Thank you, Matthew. Afternoon, everybody, and welcome to the session, From Desktop to AI, Orchestrating the New Identity Perimeter. My name is Arkadiusz Krowczynski. I'm part of the product organization at Okta and work as a principal product acceleration specialist.
Yeah, I know, complicated topic, complicated job description, complicated name, so I will try to explain it in simple terms. So, safe harbor, we will talk about forward-looking statements to be on the safe side of the house and some fictitious information while we are showing a couple of demos.
All right, for those who are talking with us or hearing us at different conferences, it's all about to get security right, you have to get identity right, right? And we also know from our point of view that AI is the biggest platform shift since the internet, so to get AI right, you still have to get identity right, correct? And it's not only about AI agents. It starts sometimes the moment your employee is touching the keyboards in the morning, so we have to secure different kinds of identities, human, non-human AI agents, but also our lovely devices.
So, some stats and figures, so 100 machines per human, so we are talking with organization enterprises and they can't tell you how many agents, non-human identities they have, let alone what they are doing, right? So that's again the message why we have and we need to secure all these different types of identities. And we also know based on different reports, 88% have had an incident, right? And 97% of those breached, that's the hard truth, lack proper controls, right? So you spend a decade developing least privilege, zero trust, adaptive auth for humans, right?
But AI agents, non-human identity devices are not humans, so sometimes there's no single sign-on, no MFA, and no standard workflows. So last year in Las Vegas at Octane, our annual conference, we talked about the concept of the identity security fabric, so a unified approach to identity security. So most of the organization focus on securing the access at or during authentication. Our fabric covers all the different kinds of use cases as you see on the slide here, before, during, and after authentication.
So I want to just showcase you and double-click what it means when we are talking about our identity security fabric. So for us, our statement is secure by default. That means no lateral movement, no unnecessary data sync, just secured and controlled access. And if we look at this, and if we look at this pipeline, so it's a busy one from your left to the right, someone wants to gain access to something. It can be a human user, it can be a non-human identity, it can be an AI agent. It doesn't matter. So in between, we as the IDP start to ask you a couple of questions. Are you authenticated?
Are you authorized? What resources should you have access to? And inside this pipeline, there are three layers. So first of all, we have this edge security in the beginning, the green bubble, where our edge security and threat insights teams are filtering out 90% of the malicious attempts, the malicious attacks, and that someone wants to knock on your door. The remaining 10% hits the global session and authentication policies. And when you see on the screen here, the next stop for us, it's our global session policy, where we are evaluating for behavior detection for different resources.
All this is happening before the user logs in. We are checking the policies and baselines in the back. And if it's needed, we are getting back to the user and asking, hey, for permissions, for prompts, et cetera. The next step is about the user interaction, so the black bubbles. If you are a known user coming from a known device that is registered in our platform with our phishing-resistant authenticator called OctaFastpass, everything is great. You just put your finger on your Touch ID Mac, you look into your cam, say hello to Windows Hello, and you are signed in.
But if you are a contractor, we will ask you for sure, please verify with a high assurance factor with OctaVerify Push. You can leverage 502 securities, security key, whatever. So we will check you and make the right decision. Next up for us are our authentication policies, that you can create a model inside our Octa platform. Within this authentication policies, you have different capabilities and options. So we are talking with all the different EDRs and MDMs and checking for different signals from CrowdStrike, Zscaler, Sentinel-1, whatever. Is your device managed? Is your device not managed?
And then we make the decision, hey, MFA or no MFA. That's it. So this is the whole so-called IDP pipeline. All you see here is happening super super fast, so between 200 and 300 milliseconds. Now while talking about this identity security fabric, we are extended also to so-called unified security outcomes to our devices with, for example, OctaDevice Access that secures the first vulnerable touchpoint, your device login, macOS, Windows, whatever.
So once you're successfully authenticated strong, which in best case a phishing-resistant authenticator, you will gain access to your dashboard, to the applications in a seamless but secure way. But if we see that the high risk occurs, we will still ask you for different kind of authenticator like FastPass, whatever. Second security outcome is recovery or device proofing. So for example, if a contractor or seasonal worker is trying to register to your platform, we have the ability to include identity proofing within our workflow in the identity security fabric.
