Delinea buys StrongDM to secure AI-era privileged access
Delinea has completed its acquisition of StrongDM, combining privileged access management with just-in-time (JIT) runtime authorisation as organisations expand the use of AI agents and automation across cloud and hybrid estates.
The deal brings together Delinea's privileged access management tools with StrongDM's runtime authorisation, which governs privileged actions as they occur. The combined offering targets security teams managing access for both human users and non-human identities such as services, workloads and AI agents.
Machine-to-machine activity has grown in modern engineering and DevOps environments, increasing the number of identities that need privileged access to infrastructure, data stores and production systems. Security teams have also had to limit permissions without slowing operations.
Runtime control
Privileged access management has often relied on standing credentials and persistent permissions. These long-lived permissions can create exposure if they are stolen or misused, or if access expands beyond what is needed over time. Delinea and StrongDM position runtime authorisation as a way to evaluate access at the moment of action, rather than relying only on initial login or static entitlements.
"Standing and hard-coded privileges remain one of the largest sources of risk in modern, AI-driven environments," said Art Gilliland, CEO of Delinea. "Security teams have historically had to balance between strong identity governance policies and maintaining developer and operational speed. By bringing StrongDM's runtime authorization capabilities to the Delinea Platform, we're empowering rapid and secure AI adoption for our customers."
The combined platform includes a unified identity security control plane and uses Delinea Iris AI for policy evaluation and governance. It assesses privileged actions taken by both human and non-human identities across modern infrastructure.
Non-human identities
Security leaders have increasingly focused on non-human identities as automation expands. These can include API clients, containerised workloads, service accounts and AI-driven tools that act autonomously. They often require elevated permissions and can operate at a pace that makes manual review difficult.
The combined platform covers infrastructure, databases, containers and CI/CD pipelines, and provides discovery and governance for privileged access across human and non-human identities. Delinea said reducing persistent credentials can cut exposure to credential theft, phishing and software supply chain attacks.
"The rise of agentic AI and non-human identities is accelerating operational workflows to machine speed, exposing the limits of static privilege models," said Emanuel Figueroa. "By incorporating StrongDM's JIT runtime capabilities into the Delinea Platform, organizations can extend Zero Trust to the precise moment of action and advance toward ZSP across both traditional and cloud-native environments."
The acquisition also reflects a broader shift in identity security. Many organisations now treat identity and authorisation layers as a central control point for security policies across distributed environments. This approach can align with Zero Trust programmes that evaluate access based on context, policy and risk signals, rather than network location alone.
Customer view
Axos Financial has used both vendors, according to its chief information security officer. The company described the combination as relevant to modern database and cloud environments, as well as traditional infrastructure.
"I'm genuinely excited about the possibilities of a unified platform. Delinea has done an excellent job securing privileged access across traditional infrastructure for nearly a decade at Axos, while StrongDM solved just-in-time access in innovative ways for modern database and cloud environments. When Delinea articulated a vision to bring these capabilities together, it immediately resonated with how we operate and where we're headed. The combined platform will significantly strengthen our security posture by enabling continuous discovery, governance, and real-time enforcement of least-privilege access across critical systems and data, which supports our AI initiatives and accelerates our move toward ZSP in alignment with business priorities."
Delinea said it will use the combined platform to evaluate and authorise privileged actions in real time across AI-driven environments. Financial terms were not disclosed.
Delinea expects the combined platform to provide centralised visibility, auditability and enforcement for privileged actions across hybrid and cloud-native environments.