Okta expands identity governance & access security
Tue, 15th Sep 2026 (Today)
Okta has introduced new products and features across its identity governance and privileged access portfolio, while expanding identity threat detection through Permiso Security.
The changes span Okta Identity Governance, Okta Privileged Access and identity threat detection tools for human users, service accounts, workloads and AI agents. The additions are intended to give security teams more automated control over access and permissions as organisations expand their use of cloud services and AI systems.
New governance measures include Advanced Entitlement Management for AWS, Intelligent Request Recommendations and Automated Drift Detection & Remediation. They are designed to help companies track detailed permissions, provide approvers with recommendations based on prior requests and usage, and identify unauthorised access changes for removal.
Okta is also rolling out what it calls 48-Hour Integrations for its governance and privileged access products. Using AI, it aims to deliver new integrations in as little as 48 hours, compared with a previous manual process that took two to three months. This builds on a catalogue of more than 8,000 pre-built integrations.
On the privileged access side, Okta is adding Unified Database Security, Dynamic Kubernetes Protection, Network Device Coverage and Machine-Speed Workload Protection. These features are aimed at controlling access to databases, servers, SaaS accounts, Active Directory environments, network hardware, automated workloads and AI agents.
Okta tied the update to concerns over standing privileges and credential misuse in corporate systems, citing data that credential abuse accounts for 39% of all breaches. The company said this reflects a shift in attack methods from breaking into systems to using valid logins.
Broader push
The changes also follow Okta's move to broaden its identity threat detection and response efforts through Permiso Security. According to Okta, Permiso adds identity risk signals, behavioural analytics and threat detection across multiple identity providers, cloud environments and SaaS applications.
This would extend monitoring beyond employee accounts to non-human identities and AI-driven processes, which now make up a larger share of enterprise technology estates. Companies increasingly have to manage access not only for staff but also for software workloads, service accounts and autonomous tools operating at high speed.
"Nobody wants to slow AI down, but you can't simply hand out access and hope for the best," said Ely Kahn, Chief Product Officer at Okta. "Enterprises need a one-stop shop to govern, secure, and monitor every identity: humans, AI agents, and non-human workloads alike. By bringing governance, privileged access management, and threat detection together on a single, independent platform, we're giving security leaders dynamic, real-time control and turning zero standing privilege from a theoretical goal into an everyday operational reality."
Okta argued that manual access reviews, overlapping permissions and approval backlogs have made access control both an operational and a security issue. A unified approach, it said, could ease those pressures while maintaining compliance requirements.
A study by Forrester Consulting, cited by Okta, found that users of its unified platform could onboard new applications 75% faster and achieve an overall return on investment of 216%. Okta presented the figures as evidence that stronger identity controls do not necessarily slow software deployment.
Regional view
Stephanie Barnett, Vice President, Presales, Asia Pacific and Japan at Okta, pointed to the pace of change in access management across the region. She said organisations are now dealing with a much broader identity base than in earlier security models.
"Across Asia Pacific, organisations are managing a rapidly expanding identity landscape. They're no longer securing access for employees alone, but also for service accounts, workloads and increasingly AI agents operating at machine speed. Static access models and fragmented security controls weren't designed for that environment. Bringing governance, privileged access and threat detection together gives organisations greater visibility and control over who, and what, has access, while helping them adopt AI and automation without introducing unnecessary risk," said Barnett.
A customer example highlighted labour savings from automating access reviews. The case reflects a core selling point for identity governance tools as security teams face pressure to manage more users and systems without adding equivalent headcount.
"We've been able to automate most of our access campaign work with Okta Identity Governance. It now takes one of us a day of work instead of two of us spending a full month of our time," said Ashley Taylor, IT Security Analyst at Instructure.