That means, for example, again you can put your IDV verification solution into the workflow or, for example, if you lost your phone, forgot your YubiKey and you have to register for a new one, no problem. High assurance, we make really sure to check everything before you will get access to our environment. Last but not least, it's all about continuous evaluation and continuous checking. So it's great if you get a 60-minute lifetime session to your environment, to your Okta dashboard, to your application.
So you are authenticating in the first minute, but hey, what about the remaining 59 minutes, right? So with our solution that we will cover also in the next slide, we are continuously checking for device posts, user session context changes, and many, many more. So this is what it calls our Okta identity security fabric. So let's dive into the security identity outcomes for Okta device access. Okta device access was built for a simple purpose, unified seamless and secure access from your device to the application. And here we are covering multiple options and multiple use cases.
Just-in-time local account creation on macOS. If you have shared devices in your macOS fleet, we got you covered. It means that if you onboard your new users, we are directly providing instant access from the macOS login window from your Okta IDP solution. The next topic is desktop password sync or nowadays platform single sign-on. That means that we keep your local password on your macOS always in sync with Okta as the identity provider.
In addition to this, we also introduced and released last week an advanced or an addition to the desktop password sync via secure enclave, means we are registering your device for platform single sign-on, but there's no need or no necessity to sync the Okta password down to a device. Desktop MFA. So it's all about, again, securing the first vulnerable touchpoint the device login. And here we are covering your Windows fleet and your macOS fleet. We are providing also a kind of passwordless solution on the Windows side of the house.
Once authenticated on device with the second, third, or whatever session, you get a seamless, secure authentication to your Windows device with a high assurance factor like a push or with a security key when it comes to phishing-resistant authenticator. On your macOS side, it's similar the same. The issue is here that unfortunately at the moment there are no capabilities providing a passwordless solution on your macOS side of the house, but we are actively working with Apple on this.
And for our Windows friends, we will release very soon also native biometric capabilities to our own Okta device access credentials provider. Next one, device-bound single sign-on.
What that means is once you successfully authenticate on the Windows side of the house with a high assurance factor or on the macOS side of the house with a secure enclave key, we are storing the key cryptographically on the device on the Windows in the TPM or on the macOS in the secure enclave, and we will give you seamless, secure access to all of your different applications that are connected to Okta without prompting for MFA again. And last but not least, device lockout.
So our Okta device access solution within our identity security platform operates and is exchanging signals with our identity threat protection solution. Means once a threat is detected and your admin has configured a device lockout policy, we will not only lock the user out of supported application, but we also lock the user out instantly out of the macOS device.
Great, so here a very short demo how a seamless, secure device onboarding on the macOS side of the house is looking like with identity security outcomes and ID verification. So let's keep it rolling. The user's unboxing the device has to provide their identity, driver license, or other documents. Once the verification was successfully completed, they will be prompted to enroll into a factor and then platform single sign-on kicks in. So in this moment, we are registering the device to the Okta platform. The MPM capabilities continue. We are enrolling into Touch ID.
And the last step for us is fully enroll the device to Okta, closing the chain and having, if you want, the password in sync or go with the secure enclave. On the second login, we are providing the user to enroll into Okta Desktop MFA, scanning the QR code for offline access so that you get access if you are sitting on the plane. And once you want to log in, you can log in with FIDO2 key.
With device post single sign-on, very fast forward here, you get seamless, secure access to all the different kinds of applications that are connected into Okta because we already stored the secure token on the device and no MFA prompts anymore. Second part when you're talking about our devices is the device assurance, the device posture part. So here we are providing you the ability to make the right access decisions. So our concept of device assurance policies have been in our platform for years.
We are now extending these capabilities to advance posture checks where you can leverage your own brain, your own OS queries and bring your intelligence into our platform to check for software that is not approved by the IT. Maybe someone has installed OpenClaw on the device. Do you really want to gain access to the platform? This is really possible with advanced posture check on the macOS side of the house but also on the Windows side of the house. Super easy to implement. Create your own advanced posture check. Attach it to your device assurance policy.
