and wrap up the webinar again, review the slides, reach out to Kupinga, reach out to Okta, and yeah, join us at IEC this year to talk about the unified security identity fabric. We will be there.
And again, thank you very much for having us. Was a pleasure to talk about the security fabric from an Okta perspective today. Thank you very much and see you at IEC. See you. Bye.
See All Locations
See All Locations