→ Back to Home
Application Security

Portnox Integrates with Microsoft Defender to Secure Emerging AI Agent Identities

Cloud-native access control provider Portnox has announced an expanded integration with Microsoft Defender, aimed at enhancing the governance and security of artificial intelligence (AI) agents and other non-human identities within corporate networks and applications. This move extends Portnox's existing integrations with endpoint security platforms like CrowdStrike and SentinelOne, allowing any of these solutions to trigger real-time access decisions. The core functionality enables Portnox's policy engine to restrict, quarantine, or revoke access for AI agents if a threat is detected or compliance is breached, based on predefined customer rules. This development is significant because it directly addresses a growing blind spot in enterprise security: the inadequate management of AI agent identities. As AI agents increasingly participate in enterprise operations, accessing sensitive data and performing actions autonomously, relying on static credentials and human-centric access models becomes a critical vulnerability. A recent VentureBeat study revealed that 54% of enterprises have already experienced a confirmed security incident involving AI agents, with 69% admitting to sharing credentials across these agents. This integration provides a much-needed "kill switch" at the network layer, offering dynamic enforcement that can precede traditional identity provider revocations. This trend aligns with the broader shift towards Zero Trust architectures and the increasing complexity of securing distributed, cloud-native environments. The proliferation of AI agents introduces a new class of identities that behave fundamentally differently from human users, necessitating continuous verification and adaptive policy enforcement. This is a natural evolution of DevSecOps principles, extending security left into the design and deployment of AI-driven applications and right into their runtime operation. The challenge is not just about identifying these agents, but about continuously monitoring their behavior and dynamically adjusting their access based on real-time threat intelligence and compliance posture. This moves beyond perimeter-based security to a more granular, identity-centric approach, which is essential in the AI era. In practice, this means security and DevOps teams must prioritize updating their IAM frameworks to include non-human identities. Practitioners should evaluate their current AI agent deployments, identify where static credentials or shared accounts are in use, and explore solutions that offer continuous monitoring and real-time enforcement. The integration of access control with endpoint detection and response (EDR) or extended detection and response (XDR) platforms, as demonstrated by Portnox, becomes crucial. Organizations should focus on establishing clear policies for AI agent behavior, implementing least privilege access, and ensuring that security tools can communicate and act in concert to prevent, detect, and respond to anomalous AI agent activity. This proactive approach is vital to mitigate the risks posed by these powerful, autonomous entities.
#ai security#identity and access management#non-human identities#devsecops#runtime security#microsoft defender
Read original source