惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
V
V2EX
爱范儿
爱范儿
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Martin Fowler
Martin Fowler
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
小众软件
小众软件
Vercel News
Vercel News
博客园 - 司徒正美
阮一峰的网络日志
阮一峰的网络日志
V
Visual Studio Blog
J
Java Code Geeks
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog
B
Blog
美团技术团队
量子位

CSO Online

New malware turns Linux systems into P2P attack networks Poisoned truth: The quiet security threat inside enterprise AI Train like you fight: Why cyber operations teams need no-notice drills Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS
Palo Alto bets on identity security for autonomous AI wit...
2026-05-13 · via CSO Online

Palo Alto Networks has launched Idira, a new identity security platform aimed at securing human users, machine identities, and AI agents amid the rising adoption of autonomous AI systems amongst enterprises.

The company is positioning Idira as a next-generation identity security platform that goes beyond traditional privileged access management (PAM) systems by applying dynamic privilege controls across every type of identity inside an enterprise.

“For most of the last two decades, identity security was built on a comfortable assumption: One can maintain a firm divide between a small number of powerful administrators and a much larger number of ordinary users; that is enough to secure the organization. That assumption no longer holds,” Peretz Regev, chief product & technology officer at Palo Alto, said in a blog post.

The launch follows Palo Alto’s acquisition and integration of CyberArk, which forms a key foundation of the platform.

Palo Alto’s bet on AI-era identity security

“The fundamental problem today is scale,” said Rohan Vaidya, AVP Sales India and SAARC.  “Most organisations are already running AI agents — and those agents authenticate, call APIs, access sensitive data, and can escalate their own privileges to complete a task. No legacy IAM or PAM platform was designed to see any of that, let alone control it.”

With Idira, Palo Alto attempts to address these risks by treating every identity in the organization as privileged.

“What Idira does differently is operate as a single control plane across all three identity types; human, machine, and agentic. On the discovery side, it continuously scans SaaS, cloud, and developer environments to surface every active agent and machine identity, enriching each one with context: who owns it, what it can access, and what permissions are actually in use. That alone closes a blind spot most security teams don’t even know they have,” Vaidya said.

Analysts say Idira is attempting to address gaps that traditional identity-management platforms such as Auth0 and SailPoint were not originally designed to handle, particularly around governing autonomous AI agents in real time.

“Auth0 excels at consumer identity and enterprise single sign-on, but its core architecture is not natively designed to govern the dynamic, autonomous nature of generative AI agents. SailPoint, on the other hand, provides excellent AI-driven insights for human access governance, such as role discovery and certification recommendations, but it primarily focuses on lifecycle management and compliance rather than runtime security for autonomous actors,” explained Amit Jaju, senior managing director at Ankura Consulting.

Jaju added that what genuinely sets Idira apart is that instead of granting an agent static access tokens (which Auth0 or SailPoint might manage), Idira dynamically elevates privileges exactly when an agent needs to execute a task and instantly revokes them afterward.

CISOs navigate AI risks

For enterprises, the launch reflects a broader industry shift toward identity-centric cybersecurity models as organizations deploy generative AI tools, autonomous agents, and cloud-native applications at scale.

Analysts say the growing number of non-human identities is creating operational and security challenges because many existing identity systems were originally built to manage employees and IT administrators rather than AI agents and automated services.

“A self-contained AI agent can engage with systems, initiate processes, and make decisions without any form of human validation. This presents a much bigger threat surface. Current technologies that help manage this issue address only some aspects of the problem, many having been built without the intent of handling machine speed, highly dynamic environments,” said Devroop Dhar, co-founder and CEO at Primus Partners.

As identity, cloud security, artificial intelligence governance, and SOC workflows continue to converge, organizations will find themselves becoming more and more reliant on one particular ecosystem, Dhar said. The advantage here is ease of operation, a consolidated view, and greater integration.

The downside is less flexibility over time. Breaking away from the system at a later date may prove challenging since identity management procedures and other processes will be woven deeply into business operations. In the coming years, CISOs will favour ecosystems that support open architectures, Dhar noted.

Analysts also caution that none of the platforms eliminates the need for multilayered security. Organizations will need to maintain good identity hygiene practices, implement least privilege, utilize MFA, rotate credentials, and conduct constant monitoring.

“Another aspect to address relates to agent governance. There must be a clear understanding of what assets can be accessed by agents, under what circumstances human intervention is required, and how agent activities are monitored,” said Dhar.

Enterprises must invest in prompt filtering systems to prevent prompt injection attacks, which currently stand as the largest vulnerability in AI systems, Jaju said. “They should also engage in continuous adversarial testing and agentic red teaming before deploying any autonomous system into a production environment.”

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.