Remember the different authentication policy in our platform and then you are good to go. So in this short demo, just want to showcase and highlight how this is looking like on a macOS device as well. This is also now supported on the Windows side of the house. The user tries to access the Okta dashboard. In this moment we are checking against the device assurance policy. So firewall is not enabled. You can push the config via MDM, whatever. Once the firewall is enabled again, hey we are checking against advanced posture checks. Firewall is on. Device assurance is met.
Authentication policy is checked. MFA being prompted and you are good to go and access your application. Next and last part is the continuous evaluation. So we secured a login. We secured the access decision. But now we have the hardest part, right? So what happens after the user has successfully authenticated to the platform? Remember the example of the 60 minutes session lifetime.
So within our fabric we have the so-called solution Identity Threat Protection, short ITP, where we are continuously evaluating against our first party signals with our own agents where we have different kind of detections like, hey someone is trying to brute force your identity against our platform or someone has stolen your session cookie and wants to get it into your platform. So these are so-called our first party detections plus the device assurance part.
And we are also interacting and talking with many, many security vendors where we are getting different security signals via the OpenID Shared Signals Framework. Because for us security is a team sport. So all the CrowdStrike, Zscaler, Sentinel ones jump out there. They are connecting with us and once their solution detects something malicious, a medium or high risk, they will send us the signals via the OpenStandard. In this moment we will re-evaluate the different kind of global session policy, authentication policy and make the decision.
Okay, if it's a medium risk, maybe I want to execute a recertification campaign in the governance part. But if it's really a high risk, I want to really lock the user out. So revoke the global session or the global token and kick the user out. In best case of all the applications, maybe move the user to a quarantine group. And if it's supported, remember the Identity Security Fabric outcome, lock the user out also on the device. Last short demo on this with our CrowdStrike friends. So here we will see a device or user that has the CrowdStrike agent successfully configured.
So he or she will successfully lock into the device with or without fast pass or phishing resistant factor, access the applications, whatever. And then in the background when bad things are happening and CrowdStrike will detect something malicious based on our EDR integration that we have in place with CrowdStrike or based on the shared signals framework SOAR workflow detection. So we have different capabilities how we are talking, interacting and executing together with CrowdStrike.
So once the CrowdStrike platform has detected malicious activity, they will send us a medium, a high or whatever risk signal that you can successfully configure in the platform. And then we are re-evaluating, as mentioned, our policies. So your access to the dashboard. And if it's a high risk, we will kick you out of all the supported applications like, hey, lock me out of Salesforce instantly, lock me out of the Okta dashboard instantly. So revoke my session.
And if you are running at the moment on a macOS device, please lock the user out of the device and maybe deactivate the device in the Okta platform. So that's the power of continuous evaluation within our platform. So coming from desktop to the AI, we also have within our platform the privileged access management capabilities that we are working on now for several years. Instant access to server infrastructure, secrets rotating. And now we are also bringing workload identity automation within our PAM solution.
So CI, CD pipeline, cloud workflows, AI agents, they all need access to something. And traditionally you have secrets that are not being rotated. And with our workload identity federation, we are stopping this. We are going into cryptography attestation and we are eliminating everything and we have short-lived tokens. So this is possible now. It's available in our platform in the privileged access management. To sum this up, this is the whole platform.
Yeah, 99% uptimes, billions of logins. And we covered a few topics today. So from a device perspective, device access, device assurance, identity threat protection, where we are securing different kinds of identities in the device.
So for us, the protection doesn't stop at for the humans. So we are covering every identity type, every identity use case, and every resource type, because it's all about risk signal exchange and sharing across the whole platform. If you want to know more how we are actively providing and talking and securing the new agentic era, feel free to come over to our keynote session tomorrow together with Essentia, where we will cover the three important questions. Where are my agents? What can they connect to? And what can they do? So thank you for your time.
I hope you enjoyed the presentation and see you next time.