This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

How an Identity Fabric Powers Zero Trust in the Agentic Era

Download resources

About this session

An Okta principal solutions architect argues that zero trust, defined after Operation Aurora and formalized by NIST in 2020, has finally found its forcing function in the agentic era: AI agents and their non-human identities multiply the attack surface faster than legacy identity practices can track. He contrasts standing, long-lived privileged accounts (the traditional DBA model) with just-in-time, short-lived access granted by policy and revoked automatically, illustrated by an anecdote where an over-scoped agent deregistered strangers from gym classes to book its owner a spot. His core argument is that identity is the only practical control plane for agentic workflows, because every agent action traces to an owner, an initiator and a chain of custody, and that visibility, inventory, scoped permissions and lifecycle management, including reassignment when an owner leaves, must replace prompt-based guardrails, which adversaries reliably defeat. He previews Okta's newly announced Blueprint Alliance with AWS, CrowdStrike, Databricks, Google Cloud and others to standardize agent security, and closes urging attendees to inventory their non-human identities, move to ephemeral access, and treat identity as a continuous process rather than a one-time project. Audience questions cover scoping an over-privileged backend engineer's access and distinguishing an agent's owner from its initiator.

For over a decade, 'Zero Trust' has been the goal, yet the promise of true least privilege remains elusive. Now, as we enter the Agentic Era, the explosion of autonomous AI and machine identities creates an unprecedented and often invisible expansion of the attack surface. This session moves beyond the buzzword to explore why traditional approaches have failed and how a modern Identity Fabric is the essential architecture to finally achieve Zero Trust. We will discuss how to shift from a flawed model of static permissions to a dynamic state of 'Zero Standing Privilege' for every identity—human and machine—across your enterprise.

Key takeaways

  • Replace standing privileged accounts with just-in-time, short-lived access granted by policy, for human admins (like DBAs) and AI agents alike.
  • Register every AI agent as a first-order identity in your IDP with a named human owner, and reassign that ownership immediately if the person leaves.
  • Never rely on prompt instructions as your primary guardrail; adversaries reliably break through context windows, so enforce control through identity and scoping instead.
  • Track both an agent's owner (accountable for governance) and its initiator (accountable for a specific run), and log the full agent-to-agent hop chain through an agentic gateway for auditability.
  • Inventory your MCP servers, service accounts and non-human identities now; unused or orphaned accounts and long-lived tokens are what agentic-speed attackers look for first.

Speakers

Mike Berthold
Mike Berthold
Principal Solutions Architect & Team Lead · OKTA
Mike is a Senior Solutions Architect based in Montreal, Canada. He covers the Okta Platform (Workforce Identity and Customer Identity) as well as Auth0 as part of Okta’s Office of the Field CTO (OFCTO) Presales team. He works with his colleagues to… Read moreRead less

Mike is a Senior Solutions Architect based in Montreal, Canada. He covers the Okta Platform (Workforce Identity and Customer Identity) as well as Auth0 as part of Okta’s Office of the Field CTO (OFCTO) Presales team. He works with his colleagues to build deep relationships with Okta customers in North America, help design successful outcomes and ensure the smooth planning, deployment, and ongoing use of Okta's solutions. Mike has been working in Identity for over 20 years and holds several certifications, including CISSP and Okta Certified Technical Architect (OCTA).

Resources

Photos

Tags

More from GoSec 2026

Also from Mike Berthold

On the same topic